⚡ New
Cyber Defence Analyst
A&O Shearman
BelfastFull-timeMid LevelOn-site
Job Description
Job Description
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team, based in the A&O Shearman’s Belfast office.\n
\n
Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary.\n
\n
What you will do\n
\n
\nInvestigate escalations:\n
- \n
- Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm’s MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. \n
- Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. \n
- Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. \n
- \n
- Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone:\n
- \n
- Conduct initial triage and investigation. \n
- Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. \n
\n - Participate in security incident response exercises and contribute to post-exercise reviews. \n
- Be part of the Cyber Defence on-call rota, which may require out-of-hours work. \n
- Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. \n
- Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. \n
- \n
- Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. \n
- Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. \n
- \n
- Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm’s security posture by implementing controls and fostering awareness. \n
- Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. \n
What you will have \n
- \n
- At least 1+ years’ experience in a security operations or similar technical security role. \n
- Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. \n
- In-depth understanding of Networking and routing protocols (e.g.
TCP/IP) and services (e.g. DNS, SMTP).
\n - Cyber defence technologies and tooling, including:\n
- \n
- SIEM solutions \n
- Intrusion Detection/Prevention Systems (ID/PS) \n
- Threat and vulnerability management platforms \n
- Endpoint protection \n
- Firewalls \n
\n - Highly analytical mindset with strong problem-solving skills. \n
- Ability to interpret data flows, assess security events, and draw logical conclusions. \n
- Excellent written and verbal communication skills. \n
- Ability to collaborate effectively across technical and non-technical teams. \n
- High level of personal integrity and ethics, demonstrating an appropriate level of judgement. \n
- A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. \n
You will stand out if you have\n
- \n
- Bachelor’s degree in Information Security, Computer Science, Engineering, Technology, or a related field. \n
- Industry-recognised certifications such as:\n
- \n
- CISSP (Certified Information Systems Security Professional) \n
- CEH (Certified Ethical Hacker) \n
- CISM (Certified Information Security Manager) \n
- CompTIA Security+ \n
\n - Practical programming or scripting experience, particularly with:\n
- \n
- Python \n
- PowerShell \n
\n
NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here.\n
\n
\n#LI
Posted Today