Airbus - Cyber Security Analyst L1
**Job Description:** An exciting opportunity for a *Cyber Security 1st line Analyst* has arisen within *Airbus Protect in Newport, South Wales* . This is a new position because of the expansion of the Security Operations Centre and will report directly to the Continuous Monitoring Team Lead under the guidance of the SOC Manager. The role covers internal and external clients and requires working closely with other departments such as our customers SPOCs, Airbus Design and Implementation Engineering, Network Operations, Service Delivery and Service Design Teams. Airbus Protect is looking for someone with 0-2 years of experience in a Cyber Analyst role. They need to be keen and enthusiastic to learn. Training will be provided, where appropriate covering a wide range of 1st Line SOC skills.
- *Tasks and responsibilities:**
- *Security Monitoring:* Continuously monitor alerts and events through Splunk, Cortex EDR, and other SOC platforms to identify potential security incidents.
- *Incident Triage:* Perform initial analysis, investigation, and prioritization of security events to determine the severity and potential impact.
- *Threat Detection:* Identify false positives, escalate confirmed incidents to L2 analysts, and assist with remediation efforts as necessary.
- *Tool Management:* Gain familiarity with and optimize tools (Splunk, Cortex EDR .e.g.) dashboards to enhance incident detection and reporting.
- *Incident Handling:* Support the incident response process, including documenting cases, contributing to post-incident reviews, and ensuring all incidents are tracked and resolved.
- *Threat Hunting (Future Growth):* Assist and eventually participate in proactive threat hunting activities to identify and mitigate potential threats.
- *Use Case Development:* Collaborate with the SOC team to develop and improve detection use cases based on emerging threats and organizational needs.
- *Reporting: * Assist in producing weekly, monthly or quarterly reports for customers, and technical demonstrations within the SOC.
- Carry out IOC searches and react using the predefined playbooks
- *Are you THE one **
- We need someone who has/is: *
- Complete work within the time-frames provided
- Experience working in high pressure environments
- Cyber technical background would be useful but not essential
- Networking knowledge would be advantageous, but not essential
- Cyber Security knowledge would be advantageous
- People around you define you as an open-minded and dynamic person.
- Adaptability
- Well-organised
- Team spirit, autonomy and good communication skills
- Proactivity
- Innovation
- *What’s in it for you...**
- * Joining Airbus Protect with : *
- A close and caring management,
- A pipeline of innovative projects,
- A community of recognised experts,
- Great career paths and training opportunities,
- * Great benefits: *
- 25 days holiday
- Option to purchase holidays
- Generous pension scheme
- Eligibility to a Company profit sharing scheme
- Share options
- Access to a benefits platform offering car leasing, family health plans, dental plan, shopping discounts and much more ...
- *Join the AIRBUS PROTECT journey, we are waiting for you!**
- *Passionate about Cyber Security, SIEM, EDR, Cloud, TTPs and have a Cyber related degree**
- *#JobAPUK**