Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Location: Sydney, Australia
Job Description:
Cyber Threat Intelligence (CTI) works with partners, both internal and external, to reduce risk to the firm and to the financial sector at large. Stakeholders include cyber-security response teams, internal lines of business, senior leadership and external organizations such as law enforcement, industry peers, key suppliers, customers and intelligence sharing partners. The Cyber Threat Intelligence (CTI) Triage team is responsible for receiving, documenting, assessing risk, and if required, escalating all incoming cyber threat information.
The CTI Triage Analyst is responsible for responsible for providing timely situational awareness, monitor a wide variety of sources, looking for indications and warnings of threats and attacks. The CTI Triage Analyst rapidly translates indicators of threat into actionable information to help reduce the potential impact to the operations of the business. This is an opportunity to work with a best in class global enterprise team. The candidate will have exposure to the latest developments in technology and latest threats.
Responsibilities:
- Work in a tactical/technical role reviewing and cultivating intelligence sources, analyzing information, creating intelligence, and hunting for exposures or related incidents.
- Participate with other triage analysts in a follow-the-sun model to provide consistent support for Cyber Security Operations. This will encompass weekend shift work on a rota basis.
- Contribute to daily internal GIS ops calls, contribute to intelligence briefings for Senior leaders.
- Work within the CTOC communicating with internal teams and minimizing response times for critical events.
- Identify, escalate and debate recommended actions that strengthen controls.
- Operate within an established Escalation Matrix to determine report priority and messaging to operations and senior executives throughout GIS and the lines of business, escalate issues to control teams and management in a timely manner with appropriate information regarding risk and impact.
- Continually and consistently review triage processes to identify reforms that could add to increased speed, efficiency and accuracy in reporting.
- Exercise independent judgment in methods, techniques and evaluation criteria for obtaining results.
- Participate in technical bridge lines to facilitate the identification, mitigation and containment of cyber-security incidents.
Skills:
- 5+ years of InfoSec experience. This is a hands-on role where the candidate will be involved in identifying and tracking cyber threats on a daily basis.
- The candidate should exhibit a firm understanding of the cyber threat landscape, geopolitical issues that could have cyber impacts, security vulnerabilities, exploits, malware, digital forensics, network security vulnerabilities, exploits and attacks.
- Experience with threat intelligence platforms, tools, and threat intelligence vendors.
- Experience supporting or contributing to incident response or major security investigations.
- Experience with JIRA/ServiceNow, Python, and other programming languages will be a strong plus.
- Experience working in a Security Operations, Incident Management or Fusion Center operation.
- Minimum 1 year working in a 24/5 or 24/7 operational environment.
- This position requires strong verbal and written communication skills.
- Bachelor’s degree or higher-level education is a strong plus.
- Technical or information security certifications are also a strong plus.