Support the bank's cyber defence functions by assisting with MSSP operations, performing security assurance tasks, and participating in purple team exercises. This role provides hands on exposure to security monitoring, control testing, and threat based validation activities in a regulated banking environment.
Key Responsibilities
Monitor MSSP alerts and escalations, ensuring timely follow up with internal teams.
Perform initial triage security events under supervision.
Assist in maintaining SIEM/EDR use cases and updating detection rules.
Prepare MSSP performance summaries and KPI reports.
Support control testing activities across EDR, network security, and application security.
Collect evidence from system owners and validate completeness and accuracy.
Assist in documenting test results, findings, and remediation tracking.
Help maintain assurance documentation, checklists, and compliance records.
Participate in purple team exercises by documenting attack steps, detection results, and gaps.
Assist in mapping detection coverage to MITRE ATT&CK techniques.
Update detection logic and playbooks based on purple team outcomes.
Lead the end to end vulnerability management lifecycle: discovery, validation, risk rating, tracking, and closure.
Coordinate patch cycles
Conduct proactive threat hunting exercises to identify and mitigate advanced persistent threats (APTs) and other sophisticated attack vectors.
Ability to conduct attack simulations (e.g., Metasploit, Cobalt strike) to validate detection coverage.
Qualifications & Experience
Bachelor's degree in Information Security, Computer Science, or related discipline.
3-5 years of experience in cybersecurity, SOC, IT operations, or risk/compliance.
Basic understanding of SIEM, EDR, network security, and common attack techniques.
Familiarity with security frameworks (NIST CSF, ISO 27001, OWASP) is an advantage.
Experience in banking or finance sectors is a plus
Possession of relevant of HKMA ECF certifications in cybersecurity.
Numbers & Facts
Location
San Francisco, CA
Skills
Applications Securityunmatched
Banking Servicesunmatched
Computer Scienceunmatched
Computer Securityunmatched
Event Managementunmatched
Financeunmatched
Huntingunmatched
ISO (International Organization for Standardization)unmatched
Information/Data Security (InfoSec)unmatched
Internet Securityunmatched
Metasploitunmatched
Network Securityunmatched
Operations Security (OPSEC)unmatched
Patient Assessmentunmatched
Performance Metricsunmatched
Product Lifecycleunmatched
Riskunmatched
Security Attacksunmatched
Security Information and Event Management (SIEM)unmatched
Security Monitoringunmatched
Software Patchesunmatched
System Validationunmatched
Team Playerunmatched
Time Managementunmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
Use Casesunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.