Security Incident Response Analyst

Endava

India

Hybrid

INR 1,500,000 - 2,100,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work
Learning opportunities
Wellbeing programme
Share plan
Performance bonuses
Global tech communities

Job summary

Endava in India seeks an Incident Response Analyst to join our Cyber Threat Intelligence and Incident Response team. You will act as a frontline responder, coordinating with SOC, IT, and legal to contain, investigate and recover from incidents.

Use SIEM/EDR tools, perform malware analysis and log reviews, and contribute to post-incident reviews. A proactive mindset and strong communication are essential as you learn evolving threat actor techniques.

Qualifications

  • Degree in Cyber Security, Computer Science, Information Technology or related discipline, or equivalent practical experience.
  • Relevant incident response, blue team or security operations certification (for example GCIH, GCED, or equivalent).
  • Demonstrated experience responding to security incidents, labs or realistic tabletop exercises.

Responsibilities

  • Act as a key responder during security incidents, supporting containment, eradication and recovery activities.
  • Perform detailed investigation and analysis of security alerts, intrusions and malware using EDR, SIEM and forensic tooling.
  • Support post-incident reviews, identifying root cause, control gaps and lessons learned.
  • Coordinate with SOC, CTI, IT, legal and third-party providers during incidents to ensure timely and effective response
  • Support evidence collection and documentation to meet legal, regulatory and internal reporting requirements.
  • In periods without active incident response activity, the analyst will actively support Cyber Threat Intelligence operations and initiatives

Skills

SIEM & EDR analysis
Malware analysis & memory forensics
Incident response & containment
Network & log analysis
MITRE ATT&CK knowledge
Documentation skills

Education

Bachelor's degree in Cyber Security or related field
GCIH / GCED certification or equivalent
Experience with security incidents / tabletop exercises

Tools

EDR tools
Threat Intelligence Platforms
Forensic tooling

Job description

Technology is our how. And people are our why. For over two decades, we have been harnessing technology to drive meaningful change.
By combining world-class engineering, industry expertise and a people-centric mindset, we consult and partner with leading brands from various industries to create dynamic platforms and intelligent digital experiences that drive innovation and transform businesses.
From prototype to real-world impact - be part of a global shift by doing work that matters.

Job Description

The Incident Response Analyst is part of the front line of our Cyber Threat Intelligence and Incident Response team, responsible for providing Endava with high fidelity, actionable cyber threat intelligence and specialist incident response capabilities.

Strong knowledge of the latest security threats, industry standard incident response methodologies, and investigation techniques is expected. Candidates should also demonstrate adaptability, knowledge of both incident response and cyber threat intelligence, and an eagerness to learn emerging threat actor tactics, tools and techniques.

Responsibilities:

  • Act as a key responder during security incidents, supporting containment, eradication and recovery activities.
  • Perform detailed investigation and analysis of security alerts, intrusions and malware using EDR, SIEM and forensic tooling.
  • Support post-incident reviews, identifying root cause, control gaps and lessons learned.
  • Coordinate with SOC, CTI, IT, legal and third-party providers during incidents to ensure timely and effective response
  • Support evidence collection and documentation to meet legal, regulatory and internal reporting requirements.
  • In periods without active incident response activity, the analyst will actively support Cyber Threat Intelligence operations and initiatives
Qualifications

Qualifications:

  • Degree in Cyber Security, Computer Science, Information Technology or a related discipline, or equivalent practical experience.
  • Relevant incident response, blue team or security operations certification (for example GCIH, GCED, or equivalent).
  • Demonstrated experience responding to security incidents, labs or realistic tabletop exercises.

Experience:

  • 6-10 years experience withIncident management
  • 3+ years in cybersecurity, with at least 2 years in SOC/CTI/Incident Response.
  • Hands-on experience in malware analysis, memory forensics, and log analysis.
  • Strong understanding of network protocols, secure configurations, and common attack techniques (MITRE ATT&CK).
  • Experience supporting or participating in security incident response activities, including investigation and containment.
  • Familiarity with SOC tooling such as SIEM, EDR, Threat Intelligence Platforms and alerting platforms.
  • Experience analysing security alerts, logs and endpoint telemetry to identify malicious activity.
  • Experience documenting incidents, investigations and lessons learned in a clear and structured manner.

Technical Skills:

  • Hands-on experience with SIEM and EDR tools for alert investigation and incident analysis.
  • Ability to analyse endpoint, network and log data to identify malicious activity.
  • Familiarity with incident response processes, including triage, containment and recovery.
  • Basic malware analysis and investigation skills, such as analysing file hashes, URLs and suspicious processes.
  • Understanding of common attack vectors, vulnerabilities and exploitation techniques.

Additional Skills:

  • Strong problem-solving and analytical skills.
  • Ability to remain calm and decisive during high-pressure incidents.
  • Excellent communication skills, both technical and non-technical.
  • Continuous learning mindset and willingness to explore new tools and methods.
Additional Information

Discover some of the global benefits that empower our people to become the best version of themselves:

  • Finance: Competitive salary package, share plan, company performance bonuses, value-based recognition awards, referral bonus;
  • Career Development: Career coaching, global career opportunities, non-linear career paths, internal development programmes for management and technical leadership;
  • Learning Opportunities: Complex projects, rotations, internal tech communities, training, certifications, coaching, online learning platforms subscriptions, pass-it-on sessions, workshops, conferences;
  • Work-Life Balance: Hybrid work and flexible working hours, employee assistance programme;
  • Health: Global internal wellbeing programme, access to wellbeing apps;
  • Community: Global internal tech communities, hobby clubs and interest groups, inclusion and diversity programmes, events and celebrations.

At Endava, we’re committed to creating an open, inclusive, and respectful environment where everyone feels safe, valued, and empowered to be their best. We welcome applications from people of all backgrounds, experiences, and perspectives—because we know that inclusive teams help us deliver smarter, more innovative solutions for our customers. Hiring decisions are based on merit, skills, qualifications, and potential. If you need adjustments or support during the recruitment process, please let us know.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defense - Cyber Triage and Forensic Analyst
Cyber Defense - Cyber Triage and Forensic Analyst

EY • Thiruvananthapuram

On-site
INR 1,200,000 - 1,500,000
Continuous learning
Transformative leadership
Diverse and inclusive culture
Cyber Defense - Cyber Triage and Forensic Analyst
Cyber Defense - Cyber Triage and Forensic Analyst

Ernst & Young Advisory Services Sdn Bhd • Thiruvananthapuram

On-site
INR 1,500,000 - 2,000,000
Security Analyst II, Splunk
Security Analyst II, Splunk

Cyderes • India

On-site
INR 900,000 - 1,500,000
Medical Insurance
Hybrid Work Model
Paid Time Off
+1
Development-Senior Developer(Python)-EN,SE
Development-Senior Developer(Python)-EN,SE

Endava • Hyderabad

Hybrid
INR 1,000,000 - 1,500,000
Competitive salary package
Career coaching
Hybrid work and flexible hours
+1
Security Analyst
Security Analyst

Persistent Systems • Bengaluru

Hybrid
INR 1,500,000 - 2,300,000
Hybrid work
Flexible work hours
Long Service awards
+3
Senior Cyber Security Analyst (R-19638)
Senior Cyber Security Analyst (R-19638)

Eyeota • Hyderabad

On-site
INR 1,100,000 - 2,400,000
CMS-Senior-Incident Orchestrator
CMS-Senior-Incident Orchestrator

EY • Tirupati

On-site
INR 1,700,000 - 2,200,000
24/7 operations center
Incident Response Manager
Incident Response Manager

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Support and coaching
Career development
Flexible working style
Cyber Security Analyst
Cyber Security Analyst

Dun & Bradstreet • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,500,000 - 2,800,000