Senior Cyber Operations Engineer
Role details
Job location
Tech stack
Job description
The Cyber Operations Engineering (COE) Team forms a key part of the Security function within Digital, Data & Technology (DD&T). Our team are responsible for:
- Onboarding new data sources from both cloud and on-prem solutions into our SIEM tooling, centralising the forensic telemetry from across the various critical systems which balance the UK energy system.
- Building and maintaining innovative security technologies that support the wider Cyber Security functions across NESO, serving as the foundation of NESO's Cyber Security Operations (CSO) capability.
- Building automation to support secure and scalable delivery across the COE team and wider functions.
The Senior Cyber Security Operations Engineer will report to the COE Delivery Manager and will be responsible for delivery of the core COE responsibilities; including but not limited to the design, implementation, and operational support of SIEM Engineering and CSO tooling capabilities within NESO. They will have strong communication and stakeholder management skills, and work in closely with the business and cyber teams as the COE internal-customers to meet these objectives.
In addition to technical delivery, they will collaborate with the Cyber Operations teams to contribute to continuous improvement initiatives, automation, and reporting - supporting and uplifting overall team maturity.
This role can be based from Wokingham or Warwick and we continue to offer hybrid working from office and home. We are open to flexible working arrangements., Delivery
- Collaborate with application administrators across the business to onboard data sources into the SIEM data lake.
- Build and deploy innovative technical solutions to advance the security capability of the Cyber Security Operations function.
- Maintain and improve various security tools to enable key stakeholders, such as CSOC and Threat Hunting and Detection Engineering (THaDE).
- Build resilient forensic telemetry collection technologies to support 24/7/365 security monitoring.
- Optimise forensic telemetry collection mechanisms to ensure accurate and efficient parsing and ingestion to the SIEM.
- Contribute to process improvement and an internal cyber engineering knowledgebase.
Stakeholder Engagement
- Collaborate with the business to support the smooth and successful engagement of log source onboarding
- Develop relationships with Cyber teams to ensure outputs from security capabilities and onboard meet their requirements.
Applicants must have the right to work in the UK by the start of employment. Visa sponsorship may not be available for this role and will be considered in line with business requirements.
Requirements
We're forging the path, and we know we can't do it alone. That's why we need visionary minds like yours to join us on this transformative journey. In this case, we're looking for someone who:
- Is passionate about security and building secure infrastructure and secure foundations.
- Is curious. We often deal with bespoke or less common data sources at NESO, and a willingness and enthusiasm to take on the challenge of making sense of these data sources is a must.
- Has proven experience working with SIEM platforms and related tooling.
- Is knowledgeable about various data source formats and protocols (e.g., syslog, JSON, REST API).
- Is comfortable with scripting or programming languages (Python, Bash, PowerShell, etc).
- Has experience in troubleshooting and resolving data quality or ingestion issues.
- Has previously worked closely with security tooling such as EDR, Deception Tech, Malware Sandboxes, Vulnerability Management Tooling, etc.
- Has strong analytical and problem-solving skills and ability to handle complex and dynamic situations.
- Has strong communication and collaboration abilities.
- Is aware of treating cyber operations engineering with a Software Development Lifecycle mindset (Using tooling such as Git forges, CI/CD pipelines, Infrastructure as Code, Detection as Code, etc).
- Is aware of security incident response and investigation processes.
- Is aware of current and emerging cyber threats, trends, and best practices.
- May have relevant certifications (e.g. GIAC), but this is not required.
Benefits & conditions
A competitive salary of £50,000 - £58,000 dependent on experience and capabilityAs well as your base salary, NESO's core benefits are the essential perks and advantages that form part of your employee package. - You will receive a bonus based on company performance- 26 days annual leave as standard - A competitive contributory pension scheme where we will double match your contribution to a maximum company contribution of 12%. - Annual Enrollment to NESO Savings Plan, when you save between £20- £500 a month from your take-home pay, we will pay a 50% matching contribution.
NESO's flexible benefits programme provides you with more flexibility around your health, lifestyle and protection benefits, here's just a few available:
- Flexible Bank Holidays & Holiday Trading
- Additional Birthday Day Off
- Cycle to Work Scheme, Retail & Gym Discounts
- Private Medical Insurance, Critical Illness Insurance & Personal Accident Insurance