Direct message the job poster from Synergize Consulting
Operations Director at Synergize Consulting Ltd
We are looking for a Cyber Security Analyst to work out of Erskine...
The Tier 2 Cyber Security Analyst is a mid-tier position within the Cyber Threat Analysis Centre (CTAC), responsible for advancing the initial work conducted by Tier 1 Analysts and providing more in-depth analysis of potential threats to the organization. This role is crucial in escalated investigations, triage, and response to cyber incidents, while supporting the development and training of Tier 1 Analysts.
The Tier 2 Analyst works closely with senior and junior analysts to ensure seamless SOC operations and acts as a bridge between foundational and advanced threat detection and response functions.
1. Conduct escalated triage and analysis on security events identified by Tier 1 Analysts, determining threat severity and advising on initial response actions.
2. Apply expertise in SIEM solutions utilizing Kusto Query Language (KQL), to perform log analysis, event correlation, and thorough documentation of security incidents.
3. Identify and escalate critical threats to Tier 3 Analysts with detailed analysis for further action, ensuring rapid response and adherence to service Tier objectives (SLOs).
4. Investigate potential security incidents by conducting deeper analysis on correlated events and identifying patterns or anomalies that may indicate suspicious or malicious activity.
5. Use OSINT (Open-Source Intelligence) to enrich contextual data and enhance detection capabilities, contributing to a proactive stance on emerging threats.
6. Monitor the threat landscape and document findings on evolving threat vectors, sharing relevant insights with CTAC teams to enhance overall situational awareness.
7. Follow established incident response playbooks, providing feedback for enhancements and suggesting updates to streamline CTAC processes and improve threat response times.
8. Coordinate with Tier 3 Analysts and management to refine detection and response workflows, contributing to continuous SOC maturity.
9. Collaborate with Tier 3 Analysts on tuning SIEM and detection tools to reduce false positives and improve alert fidelity, submitting tuning requests and testing configurations when necessary.
10. Identify gaps in current detection content and work with Senior Analysts to develop and validate new detection rules and use cases tailored to the organization’s threat profile.
11. Act as a mentor to Tier 1 Analysts, offering guidance on triage and analysis techniques and facilitating on-the-job training to elevate their technical skills and operational efficiency.
12. Assist in training sessions and knowledge-sharing activities, providing feedback on areas for growth and contributing to a supportive learning environment within the SOC.
Experience required:
1. Understands advanced networking concepts, including IP addressing, basic network protocols, and how traffic flows within a network.
2. Advanced knowledge of Windows and Linux operating environments, including standard commands, file systems, and user authentication mechanisms.
3. Competence in using SIEM solutions (e.g., ArcSight, Azure Sentinel) for monitoring and log analysis; some exposure to additional analysis tools such as basic XDR platforms.
4. Proficient in Kusto Query Language (KQL) for log searches and filtering.
5. Familiar with OSINT techniques to aid in threat identification and information gathering.
6. Effective communication skills to collaborate with team members and stakeholders, both internally and externally, under the guidance of senior analysts.
7. Ability to explain technical issues clearly to non-technical audiences.
8. Ability to produce concise, structured reports outlining findings from investigations and monitoring activities.
9. Effective workload management to ensure timely completion of tasks within the SOC.
10. Willingness to collaborate, accept guidance, and learn from more experienced analysts.
11. Shows initiative in learning new technologies and techniques, leveraging training resources.
12. Ability to perform efficiently under high-pressure situations, following procedures to ensure consistent incident management.
Education and Professional Experience
1. University Degree/Diploma in Cyber Security or equivalent experience.
2. Additional IT certifications or experience such as CISSP, COMPTIA CySA+, GCIA, GCIH are desirable.
3. IT certifications like CASP or ITIL are advantageous.
4. Experience in a SOC or equivalent environment.
5. SC / DV clearance or willingness to obtain clearance, which requires being British born with a sole British passport.
6. Full Driving Licence.
7. Fluent in written and spoken English.
Position is onsite at Erskine, 6-month contract, circa £500/day inside IR35.
Seniority level
Mid-Senior level
Employment type
Contract
Job function
Information Technology
Industries
IT Services and IT Consulting
#J-18808-Ljbffr