
SOC Insider Threat Lead Analyst
6 days ago
Excited to grow your career?
We value our talented employees, and whenever possible strive to help one of our associates grow professionally before recruiting new talent to our open positions. If you think the open position you see is right for you, we encourage you to apply
Our people make all the difference in our success.Key Responsibilities
- The analyst will perform monitoring, research, assessment and analysis on alerts from various security tools, including firewalls, antivirus systems, user behavior analytics tools, proxy devices and SIEM tools, etc. which requires demonstrable security incident response and/or insider threat experience.
- Recommend and review new use cases for insider threat monitoring
- Follow pre-defined actions to investigate security incidents or perform incident response actions, including escalating to other support groups.
- Execute daily ad hoc tasks or lead projects as needed.
- Participate in or lead daily and ad-hoc conference calls; Create, update or provide process documentation, or provide requested evidence for compliance & controls requests.
Core Role Competencies
- Processes/ Procedures: Ensures processes and procedures are in place for self and others to use. Seeks ways to improve existing processes, making adjustments or recommending reengineering improvements.
- Customer and Industry Knowledge: Consistently applies a business driver and marketplace focus when prioritizing actions.
- Risk Management: Examines and defines factors that could adversely affect task completion, delivery or achievement of customer satisfaction. Evaluates controls to help mitigate negative outcomes through prevention, detection and correction. Identifies the risks of negative outcomes, including inadvertent error or fraud. Ensures ongoing compliance with regulatory requirements.
- Stakeholder Management: Identifies key partners and their influence, implements techniques for communicating/engaging and managing expectations. Has frequent interactions. Finds the appropriate balance of completing claims by various groups of stakeholders, acting fairly and in consideration of cultural and ethical factors.
- Problem Solving and Decision Making: Makes sound decisions. Considers relevant factors and uses appropriate decision-making criteria and principles. When making decisions, uses a mix of analysis, wisdom, experience and discernment. Assesses business needs, anticipates problems. Works independently and is self-directed.
Skills / Experience Levels
- You have 6+ years working in the security & operations fields
- You have a Bachelor’s degree or higher (Computer Science or Cybersecurity preferred) or equivalent work experience
- Excellent knowledge of network security, TCP/IP, various operating systems (Windows/UNIX), and web technologies (focusing on Internet security).
- Ability to read and understand packet level data; Experience with user behavior analytics, DLP, IDS/IPS, firewalls, and host security products (HIPS, AV, EDR, etc)
- Certifications from EC-Council, GIAC, or (ISC)² are preferred [CISSP, C|EH, GCIA, CCNA].
- You have good communication skills with the ability to articulate clearly in high stress situations
- You enjoy learning and love sharing your knowledge with others
- You work independently and are self-directed
- You are a detail oriented and perseverant individual
- You have a positive attitude with the drive to get the work done
- You are a self-starter with good problem solving skills, and you continuously look for ways to improve things.
- You understand the importance of prioritization of your work.
- You have skills and proficiency with MS PowerPoint, Excel, Access or other analytical tools**Job Family Group**:
Technology
- **Job Family**:
Information Security
- **Time Type**:
Full time
- Citi is an equal opportunity and affirmative action employer.
Qualified applicants will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
View the "**EEO is the Law**" poster. View the **EEO is the Law Supplement**.
View the **EEO Policy Statement**.
View the **Pay Transparency Posting
-
Insider Threat Analyst
2 weeks ago
Singapore UBS Full timeSingapore - Information Technology (IT) - Group Functions **Job Reference #** - 267238BR **City** - Singapore **Job Type** - Full Time **Your role** - Are you a cybersecurity professional with hands on experience identifying Insider threats? Do you routinely work closely with business, legal, compliance, and technology stakeholders to investigate...
-
Insider Threat Analyst
1 day ago
Singapore INNOVATIVE CONSULTING PTE. LTD. Full timeDescription: The insider threat analyst is responsible for researching, triaging, and investigating anomalous events of concern using Behavior Analytical tools, Splunk SIEM, and other tools to determine potential malicious or risky insider activity. This analyst role will come under the IT Risk and Security department reporting to the Security Operations...
-
Insider Threat Analyst
6 days ago
Singapore R SYSTEMS (SINGAPORE) PTE LIMITED Full time**Responsibilities**: - Conduct investigations by analyzing and verifying information through various investigative techniques, internal resources, forensics, and Insider threat tools such as Data Loss Prevention, End Point Detection and Response, Network Traffic Analysis & Deceptive Technology to detect malicious lateral movement & Privilege escalation in...
-
L2 SOC Analyst Lead
3 days ago
Singapore Monster SG Pte Limited Full timeRoles & Responsibilities We are seeking a seasoned Level 2 SOC Analyst Lead to spearhead threat operations, mentor junior analysts, and drive advanced investigations within a high-stakes 24/7 Security Operations Center. You will be responsible for incident response leadership, threat hunting, forensic analysis, and client governance, while ensuring...
-
Senior SOC Cyber Threat Analyst
3 days ago
Singapore Citi Full timeWe are seeking a highly skilled and experienced Senior SOC Analyst to join our Cyber Threat team in the Security Operations Center (SOC). The Global SOC operates in a 24x7, follow the sun model and is the firm's first line of defense against evolving cyber threats, ensuring the safety and integrity of our digital assets. This role requires an individual...
-
L2 SOC Analyst Lead
4 weeks ago
Singapore PERCEPT SOLUTIONS PTE. LTD. Full timeRoles & ResponsibilitiesWe are seeking a seasoned Level 2 SOC Analyst Lead to spearhead threat operations, mentor junior analysts, and drive advanced investigations within a high-stakes 24/7 Security Operations Center. You will be responsible for incident response leadership, threat hunting, forensic analysis, and client governance, while ensuring alignment...
-
SOC Analyst
1 week ago
Singapore ITCAN Full time**SOC** **Analyst** To perform threat monitoring, advance triage, incident response, and follow up on customer query - Monitor, review and profile the events. - Assess each event based on factual information and wider contextual information available - Produce reports to provide an accurate depiction of the current threat landscape and associated risk. -...
-
Insider Threat Analyst
1 day ago
Singapore IT CONSULTANCY & SERVICES PTE LTD Full timeAnalyzing and verifying information through various investigative techniques, internal resources, forensics, and Insider threat tools such as Data Loss Prevention, End Point Detection and Response, Network Traffic Analysis & Deceptive Technology to detect malicious lateral movement & Privilege escalation in On-prem and Cloud environment.Experience using...
-
Senior SOC Cyber Threat Analyst
6 hours ago
Singapore Citi Full timeWe are seeking a highly skilled and experienced Senior SOC Analyst to join our Cyber Threat team in the Security Operations Center (SOC). The Global SOC operates in a 24x7, follow the sun model and is the firm's first line of defense against evolving cyber threats, ensuring the safety and integrity of our digital assets. This role requires an individual with...
-
SOC Analyst
1 week ago
Singapore CYBEROWL PTE. LTD. Full timeWe're CyberOwl, a dynamic venture capital backed start-up that operates globally with colleagues based in the UK, Greece, Singapore, Malaysia, Poland and Portugal. CyberOwl helps maritime and CNI asset operators gain visibility, cybersecurity and compliance of systems on their distributed, remote assets. We work with ship owners and managers where our...