The Cyber Defense Ops Specialist is an individual contributor in the Cyber Defense Threat Detection (CDTD) Cyber Defense Operations Center (CDOC), responsible for performing security monitoring, intrusion analysis, incident handling, data loss prevention, privileged user monitoring, security incident management, malware detection/eradication, and recognizing hacker/incident response tactics, techniques, and procedures. This role requires the incumbent to stay current with security technology, the threat landscape, and emerging threats.
Primary responsibilities include
- Performing ongoing monitoring and threat analysis, analyzing logs, NetFlow data, and packet capture.
- Identifying potential IT security incidents and escalating information to appropriate senior staff.
- Assessing threat and vulnerability information from all sources (both internal and external) and promptly applying applicable mitigation techniques.
Experience and Skills:
- 1 or more years of security industry experience preferably in a Security Operations Center (SOC) environment
- Experience or knowledge of the following highly desirable:
- Security Information and Event Management Tools (Arcsight, Splunk, etc.)
- Intrusion Prevention/Detection Tools (FirePower, McAfee, PaloAlto)
- Database Security Tools (Guardium, jSonar)
- Data Loss Prevention Tools (Symantec, Triton, etc.)
- Firewalls (Cisco, Palo Alto, Check Point etc.)
- Application Security Tools (Web Application Firewalls)
- Vulnerability tools
- Cyber Security Incident Response
- Host Intrusion Detection Systems
- XDR and Antivirus Tools (Crowdstrike, Symantec, MS Defender)
- Strong verbal and written communication skills including the ability to communicate technical concepts to non-technical audiences.
- Excellent critical thinking, problem-solving, and decision-making skills.
- Must possess active listening, attention to detail, customer service, prioritization, and problem-solving skills.
- Ability to work independently or strategically.
- Experience adapting and demonstrating flexibility while working in a dynamic environment.
Education and Certifications
- Bachelor’s Degree or equivalent combination of experience
- A combination of relevant industry certifications preferred (e.g. Net+, Sec+, CEH, Pentest+, AWS Certified Cloud Practitioner, Microsoft Azure Fundamentals)
Hours & Work Schedule
Hours per Week: 40 Hrs. (4 days per week)
Work Schedule: 7:00am – 5:00pm Wednesday - Saturday)
Location: Citizens Bank Johnston Campus (this is not a remote opportunity)
Pay Transparency
The salary range for this position is from $64,900 - $90,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to, the budget, work location, relevant skills, and experience.
We offer competitive pay, comprehensive medical, dental, and vision coverage, retirement benefits, maternity and paternity leave, flexible work arrangements, education reimbursement, wellness programs, and more. Citizens’ paid time off policy exceeds the mandatory paid sick or paid time away policies of local and state jurisdictions in the United States. For an overview of our benefits, visit our Careers site - https://jobs.citizensbank.com/benefits
About UsEqual Employment Opportunity
Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.
Equal Employment and Opportunity Employer
Job Applicant Data Privacy Policy
Background Check
Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.
Skills Required
- At least 1 year of security industry experience, preferably in a Security Operations Center environment
- Bachelor’s degree or equivalent combination of experience
- Knowledge or experience with SIEM tools such as ArcSight or Splunk
- Knowledge or experience with intrusion prevention and detection tools
- Knowledge or experience with database security tools
- Knowledge or experience with data loss prevention tools
- Knowledge or experience with firewalls and web application firewalls
- Knowledge or experience with vulnerability tools and cyber security incident response
- Knowledge or experience with host intrusion detection, XDR, and antivirus tools
- Strong verbal and written communication skills
- Critical thinking, problem-solving, decision-making, prioritization, and attention to detail
- Ability to work independently and adapt in a dynamic environment
- Relevant industry certifications such as Network+, Security+, CEH, Pentest+, AWS Certified Cloud Practitioner, or Microsoft Azure Fundamentals
Citizens Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Citizens and has not been reviewed or approved by Citizens.
-
Parental & Family Support — Policies include six weeks of fully paid parental leave for all parents, up to 16 weeks for birthing parents, 10 days of emergency back‑up care, and adoption assistance of more than $25,000. Recognition for adoption support underscores a strong family‑friendly posture.
-
Leave & Time Off Breadth — Time off includes 11 paid holidays and up to 27 PTO days. The breadth of leave is presented as generous versus many peers.
-
Healthcare Strength — Medical, dental, and vision options pair with an HSA that includes a company contribution, plus mental‑health access via Spring Health (eight no‑cost sessions), Hinge Health, wellness programs, and discounted gyms. Eligibility at 20+ hours per week broadens access to these resources.
Citizens Insights
What We Do
As one of the oldest and largest financial services firms in the United States with a history dating back to 1828, we’re committed to providing solutions and expertise that support our customers, clients, colleagues, and communities in what’s next on their own unique journey. We invest in the humans who build the logic, ideas, and innovations that bring new technologies to life. Investments in AI, cloud computing, machine learning and automation provide our engineers the tools that enable us to remain competitive and win in today’s environment. At Citizens, we recognize that the journey to accomplishment is no longer linear and that individuals are made of all they have done and all they are going to do. Whether you’re considering banking with us or looking to work with us, you’ll find a customer-centric culture and a supportive, collaborative workforce at Citizens. You’re made ready and so are we. If you're ready to advance your career in technology and security, learn more about opportunity's Citizens offers here: https://jobs.citizensbank.com/digital-transformation
Why Work With Us
We empower the colleagues that power our tech. With growth & upskilling opportunities and sought-after benefits, plus a diverse culture of people and perspectives, we help our colleagues achieve career goals. Because innovation can’t happen without the minds and hearts of our people. Technology is constantly evolving, and we believe you can too.
Gallery








