Senior Technical Analyst (Cyber)
CurrentWorking in the Technical Operations - Cyber Security team, this role involves improving the cyber posture of the organisation through the technical implementation of various controls, with a large portion of the position related to investigating cyber alerts through numerous channels, such as Microsoft Defender for Endpoint and Sophos. I am also the SME in Removable Media Access Control, with almost a dozen successful customer deployments of CoSoSys Endpoint Protector, and have mentored two junior members of staff. While being focused on the technical side of Cyber, we work closely with the Cyber Governance team when it comes to developing policies and procedures, and I have written SOPs and guidance documents for use by other teams within Digital Data & Technology.During my time in the Cyber team, I have achieved ISC2 Certified in Cybersecurity (CC), and am working towards CompTIA Security+ and following the ISC2 CC, SSCP certification also.Main roles and responsibilities:- Triage, investigate and remediate alerts- Perform regular threat hunting, blocking any IoCs found- Liaise with customer digital teams around implementing appropriate RMAC rulesets- Maintain regular patching schedules- Write PowerShell scripts to automate deployment of software packages- Monitor a general queue of user requests relating to products maintained by Tech Ops - CyberSoftware used:- Microsoft Defender for Endpoint- Sophos Central (Intercept X / XDR)- CoSoSys Endpoint Protector- Censornet Web Security- ManageEngine Patch Manager Plus- BeyondTrust Privileged Access Management- Certero Asset Management Studio