Cyber Defence Analyst
Core
Monitor computer systems for suspicious activity, triage and analyze security alerts, and manage cyber security incidents to protect core business platforms and data.
Role type
Tier 1 Cyber Security Analyst
Builds
Incident response workflows and detection logic for enterprise systems
Domain
Financial services cybersecurity
Deliverable
client delivery
Required skills
Incident management, SIEM tools (Splunk), Endpoint Detection and Response (MDE), cloud security (AWS/Azure), networking principles, OS knowledge, threat analysis, documentation
Preferred skills
GIAC certifications (GCIA, GCIH, GREM)
Technologies
Splunk, Microsoft Defender for Endpoints, AWS, Azure
Responsibilities
Monitor systems for suspicious activity, triage and analyze detection alerts, capture event details and artefacts, maintain event response documentation and post-mortems, escalate incidents to specialized teams, identify new detection logic for engineering teams
Seniority
Mid-Senior, hands-on IC