AVP - Security Operations (SOC) - Global Information Security
Jefferies · Pune, India · 9h ago
Innovation Hub Overview
Jefferies is creating a Technology Innovation Hub in Pune, a greenfield opportunity to build the systems that power global markets. As our first India technology center, this hub brings together hands on builders who engineer the platforms behind Jefferies’ growth across capital markets, investment banking, and institutional securities. We’re scaling toward an elite team of 500 engineers while maintaining the agility, ownership, and meritocratic spirit that defines Jefferies. From cloud and data to AI, risk, and core business technologies, teams in Pune will lead high impact work with a global mandate.
IT Security Technology
Jefferies’ IT Security Technology / Global Information Security (GIS) team protects the firm’s critical systems, sensitive information, and global operations against evolving cyber threats. GIS partners with Technology, Operations, Corporate functions, and the Business to embed security into day-to-day operations while supporting productivity, regulatory compliance, and operational resilience. GIS balances strong controls with efficiency and operates globally across the US, EMEA, and APAC to provide round-the-clock coverage.
Role Overview
Jefferies is seeking a motivated, analytical, and technically proficient Senior Security Operations Analyst to join our Global Security Operations Centre in Pune, India. The ideal candidate will have strong hands-on experience in cybersecurity operations, incident response, enterprise security monitoring, networking, cloud technologies, and security frameworks such as NIST and MITRE ATT&CK.
This role requires an experienced security professional who can monitor, detect, investigate, and respond to security events across a global enterprise environment. The candidate should be comfortable working in a fast-paced, high-pressure environment and collaborating with global technology, infrastructure, application, and security teams.
Key Responsibilities
- Monitor, detect, investigate, and respond to security events and incidents across Jefferies’ global infrastructure.
- Perform in-depth analysis of security alerts from multiple security platforms to determine scope, impact, severity, and root cause.
- Manage and respond to cybersecurity incidents, ensuring timely escalation, containment, remediation support, and thorough documentation.
- Utilize Endpoint Detection and Response tools such as CrowdStrike and Microsoft Defender to investigate endpoint-level threats and suspicious activities.
- Leverage SIEM technologies, particularly Splunk, for security monitoring, log correlation, threat hunting, alert analysis, and detection rule development.
- Investigate and respond to phishing, malicious emails, and other email-based security threats using email security solutions such as Proofpoint.
- Monitor Data Loss Prevention / Data Leak Protection tools and investigate potential unauthorized data exfiltration events.
- Conduct proactive threat hunting activities using the MITRE ATT&CK framework to identify adversary tactics, techniques, and procedures within the environment.
- Collaborate with IT, infrastructure, network, application, and global security teams to investigate security events and support remediation activities.
- Participate in security assessments, vulnerability assessments, and penetration testing activities to help identify and mitigate security risks.
- Contribute to the development, enhancement, and maintenance of SOC playbooks, runbooks, standard operating procedures, and knowledge documentation.
- Review firewall and network security policy requests, providing security analysis, recommendations, and risk-based guidance.
- Support and mentor junior SOC Analysts, promoting a culture of continuous learning, operational excellence, and knowledge sharing.
- Act as a senior escalation point during shift operations, assisting with incident triage, analyst workload coordination, and operational decision-making when delegated by SOC leadership.
- Maintain a high level of confidentiality, integrity, and professionalism while handling sensitive security information.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Minimum of 6 years of experience in cybersecurity operations, security monitoring, incident response, or SOC functions.
- Prior experience in a financial services or large enterprise environment is preferred.
- Strong understanding of cybersecurity principles, attack vectors, threat landscapes, and incident response methodologies.
- Solid knowledge of networking concepts, protocols, firewalls, proxies, DNS, VPN, and network security controls.
- Hands-on experience with enterprise security tools and technologies, including:
- SIEM platforms, preferably Splunk
- EDR tools such as CrowdStrike and Microsoft Defender
- Email security solutions such as Proofpoint
- DLP technologies and data protection controls
- Firewalls and network security platforms
- Experience with cloud platforms such as AWS and Microsoft Azure.
- Familiarity with security frameworks such as NIST, MITRE ATT&CK, and industry best practices.
- Strong analytical and problem-solving skills with the ability to think critically during high-pressure incidents.
- Ability to work independently, prioritize effectively, and make sound decisions under pressure.
- Strong communication skills with the ability to clearly convey technical security findings to both technical and non-technical stakeholders.
- Familiarity with securing and responsibly using AI technologies is preferred.
- High level of integrity, professionalism, and confidentiality.
#LI-SK1