CareerRiver

Incident Response Lead Specialist, Vice President

MUFG · Arizona

📍 Tempe, AZvia workday
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to MUFG.
Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world. With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career. Join MUFG, where being inspired is expected and making a meaningful impact is rewarded. The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details. Job Summary    In this role you will focus on researching potential cybersecurity threats to various systems, technologies, operations, and programs throughout multiple environments. You will perform analysis based on this research to determine the risk to the organization and take appropriate actions based upon that analysis. Responsibilities include rapidly responding to potential incidents and events to minimize risk exposure and ensure the confidentiality, integrity, and availability of assets and business processes. Additionally, you will seek opportunities to strengthen remediation capabilities, reduce response times for incidents, and produce analyses of cybersecurity events that include perspectives on the behavior of adversaries.  Major Responsibilities  Conduct analysis of artifacts to determine methods of intrusion and best course of resolution while driving security improvement  Strong Incident Response knowledge and experience Theoretical and practical knowledge with Mac OS, Linux, Windows operating systems and clouds such as AWS Experience with security data collection, analysis and correlation  Well-developed analytic, qualitative, and quantitative reasoning skills   Demonstrated creative problem-solving abilities  Security event monitoring, investigation, and overall incident response process  Investigate potential cybersecurity events across multiple environments using various tools and techniques  Development of information security policies, standards, and procedures  Strong time management skills to balance multiple activities and lead junior analysts as needed  Understanding of offensive security to include common attack methods  Understanding of how to pivot across multiple datasets to correlate artifacts for a single security event   A diverse skill base in both product security and information security including organizational structure and administration practices, system development and maintenance procedures, system software and hardware security controls, access controls, computer operations, physical and environmental controls, and backup and recovery procedures.  Detailed knowledge and experience in security and regulatory frameworks (ISO 27001, NIST 800 series, FFIEC, SOC2, FedRAMP, STAR, etc.)  Support inquiries from compliance teams such as IT risk management and internal and external auditors to ensure documentation is complete and processes are in compliance with information security policies  Create reports analyzing activities or trends both within and outside of the organization  Support the development of security operations detections, playbooks, and automations to ensure threat detection, monitoring, response, and forensics activities align with best practices, minimize gaps in detection and response, and provide comprehensive mitigation of threats  Reviews internal logs and alerts to identify potential cybersecurity events. Triage cases based on output from automated alerts, and determine when to escalate to other teams  Monitors external service provider activity to detect potential cybersecurity events  Analyzes security data from all systems in real time to spot and thwart potential threats, attacks, and other violations  Analyzes compromised systems and remediates to a clean state  Performs breach indicator assessments to investigate network traffic for malicious activity  Assists with internal or third-party employee investigations  Assists in the production of various reports which identify and analyze relevant upcoming and ongoing threats to the enterprise  Research evolving threats, techniques, tools, and vulnerabilities in support of information security efforts  Stays current with information security program developments, industry frameworks, changes in the company, industry trends, and current security practices  Qualifications  8 + years of experience working in the Cybersecurity Operations or Information Security  Relevant technical and industry certifications, such as CISSP, ISSMP, SANS, GIAC, GCIA, CISM, CEH, GCFA, GCFE, GCIH, or GSEC are preferred  Experience in one or more security domains including Incident Response and Forensics,  Security Governance and Oversight, Security Risk Management, Network Security, or Threat and Vulnerability Management preferred  Experience with information security risk management, including information security audits, reviews, and risk assessments Desired Skills  Understanding of enterprise detection and response technologies and processes (advanced threat detection tools, intrusion detection/prevention systems, network packet analysis, endpoint detection and response, firewalls, Anti malware/anti-virus, Security Information and Event Management tools, etc.)  Experienced with CrowdStrike, Torq, Tanium, Proofpoint, WAF, O365 security, AWS Security, and open-source incident response and forensic tools  Ability to perform risk analysis utilizing logs and other infor

More Arizona jobs

Arizona jobs · Browse all locations