This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Join us as a DFIR Lead Cyber Operations Analyst, at Barclays, we don't just adapt to the future, we create it. As a Lead Cyber Operations Analyst you will support the organisation, achieve its strategic objectives by the identification of business requirements and solutions that address business problems and opportunities.
Job Responsibility
Support the organisation achieve its strategic objectives by the identification of business requirements and solutions that address business problems and opportunities
Management of security monitoring systems, including intrusive prevention and detection systems, to alert, detect and block potential cyber security incidents, and provide a prompt response to restore normal operations with minimised system damage
Identification of emerging cyber security threats, attack techniques and technologies to detect/prevent incidents, and collaborate with networks and conferences to gain industry knowledge and expertise
Management and analysis of security information and event management systems to collect, correlate and analyse security logs, events and alerts/potential threats
Triage of data loss prevention alerts to identify and prevent sensitive data for being exfiltrated from the banks network
Management of cyber security incidents including remediation & driving to closure
Requirements
Forensic techniques applied to incident response: practical experience applying forensic techniques across common enterprise data sources (files, operating systems, network traffic, and applications) to support incident investigation and troubleshooting
Expert log and artefact analysis (multi‑source): ability to collect, examine, and analyse data from multiple sources (e.g., logs, artefacts, indicators of compromise) and perform pivoted analysis across aggregated logs and digital forensic data to define and contextualise incident scope
Advanced incident investigation and response capability: proven ability to analyse and respond to high‑priority security incidents, including timely escalation and driving incidents to closure
Technical depth across OS and networking: strong working knowledge of operating system fundamentals and security concepts, plus networking principles sufficient to interpret incident artefacts and investigative hypotheses
Coaching / guidance of junior analysts: capability to provide guidance and support to T1/T2 analysts on escalated events requiring subject matter expertise
Nice to have
Security control breadth: familiarity with security tools and controls that generate incident telemetry (e.g., network and endpoint security controls) and the ability to interpret artefacts generated by those controls during investigations
Development of work instructions / repeatable methods: experience contributing to, reviewing, or improving work instructions to ensure repeatable, auditable incident handling activities
Cloud security principles (AWS/Azure/GCP): understanding of cloud security principles and the ability to incorporate relevant cloud artefacts/logs into incident investigations where applicable
Open‑source investigation tooling / OSINT awareness: familiarity with open‑source network analysis and intelligence tools to support enrichment and investigative context
Intelligence‑driven defence / kill‑chain awareness: understanding of adversary behaviour and intelligence‑driven defence concepts to support hypothesis‑driven investigation and prioritisation