Full-Time

Security Analyst

Posted on 9/4/2026

Bloomreach

Bloomreach

1,001-5,000 employees

SaaS platform for personalized online experiences

No salary listed

Bengaluru, Karnataka, India

Remote

Remote work is available from home, with an India office option in Bengaluru.

Category
Cybersecurity (1)
Required Skills
LLM
PowerShell
Claude
Bash
Python
Incident Response
CompTIA Security+
Vulnerability Analysis
AWS
REST APIs
Splunk
Google Cloud Platform

Get referred to Bloomreach

See people who can refer or advise you

Requirements
  • Three to five years of hands-on experience in a 24×7 Security Operations Center, Cyber Fusion Center, or equivalent security operations function.
  • Hands-on experience in SaaS platform security, cloud security, API and container security, threat intelligence and threat hunting, vulnerability management, or SIEM/SOAR administration, engineering, or operational use.
  • Strong hands-on experience using SIEM platforms for security monitoring, investigation, correlation, and detection engineering.
  • Practical experience with SOAR platforms and security automation workflows.
  • Hands-on experience with Endpoint Detection and Response and related capabilities such as threat intelligence, vulnerability and exposure management, device control, or data protection.
  • Hands-on experience with CSPM or CNAPP platforms such as Wiz, CrowdStrike Falcon Cloud Security, Prisma Cloud, Microsoft Defender for Cloud, or Sysdig.
  • Hands-on experience assessing, interpreting, prioritizing, and managing vulnerabilities using platforms such as CrowdStrike Exposure Management or Spotlight, Qualys, Rapid7, or Wiz.
  • Mandatory practical experience with Amazon Web Services or Google Cloud Platform, including cloud identity, logging, networking, compute, storage, and security controls.
  • Basic scripting skills using Python, Bash, PowerShell, or equivalent for security operations, investigation, or automation use cases.
  • Experience investigating and coordinating security incidents across technical and non-technical teams.
  • Ability to act as an Incident Commander or Incident Coordinator for security incidents, driving response from initial triage through containment, remediation, recovery, and closure.
  • Ability to establish ownership of investigation workstreams, actions, dependencies, and follow-up activities during incidents.
  • Ability to make operational decisions during incidents, prioritize investigation activities, and escalate matters requiring specialist technical, legal, privacy, compliance, or management authority.
  • Ability to maintain accurate incident timelines and document key findings, decisions, actions, risks, and outstanding items.
  • Ability to provide timely incident status updates to stakeholders and Security leadership.
  • Experience supporting or leading post-incident reviews, lessons-learned exercises, and follow-up remediation tracking.
  • Understanding of the cybersecurity incident lifecycle, security frameworks and methodologies, cybersecurity risk concepts, and the technical and business impact of security issues.
  • Ability to monitor and assess emerging cybersecurity threats, vulnerabilities, attack techniques, and industry developments.
  • Strong understanding of security monitoring and investigation concepts, including correlating information across multiple security and infrastructure data sources.
  • Understanding of authentication and credential-management concepts, including public/private key authentication, API keys, access tokens, service accounts, and secure credential handling.
  • Ability to independently investigate and manage moderately complex security events and escalate higher-risk or unfamiliar situations appropriately.
  • Strong analytical and problem-solving skills and the ability to apply logical reasoning during investigations and decision-making.
  • Strong attention to detail and ability to connect findings across logs, cloud platforms, endpoints, threat intelligence, identity systems, and applications.
  • Ability to work with command-line interfaces, APIs, IDE-based tools, and modern security or cloud engineering workflows.
  • Working knowledge of AI and Large Language Model tools such as ChatGPT, Gemini, or Claude and their practical and secure application within Security Operations.
  • Strong written and verbal English communication skills for clearly communicating investigation findings, risks, status, and required actions.
  • Ability to communicate effectively during active security incidents and major incident calls.
  • Experience working within globally distributed teams and collaborating across cultures, regions, functions, and time zones.
  • Ability to engage stakeholders and escalate incidents, risks, blockers, or concerns in a timely and appropriate manner.
  • Ability to provide concise and accurate shift handovers, operational updates, and incident summaries.
  • Willingness and ability to work a 24×7 monthly rotating shift schedule, including weekends.
  • Ability to independently own shift responsibilities, ensure effective handovers, and coordinate active incidents through handover or closure.
Responsibilities
  • Monitor, analyze, and interpret security, system, application, cloud, and infrastructure logs to identify suspicious activity, configuration irregularities, and potential security incidents.
  • Use security tools, custom-built dashboards, threat intelligence, and proactive investigation techniques to detect anomalous or malicious activity.
  • Monitor cloud infrastructure and services for security-related events, misconfigurations, and indicators of compromise.
  • Monitor the evolving threat and vulnerability landscape and coordinate or escalate relevant findings.
  • Investigate security alerts, incidents, and service requests through triage, analysis, documentation, escalation, and follow-up.
  • Develop, maintain, tune, and improve security detection use cases and alerts within SIEM and other security monitoring platforms.
  • Design, implement, and maintain automation workflows using SOAR or similar security orchestration and automation technologies.
  • Collaborate with Product Security, Infrastructure Security, Application Security, GRC, Engineering, and other relevant teams during cross-functional security investigations.
  • Work with GRC, Privacy, Legal, Product, and technical teams during security or privacy-related incidents and investigations, providing technical findings and evidence where required.
  • Participate in major incident calls and support incident response activities, including investigation, evidence gathering, timeline development, and preparation of incident summaries.
  • Document, follow, and execute standard operating procedures, security playbooks, investigation procedures, and escalation processes.
  • Create, manage, maintain, and continuously improve security use cases, playbooks, runbooks, and knowledge-base articles.
  • Support audit-related activities by gathering security evidence, validating controls, and collaborating with relevant stakeholders.
  • Maintain working knowledge of AI and Large Language Model tools and apply them practically within Security Operations.
  • Take ownership of responsibilities assigned during shifts and ensure timely escalation and follow-through.
  • Proactively engage stakeholders and escalate risks, incidents, blockers, or concerns when necessary.
  • Start owning incidents and tasks as an independent contributor with peer support during the initial onboarding period.
  • Handle SIEM, SOAR, and EDR events while adhering to standard operating procedures and ticket hygiene standards.
  • Document or improve standard operating procedures and process documents.
  • Represent the team in forums, meetings, and discussions.
  • Manage shifts independently when needed and contribute to service improvement.
  • Develop a specialization area aligned with team needs and personal development goals.
Desired Qualifications
  • Experience with Splunk.
  • Entry-level or intermediate cybersecurity certifications such as CompTIA Security+, CySA+, GIAC GSEC, cloud security certifications, or equivalent industry-recognized certifications.
  • Previous experience working within a SaaS, e-commerce, cloud-native, or technology company.
  • Experience supporting security operations in large-scale cloud infrastructure, API, container, distributed application, or SaaS environments.
  • Previous experience acting as an Incident Coordinator, Incident Commander, or security incident lead.

Bloomreach is a Software-as-a-Service company that helps businesses improve their online presence by personalizing digital experiences for customers. It primarily serves the e-commerce and digital marketing space with the Bloomreach Experience Manager, a platform for creating, managing, and optimizing digital content. The system uses smart, continuously learning algorithms to understand how customers search and what they want, enabling automatic content generation and page personalization that aligns with user intent and supports higher search rankings. Compared with others, Bloomreach combines content management, search optimization, and personalization on a single SaaS platform, focusing on understanding customer language and intent at scale. Its goal is to help retailers, travel, finance, and other industries deliver relevant experiences that boost engagement, conversions, and SEO performance.

Company Size

1,001-5,000

Company Stage

Debt Financing

Total Funding

$452M

Headquarters

Mountain View, California

Founded

2009

Get referred to Bloomreach

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • August 5, 2026: Ask Me Anything routes orders, returns, and shopping questions without channel switches.
  • June 24, 2026: Loomi gained conversational insights dashboards for catalog gaps and transcript analytics.
  • August 13, 2026: Inc. 5000 recognition signals strong 2026 growth momentum.

What critics are saying

  • Fairphone's February 2026 email malfunction shows Bloomreach automation failures can hit customer trust.
  • Shopify and Salesforce can bundle native AI search, crushing Bloomreach pricing by 2027.
  • If Loomi underdelivers, merchants replace Bloomreach with platform-native AI, leaving a shrinking niche.

What makes Bloomreach unique

  • August 5, 2026: Loomi turns Bloomreach search, chat, and service into one context layer.
  • June 17, 2026: Shopify Sidekick exposes query-level ranking logic inside merchant workflows.
  • August 13, 2026: Bloomreach reported over $260 million ARR and 1,400 global brands.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Company Match

Flexible Work Hours

Remote Work Options

Paid Holidays

Professional Development Budget

Wellness Program

Mental Health Support

Stock Options

Performance Bonus

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
QUASA
Aug 29th, 2026
eComID raises $17M - its Shopping Passport needs a brand network.

eComID raises $17M - its Shopping Passport needs a brand network. Stockholm-based eComID disclosed a $17 million seed round in its August 25, 2026 funding release, naming Systemiq Capital as lead investor and Regeneration.VC, Course Corrected, Stadium and returning investor CapitalT as participants. The capital is intended for international expansion, further development of the Shopping Passport, hiring and supporting infrastructure. The product stores shopper-supplied context such as size, fit and style preferences for reuse across participating retailers, subject to the shopper's permission. The investment therefore backs a network rather than simply another recommendation feature: portable context becomes more useful only when enough brands accept it and enough shoppers consent to sharing it. The funding must expand both the product and its coverage. Improving sizing, conversational search and product discovery addresses only one part of eComID's challenge. The company must also place those capabilities across enough retail sites for shoppers to encounter the same passport repeatedly, otherwise its cross-brand proposition collapses into familiar single-store personalisation. The investor mix is relevant to that task because Stadium is also an eComID customer, giving the round a direct retail connection alongside venture backing. Even so, financing cannot create network density by itself. Each additional integration must become an active destination where shoppers see enough value to maintain a profile and permit its use. Tech Funding News's account of eComID's traction figures puts its footprint at more than 60 brands and 20 million shoppers reached each month, while repeating company claims of a 30% lower return rate among shoppers using the platform and a 10% conversion increase for brands. These are company-reported figures; the public material does not provide an independent audit, test design, comparison period or module-level breakdown. How the Shopping Passport moves context between stores. A shopper enters sizing, fit and style preferences into an eComID account. With permission, a participating retailer can use relevant information in pre-purchase tools such as size guidance, conversational search and product discovery, reducing the need to reconstruct the same profile at every store. The product is modular, so a merchant can adopt sizing, search, discovery or a combination of those functions. Vera, eComID's shopping agent, applies available shopper context on participating brands' own sites; the passport does not replace the retailer's storefront, catalogue or product data. Portability is the intended distinction. A retailer-specific personalisation system learns from activity inside one merchant's environment, while the Shopping Passport is designed to let selected context follow a shopper to another connected brand. A stored profile alone cannot guarantee a useful recommendation: the destination retailer must be integrated, its product information must support the request, and the shopper must allow access. More participating brands increase the passport's utility. The model contains a direct network dependency. Every new retailer can give an existing passport another place to work, while a larger population of active passport holders can make integration more attractive to merchants. The reverse is equally important: limited coverage gives shoppers fewer reasons to create, update or share a portable profile. Dealroom's analysis of the network bet identifies True Fit, Bloomreach, Nosto and Shopify's AI storefront tools as competing approaches, while distinguishing their retailer-level context from eComID's cross-brand model. That difference creates an adoption asymmetry: a merchant can obtain value from an in-store personalisation product independently, whereas portability becomes more compelling when shoppers repeatedly encounter connected brands. This is why the title's "needs" is consequential rather than rhetorical. If a profile works at only one retailer, it behaves much like ordinary account-based personalisation. The broader advantage emerges when multiple merchants recognise the passport and shoppers consider continuity valuable enough to authorise sharing. Consent gives shoppers control but limits automatic scale. Consent is central to the product's proposed distinction. Connecting a retailer does not automatically grant it access to a passport holder's full context; the shopper chooses what to share with that brand. Retailer integrations, registered accounts and active cross-brand exchanges are therefore different measures. The network has three necessary contributors. Shoppers provide preferences and permission, retailers provide integrated destinations and product context, and eComID's tools apply the available information to sizing, search and discovery. Weak participation on any side constrains the result: more brands do not help a shopper who declines sharing, while willing shoppers gain little portability if the stores they visit are absent. Consent quality matters as much as the presence of a consent screen. Users need to understand which details will move, which retailer will receive them and what benefit the exchange is expected to provide. The available coverage describes user control but does not publish opt-in, refusal or revocation rates for sharing with a new brand. The round funds a network thesis that remains unproven. The seed financing gives eComID resources to pursue new markets and retail integrations. It does not establish that the Shopping Passport already operates as a dense cross-brand network, nor that aggregate exposure across retail sites translates into repeated use of the same consented profile. Important adoption measures remain undisclosed: the share of reached shoppers who maintain an active passport, how often one profile is used at multiple retailers, and how commercial outcomes differ between individual modules and cross-brand use. Without those figures, monthly reach and retailer count indicate distribution potential rather than network depth. The next evidence will be whether eComID can convert funding into active passports, recurring cross-brand reuse, sustained consent and independently validated retail outcomes. For now, the confirmed story is a $17 million seed round for a portable shopper-context layer whose strongest advantage depends on brands and shoppers participating together.

Bloomreach
Aug 13th, 2026
Bloomreach named to 2026 Inc. 5000 List of America's fastest growing private companies.

Bloomreach named to 2026 Inc. 5000 List of America's fastest growing private companies. MOUNTAIN VIEW, CA, August 13, 2026 - Bloomreach, the AI company for personalization, today announced it has been named to the 2026 Inc. 5000 list, the annual list of the fastest-growing private companies in America. The list is the most prestigious ranking of the nation's most successful independent and entrepreneurial businesses, recognizing companies that have achieved remarkable growth while driving innovation, creating jobs, and shaping the future of the economy. "Earning a place on the Inc. 5000 list for the fifth year validates the remarkable results our customers are achieving and showcases the innovation our team delivers every day," said Raj De Datta, co-founder and CEO, Bloomreach. "We're honored by this achievement and remain focused on advancing AI-powered personalization for the businesses we serve around the world." This year's Inc. 5000 recognizes a new class of companies redefining what growth looks like. From AI and advanced manufacturing to healthcare, consumer products, and professional services, these businesses are expanding their impact, creating jobs and proving that entrepreneurial ambition continues to fuel the U.S. economy. Among the 5,000 companies on the list, the median three-year revenue growth rate was 130%, and those companies have collectively added more than 627,208 jobs to the U.S. economy over the past three years. "Every company on the Inc. 5000 has a story of perseverance, smart decision making, and a refusal to sit still," says Mike Hofman, editor-in-chief of Inc. "Their growth reflects more than strong financial performance-it reflects creativity, resilience, and the customer focus required to build companies that make a lasting impact. We congratulate all honorees on this significant achievement." Inc. 5000 List Methodology Companies on the 2026 Inc. 5000 are ranked according to percentage revenue growth from 2022 to 2025. To qualify, companies must have been founded and generating revenue by March 31, 2022. They must be U.S.-based, privately held, for-profit, and independent - not subsidiaries or divisions of other companies - as of December 31, 2025. (Since then, some on the list may have gone public or been acquired.) The minimum revenue required for 2022 is $100,000; the minimum for 2025 is $2 million. As always, Inc. reserves the right to decline applicants for subjective reasons. For the full Inc. 5000 list, honoree company profiles, and a searchable database by industry and location, please visit: www.inc.com/inc5000 About Bloomreach Bloomreach personalizes the customer experience for brands around the world. Loomi AI, its agentic platform, understands every customer in context - then tailors their experience in real time. Connected to applications at every touchpoint, Loomi AI brings personalization to life across email, web, messaging, mobile apps, search, and more. From retail to financial services, hospitality to gaming, Bloomreach powers end-to-end experiences for 1,400+ global brands, including American Eagle, Sonepar, and Pandora. About Inc. Inc. is the leading media brand and playbook for the entrepreneurs and business leaders shaping its future. Through its journalism, Inc. aims to inform, educate, and elevate the profile of its community: the risk-takers, the innovators, and the ultra-driven go-getters who are creating the future of business. Inc. is published by Mansueto Ventures LLC, along with fellow leading business publication Fast Company. For more information, visit www.inc.com. Media Contact Michelle DeMaio Bloomreach Corporate Communications Ready to see Bloomreach in action? Share with your community.

MarTech Vibe
Aug 7th, 2026
Bloomreach unveils 'ask Me Anything' AI shopping experience.

Bloomreach unveils 'ask Me Anything' AI shopping experience. Through integrations with any third-party customer service agent, shoppers can even ask questions related to orders and returns directly in the search bar. Bloomreach, the AI company for personalisation, has announced the launch of a new "Ask Me Anything" agentic capability for brands and retailers. Powered by Loomi, the company's agentic personalisation platform, the experience transforms the search bar into a single entry point where shoppers can search by keyword, ask conversational shopping questions, and even get help with customer service - all without switching tools or pages. The "Ask Me Anything" capability works by stitching together a number of different functionalities. Loomi conversational agent serves as the orchestration layer, recognising shopper intent and routing each request to the right experience in real time. Keyword searches leverage Loomi's deep capabilities in traditional search and merchandising to give fast, relevant responses. Shopping questions leverage its generative capabilities to provide more thorough expertise and guidance. Through integrations with any third-party customer service agent, shoppers can even ask questions related to orders and returns directly in the search bar. These questions get routed to a brand's existing service agent, easily plugging into existing workflows and service desk setups. For shoppers, everything happens within a single window, offering a seamless experience. "Shoppers don't think in channels or tools - they just have questions and needs," said Anirban Bardalaye, Chief Product Officer, Bloomreach. "What we've built brings that reality to life for ecommerce. One entry point, powered by Loomi, that understands any intent and returns the right experience instantly. That's the power of having your entire experience orchestrated by a single AI context layer." The "Ask Me Anything" experience is available and is already supporting shoppers with reduced friction, faster answers, and a richer experience from the first query to the final click. Sophia Bennett is a news curator at Martechvibe, covering global developments across marketing technology, digital transformation, AI, data, and customer experience trends. View More

Bloomreach
Aug 5th, 2026
Bloomreach launches multi-agent "ask Me Anything" Capability powered by Loomi, transforming the search bar into a single entry point for shoppers.

Bloomreach launches multi-agent "ask Me Anything" Capability powered by Loomi, transforming the search bar into a single entry point for shoppers. MOUNTAIN VIEW, CA, August 5, 2026 - Bloomreach, the AI company for personalization, today announced the launch of a new "Ask Me Anything" agentic capability for brands and retailers. Powered by Loomi, the company's agentic personalization platform, the experience transforms the search bar into a single entry point where shoppers can search by keyword, ask conversational shopping questions, and even get help with customer service - all without switching tools or pages. The "Ask Me Anything" capability works by stitching together a number of different functionalities. Loomi conversational agent serves as the orchestration layer, recognizing shopper intent and routing each request to the right experience in real time. Keyword searches leverage Loomi's deep capabilities in traditional search and merchandising to give fast, relevant responses. Shopping questions leverage its generative capabilities to provide more thorough expertise and guidance. Through integrations with any third-party customer service agent, shoppers can even ask questions related to orders and returns directly in the search bar. These questions get routed to a brand's existing service agent, easily plugging into existing workflows and service desk setups. For shoppers, everything happens within a single window, offering a seamless experience. "Shoppers don't think in channels or tools - they just have questions and needs," said Anirban Bardalaye, Chief Product Officer, Bloomreach. "What we've built brings that reality to life for ecommerce. One entry point, powered by Loomi, that understands any intent and returns the right experience instantly. That's the power of having your entire experience orchestrated by a single AI context layer." The "Ask Me Anything" experience is available now and is already supporting shoppers with reduced friction, faster answers, and a richer experience from the first query to the final click. About Bloomreach Bloomreach personalizes the customer experience through Loomi, its agentic personalization platform. With apps spanning email, web, ads, search, and more - and agents spanning marketing and conversational shopping - Loomi brings real-time personalization to life at every customer touchpoint. From retail to financial services, hospitality to gaming, Loomi powers personalization for 1,400+ global brands, including American Eagle, Sonepar, and Pandora. Ready to see Bloomreach in action? Share with your community.

Associated Press
Aug 5th, 2026
Bloomreach launches AI-powered 'Ask Me Anything' search that handles shopping queries and customer service

Bloomreach has launched an "Ask Me Anything" capability that transforms the search bar into a unified entry point for shoppers. Powered by the company's Loomi agentic personalisation platform, the feature allows customers to conduct keyword searches, ask conversational shopping questions, and access customer service without switching tools or pages. The Loomi conversational agent serves as an orchestration layer, recognising shopper intent and routing requests to the appropriate experience in real time. Through integrations with third-party customer service agents, shoppers can ask questions about orders and returns directly in the search bar. The new capability is available now and already supporting shoppers. Bloomreach provides personalisation services to over 1,400 global brands, including American Eagle, Sonepar, and Pandora.