Cyber Security Incident Detection Analyst

il y a 4 jours


Mons, Belgique Enterpryze Consulting Ltd. Temps plein

**Cyber Security Incident Detection Analyst
- **Working Location**:Mons, Belgium**
- **Security Clearance**:NATO Secret / SC**
- **Language**:High proficiency level in English language

**EXPERIENCE AND EDUCATION:
**Essential Qualifications/Experience:
- **Expert level in 3+ of the following areas and a high level of experience in several of the other areas:
ü
**Security Incidents Event Management products (SIEM) - e.g. Splunk
ü
**Network Based Intrusion Detection Systems (NIDS) - e.g. SourceFire, Palo Alto Network Threat Prevention
ü
**Host Based Intrusion Detection Systems (HIDS)
ü
**Full Packet Capture systems - e.g. Niksun, RSA/NetWitness
ü
**A variety of Security Event generating sources (e.g. Firewalls, IDS, Routers, Security Appliances)
ü
**Computer incident response centre (CIRT), computer emergency response team (CERT)
ü
**Cloud-specific security tools
ü
**Splunk ES suite and Phantom SOAR
- **Proficiency in Intrusion/Incident Detection and Handling
- **Solid knowledge and experience in Splunk Enterprise Security suite. Exceptionally this requirement can be compensated with proven level of expertise in network analysis and threat hunting
- **High level of experience in 1+ of the areas:
ü
**Creation and maintenance of SIEM use cases
ü
**Development of automation capabilities via both SOAR tools and scripting languages
ü
**Advanced searching techniques using SFPL on Splunk Enterprise Security Suite
**Desirable Qualifications/Experience:
- Industry leading certification in the area of Cybersecurity, such as GCIA, GNFA, GCIH
- A good understanding of Security, Orchestrations, Automation and Response (SOAR) concepts and their benefits to the protection of CIS infrastructures
- A solid understanding of Information Security Practices relating to the Confidentiality, Integrity and Availability of information (CIA triad)
- Solid knowledge and experience in threat hunting in corporate/government level environment
- Strong knowledge of malware families and network attack vectors
- Knowledge and experience in analysis of various threat actor groups, attack patterns and tactics, techniques, and procedures (TTPs), deep analysis of threats across the enterprise by combining security rules, content, policy and relevant datasets
- Ability to analyse attack vectors against a particular system to determine attack surface
- Ability to produce contextual attack models applied to a scenario
- Hands on experience on monitoring cloud services

**DUTIES/ROLE
- Provide detailed analysis of logs and network traffic
- Determine the severity of security alerts through investigative analysis
- Conduct detailed investigation and research of security events within NATO Cyber Security Centre (NCSC) team
- Analyse firewall, IDS, anti-virus and other sensor-produced system security events and present findings
- Provide detailed technical reports in support of incidents and capability improvements
- Share security event/incident information with stakeholders via presentations and technical reports
- Appropriately leverage the comprehensive extended toolset (e.g. Log Collection, Intrusion Detection, Packet Capture, VA, Network Devices etc) to identify malicious activity. Be able to recommend improvements to enable enhancing investigations
- Propose possible optimisations and enhancements which help to maintain and improve NATO's Cyber Security posture
- Implement and support threat hunting activities; create hunting hypothesis and technical reports when requested
- Analyse intelligence information gathered from internal and external threat intelligence resources
- Identify security gaps in NATO infrastructure and develop custom content utilising available toolset
- Provide expert investigative support of large scale and complex security incidents
- Develop and maintain SOAR playbooks
- Develop and maintain SIEM use cases, their documentation and training guides
- Support and implement day to day SOC management activities as requested
- Produce Standard Operating Procedures covering all aspects of monitoring and detection activities
- Support project activities in their area of responsibility when requested
- Perform other duties as requested by management
- Normal office conditions in a secure environment with standard working hours, with the exception of working in non-standard working hours up to 360 hours annually. In addition it may exceptionally be required to work non-standard hours in support of a major Cyber Incident, or on a shift system for a limited period of time due to urgent operational needs



  • Mons, Belgique Systems Planning and Analysis, Inc. Temps plein

    Overview: - MCR, an SPA company, is a fast-growing global company headquartered in Northern Virginia that supports defense and civilian agencies, NATO, and European ministries that face some of the most complex mission challenges in the world. If you are the best at what you do, we are looking for you. At MCR/SPA, you will contribute to programs and...


  • Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Recent practical, hands-on experience of Intrusion Detection and Incident Response (TRIAGE, Contain, Eradicate, Recover) in an enterprise-level Computer...


  • Mons, Belgique Vector Synergy Temps plein

    **Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: SC2022/002065/5 / Mons **Skills, knowledge, experience required**: - At least 3 years’ experience in Information and Knowledge Management, ideally in the field of Cyber Security; - Experience in interfacing with IT Service Management (ITSM); - Recent practical, hands-on...

  • Cyber Incident Responder

    Il y a 2 mois


    Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **Working Location**:Mons, Belgium** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Recent practical, hands-on experience of Intrusion Detection and Incident Response (TRIAGE, Contain, Eradicate, Recover) in an enterprise-level Computer Emergency Response Team, ideally making...

  • Cyber Incident Responder

    Il y a 7 mois


    Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **Working Location**:Mons, Belgium - **Security Clearance**:NATO Secret - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience**: - Excellent communications skills and reporting experience with capacity to communicate to different types of audience (senior executive, middle management,...

  • Cyber Incident Responder

    Il y a 7 mois


    Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **Working Location**:Mons, Belgium - **Security Clearance**:NATO Secret - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience**: - Excellent communications skills and reporting experience with capacity to communicate to different types of audience (senior executive, middle management,...


  • Mons, Belgique Spektrum Temps plein

    Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. **Who we are supporting** The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT)...

  • Cyber Incident Responder

    Il y a 7 mois


    Mons, Belgique Vector Synergy Temps plein

    **Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: C003641 / Mons **Skills, knowledge, experience required**: - Recent practical, hands-on experience of Intrusion Detection and Incident Response (TRIAGE, Contain, Eradicate, Recover) in an enterprise-level Computer Emergency Response Team, ideally making use of the MITRE...

  • Security Event Analyst

    Il y a 7 mois


    Mons, Belgique Uni Systems Temps plein

    At Uni Systems, we are working towards turning digital visions into reality. We are continuously growing and we are looking for a professionalSecurity Event Analyst to join our UniQue Mons team. In this role, you will have the opportunity to work closely with our customers in the public sector and you will be responsible for developing new business by...


  • Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **Cyber Security Incident Investigator - **Working Location**:Mons, Belgium - **Security Clearance**:NATO Secret / SC - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - 8+ years of demonstrable experience in handing complex Cyber Security Incidents, ideally in an international,...


  • Mons, Belgique Vector Synergy Temps plein

    **Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: SC2022/002064 / Mons **Skills, knowledge, experience required**: - At least 8 years’ demonstrable experience in handing complex cyber security incidents, ideally in an international, governmental or military environment; - Certification in: - Cyber security incident...


  • Mons, Belgique Systems Planning and Analysis, Inc. Temps plein

    Overview: Systems Planning and Analysis, Inc. (SPA) is a well-established and progressive defense contracting company in the Northern Virginia area just a few miles south of the Pentagon. We are a professional services firm established in 1972 that has a long-standing reputation for unrivaled technical and analytical support to some of the top decision...


  • Mons, Belgique Systems Planning and Analysis, Inc. Temps plein

    Overview: Systems Planning and Analysis, Inc. (SPA) is a well-established and progressive defense contracting company in the Northern Virginia area just a few miles south of the Pentagon. We are a professional services firm established in 1972 that has a long-standing reputation for unrivaled technical and analytical support to some of the top decision...


  • Mons, Belgique Systems Planning and Analysis, Inc. Temps plein

    Overview: Systems Planning and Analysis, Inc. (SPA) is a well-established and progressive defense contracting company in the Northern Virginia area just a few miles south of the Pentagon. We are a professional services firm established in 1972 that has a long-standing reputation for unrivaled technical and analytical support to some of the top decision...

  • Cyber Incident Responder

    Il y a 7 mois


    Mons, Belgique Spektrum Temps plein

    Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. **Who we are supporting** The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT)...


  • Mons, Belgique Systems Planning and Analysis, Inc. Temps plein

    Overview: MCR, an SPA company, is a fast-growing global company headquartered in Northern Virginia that supports defense and civilian agencies, NATO, and European ministries that face some of the most complex mission challenges in the world. If you are the best at what you do, we are looking for you. At MCR/SPA, you will contribute to programs and projects...


  • Mons, Belgique Vector Synergy Temps plein

    **Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: C001782 / Mons **Skills, knowledge, experience required**: - The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis; - Comprehensive knowledge of the principles of computer and communications security including...


  • Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **First Line Security Event Analyst (FLSEA) 6 - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of...


  • Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **Cyber Security Incident Investigator 2 - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - A professional certification on Cyber Security Incident Handling - A professional certification on IT Service...


  • Mons, Belgique Vector Synergy Temps plein

    **Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: C003333 / Mons **Skills, knowledge, experience required**: - The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis; - Comprehensive knowledge of the principles of computer and communications security including...