Zions Bancorporation

Senior Cyber Incident Response Engineer

Zions Bancorporation$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in technical cybersecurity domains including SIEM, IDS, and EDR tools
  • Expertise in networking and both Windows and Linux administration
  • Advanced knowledge of common attack techniques and prevention methods
  • Experience creating technical documentation and incident response playbooks
  • Development skills in scripting languages like Python or JavaScript are a plus
  • Relevant security certifications (e.g., SANS, ISC2) are advantageous

Responsibilities

  • Contribute to the growth and evolution of the CSOC's cyber incident response capabilities
  • Respond to high-priority and complex cybersecurity incidents as an escalation point
  • Serve as subject matter expert on multiple cybersecurity tools and processes
  • Develop monitoring use cases and cyber incident response procedures
  • Collaborate with other teams to enhance monitoring and alerting infrastructure
  • Train and mentor team members on incident response practices
  • Participate in an on-call rotation to provide 24/7 alert response

Benefits

  • Medical, Dental, and Vision Insurance starting day one
  • Life and Disability Insurance, Paid Parental Leave, and Adoption Assistance
  • Health Savings and Flexible Spending Accounts available
  • Generous Paid Time Off (PTO) and 11 Paid Federal Holidays
  • 401(k) plan with company match and Profit Sharing
  • Mental health benefits including coaching and therapy
  • Tuition Reimbursement for eligible employees
  • Employee Ambassador preferred banking products
Full Job Description
The Senior Cyber Incident Response Engineer will join our CSOC Team. The Cybersecurity Operations Center (CSOC) team is the cyber front line at Zions Bancorporation. If you want to work on a team where your input matters, you get to collaborate with sharp colleagues with whom you will grow, where your work is truly valued and you make a real difference, then you will be in good company.

As a Senior Cyber Incident Response Engineer you will play a key role in defending the enterprise from malicious actors. The work you do has real impact customer-wide and enterprise-wide and it is truly valued by both.

The Senior Cyber Incident Response Engineer will:
  • Act as key contributor in the CSOC's growth and evolution, actively improving our cyber incident response capabilities
  • Respond to cybersecurity incidents, especially as an escalation point for high-priority or highly complex incidents
  • Function as subject matter expert in multiple cybersecurity tools and processes such as SIEM, IDS, EDR, DLP, WAF and similar
  • Develop and implement monitoring use cases, cyber incident response procedures, playbooks and other technical documentation
  • Collaborate with Enterprise Cybersecurity Architecture and technology teams in monitoring and alerting infrastructure, processes, and tools
  • Train, mentor and guide other team members (across both the CSOC and other EIS teams) on cyber incident response practices, tooling, and capabilities
  • Participate in the on-call rotation so we can maintain 24/7 coverage in responding to alerts and possible threats
  • Other duties as assigned


Requirements:
  • Hands-on technical experience with one or more commercial SIEM products such as Splunk (preferred), IBM QRadar, LogRhythm, ArcSight, NetWitness, etc., which should include familiarity with defining and writing alert conditions/use cases in addition to daily use for investigating incidents
  • Experience producing technical documentation, standard operating procedures, and incident response playbooks
  • Expert technical knowledge in networking, Windows administration, Linux administration, common attack techniques and preventions
  • Advanced working knowledge of common attack vectors, different classes of attacks (e.g., passive, active, insider, close-in, distributed, etc.) and general attack stages (e.g., foot printing and scanning, enumeration, gaining access, escalation or privileges, maintaining access, network exploitation, covering tracks, etc.)
  • Advanced knowledge of system administration concepts for UNIX/Linux and Windows operating systems
  • Development experience with scripting languages such as R, HIVE, Python, JavaScript, etc., is a plus
  • Experience with any Endpoint Detection and Response platform is a plus
  • Relevant advanced technical certifications are a plus (ex: SANS, ISC2) with 5+ years of relevant experience in one or more technical cybersecurity domains (combination of education and experience, such as 6-8 years of relevant experience or equivalent education may meet qualifications)


Location:

This position has a hybrid work from home schedule with a minimum of three days per week in the office at the new Zions Technology Center in Midvale, UT

The Zions Technology Center is a 400,000-square-foot technology campus in Midvale, Utah. Located on the former Sharon Steel Mill superfund site, the sustainably built campus is the company's primary technology and operations center. This modern and environmentally friendly technology center enables Zions to compete for the best technology talent in the state while providing team members with an exceptional work environment with features such as:
  • Electric vehicle charging stations and close proximity to Historic Gardner Village UTA TRAX station.
  • At least 75% of the building is powered by on-site renewable solar energy.
  • Access to outdoor recreation, parks, trails, shareable bikes and locker rooms.
  • Large modern cafe with a healthy and diverse menu.
  • Healthy indoor environment with ample natural light and fresh air.
  • LEED-certified sustainable building that features include the use of low VOC-emitting construction materials.


Benefits:
  • Medical, Dental and Vision Insurance - START DAY ONE!
  • Life and Disability Insurance, Paid Parental Leave and Adoption Assistance
  • Health Savings (HSA), Flexible Spending (FSA), and dependent care accounts
  • Paid Training, Paid Time Off (PTO) and 11 Paid Federal Holidays
  • 401(k) plan with company match, Profit Sharing, competitive compensation in line with work experience
  • Mental health benefits including coaching and therapy sessions
  • Tuition Reimbursement for qualifying employees
  • Employee Ambassador preferred banking products


#dice

About Zions Bancorporation

Zions Bancorporation is a bank holding company headquartered in Salt Lake City, Utah. It is the parent company of Zions Bank, which operates in 11 Western and Southwestern states. Zions Bancorporation provides banking and related services through its subsidiaries and offers a variety of commercial, retail banking, and mortgage lending products. The company was founded in 1873 and has grown through a series of mergers and acquisitions. Zions Bancorporation is publicly traded on the NASDAQ stock exchange under the ticker symbol ZION.
Learn more about Zions Bancorporation
Size
10,000 employees
Industry
Founded
1873

Similar Jobs

More Jobs at Zions Bancorporation

More Information Technology Jobs

Find similar Senior Cyber Incident Response Engineer jobs: