SECURITY ENGINEER - Hybrid - Contract
North West
Web application experience and knowledge of tools an advantage as is being able to understand logs and python for automation. As always monitoring and response experience will help but the right investigation mindset is most important, the ability to learn quickly and being a good team fit/team player.
Resource will function as a member of an enterprise network application layer intrusion, detection, prevention, and response team. Will develop and implement custom alerts and monitoring controls to detect and mitigate threats. Provides leadership in assessing new threat vectors and designing and implementing effective controls. Leverages advanced investigative skills using best in class data correlation and log analysis tools. Will partner with senior leaders from lines of business organizations to triage security events and report on impacting security initiatives. Develops and implements processes or controls in support of audit and risk requirements.
Required Skills
- Strong Intrusion Analysis background. Resource must be able to identify and interpret web an application logs from a security perspective.
- Strong Splunk skill set. The security analyst will leverage Splunk to analyse logs and other security events including creating macros, alerts, and dashboards to find targeted attacks against network based bank assets.
- Knowledgeable of current exploits. Resource must be able to identify common exploits from the appropriate web and event logs.
- Working knowledge of Linux, Windows, and MacOS operating systems.
- Comfortable with Scripting languages and regular expressions.
- Strong knowledge common network protocols.
- Working knowledge of enterprise Client Server architecture.
We are a front line team that handles active security events and current threats. On-call and after hours work can be expected although we rotate to approximately one week every 2 months.
The analyst will use new intelligence to update existing controls to detect new threats against the bank. Will be expected to have solid technical skills to operate independently and to support others within the security team.
Desired Skills
- Able to interpret Apache web logs, IIS, Active Directory and other security logs.
- Full understanding of modern web site deployments and technology.
- Familiarity with web application attacks including SQL injection, cross-site Scripting, and remote file inclusion.
- Understanding of stateful Firewalls and able to interpret Firewall rules.
- Use tools to detect anomalous/malicious data transmissions on the network.
- Use advanced analytics/security tools to detect anomalous events on the network.
Job Title: It Security Engineer
Location: Chester, UK
Job Type: Contract