UK CTAC Analyst Tier 2 in Farnborough

UK CTAC Analyst Tier 2 in Farnborough

Farnborough Full-Time 40000 - 50000 £ / year (est.) No working from home possible
Limelight Health

At a Glance

  • Tasks: Join our team as a Tier 2 Cyber Security Analyst and tackle real cyber threats.
  • Company: DXC Technology, a leader in tech innovation and collaboration.
  • Benefits: Enjoy competitive pay, flexible work options, and opportunities for professional growth.
  • Other info: Work onsite in Erskine or Farnborough with a dynamic team focused on continuous improvement.
  • Why this job: Make a difference in cybersecurity while developing your skills in a supportive environment.
  • Qualifications: Must be a UK national with experience in cyber security and teamwork.

The predicted salary is between 40000 - 50000 £ per year.

Candidate Requirements

  • Candidates must be a sole UK national/British citizen and have resided in the UK for the past 5 years to meet current security clearance requirements.
  • This role is onsite in Erskine or Farnborough and requires the candidate to cover a 12-hour rotational shift on a 4 on 4 off pattern.

The Tier 2 Cyber Security Analyst is a mid-tier position within the Cyber Threat Analysis Centre (CTAC), responsible for advancing the initial work conducted by Tier 1 Analysts and providing more in-depth analysis of potential threats to the organization. This role is crucial in the escalated investigation, triage, and response to cyber incidents while supporting the development and training of Tier 1 Analysts. The Tier 2 Analyst works closely with senior and junior analysts to ensure a seamless SOC operation and acts as a bridge between foundational and advanced threat detection and response functions.

Responsibilities

  • Conduct escalated triage and analysis on security events identified by Tier 1 Analysts, determining threat severity and advising on initial response actions.
  • Apply expertise in SIEM solutions utilizing Kusto Query Language (KQL), to perform log analysis, event correlation, and thorough documentation of security incidents.
  • Identify and escalate critical threats to Tier 3 Analysts with detailed analysis for further action, ensuring rapid response and adherence to service tier objectives (SLOs).
  • Investigate potential security incidents by conducting deeper analysis on correlated events and identifying patterns or anomalies that may indicate suspicious or malicious activity.
  • Use OSINT (Open-Source Intelligence) to enrich contextual data and enhance detection capabilities, contributing to a proactive stance on emerging threats.
  • Monitor the threat landscape and document findings on evolving threat vectors, sharing relevant insights with CTAC teams to enhance overall situational awareness.
  • Follow established incident response playbooks, providing feedback for enhancements and suggesting updates to streamline CTAC processes and improve threat response times.
  • Coordinate with Tier 3 Analysts and management to refine detection and response workflows, contributing to continuous SOC maturity.
  • Collaborate with Tier 3 Analysts on tuning SIEM and detection tools to reduce false positives and improve alert fidelity, submitting tuning requests and testing configurations when necessary.
  • Identify gaps in current detection content and work with Senior Analysts to develop and validate new detection rules and use cases tailored to the organization’s threat profile.
  • Act as a mentor to Tier 1 Analysts, offering guidance on triage and analysis techniques and facilitating on-the-job training to elevate their technical skills and operational efficiency.
  • Assist in training sessions and knowledge-sharing activities, providing feedback on areas for growth and contributing to a supportive learning environment within the SOC.

Knowledge and Skills

  • Understands advanced networking concepts, including IP addressing, basic network protocols, and how traffic flows within a network.
  • Advanced knowledge of Windows and Linux operating environments, including standard commands, file systems, and user authentication mechanisms.
  • Competence in using SIEM solutions (e.g., ArcSight, Azure Sentinel) for monitoring and log analysis; some exposure to additional analysis tools such as basic XDR platforms.
  • Able to demonstrate proficient knowledge using Kusto Query Language (KQL) to search and filter logs effectively.
  • Familiar with open-source intelligence (OSINT) techniques to aid in identifying potential threats and gathering information.
  • Able to communicate clearly and efficiently with team members and stakeholders, both internally and externally, under direction from senior analysts.
  • Can communicate simple technical issues to non-technical individuals in a clear and understandable way.
  • Able to create concise, structured reports that outline findings from preliminary investigations and daily monitoring activities.
  • Able to manage personal workload effectively to ensure timely completion of assigned tasks within the SOC.
  • Willing to collaborate with team members, accepting guidance and learning from more experienced analysts.
  • Shows initiative in learning new technologies and techniques, leveraging internal resources and training to grow professionally.
  • Able to function efficiently during high-pressure situations, following procedures to ensure consistent performance in incident management.

Education and Professional Experience

  • Other IT certifications or experience such as CISSP, COMPTIA CySA+, GCIA, GCIH.
  • Desirable IT certifications such as CASP or ITIL.
  • Experience in a SOC or equivalent SOC environment.
  • SC / DV clearance.

Other Requirements

  • Be willing to undertake SC and / or DV clearance with multiple agencies.
  • Full Driving Licence.
  • Fluent in written and spoken English.

At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritises in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive.

UK CTAC Analyst Tier 2 in Farnborough employer: Limelight Health

At DXC Technology, we pride ourselves on being an exceptional employer that values strong connections and community. Our work culture promotes in-person collaboration while offering flexibility to support individual wellbeing and productivity, making it an ideal environment for growth and development. With opportunities for mentorship and continuous learning within the Cyber Threat Analysis Centre, employees can thrive in their careers while contributing to a vital mission in cyber security.

Limelight Health

Contact Details:

Limelight Health Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land UK CTAC Analyst Tier 2 in Farnborough

Tip Number 1

Network like a pro! Reach out to current or former employees at DXC Technology on LinkedIn. A friendly chat can give you insider info and maybe even a referral, which can really boost your chances.

Tip Number 2

Prepare for the interview by brushing up on your Kusto Query Language (KQL) skills. Be ready to discuss how you've used it in past roles, as this will show you're not just a theory buff but someone who can get hands-on with the tech.

Tip Number 3

Show off your problem-solving skills during interviews. Think of examples where you’ve triaged incidents or improved processes. This will demonstrate your ability to think on your feet and contribute to the team right away.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining the team at DXC Technology.

We think you need these skills to ace UK CTAC Analyst Tier 2 in Farnborough

Cyber Security Analysis
SIEM Solutions
Kusto Query Language (KQL)
Incident Response
Open-Source Intelligence (OSINT)
Networking Concepts
Windows Operating Environment

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the role of a Tier 2 Cyber Security Analyst. Highlight your experience with SIEM solutions, KQL, and any relevant certifications. We want to see how your skills match what we're looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your background makes you a great fit for our team. Keep it concise but impactful – we love a good story!

Show Off Your Skills:In your application, don’t just list your skills – demonstrate them! If you've worked on specific projects or have examples of how you've tackled cyber threats, share those. We’re keen to see your practical experience in action.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our team at DXC Technology!

How to prepare for a job interview at Limelight Health

Know Your Cyber Security Basics

Make sure you brush up on your knowledge of advanced networking concepts and the basics of Windows and Linux operating systems. Being able to discuss these topics confidently will show that you're well-prepared and understand the technical requirements of the Tier 2 Analyst role.

Master KQL for Log Analysis

Since you'll be using Kusto Query Language (KQL) for log analysis, practice writing queries beforehand. Familiarise yourself with common commands and how to filter logs effectively. This will not only help you in the interview but also demonstrate your hands-on skills relevant to the job.

Showcase Your Incident Response Knowledge

Be ready to discuss your experience with incident response playbooks and how you've contributed to improving processes in previous roles. Highlight any specific examples where you identified threats or escalated incidents, as this will illustrate your ability to handle real-world scenarios.

Communicate Clearly and Confidently

During the interview, practice explaining technical concepts in a way that's easy to understand. You might be asked to communicate findings to non-technical stakeholders, so showcasing your ability to simplify complex information will be a big plus. Remember, clear communication is key in a collaborative environment!