Cyber Security Threat Management SpecialistServe as a technical subject matter expert to the Threat Management Team within Vanguard’s Cyber Security Operations Center (CSOC). Develop methodologies in collecting and analyzing data from disparate systems to identify, contain, mitigate, and recover from cyber security threats or incidents. Conduct research and information gathering from multiple intelligence sources, to identify emerging cyber threats and data exfiltration techniques.
Primarily responsible for managing the network data loss prevention (nDLP) platform. Develop custom rules or tune existing nDLP ones to ensure alerts generated are actionable.Maintains and provide enhancements to existing nDLP processes and procedures. Identifying new use cases and requirements to improve detection of data loss.Performs daily triage of nDLP alerts escalating incidents to the respective CSOC teams.Develop reports needed by management for metrics, trends, and anomalies.Assist and responds independently to escalated cyber security alerts, cyber incidents, or related security investigations.Provides support in representing the CSOC in partnering with GR&S.
ES&F, IT and the business on enterprise-wide security initiatives and projects.Facilitates security operations and incident response technologies and methodologies.Develops ad-hoc reports as required by management where a more in-depth analysis is required.Works collaboratively with other cyber crew member on research projects that involve event analysis to determine trends.Mentor junior team members to improve their technical acumen.Participates in special projects and performs other duties as assigned.Minimum of 3 years related work experience in cyber security with Data Loss Prevention technology as area of focus. Knowledge on Digital Guardian’s nDLP platform preferred.Proficient in using regular expressions.Resolves security issues to determine root cause and implements corrective action with appropriate level of assistance. Where necessary, partners with other members of Information Security, Information Technology and business departments.Must have excellent interpersonal, written, and verbal communication skills.Ability to learn and operate in a dynamic environment.Must be willing to work nights, weekends and holidays.
This role is 3-day shift work.Performs rotating on-call responsibilities.Required Skills: Network Security, Python. Additional Skills: Software Developer, Security Engineer. This is a high PRIORITY requisition.