Lead Cyber Defence Analyst
Bangalore, INWichtige Merkmale des Angebots
Mind. 5 Jahre Erfahrung
Vollzeit
Remote-Arbeit - kein Pendeln
Description
Hello, we're IG Group. We are a publicly-traded FTSE250 FinTech company who run mobile, web and desktop platforms that help our clients trade stocks & shares, leveraged products, Futures & Options and Crypto.
The Perks
Matched giving for your fundraising activity
Flexible working hours and work-from-home opportunities
Performance-related bonuses
Insurance and medical plans
Career-focused technical and leadership training in class and online, incl. unlimited access to LinkedIn Learning platform
Contribution to gym memberships and more
Free Lunch/Snacks
A day off on your birthday
Two days’ volunteering leave per year.
How we work
Lead and Inspire: Drives trust, alignment, and enthusiasm
Think Big: Focus on the problems that most impact commercial outcomes
Champion the client: Understand and prioritise client's needs
Deliver at pace: Push for fast, sustainable growth;
Raise the bar: Take ownership, be accountable and share feedback
APAC (Primary Working Window)
India (IST): 08:00 – 17:00
EMEA (Primary Working Window)
India (IST): 13:30 – 23:30
What you'll do
Act as the senior escalation point for complex, high, and critical severity incidents — leading investigations, coordinating response efforts, and keeping the SOC Manager informed throughout.
Design and implement improvements to detection rules and SOAR automation, drawing on threat intelligence, lessons learnt, and emerging global threat trends.
Lead post-incident reviews for high and critical severity incidents, facilitating lessons learnt discussions and driving measurable improvements to SOC processes and tooling.
Mentor and coach L1 and L2 analysts, organise tabletop exercises focused on current threat trends, and provide cover and support for SOC Team Leaders when needed.
Maintain shift oversight, monitor team workload and incident queues, and conduct proactive threat hunts in line with the JIRA procedure.
What you'll need for this role
6+ years of extensive experience in SOC operations and incident response, with a proven ability to lead complex, high-pressure investigations and coordinate across teams.
Deep technical expertise across SIEM and SOAR platforms, EDR tooling, and threat detection technologies, including hands-on experience building and automating detection logic and playbooks in production environments.
Demonstrated ability to develop and maintain automated workflows that improve SOC efficiency and reduce analyst toil.
Strong mentoring and communication skills, with experience coaching analysts at multiple levels and delivering structured learning activities such as tabletop exercises.
A proactive, improvement-focused mindset — comfortable analysing incident metrics, identifying gaps, and taking ownership of making things better.