> Markdown version of [/jobs/ext/3061819-cyber-defence-analyst](https://www.wearedevelopers.com/jobs/ext/3061819-cyber-defence-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Defence Analyst - **Company:** Northern Ireland - **Location:** Cookstown, UK - **Contract:** Permanent contract - **Skills:** Cyber Security, Data Loss, Digital Forensics, Domain Name System (DNS), Information Systems Security Architecture Professional, Simple Mail Transfer Protocols, Routing, Security Information and Event Management, Data Streaming, TCP/IP, Software Vulnerability Management, Scripting, Cyber Threat Analysis, Information Technology - **Published:** September 25, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/cyber-defence-analyst/48050518 ## About the Role Management team, applying this knowledge in daily operations.Tooling And Process ImprovementAssist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function.Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence.Collaboration And AdvisoryCollaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness.Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language.What You Will HaveAt least 1+ years' experience in a security operations or similar technical security role.Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing.In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP).Cyber defence technologies and tooling, including:SIEM solutionsIntrusion Detection/Prevention Systems (ID/PS)Threat and vulnerability management platformsEndpoint protectionFirewallsHighly analytical mindset with strong problem-solving skills.Ability to interpret data flows, assess security events, and draw logical conclusions.Excellent written and verbal communication skills.Ability to collaborate effectively across technical and non-technical teams.High level of personal integrity and ethics, demonstrating an appropriate level of judgement.A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field.You will stand out if you haveBachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field.Industry-recognised certifications such as:CISSP (Certified Information Systems Security Professional)CEH (Certified Ethical Hacker)CISM (Certified Information Security Manager)CompTIA Security+Practical programming or scripting experience, particularly with:PythonPowerShellNO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here. #J-18808-Ljbffr ## Description Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary.We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team, based in the A&O Shearman's Belfast office.Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary.Investigate EscalationsWhat you will doInvestigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary.Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team.Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required.Incident ResponseParticipate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone:Conduct initial triage and investigation.Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately.Participate in security incident response exercises and contribute to post-exercise reviews.Be part of the Cyber Defence on-call rota, which may require out-of-hours work.Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model.Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability ## Related Videos - [How to Avoid LLM Pitfalls - Mete Atamel and Guillaume Laforge](https://www.wearedevelopers.com/videos/1328-how-to-avoid-llm-pitfalls-mete-atamel-and-guillaume-laforge) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [From Shadow AI to Secure Intelligence: Safe AI Usage in the Enterprise](https://www.wearedevelopers.com/videos/2093-from-shadow-ai-to-secure-intelligence-safe-ai-usage-in-the-enterprise) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)