Methods Business and Digital Technology Limited
Daily rate: £645 inside IR35
Onsite: 4days/week in West Midlands
Summary:
Conducting pro-active, risk-based, protective monitoring on priority cloud-based Microsoft Azure C4IS/networks to identify internal and external cyber-threats/attacks. The analyst will work within Elastic and Azure Sentinel and conduct a broad range of tasks, including the monitoring of networks to actively remediate unauthorised activities.
Responsibilities
Develop and integrate security event monitoring and incident management services. Threat Detection and Analysis: Utilize your expertise in Elastic and Sentinel to monitor, detect, and analyse potential security threats and incidents. Leverage your proficiency in Elastic tools and technologies to optimise search queries, build dashboards, and develop custom alerts for proactive threat detection. Leverage your proficiency in Azure Sentinel tools and technologies to optimise search queries, build dashboards, and develop custom alerts for proactive threat detection. Respond to security incidents as they occur as part of an incident response team. Implement metrics and dashboards to give visibility of the Enterprise infrastructure. Use of the platform to assist with playbook automation and case management capabilities to streamline team processes and tools. Produce documentation to ensure the repeatability and standardisation of security operating procedures. Develop additional investigative methods using the environment’s software toolsets to enhance recognition opportunities for specific analysis. Maintain a baseline of system security according to latest threat intelligence and evolving trends. Participate in root cause analysis of incidents in conjunction with engineers across the enterprise. Provide Subject Matter Expertise (SME) on a broad range of information security standards and best practices. Offer strategic and tactical security guidance including valuation requirement of technical controls. Liaise with the environment’s engineers to maintain up-to-date dashboards of security alerts, to allow the Authority to better respond to an incident. Document, validate and create operational processes and procedures to help develop the environment. Assist in identifying, prioritising, and coordinating the protection of critical cyber defence infrastructure and key resources.
Skills & Experience
Essential
Bachelor’s degree in Computer Science, Information Technology, or related field. 5 years of relevant operational experience will be accepted in lieu of a degree. Proven experience as a Cyber Analyst with a focus on Security Operations. Strong expertise in using Elastic Stack, including Elasticsearch, Logstash, and Kibana. Strong expertise in using Azure Sentinel. Familiarity with other SIEM tools and security technologies. Knowledge of cybersecurity best practices, threat intelligence, and incident response. Excellent analytical and problem-solving skills. Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or Elastic Certified Engineer (ECE) are a plus.
Desirable
Proven experience using the MITRE ATT&CK and Kill Chain Frameworks
Additional?
Active DV clearance is preferred although an active SC clearance, with willingness to progress to DV clearance if required is acceptable. You will be required to work onsite for 4days/week
