Senior Security Incident Response Analyst
AI Summary
Senior Security Incident Response Analyst responsible for triaging and investigating security alerts, developing and maintaining response playbooks, and ensuring the effectiveness of security logging and detection capabilities.
About this role
About the Company:
Netspend Corporation is a global, vertically-integrated financial services and technology company dedicated to the delivery of innovative financial empowerment solutions to consumers worldwide. Netspend's financial products and services span prepaid, debit, cross-border payments, and loyalty solutions for consumers and enterprise partners.
Netspend provides prepaid and debit account solutions that connect customers with secure, convenient access to global payment networks so they can manage their money and make everyday purchases. With a nationwide U.S. retail network, customers can purchase and reload Netspend products at 130,000 reload points and over 100,000 distributing locations.
Since our founding in 1999 by industry pioneers, Netspend products have processed billions of dollars in transaction volume and served millions of customers worldwide. The company is headquartered in Austin, Texas with employees worldwide.
Job Description:
We are seeking a highly skilled Senior Security Incident Response Analyst to join our global Cyber Defense organization. This individual contributor role is responsible for
triaging and investigating security alerts, developing and maintaining response playbooks, and ensuring the effectiveness of security logging and detection capabilities. The ideal candidate brings deep technical expertise, strong analytical skills, and a passion for improving detection and response processes at scale. This role will collaborate closely with Security Operations, Threat Detection Engineering, Platform/Infrastructure teams, and cross-functional partners across global time zones. The position is based in India and may support a follow-the-sun incident response model.
Key Responsibilities
Incident Monitoring & Investigation
● Continuously monitor and triage security alerts from SIEM, EDR, cloud platforms, and
other detection systems
● Conduct end-to-end investigations for potential security incidents, including scoping,
containment recommendations, and root-cause identification
● Escalate and coordinate with global IR teams for high-severity incidents.
● Perform forensic analysis on endpoints, logs, and cloud workloads as required.
Response Playbooks & Process Improvement
● Design, build, and maintain incident response playbooks covering common threat
scenarios (malware, phishing, identity compromise, insider threat, cloud
misconfigurations, etc.)
● Identify opportunities for automation and orchestration in investigation workflows
● Collaborate with Threat Detection Engineering to refine detection logic, thresholds, and
alerting criteria
● Document incident findings, lessons learned, and process improvements.
Logging & Detection Efficacy
● Evaluate the completeness and quality of security logs across infrastructure,
applications, and cloud environments (AWS/Azure/GCP).
● Recommend improvements in logging coverage, enrichment, and parsing to strengthen
detection capabilities
● Partner with Security Engineering to validate telemetry ingestion and visibility in SIEM
and EDR platforms
● Conduct periodic logging health assessments and tune noisy or low-value alerts.
Stakeholder Collaboration
● Work with IT, Cloud, Engineering, and Compliance teams to ensure incident response
readiness
● Provide guidance to junior analysts and regional partners when required
● Support tabletop exercises and readiness assessments.
Requirements
● 5–8+ years of hands-on experience in Security Operations, Incident Response, Threat
Hunting, or Detection Engineering
● Strong knowledge of SIEM platforms (e.g., Splunk, ELK, Sentinel), EDR tools
(CrowdStrike, SentinelOne, etc.), and cloud security (AWS/GCP/Azure)
● Proven ability to investigate complex security events using logs, network traffic, and
endpoint data
● Experience building IR playbooks and standard operating procedures
● Familiarity with MITRE ATT&CK, NIST Incident Response Framework, and modern
adversary TTPs
● Solid understanding of logging architectures, event taxonomies, and detection pipelines.
● Excellent communication skills and ability to work independently in a global, distributed
environment
Preferred Qualifications
● Relevant certifications (GCIA, GCIH, GCFA, GNFA, Azure/AWS Security, etc.)
● Experience with SOAR automation workflows
● Exposure to DevOps, Kubernetes, container security, or CI/CD pipeline monitoring
● Prior experience working in a global 24/7 operational security model
Skills
Explore related jobs
More jobs at Netspend
Similar AWS jobs
Jobs in Noida
SEO Intern Freshers WelcomeSEOCZAR IT SERVICES PVT LTD · Noida, India- Senior AccountantClarivate Analytics India Private Limited · R271- Noida
- IP Admin Senior AnalystClarivate Analytics India Private Limited · R271- Noida
- Lead AccountantClarivate Analytics India Private Limited · R271- Noida
- AccountantClarivate Analytics India Private Limited · R271- Noida
- Tax AnalystClarivate Analytics India Private Limited · India - Noida
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.
