
DFIR Lead Cyber Operations Analyst
Job Description
Job Description
Purpose of the role
To monitor the performance of operational controls, implement and manage security controls and consider lessons learnt in order to protect the bank from potential cyber-attacks and respond to threats.
Accountabilities
- Management of security monitoring systems, including intrusive prevention and detection systems, to alert, detect and block potential cyber security incidents, and provide a prompt response to restore normal operations with minimised system damage.
- Identification of emerging cyber security threats, attack techniques and technologies to detect/prevent incidents, and collaborate with networks and conferences to gain industry knowledge and expertise.
- Management and analysis of security information and event management systems to collect, correlate and analyse security logs, events and alerts/potential threats.
- Triage of data loss prevention alerts to identify and prevent sensitive data for being exfiltrated from the banks network.
- Management of cyber security incidents including remediation & driving to closure.
Vice President Expectations
- To contribute or set strategy, drive requirements and make recommendations for change. Plan resources, budgets, and policies; manage and maintain policies/ processes; deliver continuous improvements and escalate breaches of policies/procedures..
- If managing a team, they define jobs and responsibilities, planning for the department’s future needs and operations, counselling employees on performance and contributing to employee pay decisions/changes. They may also lead a number of specialists to influence the operations of a department, in alignment with strategic as well as tactical priorities, while balancing short and long term goals and ensuring that budgets and schedules meet corporate requirements..
- If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L – Listen and be authentic, E – Energise and inspire, A – Align across the enterprise, D – Develop others..
- OR for an individual contributor, they will be a subject matter expert within own discipline and will guide technical direction. They will lead collaborative, multi-year assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions..
- Advise key stakeholders, including functional leadership teams and senior management on functional and cross functional areas of impact and alignment.
- Manage and mitigate risks through assessment, in support of the control and governance agenda.
- Demonstrate leadership and accountability for managing risk and strengthening controls in relation to the work your team does.
- Demonstrate comprehensive understanding of the organisation functions to contribute to achieving the goals of the business.
- Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategies.
- Create solutions based on sophisticated analytical thought comparing and selecting complex alternatives. In-depth analysis with interpretative thinking will be required to define problems and develop innovative solutions.
- Adopt and include the outcomes of extensive research in problem solving processes.
- Seek out, build and maintain trusting relationships and partnerships with internal and external stakeholders in order to accomplish key business objectives, using influencing and negotiating skills to achieve outcomes.
All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.
Join us as a DFIR Lead Cyber Operations Analyst, at Barclays, we don’t just adapt to the future, we create it. As a Lead Cyber Operations Analyst you will support the organisation, achieve its strategic objectives by the identification of business requirements and solutions that address business problems and opportunities.
To be a successful DFIR Lead Cyber Operations Analyst, you should have experience with:
Forensic techniques applied to incident response: practical experience applying forensic techniques across common enterprise data sources (files, operating systems, network traffic, and applications) to support incident investigation and troubleshooting.
Expert log and artefact analysis (multi‑source): ability to collect, examine, and analyse data from multiple sources (e.g., logs, artefacts, indicators of compromise) and perform pivoted analysis across aggregated logs and digital forensic data to define and contextualise incident scope.
Advanced incident investigation and response capability: proven ability to analyse and respond to high‑priority security incidents, including timely escalation and driving incidents to closure.
Technical depth across OS and networking: strong working knowledge of operating system fundamentals and security concepts, plus networking principles sufficient to interpret incident artefacts and investigative hypotheses.
Coaching / guidance of junior analysts: capability to provide guidance and support to T1/T2 analysts on escalated events requiring subject matter expertise.
Desirable skills/Preferred Qualifications:
Security control breadth: familiarity with security tools and controls that generate incident telemetry (e.g., network and endpoint security controls) and the ability to interpret artefacts generated by those controls during investigations.
Development of work instructions / repeatable methods: experience contributing to, reviewing, or improving work instructions to ensure repeatable, auditable incident handling activities.
Cloud security principles (AWS/Azure/GCP): understanding of cloud security principles and the ability to incorporate relevant cloud artefacts/logs into incident investigations where applicable.
Open‑source investigation tooling / OSINT awareness: familiarity with open‑source network analysis and intelligence tools to support enrichment and investigative context.
Intelligence‑driven defence / kill‑chain awareness: understanding of adversary behaviour and intelligence‑driven defence concepts to support hypothesis‑driven investigation and prioritisation.
You may be assessed on key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking and digital and technology, as well as job-specific technical skills.
This role is based in Pune.