Tier I SOC Analyst
<p><span style="font-size: 22px;">Overall Purpose</span></p> <p><br></p> <p><span style="font-size: 13px;">The Security Operations team exists to protect the client by proactively detecting and responding to cyber security threats.</span></p> <p><br></p> <p><span style="font-size: 13px;">Our SOC Analysts are our front line of cyber defence: monitoring and assessing cases, correlating observables, mitigating and defending against malicious cyber activity and adapting to an ever-changing threat landscape.</span></p> <p><br></p> <p><span style="font-size: 13px;">Operating as a triage specialist responsible for the monitoring management and configuration of relevant security tools, containing and remediate attacks, as well as preventing intrusion and unauthorized access to critical data and devices.</span><span style="color: #404040; font-size: 13px; font-family: Arial;"> </span></p> <p><br></p> <p><span style="font-size: 13px;">This role requires willingness to work shifts (including unsociable hours and bank holidays where these fall into your shift pattern) as part of a 24x7 team.</span></p> <p><br></p> <p><span style="font-size: 22px;">Principal Duties and Responsibilities</span></p> <p><br></p> <ul> <li><span style="font-size: 13px;">Monitor and identify cyber security threats that pose a risk, or have the potential to pose a risk, to the client.</span></li> <li><span style="font-size: 13px;">Monitoring SIEM alerts effectively to minimize downtime and restore services.</span></li> <li><span style="font-size: 13px;">Triage alerts and alarms across a broad range of security controls as they come into the SOC and assess urgency to escalate to Tier 2 as appropriate.</span></li> <li><span style="font-size: 13px;">Ensure investigation steps are clearly documented and accurately escalated to Tier 2 when needed.</span></li> <li><span style="font-size: 13px;">Provide Tier 1 case resolution for basic security cases including generating initial reporting, providing follow-ups and requesting information and resolution activity.</span></li> <li><span style="font-size: 13px;">Responsible for providing communication directly with CyberClans’ customers regarding security incidents and other related topics.</span></li> <li><span style="font-size: 13px;">Responsible for understanding where threats may appear.</span></li> <li><span style="font-size: 13px;">Responsible for producing and maintaining documentation relevant to both the SOC and position.</span></li> <li><span style="font-size: 13px;">Responsible for updating and offering continual improvement to the knowledge base.</span></li> <li><span style="font-size: 13px;">Work with the CyberClan global team when responding to security incidents.</span></li> <li><span style="font-size: 13px;">Support the SOC team research global security events, issues and trends to produce security advisories for customers based on findings.</span></li> <li><span style="font-size: 13px;">Responsible for managing and configuring security monitoring tools.</span></li> <li><span style="font-size: 13px;">Investigating intrusion attempts and performing in-depth exploit analysis.</span></li> <li><span style="font-size: 13px;">Conducting cyber threat research and analysis for purposes of improving the strength of network security.</span></li> </ul> <p><br></p> <ul> <li><span style="font-size: 13px;">Assist with defining, testing and operating new ways of working with new technology solutions or processes supplied to the SOC team. </span></li> </ul> <ul> <li><span style="font-size: 13px;">Provide analytical feedback on client network traffic patterns.</span></li> <li><span style="font-size: 13px;">Provide analytical feedback related to malware and other network threats.</span><span style="color: #2d2d2d; font-size: 13px;"> </span></li> <li><span style="font-size: 13px;">Accept, manage and update service requests and incidents to ensure contracted Service Level Agreements are met.</span></li> </ul> <p><br><br></p> <p><span style="font-size: 22px;">Generic Duties and Responsibilities</span></p> <p><br></p> <ul> <li><span style="font-size: 13px;">To continuously develop both technical and personal skills required within the role and assist with development of other staff.</span></li> </ul> <ul> <li><span style="font-size: 13px;">Participate in identification and delivery of Service Improvement Plans.</span></li> <li><span style="font-size: 13px;">Proactively support business KPIs.</span></li> </ul> <ul> <li><span style="font-size: 13px;">Understand and comply with all Information Security policies. </span></li> <li><span style="font-size: 13px;">Understand and comply with all company policies.</span></li> <li><span style="font-size: 13px;">Interact with strategic incident response and threat intelligence vendors.</span></li> <li><span style="font-size: 13px;">To undertake other responsibilities, training and tasks as reasonably requested by line management.</span></li> </ul> <ul> <li><span style="font-size: 13px;">Undertake periodic assurance reviews and produce associated reporting as required.</span></li> </ul> <ul> <li><span style="font-size: 13px;">Participate in CyberClan internal security awareness initiatives and other training requests </span></li> <li><span style="font-size: 13px;">The job description may be altered at any time in line with the level of the post to meet changing requirements, but only in full consultation with the post holder.</span></li> </ul> <p><br></p> <p><span style="font-size: 22px;">Personal Specifications:</span></p> <p><span style="font-size: 18px;">Qualifications:</span></p> <ul> <li><span style="font-size: 13px;">Educated to GCSE level or equivalent</span></li> <li><span style="font-size: 13px;">Cyber Security Qualification (COMPTIA or equivalent experience)</span></li> <li><span style="font-size: 13px;">ITIL Foundation</span></li> </ul> <p><br></p> <p><span style="font-size: 18px;">Skills, Knowledge and Experience:</span></p> <ul> <li><span style="font-size: 13px;">Knowledge and experience of SOC tooling to identify threats.</span></li> <li><span style="font-size: 13px;">Experience of collaboration tools</span></li> <li><span style="font-size: 13px;">Keen analytical mind and approach</span></li> <li><span style="font-size: 13px;">Previous experience of SOC analysis beneficial</span></li> <li><span style="font-size: 13px;">Proactively shares own expertise with others</span></li> <li><span style="font-size: 13px;">Knowledge and experience of IT systems, networking and security threat landscape including:</span> <ul> <li><span style="font-size: 13px;">Network fundamentals for example OSI stack, TCP/IP, DNS. HTTPS, firewall logs</span></li> <li><span style="font-size: 13px;">Cloud technologies (AWS, Google Cloud, Azure)</span></li> <li><span style="font-size: 13px;">Active Directory, Group Policies, PowerShell</span></li> <li><span style="font-size: 13px;">Endpoint protection applications (Antivirus, Web Filtering, ATP, Encryption)</span></li> <li><span style="font-size: 13px;">IDP/IPS Systems</span></li> <li><span style="font-size: 13px;">SIEM tools</span></li> <li><span style="font-size: 13px;">SOAR is an added advantage</span></li> </ul> </li> <li><span style="font-size: 13px;">Knowledge of malware capabilities, attack vectors and impact.</span></li> </ul> <p><br></p> <p><span style="font-size: 18px;">Personal Qualities:</span></p> <ul> <li><span style="font-size: 13px;">Excellent interpersonal skills sufficient to develop professional relationships and rapport amongst key stakeholders</span></li> <li><span style="font-size: 13px;">Strong team player</span></li> <li><span style="font-size: 13px;">Genuine enthusiasm and drive to work within cyber security.</span></li> <li><span style="font-size: 13px;">Excellent customer service skills</span></li> <li><span style="font-size: 13px;">Good written skills to write explanations of systems, regulations and or procedures.</span></li> <li><span style="font-size: 13px;">Good verbal communication</span></li> <li><span style="font-size: 13px;">Ability to identify and suggest continual improvement</span></li> <li><span style="font-size: 13px;">Good analytical and problem-solving skills</span></li> <li><span style="font-size: 13px;">Ability to adapt to organisational change</span></li> <li><span style="font-size: 13px;">Proven ability to manage varied workload</span></li> <li><span style="font-size: 13px;">Ability to work unsupervised and under pressure.</span></li> </ul>
Apply To This Job