Security Operations Analyst responsible for developing security processes and incident response. Collaborating with multiple teams for security best practices in a hybrid work environment.
Responsibilities
Event and Alarm Triage & analysis, specifically handling escalated events.
Leading or supporting Security Incidents end to end, as part of incident response activities.
Handling escalated vulnerability, misconfiguration or threat hunting events.
Being responsible for the technical implementation of configuration or development of tools, alarms, and runbooks.
Assisting platform engineering with security best practices, responsible for liaising with appropriate teams and consulting.
Assisting software engineering with secure by design, responsible for liaising with appropriate teams and consulting.
Assisting payments with 3rd party compliance, responsible for liaising with appropriate teams and consulting.
Audit and reporting, responsible for developing and producing reports and metrics.
Oversight of the maintenance of coverage, data freshness, and noise reduction.
Organising and running tabletop, readiness, and war game exercises.
Some 3rd party management
Requirements
Proven experience of working in a Security Operations Centre (as a Senior SOC Analyst or an experienced Junior).
Strong knowledge of the information security threat landscape, tactics, techniques, attack vectors associated with security threats.
Strong knowledge of Incident response planning and playbook design
Strong knowledge of threat detection rule design/tuning
Good technical knowledge of best practice security for networks, systems, web applications, APIs and databases.
Good knowledge and hands-on experience with common security tools such as SIEM, endpoint protection, scanners, proxies, WAF, IDS/IPS.
Some technical knowledge of AWS and GCP administration, security tooling, cloud security operations and incident response.
Some knowledge of security standards and frameworks (e.g. ISO27001, PCI DSS, MITRE ATT@CK, NIST CSF).
Some Systems forensics and investigation skills (MACOS and Windows).
Security Manager leading IAM and SecOps at fintech solutions provider in Brazil. Developing and implementing information security programs aligned with best practices and compliance requirements.
Security Engineer enhancing cybersecurity tools and solutions for The Walt Disney Company. Performing system analyses and developing security configurations for improved protection against cyber threats.
Security Operations Lead responsible for security operations aligning with policies and compliance. Handling incident response, vulnerability management, and supporting IT teams with security expertise.
Cyber Security Specialist protecting digital estate from threats at the University of Edinburgh. Focused on identifying and mitigating cyber risks while supporting teaching and research services.
Lead Specialist in Security Operations, enhancing detection engineering and incident response at Pearson. Collaborate with teams and drive process improvements in a high - paced environment.
Cybersecurity Incident Response Analyst detecting and responding to cyber threats at NOV. Collaborating using AI tools to enhance cybersecurity operations across IT, cloud, and OT environments.
Security Engineer II at AvidXchange enhancing security operations and incident response. Collaborating with teams to develop, tune and improve security monitoring and automation capabilities.
Director leading security operations strategy and overseeing investigations at Ford Motor Company. Responsible for global investigations, crisis management, and team leadership.