Technology Department - Junior Blue Team Analyst

CACI Limited

Greater London

Hybrid

GBP 26,000 - 38,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

CACI Limited is seeking a Junior Blue Team Analyst to join the Infrastructure Cloud & Security Team within the Technology department in the UK. The role focuses on monitoring, triage and investigation across cloud, network and identity platforms, supporting incident response and maintaining security documentation.

The successful candidates will develop hands-on skills in SIEM technologies, vulnerability management and cloud security practices, working closely with infrastructure and security

Qualifications

  • Demonstrable interest in cybersecurity through study, projects or work experience.
  • Understanding of Windows and Active Directory.
  • Basic Linux understanding and networking basics.

Responsibilities

  • Monitor security alerts and events from Microsoft Sentinel and other security tools.
  • Perform initial triage of security incidents and escalate as needed.
  • Investigate suspicious activity across cloud, network, endpoint and identity platforms.
  • Support security incident response and evidence gathering activities.
  • Document security incidents, findings and lessons learned.

Skills

Windows
Active Directory
Networking fundamentals
Cybersecurity concepts
Cloud concepts (AWS/Azure)
MFA & access control
Log analysis
SIEM basics
Communication skills

Education

Bachelor's degree or equivalent

Tools

Microsoft Sentinel
PowerShell
Python
AWS
Azure
Check Point
Cisco

Job description

About the role

CACI is looking for a Junior Blue Team Analyst to join the Infrastructure Cloud & Security Team in the Technology department, which is CACI’s central IT team.


Key responsibilities

Security Monitoring & Incident Detection Security Monitoring & Incident Detection


  • Monitor security alerts and events from Microsoft Sentinel and other security tools.

  • Perform initial triage of security incidents and escal...

  • Investigate suspicious activity across cloud, network, endpoint and identity platforms.

  • Support security incident response and evidence gathering activities.

  • Document security incidents, findings and lessons learned.


Threat Detection & Analysis


  • Review logs from AWS, Azure, Windows, Linux, Check Point and Cisco platforms.

  • Assist in identifying indicators of compromise and malicious behaviour.

  • Support development and tuning of SIEM detection rules and alerting.

  • Contribute to threat hunting exercises and security investigations.


Vulnerability Management


  • Assist with vulnerability scanning and remediation tracking.

  • Validate remediation activities completed by infrastructure teams.

  • Help identify recurring security weaknesses and improvement opportunities.

  • Produce reports on vulnerability trends and remediation progress.


Cloud Security


  • Support monitoring of AWS and Azure security controls.

  • Review security findings from native cloud security services.

  • Assist with implementation of security best practices for cloud workloads.

  • Help maintain secure configurations and access controls.


Security Operations


  • Assist with identity and access management reviews.

  • Support privileged access monitoring and auditing activities.

  • Help maintain security documentation, standards and procedures.

  • Participate in security testing activities and support remediation efforts.


Compliance & Governance


  • Assist in maintaining ISO27001 policies, procedures and evidence.

  • Support internal and external audits.

  • Help maintain asset inventories and security records.

  • Contribute to risk assessments and security reviews.


Collaboration


  • Work closely with infrastructure, cloud, networking and support teams.

  • Provide security guidance to colleagues where appropriate.

  • Participate in security awareness and continuous improvement initiatives.


Skills & experience

Essential Skills & Experience

Technical Knowledge


  • Good understanding of Windows and Active Directory.

  • Basic understanding of Linux administration.

  • Understanding of networking fundamentals including TCP/IP, routing, DNS, VPNs and firewalls.

  • Understanding of common cybersecurity concepts, threats and attack techniques.

  • Familiarity with cloud concepts in AWS and/or Azure.

  • Understanding of authentication, MFA and access control principles.


Security Operations


  • Experience using or studying SIEM platforms such as Microsoft Sentinel.

  • Understanding of security monitoring and incident management processes.

  • Ability to analyse logs and investigate alerts.

  • Awareness of vulnerability management practices.


Analytical Skills


  • Strong troubleshooting and problem-solving skills.

  • Ability to investigate issues methodically.

  • Good attention to detail.

  • Ability to document findings clearly.


Behavioural Skills


  • Desire to build a career in cybersecurity.

  • Strong communication and interpersonal skills.

  • Ability to work as part of a team.

  • Customer-focused approach.

  • Willingness to learn new technologies and security techniques.


Desirable Skills & Experience


  • Experience with Microsoft Sentinel.

  • Exposure to AWS security services.

  • Exposure to Azure security services.

  • Experience with Check Point firewalls.

  • Experience with Cisco networking technologies.

  • Experience working in an ISO27001 environment.

  • Experience with PowerShell, Python or scripting.

  • Knowledge of MITRE ATT&CK.

  • Knowledge of threat hunting methodologies.

  • Experience with security tooling such as Defender, EDR, vulnerability scanners or email security platforms.


Qualifications

Essential


  • Demonstrable interest in cybersecurity through study, projects or work experience.


Desirable


  • Security+

  • SC-200 (Microsoft Security Operations Analyst)

  • SC-900 (Microsoft Security, Compliance and Identity Fundamentals)

  • AWS Cloud Practitioner

  • Azure Fundamentals (AZ-900)

  • ISC2 CC/SSCP

  • Related degree or other qualifications


Equal Opportunities:

CACI is proud to be an equal opportunities employer. Embracing the diversity of our people, we are on a journey to build a truly inclusive work environment where no one is treated less favourably due to ethnic origin, age, sex, gender identity, veteran status, religion or belief, sexual orientation, marital status, and disability or health condition, actively working to prevent discrimination.


AsaDisabilityConfidentemployer,wewill;



  • Provide reasonable adjustments in the recruitment process where requested (contact a member of the recruitment team on 020 7602 6000 to discuss individual requirements further)

  • Offerpeoplewithhealthconditionsanddisabilities,meetingtheminimumcriteriaforaroleaninterview.



  • Our people are unique and we encourage and support them to be confident in contributing to our inclusion journey.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technology Department - Infrastructure, Cloud & Security Engineer
Technology Department - Infrastructure, Cloud & Security Engineer

CACI Digital Experience (formerly Cyber-Duck) • Greater London

On-site
GBP 25,000 - 42,000
Technology Department - Infrastructure, Cloud & Security Engineer
Technology Department - Infrastructure, Cloud & Security Engineer

CACI Ltd • Greater London

On-site
GBP 26,000 - 34,000
Technology Department - Infrastructure, Cloud & Security Engineer
Technology Department - Infrastructure, Cloud & Security Engineer

CACI Limited • Greater London

Hybrid
GBP 28,000 - 36,000
Senior Security Operations Centre Analyst
Senior Security Operations Centre Analyst

Sopra Steria • Farnborough

On-site
GBP 52,000 - 64,000
25 days annual leave
Health cash plan
Life assurance
+2
Senior Security Consultant
Senior Security Consultant

ITC Secure • Greater London

Hybrid
GBP 70,000 - 90,000
25 days annual leave
Private health insurance
Enhanced maternity and paternity leave
+2
Security Analyst
Security Analyst

Doherty Associates • City Of London

On-site
GBP 35,000 - 52,000
Performance bonus
34 days annual leave
Private medical insurance
+2
Security Operations Technician
Security Operations Technician

CMS Distribution • Castleford

Hybrid
GBP 42,000 - 62,000
Cyber Security Engineer
Cyber Security Engineer

Jobtailor • Greater London

Hybrid
GBP 70,000 - 110,000
Security Analyst
Security Analyst

Doherty Associates • Greater London

On-site
GBP 30,000 - 42,000
34 days annual leave
Private medical insurance
Company Pension
+1
Cyber Security Analyst
Cyber Security Analyst

Novia Financial plc • Bath

On-site
GBP 55,000 - 75,000