Enable job alerts via email!

Cyber Security Playbook Developer - SOC - Splunk/Elastic Search/Python

Scope AT Limited

United Kingdom

On-site

GBP 50,000 - 70,000

Full time

Today
Be an early applicant

Job summary

A leading cybersecurity firm in the United Kingdom is seeking a Cyber Security Playbook Developer to support the incident response team. The role requires hands-on experience with improving cyber-security detection and response capabilities. Key skills include Unix/Linux command-line expertise, Shell scripting, and Python. The position involves developing analytics in Splunk and Elastic Search to ensure SOC infrastructure security and efficiency.

Qualifications

  • Must have hands-on experience focused on improving the coverage, quality and automation of cyber-security detection and response capabilities.
  • Experience with Unix/Linux at the command-line and scripting languages (Shell, Python).

Responsibilities

  • Runbook automation to improve efficiency of the SOC.
  • Develop analytics in Splunk/Elastic Search to detect actionable security alerts.
  • Ensure security and stability of SOC infrastructure.
  • Collaborate with the incident response team to enhance capabilities.

Skills

Hands-on experience improving coverage
Unix/Linux command-line
Shell Scripting
Python skills
Developing detection analytics

Tools

Splunk
Elastic Search
Job description
Overview

Cyber Security Playbook Developer, supporting the incident response team within the Security Operations Center. Must have hands-on experience focused on improving the coverage, quality and automation of cyber-security detection and response capabilities within the SOC. The role is responsible for Runbook automation to improve efficiency of the SOC, develop analytics in Splunk/Elastic Search to detect actionable security alerts, to ensure security and stability of SOC infrastructure. Must have experience working with Unix/Linux at the command-line and Shell Scripting/Python skills.

Responsibilities
  • Runbook automation to improve efficiency of the SOC.
  • Develop analytics in Splunk/Elastic Search to detect actionable security alerts.
  • Ensure security and stability of SOC infrastructure.
  • Collaborate with the incident response team to enhance detection, response, and automation capabilities.
Qualifications
  • Hands-on experience improving coverage, quality, and automation of cyber-security detection and response within a Security Operations Center.
  • Experience with Unix/Linux command-line and scripting languages (Shell, Python).
  • Experience developing and maintaining detection analytics and runbooks in a security operations context.
Privacy and Notices

By applying to this job you are sending us your CV, which may contain personal information. Please refer to our Privacy Notice to understand how we process this information. In short, in order to supply you with work finding services, we will hold and process your personal data, and only with your express permission we will share this personal data with a client (or a third party working on behalf of the client) by email or by upload to the Client/third parties vendor management system. By giving us permission to send your CV to a client, this constitutes permission to share the personal data that would be necessary to consider your application, interview you (Phone/video/face to face) and if successful hire you. Scope AT acts as an employment agency for Permanent Recruitment and an employment business for the supply of temporary workers. By applying for this job you accept the Terms and Conditions, Data Protection Policy, Privacy Notice and Disclaimers which can be found at our website

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.