At a Glance
- Tasks: Investigate security alerts and lead incident responses in a dynamic tech environment.
- Company: Join Contentful, a leading digital experience platform with a diverse and inclusive culture.
- Benefits: Enjoy stock options, generous paid time off, and a personal education budget.
- Why this job: Make a real impact on security while working with cutting-edge technology.
- Qualifications: 5+ years in Security Operations and strong analytical skills required.
- Other info: Collaborate globally and grow your career in a supportive team.
The predicted salary is between 43200 - 72000 £ per year.
Contentful strives to build a secure and safe service and commits considerable effort and resources to security. Our Security team supports corporate-wide information security management programs and collaborates closely with internal teams. We believe that Security must be anchored by DevOps principles with strong repeatable processes. We are looking for a committed and driven Senior Security Analyst with experience performing analysis and incident management of information security events, as well as experience contributing directly to the growth of and design of a security program.
As a Senior Security Analyst, you will have daily alert investigation and incident response responsibilities, but you will be empowered to proactively drive change to shape and support the growth of our Security program. Candidates should have experience triaging new and unfamiliar alerts, leading technical workstreams in incidents, or leading all aspects of medium scale incidents. They should have experience creating and maintaining high quality threat detection and demonstrate knowledge and understanding of common Information Security principles and frameworks, coupled with excellent communications skills and a continuous desire to learn and grow.
You will be expected to work independently, work as a part of a global dispersed team, and partner with stakeholders throughout the organization to ensure comprehensive risk mitigation while reducing impact to end users throughout the organization.
What to expect:
- Perform daily alert investigation and response in a hybrid environment.
- Conduct detail-oriented analysis across challenging and complex ecosystems.
- Communicate investigation and threat updates to technical and non-technical senior leaders.
- Work collaboratively across internal functions to identify, respond, and remediate security issues.
- Investigate and lead incidents of medium size and complexity.
- Investigate vulnerability exploitation and support remediation inline with vulnerability programs.
- Collaborate with the team and actively assist in major response exercises.
- Drive continuous improvement across all aspects of threat detection and response.
- Create processes, documentation, and runbooks to support a rapidly growing team.
- Identify systemic issues and collaborate on approaches to address root causes.
- Collaborate on threat models by incorporating detection use cases into designs.
- Identify and lead efforts to improve efficiency, response, detection, and preventative measures.
- Design and build detection logic across multiple platforms (e.g., SIEM, EDR, etc.).
- Play an active role in scaling Operation practices by contributing to team roadmaps.
- Provide delightful and informative interactions with all end users.
- Proactively identify opportunities for user training and awareness programs.
- Provide insights and input on tool selection to help grow our cybersecurity portfolio.
What You Need To Be Successful:
- 5+ years of Security Operations experience, including alert triage and investigation.
- 2+ years of detection and tuning experience, inclusive of Security Operations experience.
- 2+ years of Security Incident Response experience.
- Ability to support on-call and occasional off-hours incident response efforts.
- Proficiency in analysis fundamentals (e.g., log analysis, live response, forensics, etc.).
- Mastery of investigation methods and adept at handling new and unfamiliar cases.
- Firm understanding of attacker Tactics, Techniques, and Procedures.
- Proficiency in attacker techniques in cloud-native and traditional environments.
- Strong technology fundamentals (e.g., OSI Model, TCP/IP, Layer 7 protocols, etc.).
- Ability to perform detailed host analysis on Mac, Windows, & Linux systems.
- Hands-on experience using security technologies (e.g., SIEM, EDR, AntiVirus, etc.).
- Hands-on experience with malware analysis using dynamic and static analysis tools.
- Expertise in AWS audit and security services to investigate cloud-centric threats.
- Proficiency investigating incidents across SaaS platforms and identity systems.
- Experience performing investigations in cloud service providers (e.g., AWS, GCP, Azure, etc.).
- Practical experience with cross-platform and hybrid environment investigations.
- Ability to interpret designs and enumerate actionable detection use cases.
- Familiarity with modern engineering and detection engineering practices.
- Practical mindset to balance business needs with security requirements.
- A drive for change through continuous improvement.
- Capable of working independently but possesses a collaborative mindset.
- Comfortable working with a geographically dispersed team.
- Experience working independently and as part of a team.
- Ability to work in a fast-paced environment, often juggling multiple tasks, alerts, and incidents.
- Passion for solving complex security problems in innovative and scalable ways.
What’s in it for you?
- Join an ambitious tech company reshaping the way people build digital experiences.
- Full-time employees receive Stock Options for the opportunity to share in the success of our company.
- Fertility and family building benefits, including a lifetime reimbursable wallet to support your growing family.
- We value Work-Life balance and You Time!
- A generous amount of paid time off, including vacation days, sick days, education days, compassion days for loss, and volunteer days.
- Time off to care for and focus on your growing family.
- Use your personal annual education budget to improve your skills and grow in your career.
- Enjoy a full range of virtual and in-person events, including workshops, guest speakers, and fun team activities, supporting learning and networking exchange beyond the usual work duties.
- An annual wellbeing stipend to care for your physical, financial, or emotional health.
- A monthly communication phone/internet stipend and phone hardware upgrade reimbursement.
- New hire office equipment stipend for hybrid or distributed employees.
- Get the gear you need to work at your best.
Who are we?
Contentful is a leading digital experience platform that helps modern businesses meet the growing demand for engaging, personalized content at scale. By blending composability with native AI capabilities, Contentful enables dynamic personalization, automated content delivery, and real-time experimentation, powering next-generation digital experiences across brands, regions, and channels for more than 4,200 organizations worldwide. More than 700 people from more than 70 nations contribute their energy and creativity to Contentful, working from hubs in Berlin, Denver, San Francisco, London, New York, and distributed worldwide. Everyone is welcome here!
“Everyone is welcome here” is a celebrated component of our culture. At Contentful, we strive to create an inclusive environment that empowers our employees. We believe that our products and services benefit from our diverse backgrounds and experiences, and we are proud to be an equal opportunity employer. All qualified applications will receive consideration for employment without regard to race, color, national origin, religion, sexual orientation, gender, gender identity, age, physical disability, or length of time spent unemployed. We invite you to apply and join us!
If you need reasonable accommodations at any point during the application or interview process, please let your recruiting coordinator know.
Please be aware of scammers who may fraudulently allege to be from Contentful. These types of fraud can be carried out through copycat websites, fake email addresses claiming to be from our company, or social media. We do not ask for your personal information, such as bank account numbers, identification numbers, etc., through social media or chat-based apps, nor do we request or send money for the purchase of business equipment. If you suspect fraud, please report it to your local authorities, as well as reach out to us at security-esk@contentful.com with any information you may have.
Senior Security Analyst (f/m/d) employer: Contentful
Contact Detail:
Contentful Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Analyst (f/m/d)
✨Tip Number 1
Network like a pro! Reach out to your connections in the security field and let them know you're on the lookout for opportunities. A personal recommendation can go a long way in landing that Senior Security Analyst role.
✨Tip Number 2
Prepare for those interviews by brushing up on your incident response skills. Be ready to discuss your experience with alert triage and how you've handled complex security incidents in the past. Show them you’re the expert they need!
✨Tip Number 3
Don’t just apply anywhere; focus on companies that align with your values and expertise. Check out our website for openings at Contentful, where your skills in threat detection and response will be truly valued.
✨Tip Number 4
Stay updated on the latest security trends and tools. Being knowledgeable about current threats and solutions will not only boost your confidence but also impress potential employers during interviews.
We think you need these skills to ace Senior Security Analyst (f/m/d)
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Senior Security Analyst role. Highlight your relevant experience in security operations, incident response, and threat detection. We want to see how your skills align with what we're looking for!
Showcase Your Communication Skills: Since you'll be communicating with both technical and non-technical leaders, it's crucial to demonstrate your ability to convey complex information clearly. Use examples in your application that showcase your communication prowess—this will definitely catch our eye!
Highlight Continuous Learning: We love candidates who are eager to learn and grow! Mention any recent courses, certifications, or self-study you've undertaken related to information security. This shows us you're committed to staying ahead in the ever-evolving security landscape.
Apply Through Our Website: Don't forget to submit your application through our official website! This ensures your application is processed correctly and gives you the best chance of being noticed by our hiring team. We can't wait to see what you've got!
How to prepare for a job interview at Contentful
✨Know Your Stuff
Make sure you brush up on your knowledge of security principles and frameworks. Be ready to discuss your experience with alert triage, incident response, and threat detection. The more familiar you are with the tools and techniques mentioned in the job description, the more confident you'll feel during the interview.
✨Showcase Your Problem-Solving Skills
Prepare to share specific examples of how you've tackled complex security issues in the past. Think about incidents you've led or contributed to, and be ready to explain your thought process and the outcomes. This will demonstrate your ability to handle new and unfamiliar cases effectively.
✨Communicate Clearly
Since you'll need to communicate with both technical and non-technical stakeholders, practice explaining complex concepts in simple terms. During the interview, focus on clarity and ensure that your communication style aligns with the collaborative nature of the role.
✨Emphasise Continuous Improvement
Highlight your passion for learning and growing in the field of security. Discuss any recent training, certifications, or projects that showcase your commitment to staying updated with the latest trends and technologies. This will resonate well with the company's focus on driving change and improvement.