Job DescriptionThe Impact you will have in this role: Being a member of CISO team, reporting to a Cyber Monitoring & Incident Response Manager, you are responsible for detecting, analyzing, and responding to cyber security events. As a technical lead, you lead detecting, investigating, and responding to cyber security events in the organization. You are a member of the Cyber Monitoring and Incident Response Team (CMIR) and qualified to act as Incident Commander on serious incidents, as a result may be tasked with responding to cyber incidents outside of normal work hours. You are also responsible for leading certain programs and initiatives within the Cyber Monitoring as well as assisting in measuring and improving team performance and processes.
Your Primary Responsibilities:- Monitor, Detect, Analyze, research, and respond to cyber security events including Network events, OS Log events and forensic information.
- Act as an escalation point for junior team members.
- Lead and coordinate major investigations and incident response activities.
- Act as Incident Commander for serious incidents.
- Perform eDiscovery and other technical tasks.
- Independently lead technical programs and large projects.
- Train and mentor junior staff members.
- Work with management and QA/QC lead to improve the overall performance of the team.
- Work with the Content Development Team to implement content and tune security platforms.
- Collaborate with stakeholders from other business units to conduct investigations, review plans and procedures, and respond to cyber incidents.
- Participate in training, exercises, and process improvement program.
- Occasionally travel to conferences, training, and other DTCC offices (up to 10%).
- Participate in on-call rotation and occasional after-hours work.
- Create messaging, socialize your program, and evangelize security at DTCC.
**NOTE: The Primary Responsibilities of this role are not limited to the details above. **Qualifications:- Minimum of 6 years of related experience
- Bachelor's degree preferred and/or equivalent experience
Talents Needed for Success:- Have at least three (3) years previous experience as a SOC analyst or similar technical role.
- Demonstrate strong grasp of forensic interpretation of data.
- Demonstrate the ability to research and mentor team members on interpreting on OS log files, network logs, flow data and other security data.
- Have previous experience successfully leading technical projects and complex incidents requiring collaboration with multiple people.
- Demonstrate tactical leadership of teams to accomplish technical tasks and projects.
- Demonstrate the ability to produce written reports including detailed analysis and recommendations.
- Demonstrate the ability to convey complex technical concepts to both technical and non-technical audiences.
- Be a subject matter expert in a particular technology or security domain as well as have hands-on experience and knowledge of modern security tools and DFIR best practices.
- Demonstrate the ability to take minimal high-level requirements and independently produce and execute an action plan to accomplish tasks.
- Demonstrate the ability to independently prioritize and manage multiple tasks.
- Demonstrate a strong desire to achieve and contribute to a high-performing team.
The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations.