3 дня назад
24 x 7 Security Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
24 x 7 Security Analyst (Microsoft Sentinel/Defender): Detecting and responding to threats in a 24x7 SOC using SIEM, EDR, network monitoring, threat intelligence, and bespoke tooling with an accent on incident investigation, customer reporting, and defensive monitoring. Focus on threat hunting, malware analysis, detection tuning, security automation, and developing custom KQL analytics rules.
Location: Birmingham, United Kingdom
Company
Security Operations Centre providing defensive monitoring, threat detection, and response services to customers across multiple industries.
What you will do
- Monitor customer environments as part of a 24x7 SOC shift team and triage security alerts using SIEM, EDR, network monitoring, threat intelligence, and bespoke tooling.
- Investigate incidents, assess risk and threats, and produce actionable reports with recommendations, mitigations, and remediations.
- Respond to alerts and customer requests within agreed SLAs and maintain clear communication with customers, suppliers, and internal stakeholders.
- Perform threat hunting, malware analysis, detection development, and tuning of alerts, playbooks, and automations.
- Support the implementation of new security technologies and strategic cross-team projects.
- Maintain operational and management reporting, documentation, and security use cases.
Requirements
- Professional experience with Microsoft Sentinel and Microsoft Defender, including deployment, configuration, and enterprise operational management.
- Knowledge of SIEM and EDR/EPP technologies, security investigations using large datasets, and Kusto Query Language for custom queries and analytics rules.
- Understanding of enterprise IT infrastructure, including Windows and Linux, networking, and third-party security tools.
- Ability to analyse complex security data, identify patterns, prioritise threats, and distinguish normal from abnormal activity.
- Knowledge of attack vectors, the MITRE ATT&CK framework, and adversary behaviours.
- Strong communication skills and experience presenting technical findings and security risks to technical and non-technical stakeholders.
Nice to have
- Microsoft SC-200 or SC-100 certification.
- CrowdStrike CCFA or CCSA certification.
- Python, PowerShell, and regular expression skills.
Culture & Benefits
- High-trust, close-knit SOC team operating without traditional SOC tiers.
- Opportunity to contribute to defensive monitoring capabilities and cross-team security projects.
- Mentoring and development of junior staff members.
- Work governed by documented analyst best practices, compliance standards, and organisational procedures.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
SOC Analyst (Cybersecurity)
10 дней назад
Threat Analyst 2 (Cybersecurity)
5 дней назад
Security Analyst III - SOC
10 дней назад
Incident Response Engineer 2 (Cybersecurity)
10 дней назад
Staff Security Engineer (Security Operations)
WRITER
5 дней назад