Do you want to work for a global managed security service provider.
– Work with Azure Sentinel SIEM & Microsoft Defender EDR – Work in a brand new security operations centre opening in February 2024 – Get certifications paid for such as Microsoft SC-200, SC-300, SC-400 and SC-900
If this role is of interest to you please click apply!
Responsibilities: Conduct operations identifying, monitoring, investigating, and analysing security incidents Conduct security event investigation Hunt for suspicious activity based on anomalous activity and indicators of compromise from various intelligence feeds and toolsets. Contribute in the advancement of security policies, procedures, and automation. Monitor and analyse security events and alerts from multiple sources Separate true threats from false positives using network and log analysis and escalate possible intrusions and attacks. Provide support to incident investigation, handling, and response, including improving incident documentation. Initiate tickets, document, and escalate to higher-level security analysts. Contribute to incident response reporting and policy updates as needed. Perform triage of incoming issues (assess the priority, determine risk.)
Skills/Must have: – Experience with Microsoft Sentinel & Defender – Experience analysing event logs
Benefits: – 4x death in service – private healthcare – pension – 25 days annual leave + 8 bank holidays – 5 company holiday days