SC Cleared 2nd Line Security Event Analyst - SIEM

Leuze-en-Hainaut  ‐ Onsite
This project has been archived and is not accepting more applications.
Browse open projects on our job board.

Description

SC Cleared 2nd Line Security Event Analyst - Mons, Belgium - €80 - 85 per hour

1-2 months+ Extension

SC Cleared - Security Incident Event Management - SIEM - ArcSight - Splunk - Network Based Intrusion Detection Systems (NIDS) - SourceFire, Palo Alto Network Threat Prevention - Host Based Intrusion Detection Systems (HIDS) - Full Packet Capture systems - Vulnerability - Anti-virus - Intrusion & Incident Detection

As Second Line Security Event Analyst (SLSEA), provide detailed analysis of logs and network traffic and making security event determinations on alarm severity delivering second level investigation and remediation activities as member of the Cyber Security Service Line.

Main responsibilities:

  • Conduct detailed investigation and research of security events within the Cyber Security Centre (NCSC) team
  • Provide analysis of Firewall, IDS, anti-virus and other network sensor produced system security events and present findings
  • Appropriately leverage the comprehensive extended toolset (eg Log Collection, Intrusion Detection, Packet Capture, VA, Network Devices etc) to identify malicious activity)
  • Be able to recommend improvements to enable enhancing investigations
  • Provide Subject Matter Expertise supporting the end-to-end Cyber Security Incident Handling process; Propose possible optimisations and enhancement which help to both maintain and improve overall Cyber Security posture

Skills required:

Expert level in at least three of the following areas and a high level of experience in several of the other areas;

  • Security Incidents Event Management products (SIEM) - eg ArcSight, Splunk,
  • Network Based Intrusion Detection Systems (NIDS) - eg SourceFire, Palo Alto Network Threat Prevention
  • Host Based Intrusion Detection Systems (HIDS)
  • Full Packet Capture systems - eg Niksun, RSA/NetWitness,
  • A variety of Security Event generating sources (eg Firewalls, IDS, Routers, Security Appliances)
  • Computer forensics tools (stand alone, online and network)
  • Computer incident response centre (CIRT), computer emergency response team (CERT)
  • Computer security tools (Vulnerability Assessment, Anti-virus, Protocol Analysis, Anti-Virus,
  • Protocol Analysis, Anti-Spyware, etc)
  • Secure web design and development
  • Military communication systems and networks
  • Proficiency in Intrusion/Incident Detection and Handling,
  • Comprehensive knowledge of the principles of computer and communications security, networking, and the vulnerabilities of modern operating systems and applications.

Desirable:

  • Industry leading certification in the area of Cybersecurity such as CISSP, CISM, MCSE/S, CISA, GSNA, SANS GIAC.
  • A good understanding of Security, Orchestrations, Automation and Response (SOAR) concepts and their benefits to the protection of CIS infrastructures.
  • A solid understanding of Information Security Practices; relating to the Confidentiality, Integrity and Availability of information (CIA triad.)
  • Prior experience of working in an international environment comprising both military and civilian elements

SC Cleared- Security Incident Event Management - SIEM - ArcSight - Splunk - Network Based Intrusion Detection Systems (NIDS) - SourceFire, Palo Alto Network Threat Prevention - Host Based Intrusion Detection Systems (HIDS) - Full Packet Capture systems - Vulnerability - Anti-virus - Intrusion & Incident Detection

Application Closing date: 27th Oct

Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy

Damia Group is acting as an Employment Business in relation to this vacancy.

Start date
November 2020
Duration
1-2 months +
(extension possible)
From
Damia Group LTD
Published at
25.10.2020
Project ID:
1988603
Contract type
Freelance
To apply to this project you must log in.
Register