Career Central

Connecting people since 1887
Leverage our network to build your career.
Tell us about your professional DNA to get discovered by any company in our network with opportunities relevant to your career goals.

Cyber Intelligence Senior Associate | Threat Modeling Analyst



Plano, TX, USA
Posted on Friday, June 28, 2024

Job Description

Job Description

Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement.

Being a member of the Cybersecurity Operations Threat Modeling team (COTM), you'll play an integral role modeling threats and producing content that supports and drives assessment and controls uplift initiatives that ultimately protect the firm's technological assets. You will also partner with a global team of technologists and innovators in leveraging threat data to improve the firm's detect, prevent and respond capabilities and support the broader Cybersecurity Operations' mission.

Job responsibilities

  • Analyze threat intelligence and incident reports to identify threat actor's tactics, techniques and procedures and targeted technologies
  • Produce regular curated and actionable threat content (attack paths) to support internal downstream threat assessment activities and controls uplift reviews
  • Developing and maintaining standard operating procedures to ensure consistency in operations execution
  • Leverage attack paths data to identify and recommend monitoring use cases for JPMC's systems that aligns with Cyber Operations detection strategy
  • Support Cyber Ops strategic platforms development initiatives for curated threat data access and analysis
  • Participate in external research projects with MITRE Center for Threat Informed Defense (CTID) that aims to uplift the cyber capabilities of the community and member organizations.

Required qualifications, capabilities, and skills

  • 3+ years of experience in cybersecurity or resiliency, with demonstrated exceptional organizational skills to plan, design, and coordinate the development of offensive security testing, assessments, or simulation exercises
  • Strong understanding of system stack including operating systems, middleware, databases and network
  • Knowledge of attackers' tactics, techniques and procedures (TTP), attack paths and how systems or network could be compromised
  • Knowledge of cloud architecture and concepts including PaaS, SaaS and IaaS
  • Proven experience differentiating between threats and controls and articulate how controls could mitigate threats
  • Experience performing threat models, risk assessments, threat intelligence and/or SOC analysis.
  • Knowledge of US financial services sector cybersecurity or resiliency organization practices, operations risk management processes, principles, regulations, threats, risks, and incident response methodologies
  • Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels

Preferred qualifications, capabilities, and skills

  • Hold relevant industry certifications – such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Offensive Security Certified Professional (OSCP)– showcasing advanced expertise in cybersecurity and offensive testing methodologies or resiliency
  • Prior experience as a Threat Intelligence or SOC analyst is valued.