SIEM Content Development Specialist in Brentford

Location: Brentford
Salary: Hidden
Recruiter: Vodafone
Job Hours: Full-time

Start your application for this job today

Apply Now

.

Role title: SIEM Content Development Specialist

Location : Newbury

What you’ll do

  • Content Development – take part in and drive continual creation and refinement of rules and logic within the Vodafone SIEM/EDR/ELK infrastructure to improve Cyber Security Operations efficiency and effectiveness. This would include responsibilities such as the following:
  • o Develop SIEM/EDR/ELK content to address attack vectors using current industry best practices
    o Analyse threats/adversaries/attack tools to develop indicator/behavioural based detections that alert and/or prevent malicious activity
    o Evaluate and make use of multiple data sources to build content across multiple SIEM/EDR/ELK platforms
    o Utilise SIEM/EDR/ELK to facilitate metrics collection, analysis and reporting
    o Create and maintain analytics documentation
    o Effectively collaborate with colleagues and counterparts internally and externally

  • Security Analysis – take part in and may drive security event analysis activities to address current Cyber threats
  • Threat Response – may require engagement and possibly driving the analysis from blue team perspective to identify possible threat group activity
  • Security Reporting and Advisories – take part in and may drive the delivery of cyber security reports and advisories to all key stakeholders
  • Residual Risk Assessment – take part in and may drive the delivery of ‘operational and technical’ lessons learnt post incident analysis and reporting
  • Who you are

    • Minimum of 1-3 years’ experience in SIEM content (rule logic and code) development role
    • Minimum of 1 years of SOC analyst experience (Level2 or above) required
    • 5 years IT experience
    • In depth and extensive hands-on experience in security event analysis, create and refine SIEM/EDR rules and deliver efficiency within the SIEM and all other technologies used within the team
    • Deep knowledge of IPv4/IPv6, TCP networking protocols
    • Deep knowledge of Windows/Linux operating systems
    • Good working knowledge of security technologies such as SIEM (ArcSight, Sentinel, QRadar, LogRhythm, Splunk), EDR (Microsoft Defender, FireEye, Tanium), IDS/IPS, firewalls, proxies, web application firewalls, anti-virus, etc.
    • Understanding of Window Security Event logs and Syslog
    • Excellent familiarity with endpoint/perimeter security attack vectors and detection (blue/purple teaming)
    • Familiarity with standard security frameworks such as MITRE, cyber kill chain and APT campaign strategies
    • Good knowledge of cloud platforms such as Azure, O365, Google cloud, AWS, Oracle
    • Good working knowledge of regular expression development
    • Scripting and programming experience is highly desirable
    • Kusto or SQL knowledge, including rule/query optimisation
    • Proven ability to prioritise workload, meet deadlines and utilise time effectively
    • Good interpersonal and communication skills, works effectively as a team player and the ability to communicate technical information to a non-technical audience

    Must have technical / professional qualifications: 

    • Bachelor’s degree or higher in Cyber Security/Information Technology or related field
    • One or more cyber security certifications such as GCIA, GCIH, GCFA, GNFA, CEH, ECSA preferred

    What's in it for you

    Together We Can:

    #Li-Hybrid


    About Vodafone


    At Vodafone, we are known for our technology, but the truth is, it is humanity that drives our business forward. With the global pandemic raising so many questions for tech brands, it has highlighted the leading role that we need to play.

    We believe that, when working together, humanity and technology can find the answers and create a better future for all.

    Working at Vodafone is all about helping people feel ready to benefit from new technology. We bring the future to even the most remote places, using technology to help families in disaster zones, showing young people that a phone is not just for fun and thinking about technology that doesn’t even exist yet.

    More than 35 years ago, we made the first-ever mobile phone call, we sent the first SMS in Britain and have been changing the lives of billions of people ever since. Now, we are using smartphones to fight cancer, big data for social good, and we aim to connect over 250 million people to our next generation networks by 2025.

    We are passionate about building a workplace where you can truly be yourself, share inspiration, embrace new opportunities, thrive and make a real difference to people and our planet. We are known for our technology, but it is humanity that drives us forward. What are you passionate about?

    #TogetherWeCan

    The best places to find the most SIEM Content Development Specialist jobs

    Average salary comparison

    Job salary over time

    Salaries by job level

    Salary across the UK

    CV template for a SIEM Content Development Specialist

    View Now
    CV template for a SIEM Content Development Specialist

    Glassdoor Company Reviews

    Search