This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Working with the Security Operations Lead, in this role you will operate our security operations capability so that it provides an appropriate monitoring, detection, investigation and response capability. Using a range of tools, working with your security engineering colleagues, you will be part of a team building a SOC service that supports our client and internal services.
Job Responsibility:
Incident triage, analysis, response and investigations based on alerts
Monitoring and responding to endpoint detection and response
Investigating detected, suspicious behaviours and escalating as appropriate
Proactively investigating alerts and suspicious activities, following through to gain a full understanding of the behaviour
Adding context to a confirmed incident to aid understanding and response
Supporting the development of incident handling procedures
Supporting incident/crisis management
Identifying, documenting and developing detections
Building and developing incident playbooks
Creating reports and visualisations of attacks
Tracking trends for metrics and reporting
Briefing the CISO on alert findings and their impact on the business
Continuously working to decrease false positives
Maintaining the detection rules database
Requirements:
Minimum of 5 years experience or knowledge in security operations or related roles
Enjoy the challenge of delivering security into business operations
Work independently to perform analyses and investigations
Experience or knowledge of working in modern cloud environments, such as AWS, GCP or Azure
Experience using Security Information Event Management (SIEM) and related technologies
Experience using Endpoint Detection & Response (EDR) and related technologies
Strong analytical and investigation skills
Proficient in several programming languages, including Python, and/or PHP
Excellent written and verbal communication skills as well as receptive listening skills, with ability to present complex ideas in a clear, concise fashion to technical and non-technical audiences
Proactively contribute ideas to the development of security at Neo4j
Awareness of hacking techniques and trends and investigation or awareness of Cyber Threat Intelligence in a business context
Nice to have:
A software development background is desirable
Appropriate certifications or relevant experience in SOC operations