Lead Cyber Defence Analyst
Bangalore, INОсновні характеристики вакансії
Мін. 5 років досвіду
Повний робочий день
Віддалена робота - без поїздок
Description
G Group is a FTSE 100 fintech operating across five continents, serving over 1.4m customers and handling billions of dollars in transactions – built on scale, trust, and proof. We didn't pivot to innovation; it's how we've always operated. What that means for the people who work here is real: genuinely complex problems to solve, the technology and resources to tackle them properly, and the kind of scope that's rare in established businesses.
The Perks
Matched giving for your fundraising activity
Flexible working hours and work-from-home opportunities
Performance-related bonuses
Insurance and medical plans
Career-focused technical and leadership training in class and online, incl. unlimited access to LinkedIn Learning platform
Contribution to gym memberships and more
Free Lunch/Snacks
A day off on your birthday
Two days’ volunteering leave per year.
APAC (Primary Working Window)
India (IST): 08:00 – 17:00
EMEA (Primary Working Window)
India (IST): 13:30 – 23:30
What you'll do
Act as the senior escalation point for complex, high, and critical severity incidents — leading investigations, coordinating response efforts, and keeping the SOC Manager informed throughout.
Design and implement improvements to detection rules and SOAR automation, drawing on threat intelligence, lessons learnt, and emerging global threat trends.
Lead post-incident reviews for high and critical severity incidents, facilitating lessons learnt discussions and driving measurable improvements to SOC processes and tooling.
Mentor and coach L1 and L2 analysts, organise tabletop exercises focused on current threat trends, and provide cover and support for SOC Team Leaders when needed.
Maintain shift oversight, monitor team workload and incident queues, and conduct proactive threat hunts in line with the JIRA procedure.
What you'll need for this role
6+ years of extensive experience in SOC operations and incident response, with a proven ability to lead complex, high-pressure investigations and coordinate across teams.
Deep technical expertise across SIEM and SOAR platforms, EDR tooling, and threat detection technologies, including hands-on experience building and automating detection logic and playbooks in production environments.
Demonstrated ability to develop and maintain automated workflows that improve SOC efficiency and reduce analyst toil.
Strong mentoring and communication skills, with experience coaching analysts at multiple levels and delivering structured learning activities such as tabletop exercises.
A proactive, improvement-focused mindset — comfortable analysing incident metrics, identifying gaps, and taking ownership of making things better.