Ralliant Corporation Logo

Ralliant Corporation

Cyber Defense Specialist

Posted 3 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in India
Senior level
In-Office or Remote
Hiring Remotely in India
Senior level
Lead complex cybersecurity incidents from detection through recovery, conduct advanced investigations and threat hunting, manage SOC operations, DLP cases, vulnerabilities, and exposure reduction. Improve detections, playbooks, tooling, telemetry, and service-provider performance while ensuring defensible evidence, reporting, after-action follow-up, and corrective-action closure. Collaborate across security, infrastructure, cloud, legal, privacy, HR, audit, and business teams in a 24x7 operating model.
The summary above was generated by AI
Cyber Defense Specialist

ROLE DESCRIPTION

Purpose: Serve as a hands-on Cyber Defense expert responsible for advanced security operations, complex incident handling, continuous service improvement, Exposure Management, and delivery of improvement projects and After Action follow-up actions.

Location: Hybrid in Bangalore or Remote India

Role Description

The Cyber Defense Specialist is a hands-on Cyber Defense expert responsible for protecting enterprise and Operating Company (OpCo) environments through advanced security monitoring, investigation, incident handling, threat analysis, and exposure reduction. The role serves as a trusted technical authority for complex security events and drives investigations from initial detection through containment, recovery, and lessons learned.

This role operates within a 24x7 security operations and follow-the-sun model. The Specialist independently handles complex incidents and incidents that require manual intervention or escalation, leads technical workstreams during incidents, guides service providers, and makes sound risk-based decisions under pressure using established incident-management and escalation processes.

The role combines expert-level incident response with SOC operations, ticket and case triage, vulnerability and exposure management, DLP alert response, threat hunting, threat intelligence, detection improvement, and defensible evidence handling. A core expectation is to continuously improve the Cyber Defense service by identifying recurring weaknesses, contributing to improvement projects, strengthening standard work, and ensuring After Action Review commitments are implemented and validated.

The Cyber Defense Specialist works closely with global Security Operations leadership, managed security service providers, Cyber Defense Engineering, Infrastructure, Cloud, Identity, Network Security, application owners, GRC, Audit, Legal, HR, Privacy, and business stakeholders. The role supports regulated and customer-controlled environments where assigned, and executes work in accordance with Ralliant Business System (RBS) principles.

Key Responsibilities
  • Act as a technical responder for complex or high-severity security incidents, leading investigation, scoping, containment, eradication, recovery support, and technical validation through closure.

  • Perform technical incident-handling and support the incident response leads with authoritative findings, business-impact analysis, response options, decision points, and clear operational and executive-ready updates.

  • Perform advanced investigation and correlation across endpoint, identity, cloud, SaaS, email, network, and data-security telemetry to reconstruct attack paths, determine root cause, assess persistence, and identify affected assets, identities, and data.

  • Provide expert oversight of SOC monitoring, alert triage, case management, escalation, and shift handoffs; resolve ambiguous cases and ensure active work transfers without loss of context, ownership, or urgency.

  • Triage and govern security tickets and service requests, ensuring accurate prioritization, assignment, investigation quality, service-level discipline, documented decisions, and closure validation.

  • Operate SIEM and security operations platforms for advanced querying, correlation, investigation, reporting, and telemetry-quality validation; provide actionable detection and tuning recommendations.

  • Execute DLP investigations for complex or sensitive cases, preserve relevant evidence, determine security significance, and coordinate escalation through defined Legal, HR, Privacy, and Insider Risk workflows.

  • Lead technical vulnerability and exposure response by validating exploitability and attack paths, applying threat and business context, prioritizing remediation, coordinating urgent risk reduction, and verifying remediation or exception outcomes.

  • Conduct advanced threat analysis and targeted threat hunting, develop hypotheses, analyze adversary tactics and techniques, validate defensive assumptions, identify control gaps, and translate findings into improved detections and response actions.

  • Operationalize internal and external threat intelligence into investigative queries, prioritized hunts, detection requirements, response actions, and targeted advisories.

  • Drive continuous improvement of the Cyber Defense service by analyzing incident, alert, ticket, backlog, handoff, and service-performance trends; identify root causes and convert findings into practical improvements with measurable outcomes.

  • Contribute to Cyber Defense improvement projects such as playbook modernization, workflow simplification, automation, tooling enhancements, telemetry onboarding, detection-quality improvement, case-management improvement, and service-provider integration.

  • Own technical and operational work packages within improvement projects, including requirements, stakeholder coordination, testing, documentation, implementation readiness, adoption support, and validation of expected outcomes.

  • Support After Action Reviews and ensure lessons learned result in assigned corrective actions. Track actions through completion, validate effectiveness, and escalate overdue or ineffective actions so material weaknesses are not left unresolved.

  • Partner with Cyber Defense Engineering and service providers to improve detection coverage and fidelity, reduce false positives, close telemetry gaps, and ensure detections remain effective as technologies and threats change.

  • Ensure incident records, timelines, evidence, handling decisions, and investigation reports are complete, accurate, defensible, and suitable for audits, customer inquiries, regulatory obligations, or legal review.

  • Contribute to operational and leadership reporting covering incident trends, response performance, alert quality, exposure remediation, recurring drivers, backlog health, improvement-project progress, and corrective-action closure.

Qualifications
  • Bachelor’s degree in cybersecurity, information technology, computer science, digital forensics, or a related discipline is recommended; equivalent expert-level practical experience will be considered.

  • Typically, 5+ years of progressive experience in security operations, incident response, digital forensics, threat hunting, or Cyber Defense, including independent handling of complex and high-impact incidents.

  • Proven experience with Crowdstrike EDR and Exposure Management platforms , Proofpoint, Microsoft Purview and Defender services.

  • Demonstrated expert-level experience investigating incidents across endpoint, identity, cloud, SaaS, email, network, and data-security domains and correlating multiple telemetry sources into defensible conclusions.

  • Proven ability to execute technical incident-response activities, make risk-based decisions under pressure, coordinate multiple technical teams, and communicate clearly with operational and leadership stakeholders.

  • Deep practical knowledge of incident handling, attacker behavior, evidence handling, root-cause analysis, containment strategies, recovery validation, After Action Reviews, and corrective-action management.

  • Advanced experience with SIEM and security-operations tooling, including complex query development, investigation workflows, telemetry validation, operational reporting, and detection-tuning feedback.

  • Strong experience with endpoint detection and response, identity and access telemetry, email security, network security, cloud and SaaS investigation, DLP, and vulnerability or exposure management platforms.

  • Demonstrated ability to assess vulnerability exploitability and exposure paths, apply threat and business context, drive urgent remediation, and verify risk-reduction outcomes.

  • Proven experience improving an operational security service through measurable changes to processes, playbooks, detections, tooling, automation, service-provider performance, or ways of working.

  • Experience leading or delivering cross-functional Cyber Defense improvement projects from problem definition and requirements through implementation, adoption, and outcome validation.

  • Demonstrated ability to turn incident lessons learned and After Action findings into practical corrective actions, maintain ownership across teams, and verify that changes effectively address the underlying weakness.

  • Practical experience leading DLP or sensitive-data investigations with discretion, defensible documentation, and appropriate coordination with Legal, HR, Privacy, or Insider Risk stakeholders.

  • Advanced working knowledge of threat intelligence, indicators of compromise, threat-hunting methods, attack-path analysis, and frameworks such as MITRE ATT&CK.

  • Strong analytical judgment, technical writing, project execution, and verbal communication skills, including the ability to translate complex findings into business impact, risk, options, decisions, and prioritized improvement work.

  • Willingness to participate in scheduled on-call, weekend, or holiday coverage where required by the Cyber Defense operating model.

  • Relevant advanced certifications such as GCIH, GCFA, GCIA, GNFA, CISSP, or comparable platform-specific certifications are preferred but not required.

  • Alignment with Ralliant values and the Ralliant Business System (RBS), including ownership, transparency, accountability, respect, and continuous improvement.

Similar Jobs

2 Hours Ago
Remote or Hybrid
Senior level
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Leads incentive compensation strategy, quota-setting, recognition programs, analytics, governance, implementation, and continuous improvement across Pfizer’s international markets. Partners with business leaders and cross-functional teams to design compliant, motivating, and financially responsible programs, deliver data-driven recommendations, oversee payouts and operational timelines, and maintain audit readiness. The role requires strong quantitative analysis, commercial operations expertise, project management, stakeholder influence, and experience supporting pharmaceutical or healthcare organizations.
2 Hours Ago
Remote or Hybrid
Expert/Leader
Expert/Leader
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Leads marketing channel delivery and medical samples services across Malaysia, Indonesia, Singapore, and the Philippines. Oversees sample planning, logistics, compliance, campaigns, HCP portal strategy, social communications, ePermission governance, and omnichannel reporting. Partners with marketing, digital, commercial, legal, compliance, and delivery teams to implement services, manage performance, train stakeholders, maintain audit readiness, and drive process improvement and AI-enabled innovation.
Top Skills: AIEmail MarketingOmnichannel Reporting DashboardsPfizerpro
3 Hours Ago
Remote or Hybrid
2 Locations
Senior level
Senior level
Automotive
Designs, develops, and supports scalable SAP solutions using ABAP, RAP, CDS, OData, and S/4HANA extensibility. Responsibilities include API-led integrations, Fiori/UI5 backend services, BTP extensions, testing, debugging, performance optimization, code reviews, architecture discussions, and Agile delivery. The role requires maintaining custom SAP developments across S/4HANA and ECC while following clean core principles, enterprise security standards, and SAP best practices.
Top Skills: Abap Development Tools (Adt)Api ManagementCloud Application Programming Model (Cap)Core Data Services (Cds)EclipseGitIdocsObject-Oriented AbapOdata V2Odata V4Rest ApisRestful Abap Programming Model (Rap)RfcsSap AbapSap Btp Abap EnvironmentSap Business Technology Platform (Btp)Sap EccSap FioriSap GatewaySap Integration SuiteSap S/4HanaSoapUi5Web Services

What you need to know about the Chennai Tech Scene

To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account