Analyst II-Cyber Defense
Core
Technical escalation point during security incidents, determining threat extent and business impacts to contain and remediate incidents.
Role type
Mid-level IC cyber defense analyst
Builds
Incident response workflows and threat mitigation strategies for financial services clients
Domain
Financial services cybersecurity
Required skills
incident management, malware analysis, network traffic analysis, threat detection, SIEM, DLP, IDS/IPS, firewall policy analysis, scripting, adversary TTPs, log correlation
Preferred skills
financial services sector experience, shift lead experience, mentoring Level 1 analysts
Technologies
SIEM, DLP, IDS/IPS, firewalls, anti-malware, encryption, operating systems, databases, web applications, network infrastructure
Responsibilities
Act on escalated alerts and events from Level 1 Analysts; Triage malware incidents and determine escalation needs; Monitor for emerging threat patterns and vulnerabilities; Establish and maintain intrusion detection policies and offense rules; Tune response and alerting mechanisms; Import new signatures from manufacturers; Analyze and assess firewall policy and rule base sets; Handle emergencies 24x7; Provide status reports to management.
Seniority
Mid-level, hands-on IC with shift lead capability