At a Glance
- Tasks: Join the Cyber Fusion Center to analyse and respond to security threats.
- Company: Experian, a global leader in data and technology, empowering businesses worldwide.
- Benefits: Flexible work options, competitive pay, healthcare, and generous leave policies.
- Other info: Dynamic team environment with opportunities for growth and skill development.
- Why this job: Be on the front lines of cybersecurity, making a real difference in protecting data.
- Qualifications: Experience in security operations or incident response; relevant degree or certifications preferred.
The predicted salary is between 36000 - 60000 £ per year.
Company Description
Experian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare, create marketing solutions, and gain deeper insights into the automotive market, all using our unique combination of data, analytics and software. We also assist millions of people to accomplish their financial goals and help them save time and money. We operate across a range of markets, from financial services to healthcare, automotive, agribusiness, insurance, and many more industry segments. We invest in people and new advanced technologies to unlock the power of data. As a FTSE 100 Index company listed on the London Stock Exchange (EXPN), we have a team of 22,500 people across 32 countries. Our corporate headquarters are in Dublin, Ireland.
Job Description
As a Cyber Defence Analyst, you will join the Cyber Fusion Center, performing in-depth analysis, assessment, and response to security threats by following documented policies to meet Service Level Goals. The team provides global 24x7 security operations and monitoring for cybersecurity events affecting Experian. You will be a part of the first line of defence in Experian's broader incident response and incident management departments, responsible for receiving and prioritizing cybersecurity alerts, including being the dedicated contact for potential security incidents reported by users (e.g., Experian employees). Depending on the results of assessment, this team is then responsible for investigating, containing, eradicating, and recovering from events falling in its scope or escalating higher-risk events to dedicated incident response and management teams in the CFC. This role is critical in ensuring the handling of potential threats and plays a part in improving security operations. This is a home based role reporting to the Director of Security Operations for SecOps & Threat Detection. Please note that in this role, you will have an 8x5 Monday-Friday schedule, with flexibility to respond to after-hours pages for potentially major security incidents to support incident response efforts and may include assignment to an on-call rotation for evenings, weekends, holidays.
Summary Of Primary Responsibilities
- Contribute to daily security operations by overseeing response activities for security events and alerts associated with cyber threats, intrusions, and compromises alongside a team of global security analysts following documented SLOs and processes.
- Analyze events using security tooling and logging (e.g., SIEM, EDR) and assess potential risk/severity level of cyber threats; escalate higher-risk events to dedicated incident response and management teams in the CFC according to established processes.
- Collaborate with external teams for incident resolution and escalations, driving incident handling.
- Notify team Lead(s) of concerns related to operations, such as anomalous changes in metrics, notable open incidents, quality concerns, or observed risks; support with resolution if appropriate.
- Manage and complete assigned caseload throughout the incident response lifecycle, including analysis, containment, eradication, recovery, and lessons learned.
- Maintain all case documentation, including notes, analysis findings, containment steps, and cause for each assigned security incident.
- Ensure incident updates or contact with end-users are performed promptly and documented.
- Help improve relevant strategies, Standard Operating Procedures (SOPs), and training materials.
- Support management's overall strategy for CFC by participating in execution of improvement programs together with management's plans.
- Assist the team Leads and management on use case development by suggesting enhancement or tuning of use cases to improve the security posture of Experian.
Qualifications
- Some information security experience working within a Security Operations Center or Cyber Security Incident Response Teams.
- Bachelor's Degree in Computer Science, Computer Engineering, Information Systems, Information Security or professional certification related to Digital Forensics, Incident Response, or Ethical Hacking (e.g., GCIH, CEH, GCFE, GCFA, and CFCE).
- Knowledge of main concepts related to the Incident Response Life Cycle, MITRE ATT&CK Framework, Cyber Kill Chain, and other cybersecurity frameworks.
- High-level understanding of common intrusion methods and cyber-attack tactics, techniques, and procedures (TTPs), and common industry recommendations to prevent and respond to threats such as phishing, malware, network attacks, suspicious activity, data security incidents.
- Exposure to technical elements of common Operating Systems (Windows, Linux, Mac OS), Networking (Firewalls, Proxies, NetFlow), Cloud Infrastructure (AWS, Azure, GCP), and Security Technologies (Anti-Virus, Intrusion Prevention, Web Application Firewalls).
- Interest in developing knowledge across common Incident Response and Security Monitoring applications such as SIEM (e.g., Qradar, Splunk), EDR (e.g., FireEye HX, CrowdStrike Falcon, Microsoft Defender), and SOAR (Palo Alto XSOAR, Google Secops / Chronicle).
- Desire to build technical skills and hands-on knowledge in the following areas of security operations and incident response: In-depth packet analysis skills, core forensic familiarity, incident response skills, public-cloud security practices, and data fusion skills based on multiple security data sources.
- Security analysis and architecture of Azure and AWS cloud environment using security tools including Defender for Cloud, GuardDuty, CloudTrail, or CloudWatch.
- System administration on Unix, Linux, or Windows.
- Network forensics, logging, and event management.
- Defensive network infrastructure (operations or engineering).
- Vulnerability assessment and penetration testing concepts.
- Malware analysis concepts, techniques, and reverse engineering.
- In-depth knowledge of network and host security technologies and products (such as firewalls, network IDS, scanners) and improve these skills.
- Security monitoring technologies, such as SIEM, IPS/IDS, UEBA, DLP, among others.
- Scripting and automation.
Benefits Package Includes
- Flexible work environment, working hybrid or in the office if you prefer.
- Great compensation package and discretionary bonus plan.
- Core benefits include pension, Bupa healthcare, ShareSave scheme and more.
- 25 days annual leave with 8 bank holidays and 3 volunteering days. You can purchase additional annual leave.
Experian is proud to be an Equal Opportunity and Affirmative Action employer. Innovation is an important part of Experian's DNA and practices, and our diverse workforce drives our success. Everyone can succeed at Experian and bring their whole self to work, irrespective of their gender, ethnicity, religion, colour, sexuality, physical ability or age. If you have a disability or special need that requires accommodation, please let us know at the earliest opportunity.
Cyber Defence Analyst in Nottingham employer: Back on Track! Solutions
Contact Detail:
Back on Track! Solutions Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Defence Analyst in Nottingham
✨Tip Number 1
Network like a pro! Reach out to people in the industry, attend webinars, and join relevant online communities. You never know who might have the inside scoop on job openings or can refer you directly.
✨Tip Number 2
Prepare for interviews by practising common questions and scenarios related to cyber defence. Use mock interviews with friends or mentors to build confidence and get feedback on your responses.
✨Tip Number 3
Showcase your skills! Create a portfolio or GitHub repository with projects that demonstrate your knowledge in cybersecurity tools and techniques. This gives potential employers a tangible look at what you can do.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Experian.
We think you need these skills to ace Cyber Defence Analyst in Nottingham
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Cyber Defence Analyst role. Highlight relevant experience and skills that match the job description, like your knowledge of cybersecurity frameworks and incident response. We want to see how you can contribute to our team!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your background makes you a great fit for Experian. Don’t forget to mention any specific projects or experiences that relate to the role.
Show Off Your Skills: In your application, be sure to showcase your technical skills, especially those related to security operations and incident response. Mention any tools or technologies you’re familiar with, like SIEM or EDR, as these are key to the role we’re hiring for.
Apply Through Our Website: We encourage you to apply through our website for the best chance of being noticed. It’s super easy and ensures your application goes directly to us. Plus, you’ll get to see all the other cool opportunities we have at Experian!
How to prepare for a job interview at Back on Track! Solutions
✨Know Your Cybersecurity Basics
Before the interview, brush up on key concepts like the Incident Response Life Cycle and the MITRE ATT&CK Framework. Being able to discuss these frameworks confidently will show that you understand the fundamentals of cybersecurity and can apply them in real-world scenarios.
✨Showcase Your Technical Skills
Be prepared to talk about your experience with security tools like SIEM and EDR. If you've worked with specific technologies such as Splunk or CrowdStrike, mention them! Highlighting your hands-on experience will demonstrate your capability to handle the technical demands of the role.
✨Prepare for Scenario-Based Questions
Expect questions that ask how you would respond to specific security incidents. Think through potential scenarios and outline your thought process for containment, eradication, and recovery. This will help the interviewers see your problem-solving skills in action.
✨Ask Insightful Questions
At the end of the interview, don’t forget to ask questions! Inquire about the team’s current challenges or how they measure success in the Cyber Fusion Center. This shows your genuine interest in the role and helps you gauge if it’s the right fit for you.