VP, Advanced Threat Research, Information Security
Posting Date: 01-Feb-2020
Location: Alexandra, Singapore, SG
Company: United Overseas Bank Limited About UOB
United Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia Pacific, Europe and North America. In Asia, we operate through our head office in Singapore and banking subsidiaries in China, Indonesia, Malaysia and Thailand, as well as branches and offices.
Our history spans more than 80 years. Over this time, we have been guided by our values - Honorable, Enterprising, United and Committed. This means we always strive to do what is right, build for the future, work as one team and pursue long-term success. It is how we work, consistently, be it towards the company, our colleagues or our customers. About the Department
The Technology and Operations
function is comprised of five teams of specialists with distinct capabilities: business partnership, technology, operations, risk governance and planning support and services. We work closely together to harness the power of technology to support our physical and digital banking services and operations. This includes developing, centralising and standardising technology systems as well as banking operations in Singapore and overseas branches. Job Responsibilities
- Active hunting activity involving the analysis of machine data to determine anomalies, threats and suspected compromises.
- Conduct network flow and network deep packet analysis.
- Utilize advanced big data analytics tools and technology to determine anomalies and threats
- Continuously re-engineer and tune GSOC workflows and capabilities to improve operational effectiveness.
- Develop and streamline GSOC prevent, detect, response processes using automation and orchestration tools.
- Respond to Cyber threats.
- Provide subject matter expertise to the incident response manager.
- Develop and operationalize new threat response mechanism and processes.
- Conduct Cyber response exercises to tune processes and maintain operational readiness.
- Support and maintain GSOC's detection, prevention, response and monitoring systems and infrastructure via change management process.
- Enhance current detection capabilities and develop new detection use-cases
- Conduct regression testing and build enhancements on GSOC systems. Implement new technology and process improvements to security monitoring and cyber defense mechanisms.
- Research and define requirements for new projects; perform product evaluations and technical Proof of Concepts
Job Requirements Education
- Perform as a member of the Cyber security capability enhancement team to drive or participate in product evaluation, project discussion and deployments
- Work within established practices and handling guidelines to develop and deploy preventive maintenance processes for GSOC infrastructure
- Work with internal technical teams and engineers in technical troubleshooting, exercises and forums
- Available to respond to client requests and assist with troubleshooting activities
- Able to resolve customer related issues with minimal guidance
- Communicate effectively with a variety of internal teams and external contacts including technical and executive contacts
- Capable of juggling variety of priorities and deliverables in an interrupt driven environment with minimal guidance or supervision
Technical Skills and experience
- ITC/Diploma/Degree in engineering/Computer Science / IT/Cyber Security from a recognized education institution
- Professional security related qualification (e.g. SANS GCIA, GCIH etc.) is favorable
- Min 8-10 years of relevant Cyber security experience
- Good knowledge in networking technology and network security (i.e. Firewalls, WAF, IDS, IPS, VPN, HIPS, ADS, SIEM, UBA and TCP/IP protocols)
- Minimum 2 years of relevant working experience in a SOC environment
- Familiar with SOC processes
- Understanding of threat response and incident response
- Hands-on experience in Unix/Linux and Windows administration
- Hands-on experience in Security Information Event Management System (SIEMS)
- Hands-on coding experience: python, shell scripts
- Strong foundation in security threat TTPs and attack counter measure
- Analytical problem solver and good at troubleshooting technical issues
- Effective time management and organizational skills
- Operational knowledge of SIEMS, Breach Detection System, Network Forensic System, Big Data analytics, User Behavior Analytics and endpoint security technology
- Use of malware analysis platforms and tools
- Use of threat intelligence platforms and tools
- Technical/logical understanding of FW/IDS/IPS/WAF rule and SIEM rule construction
- Programming, concepts and scripting languages - Python, Ruby, Power-shell, Java, C/C++, Regex, STIX
- Good understanding of network forensics and packet analysis
- Good understanding of SQL/Database, SOAP-XML, Restful API
- Good understanding of internet concepts and technologies - internet services, search engines, open source tools, android/iOS - mobile technology, LAMP, iOT, TOR etc.
Be a part of UOB Family
- Good written and verbal communication skills
- Process and procedure adherence
- Strong analytical and problem solving skill
Apply now and make a difference.