Jobs · OTHR · Arizona

Incident Response Lead Specialist, Vice President

MUFG · Tempe, AZ · 1 wk ago
On-siteOTHR$126k–$180k/yrFull-time

About the role

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.

The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.

Responsibilities

In this role you will focus on researching potential cybersecurity threats to various systems, technologies, operations, and programs throughout multiple environments. You will perform analysis based on this research to determine the risk to the organization and take appropriate actions based upon that analysis.

  • Conduct analysis of artifacts to determine methods of intrusion and best course of resolution while driving security improvement
  • Rapidly respond to potential incidents and events to minimize risk exposure and ensure the confidentiality, integrity, and availability of assets and business processes
  • Seek opportunities to strengthen remediation capabilities, reduce response times for incidents, and produce analyses of cybersecurity events that include perspectives on the behavior of adversaries
  • Investigate potential cybersecurity events across multiple environments using various tools and techniques
  • Develop information security policies, standards, and procedures
  • Support inquiries from compliance teams such as IT risk management and internal and external auditors to ensure documentation is complete and processes are in compliance with information security policies
  • Create reports analyzing activities or trends both within and outside of the organization
  • Support the development of security operations detections, playbooks, and automations to ensure threat detection, monitoring, response, and forensics activities align with best practices
  • Reviews internal logs and alerts to identify potential cybersecurity events
  • Monitors external service provider activity to detect potential cybersecurity events
  • Analyzes security data from all systems in real time to spot and thwart potential threats, attacks, and other violations
  • Performs breach indicator assessments to investigate network traffic for malicious activity
  • Assists with internal or third-party employee investigations
  • Assists in the production of various reports which identify and analyze relevant upcoming and ongoing threats to the enterprise
  • Research evolving threats, techniques, tools, and vulnerabilities in support of information security efforts
  • Stays current with information security program developments, industry frameworks, changes in the company, industry trends, and current security practices

Qualifications

  • 8 + years of experience working in the Cybersecurity Operations or Information Security
  • Relevant technical and industry certifications, such as CISSP, ISSMP, SANS, GIAC, GCIA, CISM, CEH, GCFA, GCFE, GCIH, or GSEC are preferred
  • Experience in one or more security domains including Incident Response and Forensics, Security Governance and Oversight, Security Risk Management, Network Security, or Threat and Vulnerability Management preferred
  • Experience with information security risk management, including information security audits, reviews, and risk assessments

Skills

  • Understanding of enterprise detection and response technologies and processes
  • Experienced with CrowdStrike, Torq, Tanium, Proofpoint, WAF, O365 security, AWS Security, and open-source incident response and forensic tools
  • Ability to perform risk analysis utilizing logs and other information compiled from various sources
  • Understanding of network protocols, operating systems (Windows, Unix, Linux, databases), and mobile device security
  • Knowledge in one or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, or Incident Response and Forensics
  • Knowledge of cloud security, networks, databases, and applications
  • Knowledge of the various types of cyber-attacks and their implementations
  • A fundamental understanding of enterprise cybersecurity frameworks such as MITRE ATT&CK and Cyber Kill Chain
  • Ability to document and explain technical details in a concise, understandable manner
  • Experience in operational processes such as security monitoring, data correlation, troubleshooting, security operations, etc.

Education

Bachelor's degree in Computer Science or a closely-related discipline, or an equivalent combination of formal education and experience

Pay

The typical base pay range for this role is $126k – $180k depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation.

Benefits

Our Total Rewards program provides colleagues with a competitive benefits package that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays.

Schedule

Our hybrid work schedule is four days on-site and work remotely one day per week.

Similar jobs

Incident Response Team Lead

Peterson Technology PartnersArlington Heights, IL· 3 wk ago
Information Technology$55–$70/hrapply on easyapply.petegabi.ai