Jobs

SIEM Incident Manager


Job details
  • Hortor
  • London
  • 2 days ago

SIEM Incident SME - Contract (DV Cleared)Rate: £550pd - £650pd Inside IR35Duration: 6 monthsLocations: Hybrid and then onsite 2/3 days per week in one of the following locations: Corsham, Portsmouth or NorthallertonDue to client requirements, all applicants must require the following, to be considered for this role:Must hold active DV Clearance that has not lapsedSecurity Information and Event Management/Incident Management experienceRole Description:We are seeking a skilled SIEM / Incident Subject Matter Expert to join our clients expanding cybersecurity team. In this role, you will be responsible for designing, delivering, and maintaining operational cybersecurity capabilities. Your focus will be on conducting proactive, risk-based monitoring on priority C4IS/networks to identify both internal and external cyber threats and attacks.Responsibilities:Develop and integrate security event monitoring and incident management services.Respond to security incidents as part of an incident response team.Implement metrics and dashboards for enhanced visibility into the Enterprise infrastructure.Utilize the SOAR platform for playbook automation and case management to streamline processes.Produce documentation to ensure repeatability and standardization of security operating procedures.Enhance investigative methods using SOC software toolsets for better analysis recognition.Maintain a baseline of system security in line with the latest threat intelligence and trends.Participate in root cause analysis of incidents with enterprise engineers.Provide SME guidance on various information security standards and best practices.Offer strategic and tactical security guidance, including evaluating technical controls.Engage in the CRM process and collaborate with SOC engineers to maintain up-to-date security alert dashboards.Document, validate, and create operational processes to aid SOC development.Assist in prioritizing and coordinating the protection of critical cyber defense infrastructure.Build, install, configure, and test dedicated cyber defense hardware.Support junior analysts in managing SOC systems.Essential Experience:Must hold active DV ClearanceExperience with ELK (Elastic, Logstash, Kibana) and Tanium.Familiarity with Enterprise ICS/network architectures and technologies.Proficient in SIEM solutions, including use case identification, creation, deployment, and tuning.Previous experience mentoring or coaching junior analysts.Knowledge of MITRE ATT&CK and Cyber Kill Chain frameworks.Skilled in maintaining Microsoft directory services and using virtualization software.Understanding of key security frameworks (e.g., ISO, NIST 800-53, 800-171, 800-172, C2M2).Excellent communication skills, particularly in writing Defense/Government documentation.Desirable Qualifications:Broad Spectrum Cyber Course (SANS SEC401 or SEC501 or equivalent).SIEM Design, Architecture and Analyst Course (SANS SEC455 or SEC555 or equivalent).Advanced Analyst Course (SANS SEC503 or equivalent).TPBN1_UKTJ

Sign up for our newsletter

The latest news, articles, and resources, sent to your inbox weekly.

Similar Jobs

Cyber Security Manager

RoleThe purpose of the Security function, is to bring the organisation’s operational, technical and information security risks under explicit management control through the SOC services.Key ResponsibilitiesWithin this position the successful Cyber Security Manager will take ownership of all operational, technical processes including:Security risk managementInformation and security operational incident managementDirect Management...

Transputec London

Dfir Manager

About the roleOur Digital Forensics and Incident Response (DFIR) team leads the technical investigation and response to cybersecurity incidents for the Tesco Group. They collaborate closely with other cybersecurity teams, including Security Operations, Threat Intelligence, Automation and Detection Engineering, to protect, detect, and respond to security threats across Tesco's diverse...

Tesco London

Commercial Security Analyst

DescriptionThe Varonis Commerical Security Analyst will deliver solutions to customers to assist in gaining visibility into security events affecting their environment and assist in operations efforts alongside Incident Response Managers. They will have intimate knowledge of Varonis and must be dedicated to a career in detecting and responding to insider...

Varonis London

Information Security Manager

Information Security Manager. London (Hybrid working)Our Client: We represent a distinguished institution in London, celebrated for its dedication to academic excellence and pioneering research initiatives. The Information Technology Services (ITS) within this client is crucial in bolstering both customers and employees success, with a dedicated Information Security team at the...

London

Information Security Manager

Information Security Manager . London (Hybrid working)Please double check you have the right level of experience and qualifications by reading the full overview of this opportunity below.Our Client:We represent a distinguished institution in London, celebrated for its dedication to academic excellence and pioneering research initiatives. The Information Technology Services (ITS)...

itecopeople London

Cloud Security Engineer (Microsoft)

Cloud Security Engineer | Manchester, Hybrid | £65,000-£75,000 - Endpoint, Intune, Azure ADAbout the Role:A world-leading professional services busienss is seeking a skilled Cloud Security Engineer to secure and maintain its critical cloud infrastructure. This role will be integral in safeguarding Microsoft Endpoint, Intune, and Azure Active Directory environments, ensuring...

Manchester