Cyber Defence Analyst
Full-time Not ApplicableJob Overview
As a Cyber Defence Analyst, you will join the Cyber Fusion Center, performing in-depth analysis, assessment, and response to security threats by following documented policies to meet Service Level Goals. The team provides global 24x7 security operations and monitoring for cybersecurity events affecting Experian.
You will be a part of the first line of defence in Experian's broader incident response and incident management departments, responsible for receiving and prioritizing cybersecurity alerts, including being the dedicated contact for potential security incidents reported by users (e.g., Experian employees). Depending on the results of assessment, this team is then responsible for investigating, containing, eradicating, and recovering from events falling in its scope or escalating higher-risk events to dedicated incident response and management teams in the CFC.
This role is critical in ensuring the handling of potential threats and plays a part in improving security operations.
This is a home based role reporting to the Director of Security Operations for SecOps & Threat Detection.
Please note that in this role, you will have an 8x5 Monday-Friday schedule, with flexibility to respond to after-hours pages for potentially major security incidents to support incident response efforts and may include assignment to an on-call rotation for evenings, weekends, holidays.
Summary of Primary Responsibilities
As the Cyber Defence Analyst, you will:
- Contribute to daily security operations by overseeing response activities for security events and alerts associated with cyber threats, intrusions, and compromises alongside a team of global security analysts following documented SLOs and processes.
- Analyze events using security tooling and logging (e.g., SIEM, EDR) and assess potential risk / severity level of cyber threats; escalate higher-risk events to dedicated incident response and management teams in the CFC according to established processes.
- Collaborate with external teams for incident resolution and escalations, driving incident handling
- Notify team Lead(s) of concerns related to operations, such as anomalous changes in metrics, notable open incidents, quality concerns, or observed risks; support with resolution if appropriate
- Manage and complete assigned caseload throughout the incident response lifecycle, including analysis, containment, eradication, recovery, and lessons learned.
- Maintain all case documentation, including notes, analysis findings, containment steps, and cause for each assigned security incident. Ensure incident updates or contact with end-users are performed promptly and documented.
- Help improve relevant strategies, Standard Operating Procedures (SOPs), and training materials
- Support management's overall strategy for CFC by participating in execution of improvement programs together with management's plans
- Assist the team Leads and management on use case development by suggesting enhancement or tuning of use cases to improve the security posture of Experian
Make Your Resume Now