Ref: 150362
Job description
* Minimum three years of hands-on experience in a Security
Operations Centre (SOC, CSOC, GSOC or equivalent) or a closely
related cyber monitoring environment.
* Proven expert‑level track record of conducting in‑depth analysis
of complex cyber‑security incidents and producing clear,
authoritative reports and recommendations for supporting teams
and external partners.
* Adept at extracting, normalising and interrogating raw log data
from diverse sources (e.g., Windows Event Logs, Linux syslog,
Sysmon, EDR/XDR platforms such as Microsoft Defender,
Sentinel One, or CrowdStrike) using SIEM and query tools
(Splunk, Microsoft Sentinel, Elastic Kibana). Able to filter, correlate
and visualise events to verify alerts, reconstruct attacker activity
across hosts, and provide actionable evidence for escalation and
remediation decision
* Hands-on packet-capture (PCAP) analysis experience –
extracting, filtering and interpreting network traffic with tools such
as Wireshark, tcpdump or Zeek to corroborate alerts, reconstruct
attack timelines and support escalation decisions.
Skill, Knowledge & Experience:
* Demonstrable ability to translate attacker TTPs and threat intel
into operational detection logic and to conduct structured quality or
peer reviews of analyst investigations, identifying gaps and
recommending improvements.
* Experience in designing, developing and maintaining detection
rules, alerts and analytics across SIEM, EDR/XDR and cloud
security tools (e.g., Splunk, Microsoft Sentinel, Azure, AWS).
* Experience supporting or mentoring less-experienced analysts,
providing constructive feedback on investigation quality and
reporting standards.
* Practical experience with automation or SOAR use cases,
identifying repetitive manual tasks and creating enrichment or
workflow improvements.
* Strong written and verbal communication skills, with a history of
producing clear investigation notes, escalation summaries and
documentation.
Apply for this role
Hi I'm Ben.
I manage this role
If you would like to know more about this role or similar jobs, please get in contact with me.
Recommend.
this role to a friend
Is this role revelant to any one you know?
Share it with them now.
