JOB SUMMARYAs a Sr. Cyber Security Analyst, you will play a key role in protecting SMBC Group by helping detect, investigate, and respond to cyber threats. You will work within the Security Operations Center (SOC) to strengthen monitoring, incident response, threat hunting, and detection capabilities across a global technology environment.
In this role, you will analyze security events, identify root causes, improve detection coverage, and help enhance security controls. You will also contribute to initiatives that advance the SOC's capabilities through automation, threat intelligence, purple teaming, digital forensics, and incident response. This is an opportunity to work with modern security technologies, expand your expertise, and directly influence how we defend the organization.
PRINCIPAL DUTIES AND RESPONSIBILITIES- Monitor, investigate, and respond to security alerts, incidents, and suspicious activity across the enterprise.
- Lead technical investigations to determine root cause, assess impact, and support containment and remediation efforts.
- Conduct proactive threat hunting activities to identify emerging threats and security gaps.
- Maintain and enhance monitoring, detection, and incident response playbooks and procedures.
- Partner with detection engineering and security automation teams to improve visibility, reduce false positives, and strengthen response processes.
- Evaluate adversary tactics, techniques, and procedures (TTPs) and validate the organization's ability to detect and respond to them.
- Support the implementation, management, and optimization of security tools and platforms.
- Contribute to projects and initiatives that improve SOC operations, incident response capabilities, and overall security maturity.
POSITION SPECIFICATIONS- 5+ years of cybersecurity experience, preferably in a SOC, CSIRT, DFIR, or incident response environment.
- Experience investigating security incidents and analyzing complex threat activity.
- Experience documenting investigations, findings, and recommendations clearly and accurately.
- Strong understanding of security monitoring, incident detection, investigation, containment, and response processes.
- Knowledge of the MITRE ATT&CK framework, Cyber Kill Chain, and related threat analysis methodologies.
- Experience working with security technologies such as SIEM, EDR, NDR, XDR, and UEBA platforms.
- Strong knowledge of Windows and Linux operating systems.
- Experience with Active Directory and identity-related security concepts.
- Working knowledge of cloud technologies and cloud security principles.
- Strong analytical, problem-solving, and organizational skills.
- Strong verbal and written communication skills.
- Ability to manage multiple priorities and work effectively in a results-focused environment.
- Ability to work independently and make sound decisions during security investigations.
NICE TO HAVE
- Experience in threat hunting, digital forensics, purple teaming, detection engineering, security automation, or threat intelligence.
- Experience developing or tuning security detections and response workflows.
- Professional certifications such as GCIH, GNFA, GCFA, CEH, OSCP, CISSP, or equivalent.
- Experience working in a global enterprise or highly regulated environment, including financial services.
SMBC's employees participate in a Hybrid workforce model that provides employees with an opportunity to work from home, as well as, from an SMBC office. SMBC requires that employees live within a reasonable commuting distance of their office location. Prospective candidates will learn more about their specific hybrid work schedule during their interview process. Hybrid work may not be permitted for certain roles, including, for example, certain FINRA-registered roles for which in-office attendance for the entire workweek is required.