Analyst - Security Operations (SOC) - Global Information Security
Jefferies · Pune, India · 1d ago
Innovation Hub Overview
Jefferies is creating a Technology Innovation Hub in Pune, a greenfield opportunity to build the systems that power global markets. As our first India technology center, this hub brings together hands on builders who engineer the platforms behind Jefferies’ growth across capital markets, investment banking, and institutional securities. We’re scaling toward an elite team of 500 engineers while maintaining the agility, ownership, and meritocratic spirit that defines Jefferies. From cloud and data to AI, risk, and core business technologies, teams in Pune will lead high impact work with a global mandate.
IT Security Technology
Jefferies’ IT Security Technology / Global Information Security (GIS) team protects the firm’s critical systems, sensitive information, and global operations against evolving cyber threats. GIS partners with Technology, Operations, Corporate functions, and the Business to embed security into day-to-day operations while supporting productivity, regulatory compliance, and operational resilience. GIS balances strong controls with efficiency and operates globally across the US, EMEA, and APAC to provide round-the-clock coverage.
Role Overview
Jefferies is seeking a Security Operations / SOC Analyst to support cyber defense and incident response activities for the firm. The role will be responsible for monitoring and analyzing security alerts across SIEM, EDR, network, cloud, and identity platforms; investigating high-severity security incidents; and supporting end-to-end incident response. The individual will also contribute to detection engineering, threat hunting, DLP monitoring, and continuous improvement of Jefferies’ security monitoring and response capabilities.
Key Responsibilities
- Monitor and analyze security alerts from SIEM, EDR, firewalls, IDS/IPS, cloud platforms, and identity systems.
- Conduct detailed investigations into high-severity security incidents, including phishing, malware, lateral movement, data exfiltration, and related threats.
- Lead end-to-end incident response activities, including containment, eradication, recovery, and post-incident documentation.
- Develop and fine-tune SIEM correlation rules, EDR detections, and alerting policies to reduce false positives and improve detection coverage.
- Execute proactive threat hunting using the MITRE ATT&CK framework and IOCs across endpoints, network, cloud, and identity logs.
- Monitor Data Leak Prevention / Data Loss Prevention (DLP) tools and recommend strategies to prevent unauthorized data exfiltration.
- Stay up to date with the latest cybersecurity trends, threats, tools, and technologies to continuously strengthen the firm’s security posture.
Qualifications
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
- Minimum 2+ years of experience in SOC, incident response, or a related cybersecurity operations role, preferably within financial services.
- Proficiency in query languages and log analysis tools such as KQL, SPL, or similar for threat hunting and investigations.
- Strong understanding of the MITRE ATT&CK framework, cyber kill chain, and common attack techniques, including phishing, credential theft, lateral movement, and data exfiltration.
- Hands-on incident response experience, including evidence collection, investigation documentation, and stakeholder communication.
- Strong analytical and problem-solving skills, with the ability to communicate technical findings clearly to non-technical stakeholders.
- Relevant certifications such as GCIH, GCIA, CEH, OSCP, or equivalent are preferred.
- Prior experience working in financial services is a plus.
#LI-SK1