Malware Defense Endpoint Analyst and Incident...

Bank of America
Charlotte, NC, United States
30 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

HTML JavaScript (Programming Language) Amazon Web Services Proxy Servers Microsoft Azure Cloud Computing Digital Forensics Dynamic Program Analysis Event Logging Fiddler (Software) Cloud Services Phishing
+6 more
Security Information and Event Management Wireshark Google Cloud Malware Process Monitor Web Technologies

Job description

  • Respond, triage, and adapt to real-time threats targeting the organization through the lens of malware delivery and execution.

  • Perform static, dynamic, and behavioral analysis of malicious software and potential indicators of compromise.

  • Maintain detailed documentation regarding analysis findings and producing comprehensive reports encompassing observations, actions taken, and recommendations.

  • Identify cyber risks and help develop improvements to controls and detection mechanisms.

  • Collaborate with response teams to defend against emerging threats and contribute to Incident Response efforts., Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.

View your “Know your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12.pdf) “ poster.

View the LA County Fair Chance Ordinance (https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf) .

Requirements

  • We are looking for mid-level candidates with malware analysis and incident response experience.

  • Specific experience with triaging detections, prioritizing threats, performing static and dynamic analysis, identifying security gaps, and implementing preventative measures.

  • Candidates should have a very strong investigative mindset with an ability to drive process changes and implement control enhancements.

  • Candidates should have 3-5 years of relevant experience in one or more threat prevention disciplines focusing on Email, Web, or Endpoint., * Understanding of browser exploitation techniques

  • Familiarity of web based technologies such as Javascript or HTML and how they are commonly abused by various threat actors or techniques.

  • Experience with reviewing and analyzing Email Headers.

  • Experience with detecting phishing and other common email threats.

  • SIEM experience with event correlation and searching.

  • Experience with dynamic analysis tools such as Process Monitor, FakeDNS, Regshot, or Wireshark.

  • Familiarity with use and interpretation of malware analysis results from sandbox technologies.

  • Technical experience and ability to operate and maintain a virtualized sandbox environment.

  • Familiarity with URL categorization and analysis tools like Fiddler, commercial sandbox, or web proxy technologies.

  • Ability to assess files or URLs and extract Indicators of Compromise (IoCs) such as malicious domains, IPs, and file hashes.

  • Experience with documentation and ability to clearly articulate thoughts to a wide variety of intended audiences (teammates, technical, non-technical, leadership, etc.).

  • Knowledge of Endpoint Detection and Response (EDR) tools

  • Knowledge of forensic artifacts such as Browser, Registry, or Event Log artifacts.

  • Knowledge of Cloud based Detection and Response tools.

Desired Qualifications

  • 3+ years of experience conducting end to end Malware analysis specifically around either Email, Web, or Endpoint.

  • 3+ years of conducting incident response using commercial products and tools.

  • 3+ years of experience in digital forensics

  • Knowledge of at least one major cloud services provider (AWS, GCP, Azure) technologies

  • Ability to create scripts and other forms of automation

  • Experience conducting interviews with an interrogative mindset

About the company

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.

We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.

Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Bank of America is one of the world’s leading financial institutions, serving over 66 million consumers and small businesses. Company success is only possible with a strong cyber defense, which enables Bank of America to safely conduct global operations across the United States and in approximately 35 countries. Our primary goal is to safeguard not only the company, but our clients and their trust. The Malware Defense Team is looking for top talent who would like to join one of the most advanced cybersecurity teams in the world., Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy (“Policy”) establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.

Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank’s required accommodation request process before your first day of work.

This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:27 min

Identifying malware threats in fake job interview repositories

Chris Heilmann +2 · LIVE

2:21 min

Projecting external HTML content using default and named slots

Rowdy Rabouw Rowdy Rabouw · World Congress 2022

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

6:12 min

Streaming HTML content natively using declarative processing instructions

Chris Heilmann +2 · LIVE

Videos

See all

Related articles

See all