Listing translated from German by Talent Club.
As one of the largest banking IT service providers and digitalization partners in Europe, we are the driver of digitalization within the Sparkassen-Finanzgruppe. With over 5,000 employees at 3 locations, we make today's digital banking powerful and develop smart financial services for tomorrow. We offer a broad range of tasks in which individual strengths can be excellently applied. Whether app development, network technologies and server operations or consulting, training and support – with us, everyone finds their calling! As a specialist or as a generalist. All with the best career opportunities, plenty of room for personal development and numerous benefits.
For the Security Response organizational unit, we are looking for the earliest possible date for the location Hanover or Münster a
Cyber Threat Intelligence & Threat Hunting Analyst (m/f/d)
The Cyber Defence Center bundles competencies, processes and methods of operational IT security. For the IT landscape of Finanz Informatik, we coordinate measures in the team to detect and defend against threats at an early stage.
As the central reporting office for IT security incidents, we react within the framework of the Security-Incident-Response process and communicate necessary action measures to customers.
Our well-founded reports and situation pictures create the basis for a high level of security and stability of the IT systems throughout the entire Sparkassen-Finanzgruppe network.
Tasks:
- Responsibility for collection, validation, enrichment and assessment of tactical, operational and strategic threat data from various sources (OSINT, commercial feeds, ISACs, darknet sources, internal telemetry and log systems)
- Proactive creation of target group-oriented reports and briefings (technical to management-suitable)
- Setup, configuration and continuous optimization of Threat Intelligence Platforms (TIPs), SIEM integrations and internal knowledge bases
- Independent conception, planning and execution of hypothesis-based Threat Hunting missions
- Documentation of findings, preparation and derivation of countermeasures as well as passing on to the relevant stakeholders
- Exchange with external partners and participation in information-sharing initiatives
- Support with audits and regulatory reviews as well as implementation of compliance requirements in processes and technologies
Profile:
- Successfully completed subject-related degree or comparable training and at least 6 years of subject-related professional experience
- Very good practical knowledge of frameworks such as MITRE ATT&CK or NIST as well as network and client forensics, SIEM/EDR solutions and Threat Intelligence Platforms
- In-depth experience in the use of common scripting languages (Python, Bash, PowerShell) as well as data processing/management and automation
- Basic knowledge of relevant regulatory frameworks (including DORA, ISO27001, NIS2, BSI-KritisV)
- Pronounced ability for analytical thinking, target group-oriented communication and a strong team spirit
- High sense of responsibility and commitment to independent learning, working and further development
- Very good German and English skills in spoken and written form
Sounds interesting?
We look forward to all applications, regardless of gender, age, disability, religion, ethnic origin or sexual identity, stating the reference number 612/B.