Job Description
About the Role
Join a global Cyber Defense team as a Cybersecurity Specialist, supporting the Security Operations Center (SOC) in protecting enterprise systems, users, and data from cyber threats.
This is a hands-on cybersecurity role focused on security alert investigation, incident response, threat analysis, and proactive threat hunting. You will work with security technologies such as CrowdStrike, Microsoft Defender, and SIEM platforms, while collaborating with global IT and cybersecurity teams to strengthen overall security operations.
Key Responsibilities:
-
Investigate, validate, and respond to cybersecurity alerts and incidents across the enterprise environment.
-
Analyse security events using endpoint telemetry, SIEM logs, threat intelligence, and security monitoring tools.
-
Perform incident investigation and root cause analysis to determine the impact and scope of security incidents.
-
Execute containment and remediation activities in line with established incident response procedures.
-
Conduct threat analysis and support threat hunting and proactive security investigations.
-
Work with tools such as CrowdStrike Falcon, Microsoft Defender, and SIEM platforms to identify and investigate suspicious activities.
-
Escalate complex or high-impact incidents to senior analysts and specialised response teams when required.
-
Document incident findings, actions taken, lessons learned, and recommendations.
-
Collaborate with global SOC, IT, and cybersecurity teams to improve the organisation's overall security posture.
-
Support the development, testing, and continuous improvement of incident response playbooks and procedures.
-
Stay updated on emerging cyber threats, attack techniques, and security technologies.
-
Identify opportunities to improve security detection and incident response capabilities.
-
Participate in post-incident reviews and contribute to measures that help prevent future security incidents.
Key Requirements:
-
Bachelor's Degree in Computer Science, Cybersecurity, Information Security, or a related field.
-
1–3 years of experience in SOC, Security Operations, Incident Response, IT Security, or a related cybersecurity role. Equivalent practical experience will also be considered.
-
Hands-on experience investigating security alerts and incidents within an enterprise environment.
-
Good understanding of security monitoring, alert triage, and incident investigation methodologies.
-
Familiarity with cybersecurity frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
-
Basic knowledge of security frameworks and standards such as NIST, ISO 27001, and CIS Controls.
-
Good understanding of Windows, Active Directory, and networking fundamentals.
-
Experience with security tools such as CrowdStrike, Microsoft Defender, SIEM platforms, or similar technologies.
-
Ability to analyse logs, endpoint telemetry, and security events to assess the impact and scope of incidents.
-
Strong analytical, problem-solving, communication, and collaboration skills.
-
Comfortable working independently as well as with international cybersecurity and IT teams.
-
CrowdStrike certifications such as CCFA, CCFR, or CCFH would be an advantage.