Saint Petersburg, FL, 33747, USA
3 days ago
Lead Incident Response Analyst
**Job Description** _This position follows our hybrid-friendly schedule, so you get the best of both worlds – flexibility and collaboration. In office days will be 2-3 per week averaging 10-12 days per month._ **Job Summary** The financial services industry is constantly under attack by sophisticated cyber adversaries that range from nation states to criminals. In response, the Raymond James Cyber Threat Center (CTC) is charged with ensuring all equities are secure against all tiers of adversaries. We are the central hub for Computer Network Operations and are on the front lines of security incident response, threat hunting, and intelligence. You'll be working with emerging technologies to solve challenging security problems in a fast-paced and continuously evolving environment, while helping steer the direction and evolution of the team. This highly visible team within the organization evaluates threats to the environment and dynamically adjusts to the ever-changing threat landscape by applying practical security knowledge to developing new detective measures to protect the firm. **Responsibilities:** + Directs CTC Incident response analysts while contributing to the fulfillment of both the CTC’s mission and leadership’s vision. + Ensures continuity of mission between IR shifts + Serves as a primary member of the CTC who handles security events and incidents daily in a fast-paced environment. + Acts as an Incident Handler who can handle minor and major security incidents within the defined Computer Security Incident Response process. + Role embodies Cyber Network Defense and a successful Cyber Threat Analyst will be able to quickly analyze threats, understand risk, deploy effective countermeasures, make business-critical incident response decisions, and work as part of a team of individuals dedicated to protecting the firm. + Maintains situational awareness for cyber threats across the global firm and take action where necessary. + Daily responsibilities include, but are not limited to: o Countermeasure deployment across various technologies. o Malware and exploit analysis. o Intrusion monitoring and response. o Assessing alerts and notifications of event activity from intrusion detection systems and responding accordingly to the threat. o Continuing content development of threat detection and prevention systems. o Data analysis and threat research. o Creation of IR playbooks, and leading IR automation initiatives. o Coaching and mentorship of IR team peers. + Maintains knowledge of security principles and best practices. Must remain current with emerging threats and trends. + Assists teams in various security and privacy risk mitigation efforts; including incident response. + Leads information security related projects or in managing strategy. + Conduct forensic investigations for HR, Legal, or incident response related activities. + Develop new forensic detective and investigative capabilities using current technical solutions. + Work with various business units and technical disciplines in a security consultant, incident response subject matter expert role for cyber threats. + Shares in a weekly on-call rotation and acts as an escalation point for managed security services and associates of Raymond James. + Lead in detecting and analyzing security incidents, including attacks, breaches, and identified vulnerabilities, and remediate any security gaps in line with the security incident management procedure. + Design and implement disaster recovery and contingency plans to protect company data. + Explore and develop a detailed understanding of external developments or emerging issues and evaluate their potential impact on, or usefulness to, the organization. + Provide fault isolation and resolution for complex challenges to limit and address issues promptly. + Act as subject matter expert in an area of technology, policy, regulation, or operational management for the team. Maintain external accreditations and in-depth understanding of current and emerging external regulation and industry best practices through continuing professional development, attending conferences, and reading specialist media. + Develop procedures and interpret and apply policy for area of expertise to achieve specified outputs, or advise the wider business on application of policy, then monitor implementation of those procedures within the organization. + Manage and integrate emergency response procedures within several locations or an area. **Skills:** + Demonstrated ability to create complex scripts, develop tools, or automate processes in PowerShell, Python or Bash. + Knowledge of the following highly preferred: o Intrusion response and incident management lifecycle and processes. o Windows, Linux, memory forensics. o Log analysis (endpoint, network, email, cloud). o Knowledge of vulnerabilities and a comfort in manipulating exploit code for analysis. o Systems administration in Linux, Unix, Windows or OSX operating systems. o Forensic and analytical techniques. o Networking and the common network protocols. o Demonstrated ability to perform static and dynamic malware analysis. o Demonstrated ability to analyze large data sets and identify anomalies. o Demonstrated ability to quickly create and deploy countermeasures under pressure. o Familiarity with common infrastructure systems that can be used as enforcement points. o Basic securities industry information including concepts fundamental to working in the financial/securities industry. + Uses comprehensive knowledge and skills to act independently while guiding and training others on achieving full compliance with applicable rules and regulations in management and/or operations. + Works without supervision and provides technical guidance when required on acquiring, organizing, protecting and processing data to fulfill business objectives. + Works independently and provides guidance and training to others while interpreting and applying comprehensive knowledge of laws, regulations and policies in area of expertise. + Uses comprehensive knowledge and skills to work independently while providing guidance and training to others on analyzing data from multiple sources to draw appropriate conclusions and make suitable recommendations. + Uses comprehensive knowledge and skills to act independently while guiding and training others on monitoring, diagnosing and fixing technological problems. + Uses comprehensive knowledge and skills to act independently while guiding and training others on maintaining the security, integrity, compliance and continuity of IT systems and services. + Uses comprehensive knowledge and skills to act independently while guiding and training others on ensuring that IT applications meet required specifications by designing, executing and reporting on tests of systems and services. **Licenses/Certifications:** + Required to obtain within 1 year: SIE, CFCS, AWS Cloud Practitioner + Nice to have certifications: OSCP, OSCE, and/or SANS certifications **Education** Bachelor’s: Computer and Information Science, Bachelor’s: Information Technology **Work Experience** General Experience - 6 to 10 years **Certifications** **Travel** **Workstyle** Hybrid At Raymond James our associates use five guiding behaviors (Develop, Collaborate, Decide, Deliver, Improve) to deliver on the firm's core values of client-first, integrity, independence and a conservative, long-term view. We expect our associates at all levels to: • Grow professionally and inspire others to do the same • Work with and through others to achieve desired outcomes • Make prompt, pragmatic choices and act with the client in mind • Take ownership and hold themselves and others accountable for delivering results that matter • Contribute to the continuous evolution of the firm At Raymond James – as part of our people-first culture, we honor, value, and respect the uniqueness, experiences, and backgrounds of all of our Associates. When associates bring their best authentic selves, our organization, clients, and communities thrive. The Company is an equal opportunity employer and makes all employment decisions on the basis of merit and business needs.
Confirm your E-mail: Send Email