HamburgerMenu
hirist

Cyber Security Analyst II - Detection Engineering

Tech Grow Global
5 - 10 Years
Hyderabad

Posted on: 05/10/2026

Job Description

Cyber Security Analyst II

Role Summary:

We are looking for an experienced Cyber Security Analyst II with strong expertise in Security Operations and Detection Engineering. The ideal candidate will be responsible for end-to-end alert investigation and triage while actively improving security detection capabilities.

This role involves identifying detection gaps, tuning noisy rules, developing new detection logic, and maintaining high-quality, high-fidelity security coverage across on-premises and cloud environments.

Key Responsibilities:

- Lead end-to-end investigation and triage of security alerts across on-premises and cloud environments.

- Operate as a frontline defender within a 24x7 SOC environment.

- Collaborate with cross-functional and global teams to investigate and respond to security threats.

- Identify detection gaps and implement new or enhanced detection rules.

- Tune low-value and noisy alerts to reduce false positives.

- Review, validate, and improve detection logic aligned with MITRE ATT&CK TTPs.

- Develop new security use cases based on attacker behavior and emerging threats.

- Maintain and improve security playbooks, SOPs, and investigation documentation.

- Analyze security telemetry from SIEM, EDR, NDR, firewall, cloud, and SaaS platforms.

- Investigate cloud security threats, including IAM anomalies and SaaS security alerts.

- Monitor and defend modern cloud workloads, including containerized and serverless environments.

- Identify opportunities for automation and AI-driven workflows within detection engineering pipelines.

- Use scripting to automate security enrichment, investigation, and operational tasks.

Required Technical Skills:

- 5+ years of experience in enterprise Security Operations / SOC environments.

- Strong experience in alert triage and detection engineering / content tuning.

- Hands-on experience with SIEM platforms and rule writing.

- Experience with EDR, NDR, and firewall logs.

- Strong understanding of cloud security and cloud log analysis.

- Experience identifying IAM anomalies and SaaS security threats.

- Knowledge of security monitoring across containers and serverless workloads.

- Strong understanding of MITRE ATT&CK framework and TTP mapping.

- Scripting experience with Python, PowerShell, and/or Bash.

- Experience developing, tuning, and validating security detection rules.

- Ability to work across global time zones in a 24x7 security operations environment.

Preferred Profile:

- Strong analytical and investigative mindset.

- Excellent technical documentation and communication skills.

- Ability to work independently with minimal supervision.

- Strong ownership and end-to-end problem-solving ability.

- Comfortable working with ambiguity and making analytical security decisions.

- Experience working in medium-to-large enterprise security environments.

Key Focus Areas:

- SIEM, Detection Engineering, Alert Triage, EDR, NDR, Firewall, Cloud Security, IAM, SaaS Security, MITRE ATT&CK, Python, PowerShell, Bash, SOC, Threat Detection.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...