
- The key purpose of this role is to lead the local Security Engineering function leveraging your knowledge of industry best practices, good leadership qualities, Team management, good judgment and problem solving skills to execute security engineering activities.
- You will be working as part of the larger InfoSec team helping to design, deliver and operate the groups security capabilities. You will coordinate local resources and deal with both user and third party queries. This role may involve some travel within the UK and possibly to our Offices in India.
Core Responsibilities:
- Assist with technical control design, implementation and monitoring, support incident responses and assist with providing root cause analysis support for incidents.
- Monitor for attacks, intrusions, and un-usual, unauthorised or illegal activities when the Security Analysts are finding the instance challenging.
- Keep an eye on the alerts from systems including SEIM solutions and vulnerability monitoring services and check if the Analysts are able to handle the flow appropriately, if not then jump in and investigate if there are any abnormality in the inflow.
- Monitor identity and access management, including monitoring for abuse of permissions by authorised systems users if the stats are fluctuating or when you see a spike in the alerts.
- Assist with Information Security Reporting and metrics, providing input into improving information security reporting and metrics.
- Identify/recommend improvements on internal investigation capabilities via tool and process building/automation.
- Provide support to recovering from security breaches; participate in investigation and remediation of security incidents, which may include working as part of a team
- Assist in perform deep-dive incident analysis, determining if critical systems or data sets has been impacted.
- Assist with the definition and configuration of compliance policies for security technologies.
- Conduct research on emerging threats in support of security enhancement and development efforts; recommend security improvements, upgrades, and/or purchases.
- Support the incident response of minor incidents by advising on remediation actions, escalating major incidents to the designated parties.
- Recording lessons learnt whilst supporting on improving existing processes and procedures.
- Providing support of new analytic methods for detecting threats. Continuously seeking to identify potential service and process improvements.
- Participate in the implementation of technologies and platforms supporting the corporate infrastructure.
- Ensure that you fully understand and comply with the organisations Risk Management Policies as they relate to your area of responsibility.
- Ensure that you fully understand and comply with the organisations Data Governance Policies as they relate to your area of responsibility.
- Maintain the companys compliance standards and ensure timely completion of all mandatory on-line training modules and attestations.
- Monitoring technical controls that are in place
- Addressing quires raised by the Security Analysts during investigation or other BAU.
- Assist Security Analysts in decision making and help in setting up standards.
- Will be responsible to suggest new fine tunings in the environment to the vendor or to the technical counterparts.
- Process review and upgradation recommendation when required.
- Setting up simplified and effective steps in BAU that in turn improves the quality of the work
- Implementation of new process based on business requirements and communicating the same with the team
- Team building and team management activities will be one of the key responsibility.
Experience Requirements:
- Overall 8 12 years of industry experience.
- 6 plus years of previous hands-on experience undertaking a specialist IT Security role in large IT environments is essential.
- 4 years experience in defining and managing action plans to remediate compliance gaps is essential.
- 3+ years practical experience in supporting cyber incidents response activities is essential.
- 2 years experience supporting security work streams within IT and business projects is essential.
- 2 years experience in supporting Cloud security alerts is essential.
Knowledge Requirements:
- Excellent knowledge and experience with information security frameworks and concepts, trends and practices is essential.
- Detailed knowledge of firewalls, vulnerability management platforms, End Point Protection technologies, VLANs and custom routing is essential.
- Sound understanding of targeted cyber-attack (APT), how to analysis these and respond to and mitigate against the attacks is essential.
- Sound knowledge of project delivery phases
- Should knowledge of preparing and describing security requirements for projects
- Intermediate knowledge of working within Risk management frameworks such as RCSA is desirable.
- Intermediate knowledge of and experience of using tools for security monitoring (e.g. Rapid7, Websense, Splunk, QRadar, Intel MacAfee, ArcSight, RSA NetWitness), is essential.
- Intermediate cloud security knowledge is essential.
- Excellent knowledge of Networking TCPIP protocols is essential.
- Intermediate knowledge of IT Infrastructure (Microsoft and Linux) is essential.
- Intermediate Knowledge of Windows Active Directory environments, domain trust, federated authentication, design and implementation is desirable.
- Intermediate knowledge of Information Security standards like ISO 27001 Cyber Essentials is essential.
- Basic knowledge of and exposure dealing with external and internal auditors is desirable.
- Analytical Skills and Strong Cyber Security knowledge is a key for this role
- Good Judgemental, Problem Solving and Good Investigation Skills.
- Knowledge on Access management best practices
- Up to date with emerging threats and technology that are in use to prevent exploitation and attack.
- Knowledge on Ethical Hacking tools and the knowledge on how the tools are used by threat actors.
- Basic idea on Policy and Policy defining based on the infrastructure.
- Creating custom alerts or rules on multiple security tools
- Creating appropriate dashboards for the team to monitor with ease based on the environment on demand.
Skill and Competency Requirements:
- Proven team/resource management experience.
- Intermediate skills in respect of ability to trouble-shoot complex, technical, multi-site and multi-disciplinary problems are essential.
- Basic skills in respect of managing infrastructure and change within PCI compliant environments are desirable.
- Basic skills in respect of Application development with an understanding of secure code development are desirable
- Intermediate skills performing deep-dive incident analysis by correlating data from various sources is essential
- Excellent communication skills including presentation skills, with an ability to communicate with a range of technical and non-technical team members
- Time-management and organizational skills to manage a variety of tasks, prioritise workload and meet deadlines
- Ability to work under pressure especially when dealing with threats and at a time of high demand
- Will need to follow excellent email etiquette
Required Qualifications/Certifications:
- BE or B. Tech or Equivalent in Computer Science or Information Technology
- Computer related Degree or equivalent or equivalent IT Security certification is desirable
- Active CISSP, SSCP, SANS, CEH certifications, Azure AZ500 or equivalents is desirable
Didn’t find the job appropriate? Report this Job