Security Operations Analyst SC Required
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+5 more
Job description
We are seeking a new talent to join the Security team, where you will have the opportunity to collaborate on a UK Central Government, a government entity focused on ensuring security and compliance., * Detection engineering - Develop, maintain, and enhance security detection content primarily for the Splunk SIEM, to enable the detection of threats across diverse platforms (eg cloud, endpoints, and networks)
- Collaborate with the extended security team to identify gaps in detection coverage, log ingestion and alerting based on business risks and threats
- Review and improve existing SecOps standards and capabilities, eg by highlighting requirements for additional logging, identifying incident or threat trends, and detection and business-as-usual optimisation opportunities
- Perform security monitoring, reviewing and triaging triggered alerts, and suggesting improvements (on a rota basis, 9am-5:30pm)
- Respond to and investigate identified cyber security incidents
- Act as a point of escalation for Junior Analysts, supporting them through mentorship and shadowing
- Operate as a technical subject matter expert on client engagements and be prepared to interact with, and present to, senior stakeholders in a consulting capacity
- Participate in alert testing and incident response tabletop exercises as required
- Remain up to date with the latest threat intelligence which may be of interest to our clients
Additional Responsibilities (client dependent)
- Proactive threat hunting and tradecraft development
- Incident response and playbook development
- Change approvals (where applicable)
- Collection and interpretation of different sources of threat intelligence, and researching emerging threats and TTPs
- Vulnerability scanning, management and reporting
On-Call Requirement
This role requires approximately 1 week per month on-call availability for high-priority incident response. Please note there is additional compensation for this, and the frequency is client dependent.
Requirements
The successful candidate should have experience and skills in some of the following areas:
- Working knowledge of key threat intelligence concepts such as the Pyramid of Pain, Intelligence Preparation for the Cyber Environment (IPCE), and the Threat Intelligence Lifecycle
- Detection engineering and alert development
- Experience with Scripting and programming - eg Python/Bash/C/C++/Java
- Core cybersecurity concepts such as network security, cryptography, cloud security, forensics
- Understanding of network protocols and how they can be abused by attackers
- Up-to-date knowledge of the most prevalent APTs and their TTPs
- Knowledge of common analysis techniques associated with Windows and/or Linux
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.careerboard.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Data Analyst Salary in the UK
Dev Digest 134 - Where pixels sing?
The Most Popular IT Jobs on the Market
Understanding and Mitigating Common Web Vulnerabilities