Jobs and Careers
UN

Cyber Defense Analyst, Sr

United Bank
United Statesfull_timeVerifiedPosted 20 Aug 2024

About the role

Job Description

JOB SUMMARY:
•    The Senior Cyber Defense Analyst is a leader within United Bank’s Cyber Defense team.  This individual is responsible for engineering, managing, and providing oversight of major portions of United Bank’s Cyber Defense solutions; conducting complex technical analysis and oversight of security threat alerts and incident investigations; providing leadership, training, and guidance to junior team members. 

•    The Senior Cyber Defense Analyst’s primary areas of technical leadership, engineering, and oversight include threat response, threat monitoring and detection, and threat defense.

•    The Senior Cyber Defense Analyst’s will work closely with Cyber Defense Team members, Technical Services Teams and Information Security Team members to design and implement security controls and measures, manage incident response and investigations, and help develop and maintain security policies, governance documents, and procedures.

RESPONSIBILITIES:
Threat Response
•    Lead, oversee, and as required, perform cyber defense incident triage, tracking and documenting incidents from detection to resolution.
•    Utilize and enhance security solutions to respond, document and escalate events that may cause immediate impact to the environment.
•    Collect intrusion artifacts and use data to mitigate potential cyber defense incidents and enhance response processes.
•    Analyze malicious activity and determining weaknesses exploited, exploitation methods, and effects on systems and information.
•    Notify designated managers, cyber incident responders, and cybersecurity service provider team members of suspected incidents and recommend enhancements to enable mitigation and improve responses in accordance with the organization's cyber incident response plan.

 Threat Monitoring and Detection
•    Provide technical leadership and oversight in analyzing alerts from various sources to determine possible causes of such cyber security related alerts and incidents.
•    Provide technical leadership, oversight, to detect and identify possible attacks, anomalous activities, misuse activities, and distinguish them from benign activities.
•    Collaborate with Technical Services staff to validate network alerts and resolve incidents.
•    Provide technical leadership, oversight, and as required analyze log files to identify potential security threats and perform event correlation using information from different sources to gain situational awareness.
•    Monitor external data sources to maintain current knowledge of cyber defense threats and recommend enhancements to organization's cyber defense.

 Threat Defense
•    Engineer, manage and perform system administration on specialized cyber defense solutions.
•    Develop new defense-in-depth solutions and approaches and employ approved principles and practices.
•    Lead and manage authorized 3rd party penetration testing and vulnerability assessments.
•    Identify potential conflicts with cyber defense solution implementation and develop recommended solutions.
•    Engineer, build and administer test bed(s), perform proofs-of-concept, and evaluate cyber defense solutions.
•    Provide cybersecurity recommendations to leadership based on significant threats and vulnerabilities.
•    Lead cyber defense team members in strategic and tactical initiatives for threat response, detection, and protection.
•    Perform other duties as assigned.

Qualifications

SKILLS/QUALIFICATIONS:
•    Bachelor’s Degree in realted field and a minimum of five (5) years of IT work experience required; or twelve (12) years equivalent IT work experience required
•    Master’s degree preferred
•    Five (5) years cyber security work experience required
•    One or more of the following certifications is required; multiple are desired:
o    ISC2 CISSP
o    ISC2 CCSP 
o    ISC2 SSCP
o    EC-Council CEH
o    CCNP Security
o    CompTIA Security+
o    CompTIA CASP+
o    CompTIA CySA+
o    SANS GIAC GSEC
o    SANS GIAC GCIH
o    SANS GIAC GCIA
o    Microsoft Certified Azure Security Engineer Associate
o    Microsoft Certified Security Operations Analyst Associate
o    Microsoft Certified Cybersecurity Architect Expert
o    Microsoft Certified: Identity and Access Administrator Associate
•    Proven extensive experience with enterprise cyber security solutions such as AV/Endpoint protection solutions, Endpoint Detection and Response (EDR), Enterprise Firewalls, IPS/IDS, Log Management, or Security Information Event Management (SIEM) required.
•    Experience with Cisco ISE, TACACS, RADIUS, syslog, or VPN solutions required.
•    Experience with Vulnerability Management solutions such as Tenable Nessus, Rapid 7, Qualys, et

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

United Bank

View company profile →