This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Join Vodafone Business Security Enhanced and strengthen the cyber security of the UK's Critical National Infrastructure and public sector organisations. As a Cyber Onboarding Engineer you are key to the successful delivery of Cyber Services for both Vodafone and its customers. You are self-motivated with a strong interest in Cyber Security and can enhance detection content for our SOC Team, enabling them to provide high-quality monitoring of SIEM systems, managed firewall & IPS services and much more. This role offers full project lifecycle involvement ensuring you will develop an understanding of our customers, their risks and concerns and work collaboratively with them to create relevant SIEM content that supports agreed use-cases and threat models.
Job Responsibility:
Enhance detection content for our SOC Team
Ensure feeds into the SIEM are iteratively enhanced
Write custom IDS/IPS rules to improve detection capabilities
Assist with Vulnerability Scanning activities
Produce/Enhance/Refine Monthly Reports for internal and external audiences
Configure/Tune SIEM content, Managed Firewalls and IPS systems
Monitor Threat Intelligence – internal, open source and commercial feeds
Interact with other Cyber Defence, Security and Incident Response teams, within Vodafone, with customers and suppliers
Requirements:
Experience of SIEM content creation in a SOC environment
Ability to interpret logs and events and identify patterns of behaviour, indications of compromise
Knowledge of MITRE ATT&CK and other cyber frameworks
IT and Network Security – Windows, Linux, Firewalls, IPS, Security Appliances
Experience of programming or scripting (e.g Python,C,Java,Bash)
Educated to degree level or equivalent experience
Must be able to maintain DV security clearance
Nice to have:
Comfortable writing Regular Expressions (regex)
Knowledge of MITRE ATT&CK and previous experience mapping existing SIEM content to this framework