Citizens Bank - Johnston, RI

posted 4 months ago

Full-time - Senior
Johnston, RI
Credit Intermediation and Related Activities

About the position

The Cyber Defense Principal Security Engineer is a senior individual contributor role focused on the development, maintenance, troubleshooting, tuning, and documentation of security tool detections and rules aimed at identifying cyber-attacks, intrusions, and data loss incidents. This position requires an expert-level understanding of security use cases and the ability to apply them effectively to event data, supporting the Security Operations Center's (SOC) monitoring and response efforts. The Principal Security Engineer will engage with multiple technology platforms, with specific responsibilities for Cisco Firepower and Palo Alto IDS/IPS policies and rules, while also collaborating with various groups within the bank's Enterprise Technology & Security division. In this role, the engineer will be responsible for developing and maintaining IDS/IPS policies and rules for Cisco Firepower and Palo Alto systems. This includes regularly reviewing and updating these policies to ensure their effectiveness and developing new detection rules based on emerging threats and intelligence. Continuous optimization of IDS/IPS configurations is essential to minimize false positives and enhance detection accuracy, which involves conducting regular performance assessments and making necessary adjustments. The engineer will also be tasked with developing detections for SIEM and other SOC tools, implementing security use cases, and transforming them into correlation queries, templates, rules, and alerts across various cloud environments and on-premises technologies. Technical documentation for deployed content is crucial, as the engineer must document IDS/IPS configurations, tuning procedures, and any changes made to policies and rules, ensuring that this documentation is current and accessible to the team. Monitoring the health and performance of security tools is another key responsibility, ensuring that IDS/IPS systems function properly and addressing any performance issues in coordination with teams or vendors for support. The integration of cyber threat intelligence into defensive systems is vital for enhancing IDS/IPS capabilities, which includes integrating relevant threat intelligence feeds and indicators of compromise (IOCs). The engineer will also develop reports, dashboards, workflows, and metrics to provide visibility into IDS/IPS activity and effectiveness. Collaboration with the SIEM team is necessary to ensure effective logging, event collection, normalization, correlation, reporting, and customization that supports IDS/IPS data. The engineer will support the Security Engineering team with SOC-related technical issues and incidents, assisting in resolving complex technical issues related to IDS/IPS systems. Additionally, mentoring and training junior team members on IDS/IPS best practices, rule creation, and tuning will be part of the role, along with being available to address critical IDS/IPS issues and incidents outside of regular business hours as needed.

Responsibilities

  • Develop and maintain IDS/IPS policies and rules for Cisco Firepower and Palo Alto systems.
  • Regularly review and update IDS/IPS policies and rules to ensure they are current and effective.
  • Develop new detection rules based on emerging threats and intelligence.
  • Continuously optimize IDS/IPS configurations to minimize false positives and enhance detection accuracy.
  • Conduct regular performance assessments and make necessary adjustments.
  • Implement security use cases and transform them into correlation queries, templates, rules, and alerts across multiple cloud environments and on-premises technologies.
  • Document IDS/IPS configurations, tuning procedures, and any changes made to policies and rules.
  • Ensure documentation is up-to-date and accessible to the team.
  • Monitor the health and performance of security tools and address any performance issues.
  • Enhance IDS/IPS capabilities by integrating relevant threat intelligence feeds and indicators of compromise (IOCs).
  • Create and maintain reports and dashboards that provide visibility into IDS/IPS activity and effectiveness.
  • Work with the SIEM team to ensure effective logging, event collection, normalization, correlation, reporting, and customization that supports IDS/IPS data.
  • Assist in resolving complex technical issues related to IDS/IPS systems.
  • Provide guidance and training to junior team members on IDS/IPS best practices, rule creation, and tuning.
  • Be available to address critical IDS/IPS issues and incidents outside of regular business hours when necessary.

Requirements

  • Excellent understanding of Cybersecurity Operations and Incident Response processes.
  • Expert level knowledge of IDS/IPS technologies (Cisco Firepower, Palo Alto, etc.).
  • Expert level knowledge of detection creation/tuning concepts and best practices.
  • Experience working with cloud computing platforms such as Amazon Web Services, Azure, etc.
  • Deep understanding of events, related fields in log records, and alerts reported by various data sources such as Windows/Unix systems, IDS/IPS, HIDS/HIPS, WAFs, firewalls, and web proxies.
  • Solid understanding of various operating systems (Windows, Unix, Linux, AIX, etc.).
  • Advanced ability to develop regular expressions.
  • Advanced ability to automate tasks using a preferred language (e.g. Snort).
  • Excellent oral and written communications skills.
  • Strong analytical skills.
  • Self-motivation with the ability to work under minimal supervision.

Nice-to-haves

  • 7 years of proven hands-on experience in IDS/IPS concepts.
  • Experience with SOC technologies such as SIEM, EDR, anti-virus, network-based threat detection, and netflow.
  • Strong understanding of enterprise logging standards.
  • Understanding of cyber kill chains and campaign strategies such as MITRE ATT&CK.
  • Ability to interact with common APIs.
  • Proven successful working relationships with teams outside of Cybersecurity.

Benefits

  • Comprehensive medical, dental and vision coverage.
  • Retirement benefits.
  • Maternity/paternity leave.
  • Flexible work arrangements.
  • Education reimbursement.
  • Wellness programs.
  • Paid time off policy that exceeds mandatory requirements.
Job Description Matching

Match and compare your resume to any job description

Start Matching
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service