Who we are:
We are a start-up based out of Bengaluru & Delhi NCR. We are engaged in development of next generation missions and technologies (NGM&T) towards future warfare needs of the Indian defence forces. It is undertaking research towards enhancing persistence and autonomy for unmanned vehicles and robotic swarms. NRT’s product development portfolio includes a solar power stratospheric high altitude pseudo satellite (HAPS) unmanned platform and an air/ground launched stand-off autonomous system.
Job Title: Cybersecurity Analyst
Key Responsibilities:
-
Monitor, analyze, and respond to security events across various platforms (networks, endpoints, cloud).
-
Conduct vulnerability assessments, penetration tests, and security audits to identify and mitigate risks.
-
Investigate security incidents, perform root-cause analysis, and assist in remediation efforts.
-
Implement, manage, and optimize security tools such as firewalls, IDS/IPS, SIEM, and endpoint protection.
-
Document security breaches, assess their impact, and collaborate with the security team on testing and uncovering network vulnerabilities.
-
Fix detected vulnerabilities to maintain high security standards and stay current on IT security trends and news.
-
Provide support to colleagues regarding security software installation and information security management.
-
Collaborate with IT and development teams to ensure secure system and application configurations.
-
Develop and maintain security policies, procedures, and documentation.
-
Stay updated with emerging cybersecurity threats, vulnerabilities, and compliance requirements.
-
Assist in conducting risk assessments and recommending mitigation strategies.
-
Research and evaluate emerging cyber security threats and vulnerabilities, and develop management strategies.
-
Plan for disaster recovery and create contingency plans in the event of security breaches.
-
Monitor for attacks, intrusions, and unusual, unauthorized, or illegal activity.
-
Test and evaluate security products, and verify supplier certification, compliance, and accreditation.
-
Design new security systems or upgrade existing ones.
-
Utilize advanced analytic tools to determine emerging threat patterns and vulnerabilities.
-
Engage in 'ethical hacking' by simulating security breaches.
-
Identify potential weaknesses and implement protective measures, such as firewalls and encryption.
-
Investigate security alerts and provide incident response using established incident handling methodologies and best practices.
-
Monitor and respond to common cyber threats such as 'phishing' emails, 'pharming' activity, malware, and ransomware.
-
Monitor identity and access management, including detecting abuse of permissions by authorized system users.
-
Liaise with stakeholders regarding cybersecurity issues and provide future recommendations.
-
Record all findings, actions taken, and lessons learned following an incident to strengthen future responses.
-
Generate incident reports for both technical and non-technical staff and stakeholders.
-
Review and improve security processes.
-
Maintain an information security risk register and assist with internal and external audits related to information security.
-
Promote a culture of security among colleagues and other stakeholders, and support wider security initiatives.
-
Assist with the creation, maintenance, and delivery of cybersecurity awareness training for colleagues.
-
Provide advice and guidance to staff on issues such as spam and unwanted or malicious emails.
-
1+ years of experience in cybersecurity, information security, or related roles.
-
Strong understanding of network protocols, operating systems, and common attack vectors.
-
Experience with security tools such as SIEM platforms, vulnerability scanners, IDS/IPS, and endpoint security solutions.
-
Proficiency in analyzing security logs and generating actionable reports.
-
Knowledge of threat intelligence, incident response, and security monitoring best practices.
-
Strong problem-solving, analytical, and communication skills.
-
Hands-on experience with penetration testing, ethical hacking,red/blue/purple team exercises.
-
Familiarity with cloud security (AWS, Azure, or GCP) and container security.
-
Understanding of compliance frameworks like ISO 27001, NIST, or GDPR.
-
Relevant certifications such as CEH, CompTIA Security+, OSCP, or CISSP (Associate level) are a plus.