Engineering Division - Global Cyber Defense & Intel - Vice President - Bengaluru
Goldman Sachs
Goldman Sachs
Join our Global Cyber Defense & Intel team as a Security Engineer in Bengaluru. You'll enhance cyber threat awareness by developing security sensors and data sets, working closely with a technical team.
This role requires hands-on expertise in Windows, Linux, and network security, alongside practical experience in using security information for detection engineering, live intrusion analysis, and real-time security event triage.
You will investigate cyber events and incidents, remediating security gaps with cutting-edge tools. Opportunities exist to automate incident response workflows, boosting our overall effectiveness.
Drive a world-class cyber defense program by collaborating with technical and forensic teams to understand threat actor objectives and activities.
Innovate and design cutting-edge threat and security incident management solutions.
Coordinate and triage cybersecurity events, conducting thorough forensic analysis.
Analyze infrastructure security incidents to confirm breaches and perform detailed host-based and network forensic investigations.
Participate in a 24x7 global coverage model to protect Goldman Sachs’ network.
Enhance security sensor efficiency by tuning controls to adapt to evolving threats.
Lead assigned security projects, taking ownership from planning to implementation and coordination.
Develop use cases based on adversarial tactics, techniques, and procedures (TTPs), and optimize detection rules for improved efficacy.
Possess strong verbal and written communication skills, effectively conveying complex technical concepts to diverse audiences.
Demonstrate robust analytical and problem-solving abilities in proactively addressing security challenges and coordinating incident response.
Show a comprehensive understanding of security frameworks like MITRE ATT&CK and NIST, coupled with expertise in threat intelligence, automation, and SIEM platforms (Splunk, Elastic, BQL).
Exhibit a strong sense of ownership for task completion, managing daily operations and ensuring effective threat detection and mitigation.
Be proficient in scripting languages, particularly advanced skills in Python and PowerShell for detection queries and automation.
Hold relevant industry certifications such as GNFA, GCFE, GCFA, CCFP, CFCE, ACE, OSCP, or GCFR.
Preferred qualifications include over 7 years of cybersecurity experience, with at least 3 years focused on detection engineering and incident response, experience managing SOC activities, and knowledge of cloud security (AWS, Google, Azure).
Goldman Sachs
IT Consulting