
Cyber Defence Senior Analyst
- Belfast
- Permanent
- Full-time
- Investigate Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary.
- Assist and advise junior colleagues during investigations where additional experience is required.
- Conduct initial triage and investigation of confirmed incidents.
- Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process.
- Participate in security incident response exercises and contribute to post-exercise reviews.
- Be part of the Cyber Defence on-call rota, which may require out-of-hours work.
- Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model.
- Maintain and improve playbooks and process documentation for Cyber Defence.
- Ensure documentation reflects current threat landscapes and operational practices.
- Implement and enhance cyber defence tooling and processes under senior oversight.
- Develop new detection definitions and use cases for monitoring tools.
- Mentor junior colleagues to support their professional development and operational effectiveness.
- Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness.
- Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes.
- Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations.
- Provide cyber defence guidance to business stakeholders, translating technical concepts into business language.
- Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs).
- Assist the Information Security GRC team with client queries and audits from a cyber defence perspective.
- At least 3 years+ experience in a security operations or similar technical security role.
- Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing.
- Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP).
- Familiarity with cyber defence technologies and tooling, including:
- SIEM solutions
- Intrusion Detection & Prevention Systems (ID/PS)
- Threat and vulnerability management platforms
- Endpoint protection
- Firewalls
- Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions.
- Demonstrated ability to investigate complex security issues and propose effective solutions.
- Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams.
- High level of personal integrity and ethics, demonstrating an appropriate level of judgement.
- A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field.
- Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field.
- Industry-recognised certifications such as:
- CISSP (Certified Information Systems Security Professional)
- CEH (Certified Ethical Hacker)
- CISM (Certified Information Security Manager)
- CompTIA Security+
- Experience working with major cloud service providers (CSPs) technologies, such as:
- Microsoft Azure
- Google Cloud Platform (GCP)
- Amazon Web Services (AWS)
- Prior legal firm or professional services firm experience
- Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements.