Cyber Threat Intelligence Analyst I

bankunitedexternal

Town of Florida (NY)

On-site

USD 100,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

BankUnited is seeking a Cyber Threat Analyst to proactively assess cyber risk, analyze threats, and respond to incidents within the Cyber Threat Unit. The role requires collaboration across IT, security, and business lines to mitigate risks and strengthen defenses.

Responsibilities include monitoring traffic and events, maintaining DLP policies, and guiding incident responders with best-practice remediation.

Qualifications

  • Bachelor's degree in CS/Info Assurance/Cyber Security or equivalent with certs.
  • Experience with network and host based DLP technologies, policies and procedures.
  • Understanding of regulatory initiatives related to SOX/GLBA.
  • Cloud security experience and familiarity with cloud security tools.

Responsibilities

  • Monitor and analyze network traffic, IDS/IPS and security events.
  • Maintain DLP systems and policies; review reports for compliance.
  • Respond to incidents; follow IR processes and escalation paths.
  • Lead investigations and triage through resolution; close false positives.
  • Provide security alerts and guidance to incident responders.
  • Stay current on vulnerabilities, threats and countermeasures.
  • Collaborate with SNOC and IT teams to assess risk and implement controls.
  • Assist in threat landscape gathering and risk reporting to leadership.

Skills

Penetration testing
Vulnerability assessments
Networking fundamentals
TCP/IP
Cyber security analysis
Incident response
Team collaboration
Communication skills
Self-motivation

Education

Bachelor's degree in Computer Science / Information Assurance / Cyber Security

Tools

SIEM
SOAR
Monitoring tools
AWS Security Hub
Azure Security Center
GCP Security Command Center
Scripting languages

Job description

JOB SUMMARY:

As a member of the Cyber Threat Unit, this position is responsible for the proactive assessment and analysis of cyber risk, understanding threats as they relate to the organization, responding to cyber incidents, and implementing measures to prevent or combat existing and potential threats.


ESSENTIAL DUTIES AND RESPONSIBILITIES


  • Monitor and analyze network traffic, Intrusion Detection/Prevention Systems (IDS/IPS), Data Loss Prevention (DLP) events, security events and logs.

  • Perform secondary reviews and maintain Data Loss Prevention (DLP) systems and policies.

  • Understand a variety of security and compliance policies and incident response processes.

  • Review daily reports and files to ensure compliance to policies and standards.

  • Escalate non-compliance issues to the appropriate group and follow-up on remediation actions

  • Work with internal customers to respond to escalations.

  • Prioritize and differentiate between potential intrusion attempts and false alarms.

  • Determine if security events monitored should be escalated to incidents and follow all applicable incident response and reporting processes and procedures.

  • Create and track security investigations to resolution.

  • Open and assign tickets to the correct resolver, and validate/close tickets related to false positives.

  • Provide investigation, triage, and mitigation of detected security events.

  • Compose security alert notifications and other communications.

  • Advise incident responders in the steps to take to investigate and resolve computer security incidents.

  • Stay up to date with current vulnerabilities, attacks, and countermeasures.

  • Work closely with the SNOC 24x7 operations team, network and system administrators, other appropriate IT/IS groups and business lines to provide incident response (IR) support and determine the risk of a given event.

  • Implement and monitor controls necessary to ensure processes are performed and are effective to protect the environment from all forms of malicious cyber activity.

  • Conduct Digital Forensics and Incident Response (DFIR) analysis of suspected compromised systems.

  • Assist in establishing procedures for handling each security event detected.

  • Keep abreast of emerging technology and public policy trends in the information security space.

  • Assist in the gathering and analysis of the current and future threat landscape, and assist the SNOC Manager in providing leadership with a realistic overview of risks and threats in and to the organization.

  • Maintain knowledge of the current security threat level by monitoring related threat intelligence sources as necessary.

  • Utilize intelligence provided by the Threat Intelligence team from past or current events to improve detection, update monitoring and possibly facilitate prevention of successful cyber attacks.

  • Provide advice on IT initiatives, IT business projects, and IT engineering in regards to security industry best practices.

  • Adheres to and complies with applicable, federal and state laws, regulations and guidance, including those related to anti-money laundering (i.e. Bank Secrecy Act, US PATRIOT Act, etc.).

  • Adheres to Bank policies and procedures and completes required training.

  • Identifies and reports suspicious activity.


QUALIFICATIONS

Education


  • Bachelor's Degree in Computer Science, Information Assurance, Cyber Security or related field or equivalent combination of work with certifications is required


Experience


  • An understanding of network and host based DLP technologies, processes, policies and procedures

  • Basic understanding of regulatory compliance initiatives related to Sarbanes Oxley (SOX), and the Gramm–Leach–Bliley Act (GLBA)

  • Experience in cloud security, or cloud administration

  • Experience with cloud security tools and technologies, such as AWS Security Hub, Azure Security Center, GCP Security Command Center, etc

  • Experience with scripting languages

  • Familiarization of cyber and cloud security standards, frameworks, and guidelines such as NIST, PCI-DSS, MITRE, OWASP, etc

  • Ability to organize and analyze large amounts of data and report findings

  • Firm grasp of the design and implementation of effective IS controls

  • Proficiency with a Security Incident handling tool (ie SIEM, ESEM)

  • Experience with Security orchestration Automation Response (SOAR)

  • Working knowledge of monitoring tools

  • Familiar with Active Directory, group policies and role based concepts

  • Possess a working knowledge of TCP/IP and the functions of Network technologies

  • Possess a working understanding of Network security devices, IPSec VPNs, TCP/IP, Routing, Switching, VRF, VLANS, Bandwidth Utilization, and Load Balancers

  • Cyber security analysis, incident response, or related security experience

  • Strong analytical and problem solving skills

  • Good interpersonal, organizational, writing and communications skills

  • Ability to work well in a team environment as a whole

  • Ability to perform multiple projects simultaneously


Licenses and Certifications


  • CISSP Certified Information Systems Security Professional

  • CEH Certified Ethical Hacker

  • SANS/GIAC Training or certifications

  • SSCP Systems Security Certified Professional

  • Cloud Certifications (eg AWS)

  • Security+

  • Certificate in Cyber Security


Knowledge, Skills, and Abilities


  • Firm understanding of penetration testing and vulnerability assessments.

  • A strong networking background.

  • Demonstrated understanding of TCP/IP networking.

  • Cyber security analysis, incident response, or related security experience preferred.

  • Strong analytical and problem solving skills.

  • Good interpersonal, organizational, writing and communications skills.

  • Ability to work well in a team environment as a whole.

  • Self-motivator

  • Working knowledge with various technologies including forensic tools, network monitoring tools, host security prevention tools, etc.

  • Additional Information

  • Candidates residing in locations within BankUnited's footprint may be given preference.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Threat Intelligence Analyst I
Cyber Threat Intelligence Analyst I

BankUnited • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Cyber Threat Intelligence Analyst I
Cyber Threat Intelligence Analyst I

BankUnited • Miami (FL), Northern (KY)

Hybrid
USD 90,000 - 130,000
Technology Security Engineer (Hybrid-Miami Lakes)
Technology Security Engineer (Hybrid-Miami Lakes)

BankUnited • Town of Florida (NY)

On-site
USD 120,000 - 190,000
Sr. Technology Controls Testing Analyst (Hybrid-Miami Lakes)
Sr. Technology Controls Testing Analyst (Hybrid-Miami Lakes)

bankunitedexternal • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Technology Risk, Cyber Governance & Third-Party Risk Manager
Technology Risk, Cyber Governance & Third-Party Risk Manager

BankUnited • Town of Florida (NY)

On-site
USD 150,000 - 210,000
Technology Risk, Cyber Governance & Third-Party Risk Manager
Technology Risk, Cyber Governance & Third-Party Risk Manager

bankunitedexternal • Town of Florida (NY)

On-site
USD 140,000 - 210,000
Technology Risk, Cyber Governance & Third-Party Risk Manager
Technology Risk, Cyber Governance & Third-Party Risk Manager

BankUnited • Miami (FL), Northern (KY)

Hybrid
USD 140,000 - 190,000
Cyber Security Engineer
Cyber Security Engineer

E & C Mid-Atlantic Ventures, LLC • Torch of Friendship (FL)

On-site
USD 90,000 - 130,000
Information Security Officer
Information Security Officer

City First Bank • Inglewood (CA)

On-site
USD 100,000 - 140,000
Cyber Security Engineer III
Cyber Security Engineer III

First Citizens Bank • North Carolina

On-site
USD 110,000 - 150,000