- Define, develop, and/or implement technology controls and information security policies, programs, and tools
- Provide specialized expertise and guidance on risk assessment, gap identification, and security solutions
- Lead and coordinate real-time analysis of cyber incidents affecting bank operations
- Analyze, triage, remediate, and elevate security incidents to the CSIRT when needed
- Manage the internal incident queue and ensure incidents are recorded, updated, followed up, and closed according to SLAs
- Guide the identification, triage, and remediation of web attacks, malware incidents, and other threats
- Participate in rotating 24x7 security monitoring operations and weekly on-call coverage
- Balance operational BAU and queue work with project and improvement initiatives
- Produce complex reporting, analysis, and assessments at functional, business-line, or enterprise level
- Respond to, investigate, and remediate cyber threats to the bank
- Coordinate information among technical teams, CSOC, CSIRT, ITS, and Lines of Business Technology Solutions
Requirements
- 5–7 years of relevant experience in information security operations or a related field
- Minimum 3 years of experience leading or coordinating a Security Operations Monitoring team
- Thorough understanding of security controls, mechanisms, and threat risk assessment techniques
- Expert knowledge of security incident and event management, enterprise incident management frameworks, log analysis, network traffic analysis, malware investigation and remediation, SIEM correlation logic, and alert generation
- Expert knowledge of SIEM, EDR, XDR, firewalls, WAF, NIDS, or equivalent technologies
- Understanding of NIST Cybersecurity Framework, SANS Top 20 Critical Security Controls, and OWASP Top 10
- Expert knowledge of enterprise IT operations, incident management, change management, access/identity management, security operations, vulnerability and compliance management, ticketing systems, incident ticket lifecycles, and SLA terms
- Ability to analyze and report on information from multiple data sources using data-mining techniques
- Ability to produce reports and present results to technical and executive stakeholders
- Strong organizational and self-directing skills
- Ability to initiate, coordinate, prioritize, and complete responsibilities with minimal supervision
- Excellent written and oral communication skills
- Basic programming skills in scripting languages are desirable
- Bachelor's degree or equivalent program in Computer Science, Management Information Systems, or a similar field is required
- Completion of at least one of GIAC GSEC, GCIH, GCIA, GCFE, GCFA, CCNP, CCNA, or CISSP
- Ability to work rotating North America shifts and weekly on-call rotations
- Ability to perform sedentary work and continuous multitasking, office-equipment operation, concentration, reading, writing, comprehension, and basic arithmetic
- Occasional domestic travel and occasional lifting/carrying under 25 lbs.
Core Competencies
Demonstrates expertise in information security operations, including incident management, risk assessment, and security controls. Proficient in utilizing SIEM, EDR, and other security technologies to analyze and remediate cyber threats while effectively communicating findings to stakeholders.
Highest-signal resume keywords
- Information Security Operations
- Security Incident Management
- SIEM Expertise
- Risk Assessment Techniques
- NIST Cybersecurity Framework
ATS Optimization Keywords
Hard Skills
- Security Controls
- Threat Risk Assessment
- Log Analysis
- Network Traffic Analysis
- Malware Investigation
- Data-Mining Techniques
- Incident Ticket Lifecycles
- Vulnerability Management
- Basic Programming Skills
- Change Management
Soft Skills
- Strong Organizational Skills
- Self-Directing Skills
- Excellent Written Communication
- Excellent Oral CommunicationAbility to Prioritize Responsibilities
Certifications & Qualifications
- GIAC GSEC
- GIAC GCIH
- GIAC GCIA
- GIAC GCFE
- GIAC GCFA
- CCNP
- CCNA
- CISSP
Industry Keywords
- Cybersecurity
- Incident Response
- Operational BAU
- Security Monitoring
- Compliance Management
- Executive Stakeholders
- Rotating Shifts
- Domestic Travel
- Web Attacks
- Malware Incidents
Tools & Technologies
- SIEM
- EDR
- XDR
- Firewalls
- WAF
- NIDS
- Ticketing Systems
- CSIRT
- CSOC
- ITS