InfoSec Specialist
Description
SummaryIntegrated in Deutsche Bank’s Chief Security Office (CSO), the Information Security Threat Operations team is responsible for mitigating these risks. The Information Security Threat Operations team enables the business of Deutsche Bank by providing agile security operational capabilities.
You will be responsible for the full range of tasks associated with the detection of cyber threats in a
- paced environment for Deutsche Bank’s cloud workloads, using cloud based SIEM/SOAR solutions. Our Cloud Operations team is focused on helping develop Deutsche Bank’s new cloud architecture, platforms/systems, organizational and operational processes to allow for the detection of cyber threats. Once established the focus will shift stronger into the development to detect new threats and perform threat hunting while incorporating change in an evergreen cloud environment.
This will involve maintaining a close dialogue with various units and stakeholders for the purpose of detecting and assessing potential risks to critical business infrastructure and services.
Activities:
• You will be expected to be able to identify areas for improvement and take accountability to drive security topics forward within and outside the team.
• In this role, you will also contribute to the development of Security Information and Event Management (SIEM) content, focusing on the Cloud Platform, including detection use cases, reports, network and asset model management, dashboards, rules/logic, documentation, and process establishment.
• Collaborate with other security specialists and experts to support the architecture, design and implementation of services and processes to support our mission of detecting cyber threats.
• Work in close cooperation with Cyber Intelligence, Incident Response, and the Security Operations Centre for the purpose of extending and strengthening the division’s capabilities relating to threat analytics for cloud service.
• This will include managing and overseeing a range of sophisticated tools and services aimed at detecting cyber threats/incidents and responding to them in a determined manner.
Knowledge and Experience:
• Minimum 3 years
- on experience with GCP/AWS or alternatively MS Azure.
• Having at least 1-year experience in developing, modifying, enhancing, and
- tuning detection and alerting/threat hunting
- cases in any type of SIEM solution (Splunk, Log
Rhythm, QRadar) or at least 6 months of experience of working with cloud based SIEM solutions (Splunk, Chronicle, Sentinel).
• Experience with industry known detection query languages: YARA, YARA-l, SPL, etc.
• Familiarity with Cyber Security Incident Response or computer forensic processes, or a strong interest and capability to learn the fundamentals of security operations within a short time.
• Experience of automating smaller tasks in a short amount of time, e. g. , with scripting languages such as GCP CLI, Power
Shell, Go, Python, etc.
• Experience with assessment, development, implementation, optimization, and documentation of a comprehensive and broad set of security technologies and processes (secure software development /Application Security, data protection, cryptography, key management, identity and access management, network security) within Saa
S, Iaa
S, Paa
S, and other cloud environments
• Have at least 3 years’ work experience in the fields of either: Encryption; IAM (Identity & Access Management), Security Monitoring & Incident Response, Network Security, Pen Testing, Security Operation, Application Security.
Education and Certifications:
• Bachelor’s or master’s degree from an accredited college or university with a focus on cloud and network technology, software development, or IT security.
• Certifications as Comp
TIA Security +, Google Cloud, Azure platforms can be considered a plus but they’re not mandatory.
• Any relevant Cyber Security Certifications.
We promote good working relationships and encourage high standards of conduct and work performance.
Fii primul, care se va înregistra la oferta de muncă respectivă!
-
De ce să cauți de muncă pe Lucrezi.ro?
În fiecare zi oferte noi de muncă Puteți alege dintr-o gamă largă de locuri de muncă: Scopul nostru este de a oferi o gamă cât mai largă de opțiuni Lasă să-ți fie trimise noile oferte prin e-mail Fii primul care răspunde la noile oferte de muncă Toate ofertele de muncă într-un singur loc (de la angajatori, agenții și alte portaluri) Toate serviciile pentru persoanele aflate în căutarea unui loc de muncă sunt gratuite Vă vom ajuta să găsiți un nou loc de muncă