Security Events Analyst - SC or NATO Secret Clearance
LA International Computer Consultants Ltd
This job has now expired please search on the home page to find live IT Jobs.
As a First Line Security Event Analyst (FLSEA), the incumbent will perform initial analysis of logs and network traffic, determine alert severity and escalate when required. The analyst will collate information and present findings in a clear, structured format, providing remediation recommendations and first line response where applicable.
* Conduct research and assessments of security events within the Cyber Security Centre team
* Provide analysis of firewall, IDS, anti-virus and other network sensor produced events and present findings
* Appropriately leverage the comprehensive extended toolset (e.g. Log Collection, Intrusion Detection, Packet Capture, VA, Network Devices etc.) for enhancing investigations
* Support the end-to-end Incident Handling process
* Propose optimisations and enhancements which help to both maintain and improve the Cyber Security posture
Skills and Experience include:
A university degree in a technical subject with a focus on Information Technology (IT), obtained from a nationally recognised/certified institution in addition to a minimum of 1 year experience in the field of cyber security analysis. The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis. Similarly, candidate's lacking experience can compensate by demonstrating a high level of knowledge in the field of cybersecurity.
* Comprehensive knowledge of the principles of computer and communications security including knowledge of TCP/IP networking, Windows and Linux operating systems
* Broad understanding of common network security threats and mitigation techniques
Experience in the following:
* Security Information and Event Management products (SIEM) - e.g. ArcSight, Splunk
* Analysis of Network Based Intrusion Detection Systems (NIDS) events - e.g. SourceFire, Palo Alto Network Threat Prevention
* Log analysis from a variety of sources (e.g. Firewalls, Proxies, Routers, DNS and other security appliances)
* Network traffic capture analysis using Wireshark
* Logical approach to analysis and ability to perform structured security investigations using large, complex data sets
* Good written and spoken communication skills
* Ability to work independently and as part of a team
* Holding industry leading certification in the area of cyber security such as GCIA, GNFA, GCIH
* Computer Incident Response Centre (CIRT), Computer Emergency Response Team (CERT)
* Proficiency in Intrusion/Incident Detection and Handling
Due to the nature and urgency of this post, candidates holding or who have held high level security clearance in the past are most welcome to apply. Please note successful applicants will be required to be security cleared prior to appointment which can take up to a minimum 10 weeks.
LA International Computer Consultants Ltd is an HMG Approved Consultancy and operates as an IT & Engineering Consultancy or as an Employment Business & Agency, depending upon the precise nature of the work, for security cleared jobs or non-clearance vacancies, we welcome applications from all sections of the community and from people with diverse experience and backgrounds.
Award Winning LA International Computer Consultants Ltd (Recruiter Awards for Excellence - Best IT, Best Public Sector & Gold Awards) and the most prestigious award that any business can receive The Queens Award for Enterprise: International Trade 2015.