About this role
Capital One's mission is to change banking for good by bringing humanity, ingenuity and simplicity to banking. Sitting at the core of such values is our cyber security team, a team whose innate passion to safeguard allows Capital One to maintain the confidence of its customers while at the same time maintaining a strong market presence.
We are looking for a talented Cyber Security Analyst to join our Cyber Security Operations Center (CSOC) in Nottingham, UK. The Principal Security Analyst CSOC position will require a deep knowledge of network protocols and infrastructure, log investigation techniques, knowledge and understanding of cloud infrastructures, and incident handling experience. Not only will you need to know about the threats to networks, applications, cloud infrastructure, and theory regarding network protocols, but also the ability to proactively identify signs of misuse and abuse using various log sources.
The UK CSOC team is part of a 24/7 rotation that protects Capital One from Cyber threats.
What you’ll do
We want you to help us defend our business and customers from Cyber related attacks. A typical day would be arriving at work and then reviewing a variety of alerts that may represent a Cyber threat. Your job will be to investigate, and using a keen eye for detail, figure out if there is any risk for Capital One associated with each one.
At the end of the day, if there is no risk, great! If there is, you will use your skills (and a few more that we give you on the way!) to determine the best course to reduce or eliminate that risk.
Take a look at some of the things that you will be getting involved in;
* End-to-End Ownership: Head up complex investigations that require deep-dive analysis, from start to finish.
* Proactive Hunting: You design and execute hunting hypotheses to uncover threats that bypass traditional detection.
* Technical Mentorship: You act as a primary resource for our CSOC analysts, sharing your deep‑seated domain knowledge to level up the team's collective skill set.
* Continuous Improvement: You use your investigative insights to refine our processes and ensure our security tools are performing at their peak.
What we’re looking for
* Significant previous experience conducting Cyber Security investigations.
* In-depth knowledge and extensive hands‑on experience working with SIEM technology such as Elastic, Splunk or similar.
* Considerable evidence of working with system, cloud, application and network logs.
* Vast proven ability at analysing and identifying network traffic.
* Substantial working experience with PCAP analysis.
* Comprehensive experience analysing workstation or server logs across multiple operating system platforms.
Would be great if you had some of these too
* Proven previous experience working in a Security Operations Center (SOC) for a significant duration of time.
* Comprehensive understanding of AWS architecture, services and APIs.
* In-depth forensic analysis experience (Endpoint, Memory, Malware).
* Extensive hands‑on working experience evaluating and tuning alerts within a SIEM.
* Significant ability to leverage core security, cloud, and infrastructure technologies during investigations.
* Demonstrative evidence of experience administering or investigating Mac OS, Linux OS.
* One or more of the following certifications: CISSP, CISM, CCSP, Security+, CEH, SANS GIAC 503/504/508/509, AWS Security.
* Bachelor’s Degree in Information Technology, Cyber Security or Computer Science.
Where and how you'll work
This is a permanent position based in our Nottingham office.
We have a hybrid working model which gives you flexibility to work from our offices and from home.
You'll be based in our Nottingham office 3 days a week on Tuesdays, Wednesdays and Thursdays.
What’s in it for you
* High performers are rewarded with a role contributing to the roadmap of an organisation committed to transformation.
* Strong and diverse career progression, developing great people through Capital One University training programmes.
* Immediate access to core benefits including pension scheme, bonus, generous holiday entitlement and private medical insurance with flexible benefits such as season‑ticket loans, cycle to work scheme and enhanced parental leave.
* Open‑plan workspaces and accessible facilities designed to inspire and support you. The Nottingham head‑office has a fully‑serviced gym, subsidised restaurant, mindfulness and music rooms.
EEO Statement
Capital One is committed to diversity in the workplace.
#J-18808-Ljbffr