CaixaBank
CaixaBank

Cyber Incident Response Specialist Manager

Barcelona, Spain·Competitive·On-site·Mid·Internship·English: Required

Added 22 days ago

Need a visa?No sponsorship mentioned here. Browse visa jobs.

About the role

The aim of this call is to fill a manager vacancy in the Cybersecurity department, within the Detection, Response and Recovery division of the CaixaBank Group, to be able to respond to cyber incidents as well as mitigate potential future impacts by analyzing attackers' techniques and tactics.


Department mission


We are responsible for preventing and defending the Entity, our customers and our employees against any type of threat perpetrated through digital and technological means.


The main areas of action are detection, response to cyber incidents and preparation for recovery after a serious disruptive event:

Establish, apply and control security policies to predict, identify and mitigate emerging security risks in the organization, including operational security and fraud arising from banking activity, as well as cybersecurity arising from new internet risks

What you'll do

  • Definition and control of cyber incident response processes
  • Definition of technical playbooks for responding to cyber incidents, adapting existing ones and creating new ones to cover new cyber threats.
  • Definition of solutions to meet response needs in the different corporate technology environments
  • Definition and control of the analysis and response processes of the cybersecurity operations team (Cyber SOC)
  • Definition and control of the processes of the cybersecurity incident response center (CSIRT)
  • Definition and control of cyberattack simulation environments to ensure the completeness and effectiveness of the prevention and detection controls implemented.
  • Definition and control of post-incident recovery processes based on the defined cyber incident response playbooks.
  • Must have knowledge of the MITRE detection and attack matrix, knowledge of cyberattack techniques and tactics, as well as forensic analysis knowledge.

What we're looking for


Candidate profile: must especially have the ability to take part in cyber incident response processes, i.e., the ability to define processes, analyze and respond to incidents.

  • Technical or higher education degree in computer science or telecommunications.
  • Experience in SOC, CSIRT or DFIR management
  • Knowledge and experience in incident response.
  • Experience in managing technology projects.
  • Ability to work in cross-functional teams.
  • Communication skills and interpersonal skills.
  • Analytical and synthesis skills with strategic vision.
  • Adaptability to change.
  • Willingness to travel.
  • Spoken and written English.

Nice to have

  • Cyberattack techniques and tactics
  • Agile working methodologies.
  • Security best practices and regulations/standards.
  • Training and certifications related to cybersecurity.
  • SIEM (Sentinel, Splunk, QRadar, etc.).
  • EDR/XDR.
  • Cloud (Azure, AWS, GCP).
  • Forensic tools.
  • SOAR.
  • Threat Intelligence tools.

How you'll work


The position is located at CaixaBank's Central Services in Madrid or Barcelona.

internship

About the company & team

CaixaBank is a financial group with a socially responsible universal banking model with a long-term vision, based on quality, proximity and specialization, offering a value proposition of products and services adapted to each segment, taking on innovation as a strategic challenge and a differentiating feature of its culture, and whose leading position in retail banking in Spain and Portugal allows it to play a key role in contributing to sustainable economic growth.

What projects do we develop?


Security analytics    

Define and control security analytics processes for prevention, detection and response purposes.


Detection    

Definition of controls for detecting attacks or anomalies that could be signs of the initial stages of cyberattacks, aligned with the MITRE Att&ck matrix.


CSIRT (Computer Security Incident Response Team)    

Definition, control and execution of playbooks against cyber threats and cyberattacks. Recovery processes after cyberattacks are also defined for execution by IT teams.


Cybersecurity operations (Cyber SOC)    

Understanding of a CyberSOC and the operation of playbooks for analyzing and responding to cybersecurity events, as well as reviewing them to apply improvements.


Cyber Threat Intelligence    

Threat Intelligence process as an input to cyberattack prevention processes, which identifies malicious actors with potential impact on the entity, measures the level of impact based on the tactics, techniques and vulnerabilities they exploit, maintains a risk score per actor and overall risk as an anticipatory cyber-risk metric.

Skills

H RESEARCH ON AI TRENDS AND BUSINESS IMPACTS

H MANAGEMENT OF CONFLICTS, THREATS AND VULNERABILITIES

H SECURITY PLATFORMS

S.1.1 ALLIANCES – COLLABORATION AND CROSS-FUNCTIONALITY

S.1.4 ALLIANCES – COMMUNICATION

S.1.3 ALLIANCES – INFLUENCE

S.1.2 ALLIANCES – CUSTOMER ORIENTATION

S.2.1 HUMANISM – COMMUNICATION AND EMPATHY

S.2.2 HUMANISM – LEADERSHIP AND TEAM DEVELOPMENT / SELF-LEADERSHIP

H SECURITY ARCHITECTURE

S.4.1 ANTICIPATION – ANTICIPATION AND CHANGE MANAGEMENT

S.3.1 EMPOWERMENT – RESULTS FOCUS

H TECHNICAL DOCUMENTATION

H APPLICATION SECURITY

S.5.1 DIVERSITY – PROMOTING DIVERSITY

H CLOUD AND INFRASTRUCTURE SECURITY

H INFORMATION SECURITY TECHNOLOGIES

H ADVANCED ANALYTICS AND PREDICTIVE MODELS

H CYBERSECURITY PROCEDURES

H NETWORKS AND SECURITY

H CYBERFRAUD

H IMPLEMENTATION OF AI MARKET SOLUTIONS

H MANAGEMENT AND MONITORING OF SECURITY PLATFORMS

H AI LITERACY

This job was automatically translated to English, .

About the company

CaixaBank

CaixaBank

Banking

View company profile
Spanish company
44000 employees
Apply at CaixaBank