This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The cyber defense analyst for Services within the Business, Functions and Technology (BFT) is responsible for maintaining a secure technology ecosystem free from high-risk vulnerabilities and rapidly respond to the changing threat landscape and business demand to mitigate cyber risk for the Services business.
Job Responsibility:
Vulnerability Operations: Ensure business and technology remain within risk tolerance for all applicable Cybersecurity risk appetites and sustain it with the consistent operating model
Enhance current vulnerability management (VTM) operating model in line with BFT Risk Governance organization with Path-to-appetite and reporting
Timely escalate to CISO Leadership and Businesses and ensure VTM risk treatment responses are entered in a timely fashion
Support Vulnerability Organization to improve the quality and integrity of VTM/GEM reports
Continue supporting vulnerability management Uplift Program activities and reduce risk while reducing stakeholders’ pain-points (data/reporting, false positives, processes)
Perform root cause analysis of VA Issues and identification of repeated offenders for high risk vulnerabilities
Security Assessments: Conduct security reviews to check for security compliance to Bank’s requirements
Security Incident Response: Identify areas of repeating SIRT incidents, related trending and work with technology team and ISO contacts in reducing repeat volume instances
Identify opportunities for improving SIRT workflow efficiencies and developing reporting which better reports on root causes for bringing down repeat instance volumes
Work with SIM and ISO community to facilitate the adherence of SIRT reporting timelines as per defined within SIRT standard, as well as identify deviations and its cause
Define and document escalation and response procedures between IR CFSC and Cyber Defense
Document/update a Cyber Response plan or guideline to complement Business or Country Crisis Management Plans and support Crisis Management Team training
Requirements:
5+ years of relevant experience
Possesses deep and broad technical expertise across multiple security domains and security controls (e.g., threat intelligence, forensics, vulnerability management, security architecture, application security)
Proficient in advanced analytical techniques
What we offer:
medical, dental & vision coverage
401(k)
life, accident, and disability insurance
wellness programs
paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays