Information Security Analyst, Cyber Threat Incident Responder - Intermediate level
USAAAbout the role
Why USAA?
At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.
Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.
The Opportunity
The Cyber Threat Operations Center (CTOC) is USAA’s equivalent to a traditional Security Operations Center (SOC). The CTOC safeguards against cybersecurity threats targeting USAA. The CTOC comprises several teams supporting cyber threat intelligence, protection, monitoring, analysis, and response, all reporting under the Executive Director of Cyber Threat Operations.
USAA is seeking an Intermediate level Information Security Analyst, Cyber Threat Incident Responder for our External Threat Response (ETR) team supporting the CTOC’s efforts defending USAA’s assets against threats originating outside the environment. The ETR team reports to the Director of Cyber Threat Monitoring and Response. The team operates within defined guidelines and frameworks to identify security indicators of compromise (e.g., suspicious behavior, attacks, and security breaches) within USAA’s environment using a variety of cyber defense tools to detect, analyze, and respond to threats.
We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ or Colorado Springs, CO. Relocation assistance is not available for this position.
What you'll do:
- Maintains awareness of the latest critical information security vulnerabilities, threats, and exploits.
- Assists in conducting routine vulnerability management, security configuration assessments, and/or penetration testing operations.
- Monitors internal and external networks, systems, and applications for security anomalies and events (e.g. suspicious behavior, attacks, and security breaches).
- Assists in responding to cyber incidents, performing moderately complex analysis using security tools. Builds a broad range of knowledge, understanding, and experience (e.g. forensics, networking, servers, coding, etc.) to determine a malicious actor's tactics, techniques, and procedures.
- Under direct supervision, uses the discoveries from the incident response process to make basic improvements to the existing detection capabilities and security controls.
- Documents findings of completed alerts and assists with incident documentation.
- Serves as a resource to team members on escalated issues of a routine nature.
- Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.
What you have:
- Bachelor’s degree; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.
- 2 years of related experience in Information Security, Cybersecurity and/or Information Technology with a security focus to include accountability for moderately complex tasks and/or projects.
- 1 year of related experience in one of the following domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communications and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, Software Development Security.
- Developing level of business acumen in the areas of business operations, risk management, industry practices and emerging trends.
What sets you apart:
- Experience operating within a security operations center (SOC)
- Experience in cyber threat hunting, cyber threat monitoring, cyber threat intelligence, or cyber incident response
- Experience performing root cause analysis on security issues.
- Experience in responding to events/incidents in Windows, Linux, or MacOS environments
- Experience with enterprise logging technologies such as ELK or Splunk
- Experience with endpoint detection and response agents
- Experience with network analysis and endpoint containment
- Experience with scripting languages such as Python or PowerShell
- US military experience through military service or a military spouse/domestic partner
Compensation range: The salary range for this position is: $77,120 - $147,390.
USAA does not provide visa sponsorship for this role. Please do not apply for this role if at any time (now or in the
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s