Defensive Cyber Operations Specialist
Hybrid – 2-3 days per week onsite in Portsmouth
Permanent, full time role offering £80,000-£100,000
Active DV clearance required
British nationals only for this role
Working with a cybersecurity consultancy, we’re looking for a highly skilled and experienced Defensive Cyber Operations Specialist to join the cyber as a service delivery team. The ideal consultant will have in-depth experience in defining, developing, and implementing effective Cyber Security Operations Centres (CSOCs). The role involves leading defensive measures to protect organisational infrastructure from cyber threats, as well as working closely with cross-functional teams to ensure a robust cyber security posture.
Experience:
1. Minimum of 5 years of hands-on experience in defensive cyber operations, ideally within defense sector.
2. Proven track record in defining, developing, and managing Cyber Security Operation Centres.
3. Strong background in security incident detection and response, with experience using SIEM, IDS/IPS, and endpoint detection and response (EDR) solutions.
Desired Skills:
1. In-depth knowledge of cybersecurity operations frameworks (NIST, MITRE ATT&CK, etc.)
2. Hands-on experience with threat detection and response tools (SIEM, IDS/IPS, firewalls, etc.)
3. Familiarity with scripting languages (Python, PowerShell, etc.) to automate defensive tasks.
4. Strong understanding of malware analysis, digital forensics, and threat intelligence.
5. Ability to work under pressure and handle complex incidents in real-time.
6. Excellent problem-solving, communication, and organisational skills.
Certifications (Preferred):
1. Certified Information Systems Security Professional (CISSP)
2. Certified Ethical Hacker (CEH)
3. GIAC Certified Incident Handler (GCIH)
4. GIAC Security Operations Certified (GSOC)
Responsibilities
Cyber Security Operations Centre (CSOC) Development:
1. Lead the design, implementation, and optimisation of CSOC infrastructure and processes.
2. Develop strategies and workflows to ensure effective detection, analysis, and response to cyber threats.
3. Establish key performance indicators (KPIs) and metrics to measure and improve the effectiveness of cyber security operations.
Threat Monitoring & Incident Response:
1. Conduct continuous monitoring and analysis of security events using SIEM, IDS/IPS, and other security tools.
2. Develop, document, and maintain standard operating procedures for incident detection and response.
3. Lead investigations into potential security incidents, ensuring timely and effective resolution.
Defensive Cyber Operations Strategy:
1. Create and implement strategies to mitigate risks from emerging and existing cyber threats.
2. Provide technical leadership on defensive cyber operations, including vulnerability management and threat intelligence integration.
3. Work closely with other cybersecurity teams to establish a layered defense approach.
4. Run TTXs with the aim to enhance preparedness and response capabilities by simulating scenarios like phishing attacks, data breaches, ransomware infections, or network intrusions.
Collaboration & Advisory:
1. Serve as a subject matter expert (SME) for defensive cyber operations across the organisation.
2. Collaborate with network, infrastructure, and application teams to ensure security is embedded across all systems and services.
3. Provide advice and mentorship to junior staff and foster a culture of proactive cyber security awareness.
Documentation & Compliance:
1. Maintain detailed documentation of the CSOC’s processes, incidents, and activities.
2. Ensure that cyber security operations comply with relevant laws, regulations, and industry standards.
#J-18808-Ljbffr