Senior Incident Detection Analyst

il y a 1 semaine


Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein
**Senior Incident Detection Analyst - Cloud Security

-
Working Location:Mons, Belgium**-
Security Clearance: NATO Secret**-
Language:High proficiency level in English language

**EXPERIENCE AND EDUCATION:
**Essential Qualifications/Experience: - 2+ years of demonstrable experience in security monitoring and analysis of enterprise level cloud environments (AWS and/or Azure)

  • Expertise in at least three of the following areas and a high level of experience in several of the other areas:
ü Security monitoring and analysis using a variety of Security Event generating sources (e.g. Firewalls, IDS, Routers, EDR and AV)

ü Cloud architectures and technologies (AWS and/or Azure)

ü Managing security operations in public cloud services (AWS and/or Azure)

ü Microsoft Sentinel

ü AWS cloud security tools

ü Splunk ES suite and Splunk Search Processing Language (SPL)

ü Phantom SOAR playbook development

ü Security use case development aligned to the MITRE ATT&CK Framework

Desirable Qualifications/Experience:

  • Industry leading certification in the area of Cybersecurity, such as GCIA, GPCS, GCLD, GNFA, GCIH, CCSP, GSFE, GCFA, GCED, OSCP
  • A solid understanding of Information Security Practices relating to the Confidentiality, Integrity and Availability of information (CIA triad)
  • Experience working with Full Packet Capture Systems e.g. Niksun, RSA/NetWitness
  • Experience working with Host Based Intrusion Detection systems (HIDS)
  • Experience with Network Based Intrusion Detection Systems (NIDS) e.g. FirePower, Palo Alto Network Threat Prevention
  • Strong knowledge of malware families and network attack vectors
  • Knowledge and experience in analysis of various threat actor groups, attack patterns and tactics, techniques, and procedures (TTPs), indepth analysis of threats across enterprise environments by combining security rules, content, policy and relevant datasets
  • Ability to analyse attack vectors against a particular system to determine attack surface

DUTIES/ROLE:

  • Triage, analyse and respond to alerts originating from complex cloud infrastructure deployments and onpremise networks and security devices
  • Identify security gaps in NATO cloud security infrastructure, in addition to developing and maintaining new and existing use cases, using our onpremise SIEM solution (i.e., Splunk Enterprise Security)
  • Develop processes for cloud security monitoring, including documentation of all use cases
  • Review current log collection state for NATO cloud environments, identify gaps and suggest improvements
  • Analyse threat intelligence pertinent to cloud environments to identify any new and developing security risks
  • Propose and work towards automating repetitive tasks related to cloud security monitoring and detection
  • Be flexible and support your colleagues in securing NATO networks through ad hoc tasks
  • Ensure that the organisation's cloud infrastructure and security practices comply with applicable laws, regulations, and industry standards
  • Provide an average of 139 hours/month working onsite, embedded in the NCSC Ops Branch located in SHAPE, Casteau, Belgium
  • Develop new alerts, searches, reports and dashboards for security monitoring and detection specific to cloud environments. Each use case must reference the MITRE attack framework
  • Triage, analyse and respond to alerts. All critical alerts will be responded to within three hours
  • The service provider is expected to take the initiative to identify detection gaps, monitor the latest threats and offer suggestions for new content to the management team. Where possible full coverage of the MITRE attack framework is required. In some cases, it may be necessary to leverage solutions provided within the cloud environment itself
  • Provide and maintain full documentation for all cloud use cases, detailing the purpose of the use cases, how the logic functions and the actions that should be taken during an investigation
  • Develop dashboards that can provide situational awareness related to the security of the organisation's cloud security infrastructure. Including service KPIs and incident response metrics
  • Respond to ad hoc tasks given by the service delivery manager and cell head
  • Propose at least five security content optimisations and enhancements per week within cloud environment
  • The service provider is expected to provide accurate and complete deliverables in accordance with internal processes
  • The service provider shall be responsible for complying will all applicable local employment laws, in addition to following all SHAPE & NCIA onboarding procedures. Delivery of the service cannot begin until these requirements are fulfilled
  • Each provider of this service must pass an assessment to demonstrate proficiency before being approved to provide the service. The assessment will follow a brief familiarisation period
  • For each individual delivering the service, the provider shall allocate 10 working days to the init


  • Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein

    **Cyber Security Incident Detection Analyst- Working Location:Mons, Belgium**- Security Clearance:NATO Secret / SC**- Language:High proficiency level in English language**EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - **Expert level in 3+ of the following areas and a high level of experience in several of the other areas: ü **Security...


  • Mons, Wallonie, Belgique Spektrum Group Temps plein

    Spektrum have a wide range of exciting opportunities in several global locations.We are always looking to add great new talent to our team and look forward to hearing from you.Whom we are supportingThe NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to...

  • Security Event Analyst

    il y a 1 semaine


    Mons, Wallonie, Belgique Uni Systems Temps plein

    At Uni Systems, we are working towards turning digital visions into reality. We are continuously growing and we are looking for a professionalSecurity Event Analyst to join our UniQue Mons team.In this role, you will have the opportunity to work closely with our customers in the public sector and you will be responsible for developing new business by...


  • Mons, Wallonie, Belgique Vector Synergy Temps plein

    Location:Mons, BelgiumSecurity Clearance:NATO SecretReference No:C003259 / MonsSkills, knowledge, experience required: The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis; Comprehensive knowledge of the principles of computer and communications security including knowledge of Transmission...


  • Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein

    **First Line Security Event Analyst (FLSEA) 3- Working Location:Mons, Belgium**- Security Clearance: NATO Secret**- Language:High proficiency level in English language**EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of TCP/IP networking,...


  • Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein

    **First Line Security Event Analyst (FLSEA) 4- Working Location:Mons, Belgium**- Security Clearance: NATO Secret**- Language:High proficiency level in English language**EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of TCP/IP networking,...


  • Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein

    **First Line Security Event Analyst (FLSEA) 2- Working Location:Mons, Belgium**- Security Clearance: NATO Secret**- Language:High proficiency level in English language**EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of TCP/IP networking,...


  • Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein

    **First Line Security Event Analyst (FLSEA) 6- Working Location:Mons, Belgium**- Security Clearance: NATO Secret**- Language:High proficiency level in English language**EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of TCP/IP networking,...


  • Mons, Wallonie, Belgique Vector Synergy Temps plein

    Location:Mons, BelgiumSecurity Clearance:NATO SecretReference No:C001886 / MonsSkills, knowledge, experience required: The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis; Comprehensive knowledge of the principles of computer and communications security including knowledge of Transmission...


  • Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein

    **First Line Security Event Analyst (FLSEA) 1Working Location:Mons, Belgium- Security Clearance: NATO Secret**- Language:High proficiency level in English language**EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of TCP/IP networking,...


  • Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein

    Working Location:Mons, Belgium**- Security Clearance: NATO Secret**- Language:High proficiency level in English language**EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Recent practical, hands-on experience of Intrusion Detection and Incident Response (TRIAGE, Contain, Eradicate, Recover) in an enterprise-level Computer Emergency Response...

  • Cyber Security Analyst 1

    il y a 1 semaine


    Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein

    **Cyber Security Analyst 1- Working Location:Mons, Belgium**- Security Clearance: NATO Secret**- Language:High proficiency level in English language**EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of TCP/IP networking, Windows and Linux...


  • Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein

    **Second Line Security Event Analyst (SLSEA)- Working Location:Mons, Belgium**- Security Clearance: NATO Secret**- Language:High proficiency level in English language**EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Expert level in at least three of the following areas and a high level of experience in several of the other areas:ü...


  • Mons, Wallonie, Belgique Spektrum Temps plein

    Spektrum have a wide range of exciting opportunities in several global locations.We are always looking to add great new talent to our team and look forward to hearing from you.Who we are supportingThe NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to...


  • Mons, Wallonie, Belgique Vector Synergy Temps plein

    Location:Mons, BelgiumSecurity Clearance:NATO SecretReference No:C000244 / MonsIntroduction:As a First Line Security Event Analyst (FLSEA), the incumbent will perform initial analysis of logs and network traffic, determine alert severity and escalate when required. The analyst will collate information and present findings in a clear, structured format,...


  • Mons, Wallonie, Belgique Business Integra Inc Temps plein

    Required Security Clearance: NATO SECRETSpecific Working Conditions:Normal Office Conditions. Secure environment with standard working hours, with the exception of working in non-standard working hours up to 360 hours annually. In addition it may exceptionally be required to work non-standard hours in support of a major Cyber Incident, or on a shift system...

  • Threat Hunting Analyst

    il y a 1 semaine


    Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein

    **Threat Hunting Analyst- Working Location:Mons, Belgium**- Security Clearance: NATO Secret**- Language:High proficiency level in English language**EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Experience in analysis of threat actor group attack patterns, tactics, techniques, and procedures (TTPs). Knowledge of the TaHiTI threat hunting...


  • Mons, Wallonie, Belgique Spektrum Group Temps plein

    Spektrum have a wide range of exciting opportunities in several global locations.We are always looking to add great new talent to our team and look forward to hearing from you.Spektrum have a wide range of exciting opportunities in several global locations.We are always looking to add great new talent to our team and look forward to hearing from you.Specific...


  • Mons, Wallonie, Belgique Spektrum Group Temps plein

    Spektrum have a wide range of exciting opportunities in several global locations.We are always looking to add great new talent to our team and look forward to hearing from you.Whom we are supportingThe NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to...


  • Mons, Wallonie, Belgique Vector Synergy Temps plein

    Location:Mons, BelgiumSecurity Clearance:NATO SecretReference No:C002337 / MonsSkills, knowledge, experience required: OR experience that is/are of interest to NCIA; that is, at least 7 years extensive and progressive expertise in the duties related to the function of the post; Expert level in at least three of the following areas and a high level of...