Principal SOC Analyst(L3)
Location: Stockholm
Job type: Permanent Full-Time
Salary: Negotiable
Minimum experience required: 5+ years in an equivalent role
About Us
Integrity360 is one of Europe's leading cyber security specialists operating from office locations spread out across Europe, providing a comprehensive range of professional, support and managed cyber security services for our 300+ clients. With four top-class Security Operation Centers, we offer a complete end-to-end security services covering our clients' security from every angle. Our services include Managed Security, Cyber Security Testing, Incident Response, Security Integration, PCI Compliance and Cyber Risk & Assurance services.
What sets Integrity360 apart is our excellent team of people that drive the business forward. The company was founded with a focus on technical expertise and that philosophy remains today. The skills and experience in our company are some of the greatest in the industry and clients remain with Integrity360 because they can rely on and trust us to go above and beyond to ensure their needs are met. Listed multiple times on Gartner Market Guides for Managed Security Services.
Job Role / Responsibilities
In this role you will be expected to analyse a range of alerts and incidents, identifying threats and attacks performed by Threat Actors ranging from Cyber criminals, ATPs, and Nation States. You will leverage various threat intelligence streams to enhance your understanding of emerging threats and vulnerabilities used by Threat Actors, providing customers with your insight and experience.
You will act as a lead investigator and escalation point for security incidents and alerts analysed by the CSOC team, providing keen insights and taking action to protect customer environments. A successful principal analyst will also develop, edit, and deliver security reports to enterprise-level customers.
The role requires flexibility and the ability to work extra hours when the business calls for it, and has an on-call component. A good knowledge of Information Security is required for this role. Proactive client services, such as compromise assessments and evaluating and recommending tools and technology for incident response are also in scope. Demonstration of a strong comprehension of malware, emerging threats and adversary TTPs will be critical to success.
Primary Duties/Responsibilities include:
Deliver keen insights when reviewing security events, evaluating the risk they present to the customer, in the context of the environment they are in.
Perform hypothesis led threat hunting to identify anomalies in customer environments.
Perform in-depth investigation on confirmed security incidents, leading incidents when required and mentoring other CSOC analysts to ensure continual improvement of the team.
Identify, contain, and eradicate threats in the environment. Engaging with the i360 Incident Response team when the scope of incident has gone outside of CSOC capacity.
Perform analysis of malicious code and activity.
Continually assess, review, and tune security tooling to reduce false positives and improve the quality of detections raised by i360 security monitoring tools.
Drive our incident response process, ensuring incident reports cover the complete details of a given incident, including evidence of investigation and providing reports to incident stakeholders.
Responsible for generating reports to the partners and stakeholders showing internal threat landscape.
Continually develop, improve, and refine processes, documentation, and SOPs.
24 x 7 on-call support on a rota basis may form part of the role.
Travel in office may be required from time to time to facilitate training and development individually, and for the wider CSOC team.
Desired Skills
Experience working with security event detection tools like IPS, SIEM, DLP, Anti-virus, etc.
Proven ability to perform advanced analysis, correlating alerts across the network, host, and identity plane, applying personal insights and threat intelligence knowledge to your overall assessment.
Assist in Incident Response investigations, in the event of a major incident, escalating to our Incident Response function should the incident scope go outside of CSOC support. Support and develop security analysts during incident engagements.
Experience in performing analysis on network pcaps and documents for malicious activity or codes.
Fundamental knowledge in Networks and Network Security.
Understanding of Network infrastructure hardware and protocols (TCP/IP, switches, bridges, routers, proxy servers, VPN concentrators).
Understanding of Security protocols (IPSec), and encryption technologies (3DES, AES, SHA2, TLS).
Understanding of basic security principles such as Confidentiality, Availability, Integrity.
Familiar with security best practices.
A process of on-going certification for the benefit of the business and for self-development is encouraged.
Review the adequacy of the security controls and their ability to protect the information system and its information.
Experience with SIEM and SOAR solutions such as; Splunk, Sentinel, Swimlane is a plus.
Experience with EDR/XDR solutions such as; Defender for Endpoint, Crowdstrike, Rapid7 is a plus.
Strong Microsoft Word & Microsoft Excel skills required.
Excellent command of both written and spoken Swedish and English is a must.
Certifications/Qualifications
Any of the following accreditations/certification will be highly beneficial:
Security industry certifications: GSEC, GCIH, GCFA or similar security certifications. CYSA+, SEC+.
2+ years in an Incident Handling role or a CSIRT role.
Ideal candidates will possess a working knowledge of Intrusion Prevention System (IPS), SIEM, SOAR & DLP.
Experience working with threat hunting tools.
What's in it for you
At Integrity360 we aim to reflect what's important through the benefits we offer. We survey our people regularly and encourage discussions around these tops so we can understand what really makes a difference. Our benefits priorities are physical, mental, and financial wellbeing.
Mental & Physical wellbeing benefits:
Private healthcare provided by Attunda Hälsan.
Health insurance provided by Söderberg and Partners.
Onsite Gym (Kista office).
SEK 5,000.00/month for Friskvårdbidrag, our allowance can be used for Gym memberships, to improve health and more!
Financial wellbeing:
We guarantee that every employee will have their pay reviewed at least once every year, if not more regularly. We aim to pay within the market range for all roles and keep pace with inflation on average.
What we offer:
Twice yearly salary reviews.
6% Contributory Pension.
Income Protection.
Death-in-Service cover.
Other benefits include:
30 days' annual leave and options to carry over 5 days to the next financial year.
Our L&D program, we work with various platforms including Cybrary, Udemy, Preply, Pluralsight, Swift and HTB ensuring our people are up to date with their industry knowledge. Offering opportunities to further upskill and gain industry leading certifications.
•
SE - Stockholms kommun
December 28, 2024
På Alstom förstår vi transportnätverk och vad som rör människor. • Från höghastighetståg, tunnelbanor, monorails och spårvagnar, till nyckelfärdiga system, tjänster, infrastruktur, signalering och digital mobilitet, erbjuder vi våra olika kunder den bredaste portföljen i branschen. • Varje...
SE - Forsmark
December 22, 2024
Specialist inom radiologiska analyser sökes till Forsmarks Kraftgrupp AB • Vill du vara med och säkra Sveriges elförsörjning? Vi söker dig som vet vad du vill och som har drivkraft att utveckla dig! • I Forsmark satsar vi på framtiden och gör mångmiljardinvesteringar i anläggningen för att...
SE - Stockholm
December 29, 2024
Welcome to Warner Bros. • Discovery… the stuff dreams are made of. • Who We Are…When we say, 'the stuff dreams are made of,' we're not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. • Behind WBD's vast portfolio of iconic...
SE - Boden
December 25, 2024
SMS group GmbH SMS group is renowned worldwide for its future-oriented technologies and outstanding service for the metals industry. • In 2023, our team of over 14,400 employees around the world generated sales of more than 3.4 billion euros. • We apply our 150 years of experience and our...
SE - Linköping
December 30, 2024
This is us • Are you passionate about solving problems and delivering next-generation software to enhance the Internet experience? Join a global leader with over 20 years of experience creating software for fiber network operators. Are you looking for a place to see your ideas come to life in...
SE - Karlshamn
December 30, 2024
Site Director • Our story goes back more than 150 years, to the chilly southern coast of Scandinavia. • From our early success in Sweden and Denmark, we've grown into the world's leading specialist producer of plant-based oils, employing more than 4,000 people all across the globe. •...
Vanderbilt University Medical Center
SE - Stockholms kommun
December 30, 2024
Discover Vanderbilt University Medical Center: • Located in Nashville, Tennessee, and operating at a global crossroads of teaching, discovery, and patient care, VUMC is a community of diverse individuals who come to work each day with the simple aim of changing the world. • It is a place...
SE - Stockholms kommun
December 28, 2024
Head of Security Operations to Saab Surveillance • Apply locations: • Stockholm - Järfälla, Göteborg - Solhusgatan 10 • Time type: • Full time • Posted on: • Posted 2 Days Ago • Time left to apply: • End Date: • January 12, 2025 (21 days left to apply)...
SE - Solna kommun
December 26, 2024
Specialistläkare/biträdande överläkare/överläkare i radiologi till Nuklearmedicin, timanställning • Karolinska Universitetssjukhuset, ME Nuklearmedicin och Sjukhusfysik • Är du radiolog med intresse för nuklearmedicin? Här finns möjlighet att vara med och forma framtidens diagnostik och...
SE - Malmö
December 30, 2024
Marketing Automation Developer • THE OPPORTUNITY • Are you passionate about crafting personalized, data-driven customer journeys? Do you love the challenge of turning complex technical requirements into seamless, automated marketing processes? Do you thrive in a dynamic, fast-paced...
SE - Stockholms kommun
December 30, 2024
Mentimeter is an engagement tool with a clear goal in mind. • To turn presentations into conversations. • Through real-time interactivity and clear visualizations, we get people to participate, engage and become more productive. • Transforming all those passive meetings, airless...
Dassault Systemes Deutschland GmbH
SE - Not Specified
December 28, 2024
Dassault Systèmes is the second largest software manufacturer in Europe and has been a dynamically growing, innovative company since 1981. • As a Solution Architect (m/f/d) within our Nordics services organization your primary responsibility will be the design and architecting of technical...
Dassault Systemes Deutschland GmbH
SE - Not Specified
December 28, 2024
Dassault Systèmes is the second largest software manufacturer in Europe and has been a dynamically growing, innovative company since 1981. • As a Solution Architect (m/f/d) within our Nordics services organization, your primary responsibility will be the design and architecting of technical...
SE - Kiruna
December 28, 2024
Talent Acquisition Partner - visstid • Apply locations: Malmberget, Luleå, Kiruna • Time type: Full time • Posted on: Posted 17 Days Ago • Job requisition id: JR102961 • Job Posting End Date: 2025-01-05 • Det senaste året har vi byggt upp ett nytt Talent...
SE - Göteborg
December 30, 2024
What are we looking for • At Cosentino (***) we are looking for a City Center Manager to join our City Center located in Gothenburg. The City Centers are an example of Cosentino's total commitment to the AD community. • The City Center is the epicenter of Cosentino's commercial model, and...
SE - Göteborg
December 26, 2024
The University of Gothenburg tackles society's challenges with diverse knowledge. • 56 000 students and 6 600 employees make the university a large and inspiring place to work and study. • Strong research and attractive study programmes attract researchers and students from around the...
SE - Stockholms kommun
December 26, 2024
Bergenstråhle är ett kunskapsbolag som kombinerar strategi, juridik och finans på ett naturligt sätt i vår rådgivning och konsultuppdrag. • Med immateriella tillgångar och rättigheter som företagens mest värdefulla egendom, har vi på Bergenstråhle en viktig och rolig uppgift att hjälpa våra...
SIBA Fastigheter Aktiebolag Göteborg
SE - Göteborg
December 30, 2024
Anställningsform: • Tillsvidare- eller tidsbegränsad anställning • Kvalifikationer • Utvecklingschef - erfarenhet efterfrågas • Körkort • B - Egen bil krävs • Operativt ansvarig för utveckling och förvärv till SIBA Fastigheter • Har du en gedigen bakgrund inom...
SE - Göteborgs kommun
December 26, 2024
Overview The Spotfire visual data science product suite delivers immersive, intelligent, real-time insights through a fully-governed scalable analytics platform. • Users pose, enrich, and twist their questions. • They share their results. • They want to know: • Which is the best...