Summary of Role
The Senior Cyber Security Analyst will lead the investigations of escalated security incidents based on the tiered Incident Response approach. The primary purpose of this position is to serve as an expert in providing technical analysis, assessment and mitigation recommendations for escalated security incidents where deep technical knowledge is required.
The Role Key responsibilities include the following, however other duties may be assigned as required. Ensure timely response to any cyber incident to minimise risk exposure and production down time Conduct incident response activities, including advanced investigation (forensic analysis to include evidence seizure and malware analysis) to investigate potential security incidentsSafely acquire and preserve the integrity of cyber security data required for incident analysis to help determine the technical/operational impact, root cause(s), scope and nature of the incidentAnalyse and correlate incident data to develop a preliminary root cause and corresponding remediation strategyEvaluate target systems to analyse results of scans, identify and recommend resolutions Utilise incident response playbooks to follow established and repeatable processes for triaging and containment of an incidentProvide timely, comprehensive and accurate information to the CSIRT Manager in both written and verbal communicationsAdvise junior CSIRT team members on the technical steps to take to investigate and resolve cyber security incidentsRoutinely develop and update incident response playbooks to ensure response activities align with best practices, minimise gaps in response and provide comprehensive mitigation of threatsThe RequirementsMinimum of ten (10) years of experience in the Cybersecurity fieldMinimum of five (5) years of Information Technology experience with Windows OS platformsMinimum of five (5) years of experience as a Level 2 (or above) as Cyber Security Incident Response Analyst performing incident handling, forensics, sensor alert tracking and cybersecurity incident case managementMinimum of five (5) years of experience working with security technologies such as IDS/IPS, Firewalls, SIEM, Network Packet Analysers, Antivirus, Network Behavior Analysis tools, Malware analysis, Firewalls, DLP, endpoint protection, log collection and analysisStrong working knowledge of security relevant data, including network protocols, ports and common services such as TCP/IP protocols and application layer protocols (e.g., HTTP/S, DNS, FTP, SMTP, etc.)Knowledge of the Computer Security Incident Handling Guide, NIST 800-61 r2Professional certifications commensurate with experience, i.e. GCFA, GCIH, etc. Hands on experience with scripting languages such as Python, Perl, Bash, PowerShell or similarKnowledge of privilege escalation, persistence and lateral movement techniquesKnowledge of common malware and exploit tools and techniquesMinimum of five (5) years of experience with chain of custody, forensic tools and methodologiesKnowledge of Cloud security and incident response in a Cloud environmentUnderstanding of the Kill Chain and Diamond Method of Analysis Ability to communicate technical details in writing and verbally to non-technical and junior CSIRT team membersExperience in developing and maintaining Run-BooksStrong critical thinking and analytical problem-solving skills Work and communicate within a global team environmentThe Company
Willis Towers Watson is a leading global advisory, broking and solutions company that helps clients around the world turn risk into a path for growth. With roots dating to 1828, Willis Towers Watson has 40,000 employees serving more than 140 countries. We design and deliver solutions that manage risk, optimize benefits, cultivate talent, and expand the power of capital to protect and strengthen institutions and individuals. Our unique perspective allows us to see the critical intersections between talent, assets and ideas – the dynamic formula that drives business performance. Together, we unlock potential. Learn more at willistowerswatson.com.
Willis Towers Watson is an equal opportunity employer
Willis Towers Watson believes that effectively managing a diverse workforce is vital to our business strategy. We have an obligation to our organization, ourselves and our clients to hire and develop the best people we can find. We will continually review our policies and practices to ensure that all areas of the employment process (including recruiting, hiring, work assignments, compensation, benefits, promotions, transfers, company-sponsored development programs and overall workplace experience) are free from discriminatory practices. We are committed to equal employment opportunities at Willis Towers Watson.
Unsolicited Contact: Any unsolicited resumes/candidate profiles submitted through our web site or to personal e-mail accounts of employees of Willis Towers Watson are considered property of Willis Towers Watson and are not subject to payment of agency fees. In order to be an authorized Recruitment Agency/Search Firm for Willis Towers Watson, any such agency must have an existing formal written agreement signed by an authorized Willis Towers Watson recruiter and an active working relationship with the organization. Resumes must be submitted according to our candidate submission process, which includes being actively engaged on the particular search. Likewise, for our authorized Recruitment Agencies/Search Firms, if the candidate submission process is not followed, no agency fees will be paid by Willis Towers Watson. Willis Towers Watson is an equal opportunity employer.
Bank or payment details should not be provided when applying for a job. reed.co.uk is not responsible for any external website content. All applications should be made via the 'Apply now' button.
Report this job