SOC Cybersecurity Engineer

Job Description:

Airbus Protect brings together experts in the fields of safety, cybersecurity and sustainability. We deliver expertise to our own group, Airbus but also to external clients.
In any service business, people are key. To be in a position to offer the best-in-class services, Airbus Protect wants to retain, develop and grow its talent pool. 
Airbus Protect’s ambition is to become a market and innovation leader in safety, cybersecurity and sustainability services - a trusted business partner in managing today’s and tomorrow’s business risks, ensuring resilience and co-create a better tomorrow.
In this context, the Cyber Defence Centre in Spain is seeking to hire a SOC Cybersecurity Engineer. 
The Cyber Defence Centre  provides services in order to:
¤ Prevent a cyber risk (Consulting & audits)
¤ Detect and react on security incidents (Security Operation Centre - SOC)
¤ Respond of an attack (Computer Security Incident Response Team - CSIRT)
 
 
Position & Responsibility
Within the SOC of Airbus Protect and under the responsibility of the SOC Manager, the SOC Cybersecurity Engineer works as part of a team in charge of the Security tools and the Security monitoring. 
Main missions of the Cybersecurity Engineer:
           - Management and maintenance of the Security tools and systems.
           - Work with the SOC Analysts monitoring multiple security devices, including SIEM, IDS/IPS etc, ensuring that all customer SLAs are met.
           - Work in the development and testing of Security alerts.
You will be required to work as part of the SOC team ensuring all SOC operational tasks are completed on time and work tickets updated/closed with satisfactory technical details included.
The Cybersecurity Engineer will be comfortable at a technical level, often being required to attend technical workshops and customer briefings/service reviews.
The SOC Cybersecurity Engineer works in normal business hours and in stand-by shifts too, however It can be required to perform maintenance out of normal service hours.
 
Tasks and Accountabilities
- Ensure the availability of the Security systems.
- Support the Security Tools Administration.
- Anomaly detection.
- Decrease of false positives.
- Track trends for metrics and reporting.
- Perform alerts investigations, adding context and data from multiple tools and data sources.
- When required perform initial triage/identification of ‘Events of Interest’ using a range of monitoring and detection tools.
- Ensure that all events, events of interest, exceptions & incidents are responded to in accordance with established SOC work instructions, including remedial action/recommendations.
- Maintenance of SOC work instructions - reviews & amendments.
- Produce reports (as per templates) & trending analysis as requested by SOC Manager or key stakeholders.
- Present & review reports to internal & external key stakeholders
- Participate in recurrent meetings with the customer as the technical referee.
- Support the SOC Manager for the reporting of the activity.
 
Requirements
 - Engineer diploma with Cyber security training or equivalence after a solid experience in the domain of Cyber defence.
- Splunk Certifications.
- Security Certifications (CEH, GCIH, GMON...)
- Experience working in a SOC.
- Ticketing systems administration experience.
- Experience with EDR tools.
- TCP/IP Fundamentals
- Wireshark Packet Analysis.
- Experience working with Regular Expressions.
- Experience developing SIEM correlation rules.
- Eligibility to obtain Security Clearance.
- It will be necessary to get the Blue Team training and Certification provided. We provide training on the tools and processes for the success of your mission.
Due to the nature of SOC operations, there is the possibility that the SOC Engineer will be required to work in alternate stand-by shifts, including week-ends and nights.  
The candidates must have a valid National Security Clearance (HPS) or be eligible to get it.

This job requires an awareness of any potential compliance risks and a commitment to act with integrity, as the foundation for the Company’s success, reputation and sustainable growth.

Company:

Airbus Defence and Space SAU

Employment Type:

Permanent

-------

Experience Level:

Professional

Job Family:

Cyber Security

By submitting your CV or application you are consenting to Airbus using and storing information about you for monitoring purposes relating to your application or future employment. This information will only be used by Airbus.
Airbus is committed to achieving workforce diversity and creating an inclusive working environment. We welcome all applications irrespective of social and cultural background, age, gender, disability, sexual orientation or religious belief.

Airbus is, and always has been, committed to equal opportunities for all. As such, we will never ask for any type of monetary exchange in the frame of a recruitment process. Any impersonation of Airbus to do so should be reported to emsom@airbus.com.

At Airbus, we support you to work, connect and collaborate more easily and flexibly. Wherever possible, we foster flexible working arrangements to stimulate innovative thinking.

Organisation: 
Airbus