Senior Information Security Analyst (Incident Response)
This is a remote role that may be hired in several markets across the United States.
About the role
As a member of the bank's Cyber Incident Response team, you'll be an experienced senior-level analyst with proven skills to detect and respond to threats in the environment, interact with business stakeholders, and work to restore operations. This technical role supports Threat Hunting, Intelligence, and Monitoring functions with content creation, threat analysis, detection recommendations, and colleague mentoring. Strong communication skills are essential to distill complex issues for broader understanding and expedited incident management.
Responsibilities
- Investigate SIEM/SOAR events; apply malware analysis, network/endpoint security expertise to respond to and contain incidents.
- Lead incidents as Incident Responder/Incident Lead, coordinating investigation, mitigation, and remediation from a technical perspective while liaising with technical and business stakeholders.
- Ensure Information Security incidents are properly detected, documented, investigated, and resolved.
- Support the creation of countermeasures and mitigations in response to incidents.
- Contribute to threat hunting with operational-driven inputs (e.g., post-incident or event) and build countermeasures/mitigations to address commodity and targeted threats, including tracking evolving threat actor techniques.
- Provide post-incident recommendations to improve communication, processes, procedures, and mitigation options based on high-severity incidents.
Requirements
- Bachelor's Degree and 8 years of experience in Information Security OR High School Diploma or GED and 12 years of experience in Information Security.
- Experience with all aspects of Incident Response, including stakeholder management.
- 2+ years of Threat Hunting experience; familiarity with MITRE ATT&CK and its application to countermeasure creation is a plus.
- Experience analyzing, dispositioning, and escalating security events (systems, application, network, authentication, email events).
- Ability to translate threat actor techniques into mitigations across security technologies (e.g., Yara, Sigma, or Regular Expressions).
- Ability to define security requirements and drive project deliverables.
- Experience managing multiple incidents and ensuring timely responses.
- Experience responding to cloud-related incidents in Azure, AWS, and Google Cloud; cloud administrative experience preferred.
- 3+ years of Cyber Incident Response experience in a primary Incident Response role.
This role requires participation in an after-hours on-call rotation, cycling on a weekly basis.
Pay
The base pay for this position is generally between $140,000 and $188,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.
Benefits
Benefits are an integral part of total rewards. First Citizens Bank is committed to providing a competitive, thoughtfully designed, and quality benefits program. More information can be found at https://jobs.firstcitizens.com/benefits.