Cyber Defence Senior Analyst

A&O Shearman

Donaghadee

On-site

GBP 45,000 - 73,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Weekend premium

Job summary

A&O Shearman is seeking a Senior Cyber Defence Analyst to join the Information Security team in Belfast. The role focuses on Level 2 investigations, incident containment, and remediation within a 24-7 follow-the-sun model.

Weekend work is required with premium pay; strong cloud experience (AWS/Azure/GCP) and scripting skills (PowerShell, Python) are essential for automation and tooling enhancements.

Qualifications

  • Experience in security operations or similar technical role in at least four domains.
  • Solid understanding of networking, DNS, SMTP, and TCP/IP.
  • Familiarity with SIEM, IDS/IPS, vulnerability management, and EPP/firewalls.
  • Ability to interpret data, identify anomalies and propose remediation.
  • Industry certifications such as CISSP, CEH, CISM, or CompTIA Security preferred.
  • Experience with cloud platforms (AWS/Azure/GCP) and scripting for automation.

Responsibilities

  • Investigate Level 2 escalated events from MSSP to identify incidents.
  • Mentor junior colleagues during investigations.
  • Conduct triage and investigation of confirmed incidents.
  • Contain, mitigate, and remediate incidents with proper forensic evidence.
  • Develop detection definitions and improve playbooks.
  • Collaborate with Information Security and IT to implement controls.
  • Support Threat and Vulnerability Management in remediation activities.

Skills

Security operations
Incident response
Digital Forensics
Networking & routing
Threat intelligence
Communication
Automation scripting

Education

Bachelor's degree in Information Security / CS

Tools

PowerShell
Python
REST
AWS
Azure
GCP

Job description

Salary: £45,000 - 73,000 per year

Requirements:
  • Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, alert triaging, rule writing, incident response, Digital Forensics and Incident Response (DFIR), threat intelligence and management, vulnerability management, or security control testing.
  • Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP).
  • Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), threat and vulnerability management platforms, endpoint protection, and firewalls.
  • Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions.
  • Demonstrated ability to investigate complex security issues and propose effective solutions.
  • Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams.
  • Genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field.
  • Bachelors degree in Information Security, Computer Science, Engineering, Technology, or a related field.
  • Industry-recognised certifications such as CISSP, CEH, CISM, or CompTIA Security.
  • Experience working with major cloud service providers (CSPs) technologies, such as Microsoft Azure, Google Cloud Platform (GCP), or Amazon Web Services (AWS).
  • Prior legal firm or professional services firm experience.
  • Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements.
Responsibilities:
  • Investigate Level 2 escalated events and alerts that have been detected through Level 1 monitoring activities by our Managed Security Service Provider (MSSP) to identify potential incidents.
  • Assist and advise junior colleagues during investigations where additional experience is required.
  • Conduct initial triage and investigation of confirmed incidents.
  • Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately throughout the process.
  • Participate in security incident response exercises and contribute to post-exercise reviews.
  • Be part of the Cyber Defence on-call rota, which may require out-of-hours work.
  • Pick up and hand off incident response activities with the rest of our Belfast Cyber Defence team and other teams in different time zones across the globe, as part of our 24-7 follow-the-sun global model.
  • Maintain and improve playbooks and process documentation for Cyber Defence.
  • Ensure documentation reflects current threat landscapes and operational practices.
  • Implement and enhance cyber defence tooling and processes under senior oversight.
  • Develop new detection definitions and use cases for monitoring tools.
  • Mentor junior colleagues to support their professional development and operational effectiveness.
  • Collaborate with other teams, such as Information Security and IT, to implement security controls and raise awareness.
  • Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes.
  • Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, and apply this knowledge in daily operations.
  • Provide cyber defence guidance to business stakeholders, translating technical concepts into business language.
  • Assist the Information Security GRC team with client queries and audits from a cyber defence perspective.
Technologies:
  • AWS
  • Azure
  • Cloud
  • GCP
  • Support
  • PowerShell
  • Python
  • REST
  • Security
  • TCP/IP
  • Web
More:

We have an exciting opportunity for a Senior Cyber Defence Analyst to join our Information Security team in Belfast. Weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. We operate a 24-7 follow-the-sun global model, with incident response activities handed off across time zones as needed.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defence Analyst
Cyber Defence Analyst

Cyber UK • Belfast

Hybrid
GBP 40,000 - 55,000
Occupational pension scheme
Private medical insurance
Health and wellbeing services
Cyber Defence Senior Analyst
Cyber Defence Senior Analyst

A&O Shearman • Belfast City District

On-site
GBP 70,000 - 110,000
Cyber Defence Analyst
Cyber Defence Analyst

A&O Shearman • Belfast City District

On-site
GBP 35,000 - 52,000
Senior Cyber Defence Analyst — 24/7 Global Security
Senior Cyber Defence Analyst — 24/7 Global Security

A&O Shearman • Donaghadee

On-site
GBP 45,000 - 73,000
Weekend premium
Cyber Security Analyst
Cyber Security Analyst

Thorntons Law LLP • Dundee

Hybrid
GBP 30,000 - 70,000
39 days annual leave
Pension scheme with salary exchange
Private medical insurance
+1
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Security Wizardry Radar Page • Corsham

Hybrid
GBP 55,000 - 75,000
Senior Cyber Defence Analyst - Incident Response Lead
Senior Cyber Defence Analyst - Incident Response Lead

A&O Shearman • Belfast City District

On-site
GBP 70,000 - 110,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ashurst Perkins Coie • Glasgow

Hybrid
GBP 65,000 - 90,000
Flexible work options - part-time, WFH
Health and wellbeing benefits, gym
Career advancement - learning & de
+1
Cyber Security Analyst
Cyber Security Analyst

Xpertise Recruitment • Northampton

On-site
GBP 42,000 - 50,000
Cyber Security Engineer
Cyber Security Engineer

VanRath • Belfast City District

Hybrid
GBP 50,000 - 65,000