Cyber Security Operations Specialist
Cyber Security Operations Specialist
We are looking for an experienced Cyber Security Operations Specialist to join a growing security team responsible for protecting a complex IT, cloud and operational technology environment.
You will play a key role in detecting, investigating and responding to cyber threats, while helping to improve the organisation''s overall security monitoring and incident response capabilities. The role combines hands-on security operations, tooling optimisation and continuous improvement across a varied technology estate.
Key responsibilities:
- Monitor, triage and investigate security alerts and incidents across IT, cloud and OT environments.
- Lead or support incident response, including containment, eradication, recovery and escalation.
- Develop and optimise SIEM detection rules, EDR policies and security monitoring capabilities.
- Reduce false positives and improve detection coverage using threat intelligence and incident learnings.
- Investigate threats using frameworks such as MITRE ATT&CK.
- Work closely with internal IT, engineering and security teams, alongside external security providers.
- Maintain and improve security playbooks, procedures, documentation and response processes.
- Support security reporting, compliance and audit activity.
- Provide technical guidance and support to junior members of the security team.
Key skills and experience:
- Strong background in Security Operations, SOC or Incident Response.
- Hands-on experience with SIEM and EDR platforms, ideally including Microsoft security technologies.
- Experience investigating security incidents across cloud and on-premise environments.
- Knowledge of Windows environments, with working knowledge of Linux/Unix.
- Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework.
- Experience improving detection logic, alert quality and security controls.
- Strong stakeholder communication and incident management skills.
- Knowledge of frameworks such as ISO 27001, NIS and GDPR would be beneficial.
Desirable certifications include: SC-200, SC-300, SC-400, MS-500, Security+ or similar cyber security qualifications.
The role will involve participation in an out-of-hours incident response rota, with occasional travel where required.
Other jobs of interest...
Perform a fresh search...
-
Create your ideal job search criteria by
completing our quick and simple form and
receive daily job alerts tailored to you!