Senior Cyber Threat Analyst
Indexed description
Job Description
Essential Duties and Responsibilities
- Serve as a primary member of the Cyber Threat Center (CTC) who handles security events and incidents on a daily basis in a fast-paced environment;
- Act as an Incident Handler who can handle minor and major security incidents within the defined Computer Security Incident Response process;
- As part of the Cyber Network Defense be able to quickly analyze threats, understand risk, deploy effective countermeasures, make business critical incident response decisions, and work as part of a team of individuals dedicated to protecting the firm;
- Maintain situational awareness for cyber threats across the global firm and take action where necessary;
- Maintain knowledge of security principles and best practices. Must remain current with emerging threats and trends;
- Assist teams in various security and privacy risk mitigation efforts; including incident response;
- Lead or participate in information security related projects or in managing strategy;
- Conduct forensic investigations for HR, Legal, or incident response related activities;
- Develop new forensic detective and investigative capabilities using current technical solutions;
- Work with various business units and technical disciplines in a security consultant role for cyber threats;
- Act as an escalation point for managed security services and associates of Raymond James;
- Conduct daily responsibilities including, but not limited to:
- Countermeasure deployment across various technologies;
- Malware and exploit analysis;
- Intrusion monitoring and response;
- Assessing alerts and notifications of event activity from intrusion detection systems and responding accordingly to the threat;
- Continuing content development of threat detection and prevention systems;
- Data analysis and threat research; and
- Limited weekend after-hours / on-call cyber threat support rotation may be required.
- Networking and the common network protocols;
- Intrusion response and incident management lifecycle and processes;
- Windows, Linux, memory forensics;
- Log analysis (endpoint, network, email, cloud);
- Vulnerabilities and manipulating exploit code for analysis;
- Systems administration in Linux, Unix, Windows or OSX operating systems;
- Common infrastructure systems that can be used as enforcement points; and
- Current developments and trends in areas of expertise.
- Analysis: Identify and understand issues, problems and opportunities; compare data from different sources to draw conclusions;
- Communication: Clearly convey information and ideas through a variety of media to individuals or groups in a manner that engages the audience and helps them understand and retain the message;
- Exercising Judgment and Decision Making: Use effective approaches for choosing a course of action or developing appropriate solutions; recommend or take action that are consistent with available facts, constraints, and probable consequences;
- Building Effective Relationships: Develop and use collaborative relationships to facilitate the accomplishment of work goals;
- Client Focus: Make internal and external clients, and their needs, a primary focus of actions; develop and sustain productive client relationships.
- Perform static and dynamic malware analysis;
- Analyze large data sets and identify anomalies;
- Quickly create and deploy countermeasures under pressure; and
- Create complex scripts, develop tools, or automate processes in PowerShell, Python or Bash;
- B.S. in Computer Science, Computer Engineering, MIS, or related degree;
- A minimum of 5 years in Information Technology, including with at least 3 years of related experience in Information Security, 2 years in conducting Cyber Network Defense, and 3 years of experience with incident response methodologies, malware analysis, penetration testing, scripting and/or forensics; or
- An equivalent combination of education, training and experience.
- One or more of the following certifications or the ability to obtain within 1 year:
- CISSP: Certified Information Systems Security Professional
- SANS: GCIH – Incident Handler
- SANS: GCIA – Intrusion Analyst
- SANS: GCFE – Forensic Examiner
- SANS: GNFA – Network Forensic Analyst
- SANS: GREM – Reverse Engineering Malware
- OSCP – Offensive Security Certified Professional
- OSCE – Offensive Security Certified Expert
Work Experience
General Experience - 3 to 6 years
Certifications
Travel
Less than 25%
Workstyle
Hybrid
The total compensation for this position includes base salary or wages, and may include components such as additional compensation (cash or equity), discretionary bonuses, or commissions. This position is eligible for a benefits package that may include medical, dental, and vision; life insurance; critical illness insurance and accident insurance; disability benefits; retirement savings; paid time off (including vacation, holidays, and sick leave); and parental leave. Eligibility for benefits and specific offerings may vary based on position and employment status. To view more details of the benefits offered, visit Myrjbenefits.com.
At Raymond James our associates use five guiding behaviors (Develop, Collaborate, Decide, Deliver, Improve) to deliver on the firm's core values of client-first, integrity, independence and a conservative, long-term view.
We Expect Our Associates At All Levels To
- Grow professionally and inspire others to do the same
- Work with and through others to achieve desired outcomes
- Make prompt, pragmatic choices and act with the client in mind
- Take ownership and hold themselves and others accountable for delivering results that matter
- Contribute to the continuous evolution of the firm
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search