At a Glance
- Tasks: Conduct in-depth analysis of cyber threats and support Tier 1 Analysts.
- Company: Join DXC Technology, a leader in IT services and cybersecurity.
- Benefits: Competitive salary, professional development, and a dynamic work environment.
- Why this job: Make a real impact in cybersecurity while advancing your skills.
- Qualifications: Degree in Cyber Security or equivalent experience; knowledge of SIEM and KQL.
- Other info: Opportunity for mentorship and career growth in a supportive team.
The predicted salary is between 36000 - 60000 £ per year.
The Tier 2 Cyber Security Analyst is a mid-tier position within the Cyber Threat Analysis Centre (CTAC), responsible for advancing the initial work conducted by Tier 1 Analysts and providing more in-depth analysis of potential threats to the organization. This role is crucial in the escalated investigation, triage, and response to cyber incidents while supporting the development and training of Tier 1 Analysts. The Tier 2 Analyst works closely with senior and junior analysts to ensure a seamless SOC operation and acts as a bridge between foundational and advanced threat detection and response functions.
Responsibilities:
- Conduct escalated triage and analysis on security events identified by Tier 1 Analysts, determining threat severity and advising on initial response actions.
- Apply expertise in SIEM solutions utilizing Kusto Query Language (KQL), to perform log analysis, event correlation, and thorough documentation of security incidents.
- Identify and escalate critical threats to Tier 3 Analysts with detailed analysis for further action, ensuring rapid response and adherence to service Tier objectives (SLOs).
- Investigate potential security incidents by conducting deeper analysis on correlated events and identifying patterns or anomalies that may indicate suspicious or malicious activity.
- Use OSINT (Open-Source Intelligence) to enrich contextual data and enhance detection capabilities, contributing to a proactive stance on emerging threats.
- Monitor the threat landscape and document findings on evolving threat vectors, sharing relevant insights with CTAC teams to enhance overall situational awareness.
- Follow established incident response playbooks, providing feedback for enhancements and suggesting updates to streamline CTAC processes and improve threat response times.
- Coordinate with Tier 3 Analysts and management to refine detection and response workflows, contributing to continuous SOC maturity.
- Collaborate with Tier 3 Analysts on tuning SIEM and detection tools to reduce false positives and improve alert fidelity, submitting tuning requests and testing configurations when necessary.
- Identify gaps in current detection content and work with Senior Analysts to develop and validate new detection rules and use cases tailored to the organization’s threat profile.
- Act as a mentor to Tier 1 Analysts, offering guidance on triage and analysis techniques and facilitating on-the-job training to elevate their technical skills and operational efficiency.
- Assist in training sessions and knowledge-sharing activities, providing feedback on areas for growth and contributing to a supportive learning environment within the SOC.
Knowledge and Skills:
- Understands advanced networking concepts, including IP addressing, basic network protocols, and how traffic flows within a network.
- Advanced knowledge of Windows and Linux operating environments, including standard commands, file systems, and user authentication mechanisms.
- Competence in using SIEM solutions (e.g., ArcSight, Azure Sentinel) for monitoring and log analysis; some exposure to additional analysis tools such as basic XDR platforms.
- Able to demonstrate proficient knowledge using Kusto Query Language (KQL) to search and filter logs effectively.
- Familiar with open-source intelligence (OSINT) techniques to aid in identifying potential threats and gathering information.
- Able to communicate clearly and efficiently with team members and stakeholders, both internally and externally, under direction from senior analysts.
- Can communicate simple technical issues to non-technical individuals in a clear and understandable way.
- Able to create concise, structured reports that outline findings from preliminary investigations and daily monitoring activities.
- Able to manage personal workload effectively to ensure timely completion of assigned tasks within the SOC.
- Willing to collaborate with team members, accepting guidance and learning from more experienced analysts.
- Shows initiative in learning new technologies and techniques, leveraging internal resources and training to grow professionally.
- Able to function efficiently during high-pressure situations, following procedures to ensure consistent performance in incident management.
Education and Professional Experience:
- University Degree/Diploma in Cyber Security or Equivalent experience.
- Other IT certifications or experience such as CISSP, COMPTIA CySA+, GCIA, GCIH Desirable.
- IT certifications such as CASP or ITIL.
- Experience in a SOC or SOC equivalent.
- SC / DV clearance.
Other Requirements:
- Full Driving Licence.
- Fluent in written and spoken English.
Tier 2 SOC Analyst- Cyber Threat Analysis Center employer: DXC Technology Inc.
Contact Detail:
DXC Technology Inc. Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Tier 2 SOC Analyst- Cyber Threat Analysis Center
✨Tip Number 1
Network, network, network! Get out there and connect with folks in the cyber security field. Attend meetups, webinars, or even online forums. The more people you know, the better your chances of landing that Tier 2 SOC Analyst role.
✨Tip Number 2
Show off your skills! If you've got experience with Kusto Query Language (KQL) or SIEM solutions, make sure to highlight that in conversations. Share examples of how you've tackled security incidents or improved detection processes.
✨Tip Number 3
Don’t just apply; engage! When you find a job on our website, take the time to reach out to someone in the company. A quick message expressing your interest can set you apart from the crowd and show your enthusiasm for the role.
✨Tip Number 4
Prepare for interviews by brushing up on common SOC scenarios. Think about how you'd handle escalated threats or collaborate with Tier 3 Analysts. Being ready to discuss real-world examples will impress interviewers and show you're the right fit for the team.
We think you need these skills to ace Tier 2 SOC Analyst- Cyber Threat Analysis Center
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Tier 2 SOC Analyst role. Highlight your experience with SIEM solutions and Kusto Query Language (KQL), as these are key skills we’re looking for. Don’t just list your duties; show how you’ve made an impact in previous roles!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about cyber security and how your skills align with our needs at the Cyber Threat Analysis Centre. Keep it concise but engaging – we want to see your personality!
Showcase Your Problem-Solving Skills: In your application, give examples of how you've tackled complex security incidents or improved processes in past roles. We love seeing candidates who can think critically and adapt to challenges, so don’t hold back on sharing your success stories!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the details you need about the role and our company culture there!
How to prepare for a job interview at DXC Technology Inc.
✨Know Your Threats
Before the interview, brush up on the latest cyber threats and trends. Familiarise yourself with common attack vectors and how they relate to the role of a Tier 2 SOC Analyst. This will show your passion for the field and your proactive approach to staying informed.
✨Master KQL
Since you'll be using Kusto Query Language (KQL) for log analysis, practice writing queries beforehand. Prepare examples of how you've used KQL in past experiences or hypothetical scenarios. Being able to demonstrate your proficiency will set you apart from other candidates.
✨Showcase Your Mentorship Skills
As a Tier 2 Analyst, mentoring Tier 1 Analysts is part of the job. Think of specific instances where you've helped others grow their skills. Be ready to discuss your approach to training and how you can contribute to a supportive learning environment within the SOC.
✨Communicate Clearly
Effective communication is key in this role. Practice explaining complex technical concepts in simple terms. During the interview, aim to convey your thoughts clearly and concisely, especially when discussing your past experiences or technical knowledge.