IT Analyst | IT Analyst

Johnson Controls, Inc.

Bengaluru

On-site

INR 900,000 - 1,300,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Johnson Controls, Inc. is seeking a Security Operations and Incident Response professional to investigate alerts, contain threats, and drive improvements across detection and automation.

You will work with cross‑functional teams to strengthen readiness and resilience in a fast-paced environment. The role requires hands-on experience with SIEM/EDR, cloud security, and threat intelligence, plus strong communication skills and a track record of incident handling.

Qualifications

  • 1–3 years in a SOC, incident response, IT security operations, or adjacent role.
  • Experience with at least one of: SIEM, EDR/XDR, secure email gateway, cloud security tools (M365 Defender, Defender for Endpoint, Sentinel, Splunk, CrowdStrike, Palo Alto, Zscaler).
  • Familiarity with core investigation concepts: event correlation, user/host baselining, MITRE ATT&CK, malware/TTPS, phishing indicators.
  • Strong communication skills—able to explain technical issues to non-technical users and document clearly.
  • Understanding of basic networking (TCP/IP, DNS, HTTP, VPN) and Windows/Linux fundamentals.
  • Ability to work in a ticket-driven environment with SLAs and handoffs to an MSSP.
  • Inquisitive personality that lends itself to research.
  • Exposure to manufacturing/OT environments (ICS/SCADA basics, Purdue model, segmentation concepts, remote access risks).
  • Experience with SOAR workflows and playbooks; basic scripting (PowerShell, Python, KQL) for triage automation.
  • Knowledge of identity security (AAD, MFA, conditional access), email security, and cloud log sources.
  • Certifications: Security+, CySA+, Microsoft SC-200, GSEC, or equivalent.

Responsibilities

  • Investigate and respond to security alerts and incidents, performing root cause analysis and driving corrective actions.
  • Lead and support incident response efforts, coordinating across teams to contain and remediate threats.
  • Continuously improve detection and response processes through automation, runbook development, and SOP creation.
  • Identify and strengthen threat detection and prevention capabilities.
  • Integrate threat intelligence into operational workflows to proactively address emerging threats.
  • Collaborate with Security, IT, and Business teams to enhance readiness and resilience through joint response planning.

Skills

Security Operations
Incident Response
EDR
SIEM
Firewalls
WAF
Cloud Security
Threat Intelligence
Detection Strategies
Analytical Skills
Problem Solving
Communication
Cross-Functional
Mentoring

Tools

EDR/XDR
SIEM
M365 Defender
Defender for Endpoint
Sentinel
Splunk
CrowdStrike
Palo Alto
Zscaler

Job description

Build your best future with the Johnson Controls team

As a global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet. Join a winning team that enables you to build your best future! Our teams are uniquely positioned to support a multitude of industries across the globe. You will have the opportunity to develop yourself through meaningful work projects and learning opportunities. We strive to provide our employees with an experience, focused on supporting their physical, financial, and emotional wellbeing. Become a member of the Johnson Controls family and thrive in an empowering company culture where your voice and ideas will be heard – your next great opportunity is just a few clicks away!

What you will do:
  • Investigate and respond to security alerts and incidents, performing root cause analysis and driving corrective actions.
  • Lead and support incident response efforts, coordinating across teams to contain and remediate threats.
  • Continuously improve detection and response processes through automation, runbook development, and SOP creation.
  • Identify and strengthen threat detection and prevention capabilities.
  • Integrate threat intelligence into operational workflows to proactively address emerging threats.
  • Collaborate with Security, IT, and Business teams to enhance readiness and resilience through joint response planning.
What You’ll Need to Succeed
  • Extensive experience in Security Operations and Incident Response, with a strong track record of handling complex incidents.
  • Proficiency with modern cybersecurity tools (EDR, SIEM, firewalls, WAF, identity, and cloud security platforms).
  • Experience operationalizing threat intelligence and developing detection strategies for evolving threats.
  • Strong analytical and problem-solving skills, with a focus on process rigor and continuous improvement.
  • Ability to drive action and influence outcomes in fast-paced, cross-functional environments.
  • Excellent communication and collaboration skills, with a team-first mindset and mentoring capabilities.
What we look for:
Required
  • 1–3 years in a SOC, incident response, IT security operations, or adjacent role (e.g., EDR admin, blue team intern/co‑op).
  • Experience with at least one of: SIEM, EDR/XDR, secure email gateway, cloud security tools (M365 Defender suite, Defender for Endpoint, Sentinel, Splunk, CrowdStrike, Palo Alto, Zscaler, etc.).
  • Familiarity with core investigation concepts: event correlation, user/host baselining, MITRE ATT&CK, common malware/TTPs, phishing indicators.
  • Strong communication skills—able to explain technical issues to non-technical users and document clearly and concisely.
  • Understanding of basic networking (TCP/IP, DNS, HTTP, VPN) and Windows/Linux fundamentals (processes, services, logs, registry, authentication).
  • Ability to work in a ticket-driven environment with SLAs and handoffs to an MSSP.
  • Inquisitive personality that lends itself to question asking and research
Preferred
  • Exposure to manufacturing/OT environments (ICS/SCADA basics, Purdue model, segmentation concepts, remote access risks).
  • Experience with SOAR workflows and playbooks; basic scripting (PowerShell, Python, KQL) for triage automation.
  • Knowledge of identity security (AAD, MFA, conditional access), email security, and cloud log sources.
  • Certifications: Security+, CySA+, Microsoft SC‑200, GSEC, or equivalent
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Analyst
IT Analyst

Johnson Controls, Inc. • Bengaluru

On-site
INR 900,000 - 1,300,000
IT Analyst
IT Analyst

YDU JC Air Cond & Ref Inc.- Dubai • Bengaluru

On-site
INR 600,000 - 1,200,000
Senior Security Analyst
Senior Security Analyst

UltraViolet Cyber • Hyderabad

On-site
INR 800,000 - 1,200,000
Senior Cyber Security Analyst (R-19638)
Senior Cyber Security Analyst (R-19638)

Eyeota • Hyderabad

On-site
INR 1,100,000 - 2,400,000
Security Operations Manager
Security Operations Manager

Angel One • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

Hybrid
INR 1,500,000 - 2,100,000
Flexible/Remote work
Cyber Security Analyst
Cyber Security Analyst

Dun & Bradstreet • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Security Operations Engineer
Security Operations Engineer

NextGenEnergyJobs • Bengaluru

On-site
INR 2,500,000 - 5,200,000
Flexible time off
Wellness resources
Team events
Senior Manager, Threat Detection & Response
Senior Manager, Threat Detection & Response

Johnson & Johnson • Bengaluru

On-site
INR 2,000,000 - 3,000,000