Job Description
Airbus Protect is a European specialist in cyber security, safety and sustainability services. Our mission is to protect governments, military and essential national infrastructure enterprises from cyber threats. We are over 1800 experts based across our main locations in France, Germany and the UK, each with a Security Operating Centre. We also operate in the US and the Middle East. We provide a global cyber defence approach that aims to protect, detect and respond to cyber threats with a portfolio including managed security services, industrial control system offerings, encryption, key management and consultancy services. Our goal: Protect our customers and support their needs with cyber security products.
The Role
2nd Line Analyst within Airbus Protect in Newport. The role of the 2nd Line Analyst is to be an escalation point for all SOC operational activity. The successful candidate will be responsible for the day to day monitoring of multiple security devices, including SIEM, EDR, SOAR etc, ensuring that all customer SLAs are met. You will work as part of the SOC team ensuring all SOC operational tasks are completed on time and work tickets updated/closed with satisfactory technical details included. The 2nd Line Analyst will be comfortable at a technical level, often being required to attend technical workshops and customer briefings/service reviews. All Analysts are expected to be able to present and write professional reports to key stakeholders and exercise good time management.
Tasks and Accountabilities
- Perform further analysis of any escalated events and alarms using the SOC toolset and following the heuristic guidance steps described in the associated playbooks.
- Provide support and offer expertise across stages of the Incident Response lifecycle such as preparation, detection and analysis, containment, post‑incident activity.
- Ingest and interpret multiple sources of data from research, reports and incidents and turn them into actionable use cases across various technologies.
- Assist with the initial triage, scoping and containment efforts during incident response engagements and compromise assessments on request.
- Mentor junior analysts.
- Lead and direct efficient intelligence‑driven threat hunts.
- Act as a solid technical point of contact for customers.
- Maintain currency in cyber security concepts, tools and best practices appropriate to the Senior Cyber Defence Analyst L2 role and associated knowledge, skills, abilities at the stated competence level.
- Carry out IOC searches and react using the predefined playbooks.
- Develop playbooks for junior analysts to follow.
- Provide feedback and support along the first, second and third capability within the Airbus Protect Defence Team.
- Provide feedback and contribution into the Continual Service Improvement life cycle.
Required
- Perform further analysis of any escalated events and alarms using the SOC toolset and following the heuristic guidance steps described in the associated playbooks.
- Provide support and offer expertise across stages of the Incident Response lifecycle such as preparation, detection and analysis, containment, post‑incident activity.
- Ingest and interpret multiple sources of data from research, reports and incidents and turn them into actionable use cases across various technologies.
- Assist with the initial triage, scoping and containment efforts during incident response engagements and compromise assessments on request.
- Mentor junior analysts.
- Lead and direct efficient intelligence‑driven threat hunts.
- Act as a solid technical point of contact for customers.
- Maintain currency in cyber security concepts, tools and best practices appropriate to the Senior Cyber Defence Analyst L2 role and associated knowledge, skills, abilities at the stated competence level.
- Carry out IOC searches and react using the predefined playbooks.
- Develop playbooks for junior analysts to follow.
- Provide feedback and support along the first, second and third capability within the Airbus Protect Defence Team.
- Provide feedback and contribution into the Continual Service Improvement life cycle.
Desirable
- SANS SEC503 GCI
- SANS SEC504 GCI
- HSANS FOR508 GCF
- Security Blue BTL1 / BTL2
- PJMRCREST (Registered Intrusion Analyst) (CRIA)
Soft Skills / Qualifications
- The Analyst is expected to be able to present and write professional reports to key stakeholders.
- All staff are expected to exercise good time management and work as part of a team.
- Occasional business travel within the UK and abroad may be required.
- Positions are only open to sole British Citizens. Successful candidates will undergo security clearance vetting if not already cleared to a minimum DV level.
Benefits
- Exciting development opportunities and perspectives within Airbus as a global player.
- Attractive company pension scheme.
- Airbus Group success share scheme.
- Extensive range of additional benefits.
Employment Information
Company: Airbus Protect LimitedContract Type: PermanentExperience Level: ProfessionalJob Family: Cyber Security
Equal Employment Opportunity
We are committed to equal employment opportunities regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression or veteran status. We are proud to be an equal opportunity workplace and commit to inclusion, diversity and workplace safety.
Data Consent
By submitting your CV or application you are consenting to Airbus using and storing information about you for monitoring purposes relating to your application or future employment. This information will only be used by Airbus.
#J-18808-Ljbffr…
