Senior Cyber Security Analyst - Incident Response (Remote)

First Citizens Bank

North Carolina

On-site

USD 140,000 - 188,000

Full time

16 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

First Citizens Bank is seeking a Senior Incident Response Analyst to join its Cyber Incident Response team in a remote role across the United States. You will detect and respond to threats, interact with business stakeholders, and help restore operations.

This is a technical role supporting threat hunting, intelligence, monitoring, content creation, and mentoring colleagues. You will lead incident management, coordinate investigations, mitigate and remediate, and build countermeasures across

Qualifications

  • Bachelor's Degree and 8 years' experience in Information Security OR High School Diploma or GED/Equivalent and 12 years' experience in Information Security.

Responsibilities

  • Investigate SIEM/SOAR events; respond to and contain incidents using malware analysis and network/endpoint security.
  • Lead incidents; coordinate investigation, mitigation, and remediation with technical and business stakeholders.
  • Ensure incidents are detected, documented, investigated, and resolved.

Skills

Incident Response
Threat Hunting
Communication
Stakeholder Management
Threat Analysis
Malware Analysis

Education

Bachelor's Degree
High School Diploma or GED

Tools

SIEM/SOAR
MITRE ATT&CK
Yara
Sigma
Regular Expressions
Azure
AWS
GCP

Job description

Overview

This is a remote role that may be hired in several markets across the United States.

Overview

This is a remote role that may be hired in several markets across the United States. As a Senior Incident Response Analyst, you'll be a member of the bank's Cyber Incident Response team. We are looking for an experienced senior level analyst with proven skillsets to detect and respond to threats in the environment, interact with business stakeholders and work to restore operations. This is a technical role and will support the Threat Hunting, Intelligence, and Monitoring functions with content creation, threat analysis, detection recommendations, and colleague mentoring. Seeking a candidate with strong communication skills to complement their technical skillset providing the ability to distill down complex issues for broader understanding expedited incident management.

Responsibilities & Qualifications
Duties & Responsibilities
  • Incident Analyst/handler –investigate SIEM/SOAR events as necessary; bring experience in malware analysis, network/endpoint security to respond to and contain incidents.
  • Incident Responder/Incident Lead – Lead Incidents, coordinating the investigation, mitigation, and remediation from a technical perspective. Liaise with technical and business stakeholders.
  • Incident Management – Ensures Information Security incidents are properly detected, documented, investigated, and resolved.
  • Content Development - Support the creation of countermeasures and mitigations in response to an incident.
  • Threat Hunting - Support the operational driven inputs (eg. on the heels of an incident or event) into threat hunting and help build countermeasures/mitigations to address commodity and targeted threats. Also build a capability to track evolving threat actor techniques.
  • Post Incident Review – Provide recommendations to improve communication, processes, procedures, and mitigation options based on high severity incidents.
Qualifications

Minimum Required Education and Experience: Bachelor's Degree and 8 years' experience.

OR

High School Diploma or GED/Equivalent and 12 years' experience in Information Security.

Preferred Qualifications
  • Experience with all aspects of Incident response including stakeholder management.
  • 2+ years of Threat Hunting experience.
  • Familiarity with MITRE ATT&CK and its application to countermeasure creation is a plus.
  • Experience analyzing/dispositioning and escalating security events (systems, application, network, authentication email events)
  • Experience translating threat actor techniques to building mitigations across a variety of security technologies. This could take the form of Yara, Sigma or Regular Expressions.
  • Ability to define security requirements and drive project deliverables.
  • Ability to keep track of multiple incidents and ensure responses are provided in a timely fashion.
  • Experience responding to cloud-related incidents in Azure, AWS and Google cloud.
  • Cloud administrative experience preferred.
  • Cyber Incident Response experience – 3+ years required in which your primary job was an Incident Response role.
  • This role requires participation in the afterhours on call rotation. Rotations will cycle on a weekly basis.
Additional Information

The base pay for this position is generally between $140,000 and $188,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Analyst - Remote Cyber Defense
Senior Incident Response Analyst - Remote Cyber Defense

First Citizens Bank • Raleigh (NC)

On-site
USD 140,000 - 188,000
Senior Incident Response Lead | Remote & Threat Hunting
Senior Incident Response Lead | Remote & Threat Hunting

First Citizens Bank • Arizona

On-site
USD 140,000 - 188,000
Benefits package
Senior Incident Response & Threat Hunter (Remote)
Senior Incident Response & Threat Hunter (Remote)

First Citizens Bank • North Carolina

On-site
USD 140,000 - 188,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

MFI Technologies Incorporated • New York (NY)

On-site
USD 75,000 - 100,000
Senior Detection and Response Analyst
Senior Detection and Response Analyst

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2
Incident Response Analyst
Incident Response Analyst

Prestige Staffing • City of Yonkers (NY)

On-site
USD 125,000 - 130,000
Cyber Defense Incident Response Lead
Cyber Defense Incident Response Lead

KeyBank • United States

On-site
USD 96,000 - 181,000
Senior Incident Response Engineer
Senior Incident Response Engineer

Elsevier • New Jersey

Hybrid
USD 89,000 - 143,000
Annual incentive bonus
Cyber Security Analyst
Cyber Security Analyst

Insight Global • Irvine (CA)

On-site
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1