Information Security Specialist - Security Analytics
- Wilmington, DE, USA
- Permanent, Full time
- TD Bank Group
- 15 Dec 18
Information Security Specialist - Security Analytics
About TD Bank, America's Most Convenient Bank®
TD Bank, America's Most Convenient Bank, is one of the 10 largest banks in the U.S., providing more than 8 million customers with a full range of retail, small business and commercial banking products and services at approximately 1,300 convenient locations throughout the Northeast, Mid-Atlantic, Metro D.C., the Carolinas and Florida. In addition, TD Bank and its subsidiaries offer customized private banking and wealth management services through TD Wealth®, and vehicle financing and dealer commercial services through TD Auto Finance. TD Bank is headquartered in Cherry Hill, N.J. To learn more, visit www.tdbank.com. Find TD Bank on Facebook at www.facebook.com/TDBank and on Twitter at www.twitter.com/TDBank_US .
TD Bank, America's Most Convenient Bank, is a member of TD Bank Group and a subsidiary of The Toronto-Dominion Bank of Toronto, Canada, a top 10 financial services company in North America. The Toronto-Dominion Bank trades on the New York and Toronto stock exchanges under the ticker symbol "TD". To learn more, visit www.td.com .
Building a World-Class Technology Team at TD
We can't afford to be boring. Neither can you. The scale and scope of what TD does may surprise you. The rapid pace of change makes it a business imperative for us to be smart and open
About This Role
We are looking for someone to develop and implement Technology Controls and Information Security related policies, programs and tools. You will provide specialized expertise and guidance on assessing risks, identifying potential gaps and providing security solutions to mitigate risks and protect TD. You may also participate on projects of moderate to high complexity and provide complex reporting, analysis, and assessments at the functional, business line or enterprise level.
Meaningful work is fueled by meaningful performance and career development conversations with your manager. Here are the essential job functions of this position:
- Guide partners on a broad range of specific Technology Controls and Information Security programs, policies, standards and incidents.
- Conduct risk assessment, required controls definition, control procedure appropriateness, vulnerability assessments and any other relevant areas.
- Lead or contribute to the completion of risk and control design assessments for an assigned business application, business portfolio, and overall enterprise, as well as risk mitigation and remediation plans and remediation strategy.
- Contribute to the definition, development, and oversight of a global security management strategy and framework.
- Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology and security threats against TDBG's business.
- Develop on-going technology risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area.
- Adhere to internal policies and procedures, technology control standards, and applicable regulatory guidelines.
- Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement.
- Adhere to, advise, oversee, monitor and enforce enterprise frameworks and methodologies that relate to technology controls / information security activities.
- Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise .
What can you bring to TD? Share your credentials, but your relevant experience and knowledge can be just as likely to get our attention. Here are the minimum requirements for this position:
- University Degree.
- Information Security Certification / Accreditation an asset.
- 7+ years of relevant experience.
- Expert knowledge of IT security and risk disciplines and practices.
- Advanced knowledge of of organization, technology controls, security and risk issues.
- Demonstrated ability to participate in complex, comprehensive or large projects and initiatives.
- Ability to serve as a lead expert resource in technology controls and information security for project teams, the business, organization and outside vendors.
- Must be eligible for employment under regulatory standards applicable to the position.
Preferred Qualifications -
•3 to 5 years' work experience in information security, cyber security, data protection or a related field
•Minimum of a two-year degree in information protection, computer forensics, computer information systems, computer science, or information systems management
•Public Cloud: 2+ years of experience in performing security and compliance event management, security analytics configuration, security or UEBA use case development & tuning, and operational management & administration
•Enterprise SIEM: 3+ years of experience in performing security event management, security information event management and/ or security analytics configuration and management, security use case development and tuning, operational management and administration
•Working experience with security event management and security analytics operational governance and fundamental operational processes (intake of new log sources, on-boarding, use cases management, etc.)
•Proven experience with the successful development and deployment of use cases correlating information from various heterogeneous security feeds/platforms (e.g.: threat intel feeds, IOC. EDR, APT intelligence, etc.)
•Design and drive technical plans toward security analytics management objectives such as: integration of events from cloud platforms to enterprise SIEM; implementation of use case/policy using native public cloud security tools; net new security use cases development to support Security Logging & Monitoring/UEBA, account for the effect of the evolving threat space on the overall set of existing security use cases, net new log sources on-boarding (inclusive of testing and pre-production acceptance tasks), etc.
•Risk-based activities prioritization, reporting, and developing technical and process management remediation steps
•Develop and lead work-shopping activities for security use cases development and tuning, processes and run books for security event management and security analytics on-boarding/ off-boarding, intake management, requirements analysis, remediation, and reporting
•Identify problems and understand when to fix or when to mitigate risk
•Maintain governance material for the security event management and security analytics program as required
•Must have solid understanding of Public Cloud (infrastructure, operations, security logging & monitoring), Network and Security infrastructure, topology including firewalls, routers, wireless access points, DNS, DHCP, and Identity and Access Management technologies
•Experience with securing virtual, physical and cloud environments
•Working Experience with one or more of the following technologies:
Preferred: MS Azure Security Center (ASC), Microsoft Cloud Application Security (MCAS), Amazon Web Services (security services, e.g.: CloudTrail, CloudWatch), Splunk Enterprise Security, Splunk User Behavior Analytics
Optional: ArcSight, RSA, Securonix, Splunk, QRadar or equivalent tools
•Professional IT security certification such as CISSP, SANS Certified Intrusion Analyst (GCIA), CompTIA Security+, CEH, GSEC and/or CISM is preferred
•An understanding of regulatory and Controls requirements: PCI, FFIEC, SOX, HIPAA, ISO 2700x, NIST standards
At TD, we are committed to fostering an inclusive, accessible environment, where all employees and customers feel valued, respected and supported. We are dedicated to building a workforce that reflects the diversity of our customers and communities in which we live in and serve, and creating an environment where every employee has the opportunity to reach her/his potential.
If you are a candidate with a disability and need an accommodation to complete the application process, email the TD Bank US Workplace Accommodations Program at USWAPTDO@td.com . Include your full name, best way to reach you, and the accommodation needed to assist you with the application process.
EOE/Minorities/Females/Veterans/Individuals with Disabilities/Sexual Orientation/Gender Identity.