*Hybrid 2 days in office 3 days remote*
A prestigious financial firm is on the search for an Associate Principal, Cyber Defense. This associate principal will lead cyber security incident responders, work on digital forensics, network security, application security, etc. This company ideally needs someone out of a large financial environment.
Lead cyber security incident responders in response activities including investigation, coordination, review, and reporting.
Oversee technical analysis of security events while coordinating incident response activities with internal and external teams.
Ensure and directly oversee the collection and preservation of data associated with cyber security incident response activities following industry best practices and established procedures.
Develop and support briefings to company senior management as a trusted incident responder.
Actively monitor and research cyber threats with a direct or indirect impact to the company brand, business operations, or technology infrastructure.
Oversee process of monthly reporting to Security management on and Incident management metrics.
Prioritize and identify security risks, threats and vulnerabilities of networks, systems, applications, and new technology initiatives.
Lead various teams to operationalize remediation efforts for gaps identified.
Develop and implement security monitoring roadmaps for company technologies, applications, SaaS, and other cloud-hosted solutions. These roadmaps will direct efforts on implementation of monitoring use cases and measurement of monitoring capabilities.
Security Device Administration
Incident Response playbook development managing incident analysis and remediation
Network sniffers and packet tracing tools (DSS, NAI SnifferPro, Ethereal and tcpdump).
Standard technical writing tools including MS Word, Excel, Project and Visio
Proxy and caching services.
Client Server platforms including Windows, Linux.
Operating system hardening procedures (, Linux, Windows, etc.)
Web Application Firewalls.
Security Orchestration and Automated Response tools and concepts.
Minimum three years of information security experience, preferably in the financial services industry.
Minimum two years hands-on security operations experience including interdisciplinary experience with four or more of the following: Cyber Threat Analysis, Digital Computer Forensics, Incident Response, Application Security, Operating Systems Security, Cryptographic Controls, Networking, Programming languages, Incident Response
Minimum one year in a leadership role or team/project lead capacity.
Familiarity with computer network exploitation and network attack methodologies.
working in an on-call response capacity is required including availability for 24 x 7 on-call support responsibilities
Strongly prefer at least one of the following certifications: CISSP, GCIA, GCIH, CHFI, GCFA, CCE, CFE