Full-Time

Cybersecurity Incident Response Analyst I

Posted on 2/13/2025

Western & Southern Financial Group

Western & Southern Financial Group

1,001-5,000 employees

Provides personalized financial solutions and services

No salary listed

Entry, Junior

Cincinnati, OH, USA

Category
Cybersecurity
IT & Security
Required Skills
TCP/IP
Python
Ruby
Java
Perl
Linux/Unix
Data Analysis
Requirements
  • Bachelor's Degree In information assurance, information systems, computer science, IT, or commensurate selection criteria experience.
  • Proven experience in threat detection technologies, including intrusion detection and prevention systems (IDS/IPS), security incident and event management (SIEM) technology, and network packet analyzers.
  • Demonstrated experience in incident analysis and response activities, including execution of response and analysis plans, processes and procedures, and performing root-cause analysis.
  • Proven experience on both Linux-based and MS Windows-based system platforms with a strong IT technical understanding and aptitude for analytical problem-solving.
  • Basic experience with one or more scripting languages (examples: Python, Perl, Java or Ruby).
  • Experience with security tools, including, but not limited to, IDS (snort or suricata preferred), IPS, data analytics software, SIEM solutions (Sentinel preferred), web application firewall (WAF), malware analysis, knowledge base platforms and live response/forensics tools.
  • Demonstrated ability to serve as a subject matter expert in one or more areas of incident response, including, but not limited to, endpoint detection and response, application security or network forensics.
  • Proven SIEM utilization skills, including the ability to review and analyze security events from various monitoring and logging sources to identify or confirm suspicious activity.
  • Proven basic working knowledge of each of the specialty areas of cybersecurity (Threat Intelligence, Threat Hunting, Digital Forensics).
  • Demonstrated knowledge of current security trends, threats and techniques. Demonstrated self-driven desire to continually learn and grow in knowledge related to the constantly evolving threat landscape.
  • Demonstrated strong understanding of enterprise, network, system and application level security issues.
  • Proven understanding of the current vulnerabilities, response and mitigation strategies used in cyber security.
  • Demonstrated strong team player - collaborate well with others to solve problems and actively incorporate input from various sources.
  • Proven customer focus, evaluates decisions through the eyes of the customer; builds strong customer relationships and creates processes with customer viewpoint.
  • Demonstrated analytical skills - continuously defines problems, collects or interprets data, establishes facts, anticipates obstacles and develops plans to resolve; strong problem solving skills while communicating in a clear and succinct manner effectively evaluating information/data to make decisions.
  • Proven inherent passion for information security and service excellence.
  • Demonstrated excellent verbal and written communication skills; frequently expresses exchanges or prepares accurate information conveying information to internal and external customers in a clear, focused and concise manner. Continuously conforms to proper rules of punctuation, grammar, diction and style.
  • Proven self-starter with strong internal motivation. Proven ability to work with broad supervision or direction.
  • Demonstrated ability to work under multiple deadlines with broad supervision. Cite examples of successfully organizing and effectively completing projects where given minimal direction.
  • Proven ability to continuously perform an activity such as preparing and analyzing data and figures, and transcribing.
  • Linux-based and MS Windows-based system platforms.
  • Strong understanding of enterprise, network, system and application level security issues.
  • Understanding of enterprise computing environments, distributed applications, and a strong understanding of TCP/IP networks.
  • Fundamental or greater understanding of encryption technologies.
  • Knowledge of Identity & Access Management practices, systems and controls.
Responsibilities
  • Under broad supervision, investigates incidents that are escalated per procedure. Communicates with customers as appropriate, keeping Cybersecurity Operations Center (CSOC) management informed per incident severity requirements. Follows applicable processes and procedures while maintaining flexibility to 'think outside the box' during the investigation in order to find all affected systems, including 'patient zero'; performs root-cause analysis; determines attribution if appropriate; completes documentation; and participates in lessons learned post mortem.
  • Provides supervision and backup for monitoring capabilities. Works with Cybersecurity Threat Analysts on automation recommendations. Evaluates and makes recommendations to Senior Cybersecurity Analysts. Leads project team to implement improvements.
  • Ensures process, procedure and system documentation are complete and followed consistently. Assists senior cyber associates in creating, revising, and maintaining processes and procedures related to continuous monitoring, triage, incident analysis and incident response activities. Consults with other cyber associates to continuously improve those processes and procedures, and works with other associates to ensure that when new tools or external inputs change that the documentation is adjusted accordingly.
  • Assists in the mentoring and training of junior cyber associates to learn proper investigation techniques, documentation requirements and evidence handling. Serves as a technical consultant to those associates. Functions as a technical contact for managed security service provider (MSSP) analysts when technical questions arise, consulting with senior analysts and management for guidance as appropriate.
  • Assists more senior analysts and managed security service providers in documenting and implementing use case detections. Participates in periodic use case reviews and works with other analysts to adjust existing use cases under broad supervision.
  • Communicates with CSOC management, cyber and information security staff members, and customers in written and verbal communication regarding investigations and status updates. Maintains need-to-know discretion for all investigations.
  • Interfaces regularly with the Cybersecurity Engineer to test and improve custom tools, suggesting features and improvements in order to improve efficiency and productivity. During investigations, communicates with the engineer in order to quickly gather the information needed in the most efficient manner possible, giving constructive feedback on custom tools provided in that process.
  • Performs knowledge sharing with team members through meetings, presentations and written communications. Creates, revises and maintains documentation of incident response processes and procedures in the central knowledge base.
  • Participates in after incident lessons learned meetings to give input on recommendations for process or procedure improvements, and to provide mitigation recommendations to reduce future incidents or minimize their impact.
  • Tracks performance metrics and provides timely updates to CSOC management.
  • Performs other duties as assigned.
  • Complies with all policies and standards.
Desired Qualifications
  • Experience in a SOC environment is preferred.
  • Candidate encouraged to hold one or more of the following security certifications: Certified Information Systems Security Professional (CISSP), GIAC Certifications (GCIH, GCIA for example), Certified Ethical Hacker (CeH).
Western & Southern Financial Group

Western & Southern Financial Group

View

Western & Southern Financial Group offers financial solutions that simplify complex financial concepts for middle-market clients. They work directly with clients to understand their needs and provide tailored financial products. Their approach emphasizes personal relationships, which sets them apart from competitors. The company has a long history of financial stability since 1888, and their dedicated sales force, supported by management, focuses on delivering excellent service. Their goal is to build strong, loyal relationships with clients while maintaining a respectful and professional culture.

Company Size

1,001-5,000

Company Stage

N/A

Total Funding

N/A

Headquarters

Cincinnati, Ohio

Founded

1888

Simplify Jobs

Simplify's Take

What believers are saying

  • Growing demand for personalized financial advice aligns with Western & Southern's service model.
  • Partnership with Fidelity enhances product offerings in the retirement income market.
  • Expansion of financial literacy programs supports Western & Southern's mission to simplify finance.

What critics are saying

  • Increased competition from Fidelity's Guaranteed Income Direct solution in the retirement market.
  • Exclusion from licensing in key states like New York limits market reach.
  • Reliance on face-to-face interactions may be challenged by digital financial service growth.

What makes Western & Southern Financial Group unique

  • Western & Southern offers personalized financial solutions through face-to-face client interactions.
  • The company has a long-standing reputation for financial stability since 1888.
  • Western & Southern collaborates with Fidelity Investments to offer innovative retirement income solutions.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Performance Bonus

Company News

Cincinnati Enquirer
Aug 9th, 2024
Cincinnati-based company listed among the best for high school grads to start careers

Cincinnati-based Western & Southern was No. 48 of the top 50 companies listed on the report.

U.S. Securities and Exchange Commission
Feb 1st, 2024
SEC FORM D/A

The Securities and Exchange Commission has not necessarily reviewed the information in this filing and has not determined if it is accurate and complete.The reader should not assume that the information is accurate and complete.

Western & Southern Financial Group
Jan 31st, 2024
Western & Southern, Fidelity Investments Offer New Approach To Protected Retirement Income

Western & Southern recently introduced IncomePoint - a new single-premium immediate annuity (SPIA) - within employer-based retirement plans administered by Fidelity Investments.

Business Wire
Jan 25th, 2024
Fidelity’S® Guaranteed Income Direct Solution Available Nationally, Enabling Employees To Convert Retirement Savings Into Lifetime Income

BOSTON--(BUSINESS WIRE)--Fidelity Investments®, the nation’s retirement leader1, announces the broad availability of Guaranteed Income Direct, a new solution allowing employees to convert all or a portion of their retirement savings – from a 401(k), 403(b) or 457(b) – into an immediate income annuity to provide consistent, pension-like payments2 throughout retirement. Retirement preparedness is a source of financial stress for employees: 79% are worried they won’t have enough money to last their lifetime3, and 85% feel employers should take more responsibility in helping them prepare for retirement4. As such, guaranteed income solutions within workplace retirement plans have become increasingly popular. Fidelity research shows the number of retirees and pre-retirees deciding to stay in plan past their retirement date has continually increased over the past 10 years5, with 65% of participants expressing interest in having guaranteed income options in their workplace plans.6 For employers, the feelings are mutual: 81% of plan sponsors7 would prefer to give retirees the flexibility to stay in plan and withdraw assets throughout their retirement years. “A key challenge for employees as they transition from saving for retirement to living in retirement is ensuring there’s enough predictable income to cover essential expenses,” says Keri Dogan, senior vice president, Financial Wellness and Retirement Income Solutions at Fidelity. “Many people feel anxious about how to generate income in retirement and want to reduce the risk of outliving their assets

PR Newswire
Dec 12th, 2023
Touchstone Investments Launches Dynamic International Etf To Expand Global Exposure

The Touchstone Dynamic International ETF is Sub-advised by Los Angeles Capital ManagementCINCINNATI, Dec. 12, 2023 /PRNewswire/ -- Touchstone Investments, known for its Distinctively Active® mutual funds and exchange traded funds (ETFs), today announced the launch of the Touchstone Dynamic International ETF (TDI: NASDAQ), an actively-managed, fully-transparent ETF that seeks to invest in equity securities of non-U.S. companies domiciled in both developed and emerging markets, which began trading on December 11, 2023.In seeking to achieve its investment objective of capital appreciation, The Touchstone Dynamic International ETF is designed to offer investors a comprehensive framework of investments with broad international exposure. The strategy follows Los Angeles Capital Management's Dynamic Alpha Stock Selection Model®, an adaptive quantitative investment process that considers evolving market conditions and manages investment risk and alpha uncertainty, and weighs factors based on forward-looking expectations.Touchstone Investments launches dynamic international ETF to expand global exposure. Post thisTouchstone Investments' commitment to being Distinctively Active means executing a fully integrated and rigorous process for identifying and collaborating with best-in-class asset managers to sub-advise its funds. Like Touchstone's existing suite of ETF offerings, the Touchstone Dynamic International ETF offers potential for a more tax-efficient, cost competitive and transparent way to access Touchstone's investment strategies with no investment minimum."We are pleased to launch the Touchstone Dynamic International ETF in partnership with Los Angeles Capital Management given the team's unique investment process, designed to build equity portfolios that adapt to dynamic market conditions," said Blake Moore, president and chief executive officer of Touchstone Investments

INACTIVE