Insider Threat Engineer
CityScape, United States
Western Alliance Bank
Western Alliance Bank offers a wide range of commercial and business banking solutions including loans, lines of credit, and more. Get in touch with us today.Job Title:
Insider Threat EngineerLocation:
CityScapeWhat you'll do:
Western Alliance Bank’s (WAB) Business Information Security Office is responsible for analyzing and conducting assessments of insider related threats and vulnerabilities identified by the WAB Insider Risk Program, including policy violations, system alerts, and other reported threats to the confidentiality, integrity, and availability of information assets. The role will coordinate investigations involving a variety of highly technical and/or business functional stakeholders across the WAB enterprise. This is key to ensuring the proactive management of insider-related risk services in compliance with Western Alliance Bank policies, standards, and frameworks.This individual will work as part of a matrixed team of cybersecurity professionals in a structure designed to help them succeed in delivering best-in-class security to this stakeholder group.
- Facilitate/conduct investigations by analyzing and verifying information through various investigative techniques, internal resources, forensics, and Insider threat tools such as Data Loss Prevention, Endpoint Detection and Response, Network Traffic Analysis & Deceptive Technology to detect malicious lateral movement & privilege escalation in On-prem and Cloud environment.
- Provide actionable Insider threat analysis for remediation on all escalations.
- Triage Insider Threat alerts within SLA guidelines.
- Collaborate with internal teams to drive insider threat program continuous improvement.
- Assess and make recommendations for improvement and refinement of use cases, software tools, and other risk reduction methods used to improve the insider threat program.
- Proven experience using analytical and data visualization tools to automate the analysis and provide insights of large dataset and correlate with Elastic SIEM and other sources of information and conduct investigative works into anomalies against established baselines to identify the root cause of an incident or suspicious event.
- Stay current with the latest cyber threats, attacks, and vulnerabilities, and updated with evolving and emerging attack techniques and methods.
- Maintain and update related insider threat documentations such as IT Standards and Standard Operation Procedures and carry out activities specified in these artifacts.
- Participate in various cybersecurity exercises such as cyber tabletop and BCP.
What you'll need:
- Bachelor’s degree from a four-year college or university and eight (8) or more years of related experience and/or training; or a combination of experience and education:
- Work related experience must consist of an information security experience as an insider threat analyst, or security engineer, or a similar role, preferably with insider threat management experience in a Financial Institution environment.
- Educational experience, through in-house training sessions, formal school, or information security related curriculum, should be information security related.
- Hands on experience with investigative and/or insider threat tools, such as UEBA, DLP, EDR, Computer Forensics, Monitoring, Elastic SIEM, Incident Response, Databases, or data visualization tools in On-prem and Cloud environment.
- Understanding and/or working knowledge of insider threats in the Dark and Deep Web underground forums.
- Strong practical experience in cybersecurity: CMU Insider Threat Framework, MITRE ATT&CK Framework, Cyber kill chain, TTP, threat intelligence, malware triage.
- Strong understanding of Different Attacks on system, network, applications.
- Relevant industry certifications such as Elastic SIEM certification, CERT, CFE, CFCE, CISSP, GCIH, SANS, GIAC.
- Possess strong analytical skills, self-motivated, detail oriented and team player.
- Willing to learn and work in a collaborative manner with peers and team.
- Good interpersonal and communication skills.
- Able to work under pressure during critical situations.
- A passion for cybersecurity and data security.
Benefits you’ll love:
We offer all the important things you'd want — like competitive salaries, an ownership stake in the company, medical and dental insurance, time off, a great 401k matching program, tuition assistance program, an employee volunteer program, and a wellness program. In addition, you’ll have the opportunity to bolster your business knowledge, learning the ins and outs of how successful companies operate and manage their finances, giving you invaluable hands-on experience to help grow your career!
About the company:
Western Alliance Bank is a wholly owned subsidiary of Western Alliance Bancorporation. Alliance Bank of Arizona, Alliance Association Bank, Bank of Nevada, Bridge Bank, First Independent Bank, and Torrey Pines Bank are divisions of Western Alliance Bank; Member FDIC. AmeriHome Mortgage is a Western Alliance Bank company.
Western Alliance Bancorporation is committed to equal employment and will consider all qualified applicants without regard to race, sex, color, religion, age, nation origin, marital status, disability, protected veteran status, sexual orientation, gender identity or genetic information. Western Alliance Bancorporation is committed to working with and providing reasonable accommodations for individuals with disabilities. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process and/or need an alternative method of applying, please email HR@westernalliancebank.com or call 602-386-2488. When contacting us, please provide your contact information and state the nature of your accessibility issue. We will only respond to inquiries concerning requests that involve a reasonable accommodation in the application process.
© Western Alliance Bancorporation
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: CERT CFCE CISSP Cloud Compliance Cyber Kill Chain EDR Forensics GCIH GIAC Incident response Malware MITRE ATT&CK Monitoring SANS SIEM Threat intelligence Vulnerabilities
Perks/benefits: Career development Insurance Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.