About the Role
The Cyber Security Defense (CSD) Information Security Threat Management team aims to reduce risk across Bank of America by leveraging multiple methods of application layer intrusion detection, prevention, and response activities. As a senior member of the team, you will be at the forefront of application security detection and response practice, collaborating with other security teams.
Responsibilities
- Analyze application layer alerts and conduct investigations.
- Respond to malicious actions of threat actors.
- Provide feedback to improve defensive capabilities.
- Leverage advanced investigative skills using data correlation and network/packet analysis tools.
- Assess new threat vectors and use intelligence to update or design controls.
- Participate in testing and deployment of new controls.
- Develop and implement custom alerts and dashboards monitoring OSI layer 7 attack and threat indicators.
- Mentor and develop the skill sets of less experienced team members.
- Develop and implement processes or controls for audit, compliance, and risk requirements.
- Partner with senior leaders to triage security events and report on impact.
- Execute and improve relevant risk management strategies.
Requirements
- Strong hands-on experience in application security detection and response technologies and processes.
- Understanding of common exploits, web application attacks, network protocols, and infrastructure/application logs (e.g., weblogs, AD logs, security logs).
- Advanced log analysis skills leveraging tools such as Splunk or other SIEM solutions.
- Experience maintaining and fine-tuning signatures on WAFs of leading vendors (e.g., F5 ASM, Akamai).
- Comfortable with scripting languages and regular expressions.
- Working knowledge of common operating systems (Windows/Linux/OS X).
- Experience in packet captures and analysis (e.g., Wireshark) is desirable.
- Ability to independently work in a fast-paced environment and drive continuous improvement.
- Excellent verbal and written communication skills, adaptable to various audiences.
Skills
- Application security detection and response
- Intrusion detection
- Intrusion prevention
- Intrusion response
- Data correlation
- Network analysis
- Packet analysis
- Threat intelligence
- SIEM solutions
- Splunk
- WAF
- F5 ASM
- Akamai
- Scripting languages
- Regular expressions
- Windows
- Linux
- OS X
- Wireshark
Location
- Australia
- Singapore
- UK
- US
Work Type
- Follow the sun (FTS) model
- On call
- After-hours work
Experience Level
- Senior member
Benefits
- Competitive benefits to support physical, emotional, and financial well-being.
About the Company
- At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection.
- Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.
- Being a great place to work for our teammates around the world is key to driving Responsible Growth.
- We are devoted to being a diverse and inclusive workplace for everyone.
- We hire individuals with a broad range of backgrounds and experiences.
- We invest heavily in our teammates and their families.
- Bank of America believes in the importance of working together and offering flexibility.
- Working at Bank of America offers opportunities to learn, grow, and make an impact.
- Partnering Locally: Learn about ways Bank of America makes a difference in communities.
- Global Impact: Learn about areas guiding efforts to help make financial lives better.
- Opportunity and Inclusion: Each employee brings unique skills, background, and opinions; we see opportunity and inclusion as our platform for innovation and success.
- Our Values: Learn about the four values that represent what we believe.
Equal Opportunity
- We are devoted to being a diverse and inclusive workplace for everyone.
- We hire individuals with a broad range of backgrounds and experiences.
