Cyber Defence Analyst
A&o Shearman
Castlereagh, UK
10 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.adzuna.co.uk
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
£66,467.0
Working hours
Regular working hours
Job source
Tech stack
CompTIA Security+
Cyber Security
Computer Programming
Data Loss
Digital Forensics
Domain Name System (DNS)
Intrusion Detection and Prevention
Information Systems Security Architecture Professional
Python (Programming Language)
Simple Mail Transfer Protocols
Routing
Windows PowerShell
+8 more
Security Information and Event Management
Data Streaming
TCP/IP
Software Vulnerability Management
Scripting
Cyber Threat Analysis
Firewalls (Computer Science)
Information Technology
Job description
- Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm’s MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary.
- Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team.
- Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required.
Incident Response:
- Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone:
- Conduct initial triage and investigation.
- Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately.
- Participate in security incident response exercises and contribute to post-exercise reviews.
- Be part of the Cyber Defence on-call rota, which may require out-of-hours work.
- Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model.
- Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations.
Tooling and Process Improvement:
- Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function.
- Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence.
Collaboration and Advisory:
- Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm’s security posture by implementing controls and fostering awareness.
- Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language.
Requirements
- At least 1+ years’ experience in a security operations or similar technical security role.
- Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing.
- In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP).
- Cyber defence technologies and tooling, including:
- SIEM solutions
- Intrusion Detection/Prevention Systems (ID/PS)
- Threat and vulnerability management platforms
- Endpoint protection
- Firewalls
- Highly analytical mindset with strong problem-solving skills.
- Ability to interpret data flows, assess security events, and draw logical conclusions.
- Excellent written and verbal communication skills.
- Ability to collaborate effectively across technical and non-technical teams.
- High level of personal integrity and ethics, demonstrating an appropriate level of judgement.
- A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field.
You will stand out if you have
- Bachelor’s degree in Information Security, Computer Science, Engineering, Technology, or a related field.
- Industry-recognised certifications such as:
- CISSP (Certified Information Systems Security Professional)
- CEH (Certified Ethical Hacker)
- CISM (Certified Information Security Manager)
- CompTIA Security+
- Practical programming or scripting experience, particularly with:
- Python
- PowerShell
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.adzuna.co.uk
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
LM
Luis Minvielle
Why Upskilling And Reskilling is Important For Developers
over 2 years ago
LM
Luis Minvielle
The Most Popular IT Jobs on the Market
over 2 years ago
KD
Krissy Davis
Best Paying Jobs in Technology
over 3 years ago