Ver oferta completa

SIEM CONTENT DEVELOPMENT SPECIALIST

Descripción de la oferta de empleo

Role title.
SIEM Content Development Specialist Location.
Newbury What you’ll do Content Development – take part in and drive continual creation and refinement of rules and logic within the Vodafone SIEM/EDR/ELK infrastructure to improve Cyber Security Operations efficiency and effectiveness.
This would include responsibilities such as the following.
o    Develop SIEM/EDR/ELK content to address attack vectors using current industry best practices o    Analyse threats/adversaries/attack tools to develop indicator/behavioural based detections that alert and/or prevent malicious activity o    Evaluate and make use of multiple data sources to build content across multiple SIEM/EDR/ELK platforms o    Utilise SIEM/EDR/ELK to facilitate metrics collection, analysis and reporting o    Create and maintain analytics documentation o    Effectively collaborate with colleagues and counterparts internally and externally Security Analysis – take part in and may drive security event analysis activities to address current Cyber threats Threat Response – may require engagement and possibly driving the analysis from blue team perspective to identify possible threat group activity Security Reporting and Advisories – take part in and may drive the delivery of cyber security reports and advisories to all key stakeholders Residual Risk Assessment – take part in and may drive the delivery of ‘operational and technical’ lessons learnt post incident analysis and reporting Who you are •    Minimum of 1-3 years’ experience in SIEM content (rule logic and code) development role •    Minimum of 1 years of SOC analyst experience (Level2 or above) required •    5 years IT experience •    In depth and extensive hands-on experience in security event analysis, create and refine SIEM/EDR rules and deliver efficiency within the SIEM and all other technologies used within the team •    Deep knowledge of IPv4/IPv6, TCP networking protocols •    Deep knowledge of Windows/Linux operating systems •    Good working knowledge of security technologies such as SIEM (ArcSight, Sentinel, QRadar, LogRhythm, Splunk), EDR (Microsoft Defender, FireEye, Tanium), IDS/IPS, firewalls, proxies, web application firewalls, anti-virus, etc.
•    Understanding of Window Security Event logs and Syslog •    Excellent familiarity with endpoint/perimeter security attack vectors and detection (blue/purple teaming) •    Familiarity with standard security frameworks such as MITRE, cyber kill chain and APT campaign strategies •    Good knowledge of cloud platforms such as Azure, O365, Google cloud, AWS, Oracle •    Good working knowledge of regular expression development •    Scripting and programming experience is highly desirable •    Kusto or SQL knowledge, including rule/query optimisation •    Proven ability to prioritise workload, meet deadlines and utilise time effectively •    Good interpersonal and communication skills, works effectively as a team player and the ability to communicate technical information to a non-technical audience Must have technical / professional qualifications.
•    Bachelor’s degree or higher in Cyber Security/Information Technology or related field •    One or more cyber security certifications such as GCIA, GCIH, GCFA, GNFA, CEH, ECSA preferred   What's in it for you Discretionary yearly bonus.
10% Annual leave.
28 days + bank holidays + the opportunity to buy/sell/carry over 5 days/year Charity days.
5 days/year Maternity leave.
52 weeks out of which 39 weeks are fully paid + 13 weeks half pay and 6 months - working 4 days, getting paid 5 Private pension.
You can contribute up to 5% of your basic pay with 2.
matching from Vodafone up to 10%.
Access to.
private medical, private dental, free health assessments, share save scheme Additional discounts.
Vodafone retail, gym, cinema, cycle to work, season ticket loan Together We Can.
#Li-Hybrid Vodafone is committed to attracting, developing and retaining the very best people by offering a motivating and inclusive workplace in which talent is truly recognised and rewarded.
We are committed to promoting Inclusion for All with the belief that diversity plays an important role in the success of our business.
We actively encourage everyone to consider becoming a part of our journey.
Ver oferta completa

Detalles de la oferta

Empresa
  • Sin especificar
Localidad
  • En toda España
Dirección
  • Sin especificar - Sin especificar
Fecha de publicación
  • 24/06/2024
Fecha de expiración
  • 22/09/2024
Prácticas Content Specialist - Neerlandés o Indonesio
Rankia S.L

Interés por el sector de los mercados financieros... crear los mejores contenidos para los blogs temáticos del área... nivel avanzado/nativo de neerlandés o indonesio... conocimiento de herramientas de gestión de contenido y rrss... disponibilidad para realizar prácticas preferiblemente en horario de......

365.tours - Onboarding and Support Specialist
OtoTrak d.o.o.

Continuous learning and professional development opportunities... are you passionate about outdoor activities and adventure? do you enjoy connecting people with exciting experiences? we have an excellent opportunity for a dynamic and self-motivated individual to join our expanding outdoor activities......

Account Specialist - Gestor/a campañas digitales
Rankia S.L

Si quieres ayudarnos a construir este proyecto como si de tu propia empresa se tratará, desarrollando productos, creando procesos, analizando y tomando decisiones ¡no lo pienses más !este es tu lugar! ¿qué hace un account specialist en rankia? cómo account specialist tendrás la oportunidad colaborar......

Head of Sales Department in a New Development
SVOY Group

Are you a seasoned sales professional with a passion for real estate? do you thrive in a high-energy, team-oriented environment? if so, we have an exciting opportunity for you! we're seeking a dynamic and motivated individual to lead our sales department in a new development project......

Junior it customer success specialist (en language) (remote)
Hostinger

We are looking for a junior technical customer success specialist to join our customer success team... do you think that customers deserve more than just support, and you are willing to go above and beyond to help them succeed? do you dream of deep diving into the world of it but need some experience......

Content Manager en Prácticas
RemoteandTalent

¡haz que tu carrera despegue con nosotros como content manager en prácticas! en remote and talent estamos en la búsqueda activa de un talento único que se una a nuestro equipo para trabajar media jornada (20h semanales) de manera presencial... un horario de trabajo flexible de 4 horas seguidas, de lunes......

INTERNSHIP FRENCH CONTENT WRITER. E-COMMERCE TOURISM
Yumping.com

Conseguir experiencia con posibilidades reales de incorporación a la plantilla una vez terminado el periodo de prácticas... 30 h (1h para comer) y viernes de 9 a 15 h - beca: 300 € - 400 € brutos / mes según la jornada realizada - disponibilidad para incorporación inmediata... ¿qué funciones vas a desempeñar?......

INTERNSHIP WEB CONTENT WRITER. NATIVE ENGLISH. E-COMMERCE.
Yumping.com

Conseguir experiencia con posibilidades reales de incorporación a la plantilla una vez terminado el periodo de prácticas... búsqueda de información relacionada con el turismo activo que te ayude a realizar una publicación de contenido original - optimizar el contenido web a publicar de acuerdo con el......

Sales Development (25h)
Recruit4work SL

Identifying potential customers and generating new business opportunities for the company qualifying potential customers managing leads through the sales pipeline by setting appointments, following up on leads, and tracking progress toward meeting sales goals collaborate with the sales team to......

Social Media Platform Assistant and Creator
Vanta Recruiting

Responsibilities content utilisation: easily post high-quality content provided by our in-house team, using your iphone... content creation: optionally craft, curate, and post compelling content tailored to each platform's unique audience and best practices... must possess an iphone to access and post......