At a Glance
- Tasks: Monitor and respond to cyber threats, ensuring client networks stay secure.
- Company: Join a leading tech firm focused on innovative cyber security solutions.
- Benefits: Enjoy flexible working, generous leave, and access to mental health support.
- Other info: Great career growth opportunities in a supportive environment.
- Why this job: Make a real impact in cyber security while developing your skills in a dynamic team.
- Qualifications: Experience in cyber security and strong communication skills are essential.
The predicted salary is between 40000 - 50000 £ per year.
We're looking for a Cyber Security Analyst to join the ARCHANGEL™ Protective Monitoring (ProMon) Team. ARCHANGEL™ delivers specialist technical cyber security services to a range of clients across a variety of industries including construction, government, defence and aerospace. The ARCHANGEL™ ProMon Team sits within the Bristol Service Operations Centre (SOC) and is responsible for providing thorough initial investigation into anomalous network activity that may lead to potential security incidents.
You will be joining our highly skilled team at our Bristol site. This is a great opportunity to bring your talents and form an integral part of Leonardo's future. We can help you develop your skills and offer great opportunities to develop and grow.
At Leonardo, we believe that our employees work best when they are able to achieve balance between work and other aspects of life. That's why we are committed to designing policies and developing a working environment that promote the benefits and well-being of all our employees.
What you will do as a Cyber Security Analyst:
- Provide monitoring, alerting and incident handling services within the SOC in line with SLAs.
- Act as the initial analytical reference point for identifying and then quantifying the nature and extent of security incidents and offer initial professional advice relating to possible business impact in order to reduce both the Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
- Advise on incident containment measures through recommended initial actions to customers in collaboration with the Incident Response (IR) Team.
- Provide advice relating to potential mitigation measures in order to prevent, or limit future reoccurrence in collaboration with the Incident Response (IR) Team.
- Perform proactive analysis across client networks by staying abreast of current threats and trends.
- Develop and maintain a credible knowledge of current and emerging threats likely to affect the integrity of the managed service you are protecting.
- Review reoccurring false positive firings and assist in the tuning of SIEM and IDS rules to reduce false positives and maintain good security alerting.
- Create reporting for management and clients on security incidents and threat intelligence trends.
What you’ll bring:
- Ability to excellently communicate at all levels – working with customers is a must.
- Experience in Cyber Security, e.g. Protective Monitoring, Incident Response, Security Engineering.
- SIEM (LogRhythm, Arcsight, Splunk, etc) & IDS (Snort) experience.
- Sound knowledge of IT security best practice, common attack types & detection/prevention methods.
- Understanding of Incident Response, Cyber Kill Chain, Threat Modelling and pertinent Attack Vectors.
- Collaborative working ethos to create pertinent Playbooks, Use Cases, etc.
- Experience of analysing & interpreting system, security & application logs to diagnose faults & spot abnormal behaviours.
- Great organisational skills & attention to detail.
- Ability to work independently & as part of a team.
- Highly motivated, with the aptitude to learn new skills.
Additional skills:
- SANS SEC 503 Intrusion Detection in Depth or equivalent.
- SANS SEC 504 Incident Handling, Hacker Tools and Techniques or equivalent.
- SANS SEC 508 Advanced Incident Response, Threat Hunting, and Digital Forensics or equivalent.
- SANS SEC 511 Continuous Monitoring and Security Operations or equivalent.
- Exposure to IT service management best practices such as ITIL.
- Knowledge of standards & guidelines such as ISO27001, GDPR principles and GPG-13.
- Threat Intelligence experience.
- Report Writing.
Security Clearance:
This role is subject to pre-employment screening in line with the UK Government’s Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV).
Benefits:
- Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year.
- Secure your Future: Benefit from our award-winning pension scheme with up to 15% employer contribution.
- Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks championing inclusion and diversity.
- Rewarding Performance: All employees at management level and below are eligible for our bonus scheme.
- Never Stop Learning: Free access to 4,000+ online courses via Coursera and LinkedIn Learning.
- Refer a friend: Receive a financial reward through our referral programme.
- Tailored Perks: Spend up to £500 annually on flexible benefits including private healthcare, dental, family cover, tech & lifestyle discounts, gym memberships and more.
- Flexible working: Flexible hours with hybrid working options.
Primary Location: GB - Bristol - Coldharbour Lane
Contract Type: Permanent Hybrid Working Onsite
Cyber Security Analyst in Bristol employer: 慨正橡扯
At Leonardo, we pride ourselves on being an exceptional employer, offering a dynamic work culture that prioritises employee well-being and professional growth. Located in the vibrant city of Bristol, our Cyber Security Analyst role provides access to extensive training resources, flexible working arrangements, and a supportive environment that fosters collaboration and innovation. Join us to be part of a leading team in cyber security, where your contributions will directly impact the safety and technology solutions for clients across various critical sectors.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Analyst in Bristol
✨Tip Number 1
Network like a pro! Attend industry events, meetups, or online webinars related to cyber security. Connecting with professionals in the field can open doors and lead to job opportunities that aren't even advertised.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your projects, certifications, and any relevant experience. This gives potential employers a tangible way to see what you can bring to the table.
✨Tip Number 3
Prepare for interviews by practising common cyber security scenarios and questions. We recommend doing mock interviews with friends or using online platforms to get comfortable with articulating your thought process.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace Cyber Security Analyst in Bristol
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Cyber Security Analyst role. Highlight relevant experience in protective monitoring, incident response, and any specific tools like SIEM or IDS that you've worked with. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how you can contribute to our team. Don't forget to mention your communication skills and collaborative spirit, as these are key for working with our clients.
Showcase Your Knowledge:In your application, demonstrate your understanding of current threats and trends in cyber security. Mention any relevant certifications or training you've completed, like SANS courses, to show us you're serious about staying ahead in the field.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets to the right people. Plus, you'll find all the details about the role and our company culture there!
How to prepare for a job interview at 慨正橡扯
✨Know Your Cyber Security Basics
Make sure you brush up on your knowledge of IT security best practices, common attack types, and detection methods. Being able to discuss these confidently will show that you're not just familiar with the theory but can apply it in real-world scenarios.
✨Familiarise Yourself with Tools
Get hands-on experience with SIEM tools like LogRhythm, Arcsight, or Splunk, and IDS systems like Snort. If you can demonstrate your understanding of how these tools work during the interview, it’ll give you a significant edge.
✨Prepare for Scenario Questions
Expect to be asked about how you would handle specific security incidents. Think through potential scenarios and prepare your responses, focusing on your analytical skills and how you would communicate with clients during an incident.
✨Show Your Collaborative Spirit
Since this role involves working closely with teams, be ready to discuss examples of how you've collaborated in the past. Highlight your ability to create playbooks and use cases, as well as your experience in tuning SIEM and IDS rules to reduce false positives.