Cyber Defence Analyst
Core
Monitor enterprise computer systems for suspicious activity, triage security alerts, and manage cyber security incidents to protect core business platforms and data.
Role type
Tier 1 Cyber Security Analyst (Incident Response)
Builds
Incident response workflows and detection logic improvements
Domain
Financial Services / Cyber Security
Deliverable
client delivery
Required skills
SIEM tools (Splunk), Endpoint Detection and Response (EDR) tools, Microsoft Defender for Endpoints, cloud security (AWS/Azure), incident management, network protocols, operating systems, analytical problem-solving
Preferred skills
GIAC certifications (GCIA, GCIH, GREM), cloud platform experience
Technologies
Splunk, Microsoft Defender for Endpoints, AWS, Azure
Responsibilities
Monitor systems for suspicious activity, triage and analyze detection alerts, capture event details and artefacts, maintain event response documentation and post-mortems, escalate incidents to specialized teams, identify new detection logic for engineering teams
Seniority
Mid-Senior, hands-on IC