SC Cleared Security Analyst
The Role:
- Triage and investigate cyber security alerts and reports from users
- Use a variety of techniques to analyse systems, files, network traffic and cloud environments and understand the nature and extent of possible cyber incidents
- Support the technical response to cyber incidents by identifying and implementing (or supporting the implementation of) containment, eradication and recovery actions
- Support the coordination of cyber incidents
- Contribute to post-incident reviews to identify lessons and actions
- Identify opportunities for, and support the delivery of, continual improvements to the incident investigation and response capability
- Work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities
- Contribute to internal plans, playbooks and knowledge base articles
- Act as an escalation point for, and provide coaching and mentoring to, apprentice security analysts
- Be responsible for line management of apprentice security analysts
- Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join.
Skills Required:
- 3 years' experience working as a Cyber Security Analyst.
- Experience investigating and responding to cyber incidents.
- Knowledge of security tools (eg EDR, SIEM) to support the investigation and response to cyber incidents.
- Experience working with Splunk
- Experience of M365 (MS Defender/Sentinel/KQL)
- Experience with cloud environment such as AWS
This work has been determined as falling inside IR35.