Production Csirt Analyst Level Iii - Montréal, Canada - BNP Paribas

BNP Paribas
BNP Paribas
Verified Company
Montréal, Canada

4 weeks ago

Sophia Lee

Posted by:

Sophia Lee

beBee Recruiter


Description
PRODUCTION CSIRT ANALYST LEVEL III (


JOB NUMBER:
IT MN)

In a changing world, unprecedented challenges require unmatched talent. Join one of Montreal's Top Employers in 2023.

We are a dynamic and growing organization having its main establishment located in downtown Montreal and part of a leading international banking institution fully committed to building a more sustainable future.

Note that the position may be in the Canadian Branch of BNP Paribas or in one of its subsidiaries based in Montreal.


The position at a glance
The Production CSIRT Analyst Level III position will provide security expertise to the 24x7 Security Operation Center (SOC).

The primary purpose of this position is to help coordinate and report on cyber incidents impacting the banks critical assets by detecting, preventing, and responding to cyber threats against our group's infrastructure.

It provides critical support to the firm-wide cybersecurity program via partnerships in the region within our diverse lines of business and also externally with client, partners and regulators.


As a Production Security Analyst, you are not only responsible for hands-on real-time monitoring, analysis, and resolution of identified security incidents, but you will also be responsible to continual development and improvement of the 24x7 Security Operation Center (SOC) capabilities as the first line of defense to identify potential information security incidents.


In detail

Responsibilities include but are not limited to:

  • Provide analysis and trending of security log data from many heterogeneous security devices
  • Responsible for usecase development and validation
  • Provide Incident Response (IR) support or escalation when analysis confirms actionable incident. Provide threat and vulnerability analysis as well a security advisory service.
  • Develop threat hunting program and capabilities
  • Analyze and respond to previously undisclosed software and hardware vulnerabilities
  • Investigate, document and report on information security issues and emerging trends
  • Perform threat hunting to identify potential adversaries within the network
  • Perform forensics analysis on compromised systems to identify the extent and nature of the compromise and provide recommendations on remediation steps.
  • Provide support and /or research any security related questions or incidents.
  • Perform tasks independently with some oversight
  • Integrate and share information with other analysts and other teams.
  • Follow incidentspecific procedures to perform triage of potential security incidents to validate and determine needed mitigation and maintain said procedures up to date.
  • Escalate potential security incidents to Level IV engineers, implements countermeasures in response to others, and recommend operational improvements
  • Keep accurate incident notes in case management system
  • Maintaining awareness of the bank's technology architecture, known weaknesses, the architecture of the security solutions used for monitoring, imminent and pervasive threats as identified by client threat intelligence, and recent security incidents
  • Continuously improve the service by identifying and correcting issues or gaps in knowledge (analysis procedures, plays, client network models), false positive tuning, identifying, and recommending new or updated tools, content, countermeasures, scripts.
  • Actively seek selfimprovement through continuous learning and pursuing advancement to a Level IV Analyst
  • Adhere to internal operational security and other BNP Paribas policies
  • Perform light project work as assigned

The strengths and skills that will help you succeed

  • Knowledge or 35 years of experience with the following technologies: SIEM, ELK, IDS/IPS, network
- and host
- based firewalls, data leakage protection (DLP)

  • Direct experience with antivirus software, endpoint detection response (EDR), firewalls and content filtering
  • Experience or demonstrable knowledge in Incident response, log analysis and PCAP analysis
  • Good level of knowledge in network fundamentals, for example, OSI Stack, TCP/IP, DNS, HTTP(S), SMTP
  • Knowledge in Windows and/or Linux operating systems, how to investigate them for signs of compromise
  • Passion to learn and to contribute to the ongoing development of the team
  • Knowledge of the English language is required

Skills/Behaviors Preferred:

  • Foundational level of scripting knowledge
  • Ability to demonstrate the right approach to investigating alerts and/or indicators and document your findings in a manner that both peer and executive level colleagues can understand
  • Appreciation of the wider roles of interconnecting Cyber Security teams and collaboration with each of those (i.e., Forensics / Threat Intelligence / Penetration Testing / Vulnerability Management / "Purple Teaming" etc.)
  • Ability to handle fluctuating workloads, conflicting priorities, and concurrent activities
  • Analytical skills
  • Strategic vision
  • Rigor & Accura

More jobs from BNP Paribas