## Senior IT Security AnalystApply: Hybrid (8 days/month): IND-Pune-Smartworks: Full time: Posted Today: R0059848About the Role: As a Senior IT Security Analyst, you will engage in advanced cybersecurity tasks with a high level of autonomy. Your contributions will be crucial for maintaining a secure IT environment and anticipating potential threats. You'll exercise thorough security measures and guide less experienced team members.Key Responsibilities* Support vulnerability management activities across cloud, infrastructure, containers, Kubernetes, and application environments.* Review and analyze findings from security tools such as CSPM, vulnerability scanners, container security tools, and application security platforms.* Work with infrastructure, cloud, application, and DevOps teams to drive remediation of identified security issues.* Support cloud security posture management across AWS, Azure, or GCP environments.* Manage EDR and XDR platforms**:** Deploy, configure, and optimize security tools to monitor endpoints, integrate cross-layered telemetry (cloud, network, and email), and eliminate security silos.* Detect and respond to threats**:** Analyze advanced multi-vector alerts, hunt for hidden attackers, and orchestrate automated playbooks to rapidly isolate compromised systems and minimize response times.* Review cloud misconfigurations, exposed resources, identity risks, network security gaps, and compliance issues.* Assist in container and Kubernetes security reviews, including image vulnerabilities, runtime exposure, cluster configuration, and workload security.* Support vulnerability prioritization based on severity, exploitability, exposure, asset criticality, and business impact.* Help maintain dashboards, reports, trackers, and metrics for vulnerability remediation and security posture.* Contribute to automation of repetitive security tasks, reporting, data enrichment, and remediation workflows.* Support basic application security and shift-left activities, including SAST, DAST, SCA, dependency risks, and secure development awareness.* Assist with basic forensic analysis, incident triage, log review, and evidence collection when required.* Contribute to emerging AI security initiatives, including understanding risks around AI agents, connectors, cloud-hosted AI workloads, data exposure, and infrastructure security.* Coordinate with multiple stakeholders to track remediation progress, exceptions, risk acceptance, and closure.Required Skills and Experience* 5–6 years of experience in cybersecurity, vulnerability management, cloud security, infrastructure security, or related domains.* Good understanding of cloud security concepts across AWS, Azure, or GCP.* Hands-on or working knowledge of CSPM tools such as Orca, Wiz, Prisma Cloud, Defender for Cloud, Lacework, or similar.* Understanding of vulnerability management processes, including detection, prioritization, remediation tracking, SLA monitoring, and reporting.* Familiarity with vulnerability scanners such as Rapid7, Qualys, Tenable, or similar.* Good understanding of infrastructure security, including servers, operating systems, patching, network exposure, identity, and access controls.* Basic understanding of containers and Kubernetes security, including container images, registries, clusters, namespaces, workloads, secrets, and runtime risks.* Basic understanding of application security and shift-left practices, including SAST, DAST, SCA, CI/CD security, and secure coding concepts.* Understanding of AI security concepts such as AI agents, connectors, data access, prompt injection, excessive permissions, and secure integration with enterprise tools.* Ability to analyze security findings and translate them into clear remediation actions.* Experience working with dashboards, Excel, Power BI, ServiceNow, Jira, or similar reporting and tracking tools.* Basic scripting or automation experience using Python, PowerShell, Bash, KQL, SQL, or APIs.* Strong communication skills with the ability to work with cloud, infrastructure, application, DevOps, and leadership teams.Good to Have* Exposure to Kubernetes security tools, container scanning, runtime security, or CNAPP platforms.* Experience with ServiceNow Vulnerability Response, Jira, Power BI, Snowflake, or similar enterprise reporting platforms.* Familiarity with MITRE ATT&CK, MITRE ATLAS, OWASP Top 10, OWASP LLM Top 10, CIS Benchmarks, NIST, or cloud security frameworks.* Understanding of forensic basics such as log analysis, endpoint artifacts, timeline review, and incident evidence handling.* Experience with automation of vulnerability reporting, data cleanup, ticket enrichment, or remediation workflows.* Exposure to AI security, GenAI governance, MCP/connectors, agentic workflows, or AI infrastructure security.