Lead Information Security Engineer - Cyber Ops (Threat Monitoring)

Posted 5 Days Ago
Be an Early Applicant
Bangalore, Bengaluru Urban, Karnataka, IND
In-Office
Expert/Leader
Financial Services
The Role
Leads security operations threat monitoring and complex incident investigations across enterprise, cloud, network, endpoint, identity, and application environments. Investigates malware, phishing, ransomware, insider threats, account compromises, and advanced persistent threats; improves SIEM, SOAR, EDR, detection logic, and alerting; operationalizes threat intelligence; supports incident response, threat hunting, automation, audits, and compliance; and mentors junior SOC analysts.
Summary Generated by Built In

FC Global Services India LLP (First Citizens India), a part of First Citizens BancShares, Inc., a top 20 U.S. financial institution, is a global capability center (GCC) based in Bengaluru. Our India-based teams benefit from the company’s over 125-year legacy of strength and stability. First Citizens India is responsible for delivering value and managing risks for our lines of business. We are particularly proud of our strong, relationship-driven culture and our long-term approach, which are deeply ingrained in our talented workforce. This is evident across all key areas of our operations, including Technology, Enterprise Operations, Finance, Cybersecurity, Risk Management, and Credit Administration. We are seeking talented individuals to join us in our mission of providing solutions fit for our clients’ greatest ambitions.

Job Description:

Value Proposition

Join a high-performing Cyber Security Operations team responsible for protecting the organization against evolving cyber threats through advanced monitoring, threat detection, and incident analysis. This role offers the opportunity to lead complex investigations, enhance detection capabilities, and drive continuous improvements in security monitoring operations. As a senior individual contributor, you will play a key role in identifying threats, reducing risk, and strengthening the organization's cyber resilience.

Job Details

Position Title: Lead Information Security Engineer – Threat Monitoring
Career Level: P3
Job Category: Manager
Role Type: Hybrid
Job Location: Bangalore

About the Team

The Security Operations Center (SOC) Threat Monitoring team is responsible for continuously monitoring the organization's security landscape to detect, investigate, and respond to cyber threats. The team leverages SIEM, XDR, EDR, threat intelligence, cloud security platforms, and advanced analytics to identify malicious activities and safeguard business operations. Working closely with Incident Response, Threat Intelligence, Detection Engineering, and Infrastructure teams, the SOC serves as the frontline defense against cyber threats.

Impact

This role is critical to maintaining effective cyber defense operations by identifying and responding to security threats before they impact business operations. The Senior SOC Analyst will lead complex threat investigations, improve monitoring efficiency, enhance detection capabilities, and provide technical expertise during security incidents. Through proactive monitoring and threat analysis, the role contributes directly to reducing incident response times, minimizing business risk, and strengthening overall security posture.

Key Deliverables (Duties and Responsibilities)

  • Monitor, analyze, and investigate security alerts, events, and indicators of compromise across enterprise, cloud, network, endpoint, and identity environments.
  • Perform advanced triage and investigation of suspicious activities, security incidents, and anomalous behavior to determine potential business impact and threat severity.
  • Lead the investigation and escalation of high-priority security incidents, including malware infections, phishing attacks, insider threats, ransomware, account compromises, and advanced persistent threats (APTs).
  • Correlate information from multiple security tools and data sources to identify attack patterns, threat campaigns, and emerging risks.
  • Collaborate with Incident Response teams during containment, eradication, and recovery activities for active security incidents.
  • Develop, tune, and optimize use cases, correlation rules, detection logic, and alerting mechanisms to improve detection accuracy and reduce false positives.
  • Work closely with Threat Intelligence teams to operationalize indicators of compromise (IOCs), threat actor TTPs, and intelligence-driven detections.
  • Monitor and analyze emerging threats, vulnerabilities, and attack techniques that may impact the organization.
  • Support security monitoring across cloud environments, including Azure, AWS, GCP, SaaS platforms, and hybrid infrastructure
  • Document investigations, findings, attack timelines, and recommendations in accordance with operational and compliance requirements.
  • Mentor junior SOC analysts and provide guidance on investigation techniques, threat analysis, and operational best practices.
  • Contribute to automation initiatives that improve alert triage, enrichment, investigation workflows, and operational efficiency.
  • Maintain SOC playbooks, knowledge repositories, detection standards, and operational procedures.
  • Support audit, compliance, and governance requirements by providing relevant security monitoring evidence and reporting.
  • Participate in continuous improvement initiatives aimed at enhancing SOC maturity, monitoring coverage, and threat detection effectiveness.

Skills and Qualifications

Functional Skills

  • Strong expertise in Security Operations Center (SOC) monitoring and incident investigation.
  • Advanced analytical and critical thinking skills for identifying sophisticated attack techniques and security threats.
  • Strong understanding of incident response processes and cyber defense operations.
  • Excellent written and verbal communication skills with the ability to communicate technical findings clearly.
  • Ability to work effectively in fast-paced environments and manage multiple investigations simultaneously.
  • Strong stakeholder management and collaboration skills across technical and business teams.

Technical / Business Skills

  • 8-10 years of cybersecurity experience with significant experience in Security Operations, Threat Monitoring, or Incident Detection.
  • Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel ,QRadar, Elastic, or similar technologies.
  • Strong expertise on SOAR platform such as XSOAR.
  • Strong expertise in EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, Cortex XDR, or equivalent platforms.
  • Experience investigating and responding to endpoint, network, cloud, identity, and application security incidents.
  • Strong understanding of MITRE ATT&CK Framework, Cyber Kill Chain, attack methodologies, and adversary behaviors.
  • Experience in threat hunting, IOC analysis, and detection engineering concepts.
  • Familiarity with SOAR platforms and security automation technologies.
  • Experience working with cloud security monitoring technologies across Azure, AWS, and GCP.
  • Proficiency in KQL, SPL, SQL, PowerShell, Python, or similar scripting/query languages.
  • Knowledge of malware analysis fundamentals, phishing investigations, and forensic investigation techniques.
  • Understanding of security logging, telemetry collection, and event correlation methodologies.

Leadership Qualities

  • Demonstrates ownership and accountability for security monitoring and incident investigation activities.
  • Acts as a senior technical resource and subject matter expert within the SOC.
  • Drives operational excellence through continuous improvement of detection and monitoring processes.
  • Mentors analysts and promotes knowledge-sharing across the security organization.
  • Maintains composure and sound decision-making during high-severity incidents and crisis situations.
  • Champions proactive threat detection and continuous learning within the security operations environment.

Relationships & Collaboration

  • Collaborates closely with Threat Intelligence, Incident Response, Detection Engineering, Security Engineering, and Vulnerability Management teams.
  • Partners with Infrastructure, Cloud, Network, and Application teams during investigations and remediation activities.
  • Works with Risk, Compliance, Governance, and Audit teams to support security and regulatory requirements.
  • Engages with technology vendors and service providers during incident investigations and security operations improvements.
  • Communicates effectively with cybersecurity leadership regarding security events, operational metrics, and emerging threats.
  • Builds strong working relationships across technical and business functions to strengthen organizational cyber resilience.

Accessibility Needs

We are committed to providing an inclusive and accessible hiring process. If you require accommodations at any stage (application, interviews, assessments, or onboarding), we will work with you to ensure an equitable and seamless experience.

Equal Employment Opportunity

FC Global Services India LLP (First Citizens India) is an Equal Employment Opportunity Employer. We are committed to fostering an inclusive and accessible environment and prohibit all forms of discrimination on the basis of gender, religion, caste, disability, sexual orientation, economic status or any other characteristics protected by the law. We strive to foster a safe and respectful environment in which all individuals are treated with respect and dignity. Our EEO policy ensures fairness throughout the employee life cycle.

Skills Required

  • 8-10 years of cybersecurity experience, including significant Security Operations, Threat Monitoring, or Incident Detection experience
  • Strong expertise in SOC monitoring and incident investigation
  • Advanced analytical and critical-thinking skills for identifying sophisticated attacks and threats
  • Strong understanding of incident response and cyber defense operations
  • Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, Elastic, or equivalent
  • Strong expertise with SOAR platforms such as XSOAR
  • Strong expertise with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Cortex XDR
  • Experience investigating endpoint, network, cloud, identity, and application security incidents
  • Understanding of MITRE ATT&CK, Cyber Kill Chain, attack methodologies, and adversary behaviors
  • Experience in threat hunting, IOC analysis, and detection engineering
  • Experience with cloud security monitoring across Azure, AWS, and GCP
  • Proficiency in KQL, SPL, SQL, PowerShell, Python, or similar scripting/query languages
  • Knowledge of malware analysis fundamentals, phishing investigations, and forensic investigation techniques
  • Understanding of security logging, telemetry collection, and event correlation
  • Strong written and verbal communication skills
  • Strong stakeholder management and cross-functional collaboration skills
  • Ability to manage multiple investigations in a fast-paced environment

Silicon Valley Bank Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Silicon Valley Bank and has not been reviewed or approved by Silicon Valley Bank.

  • Healthcare Strength — Medical, dental, and vision coverage are broad, complemented by mental health resources, healthcare advocacy, and wellness programs. Multiple plan options and added programs (e.g., digital health and well-being services) indicate depth in healthcare support.
  • Retirement Support — Retirement programs include a matched 401(k) and additional savings vehicles such as ESOP and ESPP. Match levels and potential discretionary contributions signal strong employer support for long-term savings.
  • Parental & Family Support — Parental leave provides up to 12 weeks at full base pay for birth or adoption. Family support extends to back-up care, special needs assistance, college coaching, and inclusive family-building benefits like fertility, adoption, and surrogacy support.

Silicon Valley Bank Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
3,970 Employees
Year Founded: 1983

What We Do

Silicon Valley Bank (SVB), a division of First Citizens Bank, is the bank of the world’s most innovative companies and investors. SVB provides commercial and private banking to individuals and companies in the technology, life science and healthcare, private equity, venture capital and premium wine industries. SVB operates in centers of innovation throughout the United States, serving the unique needs of its dynamic clients with deep sector expertise, insights and connections. SVB's parent company, First Citizens Bancshares, Inc. (NASDAQ: FCNCA) is a top 20 U.S. financial institution with more than $200 billion in assets. First Citizens Bank, Member FDIC. Learn more at svb.com.

Similar Jobs

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Firmware Validation Engineer (Python - AI, Automation)

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
85422 Employees
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
289097 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Sales Processing Analyst

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office
2 Locations
85422 Employees

Optum Logo Optum

Director - Portfolio Marketing

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
160000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account