وظائف في الكويت

مطلوب قائد Cyber SOC في بنك الخليج في الكويت

مطلوب قائد Cyber SOC في بنك الخليج في الكويت

 

 

Cyber SOC Lead

About the job

Job Purpose

performs monitoring, research, assessment and analysis of Digital Fraud Attacks leveraging various Security Event Monitoring platforms including Web Threat Detection, Real Time Fraud Risk Assessment, Big Data and Digital Application Monitoring tools (SecureWorks, LogRhythm, Threat Intelligence Platforms, Defender, TrendMicro. Previous experience in cyber security operations or incident response is required.

Job Accountabilities

Security Operations Monitoring:

 

  • Support Perform deep packet and log analysis
  • Expert level understanding of network protocols and packet analysis
  • Take lead on incident research when required
  • When event is classed as incident, take the lead to drill with each team and identify root cause, managing the process end to end
  • Manage the security incident management process and coordinate with each stakeholder to identify root cause of the events, coordinating all communication
  • Know the environment to be able to work quickly with IT to identify and deprioritize false positive alerts
  • Being able to author SOPs and training documentation when needed
  • Provide mentorship to junior and mid-level analysts
  • Follow pre-defined actions to handle BAU and High severity issues including escalating and follow-up to other support groups until incident is resolved.
  • Write scripts to automate daily triage of events and to enhance identification of issues
  • Create Use Cases in SIEM and define requirements based upon feedback from other security stakeholders
  • Execute daily ad hoc tasks or lead small projects as needed.
  • Create and maintain operational reports for Key Performance Indicators and weekly and monthly metrics.
  • Perform assessment as well as troubleshooting to help isolate technical issues with the integration of fraud monitoring technologies
  • Participate in daily and ad hoc conference calls to manage quality assurance and documentation related tasks.
  • Identify areas for tuning use cases to enhance monitoring value.
  • Engage with Fraud Policy, Operations, Strategy and other teams for early detection, prevention and mitigation of detected fraudulent activities by writing use cases and scripts that will highlight related events.
  • Work with UEBA systems to tune the event logs to prioritise issues that are anomalous to normal user behaviour.
  • monitor, maintain and protect Gulf Bank of Kuwait’s networks, systems and assets from malicious activity using Security Incident and Event Management (SIEM) solution.
  • Assist with internal and external security audits.
  • Review the monthly SOC vendor reports and contribute towards the improvement of the SIEM solution and its monitoring capabilities.
  • Review SIEM alerts daily and analyse them to eliminate false positive. Escalate positive alerts to the Head of Cyber for further investigation.
  • Conduct bi-weekly calls with the SOC vendor to review implemented use case to fine tune and remove use cases that are not required.
  • Support the application and system owners with log integration.
  • Take lead on identifying use cases for various critical applications and servers i.e.
  • Ensure all Swift systems have their logs integrated with the SIEM solution;
  • Where systems do not have logs, integration assist the application/server owner to ensure all logs are integrated;
  • Identify use case relevant to Swift; and
  • Work with the SOC vendor to ensure all identified use cases are implemented, tested and deployed in a timely manner.
  • Escalate any issues with the SIEM solution (hardware/software) to the Head of Cyber.
  • On a monthly basis complete the Key Risk Indicators (KRI) spreadsheet for SOC related activities
  • Assist with investigations into suspicious activities.
  • Obtain logs from the SIEM solution for the various systems/devices to identify Root Case Analysis (RCA)
  • Analyse the logs to identify suspicious behaviour and provide feedback
  • Identify use cases based on the investigation for monitoring in the SIEM
  • Ensure the SIEM solution is up to date, both hardware and software.

Generic Accountabilities

إقرأ أيضا:اعلان وظائف شاغرة بالفئة الثالثة صادرعن وزارة التنمية الإجتماعية

 

  • Corporate Governance: Adhere to CBK regulations, Bank’s policies and procedures, and work standards.
  • Compliance: Compliance and awareness of Risk Policies, AML and control regulations as well as Compliance to operational procedures and instructions

Education & Qualification

bachelor’s degree in IT or equivalent experience with Professional Banking qualifications

Knowledge

 

  • Security Information and Event Management (SIEM)
  • SQL,TCP/IP, computer networking, routing and switching
  • C, C++, C#, Java, Python or PHP programming languages
  • IDS/IPS, penetration and vulnerability testing
  • Firewall and intrusion detection/prevention protocols
  • Windows, UNIX and Linux operating systems
  • Network protocols and packet analysis tools
  • Anti-virus and anti-malware

Experience

7-10 years in cyber security field

Certification/Accreditation

Security+ (beginner), GIAC (Advanced), CASP (Intermediate) GCIH, GIAC GCFA

Primary Location

Kuwait

Job

Managerial Jobs

Organization

ISS Security

Schedule

Regular

إقرأ أيضا:مطلوب محاسب لدى شركة للنقليات في الجبيل

Shift

Standard

Job Type

Full-time

Job Level

Day Job

Job Posting

Mar 26, 2024, 5:12:04 AM

تابع نشمي للوظائف على

لمشاهدة جميع الوظائف الشاغرة اضغط هنا

لمشاهدة جميع الوظائف الشاغرة على جوجل نيوز  اضغط هنا

لمشاهدة جميع الوظائف الشاغرة على الفيس بوك اضغط هنا

لمشاهدة جميع الوظائف الشاغرة على انستقرام اضغط هنا

لمشاهدة جميع الوظائف الشاغرة على لينكد اضغط هنا

لمشاهدة جميع الوظائف الشاغرة على تويتر اضغط هنا

لمشاهدة جميع الوظائف الشاغرة على تلجرام اضغط هنا

السابق
وظائف عمل في جراند حياة في الكويت
التالي
مطلوب مدير العلاقات المصرفية المتميزة في البنك الأهلي في عُمان