The role is to provide an effective and proactive response to cybersecurity-related events and incidents to protect QBE’s assets and services.
In addition, the role will support business stakeholders in the event of a security incident, and support incident management and escalation processes to the appropriate incident management teams.
We are looking for Tier 1 level support that will investigate a diverse set of alerts. The role should adapt to any changes in security operations to comply with various business requirements.
Job Description
Be part of a globally distributed team (24x7) that will use several security tools (e.g., SIEM, email triage platform, cloud security tooling, EDR solutions, etc) to investigate suspicious events.Proactively monitor and respond to suspicious or true positive incidents across our security platforms. Perform initial incident analysis of various security alerts by analysing and investigating security-related logs harvested from various security signals.Provide recommendations and initial assessments to Tier 2 resources for deeper analysis and triage.Perform timely escalation of cybersecurity incidents to Tier 2 resources and incident responders using incident management tools and other available channels.Conduct research using various proprietary and open-source tools to identify current and emerging threats and risks to QBE.Provide assessment and recommendations to mitigate potential threats or suppress any occurring false positive alerts.Perform ad-hoc tasks and completion of goals relating to ongoing projects and initiatives.Generating reports and providing insights on the efficacy of the current security tools, incident responses, procedures, and other security-related information.Required knowledge and skills:
Bachelor's degree in computer science, programming, or IT-related field. Fresh graduates are welcome to apply.The ability to work in a fast-paced and time-sensitive role.Be able to communicate effectively and update various stakeholders globally.Proactive, analytical, and able to solve complex investigations.Understanding of known threat actors, techniques, and procedures that modern attackers use to compromise organisations.Advantage, but not required knowledge and skills:
1-3 years relevant security experience performing similar duties working in a Security Operation Centre, Cybersecurity, and other IT-related fields.Advanced training or certifications (e.g., ISC2, ISACA, SANS, Azure, etc.)Knowledge of security solutions and technologies like Windows, Linux, IPS/IDS, Firewalls, Email gateways, proxy technologies, cloud solutions, endpoints, and mobile devices.Be able to perform correlations and analytics with diverse types of logs, i.e., network, active directory, database, DNS, firewalls, proxies, host-based security, cloud, and applications logs.Benefits in joining our team:
Be part of a global team and enrich your cybersecurity technical skills from subject matter experts.Tailored professional development. Exclusive access to industry-leading training platforms.Opportunity to get firsthand experience across industry-leading security tools.We are a team that values diversity and inclusion.US Only - Travel Frequency
• Infrequent (approximately 1-4 trips annually)
US Only - Physical Demands
• General office jobs: Work is generally performed in an office environment in which there is not substantial exposure to adverse environmental conditions. Must have the ability to remain in a stationary position for extended periods of time. Must be able to operate basic office equipment including telephone, headset and computer. Incumbent must be able to lift basic office equipment up to 20 lbs.
US Only - Disclaimer
• To successfully perform this job, the individual must be able to perform each essential job responsibility satisfactorily. Reasonable accommodations may be made to enable an individual with disabilities to perform the essential job responsibilities.
Job Type
• Individual Contributor
Australia/New Zealand Only - Advice/Non-Advice
• Non-Advice: This role is not authorised to provide financial product advice to retail customers in respect of General Insurance products. Financial product advice, means a statement or recommendation made to a retail customer with the intention of influencing their decision in considering a general insurance product.
Global Disclaimer
• The duties listed in this job description do not limit the assignment of work. They are not to be construed as a complete list of the duties normally to be performed in the position or those occasionally assigned outside an employee’s normal duties. Our Group Code of Ethics and Conduct addresses the responsibilities we all have at QBE to our company, to each other and to our customers, suppliers, communities and governments. It provides clear guidance to help us to make good judgement calls.
Skills:
Adaptability, Business Continuity, Communication, Critical Thinking, Customer Service, Cybersecurity Risk Management, Digital Forensics, Forensic Investigations, Intentional collaboration, Malware Analysis, Managing performance, Process Improvements, Reporting and Analysis, Risk Management, Stakeholder ManagementHow to Apply:
To submit your application, click "Apply" and follow the step by step process.
Equal Employment Opportunity:
QBE is an equal opportunity employer and is required to comply with equal employment opportunity legislation in each jurisdiction it operates.