Why USAA?
Let’s do something that really matters.
At USAA, we have an important mission: facilitating the financial security of millions of U.S. military members and their families. Not all of our employees served in our nation’s military, but we all share in the mission to give back to those who did. We’re working as one to build a great experience and make a real impact for our members.
We believe in our core values of honesty, integrity, loyalty and service. They’re what guides everything we do – from how we treat our members to how we treat each other. Come be a part of what makes us so special!
The Opportunity
The Cyber Threat Intelligence (CTI) team is seeking a motivated Cyber Threat Intelligence Technical Analyst with demonstrated experience in cyber threat-centric analytic capabilities and responsible for the identification and technical analysis of cyber advanced threats. The CTI team is USAA’s premier cyber intelligence program dedicated to support our Cyber Threat Operation Center (CTOC). The CTOC exists to detect, analyze, and respond to cyber security events. The CTOC is comprised of several teams that partner as needed to provide centralized and coordinated response activities for cyber threats. Our Cyber Threat Intelligence team is responsible for collecting, analyzing, and disseminating threat intelligence regarding threat actors targeting USAA. This information is used to continually enhance threat management capabilities to maximize our protective and detective cyber security posture and continuously improve our processes. Specifically, a successful candidate will have a strong background in cybersecurity or intelligence operations, data science, python scripting, and the ability to leverage these skills to enable threat analysis at scale.
We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ or Charlotte, NC. Relocation assistance is not available for this position.
What you'll do:
- Leads peers and team members in the execution of the Information Security domain activities while anticipating efforts that will impact their team.
- Researches and analyzes the latest information security vulnerabilities, threats, exploits, trends and intelligence. Shares intelligence with peer teams.
- Conducts advanced vulnerability management, security configuration assessments, and/or penetration testing operations and manages the resulting findings.
- Develops analysts through training and knowledge sharing activities.
- Monitors internal and external networks, systems, and applications for advanced security anomalies and events (e.g. suspicious behavior, attacks, and security breaches). Trains analysts in incident detection and response.
- Responds to cyber incidents, performing detailed analysis using complex security tools to determine root cause and impact by using a broad range of demonstrated experience (e.g. forensics, networking, servers, coding, etc.) to determine a malicious actor's tactics, techniques, and procedures. Trains new analysts in incident detection and response.
- Utilizes discoveries from the incident response process to make significant and/or complex improvements to the existing detection capabilities, operational processes and security controls.
- Prepares and delivers written and/or verbal briefs with recommendations to senior leadership on latest threats, alerts, incidents, and improvements.
- Provides insight on issues and serves as a mentor and coach to peers and team members for assigned area of responsibility.
- Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.
What you have:
- Bachelor’s degree; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.
- 6 years of related experience in Information Security, Cybersecurity and/or Information Technology with a security focus to include accountability for complex tasks and/or projects.
- 4 years of related experience in one of the following domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communications and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, Software Development Security.
- Advanced level of business acumen in the areas of business operations, risk management, industry practices and emerging trends.
- Knowledge of attacker tools/tactics/procedures and applying them to access management, governance, threat hunting, investigations, and incident response.
- Knowledge of defense-in-depth principles and security architecture.
What sets you apart:
- 3+ years experience with threat intelligence, technical analytic tradecraft, security-focused data analysis and/or network traffic analysis
- Strong understanding of the intelligence lifecycle, analytic tradecraft, and attack methodologies such as MITRE ATT&CK.
- Demonstrated experience utilizing Synapse to track threat actors and strong ability to use Synapse STORM query language
- Experience with triaging malware and conducting analysis around this triage
- 2+ years’ experience with building automation solutions using scripting languages such as Python
- Strong background in cybersecurity, threat intelligence, or data science experience
- Experience leveraging vendor and open-source security research tools' APIs
- Experience in conducting incident response and analysis; such as evaluating host and network forensic reports of electronic media, packet capture, log data analysis, malware triage on network devices in support of intrusion analysis or enterprise level information security operations
- Excellent knowledge of adversarial cyber actors, to include tactics, techniques, and procedures
- US military experience through military service or a military spouse/domestic partner
The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.
What we offer:
Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position. The actual salary for this role may vary by location. The salary range for this position is: $120,550 - $230,400.
Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.
Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.
For more details on our outstanding benefits, please visit our benefits page on USAAjobs.com.
Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting.
USAA is an equal opportunity and affirmative action employer and gives consideration for employment to qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, national origin, age, disability, genetic information, protected veteran status, or any other legally protected characteristic.