Threat Management Senior Associate
DTCCAbout the role
Are you ready to make an impact at DTCC?
Do you want to work on innovative projects, collaborate with a dynamic and encouraging team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to crafting a workplace that looks like the world that we serve.
Pay and Benefits:
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
The Impact you will have in this role:
Technology Risk Management (TRM) is responsible for setting strategic direction in the areas of IT Risk and Information Security. Maintains corporate security policies and control standards, acts as a second line of defense via a robust collection of risk and control assessments, reports to leadership and the Board on the status of the IT Risk and Information Security Programs, acts as an operational arm for supervising threat intelligence, understanding when threats are being targeted against the firm, and responding to potential incidents, and serves as the main interface for Regulatory and Client reviews that focus on IT Risk and Information Security. Threat Management ensures security monitoring controls provide proper coverage, data quality, and efficiency to improve DTCC's ability to accurately identify current cyber threats, monitor, and detect suspicious activities or instances of data loss.
Your Primary Responsibilities:
- Responsible for security detection content used by Cyber Monitoring Incident Response Team in support of established security monitoring requirements.
- To define and enhance cyber monitoring capabilities for the organization, maintain security alert definition portfolio for all systems and application use cases, and translate security monitoring requirements into relevant cyber security alerting.
- Maintain security by monitoring and ensuring compliance to standards, policies and procedures, conducting incident response analyses, developing and conducting training programs.
- Perform analysis of historical security alerts and incidents for further improvement or modification of use cases to ensure alert precision and low false positive rate.
- Provide support for the Cyber Monitoring Incident Response Team for forensic analysis of network packet captures, Domain Name System (DNS), proxy, NetFlow, malware, host-based security, and application logs, as needed during active investigations.
- Support the preparation of reports that goes out to customers and senior management.
- Participate in remediation and alignment meetings with IT teams.
- Conduct testing on the effectiveness of host and network-based security monitoring controls.
- Researches and understands a wide variety of information systems and new technologies.
- Perform quality assurance on the data consumed by security monitoring controls.
Qualifications:
- Minimum of 6 years of related experience
- Degree in Computer or Software Engineering, Computer Science, Information Management, Information Science or equivalent hands-on work experience.
- Solid understanding of the Cyber Kill Chain, MITRE ATT&CK Framework and campaign strategies.
- Solid understanding of common security technologies (e.g., firewalls, IDS/IPS, WAF, threat analytic platforms, SIEM, Database monitoring platforms, host based and network based forensic tools, email gateways, web proxies/filtering end point anti-virus, etc.).
- Demonstrable understanding of various SIEM concepts such as correlation, aggregation, normalization, and parsing.
- Demonstrated ability to communicate effectively with business and technical audiences across all levels of an organization.
- Strong knowledge and understanding of networking including IP, TCP/UDP, and common application layer protocols (E.g. HTTP, HTTPS, SSL, FTP).
- Security knowledge across multiple security domains and technologies (e.g., operating systems, databases, networking, applications, identity and access management).
- Experience working with threat intelligence reports, IOAs, IOCs, TTPs.<
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s