Annual salary: Competitive Salary
Loxam are currently recruiting an IT SOC Engineer to join our IT Security team at our Head Office in Lutterworth.
The SOC Engineer role will be part of the LOXAM Security Operations Centre and will report to the Director of Security Operations. The SOC Engineer's primary role will be to develop and maintain Security Operations Centre (SOC) tools, including Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR), to define and continuously develop a use case-driven logging, monitoring and response capability to ensure responsiveness and resilience to cyber security threats.
This role will involve a mix of technical security skills, project planning, security operations, and governance, including maintaining security operations processes and procedures and demonstrating that security controls are embedded across the SOC team.
The role will require analytical skills, solid IT skills, and an understanding of the practical application of information security.
The role will require working closely with the IT and business functions at all levels in all operating countries to ensure security-related activities are completed.
In return you will receive a Competitive Salary, 25 days annual leave plus bank holidays, Auto enrolment pension scheme, Life Assurance, Westfield Health Cash plan & Lifestyle benefits – Discount on selected stores.
Responsibilities include:
- Develop content for a complex and growing SIEM infrastructure. This includes use cases, dashboards, active channels, reports, rules, filters, trends and active lab sessions.
- Use SIEM in the daily operational work, which includes but is not limited to administering, operating, and managing the SIEM platform and regular activities of ensuring the health of log sources, parsers, alerts, reports, etc. and ensuring that the platform is operating as planned.
- Monitor SIEM and other event sources, assess, prioritise, escalate and manage security alerts.
- Perform analysis of security, network, database and application logs, correlate events and activities to create threat scenarios in order to get ahead of threat actors and reduce exposure.
- Help the imminent threat/zero-day response function across the environment.
- Translate threat intelligence into actionable security across tools such as firewalls, IPS and malware detection across multiple security vendor platforms.
- Support the tracking and resolution of security incidents on occasion, and collaborate with other teams for resolution and suggest areas for improvement.
- Must have experience building custom connectors/parsers, etc., to point devices or IT assets that are not supported out of the box.
- Continuous work with IT Operations to fine-tune security solutions to reduce the occurrence of false positive and false negative alerts.
- Working knowledge and experience with the MITRE framework for cyber adversary tactics and techniques
The ideal candidate will have/be:
- Developing and implementing SIEM solutions for large enterprises or SOC service providers.
- Have strong experience in assessing and implementing operational tools, such as a SOAR platform, and processes for a Security Operations Centre (SOC)
- Have a good technical understanding of modern and legacy enterprise technologies
- Advanced industry-standard SOC Security qualifications (SANS, ISC2, etc.).
- Proven Tier 3 SOC Engineering experience (2 years)
- Demonstrable experience working with SIEM technology and SIEM engineering (including tool configuration), i.e. within an enterprise SOC.
- Experience in the creation of use cases, analytics and playbooks.
- Experience with automation languages, such as Python
- An understanding of cloud technologies.
- Perform triage of security events; determine scope, priority and impact, and make recommendations that enable expeditious remediation.
- Conduct real-time management of security incidents from detection to resolution.
- Degree-level qualification; preferably in a technical, engineering or computing subject
- Strong understanding of Splunk SIEM and SOAR solutions.
Part of the Loxam Group, Nationwide Platforms are the UK's leading specialist provider of Powered Access rental equipment, with the largest and broadest fleet, local depots spread across the country and our wealth of experience partnering with companies in a variety of sectors including Construction, Warehouse & Distribution, Aviation, Facilities Management, Industrial Services, Telecoms and Media, our customers can depend on us to provide the right solution to support their every working at height need.
At Nationwide Platforms, your safety is absolutely our priority. Our award winning BlueSky Solutions and Training division offer our customers access to the latest and safest ways to work and through long standing partnerships with our manufacturers, we will always provide equipment that will lead the way to a safer industry. Some of our innovations include the award-winning secondary guarding systems and Harness ON™, a range of pioneering Material Handling Attachments (MHAs), and the SkySentry™ control and monitoring system.
At Nationwide Platforms, we are dedicated to fostering a diverse, equitable, and inclusive workplace. We recognise that a variety of perspectives, experiences, and backgrounds is crucial to our success in the Powered Access industry. Our commitment is to ensure that every employee feels respected, valued, and supported in their work environment