Cyber Security Analyst III

First Citizens
Austin, TX, United States
9 days ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) Private Networks Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Antivirus Softwares Automation of Tests Microsoft Azure Bash Shell Cloud Computing Security Static Program Analysis
+39 more
CompTIA Security+ Cyber Security Computer Programming Databases Web Development Github Monitoring of Systems Internet Protocol Internet Protocol Security (IP SEC) Intrusion Detection Systems Virtual Private Networks (VPN) Python (Programming Language) Machine Learning Packet Analyzer Open Web Application Security Performance Tuning Systems Development Life Cycle Regular Expressions Phishing Web Application Security SoapUI Software Engineering Network Routers Scripting Google Cloud Postman Software Security Malware Cyber Threat Analysis Firewalls (Computer Science) Cross-Site Scripting (XSS) Information Technology Virtual Agents Cyber Warfare Data Pipelines Devsecops Jenkins Static Application Security Testing Dynamic Application Security Testing

Job description

This position supports Information Security and Cyber Threat management programs within the Bank at a complex level of ability. Analyzes vulnerability and threat data that provides actionable intelligence for cyber defense efforts. Evaluates the Bank’s networks and systems to identify technical security gaps or deficiencies. Develops process improvements and technical solutions that address the identified gaps or deficiencies. Facilitates the defense of the organization’s information security and technological architecture through ongoing reporting and escalation of emerging threats. Maintains expert knowledge and educates others on security threats, industry trends, and other relevant intelligence. Assists management with special projects and oversees less experienced associates in the work group., Security Review - Monitors and evaluates security incidents, system alerts, audit events, and other activity for potential threats against the Bank’s networks and systems. Detects anomalies, malware infections, and intrusion attempts. Identifies, recommends, and executes appropriate mitigation tactics for identified threats. Provides guidance and resolution for complex security issues. Business Support - Serves as an analytics resource for associate team, management, and business units. Supports the design and implementation of new security products, services, procedures, and technologies in response to changes in the security threat landscape. Enables the defense of the organization’s information security and technological architecture through a number of operational and technical tasks. Ensures all cyber security monitoring systems are online and fully operational as well as ensuring compliance with all security policies and standards. Analysis - Analyzes data from various operating systems, databases, and applications within the Bank. Sources and interprets data to proactively search for threats. Reporting - Produces reports that document investigation and security incidents as well as the results of analysis. Provides analytics and reporting that facilitates actionable cyber-intelligence within daily operations. Conveys information to the appropriate parties, which includes both internal and external partners.

Requirements

Knowledge of security event log analytics and at least two of the following technologies: Firewall, Web-Proxy, IDS/IPS, Anti-Virus/Anti-Malware, Anti-Phishing, Malicious Web Site reporting or take-down Knowledge of at least three of the following: Insider Threats, Advanced Persistent Threats, Malware Analysis, Exploit techniques, Regular Expressions, SEIM Tuning , Alarm and Signature Creation Knowledge of Information Technologies with a focus in two or more of the following areas: operating systems, networking, computer programming, web development or database administration Understanding of Internet Protocol Suite networking, including routers, switches, public and private networks, internet protocol security, and virtual private networks Understanding of Packet Capture and analysis Knowledge of systems administration and analysis as well as risk management standards, procedures, and practices, Minimum Required Education and Experience: Bachelor’s Degree and 6 years’ experience., High School Diploma or GED/Equivalent and 10 years’ experience in Information Security., * Hands-on experience with:

  • SAST, DAST, and SCA tools
  • Web application security testing (OWASP Top 10, API security)
  • Strong understanding of:
  • Secure software development lifecycle (SDLC / DevSecOps)
  • Common vulnerabilities (e.g., injection, XSS, authentication flaws)
  • Proficiency in one or more programming/scripting languages (e.g., Python, Java, JavaScript, Bash)
  • Experience interpreting and prioritizing scan results and remediation plans, * Experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, Azure DevOps)
  • Familiarity of container and cloud security (AWS, Azure, GCP)
  • Familiarity with AI/ML concepts and security implications
  • Industry certifications such as:

  • CEH, Security+, SSCP, GIAC or comparable.

Key Skills:

  • Strong analytical and problem-solving skills
  • Provide risk-based recommendations to stakeholders
  • Ability to communicate technical findings to both technical and non-technical stakeholders
  • Experience working cross-functionally with development and engineering teams
  • Attention to detail with a risk-based security mindset

Nice-to-Have Experience:

  • API security testing tools (Postman, SoapUI)
  • AI-assisted security tooling (e.g., anomaly detection, code analysis assistants)
  • Knowledge of regulatory frameworks (NIST, ISO 27001, SOC 2)
  • AI/ML & Emerging Technologies

  • Leverage AI/ML-based security tools for enhanced detection and analysis
  • Assess risks related to AI/ML models (e.g., data poisoning, model inversion, adversarial attacks)
  • Participate in securing AI-driven applications and data pipelines

Threat Analysis & Risk Management

  • Assess potential threats and attack vectors relevant to applications and APIs
  • Apply threat modeling techniques (e.g., STRIDE) during development lifecycle

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all