Make banking a Fifth Third better®
We connect great people to great opportunities. Are you ready to take the next step? Discover a career in banking at Fifth Third Bank.
GENERAL FUNCTION:
As a Principal Cyber Threat Analyst on the Detection, Analysis, and Response team, this role is responsible for identifying, investigating, and preventing cyber threats across the enterprise. Unlike a traditional SOC, this team focuses on deep investigations, advanced detection engineering, threat hunting, and rapid response.
The ideal candidate brings deep technical expertise in threat detection, incident response, and security operations, combined with a strong understanding of business processes and the financial services landscape. This role partners closely with threat intelligence, engineering, and business stakeholders to proactively identify risk, improve detection and response capabilities, and secure emerging technologies, including AI systems, agentic workflows, and modern development environments such as CI/CD and software supply chains.
Success in this role requires initiative, technical depth, and the ability to translate complex threats into actionable outcomes that align with business risk.
Key Responsibilities
Detection, Response & Threat Analysis
- Analyze alerts, investigate incidents, and lead response activities across enterprise systems, including cloud, endpoint, identity, AI platforms, and CI/CD environments
- Act as Incident Commander and escalation point for high-severity incidents and post-incident reviews
- Perform threat hunting, retro hunting, and deep-dive analysis to identify advanced attack techniques
- Continuously improve detection and response workflows, playbooks, and automation
AI Security & SME Leadership
- Serve as the SME for AI detection and response, including threats such as prompt injection, model abuse, and data leakage
- Partner with business units to understand AI usage and provide guidance on secure implementation and monitoring
- Identify and onboard new telemetry sources for AI platforms and agentic workflows
- Translate emerging AI threats and industry trends into actionable detections and controls
Technical Leadership & Mentorship
- Provide hands-on mentorship and guidance to analysts during investigations and response efforts
- Set the technical standard for alert review, triage, detection quality, and investigation depth
- Lead by example in incident handling, documentation, and decision-making under pressure
- Support hiring, onboarding, and ongoing development of team members
Detection Engineering & Strategy
- Design and maintain detection logic, playbooks, and workflows aligned to threat coverage and business risk
- Ensure detection capabilities support key objectives such as visibility, automation, and data quality
- Identify gaps in tooling, telemetry, and processes; recommend and drive long-term improvements
- Align detection and response strategies with frameworks such as MITRE ATT&CK and emerging AI threat models
Collaboration & Business Alignment
- Partner with product owners, engineering teams, and vendors to translate business priorities into security solutions
- Organize and drive cross-functional initiatives to enhance detection and response capabilities and improve overall security maturity
- Support root cause analysis and remediation efforts across technical and business domains
- Communicate risk, threats, and security recommendations effectively to technical and non-technical stakeholders
- Contribute to strategic initiatives and influence security decisions across the organization
Supply Chain & Development Security
- Contribute to detection, analysis, and response for threats targeting CI/CD pipelines and software supply chains
- Improve visibility, telemetry, and detection coverage across the software development lifecycle
- Identify attack patterns and strengthen controls related to build systems, dependencies, and deployment workflows
Continuous Learning & Industry Engagement
- Stay current on attacker TTPs, tools, and frameworks, including AI, cloud, and supply chain threats
- Share insights through documentation, training sessions, and team knowledge transfer
- Foster a culture of experimentation, continuous improvement, and technical excellence
MINIMUM KNOWLEDGE, SKILLS AND ABILITIES REQUIRED:
- Bachelor’s Degree in Computer Science, Information Systems, or other related field, or other relevant experience.
- 6 to 8 years of experience with the analysis/investigation and containment of potential data breaches or cyber security incidents.
- Scripting/Coding experience - Python, Regex, Yara as examples
- Knowledge of current hacking techniques, vulnerability disclosures, data breach incidents, and security analysis techniques
- Knowledge of malware families, botnets, threats by sector, and various attack campaigns and attacker methods, tools/techniques/practices
- Knowledge of cloud technologies including O365
- Common security controls is required including; authentication, encryption, IDS, WAFs, firewalls, HIPS, EDR, EPP, etc.
- Proficient in both Linux and Windows operating systems.
- Understanding of application protocols
- Strong analytical, tactical and critical thinking ability.
- Ability to handle multiple competing priorities in a fast-paced environment.
- Ability to communicate effectively across multiple levels
- Preferred CISSP, GIAC, or other relevant certification
Principal Cyber Threat Analyst
Total Base Pay Range 96,500.00 - 207,500.00 USD Annual
At Fifth Third, we understand the importance of recognizing our employees for the role they play in improving the lives of our customers, communities and each other. Our Total Rewards include comprehensive benefits and differentiated compensation offerings to give each employee the opportunity to be their best every day.
The base salary for this position is reflective of the range of salary levels for all roles within this pay grade across the U.S. Individual salaries within this range will vary based on factors such as role, relevant skillset, relevant experience, education and geographic location. In addition to the base salary, this role is eligible to participate in an incentive compensation plan, with any such payment based upon company, line of business and/or individual performance.
Our extensive benefits programs are designed to support the individual needs of our employees and their families, encompassing physical, financial, emotional and social well-being. You can learn more about those programs on our 53.com Careers page at: https://www.53.com/content/fifth-third/en/careers/benefits.html or by consulting with your talent acquisition partner.
LOCATION -- Virtual, Ohio 00000
Attention search firms and staffing agencies: do not submit unsolicited resumes for this posting. Fifth Third does not accept resumes from any agency that does not have an active agreement with Fifth Third. Any unsolicited resumes – no matter how they are submitted – will be considered the property of Fifth Third and Fifth Third will not be responsible for any associated fee.
Fifth Third Bank, National Association is proud to have an engaged and inclusive culture and to promote and ensure equal employment opportunity in all employment decisions regardless of race, color, gender, national origin, religion, age, disability, sexual orientation, gender identity, military status, veteran status or any other legally protected status.