⚡ New

Cyber Defence Analyst

A&O Shearman

BelfastFull-timeMid LevelOn-site

Job Description

Job Description

We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team, based in the A&O Shearman’s Belfast office.\n
\n
Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary.\n
\n
What you will do\n
\n
\nInvestigate escalations:\n

    \n
  • Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm’s MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary.
  • \n
  • Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team.
  • \n
  • Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required.
  • \n
Incident Response:\n
    \n
  • Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone:\n
      \n
    • Conduct initial triage and investigation.
    • \n
    • Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately.
    • \n
  • \n
  • Participate in security incident response exercises and contribute to post-exercise reviews.
  • \n
  • Be part of the Cyber Defence on-call rota, which may require out-of-hours work.
  • \n
  • Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model.
  • \n
  • Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations.
  • \n
Tooling and Process Improvement:\n
    \n
  • Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function.
  • \n
  • Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence.
  • \n
Collaboration and Advisory:\n
    \n
  • Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm’s security posture by implementing controls and fostering awareness.
  • \n
  • Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language.
  • \n
\n
What you will have \n
    \n
  • At least 1+ years’ experience in a security operations or similar technical security role.
  • \n
  • Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing.
  • \n
  • In-depth understanding of Networking and routing protocols (e.g.

    TCP/IP) and services (e.g. DNS, SMTP).

  • \n
  • Cyber defence technologies and tooling, including:\n
      \n
    • SIEM solutions
    • \n
    • Intrusion Detection/Prevention Systems (ID/PS)
    • \n
    • Threat and vulnerability management platforms
    • \n
    • Endpoint protection
    • \n
    • Firewalls
    • \n
  • \n
  • Highly analytical mindset with strong problem-solving skills.
  • \n
  • Ability to interpret data flows, assess security events, and draw logical conclusions.
  • \n
  • Excellent written and verbal communication skills.
  • \n
  • Ability to collaborate effectively across technical and non-technical teams.
  • \n
  • High level of personal integrity and ethics, demonstrating an appropriate level of judgement.
  • \n
  • A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field.
  • \n
\n
You will stand out if you have\n
    \n
  • Bachelor’s degree in Information Security, Computer Science, Engineering, Technology, or a related field.
  • \n
  • Industry-recognised certifications such as:\n
      \n
    • CISSP (Certified Information Systems Security Professional)
    • \n
    • CEH (Certified Ethical Hacker)
    • \n
    • CISM (Certified Information Security Manager)
    • \n
    • CompTIA Security+
    • \n
  • \n
  • Practical programming or scripting experience, particularly with:\n
      \n
    • Python
    • \n
    • PowerShell
    • \n
  • \n
\n
NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here.\n
\n
\n#LI

Posted Today

Related Jobs

Related Searches

Apply Now