JOB DESCRIPTION
Are you ready to make an impact at DTCC
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development At DTCC, we are at the forefront of innovation in the financial markets.We'recommitted to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
Pay and Benefits:
- Competitive compensation, including base pay and annual incentive.
- Comprehensive health and life insurance and well-being benefits, based on location.
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
The impact you will have in this role:
As a member of the Cyber Monitoring & Incident Response Team at DTCC, you directly contribute to the security and stability of the global financial system. The mission of the CMIRT is to protect the organization from external cyber threats and to respond to and manage cyber incidents. Through multiple teamslocatedin different geographic locations, the team performs round-the-clock monitoring and leadscyberincident response, digital forensics, and eDiscovery functions. As a criticalcomponentof the risk organization, the team's performance and initiatives are scrutinized directly by the Executive Committee, Board of Directors, andnumerousindustry regulators. As a result of our critical mission, our team mustmaintainthe highest standards of performance and ethical behavior.
Principles that apply to every member of the CMIRT:
- Have Integrity-Tell the truth, protect the secrets that we are trusted with, and honor yourcommitments.
- Be Present -Commit to the team by showing up on time and being prepared.
- Communicate -Communicate regularlyand be proactive.
- Take Ownership -Regardless of title or position, own the outcome of the mission.
- Always Be Learning -Cyber security is not static, and neither is the CMIRT.
- Make Honest Mistakes -Mistakes will be made. Own them and learn from them.
Your Primary Responsibilities:
Reporting to the CMIRT Regional Manager and working with technical leads and other associates, youare responsible fordetecting, investigating, and responding to cyber security events in the organization as well as handling technical projects. You are a member of the CyberMonitorIncident Response Team (CMIRT)andas a result may be tasked with responding to cyber incidents outside of normal work hours.
Expectations for the Senior Associate - Quality Assurance and Quality Control (QA/QC) Program:
- Execute quality assurance reviews of cyber security incidents, alerts, investigations, and response activities.
- Validate adherence to approved job aids, playbooks, governance standards, and documentation requirements.
- Perform targeted QA/QC deep dive reviews based on risk, severity, trends, or leadership direction.
- Identifyrecurring gaps, quality issues, and systemicweaknesses,document findings clearly.
- Track QA/QC findings, corrective actions, and remediation statusthrough toclosure.
- Prepare QA/QC reports and metrics for leadership, audit, and operational review.
- Partner withCyber Offensive, Defensive, Threat Huntteams to drive continuous improvement.
- Provide constructive feedback and guidance to analysts to improve investigation quality.
- Support audit, regulatory, and internal assurance requests by providing QA/QC evidence and summaries.
- Participate in training, exercises, and process improvement initiatives.
NOTE: The Primary Responsibilities of this role are not limited to the details above.
Qualifications:
- At least 2-3 years of experience in Cyber Security Operations, Incident Response, ora relatedsecurity role.
- Bachelor's degree in information security, Computer Science, or equivalent professional experience.
Talents Needed for Success:
- Strong knowledge of incident response processes,investigationworkflows, and security operations.
- Hands-onexperience with security tools such as SIEM, EDR, email security, and case management platforms.
- Strong understanding of quality assurance and concepts within technology and cyber security operations.
- Ability to analyze investigations and produce clear, concise written reports with actionable recommendations.
- Demonstrated ability to communicate complex technical findings to both technical andnon technicalstakeholders.
- Strong attention to detail and ability toidentifygaps, inconsistencies, and risk themes.
- Ability to manage multiple QA/QC reviews and priorities with minimal guidance.
- Strong senseof ownership and commitment to improving operational quality and maturity.
- Ability to work collaboratively in afast paced,high performingcyber security environment.
ABOUT THE TEAM
Our Risk Management teams work to protect the safety and soundness of our systems and are responsible for identifying, managing, measuring and mitigating a spectrum of key risk types including credit, market, liquidity, systemic, operational and technology in all existing and new products, activities, processes and systems.