Loughton, Essex, South East, United Kingdom Hybrid / WFH Options
Profile 29
software delivery lifecycle. A key part of this position will also involve mentoring an internal engineer, developing structured security policies, and managing Sentinel, Defender and SOAR solutions for automated threat response. Additionally, the role requires liaising with third-party support partners to coordinate security solutions, manage incidents, and enhance overall cybersecurity posture. Responsibilities Infrastructure Security: Architect and secure Azure … and optimize Azure DevOps pipelines with security embedded at every stage. Cloud Security Implementation: Leverage Azure Security Centre, Microsoft Defender for Cloud, and Microsoft Sentinel for advanced security monitoring. Threat Detection & SOAR Automation: Oversee Security Orchestration, Automation, and Response (SOAR) solutions including SOC Prime. Network & Application Security: Manage Web Application Firewalls (WAF) and Intrusion Prevention Systems (IPS). Vulnerability … cyber threats. Incident Response: Formulating and documenting a solid process utilising a 3rd party support partner Security Monitoring & Logging: Develop SIEM solutions, logging strategies, and real-time threat intelligence. Monitor, audit, and improve infrastructure security posture using automated tooling. Policy & Procedures: Define and enforce security policies, incident response strategies, and structured action plans for proactive risk mitigation. More ❯
Nottingham, Nottinghamshire, East Midlands, United Kingdom Hybrid / WFH Options
Experian Ltd
Exchange (EXPN), we have a team of 22,500 people across 32 countries. Our corporate headquarters are in Dublin, Ireland. Learn more at experianplc.com. Job Description As a Cyber Defence Analyst, you will join the Cyber Fusion Center, performing in-depth analysis, assessment, and response to security threats by following documented policies to meet Service Level … ensuring the handling of potential threats and plays a part in improving security operations. This is a home based role reporting to the Director of Security Operations for SecOps & Threat Detection. Please note that in this role, you will have an 8x5 Monday-Friday schedule, with flexibility to respond to after-hours pages for potentially major security incidents to … support incident response efforts and may include assignment to an on-call rotation for evenings, weekends, holidays. Summary of Primary Responsibilities As the Cyber Defence Analyst, you will: Contribute to daily security operations by overseeing response activities for security events and alerts associated with cyberthreats, intrusions, and compromises alongside a team of global security analysts More ❯
to join our dynamic and growing team. The successful candidate will play a crucial role in supporting management with securing our organization's infrastructure, systems, and data against cyber threats. As a Security Engineer, you will be responsible for supporting the security team with designing, innovating, deploying, and maintaining security measures to safeguard our information assets. We operate … to join our dynamic and growing team. The successful candidate will play a crucial role in supporting management with securing our organization's infrastructure, systems, and data against cyber threats. As a Security Engineer, you will be responsible for supporting the security team with designing, innovating, deploying, and maintaining security measures to safeguard our information assets. We operate … Must have skills and experience : At least 3 years of hands-on, proven industry experience in a similar role. Good understanding of security principles, technologies, and best practices, including threat detection and mitigation strategies. Good level of knowledge of cloud security: AWS and Azure. Experience ensuring data confidentiality, integrity, and availability throughout its lifecycle, including during transmission, storage, and More ❯
Cambridge, Cambridgeshire, United Kingdom Hybrid / WFH Options
Arm Limited
and SIEM detections to improve the CDO's efficiency, scalability, and incident response capabilities. Design, implement, and maintain automated workflows and playbooks to streamline CDO operations, including incident response, threat hunting, cyberthreat intelligence and vulnerability management. Collaborate with CDO analysts to identify repetitive tasks and automate them to improve operational efficiency. Collaborate with ThreatMore ❯
Purpose of the role: To monitor the performance of operational controls, implement and manage security controls and consider lessons learnt in order to protect the bank from potential cyber-attacks and respond to threats. Accountabilities: * Management of security monitoring systems, including intrusive prevention and detection systems, to alert, detect and block potential cyber security incidents, and … Senior Cyber Operations Analyst you will need the following: * Proficiency in SIEM technologies including Splunk * Proactively search for potential threats using behavioural analytics, network traffic analysis, and threat intelligence. * Incident response skills, including proficiency in PCAP capture, network analysis, and traffic pattern recognition. * Knowledge of attack techniques (MITRE ATT&CK framework, malware analysis, and intrusion detection). … technical levels, depending on the audience. Some other highly valued skills may include: * A solid technical understanding of threats against the financial industry across physical and cyberthreat domains. * Proficiency in operating system fundamentals and security (Windows & Linux). * Expertise in networking principles, protocols, and practices. * Familiarity with traditional ITIL concepts, including incident, change, and problem management. More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
LA International Computer Consultants Ltd
swift, effective responses to minimize risk to the organization and its clients. Key Responsibilities: 1. Incident Detection and Response: o Utilize advanced SIEM (Security Information and Event Management) tools, threat intelligence platforms, and other security technologies to analyze and correlate security alerts. 2. Threat Hunting & Analysis: o Proactively search for threats across the environment using behavioural analysis and … threat intelligence data. o Analyse data from logs, network traffic, endpoint activities, and threat intelligence feeds to detect unusual or malicious activity. 3. Incident Forensics: o Perform in-depth forensic analysis to determine the scope, impact, and root cause of security incidents. o Collect, preserve, and analyze evidence related to breaches, intrusions, or malware infections while adhering to … legal and regulatory requirements 4. Remediation and Recovery: o Collaborate with threat intelligence teams to identify indicators of compromise (IOCs) and ensure proper actions are taken to block further attacks. 5. Compliance and Risk Management: o Ensure all incident response activities align with industry standards, regulations, and best practices (e.g., NIST, ISO 27001, GDPR, HIPAA). o Work with More ❯
Ashford, Kent, United Kingdom Hybrid / WFH Options
MAF Australia
charity work? In this role, you'll be responsible for implementing and managing security infrastructure, responding to threats, and ensuring compliance across systems. You'll work with various cyber security solutions while driving security best practices and incident response. If you have experience in cybersecurity tools, governance, and access management-and want to use your skills to support … ll lead the implementation and management of SIEM systems, Fortinet security tools, and endpoint detection & response (EDR) while conducting vulnerability assessments and penetration testing to stay ahead of cyber threats. You'll enhance identity and access management (IAM) by maintaining Active Directory, Entra ID, MFA, and Zero Trust security principles. Your expertise in network security, VPNs, SD-WAN … Demonstrated experience with SIEM implementation and management Strong background in network security and infrastructure protection Experience with IDS/IPS systems and security monitoring tools Proven incident response and threat hunting experience Programming/scripting skills for security automation Microsoft 365 Security Administration certification Cloud security certifications (Azure Security Engineer, AWS Security) Fortinet NSE certification (Level 7 or More ❯
Ashford, Kent, United Kingdom Hybrid / WFH Options
UNAVAILABLE
charity work? In this role, you'll be responsible for implementing and managing security infrastructure, responding to threats, and ensuring compliance across systems. You'll work with various cyber security solutions while driving security best practices and incident response. If you have experience in cybersecurity tools, governance, and access management-and want to use your skills to support … ll lead the implementation and management of SIEM systems, Fortinet security tools, and endpoint detection & response (EDR) while conducting vulnerability assessments and penetration testing to stay ahead of cyber threats. You'll enhance identity and access management (IAM) by maintaining Active Directory, Entra ID, MFA, and Zero Trust security principles. Your expertise in network security, VPNs, SD-WAN … Demonstrated experience with SIEM implementation and management Strong background in network security and infrastructure protection Experience with IDS/IPS systems and security monitoring tools Proven incident response and threat hunting experience Programming/scripting skills for security automation Desirable: Microsoft 365 Security Administration certification Cloud security certifications (Azure Security Engineer, AWS Security) Fortinet NSE certification (Level 7 or More ❯
charity work? In this role, you'll be responsible for implementing and managing security infrastructure, responding to threats, and ensuring compliance across systems. You'll work with various cyber security solutions while driving security best practices and incident response. If you have experience in cybersecurity tools, governance, and access management-and want to use your skills to support … ll lead the implementation and management of SIEM systems, Fortinet security tools, and endpoint detection & response (EDR) while conducting vulnerability assessments and penetration testing to stay ahead of cyber threats. You'll enhance identity and access management (IAM) by maintaining Active Directory, Entra ID, MFA, and Zero Trust security principles. Your expertise in network security, VPNs, SD-WAN … Demonstrated experience with SIEM implementation and management Strong background in network security and infrastructure protection Experience with IDS/IPS systems and security monitoring tools Proven incident response and threat hunting experience Programming/scripting skills for security automation Desirable: Microsoft 365 Security Administration certification Cloud security certifications (Azure Security Engineer, AWS Security) Fortinet NSE certification (Level 7 or More ❯
Gosport, Hampshire, South East, United Kingdom Hybrid / WFH Options
Walsh Employment
plan, life assurance, pension scheme, and a generous flexible benefits fund Key Requirements We are seeking an experienced Senior SOC Analyst who brings a strong background in security operations , threat detection, and incident response. This is a critical role that supports the defence of national infrastructure through proactive monitoring, analysis, and improvement of cybersecurity postures. Essential Skills and Experience … on expertise with SIEM tools such as Microsoft Sentinel and Splunk Solid understanding of network protocols and infrastructure (e.g. TCP/IP , VPNs , firewalls ) Skilled in incident response and threat intelligence analysis Familiarity with Mitre Att&ck framework and advanced threat detection techniques Excellent analytical and problem-solving capabilities Able to provide mentorship and leadership within a SOC … will include: Analysing security incidents using advanced SIEM platforms ( Microsoft Sentinel , Splunk ) Leading incident response and driving improvements in detection and containment strategies Tuning and maintaining detection rules, using threat frameworks like Mitre Att&ck Collaborating with colleagues to enhance the overall capability and resilience of the Security Operations Centre Staying abreast of cyberthreat developments More ❯
Warwick, Warwickshire, West Midlands, United Kingdom Hybrid / WFH Options
MYO Talent
CyberThreat Hunter/Threat Intelligence Analyst/CyberThreat Analyst/Threat Detection Analyst/Security Operations Center (SOC) Analyst/SOC Analyst/Cybersecurity Analyst/Threat Hunting/AWS/Azure/Microsoft 365 Warwickshire Permanent role - £40,000 60,000. One of our leading clients is looking … to recruit a CyberThreat Hunter/Analyst. Location Warwickshire/Remote (2 days per month in office) Salary £40,000 60,000 Experience: Working in Security Operation Centres, incident response or threat hunting and associated technologies used by these roles and functions. Experience with cloud security tools and platforms (e.g., AWS, Azure, Microsoft 365) Strong … order to provide high quality documentation for internal customers and technical teams. A good knowledge of Active Directory and Entra, knowledge of Endpoint Operating System fundamentals. Demonstrable expertise in threat hunting practices and methodologies with experience in Threat Intelligence platforms and sources. Strong understanding and experience with Windows and its related logging/telemetry. Strong and demonstrable practical More ❯
City of London, London, United Kingdom Hybrid / WFH Options
BRITISH ARAB COMMERCIAL BANK PUBLIC LIMITED COMPANY
Contract Type: Permanent Job Summary Reporting to the Head of Information Security, the role will support the delivery of the Banks IT Security strategy through implementation of the Cyber security programme, configuration and management of cyber security solutions, and proactive collaboration with the Banks security operations functions. Key Work Outputs and Accountabilities Assist with the delivery … of the Banks strategic Cyber Security roadmap and maintaining regulatory compliance Act as a security point of contact to advise and guide the IT team as to effective ways of operating the Banks diverse security tooling Lead the creation, maintenance and delivery of the Bank's cyber security awareness and training programme including mandatory training and … intended and within the Banks risk tolerance (including organising vulnerability management and penetration testing exercises) Lead the Bank's collection, interpretation and dissemination of the current Cyberthreat landscape and help with the identification of innovative controls and mitigations to match Help to generate security performance metrics and KPIs Help to ensure that the Bank can effectively More ❯
North Lanarkshire, Scotland, United Kingdom Hybrid / WFH Options
Net Talent
working) 💼 Salary: £55k+ Comprehensive Benefits Package 🕒 Type: Full-Time | Permanent Are you ready to take on a hands-on role protecting business-critical systems and data from evolving cyberthreats? We’re seeking a skilled Information Security Analyst to join our client and lead the implementation and operation of essential security controls that underpin their enterprise infrastructure. This … commercial initiatives. Collaboration with wider group and cross-functional teams—including Architecture and Security Operations—is key to aligning local and global security standards. You'll also drive cyber awareness and training initiatives for commercial teams, support regulatory compliance (e.g., ISO 27001, NIST SP 800-53, GDPR), and handle incident response, triage, and escalations per internal policies. You … and influence across diverse teams A mindset focused on continuous improvement and business alignment Experience in managing Vendor Security Familiarity with phishing simulations and awareness training to enhance cyber maturity 🌍 What We Offer Hybrid working Salary of up to £55k and benefits including pension, bonus, and professional development support The opportunity to work on high-impact projects and More ❯
Cumbernauld, Scotland, United Kingdom Hybrid / WFH Options
Net Talent
working) Salary: £55k+ Comprehensive Benefits Package Type: Full-Time | Permanent Are you ready to take on a hands-on role protecting business-critical systems and data from evolving cyberthreats? We’re seeking a skilled Information Security Analyst to join our client and lead the implementation and operation of essential security controls that underpin their enterprise infrastructure. This … commercial initiatives. Collaboration with wider group and cross-functional teams—including Architecture and Security Operations—is key to aligning local and global security standards. You'll also drive cyber awareness and training initiatives for commercial teams, support regulatory compliance (e.g., ISO 27001, NIST SP 800-53, GDPR), and handle incident response, triage, and escalations per internal policies. You … and influence across diverse teams A mindset focused on continuous improvement and business alignment Experience in managing Vendor Security Familiarity with phishing simulations and awareness training to enhance cyber maturity What We Offer Hybrid working Salary of up to £55k and benefits including pension, bonus, and professional development support The opportunity to work on high-impact projects and More ❯
Job Title: Senior Cyber Operations Analyst (AVP Level) Location: London (Hybrid – 3 days on-site, 1 day remote) Shift Pattern: 4-on, 4-off (08:00–20:00, 12-hour shifts) Cyberthreats don’t sleep — and neither do we. We’re looking for a sharp, adaptable and experienced Senior Cyber Operations Analyst to … escalate incidents with sound judgement — this isn’t checkbox security work. Dive deep into data using PCAP, endpoint logs, network telemetry and behavioral analytics. Hunt for threats proactively, leveraging threat intelligence, patterns, and instincts built from experience. Work cross-functionally with other teams to contain, mitigate and learn from security incidents. Act as a mentor to Tier 1 analysts … better tooling and smarter monitoring. What You Bring You’re not new to this. You’ve been in the trenches and know what it takes to stay ahead of threat actors. Ideally, you bring: Hands-on experience with SIEM platforms , especially Splunk. Strong familiarity with MITRE ATT&CK , intrusion detection/prevention systems, and malware behaviour. Confidence in network More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Iceberg
Job Title: Senior Cyber Operations Analyst (AVP Level) Location: London (Hybrid – 3 days on-site, 1 day remote) Shift Pattern: 4-on, 4-off (08:00–20:00, 12-hour shifts) Cyberthreats don’t sleep — and neither do we. We’re looking for a sharp, adaptable and experienced Senior Cyber Operations Analyst to … escalate incidents with sound judgement — this isn’t checkbox security work. Dive deep into data using PCAP, endpoint logs, network telemetry and behavioral analytics. Hunt for threats proactively, leveraging threat intelligence, patterns, and instincts built from experience. Work cross-functionally with other teams to contain, mitigate and learn from security incidents. Act as a mentor to Tier 1 analysts … better tooling and smarter monitoring. What You Bring You’re not new to this. You’ve been in the trenches and know what it takes to stay ahead of threat actors. Ideally, you bring: Hands-on experience with SIEM platforms , especially Splunk. Strong familiarity with MITRE ATT&CK , intrusion detection/prevention systems, and malware behaviour. Confidence in network More ❯
South East London, England, United Kingdom Hybrid / WFH Options
Iceberg
Job Title: Senior Cyber Operations Analyst (AVP Level) Location: London (Hybrid – 3 days on-site, 1 day remote) Shift Pattern: 4-on, 4-off (08:00–20:00, 12-hour shifts) Cyberthreats don’t sleep — and neither do we. We’re looking for a sharp, adaptable and experienced Senior Cyber Operations Analyst to … escalate incidents with sound judgement — this isn’t checkbox security work. Dive deep into data using PCAP, endpoint logs, network telemetry and behavioral analytics. Hunt for threats proactively, leveraging threat intelligence, patterns, and instincts built from experience. Work cross-functionally with other teams to contain, mitigate and learn from security incidents. Act as a mentor to Tier 1 analysts … better tooling and smarter monitoring. What You Bring You’re not new to this. You’ve been in the trenches and know what it takes to stay ahead of threat actors. Ideally, you bring: Hands-on experience with SIEM platforms , especially Splunk. Strong familiarity with MITRE ATT&CK , intrusion detection/prevention systems, and malware behaviour. Confidence in network More ❯
Newport, Wales, United Kingdom Hybrid / WFH Options
AIRBUS Defence and Space Limited
technical, hands-on role that will work with a variety of security tools and technologies protecting our whole enterprise. You will be responsible for managing our CyberThreat Intelligence (CTI) research and Threat Hunting activities, the entire lifecycle of our detection rules repository and SOC automation stack. You will be responsible for the technical evolution of … who live and breathe cyber security and to work for a company with great products and technologies around the globe. HOW YOU WILL CONTRIBUTE TO THE TEAM * Threat Analysis - Leverage the organization’s CTI provider as a strategic asset , not just a data source-integrating external intel with internal context to assess real impact and relevance. Conduct … depth analysis of cyberthreats (APT groups, malware campaigns, zero-days, etc.) and assess their relevance to Airbus operations, especially the aerospace and defense-related. Translate complex threat data into clear, actionable intelligence for technical and non-technical stakeholders. Produce regular and ad hoc threat intelligence reports , briefings, and dashboards tailored to specific business units or More ❯
Liverpool, Lancashire, United Kingdom Hybrid / WFH Options
Techwaka
Senior Cyber Security Engineer opportunity working within an established fintech firm in Liverpool Attractive benefits package Up to £60,000 per annum depending on experience Full Time - Permanent role - Hybrid working available Sector: Finance Benefits Competitive Salary - £55,000 - £60,000 per annum Generous Annual Leave Paid Sick days Company Pension A comprehensive in-house training Continued training … and development Friendly and supportive working culture About the Role: Lead on technical cyber security initiatives within the Security Operations team Ensure the implementation of robust security controls and best practices Provide specialist security support to IT teams, including infrastructure, development, and database teams Work with stakeholders to maintain compliance with industry standards such as ISO27001, Cyber Essentials Plus, PCI/DSS Stay ahead of cyberthreats, maintaining and improving security monitoring and risk management processes Support vulnerability management, penetration testing, and incident response Requirements for this role: 3+ years' experience in a senior cyber security role Strong knowledge of security frameworks (NIST, NCSC, CIS, MITRE ATT&CK) Hands-on experience More ❯
to work in the office 3 days per week. In this role of significant responsibility, you will operate at the cutting edge of technology, protecting the business from cyber threats. You will design, implement, and maintain security solutions that protect networks, systems, and data. You will identify vulnerabilities, harden systems, respond to threats, and ensure compliance with security … order to be suitable for this role you must have demonstrable hands-on expertise with monitoring and securing enterprise class technology estates. You will have proven experience with Cyber Security best practice including the NIST Cloud Security guidelines. You will support ISO 27001 compliance and have strong documentation skills. Experience in the Telco sector and knowledge of the … management, network security, cloud security (AWS & Azure), firewalls and intrusion detection systems. You will monitor networks and systems for security breaches, enhance the performance of SecOps tools, perform regular threat analysis and act as a subject matter expert for mitigating cyber risks. This is an outstanding opportunity for an accomplished Information Security Engineer to join a market More ❯
Wokingham, Berkshire, United Kingdom Hybrid / WFH Options
National Grid plc
Security Architecture Group meetings, contributing to the development of essential architecture strategies and patterns for NESO. Building and managing relationships with the business is key to delivering our cyber security strategy. Whether implementing new solutions, driving operational effectiveness and efficiency, or providing guidance to further enhance our strategy, the Senior Security Architect will engage with stakeholders to enable … skills and a team-oriented mindset. A proactive approach to problem-solving, with the ability to think critically and strategically about architectural challenges and opportunities. Significant experience in cyber security Strong Cloud knowledge and demonstrable experience - (Azure) Relevant cyber security qualification(s), for example Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified … knowledge of secure software development lifecycles, application architectures, key attack vectors, and corresponding compensating controls. Cloud Security (Microsoft): Demonstrated experience and proficiency in securing cloud environments. CyberThreat Intelligence: Ability to analyse and respond to emerging cyberthreats and how this can be used to update secure architecture principles. About What You'll Get A More ❯
Sindlesham, Berkshire, United Kingdom Hybrid / WFH Options
National Grid plc
Security Architecture Group meetings, contributing to the development of essential architecture strategies and patterns for NESO. Building and managing relationships with the business is key to delivering our cyber security strategy. Whether implementing new solutions, driving operational effectiveness and efficiency, or providing guidance to further enhance our strategy, the Senior Security Architect will engage with stakeholders to enable … skills and a team-oriented mindset. A proactive approach to problem-solving, with the ability to think critically and strategically about architectural challenges and opportunities. Significant experience in cyber security Strong Cloud knowledge and demonstrable experience - (Azure) Relevant cyber security qualification(s), for example Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified … knowledge of secure software development lifecycles, application architectures, key attack vectors, and corresponding compensating controls. Cloud Security (Microsoft): Demonstrated experience and proficiency in securing cloud environments. CyberThreat Intelligence: Ability to analyse and respond to emerging cyberthreats and how this can be used to update secure architecture principles. About What You'll Get A More ❯
Edinburgh, Midlothian, Scotland, United Kingdom Hybrid / WFH Options
Motability Operations
Description The Data Security Engineer is responsible for designing, implementing, and maintaining MO's data security frameworks to safeguard sensitive information against unauthorised access, breaches and cyber threats. This role focuses on identifying vulnerabilities, establishing robust security protocols and ensuring compliance with industry standards and regulatory requirements. The Data Security Engineer collaborates with cross-functional teams to develop … you, and you excel at explaining technical concepts to non-technical stakeholders, ensuring alignment across teams. Collaborative and adaptable you enjoy staying current with emerging technologies and evolving cyber threats. Integrity, resourcefulness and a commitment to continuous improvement define your approach to ensuring data security and organisational resilience. Qualifications Minimum Criteria You'll need all of these. Experience … in a hands-on Cyber Security focused role, primarily in the data security domain. A strong & demonstratable knowledge of security frameworks, standards and regulations (NIST, GDPR for example). Familiarity with cloud security principles and experience working with cloud platforms such as AWS and Snowflake. A clear and demonstratable understanding of data science principles and practices. Any security More ❯
Employment Type: Permanent, Part Time, Work From Home
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Motability Operations
Description The Data Security Engineer is responsible for designing, implementing, and maintaining MO's data security frameworks to safeguard sensitive information against unauthorised access, breaches and cyber threats. This role focuses on identifying vulnerabilities, establishing robust security protocols and ensuring compliance with industry standards and regulatory requirements. The Data Security Engineer collaborates with cross-functional teams to develop … you, and you excel at explaining technical concepts to non-technical stakeholders, ensuring alignment across teams. Collaborative and adaptable you enjoy staying current with emerging technologies and evolving cyber threats. Integrity, resourcefulness and a commitment to continuous improvement define your approach to ensuring data security and organisational resilience. Qualifications Minimum Criteria You'll need all of these. Experience … in a hands-on Cyber Security focused role, primarily in the data security domain. A strong & demonstratable knowledge of security frameworks, standards and regulations (NIST, GDPR for example). Familiarity with cloud security principles and experience working with cloud platforms such as AWS and Snowflake. A clear and demonstratable understanding of data science principles and practices. Any security More ❯
Employment Type: Permanent, Part Time, Work From Home
Join Barclays as a Senior Cyber Operations Analyst, where you will play a key role as part of a 24/7 security monitoring team. As Tier 2 Analysts you will handle escalated incidents from Tier 1 analysts, conduct deeper analysis, and work closely with senior security teams to contain and mitigate threats. This role is part of … Senior Cyber Operations Analyst you will need the following: Proficiency in SIEM technologies including Splunk Proactively search for potential threats using behavioral analytics, network traffic analysis, and threat intelligence. Incident response skills, including proficiency in PCAP capture, network analysis, and traffic pattern recognition. Knowledge of attack techniques (MITRE ATT&CK framework, malware analysis, and intrusion detection). … technical levels, depending on the audience. Some other highly valued skills may include: A solid technical understanding of threats against the financial industry across physical and cyberthreat domains. Proficiency in operating system fundamentals and security (Windows & Linux). Expertise in networking principles, protocols, and practices. Familiarity with traditional ITIL concepts, including incident, change, and problem management. More ❯