Sobre este puesto de Security Analyst en Bloomreach
- We're taking autonomous search mainstream, making product discovery more intuitive and conversational for customers, and more profitable for businesses.
- We’re making conversational shopping a reality, connecting every shopper with tailored guidance and product expertise — available on demand, at every touchpoint in their journey.
- We're designing the future of autonomous marketing, taking the work out of workflows, and reclaiming the creative, strategic, and customer-first work marketers were always meant to do.
Role Overview
We are looking for a Security Analyst to join the Bloomreach GIST (Global Information Security & Technology) team to help protect our environment from threats, vulnerabilities, and sophisticated attackers. Your work will have a significant impact on numerous customers across various e-commerce verticals and hundreds of millions of online users. As a core member of our globally distributed 24/7 Security Operations Team, you are expected to work from one of our India offices ( Bengaluru) or from home. This role is ideal for someone who has built a solid foundation in security operations and is ready to take the next step — owning more complex work, developing specialised skills, and contributing more meaningfully to the team's detection and response mission
Your job will include, but is not limited to:
- Monitor, analyze, and interpret security, system, application, cloud, and infrastructure logs to identify suspicious activity, configuration irregularities, and potential security incidents.
- Leverage security tools, custom-built dashboards, threat intelligence, and proactive investigation techniques to detect anomalous or malicious activity.
- Monitor cloud infrastructure and services for security-related events, misconfigurations, and indicators of compromise.
- Monitor the evolving threat and vulnerability landscape, including security advisories, emerging threats, and relevant vulnerabilities, and coordinate or escalate findings as appropriate.
- Investigate security alerts, incidents, and service requests, performing appropriate triage, analysis, documentation, escalation, and follow-up.
- Develop, maintain, tune, and improve security detection use cases and alerts within SIEM and other security monitoring platforms.
- Design, implement, and maintain automation workflows using SOAR or similar security orchestration and automation technologies.
- Collaborate with Product Security, Infrastructure Security, Application Security, GRC, Engineering, and other relevant teams during cross-functional security investigations.
- Work with GRC, Privacy, Legal, Product, and technical teams during security or privacy-related incidents and investigations, providing technical findings and evidence where required.
- Participate in major incident calls and support incident response activities, including investigation, evidence gathering, timeline development, and preparation of incident summaries.
- Document, follow, and execute Standard Operating Procedures (SOPs), security playbooks, investigation procedures, and escalation processes.
- Create, manage, maintain, and continuously improve security use cases, playbooks, runbooks, and knowledge-base articles.
- Support audit-related activities by gathering security evidence, validating controls, and collaborating with relevant stakeholders as required.
- Maintain a working knowledge of AI and Large Language Model (LLM) tools such as Gemini, ChatGPT, and Claude, and understand their practical application within Security Operations.
- Understand common authentication and credential-management concepts, including public/private key authentication, API keys, access tokens, service accounts, and the secure handling of credentials.
- Be comfortable working with command-line interfaces (CLI), APIs, IDE-based tools, and agent-based workflows commonly used in modern security and cloud environments.
- Take ownership of responsibilities assigned during the shift, ensuring effective handovers, timely escalation, and appropriate follow-through.
- Proactively engage relevant stakeholders and escalate risks, incidents, blockers, or concerns when necessary.
- Maintain a positive approach toward continuous learning, professional development, and upskilling as security technologies, threats, and operational practices evolve.
Professional experience, skills & requirements
Required Experience
- 3–5 years of hands-on experience working within a 24×7 Security Operations Center (SOC), Cyber Fusion Center, or equivalent security operations function.
- Hands-on experience in at least one or more of the following areas:
- SaaS platform security
- Cloud security, particularly AWS and/or Google Cloud Platform (GCP)
- API and container security
- Threat intelligence and threat hunting
- Vulnerability management
- SIEM or SOAR administration, engineering, or operational use
- Strong hands-on experience using SIEM platforms for security monitoring, investigation, correlation, and detection engineering. Experience with Splunk is preferred.
- Practical experience with SOAR platforms and security automation workflows.
- Hands-on experience with Endpoint Detection and Response (EDR) and related capabilities such as threat intelligence, vulnerability/exposure management, device control, or data protection.
- Hands-on experience with CSPM/CNAPP platforms such as Wiz, CrowdStrike Falcon Cloud Security, Prisma Cloud, Microsoft Defender for Cloud, Sysdig, or equivalent.
- Hands-on experience assessing, interpreting, prioritizing, and managing vulnerabilities using platforms such as CrowdStrike Exposure Management/Spotlight, Qualys, Rapid7, Wiz, or equivalent.
- Practical working experience with AWS or GCP is mandatory, including an understanding of cloud identity, logging, networking, compute, storage, and security controls.
- Basic scripting skills using Python, Bash, PowerShell, or equivalent for security operations, investigation, or automation use cases.
Incident Response & Coordination
- Demonstrated experience investigating and coordinating security incidents across technical and non-technical teams.
- Ability to act as an Incident Commander / Incident Coordinator for security incidents, driving the response from initial triage through containment, remediation, recovery, and closure.
- Ability to establish clear ownership of investigation workstreams, actions, dependencies, and follow-up activities during an incident.
- Ability to make operational decisions during an incident, prioritize investigation activities, and escalate matters requiring specialist technical, legal, privacy, compliance, or management authority.
- Ability to maintain accurate incident timelines and ensure key findings, decisions, actions, risks, and outstanding items are appropriately documented.
- Ability to provide clear and timely incident status updates to relevant stakeholders and Security leadership.
- Experience supporting or leading post-incident reviews, lessons-learned exercises, and follow-up remediation tracking.
Security Knowledge
- Good understanding of the cybersecurity incident lifecycle, including identification, triage, investigation, containment, remediation, recovery, and post-incident activities.
- Working knowledge of security frameworks and methodologies
- Understanding of cybersecurity risk concepts and the ability to assess the potential technical and business impact of identified security issues.
- Ability to monitor and assess emerging cybersecurity threats, vulnerabilities, attack techniques, and industry developments and determine their relevance to the organization.
- Strong understanding of security monitoring and investigation concepts, including the ability to correlate information across multiple security and infrastructure data sources.
- Understanding of authentication and credential-management concepts, including public/private key authentication, API keys, access tokens, service accounts, and secure credential handling.
Analytical & Operational Skills
- Ability to independently investigate and manage security events of moderate complexity, while appropriately escalating higher-risk, complex, or unfamiliar situations.
- Strong analytical and problem-solving skills, with the ability to apply logical reasoning during investigations and decision-making.
- Strong attention to detail and the ability to connect findings across logs, cloud platforms, endpoints, threat intelligence, identity systems, applications, and other relevant sources.
- Willingness to participate in and take ownership of Proofs of Concept (PoCs), security-tool evaluations, process improvements, and operational initiatives.
- Proactive approach to improving detections, automation, monitoring coverage, playbooks, documentation, and team knowledge.
- Ability to work with command-line interfaces, APIs, IDE-based tools, and modern security or cloud engineering workflows.
- Working knowledge of AI/LLM tools such as ChatGPT, Gemini, Claude, or equivalent, including their practical and secure application within Security Operations.
Communication & Collaboration
- Strong written and verbal communication skills in English, with the ability to communicate investigation findings, risks, status, and required actions clearly to both technical and non-technical stakeholders.
- Ability to communicate confidently and effectively during active security incidents and major incident calls.
- Experience working within globally distributed teams and collaborating effectively across cultures, regions, functions, and time zones.
- Collaborative and team-oriented approach, with the ability to work effectively with Security, Engineering, Product, Infrastructure, GRC, Privacy, Legal, and other business stakeholders.
- Ability to engage relevant stakeholders and escalate incidents, risks, blockers, or concerns in a timely and appropriate manner.
- Ability to provide concise and accurate shift handovers, operational updates, and incident summaries.
Shift Requirements
- Willingness and ability to work in a 24×7 monthly rotating shift schedule, including weekends.
- The position follows a five-day work week, with shift timings and weekly days off determined according to the applicable rotation schedule.
- Ability to independently own responsibilities assigned during a shift and ensure effective handover and follow-through.
- Willingness to take ownership during active security incidents occurring within the assigned shift and coordinate the response until an appropriate handover or closure.
Preferred Qualifications
- Entry-level or intermediate cybersecurity certifications such as CompTIA Security+, CySA+, GIAC GSEC, cloud security certifications, or equivalent industry-recognized certifications.
- Previous experience working within a SaaS, e-commerce, cloud-native, or technology company.
- Experience supporting security operations in environments involving large-scale cloud infrastructure, APIs, containers, distributed applications, or SaaS platforms.
- Previous experience acting as an Incident Coordinator, Incident Commander, or security incident lead is highly desirable.
Your success story will be:
In the first 30 days you will
- Understand the roles & responsibilities of SOC team, in-scope vs out of scope tasks
- Read & understand SOPs, Policies & working procedures of the team
- Shadow peers in day to day work, overlook tickets, alerts, incidents, understand the current state of ongoing projects/enhancements etc
- Understand the team's incident response procedures, escalation paths, and shift structure. Begin handling lower-severity alerts and incidents under guidance from senior analysts
In the next 30 days you will (60 days from start)
- Start owning incidents, tasks as independent contributor with a peer shadowing you
- Participate in incident related calls, cross team/department meetings
- Handle SIEM/SOAR/EDR events. Demonstrate consistent adherence to SOPs and ticket hygiene standards. Contribute at least one update or improvement to a runbook, playbook, or knowledge base article based on hands-on experience
In the next 30 days you will(90 days from start)
- You will start documenting or tweaking existing SOPs, process document
- You will bear responsibilities of representing team in forums/meetings/discussions
- You will start managing shift alone when needed
- You will adapt yourself to the service improvement mindset and contribute. Show measurable growth in investigation quality, speed, and documentation. Begin developing a specialisation area (e.g., cloud security monitoring, detection engineering, threat intelligence) aligned with team needs and personal development goals to overall success of the team
More things you'll like about Bloomreach:
Culture:
-
A great deal of freedom and trust. At Bloomreach we don’t clock in and out, and we have neither corporate rules nor long approval processes. This freedom goes hand in hand with responsibility. We are interested in results from day one.
-
We have defined our 5 values and the 10 underlying key behaviors that we strongly believe in. We can only succeed if everyone lives these behaviors day to day. We've embedded them in our processes like recruitment, onboarding, feedback, personal development, performance review and internal communication.
-
We believe in flexible working hours to accommodate your working style.
-
We work virtual-first with several Bloomreach Hubs available across three continents.
-
We organize company events to experience the global spirit of the company and get excited about what's ahead.
-
We encourage and support our employees to engage in volunteering activities - every Bloomreacher can take 5 paid days off to volunteer*.
-
The Bloomreach Glassdoor page elaborates on our stellar 4.7/5 rating. The Bloomreach Comparably page Culture score is even higher at 4.9/5
Personal Development:
-
We have a People Development Program - participating in personal development workshops on various topics run by experts from inside the company. We are continuously developing & updating competency maps for select functions.
-
Our resident communication coach Ivo Večeřa is available to help navigate work-related communications & decision-making challenges.*
-
Our managers are strongly encouraged to participate in the Leader Development Program to develop in the areas we consider essential for any leader. The program includes regular comprehensive feedback, consultations with a coach and follow-up check-ins.
-
Bloomreachers utilize the $1,500 professional education budget on an annual basis to purchase education products (books, courses, certifications, etc.)*
Well-being:
-
The Employee Assistance Program -- with counselors -- is available for non-work-related challenges.*
-
Subscription to Calm - sleep and meditation app.*
-
We organize ‘DisConnect’ days where Bloomreachers globally enjoy one additional day off each quarter, allowing us to unwind together and focus on activities away from the screen with our loved ones.
-
We facilitate sports, yoga, and meditation opportunities for each other.
-
Extended parental leave up to 26 calendar weeks for Primary Caregivers.*
Compensation:
-
Restricted Stock Units or Stock Options are granted depending on a team member’s role, seniority, and location.*
-
Everyone gets to participate in the company's success through the company performance bonus.*
-
We offer an employee referral bonus of up to $3,000!
-
We reward & celebrate work anniversaries -- Bloomversaries!*
(*Subject to employment type. Interns are exempt from marked benefits, usually for the first 6 months.)
Excited? Join us and transform the future of commerce experiences!
If this position doesn't suit you, but you know someone who might be a great fit, share it - we will be very grateful!
Any unsolicited resumes/candidate profiles submitted through our website or to personal email accounts of employees of Bloomreach are considered property of Bloomreach and are not subject to payment of agency fees.
#LI-Remote