Threat Detection and Response, Senior Analyst

Posted Yesterday
Be an Early Applicant
7 Locations
In-Office or Remote
Senior level
Fintech
The Role
Lead threat detection and response: research adversary behavior, monitor environments, respond to incidents, build SIEM/SOAR use cases (Splunk), perform forensics and cloud IR, produce reports, automate detection and remediation, and mentor junior analysts.
Summary Generated by Built In

Do you want your voice heard and your actions to count?

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.

With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.

Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.

Position details

In this role you will focus on researching threats posed by cyber criminals to various systems, technologies, operations, and programs, and analyzing research to determine a cyber criminal’s capabilities, intentions, and attack approaches, including those with multiple phases. Responsibilities include rapidly responding to incidents to minimize risk exposure and ensure system availability; proactively monitoring internal and external-facing environments; seeking opportunities to automate detection and remediation and reduce response times for incidents; and producing reports and briefings that include perspectives on the behavior of adversaries.

Roles and Responsibilities

  • Perform cybersecurity threat detection, assessment, and mitigation efforts
  • Support inquiries from compliance teams such as IT risk management and internal and external audit, to ensure documentation is complete and in compliance with information security policies
  • Identify, evaluate, and monitor continually threats that could affect operational and business activities
  • Support development of security operations playbooks to ensure threat detection, monitoring, response, and forensics activities align with best practices, minimize gaps in detection and response, and provide comprehensive mitigation of threats
  • Create, Enhance and manage security use cases, dashboards and alerts using Splunk
  • Research and look for opportunities to adopt the best practices and industry standards to enhance the SIEM and SOAR platforms
  • Provide guidance to junior team members

Job Requirements:

  • Bachelor’s degree in business, Management, Computer Sciences, or equivalent prior work experience in a related field
  • 5-8 years of working experience in Information Security or other Information Technology fields
  • Minimum of 5 years overall experience working in global, complex, matrix-managed organization
  • Minimum of 3 years working directly in Cybersecurity Operations or Threat and Vulnerability management
  • Experience across the following technical concentrations:

o            Network-Based Security Controls (Firewall, IPS, WAF, MDS, Proxy, VPN)

o            Anomaly Detection and Investigation

o            Host and Network Forensics

o            Operating Systems

o            Web Applications and Traffic

  • Experienced with EnCase, FTK, SIFT, Splunk, Redline, Volatility, WireShark, TCPDump, and open-source forensic tools
  • Experience responding to cyber events in public cloud environments such as AWS, Azure, Google Cloud, etc.
  • Experience creating trending, metrics, and management reports
  • Security experience in all phases of product and service development lifecycle including architecture, design, development, testing, release, and operational maintenance.
  • Experience with cloud computing security, network, operating system, database, application, and mobile device security.
  • Extensive knowledge of vulnerability management and remediation.
  • Experience with information security risk management, including conducting information security audits, reviews, and risk assessments.
  • Experience in two or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, and Incident Response and Forensics"
  • Knowledge of models/frameworks such as Kill Chain and MITRE ATT&CK
  • Strong time management skills to balance multiple activities and lead junior analysts as needed
  • Well-developed analytic, qualitative, and quantitative reasoning skills
  • Understanding of offensive security to include common attack methods
  • Understanding of how to pivot across multiple datasets to correlate artifacts for a single security event
  • A diverse skill base in both product security and information security including organizational structure and administration practices, system development and maintenance procedures, system software and hardware security controls, access controls, computer operations, physical and environmental controls, and backup and recovery procedures.
  • Detailed knowledge and experience in security and regulatory frameworks (ISO 27001, NIST 800 series, FFIEC, SOC2, FedRAMP, STAR, etc.)
  • In-depth knowledge in one or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, and Incident Response and Forensics"
  • Understanding of enterprise detection technologies and processes (advanced threat detection tools, intrusion detection system/intrusion prevention system (IDS/IPS), network packet analysis, endpoint protection, Anti malware/anti-virus).
  • Understanding of network protocols and operating systems (Windows, Unix, Linux, databases)
  • Knowledge of Splunk, Phantom, Python, CrowdStrike, Tanium, Defender, Azure, AWS and forensic security tools is preferred.
  • Experience working within the Financial Services Industry preferred.
  • Experience in one or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, and Incident Response and Forensics preferred.
  • One to three years of experience in Splunk, Splunk Enterprise Security or Splunk Phantom is preferred
  • Knowledge of scripting languages like Python is preferred
  • Knowledge in RegEx is preferred
  • Strong analytical skills (i.e., technical and non-technical problem solving skills).
  • Maintain certifications in an information security related field. The following are recommended:  CySA+, CISSP, ISSMP, SANS, GCIA, CISM, EnCE, CEH, GCFA, GCFE, GCIH, or GSEC and/or Splunk Certifications.

Mitsubishi UFJ Financial Group (MUFG) is an equal opportunity employer. We view our employees as our key assets as they are fundamental to our long-term growth and success. MUFG is committed to hiring based on merit and organsational fit, regardless of race, religion or gender.

Skills Required

  • Bachelor's degree in Business, Management, Computer Science or equivalent experience
  • 5-8 years working experience in Information Security or IT
  • Minimum 5 years experience in global, complex, matrix-managed organization
  • Minimum 3 years working directly in Cybersecurity Operations or Threat and Vulnerability Management
  • Experience with network-based security controls (Firewall, IPS, WAF, MDS, Proxy, VPN)
  • Anomaly detection and investigation experience
  • Host and network forensics experience
  • Knowledge of operating systems and web application/traffic analysis
  • Experience with EnCase, FTK, SIFT, Redline, Volatility, Wireshark, TCPDump and forensic tools
  • Experience responding to cyber events in public cloud environments (AWS, Azure, Google Cloud)
  • Experience creating trending, metrics, and management reports
  • Security experience across product/service development lifecycle (architecture through operations)
  • Experience with cloud computing security, network, OS, database, application, and mobile security
  • Extensive knowledge of vulnerability management and remediation
  • Experience with information security risk management, audits, reviews, and risk assessments
  • Experience in two or more security domains (Governance, Risk Management, Network Security, Threat/Vulnerability Management, Incident Response/Forensics)
  • Knowledge of Kill Chain and MITRE ATT&CK frameworks
  • Strong time management and ability to lead junior analysts
  • Analytic, qualitative, and quantitative reasoning skills
  • Understanding of offensive security and common attack methods
  • Ability to correlate artifacts across multiple datasets for a single security event
  • Detailed knowledge of security and regulatory frameworks (ISO 27001, NIST 800 series, FFIEC, SOC2, FedRAMP, etc.)
  • Understanding of enterprise detection technologies and processes (IDS/IPS, packet analysis, endpoint protection, anti-malware)
  • Understanding of network protocols and operating systems (Windows, Unix, Linux) and databases
  • Knowledge of Splunk, Phantom, Python, CrowdStrike, Tanium, Defender and forensic security tools
  • Experience working within the Financial Services industry
  • One to three years experience with Splunk Enterprise Security or Splunk Phantom
  • Knowledge of scripting languages like Python
  • Knowledge of RegEx
  • Maintain certifications in information security-related fields (CySA+, CISSP, CISM, GCIA, GCFA, GCIH, EnCE, SANS, Splunk certs etc.)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
30,196 Employees

What We Do

MUFG (Mitsubishi UFJ Financial Group) is one of the world's leading financial groups. Headquartered in Tokyo and with over 360 years of history, MUFG has a global network with over 2,500 locations in more than 50 markets including the Americas, Europe, the Middle East and Africa, Asia and Oceania. The Group has over 170,000 employees and offers services including commercial banking, trust banking, securities, credit cards, consumer finance, asset management, and leasing. Through close partnerships among our group companies, the Group aims to be the world's most trusted financial group, flexibly responding to all of the financial needs of its customers, serving society, and fostering shared and sustainable growth for a better world. MUFG's shares trade on the Tokyo, Nagoya, and New York stock exchanges.

Similar Jobs

Applied Systems Logo Applied Systems

Senior Manager, Software Engineering

Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Remote or Hybrid
Canada
3079 Employees
140K-185K Annually

PwC Logo PwC

Signature Events Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
64 Locations
370000 Employees
212K-244K Annually

PwC Logo PwC

National Tax Services - Tax R&Q Technology Risk Management - Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
66 Locations
370000 Employees
77K-214K Annually

PwC Logo PwC

Oracle HCM Director

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
64 Locations
370000 Employees
155K-410K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account