Founded in 1966, Mastercard is a worldwide transaction, payment-processing, and consulting company best known for its line of personal and business credit cards. As an employer, Ma
Security Response Analyst II (Insider Threat)
Location
Australia
Posted
45 days ago
Salary
0
Seniority
Mid Level
Job Description
Security Response Analyst II (Insider Threat)
Mastercard
Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Security Response Analyst II (Insider Threat) Mission First, People Always As Corporate Security, we are responsible for keeping Mastercard safe and secure from cyber and physical threats, and it is our people on the front who make this happen every day. By taking care of our people, their well-being, and their career development, we provide them with the necessary tools and environment to ensure the success of our mission. Overview The Security Event Management group is looking for a highly motivated team member to join our technical security investigative team as an Insider Threat Security Monitoring and Response Analyst II. As an Insider Threat analyst, you will work with a global team of like-minded specialists to flex your cybersecurity skills and talents to protect Mastercard's data, networks, and systems from potential insider threats. As an Insider Threat analyst on our team, you will be involved in analysing anomalous behaviour to identify suspected Insider Threats detected by our cyber security tools, such as Data Loss Prevention (DLP), User Activity Monitoring (UAM) and User Behaviour Analytics (UBA). Your day-to-day role will include triaging of alerts and incident escalations from the Security Operations Centre (SOC), conducting in-depth log analysis, generating incident reports, and documenting incidents in our case management system. You will also play a key role in maintaining and enhancing Corporate Security and Insider Threat security policies and work with key stakeholders to balance security initiatives with business, privacy and legal requirements. Additionally, you will support other members of the team and work with the team to enhance Insider Threat processes, documentation, and capability, and develop new ways of protecting the organisation against changing Insider Threat 'Tactics, Techniques, and Procedures' (TTPs). In this role, you will be: • Responding to Insider Threat incidents and alerts by analysing security event logs and user activities, providing findings to stakeholders for escalation, and documenting incident activities in the case management system.• Utilising our monitoring tools to gather data to identify insider threat trends and anomalies and using these findings to enhance our insider threat capability.• Creating and implementing countermeasures to specific weaknesses against known insider threat tactics, techniques, and procedures (TTPs)• Assisting with reviewing Data Loss Prevention (DLP) controls and assisting internal users impacted by our tools.• Establishing and maintaining Chain of Custody for any electronic data and evidence handled by the Insider Threat team.• Documenting and improving existing processes, aligning to industry standards and frameworks where appropriate (ISO, NIST, MITRE etc).• Reporting and providing metrics to leadership on key performance indicators as needed.• Interfacing with key internal stakeholders from other areas of the business such as HR, legal, and privacy teams to ensure customer needs are documented and met.• Working with other investigative teams, such as the SOC, to resolve high priority incidents.• Conducting risk assessments on insider threat security gaps and present findings to senior management and key stakeholders.• Collaborating with engineering teams to deliver capability improvements to Insider Threat tool set. All About You The ideal candidate for this position should: • Experience with investigative or technical report writing.• Familiarity with Security event log analysis and data analytics tools used for Insider Threat such as User Activity Monitoring (UAM) and User Behaviour Analytics (UBA).• Familiarity with Microsoft products such as O365 Purview, Microsoft Defender, Sentinel or DLP for Endpoint.• Experience with Data Loss Prevention (DLP) tools.• Experience in Incident Response and Digital Forensics.• Strong understanding of OSI Model, TCP/IP, MITRE ATT&CK, Kill Chain, Vulnerability Management and Networking principles. • Familiarity with the key high-level differences between Mac and Windows operating systems.• Experience with Security Incident and Event Management (SIEM) tools such as Splunk, ArcSight, Rapid7 InsightIDR etc.• Understanding of web proxies and ability to analyse web proxy logs.• Familiarity with OSINT techniques and threat hunting methodologies.• Excellent written and verbal communication skills to be able to communicate effectively to a wide variety of stakeholders. • Relevant industry certifications such as Security+, GCIA, GCIH, or CISSP are a plus. • Familiarity or training with local privacy laws (GDPR) is beneficial. Corporate Security Responsibility All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: - Abide by Mastercard's security policies and practices; - Ensure the confidentiality and integrity of the information being accessed; - Report any suspected information security violation or breach, and - Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Benefits
- 401(K), 401(K) matching, Adoption Assistance, Childcare benefits, Commuter benefits, Company equity, Company-sponsored outings, Company sponsored family events, Customized development tracks, Dedicated diversity and inclusion staff, Dental insurance, Disability insurance, Documented equal pay policy, Volunteer in local community, Employee stock purchase plan, Family medical leave, Fitness stipend, Flexible Spending Account (FSA), Flexible work schedule, Generous parental leave, Generous PTO, Company-sponsored happy hours, Health insurance, Job training & conferences, Life insurance, Charitable contribution matching, Mentorship program, Paid volunteer time, Online course subscriptions available, Onsite gym, Open office floor plan, Paid holidays, Paid industry certifications, Paid sick days, Onsite office parking, Partners with nonprofits, Performance bonus, Pet insurance, Promote from within, Recreational clubs, Lunch and learns, Relocation assistance, Free snacks and drinks, Team based strategic planning, Team workouts, Tuition reimbursement, Vision insurance, Wellness programs, Some meals provided, Mental health benefits, Diversity employee resource groups, Fertility benefits, Employee resource groups, Employee-led culture committees, Hybrid work model, In-person all-hands meetings, Employee awards, Pay transparency, Transgender health care benefits, Wellness days, Abortion travel benefits, Meditation space, Mother's room, Personal development training, Virtual coaching services, Apprenticeship programs, Flexible time off, Floating holidays, Bereavement leave benefits
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Tier 1 SOC Analyst
LeidosLeidos is an innovation company rapidly addressing the world’s most vexing challenges in national security and health.
• Monitor network traffic for unusual activity and respond to threats or escalate to Tier 2. • Maintain awareness of ongoing cyber threats over time. • Constantly monitor systems and networks for signs of intrusion, malware, or other security risks. • Document incidents, threats, and false positives in detail. • Update and maintain documentation on current vulnerabilities, and escalate to primary shareholders for critical vulnerabilities. • Relay information about current threats and incidents to team members and stakeholders. • Continuously share knowledge and contribute to improvement of SOC tools and processes. • Stay updated with the latest cybersecurity threats and defense strategies through continuous learning and training.
Senior Manager, Security Operations
SemrushYour competitors' favorite marketing platform used by 10,000,000 marketers
• Own and continuously improve the Security Incident Response process end-to-end. • Act as Incident Commander for high-severity security incidents. • Serve as Security Lead in cross-functional incidents with a security impact. • Ensure clear coordination, communication, and stakeholder alignment during incidents. • Own post-incident reviews, including root cause analysis, action item definition, and tracking to completion. • Maintain and evolve incident documentation standards, runbooks governance, and response playbooks oversight. • Ensure appropriate escalation handling for high-severity incidents outside business hours on a best-effort basis. • Own the Security Monitoring process, ensuring alert quality, signal-to-noise balance, and operational efficiency. • Oversee Detection Engineering as a managed process, including prioritization, quality control, and alignment with threat landscape. • Ensure effective integration of Threat Intelligence into detection and response workflows. • Own Log Management from an operational perspective, including logging requirements, coverage, ingestion health, and data quality oversight. • Coordinate response to logging-related incidents affecting monitoring capabilities. • Own the SOC operational metrics framework, be accountable for key performance indicators including: Alert response times (MTTA), Mean Time to Contain and incident lifecycle efficiency, Incident SLO adherence, Alert quality and false positive reduction, Monitoring coverage and logging health indicators. • Drive metric-based prioritization and improvements across SOC processes. • Provide structured reporting to leadership on SOC performance and risks. • Lead a lean SOC team composed of Analysts and a Security Data Engineer. • Conduct performance reviews and regular one-to-ones. • Own individual development plans and learning roadmaps for team members. • Manage hiring, onboarding, staffing, and workload planning. • Ensure sustainable coverage model and operational resilience. • Conduct tabletop exercises and ensure team readiness for high-severity events. • Own the SOC operational roadmap and backlog. • Prioritize initiatives based on risk, impact, and available resources. • Manage operational trade-offs in a resource-constrained environment. • Collaborate with internal stakeholders across Engineering, Product, and Corporate functions. • Participate in vendor relationship oversight within the SOC technology stack. • Support external audits such as SOC 2 and PCI DSS from an operational perspective, including process explanation and evidence coordination.
Engineer - Aircraft Cybersecurity Operations (Remote)
United AirlinesUnited Airlines is a publicly-traded, global airline operating over 4,500 flights every day to more than 335 airports on five continents. In the past, the company has supported fle
Achieving our goals starts with supporting yours. Grow your career, access top-tier health and wellness benefits, build lasting connections with your team and our customers, and travel the world using our extensive route network. Come join us to create what’s next. Let’s define tomorrow, together. Description Connecting People. Uniting the World. There’s never been a more exciting time to join United Airlines! As a global company that operates in hundreds of locations around the world — with millions of customers and tens of thousands of employees — we have a unique responsibility to uplift and provide opportunities in the places where we work, live and fly. We’re on a path to becoming the best airline in aviation history. Join our Cybersecurity and Digital Risk (CDR) team to help lead the industry in cyber safety, security and resilience. United's CDR team plays a critical role in protecting our operations by enabling secure and resilient systems, managing threats and vulnerabilities, and ensuring swift response and recovery. Our mission is to seamlessly embed cybersecurity and digital risk management into every aspect of our business. We help drive progress and growth through trusted digital solutions, safeguarding assets and empowering our team, all while promoting a cyber-safe and secure environment that supports resilient airline operations. United offers a competitive benefits package aimed at keeping you happy, healthy, and well-traveled. From employee-run "Business Resource Group" communities to world-class benefits like parental leave, 401(k), and privileges like space-available travel, United is truly a one-of-a-kind place to work. Are you ready to travel the world and help us keep our airline cyber safe? Apply today! Job overview and responsibilities Engineer – Aircraft Cybersecurity Operations is responsible for supporting internal and external partners - such as Avionics Engineering, Powerplant Engineering, Government Affairs, Corporate Security, Corporate Safety, Industry working groups, OEMs, and FAA - to help drive United’s aircraft cybersecurity operations to be consistent with the latest developments in aviation cyber security. This individual will support identifying the aviation cyber risk landscape and will support performing cybersecurity threat analysis and assessment actions, perform security tests, and validate security mitigations that should be executed to ensure a safe and secure continued airworthiness for all United aircraft. This individual will also be responsible for drafting regulatory responses to meet continued airworthiness. - Support cybersecurity threat assessments and mitigation strategy solutioning - Support the development of aviation cybersecurity risk-related papers, reports, alerts, and bulletins - Support the development of AISP/ANSP responses in support of regulatory cybersecurity implications to the aircraft - Coordinate with internal and external partners to help operationalize cybersecurity improvements to aircraft and airport operations - Continue to gain knowledge and understanding of industry standards and regulatory best practices related to aircraft cybersecurity Qualifications What’s needed to succeed (Minimum Qualifications): - Bachelor's degree required, STEM field preferred - 2 or more years of combined related experience in either aircraft engineering, aircraft cybersecurity, embedded product security, or other similar related fields - Basic understanding of airport operations - Basic understanding of aircraft avionics, cabin, and propulsion systems - Basic knowledge of risk assessments - Basic understanding of cryptography concepts - Basic understanding of network exploitation, attack strategies and methods, current IT security technology, software, and cyber threat mitigation tools - Working knowledge of computer operating systems, network design, embedded security, and security architecture principles - Ability to work independently and self-motivate - Excellent problem solving, critical thinking, interpersonal, collaboration, written and verbal communication skills - Must be legally authorized to work in the United States for any employer without sponsorship - Successful completion of interview required to meet job qualification - Reliable, punctual attendance is an essential function of the position What will help you propel from the pack (Preferred Qualifications): - Aviation experience - Working knowledge navigating hardware-based security techniques and assessments - Working knowledge of programming languages - Basic understanding of digital design and understanding of hardware at the component level - Basic understanding of security risk methodologies consistent with the aviation industry - Basic understanding of aviation security regulations and standards The base pay range for this role is $94,145.00 to $122,550.00. The base salary range/hourly rate listed is dependent on job-related, factors such as experience, education, and skills. This position is also eligible for bonus and/or long-term incentive compensation awards. You may be eligible for the following competitive benefits: medical, dental, vision, life, accident & disability, parental leave, employee assistance program, commuter, paid holidays, paid time off, 401(k) and flight privileges. United Airlines is an Equal Opportunity Employer. We recruit, employ, train, compensate, and promote without regard to race, color, religion, national origin, gender identity, sexual orientation, disability, age, veteran status, or any other protected category under applicable law. We provide reasonable accommodations for applicants and employees with disabilities. To request an accommodation, contact JobAccommodations@united.com
Senior Director, Product Marketing – SecOps
ZscalerWe make it easy to secure your cloud transformation. Get fast, secure, and direct access to apps without appliances.
• Develop product positioning and messaging that clearly differentiates Zscaler’s Data Security solutions in a highly competitive market. • Collaborate cross-functionally with Product Management, Sales, Enablement, and Demand Gen teams to lead high-impact product launches. • Create impactful content for a variety of formats and audiences—from technical buyers to business leaders—to support awareness, demand, and enablement. • Communicate the core value proposition of our solutions to the sales organization and develop tactical tools that accelerate the end-to-end selling process. • Monitor enterprise AI trends and data security challenges to ensure our go-to-market strategy aligns with evolving customer needs.




