The SOC Engineer is part of the IT organisation working in the Security Operations and Networks team. Reporting to the vSNOC manager your role is primarily technical across a variety of fields including computer, network and communications systems for the purposes of Security Operations. You will be a key player across technology groups interfacing with Network, Data Centres and our internal design authority with a remit of driving cyber best practises into our operation.
You will be responsible for the daily maintenance and support of applications and related hardware associated with our solutions for intrusion detection (IDS), Security Incident Event Monitoring (SIEM), and packet capture (PCAP). You will also be a subject matter expert for these tools, providing guidance to our security Operations centre.
Specifically you will be expected to deliver upgrades and manage configuration of technology that underpins cyber operations, this is will include working with and management of external vendors and service partners.
Responding to requests from SOC to tune SIEM, IDS and associated tooling in an effective and timely manner
Working with threat management teams and liaising directly with Network and DC teams to ensure Network architecture, Security Zone configuration and deployment of sensors and remediation platforms Is optimal and effective.
Proficiency in use and maintenance of SIEM or Security Toolsets (such as Nexpose, Qradar, Splunk, Tenable, Magnet, Encase, Becrypt, and SANDBox systems)
Responsible for the maintenance and currency of tooling, ensuring tools are available and being maintained supporting Incident and Vulnerability response
Planning, preparing and executing technology change across a rapidly evolving environment
You will be a self-starter with the ability to prioritise your own workload.
Experience of working in a SOC environment with proven experience in systems management
Experience of SIEM Engineering including on-boarding, troubleshooting and administration of log sources
Ability to obtain and maintain full UK Secret clearance
Experienced in working with TCP/IP, Firewalls and network technology (Cisco, Juniper, Microsoft etc)
Industry qualifications such as CISSP, CCNP, MCSE or CMI Malware Investigations or equivalent
Excellent customer facing skills, internally and externally facing with nationals and international agencies.
Experience of creating small utilities or scripting in Powershell, Perl or Python
Experience of working in MOD and/or other regulated industries i.e. banking, telecommunications
Experience of usecase development and implementation.
An understanding of designing and implementing secure systems to HMG security requirements.
Any knowledge of cyber security best practises such as GPG13, NIST 800-53, NIST 800-171, ISO27001 would be advantageous.
Bachelor’s Degree in Computer Science, Engineering, Information Systems, Mathematics or proven experience in a required area of expertise.
? 25 days holiday + statutory public holidays
? Contributory Pension Scheme (up to 10.5% company contribution)
? 6 times salary ‘Life Assurance’
? Flexible Benefits scheme with extensive salary sacrifice scheme’s.
? Enhanced sick pay scheme
? Enhanced Family Friendly Policies, including enhanced Maternity & Shared Parental leave.
? 37hr working week, with an early finish Friday (hours may vary depending on role, job requirement or site specifics arrangements). Flexible working arrangements can be considered depending on the role and subject to line manager approval.
? Canteen facilities available at Harlow & Glenrothes sites and Manchester & Gloucester offer free snacks & drinks (hot & cold) available.