Title- Technical Specialist- Detection engineering and Automation
Years of exp. required for this role- 5 years to 10 years (Max.)
Key Responsibilities
- Ensure controls are kept up to date, analysing and utilising new features as they are released
- Working as part of a global engineering team to deliver high priority and high impact items
- Proactively improve our front-line teams BAU activities
- Focus on improvements and innovation that can immediately help free up analyst time
- Lead regular workshops to obtain suggestions and demonstrate improvements for high firing use-cases, updates to response processes, etc.
- Working with other security teams to look at how we can use their data to enhance our own monitoring.
- Ensure integration between security tools is effective and bug free.
Experience and Qualifications
- Experience and strong understanding of frontline security operations.
- At least 2 years of experience working in Security Operations Engineering with experience in Log On-boarding, Logging Assessment, management of Email security solutions.
- Competent in scripting languages required for automation e.g KQL, Python, etc
- Experience working with / managing security solutions like SIEM (Sentinel preferably), Email protection, IDS/IPS, Anti-Virus, EDR (Microsoft Defender), Ticketing tool like ServiceNow (SecOps)
- Experience in building and fine-tuning Security Use-cases, development of response processes used by SOC.
- Experience working with Change Management controls and processes for safer release of Changes into the environment.
- Ability to automate tasks using scripting on both Windows and Linux systems.
- Programming experience (PowerShell, Bash, Python, JavaScript, Terraform)
- Familiarity with how to build controls in a scalable easily maintainable way, with exposure to Infrastructure-as-a-code
- In depth understanding of modern security automation technologies and API's
- Banking or Finance industry related experience desirable
Nice to have
- Experience dealing with security incidents using the NIST framework.
- Security+, CySA+, SC-200, GCIH, GCFA, SSCP, OSCP, ITIL
- Experience in ServiceNow Security Operations Module
- Whilst not mandatory, previous experience working in Incident Response, SOC (L2 / L3) will be good