SecOps Engineer, Hybrid Working, Hatfield, Competitive Salary plus Benefits! Join Our Team: SecOps Engineer Needed Are you passionate about IT security and eager to work at the forefront of protecting IT infrastructure? We are seeking a skilled SecOps Engineer to join my clients dynamic team, offering a pivotal role in bridging the gap between information security and IT operations. Your expertise will be crucial in managing application, infrastructure, and network security, ensuring a proactive approach is taken to the management of vulnerabilities. This is a brand-new position within my client's IT division. This will provide you with the opportunity to introduce a new way of working and will best suit a confident person with a self-starter attitude to be willing to get to know the wider business and collaborate. As a SecOps Engineer, you will be entrusted with a broad spectrum of security technologies, with an immediate focus on fortifying the security posture of their multi-country IT infrastructure and minimising vulnerabilities. Your responsibilities will include: - Creating and implementing security solutions across on-premises and cloud platforms. - Vigilant monitoring of security systems for potential threats and efficient incident management. - Establishing technical standards aligned with corporate security policies and regulatory compliance. - Conducting thorough vulnerability assessments and driving effective remediation strategies. - Engaging in security architecture reviews to identify and rectify gaps. - Playing an active role in the Change Advisory Board to manage the security aspects of IT changes. - Leading the response to high-priority security incidents within the organisation. You'll work with tools like Varonis DatAdvantage, Qualys, SCCM, Symantec Endpoint Protection, QRadar, and more, across platforms such as Azure, AWS, and Microsoft Office365. Knowledge of Active Directory, network protocols, and virtual platforms is highly desirable. This role is not just a job; it's an opportunity to make a significant impact on the security and integrity of my client's IT operations. If you are ready to take on this challenge and contribute to their mission of maintaining a secure and resilient IT environment, apply now!
19/04/2024
Full time
SecOps Engineer, Hybrid Working, Hatfield, Competitive Salary plus Benefits! Join Our Team: SecOps Engineer Needed Are you passionate about IT security and eager to work at the forefront of protecting IT infrastructure? We are seeking a skilled SecOps Engineer to join my clients dynamic team, offering a pivotal role in bridging the gap between information security and IT operations. Your expertise will be crucial in managing application, infrastructure, and network security, ensuring a proactive approach is taken to the management of vulnerabilities. This is a brand-new position within my client's IT division. This will provide you with the opportunity to introduce a new way of working and will best suit a confident person with a self-starter attitude to be willing to get to know the wider business and collaborate. As a SecOps Engineer, you will be entrusted with a broad spectrum of security technologies, with an immediate focus on fortifying the security posture of their multi-country IT infrastructure and minimising vulnerabilities. Your responsibilities will include: - Creating and implementing security solutions across on-premises and cloud platforms. - Vigilant monitoring of security systems for potential threats and efficient incident management. - Establishing technical standards aligned with corporate security policies and regulatory compliance. - Conducting thorough vulnerability assessments and driving effective remediation strategies. - Engaging in security architecture reviews to identify and rectify gaps. - Playing an active role in the Change Advisory Board to manage the security aspects of IT changes. - Leading the response to high-priority security incidents within the organisation. You'll work with tools like Varonis DatAdvantage, Qualys, SCCM, Symantec Endpoint Protection, QRadar, and more, across platforms such as Azure, AWS, and Microsoft Office365. Knowledge of Active Directory, network protocols, and virtual platforms is highly desirable. This role is not just a job; it's an opportunity to make a significant impact on the security and integrity of my client's IT operations. If you are ready to take on this challenge and contribute to their mission of maintaining a secure and resilient IT environment, apply now!
Position: Windows/Dell Infra Admin Location: Rugby, UK Duration: Permanent JOB DESCRIPTION: As a Senior Windows Infrastructure Admin/Engineer, you'll have a broad remit of responsibilities across the entire Windows infrastructure, service operations and support, including Active Directory, DNS, DHCP, Group policy, MFA (Multi-Factor Authentication) and Windows Server 2003 to 2012 R2 and Widows desktop solutions. You will proactively troubleshoot complex issues, devising innovative solutions and proactively introducing improvements, enhancements, and automation. Working with a wide variety of platforms and programming languages, you will be a key player in delivering a reliable, high-quality trading environment as part of a diverse, globally distributed team. Essential Responsibilities/Qualifications: Take ownership of Active Directory and Windows Server infrastructure, service operations and support. Proven track record in a similar role supporting and maintaining Microsoft AD & Server Environments. Lead on all phases of Active Directory and Windows Server estate life cycle management. Lead on troubleshooting Active Directory, DNS, DHCP, MFA and Group Policy issues. Strong technical experience in administering MFA (Multi-Factor Authentication) technologies across server and client components. Actively manage and monitor Active Directory and Server estate related ServiceNow tickets, and remediations from monitoring and alerting systems. Strong Windows Support Skills - 2012 to 2019. Experience in supporting MS Exchange. Experience in Microsoft 365 services and Endpoint Manager Good knowledge of VMWare ESX. Strong PowerShell, SCCM and SCOM skills. Contribute to IT infrastructure related security, maintenance, performance, capacity, and life cycle management. Contribute reports on infrastructure operations, services, and major incidents. Create and maintain work plans, design, and operations documentation sets. Create and review change requests to support project delivery and operational change. Work as part of a team to deliver complex solutions as lead specialist, project team resource or technical support. Good understanding of ITIL & related processes. Liaise with third parties and vendors. ITILv3/ITIL4 certified or recent relevant experience working in ITIL controlled environment. Experience writing process documentation including operational support guidelines, policies, and procedures. Strong Change management, Incident Management and Problem Management processes. Ability to create and maintain technical and design documents. Must be willing to work out of Rugby, UK site (subject to COVID regulations). Candidate must have the valid SC Clearance. Look forward to your response at earliest.
18/04/2024
Full time
Position: Windows/Dell Infra Admin Location: Rugby, UK Duration: Permanent JOB DESCRIPTION: As a Senior Windows Infrastructure Admin/Engineer, you'll have a broad remit of responsibilities across the entire Windows infrastructure, service operations and support, including Active Directory, DNS, DHCP, Group policy, MFA (Multi-Factor Authentication) and Windows Server 2003 to 2012 R2 and Widows desktop solutions. You will proactively troubleshoot complex issues, devising innovative solutions and proactively introducing improvements, enhancements, and automation. Working with a wide variety of platforms and programming languages, you will be a key player in delivering a reliable, high-quality trading environment as part of a diverse, globally distributed team. Essential Responsibilities/Qualifications: Take ownership of Active Directory and Windows Server infrastructure, service operations and support. Proven track record in a similar role supporting and maintaining Microsoft AD & Server Environments. Lead on all phases of Active Directory and Windows Server estate life cycle management. Lead on troubleshooting Active Directory, DNS, DHCP, MFA and Group Policy issues. Strong technical experience in administering MFA (Multi-Factor Authentication) technologies across server and client components. Actively manage and monitor Active Directory and Server estate related ServiceNow tickets, and remediations from monitoring and alerting systems. Strong Windows Support Skills - 2012 to 2019. Experience in supporting MS Exchange. Experience in Microsoft 365 services and Endpoint Manager Good knowledge of VMWare ESX. Strong PowerShell, SCCM and SCOM skills. Contribute to IT infrastructure related security, maintenance, performance, capacity, and life cycle management. Contribute reports on infrastructure operations, services, and major incidents. Create and maintain work plans, design, and operations documentation sets. Create and review change requests to support project delivery and operational change. Work as part of a team to deliver complex solutions as lead specialist, project team resource or technical support. Good understanding of ITIL & related processes. Liaise with third parties and vendors. ITILv3/ITIL4 certified or recent relevant experience working in ITIL controlled environment. Experience writing process documentation including operational support guidelines, policies, and procedures. Strong Change management, Incident Management and Problem Management processes. Ability to create and maintain technical and design documents. Must be willing to work out of Rugby, UK site (subject to COVID regulations). Candidate must have the valid SC Clearance. Look forward to your response at earliest.
LA International Computer Consultants Ltd
Hereford, Herefordshire
DV Cleared Onsite in Hereford Duration: 6 months initially Market Rates via Umbrella Role Description: Cyber Defence Engineer will join a growing security team responsible for the testing, implementation, deployment, maintenance, configuration and troubleshooting of the SOC's technology stack (hardware and software). The engineer will also assist with the continued development and maintenance of data pipelines and signature updates and the professional development of the system engineering team. Tasks: * Perform system administration on specific cyber defence applications and systems to include installation, configuration, maintenance, troubleshooting, backup and restoration. * Manage system/server resources including performance, capacity, availability, serviceability, and recoverability. * Diagnose and resolve customer reported system incidents, problems, and events to ensure continuing operability. * Coordinate with SOC and CTI Analysts to assist in the development of signatures which can be implemented on cyber defence network tools in response to new or observed threats within the network environment or enclave. * Manage the compilation, cataloguing, distribution, and retrieval of data from a range of enterprise networks and data sources. * Implement data management standards, requirements, and specifications. * Develop data standards, policies, and procedures. * Analyse data sources to provide actionable recommendations and facilitate data-gathering methods. * To share knowledge, skills and experience, create and improve documentation, and train new members of the data engineering team. Knowledge: * Knowledge of big data technologies and ecosystems (eg, NiFi). * Knowledge of current market and emerging leaders in data analytical and SIEM platforms. * Knowledge of network security implementations (eg, host-based IDS, IPS), including their function and placement in a network. * Knowledge of intrusion detection systems and signature development. * Knowledge of Front End collection systems, including network traffic collection, filtering, and selection. * Knowledge of system administration concepts for operating systems such as but not limited to Unix/Linux, IOS, Android, and Windows operating systems. * Knowledge of cyber defence and information security policies, procedures and regulations. * Knowledge of network security architecture concepts including topology, protocols, components and principles. Skills/Experience: * Previous experience of Enterprise ICS/network architectures and technologies. * Working with frameworks and technologies that support data-intensive distributed applications. * Experience maintaining and administrating data analytical and SIEM platforms. * Experience using host and network-based IDS/IPS. Experience using packet capture solutions. * Skill in developing and deploying signatures. * Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). * Ability to provide technical and service leadership to junior SOC Engineers (mentor/coach). Desirable Qualifications/Certifications * Red Hat System Administration I & II (RH124/RH134). * Baseline Cyber Courses eg Cyber Foundation Pathway, SANS SEC 301 Intro to Information Security, SANS 401 Security Essentials Bootcamp. * Certified engineer in a market leading data analysis/SIEM platform. * SANS SEC501 Advanced Security Essentials Enterprise Defender. * SANS SEC 511 Continuous Monitoring & Security Operations. * SANS SEC555: SIEM with Tactical Analytics Available locations: -Hereford -Northallerton -Corsham -Portsmouth Due to the nature and urgency of this post, candidates holding or who have held high level security clearance in the past are most welcome to apply. Please note successful applicants will be required to be security cleared prior to appointment which can take up to a minimum 18 weeks. LA International is a HMG approved ICT Recruitment and Project Solutions Consultancy, operating globally from the largest single site in the UK as an IT Consultancy or as an Employment Business & Agency depending upon the precise nature of the work, for security cleared jobs or non-clearance vacancies, LA International welcome applications from all sections of the community and from people with diverse experience and backgrounds. Award Winning LA International, winner of the Recruiter Awards for Excellence, Best IT Recruitment Company, Best Public Sector Recruitment Company and overall Gold Award winner, has now secured the most prestigious business award that any business can receive, The Queens Award for Enterprise: International Trade, for the second consecutive period.
17/04/2024
Project-based
DV Cleared Onsite in Hereford Duration: 6 months initially Market Rates via Umbrella Role Description: Cyber Defence Engineer will join a growing security team responsible for the testing, implementation, deployment, maintenance, configuration and troubleshooting of the SOC's technology stack (hardware and software). The engineer will also assist with the continued development and maintenance of data pipelines and signature updates and the professional development of the system engineering team. Tasks: * Perform system administration on specific cyber defence applications and systems to include installation, configuration, maintenance, troubleshooting, backup and restoration. * Manage system/server resources including performance, capacity, availability, serviceability, and recoverability. * Diagnose and resolve customer reported system incidents, problems, and events to ensure continuing operability. * Coordinate with SOC and CTI Analysts to assist in the development of signatures which can be implemented on cyber defence network tools in response to new or observed threats within the network environment or enclave. * Manage the compilation, cataloguing, distribution, and retrieval of data from a range of enterprise networks and data sources. * Implement data management standards, requirements, and specifications. * Develop data standards, policies, and procedures. * Analyse data sources to provide actionable recommendations and facilitate data-gathering methods. * To share knowledge, skills and experience, create and improve documentation, and train new members of the data engineering team. Knowledge: * Knowledge of big data technologies and ecosystems (eg, NiFi). * Knowledge of current market and emerging leaders in data analytical and SIEM platforms. * Knowledge of network security implementations (eg, host-based IDS, IPS), including their function and placement in a network. * Knowledge of intrusion detection systems and signature development. * Knowledge of Front End collection systems, including network traffic collection, filtering, and selection. * Knowledge of system administration concepts for operating systems such as but not limited to Unix/Linux, IOS, Android, and Windows operating systems. * Knowledge of cyber defence and information security policies, procedures and regulations. * Knowledge of network security architecture concepts including topology, protocols, components and principles. Skills/Experience: * Previous experience of Enterprise ICS/network architectures and technologies. * Working with frameworks and technologies that support data-intensive distributed applications. * Experience maintaining and administrating data analytical and SIEM platforms. * Experience using host and network-based IDS/IPS. Experience using packet capture solutions. * Skill in developing and deploying signatures. * Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). * Ability to provide technical and service leadership to junior SOC Engineers (mentor/coach). Desirable Qualifications/Certifications * Red Hat System Administration I & II (RH124/RH134). * Baseline Cyber Courses eg Cyber Foundation Pathway, SANS SEC 301 Intro to Information Security, SANS 401 Security Essentials Bootcamp. * Certified engineer in a market leading data analysis/SIEM platform. * SANS SEC501 Advanced Security Essentials Enterprise Defender. * SANS SEC 511 Continuous Monitoring & Security Operations. * SANS SEC555: SIEM with Tactical Analytics Available locations: -Hereford -Northallerton -Corsham -Portsmouth Due to the nature and urgency of this post, candidates holding or who have held high level security clearance in the past are most welcome to apply. Please note successful applicants will be required to be security cleared prior to appointment which can take up to a minimum 18 weeks. LA International is a HMG approved ICT Recruitment and Project Solutions Consultancy, operating globally from the largest single site in the UK as an IT Consultancy or as an Employment Business & Agency depending upon the precise nature of the work, for security cleared jobs or non-clearance vacancies, LA International welcome applications from all sections of the community and from people with diverse experience and backgrounds. Award Winning LA International, winner of the Recruiter Awards for Excellence, Best IT Recruitment Company, Best Public Sector Recruitment Company and overall Gold Award winner, has now secured the most prestigious business award that any business can receive, The Queens Award for Enterprise: International Trade, for the second consecutive period.
SAP Basis Consultant - Contract A leading organisation is looking for a SAP Basis Consultant that will focus on the maintenance, support, and optimization of the SAP systems landscape. Your main responsibility will be to maintain the stability, efficiency, and security of our SAP system, which involves handling installations, upgrades, and patches. This position demands solid technical skills in SAP Basis administration, along with the capability to work well with teams across different functions. Key Responsibilities for the SAP Basis Consultant : Previous experience as a SAP Basis Consultant/Analyst/Engineer. Administer and maintain SAP systems, including installation, configuration. SAP Basis Netweaver and Hana database maintenance, support and tuning. Monitor system performance and troubleshoot issues to ensure optimal uptime and reliability. Responsible for the analysis of error trends and problem management. Incident response Documentation: current and new systems - administering correct documentation Implementing and maintaining security policies and procedures to protect sensitive data (SAP Security) would be beneficial. Collaborate with other IT teams and business stakeholders to understand requirements and provide technical solutions. Perform system tuning and optimization to enhance performance and scalability. Technology Stack SAP Basis Hana and Unix/Linux Performance Tuning (SAP Hana) SAP ECC, APO, BW, APO, PI, IBP, C4C, Cloud Connector, Fiori This SAP Basis Consultant will be hybrid, working 3 days a week onsite in North London. To discuss this exciting opportunity in more detail, please APPLY NOW for a no obligation chat with your VIQU Consultant. Additionally, you can contact Connor Smal, by exploring the VIQU IT Recruitment website.
17/04/2024
Project-based
SAP Basis Consultant - Contract A leading organisation is looking for a SAP Basis Consultant that will focus on the maintenance, support, and optimization of the SAP systems landscape. Your main responsibility will be to maintain the stability, efficiency, and security of our SAP system, which involves handling installations, upgrades, and patches. This position demands solid technical skills in SAP Basis administration, along with the capability to work well with teams across different functions. Key Responsibilities for the SAP Basis Consultant : Previous experience as a SAP Basis Consultant/Analyst/Engineer. Administer and maintain SAP systems, including installation, configuration. SAP Basis Netweaver and Hana database maintenance, support and tuning. Monitor system performance and troubleshoot issues to ensure optimal uptime and reliability. Responsible for the analysis of error trends and problem management. Incident response Documentation: current and new systems - administering correct documentation Implementing and maintaining security policies and procedures to protect sensitive data (SAP Security) would be beneficial. Collaborate with other IT teams and business stakeholders to understand requirements and provide technical solutions. Perform system tuning and optimization to enhance performance and scalability. Technology Stack SAP Basis Hana and Unix/Linux Performance Tuning (SAP Hana) SAP ECC, APO, BW, APO, PI, IBP, C4C, Cloud Connector, Fiori This SAP Basis Consultant will be hybrid, working 3 days a week onsite in North London. To discuss this exciting opportunity in more detail, please APPLY NOW for a no obligation chat with your VIQU Consultant. Additionally, you can contact Connor Smal, by exploring the VIQU IT Recruitment website.
Cyber Security Engineer - Luxemburg - 60-77k + Bonus Global IT Services provider are recruiting for multiple mid level and senior security engineers to work on a security cleared project based in Luxemburg. The client is happy to consider people relocating from anywhere in the UK, EU or US. you will be responsible for designing, implementing, and managing security solutions to safeguard the network, applications, and digital assets. Key Responsibilities Replace/upgrade the current infrastructure with new versions or solutions. Recommend and implement new cyber security technologies and solutions. Monitor operational infrastructure - you will leverage standard tools and processes to respond and resolve incidents and requests. Incident Response - Monitor security events, investigate and respond to security incidents, and assist in post-incident analysis and remediation. Documentation: Create and maintain comprehensive documentation related to security configurations, policies, procedures, and incidents. Collaboration: Work closely with cross-functional teams, including IT, Network, and Application Development, to ensure the integration of security measures across the organization. Research and Innovation: Stay up-to-date with emerging security threats, technologies, and best practices, and provide recommendations where appropriate. Qualifications Bachelor's degree in Computer Science, Information Security, or a related field. At least 6 years of field experience in the networking and security area with solutions. Proven experience in network and application security, with expertise in Palo Alto, Bluecoat, F5 (LTM, ASM, APM), ASA VPN or Splunk. Knowledge of Firewall management, intrusion detection, content filtering, web application security, and VPN technologies. Proficiency in PKI design and management, digital certificate issuance, and secure key management. Strong communication skills and the ability to collaborate with diverse teams. A proactive approach to identifying and mitigating security vulnerabilities and risks. Demonstrated ability to work in a fast-paced and dynamic environment. Fluent in English Key Skills Automation Tools, Cloud Security, Firewalls, Local Area Network (LAN), Palo Alto Networks Prisma Access Secure Access Service Edge (SASE), Security Technologies, TCP/IP Networking, Threat Management Cyber Security Engineer - Luxemburg - 60-77k + Bonus Desired Skills and Experience Palo Alto/Blue Coat/F5/Splunk/Fireye/Network Security
17/04/2024
Full time
Cyber Security Engineer - Luxemburg - 60-77k + Bonus Global IT Services provider are recruiting for multiple mid level and senior security engineers to work on a security cleared project based in Luxemburg. The client is happy to consider people relocating from anywhere in the UK, EU or US. you will be responsible for designing, implementing, and managing security solutions to safeguard the network, applications, and digital assets. Key Responsibilities Replace/upgrade the current infrastructure with new versions or solutions. Recommend and implement new cyber security technologies and solutions. Monitor operational infrastructure - you will leverage standard tools and processes to respond and resolve incidents and requests. Incident Response - Monitor security events, investigate and respond to security incidents, and assist in post-incident analysis and remediation. Documentation: Create and maintain comprehensive documentation related to security configurations, policies, procedures, and incidents. Collaboration: Work closely with cross-functional teams, including IT, Network, and Application Development, to ensure the integration of security measures across the organization. Research and Innovation: Stay up-to-date with emerging security threats, technologies, and best practices, and provide recommendations where appropriate. Qualifications Bachelor's degree in Computer Science, Information Security, or a related field. At least 6 years of field experience in the networking and security area with solutions. Proven experience in network and application security, with expertise in Palo Alto, Bluecoat, F5 (LTM, ASM, APM), ASA VPN or Splunk. Knowledge of Firewall management, intrusion detection, content filtering, web application security, and VPN technologies. Proficiency in PKI design and management, digital certificate issuance, and secure key management. Strong communication skills and the ability to collaborate with diverse teams. A proactive approach to identifying and mitigating security vulnerabilities and risks. Demonstrated ability to work in a fast-paced and dynamic environment. Fluent in English Key Skills Automation Tools, Cloud Security, Firewalls, Local Area Network (LAN), Palo Alto Networks Prisma Access Secure Access Service Edge (SASE), Security Technologies, TCP/IP Networking, Threat Management Cyber Security Engineer - Luxemburg - 60-77k + Bonus Desired Skills and Experience Palo Alto/Blue Coat/F5/Splunk/Fireye/Network Security
DV Cleared SIEM/Incident SME Location: Northallerton/Corsham/Portsmouth Duration: 6 - 12 Months Rate to SSC: Market Rate MUST BE PAYE THROUGH UMBRELLA Role Description: The Cyber Defence Analyst will join a growing security team responsible for designing, delivering and maintaining operational cybersecurity capabilities. Conducting pro-active, risk-based, protective monitoring on priority C4IS/networks to identify internal and external cyber-threats/attacks. This position involves a broad range of skills, including the development and mentoring of Junior Analysts, monitoring networks to actively remediate unauthorised activities. Your role Develop and integrate security event monitoring and incident management services. Respond to security incidents as they occur as part of an incident response team. Implement metrics and dashboards to give visibility of the Enterprise infrastructure. Use of the SOAR platform to assist with playbook automation and case management capabilities to streamline team processes and tools. Produce documentation to ensure the repeatability and standardisation of security operating procedures. Develop additional investigative methods using the SOC's software toolsets to enhance recognition opportunities for specific analysis. Maintain a baseline of system security according to latest threat intelligence and evolving trends. Participate in root cause analysis of incidents in conjunction with engineers across the enterprise. Provide Subject Matter Expertise (SME) on a broad range of information security standards and best practices. Offer strategic and tactical security guidance including valuation requirement of technical controls. Be part of the CRM process Liaise with the SOC engineers to maintain up-to-date dashboards of security alerts, to allow the organisation to better respond to an incident. Document, validate and create operational processes and procedures to help develop the SOC. Assist in identifying, prioritising, and coordinating the protection of critical cyber defence infrastructure and key resources. Build, install, configure, and test dedicated cyber defence hardware. Support Junior Analysts to manage SOC systems. Previous experience of Enterprise ICS/network architectures and technologies Experience and knowledge of SIEM solutions; having the ability to identify use cases and their creation, their deployment and tuning. Experience as a mentor/coach to Junior Analysts Your profile Previous experience of utilising the MITRE ATT&CK and Cyber Kill Chain frameworks Skilled in maintaining Microsoft directory services. Skilled in using virtualisation software. Knowledge of key security frameworks (eg ISO, NIST 800-53, 800-171, 800-172, C2M2) Excellent communication skills Experience of writing Defence/Government documentation Desirable Qualifications: Broad Spectrum Cyber Course (SANS SEC401 or SEC501 or equivalent) SIEM Design, Architecture and Analyst Course (SANS SEC455 or SEC555 or equivalent) Advanced Analyst Course (SANS SEC503 or equivalent)
15/04/2024
Project-based
DV Cleared SIEM/Incident SME Location: Northallerton/Corsham/Portsmouth Duration: 6 - 12 Months Rate to SSC: Market Rate MUST BE PAYE THROUGH UMBRELLA Role Description: The Cyber Defence Analyst will join a growing security team responsible for designing, delivering and maintaining operational cybersecurity capabilities. Conducting pro-active, risk-based, protective monitoring on priority C4IS/networks to identify internal and external cyber-threats/attacks. This position involves a broad range of skills, including the development and mentoring of Junior Analysts, monitoring networks to actively remediate unauthorised activities. Your role Develop and integrate security event monitoring and incident management services. Respond to security incidents as they occur as part of an incident response team. Implement metrics and dashboards to give visibility of the Enterprise infrastructure. Use of the SOAR platform to assist with playbook automation and case management capabilities to streamline team processes and tools. Produce documentation to ensure the repeatability and standardisation of security operating procedures. Develop additional investigative methods using the SOC's software toolsets to enhance recognition opportunities for specific analysis. Maintain a baseline of system security according to latest threat intelligence and evolving trends. Participate in root cause analysis of incidents in conjunction with engineers across the enterprise. Provide Subject Matter Expertise (SME) on a broad range of information security standards and best practices. Offer strategic and tactical security guidance including valuation requirement of technical controls. Be part of the CRM process Liaise with the SOC engineers to maintain up-to-date dashboards of security alerts, to allow the organisation to better respond to an incident. Document, validate and create operational processes and procedures to help develop the SOC. Assist in identifying, prioritising, and coordinating the protection of critical cyber defence infrastructure and key resources. Build, install, configure, and test dedicated cyber defence hardware. Support Junior Analysts to manage SOC systems. Previous experience of Enterprise ICS/network architectures and technologies Experience and knowledge of SIEM solutions; having the ability to identify use cases and their creation, their deployment and tuning. Experience as a mentor/coach to Junior Analysts Your profile Previous experience of utilising the MITRE ATT&CK and Cyber Kill Chain frameworks Skilled in maintaining Microsoft directory services. Skilled in using virtualisation software. Knowledge of key security frameworks (eg ISO, NIST 800-53, 800-171, 800-172, C2M2) Excellent communication skills Experience of writing Defence/Government documentation Desirable Qualifications: Broad Spectrum Cyber Course (SANS SEC401 or SEC501 or equivalent) SIEM Design, Architecture and Analyst Course (SANS SEC455 or SEC555 or equivalent) Advanced Analyst Course (SANS SEC503 or equivalent)
Cyber Defence Engineer Location: Full Time onsite in Hereford Duration: 6 months MUST BE PAYE THROUGH UMBRELLA We are heading up a recruitment drive on behalf of a leading IT consultancy that require a DV cleared Cyber Defence Engineer to join their team on a major defence project that is based in Hereford. Role Description: Role Description: Cyber Defence Engineer will join a growing security team responsible for the testing, implementation, deployment, maintenance, configuration and troubleshooting of the SOC's technology stack (hardware and software). The engineer will also assist with the continued development and maintenance of data pipelines and signature updates and the professional development of the system engineering team. Tasks: Perform system administration on specific cyber defence applications and systems to include installation, configuration, maintenance, troubleshooting, backup and restoration. Manage system/server resources including performance, capacity, availability, serviceability, and recoverability. Diagnose and resolve customer reported system incidents, problems, and events to ensure continuing operability. Coordinate with SOC and CTI Analysts to assist in the development of signatures which can be implemented on cyber defence network tools in response to new or observed threats within the network environment or enclave. Manage the compilation, cataloguing, distribution, and retrieval of data from a range of enterprise networks and data sources. Implement data management standards, requirements, and specifications. Develop data standards, policies, and procedures. Analyse data sources to provide actionable recommendations and facilitate data-gathering methods. To share knowledge, skills and experience, create and improve documentation, and train new members of the data engineering team. Knowledge: Knowledge of big data technologies and ecosystems (eg, NiFi). Knowledge of current market and emerging leaders in data analytical and SIEM platforms. Knowledge of network security implementations (eg, host-based IDS, IPS), including their function and placement in a network. Knowledge of intrusion detection systems and signature development. Knowledge of Front End collection systems, including network traffic collection, filtering, and selection. Knowledge of system administration concepts for operating systems such as but not limited to Unix/Linux, IOS, Android, and Windows operating systems. Knowledge of cyber defence and information security policies, procedures and regulations. Knowledge of network security architecture concepts including topology, protocols, components and principles. Skills/Experience: Previous experience of Enterprise ICS/network architectures and technologies. Working with frameworks and technologies that support data-intensive distributed applications. Experience maintaining and administrating data analytical and SIEM platforms. Experience using host and network-based IDS/IPS Experience using packet capture solutions. Skill in developing and deploying signatures. Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). Ability to provide technical and service leadership to junior SOC Engineers (mentor/coach). Desirable Qualifications/Certifications Red Hat System Administration I & II (RH124/RH134). Baseline Cyber Courses eg Cyber Foundation Pathway, SANS SEC 301 Intro to Information Security, SANS 401 Security Essentials Bootcamp. Certified engineer in a market leading data analysis/SIEM platform. SANS SEC501 Advanced Security Essentials Enterprise Defender. SANS SEC 511 Continuous Monitoring & Security Operations. SANS SEC555: SIEM with Tactical Analytics
15/04/2024
Project-based
Cyber Defence Engineer Location: Full Time onsite in Hereford Duration: 6 months MUST BE PAYE THROUGH UMBRELLA We are heading up a recruitment drive on behalf of a leading IT consultancy that require a DV cleared Cyber Defence Engineer to join their team on a major defence project that is based in Hereford. Role Description: Role Description: Cyber Defence Engineer will join a growing security team responsible for the testing, implementation, deployment, maintenance, configuration and troubleshooting of the SOC's technology stack (hardware and software). The engineer will also assist with the continued development and maintenance of data pipelines and signature updates and the professional development of the system engineering team. Tasks: Perform system administration on specific cyber defence applications and systems to include installation, configuration, maintenance, troubleshooting, backup and restoration. Manage system/server resources including performance, capacity, availability, serviceability, and recoverability. Diagnose and resolve customer reported system incidents, problems, and events to ensure continuing operability. Coordinate with SOC and CTI Analysts to assist in the development of signatures which can be implemented on cyber defence network tools in response to new or observed threats within the network environment or enclave. Manage the compilation, cataloguing, distribution, and retrieval of data from a range of enterprise networks and data sources. Implement data management standards, requirements, and specifications. Develop data standards, policies, and procedures. Analyse data sources to provide actionable recommendations and facilitate data-gathering methods. To share knowledge, skills and experience, create and improve documentation, and train new members of the data engineering team. Knowledge: Knowledge of big data technologies and ecosystems (eg, NiFi). Knowledge of current market and emerging leaders in data analytical and SIEM platforms. Knowledge of network security implementations (eg, host-based IDS, IPS), including their function and placement in a network. Knowledge of intrusion detection systems and signature development. Knowledge of Front End collection systems, including network traffic collection, filtering, and selection. Knowledge of system administration concepts for operating systems such as but not limited to Unix/Linux, IOS, Android, and Windows operating systems. Knowledge of cyber defence and information security policies, procedures and regulations. Knowledge of network security architecture concepts including topology, protocols, components and principles. Skills/Experience: Previous experience of Enterprise ICS/network architectures and technologies. Working with frameworks and technologies that support data-intensive distributed applications. Experience maintaining and administrating data analytical and SIEM platforms. Experience using host and network-based IDS/IPS Experience using packet capture solutions. Skill in developing and deploying signatures. Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). Ability to provide technical and service leadership to junior SOC Engineers (mentor/coach). Desirable Qualifications/Certifications Red Hat System Administration I & II (RH124/RH134). Baseline Cyber Courses eg Cyber Foundation Pathway, SANS SEC 301 Intro to Information Security, SANS 401 Security Essentials Bootcamp. Certified engineer in a market leading data analysis/SIEM platform. SANS SEC501 Advanced Security Essentials Enterprise Defender. SANS SEC 511 Continuous Monitoring & Security Operations. SANS SEC555: SIEM with Tactical Analytics
Security Engineer - SOAR One of our Global consultancy clients is looking for an experienced Security Engineer for one of its leading multinational Travel clients. This is an exciting contract opportunity which is initially until 31/12/24 with potential to extend. This role is hybrid with 3 days per week (may be flexible further down the line) being based out of the clients office in Villeneuve Loubet - 15 mins from Nice Airport. The end client works at the heart of the global travel industry and provides the technology which keeps the travel sector moving - from initial search to making a booking, from pricing to ticketing, from managing reservations to managing check-in and departure processes. Their products and solutions help to improve the business performance of their customers; travel agencies, corporations, airlines, ground handlers, hotels, railways, car rental companies, airports, cruise lines and ferry operators. Responsibilities: We are seeking a Security Orchestration and Automated Response (SOAR) engineer responsible for maintaining our SOAR solution, developing playbooks and implementing integrations within the SOC Platform Engineering team. The SOAR engineer will collaborate closely with cross-functional teams, leveraging various technologies to implement security automation and supporting our Incident Response Team in improving analyst productivity against cyber threats. Key Responsibilities: Maintain our SOAR platform at its optimum level, Update and enhance existing playbooks to adapt to organizational needs, Develop new playbooks to address specific security requirements, Collaborate with stakeholders to identify use cases, Develop and maintain automation scripts (Python), Support security analysts in automating incident response activities, Document processes and workflows for internal sharing, Participate in technical study. Requirements: 2 or more years of experience in developing playbooks and implementing integrations. Experience with SIEM or Cloud Infrastructure, such as Splunk or Microsoft Azure. Ideally a degree in IT or Computer Science Python Skill Level - Advanced Fluent in French and English
15/04/2024
Project-based
Security Engineer - SOAR One of our Global consultancy clients is looking for an experienced Security Engineer for one of its leading multinational Travel clients. This is an exciting contract opportunity which is initially until 31/12/24 with potential to extend. This role is hybrid with 3 days per week (may be flexible further down the line) being based out of the clients office in Villeneuve Loubet - 15 mins from Nice Airport. The end client works at the heart of the global travel industry and provides the technology which keeps the travel sector moving - from initial search to making a booking, from pricing to ticketing, from managing reservations to managing check-in and departure processes. Their products and solutions help to improve the business performance of their customers; travel agencies, corporations, airlines, ground handlers, hotels, railways, car rental companies, airports, cruise lines and ferry operators. Responsibilities: We are seeking a Security Orchestration and Automated Response (SOAR) engineer responsible for maintaining our SOAR solution, developing playbooks and implementing integrations within the SOC Platform Engineering team. The SOAR engineer will collaborate closely with cross-functional teams, leveraging various technologies to implement security automation and supporting our Incident Response Team in improving analyst productivity against cyber threats. Key Responsibilities: Maintain our SOAR platform at its optimum level, Update and enhance existing playbooks to adapt to organizational needs, Develop new playbooks to address specific security requirements, Collaborate with stakeholders to identify use cases, Develop and maintain automation scripts (Python), Support security analysts in automating incident response activities, Document processes and workflows for internal sharing, Participate in technical study. Requirements: 2 or more years of experience in developing playbooks and implementing integrations. Experience with SIEM or Cloud Infrastructure, such as Splunk or Microsoft Azure. Ideally a degree in IT or Computer Science Python Skill Level - Advanced Fluent in French and English
Junior SOC Analyst - Hybrid - 3 days on site - Nottinghamshire Main Responsibilities: - Triage, analyse and investigate alerts, log data and network traffic using security tools to identify cyber-attacks/security incidents. This includes the investigation and root cause analysis of potential security incidents. - Proactively investigate potential security breaches by utilising threat intelligence and internal and external security systems and provide subject matter expertise for technical responses to confirmed cyber security incidents. - Create and maintain the clients target cyber security architecture. - Deliver subject matter expertise to key stakeholders to drive the implementation of security controls to meet the target architecture. - Accountable for vulnerability scanning, including the prioritisation of unpatched vulnerabilities and reporting against agreed KPIs and KRIs. - Support the annual penetration testing schedule by arranging penetration testing, including tracking, and communicating penetration testing results. - Perform supplementary testing of clients detection and response controls by procuring, installing, and running penetration testing tooling. - Participate in process improvement work to automate and improve critical cyber security processes such as monitoring, patching, and hardening. - Develop and maintain process documentation for security architecture, vulnerability management, cyber incident response, and playbooks. - Provide security representation across multiple geographies, business units and teams to achieve objectives, including engagement with the Information Security Enhancement Office. Skills, Knowledge and Experience - Has obtained one or more of the following qualifications: CEH, CRTSA, and OSCP. - Qualifications such as CISSP and CISM would be advantageous. - Problem solving skills, and the ability to come up with new solutions to existing challenges. - Strengths in key 'soft skill' areas such as relationship management, communication, and presentation of technical security information to a variety of audiences. - Technical skills to investigate potential breaches through existing tools, packet capture and log file analysis. - A logical mindset, the ability to identify proportionate, appropriate mitigations to identified security incidents, and to prioritise incidents based on risk. - Capable of working independently/without ongoing supervision on projects and day to day tasks. Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
12/04/2024
Full time
Junior SOC Analyst - Hybrid - 3 days on site - Nottinghamshire Main Responsibilities: - Triage, analyse and investigate alerts, log data and network traffic using security tools to identify cyber-attacks/security incidents. This includes the investigation and root cause analysis of potential security incidents. - Proactively investigate potential security breaches by utilising threat intelligence and internal and external security systems and provide subject matter expertise for technical responses to confirmed cyber security incidents. - Create and maintain the clients target cyber security architecture. - Deliver subject matter expertise to key stakeholders to drive the implementation of security controls to meet the target architecture. - Accountable for vulnerability scanning, including the prioritisation of unpatched vulnerabilities and reporting against agreed KPIs and KRIs. - Support the annual penetration testing schedule by arranging penetration testing, including tracking, and communicating penetration testing results. - Perform supplementary testing of clients detection and response controls by procuring, installing, and running penetration testing tooling. - Participate in process improvement work to automate and improve critical cyber security processes such as monitoring, patching, and hardening. - Develop and maintain process documentation for security architecture, vulnerability management, cyber incident response, and playbooks. - Provide security representation across multiple geographies, business units and teams to achieve objectives, including engagement with the Information Security Enhancement Office. Skills, Knowledge and Experience - Has obtained one or more of the following qualifications: CEH, CRTSA, and OSCP. - Qualifications such as CISSP and CISM would be advantageous. - Problem solving skills, and the ability to come up with new solutions to existing challenges. - Strengths in key 'soft skill' areas such as relationship management, communication, and presentation of technical security information to a variety of audiences. - Technical skills to investigate potential breaches through existing tools, packet capture and log file analysis. - A logical mindset, the ability to identify proportionate, appropriate mitigations to identified security incidents, and to prioritise incidents based on risk. - Capable of working independently/without ongoing supervision on projects and day to day tasks. Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website