A focused course, tailored for you
The Bank Security Analyst Detection-Engineering Playbook
Turn the queue of alerts, threat-intel emails and audit pings into a documented detection programme that holds up under FFIEC and SOX 404.
You catch real attacks. Then you spend Friday afternoon trying to prove to internal audit that you caught them, using screenshots and saved searches nobody else can read.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
A bank security analyst's day is a mix of three queues nobody outside the SOC sees in the same window. The SIEM alert queue with detections you wrote, refined and now half-trust. The threat-intel inbox with IOCs from FS-ISAC, the OCC alerts list and the federal advisories. The audit-ask folder where internal audit, the FFIEC examiners, the SOX 404 control owners and the third-party risk team all want evidence in different shapes.
The technical work is fine. The detections fire, the SOAR playbooks run, the tickets get closed. The gap is everything around the detections. Sigma-style version control of rules. ATT&CK coverage maps that show the board what is and is not covered. Purple-team test cases that prove a rule still works after a SIEM upgrade. SOX 404 control narratives that explain to an auditor, in language they read, how alert-to-ticket-to-resolution maps to a control activity. FFIEC IT handbook citations for each layer of the monitoring stack. None of that is in the security analyst job description, but all of it lands on the analyst's desk because nobody else has the underlying knowledge.
The course teaches the discipline that closes that gap. Not a SIEM tool tutorial. The engineering practice that turns ad-hoc rule writing into a documented, testable, audit-defensible detection programme.
What you walk away with
- Version-controlled SIEM detection content in a Sigma-style repository, with peer review and rollback.
- An ATT&CK coverage map that shows which techniques the bank can detect today, which are partial, which are blind.
- Purple-team test cases for the top twenty detections, replayable after every SIEM platform change.
- SOX 404 control narratives and FFIEC IT handbook citations for the monitoring stack you own.
- A documented detection-engineering practice an examiner can read in one sitting and understand.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve text-based modules in the Art of Service learning environment, each with downloadable templates and worked examples.
- A Sigma-style starter repository for bank-relevant detections, with a CI test harness.
- ATT&CK coverage map template and scoring rubric calibrated to a retail-bank threat model.
- FFIEC IT Examination Handbook citation table template for the monitoring layer.
- SOX 404 control narrative template, six worked examples for security-monitoring controls.
- The hand-built implementation playbook, tuned to your stack and audit cadence, delivered alongside course access.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours of purchase the learning environment account is provisioned.
Twelve modules, each completable in 60 to 90 minutes of focused work, plus exercises.
The hand-built implementation playbook is delivered alongside course access and tuned to your stack.
Suggested cadence: two modules a week over six weeks, with the implementation playbook actioned in parallel.
Before and after
Detections live as saved searches in one or two analysts' heads. The ATT&CK coverage answer is a guess. Every audit cycle the evidence gets rebuilt by hand. FFIEC and SOX questions get answered with screenshots and a verbal walk-through.
Detections live in a Git repository with peer review and a test harness. ATT&CK coverage is a heat map the board CRO sees quarterly. FFIEC citations and SOX 404 narratives are documented, evidence files attach themselves, and the next audit cycle is a review, not a rebuild.
What happens if you do not address this
The detection content you wrote becomes tribal knowledge that walks out the door when you take a new role. The next audit cycle eats a month of the team's calendar. The first OCC matter requiring action against the monitoring programme would land on whoever happens to be in the room.
Who it is for
Security analysts and senior security analysts inside US retail and commercial banks, who own SIEM content, run a chunk of the SOC's day-to-day detection work, and increasingly get pulled into audit-evidence and control-narrative conversations they were not hired for. Two to seven years in, comfortable in Splunk or Sentinel, decent with Python or KQL, but no formal detection-engineering training and no clean way to prove to FFIEC examiners how the monitoring layer actually meets the control objective.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Roughly 14 to 18 hours of module work, plus 6 to 10 hours actioning the implementation playbook against your own SIEM repository, audit cadence and reporting templates.
Why $199 is the right number
SANS detection-engineering courses are excellent and cost five to seven thousand USD. Vendor-specific Splunk or Sentinel certifications teach the tool, not the bank-context discipline. Free MITRE ATT&CK material covers the framework, not the operating model around it. This course sits between those: bank-specific, practice-focused, with the implementation playbook handing you the artefacts an auditor and an examiner actually want.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.