Cyber Defense Specialist at Ralliant. Location Information: . Cyber Defense Specialist. ROLE DESCRIPTION. Purpose: . Serve as a hands-on Cyber Defense expert responsible for advanced security operations, complex incident handling, continuous service improvement, Exposure Management, and delivery of improvement projects and After Action follow-up actions.. Location:. Hybrid in Bangalore or Remote India. Role Description. The Cyber Defense Specialist is a hands-on Cyber Defense expert responsible for protecting enterprise and Operating Company (OpCo) environments through advanced security monitoring, investigation, incident handling, threat analysis, and exposure reduction. The role serves as a trusted technical authority for complex security events and drives investigations from initial detection through containment, recovery, and lessons learned.. This role operates within a 24x7 security operations and follow-the-sun model. The Specialist independently handles complex incidents and incidents that require manual intervention or escalation, leads technical workstreams during incidents, guides service providers, and makes sound risk-based decisions under pressure using established incident-management and escalation processes.. The role combines expert-level incident response with SOC operations, ticket and case triage, vulnerability and exposure management, DLP alert response, threat hunting, threat intelligence, detection improvement, and defensible evidence handling. A core expectation is to continuously improve the Cyber Defense service by identifying recurring weaknesses, contributing to improvement projects, strengthening standard work, and ensuring After Action Review commitments are implemented and validated.. The Cyber Defense Specialist works closely with global Security Operations leadership, managed security service providers, Cyber Defense Engineering, Infrastructure, Cloud, Identity, Network Security, application owners, GRC, Audit, Legal, HR, Privacy, and business stakeholders. The role supports regulated and customer-controlled environments where assigned, and executes work in accordance with Ralliant Business System (RBS) principles.. Key Responsibilities. Act as a technical responder for complex or high-severity security incidents, leading investigation, scoping, containment, eradication, recovery support, and technical validation through closure.. Perform technical incident-handling and support the incident response leads with authoritative findings, business-impact analysis, response options, decision points, and clear operational and executive-ready updates.. Perform advanced investigation and correlation across endpoint, identity, cloud, SaaS, email, network, and data-security telemetry to reconstruct attack paths, determine root cause, assess persistence, and identify affected assets, identities, and data.. Provide expert oversight of SOC monitoring, alert triage, case management, escalation, and shift handoffs; resolve ambiguous cases and ensure active work transfers without loss of context, ownership, or urgency.. Triage and govern security tickets and service requests, ensuring accurate prioritization, assignment, investigation quality, service-level discipline, documented decisions, and closure validation.. Operate SIEM and security operations platforms for advanced querying, correlation, investigation, reporting, and telemetry-quality validation; provide actionable detection and tuning recommendations.. Execute DLP investigations for complex or sensitive cases, preserve relevant evidence, determine security significance, and coordinate escalation through defined Legal, HR, Privacy, and Insider Risk workflows.. Lead technical vulnerability and exposure response by validating exploitability and attack paths, applying threat and business context, prioritizing remediation, coordinating urgent risk reduction, and verifying remediation or exception outcomes.. Conduct advanced threat analysis and targeted threat hunting, develop hypotheses, analyze adversary tactics and techniques, validate defensive assumptions, identify control gaps, and translate findings into improved detections and response actions.. Operationalize internal and external threat intelligence into investigative queries, prioritized hunts, detection requirements, response actions, and targeted advisories.. Drive continuous improvement of the Cyber Defense service by analyzing incident, alert, ticket, backlog, handoff, and service-performance trends; identify root causes and convert findings into practical improvements with measurable outcomes.. Contribute to Cyber Defense improvement projects such as playbook modernization, workflow simplification, automation, tooling enhancements, telemetry onboarding, detection-quality improvement, case-management improvement, and service-provider integration.. Own technical and operational work packages within improvement projects, including requirements, stakeholder coordination, testing, documentation, implementation readiness, adoption support, and validation of expected outcomes.. Support After Action Reviews and ensure lessons learned result in assigned corrective actions. Track actions through completion, validate effectiveness, and escalate overdue or ineffective actions so material weaknesses are not left unresolved.. Partner with Cyber Defense Engineering and service providers to improve detection coverage and fidelity, reduce false positives, close telemetry gaps, and ensure detections remain effective as technologies and threats change.. Ensure incident records, timelines, evidence, handling decisions, and investigation reports are complete, accurate, defensible, and suitable for audits, customer inquiries, regulatory obligations, or legal review.. Contribute to operational and leadership reporting covering incident trends, response performance, alert quality, exposure remediation, recurring drivers, backlog health, improvement-project progress, and corrective-action closure.. Qualifications. Bachelor’s degree in cybersecurity, information technology, computer science, digital forensics, or a related discipline is recommended; equivalent expert-level practical experience will be considered.. Typically, 5+ years of progressive experience in security operations, incident response, digital forensics, threat hunting, or Cyber Defense, including independent handling of complex and high-impact incidents.. Proven experience with Crowdstrike EDR and Exposure Management platforms , Proofpoint, Microsoft Purview and Defender services.. Demonstrated expert-level experience investigating incidents across endpoint, identity, cloud, SaaS, email, network, and data-security domains and correlating multiple telemetry sources into defensible conclusions.. Proven ability to execute technical incident-response activities, make risk-based decisions under pressure, coordinate multiple technical teams, and communicate clearly with operational and leadership stakeholders.. Deep practical knowledge of incident handling, attacker behavior, evidence handling, root-cause analysis, containment strategies, recovery validation, After Action Reviews, and corrective-action management.. Advanced experience with SIEM and security-operations tooling, including complex query development, investigation workflows, telemetry validation, operational reporting, and detection-tuning feedback.. Strong experience with endpoint detection and response, identity and access telemetry, email security, network security, cloud and SaaS investigation, DLP, and vulnerability or exposure management platforms.. Demonstrated ability to assess vulnerability exploitability and exposure paths, apply threat and business context, drive urgent remediation, and verify risk-reduction outcomes.. Proven experience improving an operational security service through measurable changes to processes, playbooks, detections, tooling, automation, service-provider performance, or ways of working.. Experience leading or delivering cross-functional Cyber Defense improvement projects from problem definition and requirements through implementation, adoption, and outcome validation.. Demonstrated ability to turn incident lessons learned and After Action findings into practical corrective actions, maintain ownership across teams, and verify that changes effectively address the underlying weakness.. Practical experience leading DLP or sensitive-data investigations with discretion, defensible documentation, and appropriate coordination with Legal, HR, Privacy, or Insider Risk stakeholders.. Advanced working knowledge of threat intelligence, indicators of compromise, threat-hunting methods, attack-path analysis, and frameworks such as MITRE ATT&CK.. Strong analytical judgment, technical writing, project execution, and verbal communication skills, including the ability to translate complex findings into business impact, risk, options, decisions, and prioritized improvement work.. Willingness to participate in scheduled on-call, weekend, or holiday coverage where required by the Cyber Defense operating model.. Relevant advanced certifications such as GCIH, GCFA, GCIA, GNFA, CISSP, or comparable platform-specific certifications are preferred but not required.. Alignment with Ralliant values and the Ralliant Business System (RBS), including ownership, transparency, accountability, respect, and continuous improvement.. Ralliant Corporation Overview. Ralliant, originally part of Fortive, now stands as a bold, independent public company driving innovation at the forefront of precision technology. With a global footprint and a legacy of excellence, we empower engineers to bring next-generation breakthroughs to life — faster, smarter, and more reliably. Our high-performance instruments, sensors, and subsystems fuel mission-critical advancements across industries, enabling real-world impact where it matters most. At Ralliant we’re building the future, together with those driven to push boundaries, solve complex problems, and leave a lasting mark on the world. . We Are an Equal Opportunity Employer. Ralliant Corporation and all Ralliant Companies are proud to be equal opportunity employers. We value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, national origin, religion, sex, age, marital status, disability, veteran status, sexual orientation, gender identity or expression, or other characteristics protected by law. Ralliant and all Ralliant Companies are also committed to providing reasonable accommodations for applicants with disabilities. Individuals who need a reasonable accommodation because of a disability for any part of the employment application process, please contact us at [email protected]. . Bonus or Equity. This position is also eligible for bonus as part of the total compensation package.
Cyber Defense Specialist at Ralliant