7900 Westpark Drive (12131), United States of America, McLean, Virginia
Threat Content Signature Engineer
Capital Ones Cyber Organization is a fast-paced, dynamic environment committed to enabling and securing the business. In this role, you will be responsible for solving hard problems using cutting edge technology in the areas of engineering, alert development, and monitoring.
Primary Responsibilities
* Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities.
* Lead the construction of signatures which can be implemented on cyber defense network tools in response to new or observed threats within the network environment or enclave.
* Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain currency of cyber defense threat condition and determine which security issues may have an impact on the enterprise.
* Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources.
* Analyze and report organizational security posture trends.
* Provide thought leadership to implement best practices to detect malicious activity in a fast-paced, ever-changing technology environment
* Engage with internal teams, industry partners, and information sharing centers to leverage intelligence about the threat landscape and prioritize the creation of signatures
* Understand the business drivers of the enterprise and partner with relevant stakeholders to ensure robust monitoring and expanded coverage across our hosts, networks, and applications
* Collaborate with operation teams to build novel detections, establish repeatable processes, and drive automation for containment and remediation activities
* Analyze and define data requirements and specifications for log ingestion and new security products
* Coordinate and provide expert technical leadership to enterprise-wide cyber defense operators to resolve cyber defense incidents.
* Coordinate with enterprise-wide cyber defense staff to validate alerts and conduct continuous testing.
* Demonstrate a deep knowledge of adversary techniques and emerging threats that could adversely impact business activities.
* Support ongoing incident response and technical investigations.
* Support audit assessments.
Basic Qualifications
* At least 5 years of experience in Information Technology.
* At least 3 years of experience working with Host and Network based Intrusion detection and prevention systems including signature development and event alert analysis.
* At least 3 years of experience using Security Information and Event Management technologies (Securonix, ArcSight, LogRhythm, ELK, Splunk).
* At least 3 years of experience with cyber use case and content development within SIEM systems, including SOAR methodologies.
* At least 3 years of experience working with cyber threat intelligence and the Mitre ATT&CK; framework.
* At least 3 years of experience securing Cloud Security across AWS, Azure, or GCP.
Preferred Qualifications
* 7+ years of experience working with network & operating system security concepts.
* 2+ years of experience performing cyber defense analysis specifically using Securonix SIEM.
* 2+ years of experience working in the financial industry or similarly regulated environment.
* 2+ years of experience writing regular expressions.
At this time, Capital One will not sponsor a new applicant for employment authorization for this position.
McLean, VA
Capital One Financial Corporation operates as the bank holding company for the Capital One Bank (USA), National Association; and Capital One, National Association, which provides various financial products and services in the United States, the United Kingdom, and Canada. It operates through three segments: Credit Card, Consumer Banking, and Commercial Banking.
The company offers non-interest-bearing and interest-bearing deposits, such as checking accounts, money market deposit accounts, negotiable order of withdrawals, savings deposits, and time deposits. It also provides credit card loans; auto, home, and retail banking loans; and commercial and multifamily real estate, commercial and industrial, and small-ticket commercial real estate loans. In addition, the company offers credit and debit card products; online direct banking services; and treasury management and depository services.
It serves consumers, small businesses, and commercial clients through the Internet and mobile banking, as well as through Cafés, ATMs, and branches located in New York, Louisiana, Texas, Maryland, Virginia, New Jersey, and the District of Columbia. Capital One Financial Corporation was founded in 1988 and is headquartered in McLean, Virginia.