Principal Security Analyst - Csoc

Capital One Capital One · Banking · Nottingham, United Kingdom

This role is for a Principal Security Analyst in a Cyber Security Operations Center (CSOC). The primary responsibilities include investigating cyber threats, performing proactive threat hunting, providing technical mentorship to other analysts, and improving security processes and tools. The role requires deep knowledge of network protocols, log investigation techniques, cloud infrastructures, and incident handling.

What you'd actually do

  1. Head up complex investigations that require deep-dive analysis, from start to finish.
  2. You design and execute hunting hypotheses to uncover threats that bypass traditional detection.
  3. You act as a primary resource for our CSOC analysts, sharing your deep-seated domain knowledge to level up the team's collective skill set.
  4. You use your investigative insights to refine our processes and ensure our security tools are performing at their peak.

Skills

Required

  • Cyber Security investigations
  • SIEM technology (Elastic, Splunk)
  • System, cloud, application and network logs analysis
  • Network traffic analysis
  • PCAP analysis
  • Workstation or server logs analysis (multiple OS platforms)

Nice to have

  • Security Operations Center (SOC) experience
  • AWS architecture, services and APIs
  • Forensic analysis (Endpoint, Memory, Malware)
  • Evaluating and tuning alerts within a SIEM
  • Leveraging core security, cloud, and infrastructure technologies
  • Mac OS, Linux OS administration or investigation
  • CISSP, CISM, CCSP, Security+, CEH SANS GIAC 503/504/508/509, AWS Security certifications
  • Bachelor’s Degree in Information Technology, Cyber Security or Computer Science

What the JD emphasized

  • Significant previous experience conducting Cyber Security investigations
  • In-depth knowledge and extensive hands-on experience working with SIEM technology such as Elastic, Splunk or similar
  • Considerable evidence of working with system, cloud, application and network logs
  • Vast proven ability at analysing and identifying network traffic
  • Substantial working experience with PCAP analysis
  • Comprehensive experience analysing workstation or server logs across multiple operating system platforms