Cyber Data Scientist
Cyber Data Scientist
London, Docklands (hybrid - 2 days in office)
Up to £110,000 per annum + annual discretionary bonus
On behalf of a market leading financial services client, I am seeking an experienced Cyber Data Scientist to join a global threat intelligence team. The position will report to the Head of Cyber Threat Intelligence and will involve applying advanced statistical analysis, machine learning, and data engineering to identify, detect, and mitigate digital threats.
The ideal candidate will be aware of industry trends and frameworks and how they could impact their business, including threat actor groups, their TTPs, intrusion activities. The candidate will work in support of the Cyber Security Operations, Cyber Threat Intelligence, and Threat Hunting teams.
The client offers this role on a hybrid working basis with a non-negotiable two days per week in their London office.
Responsibilities:
- Develop and implement machine learning models (ie anomaly detection, classification) to identify patterns indicating malicious activity, malware, or insider threats
- Clean normalise, and manage massive datasets from disparate security systems (SIEM, Firewalls, endpoints) to make them usable for analysis
- Analyse historical security data and external threat intelligence to forecast potential attack vectors
- Present complex technical findings via dashboards to non-technical stakeholders
- Work with CTI analysts to produce reports for both executive and technical stakeholders and be able to brief all stakeholders.
- Develop and maintain clear documentation of activities, findings, and lessons learned
- Assess emerging threats against our operational environment and work in partnership with our security teams for detection, mitigation, and remediation efforts
- Perform trend and correlation of cyber intelligence for recommendation-based countermeasures
- Support and engage in incident response investigations
- Review other analysts work and provide mentorship and guidance
Experience/Skills required:
- 5+ years of direct cybersecurity related data scientist experience
- 5+ years of progressive experience in information security (cyber security) field, preferable in Security Operations or Incident Response roles
- Understanding of intelligence life cycle and risk management
- Experience of working within a regulated financial services environment is extremely advantageous.
- Knowledge of fundamentals of threat actors' TTP
- Understanding of IOC validation practices and sources
- Familiarity with MITRE ATT&CK framework and mapping
- Excellent interpersonal and relationship management skills
- Individual contributor whilst also contributing to a small team
- Security certification such as SANS GIAC (or equivalent) ideally GMLE or CERT Applied Data Science for Cybersecurity Professional, or working towards certification (or equivalent), CISSP and Security+
- Experience with threat intelligence and SOC/CIRT interaction.