Jobs

Incident Management Specialist


Job details
  • Pharaoh Capital
  • Chippenham
  • 1 week ago

SIEM Incident SME - Contract (DV Cleared)

Rate:£550pd - £650pd Inside IR35

Duration:6 months

Locations:Hybrid and then onsite 2/3 days per week in one of the following locations:Corsham, Portsmouth or Northallerton


Due to client requirements, all applicants must require the following, to be considered for this role:

  • Must holdactive DV Clearancethat has not lapsed
  • Security Information and Event Management/Incident Management experience


Role Description:

We are seeking a skilledSIEM / Incident Subject Matter Expertto join our clients expanding cybersecurity team. In this role, you will be responsible for designing, delivering, and maintaining operational cybersecurity capabilities. Your focus will be on conducting proactive, risk-based monitoring on priority C4IS/networks to identify both internal and external cyber threats and attacks.


Responsibilities:

  • Develop and integrate security event monitoring and incident management services.
  • Respond to security incidents as part of an incident response team.
  • Implement metrics and dashboards for enhanced visibility into the Enterprise infrastructure.
  • Utilize the SOAR platform for playbook automation and case management to streamline processes.
  • Produce documentation to ensure repeatability and standardization of security operating procedures.
  • Enhance investigative methods using SOC software toolsets for better analysis recognition.
  • Maintain a baseline of system security in line with the latest threat intelligence and trends.
  • Participate in root cause analysis of incidents with enterprise engineers.
  • Provide SME guidance on various information security standards and best practices.
  • Offer strategic and tactical security guidance, including evaluating technical controls.
  • Engage in the CRM process and collaborate with SOC engineers to maintain up-to-date security alert dashboards.
  • Document, validate, and create operational processes to aid SOC development.
  • Assist in prioritizing and coordinating the protection of critical cyber defense infrastructure.
  • Build, install, configure, and test dedicated cyber defense hardware.
  • Support junior analysts in managing SOC systems.


Essential Experience:

  • Must hold active DV Clearance
  • Experience with ELK (Elastic, Logstash, Kibana) and Tanium.
  • Familiarity with Enterprise ICS/network architectures and technologies.
  • Proficient in SIEM solutions, including use case identification, creation, deployment, and tuning.
  • Previous experience mentoring or coaching junior analysts.
  • Knowledge of MITRE ATT&CK and Cyber Kill Chain frameworks.
  • Skilled in maintaining Microsoft directory services and using virtualization software.
  • Understanding of key security frameworks (e.g., ISO, NIST 800-53, 800-171, 800-172, C2M2).
  • Excellent communication skills, particularly in writing Defense/Government documentation.


Desirable Qualifications:

  • Broad Spectrum Cyber Course (SANS SEC401 or SEC501 or equivalent).
  • SIEM Design, Architecture and Analyst Course (SANS SEC455 or SEC555 or equivalent).
  • Advanced Analyst Course (SANS SEC503 or equivalent).

Sign up for our newsletter

The latest news, articles, and resources, sent to your inbox weekly.

Similar Jobs

Service Delivery Analyst

Service Delivery AnalystLocation: Stoke/ManchesterAbout usA leading and expanding motor insurance group, renowned for staff reward and recognition, is looking to add to our Service Delivery Team.Purpose of role:The purpose of the Service Delivery Analyst is to embed control and governance processes to protect and improve service, in line with business...

Manchester

Threat & Vulnerability Management Specialist

Job summaryClient is seeking a highly skilled Threat and Vulnerability Management Specialist to join the team.Key skills required for this roleThreat & Vulnerability Management SpecialistImportantThreat and vulnerability management specialistJob descriptionIntroductionOur client, a leading technology company, is seeking a talented TVM Specialist to join their team. As a TVM Specialist, you...

Matchtech

SOC SME Coaching Specialist

SOC SME COACHING SPECIALIST REMOTE WITH OCCASIONAL TRIPS TO LONDONFLEXIBLE RATES ASAP START6 MONTH CONTRACTJD / DELIVERABLES AVAILABLE Principal accountabilities• Mentorship and Training: Provide ongoing coaching and support to SOC team members, fostering a culture of continuous learning and improvement.• Skill Development: Design and deliver training programs on AWS, security...

Finsbury Square

Cyber Incident Response Specialist

Division:CISOCyber Defense Center (CDC) is part of the Chief Information Security Officer Office. The main responsibility of the team is to reduce the risk of Euroclear cyber threat surface by supervising for malicious intent targeted at Euroclear’s services, its supporting assets, and people. We do this through the Security Operations...

Euroclear

Infrastructure Engineer

Cloud and Hosting Specialist – InfrastructureLocation: Birmingham – 2 days a week Salary: Up to 60kSecurity Clearance : Active/EligibilityAt Khuda Technology, we are searching for a talented Cloud and Hosting Specialist to join our team and work with an international MSP. This role supports the Cloud and Data Centre management...

Birmingham

Security Operations Developer

Security Operations Developer - 45k!Nigel Frank are delighted to be working with one of the leading Microsoft Security Specialists in the UK. We are supporting our client with several new additions to their thriving UK team. As a Microsoft Partner they invest heavily in training and provide the time and...

City of London