- Company Name
- First Horizon Bank
- Job Title
- Information Security Engineer
- Job Description
-
Job title: Information Security Engineer
Role Summary:
Mid-level Cyber Security Engineer responsible for second‑level SOC alert analysis, incident containment, threat intelligence collection and dissemination, configuration and file integrity management, and support of enterprise security governance across cloud and on‑prem environments.
Expectations:
- Deliver and maintain a comprehensive threat management strategy, ensuring integration with security tools (IPS, EDR, TIP).
- Support CIRT operations, provide tier II incident response, and recommend preventive and corrective actions.
- Utilize MITRE ATT&CK framework for threat mapping and alert development.
Key Responsibilities:
- Respond to SOC alerts, perform triage, analysis, and containment of security events.
- Provide tier II support for escalated incidents and collaborate with CIRT.
- Operate configuration management program to track and remediate drift; collaborate with asset custodians.
- Operate File Integrity Management program to detect critical system file changes.
- Collect, analyze, and produce threat intelligence reports; integrate findings into the global threat platform or SIEM.
- Design, test, and develop custom content and alerts targeting critical assets.
- Document incident response playbooks for new threat content.
- Share cyber intelligence with partners, vendors, and law enforcement as required.
- Generate weekly and monthly operational metrics.
- Work with vendors and internal customers to respond to escalations and recommend security actions.
- Maintain current knowledge of attack vectors, emerging threats, and compliance requirements.
Required Skills:
- Proficiency in SOC alert triage, incident analysis, and containment.
- Experience with configuration scanning tools and file integrity monitoring (e.g., Tripwire).
- Knowledge of cloud security and incident response in Azure.
- Familiarity with compliance regulations: SOX, PCI‑DSS, GLBA, and related banking regulations.
- Ability to map threats and vulnerabilities to the MITRE ATT&CK framework.
- Strong teamwork, communication, and professional integrity.
- Excellent analytical, problem‑solving, and documentation skills.
Required Education & Certifications:
- High School diploma or equivalent (required).
- Bachelor’s degree in Computer Engineering, Computer Science, or related field preferred.
- 3+ years of experience in cyber threat or information security.
- Security certifications such as CISSP, GSEC, GCIH, CEH are preferred but not mandatory.
Charlotte metro, United states
On site
Junior
05-11-2025