S

Senior Manager - Information Security

S&P Global · Hyderabad, Telangana

10–18 yrs experiencePosted 1w ago

Job description

About the Role: Grade Level (for internal use): 11S&P Global CorporateThe Role: Senior Manager, Information Security The Team: You will be a Cyber Security Detection Engineer in S&P Global’s Cyber Fusion Center within the Information Security department. You will play a pivotal role in safeguarding the organization’s digital assets. You will design, implement, and optimize detection rules and analytics to identify and mitigate cyber threats across our multi-cloud and hybrid environments. You will work closely with global teams to ensure our detection capabilities are robust, scalable, and aligned with industry best practices.The Impact: You will collaborate with cross-functional teams to enhance our cybersecurity posture, develop strategic plans, and drive continuous improvement in threat detection and incident response capabilities.What’s in it for you: • Opportunity to work on a wide & industry leading Cyber technology stack. • Immense opportunity to learn new technologies & gain new skill set. • Work with a leading brand & attractive benefit.  Responsibilities: • Develop, tune, and maintain detection rules and analytics within Google SecOps (Chronicle Security Operations), using YARA-L and other relevant tools, specifically tailored to S&P Global’s environment. • Strong expertise in log analysis and threat hunting with Google BigQuery.Solid understanding of cloud security concepts across AWS, Azure and GCP environments. • Conduct proactive threat hunting and log analysis across global infrastructure including cloud (AWS, Azure, GCP) • Integrate actionable threat intelligence into detection logic, collaborating closely with Threat Intelligence, Incident Response, and SOC teams to optimize detection and response workflows. • Demonstrate strong analytical and problem-solving skills to identify and mitigate threats in large-scale enterprise environments. • Communicate effectively and document clearly, especially for detection playbooks and security operations. • Stay up-to-date with the latest security threats, vulnerabilities, and attack techniques relevant to the financial sector. • Support compliance initiatives and reporting (e.g., SOX, GDPR) by providing detection-related evidence and metrics from SIEM, Data lake platforms. • Participate in the evaluation and deployment of new security technologies and products within the security ecosystem. • Proficiency in using Cribl for data stream management, log routing, filtering, enrichment, and optimization to enhance security analytics and improve detection capabilities within large-scale cloud and hybrid environments. • Work collaboratively with global teams to continuously improve S&P Global’s cyber defense capabilities. • Automate detection and response processes using scripting languages (Python, PowerShell, Google Cloud Functions) and orchestration tools. • Maintain and update documentation, detection playbooks, and knowledge bases, with a focus on Cloud security operations and best practices. • Solid understanding of cyber security governance frameworks (e.g., NIST, ISO/IEC 27001, CIS Controls). • Experience in implementing and maintaining security policies, standards, and procedures. • Ability to assess and ensure compliance with regulatory requirements (e.g., SOX, GDPR) relevant to the financial sector. • Proficiency in documenting and reporting security controls, risk assessments, and audit findings. • Familiarity with conducting gap analyses to identify and remediate compliance deficiencies. • Strong knowledge of risk management principles and their application in enterprise environments. • Experience collaborating with internal audit, risk, and compliance teams to support security initiatives. • Ability to translate technical security requirements into clear, actionable policies and guidelines. • Up-to-date awareness of emerging regulations, industry standards, and best practices in cyber security governance and compliance.  What We’re Looking For: • Minimum 7 years of experience in cyber security detection engineering and/or SOC operations. • Strong understanding of cloud security (AWS, Azure, GCP) and hybrid environments. • Proficiency in log analysis, threat hunting, and incident response. • Broad knowledge of Active Directory, Microsoft S