Network Cyber Threat Defense Security Engineer - DDOS
Role details
Job location
Tech stack
Job description
This is a Cyber Security role in Information Security with a focus on Network Security Engineering. The candidate will work in a fast paced environment, identifying and responding to cyber security events, while developing engineering solutions and network architectures that enable efficient and timely responses to mitigate malicious actors.
The Network Defense (ND) team in the Global Information Security organization is responsible for defending the Bank's Internet facing networks and applications from disruptive security threats such as Distributed Denial of Service (DDoS) attacks. Network Defense works at the tip of the spear to ensure that customers have an uninterrupted network experience, by rapidly responding to security events, developing defenses, and mitigating attacks. ND team members are expected to be subject matter experts on disruptive security events and able to apply their extensive knowledge of computer networking and cyber security threats in order to develop solutions to complex cyber scenarios.
Minimum Years of Experience - 3
Key Responsibilities
-
Lead end-to-end engineering projects for network security infrastructure, including DDoS mitigation platforms, BGP routing safeguards, and global cloud scrubbing services.
-
Architect, plan, and execute platform upgrades and large-scale control improvements.
-
Evaluate, select, and implement next-generation security controls, aligning with regulatory and financial services industry standards.
-
Define and maintain baseline configurations for on and off premise DDoS scrubbing solutions, CDN rules, cloud security controls, and other related security controls.
-
Partner with enterprise network engineering teams to ensure security considerations are integrated into all bank-wide infrastructure projects.
-
Conduct validation and testing of controls before and after deployment; maintain full auditable documentation for regulatory compliance.
-
Act as a subject matter expert on DDoS defense, BGP hijack protection, and internet-scale threat resilience.
-
Provide advanced troubleshooting and resolution of complex configuration issues across global environments.
-
Mentor a diverse group of network engineers and security operations experts in the delivery of network security responsibilities., Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
View your "Know your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12.pdf) " poster.
View the LA County Fair Chance Ordinance (https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf) .
Requirements
-
Expertise in DDoS defense technologies
-
Strong understanding of BGP routing, border gateway security, and internet-scale resiliency engineering.
-
Deep knowledge of network protocols (GRE, TCP/IP, UDP, DNS, HTTP/S).
-
Experience with enterprise-scale infrastructure projects and cloud security integration.
-
Hands-on with configuration management, validation frameworks, and automated monitoring solutions.
-
Familiarity with regulatory compliance frameworks (FFIEC, OCC, SOX, PCI DSS) in financial services.
-
Demonstrated leadership in global project delivery across distributed teams.
Skills:
- Cyber Security
- Data Privacy and Protection
- Problem Solving
- Process Management
- Threat Analysis
- Business Acumen
- Data and Trend Analysis
- Interpret Relevant Laws, Rules, and Regulations
- Risk Analytics
- Stakeholder Management
- Access and Identity Management
- Data Governance
- Encryption
- Information Systems Management
- Technology System Assessment