Enable job alerts via email!

Front Line Analyst – National Security – Leeds

BAE Systems

Leeds

Hybrid

GBP 40,000 - 60,000

Full time

12 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company specializing in digital intelligence is seeking a Front Line Analyst to enhance cybersecurity measures. This role involves monitoring for intrusions, conducting threat analysis, and mentoring junior analysts. Candidates should possess relevant experience and certifications in cyber security, particularly in intrusion analysis and threat hunting. We promote a flexible working environment, embracing diversity and collaboration.

Qualifications

  • Knowledge of intrusion analysis on Windows devices and servers.
  • Experience with Azure cloud services and attack methods.
  • Relevant security certifications (SANS, CompTIA) desired.

Responsibilities

  • Conduct cybersecurity monitoring to detect hacking and malware attempts.
  • Create and maintain SIEM/SOAR playbooks adapting to evolving threats.
  • Lead threat hunting workgroups and deliver training to teams.

Skills

Intrusion analysis
Cybersecurity monitoring
Networking concepts
Threat hunting
SIEM/SOAR practices

Education

Degree in Cyber Security or related field
Certifications like CompTIA Network+, Security+
SANS GCIH, GCIA or similar certifications

Tools

Microsoft Graph API
Azure
AWS Cloud Essentials

Job description

Location(s): UK, Europe & Africa: UK: Leeds

BAE Systems Digital Intelligence is home to 4,500 digital, cyber, and intelligence experts. We work across 10 countries to collect, connect, and understand complex data, enabling governments, armed forces, and commercial businesses to unlock digital advantages in demanding environments.

Job Title: Front Line Analyst

Requisition ID: 121791

Location: Leeds – We offer hybrid and flexible working arrangements. Please discuss options with your recruiter.

Grade: GG08

Referral Bonus: £2,000

Job Description
  • Conduct cybersecurity monitoring to detect hacking/malware intrusion attempts against customer IT systems.
  • Triaging detection alarms to identify causes such as active infections, intrusion attempts, or false positives.
  • Identify and document attack sources, techniques, tactics, and procedures (TTPs), and assess attack scope.
  • Document attack chain details and update detection capabilities accordingly.
  • Maintain monitoring effectiveness by creating and updating SIEM/SOAR playbooks, adapting to evolving TTPs.
  • Use intrusion analysis skills to contribute to new detection techniques and research industry capabilities.
  • Coordinate with government or commercial security operation centers for root cause analysis.
  • Create KQL analytics and hunt queries, conduct IOC and anomaly-based threat hunts.
  • Identify and tag incorrect alert logic or high false positive detection rules for review.
  • Transform internal and partner threat intelligence into actionable detections.
  • Coach junior analysts and colleagues as needed.
  • Lead threat hunting workgroups during complex TTPs across industries.
  • Deliver training and workshops to promote security awareness and knowledge sharing.
  • Provide daily SITREPs on attacker activity.
Experience
  • Knowledge of intrusion analysis on Windows devices and servers.
  • Experience with intrusion analysis in Azure, including attacker methods like ‘living off the cloud’ (e.g., Microsoft Graph API, app registrations, managed identities).
  • Ability to research and learn new tools and techniques quickly.
  • Good working knowledge of MITRE ATT&CK framework.
  • Understanding of networking concepts and protocols (TCP/IP, UDP, DNS, DHCP, HTTP).
  • Experience with intrusion analysis on Windows and Azure cloud architecture.
  • Relevant certifications such as SANS GCIH, GCIA, or similar.
  • Understanding of operating system functionalities.
  • Develop hypotheses and perform threat hunting in Azure cloud or Windows device data.
Desirable Qualifications
  • Degree in Cyber Security or related field.
  • Certifications like CompTIA Network+, Security+, CREST (Intrusion Analyst, Cyber Threat Intelligence), Azure (AZ900, SC200, SC900), AWS Cloud Essentials.
  • SANS GCIH, GCIA, or similar certifications.
Life at BAE Systems Digital Intelligence

We embrace hybrid working, allowing flexibility in when and where you work, including from home, offices, or client sites. We foster a culture of diversity and inclusion, encouraging employees of varied backgrounds and perspectives to collaborate and achieve excellence.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Front Line Analyst - National Security - Leeds

Babcock

Leeds

Hybrid

GBP 35,000 - 50,000

10 days ago

Front Line Analyst – National Security – Leeds

BAE Systems (New)

Leeds

Hybrid

GBP 40,000 - 55,000

12 days ago