Senior Information Security Analyst (Incident Response)
This is a remote role that may be hired in several markets across the United States.
About the role
As a member of the bank's Cyber Incident Response team, you'll be an experienced senior-level analyst with proven skills to detect and respond to threats in the environment, interact with business stakeholders, and work to restore operations. This technical role supports Threat Hunting, Intelligence, and Monitoring functions with content creation, threat analysis, detection recommendations, and colleague mentoring. Strong communication skills are essential to distill complex issues for broader understanding and expedited incident management.
Responsibilities
- Incident Analyst/Handler – Investigate SIEM/SOAR events as necessary; bring experience in malware analysis, network/endpoint security to respond to and contain incidents.
- Incident Responder/Incident Lead – Lead incidents, coordinating investigation, mitigation, and remediation from a technical perspective. Liaise with technical and business stakeholders.
- Incident Management – Ensure Information Security incidents are properly detected, documented, investigated, and resolved.
- Content Development – Support the creation of countermeasures and mitigations in response to an incident.
- Threat Hunting – Support operational-driven inputs (e.g., on the heels of an incident or event) into threat hunting and help build countermeasures/mitigations to address commodity and targeted threats. Build capability to track evolving threat actor techniques.
- Post-Incident Review – Provide recommendations to improve communication, processes, procedures, and mitigation options based on high-severity incidents.
Requirements
- Bachelor's Degree and 8 years of experience in Information Security OR High School Diploma or GED and 12 years of experience in Information Security.
- Experience with all aspects of Incident Response, including stakeholder management.
- 2+ years of Threat Hunting experience. Familiarity with MITRE ATT&CK and its application to countermeasure creation is a plus.
- Experience analyzing, dispositioning, and escalating security events (systems, application, network, authentication, email events).
- Experience translating threat actor techniques to building mitigations across a variety of security technologies (e.g., Yara, Sigma, or Regular Expressions).
- Ability to define security requirements and drive project deliverables.
- Ability to keep track of multiple incidents and ensure timely responses.
- Experience responding to cloud-related incidents in Azure, AWS, and Google Cloud. Cloud administrative experience preferred.
- 3+ years of Cyber Incident Response experience in a primary Incident Response role.
- Participation in the after-hours on-call rotation (rotations cycle on a weekly basis).
Pay
The base pay for this position is generally between $140,000 and $188,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.
Benefits
Benefits are an integral part of total rewards. First Citizens Bank is committed to providing a competitive, thoughtfully designed, and quality benefits program. More information can be found at https://jobs.firstcitizens.com/benefits.