At FNZ, our purpose is to make wealth management more accessible, bringing easier, fairer and more inclusive solutions to people worldwide. Here in the Global Cyber & Information Security team, we are on a mission to embed cyber resilience across FNZ, protecting the platforms that support investment solutions for over 20 million people.
FNZ security technology and operations is seeking an experienced threat detection and automation specialist with a background in devops or cybersecurity to fill a newly created role. Candidates should have hands-on experience with automation tooling and demonstrable evidence of having streamlined manual processes, in particular using a Security Orchestration, Automation, and Response (SOAR) platform. Past experience within a threat detection or SIEM engineering team is required.
This is a technical, hands-on role whereby the successful candidate will be expected to create complex SOAR playbooks to automate existing tasks and create new opportunities to streamline workflows. The successful candidate will liaise closely with stakeholders across cybersecurity, gaining exposure to different areas work and leading on recent solutions. The role is vital to the success of a new project at FNZ, onboarding the latest technology in response to AI innovations and the latest external threat landscape.
Specific Role Responsibilities:
- Take a lead role in identifying automation opportunities and supporting the onboarding of new technology to meet the latest cyber threats faced by FNZ.
- Automate existing security operations processes using a SOAR platform.
- Onboard data from different enterprise sources into a new platform at FNZ.
- Work closely with stakeholders across security and technology functions to understand requirements for automating existing manual operations through platform integrations and playbooks.
- Parse data from API integrations between vulnerability, detection, and response tools.
- Be comfortable using an existing detection-as-code pipeline to deploy threat detection rules into the security monitoring environment as required.
- Prove the functioning of new threat detection rules through testing.
- Map threat actors tactics, techniques, and procedures (TTPs) to the FNZ control environment.
- Ensure indicators of compromise are triaged and prioritised in an automated fashion. Use multiple enrichment sources in a single platform.
- Collaborate closely with peers in the threat, detection, and vulnerability management team in increasing security monitoring coverage and driving down risk.
- Interface regularly with incident responders to improve the tooling and tune rulesets.
Experience required:
- Hands on experience of a SOAR platform and automating manual processes.
- Demonstrable knowledge of threat detection and security monitoring technologies including SIEM and EDR solutions.
- Demonstrable evidence of having worked with APIs to integrate technologies and then parse the ingested data for operational use.
- Past scripting experience in a cybersecurity environment.
- Evidence of past cooperation with senior stakeholders in identifying opportunities to improve processes.
- Past engagement with incident response teams.
- Knowledge of detection rule generation processes in the SIEM.
- Understanding of the current cyber threat landscape, including relevant threat groups, TTPs, and attack vectors of relevance to financial services.
- Particularly strong analytical and problem-solving skills, with a proactive approach to identifying and mitigating security risks.
- Experience of the MITRE ATT&CK; framework for improving detective and preventative controls.
📌 Security Automation Lead (Pune)
🏢 FNZ Group
📍 Pune
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.