• Preferred experience with operating or administrating a SIEM (e.g., Splunk/QRadar/LogRhythm).
• Solid understanding of networks including the TCP/IP stack, typical organisation architectures, and common protocols abused by malware.
• Experience in security event analysis & triage, incident handling and root-cause identification.
• Understanding of tools, techniques and procedures that attackers use to compromise organisations, ideally from direct experience.
• Knowledge of cyber security either academically or within corporate environments.
• Ability to work in a fast-paced and demanding environment while remaining calm.
• Strong verbal and written communication and collaboration skills.
• Security industry specific and core technical accreditations such as OSCP, GIAC, CCNA.
• Certification demonstrating SIEM operational competences.
• Proficient with one or more programming languages (e.g., Python, PowerShell, Java, C#).