Job Description: Job Title: Attack Surface Research Analyst Corporate Title: Up to Vice President Location: Chester or Dublin Company Overview : At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth.
This includes our commitment to being a diverse and inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Location Overview: Chester Find us in the city of Chester, a destination renowned for its culture, history, and beauty. Working at Bank of America Chester offers a far-reaching global career for a world-renowned organisation, whilst being ideally situated against the backdrop of the rolling North Wales hills and the banks of the serene River Dee. Central Park Overlooking the spectacular Iveagh Gardens with access to all amenities in the beating heart of central Dublin is our Park Place office.
Travel options include the LUAS, Dublin Bus networks as well as the Dublin Bikes station, positioned just outside our front doors. As part of our commitment to supporting staff travel to and from work in the most sustainable way possible, we also provide tax saver tickets as part of our award-winning benefits package which means getting to work has never been easier Role Description: The Cyber Security Assurance, Attack Surface Research (ASR) role maintains and performs queries across a wide array of asset enumeration and research toolsets, spanning on-premises and cloud platforms, to effectively map, measure, and report on the topography of the Bank’s network endpoints and other assets for vulnerability risk.
In addition to core investigative matters, the role is responsible for ensuring the stability and enhancement of the backend infrastructure used to create high quality queries, datasets, and visualizations from various enterprise platforms and security data sources. Individuals in the role will routinely ad-hoc investigate infrastructure and vulnerability asset data in support of partner Information Security teams, to help correctly ascertain and communicate vulnerability risk to both technical and non‑technical stakeholders.
The role requires a highly collaborative, analytical and detail-oriented mindset, with a focus on ensuring conclusions and/or insights reflect innovative thinking as well as accurate information gathering under time pressure to fully answer three core questions as quickly as possible. • Do we have it? • Are we vulnerable? • Is it exploitable? Persons in this role operate as part of a team developing methods to quickly reference systems of record (SORs), systems of origin (SOOs) and other available data stores to provide a comprehensive, reliable and timely view of the Bank’s Attack Surface, both as it relates to vulnerability exploitation risk as well as other concerns.
Responsibilities: Create SQL and Python scripts within Qualys, Tanium and BladeLogic to query datasets, to support Attack Surface Review. Perform hands-on analysis of large-scale datasets to correlate map, measure, and report on the overall vulnerability attack surface of the Bank. Leverage Python, SQL, and other languages/platforms to automate data ingestion, transformation, enrichment, and quality validation (ETL) Develop and maintain visualizations and reports in Power BI or MS-Reporting Services (SSRS) MS-Integration Services (MSIS) that support operational teams, cyber leadership, and stakeholders across Information Security and broader risk teams.
Possesses network