Rubiscape’s platform processes sensitiveenterprise data and powers business-critical decisions for customers inbanking, insurance, manufacturing, and government — making continuous securitymonitoring non-negotiable. As a SecOps Analyst, you will be the first line ofdetection and response for threats across Rubiscape’s SaaS infrastructure,internal systems, and customer-facing platform. You will operate the SIEM,investigate alerts, and work with the security engineering team toprogressively automate response playbooks, raising Rubiscape’s mean time todetect and respond with every quarter.
Key Responsibilities
- Monitor SIEM dashboards (Splunk/ ELK) and triage security alerts across cloud infrastructure, applicationlogs, and endpoint telemetry; elevate confirmed incidents per runbook.
- Conduct first-responseinvestigation and containment for security incidents including accountcompromise, data exfiltration attempts, malware, and DDoS events.
- Maintain and improve detectionrules, correlation searches, and alert thresholds in the SIEM; reducefalse-positive rate while increasing signal fidelity for Rubiscape-specificthreat patterns.
- Operate vulnerabilitymanagement workflows: ingest scanner output (Qualys, Tenable, or equivalent),track remediation status, and report SLA compliance to security engineering.
- Contribute to threatintelligence enrichment — mapping IOCs and TTPs from CERT-IN advisories, ISACs,and threat feeds to Rubiscape’s detection coverage.
- Document incident timelines,evidence chains, and post-incident reports to audit-ready standard for ISO27001 and SOC 2 evidence requirements.
- Participate in tabletopexercises and red team/blue team drills to validate detection and responsecapabilities.
Nice to Have
- Certifications: CompTIASecurity+, CySA+, or GIAC GCIH / GCFE.
- Experience with SOAR platforms(Palo Alto XSOAR, Splunk SOAR) and writing automated response playbooks.
- Familiarity with CERT-INempanelled auditor processes and incident reporting obligations under Indianregulatory frameworks.
- Exposure to cloud-nativesecurity tooling (AWS GuardDuty, Azure Defender, GCP Security Command Center)in an operational monitoring context.
About Rubiscape
Rubiscape is India’s leading DecisionIntelligence Platform, unifying data engineering, BI, machine learning, andagentic AI in a single governed platform. Built in Pune and trusted by Fortune500 enterprises across BFSI, manufacturing, healthcare, and government. 8international innovation patents. 10 Industry-Academia Labs & COEs. From BIto AI — One Platform. Every Decision.
Requirements
- 2+ years of experience in aSecurity Operations Centre (SOC) or security monitoring role.
- Hands-on experience with SIEMplatforms (Splunk, ELK/OpenSearch, Microsoft Sentinel, or equivalent) includingquery authoring and dashboard creation.
- Solid understanding of attackframeworks (MITRE ATT&CK) and common attacker TTPs relevant to cloud-hostedSaaS platforms.
- Experience with vulnerabilitymanagement tools and ability to assess and prioritise CVEs in the context of acloud-native application stack.
- Ability to analyse networktraffic, application logs, and endpoint telemetry to reconstruct attack chainsand determine blast radius.