177 Security Leadership jobs in Singapore
Security Leadership Role
Posted today
Job Viewed
Job Description
Cybersecurity Operations Team Lead
Role Overview:
This is a key leadership position responsible for leading a cybersecurity operations team. The role ensures operational efficiency, technical excellence, and compliance with established security standards.
Key Responsibilities:
- Lead and manage the Day 2 Operations team, including scheduling, workload assignment, and performance monitoring.
- Act as the primary escalation point for operational, technical, and stakeholder issues.
- Oversee the execution of regular account and log reviews using Splunk, CyberArk, Trellix, Carbon Black, and other security tools.
- Provide guidance on incident investigation, root cause analysis, and remediation tracking.
- Ensure all security alerts and incidents are handled according to established SLAs.
Stakeholder Engagement:
Serve as the central point of contact with HTSOC, GSOC, FM Teams (System, Cloud, Network), and tenants (Application).
Facilitate remediation follow-up, risk register maintenance, and VAPT action closure.
Work closely with the external CISO on compliance initiatives, policy enforcement, and audit readiness.
Continuous Improvement:
- Identify process gaps and recommend enhancements to improve operational efficiency and security posture.
- Mentor and upskill engineers to maintain high technical competency across all required tools.
- Be available and must be able to respond to high-priority incidents outside standard working hours as part of standby duty.
Required Skills & Qualifications:
- Technical Skills:
- Strong working knowledge of SIEM (Splunk), PAM (CyberArk), EDR (VMware Carbon Black), and endpoint protection (Trellix).
- Understanding of security incident lifecycle, vulnerability management, and compliance frameworks.
- Leadership Skills:
- Proven ability to lead technical teams in a 24/7 standby environment.
- Strong decision-making, prioritisation, and conflict-resolution skills.
- Experience:
- At least 2 years in a leadership role.
- Experience coordinating with multiple stakeholders across different technical and business domains.
Reporting & Governance:
Consolidate and review team inputs for monthly operational reports.
Provide ad-hoc reports and security status updates to management as required.
Track KPIs and SLAs to ensure service quality and compliance.
Remediation
Vulnerability Management
Enforcement
Root Cause Analysis
Incident Investigation
Stakeholder Engagement
Petrochemical
Audit
EHS
Cyber Security Leadership Position
Posted today
Job Viewed
Job Description
We are seeking an experienced Cybersecurity Lead to deliver comprehensive cybersecurity and infrastructure support across our ongoing projects. This key position will manage external cybersecurity vendors, ensure alignment with evolving security threats, and lead incident response efforts.
Key Responsibilities:
- Provide end-to-end cybersecurity support for project and infrastructure needs.
- Manage external cybersecurity experts to address emerging threats.
- Lead and participate in incident response and resolution efforts.
- Apply deep knowledge of IT and network security to protect systems.
- Collaborate with stakeholders to ensure alignment with security objectives.
Requirements & Qualifications:
- 3–5 years in cybersecurity, including network security, endpoint protection, SIEM, and incident response.
- Experience in project-based or client-facing environments.
- Strong technical skills in OS/network architecture, next-gen firewalls, EDR, and SIEM/SOAR platforms.
- Familiar with compliance frameworks (e.g., IM8, CCoP).
- Proficient in assessing and executing cybersecurity tasks efficiently.
Leadership & Communication Skills:
- Skilled in stakeholder management and expectation setting.
- Strong communicator with the ability to simplify complex technical concepts.
- Capable of building trust and strong working relationships across teams.
Benefits:
- Relevant certifications (e.g., SSCP, CISSP) preferred.
- Knowledge of core cybersecurity domains and playbooks is an advantage.
- Adaptable, detail-oriented, and effective in fast-paced, collaborative settings.
About this role
- This role offers a challenging and dynamic environment where you can apply your skills and expertise to drive business success.
- You will work closely with internal teams to maintain strong cybersecurity practices and uphold organizational standards.
Security Systems Leadership Role
Posted today
Job Viewed
Job Description
Technical Operations Manager (Security Systems)
Job Description:
We are seeking a highly skilled and experienced Technical Operations Manager to lead our Security Systems team. The successful candidate will be responsible for managing a team of technical professionals, providing project management, system commissioning, technical support, and pre-sales services to meet customer requirements and achieve business objectives.
Key Responsibilities:
- Manage a team of technical professionals to provide project management, system commissioning, technical support, and pre-sales services.
- Provide guidance and mentorship to team members, fostering a collaborative and innovative work environment.
- Effectively allocate tasks and responsibilities among team members based on their skills and expertise.
- Establish clear communication channels within the team to ensure that team members are kept informed about project updates, organization changes, and any other relevant information.
- Conduct performance evaluations, set goals, and provide feedback to team members to enhance their performance and career development.
- Collaborate with other departments to ensure alignment and coordination of technical activities with overall business objectives.
Requirements:
- Bachelor's degree in Engineering or equivalent.
- At least 5-8 years of relevant working experience in the security industry, managing a group of 5 or more engineers.
If you are a motivated and experienced leader looking for a new challenge, please submit your application for this exciting opportunity.
Information Security Management System Manager
Posted today
Job Viewed
Job Description
Information Security Management System (ISMS) Manager
We are seeking a highly skilled Information Security Management System (ISMS) Manager to lead our organization's efforts in implementing and maintaining a robust ISMS. As the successful candidate, you will develop and implement an effective ISMS that aligns with EASA Part-IS requirements, ensuring compliance and minimizing risk.
Security Management & Engagement
Posted 13 days ago
Job Viewed
Job Description
Join to apply for the Security Management & Engagement role at Prudential plc
Join to apply for the Security Management & Engagement role at Prudential plc
Get AI-powered advice on this job and more exclusive features.
Prudential's purpose is to help people get the most out of life. We will deliver our purpose by creating a culture in which diversity is celebrated and inclusion assured, for our colleagues, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and in exchange, we support our people's career ambitions. We pledge to make Prudential a place where you can Connect, Grow and Succeed.
Job Purpose
The Senior Manager, Security Management & Engagement, is responsible for ensuring the adequate protection of the confidentiality, integrity and availability of business information assets against latest threats and vulnerabilities as well as ensuring ongoing adherence to Group, Regional and country regulations and policies with respect to information security and privacy.
Essential Job Duties & Responsibilities
- Coaches and provides sound information security direction, advice and consultation
- Facilitates assessments over information security management controls and third-party assessments.
- Facilitates implementation of appropriate access using knowledge of business roles and assists management with performing regular access certifications.
- Proactively engages the businesses to identify, document and drive remediation of risks by working with the business to design, implement or otherwise improve control activities to achieve Information Security objectives.
- Leads data protection program within each of the business units assigned, including unstructured data classification activities.
- Participates in the identification of Information Security Training and Awareness needs assessment on a regular basis and supports implementation of Information Security training and awareness plan and associated activities.
- Ensures stakeholders understand the state of the controls they are accountable for and understand their responsibilities as to risk mitigation and remediation.
- Provides direction on process improvements, remediating control gaps, and enhancing current tools for strengthening the overall information security control posture.
- Advises the business on security policies and standards to achieve security objectives and reduce the likelihood and impact of security risks.
- Plans and coordinates Information Security projects and initiatives within the business according to established plans and timelines.
- Works to ensure monitoring and tracking of country, state and federal regulations pertinent to information security and privacy within the assigned business area(s).
- Liaises and facilitates internal audit, external audit, investigation and compliance review of security activities employed by the business.
- Coordinates the understanding and reporting on the overall information security risk posture of the business unit, providing a holistic view of vulnerabilities and associated risks to the business and Information Security.
- Communication - Able to work and spread positive "security awareness and control due-diligence" influence with people from various level of the organization effectively.
- Technical Depth - Technically competent to be able to translate information security topics, initiatives / program into something that is digestible for stakeholders outside of information security community.
- Technical Breadth - Display subject matter experience in diverse information security and Privacy areas (e.g. application security, Cloud security, Vulnerability Management, agile lifecycle management, DevSecOps, etc)
- Know your Business - Strong business acumen within the insurance / financial services industry and related operational fields.
- Controls Framework - Knowledge of industry control framework, best practise, laws (e.g. GDPR, countries privacy laws, etc) and regulatory landscape
- Risk Management - Able to provide information security advises and opinions that continuously strike the right balance between controls enforcement, risk appetite and nett risk exposure.
- 5+ years experiences in privacy, security, or related data protection fields.
- Bachelors degree or equivalent professional experience required.
- Legal and/or financial services background/experience preferred.
- Other Privacy Certifications such as CIPP/M or CIPT preferred.
- Certified Information Security Professional (CISSP), or other related certifications (e.g. CISM, CISA) preferred.
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Other, Information Technology, and Management
Referrals increase your chances of interviewing at Prudential plc by 2x
Sign in to set job alerts for “Security Professional” roles. Security Officer - No PLRD license welcome to apply Security Officer (Conrad Singapore Orchard) Security Officer/Senior Security Officer (General Posting) Global Security Specialist (Asia-Pacific) Associate / Senior Associate Airport Operations (Safety, Security & Compliance) Cybersecurity Officer for Southeast Asia Security Manager, Global Corporate Security Information Technology - Cyber Security Analyst (Scoot) Information Technology - Cyber Security Specialist (Risk and Governance) Senior Security, Resiliency and Control ManagerWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrSecurity Management & Engagement
Posted today
Job Viewed
Job Description
Join to apply for the Security Management & Engagement role at Prudential plc
Join to apply for the Security Management & Engagement role at Prudential plc
Get AI-powered advice on this job and more exclusive features.
Prudential's purpose is to help people get the most out of life. We will deliver our purpose by creating a culture in which diversity is celebrated and inclusion assured, for our colleagues, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and in exchange, we support our people's career ambitions. We pledge to make Prudential a place where you can Connect, Grow and Succeed.
Job Purpose
The Senior Manager, Security Management & Engagement, is responsible for ensuring the adequate protection of the confidentiality, integrity and availability of business information assets against latest threats and vulnerabilities as well as ensuring ongoing adherence to Group, Regional and country regulations and policies with respect to information security and privacy.
Essential Job Duties & Responsibilities
- Coaches and provides sound information security direction, advice and consultation
- Facilitates assessments over information security management controls and third-party assessments.
- Facilitates implementation of appropriate access using knowledge of business roles and assists management with performing regular access certifications.
- Proactively engages the businesses to identify, document and drive remediation of risks by working with the business to design, implement or otherwise improve control activities to achieve Information Security objectives.
- Leads data protection program within each of the business units assigned, including unstructured data classification activities.
- Participates in the identification of Information Security Training and Awareness needs assessment on a regular basis and supports implementation of Information Security training and awareness plan and associated activities.
- Ensures stakeholders understand the state of the controls they are accountable for and understand their responsibilities as to risk mitigation and remediation.
- Provides direction on process improvements, remediating control gaps, and enhancing current tools for strengthening the overall information security control posture.
- Advises the business on security policies and standards to achieve security objectives and reduce the likelihood and impact of security risks.
- Plans and coordinates Information Security projects and initiatives within the business according to established plans and timelines.
- Works to ensure monitoring and tracking of country, state and federal regulations pertinent to information security and privacy within the assigned business area(s).
- Liaises and facilitates internal audit, external audit, investigation and compliance review of security activities employed by the business.
- Coordinates the understanding and reporting on the overall information security risk posture of the business unit, providing a holistic view of vulnerabilities and associated risks to the business and Information Security.
- Communication - Able to work and spread positive "security awareness and control due-diligence" influence with people from various level of the organization effectively.
- Technical Depth - Technically competent to be able to translate information security topics, initiatives / program into something that is digestible for stakeholders outside of information security community.
- Technical Breadth - Display subject matter experience in diverse information security and Privacy areas (e.g. application security, Cloud security, Vulnerability Management, agile lifecycle management, DevSecOps, etc)
- Know your Business - Strong business acumen within the insurance / financial services industry and related operational fields.
- Controls Framework - Knowledge of industry control framework, best practise, laws (e.g. GDPR, countries privacy laws, etc) and regulatory landscape
- Risk Management - Able to provide information security advises and opinions that continuously strike the right balance between controls enforcement, risk appetite and nett risk exposure.
- 5+ years experiences in privacy, security, or related data protection fields.
- Bachelors degree or equivalent professional experience required.
- Legal and/or financial services background/experience preferred.
- Other Privacy Certifications such as CIPP/M or CIPT preferred.
- Certified Information Security Professional (CISSP), or other related certifications (e.g. CISM, CISA) preferred.
Seniority level
Seniority level
Mid-Senior level
Employment type
Employment type
Full-time
Job function
Job function
Other, Information Technology, and Management
Referrals increase your chances of interviewing at Prudential plc by 2x
Sign in to set job alerts for “Security Professional” roles.
Security Officer - No PLRD license welcome to apply
Security Officer (Conrad Singapore Orchard)
Security Officer/Senior Security Officer (General Posting)
Global Security Specialist (Asia-Pacific)
Associate / Senior Associate Airport Operations (Safety, Security & Compliance)
Cybersecurity Officer for Southeast Asia
Security Manager, Global Corporate Security
Information Technology - Cyber Security Analyst (Scoot)
Information Technology - Cyber Security Specialist (Risk and Governance)
Senior Security, Resiliency and Control Manager
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrSecurity Management & Engagement
Posted today
Job Viewed
Job Description
Join to apply for the
Security Management & Engagement
role at
Prudential plc
Join to apply for the
Security Management & Engagement
role at
Prudential plc
Get AI-powered advice on this job and more exclusive features.
Prudential's purpose is to help people get the most out of life. We will deliver our purpose by creating a culture in which diversity is celebrated and inclusion assured, for our colleagues, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and in exchange, we support our people's career ambitions. We pledge to make Prudential a place where you can Connect, Grow and Succeed.
Job Purpose
The Senior Manager, Security Management & Engagement, is responsible for ensuring the adequate protection of the confidentiality, integrity and availability of business information assets against latest threats and vulnerabilities as well as ensuring ongoing adherence to Group, Regional and country regulations and policies with respect to information security and privacy.
Essential Job Duties & Responsibilities
Coaches and provides sound information security direction, advice and consultation
Facilitates assessments over information security management controls and third-party assessments.
Facilitates implementation of appropriate access using knowledge of business roles and assists management with performing regular access certifications.
Proactively engages the businesses to identify, document and drive remediation of risks by working with the business to design, implement or otherwise improve control activities to achieve Information Security objectives.
Leads data protection program within each of the business units assigned, including unstructured data classification activities.
Participates in the identification of Information Security Training and Awareness needs assessment on a regular basis and supports implementation of Information Security training and awareness plan and associated activities.
Ensures stakeholders understand the state of the controls they are accountable for and understand their responsibilities as to risk mitigation and remediation.
Provides direction on process improvements, remediating control gaps, and enhancing current tools for strengthening the overall information security control posture.
Advises the business on security policies and standards to achieve security objectives and reduce the likelihood and impact of security risks.
Plans and coordinates Information Security projects and initiatives within the business according to established plans and timelines.
Works to ensure monitoring and tracking of country, state and federal regulations pertinent to information security and privacy within the assigned business area(s).
Liaises and facilitates internal audit, external audit, investigation and compliance review of security activities employed by the business.
Coordinates the understanding and reporting on the overall information security risk posture of the business unit, providing a holistic view of vulnerabilities and associated risks to the business and Information Security.
Knowledge, Skills & Abilities
Communication - Able to work and spread positive "security awareness and control due-diligence" influence with people from various level of the organization effectively.
Technical Depth - Technically competent to be able to translate information security topics, initiatives / program into something that is digestible for stakeholders outside of information security community.
Technical Breadth - Display subject matter experience in diverse information security and Privacy areas (e.g. application security, Cloud security, Vulnerability Management, agile lifecycle management, DevSecOps, etc)
Know your Business - Strong business acumen within the insurance / financial services industry and related operational fields.
Controls Framework - Knowledge of industry control framework, best practise, laws (e.g. GDPR, countries privacy laws, etc) and regulatory landscape
Risk Management - Able to provide information security advises and opinions that continuously strike the right balance between controls enforcement, risk appetite and nett risk exposure.
Education and Experience
5+ years experiences in privacy, security, or related data protection fields.
Bachelors degree or equivalent professional experience required.
Legal and/or financial services background/experience preferred.
Other Privacy Certifications such as CIPP/M or CIPT preferred.
Certified Information Security Professional (CISSP), or other related certifications (e.g. CISM, CISA) preferred.
Prudential is an equal opportunity employer.
We provide equality of opportunity of benefits for all who apply and who perform work for our organisation irrespective of sex, race, age, ethnic origin, educational, social and cultural background, marital status, pregnancy and maternity, religion or belief, disability or part-time / fixed-term work, or any other status protected by applicable law. We encourage the same standards from our recruitment and third-party suppliers taking into account the context of grade, job and location. We also allow for reasonable adjustments to support people with special requirements.
Seniority level
Seniority level Mid-Senior level
Employment type
Employment type Full-time
Job function
Job function Other, Information Technology, and Management
Referrals increase your chances of interviewing at Prudential plc by 2x
Sign in to set job alerts for “Security Professional” roles.
Security Officer - No PLRD license welcome to apply
Security Officer (Conrad Singapore Orchard)
Security Officer/Senior Security Officer (General Posting)
Global Security Specialist (Asia-Pacific)
Associate / Senior Associate Airport Operations (Safety, Security & Compliance)
Cybersecurity Officer for Southeast Asia
Security Manager, Global Corporate Security
Information Technology - Cyber Security Analyst (Scoot)
Information Technology - Cyber Security Specialist (Risk and Governance)
Senior Security, Resiliency and Control Manager
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-Ljbffr
Be The First To Know
About the latest Security leadership Jobs in Singapore !
Vice President, Information Security Threat Management Specialist, Global Information Security
Posted 5 days ago
Job Viewed
Job Description
Singapore, Singapore
**To proceed with your application, you must be at least 18 years of age.**
Acknowledge
Refer a friend
**To proceed with your application, you must be at least 18 years of age.**
Acknowledge ( Description:**
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
**Job Description:**
The Identity Defense team aims to mitigate incidents through monitoring of network account usage, authentication activities and authentication behaviors. The team is responsible to reduce the risk associated with misuse or illicit use of accounts which grant access to Bank of America's workforce network. An Identity Defense analyst is accountable for researching, designing, engineering, implementing, and supporting solutions to prevent and detect anomalous use of accounts.
**Responsibilities:**
The Identity Defense Specialist will support design efforts to build out new processes, controls, and supporting governance related to implementation of human and non-human account monitoring to protect the Bank. You will utilize in-depth technical knowledge and business requirements to help implement scalable solutions, inclusive of monitoring, alerting, and escalation frameworks focused on core account protections. Leveraging your knowledge of both common and emerging threats related to account take-over, you will have an opportunity to proactively develop, implement, and influence controls and policy within the digital identity domain. You will partner with leaders from line of business organizations to triage security events and report on impacting security incidents.
The Analyst will regularly collaborate with experts in and out of our team, both in country and in other regions, so excellent communication skills are very important. The role will also involve discussion with employees as part of alert analysis and disposition. If you are seeking a demanding role within Global Information Security (GIS) and have the required skills, this will be a great opportunity for you. Typically, applicants should have 3+ years of cybersecurity or engineering experience. Responsibilities include, but are not limited to:
+ Actively investigate alerts related to potentially anomalous behavior/activity.
+ Confidently and professionally interview/question users to determine or confirm root cause.
+ Communicate effectively with response and business partners.
+ Build and monitor Splunk alerting and dashboards.
+ Identify areas for further process automation, simplification, and improvement.
+ Provide status updates for executives and stakeholders in non-technical terms encompassing risk, impact, containment, remediation, etc.
+ Risk management.
+ Comprehensively document analysis, investigative activities, actions, etc.
**Required Skills:**
+ 3+ years of experience with cloud information security related activities.
+ 3+ years of experience in an operations focused cloud information security role.
+ Experience conducting analysis/investigation and containment of potential data breaches or cyber security incidents.
+ Ability to analyze data and evaluate relevance to a specific incident under investigation.
+ Ability to handle multiple competing priorities in a fast-paced environment; ability to be decisive and take action without causing an undue delay.
+ Ability to exercise independent judgment when responding to alerts.
+ Ability to communicate effectively across all levels of the organization, to both technical and non-technical audiences.
+ Familiarity with security vulnerabilities exploits and hacker techniques.
+ Familiarity identity management standards, social engineering TTPs, and the incident response lifecycle.
+ Familiarity with Splunk, and the ability to build queries, alerts, dashboards, etc.
+ Knowledgeable of current authentication-based exploits.
+ Proven experience presenting findings via written reports and orally to key stakeholders in clear and concise language.
+ Supportive and can work well as part of a team as well as independently.
+ Can remain calm under pressure.
+ Ability to work in a strong team-orientated environment with a sense of urgency and resilience.
+ Critical thinking - must be able to think outside the box and develop solutions to accomplish seemingly impossible tasks while remaining risk and objective focused.
**Desired Skills:**
Desired Skills/Qualifications/Certifications:
Cloud+; AZ-900 (Azure Fundamentals), AZ-500 (Azure Security Engineer Associate), SC-900 (Security, Compliance and Identity Fundamentals); AWS Certified Security Specialty 2024
Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
To view the "Know your Rights" poster, CLICK HERE ( .
View the LA County Fair Chance Ordinance ( .
Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy ("Policy") establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank's required accommodation request process before your first day of work.
This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.
Vice President, Information Security Threat Management Specialist, Global Information Security
Posted today
Job Viewed
Job Description
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us
Job Description:
The Identity Defense team aims to mitigate incidents through monitoring of network account usage, authentication activities and authentication behaviors. The team is responsible to reduce the risk associated with misuse or illicit use of accounts which grant access to Bank of America's workforce network. An Identity Defense analyst is accountable for researching, designing, engineering, implementing, and supporting solutions to prevent and detect anomalous use of accounts.
Responsibilities:
The Identity Defense Specialist will support design efforts to build out new processes, controls, and supporting governance related to implementation of human and non-human account monitoring to protect the Bank. You will utilize in-depth technical knowledge and business requirements to help implement scalable solutions, inclusive of monitoring, alerting, and escalation frameworks focused on core account protections. Leveraging your knowledge of both common and emerging threats related to account take-over, you will have an opportunity to proactively develop, implement, and influence controls and policy within the digital identity domain. You will partner with leaders from line of business organizations to triage security events and report on impacting security incidents.
The Analyst will regularly collaborate with experts in and out of our team, both in country and in other regions, so excellent communication skills are very important. The role will also involve discussion with employees as part of alert analysis and disposition. If you are seeking a demanding role within Global Information Security (GIS) and have the required skills, this will be a great opportunity for you. Typically, applicants should have 3+ years of cybersecurity or engineering experience. Responsibilities include, but are not limited to:
- Actively investigate alerts related to potentially anomalous behavior/activity.
- Confidently and professionally interview/question users to determine or confirm root cause.
- Communicate effectively with response and business partners.
- Build and monitor Splunk alerting and dashboards.
- Identify areas for further process automation, simplification, and improvement.
- Provide status updates for executives and stakeholders in non-technical terms encompassing risk, impact, containment, remediation, etc.
- Risk management.
- Comprehensively document analysis, investigative activities, actions, etc.
Required Skills:
- 3+ years of experience with cloud information security related activities.
- 3+ years of experience in an operations focused cloud information security role.
- Experience conducting analysis/investigation and containment of potential data breaches or cyber security incidents.
- Ability to analyze data and evaluate relevance to a specific incident under investigation.
- Ability to handle multiple competing priorities in a fast-paced environment; ability to be decisive and take action without causing an undue delay.
- Ability to exercise independent judgment when responding to alerts.
- Ability to communicate effectively across all levels of the organization, to both technical and non-technical audiences.
- Familiarity with security vulnerabilities exploits and hacker techniques.
- Familiarity identity management standards, social engineering TTPs, and the incident response lifecycle.
- Familiarity with Splunk, and the ability to build queries, alerts, dashboards, etc.
- Knowledgeable of current authentication-based exploits.
- Proven experience presenting findings via written reports and orally to key stakeholders in clear and concise language.
- Supportive and can work well as part of a team as well as independently.
- Can remain calm under pressure.
- Ability to work in a strong team-orientated environment with a sense of urgency and resilience.
- Critical thinking - must be able to think outside the box and develop solutions to accomplish seemingly impossible tasks while remaining risk and objective focused.
Desired Skills:
Desired Skills/Qualifications/Certifications:
Cloud+; AZ-900 (Azure Fundamentals), AZ-500 (Azure Security Engineer Associate), SC-900 (Security, Compliance and Identity Fundamentals); AWS Certified Security Specialty 2024
Tell employers what skills you haveInformation Security
Remediation
Splunk
Analytical thinking
Azure
Teamorientated
Cyber Security
Critical Thinking
Investigation
Risk Management
cloud servers
Vice President, Information Security Threat Management Specialist, Global Information Security
Posted today
Job Viewed
Job Description
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us
Job Description:
The Identity Defense team aims to mitigate incidents through monitoring of network account usage, authentication activities and authentication behaviors. The team is responsible to reduce the risk associated with misuse or illicit use of accounts which grant access to Bank of America's workforce network. An Identity Defense analyst is accountable for researching, designing, engineering, implementing, and supporting solutions to prevent and detect anomalous use of accounts.
Responsibilities:
The Identity Defense Specialist will support design efforts to build out new processes, controls, and supporting governance related to implementation of human and non-human account monitoring to protect the Bank. You will utilize in-depth technical knowledge and business requirements to help implement scalable solutions, inclusive of monitoring, alerting, and escalation frameworks focused on core account protections. Leveraging your knowledge of both common and emerging threats related to account take-over, you will have an opportunity to proactively develop, implement, and influence controls and policy within the digital identity domain. You will partner with leaders from line of business organizations to triage security events and report on impacting security incidents.
The Analyst will regularly collaborate with experts in and out of our team, both in country and in other regions, so excellent communication skills are very important. The role will also involve discussion with employees as part of alert analysis and disposition. If you are seeking a demanding role within Global Information Security (GIS) and have the required skills, this will be a great opportunity for you. Typically, applicants should have 3+ years of cybersecurity or engineering experience. Responsibilities include, but are not limited to:
- Actively investigate alerts related to potentially anomalous behavior/activity.
- Confidently and professionally interview/question users to determine or confirm root cause.
- Communicate effectively with response and business partners.
- Build and monitor Splunk alerting and dashboards.
- Identify areas for further process automation, simplification, and improvement.
- Provide status updates for executives and stakeholders in non-technical terms encompassing risk, impact, containment, remediation, etc.
- Risk management.
- Comprehensively document analysis, investigative activities, actions, etc.
- 3+ years of experience with cloud information security related activities.
- 3+ years of experience in an operations focused cloud information security role.
- Experience conducting analysis/investigation and containment of potential data breaches or cyber security incidents.
- Ability to analyze data and evaluate relevance to a specific incident under investigation.
- Ability to handle multiple competing priorities in a fast-paced environment; ability to be decisive and take action without causing an undue delay.
- Ability to exercise independent judgment when responding to alerts.
- Ability to communicate effectively across all levels of the organization, to both technical and non-technical audiences.
- Familiarity with security vulnerabilities exploits and hacker techniques.
- Familiarity identity management standards, social engineering TTPs, and the incident response lifecycle.
- Familiarity with Splunk, and the ability to build queries, alerts, dashboards, etc.
- Knowledgeable of current authentication-based exploits.
- Proven experience presenting findings via written reports and orally to key stakeholders in clear and concise language.
- Supportive and can work well as part of a team as well as independently.
- Can remain calm under pressure.
- Ability to work in a strong team-orientated environment with a sense of urgency and resilience.
- Critical thinking - must be able to think outside the box and develop solutions to accomplish seemingly impossible tasks while remaining risk and objective focused.
Desired Skills/Qualifications/Certifications:
Cloud+; AZ-900 (Azure Fundamentals), AZ-500 (Azure Security Engineer Associate), SC-900 (Security, Compliance and Identity Fundamentals); AWS Certified Security Specialty 2024