Jobs and Careers
DI

Principal Incident & Threat Analyst

Discover
Riverwoods, IL, United Statesfull_timeVerifiedPosted 11 Oct 2024
💰 $149,300/yr($88,500/yr$149,300/yr)

About the role

Discover. A brighter future.

With us, you’ll do meaningful work from Day 1. Our collaborative culture is built on three core behaviors: We Play to Win, We Get Better Every Day & We Succeed Together. And we mean it — we want you to grow and make a difference at one of the world's leading digital banking and payments companies. We value what makes you unique so that you have an opportunity to shine.

Come build your future, while being the reason millions of people find a brighter financial future with Discover.

Job Description:

At Discover, be part of a culture where diversity, teamwork and collaboration reign. Join a company that is just as employee-focused as it is on its customers and is consistently awarded for both. We’re all about people, and our employees are why Discover is a great place to work. Be the reason we help millions of consumers build a brighter financial future and achieve yours along the way with a rewarding career.

What You’ll Do

Guides and supports incident response teams through mastery of the information, data, and technology available.  Maintains expert-level knowledge of detection capabilities and attacker techniques.  Develops effective security controls to enhance the business environment and improves management decision making. Actively manages and escalates risk and customer-impacting issues within the day-to-day role to management.

How You’ll Do It

  • Incident lead for all analysis and response functions during high impact cyber events. Conducts malware analysis to identify indicators of compromise, determine scope, and assess impact. Translate technical details pertaining to threats and incidents into consumable elements for non-technical groups.

  • Develops mitigation and countermeasure strategies based on knowledge of attack tactics and techniques

  • Develops innovative solutions which enable rapid analysis and response to security incidents at the enterprise scale

  • Builds and maintains effective relationships with peers and internal business partners.

  • Delivers presentations and executive briefings regarding relevant security incidents and findings to senior management.

  • Assist in the design and development of security solutions and processes consistent with Cyber Incident and Threat Management program goals. Provides program subject matter expertise to influence Cyber-led security optimization initiatives. Collects and documents, and implements solutions to remediate identified lessons learned

  • Enriches team value by creating training and knowledge sharing opportunities.

  • Utilize knowledge of the MITRE ATT&CK framework to overlay researched threats to existing controls

  • Work with the alert logic creation team to develop succinct detection rules to identify threats in the environment

  • Review triage and incident cases for trend analysis

  • Conduct threat briefings across the enterprise at varying levels of knowledge and understanding.

  • Work with the Enterprise Vulnerability Management team to identify and address emergent threats to the firm

  • Coordinate with the Incident and Crisis Management team to mitigate the risk of external vendor compromises

  • Educate members of the Cyber Security group on relevant threats to the environment and to our vertical

  • Create and disseminate Threat Bulletins, Reports, and Updates on a regular basis

  • Monitor and track threat actors/groups identified as most likely to attack the firm and/or our vertical and work with relevant internal teams on defensive measures

  • Monitor Intelligence feeds/sources for work initiation

  • Develop/Mentor junior members of the team through training and knowledge sharing opportunities.

  • Key contributor to strategy and prioritization of program initiatives

  • Coordinate prioritization of team assignments with Sr. Manager

Qualifications You’ll Need
The Basics

  • Bachelor’s degree in Computer Science or Information Technology.

  • 6+ years of experience with Information Security, Computer Science, Data Analytics, or related.

  • In lieu of education, 8+ years of experience with Cybersecurity, Software Engineering, Data Analytics, or related.

Preferred Qualifications 

If we had our say, we’d also look for: 

  • Certifications in GIAC, Security +, or Network +

  • Prior Cyber Threat Intelligence Experience

  • Demonstrable experience with cyber threat intelligence vendor tools and services

  • Knowledge and understanding of t

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Discover

View company profile →