Security Analyst
Location – Krakow
Why is this job for you:
The Group IT organisation is responsible for aligning IT with the business on the delivery of DS Smith’s strategic priorities. It will do this by building strategic capabilities, enabling transformational efforts and embedding quality in all systems and processes.
As a Security Analyst you will be part of an IT Security Operations team that will work in collaboration with Group IT functions, the third-party Security Operations Centre (SOC) and Computer Security Incident Response Team (CSIRT) to ensure IT and Information security controls are in-place to protect the business against cyber threats.
As a Security Analyst you will be responsible for triage of security incidents, managing, root causing and remediating incidents. Briefing up to line management and other stakeholders on any incident escalation or incidents which require wider support.
Building business relationships and trust in this role is key in order to support the business in maturing it’s IT Security Operations and Incident Response capability.
You will be expected to provide advice and guidance to a range of information and cyber security initiatives. This will include documenting and recording processes, ways of working, ‘play books’ and other improvement activities. You will be expected to fully document all activities in the ServiceNow ticketing system and to undertake a range of daily checks in key security tooling.
You will support the end-to-end management, communication, escalation, investigation and resolution of all IT and Information Security incidents. The role will work closely with the wider Group IT and Group functions to drive continuous improvement in technical and process controls as they relate to DS Smith’s information assets.
You will:
Monitor security events, alerts, and logs across the organisation's infrastructure using advanced tools such as the Microsoft Defender suite to detect potential threats and vulnerabilities in real-time
Investigate and triage security incidents, leveraging Microsoft Defender for Endpoint, Microsoft Defender for Identity, and related components to perform detailed forensic analysis and root cause determination
Lead incident response activities, including containment, eradication, and recovery efforts, utilising Microsoft Defender's automation and orchestration capabilities to minimize downtime and mitigate risks
Collaborate with cross-functional teams, including IT operations and compliance, to implement security controls and remediation strategies based on incident findings
Document incident details, response actions, and lessons learned in compliance with organisational policies and regulatory requirements, contributing to post-incident reports and knowledge base updates
Maintain and optimize endpoint security postures by utilising endpoint management platforms such as Tanium for asset inventory, patch management, and rapid deployment of security measures
Stay abreast of emerging cyber threats and best practices, recommending enhancements to the security toolkit and processes to strengthen overall defence mechanisms
Identify and Triage Security Incidents and Tasks within Service Now, Group Mailbox or any other notification mechanism following the advice of the Head of IT Security Operations and the Senior Security Analyst
Bring incidents to successful conclusions. Actively work with partners, suppliers and the wider IT community to coordinate and support any security or cyber incidents response activities
Prepare and document standard operating procedures and protocols (Playbooks) to support Security Operations
Build and maintain relationships with third party Security Operations Centre (SOC)
Ensuring information security compliance with policies, standards and industry best practice
Provide advice and guidance to local IT and users on IT Security
Understand critical assets and data for local sites and work to ensure they are effectively protected
Create, perform, update daily checks
You have:
2-3 years of experience as Security Incident Response Analyst with significant expertise in Incident Response, Threat mitigations and Incident remediation using Microsoft Defender XDR threat protection
Familiar with Microsoft Security toolset
Experience managing multiple tasks simultaneously and meeting established deadlines
Knowledge of securing network technologies, client, and server operating systems
Excellent interpersonal, communication, and presentation skills, including formal report writing experience
Significant understanding of security across - policy, culture, incident response. Have practical work-based experience in all of these areas
Experience of working as part of a team and in actively contributing to overall team deliverables
Be able to design processes and procedures, and take the lead on embedding these within security operations or across the business
Proficiency in a wide range of information security technologies including e-mail protection, active directory, end point security and a knowledge of the Microsoft security stack M365 Defender, Azure AD
Ability to take responsibility and make sound decisions on security incident remediation
Understanding and application of Cyber security frameworks e.g. NIST, ISO-27001 and Information Security Management System – ISMS would be beneficial
Highly desirable a professional certifications and or membership in professional associations is (e.g. CISSP, ISO27000 certification, CISM, CEH, NCSC, CCP)
IT Security certification such as Microsoft Certified: Security Operations Analyst Associate are beneficial but not essential
Fluency in English