368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$84k – $100k per year
Location
Remote (United States)
Seniority
Senior · 3+ years exp
Overview
Company
Impact
Profile match
Citizens Financial Group is one of the oldest and largest financial institutions in the United States, offering a comprehensive suite of commercial and retail banking services. Headquartered in Providence, Rhode Island, the enterprise operates an extensive network of physical branches, ATMs, and digital platforms across multiple regions. Through its tailored personal, private, and corporate solutions, the bank assists individuals, small businesses, and institutions in managing capital and achieving their financial goals.

As a Sr. Cyber Defense Ops Specialist, you are a senior individual contributor in the Cyber Defense Threat Detection (CDTD) Cyber Defense Operations Center (CDOC), responsible for performing security monitoring, intrusion analysis, incident handling, data loss prevention, privileged user monitoring, training of analysts, security incident management, malware detection/eradication, and recognizing hacker/incident response tactics, techniques, and procedures. You will have responsibility for one or more of the security systems aligned with their specific function, either directly or indirectly; and will be a technical authority for critical operational decisions having significant impact to the organization with authority extending beyond the team to include both technology and business line areas in security related decisions. This role requires you to stay current with security technology, the threat landscape, and emerging threats. You will also act as a subject matter expert in their specific disciplines and will provide management with recommendations and guidance as needed.

Primary responsibilities include

  • Performing ongoing monitoring and threat analysis, analyzing logs, NetFlow data, and packet capture.
  • Identifying potential IT security incidents and escalating information to appropriate IR senior staff.
  • Assessing threat and vulnerability information from all sources (both internal and external) and promptly applying applicable mitigation techniques.
  • Developing meaningful metrics to reflect the true posture of the environment allowing the organization to make educated decisions based on risk.
  • Using information from cyber security tools and processes, assessing potential security and business impacts while communicating recommendations to management.
  • Representing Cyber Defense as needed on security related or risk related initiatives or working groups where technical skills and security expertise are required.
  • Proactively protecting, monitoring, investigating and resolving threats to secure user environment and company assets.

Experience and Skills:

  • 3 or more years of security industry experience preferably in a Security Operations Center (SOC) environment
  • Experience with the following highly desirable:
    • Security Information and Event Management Tools (Arcsight, Splunk, etc.)
    • Intrusion Prevention/Detection Tools (FirePower, McAfee)
    • Database Security Tools (Guardium, jSonar)
    • Data Loss Prevention Tools (Symantec, Triton, etc.)
    • Firewalls (Cisco, Palo Alto, Check Point etc.)
  • Application Security Tools (Web Application Firewalls)
  • Vulnerability tools
  • Cyber Security Incident Response
  • Host Intrusion Detection Systems
  • XDR and Antivirus Tools (Crowdstrike, Symantec, MS Defender)
  • Strong verbal and written communication skills including the ability to communicate technical concepts to non-technical audiences.
  • Excellent critical thinking, problem-solving, and decision-making skills.
  • Must possess active listening, attention to detail, customer service, prioritization, and problem-solving skills.
  • Ability to work independently or strategically.
  • Experience adapting and demonstrating flexibility while working in a dynamic environment.

Education and Certifications

  • Bachelor’s Degree or equivalent combination of experience
  • A combination of relevant industry certifications preferred (e.g. Net+, Sec+, CySA+, CEH, Pentest+, GCFA, GSOC, AWS Certified Cloud Practitioner, Microsoft Azure Fundamentals)

Hours & Work Schedule

Hours per Week: 40 Hrs. (4 days per week)

Work Schedule: 7:00AM - 5:00PM (Tuesday - Friday)

Location: One Citizens Way, Johnston, RI - Citizens Bank Johnston Campus (this is not a remote opportunity)

Pay Transparency

The salary range for this position is $84,000 - 100,000 per year, plus an opportunity to earn additional incentive earnings (if applicable). Actual pay is based on various factors including, but not limited to, the budget, work location, and relevant skills and experience. We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens’ paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States. For an overview of our benefits, visit Citizens Benefits

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$142k – $224k per year • In office • Full-Time • 11+ years exp • Bachelor's Degree • Rahway
Databases
SAP HANA
Trino
DevOps
Amazon S3
Incident Management
Analytics
ETL/ELT
Apply
$45k – $114k per year (Estimated) • Remote • Full-Time • São Paulo • Vitoria-Gasteiz • Fortaleza • Rio de Janeiro • Recife
DevOps
AWS
Azure
Azure DevOps
Bicep
CI/CD
CloudFormation
GCP
GitHub
GitHub Actions
GitLab
GitLab CI
IAM
Incident Management
Jenkins
Kubernetes
Terraform
Apply
$141k – $265k per year (Estimated) • Equity • Remote • Contractor • 8+ years exp
Python
Ruby
DevOps
AWS
Blue-Green Deployment
CI/CD
GCP
GitOps
Grafana
Incident Management
Kubernetes
OpenTelemetry
Prometheus
Pulumi
Terraform
Cybersecurity
FedRAMP
NIST 800-53
SentinelOne
Apply
$205k – $235k per year • Remote • 8+ years exp • Bachelor's Degree
SQL
DevOps
Incident Management
Cybersecurity
HIPAA
Robotics
Digital Twin
Apply
$148k – $284k per year (Estimated) • Equity • In office • 8+ years exp • Denver
AI/ML
AI Agents
Anthropic
DevOps
Incident Management
Apply
In office • 4+ years exp • High School Diploma
JavaScript
Python
SQL
Databases
Amazon Redshift
MS SQL
Oracle
PostgreSQL
DevOps
Rest API
Analytics
Tableau
ETL/ELT
Apply
$85k – $207k per year (Estimated) • Remote • 2+ years exp • Master's Degree
JavaScript
C#
C#
.NET
DevOps
Git
Jenkins
Analytics
ETL/ELT
Apply
$108k – $242k per year (Estimated) • Remote • 3+ years exp • High School Diploma
Java
SQL
JavaScript
Java
Hibernate
Maven
Spring Boot
Spring MVC
Databases
Apache Kafka
AI/ML
JAX
Frontend
Bootstrap
Mobile
JUnit
DevOps
Bitbucket
CI/CD
Datadog
Docker
Git
Kubernetes
Logstash
Rest API
ZooKeeper
QA
Swagger
Apply
Network Engineer I 6 days ago
$74k – $90k per year • In office • 2+ years exp
DevOps
Splunk
Apply
In office • 7+ years exp • Bachelor's Degree
AI/ML
AI Agents
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.