General Job Summary
The Tier 1 Security Operations Analyst will serve as the frontline defender protecting University Bank’s critical infrastructure, financial data, and customer trust. Operating in a fast-paced, 24/7/365 environment, this associate-level role will work closely with other members of the Information Security and Information Technology teams, and various business units to monitor security consoles in real-time to identify, triage, and investigate potential threats against the network, ensuring minor anomalies do not escalate into major breaches.
Additionally, this position helps guide the development and operational aspects of University Bank’s Information Security Program. The analyst works closely with other members of the Information Security and Information Technology teams, as well as various business units, to ensure confidentiality, integrity, and availability of infrastructure and customer data.
Summary of Essential Job Functions
The Tier 1 Security Operations Analyst role is composed of a variety of administrative and operational activities supporting University Bank’s real-time defense and departmental initiatives as outlined below:
Real-Time Monitoring & Threat Detection
- Dashboard Oversight: Actively monitor Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) dashboards to detect anomalous activity, unauthorized access, or potential intrusions.
- Log Analysis: Review security logs and reports from firewalls, intrusion detection/prevention systems (IDS/IPS), network databases, Web Filters, Email Filters, Endpoints, and third-party monitoring services to identify trends and potential indicators of compromise (IOCs).
- Security Controls Review: Review security requirements for new systems, existing systems, and system upgrades, while designing appropriate security controls for projects and operations.
Incident Triage, Escalation & Tracking
- Alert Verification: Triage incoming security alerts efficiently, distinguishing between benign false positives and true malicious threats.
- Incident Escalation: Execute established standard operating procedures (SOPs) to escalate critical, high-risk events to the Information Security Engineer, Security Manager, or Information Security Officer (ISO).
- Financial Scope Awareness: Maintain a high level of awareness regarding threats specific to financial systems, such as wire fraud patterns, data exfiltration attempts, and ransomware.
- Documentation & Remediation: Track remediation efforts related to any information security items and document every step taken during the initial triage process clearly and comprehensively within the enterprise ticketing system.
- Playbook & Procedure Maintenance: Assist with the maintenance and development of departmental procedures, guides, checklists, forms, and Security Operations playbooks based on observed trends and evolving attack vectors.
Phishing Analysis & Security Awareness
- Pipeline Management & Extraction: Review and analyze suspicious emails reported by banking and corporate staff via the internal phishing reporting pipeline, safely extracting artifacts like email headers, attachments, and URLs to identify phishing campaigns, credential harvesting, or malware delivery methods.
- Platform Administration: Assist the primary technical administrator for the corporate security awareness platform (KnowBe4).
- Phishing Assessments: Assist in the design, implementation, and execution corporate-wide simulated email phishing testing exercises and assessments.
- Training & Materials: Help design, publish, distribute, and deliver printed, electronic, virtual, and on-premises security awareness training activities, ensuring the program meets established industry best practices.
- KPI Reporting: Remain current on key awareness topics and interpret and report awareness-related key performance indicators (KPIs) to the ISO.
Audit, Risk Assessments
- Audit Preparation: Perform document collection, track requests, and assist leadership in preparing materials for information security audits and exams.
- Risk Tool Updates: Assist in reviewing and completing annual updates to the IT Risk Assessment, Information Security risk assessment, FFIEC Cyber Security Awareness Tool, and information security aspects of the GLBA risk assessment.
- Policy Maintenance: Work with leadership to develop, implement, and maintain information security policies and programs.
Other Job Functions
- All other duties as assigned by management.
Education, Training, and Work Experience
- 1–2 years of professional experience in security operations; OR a college degree (e.g., Cybersecurity, Computer Science) or completion of a recognized, rigorous cybersecurity bootcamp.
- Alternatively, 3–5 years of demonstrated work experience working in an Information Security, Information Technology, or Risk Management environment is accepted.
- Experience working in a regulated industry is preferred.
- Information Security, Information Technology or Risk Management Certifications (preferred) – Examples such as but not limited to CompTIA Net+ Security+, ISC2 CISSP, GIAC credentials such as GCIH or GMON, Cisco CCNA / CCNP.
- Understanding of policies, procedures, standards, and guideline structure.
Knowledge, Skills, and Abilities
- A foundational understanding of the TCP/IP stack, routing protocols, and network traffic analysis.
- Knowledge of and hands-on familiarity with computer operating systems, including Microsoft Windows and Linux environments, including command-line interfaces.
- Basic understanding of common attack vectors (e.g., SQL injection, DDoS, brute force), defense-in-depth concepts, and a structural understanding of policies, procedures, standards, and guidelines.
- Ability to conduct research, review, testing, and administration of information security tools.
- Strong attention to detail, proactive problem-solving abilities, and a high degree of accuracy and accountability.
- Strong organizational and planning skills.
- Excellent time management skills and the ability to multi-task productively.
- Strong written and verbal communication skills.
- Able to take ownership and work productively with others to ensure the successful completion of assignments.
- Familiarity with applicable legal and regulatory requirements, including, but not limited to, the U.S. Sarbanes-Oxley Act, the U.S. Health Insurance Portability and Accountability Act (HIPAA), FFIEC Guidelines.
- Ability to handle sensitive information with confidentiality and integrity.
Working Environment
Primary working environment is within an indoor climate-controlled office space and/or a private home office or some combination which will be at management’s sole discretion. Employee may be subject to florescent lighting, dust, and other normal indoor allergens. Employee may work in close proximity of coworkers and occasionally independently in quiet environments.
Physical Requirements
- Able to lift up to 20 pounds.
- May be exposed to extended periods of interaction with others (listening/talking/taking notes)
- Extended periods of sitting (at computer desk)
- Complete repetitive tasks (including operation of computer mouse/keyboard)
Disclaimer
The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities from time to time, as needed.
The salary range for this role takes into consideration a wide range of factors including but not limited to the duties of the role, experience, location, and certificates and/or education. The target salary range for this position is between $45,000 and $55,000 per year.
**University Bank is an Equal Opportunity / Affirmative Action Employer**