Banner Default Image

2nd Line Cyber Security Analyst

Go back
  • Location:

    Corsham

  • Sector:

    Technology & Digital

  • Job type:

    Contract

  • Salary:

    £70 - £80 per hour

  • Contact:

    Jake Appleton

  • Email:

    Jake.Appleton@yolkrecruitment.com

  • Job ref:

    BBBH31397_1674120533

  • Published:

    12 days ago

  • Duration:

    6 Months

  • Expiry date:

    18 February 2023

  • Start date:

    ASAP

2nd Line Cyber Security Analyst - Inside IR35 - £80 per hour - DV CLEARED - CORSHAM - 6 MONTHS - DAYS - SINGLE STAGE PROCESS

Yolk Recruitment are recruiting for a 2nd Line Cyber Security Analyst to work a 6 month contract from Corsham with a major defence client.

The role of the 2nd Line Analyst will be an escalation point for all SOC operational activity. The successful candidate will be responsible for the day to day monitoring of multiple security devices, including SIEM, IDS/IPS etc, ensuring that all customer SLAs are met.

The 2nd Line Analyst will be comfortable at a technical level, often being required to attend technical workshops and customer briefings/service reviews.

All Analysts are expected to be able to present and write professional reports to key stakeholders and exercise good time management.

Tasks and Accountabilities

  • Maintain currency in security concepts, tools and best practices
  • When required perform initial triage/identification of 'Events of Interest' using a range of monitoring and detection tools.
  • Complete analysis/correlation of 'Events of Interest' to identify incidents
  • Ensuring that all events, events of interest, exceptions & incidents are responded to in accordance with established SOC work instructions, including remedial action/recommendations.
  • Responsible for maintaining SOC work instructions - reviews & amendment.
  • Maintain currency in security concepts, tools and best practices
  • Produce reports (as per templates) & vulnerability/trending analysis as requested by UK SOC Manager or key stakeholders.
  • Present & review reports to internal & external key stakeholders
  • Complete tooling configuration changes including but not limited to filters/tuning/dashboards as authorised.
  • Carry out minor tool maintenance as directed by SOC lead engineer.
  • Support the lead engineer for rules/policy/filters/use cases on SOC tooling.
  • Research causes and effects of incidents and exceptions. Provide solutions to procedural failures and improvements to working practices.
  • Mentoring - Improve inter team development through mentoring, knowledge sharing, briefing and production of guides and incident scenarios. Show flexibility in developing knowledge of supporting areas and performing their responsibilities during times of operational needs.

Skills & Experience

Essential

  • TCP/IP Fundamentals
  • ITIL Fundamentals (or equivalent)
  • CompTIA Security (or equivalent)
  • CompTIA Network (or equivalent)
  • Wireshark Packet Analysis
  • SIEM Administrator/Analyst
  • SANS SEC401: Security Essentials (or equivalent)
  • SANS SEC503: Intrusion Detection in-depth (or equivalent)
  • SANS SEC504: Hacker Tools, Techniques, Exploits and Incident Handling (or equivalent)

Desirable

  • CCENT
  • Ethical Hacker (CEH)
  • Cisco Certified Network Associate CCNA
  • FIAHMG - Fundamentals of Information Assurance in HMG (leading to CCP)
  • CREST (Registered Intrusion Analyst) (CRIA)
  • SANS SEC501: Advanced Security Essentials