Summary
The Security Senior Analyst role is responsible for managing services for Managed Security Service customers. The Security Specialist has the remit of assessing, discovering and directing remediation of security threats & vulnerabilities within client environments whilst working as part of a managed security team on various cyber security projects and tasks.
This role involves working at all levels with Solution Architects, Development Operations, Engineers, SOC Analysts, clients and other stakeholders in building and managing security architecture and systems which are kept up-to-date and relevant in the rapidly evolving Managed Security Services industry.
This is a senior technical SOC role and the role holder is expected to provide Tier 3 analysis, advanced investigation, threat hunting, forensic support and technical leadership for complex or critical incidents. The role also supports mentoring, service improvement, playbook evolution and close collaboration with clients, internal teams, channel partners and vendors.
Essential Duties and Responsibilities
Handles internal and client escalations by engaging with key stakeholders.
Follows & oversees that the team follows published SOC policies and procedures.
Acts as subject matter expert across Managed Security Service and be able to clearly articulate deliverables, limitations, feasibility, etc.
Demonstrates thorough experience of the configuration, tuning and maintenance of SOC tools to improve detection capability and building re-usable visualisations / dashboards for security alert triage, threat hunting and similar use cases, etc.
Develops Standard Operating Procedures (SOPs) and use cases for monitoring and handling different types of security events.
Performs Threat intelligence gathering to ensure that detection methods are effective against current threats.
Hunts for suspicious activity based on anomalous activity.
Handles events as part of the Security Incident Management Process.
Works with both internal and external partners to investigate and advise on security incidents and anomalies.
Prepares detailed reports, providing information on findings, status and progress of investigations, as well as vulnerability and risk factors.
Serves as the senior technical escalation point and mentor for colleagues.
Produces incident response playbooks to drive a consistent approach to handling common incidents and improve operational processes.
Analyzes structured security log data through the creation of aggregated / correlated reports or visualizations.
Identifies and implements opportunities for innovative and continuous improvement.
Leads on customer incident response investigations and containment of threats, advising on remediation.
Participates in the Security Operations Centre on-call rotation.
Demonstrates and actively promotes an understanding and commitment to the mission of Logicalis through performing behaviors consistent with the organization's values.
Maintains a workin