Role Description:
At FNZ, our purpose is to make wealth management more accessible, bringing easier, fairer and more inclusive solutions to people worldwide. Here in the Global Information Security team, we work to protect the platforms that support investment solutions for over 20 million people.
We are looking for a Security Operations Lead Analyst to join the Security Operations team. You will have knowledge of Information Technology concepts and have 3+ years experience in Security Operations in a commercial environment. You will be excited to develop your knowledge and abilities in a global, complex organisation. You will be able to learn quickly and must be able to show how you develop yourself and your career. You will be joining an experienced team and working to support some of the biggest financial services clients in the world.
Reporting directly to the Head of Cyber Fusion Centre, you will lead a team of analysts responsible for monitoring and responding to security incidents, implementing proactive measures, and ensuring the overall safety and integrity of our systems, networks, and data.
Team Responsibilities:
The team are responsible for:
Providing high quality and timely response to alerting.
Shift work covering 24/5 plus on-call weekend work
Incident resolution and triage – resolve incidents as per agreed procedures and escalate internally to relevant teams to resolve any incidents outwith our remit.
Stakeholder Communication – Triage incidents and manage stakeholder expectations for incident resolution.
Post Incident reviews – evaluate the incident management response and recovery effort for major, critical and high priority incidents to provide continual improvement of our incident responses.
Specific Role Responsibilities
Responsible for the regional Incident response team.
Building the team
Fostering a great culture
Supporting and growing the team members in their career
Managing team rotas and absence
Knowledge sharing and mentoring
Incident Management: Lead and supervise a team of security analysts to promptly detect, investigate, and respond to security incidents. Ensure the appropriate escalation procedures are followed when necessary and coordinate incident resolution efforts effectively.
Lead incident escalation and communication for internal and external stakeholders.
Use application management software and tools to collect agreed performance statistics.
Security Operations Center (SOC) Management: Manage day-to-day SOC operations, ensuring that monitoring activities are performed round-the-clock, and shift schedules are organized efficiently.
Security Incident Response: Develop and maintain an incident response plan, conduct periodic exercises to test the response readiness of the team, and continually enhance the incident response process.
Team Training and Development: Provide mentorship and training to security analysts, ensuring they are equipped with the necessary skills and knowledge to excel in their roles.
Security Incident Remediation: Coordinate with IT and infrastructure teams to implement necessary remediation actions following security incidents, including applying patches, updating configurations, or deploying new security measures.
Triage of alerts from FNZ Group systems
Lead post Incident reviews, helping to provide a continually improved service for our customers and stakeholders.
Define Standard Operating Procedures and playbooks to respond to incidents
Supporting development and enhancement of SIEM detection and playbooks
Experience required:
Primary requirements
Bachelor’s Degree or higher in Computer Science, Mathematics, Engineering, Physics or other Sciences or equivalent working experience. Degree preferable in either Commerce or IT; (A-B + average) or equivalent;
Intermediate SQL skills;
Interest / familiarity with financial markets and products beneficial but not essential;
Excellent spoken and written English
Experience of Incident Response (triage, classification, investigation, escalation)
Knowledge of networking protocols and investigation (capture, Wireshark)
Knowledge of Operating Systems, Databases and Applications (Windows, Linux, SQL, F5)
Knowledge of SIEM tools (Splunk, Sentinel)
Knowledge of EDR tools (Defender, Crowdstrike)
Knowledge of security concepts (MITRE, Kill-Chain)
Willing to work in shift patterns
Nice to have:
Written/spoken German
#LI-CM1
About FNZ
FNZ is committed to opening up wealth so that everyone, everywhere can invest in their future on their terms. We know the foundation to do that already exists in the wealth management industry, but complexity holds firms back.
We created wealth’s growth platform to help. We provide a global, end-to-end wealth management platform that integrates modern technology with business and investment operations. All in a regulated financial institution.
We partner with over 650 financial institutions and 12,000 wealth managers, with US$1.5 trillion in assets under administration (AUA).
Together with our customers, we help over 20 million people from all wealth segments to invest in their future.