We Hire America Jobs

Mobile We Hire America Logo
WeHireAmerica.jobs is a service of HR Policy Foundation and DirectEmployers Association. These two non-profit organizations are providing this free resource to help educators, policy makers and job seekers understand the great employment opportunities available here in the U.S. at some of America's biggest and best companies.

Job Information

USAA Information Security Analyst Senior- Cybersecurity/Model Risk in Phoenix, Arizona

Why USAA?

At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.

Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.

The Opportunity

The Cyber Threat Enterprise Capabilities (CTEC) Team is seeking a dedicated Information Security Analyst Senior- Cybersecurity/Model Risk that will work in a team responsible for front-line management of model risk in the cybersecurity domain. This role involves collaborating across the 3 Lines of Defense (Specifically: Cyber Threat Operations Center, Information Technology, Compliance, Risk and Audit), relationship-building, technical analysis, solutioning and technical writing which needs an individual with demonstrable skills and experience in cybersecurity with a focus on model risk management. The position provides centralized model life-cycle management for all Cyber Threat Operations Center (CTOC) technology solutions that contain custom and vendor models. The position will define data science life-cycle management requirements; conduct rapid and through research of custom and vendor solutions; develop and/or analyze model features; lead development and integration, testing and validation of models; designing and operating model risk performance and reporting tools; operational and model risk compliance technical writing; vendor and partner communications.

This position can work remotely in the continental U.S. with occasional business travel.

Investigates, analyzes, and responds to security anomalies and events (e.g. suspicious behavior, attacks, and security breaches) within USAA’s environments using a variety of cyber defense tools to detect and respond to threats. Conducts vulnerability, security configuration, and/or penetration testing assessments of systems and networks. Identifies cyber threats, analyzes operational impacts, and communicates to appropriate partners. Stays ahead of latest information security threats, exploits, trends, and intelligence.

What you'll do:

  • Leads peers and team members in the execution of the Information Security domain activities while anticipating efforts that will impact their team.

  • Researches and analyzes the latest information security vulnerabilities, threats, exploits, trends and intelligence. Shares intelligence with peer teams.

  • Conducts sophisticated vulnerability management, security configuration assessments, and/or penetration testing operations and handles the resulting findings.

  • Develops analysts through training and knowledge sharing activities.

  • Monitors internal and external networks, systems, and applications for sophisticated security anomalies and events (e.g. suspicious behavior, attacks, and security breaches). Trains analysts in incident detection and response.

  • Responds to cyber incidents, performing detailed analysis using complex security tools to determine root cause and impact by using a broad range of demonstrated experience (e.g. forensics, networking, servers, coding, etc.) to determine a malicious actor's tactics, techniques, and procedures. Trains new analysts in incident detection and response.

  • Uses discoveries from the incident response process to make significant and/or complex improvements to the existing detection capabilities, operational processes and security controls.

  • Prepares and delivers written and/or verbal briefs with recommendations to senior leadership on latest threats, alerts, incidents, and improvements.

  • Provides insight on issues and serves as a mentor and coach to peers and team members for assigned area of responsibility.

  • Ensures risks associated with business activities are effectively identified, measured, supervised, and controlled in accordance with risk and compliance policies and procedures.

What you have:

  • Bachelor’s degree; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.

  • 6 years of related experience in Information Security, Cybersecurity and/or Information Technology with a security focus to include accountability for complex tasks and/or projects.

  • 4 years of related experience in one of the following disciplines: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communications and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, Software Development Security.

  • Sophisticated level of business sense in the areas of business operations, risk management, industry practices and emerging trends.

  • Knowledge of attacker tools/tactics/procedures and applying them to access management, governance, threat hunting, investigations, and incident response.

  • Knowledge of defense-in-depth principles and security architecture.

What sets you apart:

  • Expert skill at producing high quality technical documentation following Enterprise Model Risk Management policy, standards, procedures, and templates.

  • Deep understanding of Cybersecurity, Risk and Model Risk Management and skills to translate cybersecurity technical language into model risk language is required.

  • Prepare and deliver written and/or verbal briefs with recommendations to senior leadership on latest threats, alerts, incidents, and improvements. Solid experience communicating complex quantitative/technical concepts and conclusions to leadership, risk, compliance, and auditors.

  • Subject matter depth and breadth on cybersecurity maturity, programs, processes, and spectrum of cybersecurity tooling.

  • Ability to craft and monitor controls using quantitative techniques.

  • Strong business context knowledge in operational and support functions of financial sector as well as associated modeling and analytics knowledge.

  • Business and industry foresight in modeling regulatory requirements, governance and operational application of techniques and approaches to satisfy complex requirements. In-depth knowledge of industry and government regulations affecting financial sector security practices, OCC Bulletin 2011-12 Model Risk Management, FFIEC IT handbooks and 3rd party (vendor) risk management.

  • Programming skills in R, Python, SAS, Java, C, SQL, and/or other comparable programming languages is desired

Compensation range: The salary range for this position is: $127,310 - $243,340.

Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position. The actual salary for this role may vary by location.

Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.

The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.

Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.

For more details on our outstanding benefits, visit our benefits page on USAAjobs.com.

Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting.

USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

If you are an existing USAA employee, please use the internal career site in OneSource to apply.

Please do not type your first and last name in all caps.

Find your purpose. Join our mission.

USAA is unlike any other financial services organization. The mission of the association is to facilitate the financial security of its members, associates and their families through provision of a full range of highly competitive financial products and services; in so doing, USAA seeks to be the provider of choice for the military community. We do this by upholding the highest standards and ensuring that our corporate business activities and individual employee conduct reflect good judgment and common sense, and are consistent with our core values of service, loyalty, honesty and integrity.

USAA attributes its long-standing success to its most valuable resource: our 35,000 employees. They are the heart and soul of our member-service culture. When you join us, you'll become part of a thriving community committed to going above for those who have gone beyond: the men and women of the U.S. military, their associates and their families. In order to play a role on our team, you don't have to be connected to the military yourself – you just need to share our passion for serving our more than 13 million members.

USAA is an EEO/AA Employer - applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, sexual orientation, gender identity or expression, pregnancy, protected veteran status or other status protected by law.

California applicants, please review our HR CCPA - Notice at Collection (https://statmcstg.usaa.com/mcontent/static_assets/Media/enterprise_hr_cpra_notice_at_collection.pdf) here.

USAA is an EEO/AA Employer - applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, sexual orientation, gender identity or expression, pregnancy, protected veteran status or other status protected by law.

DirectEmployers