55 Exec Search
London
Full Time
Permanent
Cyber Threat Investigator - Sentinel
Our client is a pure-play cyber security consulting firm, due to a recent M&A and continued growth they are looking for a technical and driven Cyber Threat Investigator to join the growing team.
You will collaborate closely with the SOC analysts, ensuring clients’ security posture is enhanced. As a Cyber Threat Investigator, you will play a pivotal role within the SOC Team.
As this is a new role, our client will be providing you with the training required to be successful in this role, as a baseline we are looking for candidates who have experience within MS Sentinel, specifically working with LogicApps and automation playbooks and experience developing rules in MS Sentinel. It is also important to have a good understanding of KQL.
You'll lead the charge in planning and managing the development, testing, and implementation of cutting-edge rules and analytics for SIEM and SOAR platforms.
Your day-to-day will be dynamic and collaborative, working closely with SOC Operations Teams to fine-tune existing security use cases and create innovative detection content. You'll be orchestrating each release, overseeing all aspects of design, development, testing, and implementation.
As a Cyber Threat Investigator, you'll become a master at crafting cutting-edge detection and response solutions, leveraging advanced technologies like Lucene, YARA, Sigma and more!
Additionally with the right training, you'll be the key driver and main point of contact for the revolutionary zero-trust protection product. This role includes full ownership and management, ensuring its optimal performance, implementing enhancements, handling customer requests, and serving as the primary escalation contact. Naturally our client will provide you with all training whilst on the job!
No two days are the same in the SOC, responsibilities include but not limited to:
Required skills/experience of Cyber Threat Investigator:
Client Key Facts:
55 Exec Search
London
Full Time
Permanent