Cybersecurity Operations Defense Analyst III

Buffalo, NY

M&T Bank

With a community bank approach, M&T Bank helps people reach their personal and business goals with banking, mortgage, loan and investment services.

View all jobs at M&T Bank

Apply now Apply later

The Bank sponsors individuals for TN and H-1B transfers on a case by case basis. Please note that this position is not open to anyone on an F-1 student visa including those eligible for CPT/OPT or the Stem OPT extension.

This role offers a hybrid work schedule; offering the flexibility to work remotely two days a week, while providing the opportunity for in-person collaboration at our Buffalo, NY Tech Hub.

Schedule:

Tuesday: 7am to 7pm

Thursday: 7am to 7pm

Friday: 7am to 7pm

*Employees also receive additional 4 hours of flex time to provide a total 40 hours per week

Overview:

Uses defensive measures and information collected from various sources to identify, analyze and report events occurring within the network to protect information, information systems and networks from threats.  Recognizes corollary or potentially-related events to identify trends and impacts to the organization's security posture and proactively mitigates associated risks.  Provides detailed reports, Standard Operating Procedures (SOPs) and documentation related to identified events and/or new processes.

Primary Responsibilities:

  • Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources.
  • Capture and analyze system and event logs associated with malicious activities using security monitoring tools.
  • Collect intrusion artifacts and use discovered data to enable mitigation of potential cyber defense incidents within the enterprise.
  • Complete static malware, threat and log analysis in coordination with past incident analysis data and/or current or emerging threat analysis.
  • Conduct research, analysis and correlation across all source data sets including indications and warnings.
  • Analyze incident data for security events and identify emerging trends and identify possible causes.
  • Maintain incident tracking and solution database and provide recommendations for training, tuning and optimization of processes.
  • Notify designated managers, cyber incident responders and appropriate stakeholders of suspected cyber incidents and articulate the event's history, status and potential impact for further action in accordance with the organization's cyber incident response plan.
  • Conduct independent analysis of log files, evidence and other information to determine best methods for identifying the perpetrator(s) of a network intrusion or other crimes in coordination with appropriate persons, teams, and stakeholders.
  • Provide timely notice of imminent or hostile intentions or activities impacting organization objectives, resources or capabilities.
  • Provide daily summary reports of network events and activity relevant to cyber defense practices as part of shift turnover activities.
  • Follow Cybersecurity SOPs and assist in creation, development and validation of current or new SOPs.
  • Understand and adhere to the Company’s risk and regulatory standards, policies and controls in accordance with the Company’s Risk Appetite.  Identify risk-related issues needing escalation to management.
  • Promote an environment that supports diversity and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.

Scope of Responsibilities:

Education and Experience Required:

Associates degree in an applicable discipline and a minimum of 2 years’ relevant work experience in two (2) or more of the following Cybersecurity domains:  Security and Risk Management, Asset Security, Security Engineering, Communication and Network Security, Identity and Access Management, Security Testing and Security Operations, or in lieu of a degree, a combined minimum of 4 years’ higher education and/or work experience, including a minimum of 2 years’  relevant work experience in two (2) or more of the following Cybersecurity domains:  Security and Risk Management, Asset Security, Security Engineering, Communication and Network Security, Identity and Access Management, Security Testing and Security Operations

Understanding of System Development Life Cycle (SDLC)

Detailed knowledge of application development support software and hardware platforms

Technical understanding of mainframe and/or distributed computing environments

Prior experience completing complex problem analysis and problem resolution

Prior experience quickly learning new technical skills and supporting systems, tools and processes

Experience with active participation in technical analysis walkthroughs

Education and Experience Preferred:

Bachelor’s degree in an applicable discipline

Minimum of 4 years’ relevant work experience in two (2) or more of the following Cybersecurity domains:  Security and Risk Management, Asset Security, Security Engineering, Communication and Network Security, Identity and Access Management, Security Testing and Security Operations

Knowledge of the Bank’s application development support software and hardware platforms

Experience researching and recommending application development support software and hardware platforms through an understanding of client area function and deliverable requirements for current and future-state planning

Technical experience with mainframe, virtual and/or distributed computing environments

Experience completing complex problem analysis and problem resolution

Knowledge of programming language syntax, with a focus on scripting-oriented languages (e.g., Python, PowerShell, etc.)

CYSA (Cybersecurity Analyst+ Certification) certification or applicable Cybersecurity domain-related industry-recognized certification

Ability to complete all shift work to support 24x7 team

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $28.48 - $47.46 Hourly (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.

LocationBuffalo, New York, United States of America
Apply now Apply later
  • Share this job via
  • 𝕏
  • or
Job stats:  1  0  0

Tags: Cyber defense IAM Incident response Log analysis Log files Mainframe Malware Monitoring Network security PowerShell Python Risk management Scripting SDLC STEM

Perks/benefits: Competitive pay Team events

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.