Description
Please Note: Any offer of employment is subject to satisfactory BPSS and SC security clearance which requires 5 years continuous UK address history (typically including no periods of 30 consecutive days or more spent outside of the UK) at the point of application.
The above information relates to a specific client requirement
Our Cyber Practice is a fast-growing community of industry leading experts. The practice covers Assurance, Compliance, Security Operations (SecOps), Offensive Security and Security Research. It is critical that the relevance and quality of the services that we provide is maintained and augmented and that the team members have every opportunity to grow and learn with the organisation.
As part of our Blue Team, you’ll use the latest intelligence and tooling to analyse information systems to ensure effective incident detection and response.
Job Description
An exciting opportunity for technical specialists who are looking to drive SecOps capabilities forward and aid in the development of new and improved Cybersecurity Detection Engineering practices and alerts.
Key responsibilities of the role are summarised below:
Detection engineering - Develop, maintain, and enhance security detection content primarily for the Splunk SIEM, to enable the detection of threats across diverse platforms (e.g. cloud, endpoints, and networks)
Collaborate with the extended security team to identify gaps in detection coverage based on business risks and threats, leading to new alerting
Review and improve existing detection standards and capabilities e.g. by highlighting requirements for additional logging, identifying trends and detection optimisation opportunities
Use analytical platforms to query high volume datasets to identify trends and spot unusual behaviours, indicative of malicious activity
Maintain a robust version control system for detection rules and related scripts, leveraging platforms like GitHub and Jira
Act as a point of escalation for junior analysts, and a point of review for the approval of new detection content
Use frameworks like MITRE ATT&CK to map detection rules and maximise threat coverage
Operate as a technical subject matter expert on client engagements
Provide detailed reports (both verbal and written) to a range of stakeholders, focussed on detection effectiveness and coverage
Participate in alert testing exercises such as Purple Teaming to validate detection efficacy and capabilities
Additional responsibilities requirements may include (client dependent):
Proactive threat hunting and tradecraft development
Monitoring, incident response and playbook development
Change approvals (where applicable)
Collection and interpretation of different sources of threat intelligence and researching emerging threats and TTPs
Vulnerability scanning, management and reporting
Qualifications
The successful candidate should have experience in some of the following areas:
Detection Engineering and Alert Development
Experience with Scripting and Programming – e.g. Python/Bash/c/c++/Java
Core cybersecurity concepts such as network security, cryptography, cloud security, forensics
Understanding of network protocols and how they can be abused by attackers
Up to date knowledge of the most prevalent APTs and their TTPs
Knowledge of common analysis techniques associated with Windows and/or Linux
Don’t worry if you don’t tick every box – we’d still love to hear from you! If you’re excited about the role and think you could make a difference, please get in touch.
What’s In It For You
At Accenture in addition to a competitive basic salary, you will also have an extensive benefits package which includes up to 30 days of vacation per year, private medical insurance and three days leave per year for charitable work of your choice!
Flexibility and mobility are required to deliver this role to deliver the first-class services we are known for.
About Accenture
Accenture is a leading global professional services company that helps the world’s leading organizations build their digital core, optimize their operations, accelerate revenue growth and enhance services—creating tangible value at speed and scale. We are a talent- and innovation-led company with 774,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities. Visit us at www.accenture.com
Accenture provides a broad range of services in strategy and consulting, interactive, technology and operations, with digital capabilities across all these services. With our thought leadership and culture of innovation, we apply industry expertise, diverse skill sets and next-generation technology to each business challenge.
We believe in inclusion and diversity and supporting the whole person. Our core values comprise of Stewardship, Best People, Client Value Creation, One Global Network, Respect for the Individual and Integrity. Year after year, Accenture is recognized worldwide not just for business performance but for inclusion and diversity too.
“Across the globe, one thing is universally true of the people of Accenture: We care deeply about what we do and the impact we have with our clients and with the communities in which we work and live. It is personal to all of us.” – Julie Sweet, Accenture CEO
Equal Employment Opportunity Statement All employment decisions shall be made without regard to age, race, creed, colour, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by applicable law. Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process.
Closing Date for Applications: 28/02/2025
Accenture reserves the right to close the role prior to this date should a suitable applicant be found.
Qualifications
The successful candidate will have experience in several of the following areas:
Threat Hunting
Threat Intelligence
Incident Response
Technical Vulnerability Analysis
Malware Analysis
Digital Forensics
Detection Engineering and Alert Development
Scripting and Programming
Technical Risk Assessment Knowledge
The successful candidate will have knowledge of the following areas:
Core cybersecurity concepts such as network security, cryptography, cloud security, forensics.
Understanding of network protocols and how they can be abused by attackers.
Up to date knowledge of APTs and their TTPs.
Working knowledge of key vulnerabilities and proof of concept exploits.
Knowledge of common analysis techniques associated with Windows and/or Linux.