Job description
Job Reference #
City
Job Type
Your role
We’re looking for a Cyber Security Risk Hunter to:
- serve as a subject matter expert in a number of Cyber and Information Security (CIS) domains, providing proactive risk oversight to identify emerging risks or deficiencies in UBS’s defense capabilities
- be a power user of the firm’s data-orientated cyber risk identification solution, the Risk Identification Engine, which is currently under development
- drive improvement of the Risk Identification Engine, identifying data sources and metrics to drive risk identification and measurement
- continuously measure the effectiveness and maturity of UBS’s CIS capabilities in order to assess the firm’s residual risk in key threat scenarios
- develop long-term relationships with security professionals and other stakeholders across the organization to ensure rapid investigations and escalations of potential CIS risk issues
- innovate by identifying operational risks, proposing realistic remediation or improvement solutions, while understanding potential tradeoffs and minimizing risk
- collaborate in multi-disciplinary teams on change initiatives across different geographies and business divisions
Your team
Your expertise
- Deep understanding and proven technical security experience covering two or more CIS domains – for example, but not limited to: network security, database security, cloud security, vulnerability and patch management, key management, endpoint security, application security, infrastructure and system hardening, identity and access management, crisis management, or supply chain security risk management
- strong technical skills with the ability to judge the effectiveness of security control implementation against threats and risk scenarios
- data science skills such as data analysis, visualization, modelling, interrogation of production operational data sources and/or creation of clean, automated data pipelines
- knowledge of CIS risk management and control frameworks (e.g. NIST CSF, CRI Profile) and operational threat management frameworks (e.g. MITRE ATT&CK)
- exposure to technology and cyber and information security regulatory requirements
- experience in an operational security role with the desire to shift toward a governance and risk role
- industry recognized certifications such as CISSP, CCSP, CISM, CISA, OSCP, SANS are a bonus
- understanding of the financial services industry
- strong problem solving skills along with a structured but pragmatic attitude
- team player with the ability to take initiative in order to organize, manage and complete projects and deliverables within tight deadlines
#LI-Hybrid
About us
With more than 70,000 employees, we have a presence in all major financial centers in more than 50 countries. Do you want to be one of us?
How we hire
Join us
From gaining new experiences in different roles to acquiring fresh knowledge and skills, we know that great work is never done alone. We know that it's our people, with their unique backgrounds, skills, experience levels and interests, who drive our ongoing success. Together we’re more than ourselves. Ready to be part of #teamUBS and make an impact?
Disclaimer / Policy Statements