NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in India
7 hours agoBe an early applicant
Apply with autofill
Apply with autofill
Svb·7 hours ago
7 hours agoBe an early applicant

Lead Information Security Engineer - Cyber Ops (Threat Monitoring)

Bengaluru, IndiaSenior · 6-10 yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at svb

How you compare FREE

?
Your scoreYour score: not yet known
→
64
Top 10%Top 10%: 64 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in India.

Must-have skills for this role

  • splunk
  • microsoft sentinel
  • qradar
  • elastic

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Monitor, analyze, and investigate security alerts, events, and indicators of compromise across enterprise, cloud, network, endpoint, and identity environments.
  • Perform advanced triage and investigation of suspicious activities, security incidents, and anomalous behavior to determine potential business impact and threat severity.
  • Lead the investigation and escalation of high-priority security incidents, including malware infections, phishing attacks, insider threats, ransomware, account compromises, and advanced persistent threats (APTs).
  • Correlate information from multiple security tools and data sources to identify attack patterns, threat campaigns, and emerging risks.
  • Collaborate with Incident Response teams during containment, eradication, and recovery activities for active security incidents.
  • Develop, tune, and optimize use cases, correlation rules, detection logic, and alerting mechanisms to improve detection accuracy and reduce false positives.
  • Work closely with Threat Intelligence teams to operationalize indicators of compromise (IOCs), threat actor TTPs, and intelligence-driven detections.
  • Monitor and analyze emerging threats, vulnerabilities, and attack techniques that may impact the organization.
  • Support security monitoring across cloud environments, including Azure, AWS, GCP, SaaS platforms, and hybrid infrastructure
  • Document investigations, findings, attack timelines, and recommendations in accordance with operational and compliance requirements.
  • Mentor junior SOC analysts and provide guidance on investigation techniques, threat analysis, and operational best practices.
  • Contribute to automation initiatives that improve alert triage, enrichment, investigation workflows, and operational efficiency.

What they're looking for

  • 8-10 years of cybersecurity experience with significant experience in Security Operations, Threat Monitoring, or Incident Detection.
  • Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel ,QRadar, Elastic, or similar technologies.
  • Strong expertise on SOAR platform such as XSOAR.
  • Strong expertise in EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, Cortex XDR, or equivalent platforms.
  • Experience investigating and responding to endpoint, network, cloud, identity, and application security incidents.
  • Strong understanding of MITRE ATT&CK Framework, Cyber Kill Chain, attack methodologies, and adversary behaviors.
  • Experience in threat hunting, IOC analysis, and detection engineering concepts.
  • Familiarity with SOAR platforms and security automation technologies.
  • Experience working with cloud security monitoring technologies across Azure, AWS, and GCP.
  • Proficiency in KQL, SPL, SQL, PowerShell, Python, or similar scripting/query languages.
  • Knowledge of malware analysis fundamentals, phishing investigations, and forensic investigation techniques.
  • Understanding of security logging, telemetry collection, and event correlation methodologies.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

FC Global Services India LLP (First Citizens India), a part of First Citizens BancShares, Inc., a top 20 U.S. financial institution, is a global capability center (GCC) based in Bengaluru. Our India-based teams benefit from the company’s over 125-year legacy of strength and stability. First Citizens India is responsible for delivering value and managing risks for our lines of business. We are particularly proud of our strong, relationship-driven culture and our long-term approach, which are deeply ingrained in our talented workforce. This is evident across all key areas of our operations, including Technology, Enterprise Operations, Finance, Cybersecurity, Risk Management, and Credit Administration. We are seeking talented individuals to join us in our mission of providing solutions fit for our clients’ greatest ambitions.

Job Description:

Value Proposition


Join a high-performing Cyber Security Operations team responsible for protecting the organization against evolving cyber threats through advanced monitoring, threat detection, and incident analysis. This role offers the opportunity to lead complex investigations, enhance detection capabilities, and drive continuous improvements in security monitoring operations. As a senior individual contributor, you will play a key role in identifying threats, reducing risk, and strengthening the organization's cyber resilience.



Job Details

Position Title: Lead Information Security Engineer – Threat Monitoring
Career Level: P3
Job Category: Manager
Role Type: Hybrid
Job Location: Bangalore


About the Team

The Security Operations Center (SOC) Threat Monitoring team is responsible for continuously monitoring the organization's security landscape to detect, investigate, and respond to cyber threats. The team leverages SIEM, XDR, EDR, threat intelligence, cloud security platforms, and advanced analytics to identify malicious activities and safeguard business operations. Working closely with Incident Response, Threat Intelligence, Detection Engineering, and Infrastructure teams, the SOC serves as the frontline defense against cyber threats.


Impact

This role is critical to maintaining effective cyber defense operations by identifying and responding to security threats before they impact business operations. The Senior SOC Analyst will lead complex threat investigations, improve monitoring efficiency, enhance detection capabilities, and provide technical expertise during security incidents. Through proactive monitoring and threat analysis, the role contributes directly to reducing incident response times, minimizing business risk, and strengthening overall security posture.


Key Deliverables (Duties and Responsibilities)

  • Monitor, analyze, and investigate security alerts, events, and indicators of compromise across enterprise, cloud, network, endpoint, and identity environments.
  • Perform advanced triage and investigation of suspicious activities, security incidents, and anomalous behavior to determine potential business impact and threat severity.
  • Lead the investigation and escalation of high-priority security incidents, including malware infections, phishing attacks, insider threats, ransomware, account compromises, and advanced persistent threats (APTs).
  • Correlate information from multiple security tools and data sources to identify attack patterns, threat campaigns, and emerging risks.
  • Collaborate with Incident Response teams during containment, eradication, and recovery activities for active security incidents.
  • Develop, tune, and optimize use cases, correlation rules, detection logic, and alerting mechanisms to improve detection accuracy and reduce false positives.
  • Work closely with Threat Intelligence teams to operationalize indicators of compromise (IOCs), threat actor TTPs, and intelligence-driven detections.
  • Monitor and analyze emerging threats, vulnerabilities, and attack techniques that may impact the organization.
  • Support security monitoring across cloud environments, including Azure, AWS, GCP, SaaS platforms, and hybrid infrastructure
  • Document investigations, findings, attack timelines, and recommendations in accordance with operational and compliance requirements.
  • Mentor junior SOC analysts and provide guidance on investigation techniques, threat analysis, and operational best practices.
  • Contribute to automation initiatives that improve alert triage, enrichment, investigation workflows, and operational efficiency.
  • Maintain SOC playbooks, knowledge repositories, detection standards, and operational procedures.
  • Support audit, compliance, and governance requirements by providing relevant security monitoring evidence and reporting.
  • Participate in continuous improvement initiatives aimed at enhancing SOC maturity, monitoring coverage, and threat detection effectiveness.

Skills and Qualifications

Functional Skills

  • Strong expertise in Security Operations Center (SOC) monitoring and incident investigation.
  • Advanced analytical and critical thinking skills for identifying sophisticated attack techniques and security threats.
  • Strong understanding of incident response processes and cyber defense operations.
  • Excellent written and verbal communication skills with the ability to communicate technical findings clearly.
  • Ability to work effectively in fast-paced environments and manage multiple investigations simultaneously.
  • Strong stakeholder management and collaboration skills across technical and business teams.

Technical / Business Skills

  • 8-10 years of cybersecurity experience with significant experience in Security Operations, Threat Monitoring, or Incident Detection.
  • Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel ,QRadar, Elastic, or similar technologies.
  • Strong expertise on SOAR platform such as XSOAR.
  • Strong expertise in EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, Cortex XDR, or equivalent platforms.
  • Experience investigating and responding to endpoint, network, cloud, identity, and application security incidents.
  • Strong understanding of MITRE ATT&CK Framework, Cyber Kill Chain, attack methodologies, and adversary behaviors.
  • Experience in threat hunting, IOC analysis, and detection engineering concepts.
  • Familiarity with SOAR platforms and security automation technologies.
  • Experience working with cloud security monitoring technologies across Azure, AWS, and GCP.
  • Proficiency in KQL, SPL, SQL, PowerShell, Python, or similar scripting/query languages.
  • Knowledge of malware analysis fundamentals, phishing investigations, and forensic investigation techniques.
  • Understanding of security logging, telemetry collection, and event correlation methodologies.

Leadership Qualities

  • Demonstrates ownership and accountability for security monitoring and incident investigation activities.
  • Acts as a senior technical resource and subject matter expert within the SOC.
  • Drives operational excellence through continuous improvement of detection and monitoring processes.
  • Mentors analysts and promotes knowledge-sharing across the security organization.
  • Maintains composure and sound decision-making during high-severity incidents and crisis situations.
  • Champions proactive threat detection and continuous learning within the security operations environment.

Relationships & Collaboration

  • Collaborates closely with Threat Intelligence, Incident Response, Detection Engineering, Security Engineering, and Vulnerability Management teams.
  • Partners with Infrastructure, Cloud, Network, and Application teams during investigations and remediation activities.
  • Works with Risk, Compliance, Governance, and Audit teams to support security and regulatory requirements.
  • Engages with technology vendors and service providers during incident investigations and security operations improvements.
  • Communicates effectively with cybersecurity leadership regarding security events, operational metrics, and emerging threats.
  • Builds strong working relationships across technical and business functions to strengthen organizational cyber resilience.

Accessibility Needs

We are committed to providing an inclusive and accessible hiring process. If you require accommodations at any stage (application, interviews, assessments, or onboarding), we will work with you to ensure an equitable and seamless experien

ce.

Equal Employment Opportunity

FC Global Services India LLP (First Citizens India) is an Equal Employment Opportunity Employer. We are committed to fostering an inclusive and accessible environment and prohibit all forms of discrimination on the basis of gender, religion, caste, disability, sexual orientation, economic status or any other characteristics protected by the law. We strive to foster a safe and respectful environment in which all individuals are treated with respect and dignity. Our EEO policy ensures fairness throughout the employee life cycle.

Company

Svb
Bengaluru, India

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Svb's careers site·first seen 22 Sept 2026·last verified 22 Sept 2026·How we source jobs

Similar jobs

  • SOC Detection and Response - Engineer Cyber Security Engineer at UnisysBengaluru, India–match not yet calculated
  • Sr. Cybersecurity Engineer at AbbottMumbai, India–match not yet calculated
  • DevSecOps & Product Security Engineer at weekdayworksHyderabad, India–match not yet calculated
  • Product Security Engineer, Senior at tracelinkincPune, India–match not yet calculated
  • Application and Product Security II Engineer II at VertivPune, India–match not yet calculated

Browse more jobs

  • Security Engineer jobs in India
  • Security Analyst jobs in India
  • Cloud Security Engineer jobs in India
  • Penetration Tester jobs in India
  • Security Engineer jobs in United States
  • Security Engineer jobs in United Kingdom