Principal Cyber Incident Coordinator
The Principal Cyber Incident Coordinator acts as the dedicated cyber interface to both internal and external teams. The Principal Cyber Incident Coordinator is responsible for timely execution of all tasks within the incident response plan.
The Principal Cyber Incident Coordinator role functions as both a team leader and an individual contributor of a small group, responsible for coordinating proactive and reactive incident response activities, periodically communicating with relevant stakeholders to facilitate readiness and a continually improving incident response capability.
Job Responsibilities:
Cyber Incident Coordination
- Facilitates and coordinates the cybersecurity response across people, processes, and technology to reduce the impact of and the recovery time for cyber incidents.
- Delivers key takeaways and insights for executive consumption on impact and improvements as a retrospective after an incident.
- Assists Cyber Defense Operations teams in determining if an event needs to be declared as a major security incident, according to defined criteria that is in line with Comerica's compliance responsibilities.
- Leads the integration of cyber incident response activities with the broader organization's incident response processes to ensure cyber risk preparedness and consistency / alignment with the enterprise.
- Oversees incident response activities and keep management informed of the status of incidents through accurate, timely, and appropriate reporting.
- Serves as the interface and main point-of-contact between the cybersecurity teams and relevant business stakeholders to ensure proper incident handling.
- Interfaces with legal teams on applicability of legislation / regulation for threat scenarios and ensure that the response process adheres to legal requirements for Comerica.
Communication and Administration
- Responsible for the maintenance and enhancement of incident response plans, relevant playbooks, and knowledge base to increase efficiencies and control organizational risk.
- Engages and leads process improvement projects across Cyber Defense, enhancing cross-team workflows to drive collaboration between teams to resolve Cyber Incidents.
- Drives partnership with internal compliance organization to ensure alignment across regulatory frameworks.
- Plans, participates, and oversees tabletop exercises and incident simulations to ensure operational readiness and the updates necessary to support coordinated response.
- Continually improves the Cyber Incident Response function through post incident retrospectives (AARs) and soliciting feedback from partners within the cybersecurity organization, as well as engineering and partner teams across Comerica.
- Other duties as assigned.
Job Qualifications:
- Bachelor's Degree from an accredited university in Computer Science, Engineering, Information Systems, Cybersecurity, or Business Administration or other relevant degree -- OR - High School/GED with 12 years progressive relevant experience
- 6 years of experience in cybersecurity incident management and/or/response experience
- 5 years of experience as a member of a response team or with cyber task management (e.g. Security Operations Center, Forensics, Incident Management and/or Response (Cyber or Technology), Business Continuity, Disaster Recovery, Cyber Risk Management, Cyber Maturity Projects)
- 5 years of experience with business teams to solicit requirements and ensure ongoing satisfaction with solutions that have been delivered
- 5 years of experience with knowledge of regulatory requirements and information security management frameworks, including ISO/IEC 27001, ITIL, SOX, PCI, NIST 800-61 (Incident Handling), NIST CSF
- 5 years of experience in all levels of the technology stack and security solution capabilities such as: firewalls, intrusion prevention & detection, perimeter appliances, filtering (virus, spam, etc.), network segmentation, authentication, enterprise portals, data encryption, enterprise directories (LDAP and Active Directory), endpoint security controls, application security and secure coding techniques
- 4 years of experience with the banking sector, its regulations, and incident reporting requirements
Licenses/Certifications:
- CISSP (Certified Information Systems Security Professional) preferred
- CISM (Certified Information Security Manager) preferred
- CRISC, CISA, CGIH preferred
Work Best Category: Category C - Days in the office will either be designated days or will vary week to week from 2-5 days
Hours: 8:00am - 5:00pm Monday - Friday
Salary: To Be Determined Based on Individual Experience
About Comerica We know our employees are critical to our overall success and we are dedicated to investing in their future. One of the ways we do this is to offer a comprehensive Total Rewards package designed to recognize and reward individual performance, as well support health, well-being, development and security for our colleagues and their family. Total Rewards consists of cash compensation, development and flexible benefit programs designed to meet individual needs today and in the future. Your salary will be commensurate with your work experience and our programs are reviewed regularly to ensure each remain competitive. We are proud to offer benefits such as health and welfare programs, strong retirement benefits, and generous paid time off programs. You and your eligible family members, including domestic partners and their children, can participate in medical, dental, and vision benefits, 401(k) and pension, income protection benefits such as life insurance, AD&D, and supplemental health programs to offset unexpected health care expenses. We also have a variety of time off programs for things like vacation, sick time, disability, and parental leave. Eligibility for some programs varies based on employment status and tenure.
Upon offer, Comerica conducts a comprehensive background and fingerprint check.
NMLS certification requirement: where applicable, a favorable background check screening, credit check, fingerprint check, and NMLS certification is required in accordance with the SAFE Act.
Comerica Incorporated (NYSE: CMA) is a financial services company headquartered in Dallas, Texas, and strategically aligned into three major business segments; the Commercial Bank, the Retail Bank, and Wealth Management. Comerica's colleagues focus on relationships, and helping people and businesses be successful. In addition to Texas, Comerica Bank locations can be found in Arizona, California, Florida and Michigan, with select businesses operating in several other states, as well as in Canada and Mexico.
Comerica is proud to be an Equal Opportunity Employer - veterans/individuals with disabilities, committed to workplace diversity.
|