Senior Incident Detection Analyst

il y a 3 semaines


Mons, Belgique Vector Synergy Temps plein

**Location**:
Mons, Belgium

**Security Clearance**:
NATO Secret

**Reference No**:
SC2023/002718 / Mons

**Skills, knowledge, experience required**:

- At least two years of demonstrable experience in security monitoring and analysis of enterprise level cloud environments (AWS and/or Azure);
- Expertise in at least three of the following areas and a high level of experience in several of the other areas:

- Security monitoring and analysis using a variety of Security Event generating sources (e.g. Firewalls, IDS, Routers, EDR and AV);
- Cloud architectures and technologies (AWS and/or Azure);
- Managing security operations in public cloud services (AWS and/or Azure);
- Microsoft Sentinel;
- AWS cloud security tools;
- Splunk ES suite and Splunk Search Processing Language (SPL);
- Phantom SOAR playbook development;
- Security use case development aligned to the MITRE ATT&CK Framework;
**Desirable**:

- Experience in:

- Working with Full Packet Capture Systems e.g. Niksun, RSA/NetWitness;
- Working with Host Based Intrusion Detection systems (HIDS);
- Experience with Network Based Intrusion Detection Systems (NIDS) - e.g. FirePower, Palo Alto Network Threat Prevention;
- Knowledge and experience in analysis of various threat actor groups, attack patterns and tactics, techniques, and procedures (TTPs), in-depth analysis of threats across enterprise environments by combining security rules, content, policy and relevant datasets;
- Industry leading certification in the area of Cybersecurity, such as GCIA, GPCS, GCLD, GNFA, GCIH, CCSP, GSFE, GCFA, GCED, OSCP;
- A solid understanding of Information Security Practices relating to the Confidentiality, Integrity and Availability of information (CIA triad);
- Strong knowledge of malware families and network attack vectors;
- Ability to analyse attack vectors against a particular system to determine attack surface.

**Duties/role**:

- Providing:

- Detailed analysis of logs and network traffic with a focus on cloud infrastructure;
- Subject matter expertise in the area of cyber security monitoring and detection within cloud infrastructure environments;
- An average of 139 hours/month working on-site, embedded in the NCSC Ops Branch located in SHAPE, Casteau, Belgium;
- Accurate and complete deliverables in accordance with internal processes;
- Being responsible for:

- Managing and maintaining the organisation's cloud security operations, including monitoring for and responding to security incidents;
- Complying will all applicable local employment laws, in addition to following all SHAPE & NCIA on-boarding procedures. Delivery of the service cannot begin until these requirements are fulfilled;
- Triaging, analysing and responding to alerts originating from complex cloud infrastructure deployments and on-premise networks and security devices;
- Identifying security gaps in NATO cloud security infrastructure, in addition to developing and maintaining new and existing use cases, using on-premise SIEM solution (i.e., Splunk Enterprise Security);
- Developing:

- Processes for cloud security monitoring, including documentation of all use cases;
- Dashboards that can provide situational awareness related to the security of the organisation's cloud security infrastructure. Including service KPIs and incident response metrics;
- Reviewing current log collection state for NATO cloud environments, identify gaps and suggest improvements;
- Analysing threat intelligence pertinent to cloud environments to identify any new and developing security risks;
- Proposing and working towards automating repetitive tasks related to cloud security monitoring and detection;
- Being flexible and support your colleagues in securing NATO networks through ad hoc tasks;
- Ensuring that the organisation's cloud infrastructure and security practices comply with applicable laws, regulations, and industry standards;
- Developing new alerts, searches, reports and dashboards for security monitoring and detection specific to cloud environments;
- Triaging, analysing and responding to alerts. All critical alerts will be responded to within three hours;
- Taking the initiative to identify detection gaps, monitoring the latest threats and offering suggestions for new content to the management team. Where possible full coverage of the MITRE attack framework is required. In some cases, it may be necessary to leverage solutions provided within the cloud environment itself;
- Providing and maintaining full documentation for all cloud use cases, detailing the purpose of the use cases, how the logic functions and the actions that should be taken during an investigation;
- Responding to ad hoc tasks given by the service delivery manager and cell head;
- Proposing at least five security content optimisations and enhancements per week within cloud environment.

VECTOR SYNERGY sp. z o.o., ul. Marcelińska 90, 60-324 Poznań, NIP PL7811857270, REGON 301575740, KRS: 0000369575

Rejestr Przedsiębiorców KRS prowadzo



  • Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein

    **Senior Incident Detection Analyst - Cloud Security- Working Location:Mons, Belgium**- Security Clearance: NATO Secret**- Language:High proficiency level in English language**EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - 2+ years of demonstrable experience in security monitoring and analysis of enterprise level cloud environments (AWS...


  • Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **Cyber Security Incident Detection Analyst - **Working Location**:Mons, Belgium** - **Security Clearance**:NATO Secret / SC** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - **Expert level in 3+ of the following areas and a high level of experience in several of the other...


  • Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **Senior Incident Detection Analyst - Cloud Security - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - 2+ years of demonstrable experience in security monitoring and analysis of enterprise level cloud...


  • Mons, Wallonie, Belgique Enterpryze Consulting Ltd. Temps plein

    **Cyber Security Incident Detection Analyst- Working Location:Mons, Belgium**- Security Clearance:NATO Secret / SC**- Language:High proficiency level in English language**EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - **Expert level in 3+ of the following areas and a high level of experience in several of the other areas: ü **Security...


  • Mons, Wallonie, Belgique Spektrum Group Temps plein

    Spektrum have a wide range of exciting opportunities in several global locations.We are always looking to add great new talent to our team and look forward to hearing from you.Whom we are supportingThe NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to...


  • Mons, Belgique Spektrum Group Temps plein

    Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. **Whom we are supporting** The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT)...

  • Cyber Incident Responder

    il y a 4 jours


    Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **Working Location**:Mons, Belgium - **Security Clearance**:NATO Secret - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience**: - Excellent communications skills and reporting experience with capacity to communicate to different types of audience (senior executive, middle management,...

  • Cyber Incident Responder

    il y a 2 jours


    Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **Working Location**:Mons, Belgium - **Security Clearance**:NATO Secret - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience**: - Excellent communications skills and reporting experience with capacity to communicate to different types of audience (senior executive, middle management,...

  • Security Event Analyst

    Il y a 2 mois


    Mons, Belgique Uni Systems Temps plein

    At Uni Systems, we are working towards turning digital visions into reality. We are continuously growing and we are looking for a professionalSecurity Event Analyst to join our UniQue Mons team. In this role, you will have the opportunity to work closely with our customers in the public sector and you will be responsible for developing new business by...


  • Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **First Line Security Event Analyst (FLSEA) 6 - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of...


  • Mons, Belgique Vector Synergy Temps plein

    **Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: C001782 / Mons **Skills, knowledge, experience required**: - The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis; - Comprehensive knowledge of the principles of computer and communications security including...

  • Security Event Analyst

    il y a 6 jours


    Mons, Wallonie, Belgique Uni Systems Temps plein

    At Uni Systems, we are working towards turning digital visions into reality. We are continuously growing and we are looking for a professionalSecurity Event Analyst to join our UniQue Mons team.In this role, you will have the opportunity to work closely with our customers in the public sector and you will be responsible for developing new business by...


  • Mons, Belgique Park Lane Recruitment Temps plein

    Deadline Date: 03 May 2024 - Location: Mons, Belgium - Required Start Date: 16-JUN-2024 **Deadline Date**:03 May 2024 **Requirement Title**:First Line Security Event Analyst (FLSEA) 3** **Location**:Mons, Belgium **Full time on-site**: Yes **Not to Exceed**: 97 Euro **Total Scope of the request (hours)**:1370.5 **Required Start Date**:...


  • Mons, Belgique Vector Synergy Temps plein

    **Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: C003186 / Mons **Skills, knowledge, experience required**: - The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis; - Comprehensive knowledge of the principles of computer and communications security including...


  • Mons, Belgique Vector Synergy Temps plein

    **Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: C001886 / Mons **Skills, knowledge, experience required**: - The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis; - Comprehensive knowledge of the principles of computer and communications security including...


  • Mons, Belgique Vector Synergy Temps plein

    **Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: C003333 / Mons **Skills, knowledge, experience required**: - The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis; - Comprehensive knowledge of the principles of computer and communications security including...

  • Cyber Security Analyst 2

    il y a 3 semaines


    Mons, Belgique Vector Synergy Temps plein

    **Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: SC2023/002717 / Mons **Skills, knowledge, experience required**: - Experience in: - Security information and event management products (SIEM) - e.g. Splunk; - Analysis of network based intrusion detection systems (NIDS) events - e.g. FirePower, Palo Alto Network Threat...


  • Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **First Line Security Event Analyst (FLSEA) 1 - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of...


  • Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **First Line Security Event Analyst (FLSEA) 3 - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of...


  • Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **First Line Security Event Analyst (FLSEA) 4 - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Comprehensive knowledge of the principles of computer and communications security including knowledge of...