CyberSOC Security Analyst
Role Description
Job Purpose
The role of the CyberSOC Security Analyst is responsible for log and event analysis using solutions like SIEM, IDS/IPS and different endpoint and EDR solutions. Reporting to the CyberSOC Team Leader and working closely with GOPS colleagues to provide a thorough analysis of the events and alerts that any of the Cyber Security Operations Centre (CyberSOC) supported tools generate. To be able to conduct the analysis you are required to have sufficient technical skills and knowledge of any specific customer requirements or routines. You must also know how to handle and report incidents in the Incident Management system, write knowledge base articles and engage in direct contact with customers.
In order to provide a solid analysis towards a customer you should be able to do both automatic and manual correlation based on all information available. You must also be passionate about security & love what you do.
Your responsibility as a Security Analyst means that you must deliver the expected quality towards our customers and you must continue to enhance your skills and knowledge in both technical and non-technical terms. To be successful in the role, you will be provided with tools and capabilities but it is also very important that you continue to develop your own skill set by both teaching others and yourself.
Key Responsibilities - Strategic
Actively provide feedback to the group and management about challenges and potential opportunities.
Help enhance the current delivery in both technical and non-technical terms.
Keep yourself updated from a security perspective about current threats, vulnerabilities and other relevant it security related risks.
Be aware of the SLA’s that are used and how they work towards overall delivery and specific customers.
Provide continuous feedback to your colleagues and management.
It is included in the role of the Security analysts to be TDM for one or more customers. See the role description for the TDM role in the Role Description Library.
Mandate according to the business plan, assignment, budget, result, annual goals and authorisation rules.
Key Responsibilities - Tactical
Understand and possess knowledge about customer networks and technology.
Understand how escalation and follow ups is done towards customers.
Maintain documentation and keep information updated.
Add new information to documentation system when necessary.
Participate in meetings both internally and externally.
Adhere to, and keep yourself updated on workflows, instructions and guidelines for the overall group.
Participate actively in reporting towards customers and management when desired.
Supervisory requirements of the role
The role has no direct reports, but as with all other members of the OCD-GOPS team, will be expected to contribute to the mentoring of junior staff, trainees and apprentices as required.
Skills & Experience
The CyberSOC Security Analyst will need to possess the following skills and experience:
Sufficient understanding of scripting languages such as Bash, Python and JavaScript.
Good knowledge of operating system concepts related to Windows, Linux and OS X.
Knowledge over technical products and their role in the IT security environment.
Solid understanding of malware, exploits, vulnerabilities and the overall threat landscape.
Understanding of the cyber kill chain and threat hunting concepts.
Good knowledge of red teaming procedures and tools used.
Key Responsibilities - Information Security
In common with all roles in OCD-GOPS, this role must comply with the Information Security policies and procedures in place at the time, as specified in the OCD-GOPS-ISMS Space.
Key Responsibilities - Data Protection
In common with all roles in OCD-GOPS, this role must comply with the Data Protection policies and procedures in place at the time, as specified in the Group Data Protection Space.
Location, Travel and Working Hours
This role will be based in a GOPS CyberSOC hub in Malmo, Sweden.
- Department
- CyberSOC
- Locations
- Malmö
- Remote status
- Hybrid
- Required languages
- English, Swedish