Senior Incident Detection Analyst
il y a 4 heures
**Senior Incident Detection Analyst - Cloud Security
- **Working Location**:Mons, Belgium**
- **Security Clearance**: NATO Secret**
- **Language**:High proficiency level in English language
**EXPERIENCE AND EDUCATION:
**Essential Qualifications/Experience:
- 2+ years of demonstrable experience in security monitoring and analysis of enterprise level cloud environments (AWS and/or Azure)
- Expertise in at least three of the following areas and a high level of experience in several of the other areas:
ü Security monitoring and analysis using a variety of Security Event generating sources (e.g. Firewalls, IDS, Routers, EDR and AV)
ü Cloud architectures and technologies (AWS and/or Azure)
ü Managing security operations in public cloud services (AWS and/or Azure)
ü Microsoft Sentinel
ü AWS cloud security tools
ü Splunk ES suite and Splunk Search Processing Language (SPL)
ü Phantom SOAR playbook development
ü Security use case development aligned to the MITRE ATT&CK Framework
**Desirable Qualifications/Experience**:
- Industry leading certification in the area of Cybersecurity, such as GCIA, GPCS, GCLD, GNFA, GCIH, CCSP, GSFE, GCFA, GCED, OSCP
- A solid understanding of Information Security Practices relating to the Confidentiality, Integrity and Availability of information (CIA triad)
- Experience working with Full Packet Capture Systems e.g. Niksun, RSA/NetWitness
- Experience working with Host Based Intrusion Detection systems (HIDS)
- Experience with Network Based Intrusion Detection Systems (NIDS) - e.g. FirePower, Palo Alto Network Threat Prevention
- Strong knowledge of malware families and network attack vectors
- Knowledge and experience in analysis of various threat actor groups, attack patterns and tactics, techniques, and procedures (TTPs), in-depth analysis of threats across enterprise environments by combining security rules, content, policy and relevant datasets
- Ability to analyse attack vectors against a particular system to determine attack surface
**DUTIES/ROLE**:
- Triage, analyse and respond to alerts originating from complex cloud infrastructure deployments and on-premise networks and security devices
- Identify security gaps in NATO cloud security infrastructure, in addition to developing and maintaining new and existing use cases, - using our on-premise SIEM solution (i.e., Splunk Enterprise Security)
- Develop processes for cloud security monitoring, including documentation of all use cases
- Review current log collection state for NATO cloud environments, identify gaps and suggest improvements
- Analyse threat intelligence pertinent to cloud environments to identify any new and developing security risks
- Propose and work towards automating repetitive tasks related to cloud security monitoring and detection
- Be flexible and support your colleagues in securing NATO networks through ad hoc tasks
- Ensure that the organisation's cloud infrastructure and security practices comply with applicable laws, regulations, and industry standards
- Provide an average of 139 hours/month working on-site, embedded in the NCSC Ops Branch located in SHAPE, Casteau, Belgium
- Develop new alerts, searches, reports and dashboards for security monitoring and detection specific to cloud environments. Each use case must reference the MITRE attack framework
- Triage, analyse and respond to alerts. All critical alerts will be responded to within three hours
- The service provider is expected to take the initiative to identify detection gaps, monitor the latest threats and offer suggestions for new content to the management team. Where possible full coverage of the MITRE attack framework is required. In some cases, it may be necessary to leverage solutions provided within the cloud environment itself
- Provide and maintain full documentation for all cloud use cases, detailing the purpose of the use cases, how the logic functions and the actions that should be taken during an investigation
- Develop dashboards that can provide situational awareness related to the security of the organisation's cloud security infrastructure. Including service KPIs and incident response metrics
- Respond to ad hoc tasks given by the service delivery manager and cell head
- Propose at least five security content optimisations and enhancements per week within cloud environment
- The service provider is expected to provide accurate and complete deliverables in accordance with internal processes
- The service provider shall be responsible for complying will all applicable local employment laws, in addition to following all SHAPE & NCIA on-boarding procedures. Delivery of the service cannot begin until these requirements are fulfilled
- Each provider of this service must pass an assessment to demonstrate proficiency before being approved to provide the service. The assessment will follow a brief familiarisation period
- For each individual delivering the service, the provider shall allocate 10 working days to the init
-
Cyber Security Incident Detection Analyst
il y a 5 jours
Mons, Belgique Enterpryze Consulting Ltd. Temps plein**Cyber Security Incident Detection Analyst - **Working Location**:Mons, Belgium** - **Security Clearance**:NATO Secret / SC** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - **Expert level in 3+ of the following areas and a high level of experience in several of the other...
-
Cyber Security Incident Detection Analyst
il y a 2 semaines
Mons, Belgique Systems Planning and Analysis, Inc. Temps pleinOverview: - MCR, an SPA company, is a fast-growing global company headquartered in Northern Virginia that supports defense and civilian agencies, NATO, and European ministries that face some of the most complex mission challenges in the world. If you are the best at what you do, we are looking for you. At MCR/SPA, you will contribute to programs and...
-
Cyber Incident Responder
Il y a 7 mois
Mons, Belgique Enterpryze Consulting Ltd. Temps plein**Working Location**:Mons, Belgium - **Security Clearance**:NATO Secret - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience**: - Excellent communications skills and reporting experience with capacity to communicate to different types of audience (senior executive, middle management,...
-
Cyber Incident Responder
Il y a 7 mois
Mons, Belgique Enterpryze Consulting Ltd. Temps plein**Working Location**:Mons, Belgium - **Security Clearance**:NATO Secret - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience**: - Excellent communications skills and reporting experience with capacity to communicate to different types of audience (senior executive, middle management,...
-
Security Event Analyst
Il y a 7 mois
Mons, Belgique Uni Systems Temps pleinAt Uni Systems, we are working towards turning digital visions into reality. We are continuously growing and we are looking for a professionalSecurity Event Analyst to join our UniQue Mons team. In this role, you will have the opportunity to work closely with our customers in the public sector and you will be responsible for developing new business by...
-
Cyber Security Incident Responder
Il y a 7 mois
Mons, Belgique Vector Synergy Temps plein**Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: SC2022/002065/5 / Mons **Skills, knowledge, experience required**: - At least 3 years’ experience in Information and Knowledge Management, ideally in the field of Cyber Security; - Experience in interfacing with IT Service Management (ITSM); - Recent practical, hands-on...
-
First Line Security Event Analyst
Il y a 7 mois
Mons, Belgique Enterpryze Consulting Ltd. Temps plein**First Line Security Event Analyst (FLSEA) 6 - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of...
-
First Line Security Event Analyst
Il y a 7 mois
Mons, Belgique Vector Synergy Temps plein**Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: C001782 / Mons **Skills, knowledge, experience required**: - The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis; - Comprehensive knowledge of the principles of computer and communications security including...
-
First Line Security Event Analyst
Il y a 7 mois
Mons, Belgique Vector Synergy Temps plein**Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: C003333 / Mons **Skills, knowledge, experience required**: - The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis; - Comprehensive knowledge of the principles of computer and communications security including...
-
First Line Security Event Analyst
Il y a 7 mois
Mons, Belgique Enterpryze Consulting Ltd. Temps plein**First Line Security Event Analyst (FLSEA) 3 - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of...
-
First Line Security Event Analyst
Il y a 7 mois
Mons, Belgique Enterpryze Consulting Ltd. Temps plein**First Line Security Event Analyst (FLSEA) 1 - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of...
-
First Line Security Event Analyst
il y a 2 semaines
Mons, Belgique Vector Synergy Temps plein**Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: C000339 / Mons **Skills, knowledge, experience required**: - The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis; - Comprehensive knowledge of the principles of computer and communications security including...
-
Cyber Incident Responder
Il y a 2 mois
Mons, Belgique Enterpryze Consulting Ltd. Temps plein**Working Location**:Mons, Belgium** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Recent practical, hands-on experience of Intrusion Detection and Incident Response (TRIAGE, Contain, Eradicate, Recover) in an enterprise-level Computer Emergency Response Team, ideally making...
-
Cyber Security Analyst 1
il y a 4 heures
Mons, Belgique Enterpryze Consulting Ltd. Temps plein**Cyber Security Analyst 1 - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of TCP/IP networking,...
-
First Line Security Event Analyst
Il y a 7 mois
Mons, Belgique Enterpryze Consulting Ltd. Temps plein**First Line Security Event Analyst (FLSEA) 1 **Working Location**:Mons, Belgium - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of TCP/IP...
-
First Line Security Event Analyst
Il y a 7 mois
Mons, Belgique Enterpryze Consulting Ltd. Temps plein**First Line Security Event Analyst (FLSEA) 6 - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of...
-
Threat Hunting Analyst
il y a 1 semaine
Mons, Belgique Systems Planning and Analysis, Inc. Temps pleinOverview: Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and...
-
First Line Security Event Analyst
il y a 2 semaines
Mons, Belgique Enterpryze Consulting Ltd. Temps plein**First Line Security Event Analyst (FLSEA) - **Working Location**:Mons, Belgium - **Security Clearance**:NATO Secret / SC - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience**: - Comprehensive knowledge of the principles of computer and communications security including knowledge of...
-
Cyber Incident Responder
Il y a 7 mois
Mons, Belgique Spektrum Temps pleinSpektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. **Who we are supporting** The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT)...
-
Cyber Security Incident Responder
Il y a 7 mois
Mons, Belgique Enterpryze Consulting Ltd. Temps plein**Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Recent practical, hands-on experience of Intrusion Detection and Incident Response (TRIAGE, Contain, Eradicate, Recover) in an enterprise-level Computer...