Title: Cyber Threat Analyst - Remote
US
Donnelley Financial Solutions (DFIN) is a leader in risk and compliance solutions, providing insightful technology, industry expertise and data insights to clients across the globe. We’re here to help you make smarter decisions with insightful technology, industry expertise and data insights at every stage of your business and investment lifecycles. As markets fluctuate, regulations evolve and technology advances, we’re there. And through it all, we deliver confidence with the right solutions in moments that matter.
Summary:
The Cyber Threat Analyst will support and participate in efforts to investigate cybersecurity events from end-to-end, engaging and coordinating peer teams, stakeholders, and other entities as necessary. This person will play a role of analyst in the areas of incident response, threat hunting, and email analysis. The Cyber Threat Analyst will help create and update existing incident response documentation and training materials.
Responsibilities:
- Escalate and engage in incident response activities to identify, assess, contain, mitigate, and resolve all observed threats
- Document all investigational efforts and actions in the ticketing system
- Create and update incident response runbooks
- Document and track incident response investigations, including observed IOCs and TTPs, system(s) impacted, criticality and scope of any data exposure, lessons learned, follow-up items
- Act as incident investigator for all observed and escalated cyber security events
- Collect, organize, and analyze data using various cyber security tools and data sources a SIEM, endpoint detection and response, tools, firewall logs, and custom detections (to include threat intelligence sources)
- Identify, analyze, and interpret trends or patterns in complex data sets
- Work with the functional business areas as needed during incident response investigations
- Demonstrate subject matter proficiency with threat intelligence processes
- Perform other duties as assigned
Qualifications:
- Bachelor’s degree or 3+ years of relevant work experience
- 3+ years of cybersecurity investigation experience
- 3+ years of intensive incident response experience
- A demonstrable understanding of operating systems, including Microsoft Windows, Mac OSX, Linux, Unix, and mobile devices
Preferred Skills:
- Analytical skills applying logic and intel threat modeling to available data points.
- Well-versed in multiple cyber security domains and technologies such as firewalls, intrusion detection systems, and other network security platforms
- Deep understanding of how to leverage threat intelligence
- Advanced knowledge of cyber-attack techniques, and mitigation strategies
- Ability to effectively communicate complex topics to engineers and leadership
- Ability to properly handle confidential data and strictly follow business processes and procedures
- Security certifications such as Security+, CISSP, GSEC, GCFA, GCFE are a plus
- Ability to operate effectively in fast paced and high stress situations
- Ability to communicate findings and requirements effectively
- In- depth level knowledge in incident response, computer forensics, network traffic analysis, log file analysis, malware analysis
- Knowledge of the MITRE ATT&CK framework
- Experience using SIEM, SOAR, and/or EDR platforms to identify and mitigate cybersecurity incidents.
- Experience in securing and investigating incidents in modern cloud environments such as Microsoft Azure/Amazon Cloud/Google Cloud
It is the policy of Donnelley Financial Solutions to select, place and manage all its employees without discrimination based on race, color, national origin, gender, age, religion, actual or perceived disability, veteran's status, actual or perceived sexual orientation, genetic information or any other protected status.
If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access jobs.dfinsolutions.com as a result of your disability. You can request a reasonable accommodation by sending an email to AccommodationRequests@dfinsolutions.com.
Job Segment:
Linux, Unix, Technology