Sr. Malware Threat Intelligence Control Owner
Role details
Job location
Tech stack
Job description
The Threat Intelligence Control Owner is responsible for overseeing and enhancing the threat intelligence "processing" procedures within the Malware Defense program. This role involves close collaboration with cross-functional teams to ensure threat intelligence workflows are efficient, scalable, and aligned with enterprise security objectives. The Control Owner will drive improvements in automation, integration, and operational effectiveness using relevant technologies and platforms., + Own and manage the threat intelligence processing control, ensuring consistent execution and continuous improvement.
-
Collaborate with internal teams to refine procedures for investigating indicators of compromise (IOCs) across various log sources and controls.
-
Integrate and optimize relevant technologies and platforms to support and enhance threat intelligence workflows, automation, and operational efficiency.
-
Maintain, optimize, and automate Malware Defense's custom intelligence gathering workflows to improve speed, accuracy, and scalability.
-
Define and maintain documentation for threat intelligence processing standards, playbooks, and escalation paths.
-
Monitor control performance and identify opportunities for automation and efficiency.
-
Support audit and compliance efforts related to threat intelligence controls., Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
View your "Know your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12.pdf) " poster.
View the LA County Fair Chance Ordinance (https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf) .
Requirements
-
Threat Intelligence Experience: Intermediate to Advanced understanding of threat actor tactics, techniques, and procedures (TTPs).
-
Log Investigation Skills: Intermediate to Advanced experience analyzing logs from email, web, and endpoint sources.
-
Scripting & Development Experience: Intermediate proficiency with:
-
Languages & Frameworks: Python, Node.js, JavaScript
-
Web Frameworks: Django, FastAPI, Flask, Streamlit
-
Infrastructure & Tools: Linux, Docker, NGINX
-
Databases & Caching: PostgreSQL, Redis
-
API Integration: Experience utilizing RESTful APIs for application and platform integrations
-
Technology Proficiency:
-
LogScale (Log Analysis)
-
CrowdStrike Falcon (EDR), + Strong organizational and documentation skills.
-
Experience working in cross-functional environments.
-
Ability to identify gaps and drive process improvements.
-
Familiarity with control ownership responsibilities in a cybersecurity or risk management context.