
Security Operation Analyst-SIEM
- Guangzhou, Guangdong
- Permanent
- Full-time
SOC Operations:
- Monitor and analyze security alerts from financial systems, applications, and infrastructure using SIEM and other security tools. This role would need to on call.
- Investigate and respond to security incidents, ensuring minimal impact to financial operations and customer data.
- Perform threat analyse and anomaly detection using financial threat intelligence and behavioral analytics.
- Maintain and enhance incident response playbooks tailored to financial threats (e.g., fraud, insider threats, phishing).
- Develop and maintain automation scripts and tools to streamline SOC workflows (Python, PowerShell, etc.).
- Engineer integrations between security platforms (SIEM, SOAR, EDR) and financial systems (e.g., core banking, payment gateways).
- Build dashboards and reporting tools for compliance, audit, and executive visibility.
- Collaborate with IT and DevOps to implement secure configurations and CI/CD pipelines.
- Work closely with threat intelligence, fraud detection, red team, and compliance teams.
- Correlate financial threat intelligence with internal telemetry to identify emerging risks.
- Support proactive defense strategies for financial services.
- Participate in purple team exercises and post-incident reviews.
- Display exemplary conduct and live by the Group's Values and Code of Conduct.
- Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across Standard Chartered Bank. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct.
- Effectively and collaboratively identify, escalate, mitigate and resolve risk, conduct and compliance matters.
- [Fill in for regulated roles]
- Lead the team to achieve the outcomes set out in the Bank's Conduct Principles: [Fair Outcomes for Clients; Effective Financial Markets; Financial Crime Compliance; The Right Environment.] *
- [Insert local regulator e.g. PRA/FCA prescribed responsibilities and Rationale for allocation].
- Serve as a Director of the Board of [insert name of entities]
- Exercise authorities delegated by the Board of Directors and act in accordance with Articles of Association (or equivalent)
Embed Here for good and Group's brand and values in XXXX [country / business unit / team]; Perform other responsibilities assigned under Group, Country, Business or Functional policies and procedures; Multiple functions (double hats); [List all responsibilities associated with the role]Skills and Experience
- Certifications: CEH, GCIA, GCIH, CISSP, or equivalent.
- Experience with fraud detection systems and secure payment technologies.
- Knowledge of financial network protocols, transaction systems, and secure APIs.
- Ability to work in a high-pressure, compliance-driven environment
- SOC Operations
- Engineering & Automation:
- Cyber Fusion Centre Collaboration
- Bachelor's degree in computer science, Cybersecurity, Engineering, or related field.
- 3+ years of experience in SOC or cybersecurity operations, preferably in financial services.
- Strong scripting and automation skills (Python, Bash, PowerShell).
- Experience with SIEM platforms (e.g., Splunk, QRadar, Sentinel) and SOAR tools.
- Familiarity with financial regulations (e.g., PCI-DSS, MAS TRM).
- Understanding of MITRE ATT&CK framework and financial threat intelligence.
- Do the right thing and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do
- Never settle, continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well
- Are better together, we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term
- Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations.
- Time-off including annual leave, parental/maternity (20 weeks), sabbatical (12 months maximum) and volunteering leave (3 days), along with minimum global standards for annual and public holiday, which is combined to 30 days minimum.
- Flexible working options based around home and office locations, with flexible working patterns.
- Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits
- A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning.
- Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.