Lead Cyber Security Operations Center (SOC) Analyst

    • State Street Corporation
  • Posted 14 days ago | Updated 14 days ago

Overview

On Site
USD 100,000.00 - 160,000.00 per year
Full Time

Skills

Cyber security
Enterprise networks
Threat analysis
Incident management
Knowledge sharing
Operating systems
Malware analysis
IT architecture
Proxies
Information Technology
Computer science
Tier 3
Penetration testing
Financial services
Software development
Product innovation
Investment management
Leadership
Operations
System on a chip
Fusion
Management
KPI
Metrics
Collaboration
Mentorship
Solaris
Administration
Microsoft Windows
Linux
Forensics
National Institute of Standards and Technology
Network
Storage
Cloud computing
SIEM
AV
PostScript
PKI
Dragon NaturallySpeaking
CISSP
Certified Ethical Hacker
OSCP
Information retrieval
Scripting
Python
Windows PowerShell
SQL
Banking
Value engineering
Investments
Data
Analytics
Research
Trading
Expect
Insurance

Job Details

Who are we looking for:

State Street seeks to recruit an Lead Cyber Security Operations Center (SOC) analyst that will assist in the detection, triage, analysis and response to cyber-attacks. The analyst will join our SOC team which will run a 24/7 coverage, 365 days a year model, with a partner team in Ireland.
The SOC team is responsible for analyzing events from multiple sources from across a large enterprise network. The SOC will partner with multiple teams in our Cyber Fusion Center including but not limited to Advanced Threat, Cyber Threat Intelligence, & Red/Purple teams.
Join us in evolving our response capabilities to protect State Street, its customers and partners from ever-evolving and sophisticated threat actors. State Street's Fusion Center is responsible for detecting and responding to various cyber threats 24/7 365 days a year, that are directed towards the enterprise.

This role will be Monday - Friday and will be on-site in State Street's office in Quincy.

What will you be responsible for:
  • Leading the cyber incident response process to ensure timely triage, analysis, containment, eradication and return to service for high severity or long running incidents.
  • Author incident status updates and closure reports to leadership.
  • Produce post mortem reports to identify lessons learned and recommendations.
  • Continuously prepare for incidents by updating and maintaining incident response plans, playbooks and procedures.
  • Manage and participate in cyber related exercises such as table tops and cyber ranges.
  • Measure the effectiveness and performance of the incident response process through KRI and KPI metrics.
  • Identify methods to continuously enhance the incident response process
  • Work closely with the SOC to drive development and collaboration
  • Train and Mentor SOC personnel
  • Creating an environment which drives knowledge sharing with teams across the Fusion Center.
  • Help developing the Fusion Center mindset and follow the sun model
What we value:
  • Experience with investigating & managing major/complex cyber incidents end to end.
  • Experience working/leading in a SOC or Fusion Center.
  • Strong operating systems administration skills (Windows, Linux, Mac).
  • Strong malware analysis expertise.
  • Experience in performing memory forensics.
  • Knowledge of adversarial tactics, techniques, procedures (TTPs) & Industry standard frameworks (NIST, Mitre Att&ck).
  • Knowledge of IT architecture and operations (computing, network, storage & cloud)
  • Strong working knowledge of security technologies including but not limited to SIEM, EDR/EPP, AV, ID/PS, HIPS, Web Proxy/Content filtering, AD, PKI and DNS
  • Bachelor's in Cyber Security, Information Technology, Computer Science and/or completion of a Cybersecurity boot camp. In lieu of education requirements, relevant industry experience will be considered
  • CISSP, CEH, OSCP,OSCE IH or applicable certification in Security field
  • 4+ years in a cyber security SOC/IR type skill role - Incident Response, SOC Tier 3/Lead Analyst, Threat Hunter, Penetration testing, etc.
  • Financial Services experience a plus.
  • Software development and/or scripting experience a plus: Python, Powershell, SQL etc.

About State Street
What we do. State Street is one of the largest custodian banks, asset managers and asset intelligence companies in the world. From technology to product innovation, we're making our mark on the financial services industry. For more than two centuries, we've been helping our clients safeguard and steward the investments of millions of people. We provide investment servicing, data & analytics, investment research & trading and investment management to institutional clients.
Work, Live and Grow. We make all efforts to create a great work environment. Our benefits packages are competitive and comprehensive. Details vary by location, but you may expect generous medical care, insurance and savings plans, among other perks. You'll have access to flexible Work Programs to help you match your needs. And our wealth of development programs and educational support will help you reach your full potential.
Inclusion, Diversity and Social Responsibility. We truly believe our employees' diverse backgrounds, experiences and perspectives are a powerful contributor to creating an inclusive environment where everyone can thrive and reach their maximum potential while adding value to both our organization and our clients. We warmly welcome candidates of diverse origin, background, ability, age, sexual orientation, gender identity and personality. Another fundamental value at State Street is active engagement with our communities around the world, both as a partner and a leader. You will have tools to help balance your professional and personal life, paid volunteer days, matching gift programs and access to employee networks that help you stay connected to what matters to you.
State Street is an equal opportunity and affirmative action employer.

Salary Range:
$100,000 - $160,000 Annual
The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.