Work Location:
Mount Laurel, New Jersey, United States of America
Hours:
40
Pay Details:
$79,160 - $127,670 USD
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Line of Business:
Technology Solutions
Job Description:
The Senior Information Security Analyst defines, develops and/or implements Technology Controls / Information Security related policies, programs, tools and provides specialized expertise and guidance on assessing risks, identifying potential gaps and providing security solutions to mitigate risks and protect the Bank. Participates on projects of moderate to high complexity and provide complex reporting, analysis, and assessments at the functional, business line or enterprise level for own area.
Key Accountabilities
Lead and coordinate Real-time analysis on identified cyber incidents currently impacting the bank’s operations.
Analyze, triage, and remediate security incidents internally and/or escalate to Cyber Security Incident Response team (CSIRT) for further investigation, treatment or support if needed.
Manage incident queue in internal ticketing system in a timely and accurate manner to resolve a multitude of information security related situations and ensure that intake of incidents and reports from internal customers are properly recorded, timely updated, followed up and closed as per agreed SLA level ensuring quality and accurately in reporting.
The ability to guide team to identify, triage and remediate security incidents related to Web Attacks, Malware incidents, and other external and internal threats is required.
This role will be primarily required to participate in shift rotations to support as part of a cyber security operations team responsible for carrying out 24x7 on-site security monitoring operations which are carried out in North America shifts that run from 7am-3pm, 12pm-8pm or 7pm-7am on a rotating basis.
The personnel may be assigned to be on call rotationally on a weekly basis to support and coordinate with the team for any notable events during after office hours and weekend.
Time will be balanced between 80% operational (BAU and Queue work) and 20% project work (improvement initiatives, Subject matter expert on SOC projects etc.)
Authorities Scope & Impact
Accountable to respond to, investigate and remediate cyber threats to the bank. Escalate to internal and Cyber Security Incident Response team if required. This job contributes to Technology and Operations through first line management and identifications of electronic threats to TDBG’s infrastructure.
Cross Functional Relationships
The Senior Information Security Analyst will be responsible for managing information between multiple technical teams, the CSOC, CSIRT and ITS, LOB TS when appropriate.
Education & Experience:
Bachelor's degree preferred
Information security certification / accreditation an asset
5-7 years of relevant experience
Preferred Qualifications :
5 - 7 years of experience in Information Security Operations or related field is required.
A minimum of 3 years' experience of leading or coordinating the Security Operations Monitoring team.
A thorough understanding of security controls and mechanisms, as well as threat risk assessment techniques related to complex data, applications, and networking environment.
Must have expert knowledge of security incident and event management using an enterprise incident management framework, log analysis, network traffic analysis, malware investigation and remediation, SIEM correlation logic and alert generation.
Ability to perform analysis and reporting on information from multiple data sources using data mining technique for the purpose of documenting analysis results, produce report and present to a technical and executive stakeholder.
Must have expert knowledge in SIEM, EDR, XDR, Firewall, WAF, NIDS and equivalent.
Understanding of Security principles, techniques, and technologies such as NIST Cybersecurity Framework, SANS Top 20 Critical Security Controls and OWASP Top 10.
Strong organizational and self-directing skills. Ability to initiate, coordinate and prioritize responsibilities and follow through on tasks to completion.
Must demonstrate expert knowledge in Enterprise IT operations, incident management, change management, Access/Identity Management, security operations, vulnerability and compliance management, ticketing system, incident ticket life cycle and SLA terms.
Must have excellent written and oral communication skills.
Ability to work independently on a variety of assignments with minimal supervision.
Ability to work without supervision with the senior leadership team.
Good to have basic programming skills in various disciplines including scripting languages.
Completion of a bachelor's degree or equivalent program in Computer Science, Management Information Systems or similar field is required.
Completion of at least one of the following: GIAC (GSEC, GCIH, GCIA, GCFE, GCFA), CCNP, CCNA, CISSP
Location : Mount Laurel, NJ
Physical Requirements:
Never: 0%; Occasional: 1-33%; Frequent: 34-66%; Continuous: 67-100%
Domestic Travel – Occasional
International Travel – Never
Performing sedentary work – Continuous
Performing multiple tasks – Continuous
Operating standard office equipment - Continuous
Responding quickly to sounds – Occasional
Sitting – Continuous
Standing – Occasional
Walking – Occasional
Moving safely in confined spaces – Occasional
Lifting/Carrying (under 25 lbs.) – Occasional
Lifting/Carrying (over 25 lbs.) – Never
Squatting – Occasional
Bending – Occasional
Kneeling – Never
Crawling – Never
Climbing – Never
Reaching overhead – Never
Reaching forward – Occasional
Pushing – Never
Pulling – Never
Twisting – Never
Concentrating for long periods of time – Continuous
Applying common sense to deal with problems involving standardized situations – Continuous
Reading, writing and comprehending instructions – Continuous
Adding, subtracting, multiplying and dividing – Continuous
The above statements are intended to describe the general nature and level of work being performed by people assigned to this job. They are not intended to be an exhaustive list of all responsibilities, duties and skills required. The listed or specified responsibilities & duties are considered essential functions for ADA purposes.