Senior SOC Analyst - Leeds - National Security

at  BAE Systems

Leeds, England, United Kingdom -

Start DateExpiry DateSalaryPosted OnExperienceSkillsTelecommuteSponsor Visa
Immediate19 Jul, 2024Not Specified19 Apr, 2024N/AOs X,Linux,Aws,Technology,Cloud Services,Windows,Threat Intelligence,Stakeholder Engagement,Report Writing,SplunkNoNo
Add to Wishlist Apply All Jobs
Required Visa Status:
CitizenGC
US CitizenStudent Visa
H1BCPT
OPTH4 Spouse of H1B
GC Green Card
Employment Type:
Full TimePart Time
PermanentIndependent - 1099
Contract – W2C2H Independent
C2H W2Contract – Corp 2 Corp
Contract to Hire – Corp 2 Corp

Description:

LOCATION(S): UK, EUROPE & AFRICA : UK : LEEDS

BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.
Role description
BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to.
The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location).
The SOC Analyst roles are ‘hands-on’ shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC’s Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks.
These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Due to timelines for the start of operations, it will not be possible to sponsor new clearances so candidates must have existing clearances.
Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis.

REQUIREMENTS

Technical

  • Basic Python and/or scripting skills, Windows, OS X, and Linux
  • Experience using Splunk and Sentinal
  • Working with a range of security tooling/technology
  • Strong understanding of security architecture, in particular networking
  • Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence.
  • Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks).
  • Understand TCP/IP component layers to identify normal and abnormal traffic
  • Understanding of AWS &/or Azure cloud services
  • Experience of Splunk (with ES) &/or Sentinel, content development experience desirable

Non-technical

  • Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing)
  • Coaching mindset – Mentor team.
  • Security process development
  • Able to understand and adapt to different cultures and hierarchical structures.
  • Self-starter and capable of independent working
  • Team player and adept at working in multi-disciplinary and diverse teams

DIVISION OVERVIEW: CAPABILITIES

At BAE Systems Digital Intelligence, we pride ourselves in being a leader in the cyber defence industry, and Capabilities is the engine that keeps the business moving forward. It is the largest area of Digital Intelligence, containing our Engineering, Consulting and Project Management teams that design and implement the defence solutions and digital transformation projects that make us a globally recognised brand in both the public and private sector.
As a member of the Capabilities team, you will be creating and managing the solutions that earn us our place in an ever changing digital world. We all have a role to play in defending our clients, and this is yours

Responsibilities:

  • Ensure that the shift handover brief is prepared and delivered to the incoming shift
  • Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents.
  • Categorise all suspected incidents in line with the Security Incident policy
  • Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information.
  • Write up high quality security incident tickets using a combination of existing knowledge resources and independent research.
  • Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks.
  • Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review.
  • Understand Threat Intelligence and its use in an operational environment
  • Support incident response to national scale incidents in a coaching capacity
  • Work with other teams within BAE to improve services on the basis of customer needs.
  • Produce new workflows for automation into SOAR tools for common attack types.
  • Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat.


REQUIREMENT SUMMARY

Min:N/AMax:5.0 year(s)

Information Technology/IT

IT Software - Network Administration / Security

Other

Graduate

Proficient

1

Leeds, United Kingdom