Senior Cyber Security Incident Response Analyst

  • Ashburn, VA, USA
  • Full-time

Company Description

Common Purpose, Uncommon Opportunity.  Everyone at Visa works with one goal in mind – making sure that Visa is the best way to pay and be paid, for everyone everywhere. This is our global vision and the common purpose that unites the entire Visa team.  As a global payments technology company, tech is at the heart of what we do.  CyberSource, a Visa company, has been and continues to be a pioneer within the e-Commerce Payment Management world. Our VisaNet network is capable of handling over 65,000 transaction messages per second for people and businesses around the world, enabling them to use digital currency instead of cash and checks. We are also global advocates for financial inclusion, working with partners around the world to help those who lack access to financial services join the global economy. Visa’s sponsorships, including the Olympics and FIFA™ World Cup, celebrate teamwork, diversity, and excellence throughout the world. If you have a passion to make a difference in the lives of people around the world, Visa offers an uncommon opportunity to build a strong, thriving career. Visa is fueled by our team of talented employees who continuously raise the bar on delivering the convenience and security of digital currency to people all over the world. Join our team and find out how Visa is everywhere you want to be.

Job Description

Information security is an integral part of Visa's corporate culture. It is essential to maintaining our position as an industry leader in electronic payments, which is why Visa has made it a priority to create top-tier security operations and incident response teams to defend the company against evolving cyber threats. If you would like to join a company where security is truly valued, where you can work with like-minded peers who are passionate about the art & science of cyber defense, and where you can use state of the art tools for maximum impact, then we have a home for you.

You will be responsible for providing cyber incident response subject matter expertise while collaborating on numerous security projects and operational improvement initiatives. This position will support the operational activities of junior-level cyber analysts while helping to develop the team’s investigative skillset, process and playbooks.  In this role you will champion incident response services enrollment requirements to ensure progressive operational effectiveness and alert fidelity. In addition, you will be responsible for continuously identifying gaps and manage the improvements in security response process, technologies, and monitoring. Working closely with internal architecture, engineering and project management teams, you will ensure cyber-defense requirements are identified and communicated early in the project life-cycle.


  • Support cyber incident response actions to ensure proper assessment, containment, mitigation and documentation

  • Support cyber investigations and contribution to large and small scale computer security breaches

  • Review and analyze cyber threats and provide SME support and training to junior level security analysts

  • Interact and assist other investigative teams within Visa on time sensitive, critical investigations

  • Participate as part of a close team of technical specialists on coordinated responses and subsequent remediation of security incidents

  • Manage the security monitoring enrollment process to ensure adequate coverage and effectiveness of all new and existing cloud and premise based applications, services and platforms

  • Maintain detailed tracking plan of all internal/external enrollment outcomes/recommendations and provide support through to implementation

  • Act as a liaison between cyber-defense, engineering, security architecture, network & system operations, and functional project teams to ensure effective project implementation that meets incident response requirements

  • Work with colleagues in other technology departments as well as the business and product offices to establish effective, productive business relationships

  • Define baseline security monitoring requirements for all new projects, services and applications joining the Visa network

  • Facilitate the development and tuning of SIEM rules to support enrollments and ensure high fidelity alerting



  • 5+ years’ experience in security, network or cyber engineering operations
  • 3 - 5+ years of related experience in cybersecurity or computer network defense
  • Bachelor's degree in computer science, information systems, or a related technical discipline or equivalent professional experience directly related to information security, cyber, or computer network defense
  • Relevant security related certifications a plus: CISSP, GCIA, GSEC, GCIH, GCED, GCFA, GREM
  • Proven subject matter expertise in relevant areas, such as incident response, intrusion analysis, incident handling, malware analysis or security engineering
  • Strong knowledge of malware families and network attack vectors
  • Strong knowledge of Linux, Windows system internals
  • Strong knowledge of web applications and APIs
  • Strong Python scripting skills
  • YARA, RegEx experience required
  • Demonstrated experience in an enterprise-level incident response team or security operations center. Direct experience handling advanced cyber security incidents and associated incident response toolset
  • Strong working knowledge of common security tools, such as a SIEM, AV, scanners, proxies, WAF, netflow, IDS or forensics tools
  • Advanced technical knowledge associated with various operating systems, network services and applications. A keen understanding of logging components and capabilities
  • Strong interpersonal and leadership skills to influence and build credibility as a peer
  • Possess a demonstrated sense of urgency with the ability to perform well under significant enterprise-wide pressure
  • Excellent communication and presentation skills with demonstrated skill in presenting analytical data effectively to varied (including executive) audiences
  • Knowledge of the Visa business and core systems to ensure integrated approach to the enrollment process a plus


Additional Information

All your information will be kept confidential according to EEO guidelines.


Privacy Policy