18 Aug
|
Brevan Howard
|
Bengaluru
18 Aug
Brevan Howard
Bengaluru
The Firm:
Brevan Howard Asset Management is one of the leading absolute return/hedge fund managers, overseeing assets on behalf of institutional investors from around the world, including pension funds, endowments, insurance companies, government agencies, private banks, and fund of funds.
Brevan Howard was founded in 2002 and launched its flagship global macro strategy in April 2003. The firm currently manages over $34bn and engages predominantly in discretionary directional and relative value trading in fixed income, FX markets, and equities. BH Digital, a division within Brevan Howard that manages crypto and digital asset strategies was launched in 2022.
The firm currently employs over 1,000 personnel worldwide, including over 400 investment professionals. This global presence gives Brevan Howard the ability to identify and source attractive investment opportunities, as well as investment management talent wherever they may be. Brevan Howard has won several industry awards for excellence in risk management, operational robustness, and investment performance.
The firm’s main hubs are in London, Jersey, Geneva, New York, Austin, Hong Kong, Singapore, Abu Dhabi and Bengaluru.
The Department:
The Information Security Team is responsible for protecting the company’s infrastructure, intellectual property and digital assets. The team has a broad scope of responsibilities and tackles projects in different security verticals (IAM, GRC, Cloud Security, Application Security, Detection and Response, etc.)
The Security Operations capabilities will be continuously improved so there is a requirement to build new and improve existing capabilities, not just operate and run the existing tools, processes and services.
Essential Responsibilities:
The Security Operations Senior Engineer is a senior in-house position within Brevan Howard’s hybrid SOC, accountable for the end-to-end management of security incidents, proactive threat hunting, and the ongoing maturity of the firm’s Security Operations Programme. Operating across SIEM, SOAR, EDR, and cloud environments, the engineer is expected to bring both analytical depth and technical breadth — including cloud security (AWS/GCP), scripting, and IaC tooling — to a high-trust, low-latency trading environment.
The role focuses on independent, high-judgement investigation of escalated threats across endpoint, cloud, and identity attack surfaces. They are expected to operate with a high degree of autonomy, own escalated cases, and contribute directly to improving the organisation’s detection and response capabilities in a demanding, high-performance, low-latency regulated financial environment. Where an MSP or more junior SOC analyst is involved, they must collaborate effectively and provide appropriate feedback for improvement.
- Lead triage, investigation, and response for incidents across trading infrastructure, endpoints, cloud environments (AWS/GCP), and identity platforms
- Own complex incident response end-to-end: scoping, containment, forensic analysis, eradication, recovery, and post-incident review
- Perform advanced threat analysis and multi-source correlation across SIEM, EDR, SOAR, and cloud telemetry to identify sophisticated attack patterns
- Design, build, and continuously tune detection rules, use cases, and SOAR playbooks; manage rule lifecycle via version-controlled repositories (GitHub/Terraform)
- Own and drive vulnerability management programme outcomes, including prioritisation, remediation tracking, and integration with threat intelligence
- Author and maintain advanced incident response playbooks, threat models, and response procedures; lead tabletop exercises where required
- Conduct deep-dive log analysis and forensic investigation across endpoint, cloud (AWS/GCP), application, and network telemetry
- Lead proactive threat hunting initiatives using hypothesis-driven methodologies, leveraging EDR, SIEM, and threat intelligence feeds
- Produce high-quality incident reports, executive-level summaries, and lessons-learned documentation suitable for senior stakeholders
- Develop, maintain, operate and manage relevant security services and tools
WORK EXPERIENCE/BACKGROUND:
Essential
- Proven hands-on experience with SIEM platforms (e.g. Splunk, Sentinel, Exabeam) including query development, dashboarding, and alert tuning
- Detection engineering experience: authoring, testing, and lifecycle management of detection logic across SIEM and EDR platforms
- Experience detecting and investigating insider threats, abnormal user behaviour, and identity-based attacks using UEBA and related tooling
- Significant experience owning escalated security incident response end-to-end: triage, scoping, containment, forensic analysis, eradication, recovery, and post-incident review
- Background in an in-house SOC or dedicated incident response function at Tier 2 or above; experience on the client side rather than MSSP preferred
Desirable
- Background in financial services, trading firms, or other high-value, low-latency data environments
- Experience with data loss prevention (DLP), information protection controls, and insider risk programmes
- Experience working in small, high-trust security teams
- Led or contributed to structured threat hunting programmes using hypothesis-driven or TTP-based methodologies (e.g. MITRE ATT&CK;)
TECHNICAL/BUSINESS SKILLS & KNOWLEDGE:
Essential
- Strong scripting and automation capability (Python, PowerShell) for rapid response, tooling development,
and workflow automation via SOAR
- Deep alert investigation and incident response capability; comfortable leading multi-stream investigations autonomously
- Advanced EDR proficiency (e.g. CrowdStrike Falcon, SentinelOne, Defender for Endpoint) including policy management, telemetry analysis, and response actions
- Strong understanding of Windows internals, Entra ID, and enterprise security architecture including AD, Group Policy, and identity attack paths
- Solid grounding in endpoint and identity-focused security: EDR, IAM, MFA, PAM, and privileged access controls
- Hands-on cloud security experience across AWS and/or GCP: understanding of cloud-native logging, IAM, security services (e.g. GuardDuty, Security Command Center), and attack patterns specific to cloud workloads
- Working knowledge of network security fundamentals; ability to analyse packet captures, NetFlow, and proxy logs as part of broader investigations
- Practical experience consuming and applying threat intelligence (STIX/TAXII, TIPs, OSINT) to enrich investigations and inform detection logic
- Hands-on experience with vulnerability management solutions (e.g. Tenable, Qualys, Rapid7); able to own prioritisation, remediation tracking, and risk reporting
Desirable
- Experience building and operating SOAR playbooks and automation workflows (e.g. Palo Alto XSOAR, Splunk SOAR, Tines)
- CSPM experience (e.g. Wiz, Prisma Cloud, AWS Security Hub) including misconfiguration detection and cloud posture remediation
- Experience integrating vulnerability management data into SIEM or SOAR workflows for automated prioritisation and remediation tracking
- Familiarity with offensive security techniques and penetration testing outputs; able to contextualise findings and drive remediation prioritisation
- Exposure to Red/Purple Team activity and structured adversary emulation exercises
- Experience with infrastructure-as-code and version control tooling (Terraform, GitHub) to manage and deploy security configurations at scale
KEY COMPETENCIES:
Essential
- High signal-to-noise judgement; able to rapidly prioritise and contextualise alerts without over-escalating or under-triaging
- High degree of discretion and data sensitivity awareness, commensurate with operating in a regulated financial services environment
- Clear, concise communication under pressure; able to produce executive-level incident summaries as well as technical deep-dives for engineering peers
- Pragmatic, risk-based approach to security decision-making; understands the trade-offs between security posture and business continuity in a trading workplace
- Comfortable operating autonomously on escalated cases with minimal process overhead; self-directing and outcome-focused
- Strong collaborative instinct; willing to mentor junior analysts and contribute to broader team capability, whilst maintaining individual delivery at senior level
📌 Security Operations Engineer (Bengaluru)
🏢 Brevan Howard
📍 Bengaluru