Job DescriptionJOB SUMMARY: As a member of the Cyber Threat Unit, this position is responsible for the proactive assessment and analysis of cyber risk, understanding threats as they relate to the organization, responding to cyber incidents, and implementing measures to prevent or combat existing and potential threats.ESSENTIAL DUTIES AND RESPONSIBILITIESMonitor and analyze network traffic, Intrusion Detection/Prevention Systems (IDS/IPS), Data Loss Prevention (DLP) events, security events and logs.Perform secondary reviews and maintain Data Loss Prevention (DLP) systems and policies.Understand a variety of security and compliance policies and incident response processes.Review daily reports and files to ensure compliance to policies and standards.Escalate non-compliance issues to the appropriate group and follow-up on remediation actionsWork with internal customers to respond to escalations.Prioritize and differentiate between potential intrusion attempts and false alarms.Determine if security events monitored should be escalated to incidents and follow all applicable incident response and reporting processes and procedures.Create and track security investigations to resolution.Open and assign tickets to the correct resolver, and validate/close tickets related to false positives.Provide investigation, triage, and mitigation of detected security events.Compose security alert notifications and other communications.Advise incident responders in the steps to take to investigate and resolve computer security incidents.Stay up to date with current vulnerabilities, attacks, and countermeasures.Work closely with the SNOC 24x7 operations team, network and system administrators, other appropriate IT/IS groups and business lines to provide incident response (IR) support and determine the risk of a given event.Implement and monitor controls necessary to ensure processes are performed and are effective to protect the environment from all forms of malicious cyber activity.Conduct Digital Forensics and Incident Response (DFIR) analysis of suspected compromised systems.Assist in establishing procedures for handling each security event detected.Keep abreast of emerging technology and public policy trends in the information security space.Assist in the gathering and analysis of the current and future threat landscape, and assist the SNOC Manager in providing leadership with a realistic overview of risks and threats in and to the organization.Maintain knowledge of the current security threat level by monitoring related threat intelligence sources as necessary.Utilize intelligence provided by the Threat Intelligence team from past or current events to improve detection, update monitoring and possibly facilitate prevention of successful cyber attacks.Provide advice on IT initiatives, IT business projects, and IT engineering in regards to security industry best practices.Adheres to and complies with applicable, federal and state laws, regulations and guidance, including those related to anti-money laundering (i.e. Bank Secrecy Act, US PATRIOT Act, etc.).Adheres to Bank policies and procedures and completes required training.Identifies and reports suspicious activity.QUALIFICATIONSEducationBachelor's Degree in Computer Science, Information Assurance, Cyber Security or related field or equivalent combination of work with certifications is requiredExperienceAn understanding of network and host based DLP technologies, processes, policies and proceduresBasic understanding of regulatory compliance initiatives related to Sarbanes Oxley (SOX), and the Gramm–Leach–Bliley Act (GLBA)Experience in cloud security, or cloud administrationExperience with cloud security tools and technologies, such as AWS Security Hub, Azure Security Center, GCP Security Command Center, etcExperience with scripting languagesFamiliarization of cyber and cloud security standards, frameworks, and guidelines such as NIST, PCI-DSS, MITRE, OWASP, etcAbility to organize and analyze large amounts of data and report findingsFirm grasp of the design and implementation of effective IS controlsProficiency with a Security Incident handling tool (ie SIEM, ESEM)Experience with Security orchestration Automation Response (SOAR)Working knowledge of monitoring toolsFamiliar with Active Directory, group policies and role based conceptsPossess a working knowledge of TCP/IP and the functions of Network technologiesPossess a working understanding of Network security devices, IPSec VPNs, TCP/IP, Routing, Switching, VRF, VLANS, Bandwidth Utilization, and Load BalancersCyber security analysis, incident response, or related security experienceStrong analytical and problem solving skillsGood interpersonal, organizational, writing and communications skillsAbility to work well in a team environment as a wholeAbility to perform multiple projects simultaneouslyLicenses and CertificationsCISSP Certified Information Systems Security ProfessionalCEH Certified Ethical HackerSANS/GIAC Training or certificationsSSCP Systems Security Certified ProfessionalCloud Certifications (eg AWS)Security+Certificate in Cyber SecurityKnowledge, Skills, and AbilitiesFirm understanding of penetration testing and vulnerability assessments.A strong networking background.Demonstrated understanding of TCP/IP networking.Cyber security analysis, incident response, or related security experience preferred.Strong analytical and problem solving skills.Good interpersonal, organizational, writing and communications skills.Ability to work well in a team environment as a whole.Self-motivatorWorking knowledge with various technologies including forensic tools, network monitoring tools, host security prevention tools, etc.Additional InformationCandidates residing in locations within BankUnited's footprint may be given preference.Job DetailsJob Type: Full Time - PermanentCategory: Information Security
...program and profit-sharing contributions.Discretionary Bonus Program - Recognizing employee contributions.Flexible Spending Accounts (FSA) - Pre-tax savings for dependent care, transportation, and eligible medical expenses.Paid Time Off (PTO) - Begins accruing on the...
...Bus Driver Opportunity Happy Day Transit has provided bus, livery, and ambulette transportation services in New York City since 1982. We are a family-owned business that currently operates 80 vehicles. We are hiring drivers to expand our bus operation in Brooklyn and...
SAS Retail Services is seeking a dynamic and detail-oriented Traveling Retail Merchandiser to join our team. In this role, you will be pivotal in executing merchandising strategies in various retail locations nationwide. You will help ensure that products appear in the...
...Assistant Librarian: Digital Processing Archivist Indiana University is an equal opportunity employer and provider of ADA services... ...is responsible for advancing the mission of the IU Northwest Archives and Special Collections, leads and oversees archival processing...
...empowered to do their best work. Job Skills / Requirements ESS Clean is looking for an organized, people-focused HR & Recruiting Coordinator to join our team at our Corporate Office in Urbana, Illinois. HR or recruiting experience is welcome, but it is not...