YOU MUST HAVE ACTIVE DV CLEARANCE
Senior SOC Analyst
£75 per hour
12 Hour shifts (7am-7pm & 7pm-7am)
7 Days & 7 Nights over a 4-week pattern
6 month contract initially
Buckinghamshire
Summary - The 4x Senior SOC Analysts will be responsible for the operational leadership of the Security Monitoring function, ensuring the consistent delivery of high-quality security monitoring, investigation and escalation activities.
Responsibilities
Monitor the organisation’s technology estate to identify cyber security events, suspicious activity and indicators of compromise using approved monitoring platforms and analytical tools.
Independently investigate security alerts and complex cyber security events, determining their significance, potential impact and appropriate course of actions.
Correlate information from multiple data sources to establish attack timelines, identify affected systems and support the assessment of cyber security incidents.
Analyse indicators of compromise, attacker techniques and available threat intelligence to determine the nature and severity of security events.
Escalate indicators confirmed or suspected cyber security incidents to the Lead SOC Analyst or Incident Responder team in accordance with established operational procedures.
Support Incident Responders by providing accurate analytical findings, supporting evidence, timelines and technical information throughout incident investigations.
Contribute to the continual improvement of monitoring capability by identifying opportunities to improve alert quality, investigation processes, monitoring coverage and detection effectiveness.
Validate new monitoring content, detection rules and operational procedures before deployment into the live SOC environment.
Assist in the onboarding of new systems, cloud services and application into SOC monitoring by validating operational visibility and monitoring effectiveness.
Maintain accurate investigations records, ensuring all analytical activities are fully documented in accordance with organisational procedures.
Share knowledge, provide technical guidance and support the development of Practitioner SOC Analysts through coaching and day-to-day mentoring.
Contribute to operational reviews, lessons identified and post-incident activities, recommending improvements to monitoring capability and operational processes.
Maintain awareness of emerging cyber threats, attacker techniques and monitoring technologies to support continual professional development and improved operational effectiveness
Required Skills / Experience
The Senior SOC Analyst should demonstrable knowledge and skills in the areas: Cyber security operations, Forensics, Incident management, incident investigation and response, Information risk assessment and risk management, Intrusion detection analysis, Protective security, Secure operations management, Threat intelligence and threat assessment
Experience working within a SOC or comparable cyber security operations environment.
Experience investigating cyber security alerts and security events using enterprise monitoring techniques.
Good knowledge of SIEM platforms, security monitoring tools and log analysis techniques.
Understanding of cyber attack methodologies, indicators or compromise, threat intelligence and common attacker techniques.
Experience analysing information from multiple technical sources to investigate cyber security events.
Experience supporting cyber incident response activities.
Strong analytical and problem-solving skills with the ability to made sound technical judgements.
Good written and verbal communication skills with the ability to produce accurate technical reports and investigation findings.
Ability to work effectively within a shift-based 24/7 environment.
Professional certifications such as Microsoft SC-200, CompTIA CySA+, GIAC, GCIA or equivalentDesirable:
Experience using Microsoft Sentinel, LogRhythm, or equivalent enterprise SIEM platforms.
Experience developing monitoring improvements, detection tuning, or operational process development.
Experience supporting Incident Responder activities during major cyber security incidents.
Experience contributing to the development of monitoring use cases and detection improvements.
Applied knowledge of MITRE ATT&CK or equivalent adversary behaviour frameworks