About this role
Salary: £45,000 - 73,000 per year
Requirements: Experience in a security operations or similar technical security role, operationally in at least four of the following domains: Security engineering, alert triaging, rule writing, incident response, Digital Forensics and Incident Response (DFIR), threat intelligence and management, vulnerability management, or security control testing.Strong understanding of networking and routing protocols (e.g. TCP/IP) and core services (e.g. DNS, SMTP).Familiarity with cyber defence technologies and tooling, including SIEM solutions, Intrusion Detection & Prevention Systems (ID/PS), threat and vulnerability management platforms, endpoint protection, and firewalls.Highly analytical mindset with the ability to interpret data flows, assess anomalies, and draw meaningful conclusions.Demonstrated ability to investigate complex security issues and propose effective solutions.Excellent verbal and written communication skills, translating cyber security terminology into professional and straightforward language suitable for a global law firm which includes technical and non-technical teams.Genuine passion for continuous learning and development in cybersecurity, staying up to date with the latest developments, trends, and technologies in the field.Bachelors degree in Information Security, Computer Science, Engineering, Technology, or a related field.Industry-recognised certifications such as CISSP, CEH, CISM, or CompTIA Security.Experience working with major cloud service providers (CSPs) technologies, such as Microsoft Azure, Google Cloud Platform (GCP), or Amazon Web Services (AWS).Prior legal firm or professional services firm experience.Practical experience with scripting languages such as Python or PowerShell to support automation and tooling enhancements. Responsibilities: Investigate Level 2 escalated events and alerts that have been detected through Level 1 monitoring activities by our Managed Security Service Provider (MSSP) to identify potential incidents.Assist and advise junior colleagues during investigations where additional experience is required.Conduct initial triage and investigation of confirmed incidents.Perform containment, mitigation, and remediation activities for incidents, ensuring that any required forensic evidence is gathered and documented appropriately throughout the process.Participate in security incident response exercises and contribute to post-exercise reviews.Be part of the Cyber Defence on-call rota, which may require out-of-hours work.Pick up and hand off incident response activities with the rest of our Belfast Cyber Defence team and other teams in different time zones across the globe, as part of our 24-7 follow-the-sun global model.Maintain and improve playbooks and process documentation for Cyber Defence.Ensure documentation reflects current threat landscapes and operational practices.Implement and enhance cyber defence tooling and processes under senior oversight.Develop new detection definitions and use cases for monitoring tools.Mentor junior colleagues to support their professional development and operational effectiveness.Collaborate with other teams, such as Information Security and IT, to implement security controls and raise awareness.Support the Threat and Vulnerability Management team in remediation activities by executing system and configuration changes.Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, and apply this knowledge in daily operations.Provide cyber defence guidance to business stakeholders, translating technical concepts into business language.Assist the Information Security GRC team with client queries and audits from a cyber defence perspective. Technologies: AWSAzureCloudGCPSupportPowerShellPythonRESTSecurityTCP/IPWeb More:
We have an exciting opportunity for a Senior Cyber Defence Analyst to join our Information Security team in Belfast. Weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. We operate a 24-7 follow-the-sun global model, with incident response activities handed off across time zones as needed.
last updated 37 week of 2026