Sr. Information Security Analyst – Cyber Threat Management (CrowdStrike/Splunk)
320 Front Street West Insurance, Toronto, Ontario, Canada
Full Time Senior-level / Expert USD 76K - 115K
TD
Explore what TD Canada Trust is all about. Learn about our values, initiatives, reporting, news, careers, recent awards, and more.Work Location:
Toronto, Ontario, CanadaHours:
37.5Line of Business:
Technology SolutionsPay Details:
$76,800 - $115,200 CADThis role is eligible for a discretionary variable compensation award that considers business and individual performance.TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Job Description:
Job Description
- Real-time analysis on identified cyber incidents currently impacting the bank’s operations.
- Analyze and remediate security incidents internally, malware investigation, windows forensics and network traffic analysis.
- Manage incident queue in internal ticketing system in a timely and accurate manner in order to resolve a multitude of information security related situations and ensure that intake of incidents and reports from internal customers are properly recorded, timely updated, followed up and closed as per agreed SLA level ensuring quality and accurately in reporting.
- Identify potential gaps and provide solutions to mitigate threats and protect the Bank. They participate in projects of moderate to high complexity and provide complex reporting, analysis, and assessments at the functional, business line or enterprise level for own area.
- The Senior Information Security Analyst will be responsible for managing information between multiple technical teams, the CSOC, ASR and ITS, LOB TS when appropriate.
- The personnel in this role will work as part of a cyber security operations team responsible for carrying out 24x7 security monitoring operations. Operations are carried out on a rotating shift schedule than involves occasional on-call and/or weekend support.
Job Requirements
Knowledge and Skills:
- In depth understanding of security controls/mechanisms and threat/risk assessment techniques pertaining to complex data, application and networking environments.
- Organizational and self-directing skills – ability to initiate, coordinate and prioritize responsibilities and follow through on tasks to completion. Ability to collaborate with the team and coordinate activity for cyber security investigations.
- An approach to work that includes initiative, sound judgment, diplomacy and discretion.
- Ability to work independently on a variety of assignments with minimal supervision.
- Expert knowledge of security incident and event management using an enterprise incident management framework, log analysis, network traffic analysis, malware investigation and remediation, SIEM correlation logic and alert generation.
- Ability to perform analysis and reporting on information from multiple data sources using data mining technique for the purpose of documenting analysis results, produce report and present to a technical and executive stakeholders.
- Understanding of Security principles, techniques and technologies such as NIST Cybersecurity Framework, SANS Top 20 Critical Security Controls and OWASP Top 10, MITRE Attack.
- Basic programming skills in various disciplines including scripting languages, PowerShell.
- Expert knowledge of SIEM and UEBA solutions such as Splunk, Azure Sentinel or similar, along with experience of CrowdStrike, MS Defender for Endpoint, XSOAR.
- Expert knowledge of forensics tools such as Encase, Axiom, Autospy, OSForenscis, FTK imager or similar.
- Demonstrate expert knowledge in Enterprise IT operations, incident management, change management, Access/Identity Management, security operations, vulnerability and compliance management, ticketing system, incident ticket life cycle and SLA terms.
- 3+ years of Information Security Operations or similar working experience
Background and Education:
- Completion of a Bachelor’s degree or equivalent program in Computer Science, Management Information Systems or similar field is required.
- Completion of a Master's degree or equivalent program in Computer Science, Management Information Systems or similar field is preferred.
Bonus:
Certifications: GIAC (GCIA, GPEN, GWAPT, GCIH, GSEC, GCFA), CCNP, CCNA, CISSP, Cloud security
Who We Are:
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you’ve got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we’re here to support you towards your goals. As an organization, we keep growing – and so will you.
Our Total Rewards Package
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more
Additional Information:
We’re delighted that you’re considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we’re committed to providing the support our colleagues need to thrive both at work and at home.
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
Colleague Development
If you’re interested in a specific career path or are looking to build certain skills, we want to help you succeed. You’ll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD – and we’re committed to helping you identify opportunities that support your goals.
Training & Onboarding
We will provide training and onboarding sessions to ensure that you’ve got everything you need to succeed in your new role.
Interview Process
We’ll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
Accommodation
Your accessibility is important to us. Please let us know if you’d like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.
We look forward to hearing from you!
Language Requirement (Quebec only):
Sans ObjetTags: Azure Banking CCNP CISSP Cloud Compliance Computer Science CrowdStrike CSOC EnCase Forensics GCFA GCIA GCIH GIAC GPEN GSEC GWAPT Log analysis Malware Monitoring NIST OWASP PowerShell Risk assessment SANS Scripting Sentinel SIEM SOAR Splunk Strategy Windows XSOAR
Perks/benefits: Career development Competitive pay Flex hours Health care
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.