Info Security Analyst mid-level - SOC/CTOC external threat team
Location: Sun City
Posted on: May 9, 2022
Purpose of Job About USAA
USAA knows what it means to serve. We facilitate the financial
security of millions of U.S. military members and their families.
This singular mission requires a dedication to innovative thinking
at every level.
About USAA IT
Our most meaningful qualification isn't technical, it's human.
Here, we don't just sit in front of a screen. We stand behind our
13 million members who rely on us every day.
We're proud of USAA's strong history -- and we're even more
passionate about our future. That's why we have a team of
supportive and collaborative hardworking technology professionals
focused on doing more for our members. And why we're continuing to
add innovative problem solvers to our team. With us, you'll find
exciting challenges that inspire you to continue learning and
USAA is seeking a hard-working InfoSec analyst - SOC/CTOC for our
San Antonio, TX, CO Springs, CO, or Phoenix, AZ facilities. The
role can also be hired 100% remote.
The Cyber Threat Operations Center (CTOC) is USAA's equivalent to a
Security Operations Center (SOC). The CTOC exists to detect,
analyze, and respond to cyber security events. The CTOC is
comprised of several teams, all reporting to the AVP of IS
Engineering & Cybersecurity. These teams are individual units that
partner as needed to provide centralized and coordinated response
USAA values a culture that is highly collaborative, and we have
found that a hybrid work type helps employees gain the best of both
worlds - collaborating in-person in the office and working from
home when needed to achieve focused results. The actual onsite days
are resolved between each employee and the employee's manager.
Investigates, analyzes, and responds to security anomalies and
events (e.g., suspicious behavior, attacks, and security breaches)
within USAA's environments using a variety of cyber defense tools
to detect and respond to threats. Conducts vulnerability, security
configuration, and/or penetration testing assessments of systems
and networks. Identifies cyber threats, analyzes operational
impacts, and communicates to appropriate stakeholders. Stays
current with latest information security threats, exploits, trends,
Identifies and manages existing and emerging risks that stem from
business activities and the job role.
Ensures risks associated with business activities are effectively
identified, measured, monitored, and controlled.
Follows written risk and compliance policies, standards, and
procedures for business activities.
Researches and analyzes the latest information security
vulnerabilities, threats, exploits, trends and intelligence.
Conducts routine vulnerability management, security configuration
assessments, and/or penetration testing operations and manages the
Monitors internal and external networks, systems, and applications
for security anomalies and events (e.g., suspicious behavior,
attacks, and security breaches). Responds to cyber incidents,
performing detailed analysis using complex security tools to
determine root cause by using a broad range of demonstrated
experience (e.g. forensics, networking, servers, coding, etc.) to
determine a malicious actor's tactics, techniques, and
Utilizes discoveries from the incident response process to make
moderately complex improvements to the existing detection
capabilities and security controls.
Prepares written briefs with recommendations to leadership on
latest threats, alerts, and incidents.
Serves as a resource to team members on escalated issues of an
Bachelor's degree; OR 4 years of related experience (in addition to
the minimum years of experience required) may be substituted in
lieu of degree.
4 years of related experience in Information Security,
Cybersecurity and/or Information Technology with a security focus
to include accountability for complex tasks and/or projects.
2 years of related experience in one of the following domains:
Security and Risk Management, Asset Security, Security Architecture
and Engineering, Communications and Network Security, Identity and
Access Management, Security Assessment and Testing, Security
Operations, Software Development Security.
Proficient level of business acumen in the areas of business
operations, risk management, industry practices and emerging
Knowledge and application of security-related monitoring, intrusion
detection and scanning tools.
Knowledge of system administration, network, and operating system
Demonstrated ability to evaluate current security practices,
identify compliance gaps, and propose remediation.
Experience with MITRE ATT&CK
Experience with building Threat Detections, performing Threat
Hunting and/or conducting Incident Response
Familiarity with enterprise logging technologies such as Elastic
(ELK stack) or Splunk
Experience with KANSA, Endpoint Detection & Response (EDR),
OSQuery, and / or Velociraptor
Experience with malware analysis using Sandbox technology or memory
One or more of the following certifications: GCFA, GPEN, GCFA,
GCIH, GNFA, GREM, GDAT, GPEN, GXPN, OSCP, GWAPT, AWS
Experience with Python or PowerShell
The above description reflects the details considered necessary to
describe the principal functions of the job and should not be
construed as a detailed description of all the work requirements
that may be performed in the job.
USAA has an effective process for assessing market data and
establishing ranges to ensure we remain competitive. You are paid
within the salary range based on your experience and market
position. The salary range for this position is: $88,200.00 -
158,900.00 * .
Employees may be eligible for pay incentives based on overall
corporate and individual performance or at the discretion of the
USAA Board of Directors.
- Geographical Differential : Geographic pay differential is
additional pay provided to eligible employees working in locations
where market pay levels are above the national average.Shift
premium will be addressed on an individual basis for applicable
roles that are consistently scheduled for non-core hours.
At USAA our employees enjoy best-in-class benefits to support their
physical, financial, and emotional wellness. These benefits include
comprehensive medical, dental and vision plans, 401(k), pension,
life insurance, parental benefits, adoption assistance, paid time
off program with paid holidays plus 16 paid volunteer hours, and
various wellness programs. Additionally, our career path planning
and continuing education assists employees with their professional
Please click on the link below for more details.
USAA Total Rewards
Relocation assistance is not available for this position.
Keywords: USAA, Sun City , Info Security Analyst mid-level - SOC/CTOC external threat team, Professions , Sun City, Arizona
Didn't find what you're looking for? Search again!