Cybersecurity Incident Response Analyst / Incident Response Lead Analyst / Hyderabad/ Cybersecurity
HSBC Group
1 month ago
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Experience level
Senior Compensation
£ 42KJob location
Tech stack
Java
Microsoft Windows
Amazon Web Services (AWS)
Android
iOS
Azure
Big Data
Cloud Computing
Communications Protocols
Computer Security
Computer Programming
Dynamic Host Configuration Protocol
Linux
DNS
Hypertext Transfer Protocols (HTTP)
Networking Hardware
Internet Protocol Security (IP SEC)
Intrusion Detection Systems
Kali Linux
Network Protocols
Security Information and Event Management
Transmission Control Protocol (TCP)
Scripting (Bash/Python/Go/Ruby)
Malware
Firewalls (Computer Science)
IDA Pro
Encase
REST
Job description
We are currently seeking an experienced professional to join our team in the role of Incident Response Lead Analyst.
In this role, you will:
- Performing the technical and forensic investigations into cyber security events across the globe, taking responsibility for the timely identification of cyber-threats and where possible, minimizing further risk to HSBC's information assets and services.
- Carrying out post-incident reviews, assessing the effectiveness of controls, detection and response capability and supporting the required improvements with the responsible owners.
- Performing the forensic services for the collection, processing, preservation, analysis, and presentation of evidence in support of vulnerability mitigation and information security incident investigations.
- Maintaining a strong awareness of technology trends and industry best practice, to enable the provision of informed advice and guidance to HSBC Business functions and HSBC IT.
- Collaboration with the wider GCO teams (and wider business/function teams where applicable) in the production and maintenance of efficient and effective incident response playbooks.
- Supporting the Identification, development, and implementation of new detections (Use cases).
- Developing and defining detailed processes and procedures to manage the response to cyber security events.
- Directly contributing to the continued technical enhancement of the security platforms.
- Supporting the continued evolution of incident response and forensic capabilities and processes, including automation and orchestration.
- Training and developing other members of the Incident Management and Response team as well as other members of the Global Cybersecurity Operations function.
- Supporting a "self-critical" culture whereby identification of weaknesses in the bank's control plane (people, process, and technology) are brought to light in an effective manner and addressed.
- Supporting a culture of individual self-improvement whereby staff are expected to maintain subject matter expertise within their area of focus and within the realm of cybersecurity more broadly.
- Supporting engagement of Global Businesses and Functions everywhere HSBC does business that drives a global up-lift in cybersecurity awareness helping to "tell the story" of HSBC Cybersecurity efforts.
- Production of Management Information related to the CSIRT mission that is appropriate to the target audience, supported by data and experienced analysis enabling informed decisions.
Requirements
We are looking for a Java Developer with experience in related technologies like Spring, REST API technologies and techniques who is comfortable working alongside a strong, international team of engineers, to build applications for a key HSBC initiative., * Excellent knowledge and demonstrated experience of common cybersecurity technologies such as IDS / IPS / HIPS, Advanced Anti-malware prevention and analysis, Firewalls, Proxies, MSS, etc.
- Excellent knowledge of common network protocols such as TCP, UDP, DNS, DHCP, IPSEC, HTTP, etc. and network protocol analysis suits.
- Excellent knowledge of common enterprise technology infrastructure, platforms and tooling, including Windows, Linux, infrastructure management and networking hardware.
- Excellent knowledge and demonstrated experience in common cybersecurity incident response and forensic investigation tools such as: EnCase, FTK, Sleuthkit, Kali Linux, IDA Pro, DEFT, SANS SIFT, etc.
- Very good knowledge and demonstrated experience in analysis and dissection of advanced attacker tactics, techniques and procedures in order to inform adjustments to the control plane.
- Very good knowledge and demonstrated experience of common log management suites, Security Information and Event Management (SIEM) tools, use of "Big Data" and Cloud-based solution for the collection and real-time analysis of security information.
- Good knowledge of common mobile platforms, such as Blackberry, iOS, Android and Windows.
- Good knowledge of scripting, programming and/or development of bespoke tooling or solutions to solve unique problems.
- Some knowledge and technical experience of 3rd party cloud computing platforms such as AWS, Azure, and Google.
About the company
If you're looking for a career that will help you stand out, join HSBC and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further.
HSBC is one of the largest banking and financial services organizations in the world, with operations in 64 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people to fulfil their hopes and realize their ambitions.