Security Analyst, Incident Response (GSOC London)

Royal Bank of Canada
London, UK
24 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Bash Shell Cyber Security Computer Networks Intrusion Detection and Prevention Python (Programming Language) Windows PowerShell Regular Expressions Security Information and Event Management Scripting Malware Information Technology Cybercrime

Job description

You will be a key member of the RBC Global Security Incident Response team as an experienced Security Analyst. This is a key role within the Global Security Operations Centre (GSOC).

You will be providing technical expertise and leadership support to the proactive and reactive responses to cyber threats targeting RBC’s global environment.

You will report to the Senior Manager, Incident Response and work with a team of 4-6 technical specialists. You will act as the focal point of contact for GSOC management with regards to security incidents. You will provide support to local and extended team members with critical incidents impacting RBC users, systems, infrastructure, and resources.

Should you be shortlisted, do please let us know if you have any specific requirements for the interview.

This is a permanent, full-time role and requires 4 days in our London Fenchurch office.

What will you do?

  • Global accountability to respond to critical security incidents/events providing accurate and timely reporting to Global Cyber Security Leadership.
  • Provide 7/24/365 support for security incidents impacting mission critical business and IT infrastructure, including supporting global incident management and response, remediation and reporting.
  • Support and maintain communication with Computer Security Incident Response Team (CSIRT) extended team members ensuring timely communication to all stakeholders regarding incident response activities.
  • Provide post mortem reporting for leadership detailing security vulnerabilities, technology gaps, shortcomings or miscellaneous security issues.
  • Responsible for working with threat intelligence, Security Operations Centre and extended teams to ensure global compliance to RBC standards with respect to security incidents and related findings.
  • Responsible for driving to resolution security incidents in a timely and effective manner.
  • Work collaboratively with Cybersecurity Command Centre technical analysts, specialists and management to detail and report on the status and resolution of critical incidents.
  • Execute incident response actions and engage with business/technical stakeholders.

Requirements

  • Bachelor’s degree in computer sciences and/or IT related disciplines and Certifications in information security preferred (one or more of the following; CISSP, GCIA, GCIH, GREM, CEH).
  • Demonstrated experience performing investigation activities for security related events in a complex Incident Management or Security Operations Center environment.
  • Thorough understanding of Security Information and Incident Management methodologies.
  • Proven experience in a SOC environment.
  • Exposure to malware and sandbox analysis.
  • Robust computer networking & OS knowledge.

Nice-to-have

  • Experience with SOAR platforms.
  • Familiarity with threat hunting techniques and scenarios.
  • Knowledge in detection engineering.
  • Understanding of current threat landscape and threat actor TTPs.
  • Experience with scripting languages (PowerShell, python, regex, bash, etc.)
  • Industry recognized certifications from ISC2, SANS, ISACA, etc., Business Perspective, Critical Thinking, Decision Making, Detail-Oriented, Forensic Computing, Group Problem Solving, Information Security Operation Center (ISOC), IT Incident Management, Security Information and Event Management (SIEM), Threat Management

About the company

We thrive on the challenge to be our best - progressive thinking to keep growing and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.

  • Help to develop the ethos and environment of a new team.
  • Leaders who will support your development through coaching and managing opportunities
  • Have the opportunities to work with the best in the field
  • Ability to make a difference and lasting impact
  • Work in a dynamic, collaborative, progressive, and high-performing team, At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · WWC 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

Videos

See all

Related articles

See all