
Cyber Security Analyst - XDR
- Exeter Leeds
- £57,372-65,652 per year
- Contract
- Full-time
- Cyber Security Operations Unit (CSOU)
- Cyber Delivery Unit (CDU)
- Cyber Improvement Programme
- Chief Information Security Office Function (CISO)
- Act as a Tier 2 Extended Detection and Response (XDR) analyst for the Security Operations team.
- Deputise for Senior Analysts in their absence.
- Act as an escalation point for Tier 1 Junior Analysts for incidents and investigations.
- Offer mentorship and guidance to Tier 1 Junior Analysts to support others and their own growth and development.
- Keep up to date with the latest security and technology developments, including researching and evaluating emerging cyber security threats and ways to manage them.
- Use advanced analytic tools including SIEMs and XDR platforms to determine emerging threat patterns and vulnerabilities.
- Apply experience and knowledge to assist with investigations of triggered security alerts.
- Assist with the refinement of Use Cases and identification of areas for improvement of overall security posture.
- Provide technical support to NHS organisations in investigating XDR incidents.
- Enabling local systems and providers to improve the health of their people and patients and reduce health inequalities.
- Making the NHS a great place to work, where our people can make a difference and achieve their potential.
- Working collaboratively to ensure our healthcare workforce has the right knowledge, skills, values and behaviours to deliver accessible, compassionate care
- Optimising the use of digital technology, research, and innovation
- Delivering value for money.
- Proven knowledge of concepts, issues, and techniques of Endpoint Security. Ability to ensure security compliance of endpoint devices in various circumstances.
- Working knowledge of modules, processes, and technologies of an Information Security Operation Centre (SOC); ability to detect, respond and utilise related platform and applications to perform cyber security initiatives.
- Working knowledge of concept, procedures and processes of Security Information and Event Management (SIEM); ability to utilise related applications to protect organisational networks from cyber risks.
- Proven knowledge of concept, issues and techniques of Email Security. Ability to detect, monitor, analyse and prevent unauthorised access, loss or compromise of business email accounts.
- Proven knowledge of tools, techniques and processes of intrusion detection and prevention; ability to detect, resolve and prevent intrusion behaviours to protect organisational networks.
- Post-graduate level degree or equivalent level of experience.
- Proven knowledge of concepts, issues, and techniques of Endpoint Security. Ability to ensure security compliance of endpoint devices in various circumstances.
- Working knowledge of modules, processes, and technologies of an Information Security Operation Centre (SOC); ability to detect, respond and utilise related platform and applications to perform cyber security initiatives.
- Working knowledge of concept, procedures and processes of Security Information and Event Management (SIEM); ability to utilise related applications to protect organisational networks from cyber risks.
- Proven knowledge of concept, issues and techniques of Email Security. Ability to detect, monitor, analyse and prevent unauthorised access, loss or compromise of business email accounts.
- Proven knowledge of tools, techniques and processes of intrusion detection and prevention; ability to detect, resolve and prevent intrusion behaviours to protect organisational networks.
- Post-graduate level degree or equivalent level of experience.