Essential Duties and Responsibilities
Serve as a primary member of the Cyber Threat Center (CTC) who handles security events and incidents on a daily basis in a fast-paced environment;
Act as an Incident Handler who can handle minor and major security incidents within the defined Computer Security Incident Response process;
As part of the Cyber Network Defense be able to quickly analyze threats, understand risk, deploy effective countermeasures, make business critical incident response decisions, and work as part of a team of individuals dedicated to protecting the firm;
Maintain situational awareness for cyber threats across the global firm and take action where necessary;
Maintain knowledge of security principles and best practices. Must remain current with emerging threats and trends;
Assist teams in various security and privacy risk mitigation efforts; including incident response;
Lead or participate in information security related projects or in managing strategy;
Conduct forensic investigations for HR, Legal, or incident response related activities;
Develop new forensic detective and investigative capabilities using current technical solutions;
Work with various business units and technical disciplines in a security consultant role for cyber threats;
Act as an escalation point for managed security services and associates of Raymond James;
Conduct daily responsibilities including, but not limited to:
Countermeasure deployment across various technologies;
Malware and exploit analysis;
Intrusion monitoring and response;
Assessing alerts and notifications of event activity from intrusion detection systems and responding accordingly to the threat;
Continuing content development of threat detection and prevention systems;
Data analysis and threat research; and
Limited weekend after-hours / on-call cyber threat support rotation may be required.
Qualifications
Knowledge, Skills, and Abilities
Knowledge of
Networking and the common network protocols;
Intrusion response and incident management lifecycle and processes;
Windows, Linux, memory forensics;
Log analysis (endpoint, network, email, cloud);
Vulnerabilities and manipulating exploit code for analysis;
Systems administration in Linux, Unix, Windows or OSX operating systems;
Common infrastructure systems that can be used as enforcement points; and
Current developments and trends in areas of expertise.
Skill in
Analysis: Identify and understand issues, problems and opportunities; compare data from different sources to draw conclusions;
Communication: Clearly convey information and ideas through a variety of media to individuals or groups in a manner that engages the audience and helps them understand and retain the message;
Exercising Judgment and Decision Making: Use effective approaches for choosing a course of action or developing appropriate solutions; recommend or take action that are consistent with available facts, constraints, and probable consequences;
Building Effective Relationships: Develop and use collaborative relationships to facilitate the accomplishment of work goals;
Client Focus: Make internal and external clients, and their needs, a primary focus of actions; develop and sustain productive client relationships.
Ability to
Perform static and dynamic malware analysis;
Analyze large data sets and identify anomalies;
Quickly create and deploy countermeasures under pressure; and
Create complex scripts, develop tools, or automate processes in PowerShell, Python or Bash;
Educational/Previous Experience Requirements
B.S. in Computer Science, Computer Engineering, MIS, or related degree;
A minimum of 5 years in Information Technology, including with at least 3 years of related experience in Information Security, 2 years in conducting Cyber Network Defense, and 3 years of experience with incident response methodologies, malware analysis, penetration testing, scripting and/or forensics; or
An equivalent combination of education, training and experience.
Licenses/Certifications
One or more of the following certifications or the ability to obtain within 1 year:
CISSP: Certified Information Systems Security Professional
SANS: GCIH - Incident Handler
SANS: GCIA - Intrusion Analyst
SANS: GCFE - Forensic Examiner
SANS: GNFA - Network Forensic Analyst
SANS: GREM - Reverse Engineering Malware
OSCP - Offensive Security Certified Professional
OSCE - Offensive Security Certified Expert