Assistant Vice President / Vice President, Cloud Security Analyst, Global Information Security, Sydney, Australia
Ghr
·Today
- Location
- Sydney, Australia
- Workplace
- Onsite
- Type
- Full-time
- Department
- IT
- Seniority
- VP
- Education
- Bachelor
- Source
- Workday
Description
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
We are seeking a skilled and motivated Cloud Security Analyst to join our cybersecurity team. This role focuses on proactively identifying, analyzing, and mitigating security threats and alerts across cloud-native environments (IaaS, PaaS, SaaS). The ideal candidate will have a deep knowledge of cloud security principles, hands-on experience cloud security monitoring tools, and a good understanding of security threats to cloud environments. Ideal candidate has worked in a security operations center previously.
The Cloud Security Analyst will work closely with other GIS teams as experts in the detection and analysis of all suspicious activity originating in or related to the bank’s cloud environments. The Analyst is responsible for the timely and accurate identification of security events, mastery of the technologies and information that we analyze, while maintaining knowledge of detection tools and techniques, and proper escalation of incidents for immediate response, containment, and recovery.
Operates processes and/or tools that provide alert monitoring, analysis, triage, and incident response. Uses understanding of security threats, vulnerabilities, exploits, attack vectors, malware, and digital forensics to guide operations and reporting. Typically has 2-5 years of relevant experience across multiple information security and SOC disciplines as an individual contributor.
This is a full-time role (38 hours per week), with standard working hours of 9:00AM to 7:30PM AEST 4 days per week (Wednesday to Saturday) to align with the nature of the support provided by the team.
Flexibility may occasionally be required to support business, operational, or project deliverables.
Job Responsibilities:
- Responsible for providing AWS and Azure Cloud event monitoring, dispositioning of cases and escalation to designated control partners
- Update documentation as new changes occur in the environment or tooling.
- Tune existing alerts to remove false positives.
- Able to understand and articulate current threats against cloud environments including AWS, Azure, and GCP.
- Monitoring for suspicious AI utilization and jailbreak attempts.
- Utilize Splunk and Log Analytics for viewing cloud logs related to AWS and Azure cloud environments.
- Triage and report critical cloud vulnerabilities.
- Expectation of weekend shift work
- Motivated self-starter and willing to learn
- Broad awareness of information security operations and/or enterprise information technology (Enterprise data management, application development, network management)
Experience
- Two (2) to five (5) years of experience in Cyber Security, Incident Response, or related field.
- 2 years’ experience using splunk in security investigations.
- Experience with Azure Security Center, AWS Cloud Security Hub, or Google Cloud Security
- Bachelor’s Degree in Computer Science, Information Systems, Cyber Security, or related experience.
- Experience working with incident response teams, vulnerability managers, threat intelligence researchers, Red/Purple teams, and/or HUNT researchers.
- A broad knowledge of information security principles and security capabilities
- Some experience with large on-prem or hybrid-cloud environments deployments.
- Understanding of configuration management, orchestration, and automation tools, such as Terraform, Ansible, Puppet, Chef, SaltStack, or Packer.
- Basic familiarity with common Information Security and data protection frameworks and standards (i.e. CIS, NIST, MITRE, ITIL, HIPAA, GDPR, PCI DSSS, ISO 270001).
Desired Skills:
- CISSP/CCSP/CISM
- Cloud specific Security certifications such as SANS/GIAC
- Vendor specific and relevant certifications – AZ-500, SC-200, AZ-204, CKA, CKS, RHCE, etc
- Bachelors degree in a technical field
- Bachelor’s degree in information technology or related field
- Leadership competency in geographically diverse matrixed environment.
- Relevant Cyber Security Certificate
- Worked in SOC environment before
- Familiarity with Cyber Security and Information Technology.
- Strong problem-solving and critical thinking skills.
- Effective communication and interpersonal skills.