Company Description
Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success. Our deep expertise enables our customers to navigate the rapidly evolving technology landscape. We foster strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake, ensuring that our customers are provided with the highest quality solutions and services.
Company Description
Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success. Our deep expertise enables our customers to navigate the rapidly evolving technology landscape. We foster strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake, ensuring that our customers are provided with the highest quality solutions and services.
Job Description
We are seeking an experienced Senior Cyber Security Operations Analyst to join our team. The ideal candidate will have a strong background in cloud security, incident response, and vulnerability management. Working with greater independence than an analyst, you will take ownership of complex investigations, drive improvements to security processes, and support the development of those around you — without being a team lead.
Key Responsibilities
Incident Response
- Own and lead complex incident response investigations end-to-end, from detection through to post-incident review, without direct supervision.
- Investigate security breaches and provide detailed reports on findings and recommendations.
- Coordinate with IT teams to ensure timely resolution of security incidents, acting as a point of escalation for complex or ambiguous events.
- Participate in and help plan regular Audits, Tabletops, and Purple Team exercises; share lessons learned with the team.
- Perform alert triage and severity assessment on incoming security alerts from multiple sources.
- Investigate phishing incidents including email header analysis, sender verification, and payload identification; coordinate remediation.
- Conduct data exfiltration investigations: scope of compromise, affected data identification, business impact assessment, and containment coordination.
- Perform endpoint forensics including process analysis, malware identification, timeline reconstruction, and evidence collection.
- Document findings with detailed incident timelines and evidence preservation for audit compliance.
- Execute containment actions and coordinate with IT teams.
- Participate in the Cyber Security on-call rota, providing out-of-hours support for security incidents, critical alerts, and escalations.
General Responsibilities
- Stay up-to-date with the latest security trends, threats, and technologies; proactively share insights with the team.
- Provide technical advice and support to other departments on security-related matters.
- Mentor and support junior analysts, sharing knowledge and helping them grow.
- Identify gaps in security processes and take ownership of improving them.
- Conduct training sessions to educate staff on security best practices.
- Prepare and deliver comprehensive reports on security assessments and incident responses.
- Manage and maintain security tooling and infrastructure e.g. Defender XDR, DLP, security configuration management tools.
- Coordinate with internal teams and external parties to resolve incidents and track remediation.
Cloud Security
- Evaluate and implement cloud security solutions to protect against breaches and data loss.
- Lead risk assessments and security audits for cloud environments; own the output and follow-through.
- Develop and maintain cloud security policies and procedures, identifying gaps and driving resolution.
Qualifications
Beneficial Qualifications
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- 5+ years of experience in cybersecurity, with a focus on cloud security, incident response, and vulnerability management.
- Relevant certifications such as CompTIA Security+, Blue Team Level 1 (BTL1), GIAC Certified Incident Handler (GCIH) or GIAC Security Operations Certified (GSOC).
- Strong understanding of cybersecurity frameworks, standards and regulations (e.g., NIST, ISO 27001, Cyber Essentials, GDPR).
Preferred Skills
- Experience with cloud platforms such as Azure, AWS and various SaaS products.
- Knowledge of scripting languages (e.g., Python, PowerShell) for automation.
- Experience with security tools such as SIEM, IDS/IPS, and vulnerability scanners; able to develop and tune detection rules independently.
- Excellent problem-solving skills and attention to detail; targets results, accepts accountability, and pushes through obstacles.
- Hands-on experience with Defender Endpoint and endpoint detection and response (EDR) tools.
- Experience with endpoint management and