West Midlands, United Kingdom | Posted on 21/03/2025
TheCyber Defence Analyst will join a rapidly growingsecurity team responsible for designing, delivering and maintaining operationalcybersecurity capabilities. Conducting pro-active, risk-based, protectivemonitoring on priority C4IS/networks in order to identify internal and externalcyber-threats/attacks. This position involves a broad range of skills,including the development and mentoring of the Level 2 Analyst, monitoringnetworks to actively remediate unauthorised activities.
Requirements
Tasks:
- Developand integrate security event monitoring and incident management services.
- Respond tosecurity incidents as they occur as part of an incident response team.
- Implementmetrics and dashboards to give visibility of the Enterprise infrastructure.
- Assistwith the leadership of a composite cyber response team during incidents andinvestigations
- Use of theSOAR platform to assist with playbook automation and case managementcapabilities to streamline team processes and tools.
- Produce documentationto ensure the repeatability and standardisation of security operatingprocedures.
- Developadditional investigative methods using the Authority’s environment’s softwaretoolsets to enhance recognition opportunities for specific analysis.
- Maintain abaseline of system security according to latest threat intelligence andevolving trends.
- Participatein root cause analysis of incidents in conjunction with analysts and engineersacross the enterprise.
- ProvideSubject Matter Expertise (SME) on a broad range of information securitystandards and best practices.
- Offerstrategic and tactical security guidance including valuation requirement oftechnical controls.
- Be part ofthe CRM process
- Liaisewith the Authority’s environment’s Level 3 engineers to maintain up-to-datedashboards of security alerts, to allow the Authority to better respond to anincident.
- Document,validate and create operational processes and procedures to help develop theAuthority’s environment.
- Assist inidentifying, prioritising, and coordinating the protection of critical cyberdefence infrastructure and key resources.
- Build,install, configure, and test dedicated cyber defence hardware.
- SupportLevel 1 Analysts to manage Authority’s environment’s systems.
Skills/Experience:
- Previousexperience of Enterprise ICS/network architectures and technologies
- Experienceand knowledge of SIEM solutions; having the ability to identify use cases andtheir creation, their deployment and tuning.
- Experienceas a mentor/coach to junior analysts
- Previousexperience of utilising the MITRE ATT&CK and Cyber Kill Chain frameworks
- Skilled inmaintaining Microsoft directory services.
- Skilled inusing virtualisation software.
- Knowledgeof key security frameworks (e.g. ISO, NIST 800-53)
- Experienceof writing Defence/Government documentation
- BroadSpectrum Cyber Course (SANS SEC401 or SEC501 or equivalent)
- Experienceof managing cyber incidents and investigations
- SIEMDesign, Architecture and Analyst Course (SANS SEC455 or SEC555 or equivalent)
- AdvancedAnalyst Course (SANS SEC503 or equivalent)