Overview
As a Senior Cyber Security Analyst, you will join a fast-growing Blue Team within a dynamic Cyber Practice to deliver threat detection, monitoring, and incident response for client environments. You will work closely with analysts and stakeholders to enhance SecOps capabilities and play a key role in mentoring junior staff. Your work covers detection engineering, monitoring, and advisory tasks, with opportunities to influence security decisions at senior levels. This role offers hands-on technical impact on high-profile engagements and a chance to shape security operations at scale.
Pay / Benefits
- on-call for high-priority incident response with additional compensation
Responsibilities
- Develop, maintain and enhance SIEM detection content (primarily Splunk) across cloud, endpoints and networks
- Identify gaps in detection, logging and alerts aligned to business risk
- Review and optimise SecOps standards and logging requirements
- Conduct security monitoring, triage alerts and recommend improvements
- Respond to and investigate incidents and escalate where needed
- Mentor and support junior analysts as a technical escalation point
- Present findings and guidance to senior stakeholders as a technical SME on client engagements
- Participate in alert testing, incident response exercises and tabletop simulations
- Stay current with emerging threats and TTPs relevant to client environments
- Proactive threat hunting and development of tradecraft (client dependent)
- Incident response playbook creation (client dependent)
- Threat intelligence collection and interpretation (client dependent)
- Vulnerability scanning, reporting and management (client dependent)
- Leadership opportunities in client environments (incident and operations management)
- Note: approximately one week per month on-call for high-priority incident response with additional compensation
Key requirements
- Threat intelligence concepts (Pyramid of Pain, IPCE, Threat Intelligence Lifecycle)
- Detection engineering and alert development experience
- Scripting/programming skills (Python, Bash, C/C++, Java)
- Core cybersecurity concepts: network security, cryptography, cloud security, forensics
- Knowledge of network protocols and attacker exploitation
- Up-to-date awareness of APT groups and their TTPs
- Experience analysing Windows and/or Linux environments
- Mentoring and supporting junior staff
- Stakeholder engagement with senior colleagues
- Self-motivated and inquisitive mindset
- Splunk SIEM
- Detection engineering and alert development
- Incident response
…
