Senior CTOC Analyst
Harbourside 2, United Kingdom
ā ļø We'll shut down after Aug 1st - try fooš¦ for all jobs in tech ā ļø
Hargreaves Lansdown
Hargreaves Lansdown is an award-winning investment and active saving service that can save you time and money - explore our ISAs, pensions, investments and active savings accounts.Our purpose is to make it easy for people to save and invest for a better future. We are looking for great people to join us, so please come and invest in YOUR future at Hargreaves Lansdown.
We know that sometimes people can be put off applying for a job if they don't tick every box. If you're excited about working for us and have most of the skills or experience we're looking for, please go ahead and apply. Weād love to hear from you!
About the role
The Senior CTOC Analyst (Cyber Threat Operations Centre) will join an experienced team of security analysts and provide technical expertise into investigations and incidents. This role will have a focus on handling escalations from the team on alerts or incidents which require a deeper technical analysis which should lead to recommendations and improvements. You will also have the responsibility of handling proactive Threat Hunting and Detection Engineering capabilities within the team. These are heavily technical functions which require a deep understanding of our toolset and query language, and the tools, techniques and procedures (TTPs) used by threat actors.What youāll be doing
- Provide detailed and in-depth analysis of security incidents ensuring they are properly documented and escalated as required.
- Act as the escalation point for security incidents that have been processed by the CTOC Analysts.
- Write detailed incident reports which are consumable by audiences of varying technical understanding.
- Support the Incident Response function by providing technical guidance and analysis on active or ongoing incidents.
- Respond to requests for Threat Hunting, as well as, proactively run threat hunts based on incidents and activity seen during the daily operations.
- Maintain SME level knowledge and expertise for security platforms which are in use by the CTOC and proactively develop skills as required.
- Work with our SIEM and cloud security solutions to investigate threats, deliver or recommend countermeasures, and perform advanced network and host analysis in the event of a compromise.
- Design, build and deploy threat driven detections within the SIEM platform in-line with internal processes.
- Maintain and update as required the existing detections, ensuring they are fit for purpose, tested and validated. Ā
Ā
About you
- Proven experience in a security operations role, or technical security role, supporting incident investigations and remediation activities.
- Excellent security analysis skills utilising SIEM technologies and query languages for advanced analysis and threat hunting
- Ability to research and deploy new threat-driven detections into SIEM environment
- Coding scripting
- Demonstrated experience of working within hybrid cloud environments.
- Up to date knowledge of current threats, vulnerabilities, and attack trends.
- Demonstrated experience with enterprise networking and operating systems, with an understanding of networking principles (TCP/IP, DNS, VPN, etc.).
- Strong knowledge of network security technologies such as firewalls, IDS/IPS, NX Agents
- Strong knowledge with common operating systems (Windows, Linux, macOS) and their security features.
Interview process
This will be a two-stage interview process, including an introductory call and a competency-based interview.
Working Schedule
We are based in Bristol, BS1 5HL. This role is permanent, full time, 37.5 hours per week, Monday to Friday. We have returned to the office, however for this role we offer a flexible working pattern to enable you the option of working from home and coming into the office around once/twice a month.
Why us?
Here at HL, weāre the UKās number 1 investment platform for private investors, based in Bristol. For more than 40 years weāve helped investors save time, tax and money on their investments.
To achieve our mission, we believe we have a workplace like no other, with constant learning, dynamic teams, and a great ethos. We're steered by core values that promote service, quality, innovation, and opportunity in everything we do.
What's on offer?
- Discretionary annual bonus* and annual pay reviewĀ
- 25 days* holiday plus bank holidays and 1-day additional Christmas closureĀ
- Option to purchase an additional 5 days holiday**Ā Ā
- Flexible working options available, including hybrid workingĀ Ā
- Enhanced parental leaveĀ
- Pension scheme up to 11% employer contributionĀ
- Income Protection and Life insurance (4 x salary core level of cover)Ā Ā
- Private medical insurance*Ā
- Health care cash plans - including optical, dental, and outpatient careĀ
- Health screening programme
- Help@hand - confidential support including mental health counselling and remote GPĀ
- Wellhub - unlimited access to fitness providers and wellness coach sessionsĀ
- Variety of travel to work schemes with bike storage and shower facilitiesĀ
- Inhouse barista and deli serving subsidised coffee and sandwichesĀ
- Two paid volunteering days per yearĀ
* dependant on role levelĀ
** only available to select during our annual benefits window, in November each yearĀ
ā
Hargreaves Lansdown is an inclusive employer that values diversity in its workforce. We encourage applications from all individuals without regard to race, religion, gender, sexual orientation, national origin, disability or age.
This role may also be available on a flexible working or part time basis ā please ask the Recruitment & Onboarding team for more information.
Please note, we are unable to provide employment sponsorship to candidates.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index š°
Tags: Cloud DNS Firewalls IDS Incident response IPS Linux MacOS Network security Scripting Security analysis SIEM TCP/IP TTPs VPN Vulnerabilities Windows
Perks/benefits: Career development Flex hours Flex vacation Health care Insurance Medical leave Parental leave Salary bonus Unlimited paid time off
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.