Search jobs > Dallas, TX > Threat analyst

Threat Detection Analyst Lead

Triumph Financial
Dallas, TX, US
Full-time

Join TriumphX!

TriumphX, a member of the Triumph Financial portfolio of brands, provides a concentration of technology and project management resources the members of the Triumph Financial portfolio of brands TriumphPay, Triumph and TBK Bank via a shared service model.

We’re looking for top tech and project management talent to analyze, recommend and build strategic solutions that support Triumph Financial’s mission to become a world-class, market-leading financial and technology company.

This is a pipeline requisition and not a job opening. We are in the process of pipelining for anticipated future job openings.

As a Threat and Detection Analyst Lead, you will work with a team to help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information.

You will design, deploy, configure, and manage the Security information and event management, (SIEM) to ensure effective and efficient threat detection and incident response capabilities.

You will collaborate with internal stakeholders to identify and define SIEM use cases, threat detection rules, alerts, and correlation rules based on industry standards and best practices.

And you will monitor and analyze security events and logs to identify potential security incidents, intrusions, and vulnerabilities.

A Day in the Life :

Investigate and respond to security alerts and initiate incident response procedures as required.

Conduct advanced log analysis and perform forensic investigations to identify indicators of compromise (IOCs) and patterns of malicious activity.

Develop and maintain incident response playbooks and procedures, and participate in incident response activities as needed.

Conduct periodic reviews and assessments of SIEM configurations, rules, and processes to identify areas for improvement and optimization.

Stay up to date with the latest industry trends, threat intelligence, and emerging technologies in the field of SIEM and threat detection.

Provide guidance, training, and knowledge transfer to junior team members on detection engineering and SIEM best practices.

Protects the confidentiality, integrity and availability of critical data, systems, and services

Safeguard information system assets by identifying and solving potential and actual security and risk concerns

Protects systems by defining role and attribute-based access privileges, control structures, and resources

Categorizes risks and threats by identifying abnormalities and reporting violations

Implements security improvements by assessing situation; evaluating trends; anticipating requirements

Determines security violations and inefficiencies by conducting periodic audits

Monitors, investigates, and responds to security alerts

Upgrades cyber security program and capabilities by implementing and maintaining security controls

Prepares performance and stability reports to communicate system status to users and management

Performs other duties as required

To succeed in this role, we hope you bring :

Bachelor’s degree in Information Security, Information Systems, Computer Science, or equivalent work experience

SANS certification Preferred (GSEC, GCIH, GCFA, GDAT, GCDA)

5+ years experience in threat detection or threat hunting

Certified Information Systems Security Professional (CISSP) Preferred

Cloud analytic security tools

CIS 2.0 security and NIST 800-53 framework controls

FFIEC Cyber Assessment Tool (CAT)

SOC I, SOX, GLBA, and FFIEC regulatory compliance

Experience developing SIEM correlation rules.

Experience creating EDR detection and exclusion rules.

Familiarity with SOAR is a plus.

Strong self-motivation and time management skills required.

Excellent written and verbal communication skills required.

Experience with Active Directory / Entra ID

Experience with offensive security frameworks and tooling

Experience with network security controls (e.g., firewalls, proxy, IPS / IDS)

Understanding of Authentication and Authorization protocols

Some Additional Skills and Abilities that would be ideal to have :

Ability to function with limited supervision and provides support to junior associates

Strong interpersonal skills.

Quality written and oral communication, and presentation skills.

Critical thinking and problem-solving skills.

Attention to detail.

Commitment to operational excellence and continuous process improvement.

Willingness to expand and apply security knowledge, skills, and abilities to department initiatives.

Strategic project management and oversight of milestones and deliverables.

Threat management and response

System administration

Network security concepts

Information security policy

Firewall administration

Network protocols

Intrusion Detection and Prevention systems (IDS / IPS)

Data Loss Prevention (DLP)

Endpoint Detection and Response (EDR)

Mobile Device Management (MDM)

Identity Access Management and Privileged Access Management (IAM and PAM)

Role and attribute-based access controls

RBAC and ABAC)

TLS and certificate management

Log analysis

URL filtering

Patch Management

Security Information and Event Monitoring Tools (SIEM)

Vulnerability scanners

E-mail filtering, phishing, SMTP header analysis

Wireless technology and security

Work Environment :

The work environment characteristics described here maybe encountered while performing the essential functions of this job.

Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Moderate noise (i.e. business office with computers, phone, and printers, light traffic).

Ability to work in a confined area.

Ability to sit at a computer terminal for an extended period of time. Occasional stooping or kneeling may be necessary.

While performing the duties of this job, the employee is regularly required to stand, sit, talk, hear and use hands and fingers to operate a computer keyboard and telephone.

Specific vision abilities are required by this job due to computer work.

Light to moderate lifting is required.

Regular, predictable attendance is required.

LI-JC1

We offer Medical, Dental, Vision, Paid Time Off, 401k and much more.

30+ days ago
Related jobs
Triumph Financial
Dallas, Texas

As a Threat and Detection Analyst Lead, you will work with a team to help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Stay up to date with the la...

Goldman Sachs
Richardson, Texas

Across Wealth Management, our growth is driven by a relentless focus on our people, our clients and customers, and leading-edge technology, data and design. Review developing cases, identify and analyze points of compromise, and communicate potential risk to Fraud leadership. Minimum of 1-3 years of...

Promoted
Hispanic Technology Executive Council
Irving, Texas

Citi is looking for a security focused person with a good understanding of cybersecurity principles to work in the Cloud Threat Modeling team. IT experience minimum of 10 years, with minimum a of 4 years in Cyber-Security/Information Security. Experience working in a cyber-security role. Security pr...

Promoted
VirtualVocations
Irving, Texas

A company is looking for a Medicaid Financial Analyst to manage client Medicaid revenue and reporting in multiple states. ...

Promoted
LHH
TX, United States

Project Manager (Non Tech 3 - REMOTE) Needed!. LHH has a client located in Redmond, WA who needs a Project Manager (Non Tech 3) on a contract opportunity!. Title: Project Manager (Non Tech 3). We are seeking a highly skilled and experienced Senior Project Manager to be part of AI Business Strategy t...

Promoted
Elit IT Inc.
Dallas, Texas

Job Title: Technical Project Manager. Lead, plan, and manage multiple technology projects from initiation through completion, ensuring adherence to timelines, budgets, and quality standards. Oversee all phases of the project lifecycle, coordinating activities across engineering, QA, and cross-functi...

Promoted
Connective Talent
TX, United States

Join one of the nation's top ranked Title Insurance companies, looking for an Application Security Engineer to join their security team. Highly visible - Direct channels to the Director of Information Security. Expertise in cloud security - Azure environments preferred. Experience with API security ...

Promoted
Agile Resources, Inc.
TX, United States

Cybersecurity, IT, Security, Compliance, NIST, SOC, Azure, AWS, Cloud, Assessment, Audit, CISSP, CISM, Cyber Security. They are seeking a Cybersecurity Engineer to add to their team. Experience with Azure cloud infrastructure and security. Experience with risk management in compliance and security. ...

Promoted
Stream Realty
Dallas, Texas

This Senior Financial Analyst will work in Stream’s downtown Dallas headquarters office and will work in-office daily. This position will support the entire team with a focus on financial aspects and will be an important part of the detailed operations of the group. Knowledge of real estate fi...

Promoted
Raymond L Goodson Jr Inc
Dallas, Texas

Where applicable, directs and oversees junior or subordinate staff members regarding construction operations, and / or maintenance tasks and assignments at a project site. Must be able to travel to various project sites, meetings, etc. ...