Key responsibilities & accountabilities
We are seeking a skilled and proactive Senior Security Analyst to join our Global CISO team. This role is pivotal in maintaining and enhancing our business-as-usual (BAU) security posture. The successful candidate will be responsible for triaging and actioning SOC tickets responding to alerts from security controls supporting vendor engagements and contributing to the development of playbooks and incident response processes.
Key Responsibilities Include:
SOC Ticket Triage & Response:
- Monitor triage and respond to security events and incidents raised via the Security Operations Centre (SOC).
- Prioritize and escalate incidents based on severity and impact.
- Ensure threat intelligence capability is fed into decision making for ticket triage and updates to the management team
Alert Management:
- Action alerts generated by BAU security controls (e.g. SIEM EDR IDS/IPS).
- Perform initial investigation and remediation steps ensuring timely resolution.
- Action tickets from tech teams.
Vendor Support & Configuration:
- Collaborate with third-party vendors to support tool configuration updates troubleshooting and enhancements.
- Participate in regular vendor calls to ensure alignment with operational needs and security standards.
Playbook Development:
- Draft and maintain security playbooks to standardise response procedures for common incidents and alerts.
- Continuously improve playbooks based on lessons learned and evolving threat landscapes.
Incident Response Contribution:
- Support incident response activities including containment eradication and recovery.
- Assist in post-incident reviews and root cause analysis.
Continuous Improvement:
- Identify gaps in existing security controls and processes recommending improvements.
- Stay current with emerging threats vulnerabilities and industry best practices.
Reporting:
- Develop and send out a daily report on alerts triaging status and control coverage
Skills & Ability
- Proven experience in a SOC or security analyst role.
- Strong understanding of security technologies including SIEM EDR firewalls and vulnerability management tools.
- Experience with incident response and playbook development.
- Excellent communication and stakeholder management skills.
- Relevant certifications (e.g. CISSP GIAC CompTIA Security) are a plus.
- Experience working in multiple time zones
Qualifications :
Essential Knowledge & Experience
- 2 years of experience in a security operation role
- Experience using a range of security tools
- Experience using ticketing systems for triage
- Experience in financial services or regulated industries.
Remote Work :
No
Employment Type :
Full-time