Lead Cybersecurity Analyst

Visa Austin , TX 78719

Posted 3 months ago

As the world's leader in digital payments technology, Visa's mission is to connect the world through the most creative, reliable and secure payment network - enabling individuals, businesses, and economies to thrive. Our advanced global processing network, VisaNet, provides secure and reliable payments around the world, and is capable of handling more than 65,000 transaction messages a second. The company's dedication to innovation drives the rapid growth of connected commerce on any device, and fuels the dream of a cashless future for everyone, everywhere. As the world moves from analog to digital, Visa is applying our brand, products, people, network and scale to reshape the future of commerce.

At Visa, your individuality fits right in. Working here gives you an opportunity to impact the world, invest in your career growth, and be part of an inclusive and diverse workplace. We are a global team of disruptors, trailblazers, innovators and risk-takers who are helping drive economic growth in even the most remote parts of the world, creatively moving the industry forward, and doing meaningful work that brings financial literacy and digital commerce to millions of unbanked and underserved consumers.

You're an Individual. We're the team for you. Together, let's transform the way the world pays.

The Lead Cybersecurity Analyst will work as a member of Visa's Ethical Hacking (Penetration testing) program in Global Information Security. The objective of Visa's Penetration Testing program is to pro-actively identify weaknesses and shortcomings in Visa's security posture and recommend necessary controls and procedures to protect Visa adversarial threats. With this mission in mind, Visa's penetration test team experts are pro-actively involved in engagements that simulate adversarial threats and attacks in a timely manner.

The Lead Cybersecurity Analyst will be a key contributor for performing internal and external ethical hacks of Visa applications and systems. Pentest team members also help with design, development and recommendation of security solutions to protect Visa proprietary/confidential data and systems. The candidate will also assist with compliance objectives; provide guidance and direction for the logical protection of information systems assets to other functional units. Prepare reports regarding effectiveness of information security adherence and make recommendations for the adoption of new policies and procedures for Visa services.

Basic Qualifications

  • 10 years of work experience with a Bachelor's Degree or at least 8 years of work experience with an Advanced Degree (e.g. Masters/MBA/JD/MD) or at least 3 years of work experience with a PhD

Preferred Qualifications

  • 12-15 years of work experience with a Bachelor's Degree or 8-10 years of experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) or 6+ years of work experience with a PhD

  • Bachelor's Degree (or equivalent) in Computer Science, Information Security or a related field

  • At least 8-10 years of progressive experience with increasing responsibility in Information Technology, Information Security and Compliance that includes a combination of technical and project leadership responsibilities

  • Prior experience or expertise performing application and infrastructure penetration tests

  • Experience in writing proof-of-concept exploits

  • Well versed in system exploits (e.g. Buffer Overflows, PTH attacks, windows authentication framework etc.), network exploitation (e.g. VLAN hopping) or web application exploitation

  • Well versed with security tools & frameworks like Burp Suite Professional, Metasploit, Nmap, Nessus, AppScan, WebInspect, etc.

  • Extensive understanding of cryptographic concepts and applied cryptography

  • Proficiency in one or more scripting language. E.g. Perl, Python, Shell Scripting etc.

  • Good interpersonal, facilitation, and demonstrated emerging leadership skills

  • Able to operate at an advanced level of written and spoken communication; write and speak effectively with impact

  • Good understanding of Ethernet, switched LAN and WAN environment and detailed understanding of layer 3 and layer 4 specifications, including IP, TCP, TCP/IP routing protocols and management of ACLs.

  • Knowledge of logical / physical access control methods, connections alternatives using private, public and wireless solutions, Network/Host Intrusion Detection Engines, Vulnerability Management Tools, Patch Management Tools, Penetration Testing Tools, Anti-Virus/Anti-Spyware solutions

  • Conducts complex analytical functions by performing security assessments and ethical hacks of high risk sensitive applications

Essential Functions

  • Conduct high risk and sensitive ethical hacks of internally and externally hosted applications globally according to scope defined by the penetration test team.

  • Subject matter expertise in web, mobile or network penetration testing with track record of end to end testing of complex systems.

  • Co-ordinate and execute system/network level penetration tests and ethical hacking exercises.

  • Pro-actively research and Identify network and system vulnerabilities and provide recommended counter measures or mitigating controls to reduce risk to an acceptable and manageable level.

  • Reviews results of network and application ethical hacks in order to determine severity of findings and to ensure proper remediation is applied.

  • Provide accurate and timely reporting of findings and proposed remediation and mitigations.

  • Technical support could include but not limited to the following: (1) Audit support & remediation, (2) Process Improvement, (3) Analysis & Reporting, (4) Cross Divisional Functional education, training and awareness, (5) Function/Methodology/Strategy advancement.

  • Provide technical support to senior management in identifying and streamlining new/existing protocols and tools used by the penetration testing team.

  • Develop and automate scripts, tools and resources needed to advance ethical hacking capabilities around new and emerging technologies like mobile, cloud and embedded systems.

  • Actively involved in security research around new and emerging technologies.

Work Hours

Incumbent must make themselves available during core business hours.

Travel Requirements

This position requires the incumbent to travel for work 0-10% of the time

Physical Requirements

This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers, reach with hands and arms, and bend or lift up to 25 pounds.

Visa will consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law.

icon no score

See how you match
to the job

Find your dream job anywhere
with the LiveCareer app.
Mobile App Icon
Download the
LiveCareer app and find
your dream job anywhere
App Store Icon Google Play Icon

Boost your job search productivity with our
free Chrome Extension!

lc_apply_tool GET EXTENSION

Similar Jobs

Want to see jobs matched to your resume? Upload One Now! Remove
Cybersecurity Threat Intelligence Analyst

HP Inc

Posted 4 days ago

VIEW JOBS 10/14/2019 12:00:00 AM 2020-01-12T00:00 Job Description The Cybersecurity Threat Intelligence Analyst is charged with advancing our knowledge of adversary intent, opportunity, and capability to cause harm to HP's global business. They are responsible for the collection, analysis, and dissemination of Cyber Threat Intel, enabling both internal Cybersecurity teams to focus prevention and detection efforts as well as enabling the business to better make informed, risk-based decisions. Responsibilities: * Develop and refine cyber threat intelligence collection and analysis processes * Collect and process both technical and non-technical, internal and external, threat intelligence * Produce detailed intelligence analysis reports on cyber threats with a potential to impact HP * Present relevant findings to both technical and non-technical audiences * Develop executive briefings * Issue advisories on critical threats and vulnerabilities * Identifies gaps in both processes and technology, develop capabilities to enhance existing cyber threat intelligence functions * Support detection and response teams with context and analysis support, provide industry expertise and recommend relevant remediation and countermeasures * Develop in-house tools to assist with collection and analysis of intelligence information Knowledge and Skills Required: * Extensive knowledge of standards of intelligence collection and analysis tradecraft. * Experience tracking and reporting on cyber espionage, cyber crime, and other malicious cyber actors. * Extensive knowledge of standard signature and information sharing data formats and exchange protocols - e.g., Yara, STIX/TAXII, etc. * Understanding of common operating systems and IT Infrastructure such as Windows, Unix/Linux, Active Directory, firewalls, proxies, etc. * Familiarity with automation concepts and proficiency in scripting languages such as Python, Perl, Ruby, JavaScript, Powershell, etc. * Strong analytical skills and critical thinking skills * Effective communication skills (both written and verbal) * Strong organization, prioritization, and rationalization skills. * Knowledge of public cloud services a strong plus Education and Experience Required: * Bachelor's Degree or higher in the field of Computer Science or Information Security or related field (may be substituted for experience and industry certifications) * 5 or more years experience in one or more of the following cybersecurity functions: * Cyber Threat Intelligence * Intrusion Detection/Prevention Monitoring * Incident Response * Forensics * Vulnerability Management * Individual technical Cyber Security Certification through one of the recognized bodies preferred: SANS, ISACA, (ICS)2, GIAC, CompTIA, etc. #Li-post HP Inc Austin TX

Lead Cybersecurity Analyst