UK CTAC Analyst Tier 2 at DXC Technology

Farnborough, England, United Kingdom

DXC Technology Logo
Not SpecifiedCompensation
Mid-level (3 to 4 years)Experience Level
Full TimeJob Type
NoVisa
Cybersecurity, TechnologyIndustries

Requirements

  • Sole UK national/British citizen and resided in the UK for the past 5 years to meet security clearance requirements
  • Ability to work onsite in Erskine or Farnborough and cover 12-hour rotational shift (4 on, 4 off) pattern
  • Understands advanced networking concepts, including IP addressing, basic network protocols, and network traffic flow
  • Advanced knowledge of Windows and Linux operating environments, including standard commands, file systems, and user authentication mechanisms
  • Competence in using SIEM solutions (e.g., ArcSight, Azure Sentinel) for monitoring and log analysis; some exposure to basic XDR platforms
  • Proficient knowledge of Kusto Query Language (KQL) to search and filter logs effectively
  • Familiar with open-source intelligence (OSINT) techniques to identify potential threats and gather information
  • Able to communicate clearly and efficiently with team members and stakeholders, both internally and externally, under direction from senior analysts
  • Able to communicate simple technical issues to non-technical individuals in a clear and understandable way
  • Able to create concise, structured reports that outline findings from preliminary investigations

Responsibilities

  • Conduct escalated triage and analysis on security events identified by Tier 1 Analysts, determining threat severity and advising on initial response actions
  • Apply expertise in SIEM solutions utilizing Kusto Query Language (KQL) to perform log analysis, event correlation, and thorough documentation of security incidents
  • Identify and escalate critical threats to Tier 3 Analysts with detailed analysis for further action, ensuring rapid response and adherence to service level objectives (SLOs)
  • Investigate potential security incidents by conducting deeper analysis on correlated events and identifying patterns or anomalies that may indicate suspicious or malicious activity
  • Use OSINT (Open-Source Intelligence) to enrich contextual data and enhance detection capabilities, contributing to a proactive stance on emerging threats
  • Monitor the threat landscape and document findings on evolving threat vectors, sharing relevant insights with CTAC teams to enhance overall situational awareness
  • Follow established incident response playbooks, providing feedback for enhancements and suggesting updates to streamline CTAC processes and improve threat response times
  • Coordinate with Tier 3 Analysts and management to refine detection and response workflows, contributing to continuous SOC maturity
  • Collaborate with Tier 3 Analysts on tuning SIEM and detection tools to reduce false positives and improve alert fidelity, submitting tuning requests and testing configurations when necessary
  • Identify gaps in current detection content and work with Senior Analysts to develop and validate new detection rules and use cases tailored to the organization’s threat profile
  • Act as a mentor to Tier 1 Analysts, offering guidance on triage and analysis techniques and facilitating on-the-job training to elevate their technical skills and operational efficiency
  • Assist in training sessions and knowledge-sharing activities, providing feedback on areas for growth and contributing to a supportive learning environment within the SOC

Skills

KQL
SIEM
OSINT
Log Analysis
Event Correlation
Incident Triage
Threat Analysis
Incident Response

DXC Technology

IT services for enterprise modernization and management

About DXC Technology

DXC Technology provides IT services to large enterprises, focusing on modernizing their critical systems and operations. The company uses the Enterprise Technology Stack to enhance IT infrastructure, optimize data architectures, and ensure security across various cloud environments, including public, private, and hybrid. DXC operates on a contractual basis, offering consulting, system integration, and managed services to help clients improve their IT operations. What sets DXC apart from competitors is its strong commitment to innovation, sustainability, and corporate responsibility, which has earned it recognition as one of the Most Responsible Companies. The goal of DXC Technology is to be a trusted partner for enterprises, helping them achieve scalable and secure IT solutions while promoting inclusion and diversity within its workforce.

McLean, VirginiaHeadquarters
2017Year Founded
$14.6MTotal Funding
IPOCompany Stage
Consulting, Enterprise SoftwareIndustries
10,001+Employees

Risks

Emerging IT service providers offer cost-effective solutions, threatening DXC's market share.
Rapid technological changes may outpace DXC's innovation, risking service obsolescence.
Economic downturns could reduce IT spending, impacting DXC's long-term contract revenue.

Differentiation

DXC Technology is a Fortune 500 global IT services leader.
The company specializes in modernizing mission-critical systems for large enterprises.
DXC's Enterprise Technology Stack ensures security and scalability across cloud environments.

Upsides

DXC is recognized as a leader in the 2024 Magic Quadrant for Outsourced Digital Workplace Services.
The Quercus AI platform collaboration with Ferrovial and Microsoft enhances DXC's innovation capabilities.
DXC's role in transforming Italy's healthcare sector showcases its expertise in digital transformation.

Land your dream remote job 3x faster with AI