Walmart logo

Intrusion Analyst III

Walmart

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

Position Summary... What youll do... Job Summary As a SOC Analyst, you will monitor, detect, analyze, investigate, and support remediation of cybersecurity events in accordance with established standard operating procedures. You will combine hands-on security operations expertise with data-driven investigation, automation, and responsible use of AI/Generative AI to improve analyst effectiveness, detection quality, investigation consistency, and response outcomes. The role requires close collaboration with stakeholders, engineering teams, incident responders, and business units across a global operating environment.About the TeamThe Information Security organization helps protect Walmart s customers, associates, information assets, and technology environment. SOC Incident Management is a centralized security operations function responsible for monitoring, detecting, analyzing, investigating, escalating, and responding to security threats. Analysts work alongside security engineers, incident responders, threat intelligence teams, and other cybersecurity professionals to protect the organization s information assets and networks.Key ResponsibilitiesSecurity Monitoring, Investigation Incident Response

  • Monitor, triage, analyze, investigate, and support remediation of cyber events using defined SOC procedures, playbooks, escalation paths, and service expectations.
  • Perform investigation across endpoint, network, email, identity, cloud, Windows, and Linux telemetry; correlate evidence across multiple data sources to determine scope, impact, root cause, and recommended actions.
  • Run approved commands, queries, scripts, and automation for assigned areas of work while maintaining appropriate operational controls and documentation.
  • Identify indicators of compromise, suspicious behaviors, attack patterns, and emerging risks; escalate confirmed or high-risk incidents to the appropriate response teams.
  • Communicate clearly with technical and business stakeholders during troubleshooting and security events, providing timely status, findings, risk context, and recommended next steps.

Detection Engineering Continuous Improvement

  • Provide actionable input to improve alert logic, correlation rules, detection use cases, thresholds, enrichment, prioritization, and suppression of known false positives.
  • Identify opportunities for new risk detection based on investigation trends, threat intelligence, recurring incidents, control gaps, and observed attacker behavior.
  • Partner with engineering and platform teams to validate and operationalize detection improvements across SIEM, EDR, SOAR, email security, firewall, IPS, and cloud security tooling.
  • Capture investigation learnings, recurring patterns, root causes, and operational gaps; recommend measurable improvements to SOC processes, playbooks, documentation, and analyst workflows.

AI / Generative AI Responsibilities

  • Use approved AI/GenAI capabilities (for example, Copilot, ChatGPT, Gemini, or enterprise-approved equivalents) to assist with investigation summarization, evidence correlation, query/script drafting, threat-context synthesis, case documentation, and recommendation generation.
  • Critically validate AI-generated analysis against authoritative telemetry and security evidence before using it for incident decisions, escalation, remediation, or stakeholder communication. Maintain analyst accountability for final conclusions.
  • Assess the quality of AI-assisted investigations by identifying inaccurate conclusions, missed evidence, weak reasoning, hallucinations, incomplete recommendations, or inconsistent outputs, and provide structured feedback for improvement.
  • Help develop and refine prompts, analyst workflows, evaluation criteria, test cases, and feedback loops that improve the accuracy, consistency, explainability, and operational usefulness of AI-assisted SOC analysis.
  • Identify appropriate opportunities to integrate AI/GenAI with SIEM, SOAR, EDR, threat intelligence, case-management, and knowledge-management workflows to reduce repetitive analyst effort and accelerate triage and investigation.
  • Apply responsible-AI and security principles when using AI tools, including data handling, confidentiality, access controls, human oversight, traceability, and compliance with company policies and approved-use requirements.
  • Monitor AI-assisted workflows for quality and operational risk, and escalate cases where AI output could create false assurance, inappropriate remediation, data exposure, or other security impact.
  • Contribute to AI readiness across the SOC by documenting effective practices, sharing lessons learned, and supporting analyst adoption and training for approved AI-enabled capabilities.

Cybersecurity Technology Solution Support

  • Support cybersecurity intelligence and security-operations solutions by gathering requirements, researching technologies, participating in solution reviews, and contributing to supplier/product evaluations.
  • Develop and review system, process, investigation, and operational documentation to support consistent execution and knowledge transfer.
  • Maintain current knowledge of cybersecurity threats, attacker techniques, security technologies, automation, and AI/GenAI developments relevant to SOC operations.

Collaboration, Documentation Stakeholder Management

  • Participate in team assignments and projects, provide timely progress updates, contribute to team meetings and technical discussions, and support cross-functional initiatives.
  • Create and review high-quality case notes, standard operating procedures, playbooks, knowledge articles, metrics, reports, and presentations for management, technical teams, customers, suppliers, and other stakeholders.
  • Build collaborative relationships across functional and organizational boundaries and respond effectively to stakeholder and business-unit requests.

Governance, Ethics Compliance

  • Operate in accordance with company policies, security standards, procedures, ethical expectations, and applicable compliance requirements.
  • Protect sensitive information throughout investigations and communications, using approved systems and appropriate data-handling practices.
  • Demonstrate professional judgment, fact-based decision-making, transparency, and appropriate escalation when evidence is incomplete or risk is uncertain.

Required Experience Technical Skills

  • B.E./B.Tech/M.S./M.Tech/MCA or equivalent technical qualification, with approximately 4-6 years of relevant SOC/cybersecurity operations experience.
  • Hands-on experience with EDR and SIEM technologies across on-premises and cloud environments; Azure Sentinel/Microsoft Sentinel and Google Chronicle experience is desirable.
  • Experience with SOAR, email security, incident/case management, firewall, IPS, security correlation, detection use-case development, and deployment.
  • Hands-on cybersecurity investigation skills including malware analysis, phishing/email analysis, network and endpoint investigation, and Windows/Linux operating-system analysis.
  • Practical exposure to AI/GenAI tools such as Copilot, ChatGPT, and Gemini, with the ability to use them responsibly and critically in cybersecurity workflows.
  • Ability to develop or adapt security queries, scripts, and automation to support investigation and operational efficiency.
  • Experience working with global teams and flexibility to work rotational shifts as business needs require.

Core Competencies Professional Judgment: Researches and integrates relevant information and evidence, applies fact-based criteria, looks beyond symptoms, identifies root causes, and makes defensible recommendations. Execution Results: Prioritizes effectively, uses established tools and processes, manages time and operational challenges, and delivers against business and security objectives. Planning Continuous Improvement: Develops practical improvement plans, anticipates potential problems, and identifies opportunities to streamline processes and improve SOC performance. Influence Communication: Communicates technical findings and risk clearly, proactively shares timely updates, listens actively, and prepares effective documentation and presentations. Relationship Building: Builds trusting, collaborative relationships across teams, organizational levels, and diverse backgrounds. Customer/Member Focus: Understands stakeholder needs and uses data, analysis, and insights to improve service and security outcomes. Ethics Compliance: Models ethical conduct, follows policies and procedures, protects sensitive information, and supports compliance expectations. Adaptability Learning: Adapts to changing priorities, embraces new responsibilities and technologies, and continuously updates and shares knowledge. Analytical Problem Solving: Demonstrates strong investigation, reasoning, decision-making, and problem-solving skills in complex and fast-moving situations. Preferred Qualifications

  • Industry certifications such as CIH, CompTIA Security+/CySA+ or related CompTIA certifications, CEH, or other relevant cybersecurity certifications.
  • Experience improving SOC processes through automation, detection engineering, analytics, or AI-assisted investigation workflows.
  • Demonstrated interest in emerging technology and a track record of taking ownership in a fast-paced, results-driven environment.

About Walmart Global Tech
. . Work Walmart s culture sets us apart, and we know being together helps us innovate, learn and grow great careers. This role is based in our Bangalore office for daily work, with the flexibility for associates to manage their personal lives. Benefits . Belonging . At Walmart, our vision is "everyone included." By fostering a workplace culture where everyone is-and feels-included, everyone wins. Our associates and customers reflect the makeup of all 19 countries where we operate. By making Walmart a welcoming place where all people feel like they belong, we re able to engage associates, strengthen our business, improve our ability to serve customers, and support the communities where we operate. Equal Opportunity Employer Walmart, Inc., is an Equal Opportunities Employer - By Choice. We believe we are best equipped to help our associates, customers and the communities we serve live better when we really know them. That means understanding, respecting and valuing unique styles, experiences, identities, ideas and opinions - while being inclusive of all people. Minimum Qualifications...

Outlined below are the required minimum qualifications for this position. If none are listed, there are no minimum qualifications.

Option 1: Bachelor s degree in computer science, information technology, engineering, information systems, cybersecurity or related area and 2
years experience in intrusion analysis or related area at a technology, retail, or data-driven company. Option 2: 4 years experience in intrusion
analysis or related area at a technology, retail, or data-driven company. Preferred Qualifications...

Outlined below are the optional preferred qualifications for this position. If none are listed, there are no preferred qualifications.

Certification in Security+, Network+, GISF, CISA ,CISSP, CCSP, or GCIH., Master s degree in computer science, information technology, engineering, information systems, cybersecurity or related area. Primary Location... Building 10 (sez), Cessna Business Park, Kadubeesanahalli Village, Varthur Hobli , India

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at Walmart was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.