The Opportunity
As the SOC Analyst Tier 2 you will be responsible for monitoring, detecting, containing, and remediating security incidents utilizing a suite of security software tools. This critical role supports the internal JLR SOC and directing an outsourced tier 1 2 SOC MSSP to deliver robust security operations.
Key Performance Indicators
- Number of identified vulnerabilities
- Number of vulnerabilities contained
- Number of vulnerabilities mitigated
- Time to detect
- Time to respond
- Time to mitigate
Key Responsibilities :
Manage a suite of Security Products.Evaluates incidents identified by tier 1 analystsUses threat intelligence such as updated rules and Indicators of Compromise (IOCs) to pinpoint affected systems and the extent of the attack.Consolidating data from alert triage to provide context necessary to initiate Tier-3 workConduct security research and intelligence gathering on emerging threatsCan offer SME advice to security driven projects.Ability to provide technical and service leadership to T1 analystsGood understanding of ITIL processes, including Change Management, Incident Management and Problem Management.Contribute to Incident Response investigations working with the Incident Response team.Continual development of analysis playbooks and tradecraftProactively contribute to SOC strategy by refining standards, processes and procedures.Handle incidents across Windows, Mac, and Linux platforms.Develop and improve processes for incident detection and the execution of countermeasures.Actively maintains awareness of developments in the intrusion analysis, incident response and information security fields.Maintaining SecOps documentation.Conduct proactive threat researchKey Interactions
External Security Operations Centre (currently TCS)ManufacturingEngineeringData Protection Officer / LegalBusiness ProtectionOther IT functionsGDPRKnowledge, Skills and Experience
Essential :
Experience working within a SOC / NOC environmentExperience in handling incident response for large organizationsExperience in NextGen EPP and EDR such as SentinelOneBackground in Vulnerability Management such as QualysCustomer-oriented, flexible and demonstrated tendency to go above and beyondAbility to communicate efficiently with clients and internal team members at all levels and across functional and organizational boundaries.Comfortable working against deadlines in a fast-paced environment.TCP / IP NetworkingFamiliarity with common IDS / IPS and FirewallsIncident handling / response.Some out of hours work may be required to support incidents and investigationsProblem solving skills and ability to work under pressureEngineering experience supporting the following technologies :Tibco logging management.SIEM technologies (Exabeam & LogRhythm)McAtee ePODesirable :
Qualifications :CEHCompTIA CySA+GSECSSCPCISSPITILExperience of network-based User Behaviour Analytics (DarkTrace, ArcSight User Behaviour Analytics etc)Experience of security assessment and penetration testing toolsExperience of packet-capture tools and analysis of packet flowsPersonal Profile
Essential :
An individual with a customer first mindset who is easy to do business with and makes people feel special, driven to deliver experiences that are personalised, transparent and dependable.An individual who is results driven, demonstrates, tenacity, drive and perseverance, with the ability to deliver in a complex, highly demanding environment.An individual with the ability to combine a short term, pragmatic focus with longer term planningAn individual who is resilient, energetic and enthusiastic, able to deliver results under pressure, whilst responding constructively to challenging new ideas and inputsAn individual who can challenge existing thinking in a positive way whilst building credibility and trust through experience and personal styleA good communicator who can communicate complex ideasAn effective team player, actively leads, develops and supports team membersDesirable :
An individual who enables speed in decision making through establishing alignment, clarity, appropriate resources and sense of urgency whilst bringing others along.Skills Required
Soc