Principal Cyber Security Operations Engineer - NESO
We are one of the world’s largest investor-owned energy companies, committed to delivering electricity and gas safely, reliably and efficiently to the customers and communities we serve.
We are seeking a highly skilled and experienced Principal Cyber Operations Engineer to join our team. The ideal candidate will possess strong SIEM engineering skills and will also be comfortable in a mentorship role, providing advice and guidance to other members of the Engineering team. The Principal Cyber Operations Engineer will be responsible for working with other Cyber Operations Engineers to onboard data sources into a central SIEM, ensuring data quality, and addressing any data quality issues that may arise. The Principal Cyber Operations Engineer will also be responsible for maintaining and validating the configuration of various security tooling that serves the needs of the SOC and Cyber Operations team, such as EDR and other detection tooling.
This role requires a proactive and detail-oriented individual with a broad understanding of the data requirements and needs of a Security Operations function, and a proven track record of working in a previous Cyber Operations Engineering environment, or in a Security Operations role. We also value curious individuals with a passion for security, who are interested in working in an environment with bespoke systems and processes which not everyone gets to encounter.
This role can be based from Wokingham or Warwick, and we continue to offer hybrid working from office and home.
Key Accountabilities
* Provide mentorship and guidance to other members of the Engineering team.
* Weigh in on tough technical decisions where competing interests or solutions require consideration.
* Identify and highlight potential avenues for increasing efficiency of delivery and process within the Engineering team.
* Provide technical guidance and support to other team members as needed.
* Suggest and recommend updates to operational procedures and flows to optimise the onboarding of data sources and ensure the widest security visibility across NESO.
* Collaborate with stakeholders to onboard data sources into the SIEM platform.
* Configure and optimize data collection and parsing mechanisms to ensure accurate and efficient data ingestion.
* Investigate and resolve data quality issues, working closely with stakeholders to implement necessary corrective actions.
* Develop and maintain documentation related to data source onboarding processes and procedures.
* Help maintain and validate the configuration of various security tools to serve the needs of the SOC and Threat Detection teams, such as EDR and other detection tooling.
About You
* A proven ability to lead on technical implementation and decision making within an Engineering or Security context.
* Passionate about security, and building secure infrastructure and secure foundations.
* Proven experience working with SIEM platforms and related tooling.
* Strong understanding of SIEM (Security Information and Event Management) concepts and best practices.
* Familiarity with SIEM data onboarding processes and techniques.
* Awareness and familiarity of treating cyber operations engineering using a Software Development Lifecycle mindset.
* Knowledge of various data source formats and protocols (e.g., syslog, JSON, REST API).
* Experience in troubleshooting and resolving data quality issues.
* Experience working with security tooling such as EDR, Deception Tech, Malware Sandboxes, Vulnerability Management Tooling, etc.
* Excellent problem-solving and analytical skills.
* Strong communication and collaboration abilities.
* Relevant certifications (e.g. GIAC) are a plus.
* Curiosity – a willingness and enthusiasm to take on the challenge of making sense of bespoke data sources.
* Experience integrating applications, platforms, and tooling into security monitoring infrastructure.
* In-depth knowledge and experience in security engineering, operations, analysis, and response.
* Experience in scripting or programming (Python, Bash, PowerShell, etc).
* Strong analytical and problem-solving skills and ability to handle complex and dynamic situations.
* Awareness of current and emerging cyber threats, trends, and best practices.
What You'll Get
A competitive salary between £64,000 – 69,000 – dependent on experience and capability. As well as your base salary, there is a bonus scheme, 28 days annual leave as standard, and a competitive contributory pension scheme where we will double match your contribution to a maximum company contribution of 12%.
You will also have access to a comprehensive benefits package tailored to support your well-being and professional success. From a competitive salary to flexible work arrangements, we promote your work-life balance.
More Information
This role closes on 02/10/2024 at 23:59, however we encourage candidates to submit their application as early as possible and not wait until the published closing date as this can vary.
We work towards the highest standards in everything we do, including how we support, value and develop our people. Our aim is to encourage and support employees to thrive and be the best they can be.
#J-18808-Ljbffr