Jobs and Careers
EM

Senior Security Analyst

Empower
Overland Park, United Statesfull_timeVerifiedPosted 8 Aug 2024
💰 $143,525/yr($101,600/yr$143,525/yr)

About the role

Grow your career with a growing organization

Whether they’re helping people reach their long-term financial goals or providing personal wealth management strategies, every associate contributes to changing the lives of those we serve for the better. When it comes to job satisfaction, that’s hard to beat. And from a personal satisfaction perspective, you’ll enjoy the freedom to support causes that matter to you and experience a truly inclusive work environment. Your future starts now.

As a Senior Security Analyst, you will work with our Security Information and Event Management and Detection Engineering teams. You will be part of a team of individuals that are responsible for developing, reviewing, and updating Empower SIEM detections and helping drive key components of the SIEM and Detection engineering program. You’ll work closely with our Cybersecurity teams to leverage threat intelligence sources, identify new threats in the wild, and verify the organization's security posture by simulation and testing, leading to development of new SIEM detections.

What you will do: 

  • Provide finished threat analysis to develop Splunk ES Cloud SIEM platform and the overall detection use cases
  • When threats are identified, you will work closely with other areas of the security team to identify appropriate solutions
  • Proven ability to distill complex technical information into clear, concise yet comprehensive communication material
  • Leverage offensive security experience to coordinate the execution of cybersecurity solutions to benefit security engagements and mitigate cyber threats (Red and Blue team a plus) 
  • Improve operational efficiency by building and evaluating workflow processes, procedures, checklists, automation, and tooling
  • Experience assessing, securing, and managing cloud infrastructure (AWS, Azure, Oracle)
  • Hands-on experience analyzing and responding to security events, such as conducting log analysis, developing queries and analytics, troubleshooting security issues, and correlating complex data sets
  • Identifying trends, insights, and relationships between internal and external data and intelligence sources to provide recommended risk mitigation
  • Able to script and develop automations, preferably using Python

What you will bring: 

  • Minimum of 5 years previous information technology security operations, and threat detection
  • Significant experience with SIEM, IDS/IPS, firewall, web application, and security event correlation
  • Must have common knowledge of standard network infrastructure
  • Possess a breadth of knowledge and experience across the information security domain, with familiarity in a combination of endpoint, email, network, identity management, cloud security; vulnerability management; incident response; and threat intelligence
  • Recognize potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information
  • Experience in a highly complex technical environment, preferably within the financial services sector
  • Previous experience should include security operations and monitoring, and incident response
  • ​Familiar with Risk Based Alerting (RBA) frameworks and implementation
  • Bachelor s Degree (Computer Science or Information Systems) or equivalent applicable experience 
  • SANS/GIAC, OSCP or similar certifications

What will set you apart: 

  • Experience operationalizing the MITRE ATT&CK framework to improve security detection
  • Experience using Elastic, Splunk and/or other SIEMs
  • Experience with scripting languages, such a Python, for the purposes of automating security operations and incident response processes
  • Experience with reverse engineering, C2 exploitation, and broader system/network forensics
  • Security community contributions (blog posts, conference talks, CTFs, tool development, etc.) 
  • Knowledge of cloud infrastructure and cloud security in Azure or AWS
  • Understanding of log collection methodologies and aggregation techniques
  • Demonstrated working knowledge of information systems security standards and practices (e.g., access control and system hardening, system audit and log file monitoring, security policies, and incident handling) 
  • Coding experience a plus 
  • Understanding of security models and frameworks such as MITRE ATT&CK, cyber kill chain, and NIST CSF

***Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time, including CPT/OPT.***

What we offer you

We offer an array of diverse and inclusive benefits regardless of where you are in your career. We b

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Empower

View company profile →