5 дней назад
Advanced Cyber Threat Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Advanced Cyber Threat Analyst (Cybersecurity): Investigating and responding to complex cyber incidents across cloud, endpoint, identity, email, and network environments with an accent on threat hunting, detection engineering, and AI-assisted analysis. Focus on identifying attack paths, validating analytical rules, improving defensive capabilities, and making accountable response decisions from incomplete or time-sensitive evidence.
Location: Stirling, United Kingdom
Company
M&G provides savings, investment, asset management, and insurance solutions through its Asset Management and Life segments.
What you will do
- Investigate complex security incidents across cloud, endpoint, identity, email, and network environments.
- Assess business impact and recommend proportionate containment, remediation, and recovery actions.
- Conduct intelligence-led threat hunts based on adversary campaigns, behaviours, tactics, techniques, and procedures.
- Develop, tune, and validate detections, analytical rules, controls, and response processes.
- Use AI-assisted analysis and advanced analytics while validating outputs and retaining accountability for conclusions and decisions.
- Collaborate with Security Operations Engineering, Threat Intelligence, internal stakeholders, and external security providers to improve telemetry, automation, resilience, and audit evidence.
Requirements
- Practical experience in a Security Operations environment, including cyber incident investigation and response.
- Experience analysing endpoint, identity, cloud, email, or network security activity and conducting structured threat hunting.
- Ability to develop, tune, or validate security detections and analytical rules.
- Knowledge of Microsoft Azure security environments, including Entra and Microsoft Defender capabilities.
- Strong risk assessment, judgement, documentation, governance, and audit discipline.
- Knowledge of responsible AI-assisted security operations, including human oversight and output validation.
Nice to have
- Experience with Microsoft Sentinel, log analysis, analytical rule management, and playbook development.
- Experience with Endpoint Detection and Response technologies, Microsoft Defender for Endpoint, Defender for Identity, or Defender for Cloud.
- Experience developing investigation, enrichment, or response automation.
- Experience in financial services or another highly regulated environment.
- CompTIA Security+, CySA+, ISC2 SSCP, SANS, SC-200, AZ-500, or equivalent certifications.
Culture & Benefits
- Flexible working arrangements and workplace adjustments are available.
- Pension scheme with contributions of up to 18%.
- Share Save, Share Incentive Plan, and financial wellbeing support.
- 38 days of annual leave including bank holidays, with the option to purchase five additional days.
- Paid parental leave, private healthcare, critical illness cover, and life assurance.
- Inclusive culture with employee-led networks, development opportunities, and support for reasonable adjustments during recruitment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →