Senior Security Analyst (f/m/d)

Contentful Contentful · Enterprise · London, United Kingdom · Security

Senior Security Analyst role focused on incident response, threat detection, and contributing to the growth and design of the security program. Requires experience in alert investigation, incident management, and security principles within a hybrid and cloud-native environment.

What you'd actually do

  1. Perform daily alert investigation and response in a hybrid environment.
  2. Conduct detail-oriented analysis across challenging and complex ecosystems.
  3. Communicate investigation and threat updates to technical and non technical senior leaders.
  4. Work collaboratively across internal functions to identify, respond, and remediate security issues.
  5. Investigate and lead incidents of medium size and complexity.

Skills

Required

  • Security Operations experience
  • alert triage
  • investigation
  • detection and tuning
  • Security Incident Response
  • log analysis
  • live response
  • forensics
  • attacker Tactics, Techniques, and Procedures
  • cloud-native and traditional environments attacker techniques
  • OSI Model
  • TCP/IP
  • Layer 7 protocols
  • Mac, Windows, & Linux systems analysis
  • SIEM
  • EDR
  • AntiVirus
  • malware analysis
  • AWS audit and security services
  • SaaS platforms and identity systems investigation
  • cloud service providers investigation (AWS, GCP, Azure)
  • cross-platform and hybrid environment investigations
  • detection use cases
  • modern engineering and detection engineering practices

Nice to have

  • contributing directly to the growth of and design of a security program
  • leading technical workstreams in incidents
  • leading all aspects of medium scale incidents
  • creating and maintaining high quality threat detection
  • knowledge and understanding of common Information Security principles and frameworks
  • excellent communications skills
  • continuous desire to learn and grow
  • work independently
  • work as a part of a global dispersed team
  • partner with stakeholders
  • comprehensive risk mitigation
  • reducing impact to end users
  • Work collaboratively
  • identify, respond, and remediate security issues
  • investigate vulnerability exploitation
  • support remediation inline with vulnerability programs
  • actively assist in major response exercises
  • Drive continuous improvement
  • Create processes, documentation, and runbooks
  • Identify systemic issues
  • collaborate on approaches to address root causes
  • Collaborate on threat models
  • Identify and lead efforts to improve efficiency, response, detection, and preventative measures
  • Design and build detection logic across multiple platforms
  • Play an active role in scaling Operation practices
  • contributing to team roadmaps
  • Provide delightful and informative interactions with all end users
  • Proactively identify opportunities for user training and awareness programs
  • Provide insights and input on tool selection
  • Practical mindset to balance business needs with security requirements.
  • A drive for change through continuous improvement
  • Capable of working independently but possesses a collaborative mindset
  • Comfortable working with a geographically dispersed team.
  • Experience working independently and as part of a team
  • Ability to work in a fast-paced environment, often juggling multiple tasks, alerts, and incidents
  • Passion for solving complex security problems in innovative and scalable ways

What the JD emphasized

  • 5+ years of Security Operations experience
  • 2+ detection and tuning experience
  • 2+ years of Security Incident Response experience
  • Ability to support on call and occasional off-hours incident response efforts
  • Proficiency in analysis fundamentals
  • Mastery of investigation methods
  • Firm understanding of attacker Tactics, Techniques, and Procedures
  • Proficiency in attacker techniques in cloud-native and traditional environments.
  • Strong technology fundamentals
  • Ability to perform detailed host analysis on Mac, Windows, & Linux systems.
  • Hands-on experience using security technologies
  • Hands-on experience with malware analysis
  • Expertise in AWS audit and security services
  • Proficiency investigating incidents across SaaS platforms and identity systems
  • Experience performing investigations in cloud service providers
  • Practical experience with cross-platform and hybrid environment investigations
  • Ability to interpret designs and enumerate actionable detection use cases
  • Familiarity with modern engineering and detection engineering practices