We have been made aware of a number of scams where fraudsters are claiming to represent our organisation or organisations we work with. Please click here to find out more details and what to do if you are contacted.

menu

Accessibility tools

DFIR Analyst

Remote

  1. Full time

About the job

The Digital Forensics and Incident Response Analyst role will sit within our Security Operations Department. This is a hands-on technical role.

We are looking for someone with a technical background and experience in incident response with an emphasis on cloud response. Someone with excellent documentation skills who is a team player, working closely with their peers. This person will be part of the main escalation point for our SOC and an active member of purple team activities.

The right candidate will be able to work alongside senior stakeholders across the business and represent security operations with the technology risk teams. When not responding to and managing incidents, you will be expected to take part in threat hunting, supporting other investigations and driving post incident review activities. The candidate will also support other initiatives such as constant reviews of processes and procedures, developing new playbooks, running business-wide tabletop sessions (including extinction level attacks) and assessing our overall digital forensic and incident response maturity levels.

Being able to distil technical information to non-technical members of Admiral is important. The successful candidate should not be afraid to question what is being presented to them, constantly searching for answers to “why” something has happened and persisting with through resolution to learn as a business.

Essential Skills

  • 2+ years of experience conducting incident response and forensic investigations.
  • Experience with incidents in the cloud (Azure and/or GCP).
  • Hands-on experience with proxies, load balancers, virtual machines, containers, and/or serverless technologies.
  • Experience with cloud-native security capabilities and features (e.g., GuardDuty, Sentinel, CloudTrail etc.), common enterprise security tools (SIEM, EDR, etc), and cloud-specific security tools.
  • Proficient use of Linux, MacOS, and Windows Operating System tools (such as curl, wget, nslookup, etc).
  • Practical programming knowledge or experience in writing scripts in Python, PowerShell, Java, etc.
  • Broad understanding of networking and common enterprise technologies.
  • A demonstrable understanding of the Cyber Kill Chain, MITRE ATT&CK and other information security defence and intelligence frameworks.
  • Ability to support business objectives, work with cross-functional teams and support third party responses.

While you may not have all the relevant experience above, if you are proactive and eager to learn we would love to hear from you!

Admiral: Where You Can

We take pride in being a diverse and inclusive business. It's a place where you can Be You, and show up as you are. We’re committed to fostering a people-first culture where everyone is accepted, supported, and empowered to be brilliant. You can, Grow And Progress at a pace and direction that suits you, Make A Difference for our customers and each other, and Share in Our Future with all colleagues eligible for up to £3,600 of free shares each year after one year of service.

Everyone receives 33 days holiday (including bank holidays) when they join us, increasing the longer you stay with us, up to a maximum of 38 days (including bank holidays). You also have the option to buy or sell up to an additional five days of annual leave.

We’re proud of our people-first culture. In fact, we've been recognised as a Great Place to Work for Women, a Great Place to Work for Wellbeing, and an overall Great Place to Work for over 25 years! We’re fully committed to making sure your progression is not slowed or halted by barriers related to race, gender, age, sexuality or any of the protected characteristics.

Our fantastic benefits make sure our colleagues have a great work-life balance; You can view some of our other key benefits here.

#LI-CS1

  1. Full time
  2. Admiral Tech

__jobinformationwidget.freetext.LocationText__

Remote

Our Achievements

colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop


colleags at a laptop
jobs

Related jobs

Risk and Governance Manager (12 Month FTC)

Salary

Location

Hybrid

Job Type

Full time

Location

Hybrid

Brand

Admiral Group

Department

Corporate Governance

Office address

Tŷ Admiral, David Street, Cardiff, CF10 2EH

Description

Risk & Governance Manager (12 month FTC) We are delighted to offer an exciting opportunity to join the Admiral Risk team on a 12 month Fixed Term Contract basis.  This role is central to nurturing

Reference

11014

Expiry Date

01 Jan 0001

Helen Hunt

Vacancy managed by

Helen Hunt
Helen Hunt

Vacancy managed by

Helen Hunt
View Shortlist
Senior Regulatory Advice Manager

Salary

Location

Cardiff

Job Type

Full time

Location

Cardiff

Brand

Admiral Group

Department

Corporate Governance, Operational Support

Office address

Tŷ Admiral, David Street, Cardiff, CF10 2EH

Description

(This is a hybrid role, and it requires travel to our Cardiff office regularly) Senior Regulatory Advice Manager  We are seeking a Senior Regulatory Advice Manager to join our team in Customer a

Reference

10537

Expiry Date

01 Jan 0001

Helen Hunt

Vacancy managed by

Helen Hunt
Helen Hunt

Vacancy managed by

Helen Hunt
View Shortlist
Vulnerable Customer Manager

Salary

Location

Cardiff

Job Type

Full time

Location

Cardiff

Brand

Admiral Group

Department

Corporate Governance

Office address

Tŷ Admiral, David Street, Cardiff, CF10 2EH

Description

(This is a hybrid role, and it requires travel to our Cardiff office regularly) Vulnerable Customer Manager  The Vulnerable Customer manager will report into the Vulnerable Customer senior manag

Reference

11068

Expiry Date

01 Jan 0001

Helen Hunt

Vacancy managed by

Helen Hunt
Helen Hunt

Vacancy managed by

Helen Hunt
View Shortlist

Our Benefits

We know our colleagues work hard to serve our customers and keep us innovating, so it’s important to us that they’re well-rewarded.
 
Alongside our competitive pay we also offer a share package, career growth and development opportunities and a whole host of other great benefits!

Explore our benefits below to discover Where You Can

Where You Can Be You

Financial & Mortgage Advice

Financial & Mortgage
Advice

Ecare

24-Hour
Ecare

Cycle to Work Scheme

Cycle to Work
Scheme

Annual Holiday Allowance

Annual Holiday
Allowance

Flexible Working

Flexible
Working

Simply Health

Simply
Health

Private Health Cover

Private Health
Cover

Critical Illness Cover

Critical Illness
Cover

Where You Can Grow & Progress

Learning and Development

Learning and
Development

Educational Sponsorship

Educational
Sponsorship

Accredited Qualifications ILM

Accredited
Qualifications ILM

iLearn

iLearn
Online Learning

Buy a Book Scheme

Buy a Book
Scheme

Developmental Coaching

Developmental
Coaching

Port of Calls

Port of
Calls

Internal Mobility

Internal
Mobility

Where You Can Make a Difference

Groups & Societies

Groups and
Societies

Socials & Team Days Out

Socials and Team
Days Out

Multi Faith / Quiet Rooms

Multi Faith / Quiet
Rooms

Admiral Community Fund

Admiral Community
Fund

Give as You Earn

Give as You
Earn

Awards & Star Lunches

Awards and Star
Lunches

Corporate Social Responsibility

Corporate Social
Responsibility

Impact Hours

Impact
Hours

Where You Can Share In Our Future

Share Schemes

Share
Schemes

Refer a Friend Bonus

Refer a Friend
Bonus

Colleague and Family Discount

Colleague and Family
Insurance Discount

Group Life Assurance

Group Life
Assurance

Pension

Pension
Scheme

Life Event Loan

Life Event
Loan

Tickets to Sponsored Events

Tickets to Sponsored
Events

Tusker

Tusker Salary
Sacrifice

Click here to download our full benefits brochure