Cybersecurity Analyst I (Remote)

About the position

The SouthState story is one of steady growth, deep community roots, and an unwavering commitment to helping our customers move forward. Since our beginnings in the 1930s to becoming a trusted financial partner across the South and beyond - we are known for combining personal relationships with forward-thinking solutions. We are committed to helping our team members find their success while maintaining the integrity of our values: building trust, fostering lasting relationships and pursuing excellence. At SouthState, individual contributions are recognized, potential is cultivated and team members are inspired to achieve their greater purpose. Your future begins here! SUMMARY/OBJECTIVES It is the responsibility of the Cybersecurity Analyst to take ownership of all tasks and challenges that they encounter in the operation of their assigned position. Cybersecurity Analysts (CSA) are utilized across multiple teams within Cybersecurity Operations and thereby have distinct roles within their team. In general, a Cybersecurity Analyst is responsible for the collection, analysis, validation, monitoring, and response to cybersecurity intelligence and events. The CSA I performs day-to-day operational tasks by analyzing and responding to security events that have been logged and correlated by the SIEM or other security platform. A successful CSA I will have a strong understanding of the attack vectors present in the environment, the cyber kill chain, and how a threat actor would leverage those factors to perform a successful attack. The CSA I position requires initiative, accountability and ownership of tasks presented, leveraging knowledge and utilizing technical resources and other team members to drive success. ESSENTIAL FUNCTIONS Ensures compliance with all bank policies and procedures as well as state, federal, and regulatory requirements. Be fully aware of the enterprise’s security goals as established by its stated policies, procedures, and guidelines and actively work towards upholding those goals. Monitoring & Threat Management Monitor all in-place security solutions for efficient and appropriate operations. Review logs and reports of all in-place devices, whether they be under direct control (i.e., security tools) or not (i.e. workstations, servers, network devices, etc.). and interpret the implications of that activity to devise plans for appropriate resolution. Participate in investigation and resolution of anomalous activity. Serve as a first responder and assist with initial investigations for potential security events. Serve as the operational focal point for third-party security vendors regarding analyzing security logs. Collect, analyze, and disseminate cybersecurity threat intelligence. Analyze configuration and vulnerability information to determine risk to the Bank’s data security. Escalate adverse activity to the Incident Response Team. Participate in the cybersecurity on-call rotation. Operational Management Provide feedback on tuning of rules and alerts. Provide feedback on operational tasks to assist with increasing the efficacy of the cybersecurity program. Recommend tuning of rules that generate alerts to ensure low false positive rates. Validate log sources and logged event types to ensure expected level of logging from systems. Ability to analyze system configurations and technical specifications against security control standards and identify deficiencies. Threat Intelligence Collect and analyze threat intelligence. Assess the fidelity of received threat intelligence and implement enhancements. Tune current threat intelligence sources and implement new sources of threat intelligence. Provide threat intelligence to Cyber Threat Intelligence for sharing with FS-ISAC and other threat intelligence sharing communities. Assess and make enhancements to platforms that collect and analyze threat intelligence in collaboration with Cyber Threat Intelligence. Incident Response Serve as a member of the incident response team as needed for response to cybersecurity incidents. Participate in incident response planning and testing exercises. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Responsibilities

  • Ensures compliance with all bank policies and procedures as well as state, federal, and regulatory requirements.
  • Be fully aware of the enterprise’s security goals as established by its stated policies, procedures, and guidelines and actively work towards upholding those goals.
  • Monitor all in-place security solutions for efficient and appropriate operations.
  • Review logs and reports of all in-place devices, whether they be under direct control (i.e., security tools) or not (i.e. workstations, servers, network devices, etc.). and interpret the implications of that activity to devise plans for appropriate resolution.
  • Participate in investigation and resolution of anomalous activity.
  • Serve as a first responder and assist with initial investigations for potential security events.
  • Serve as the operational focal point for third-party security vendors regarding analyzing security logs.
  • Collect, analyze, and disseminate cybersecurity threat intelligence.
  • Analyze configuration and vulnerability information to determine risk to the Bank’s data security.
  • Escalate adverse activity to the Incident Response Team.
  • Participate in the cybersecurity on-call rotation.
  • Provide feedback on tuning of rules and alerts.
  • Provide feedback on operational tasks to assist with increasing the efficacy of the cybersecurity program.
  • Recommend tuning of rules that generate alerts to ensure low false positive rates.
  • Validate log sources and logged event types to ensure expected level of logging from systems.
  • Ability to analyze system configurations and technical specifications against security control standards and identify deficiencies.
  • Collect and analyze threat intelligence.
  • Assess the fidelity of received threat intelligence and implement enhancements.
  • Tune current threat intelligence sources and implement new sources of threat intelligence.
  • Provide threat intelligence to Cyber Threat Intelligence for sharing with FS-ISAC and other threat intelligence sharing communities.
  • Assess and make enhancements to platforms that collect and analyze threat intelligence in collaboration with Cyber Threat Intelligence.
  • Serve as a member of the incident response team as needed for response to cybersecurity incidents.
  • Participate in incident response planning and testing exercises.

Requirements

  • Excellent interpersonal skills, excellent computer skills, ability to read, write, speak, and understand English
  • Proven analytical and problem-solving abilities.
  • Ability to effectively prioritize and execute tasks in a high-pressure environment.
  • Ability to conduct research into cybersecurity issues and products as required.
  • Ability to present ideas in business-friendly and user-friendly language.
  • Highly self-motivated and directed.
  • Keen attention to detail.
  • Team-oriented and skilled in working within a collaborative environment.
  • Ability to learn and process new information and apply what was learned to the job.
  • Associate Degree (or equivalent work experience) from a regionally accredited institution in Information Security, computer science, mathematics, engineering, or a closely related field.
  • Two (2) or more years of direct Cybersecurity experience preferably as a cybersecurity analyst or similar role performing analysis and response to cybersecurity events at a financial institution.
  • A strong security mindset, understanding of financial sector regulatory requirements and security best practice.

Nice-to-haves

  • One or more of the following (or similar) certifications preferred: Global Information Assurance Certification (GIAC) Certifications (e.g., GIAC Security Essentials (GSEC), GIAC Certified Incident Handler (GCIH), GIAC Continuous Monitoring Certification (GMON), GIAC Certified Intrusion Analyst (GCIA), GIAC Security Operations Certified (GSOC), GIAC Certified Enterprise Defender (GCED), GIAC Certified Detection Analyst (GCDA))
  • CompTIA Certifications (e.g., Security+, CySA+)
  • Other certificates and professional credentials with cybersecurity relevance will be considered.

Benefits

  • Benefits
Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...