Role Description
We are looking for a Security Analyst to join the Bloomreach GIST (Global Information Security & Technology) team to help protect our environment from threats, vulnerabilities, and sophisticated attackers. Your work will have a significant impact on numerous customers across various e-commerce verticals and hundreds of millions of online users. As a core member of our globally distributed 24/7 Security Operations Team, you are expected to work from one of our India offices (Bengaluru) or from home. This role is ideal for someone who has built a solid foundation in security operations and is ready to take the next step β owning more complex work, developing specialised skills, and contributing more meaningfully to the team's detection and response mission.
-
Monitor, analyze, and interpret security, system, application, cloud, and infrastructure logs to identify suspicious activity, configuration irregularities, and potential security incidents.
-
Leverage security tools, custom-built dashboards, threat intelligence, and proactive investigation techniques to detect anomalous or malicious activity.
-
Monitor cloud infrastructure and services for security-related events, misconfigurations, and indicators of compromise.
-
Monitor the evolving threat and vulnerability landscape, including security advisories, emerging threats, and relevant vulnerabilities, and coordinate or escalate findings as appropriate.
-
Investigate security alerts, incidents, and service requests, performing appropriate triage, analysis, documentation, escalation, and follow-up.
-
Develop, maintain, tune, and improve security detection use cases and alerts within SIEM and other security monitoring platforms.
-
Design, implement, and maintain automation workflows using SOAR or similar security orchestration and automation technologies.
-
Collaborate with Product Security, Infrastructure Security, Application Security, GRC, Engineering, and other relevant teams during cross-functional security investigations.
-
Work with GRC, Privacy, Legal, Product, and technical teams during security or privacy-related incidents and investigations, providing technical findings and evidence where required.
-
Participate in major incident calls and support incident response activities, including investigation, evidence gathering, timeline development, and preparation of incident summaries.
-
Document, follow, and execute Standard Operating Procedures (SOPs), security playbooks, investigation procedures, and escalation processes.
-
Create, manage, maintain, and continuously improve security use cases, playbooks, runbooks, and knowledge-base articles.
-
Support audit-related activities by gathering security evidence, validating controls, and collaborating with relevant stakeholders as required.
-
Maintain a working knowledge of AI and Large Language Model (LLM) tools such as Gemini, ChatGPT, and Claude, and understand their practical application within Security Operations.
-
Understand common authentication and credential-management concepts, including public/private key authentication, API keys, access tokens, service accounts, and the secure handling of credentials.
-
Be comfortable working with command-line interfaces (CLI), APIs, IDE-based tools, and agent-based workflows commonly used in modern security and cloud environments.
-
Take ownership of responsibilities assigned during the shift, ensuring effective handovers, timely escalation, and appropriate follow-through.
-
Proactively engage relevant stakeholders and escalate risks, incidents, blockers, or concerns when necessary.
-
Maintain a positive approach toward continuous learning, professional development, and upskilling as security technologies, threats, and operational practices evolve.
Qualifications
-
3β5 years of hands-on experience working within a 24Γ7 Security Operations Center (SOC), Cyber Fusion Center, or equivalent security operations function.
-
Hands-on experience in at least one or more of the following areas:
-
SaaS platform security
-
Cloud security, particularly AWS and/or Google Cloud Platform (GCP)
-
API and container security
-
Threat intelligence and threat hunting
-
Vulnerability management
-
SIEM or SOAR administration, engineering, or operational use
-
Strong hands-on experience using SIEM platforms for security monitoring, investigation, correlation, and detection engineering. Experience with Splunk is preferred.
-
Practical experience with SOAR platforms and security automation workflows.
-
Hands-on experience with Endpoint Detection and Response (EDR) and related capabilities such as threat intelligence, vulnerability/exposure management, device control, or data protection.
-
Hands-on experience with CSPM/CNAPP platforms such as Wiz, CrowdStrike Falcon Cloud Security, Prisma Cloud, Microsoft Defender for Cloud, Sysdig, or equivalent.
-
Hands-on experience assessing, interpreting, prioritizing, and managing vulnerabilities using platforms such as CrowdStrike Exposure Management/Spotlight, Qualys, Rapid7, Wiz, or equivalent.
-
Practical working experience with AWS or GCP is mandatory, including an understanding of cloud identity, logging, networking, compute, storage, and security controls.
-
Basic scripting skills using Python, Bash, PowerShell, or equivalent for security operations, investigation, or automation use cases.
Requirements
-
Demonstrated experience investigating and coordinating security incidents across technical and non-technical teams.
-
Ability to act as an Incident Commander / Incident Coordinator for security incidents, driving the response from initial triage through containment, remediation, recovery, and closure.
-
Ability to establish clear ownership of investigation workstreams, actions, dependencies, and follow-up activities during an incident.
-
Ability to make operational decisions during an incident, prioritize investigation activities, and escalate matters requiring specialist technical, legal, privacy, compliance, or management authority.
-
Ability to maintain accurate incident timelines and ensure key findings, decisions, actions, risks, and outstanding items are appropriately documented.
-
Ability to provide clear and timely incident status updates to relevant stakeholders and Security leadership.
-
Experience supporting or leading post-incident reviews, lessons-learned exercises, and follow-up remediation tracking.
Benefits
-
Culture:
-
A great deal of freedom and trust. At Bloomreach we donβt clock in and out, and we have neither corporate rules nor long approval processes.
-
Defined values and behaviors embedded in our processes.
-
Flexible working hours to accommodate your working style.
-
Virtual-first work environment with several Bloomreach Hubs available across three continents.
-
Company events to experience the global spirit of the company.
-
Encouragement and support for volunteering activities - every Bloomreacher can take 5 paid days off to volunteer.
-
Personal Development:
-
People Development Program with workshops on various topics.
-
Access to a communication coach for work-related challenges.
-
Managers encouraged to participate in the Leader Development Program.
-
$1,500 professional education budget on an annual basis.
-
Well-being:
-
Employee Assistance Program with counselors for non-work-related challenges.
-
Subscription to Calm - sleep and meditation app.
-
βDisConnectβ days for additional time off each quarter.
-
Facilitation of sports, yoga, and meditation opportunities.
-
Extended parental leave up to 26 calendar weeks for Primary Caregivers.
-
Compensation:
-
Restricted Stock Units or Stock Options based on role, seniority, and location.
-
Participation in the company's performance bonus.
-
Employee referral bonus of up to $3,000.
-
Celebration of work anniversaries - Bloomversaries.