Job Title: Senior SOC Analyst
Job Type: Full-time
Location: India / Hybrid
Department: CISO
About CloudBees
CloudBees helps organizations build, run, and govern software factories, giving enterprises the confidence to ship software better, faster, and safer.
Writing code is no longer the bottleneck. Governing what reaches production and validating its impact is. As enterprises adopt agentic coding, software is created faster than most teams can review, secure, and validate. Without consistent governance, organizations risk shipping code they cannot explain, audit, or trust.
CloudBees addresses this challenge without asking teams to replace the tools they already use. Across every toolchain a customer runs, CloudBees makes each change, human or AI, visible, auditable, and accountable before it reaches production. CloudBees Unify is the product behind this: a governance layer, with context and control-plane capabilities, that enforces consistent policy and evidence across every tool, team, and workflow.
Founded in 2010, CloudBees is backed by Goldman Sachs, Morgan Stanley, Bridgepoint Capital, HSBC, Golub Capital, Delta-v Capital, Matrix Partners, and Lightspeed Venture Partners.
Visit us at www.cloudbees.com.
About the job
We have a new opening for a Senior SOC Analyst to join our team. This is not a traditional SOC role. Instead of spending your entire day triaging alerts, you'll mainly work on different cyber security projects such as building detection logic, automating repetitive workflows and partnering closely with GRC and Product Security to improve security telemetry across the CloudBees enterprise and product environment.
The role has wide ranging responsibilities for the Information Security department; including undertaking business as usual activities like alert triage, technical incident management, improving threat detections, consuming threat intelligence, assessing cloud risks, vulnerability assessment, and working on various other cyber security projects.
Previous experience working in a SOC team is necessary as well as being able to operate SIEM, EDR, DLP, CNAPP, and other core SOC tools.
You will join a team of globally dispersed SOC Analysts and must be able to work in a
highly dynamic environment. If you are a proactive self-starter that is looking to join a fast-growing team, we would love to hear from you.
What Success Looks Like:
Within your first year you'll help CloudBees:
- Increase detection coverage across enterprise and production (cloud) environments.
- Improve automation throughout Security Operations by utilising AI.
- Reduce manual investigation effort.
- Improve incident response efficiency.
What You'll Get:
- Highly competitive benefits and vacation package.
- Ability to work for one of the fastest growing companies with some of the most talented people in the industry.
- Team outings.
- Fun, Hardworking, and Casual Environment.
- Endless Growth Opportunities.
What you will do:
- Provide security monitoring and incident response of cyber security events in a high availability SaaS cloud environment and enterprise
- Directly or indirectly support internal and external customers
- Monitor and analyze Security Information and Event Management (SIEM) alerts to identify security issues
- Operate security tools like SIEM, EDR, DLP, CNAPP, vulnerability management solutions, and others
- Develop correlation rules to expand our threat detection capability; enrich the rules with threat intelligence
- Perform threat hunting to proactively detect incidents
- Investigate, document, and report on information security issues and emerging trends.
Who you are:
- 3+ years of experience working within a global Security Operations Center (SOC)
- Familiarity with tuning and/or configuring SIEM detection logic
- Knowledge of SOC standard operating procedures and mainstream security solutions
- Ability to analyze endpoint, network, and application logs
- Excellent communication skills with both Security and Engineering teams
- Knowledge of common Internet protocols and applications
- Working knowledge of cloud services (AWS, GCP, or Azure)
- Familiarity with software development environments (DevOps) and SDLC is a plus
- Scripting / SOAR / security automation experience is a plus
- Relevant certifications including GCIH, GCIA, GCDA, GCED or AWS Security Specialty are a plus