Information Security Sr Analyst
Role details
Job location
Tech stack
Job description
The Senior SOC Analyst will be responsible for day-to-day security threats, vulnerability management, analysis, and response. You will manage security incidents and review security alerts, determine if the security events are false positives, true positives, or false negatives, while working with incident responders on known or suspected security threats. The Senior SOC Analyst will work on log analysis, vulnerabilities and emerging threats, threat hunting and incident response that adhere to best practices and recognized control frameworks while mentoring analysts and being their escalation point. You will help provide security metrics, threat landscape updates and emerging trends. This role requires both deep analytical skills for threat detection and response, as well as technical engineering abilities to build, enhance, and automate security tools and processes. The Senior SOC Analyst will lead complex security investigations, develop automation solutions, and contribute to the strategic improvement of our security posture.
Responsibilities
-
Responsible for working in Security Operation Center (SOC) team environment.
-
Monitor, analyse, investigate security incidents and events using various tools and technologies including SIEM, UEBA, Threat Intel and EDR.
-
Perform security incident and event correlation, analysis, triage using information gathered from a variety of sources within the enterprise.
-
Generate reports, dashboards, and presentations from security technologies.
-
Point of conduct for Tier 1 & Tier 2 escalations for in-depth investigations of events.
-
Able to participate in an on-call rotation.
-
Provide analysis of trending security data from a large number of heterogeneous security devices across different layers.
-
Provide Incident Response (IR) support when analysis confirms an actionable incident.
-
Communicate and collaborate with stakeholders, including internal customers and senior management to provide updates on security incidents and to ensure proper resolution.
-
Investigate, document, and report on information security threats and emerging trends.
-
Integrate technologies and share information with SOC analysts and external teams.
-
Participate in internal projects and initiatives to increase SOC efficiency and improve SOC tooling.
-
Improve and challenge existing processes and procedures in an agile and fast-moving environment.
-
Maintain and update security documentation, including incident reports and KB articles.
-
Provide technical expertise, team member mentoring and advice to other departments.
-
Perform advanced threat hunting activities using custom queries, behavioral analysis, and threat modeling frameworks.
-
Develop and maintain security dashboards, metrics, and executive-level reporting.
-
Develop and maintain security tools, playbooks, and SOAR workflows to improve SOC efficiency.
Requirements
Do you have experience in TCP/IP?, Do you have a Bachelor's degree?, * Bachelor's degree in a related field (Security, Forensics, Cyber Security, or Computer Science is preferred) or equivalent industry related experience.
-
At least 5 years' experience working within an information security / cyber security role.
-
Desirable | Proven experience as a security analyst, incident handler/responder, security engineer, or penetration tester.
-
Knowledge of security methodologies, processes (i.e., Cyber Kill Chain/Diamond Models, and the MITRE ATT&CK/D3FEND framework).
-
Knowledge of technical security solutions (such as but not limited to firewalls, SIEM, NIDS/NIPS/HIDS/HIPS, EDR, DLP, SOAR, proxies, network behavioural analytics, orchestration, automation and cloud security).
-
Deep knowledge of TCP/IP, UDP, DNS, FTP, SSH, SSL/TLS and HTTP Protocols, network analysis, and network/security applications and email security.
-
Good knowledge of common malware threats and attack methodologies.
-
Good knowledge of scripting languages and programming languages (PowerShell, Python, Bash, .NET, Ruby,Java, C, etc.)
-
Experience with Infrastructure as Code.
-
Desirable Professional Certifications: GCIA, GCIH, GCFE, GCFA, Security+, CCNA CyberOps, OSCP, GPEN, GWAPT, CEH, CySA+
Core Competencies
-
Accountable for the successful completion of multiple, individual projects simultaneously.
-
Communicate effectively by contributing significantly to the development and delivery of a variety of written and visual documents for diverse audiences.
-
Manage change and demonstrate adaptability by adjusting priorities or processes and approaching as needs dictate.
-
Work independently as a team representative of Information Security as well as showing excellent teamwork skills.
-
Ability to develop thorough documentation and operational playbooks, in addition, to suggest alert enhancements to improve detection capability.
-
Ability to mentor and support team members to advance the security program.
-
Fundamental knowledge of network and system technologies and practices.
-
Desire for continual learning of new technologies and developing knowledge / skills.
Benefits & conditions
Pulled from the full job description
-
Annual leave
-
Life insurance
-
Matching gift scheme
-
Company pension
-
Private medical insurance
-
Flexible schedule, * 28 days annual leave plus 10 NI national holidays.
-
Pension matched up to 7%
-
Private health insurance for medical and dental.
-
Life Insurance.
-
Great work/life balance and flexible working hours.
-
Monthly catered lunches.
-
Unlimited drinks and snacks.
-
Charitable matching gift program.
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
Our Rewards
We offer a robust package of employee perks and benefits, including a market-leading salary with an annual bonus, 28 days of annual leave plus 10 Northern Ireland national holidays, a training and development budget, and a pension matched up to 7%. Our benefits also cover private health insurance for medical, dental, and optical care, and life insurance. We emphasize work-life balance with flexible working hours, parental leave, a modern city center office, and a hybrid work schedule that allows for greater flexibility by partially working from home. Additional perks include monthly catered lunches, unlimited drinks and snacks, hackathon events, poker tournaments, and a charitable matching gift program.