Threat Specialist

Drweng

Greater London

On-site

GBP 60,000 - 85,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

DRW is seeking a Threat Specialist for our London office to join the Global Security Operations team. You will research and evaluate new security solutions, work with engineers, and help protect our digital assets across markets.

The role focuses on triage, incident response, threat detection creation, and tool administration. A background in security operations and scripting will help you succeed.

Qualifications

  • A bachelor’s degree, or equivalent experience for 1–3 years in industry.
  • Interest in digital forensics and physical security.
  • A passion for security and problem solving.
  • Heightened attention to detail and forward thinking.
  • Strong knowledge of Windows, MacOS, or Linux with willingness to learn others.
  • Knowledge of the Incident Response Cycle.
  • Knowledge of static & dynamic malware analysis, including network packet captures.
  • Knowledge of core networking & cloud security concepts.
  • Experience with Security Information and Event Management (SIEM) products.
  • Experience with Endpoint Detection & Response (EDR) products.
  • Experience with SOAR products.
  • Experience with data analysis of events in security sources such as IPS, Web Security, Endpoint Protection, Event Logs.
  • Experience working with GitHub.
  • Experience with PowerShell, Bash, Python, Ruby, or Perl.
  • Exceptional time management skills.
  • Excellent verbal and written communication skills.

Responsibilities

  • Triage global security alerts from IPS, Web Security, logs, EDR, and more.
  • Respond to identified incidents from analysis of alerts.
  • Triage and route internal security tickets.
  • Create and revise threat detections.
  • Perform SIEM product administration for event correlation and threat detection.
  • Manage SOAR playbooks and dashboards; administer tools.
  • Assist internal teams with insider threat investigations.
  • Drive automated detection, response, and configuration via scripting.
  • Evaluate commercial and open-source security tools as needed.
  • Collaborate with internal Infosec peers to improve security posture.
  • Contribute to internal documentation of standard processes & procedures.
  • Educate users on security best practices.
  • Assess security risks related to new projects and initiatives.
  • Attend security conferences and training to stay ahead.

Skills

Bachelor’s degree / experience
Security awareness
Attention to detail
Windows / MacOS / Linux
Incident response
Malware analysis
Networking & cloud security
SIEM
EDR
SOAR
Data analysis of security events
GitHub
PowerShell
Bash
Python / Ruby / Perl
Communication skills
Time management

Education

Bachelor’s degree or equivalent experience

Tools

SIEM products
EDR products
SOAR products
PowerShell
Bash
Python
GitHub

Job description

DRW is a diversified trading firm with over 3 decades of experience bringing sophisticated technology and exceptional people together to operate in markets around the world. We value autonomy and the ability to quickly pivot to capture opportunities, so we operate using our own capital and trading at our own risk.

DRW is headquartered in Chicago with offices throughout the U.S., Canada, Europe, and Asia, and we trade a variety of asset classes including Fixed Income, ETFs, Equities, FX, Commodities and Energy across all major global markets. We have also leveraged our expertise and technology to expand into three non-traditional strategies: real estate, venture capital and cryptoassets.

We operate with respect, curiosity and open minds. The people who thrive here share our belief that it’s not just what we do that matters–it's how we do it. DRW is a place of high expectations, integrity, innovation and a willingness to challenge consensus.

Our global Security Operations team is looking for a talented Threat Specialistto join the team in our London office. To flourish in this role, you will need a strong drive to learn and improve. When it comes to new technology, you’ll enjoy researching and evaluating new solutions using custom and commercial testing tools. You will be given the freedom and resources while being mentored by industry-leading engineers, all to provide you with the best possible environment to succeed at DRW.

How you will make an impact:
  • Perform triage of global security alerts generated from various sources (including IPS, Web Security, Event Logs, Endpoint Protection, Brand Protection, Phishing)
  • Respond to any incidents identified from analysis of security alerts
  • Triage & route internal support tickets sent to the Security team
  • Creation & revision of threat detections
  • Perform SIEM product administration for event correlation and threat detection
  • Perform SOAR playbook/dashboard management and product administration
  • Provide insider threat investigation assistance to teams of internal stakeholders
  • Drive automated detection, response, and configuration through various scripting and programming languages
  • Evaluate commercial and open-source tools as needed
  • Collaborate with internal Infosec peers to continuously improve security posture
  • Contribute to internal documentation of standard processes & procedures
  • Educate users on security best practices
  • Assess security risks as they relate to new projects and initiatives
  • Attend security conferences, seminars, and regular training to stay ahead of the ever-changing security landscape
What you bring to the team:
  • A bachelor’s degree, or equivalent experience for 1-3 years in industry
  • Interest in digital forensics and physical security
  • A passion for security and problem solving
  • Heightened attention to detail and forward thinking
  • Strong knowledge of either Windows, MacOS, or Linux with an interest in learning the details of platforms that you might not have experience with
  • Knowledge of the Incident Response Cycle
  • Knowledge of static & dynamic malware analysis, including network packet captures
  • Knowledge of core networking & cloud security concepts
  • Experience with Security Information and Event Management (SIEM) products
  • Experience with Endpoint Detection & Response (EDR) products
  • Experience with SOAR (Security Orchestration, Automation, and Response) products
  • Experience with data analysis of events in security related sources such as IPS, Web Security, Endpoint Protection, Event Logs
  • Experience working with GitHub
  • Experience with PowerShell, Bash, Python, Ruby, or Perl
  • Exceptional time management skills
  • Excellent verbal and written communication skills

For more information about DRW's processing activities and our use of job applicants' data, please view our Privacy Notice at https://drw.com/privacy-notice.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Specialist
Threat Specialist

DRW • City Of London

On-site
GBP 60,000 - 90,000
Threat Specialist
Threat Specialist

P2P • Greater London

On-site
GBP 65,000 - 90,000
Threat Detection & Incident Response Specialist
Threat Detection & Incident Response Specialist

DRW • City Of London

On-site
GBP 60,000 - 90,000
Threat Hunter & Incident Response Pro
Threat Hunter & Incident Response Pro

Drweng • Greater London

On-site
GBP 60,000 - 85,000
Threat Hunter & Incident Response Engineer
Threat Hunter & Incident Response Engineer

P2P • Greater London

On-site
GBP 65,000 - 90,000
Trading Systems Engineer, Cumberland Mining DRW · London, United Kingdom 2 weeks ago
Trading Systems Engineer, Cumberland Mining DRW · London, United Kingdom 2 weeks ago

Tradermath • Greater London

Hybrid
GBP 110,000 - 160,000
Developer Experience Engineer
Developer Experience Engineer

DRW • Greater London

Hybrid
GBP 90,000 - 130,000
Trading Systems Engineer, Cumberland Mining
Trading Systems Engineer, Cumberland Mining

DRW • Greater London

On-site
GBP 60,000 - 80,000
Trading Systems Engineer, Cumberland Mining
Trading Systems Engineer, Cumberland Mining

P2P • Greater London

On-site
GBP 60,000 - 80,000
Trading Systems Engineer: 24/7 Production & Automation
Trading Systems Engineer: 24/7 Production & Automation

P2P • Greater London

On-site
GBP 60,000 - 80,000