Citi Technology Infrastructure (CTI) provides the products and services that enable Citi's workforce, along with the majority of the financial solutions that Citi's customers rely on. We provide the critical technical foundation for Citi's operations through the infrastructure that runs business and general user computing services. We do this by working as one-team to deliver high quality, reliable and modern infrastructure technologies at the right cost. We drive to optimize the functionality and capability of the infrastructure technologies.
This role is an integral part of Cyber Security Services as part of our Global Security Operations Center.
The Security Operations Center Incident Response/Insider Threat role will be part of the Global SOC.The SOC is responsible for monitoring, analyzing, and responding to cybersecurity and infrastructure threats on a 24x7 basis.
In CTI, we are focused on delivering the best for our clients, and we know that to do this we need a talented team with diverse experiences, backgrounds and skills.
* The analyst will perform monitoring, research, assessment and analysis on alerts from various security tools, including Intrusion Detection and Prevention tools, anomaly detection systems, firewalls, antivirus systems, user behavior analytics tools, proxy devices (ArcSight, Arbor PeakFlow, Palo Alto Networks, etc.) which requires demonstrable security incident response and/or insider threat experience. * Recommend and review new use cases for insider threat monitoring
* Support the development and enhancement of SOC incident response capabilities.
* Follow pre-defined actions to investigate security incidents or perform incident response actions, including escalating to other support groups.
* Execute daily ad hoc tasks or lead projects as needed.
* Participate in or lead daily and ad-hoc conference calls; Create, update or provide process documentation, or provide requested evidence for compliance & controls requests.
Core Role Competencies
* Technical Knowledge: Has a recognizable area of technical competence. Familiar with appropriate standards. Applies subject domain knowledge to meet organizational need/guide actions. Keeps up with current and possible future technological developments in the field. * Processes/ Procedures: Ensures processes and procedures are in place for self and others to use. Seeks ways to improve existing processes, making adjustments or recommending reengineering improvements. * Customer and Industry Knowledge: Consistently applies a business driver and marketplace focus when prioritizing actions. * Risk Management: Examines and defines factors that could adversely affect task completion, delivery or achievement of customer satisfaction. Evaluates controls to help mitigate negative outcomes through prevention, detection and correction. Identifies the risks of negative outcomes, including inadvertent error or fraud. Ensures ongoing compliance with regulatory requirements. * Stakeholder Management: Identifies key partners and their influence, implements techniques for communicating/engaging and managing expectations. Has frequent interactions. Finds the appropriate balance of completing claims by various groups of stakeholders, acting fairly and in consideration of cultural and ethical factors. * Problem Solving and Decision Making: Makes sound decisions. Considers relevant factors and uses appropriate decision-making criteria and principles. When making decisions, uses a mix of analysis, wisdom, experience and discernment. Assesses business needs, anticipates problems. Works independently and is self-directed.
Skills / Experience Levels
* You have 4+ years working in the security & operations fields * You have a Bachelor's degree or higher (Computer Science or Cybersecurity preferred) or equivalent work experience * Excellent knowledge of network security, TCP/IP, various operating systems (Windows/UNIX), and web technologies (focusing on Internet security).
* Ability to read and understand packet level data; Experience with intrusion detection and prevention systems, network security products (IDS/IPS, firewalls, etc.) and host security products (HIPS, AV, EDR, etc.)
* Knowledge of cutting edge threats and technologies affecting Web Application vulnerabilities and recent internet threats.
* Exposure to vulnerability assessment tools and techniques; experience with penetration testing or forensic analysis fields is a plus.
* Certifications from EC-Council, GIAC, or (ISC)² are preferred [CISSP, C|EH, GCIA, CCNA]. * You have good communication skills with the ability to articulate clearly in high stress situations * You enjoy learning and love sharing your knowledge with others * You work independently and are self-directed * You are a detail oriented and perseverant individual * You have a positive attitude with the drive to get the work done * You are a self-starter with good problem solving skills, and you continuously look for ways to improve things. * You understand the importance of prioritization of your work. * You have skills and proficiency with MS PowerPoint, Excel, Access or other analytical tools
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Citigroup is a company providing financial products and services.