{"id":121222,"date":"2026-09-29T15:13:38","date_gmt":"2026-09-29T19:13:38","guid":{"rendered":"https:\/\/glginsights.com\/?post_type=jobs&#038;p=121222"},"modified":"2026-09-30T19:02:47","modified_gmt":"2026-09-30T23:02:47","slug":"8008121003","status":"publish","type":"jobs","link":"https:\/\/glginsights.com\/ko\/job\/8008121003\/","title":{"rendered":"Senior Security Engineer"},"content":{"rendered":"<p><span style=\"text-decoration: underline;\"><strong><span data-contrast=\"none\">About the role:<\/span><\/strong><\/span><\/p>\n<p><strong><span data-contrast=\"auto\">Working hours:<\/span><\/strong><span data-contrast=\"auto\">&nbsp;Aligned to US Eastern business hours (approximately 09:00&nbsp;to 18:00 ET), Monday to Friday.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:140}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">We are looking to hire a&nbsp;Senior&nbsp;Security Engineer to own GLG&#8217;s threat detection and incident response capability during US business hours. This is a senior individual contributor role, reporting to&nbsp;Nick Franzi. The successful candidate will be the firm&#8217;s primary subject matter expert for detection engineering, security operations, and incident response:&nbsp;responsible for ensuring threats are&nbsp;identified&nbsp;early, investigated thoroughly, and resolved with durable outcomes.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:140}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">This individual will build and&nbsp;maintain&nbsp;the systems, processes, and playbooks that underpin GLG&#8217;s operational security posture. They will work closely with IT, engineering, legal, and business teams across the firm, as well as dedicated platform SMEs within the Information Security team, and will serve as the primary point of escalation for active security events during US business hours.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:140}\">&nbsp;<\/span><\/p>\n<p><span style=\"text-decoration: underline;\"><strong><span data-contrast=\"none\">What you&#8217;ll do:<\/span><\/strong><\/span><\/p>\n<p><strong><span data-contrast=\"none\">Threat detection and incident response<\/span><\/strong><span data-ccp-props=\"{&quot;335559738&quot;:220,&quot;335559739&quot;:90}\">&nbsp;<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Operate and contribute to the improvement of GLG&#8217;s detection capability across SIEM, EDR, and email security platforms during US business hours:&nbsp;working with platform SMEs to tune detection logic, surface threats early, and&nbsp;maintain&nbsp;high signal fidelity.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Lead incident response end to end within US operational coverage: scope,&nbsp;contain, eradicate, and document. Produce post-incident reviews that drive lasting remediation.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Author and&nbsp;maintain&nbsp;response playbooks that enable consistent, decisive action across incident scenarios, coordinating handoffs with global team members where applicable.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Serve as the firm&#8217;s primary US-hours escalation point for active security events.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<\/ul>\n<p><strong><span data-contrast=\"none\">Vulnerability and exposure management<\/span><\/strong><span data-ccp-props=\"{&quot;335559738&quot;:220,&quot;335559739&quot;:90}\">&nbsp;<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Execute vulnerability scanning across endpoints, servers, and cloud assets; apply risk-based prioritization and drive remediation with US-based and global asset owners to defined SLAs.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Track and report on the firm&#8217;s&nbsp;exposure&nbsp;posture over time, translating technical findings into actionable reporting for leadership.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Contribute to the firm&#8217;s external attack surface management program.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Serve as the security reviewer for new services, platforms, and major changes:&nbsp;assess designs, model threats, identify the handful of issues that actually matter, and negotiate practical mitigations with engineering teams.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<\/ul>\n<p><strong><span data-contrast=\"none\">Identity threat monitoring<\/span><\/strong><span data-ccp-props=\"{&quot;335559738&quot;:220,&quot;335559739&quot;:90}\">&nbsp;<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Monitor identity-layer telemetry during US business hours for threats, anomalies, and policy violations:&nbsp;with particular focus on account compromise and insider risk scenarios.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Support access reviews, MFA enforcement operations, and anomalous access investigation across the US user base and beyond.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<\/ul>\n<p><strong><span data-contrast=\"none\">Security platform operations<\/span><\/strong><span data-ccp-props=\"{&quot;335559738&quot;:220,&quot;335559739&quot;:90}\">&nbsp;<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Serve as a day-to-day operator across core security platforms \u2014 EDR, SIEM, email security, and DLP tooling \u2014 working alongside platform SMEs to ensure consistent operational effectiveness.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Contribute to automation efforts that reduce manual effort and improve response consistency, particularly to extend effective coverage beyond US business hours.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Support the firm&#8217;s ISO 27001 program through evidence collection, control testing, and audit readiness activities.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Improve logging, detection coverage, and alerting for cloud\/on-prem activity and resources (Palo Alto, Windows, Linux, CloudTrail, GuardDuty, Azure Activity Logs, Defender for Cloud, etc)<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<\/ul>\n<p><span style=\"text-decoration: underline;\"><strong><span data-contrast=\"none\">What we&#8217;re looking for:<\/span><\/strong><\/span><\/p>\n<p><strong><span data-contrast=\"none\">Required<\/span><\/strong><span data-ccp-props=\"{&quot;335559738&quot;:220,&quot;335559739&quot;:90}\">&nbsp;<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">5+ years in security engineering or security operations, with demonstrated ownership of detection, response, and tooling:&nbsp;not just participation.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Hands-on SIEM experience: writing detection logic, tuning alert rules, and building investigation workflows.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Experience with EDR platforms and a strong understanding of endpoint-based threat detection and response.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Working knowledge of email-based threats:&nbsp;phishing, BEC, and the authentication controls (SPF, DKIM, DMARC) that govern them.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Solid understanding of identity and access management; experience investigating identity-layer threats.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Ability to communicate risk and technical findings clearly to both engineering peers and non-technical stakeholders, including senior leadership.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Sound judgment under pressure:&nbsp;able to make defensible decisions in ambiguous situations and drive them to resolution.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<\/ul>\n<p><strong><span data-contrast=\"none\">Nice to have<\/span><\/strong><span data-ccp-props=\"{&quot;335559738&quot;:220,&quot;335559739&quot;:90}\">&nbsp;<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Experience with vulnerability management platforms and risk-based prioritization frameworks.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Familiarity with ISO 27001 or similar compliance and audit frameworks.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Scripting or automation experience (Python, PowerShell, etc.) applied to security operations workflows.<\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\">Relevant certifications (CySA+, CISSP, CISM) are a plus but not&nbsp;required.<br \/><\/span><span data-ccp-props=\"{&quot;335559739&quot;:60}\">&nbsp;<\/span><\/li>\n<\/ul>\n<div class=\"content-conclusion\">\n<p><strong>About GLG \/ Gerson Lehrman Group<\/strong><\/p>\n<\/p>\n<p>GLG is the world\u2019s leading platform for trusted human expertise. We connect global decision-makers\u2014from hedge fund managers and private equity partners to strategy leaders at Fortune 500s\u2014with the specific, authoritative voices required to answer their most critical questions.<\/p>\n<p>At GLG, you are an extension of our clients&#8217; core teams. You will work at the intersection of industries and global markets, navigating high-stakes challenges across the full spectrum of their strategic initiatives. Operating within the industry\u2019s most trusted research environment, you\u2019ll help our clients capture the nuanced perspectives that drive smarter, faster business outcomes.<\/p>\n<p>We are a global team of pragmatic problem-solvers who mirror the intensity of the markets we serve. If you are driven by intellectual curiosity and a bias toward action, join us in reinventing the industry we invented.<\/p>\n<p>Gerson Lehrman Group, Inc. (\u201cGLG\u201d) is an equal opportunity employer and will not discriminate against any employee or applicant on the basis of age, race, religion, color, marital status, disability, gender, national origin, sexual orientation, veteran status, or any classification protected by federal, state, or local law.<\/p>\n<\/div>\n","protected":false},"template":"","meta":{"team":[]},"department":[1901],"offices":[1870],"team":[],"class_list":["post-121222","jobs","type-jobs","status-publish","hentry","department-core-engineering","offices-gurugram"],"_links":{"self":[{"href":"https:\/\/glginsights.com\/ko\/wp-json\/wp\/v2\/jobs\/121222","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/glginsights.com\/ko\/wp-json\/wp\/v2\/jobs"}],"about":[{"href":"https:\/\/glginsights.com\/ko\/wp-json\/wp\/v2\/types\/jobs"}],"wp:attachment":[{"href":"https:\/\/glginsights.com\/ko\/wp-json\/wp\/v2\/media?parent=121222"}],"wp:term":[{"taxonomy":"department","embeddable":true,"href":"https:\/\/glginsights.com\/ko\/wp-json\/wp\/v2\/department?post=121222"},{"taxonomy":"offices","embeddable":true,"href":"https:\/\/glginsights.com\/ko\/wp-json\/wp\/v2\/offices?post=121222"},{"taxonomy":"team","embeddable":true,"href":"https:\/\/glginsights.com\/ko\/wp-json\/wp\/v2\/team?post=121222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}