Cyber Security Analyst
Digital Waffle · London Area, United Kingdom
قدّم وتابع مع أبلاي إيدجLocation: London (On-site Shift Pattern)Salary: Up to £70,000 + On-Call Allowance + BenefitsSecurity Clearance: Active SC Clearance required (Must be a British National and eligible to obtain higher levels of UK security clearance)We're working with a leading organisation supporting critical national security programmes, who are looking to recruit an experienced Security Analyst to join their 24/7 Security Operations Centre (SOC)You'll play a key role in monitoring, detecting and responding to cyber security threats across complex enterprise environments, working with industry-leading technologies including Elastic and Splunk. This is an excellent opportunity for someone who thrives in a fast-paced operational environment and enjoys working on high-profile, mission-critical systems.Key ResponsibilitiesMonitor security alerts and events across enterprise environments using Elastic and SplunkInvestigate, triage and respond to security incidents in line with established playbooks and SLAsPerform threat hunting and proactive analysis to identify malicious activity.Analyse logs from endpoints, networks, cloud services and security tools to detect suspicious behaviourEscalate incidents where appropriate and work closely with engineering and incident response teamsDevelop and improve SIEM detection rules and alert tuning to reduce false positivesProduce clear incident reports and maintain accurate documentationParticipate in the on-call rota and support major incident response when requiredContribute to the continuous improvement of SOC processes, tooling and operational proceduresSkills & ExperienceExperience working within a 24/7 Security Operations Centre (SOC) or equivalent cyber security environmentStrong hands-on experience using Elastic and/or Splunk for security monitoring and investigationsGood understanding of SIEM technologies, log analysis and threat detectionsKnowledge of security frameworks such as MITRE ATT&CK and the Cyber Kill ChainExperience investigating phishing, malware, endpoint, identity and network security incidentsFamiliarity with Windows, Linux, Active Directory and cloud environments (AWS, Azure or Microsoft 365)Strong analytical and problem-solving skills with the ability to make decisions under pressureExcellent written and verbal communication skillsEssential RequireActive SC ClearanceBritish National, with eligibility to obtain higher levels of UK security clearanceWillingness to work a 24/7 rotating shift pattern (4 days on rotation)Able to work from the London office as required