Cyber Defence Analyst

Plannedlink

West Midlands

On-site

GBP 55,000 - 76,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Plannedlink in the West Midlands region is seeking a Cyber Defence Analyst to join a growing security team. You will design, deliver and maintain operational cybersecurity capabilities, performing proactive, risk-based monitoring of priority networks to identify threats and respond to incidents.

The role involves mentoring Level 2 analysts, developing dashboards, and coordinating with Level 3 engineers to keep security alerts current and actionable.

Qualifications

  • Previous experience with Enterprise ICS/network architectures.
  • Experience with SIEM solutions and tuning.
  • Mentoring or coaching junior analysts.
  • Familiarity with MITRE ATT&CK and Cyber Kill Chain.
  • Experience maintaining directory services and virtualization tools.
  • Knowledge of security frameworks (ISO, NIST 800-53).
  • Experience writing Defence/Government documentation.
  • Broad cyber course background (SANS SEC401/501 or equivalent).
  • Experience managing cyber incidents and investigations.

Responsibilities

  • Develop and integrate security event monitoring and incident management services.
  • Respond to security incidents as part of an incident response team.
  • Implement metrics and dashboards for visibility of the Enterprise infra.
  • Lead a composite cyber response team during incidents and investigations.
  • Utilise the SOAR platform for playbook automation and case management.
  • Document standard operating procedures and repeatable processes.
  • Develop investigative methods using the Authority's tooling to enhance detections.
  • Maintain baseline security aligned with threat intelligence and trends.
  • Participate in root cause analyses with analysts and engineers.
  • Provide SME guidance on information security standards and practices.

Skills

Cyber incident response
Security monitoring
Threat detection
Mentoring junior analysts
Dashboards & metrics
SOAR playbooks
Documentation
Root cause analysis
SME on security standards
Strategic/tactical security guidance
Stakeholder liaison
Incident response leadership
CRM process involvement
Team leadership
Incident investigations
Security governance

Tools

SOAR platform
Virtualisation software
Microsoft directory services

Job description

West Midlands, United Kingdom | Posted on 21/03/2025

TheCyber Defence Analyst will join a rapidly growingsecurity team responsible for designing, delivering and maintaining operationalcybersecurity capabilities. Conducting pro-active, risk-based, protectivemonitoring on priority C4IS/networks in order to identify internal and externalcyber-threats/attacks. This position involves a broad range of skills,including the development and mentoring of the Level 2 Analyst, monitoringnetworks to actively remediate unauthorised activities.

Requirements

Tasks:

  • Developand integrate security event monitoring and incident management services.
  • Respond tosecurity incidents as they occur as part of an incident response team.
  • Implementmetrics and dashboards to give visibility of the Enterprise infrastructure.
  • Assistwith the leadership of a composite cyber response team during incidents andinvestigations
  • Use of theSOAR platform to assist with playbook automation and case managementcapabilities to streamline team processes and tools.
  • Produce documentationto ensure the repeatability and standardisation of security operatingprocedures.
  • Developadditional investigative methods using the Authority’s environment’s softwaretoolsets to enhance recognition opportunities for specific analysis.
  • Maintain abaseline of system security according to latest threat intelligence andevolving trends.
  • Participatein root cause analysis of incidents in conjunction with analysts and engineersacross the enterprise.
  • ProvideSubject Matter Expertise (SME) on a broad range of information securitystandards and best practices.
  • Offerstrategic and tactical security guidance including valuation requirement oftechnical controls.
  • Be part ofthe CRM process
  • Liaisewith the Authority’s environment’s Level 3 engineers to maintain up-to-datedashboards of security alerts, to allow the Authority to better respond to anincident.
  • Document,validate and create operational processes and procedures to help develop theAuthority’s environment.
  • Assist inidentifying, prioritising, and coordinating the protection of critical cyberdefence infrastructure and key resources.
  • Build,install, configure, and test dedicated cyber defence hardware.
  • SupportLevel 1 Analysts to manage Authority’s environment’s systems.

Skills/Experience:

  • Previousexperience of Enterprise ICS/network architectures and technologies
  • Experienceand knowledge of SIEM solutions; having the ability to identify use cases andtheir creation, their deployment and tuning.
  • Experienceas a mentor/coach to junior analysts
  • Previousexperience of utilising the MITRE ATT&CK and Cyber Kill Chain frameworks
  • Skilled inmaintaining Microsoft directory services.
  • Skilled inusing virtualisation software.
  • Knowledgeof key security frameworks (e.g. ISO, NIST 800-53)
  • Experienceof writing Defence/Government documentation
  • BroadSpectrum Cyber Course (SANS SEC401 or SEC501 or equivalent)
  • Experienceof managing cyber incidents and investigations
  • SIEMDesign, Architecture and Analyst Course (SANS SEC455 or SEC555 or equivalent)
  • AdvancedAnalyst Course (SANS SEC503 or equivalent)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defence Engineer
Cyber Defence Engineer

Plannedlink • West Midlands

On-site
GBP 60,000 - 90,000
Cyber Defence Analyst: Incident Response, SIEM & SOAR Expert
Cyber Defence Analyst: Incident Response, SIEM & SOAR Expert

Plannedlink • West Midlands

On-site
GBP 55,000 - 76,000
Cyber Security Analyst
Cyber Security Analyst

Radiuslimited • Crewe

On-site
GBP 45,000 - 65,000
Cyber Security Analyst
Cyber Security Analyst

Novia Financial plc • Bath

On-site
GBP 55,000 - 75,000
IT Security Analyst
IT Security Analyst

Castle Employment • Beverley

On-site
GBP 40,000 - 65,000
Cyber Security Analyst
Cyber Security Analyst

Synapri • Greater London

Hybrid
GBP 50,000 - 70,000
SOC Team Lead
SOC Team Lead

Jobtailor • Greater London

On-site
GBP 90,000 - 120,000
3rd Line Security Analyst
3rd Line Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 51,000 - 69,000
SOC / Cyber Threat Detection Analyst – SANS/GIAC
SOC / Cyber Threat Detection Analyst – SANS/GIAC

Cyber UK • Wokingham

On-site
GBP 45,000 - 70,000
Excellent benefits and training
Security Operations Analyst: Threat Detection & Response
Security Operations Analyst: Threat Detection & Response

Graphic Packaging International • United Kingdom

On-site
GBP 40,000 - 70,000