Senior Security Incident Response Analyst

Posted 9 Days Ago
Be an Early Applicant
Noida, Gautam Buddha Nagar, Uttar Pradesh, IND
In-Office
Senior level
Financial Services
The Role
Monitor and triage security alerts from SIEM/EDR/cloud; perform end-to-end incident investigations and forensics; develop and maintain IR playbooks; improve logging, detection, and automation; collaborate with engineering, threat detection, and global IR teams; support tabletop exercises and mentor junior analysts.
Summary Generated by Built In

About the Company:

Netspend Corporation is a global, vertically-integrated financial services and technology company dedicated to the delivery of innovative financial empowerment solutions to consumers worldwide. Netspend's financial products and services span prepaid, debit, cross-border payments, and loyalty solutions for consumers and enterprise partners.
Netspend provides prepaid and debit account solutions that connect customers with secure, convenient access to global payment networks so they can manage their money and make everyday purchases. With a nationwide U.S. retail network, customers can purchase and reload Netspend products at 130,000 reload points and over 100,000 distributing locations.
Since our founding in 1999 by industry pioneers, Netspend products have processed billions of dollars in transaction volume and served millions of customers worldwide. The company is headquartered in Austin, Texas with employees worldwide.


Job Description:

We are seeking a highly skilled Senior Security Incident Response Analyst to join our global Cyber Defense organization. This individual contributor role is responsible for

triaging and investigating security alerts, developing and maintaining response playbooks, and ensuring the effectiveness of security logging and detection capabilities. The ideal candidate brings deep technical expertise, strong analytical skills, and a passion for improving detection and response processes at scale. This role will collaborate closely with Security Operations, Threat Detection Engineering, Platform/Infrastructure teams, and cross-functional partners across global time zones. The position is based in India and may support a follow-the-sun incident response model.

Key Responsibilities

Incident Monitoring & Investigation

● Continuously monitor and triage security alerts from SIEM, EDR, cloud platforms, and other detection systems

● Conduct end-to-end investigations for potential security incidents, including scoping, containment recommendations, and root-cause identification

● Escalate and coordinate with global IR teams for high-severity incidents.

● Perform forensic analysis on endpoints, logs, and cloud workloads as required.

Response Playbooks & Process Improvement

● Design, build, and maintain incident response playbooks covering common threat

scenarios (malware, phishing, identity compromise, insider threat, cloud

misconfigurations, etc.)

● Identify opportunities for automation and orchestration in investigation workflows

● Collaborate with Threat Detection Engineering to refine detection logic, thresholds, and alerting criteria

● Document incident findings, lessons learned, and process improvements.

Logging & Detection Efficacy

● Evaluate the completeness and quality of security logs across infrastructure,

applications, and cloud environments (AWS/Azure/GCP).

● Recommend improvements in logging coverage, enrichment, and parsing to strengthen detection capabilities

● Partner with Security Engineering to validate telemetry ingestion and visibility in SIEM and EDR platforms

● Conduct periodic logging health assessments and tune noisy or low-value alerts.

Stakeholder Collaboration

● Work with IT, Cloud, Engineering, and Compliance teams to ensure incident response readiness

● Provide guidance to junior analysts and regional partners when required

● Support tabletop exercises and readiness assessments.

Requirements

● 5–8+ years of hands-on experience in Security Operations, Incident Response, threat hunting, or Detection Engineering

● Strong knowledge of SIEM platforms (e.g., Splunk, ELK, Sentinel), EDR tools

(CrowdStrike, SentinelOne, etc.), and cloud security (AWS/GCP/Azure)

● Proven ability to investigate complex security events using logs, network traffic, and

endpoint data

● Experience building IR playbooks and standard operating procedures

● Familiarity with MITRE ATT&CK, NIST Incident Response Framework, and modern

adversary TTPs

● Solid understanding of logging architectures, event taxonomies, and detection pipelines.

● Excellent communication skills and ability to work independently in a global, distributed environment

Preferred Qualifications

● Relevant certifications (GCIA, GCIH, GCFA, GNFA, Azure/AWS Security, etc.)

● Experience with SOAR automation workflows

● Exposure to DevOps, Kubernetes, container security, or CI/CD pipeline monitoring

● Prior experience working in a global 24/7 operational security model

Skills Required

  • 5-8+ years hands-on experience in Security Operations, Incident Response, threat hunting, or Detection Engineering
  • Strong knowledge of SIEM platforms (Splunk, ELK, Sentinel)
  • Experience with EDR tools (CrowdStrike, SentinelOne)
  • Cloud security experience (AWS, GCP, Azure)
  • Proven ability to investigate complex security events using logs, network traffic, and endpoint data
  • Experience building incident response playbooks and standard operating procedures
  • Familiarity with MITRE ATT&CK and NIST Incident Response Framework
  • Solid understanding of logging architectures, event taxonomies, and detection pipelines
  • Excellent communication skills and ability to work independently in a global, distributed environment
  • Perform forensic analysis on endpoints, logs, and cloud workloads
  • Experience designing, building, and maintaining response playbooks for common threat scenarios
  • Collaborate with Threat Detection Engineering and Security Engineering to validate telemetry and refine detections
  • Relevant certifications (GCIA, GCIH, GCFA, GNFA, Azure/AWS Security)
  • Experience with SOAR automation workflows
  • Exposure to DevOps, Kubernetes, container security, or CI/CD pipeline monitoring
  • Prior experience working in a global 24/7 operational security model
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Austin, TX
687 Employees

What We Do

Netspend is a leading provider of payments and financial solutions for consumers and businesses. As the trusted partner to many of the world’s most recognized brands, Netspend connects people, brands and payment products to deliver innovative financial solutions for everyone. A pioneer in providing financial services to traditionally underserved consumers, Netspend is continuing to make payments accessible to more markets in more ways. Netspend’s open technology platform enables businesses to quickly and securely embed payments solutions into their ecosystems, and seamlessly brings innovation to market. From prepaid, paycard and debit solutions to digital account and money movement services, Netspend has a broad suite of products and technologies that deliver exceptional experiences for its customers and business partners. Netspend products can be acquired online, through its mobile apps, and at more than 100,000 locations nationwide including retail outlets, tax preparation offices and financial service providers, and through corporate paycard and tips partners. Based in Austin, Texas, Netspend is a wholly owned subsidiary of Global Payments Inc.

Similar Jobs

Ericsson Logo Ericsson

Senior Engineer

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Noida, Gautam Buddha Nagar, Uttar Pradesh, IND
88000 Employees

Ericsson Logo Ericsson

Engineer-RAN Monitoring

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Noida, Gautam Buddha Nagar, Uttar Pradesh, IND
88000 Employees

Ericsson Logo Ericsson

GitOps Engineer

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
4 Locations
88000 Employees

Capco Logo Capco

Senior Project Program Portfolio Mgmt - Portfolio Manager

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account