SecJobs
RoleSuite
CompaniesRemoteAboutMethodologyContactPrivacy
Updated 2026-06-11 13:00 UTC·© 2025–2026 RoleSuite
← Back to listings

Security Analyst (Cyber Defense Analyst)

AHEAD · India

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.
 
At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD. 
 
We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived. 
 
We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD. 

AHEAD is seeking a Cyber Defense Analyst to join the AHEAD Corporate Security Cyber Defense team. This position contributes to the successful delivery of AHEAD’s information security program in order to assure AHEAD stakeholders of strong operating controls and effective defensive capabilities.

The Cyber Defense Analyst is responsible for monitoring, triaging, investigating, and reporting on security events across the enterprise. A typical day will include reviewing and remediating alerts in our security platforms, supporting incident response activities, improving detections, and working on information security-related projects that strengthen AHEAD’s overall security posture.

Reporting directly to Corporate Security leadership, the ideal candidate must be a professional, collaborative team player that is comfortable working with people at all levels of the organization. Applicants should possess strong analytical, communication, follow-up and quality assurance skills, along with the ability to operate effectively in a fast-paced security environment.

Responsibilites:

  • Monitor, triage, and analyze security alerts, telemetry, and log data across enterprise security platforms, including SIEM and other detection technologies.
  • Perform in-depth analysis of exploits, attacker behavior, and anomalous activity across endpoint, identity, network, cloud, and application data sources.
  • Review and correlate security events in the SIEM to identify threats, validate detections, and support timely incident declaration and escalation decisions.
  • Document investigative findings, response actions, and evidence throughout the incident lifecycle, and provide timely status updates to leadership and stakeholders.
  • Conduct proactive threat hunting and threat research to identify emerging risks, adversary techniques, and gaps in current detection coverage.
  • Contribute to detection engineering and response automation efforts that improve Cyber Defense monitoring and containment capabilities.
  • Support security tooling operations by helping maintain the effectiveness, reliability, and visibility of core defensive technologies used by the Cyber Defense team.
  • Assist with the development and refinement of incident response processes, playbooks, workflows, and operational procedures to improve overall Cyber Defense effectiveness.
  • Communicate intrusion activity, incident details, threat trends, and recommended actions clearly to internal stakeholders and leadership.
  • Partner with infrastructure teams and system owners to review vulnerability findings, help prioritize remediation, and track closure of high-risk issues.
  •  

    Qualifications:

  • 5+ years of experience in information security, ideally including direct experience in incident response, cyber defense, or security operations in a corporate or enterprise environment
  • Hands-on experience with SIEM platforms, including creating and using searches, dashboards, alerts, and investigations; experience with CrowdStrike NG-SIEM strongly preferred
  • Experience with Microsoft 365 security technologies, including Microsoft Defender XDR for email, identity, and collaboration platforms
  • Basic knowledge of networking concepts and cloud environments, including AWS and Azure
  • Foundational knowledge of Windows and macOS
  • Strong written and verbal communication skills, including clear incident documentation and the ability to communicate technical findings to non-technical stakeholders in a global environment
  • Familiarity with MITRE ATT&CK, NIST CSF, CIS Controls, or similar security frameworks is preferred
  • Basic familiarity with scripting or query languages such as PowerShell, Python, or similar to support automation and analysis is preferred
  • Experience supporting vulnerability management processes using tools such as Tenable and Wiz, including triage, validation, prioritization, and remediation tracking is preferred
  • Bachelor's Degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field
  • Certifications:

  • CCSP, GCIH, CySA+, GSEC, SSCP or similar cybersecurity certification required
  •  

    Security pay context

    Based on 1,614 disclosed Security salaries on RoleSuite, the role pays a median of $142K/year, with most offers between $114K and $184K (10th–90th percentile: $92K–$219K).

    See the full Security salary breakdown →
    Apply →

    Other roles at AHEAD

    • Product Engineer IIIndia
    • Manager SecurityGurugram, Haryana / Hyderabad / Bangalore
    • Corporate Technical RecruiterReading
    • Principal Technical Consultant – VMware Cloud Foundation (VCF)United Kingdom
    • Senior Technical Consultant – VMware Cloud Foundation (VCF)United Kingdom
    • Senior Engineer - Privileged Access ManagementUnited States
    • Engineering TechnicianIndia
    • DevSecOps EngineerGurugram, Haryana
    • Security AnalystIndia
    • Technical Team Lead - AWSGurugram, Haryana

    More Security roles

    • Security EngineerDialpad · Bengaluru, India
    • Security Operations AnalystJobgether · US
    • Vulnerability Management Specialist - Assistant Vice PresidentiCapital · Lisbon, Portugal
    • Security Engineer, Data Center Network Device SecurityGoogle · Sunnyvale, CA, USA
    • Security Researcher - Bot Detection Adversarial ResearchJobgether · Estonia
    • Security Researcher - Bot Detection Adversarial ResearchJobgether · Hungary
    • Security Researcher - Bot Detection Adversarial ResearchJobgether · Finland
    • Security Researcher - Bot Detection Adversarial ResearchJobgether · Czechia
    • Security Researcher - Bot Detection Adversarial ResearchJobgether · Norway
    • Security Researcher - Bot Detection Adversarial ResearchJobgether · Luxembourg