Holiday, United States
Business Operations and Analytics
Permanent | Full Time
Purpose of Job The Cyber Threat Operations Center (CTOC) is excited to add a new Cloud Threat Response team to monitor and respond to threats in both our public and private cloud environment. We are actively looking for a talented Cloud Threat Response- Senior Info Security Analyst to join this team.
In this role you will investigate, analyze, and respond to security anomalies and events (e.g. suspicious behavior, attacks, and security breaches) within USAAs environments using a variety of cyber defense tools to detect and respond to threats. Conduct vulnerability, security configuration, and/or penetration testing assessments of systems and networks. Identifies cyber threats, analyzes operational impacts, and communicates to appropriate stakeholders. Stay current with latest information security threats, exploits, trends, and intelligence.
This role can work in a 100% Remote Work Environment or at one of our many locations across the US such as: San Antonio, Plano, Phoenix, Colorado, and Tampa.
USAA knows what it means to serve. We facilitate the financial security of millions of U.S. military members and their families. This outstanding mission requires a dedication to innovative thinking at every level.
USAA Careers World Class Benefits (31 seconds)
About USAA IT
Our most meaningful qualification isn't technical, it's human. Here, we don't just sit in front of a screen. We stand behind our 12 million members who rely on us every day.
We are over 5,000 employees strong, a passionately supportive and collaborative team built on agile principles. We've been a top-two Computerworld 100 Best Places to Work in IT five years in a row and were recently named a Top 50 Employer for Minority Engineers & IT by Workforce Diversity Magazine.
Identifies and manages existing and emerging risks that stem from business activities and the job role.
Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled.
Follows written risk and compliance policies and procedures for business activities.
Leads peers and team members in the execution of the Information Security domain activities while anticipating efforts that will impact their team.
Researches and analyzes the latest information security vulnerabilities, threats, exploits, trends and intelligence. Shares intelligence with peer teams.
Conducts advanced vulnerability management, security configuration assessments, and/or penetration testing operations and manages the resulting findings.
Develops analysts through training and knowledge sharing activities.
Monitors internal and external networks, systems, and applications for advanced security anomalies and events (e.g. suspicious behavior, attacks, and security breaches). Trains analysts in incident detection and response.
Responds to cyber incidents, performing detailed analysis using complex security tools to determine root cause and impact by using a broad range of demonstrated experience (e.g. forensics, networking, servers, coding, etc.) to determine a malicious actor's tactics, techniques, and procedures. Trains new analysts in incident detection and response.
Utilizes discoveries from the incident response process to make significant and/or complex improvements to the existing detection capabilities, operational processes and security controls.
Prepares and delivers written and/or verbal briefs with recommendations to senior leadership on latest threats, alerts, incidents, and improvements.
Provides insight on issues and serves as a mentor and coach to peers and team members for assigned area of responsibility.
6 years of related experience in Information Security, Cybersecurity and/or Information Technology with a security focus to include accountability for complex tasks and/or projects.
4 years of related experience in one of the following domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communications and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, Software Development Security.
Advanced level of business acumen in the areas of business operations, risk management, industry practices and emerging trends.
Knowledge of attacker tools/tactics/procedures and applying them to access management, governance, threat hunting, investigations, and incident response.
Knowledge of defense-in-depth principles and security architecture.
When you apply for this position, you will be required to answer some initial questions. This will take approximately 5 minutes. Once you begin the questions you will not be able to finish them at a later time and you will not be able to change your responses.
Two years of experience performing Security Monitoring or Incident Response within AWS, GCP and/or other public cloud environments (not specifically tools that are hosted in the Cloud).
At least 2 Cloud certifications from any of the major Cloud Service Providers
Developing use cases, creating alerts, writing playbooks, and building response capabilities.
Hands-on experience with Docker and/or Kubernetes
Familiar with attacker tools/tactics/procedures and applying them to hunts, investigations, and incident response.
Familiar with MITRE ATT&CK
Familiar with Auto-remediation/Auto-mitigation capabilities
Experience with Python
The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.
USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market position. The salary range for this position is: $ 106,800 - $ 192,300 *( this does not include geographic differential it may be applied based on your work location)
Employees may be eligible for pay incentives based on overall corporate and individual performance or at the discretion of the USAA Board of Directors.
Loading please wait...