hackajob is partnering with Barclays to fill this position. Create a profile to be automatically considered for this role—and others that match your experience.
Join us as a DFIR Lead Cyber Operations Analyst, at Barclays, we don’t just adapt to the future, we create it. As a Lead Cyber Operations Analyst you will support the organisation, achieve its strategic objectives by the identification of business requirements and solutions that address business problems and opportunities.
To be a successful DFIR Lead Cyber Operations Analyst, you should have experience with:
Forensic techniques applied to incident response: practical experience applying forensic techniques across common enterprise data sources (files, operating systems, network traffic, and applications) to support incident investigation and troubleshooting.
Expert log and artefact analysis (multi‑source): ability to collect, examine, and analyse data from multiple sources (e.g., logs, artefacts, indicators of compromise) and perform pivoted analysis across aggregated logs and digital forensic data to define and contextualise incident scope.
Advanced incident investigation and response capability: proven ability to analyse and respond to high‑priority security incidents, including timely escalation and driving incidents to closure.
Technical depth across OS and networking: strong working knowledge of operating system fundamentals and security concepts, plus networking principles sufficient to interpret incident artefacts and investigative hypotheses.
Coaching / guidance of junior analysts: capability to provide guidance and support to T1/T2 analysts on escalated events requiring subject matter expertise.
Desirable skills/Preferred Qualifications:
Security control breadth: familiarity with security tools and controls that generate incident telemetry (e.g., network and endpoint security controls) and the ability to interpret artefacts generated by those controls during investigations.
Development of work instructions / repeatable methods: experience contributing to, reviewing, or improving work instructions to ensure repeatable, auditable incident handling activities.
Cloud security principles (AWS/Azure/GCP): understanding of cloud security principles and the ability to incorporate relevant cloud artefacts/logs into incident investigations where applicable.
Open‑source investigation tooling / OSINT awareness: familiarity with open‑source network analysis and intelligence tools to support enrichment and investigative context.
Intelligence‑driven defence / kill‑chain awareness: understanding of adversary behaviour and intelligence‑driven defence concepts to support hypothesis‑driven investigation and prioritisation.
You may be assessed on key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking and digital and technology, as well as job-specific technical skills.
This role is based in Pune.
Purpose of the role
To monitor the performance of operational controls, implement and manage security controls and consider lessons learnt in order to protect the bank from potential cyber-attacks and respond to threats.
Accountabilities
Vice President Expectations
All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.
hackajob is partnering with Barclays to fill this position. Create a profile to be automatically considered for this role—and others that match your experience.
Level up the hackajob way. Verify your skills, learn brand new ones and test your ability with Pathways, our learning and development platform.