• Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
  • Sign in
  • Sign up
  • Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

21 jobs found

Email me jobs like this
Refine Search
Current Search
senior it security analyst cissp
Senior Incident Response Consultant, Rapid Response
Sophos Group Oxford, Oxfordshire
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies - including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at . Role Summary Sophos is seeking an experienced and motivated Senior Incident Response Consultant to join our Incident Response (IR) service. The Sophos IR team is an elite group of incident responders that are engaged by organizations worldwide to respond to and neutralize cyber threats. Specializing in industry-standard forensic tools and Sophos technologies, the team provides comprehensive investigations, response actions, remediation guidance, and root cause analysis to combat a wide range of cybersecurity incidents. As a Senior Incident Response Consultant on the Sophos IR team, you will be responsible for spearheading incident response engagements for customers who have experienced a cybersecurity attack. In this role, you will lead a team of Incident Response Consultants, running customer-facing calls, providing detailed written updates via email, and determining the priorities of the investigation, delegating tasks accordingly to your team. In this role, you will be accountable for ensuring that the appropriate actions have been taken by both your team and the customer to effectively neutralize the threat. Additionally, you will be tasked with conducting a thorough root cause analysis to determine the origin of the incident, including identifying whether any data exfiltration occurred, provided the necessary evidence is available. At the culmination of each engagement, you will be responsible for producing an executive summary-style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident and provide remediation guidance. The ideal candidate for this role will possess extensive experience leading incident response efforts, a deep understanding of cybersecurity threats and mitigation strategies, and the ability to communicate complex technical information to executive-level stakeholders in a clear and concise manner. What You Will Do The working week for this role will be Fri, Sat, Sun and Monday working with Tues, Wed and Thursdays off Lead kick off calls with customers to understand their situation and identify initial response actions to contain the threat Provide guidance to customers on best practices following an incident Lead daily update calls for customers to deliver forensic findings Deliver concise email updates to customers between update calls Direct the forensic investigations, identify priorities, and delegate tasks to analysts Conduct multiple Rapid Response incidents concurrently Determine TTPs identified by analysts and add them to the threat intel platform Write clear and concise Executive Summary style reports in a timely manner Responsible for basic to moderate complexity projects that contribute to the development of the Sophos Rapid Response service Provide daily handover notes to teams located in different time zones, or when incident responsibility is being transferred to another Incident Lead What You Will Bring 5+ years of experience leading incident response investigations involving ransomware Experience leading BEC investigations Continuously learning and staying informed of the changing threat landscape Proven track record of successful neutralization and remediation of ransomware threats Excellent understanding of the Incident Response process Excellent understanding of cyber risks and able to qualify them to customers Excellent oral communication skills Strong written communication skills Ability to manage time effectively Able to delegate and prioritize tasks across multiple incidents Able to excel under stressful circumstances Occasionally willing to begin work early and/or stay late when warranted for customer engagements Strong grasp of the MITRE ATT&CK framework Enjoy mentoring and assisting in the development of junior analysts A team-player attitude with a willingness to share knowledge Ability to work some weekends and holidays Post-secondary education in Cybersecurity, comparable Desirable: Cybersecurity certifications an asset (e.g. CISSP, GCFA, or similar) Experience with SIEM technology (e.g. Splunk, ELK, etc.) Willingness to work occasional overtime during peak times or holidays Experience writing SQL queries Experience writing PowerShell, Python, or Bash scripts Ready to Join Us? What's Great About Sophos? Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. While we are a remote first organization, applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship. Our people - we innovate and create, all of which are accompanied by a great sense of fun and team spirit Employee-led diversity and inclusion networks that build community and provide education and advocacy Annual charity and fundraising initiatives and volunteer days for employees to support local communities Global employee sustainability initiatives to reduce our environmental footprint Global fitness and trivia competitions to keep our bodies and minds sharp Global wellbeing days for employees to relax and recharge Monthly wellbeing webinars and training to support employee health and wellbeing Our Commitment To You We're proud of the diverse and inclusive environment we have at Sophos, and we're committed to ensuring equality of opportunity. We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team. All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos' data protection practices, please consult our Privacy Policy Cybersecurity as a Service Delivered Sophos
Sep 17, 2026
Full time
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies - including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at . Role Summary Sophos is seeking an experienced and motivated Senior Incident Response Consultant to join our Incident Response (IR) service. The Sophos IR team is an elite group of incident responders that are engaged by organizations worldwide to respond to and neutralize cyber threats. Specializing in industry-standard forensic tools and Sophos technologies, the team provides comprehensive investigations, response actions, remediation guidance, and root cause analysis to combat a wide range of cybersecurity incidents. As a Senior Incident Response Consultant on the Sophos IR team, you will be responsible for spearheading incident response engagements for customers who have experienced a cybersecurity attack. In this role, you will lead a team of Incident Response Consultants, running customer-facing calls, providing detailed written updates via email, and determining the priorities of the investigation, delegating tasks accordingly to your team. In this role, you will be accountable for ensuring that the appropriate actions have been taken by both your team and the customer to effectively neutralize the threat. Additionally, you will be tasked with conducting a thorough root cause analysis to determine the origin of the incident, including identifying whether any data exfiltration occurred, provided the necessary evidence is available. At the culmination of each engagement, you will be responsible for producing an executive summary-style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident and provide remediation guidance. The ideal candidate for this role will possess extensive experience leading incident response efforts, a deep understanding of cybersecurity threats and mitigation strategies, and the ability to communicate complex technical information to executive-level stakeholders in a clear and concise manner. What You Will Do The working week for this role will be Fri, Sat, Sun and Monday working with Tues, Wed and Thursdays off Lead kick off calls with customers to understand their situation and identify initial response actions to contain the threat Provide guidance to customers on best practices following an incident Lead daily update calls for customers to deliver forensic findings Deliver concise email updates to customers between update calls Direct the forensic investigations, identify priorities, and delegate tasks to analysts Conduct multiple Rapid Response incidents concurrently Determine TTPs identified by analysts and add them to the threat intel platform Write clear and concise Executive Summary style reports in a timely manner Responsible for basic to moderate complexity projects that contribute to the development of the Sophos Rapid Response service Provide daily handover notes to teams located in different time zones, or when incident responsibility is being transferred to another Incident Lead What You Will Bring 5+ years of experience leading incident response investigations involving ransomware Experience leading BEC investigations Continuously learning and staying informed of the changing threat landscape Proven track record of successful neutralization and remediation of ransomware threats Excellent understanding of the Incident Response process Excellent understanding of cyber risks and able to qualify them to customers Excellent oral communication skills Strong written communication skills Ability to manage time effectively Able to delegate and prioritize tasks across multiple incidents Able to excel under stressful circumstances Occasionally willing to begin work early and/or stay late when warranted for customer engagements Strong grasp of the MITRE ATT&CK framework Enjoy mentoring and assisting in the development of junior analysts A team-player attitude with a willingness to share knowledge Ability to work some weekends and holidays Post-secondary education in Cybersecurity, comparable Desirable: Cybersecurity certifications an asset (e.g. CISSP, GCFA, or similar) Experience with SIEM technology (e.g. Splunk, ELK, etc.) Willingness to work occasional overtime during peak times or holidays Experience writing SQL queries Experience writing PowerShell, Python, or Bash scripts Ready to Join Us? What's Great About Sophos? Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. While we are a remote first organization, applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship. Our people - we innovate and create, all of which are accompanied by a great sense of fun and team spirit Employee-led diversity and inclusion networks that build community and provide education and advocacy Annual charity and fundraising initiatives and volunteer days for employees to support local communities Global employee sustainability initiatives to reduce our environmental footprint Global fitness and trivia competitions to keep our bodies and minds sharp Global wellbeing days for employees to relax and recharge Monthly wellbeing webinars and training to support employee health and wellbeing Our Commitment To You We're proud of the diverse and inclusive environment we have at Sophos, and we're committed to ensuring equality of opportunity. We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team. All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos' data protection practices, please consult our Privacy Policy Cybersecurity as a Service Delivered Sophos
Xact Placements Limited
3rd Line Security Analyst
Xact Placements Limited Reading, Berkshire
3rd Line Security Analyst My client, a well-established organisation within the ICT Services sector, are looking to recruit an experienced 3rd Line Security Analyst to join their Security Operations function. This is a senior, hands-on technical role rather than a queue-driven analyst position. The successful candidate will take ownership of the engineering, administration, health and continuous improvement of the security platforms, detection content and automation that underpin threat monitoring, detection and incident response across my client's internal and managed customer environments. They will act as the final internal escalation point for complex and high-severity security incidents, the technical design authority for detection and automation content, and a mentor who raises the technical capability of the wider 2nd line team. Reporting to the Security Operations Manager, this role sits within ICT Services and carries genuine scope and technical authority, including sign-off on detection content, SOAR playbooks and hunting queries, named administrative ownership of key security platforms, and the authority to take immediate containment action during live incidents. Key Responsibilities Lead the end-to-end management of complex and high-severity security incidents, including investigation, containment, eradication, recovery and post-incident review. Conduct digital forensic investigations across cloud, identity, endpoint and network platforms, and carry out malware analysis and threat validation. Design, implement and optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra ID, Intune, Darktrace and supporting technologies, managing platform health, onboarding and configuration. Design and maintain automation and orchestration workflows using Logic Apps, Sentinel Playbooks, Power Automate, PowerShell, Python and API integrations to reduce manual operational effort. Conduct proactive, intelligence-led and hypothesis-driven threat hunting, translating findings into detections, hunts and customer recommendations. Monitor, investigate and respond to security events across Microsoft 365, Azure, AWS and hybrid environments. Support compliance activities relating to ISO 27001 and Cyber Essentials, maintaining technical documentation, runbooks and standard operating procedures. Provide technical leadership, mentoring and knowledge transfer to Security Analysts and Service Desk teams. What My Client Is Looking For Significant experience within a Security Operations Centre (SOC), Cyber Security Operations or Security Engineering function, including at a senior technical level. Strong hands-on experience administering and engineering Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon and associated security technologies. Proven experience in incident response, threat hunting, malware analysis, digital forensics and security investigations. Advanced KQL skills, with the ability to develop and optimise complex detections and threat hunting queries. Strong scripting and automation experience using PowerShell and/or Python, including API integrations and workflow automation. Experience administering Microsoft Entra ID, Conditional Access, Intune and Microsoft 365 security solutions. Good understanding of Azure, AWS and hybrid infrastructure security, with strong knowledge of networking, operating systems and attacker techniques. Practical understanding of MITRE ATT&CK, Cyber Kill Chain, NIST and SANS incident response frameworks. Experience working within regulated and audited environments, including ISO 27001 and Cyber Essentials. Excellent communication, stakeholder management and documentation skills, with the ability to engage effectively across technical and non-technical audiences. Desirable CISSP (Certified Information Systems Security Professional) certification. Experience designing or improving SOC operating models, detection strategies, or security platforms at scale. Exposure to security architecture or security engineering activities beyond day-to-day SOC operations. Experience contributing to or leading continuous improvement initiatives, automation strategy, or security service maturity. Additional Requirements Ability to prioritise work under pressure and meet strict deadlines. Excellent written and verbal communication skills. Candidates must be able to pass security vetting (BS7858). Salary: £60,000 Location: Reading / hybrid 2 days from home
Sep 17, 2026
Full time
3rd Line Security Analyst My client, a well-established organisation within the ICT Services sector, are looking to recruit an experienced 3rd Line Security Analyst to join their Security Operations function. This is a senior, hands-on technical role rather than a queue-driven analyst position. The successful candidate will take ownership of the engineering, administration, health and continuous improvement of the security platforms, detection content and automation that underpin threat monitoring, detection and incident response across my client's internal and managed customer environments. They will act as the final internal escalation point for complex and high-severity security incidents, the technical design authority for detection and automation content, and a mentor who raises the technical capability of the wider 2nd line team. Reporting to the Security Operations Manager, this role sits within ICT Services and carries genuine scope and technical authority, including sign-off on detection content, SOAR playbooks and hunting queries, named administrative ownership of key security platforms, and the authority to take immediate containment action during live incidents. Key Responsibilities Lead the end-to-end management of complex and high-severity security incidents, including investigation, containment, eradication, recovery and post-incident review. Conduct digital forensic investigations across cloud, identity, endpoint and network platforms, and carry out malware analysis and threat validation. Design, implement and optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra ID, Intune, Darktrace and supporting technologies, managing platform health, onboarding and configuration. Design and maintain automation and orchestration workflows using Logic Apps, Sentinel Playbooks, Power Automate, PowerShell, Python and API integrations to reduce manual operational effort. Conduct proactive, intelligence-led and hypothesis-driven threat hunting, translating findings into detections, hunts and customer recommendations. Monitor, investigate and respond to security events across Microsoft 365, Azure, AWS and hybrid environments. Support compliance activities relating to ISO 27001 and Cyber Essentials, maintaining technical documentation, runbooks and standard operating procedures. Provide technical leadership, mentoring and knowledge transfer to Security Analysts and Service Desk teams. What My Client Is Looking For Significant experience within a Security Operations Centre (SOC), Cyber Security Operations or Security Engineering function, including at a senior technical level. Strong hands-on experience administering and engineering Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon and associated security technologies. Proven experience in incident response, threat hunting, malware analysis, digital forensics and security investigations. Advanced KQL skills, with the ability to develop and optimise complex detections and threat hunting queries. Strong scripting and automation experience using PowerShell and/or Python, including API integrations and workflow automation. Experience administering Microsoft Entra ID, Conditional Access, Intune and Microsoft 365 security solutions. Good understanding of Azure, AWS and hybrid infrastructure security, with strong knowledge of networking, operating systems and attacker techniques. Practical understanding of MITRE ATT&CK, Cyber Kill Chain, NIST and SANS incident response frameworks. Experience working within regulated and audited environments, including ISO 27001 and Cyber Essentials. Excellent communication, stakeholder management and documentation skills, with the ability to engage effectively across technical and non-technical audiences. Desirable CISSP (Certified Information Systems Security Professional) certification. Experience designing or improving SOC operating models, detection strategies, or security platforms at scale. Exposure to security architecture or security engineering activities beyond day-to-day SOC operations. Experience contributing to or leading continuous improvement initiatives, automation strategy, or security service maturity. Additional Requirements Ability to prioritise work under pressure and meet strict deadlines. Excellent written and verbal communication skills. Candidates must be able to pass security vetting (BS7858). Salary: £60,000 Location: Reading / hybrid 2 days from home
A&O Shearman
Cyber Defence Senior Analyst
A&O Shearman Dundonald, Belfast
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 15, 2026
Full time
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Senior Analyst
A&O Shearman Dromore, County Down
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 15, 2026
Full time
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Senior Analyst
A&O Shearman Craigavon, County Armagh
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 15, 2026
Full time
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Senior Analyst
A&O Shearman Portadown, County Armagh
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 15, 2026
Full time
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Senior Analyst
A&O Shearman Newtownabbey, County Antrim
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 14, 2026
Full time
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Senior Analyst
A&O Shearman Lisburn, County Antrim
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 14, 2026
Full time
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Senior Analyst
A&O Shearman Kilkeel, County Down
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 14, 2026
Full time
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Senior Analyst
A&O Shearman Bangor, County Down
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 14, 2026
Full time
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Senior Analyst
A&O Shearman Downpatrick, County Down
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 14, 2026
Full time
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Senior Analyst
A&O Shearman Dunmurry, Belfast
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 14, 2026
Full time
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Senior Analyst
A&O Shearman Millisle, County Down
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 14, 2026
Full time
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Senior Analyst
A&O Shearman City, Belfast
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 14, 2026
Full time
We have an exciting opportunity for a Senior Cyber Defence Analyst to join the Information Security team at A&O Shearman in Belfast. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do The Cyber Defence Senior Analyst will reside within the firm's information security team and will be based in Belfast. They will perform a critical role in solidifying the firm's security posture, focusing on the in-depth analysis, and effective response to cyber security events and incidents within their time-zone. They will also contribute to the effectiveness and cohesion of the Cyber Defence team by providing guidance to, and sharing knowledge with, more junior Cyber Defence Colleagues. Investigating escalations: Investigate Level 2 escalated events and alerts which have detected been through Level 1 monitoring activities by the firm's Managed Security Service Provider (MSSP) to identify potential incidents. Assist and advise junior colleagues during investigations where additional experience is required. Incident Response: Conduct initial triage and investigation of confirmed incidents. Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately along the process. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Documentation and Process Improvement: Maintain and improve playbooks and process documentation for Cyber Defence. Ensure documentation reflects current threat landscapes and operational practices. Implement and enhance cyber defence tooling and processes under senior oversight. Develop new detection definitions and use cases for monitoring tools. Mentoring, Collaboration, and Support: Mentor junior colleagues to support their professional development and operational effectiveness. Collaborate with other teams (e.g. Information Security, IT) to implement security controls and raise awareness. Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Provide cyber defence guidance to business stakeholders, translating technical concepts into business language. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs). Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. What you will have Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP). Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), Threat and vulnerability management platforms, Endpoint protection, and Firewalls. Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions. Demonstrated ability to investigate complex security issues and propose effective solutions. Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams. A genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field. You will stand out if you bring Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as, CISSP, CEH, CISM, CompTIA Security+ Experience working with major cloud service providers (CSPs) technologies, such as: Microsoft Azure Google Cloud Platform (GCP) Amazon Web Services (AWS) Prior legal firm or professional services firm experience Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
CapGemini
Senior Service Designer (SC Cleared) - Senior Consultant - AI & Digital Factory
CapGemini
# Senior Service Designer (SC Cleared) - Senior Consultant - AI & Digital FactoryGlasgow, London, Manchester, Newcastle Bank HouseApply for this job Permanent Experienced Professionals Strategy & Transformation ID 517386-en\_GB# Capgemini Invent, we believe difference drives change. As inventive transformation consultants, we blend our strategic, creative and scientific capabilities, collaborating closely with clients to deliver cutting-edge solutions. Join us to drive transformation tailored to our client's challenges of today and tomorrow. Informed and validated by science and data. Superpowered by creativity and design. All underpinned by technology created with purpose. AS A SENIOR SERVICE DESIGNER YOU WILL Lead workstreams through the end-to-end service design process to design and develop innovative products and services from ideation through to solution build and testing for our public sector clients. Define and structure service design approaches, methods and outputs tailored to your client's needs based on their design maturity and project specific needs Develop and oversee the delivery of high-quality service design artefacts ensuring consistency and impact Apply deep expertise in GDS standards, accessibility and inclusive design in order to successfully pass service assessments Facilitate and lead workshops and co-design sessions as necessary Communicate complex ideas using storytelling and visualization Possess strong stakeholder management skills, with the ability to balance competing views as part of the design process and advocate for user-centred design Manage priorities, risks, dependencies and delivery Support the service design capability and the mentoring of junior colleagues, delegating when necessary Shape service design tools, methods and propositions within AI & Digital Factory by staying in tune with trends and demands in the market Hold active SC (Security Check) Clearance. YOUR EXPERIENCE Minimum 5+ years of experience designing services and products. Proven experience leading a service design workstream with multiple clients or projects, autonomously with minimal support Deep expertise working with Government Digital Service (GDS) service standards, applying GDS design principles with public sector clients and passing service assessments or similar Proven experience not only creating service design artefacts and outputs, but defining the best approach, methods and appropriate artefacts for your client based on their maturity and parameters Experience facilitating workshops, ideation sessions and related activities to progress through design sprints Experience breaking down complex problems in a fast-paced environment, with a knack for storytelling to diverse stakeholders Strong understanding and experience of working in an agile (scrum) environment in a cross-functional team including but not limited to user researchers, UX/UI designers, business analysts, product owners, delivery managers and developers Ability to manage competing priorities in a tight timeframe with a proactive mindset Experience working directly with other teams such as legal or policy and facilitating conversations to progress design and service decisions that meet the needs of all stakeholders Comfortability picking up responsibilities where there is a gap across UCD disciplines or project management when necessary You will be expected to show examples of work, this does not need to be a formal portfolio or comprehensive story but rather speak to your diverse experience through visual artefacts so that we may understand your process and the type of artefacts you typically output. Hold active SC (Security Check) Clearance YOUR ROLE As a Senior Service Designer, you will be expected to lead the design and delivery of service design workstreams on our public sector client projects, taking ownership of the approach, outputs and outcomes. You will work independently within multidisciplinary teams, shaping services end-to-end and ensuring the delivery of high-quality, user-centred solutions.You will be joining the growing and exciting AI & Digital Factory community who are continually sharing knowledge and expertise. As a Senior Service Designer, you will also contribute to business development and the growth of the service design capability. You will be part of a collaborative and high-performing community passionate about user-centred design and transformation. You will bring strong service design expertise and experience leading workstreams independently within complex environments. As part of your role you will also have the opportunity to contribute to the business and your own personal growth, through activities that form part of the following categories: Business Development - Leading/contributing to proposals, RFPs, bids, proposition development, client pitch contribution, client hosting at events. Internal contribution - Campaign development, internal think-tanks, whitepapers, practice development (operations, recruitment, team events & activities), offering development. Learning & development - Training to support your career development and the skills demand within the company, certifications etc. WHAT YOU'LL LOVE ABOUT WORKING HERE? We are delighted to have received the"Glassdoor Best Places to work UK' accolade for 5 consecutive years. To see what it's like to work at Capgemini Invent, visit our Glassdoor page. Capgemini Invent offers Consultants a culture of learning, ownership, and focus on value. You'll gain exposure to high-profile transformations and gain hands-on exposure to leading technologies. Our consultants are formally trained by industry experts in consulting and client delivery. Consultants have access to a vast array for different training and certifications in a variety of areas: cloud technologies (AWS, Azure, GCP), programming (Java, Kotlin, NodeJS, Spring Boot), DevOps (Terraform, Kubernetes, Docker), Cybersecurity (CISSP, CISM) and Agile delivery (Scrum Master, Product Owner, Scaled Agile Framework). Capgemini Invent offers you the flexibility to develop various areas of knowledge in technical domains aligned both to your interests and our client's outcomes. Les Fontaines: Capgemini Invent has a unique training environment just outside of Paris, where we can immerse ourselves in thought-leadership, share knowledge and build capabilities that will help us and our clients to succeed. We hold monthly showcases of our digital transformation initiatives, sharing knowledge and showing off how the power of technology is impacting our clients. There are monthly team drinks, and it's a chance to connect face-to-face with the wider team over a few drinks in the city. The monthly team breakfasts give you a different, more relaxed setting to meet up in the office to hear from the leadership, meet colleagues and discuss the trends and insights within the market. Team away days are always a chance to connect with the team, have fun and learn something new. NEED TO KNOW At Capgemini we don't just believe in inclusion, we actively go out to making it a working reality. Driven by our core values and Inclusive Futures for All campaign, we build environments where you can bring you whole self to work. We aim to build an environment where employees can enjoy a positive work-life balance. We embed hybrid working in all that we do and make flexible working arrangements the day-to-day reality for our people. All UK employees are eligible to request flexible working arrangements. Employee wellbeing is vitally important to us as an organisation. We see a healthy and happy workforce a critical component for us to achieve our organisational ambitions. To help support wellbeing we have trained 'Mental Health Champions' across each of our business areas. We have also invested in wellbeing apps such as Thrive and Peppy.Capgemini is proud to be a Disability Confident Employer (Level 2) under the UK Government's Disability Confident scheme. As part of our commitment to inclusive recruitment, we will offer an interview to all candidates who: Declare they have a disability, and Meet the minimum essential criteria for the role.Please opt in during the application process. CSR: We're also focused on using tech to have a positive social impact. So, we're working to reduce our own carbon footprint and improve everyone's access to a digital world. It's something we're really serious about. In fact, we were even named as one of the world's most ethical companies by the Ethisphere Institute for the 10th year. When you join Capgemini, you'll join a team that does the right thing.Whilst you will have London, Manchester or Glasgow as an office base location, you must be fully flexible in terms of assignment location, as these roles may involve periods of time away from home at short notice.We offer a remuneration package which includes flexible benefits options for you to choose to suit your own personal circumstances and a variable element dependent grade and on company and personal performance. ABOUT CAPGEMINI Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organizations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2025 global revenues of €22.5 billion.Make it real.
Sep 12, 2026
Full time
# Senior Service Designer (SC Cleared) - Senior Consultant - AI & Digital FactoryGlasgow, London, Manchester, Newcastle Bank HouseApply for this job Permanent Experienced Professionals Strategy & Transformation ID 517386-en\_GB# Capgemini Invent, we believe difference drives change. As inventive transformation consultants, we blend our strategic, creative and scientific capabilities, collaborating closely with clients to deliver cutting-edge solutions. Join us to drive transformation tailored to our client's challenges of today and tomorrow. Informed and validated by science and data. Superpowered by creativity and design. All underpinned by technology created with purpose. AS A SENIOR SERVICE DESIGNER YOU WILL Lead workstreams through the end-to-end service design process to design and develop innovative products and services from ideation through to solution build and testing for our public sector clients. Define and structure service design approaches, methods and outputs tailored to your client's needs based on their design maturity and project specific needs Develop and oversee the delivery of high-quality service design artefacts ensuring consistency and impact Apply deep expertise in GDS standards, accessibility and inclusive design in order to successfully pass service assessments Facilitate and lead workshops and co-design sessions as necessary Communicate complex ideas using storytelling and visualization Possess strong stakeholder management skills, with the ability to balance competing views as part of the design process and advocate for user-centred design Manage priorities, risks, dependencies and delivery Support the service design capability and the mentoring of junior colleagues, delegating when necessary Shape service design tools, methods and propositions within AI & Digital Factory by staying in tune with trends and demands in the market Hold active SC (Security Check) Clearance. YOUR EXPERIENCE Minimum 5+ years of experience designing services and products. Proven experience leading a service design workstream with multiple clients or projects, autonomously with minimal support Deep expertise working with Government Digital Service (GDS) service standards, applying GDS design principles with public sector clients and passing service assessments or similar Proven experience not only creating service design artefacts and outputs, but defining the best approach, methods and appropriate artefacts for your client based on their maturity and parameters Experience facilitating workshops, ideation sessions and related activities to progress through design sprints Experience breaking down complex problems in a fast-paced environment, with a knack for storytelling to diverse stakeholders Strong understanding and experience of working in an agile (scrum) environment in a cross-functional team including but not limited to user researchers, UX/UI designers, business analysts, product owners, delivery managers and developers Ability to manage competing priorities in a tight timeframe with a proactive mindset Experience working directly with other teams such as legal or policy and facilitating conversations to progress design and service decisions that meet the needs of all stakeholders Comfortability picking up responsibilities where there is a gap across UCD disciplines or project management when necessary You will be expected to show examples of work, this does not need to be a formal portfolio or comprehensive story but rather speak to your diverse experience through visual artefacts so that we may understand your process and the type of artefacts you typically output. Hold active SC (Security Check) Clearance YOUR ROLE As a Senior Service Designer, you will be expected to lead the design and delivery of service design workstreams on our public sector client projects, taking ownership of the approach, outputs and outcomes. You will work independently within multidisciplinary teams, shaping services end-to-end and ensuring the delivery of high-quality, user-centred solutions.You will be joining the growing and exciting AI & Digital Factory community who are continually sharing knowledge and expertise. As a Senior Service Designer, you will also contribute to business development and the growth of the service design capability. You will be part of a collaborative and high-performing community passionate about user-centred design and transformation. You will bring strong service design expertise and experience leading workstreams independently within complex environments. As part of your role you will also have the opportunity to contribute to the business and your own personal growth, through activities that form part of the following categories: Business Development - Leading/contributing to proposals, RFPs, bids, proposition development, client pitch contribution, client hosting at events. Internal contribution - Campaign development, internal think-tanks, whitepapers, practice development (operations, recruitment, team events & activities), offering development. Learning & development - Training to support your career development and the skills demand within the company, certifications etc. WHAT YOU'LL LOVE ABOUT WORKING HERE? We are delighted to have received the"Glassdoor Best Places to work UK' accolade for 5 consecutive years. To see what it's like to work at Capgemini Invent, visit our Glassdoor page. Capgemini Invent offers Consultants a culture of learning, ownership, and focus on value. You'll gain exposure to high-profile transformations and gain hands-on exposure to leading technologies. Our consultants are formally trained by industry experts in consulting and client delivery. Consultants have access to a vast array for different training and certifications in a variety of areas: cloud technologies (AWS, Azure, GCP), programming (Java, Kotlin, NodeJS, Spring Boot), DevOps (Terraform, Kubernetes, Docker), Cybersecurity (CISSP, CISM) and Agile delivery (Scrum Master, Product Owner, Scaled Agile Framework). Capgemini Invent offers you the flexibility to develop various areas of knowledge in technical domains aligned both to your interests and our client's outcomes. Les Fontaines: Capgemini Invent has a unique training environment just outside of Paris, where we can immerse ourselves in thought-leadership, share knowledge and build capabilities that will help us and our clients to succeed. We hold monthly showcases of our digital transformation initiatives, sharing knowledge and showing off how the power of technology is impacting our clients. There are monthly team drinks, and it's a chance to connect face-to-face with the wider team over a few drinks in the city. The monthly team breakfasts give you a different, more relaxed setting to meet up in the office to hear from the leadership, meet colleagues and discuss the trends and insights within the market. Team away days are always a chance to connect with the team, have fun and learn something new. NEED TO KNOW At Capgemini we don't just believe in inclusion, we actively go out to making it a working reality. Driven by our core values and Inclusive Futures for All campaign, we build environments where you can bring you whole self to work. We aim to build an environment where employees can enjoy a positive work-life balance. We embed hybrid working in all that we do and make flexible working arrangements the day-to-day reality for our people. All UK employees are eligible to request flexible working arrangements. Employee wellbeing is vitally important to us as an organisation. We see a healthy and happy workforce a critical component for us to achieve our organisational ambitions. To help support wellbeing we have trained 'Mental Health Champions' across each of our business areas. We have also invested in wellbeing apps such as Thrive and Peppy.Capgemini is proud to be a Disability Confident Employer (Level 2) under the UK Government's Disability Confident scheme. As part of our commitment to inclusive recruitment, we will offer an interview to all candidates who: Declare they have a disability, and Meet the minimum essential criteria for the role.Please opt in during the application process. CSR: We're also focused on using tech to have a positive social impact. So, we're working to reduce our own carbon footprint and improve everyone's access to a digital world. It's something we're really serious about. In fact, we were even named as one of the world's most ethical companies by the Ethisphere Institute for the 10th year. When you join Capgemini, you'll join a team that does the right thing.Whilst you will have London, Manchester or Glasgow as an office base location, you must be fully flexible in terms of assignment location, as these roles may involve periods of time away from home at short notice.We offer a remuneration package which includes flexible benefits options for you to choose to suit your own personal circumstances and a variable element dependent grade and on company and personal performance. ABOUT CAPGEMINI Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organizations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2025 global revenues of €22.5 billion.Make it real.
Lumentum
Senior Information Security Analyst
Lumentum Towcester, Northamptonshire
At Lumentum, we develop the technologies that power the world's most advanced communications, industrial and cloud infrastructure. Security is fundamental to everything we do, and we're looking for an experienced Senior Information Security Analyst to help protect our people, data and global operations. This is an opportunity to join a collaborative cyber security team where you'll lead complex investigations, strengthen security controls and influence how we defend against an evolving threat landscape. You'll work across cloud, identity, endpoint, network and data security while partnering with technical and business teams to continuously improve our security capability. If you enjoy solving challenging security problems, mentoring others and driving meaningful improvements, we'd love to hear from you. What you'll be doing As a senior member of our Information Security team, you'll: Lead the investigation and response to complex cyber security incidents across cloud, endpoint, identity, network, email and application environments. Drive improvements to our Security Operations capability through enhanced detections, playbooks, automation and operational processes. Own and enhance key security controls, including Data Loss Prevention (DLP) and Multi-Factor Authentication (MFA), ensuring they remain effective, measurable and aligned with business needs. Assess vulnerabilities, prioritise remediation activities and work with technology teams to reduce cyber risk across the organisation. Provide security assurance for new projects and technology changes, helping embed security by design. Produce meaningful security metrics and reporting for technical and business stakeholders. Coach and mentor colleagues, sharing knowledge and raising security capability across the organisation. Translate complex technical issues into clear, practical recommendations that support informed business decisions. What you'll bring You'll have experience in several of the following areas: Security Operations, Security Incident Response or Security Engineering. Security Information and Event Management (SIEM) and Endpoint Detection & Response (EDR) technologies. Identity and Access Management, including MFA, Conditional Access and Privileged Access. Data Loss Prevention (DLP) technologies and policy management. Vulnerability Management and security hardening. Security architecture reviews and technical assurance. Threat detection, investigation and root cause analysis. Security automation, scripting or workflow improvement. You'll also be comfortable working with recognised security frameworks such as NIST CSF, ISO 27001, CIS Controls or the NCSC Cyber Assessment Framework. About you We're looking for someone who: Has significant experience within cyber security, information security or security operations. Enjoys leading investigations and solving complex technical challenges. Can influence stakeholders at all levels with clear, confident communication. Thinks strategically while remaining hands-on. Takes ownership and is driven by continuous improvement. Builds strong relationships and enjoys developing others. Professional certifications such as CISSP, CISM or CISA are desirable but not essential if you can demonstrate equivalent experience. Why join Lumentum? At Lumentum, you'll work alongside talented people solving real-world technology challenges in a global organisation that values innovation, collaboration and continuous learning. In return, you'll benefit from: The opportunity to influence enterprise-wide cyber security. Exposure to modern cloud and security technologies. A collaborative and supportive team environment. Ongoing professional development and learning opportunities. The chance to make a genuine impact protecting critical business services. Ready to make an impact? If you're passionate about cyber security, thrive in a fast-paced environment and want to help shape the future of security at a global technology leader, we'd love to hear from you.
Sep 10, 2026
Full time
At Lumentum, we develop the technologies that power the world's most advanced communications, industrial and cloud infrastructure. Security is fundamental to everything we do, and we're looking for an experienced Senior Information Security Analyst to help protect our people, data and global operations. This is an opportunity to join a collaborative cyber security team where you'll lead complex investigations, strengthen security controls and influence how we defend against an evolving threat landscape. You'll work across cloud, identity, endpoint, network and data security while partnering with technical and business teams to continuously improve our security capability. If you enjoy solving challenging security problems, mentoring others and driving meaningful improvements, we'd love to hear from you. What you'll be doing As a senior member of our Information Security team, you'll: Lead the investigation and response to complex cyber security incidents across cloud, endpoint, identity, network, email and application environments. Drive improvements to our Security Operations capability through enhanced detections, playbooks, automation and operational processes. Own and enhance key security controls, including Data Loss Prevention (DLP) and Multi-Factor Authentication (MFA), ensuring they remain effective, measurable and aligned with business needs. Assess vulnerabilities, prioritise remediation activities and work with technology teams to reduce cyber risk across the organisation. Provide security assurance for new projects and technology changes, helping embed security by design. Produce meaningful security metrics and reporting for technical and business stakeholders. Coach and mentor colleagues, sharing knowledge and raising security capability across the organisation. Translate complex technical issues into clear, practical recommendations that support informed business decisions. What you'll bring You'll have experience in several of the following areas: Security Operations, Security Incident Response or Security Engineering. Security Information and Event Management (SIEM) and Endpoint Detection & Response (EDR) technologies. Identity and Access Management, including MFA, Conditional Access and Privileged Access. Data Loss Prevention (DLP) technologies and policy management. Vulnerability Management and security hardening. Security architecture reviews and technical assurance. Threat detection, investigation and root cause analysis. Security automation, scripting or workflow improvement. You'll also be comfortable working with recognised security frameworks such as NIST CSF, ISO 27001, CIS Controls or the NCSC Cyber Assessment Framework. About you We're looking for someone who: Has significant experience within cyber security, information security or security operations. Enjoys leading investigations and solving complex technical challenges. Can influence stakeholders at all levels with clear, confident communication. Thinks strategically while remaining hands-on. Takes ownership and is driven by continuous improvement. Builds strong relationships and enjoys developing others. Professional certifications such as CISSP, CISM or CISA are desirable but not essential if you can demonstrate equivalent experience. Why join Lumentum? At Lumentum, you'll work alongside talented people solving real-world technology challenges in a global organisation that values innovation, collaboration and continuous learning. In return, you'll benefit from: The opportunity to influence enterprise-wide cyber security. Exposure to modern cloud and security technologies. A collaborative and supportive team environment. Ongoing professional development and learning opportunities. The chance to make a genuine impact protecting critical business services. Ready to make an impact? If you're passionate about cyber security, thrive in a fast-paced environment and want to help shape the future of security at a global technology leader, we'd love to hear from you.
Senior Cyber Security Analyst, Professional Services, CompTIA, CISSP
Carrington Recruitment Solutions Limited City, London
Senior Cyber Security Analyst, Professional Services, CompTIA, SIEM, ISO27001, Part Remote Senior Cyber Security Analyst required to work for a Law Firm based in the City of London. It will be 3 days a week in the office and 2 from home. We need an experienced Senior Cyber Security Analyst who is preferably from another Law Firm, or Professional Services at least click apply for full job details
May 30, 2026
Full time
Senior Cyber Security Analyst, Professional Services, CompTIA, SIEM, ISO27001, Part Remote Senior Cyber Security Analyst required to work for a Law Firm based in the City of London. It will be 3 days a week in the office and 2 from home. We need an experienced Senior Cyber Security Analyst who is preferably from another Law Firm, or Professional Services at least click apply for full job details
Senior Cyber Security Analyst, Professional Services, CompTIA, CISSP
Carrington Recruitment Solutions Limited City, London
Senior Cyber Security Analyst, Professional Services, CompTIA, SIEM, ISO27001, Part Remote Senior Cyber Security Analyst required to work for a Law Firm based in the City of London. It will be 3 days a week in the office and 2 from home. We need an experienced Senior Cyber Security Analyst who is preferably from another Law Firm, or Professional Services at least click apply for full job details
May 28, 2026
Full time
Senior Cyber Security Analyst, Professional Services, CompTIA, SIEM, ISO27001, Part Remote Senior Cyber Security Analyst required to work for a Law Firm based in the City of London. It will be 3 days a week in the office and 2 from home. We need an experienced Senior Cyber Security Analyst who is preferably from another Law Firm, or Professional Services at least click apply for full job details
EXPERIS
SOC Technical Lead
EXPERIS
Role Overview We are seeking an experienced and hands-on SOC Operations Technical Lead to lead a team of SOC Analysts operating in a 24/7/365 environment. This is a senior, technically focused leadership role within our Managed Security Services (MSSP) function, reporting directly to the Head of SOC Operations. You will act as the senior technical authority, driving excellence in threat detection, incident response, and security operations across a diverse, multi-client portfolio. While you will lead and mentor a team, this is not a purely managerial role. You will remain deeply involved in technical delivery, acting as an escalation point, leading complex investigations, and continuously improving SOC capabilities. Key Responsibilities Team Leadership & SOC Operations Lead day-to-day SOC operations across all shifts, ensuring consistent 24/7 coverage Manage shift schedules, handovers, and on-call rotations Act as the primary escalation point for security incidents and analyst queries Ensure high-quality triage, investigation, and response aligned to SOC processes Drive team development through training, coaching, and technical mentoring Ensure accurate and timely case management (HALO) and delivery against SLAs Technical Leadership & Continuous Improvement Provide expert guidance on threat detection, incident response, and threat hunting Lead escalations for complex or high-severity incidents across client environments Develop and optimise detection rules, playbooks, and automation Improve SOC tooling (SIEM, EDR/XDR, SOAR) and operational processes Design and maintain advanced detection use cases and correlation logic Client Engagement & Consulting Act as a trusted advisor to clients, supporting security reviews and incident analysis Translate technical findings into clear, actionable recommendations Support continuous improvement of client security posture Collaboration Work closely with Threat Intelligence, Engineering, and Incident Response teams Enhance detection capability through intelligence sharing and tool optimisation Align processes to strengthen overall security operations effectiveness Strategic Contribution Identify opportunities to enhance MSSP services and capabilities Monitor emerging threats, technologies, and industry trends Ensure compliance with regulatory standards and internal frameworks Skills & Experience Essential 7+ years in Security Operations, including 3-4 years in a senior/lead SOC role Strong hands-on experience with: SIEM (e.g. Microsoft Sentinel, CrowdStrike) EDR/XDR (e.g. CrowdStrike, Microsoft Defender, Carbon Black) SOAR and threat intelligence platforms Proven expertise in threat hunting and incident response Experience developing and tuning detection rules in multi-tenant environments Strong automation skills to improve SOC efficiency Excellent client-facing and communication skills Desirable Certifications such as CISSP, GIAC (GCIH, GCIA, GREM), SC-200 or SC-300 Experience in cloud security operations Background in MSSP or consulting environments Familiarity with frameworks such as NIST, ISO27001, or ITIL Key Competencies Strong technical depth with the ability to simplify complex concepts Excellent analytical and problem-solving skills under pressure Confident communicator with strong stakeholder engagement skills Collaborative leadership style with a focus on mentoring and development Ability to manage multiple priorities in a fast-paced SOC environment
May 26, 2026
Full time
Role Overview We are seeking an experienced and hands-on SOC Operations Technical Lead to lead a team of SOC Analysts operating in a 24/7/365 environment. This is a senior, technically focused leadership role within our Managed Security Services (MSSP) function, reporting directly to the Head of SOC Operations. You will act as the senior technical authority, driving excellence in threat detection, incident response, and security operations across a diverse, multi-client portfolio. While you will lead and mentor a team, this is not a purely managerial role. You will remain deeply involved in technical delivery, acting as an escalation point, leading complex investigations, and continuously improving SOC capabilities. Key Responsibilities Team Leadership & SOC Operations Lead day-to-day SOC operations across all shifts, ensuring consistent 24/7 coverage Manage shift schedules, handovers, and on-call rotations Act as the primary escalation point for security incidents and analyst queries Ensure high-quality triage, investigation, and response aligned to SOC processes Drive team development through training, coaching, and technical mentoring Ensure accurate and timely case management (HALO) and delivery against SLAs Technical Leadership & Continuous Improvement Provide expert guidance on threat detection, incident response, and threat hunting Lead escalations for complex or high-severity incidents across client environments Develop and optimise detection rules, playbooks, and automation Improve SOC tooling (SIEM, EDR/XDR, SOAR) and operational processes Design and maintain advanced detection use cases and correlation logic Client Engagement & Consulting Act as a trusted advisor to clients, supporting security reviews and incident analysis Translate technical findings into clear, actionable recommendations Support continuous improvement of client security posture Collaboration Work closely with Threat Intelligence, Engineering, and Incident Response teams Enhance detection capability through intelligence sharing and tool optimisation Align processes to strengthen overall security operations effectiveness Strategic Contribution Identify opportunities to enhance MSSP services and capabilities Monitor emerging threats, technologies, and industry trends Ensure compliance with regulatory standards and internal frameworks Skills & Experience Essential 7+ years in Security Operations, including 3-4 years in a senior/lead SOC role Strong hands-on experience with: SIEM (e.g. Microsoft Sentinel, CrowdStrike) EDR/XDR (e.g. CrowdStrike, Microsoft Defender, Carbon Black) SOAR and threat intelligence platforms Proven expertise in threat hunting and incident response Experience developing and tuning detection rules in multi-tenant environments Strong automation skills to improve SOC efficiency Excellent client-facing and communication skills Desirable Certifications such as CISSP, GIAC (GCIH, GCIA, GREM), SC-200 or SC-300 Experience in cloud security operations Background in MSSP or consulting environments Familiarity with frameworks such as NIST, ISO27001, or ITIL Key Competencies Strong technical depth with the ability to simplify complex concepts Excellent analytical and problem-solving skills under pressure Confident communicator with strong stakeholder engagement skills Collaborative leadership style with a focus on mentoring and development Ability to manage multiple priorities in a fast-paced SOC environment
AJ Bell
Senior Information Security Analyst
AJ Bell Manchester, Lancashire
Job Description We're recruiting a Senior Information Security Analyst to support the Chief Information Security Officer in protecting and enhancing the organisation's security posture across Technology Services. This is a hands-on, operational role focused on monitoring, analysing and responding to security threats, while driving continuous improvement across our security operations capability. You'll play a key role in incident response, threat intelligence, vulnerability management and ensuring effective use of our security tools and processes to reduce risk across the technology estate. Key responsibilities Monitor, triage and respond to security alerts and events, ensuring effective prioritisation based on risk and impact Act as a first responder for security incidents, including participation in on-call support Analyse security data and alerts to identify trends, risks and potential threats Act as an escalation point for information security queries from colleagues and service delivery teams Support and coordinate patch management activities, validating effectiveness through vulnerability scanning Oversee and operate key security technologies, including SIEM, email and web gateways, and endpoint protection tools Monitor external threat intelligence sources and assess relevance to the organisation Produce and report on security metrics, KPIs and operational performance Technical expertise Good understanding of information security principles, risk management and the threat landscape Experience of operating and monitoring security tooling, including SIEM, endpoint protection, and email/web security solutions Ability to proactively conduct threat hunting activities and develop or enhance detection analytics to improve identification of malicious activity Awareness of cloud security controls and standards Experience of managing enterprise systems, including Microsoft Active Directory, Windows and Linux Knowledge of network security technologies, including proxies, end point security tools and data loss prevention controls are highly advantageous Skills and experience Experience working within recognised information security frameworks (e.g. ISO27001, NIST) Proven experience in an information security role, preferably within financial services or e-commerce Strong analytical capability, with the ability to interpret data and support decision-making Ability to take ownership of tasks and deliver through to completion Confident in providing challenge to improve security outcomes Effective communication skills, both written and verbal Well organised, with strong attention to detail and the ability to manage competing priorities Demonstrates a commitment to continuous professional development (e.g. CISSP or equivalent) About AJ Bell AJ Bell is one of the UK's fastest-growing investment platform businesses, providing award-winning solutions for everyone, from professional financial advisers to first-time investors. Today, over 644,000 customers trust us to manage more than £103.3 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures. We're proud to be recognised as one of the UK's Best 100 Companies to Work For, for six consecutive years, and a Great Place to Work in 2025 and 2026 a reflection of our supportive and collaborative culture. What we offer 26 days holiday, increasing with service + buy/sell scheme + bank holidays 7% Pension with matched contributions Discretionary bonus scheme Share schemes (including free shares and BAYE) Health Cash Plan and discounted private healthcare Free onsite gym Enhanced family leave (subject to qualifying criteria) Travel and bike loan schemes Employee Assistance Programme Life at AJ Bell Regular social events including summer and Christmas parties Learning and development opportunities tailored to you Casual dress code Friendly, supportive team environment Our ways of working We offer hybrid working, with a minimum of 50% of your working time per month spent in the office. For new starters, there's an initial period of full-time office working to help you settle in and build relationships. Inclusion & diversity We're committed to creating an inclusive environment where everyone feels respected and able to be themselves at work. We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential.
May 03, 2026
Full time
Job Description We're recruiting a Senior Information Security Analyst to support the Chief Information Security Officer in protecting and enhancing the organisation's security posture across Technology Services. This is a hands-on, operational role focused on monitoring, analysing and responding to security threats, while driving continuous improvement across our security operations capability. You'll play a key role in incident response, threat intelligence, vulnerability management and ensuring effective use of our security tools and processes to reduce risk across the technology estate. Key responsibilities Monitor, triage and respond to security alerts and events, ensuring effective prioritisation based on risk and impact Act as a first responder for security incidents, including participation in on-call support Analyse security data and alerts to identify trends, risks and potential threats Act as an escalation point for information security queries from colleagues and service delivery teams Support and coordinate patch management activities, validating effectiveness through vulnerability scanning Oversee and operate key security technologies, including SIEM, email and web gateways, and endpoint protection tools Monitor external threat intelligence sources and assess relevance to the organisation Produce and report on security metrics, KPIs and operational performance Technical expertise Good understanding of information security principles, risk management and the threat landscape Experience of operating and monitoring security tooling, including SIEM, endpoint protection, and email/web security solutions Ability to proactively conduct threat hunting activities and develop or enhance detection analytics to improve identification of malicious activity Awareness of cloud security controls and standards Experience of managing enterprise systems, including Microsoft Active Directory, Windows and Linux Knowledge of network security technologies, including proxies, end point security tools and data loss prevention controls are highly advantageous Skills and experience Experience working within recognised information security frameworks (e.g. ISO27001, NIST) Proven experience in an information security role, preferably within financial services or e-commerce Strong analytical capability, with the ability to interpret data and support decision-making Ability to take ownership of tasks and deliver through to completion Confident in providing challenge to improve security outcomes Effective communication skills, both written and verbal Well organised, with strong attention to detail and the ability to manage competing priorities Demonstrates a commitment to continuous professional development (e.g. CISSP or equivalent) About AJ Bell AJ Bell is one of the UK's fastest-growing investment platform businesses, providing award-winning solutions for everyone, from professional financial advisers to first-time investors. Today, over 644,000 customers trust us to manage more than £103.3 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures. We're proud to be recognised as one of the UK's Best 100 Companies to Work For, for six consecutive years, and a Great Place to Work in 2025 and 2026 a reflection of our supportive and collaborative culture. What we offer 26 days holiday, increasing with service + buy/sell scheme + bank holidays 7% Pension with matched contributions Discretionary bonus scheme Share schemes (including free shares and BAYE) Health Cash Plan and discounted private healthcare Free onsite gym Enhanced family leave (subject to qualifying criteria) Travel and bike loan schemes Employee Assistance Programme Life at AJ Bell Regular social events including summer and Christmas parties Learning and development opportunities tailored to you Casual dress code Friendly, supportive team environment Our ways of working We offer hybrid working, with a minimum of 50% of your working time per month spent in the office. For new starters, there's an initial period of full-time office working to help you settle in and build relationships. Inclusion & diversity We're committed to creating an inclusive environment where everyone feels respected and able to be themselves at work. We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential.

Modal Window

  • Home
  • Contact
  • About Us
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • Facebook
  • Twitter
  • Google Plus
  • LinkedIn
Parent and Partner sites: IT Job Board | Jobs Near Me | RightTalent.co.uk | Quantity Surveyor jobs | Building Surveyor jobs | Construction Recruitment | Talent Recruiter | Construction Job Board | Property jobs | myJobsnearme.com | Jobs near me
© 2008-2026 Jobsite Jobs | Designed by Web Design Agency