At a Glance
- Tasks: Monitor and respond to security threats while collaborating with cross-functional teams.
- Company: Anduril Industries, a cutting-edge defence technology company.
- Benefits: Comprehensive benefits package, health support, and career development opportunities.
- Other info: Dynamic work environment with opportunities for growth and innovation.
- Why this job: Join a mission-driven team transforming military capabilities with advanced technology.
- Qualifications: Experience in security monitoring, Python development, and SIEM languages required.
The predicted salary is between 60000 - 70000 £ per year.
Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.
Anduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defence technologies. As a SecOps analyst on the detection and response team, you will be responsible for monitoring and responding to adversarial activity while helping incorporate key detection feedback loops with the detection engineering team. When not responding to threats, you will be asking questions of our data sets, conducting threat hunting and data normalisation operations across the organization to understand user behavior and identify anomalies.
WHAT YOU'LL DO
- Triage and respond to alerts/incidents covering multiple disciplines including, but not limited to, phishing, endpoints, cloud infrastructure and services, and SaaS applications.
- Build and optimise tailored detection signatures, response playbooks, and response automation using detection-as-code principles.
- As the frontline of DNR, you will lead the feedback loop for detections, ensuring alerts are fine-tuned to reduce false positives.
- Participate in threat modeling scenarios with cross-functional partners to understand weaknesses across Cloud, Mobile, Endpoints, and other environments incorporating findings into security controls and/or detection signatures.
- Organise and conduct threat hunting and data baselines to identify anomalous patterns in data.
- Participate in an on-call rotation responding to security events and conducting incident response investigations while effectively communicating findings to key stakeholders.
- Proactively collaborate with a wide range of stakeholders.
REQUIRED QUALIFICATIONS
- Experience in security monitoring, log analysis, and detection engineering within large data sets across endpoint, network, and a wide variety of application log sources.
- Experience in Python development, specifically contributing to a shared codebase used for automating SOC operations.
- Must have experience with one or more SIEM languages (SPL, KQL, SQL).
- Broad range of practical security knowledge across the spectrum of endpoint, network, identity, application, and cloud infrastructure.
- Knowledge of attacker tactics, techniques, and procedures (TTPs) across Windows, Linux, MacOS, AWS/Azure, etc.
- Strong communication skills and experience collaborating with internal and external stakeholders.
- Eligible to obtain and maintain an Australian NV2 clearance.
PREFERRED QUALIFICATIONS
- Experience conducting incident response in the Cloud (AWS, Azure, GCP).
- Digital Forensics and/or reverse engineering experience is a plus!
Benefits
At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next.
Data Privacy
To view Anduril's candidate data privacy policy, you can visit Anduril's Privacy Notice.
Security Operations Analyst, UK employer: Triwill Group
Vercel is an exceptional employer that prioritises a culture of innovation and collaboration, making it an ideal place for leaders in the tech industry. With a competitive compensation package, flexible time off, and ample opportunities for mentorship and professional growth, employees are empowered to excel in their roles while contributing to the cutting-edge development of web technologies. Located in London, Vercel offers a dynamic work environment that fosters creativity and supports a diverse workforce, ensuring that every team member can thrive and make a meaningful impact.