Threat Detection Architect Dallas or Detroit metro
Auburn Hills, MI, United States
Applications have closed
Comerica Incorporated
Comerica Incorporated (NYSE: CMA) is a financial services company headquartered in Dallas, Texas, and strategically aligned by three business segments: The Business Bank, The Retail Bank, and Wealth Management. Comerica focuses on...
Threat Detection Architect
The Threat Detection Architect is responsible for establishing and maintaining the detection targets / roadmaps and overseeing process / execution of detection content and use cases through collaboration with Operational and Engineering teams. The architect will perform analysis on and recommend solutions for detection gaps to build an ecosystem of robust detection rules across multiple security tools to address Cyber threats. The architect will provide subject matter expertise, mentorship, and leadership in the utilization of tools across the environment to complete and resolve the most complex security investigations. When needed, the architect will provide the highest level of technical capabilities and support across security tools in the environment to investigate, contain, and mitigate the impact of complex/critical security incidents. This role reports directly to the Director of Cyber Defense Operations.
The Cyber Defense Operations team is responsible for the protection, monitoring, detection, response, and recovery from security incidents across Comerica's environment. The team includes, amongst others, the Security Operations Center (SOC) and Threat and Vulnerability Management (TVM). The TVM team includes Cyber Fraud Operations, Threat Hunting, Threat Intelligence, and Vulnerability Management. The Threat Detection Architect role resides at the epicenter of these two core Cyber Defense teams, providing support to the SOC and TVM teams in the identification and creation of detection content and is ultimately responsible for the lifecycle of detection content. The ideal candidate will have Cybersecurity / IT certifications (e.g. CompTIA Network+, CompTIA Security+, GCIA, GCIH, GREM, or GPEN) Position Responsibilities: Threat Detection Architecture
The Threat Detection Architect is responsible for establishing and maintaining the detection targets / roadmaps and overseeing process / execution of detection content and use cases through collaboration with Operational and Engineering teams. The architect will perform analysis on and recommend solutions for detection gaps to build an ecosystem of robust detection rules across multiple security tools to address Cyber threats. The architect will provide subject matter expertise, mentorship, and leadership in the utilization of tools across the environment to complete and resolve the most complex security investigations. When needed, the architect will provide the highest level of technical capabilities and support across security tools in the environment to investigate, contain, and mitigate the impact of complex/critical security incidents. This role reports directly to the Director of Cyber Defense Operations.
The Cyber Defense Operations team is responsible for the protection, monitoring, detection, response, and recovery from security incidents across Comerica's environment. The team includes, amongst others, the Security Operations Center (SOC) and Threat and Vulnerability Management (TVM). The TVM team includes Cyber Fraud Operations, Threat Hunting, Threat Intelligence, and Vulnerability Management. The Threat Detection Architect role resides at the epicenter of these two core Cyber Defense teams, providing support to the SOC and TVM teams in the identification and creation of detection content and is ultimately responsible for the lifecycle of detection content. The ideal candidate will have Cybersecurity / IT certifications (e.g. CompTIA Network+, CompTIA Security+, GCIA, GCIH, GREM, or GPEN) Position Responsibilities: Threat Detection Architecture
- Establish and maintain threat detection coverage targets.
- Collaborate closely with the Threat Intelligence team to perform research on current threats and adversaries that target institutions similar to Comerica, to gain an understanding of current tactics, techniques, and procedures utilized.
- Conduct regular analysis of the current state of detection rules within Comerica's security suite of tools against the threat landscape to identify coverage gaps and areas for improvement.
- Perform innovative detection development through hypothesis and supporting research.
- Propose and ensure validation of detection rules, in collaboration with the SOC and TVM teams, to address coverage gaps and improve threat detection capability across the environment.
- Identify - evaluate vendors, products, and solutions to enhance threat detection.
- Participate in the testing and rollout of proposed rules across the environment to ensure that the quality of the implemented rule is appropriate for operationalization by the SOC.
- Upkeep and maintain the system of record for detection use cases, ensuring that it provides a live, up-to-date view of detection capabilities across the environment.
- Update MITRE ATT-CK mapping within the system of record, both to maintain alignment with updates to the MITRE ATT-CK framework and to provide an accurate depiction of detection coverage across the framework.
- Support response to major incidents by developing custom rules to detect anomalies, interfacing with the Threat Hunting and Threat Intelligence teams to do so.
- Collaborate with other Engineering and Operations teams within Comerica to troubleshoot, respond, and improve detection capabilities.
- Perform advanced technical and forensic analysis for payloads used by threat actors.
- Provide recommendations on remediation plans for critical incidents to minimize business impact and ensure continuity.
- Provide advanced subject matter expertise across malware, phishing, cloud access security brokers (CASB), network, and configuration compliance domains to investigate, contain, and mitigate the impact of complex/critical security incidents.
- Provide clear direction and documentation to Cyber Engineering teams to facilitate the development and implementation of detection rules into security tools.
- Maintain and provide accurate executive/compliance reporting on detection coverage, both against specific threats or techniques, as well as on the detection program as a whole.
- Participate in the development / enhancement of processes and technologies impacting the Cyber Defense Operations function.
- Handle sensitive information in accordance with the Corporate Information Protection Policy.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
2
0
0
Categories:
Architecture Jobs
Threat Intel Jobs
Tags: CASB Cloud Compliance CompTIA Cyber defense GCIA GCIH GPEN GREM Incident response Malware Monitoring SOC Threat detection Threat intelligence Vulnerability management
Region:
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Product Security Engineer jobsSecurity Operations Engineer jobsSenior Security Analyst jobsSystems Administrator jobsSenior Cybersecurity Engineer jobsSenior Information Security Analyst jobsCybersecurity Editor jobsCybersecurity Content Editor jobsCyber Security Specialist jobsInformation Security Manager jobsIT Security Analyst jobsSenior Network Security Engineer jobsSenior Information Security Engineer jobsSenior Product Security Engineer jobsInformation System Security Officer (ISSO) jobsSecurity Consultant jobsChief Information Security Officer jobsIT Security Engineer jobsInformation Systems Security Engineer jobsSecurity Specialist jobsSenior Cyber Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Software Engineer jobsCybersecurity Specialist jobsSenior IT Auditor jobs
EDR jobsTS/SCI jobsJava jobsEncryption jobsCEH jobsSplunk jobsTop Secret jobsSDLC jobsIDS jobsThreat detection jobsTerraform jobsIPS jobsMalware jobsFinance jobsRMF jobsSQL jobsDocker jobsForensics jobsSOC 2 jobsActive Directory jobsIntrusion detection jobsCompTIA jobsOWASP jobsITIL jobsTCP/IP jobs
HIPAA jobsCRISC jobsGIAC jobsAnsible jobsClearance Required jobsVPN jobsDoDD 8570 jobsMITRE ATT&CK jobsIT infrastructure jobsOSCP jobsJira jobsData Analytics jobsSOAR jobsDNS jobsSOX jobsJavaScript jobsBanking jobsUNIX jobsCCSP jobsIndustrial jobsZero Trust jobsCISO jobsGCIH jobsArtificial Intelligence jobsSANS jobs