Senior Security Events Analyst

Location
Mons, Belgium (BE)
Salary
Negotiable daily rate
Posted
16 Oct 2017
Closes
13 Nov 2017
Ref
TI1222
Clearance Level
DV, NATO, SC
Job Type
Contract

Senior Security Events Analyst

 

LOCATION: Mons, Belgium

CLIENT: NATO

DURATION: 6 months with possible extensions

CONTRACT: Consultant

SALARY: Negotiable daily rate

WORK HOURS: Monday to Friday, normal working hours

CLEARANCE: NATO SECRET

SCOPE OF WORK

GLOBAL Technologies is looking for a Senior (Level 2) Security Event Analysts contracted to work at SHAPE in Mons, Belgium. The role will require candidates to have significant experience in the analysis and handling of network security related events and security event management, with experience of working at expert level as a security event analyst or cyber tools specialist in multiple areas of cyber technologies.

As the Senior Security Event Analyst working embedded within the NCIRC customer working environment, the successful candidate will be required to use their in-depth knowledge gained from both experience and qualifications in the Cyber Defence arena to work on advanced cyber-attacks against one of the largest cyber implementations outside of North America. This will include the utilisation of log analysis, IDS/IPS, FPC and forensics tools across a distributed sensor network. The SSEA will be required to provide leadership, mentoring and guidance to other staff members within the Event Analysis team.

TASKS

  • Support to Level 1 Event Analysts
  • Reviewing of tickets
  • Support for analysis of events
  • Retrieval and support in the analysis of Full Packet Captures (FPC)
  • Provision of in-depth analysis after ticket escalation
  • New threat analysis
  • Vulnerability Assessment scanning
  • Signature creation e.g. SNORT rules
  • Test and evaluation of signatures and rules prior to deployment in the operational environment
  • Evaluation and implementation of sensor tuning requests
  • Online research, such as creating new signatures, developing new methods of detecting and monitoring new threats, keeping abreast of developments in the cyber arena
  • Assistance in the support of legacy cyber sensor products
  • Provision of On-the-Job Training (OJT) for the Level 1 event analysts, including tools familiarisation
  • Creation and updating of Standard Operating Procedures (SOPs) and Security Policies
  • Creation of a monthly report to the Customer and the Business
  • Ad-hoc taskings from the Incident Management Section (IMS) in support to investigations
  • Occasionally deputising for NCIA Subject Matter Experts (when required)
  • Monthly knowledge transfer meetings for information exchange with the internal cell

REQUIREMENTS

  • Significant experience in the analysis and handling of network security related events and security event management.
  • Essential to have one of more professional SANS (e.g., GSEC, GCIA) or CISSP certifications.
  • Expert level of management and analysis of (i.e. Security Event Analyst experience), or configuration, operation, troubleshooting and management (i.e. Tools Specialist) in at least three of the following areas, and a high level of experience in several of the other areas:
  • ArcSight products,
  • Network Based Intrusion Detection Systems (NIDS),
  • Host Based Intrusion Detection Systems (HIDS),
  • Network security appliances and networking devices and associated management software,
  • A variety of Security Event generating sources (e.g. Firewalls, IDS, Routers, Security Appliances),
  • Computer Incident Response Centre (CIRT), Computer Emergency Response Team (CERT),
  • Computer forensics tools (stand alone, online and network)
  • Computer security tools (Vulnerability Assessment, Anti-virus, Protocol Analysis, Anti-Virus, Protocol Analysis, Anti-Spyware, etc.),
  • Secure web design and development,
  • Military communication systems and networks,
  • Network, system and application level troubleshooting techniques.
  • Ability to manage workload for themselves in pressurised environments to Time, Quality and Standards
  • Ability to communicate technical solutions to both technical and non-technical audiences
  • Security clearances to SC minimum (NATO SECRET required)
  • Ability to mentor staff
  • Ability to work in an International environment embedded in customer location in Belgium.