Svb
Lead Information Security Engineer - Cyber Ops (Threat Monitoring)
Bangalore, India
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Role family
- Engineering
- Seniority
- Lead / management
- Country
- IN
- Work mode
- On-site / unstated
- First seen by hirly
- 23 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
FC Global Services India LLP (First Citizens India), a part of First Citizens BancShares, Inc., a top 20 U.S. financial institution, is a global capability center (GCC) based in Bengaluru. Our India-based teams benefit from the company’s over 125-year legacy of strength and stability. First Citizens India is responsible for delivering value and managing risks for our lines of business. We are particularly proud of our strong, relationship-driven culture and our long-term approach, which are deeply ingrained in our talented workforce. This is evident across all key areas of our operations, including Technology, Enterprise Operations, Finance, Cybersecurity, Risk Management, and Credit Administration. We are seeking talented individuals to join us in our mission of providing solutions fit for our clients’ greatest ambitions.
Job Description:
Value Proposition
Join a high-performing Cyber Security Operations team responsible for protecting the organization against evolving cyber threats through advanced monitoring, threat detection, and incident analysis. This role offers the opportunity to lead complex investigations, enhance detection capabilities, and drive continuous improvements in security monitoring operations. As a senior individual contributor, you will play a key role in identifying threats, reducing risk, and strengthening the organization's cyber resilience.
Job Details
- Position Title : Lead Information Security Engineer – Threat Monitoring
- Career Level : P3
- Job Category : Manager
- Role Type : Hybrid
- Job Location : Bangalore
About the Team
The Security Operations Center (SOC) Threat Monitoring team is responsible for continuously monitoring the organization's security landscape to detect, investigate, and respond to cyber threats. The team leverages SIEM, XDR, EDR, threat intelligence, cloud security platforms, and advanced analytics to identify malicious activities and safeguard business operations. Working closely with Incident Response, Threat Intelligence, Detection Engineering, and Infrastructure teams, the SOC serves as the frontline defense against cyber threats.
Impact
This role is critical to maintaining effective cyber defense operations by identifying and responding to security threats before they impact business operations. The Senior SOC Analyst will lead complex threat investigations, improve monitoring efficiency, enhance detection capabilities, and provide technical expertise during security incidents. Through proactive monitoring and threat analysis, the role contributes directly to reducing incident response times, minimizing business risk, and strengthening overall security posture.
Key Deliverables (Duties and Responsibilities)
- Monitor, analyze, and investigate security alerts, events, and indicators of compromise across enterprise, cloud, network, endpoint, and identity environments.
- Perform advanced triage and investigation of suspicious activities, security incidents, and anomalous behavior to determine potential business impact and threat severity.
- Lead the investigation and escalation of high-priority security incidents, including malware infections, phishing attacks, insider threats, ransomware, account compromises, and advanced persistent threats (APTs).
- Correlate information from multiple security tools and data sources to identify attack patterns, threat campaigns, and emerging risks.
- Collaborate with Incident Response teams during containment, eradication, and recovery activities for active security incidents.
- Develop, tune, and optimize use cases, correlation rules, detection logic, and alerting mechanisms to improve detection accuracy and reduce false positives.
- Work closely with Threat Intelligence teams to operationalize indicators of compromise (IOCs), threat actor TTPs, and intelligence-driven detections.
- Monitor and analyze emerging threats, vulnerabilities, and attack techniques that may impact the organization.
- Support security monitoring across cloud environments, including Azure, AWS, GCP, SaaS platforms, and hybrid infrastructure
- Document investigations, findings, attack timelines, and recommendations in accordance with operational and compliance requirements.
- Mentor junior SOC analysts and provide guidance on investigation techniques, threat analysis, and operational best practices.
- Contribute to automation initiatives that improve alert triage, enrichment, investigation workflows, and operational efficiency.
- Maintain SOC playbooks, knowledge repositories, detection standards, and operational procedures.
- Support audit, compliance, and governance requirements by providing relevant security monitoring evidence and reporting.
- Participate in continuous improvement initiatives aimed at enhancing SOC maturity, monitoring coverage, and threat detection effectiveness.
Skills and Qualifications
Functional Skills
- Strong expertise in Security Operations Center (SOC) monitoring and incident investigation.
- Advanced analytical and critical thinking skills for identifying sophisticated attack techniques and security threats.
- Strong understanding of incident response processes and cyber defense operations.
- Excellent written and verbal communication skills with the ability to communicate technical findings clearly.
- Ability to work effectively in fast-paced environments and manage multiple investigations simultaneously.
- Strong stakeholder management and collaboration skills across technical and business teams.
Technical / Business Skills
- 8-10 years of cybersecurity experience with significant experience in Security Operations, Threat Monitoring, or Incident Detection.
- Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel ,QRadar, Elastic, or similar technologies.
- Strong expertise on SOAR platform such as XSOAR.
- Strong expertise in EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, Cortex XDR, or equivalent platforms.
- Experience investigating and responding to endpoint, network, cloud, identity, and application security incidents.
- Strong understanding of MITRE ATT&CK Framework, Cyber Kill Chain, attack methodologies, and adversary behaviors.
- Experience in threat hunting, IOC analysis, and detection engineering concepts.
- Familiarity with SOAR platforms and security automation technologies.
- Experience working with cloud security monitoring technologies across Azure, AWS, and GCP.
- Proficiency in KQL, SPL, SQL, PowerShell, Python, or similar scripting/query languages.
- Knowledge of malware analysis fundamentals, phishing investigations, and forensic investigation techniques.
- Understanding of security logging, telemetry collection, and event correlation methodologies.
Leadership Qualities
- Demonstrates ownership and accountability for security monitoring and incident investigation activities.
- Acts as a senior technical resource and subject matter expert within the SOC.
- Drives operational excellence through continuous improvement of detection and monitoring processes.
- Mentors analysts and promotes knowledge-sharing across the security organization.
- Maintains composure and sound decision-making during high-severity incidents and crisis situations.
- Champions proactive threat detection and continuous learning within the security operations environment.
Relationships & Collaboration
- Collaborates closely with Threat Intelligence, Incident Response, Detection Engineering, Security Engineering, and Vulnerability Management teams.
- Partners with Infrastructure, Cloud, Network, and Application teams during investigations and remediation activities.
- Works with Risk, Compliance, Governance, and Audit teams to support security and regulatory requirements.
- Engages with technology vendors and service providers during incident investigations and security operations improvements.
- Communicates effectively with cybersecurity leadership regarding security events, operational metrics, and emergi
Similar jobs
- NETSKOPE SECURITY ENGINEERVrinda International · Bangalore, Karnataka, IndiaFirst seen 2d ago
- Staff Cyber Security EngineerGehc · IND19-01-Bengaluru-EPIP 122 (Phase II)First seen 2d ago
- Lead Information Security Engineer, ITCNike · Karnataka, IndiaFirst seen 2d ago
- Lead Information Security Engineer, ITCNike · Karnataka, IndiaFirst seen 2d ago
- Sr. Security EngineerCoupang · BengaluruFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job