Purpose of the role
To monitor the performance of operational controls, implement and manage security controls and consider lessons learnt in order to protect the bank from potential cyber-attacks and respond to threats.
Accountabilities
Vice President Expectations
All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.
Join us as a DFIR Lead Cyber Operations Analyst, at Barclays, we don’t just adapt to the future, we create it. As a Lead Cyber Operations Analyst you will support the organisation, achieve its strategic objectives by the identification of business requirements and solutions that address business problems and opportunities.
To be a successful DFIR Lead Cyber Operations Analyst, you should have experience with:
Forensic techniques applied to incident response: practical experience applying forensic techniques across common enterprise data sources (files, operating systems, network traffic, and applications) to support incident investigation and troubleshooting.
Expert log and artefact analysis (multi‑source): ability to collect, examine, and analyse data from multiple sources (e.g., logs, artefacts, indicators of compromise) and perform pivoted analysis across aggregated logs and digital forensic data to define and contextualise incident scope.
Advanced incident investigation and response capability: proven ability to analyse and respond to high‑priority security incidents, including timely escalation and driving incidents to closure.
Technical depth across OS and networking: strong working knowledge of operating system fundamentals and security concepts, plus networking principles sufficient to interpret incident artefacts and investigative hypotheses.
Coaching / guidance of junior analysts: capability to provide guidance and support to T1/T2 analysts on escalated events requiring subject matter expertise.
Desirable skills/Preferred Qualifications:
Security control breadth: familiarity with security tools and controls that generate incident telemetry (e.g., network and endpoint security controls) and the ability to interpret artefacts generated by those controls during investigations.
Development of work instructions / repeatable methods: experience contributing to, reviewing, or improving work instructions to ensure repeatable, auditable incident handling activities.
Cloud security principles (AWS/Azure/GCP): understanding of cloud security principles and the ability to incorporate relevant cloud artefacts/logs into incident investigations where applicable.
Open‑source investigation tooling / OSINT awareness: familiarity with open‑source network analysis and intelligence tools to support enrichment and investigative context.
Intelligence‑driven defence / kill‑chain awareness: understanding of adversary behaviour and intelligence‑driven defence concepts to support hypothesis‑driven investigation and prioritisation.
You may be assessed on key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking and digital and technology, as well as job-specific technical skills.
This role is based in Pune.

Barclays is a British universal bank. Our vision is to be the UK-centred leader in global finance. We are a diversified bank with comprehensive UK consumer, corporate and wealth and private banking franchises, a leading investment bank and a strong, specialist US consumer bank. Through these five divisions, we are working together for a better financial future for our customers, clients and communities.
With over 325 years of history and expertise in banking, Barclays operates in over 40 countries and employs approximately 83,500 people. Barclays moves, lends, invests and protects money for customers and clients worldwide.
Barclays is a trading name of Barclays Bank PLC and its subsidiaries. Barclays Bank PLC is registered in England and is authorised by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and the Prudential Regulation Authority. Registered in England. Registered No. 1026167. Registered office: 1 Churchill Place, London E14 5HP.