Act as an escalation point for the Security Operations Centre (SOC) and coordinate response activities with internal teams and external security providers.
Conduct digital forensics and incident investigations across systems, endpoints and other technology environments.
Improve SOC detection use cases, incident response playbooks and operational processes.
Work with SIEM, EDR, SOAR and Threat Intelligence platforms to improve monitoring, detection and response capabilities.
Identify and validate security weaknesses using manual testing techniques and offensive security tools.
Document security findings, including risk, business impact, technical impact and remediation recommendations.
Support the development of incident response playbooks, procedures and standard operating processes.
Help automate and integrate security tools and response processes using scripting and automation.
Support tabletop exercises, cyber simulations and security control testing.
Work closely with Cyber Defence, Cyber Engineering and IT teams to implement lessons learned from incidents and improve the overall security posture.
Stay up to date with emerging cyber threats, vulnerabilities and attacker techniques.
Participate in an on-call rota for major cyber security incidents.
What We’re Looking For
8+ years’ experience in Cyber Security and/or IT, with at least 4 years in SOC, Incident Response or Offensive Security.
Strong hands-on experience managing and investigating cyber security incidents.
Experience with incident triage, digital forensics, investigation and remediation.
Hands-on experience with SIEM, EDR/XDR, SOAR and Threat Intelligence platforms.
Experience with technologies such as Splunk, CrowdStrike, ZeroFox or similar security tools.
Practical experience with offensive security tools including Burp Suite, Nmap and Metasploit.
Experience using Python, PowerShell, Bash or another scripting/programming language.
Ability to improve SOC processes, detection use cases and incident response playbooks.
Strong understanding of the cyber incident lifecycle and the ability to independently manage low-to-medium severity incidents.
A proactive mindset with the ability to identify opportunities for automation, process improvement and stronger security controls.
To apply for this job email your details to [email protected]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
