SIEM Analyst
The role you're considering The Cyber Delivery Team sits within a wider Managed Services function, residing in the Cloud Infrastructure Services (CIS) UK business line. You will have the opportunity to interact with our global team of security experts, from Architects to Engineers, Analysts to Compliance Managers. Outreach in CIS doesn’t just stop at security, as we actively encourage our staff to engage with other areas of the business and local communities. We are seeking a SOC Analyst with proven experience of delivery in a Security Operations Centre to join our cybersecurity team. The ideal candidate will protecting our clients' data and systems from cyber threats with robust security monitoring and incident response capabilities. This role requires you to be onsite 5 days per week in Warwick If you are successfully offered this position, you will go through a series of pre-employment checks, including: Identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service) Your role Embedded within an existing Customer SOC, you will work as part of a team with the customer’s SOC analysts and Capgemini SIEM engineers monitoring and responding to events through a SIEM platform. Other responsibilities include:
- Monitor and analyse security events and incidents using security tools.
- Develop and maintain security dashboards, alerts, and reports within the SIEM platform.
- Conduct threat hunting and forensic analysis to identify and mitigate potential security threats.
- Collaborate with IT and security teams to implement and improve security measures.
- Investigate and respond to security incidents, providing detailed analysis and recommendations.
- Analyse network traffic and logs to identify unusual patterns and potential threats.
- Proven experience as a Security Analyst, preferably with a focus on Elastic Security, Splunk and Sentinel.
- Experience with security information and event management (SIEM) systems.
- Familiarity with threat intelligence and incident response methodologies.
- Excellent analytical and problem-solving skills.
- Strong communication and teamwork abilities.
- Relevant certifications (e.g., Comptia SySA +, CISSP, Elastic Certified) are a plus but not essential
- Declare they have a disability, and
- Meet the minimum essential criteria for the role.