Cyber Incident Response Specialist Manager
Barcelona, Spain·Competitive·On-site·Mid·Internship·English: Required
Need a visa?No sponsorship mentioned here. Browse visa jobs.
About the role
The aim of this call is to fill a manager vacancy in the Cybersecurity department, within the Detection, Response and Recovery division of the CaixaBank Group, to be able to respond to cyber incidents as well as mitigate potential future impacts by analyzing attackers' techniques and tactics.
Department mission
We are responsible for preventing and defending the Entity, our customers and our employees against any type of threat perpetrated through digital and technological means.
The main areas of action are detection, response to cyber incidents and preparation for recovery after a serious disruptive event:
Establish, apply and control security policies to predict, identify and mitigate emerging security risks in the organization, including operational security and fraud arising from banking activity, as well as cybersecurity arising from new internet risks
What you'll do
- Definition and control of cyber incident response processes
- Definition of technical playbooks for responding to cyber incidents, adapting existing ones and creating new ones to cover new cyber threats.
- Definition of solutions to meet response needs in the different corporate technology environments
- Definition and control of the analysis and response processes of the cybersecurity operations team (Cyber SOC)
- Definition and control of the processes of the cybersecurity incident response center (CSIRT)
- Definition and control of cyberattack simulation environments to ensure the completeness and effectiveness of the prevention and detection controls implemented.
- Definition and control of post-incident recovery processes based on the defined cyber incident response playbooks.
- Must have knowledge of the MITRE detection and attack matrix, knowledge of cyberattack techniques and tactics, as well as forensic analysis knowledge.
What we're looking for
Candidate profile: must especially have the ability to take part in cyber incident response processes, i.e., the ability to define processes, analyze and respond to incidents.
- Technical or higher education degree in computer science or telecommunications.
- Experience in SOC, CSIRT or DFIR management
- Knowledge and experience in incident response.
- Experience in managing technology projects.
- Ability to work in cross-functional teams.
- Communication skills and interpersonal skills.
- Analytical and synthesis skills with strategic vision.
- Adaptability to change.
- Willingness to travel.
- Spoken and written English.
Nice to have
- Cyberattack techniques and tactics
- Agile working methodologies.
- Security best practices and regulations/standards.
- Training and certifications related to cybersecurity.
- SIEM (Sentinel, Splunk, QRadar, etc.).
- EDR/XDR.
- Cloud (Azure, AWS, GCP).
- Forensic tools.
- SOAR.
- Threat Intelligence tools.
How you'll work
The position is located at CaixaBank's Central Services in Madrid or Barcelona.
internship
About the company & team
CaixaBank is a financial group with a socially responsible universal banking model with a long-term vision, based on quality, proximity and specialization, offering a value proposition of products and services adapted to each segment, taking on innovation as a strategic challenge and a differentiating feature of its culture, and whose leading position in retail banking in Spain and Portugal allows it to play a key role in contributing to sustainable economic growth.
What projects do we develop?
Security analytics
Define and control security analytics processes for prevention, detection and response purposes.
Detection
Definition of controls for detecting attacks or anomalies that could be signs of the initial stages of cyberattacks, aligned with the MITRE Att&ck matrix.
CSIRT (Computer Security Incident Response Team)
Definition, control and execution of playbooks against cyber threats and cyberattacks. Recovery processes after cyberattacks are also defined for execution by IT teams.
Cybersecurity operations (Cyber SOC)
Understanding of a CyberSOC and the operation of playbooks for analyzing and responding to cybersecurity events, as well as reviewing them to apply improvements.
Cyber Threat Intelligence
Threat Intelligence process as an input to cyberattack prevention processes, which identifies malicious actors with potential impact on the entity, measures the level of impact based on the tactics, techniques and vulnerabilities they exploit, maintains a risk score per actor and overall risk as an anticipatory cyber-risk metric.
Skills
H RESEARCH ON AI TRENDS AND BUSINESS IMPACTS
H MANAGEMENT OF CONFLICTS, THREATS AND VULNERABILITIES
H SECURITY PLATFORMS
S.1.1 ALLIANCES – COLLABORATION AND CROSS-FUNCTIONALITY
S.1.4 ALLIANCES – COMMUNICATION
S.1.3 ALLIANCES – INFLUENCE
S.1.2 ALLIANCES – CUSTOMER ORIENTATION
S.2.1 HUMANISM – COMMUNICATION AND EMPATHY
S.2.2 HUMANISM – LEADERSHIP AND TEAM DEVELOPMENT / SELF-LEADERSHIP
H SECURITY ARCHITECTURE
S.4.1 ANTICIPATION – ANTICIPATION AND CHANGE MANAGEMENT
S.3.1 EMPOWERMENT – RESULTS FOCUS
H TECHNICAL DOCUMENTATION
H APPLICATION SECURITY
S.5.1 DIVERSITY – PROMOTING DIVERSITY
H CLOUD AND INFRASTRUCTURE SECURITY
H INFORMATION SECURITY TECHNOLOGIES
H ADVANCED ANALYTICS AND PREDICTIVE MODELS
H CYBERSECURITY PROCEDURES
H NETWORKS AND SECURITY
H CYBERFRAUD
H IMPLEMENTATION OF AI MARKET SOLUTIONS
H MANAGEMENT AND MONITORING OF SECURITY PLATFORMS
H AI LITERACY
About the role
El objetivo de esta convocatoria es cubrir una vacante de gestor/a en el departamento de Ciberseguridad, en la dirección de Detección, Respuesta y Recuperación del Grupo CaixaBank, para poder dar respuesta a ciberincidentes así como mitigar posibles futuros impactos analizando las técnicas y las tácticas de los atacantes.
Misión del departamento
Somos responsables de prevenir y defender a la Entidad, a nuestros clientes y a nuestros empleados ante cualquier tipo de amenaza perpetrada por medios digitales y tecnológicos.
Los ámbitos de actuación principales son la detección, la respuesta ante ciberincidentes y la preparación para la recuperación ante un evento disruptivo grave:
Establecer, aplicar y controlar las políticas de seguridad para predecir, identificar y mitigar los riesgos de seguridad emergentes en la organización, incluyendo la seguridad operacional y fraude, que derivan de la actividad bancaria, así como la ciberseguridad, que deriva de los nuevos riesgos de internet
What you'll do
- Definición y control de los procesos de respuesta ante ciber-incidentes
- Definición de los playbooks técnicos de respuesta a ciber-incidentes, adaptando los existentes y creando nuevos para cubrir las nuevas ciber-amenazas.
- Definición de las soluciones para cubrir las necesidades de respuesta en los diferentes entornos tecnológicos corporativos
- Definición y control de los procesos de análisis y respuesta del equipo de operación de ciberseguridad (Cyber SOC)
- Definición y control de los procesos del centro de respuesta a incidentes de ciberseguridad (CSIRT)
- Definición y control de los entornos de simulación de ciber-ataques para asegurarse de la completitud y efectividad los controles de prevención y detección implantados.
- Definición y control de los procesos de recuperación post-incidente en base a los playbooks de respuesta a ciber-incidente definidos.
- Debe tener conocimiento de la matriz de MITRE de detección y ataque, debe tener conocimientos de técnicas y tácticas de ciber-ataques, así como conocimientos de análisis forense.
What we're looking for
Perfil del candidato: debe tener, en especial, la capacidad de formar parte de procesos cyber de respuesta a incidentes, es decir, la capacidad de definición de procesos, análisis y respuesta a incidentes.
- Titulación técnica o superior en informática o telecomunicaciones.
- Experiencia en gestión de SOC, CSIRT o DFIR
- Conocimientos y experiencia en respuesta a incidentes.
- Experiencia en dirección de proyectos tecnológicos.
- Capacidad de trabajo en equipos trasversales.
- Capacidad de comunicación y habilidades relacionales.
- Capacidad analítica y de síntesis con visión estratégica.
- Adaptación al cambio.
- Disponibilidad para viajar.
- Inglés hablado y escrito.
Nice to have
- Técnicas y tácticas de ciber-ataques
- Metodologías de trabajo Agile.
- Buenas prácticas y regulaciones/estándares de seguridad.
- Formación y certificaciones relacionadas con ciberseguridad.
- SIEM (Sentinel, Splunk, QRadar, etc.).
- EDR/XDR.
- Cloud (Azure, AWS, GCP).
- Herramientas forenses.
- SOAR.
- Herramientas Threat Intelligence.
How you'll work
El puesto de trabajo está ubicado en los Servicios Centrales de CaixaBank en Madrid o Barcelona.
internship
About the company & team
CaixaBank es un grupo financiero con un modelo de banca universal socialmente responsable con visión a largo plazo, basado en la calidad, la cercanía y la especialización, que ofrece una propuesta de valor de productos y servicios adaptada para cada segmento, asumiendo la innovación como un reto estratégico y un rasgo diferencial de su cultura, y cuyo posicionamiento líder en banca minorista en España y Portugal le permite tener un rol clave en la contribución al crecimiento económico sostenible.
¿Qué proyectos desarrollamos?
Analítica de seguridad
Definir y controlar los procesos de analítica de seguridad con fines de prevención, detección y respuesta.
Detección
Definición de los controles de detección de ataques o anomalías que podrían ser indicios de fases iniciales de ciberataques, alineados con la matriz MITRE Att&ck.
CSIRT (Computer Security Incident Response Team)
Definición, control y ejecución de playbooks ante ciberamenazas y ciberataques. Tambien se definen los procesos de recuperación ante ciberataques para su ejecución por parte de los equipos IT.
Operación en ciberseguridad (Cyber SOC)
Entendimiento de un CyberSOC y de la operación de playbooks de análisis y respuesta ante eventos de ciberseguridad asi como la revisión de estos para aplicar mejoras.
Cyber Threat Intelligence
Proceso de Threat Intelligence como input a los procesos de prevención ante ciberataques, que identifica los actores maliciosos con potencial impacto en la entidad, mide el nivel de impacto en base a las tácticas y técnicas y vulnerabilidades de las cuales que hace uso, mantiene un scoring de riesgo por actor y en general de riesgo como métrica anticipativa de ciber-riesgo.
Competencias
H INVESTIGACIÓN DE TENDENCIAS E IMPACTOS DE IA AL NEGOCIO
H GESTIÓN DE CONFLICTOS, AMENAZAS Y VULNERABILIDADES
H PLATAFORMAS DE SEGURIDAD
S.1.1 ALIANZAS – COLABORACIÓN Y TRANSVERSALIDAD
S.1.4 ALIANZAS – COMUNICACIÓN
S.1.3 ALIANZAS – INFLUENCIA
S.1.2 ALIANZAS – ORIENTACIÓN A CLIENTE
S.2.1 HUMANISMO – COMUNICACIÓN Y EMPATÍA
S.2.2 HUMANISMO – LIDERAZGO Y DESARROLLO DE EQUIPOS / AUTOLIDERAZGO
H ARQUITECTURA DE SEGURIDAD
S.4.1 ANTICIPACIÓN – ANTICIPACIÓN Y GESTIÓN DEL CAMBIO
S.3.1 EMPODERAMIENTO – FOCO EN RESULTADOS
H DOCUMENTACIÓN TÉCNICA
H SEGURIDAD DE APLICACIONES
S.5.1 DIVERSIDAD – IMPULSO DE LA DIVERSIDAD
H CLOUD AND INFRAESTRUCTURE SECURITY
H TECNOLOGÍAS DE SEGURIDAD DE LA INFORMACIÓN
H ANALÍTICA AVANZADA Y MODELOS PREDICTIVOS
H PROCEDIMIENTOS DE CIBERSEGURIDAD
H REDES Y SEGURIDAD
H CIBERFRAUDE
H IMPLANTACIÓN SOLUCIONES DE MERCADO DE IA
H GESTIÓN Y MONITORIZACIÓN DE PLATAFORMAS DE SEGURIDAD
H IA LITERACY
This job was automatically translated to English, .