VIRTUAL27 - HomeRes - NE XXXXX Nebraska,XXXXX
Monitors, analyzes and responds to Cyber Security events in real-time within DLP, UEBA and CASB platforms with the objective of detecting insider threats, preventing data exfiltration, reducing risk and increasing the Bank's security posture. Generates internal metrics & SLAs for DLP, UEBA and Incident Forensics programs.
Responsibilities Include (but are not limited to):
- DLP, UEBA and CASB event monitoring & incident response
- Triage, Analysis, and Escalation of internal Cyber Security events of interest
- Conduct Internal Security Investigations in partnership with Legal/Regulatory Compliance and Incident Response teams
- Evidence gathering in support of Forensic and Legal Investigations
- Implementation of tactical, operational & preventative controls to mitigate data exfiltration
- Identification of Insider Threats and Repeat Offenders using quantitative risk analysis
- Metrics, Data Analytics and Reporting of Cyber Security incidents
- Alert tuning and False Positive reviews
- Incident Response, specific to Insider Threat detection and Data Exfiltration
- Detection and Prevention of Cyber Security incidents across multiple channels
- User/Entity baseline, behavior and anomaly analytics
- Detection and Prevention of data exfiltration via Cloud service providers
- Monitoring of signature and behavioral-based real-time Cyber Defence technologies to protect the Bank's information
- Metrics generation as a part of Incident Reporting and Event Analytics
- Corresponding with internal employees as well as their managers, determining next steps and escalation paths based on incoming incidents
- Cyber Security procedural documentation in support of Security Orchestration
- Work closely with Identity & Access Management, Data Protection, Privacy and Legal teams on Cyber Security cases
TOP SKILLS / EXPERIENCE:
- The ideal candidate will have 1-2 years' experience within an enterprise Cyber Security Operations Centre as a SOC Analyst performing event monitoring and incident response
- The ideal candidate will have 1-2 years' experience with enterprise DLP, UEBA, CASB, SIEM and SOAR technologies
- Ability to identify, collect, interpret and respond to evidence from a variety of security technologies and intelligence/data gathering sources
- Knowledge of scripting is a desired asset (Python, PowerShell)
- Understanding of Microsoft Active Directory
- Understanding of Cyber Security investigative techniques
- Understanding of Cyber Security Case Management and SOAR technologies
- An understanding of Digital Forensics collection, examination, analysis, reporting and evidence handling techniques would be considered an asset
- Ability to detect common Network Security evasion techniques
- Ability to understand and reconstruct network packet captures
- Applied knowledge of common Enterprise / Open Source Cyber Security tools & frameworks
- Ability to conduct real-time analysis and correlation of Data Loss Prevention (DLP), User & Entity Behavior Analytics (UEBA) and Cloud Access Security Broker (CASB) events
- Ability to monitor, triage, and investigate Cyber Security incidents
- Understanding of Red Team methodologies and Penetration Testing techniques
- Responsible for providing efficient and accurate Metrics and Reporting
- Understanding of Cloud Access Security Brokers
- An interest and understand of Banking & Financial Services
NICE TO HAVE SKILLS/EXPERIENCE:
- CompTIA Security+, Associate of ISC2, CISSP or other relevant industry certifications would be considered an asset.
SOFT SKILLS
- Must be a Team player
- Strong analytical skills with an ability to adapt to an evolving Cyber Security landscape within a complex, dynamic environment
- Coachable and willingness to learn
- Previous experience in Banking / Critical Infrastructure considered an asset
Compensation and Benefits:
$87,000.00 - $161,400.00
Pay Type:
Salaried
The above represents BMO Financial Group’s pay range and type.
Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.
BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards
We’re here to help
At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.
As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.
To find out more visit us at https://jobs.bmo.com/us/en
BMO is committed to an inclusive, equitable and accessible workplace. By learning from each other’s differences, we gain strength through our people and our perspectives. BMO is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.
Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.