Senior Threat Detection Analyst
5 hours ago
Senior Threat Detection Analyst
Capability: Enterprise-Wide Technology
Team: Threat Detection (SOC)
Job Title: Senior Threat Detection Analyst
Enterprise-Wide Technology
EWT is the UK Firm’s internal technology division and is accountable for delivering a range of services to the UK Firm. Taking a holistic approach, this includes gathering requirements, solution design, build and run and the execution of complex change portfolios focused on security, data, core infrastructure and business applications.
Threat Detection Team
The Team is an important function within Security Operations. The team play a key role in ensuring that the business IT systems are protected and monitored from cyber threats. The team works with external MSSPs to monitor, analyse, report cyber security threats and respond accordingly. The team works with the different internal business capabilities to ensure that security monitoring service is embedded into their solutions. The team is also responsible for making sure that security monitoring is aligned with cyber threat landscape and business risks on an ongoing basis.
Senior Threat Detection Analyst (SOC)
The person will be playing a key role in ensuring that the business IT systems are protected and monitored from threats, participate in the active monitoring of the security sensors and ensure that appropriate actions are taken as part of the Incident Response process, work with the different# business capabilities to ensure that security monitoring service is embedded into their solutions.
You will be part of on-call rota for SOC and required to be on-call for one week at a time typically, during a month.
Key Responsibilities
- Act as an escalation point for other security analysts in the SOC, including 3rd party MSSP
- Co-ordinate SOC team response and work with Threat Detection manager to improve triage processes
- Deputise Threat Detection Manager with full delegated responsibilities, when required
- Proactively monitor the network security sensors ensuring timely detection, investigation and remediation of potential threats in line with the incident management lifecycle
- Use the advanced security analytics toolsets to monitor for emerging threat patterns and vulnerabilities, attempted or successful breaches
- Work closely with other teams to ensure that all technologies are activity monitored including troubleshooting where necessary
- Interact with the Global Security Operations Centre (GSOC) & MSSP, including Incident response and intelligence sharing, escalating to management where required
- Triage and manage incidents, events and queries from the business to the relevant resolver group
- Contribute to the Continual Service Improvement of the teams' operations through proactive analysis, engagement and collaboration
- Detect, respond and coordinate response for security events while capturing essential details and artefacts
- Operationalise actionable intelligence reports from Threat Intelligence team and external sources
- Maintain event response documentation, participate in post-mortems, and write event reports
- Contribute to projects that enhance the security posture of the business
- Identify trends, potential new technologies, and emerging threats, which may impact the business
- Review and prioritise alerts based on Standard Operating Procedures
- Review and triage suspected security events reported by staff members or Security Monitoring platforms
- Accurately document work in Incident case management system as per defined standards
- Leverage multiple data sources to analyse detection alerts and staff reported cyber-attacks to identify which events require response activities based on Standard Operating Procedures
- Declare an incident and escalate it to Incident Response team, ensuring findings have been accurately captured in the Incident case management system as per defined standards
- Ensure that cases are accurately categorised to ensure the appropriate feedback is provided to the Detection and Response Engineering team and to facilitate reporting
- Identify and record gaps in visibility and security posture through the course of investigations as per defined Standard Operating Procedures
- Identify potential new detection logic and escalate to the Detection and Response Engineering team
- Hunt for threat indicators from log data and other available endpoint/network artefacts
Key Attributes
- Prior experience in Cyber Security
- Experience of working in a Security Operations Centre or Security Monitoring Team.
- Experience with managed security services and security consulting would be a plus
Essential Skills and Experience
- Hands on SIEM and EDR tooling knowledge and experience including technologies such as Microsoft Sentinel, Microsoft Defender Suite etc.
- Experience in end-to-end information security incident management and mitigating and addressing threat vectors including Advanced Persistent Threat (APTs), Distributed Denial of Service (DDoS), Phishing, Malicious Payloads, Malware, etc
- Experience with Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), Web Application, Firewalls, Firewall logs, systems logs, web logs, application logs and Security Information and Event Management (SIEM) systems
- Experience with technologies, tools, and process controls to minimise risk and data exposure.
- Experience in search query languages such as KQL, OSquery or SPL
- Solid experience of working in Cloud environments such as AWS, Azure, & GCP
- Experience with building threat-based Use Cases using frameworks such as MITRE ATT&CK
- Solid understanding of ISO 27001, Cyber Essentials/Essentials Plus, GDPR and other information security-related regulatory and compliance standards
- Understanding of security threats, attack scenarios, intrusion detection and incident management
- Ability to function effectively in a matrix structure
- Ability to deal with ambiguity and to keep a cool head when dealing with crisis or stressful situations
- Strong analytical skills
- Apply analytical rigor and demonstrate business acumen to understand complex business scenarios
- Fluent in English
- Already holds, or can be SC cleared
Desirable Skills and Experience
- Bachelor’s degree in Computer Science or related field
- Information Security and/or Information Technology industry certification (CISSP, SANS GIAC, SC-200, AZ-500 or equivalent)
If this sounds of interest please apply or reach out to ross.downham@lorienglobal.com
-
Threat Detection Expert
2 days ago
Manchester, United Kingdom NCC Group Full timeResponsibilities and RequirementsWe are seeking a highly skilled Threat Detection Expert to join our team at NCC Group. As a key member of our security team, you will play a vital role in helping our customers protect their brand, value, and reputation against the ever-evolving threat landscape.Your primary responsibility will be to design, implement, and...
-
Cybersecurity Threat Analyst
2 days ago
Manchester, United Kingdom DC Thomson Full timeAbout UsAt DC Thomson, we're a leading provider of colocation, cloud, and cybersecurity solutions. Our experts bring together innovative ideas with solid solutions to meet our customers' business needs and ambitions.Job Summary:We're seeking a highly skilled Cybersecurity Threat Analyst to join our Security Operations Centre (SOC) team. The successful...
-
Advanced Threat Detection Specialist
2 days ago
Manchester, United Kingdom Iceberg Cyber Security Full timeIceberg Cyber Security is committed to advancing the security of AI systems, and we're seeking a talented AI Security Engineer to join our team. In this role, you'll work closely with our cybersecurity team to design and implement advanced threat detection and prevention strategies, ensuring that our AI systems remain secure and compliant with industry...
-
Senior XDR Threat Investigator
2 days ago
Manchester, United Kingdom NCC Group Full timeRole DescriptionThe Cloud XDR Team at NCC Group are looking for a Senior XDR Security Analyst with a passion for security to join the team. The successful candidate will have a strong focus on detection and response to cyber incidents, with a proven track record of in-depth analysis of security alerts utilizing Microsoft XDR suite (Sentinel/Defender...
-
Digital Threat Detection Specialist
3 days ago
Manchester, United Kingdom NCC Group Full timeAbout the RoleWe are seeking an experienced Digital Threat Detection Specialist to join our Detection Engineering Team. As a key member of the team, you will be responsible for reviewing red team/Pentest activities and evaluating them from a detection engineering improvement perspective.You will also provide detection engineering support for our Managed...
-
AWS Threat Detection Engineer
2 days ago
Manchester, United Kingdom Amazon Full timeJob Description:We are looking for a talented AWS Security Engineer to join our team at Amazon. As an AWS Security Engineer, you will be responsible for designing and implementing secure systems and solutions for our customers.About the Team:Our team is responsible for ensuring the security of our customers' data and systems. We work closely with other teams...
-
Digital Threat Investigator
2 days ago
Manchester, United Kingdom Laraveldaily Full timeAbout the RoleLaraveldaily is seeking a highly skilled Cybersecurity Analyst to join our team in Manchester. As a key member of our security team, you will be responsible for protecting our digital assets and ensuring the integrity of our critical information.This is an exciting opportunity for an individual who is passionate about identifying and mitigating...
-
Cyber Threat Hunting Analyst
1 month ago
Manchester, United Kingdom NatWest Full timeJoin us as a Cyber Threat Hunting AnalystTake on a new challenge and use your specialist knowledge to support the wider organisation in building and operating secure services that protect both colleagues and customersYou’ll act as a subject matter expert in a Cyber Defence, making sure that the security implications of the remediating actions are...
-
Cyber Security Threat Analyst
2 days ago
Manchester, United Kingdom NCC Group Full timeJob SummaryWe are seeking a skilled Cyber Security Threat Analyst to join our team. As a key member of the Security Operations Centre, you will contribute to the organisation's overall cybersecurity posture by actively participating in the monitoring, analysis, and response to security incidents and events. With a focus on continuous learning and...
-
Cybersecurity Threat Analyst
2 days ago
Manchester, United Kingdom Be-IT Full time £45,000Be-IT is seeking a highly motivated Cybersecurity Threat Analyst to join their growing security team. This role involves delivering managed security services to customers across various sectors. The ideal candidate will have commercial experience in security positions, excellent customer service skills, and a willingness to learn.Key Responsibilities:-...
-
Enterprise Cyber Threat Analyst
4 weeks ago
Manchester, United Kingdom ANS Full time**Job Title:** Enterprise Cyber Threat AnalystWe are seeking an experienced Enterprise Cyber Threat Analyst to join our team at ANS. As a key member of our security operations team, you will play a critical role in protecting our customers' assets from cyber threats.The ideal candidate will have a strong background in security engineering or operations, with...
-
Cybersecurity Threat Analyst
2 days ago
Manchester, United Kingdom NCC Group Full timeCybersecurity Threat AnalystAt NCC Group, we are committed to creating a more secure digital future.We are seeking a highly skilled Cybersecurity Threat Analyst to join our Security Operations Centre (SOC) team. This is an excellent opportunity for individuals with a passion for cybersecurity and a desire to make a meaningful impact in the industry.The...
-
Senior XDR Threat Hunter
5 days ago
Manchester, United Kingdom NCC Group Full timeJob DescriptionAs a Senior XDR Security Analyst, you will play a key role in helping our customers get the most out of our services and protect their networks. You will perform in-depth analysis of security alerts, document and conform to processes related to security monitoring procedures, and provide assistance to XDR Security Analysts on general Triage...
-
IT Cybersecurity Threat Analyst
2 days ago
Manchester, United Kingdom Smart DCC Full timeAre you passionate about protecting digital assets? Smart DCC seeks an IT Cybersecurity Threat Analyst to lead our cybersecurity efforts.About the Opportunity:We offer a rewarding role in Manchester with a salary range of £55,000 - £65,000 per annum, along with attractive benefits.Responsibilities:Leading the analysis and implementation of cybersecurity...
-
Digital Threat Protection Specialist
3 weeks ago
Manchester, United Kingdom Digital Waffle Full time**Digital Waffle: A Leader in Innovation**We are a forward-thinking company based in Manchester, dedicated to delivering exceptional digital solutions. Our organisation values creativity, expertise, and collaboration.**Job Overview:** As our new **Digital Threat Protection Specialist**, you will play a critical role in protecting our organisation's digital...
-
Threat Detection Specialist
1 week ago
Manchester, United Kingdom Ans Full timeCybersecurity Threat Investigator at ANSAs a Cybersecurity Threat Investigator at ANS, you will play a crucial role in identifying and mitigating emerging cyber threats. With our state-of-the-art technology and experienced team of security experts, you will be responsible for triage and investigation of Security Incidents in Sentinel, tuning of Alerts in...
-
Security Operations Center Analyst
4 hours ago
Manchester, United Kingdom MAC Recruit Group Ltd Full timeAn expert MSP in cloud and cybersecurity solutions is looking to hire 2 x SOC Analysts to join their existing team of 5. They offer custom-built colocation, hybrid cloud expertise and the latest in cybersecurity technology, with the end goal of providing a future proofed and industry leading solution to their customers.Due to expansion across the UK and new...
-
Cyber Operations Lead Analyst
3 weeks ago
Bolton, Greater Manchester, United Kingdom Barclays Bank PLC Full timeJoin us as Senior Cyber Operations Analyst at Barclays, where youll spearhead the evolution of our digital landscape, driving innovation and excellence. Youll harness cutting-edge technology to revolutionise our digital offerings, ensuring unparalleled customer experiences. As a Senior Cyber Operations Analyst, youll lead cyber defence, monitor activities...
-
Cyber Security Analyst
3 days ago
Manchester, United Kingdom Exalto Consulting Ltd Full timeCyber Security Analyst - Manchester Do you thrive in a fast-paced environment, protecting critical IT infrastructure against the ever-evolving threat of cyberattacks?Are you eager to make a real difference in safeguarding digital systems, data, and processes?If so, we invite you to join our innovative and proactive team, committed to delivering the highest...
-
Threat Intelligence Specialist
23 hours ago
Manchester, United Kingdom NCC Group Full timeAbout the RoleNCC Group is a leading provider of cybersecurity services, and we are seeking an experienced Threat Intelligence Specialist to join our team.The successful candidate will have experience working as a Threat Intelligence analyst, knowledge of technical writing, and a strong understanding of the cyber threat landscape.This role involves tracking...