What You’ll Be Doing:
• Oversee completion of day-to-day checklist(s), including log review, management report scheduling & running, alert analysis, and escalation follow up
• Remain current on cyber security trends and intelligence (open source and commercial) in order to guide the security analysis & identification capabilities of the CSOC team
• Provide oversight, guidance and mentoring to L2 & L3 analysts, and fulfil SOC Manager responsibilities in the absence of the SOC Manager
• Oversee a number of analysts as part of a virtual team of L1 and L2 analysts, including objectives setting, performance management / reviews, training & development, and BAU activities including shift cover etc.
• Perform advanced event and incident analysis, including baseline establishment and trend analysis.
• Support on-call arrangements as part of a Rota, to support L1 Analysts working out of hours
• Support Major Incident Response activity, from a Protective Monitoring perspective, including supporting teams in identification, containment, and remediation of security related threat.
• Provide timely advice and guidance on the response action plans for events and incidents based on incident type and severity.
• Identify, create and implement improvements to procedures and processes, with the SOC Manager’s approval.
• Identify opportunities for SOC and client SIEM platform configuration improvements, use case development, monitoring rule creation, tuning & optimization.
• Stakeholder and Client Reporting, and engagement
• Assist in architectural design to facilitate the onboarding of new information systems, including the assessment, parsing, onboarding of log sources, and use case and rule development.