Security Operations Analyst
Title: Security Operations Analyst
Type: Contract | ASAP START - 31/03/2027
Day Rate: £537.49 (Umbrella Equivalent Rate)
Location: Remote
MUST HAVE SC - SECURITY CLEARANCE!
Our client a seeking a Security Operations Analyst to join their security team on an IMPORTANT Project!
Note: This role requires an approximately 1-week month on-call availability for high priority incident response. Please note there is additional compensation for this, and the frequency is client dependent.
Responsibilities
- Detection engineering - Develop, maintain, and enhance security detection content primarily for the Splunk SIEM, to enable the detection of threats across diverse platforms (e.g. cloud, endpoints, and networks)
- Collaborate with the extended security team to identify gaps in detection coverage, log ingestion and alerting based on business risks and threats
- Review and improve existing SecOps standards and capabilities e.g. by highlighting requirements for additional logging, identifying incident or threat trends and detection and business-as-usual optimisation opportunities
- Perform security monitoring, reviewing and triaging triggered alerts, and suggesting improvements (on a rota basis 9AM to 5:30PM)
- Respond to and investigate identified cyber security incidents
- Act as a point of escalation for junior analysts, supporting them through mentorship and shadowing
- Operate as a technical subject matter expert on client engagements and be prepared to interact with, and present to, senior stakeholders in a consulting capacity
- Participate in alert testing and incident response tabletop exercises as required
- Remain up to date with latest threat intelligence which may be of interest to our clients
- Additional responsibilities may include (client dependent):Proactive threat hunting and tradecraft development
- Incident response and playbook development Change approvals (where applicable)
- Collection and interpretation of different sources of threat intelligence and researching emerging threats and TTPs.
- Vulnerability scanning, management and reporting
Desirable Attribute s
- Working knowledge of key threat intelligence concepts such as the Pyramid of Pain, Intelligence Preparation for the Cyber Environment (IPCE), and the Threat Intelligence Lifecycle
- Detection Engineering and Alert Development
- Experience with Scripting and Programming – e.g. Python/Bash/c/c++/JavaCore cybersecurity concepts such as network security, cryptography, cloud security, forensics
- Understanding of network protocols and how they can be abused by attackers
- Up to date knowledge of the most prevalent APTs and their TTPs.
- Knowledge of common analysis techniques associated with Windows and/or Linux