Tier 1 Security Operations Analyst
General Job Summary
The Tier 1 Security Operations Analyst will serve as the frontline defender protecting University Bank’s critical infrastructure, financial data, and customer trust. Operating in a fast-paced, 24/7/365 environment, this associate-level role will work closely with other members of the Information Security and Information Technology teams, and various business units to monitor security consoles in real-time to identify, triage, and investigate potential threats against the network, ensuring minor anomalies do not escalate into major breaches.
Additionally, this position helps guide the development and operational aspects of University Bank’s Information Security Program. The analyst works closely with other members of the Information Security and Information Technology teams, as well as various business units, to ensure confidentiality, integrity, and availability of infrastructure and customer data.
Summary of Essential Job Functions
The Tier 1 Security Operations Analyst role is composed of a variety of administrative and operational activities supporting University Bank’s real-time defense and departmental initiatives as outlined below:
Real-Time Monitoring & Threat Detection
- Dashboard Oversight: Actively monitor Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) dashboards to detect anomalous activity, unauthorized access, or potential intrusions.
- Log Analysis: Review security logs and reports from firewalls, intrusion detection/prevention systems (IDS/IPS), network databases, Web Filters, Email Filters, Endpoints, and third-party monitoring services to identify trends and potential indicators of compromise (IOCs).
- Security Controls Review: Review security requirements for new systems, existing systems, and system upgrades, while designing appropriate security controls for projects and operations.
Incident Triage, Escalation & Tracking
- Alert Verification: Triage incoming security alerts efficiently, distinguishing between benign false positives and true malicious threats.
- Incident Escalation: Execute established standard operating procedures (SOPs) to escalate critical, high-risk events to the Information Security Engineer, Security Manager, or Information Security Officer (ISO).
- Financial Scope Awareness: Maintain a high level of awareness regarding threats specific to financial systems, such as wire fraud patterns, data exfiltration attempts, and ransomware.
- Documentation & Remediation: Track remediation efforts related to any information security items and document every step taken during the initial triage process clearly and comprehensively within the enterprise ticketing system.
- Playbook & Procedure Maintenance: Assist with the maintenance and development of departmental procedures, guides, checklists, forms, and Security Operations playbooks based on observed trends and evolving attack vectors.
Phishing Analysis & Security Awareness
- Pipeline Management & Extraction: Review and analyze suspicious emails reported by banking and corporate staff via the internal phishing reporting pipeline, safely extracting artifacts like email headers, attachments, and URLs to identify phishing campaigns, credential harvesting, or malware delivery methods.
- Platform Administration: Assist the primary technical administrator for the corporate security awareness platform (KnowBe4).
- Phishing Assessments: Assist in the design, implementation, and execution corporate-wide simulated email phishing testing exercises and assessments.
- Training & Materials: Help design, publish, distribute, and deliver printed, electronic, virtual, and on-premises security awareness training activities, ensuring the program meets established industry best practices.
- KPI Reporting: Remain current on key awareness topics and interpret and report awareness-related key performance indicators (KPIs) to the ISO.
Audit, Risk Assessments
- Audit Preparation: Perform document collection, track requests, and assist leadership in preparing materials for information security audits and exams.
- Risk Tool Updates: Assist in reviewing and completing annual updates to the IT Risk Assessment, Information Security risk assessment, FFIEC Cyber Security Awareness Tool, and information security aspects of the GLBA risk assessment.
- Policy Maintenance: Work with leadership to develop, implement, and maintain information security policies and programs.
Other Job Functions
- All other duties as assigned by management.