Back to jobs
C
Hiring companyC3/CustomerContactChannels

Verified today

Specialist - Information Security

India Full-time

About the role

Everise is a global experience company seeking a Specialist - Information Security to support its security operations. The role combines SOC monitoring and VAPT execution, including investigating alerts from SIEM, endpoint, identity, email, DLP, and VPN/proxy sources, enriching alerts, and documenting investigations. The specialist executes vulnerability scans, performs web/API security testing, reviews SAST/DAST findings, coordinates remediation with development owners, and maintains evidence-backed tickets in ServiceNow. Based in India, the role operates within a hybrid scope balancing SOC alert response with VAPT execution.

What you’ll do

  • Monitor SOC queues and investigate alerts from Managed SOC/SIEM, endpoint, identity, email-security, DLP, VPN/proxy and endpoint-compliance sources
  • Enrich SOC alerts using user, device, IP, ASN, geo-location, application, timestamp, IOC, endpoint posture, related tickets and historical evidence
  • Document investigations with working notes, screenshots, containment status, closure rationale, ticket updates and shift handover notes
  • Execute scheduled and ad hoc vulnerability scans for infrastructure and applications; validate findings before escalation
  • Perform web application and API security testing under defined scope; mobile application testing is excluded unless separately assigned
  • Review SAST/DAST findings, assist with secure-code review and coordinate with application/development owners for remediation evidence
  • Track vulnerability remediation and retesting in ServiceNow or approved workflow tools; maintain clean closure, retest and exception evidence
  • Support containment actions including account disablement, device freeze/quarantine/isolation, suspicious-session review, user outreach and restoration evidence

What you’ll bring

  • 3-5 years of experience in SOC, MDR, InfoSec operations, endpoint security, vulnerability management, or security monitoring support
  • Hands-on investigative mindset with discipline to perform practical triage and testing
  • Strong escalation discipline to Consultant/InfoSec lead, IT Ops, GSD, Endpoint, Development, HR/Ops, TAM, or Legal based on severity and impact
  • Meticulous evidence and retesting hygiene, capturing screenshots, timestamps, tool outputs, reproduction steps, and closure comments
  • Clear, business-formal written communication for incident notes, vulnerability findings, remediation follow-ups, and shift handovers
  • Ability to run scans, validate vulnerabilities, capture evidence, prepare remediation notes, and support retesting
  • Working knowledge of OWASP Top 10, web/API testing methodology, and manual validation using Burp Suite or OWASP ZAP
  • Ability to review SAST/DAST tool findings, understand vulnerable code patterns, and coordinate with developers under senior guidance

Nice to have

  • BPO, healthcare, PCI, or client-regulated environment exposure
  • Nessus/Qualys/OpenVAS and ServiceNow remediation tracking experience
  • Experience preparing concise technical finding write-ups
  • Familiarity with SonarQube, Snyk, Semgrep, Checkmarx, Veracode, or Fortify
  • Arctic Wolf/Aurora, Microsoft Sentinel or equivalent SIEM, Splunk/QRadar fundamentals
  • Microsoft Entra ID, Conditional Access, MFA, Defender for Endpoint, FortiEDR, Absolute, Intune/JamF, BitLocker/FileVault
  • Abnormal AI / O365 email security, Microsoft Purview DLP, phishing/BEC/ATO investigation queues
  • eJPT / PNPT / CEH Practical, CompTIA PenTest+ / Security+ / CySA+, Burp Suite certification or web testing training, Splunk Core / SIEM fundamentals

Skills

SOC OperationsVulnerability AssessmentWeb/API TestingSAST/DAST/Code ReviewSIEM/MDR ToolingIdentity/Endpoint ToolingEmail/DLP ToolingNetwork Vulnerability Tools