Cyber Security Monitoring and Investigations - Threat Detection Analyst

apartmentGovernment Recruitment Service placeManchester calendar_month 

You will work as part of the Department’s Cyber Resilience Centre (CRC) as a Threat Detection Analyst in the Cyber Security Monitoring & Investigations team. You will play a vital role in securing the DWP IT Estate; ensuring that service delivery is not affected as a result of potential malicious activity from either internal or external threat.

Working as a Threat Detection Analyst in the Cyber Security Monitoring and Investigations team, you will be part of an innovative and service-orientated team of analysts, focused on the detection and investigation of potential indicators of compromise or malicious activity on DWP systems and devices. Your main responsibilities will be to:

  • Provide a second-tier escalation function for the resolution of security events that have been triaged by others, providing direction and guidance, and ensuring an effective response to alerts and risks as they are identified.
  • Undertake comprehensive investigation of security alerts as well as proactive analysis of activity captured in system logs and security tools, to quickly determine if systems have been compromised.
  • Support Intelligence Analysts and the Security Incident Response Team, by providing detailed technical input to on-going investigations, building on detailed log data, digital outputs, and threat intelligence in relation to the mitigation, detection and response to potential cyber-attacks.
  • Effectively use the latest analytical SIEM tools including open-source intelligence to identify security compromises within large amounts of complex data.
  • Use digital forensic and malware analysis tools (commercial and/or open source) to support analysis and decision making.
  • Demonstrate strong knowledge of the latest security threats and indicators of compromise to ensure a robust response to new threats and attack vectors.
  • Provide timely intervention to protect the DWP IT Estate through recommending and operating containment processes to isolate and prevent the spread of malware.
  • Drive forward the development of monitoring systems and supporting processes and playbooks, ensuring systems are in place to review and continually improve existing capabilities.
  • Ensure intelligence is effectively used to maintain the integrity of alerts and to ensure alerts continue to remain relevant and focused on the latest threats.
  • Develop influential relationships with key stakeholders across the Department to support improvement activity thereby mitigating the risks from malicious activity.
  • Demonstrate strong knowledge and understanding of the concepts of information security, and of current and emerging IT security, data protection and information risk principles and technologies.
  • Support the transformation of the Department’s response to digital delivery and the security threats this presents; including operating new analytical tools to generate innovative security alerts.
  • Support remedial activity as a result of identified weaknesses within the estate.
  • Manage multiple priorities and respond flexibly to competing demands.

The Cyber Security Monitoring & Investigations team operates 24 hours a day, 7 days a week and as a result, post holders may be required to work outside of usual office hours as investigations dictate. Travel to different sites with occasional overnight stays may also be required.

apartmente-Careers LimitedplaceGlazebury, 9 mi from Manchester
IDEAL FOR A NEW CAREER STARTER, NO EXPERIENCE REQUIRED, WE WILL PROVIDE FULL TRAINING AT NO COST. Overview We have a pool of companies who are looking to employ someone for the role of Cyber Security Trainee. The candidate does NOT need to have...
apartmentMichael PageplaceManchester
of a security breach The Successful Applicant  •  An educational background in Computer Science, Information Technology or a related field.  •  Proven experience as a Security Operations / Cyber Security Analyst or similar role.  •  Experience in broad range...
apartmentGovernment Recruitment ServiceplaceLeeds, 38 mi from Manchester
You will work as part of the Department’s Cyber Resilience Centre (CRC) as a Threat Detection Analyst in the Cyber Security Monitoring & Investigations team. You will play a vital role in securing the DWP IT Estate; ensuring that service delivery...