Cyber Defence Senior Analyst
hace 10 días
Belfast
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. The Cyber Defence Senior Analyst will reside within the firm’s information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. • Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm’s Managed Security Service Provider (MSSP) to identify potential incidents., • Assist and advise junior colleagues during investigations where additional experience is required., • Conduct initial triage and investigation of confirmed incidents., • Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process., • Participate in security incident response exercises and contribute to post-exercise reviews., • Be part of the Cyber Defence on-call rota, which may require out-of-hours work., • Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model., • Maintain and improve playbooks and process documentation for Cyber Defence., • Ensure documentation reflects current threat landscapes and operational practices., • Implement and enhance cyber defence tooling and processes under senior oversight., • Develop new detection definitions and use cases for monitoring tools., • Mentor junior colleagues to support their professional development and operational effectiveness., • Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness., • Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes., • Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations., • Provide cyber defence guidance to business stakeholders, translating technical concepts into business language., • Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs)., • Assist the Information Security GRC team with client queries and audits from a cyber defence perspective., • Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing., • Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP)., • Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls., • Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions., • Demonstrated ability to investigate complex security issues and propose effective solutions., • Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams., • A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field., • Bachelor’s degree in Information Security, Computer Science, Engineering, Technology, or a related field., • Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+, • Experience working with major cloud service providers (CSPs) technologies, such as:, • Microsoft Azure, • Google Cloud Platform (GCP), • Amazon Web Services (AWS), • Prior legal firm or professional services firm experience, • Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here. #J-18808-Ljbffr