Senior Security Specialist - Threat Hunting
Yolk Recruitment Ltd
Cardiff, UK
7 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source
Tech stack
Data Analysis
Cloud Computing
Cyber Security
EHealth
Intrusion Detection and Prevention
Kusto Query Language
Security Information and Event Management
Data Logging
Software Security
Cybercrime
Microsoft Sentinel
Tools for Reporting
Job description
Support Digital Health and Care Wales in protecting critical systems, applications and sensitive data by leading proactive threat hunting, improving detection capabilities, and providing expert cyber security guidance. The role is a senior technical position within the Cyber Security Operations Centre (CSOC) and includes participation in the cyber on-call rota., * Lead proactive threat hunting using intelligence-led and hypothesis-driven approaches.
- Investigate complex security incidents and provide technical escalation within the CSOC.
- Develop and optimise SIEM detections, analytics, use cases and KQL queries to improve threat detection and reduce false positives.
- Identify gaps in logging, monitoring and telemetry across cloud, identity, endpoint, network and application environments.
- Analyse threat intelligence and emerging risks to improve cyber resilience.
- Produce technical reports, recommendations and threat hunting outcomes.
- Provide expert security advice and mentor colleagues through training and knowledge sharing.
- Collaborate with technical teams and stakeholders to enhance cyber security capabilities across NHS Wales.
Requirements
- Degree (or equivalent experience) in Cyber Security, IT or a related technical discipline.
- Strong knowledge of cyber security operations, threat hunting, incident response and security monitoring.
- Experience with SIEM platforms (ideally Microsoft Sentinel), KQL or similar analytics tools.
- Good understanding of cloud, endpoint, identity, network and application security.
- Knowledge of security frameworks such as NIST or ISO 27001.
Experience
- Proven experience in cyber security operations, SOC, incident response or threat hunting within a complex environment.
- Experience analysing security events and telemetry from multiple sources.
- Experience improving detection capabilities, developing security use cases and tuning SIEM alerts.
- Experience producing technical reports and security recommendations.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.totaljobs.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
EM
Eli McGarvie
about 3 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
EM
Eli McGarvie
IT Salaries in UK
almost 3 years ago
EM
Eli McGarvie
Data Engineer Salary UK
about 3 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
DC
Daniel Cranney
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
10 months ago