Senior Security Engineer
GLG · Gurgaon
- Experience5–6 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted29 Sept 2026
About GLG
GLG is hiring in Gurgaon in professional services. This role looks for around 5+ years of experience.
Skills
- SIEM
- Endpoint Detection and Response
- Email Security
- Identity and Access Management
- Incident Response
- Threat Detection
- Security Operations
- DLP
- Vulnerability Scanning
- CloudTrail
- GuardDuty
- Azure Activity Logs
- Defender for Cloud
- Windows
- Linux
- SPF
- DKIM
- DMARC
The role
A security engineer at a professional services marketplace designs threat detection and incident response operations, applying SIEM and endpoint detection and response to investigate and resolve security events. The role also manages identity and access management and vulnerability management, with security platform operations supporting resilient protection across cloud and on-premises environments.
Full job description
About The Role
Working hours: Aligned to US Eastern business hours (approximately 09:00 to 18:00 ET), Monday to Friday.
We are looking to hire a Senior Security Engineer to own GLG's threat detection and incident response capability during US business hours. This is a senior individual contributor role, reporting to Nick Franzi. The successful candidate will be the firm's primary subject matter expert for detection engineering, security operations, and incident response: responsible for ensuring threats are identified early, investigated thoroughly, and resolved with durable outcomes.
This individual will build and maintain the systems, processes, and playbooks that underpin GLG's operational security posture. They will work closely with IT, engineering, legal, and business teams across the firm, as well as dedicated platform SMEs within the Information Security team, and will serve as the primary point of escalation for active security events during US business hours.
What You'll Do
Threat detection and incident response
Operate and contribute to the improvement of GLG's detection capability across SIEM, EDR, and email security platforms during US business hours: working with platform SMEs to tune detection logic, surface threats early, and maintain high signal fidelity. Lead incident response end to end within US operational coverage: scope, contain, eradicate, and document. Produce post-incident reviews that drive lasting remediation. Author and maintain response playbooks that enable consistent, decisive action across incident scenarios, coordinating handoffs with global team members where applicable. Serve as the firm's primary US-hours escalation point for active security events.
Vulnerability and exposure management
Execute vulnerability scanning across endpoints, servers, and cloud assets; apply risk-based prioritization and drive remediation with US-based and global asset owners to defined SLAs. Track and report on the firm's exposure posture over time, translating technical findings into actionable reporting for leadership. Contribute to the firm's external attack surface management program. Serve as the security reviewer for new services, platforms, and major changes: assess designs, model threats, identify the handful of issues that actually matter, and negotiate practical mitigations with engineering teams.
Identity threat monitoring
Monitor identity-layer telemetry during US business hours for threats, anomalies, and policy violations: with particular focus on account compromise and insider risk scenarios. Support access reviews, MFA enforcement operations, and anomalous access investigation across the US user base and beyond.
Security platform operations
Serve as a day-to-day operator across core security platforms — EDR, SIEM, email security, and DLP tooling — working alongside platform SMEs to ensure consistent operational effectiveness. Contribute to automation efforts that reduce manual effort and improve response consistency, particularly to extend effective coverage beyond US business hours. Support the firm's ISO 27001 program through evidence collection, control testing, and audit readiness activities. Improve logging, detection coverage, and alerting for cloud/on-prem activity and resources (Palo Alto, Windows, Linux, CloudTrail, GuardDuty, Azure Activity Logs, Defender for Cloud, etc)
Required
What we're looking for:
5+ years in security engineering or security operations, with demonstrated ownership of detection, response, and tooling: not just participation. Hands-on SIEM experience: writing detection logic, tuning alert rules, and building investigation workflows. Experience with EDR platforms and a strong understanding of endpoint-based threat detection and response. Working knowledge of email-based threats: phishing, BEC, and the authentication controls (SPF, DKIM, DMARC) that govern them. Solid understanding of identity and access management; experience investigating identity-layer threats. Ability to communicate risk and technical findings clearly to both engineering peers and non-technical stakeholders, including senior leadership. Sound judgment under pressure: able to make defensible decisions in ambiguous situations and drive them to resolution.
Nice to have
Experience with vulnerability management platforms and risk-based prioritization frameworks. Familiarity with ISO 27001 or similar compliance and audit frameworks. Scripting or automation experience (Python, PowerShell, etc.) applied to security operations workflows. Relevant certifications (CySA+, CISSP, CISM) are a plus but not required.
About GLG / Gerson Lehrman Group
GLG is the world’s leading platform for trusted human expertise. We connect global decision-makers—from hedge fund managers and private equity partners to strategy leaders at Fortune 500s—with the specific, authoritative voices required to answer their most critical questions.
At GLG, you are an extension of our clients' core teams. You will work at the intersection of industries and global markets, navigating high-stakes challenges across the full spectrum of their strategic initiatives. Operating within the industry’s most trusted research environment, you’ll help our clients capture the nuanced perspectives that drive smarter, faster business outcomes.
We are a global team of pragmatic problem-solvers who mirror the intensity of the markets we serve. If you are driven by intellectual curiosity and a bias toward action, join us in reinventing the industry we invented.
Gerson Lehrman Group, Inc. (“GLG”) is an equal opportunity employer and will not discriminate against any employee or applicant on the basis of age, race, religion, color, marital status, disability, gender, national origin, sexual orientation, veteran status, or any classification protected by federal, state, or local law.