Job Purpose:
In the Cluster Cyber Defence & Bases Services we are the Commerzbanks 1st Line of Defense to protect the bank against Cyber Threats and potential Cyber Attacks. Together with the already existing Security Operations Centers in Frankfurt, Singapore and NY acting as a 2nd layer of the SOC the new team in KL will be a 1st layer SOC and is supposed to provide 24/7 coverage for monitoring and reacting to security incidents and potential Cyber threats.
Key Activities:
- The Active Defense Center is responsible for the early and effective detection and prevention of attacks on the bank's data integrity and information security in the exciting environment of Cyber Security. We achieve this together with our 3 existing ADC locations in Singapore, Frankfurt and New York together with our new 24/7 first level SOC in KL. We are responsible for the detection and proactive defense against cyber-attack scenarios and actively define and manage the implementation and configuration of appropriate security measures.
- In the first level SOC you will be responsible for monitoring our core SIEM tool Google Chronicle as well as MS-Defender and VectraAI. Based on pre-defined playbooks you will initiate response measures as well as document and track incidents in ServiceNowSecOps. In addition, you will provide comprehensive reports on Cyber incidents. Further you will monitor external information sources on upcoming vulnerabilities and available patches and create internal patch advisories for distribution into the Bank. You are characterized by a high level of flexibility and commitment and a basic understanding of Cyber security topics.The role also includes the participation in task forces to respond to cyber threats.
Specialist knowledge (work experience, further qualification):
- Studies or equivalent training with a focus on information and Cyber security
- Basic understanding of cyber-attack scenarios, information security and cyber defense
- Experience with at least some of the relevant tools and applications - in particular SIEM (preferrable Chronicle), IDS/IPS, Web Application Firewalls, Defender)
- Basic understanding of relevant infrastructure architecture and systems in the bank (firewall, proxy, logging & monitoring, MS-Defender, Office 365, Exchange Online, Cloud, Active Directory, etc.)
- Good understanding of Unix, Windows, MS Office applications and SharePoint
- Strong analytical solution and customer-oriented thinking and action
- Decision-making, conflict and integration skills, thinking outside the box
- Outstanding communication skills in English