Jobs and Careers
JP

Security Operations Senior Associate

JPMorgan Chase & Co.
United Statesfull_timeVerifiedPosted 21 May 2024

About the role

Seize the opportunity to enhance cybersecurity, utilizing your skills in threat analysis and incident response to protect vital data and systems.

As a Security Operations Senior Associate in Cybersecurity &and Technology Controls organization, you will play an important role in safeguarding the organization's digital assets and infrastructure by proactively detecting, assessing, and responding to threats, vulnerabilities, and security incidents. Drawing on your knowledge of security principles, practices, and theories, you will collaborate with cross-functional teams to develop a coordinated approach to security and educate employees on best practices, policies, and procedures. Your work will have a direct impact on departmental outcomes, as you plan and ensure progress, identify gaps in information, and conduct analyses to solve complex cybersecurity problems. By utilizing your advanced analytical, technical, and problem-solving skills, you will contribute to the continuous improvement of our cybersecurity posture and help maintain the integrity, confidentiality, and availability of sensitive data and systems.

Job responsibilities

Vulnerability Management Operations - Response Analyst, you will be a key member of the North America team, as part of a follow-the-sun global team. You will work directly with Line of Business Application Teams, Subject Matter Experts, Production Management Teams, Product Owners, Senior Technology Management, External Vendors and Risk and Control functions on:

  • Review new vulnerabilities published from multiple sources and identify those that may pose risk to the firm. 
  • Define an accurate risk rating in line with proprietary and industry standard risk rating methodologies. 
  • Identify the impacted assets and/or application(s) at risk.
  • Document the vulnerability providing a detailed write up on the risk and exposure.
  • Confirm any risk mitigation factors and define the remediation activity if known.
  • Assess exploit code and/or conceptual code to determine attack vectors. 
  • Recommend any risk mitigation factors and define the remediation activity if known.
  • Assess security researcher identified vulnerabilities to provide recommendations on remediation and identify additional risk
  • Monitor and analyze security infrastructure, contributing to detection and response to threats, vulnerabilities, and incidents to ensure the integrity, confidentiality, and availability of sensitive data and systems
  • Conduct in-depth security investigations, analyzing logs, network traffic, and other data sources to identify root causes, assess impact, and gather evidence for response and mitigation actions
  • Develop and maintain threat detection and response playbooks, incorporating industry best practices, regulatory requirements, and lessons learned from previous incidents

Required qualifications, capabilities, and skills

  • 3+ years of experience in cybersecurity operations, including threat detection, incident response, and vulnerability management
  • Demonstrated experience in network traffic analysis, log analysis, vulnerability analysis, exploitation, and security investigation techniques to identify and respond to security incidents.  A strong knowledge of operational processes supporting Vulnerability Management and the wider SOC; with the ability to demonstrate comprehension of the end-to-end Vulnerability Management workflow (to include industry standards such as CVE, CPE, CVSS).
  • Proficiency in scripting to automate tasks, implement controls, and manipulate data
  • Proven experience in command & control practices like Incident Management and/or Cyber incident response methodologies. 
  • Strong and broad understanding of Cyber Security Controls (Physical, Logical, Processes and Procedures)
  • Strong and broad understanding of leading vendor products/applications e.g., Oracle [Java], VMWare, F5, Citrix, Microsoft; to include product lifecycle & release schedules.
  • Strong and broad understanding of open-source software deployment in a large technology estate. 
  • Strong understanding of Cloud and Public/Private Cloud environments.   
  • Familiarity with Cyber scanning tools including Qualys, Snyk, CrowdStrike, and other tools is an advantage.
  • Experience with Agile and experience working to manage remediation actions via an active backlog and Jira an advantage. 
  • Previous 24 x 7 operations experience.

Preferred qualifications, capabilities, and skills

  • Experience of working with data sources via SQL, JSON, APIs and Splunk will be highly beneficial.


 

JPMorgan Chase & Co., one of the oldest financial institutions, offers innovative financial solutions

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

JPMorgan Chase & Co.

View company profile →