Singapore, SingaporeTechnology Solutions
JobRole/Responsibilities
The Information Security Analyst is responsible for tier 1/tier 2 triage, investigation, and incident response for Cyber security incidents.
- Conduct Real-time analysis on identified cyber incidents currently impacting the bank’s operations.
- Analyze, triage and remediate security incidents internally and/or escalate to Cyber Security Incident Response team (CSIRT) for further investigation, treatment or support if needed.
- Manage intake of incidents and reports from internal customers through internal ticketing system in a timely accurate manner in order to resolve a multitude of information security related situations.
- The ability to identify and triage and remediate security incidents such as Malware, Phishing and Web Attacks is required.
- The CSOC Security Analyst is responsible for supporting the event log monitoring, analysis needs of customers.
- The personnel in this role will work as part of a cyber security operations team responsible for carrying out 24x7 on-site security monitoring operations. Operations which are carried out in Singapore shifts that run from 7am-3pm, 12pm-8pm or 7pm-7am on a rotating basis.
- Accountable to respond to, investigate and remediate cyber threats to the bank. Escalate to internal and Cyber Security Incident Response team if required.
- This job contributes to Technology and Operations through first line management and identifications of electronic threats to TDBG’s infrastructure.
- The Information Security Analyst will be responsible for managing information between multiple technical teams, the CSOC, CSIRT and ITS, LOB TS when appropriate.
Job Requirements
- Min 3 years of Information Security Operations or similar working experience
- Understanding of security controls/mechanisms and threat/risk assessment techniques pertaining to complex data, application and networking environments.
- Excellent written and oral communication skills.
- Organizational and self-directing skills – ability to initiate, coordinate and prioritize responsibilities and follow through on tasks to completion.
- An approach to work that includes initiative, sound judgment, diplomacy and Discretion.
- Ability to work independently on a variety of assignments with minimal supervision.
- Ability to work without supervision with senior managers, supervisors, VIPs and Users.
- Advanced knowledge of security incident and event management, log analysis, Network traffic analysis, Malware investigation and remediation, SIEM correlation logic and alert generation.
- Ability to perform analysis and reporting on information from multiple data sources using data mining technique for the purpose of documenting analysis results, produce report and present to a technical and executive stakeholders.
- Understanding of Security principles, techniques and technologies such as SANS Top 20 Critical Security Controls and OWASP Top 10.
- A background with Cloud Security Monitoring is highly desired, preferably with Azure Security Center, Microsoft MCAS, AWS.
- Basic programming skills in various disciplines including scripting languages.
- Candidate should possess strong hands-on experience with traditional incidents response detection tools such as SIEM, EDR, XDR, Firewall, WAF, NIDS and equivalent.
- Experience with Security Orchestration, Automation and Response tools (SOAR).
- Demonstrate expert knowledge in Enterprise IT operations, incident management, change management, Access/Identity Management, Security Operations, vulnerability and compliance management, ticketing system, incident ticket life cycle and SLA terms
Background and Education:
- Completion of a Bachelor’s degree or equivalent program in Computer Science, Management Information Systems or similar field is required.
- Completion of a Master's degree or equivalent program in Computer Science, Management Information Systems or similar field is preferred.
- Preferably to have at least one of the following: GIAC (GSEC, GCIH, GCIA, GCFE, GCFA) CompTIA Security+ / CySA+, SC200, CISSP, CCSP
If you’re interested in a specific career path or are looking to build certain skills, we want to help you succeed. You’ll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD – and we’re committed to helping you identify opportunities that support your goals.
We will provide training and onboarding sessions to ensure that you’ve got everything you need to succeed in your new role.