Rubiscape’s platform processes sensitive
enterprise data and powers business-critical decisions for customers in
banking, insurance, manufacturing, and government — making continuous security
monitoring non-negotiable. As a SecOps Analyst, you will be the first line of
detection and response for threats across Rubiscape’s SaaS infrastructure,
internal systems, and customer-facing platform. You will operate the SIEM,
investigate alerts, and work with the security engineering team to
progressively automate response playbooks, raising Rubiscape’s mean time to
detect and respond with every quarter.
· Monitor SIEM dashboards (Splunk
/ ELK) and triage security alerts across cloud infrastructure, application
logs, and endpoint telemetry; escalate confirmed incidents per runbook.
· Conduct first-response
investigation and containment for security incidents including account
compromise, data exfiltration attempts, malware, and DDoS events.
· Maintain and improve detection
rules, correlation searches, and alert thresholds in the SIEM; reduce
false-positive rate while increasing signal fidelity for Rubiscape-specific
threat patterns.
· Operate vulnerability
management workflows: ingest scanner output (Qualys, Tenable, or equivalent),
track remediation status, and report SLA compliance to security engineering.
· Contribute to threat
intelligence enrichment — mapping IOCs and TTPs from CERT-IN advisories, ISACs,
and threat feeds to Rubiscape’s detection coverage.
· Document incident timelines,
evidence chains, and post-incident reports to audit-ready standard for ISO
27001 and SOC 2 evidence requirements.
· Participate in tabletop
exercises and red team/blue team drills to validate detection and response
capabilities.
· Certifications: CompTIA
Security+, CySA+, or GIAC GCIH / GCFE.
· Experience with SOAR platforms
(Palo Alto XSOAR, Splunk SOAR) and writing automated response playbooks.
· Familiarity with CERT-IN
empanelled auditor processes and incident reporting obligations under Indian
regulatory frameworks.
· Exposure to cloud-native
security tooling (AWS GuardDuty, Azure Defender, GCP Security Command Center)
in an operational monitoring context.
Rubiscape is India’s leading Decision
Intelligence Platform, unifying data engineering, BI, machine learning, and
agentic AI in a single governed platform. Built in Pune and trusted by Fortune
500 enterprises across BFSI, manufacturing, healthcare, and government. 8
international innovation patents. 10 Industry-Academia Labs & COEs. From BI
to AI — One Platform. Every Decision.
RequirementsRequirements
· 2+ years of experience in a
Security Operations Centre (SOC) or security monitoring role.
· Hands-on experience with SIEM
platforms (Splunk, ELK/OpenSearch, Microsoft Sentinel, or equivalent) including
query authoring and dashboard creation.
· Solid understanding of attack
frameworks (MITRE ATT&CK) and common attacker TTPs relevant to cloud-hosted
SaaS platforms.
· Experience with vulnerability
management tools and ability to assess and prioritise CVEs in the context of a
cloud-native application stack.
· Ability to analyse network
traffic, application logs, and endpoint telemetry to reconstruct attack chains
and determine blast radius.


