Design and implement incident response playbooks and automation.
Implement, develop, and maintain Allwyn Lottery Solution’s security platforms and assist other engineering and platform teams to build security into their platforms and projects.
Select and implement technical security controls and platforms.
Provide security SME support to IT infrastructure and development projects.
Participate in security product evaluations and carry out technical evaluations and POCs for security tools used within Allwyn LS.
Create design documentation and plan the implementation and integration of new security products with existing platforms and processes.
Develop and continually improve security automation and orchestration capabilities, and the effective integration between platforms.
Develop, update, and maintain security governance documentation such as policies, standards, and baselines.
Collaborate with external teams to ensure that the SIEM platform maintains access to all systems and data necessary to perform their function.
Manage security tooling and alerts.
Manage the remediation of outstanding vulnerabilities.
Act as the primary escalation point to other Security Analysts monitoring the Security Information and Event Management (SIEM) System & provide an initial investigation of security incidents. Take an active part in the containment of incidents, even after they are escalated.
Act as a point of contact regarding security advisory, best practices and security concerns coming from other teams. Promote security awareness and education.
Keep up to date with emerging cyber threats.
Requirements
Experience securing cloud applications and services.
Experience with SIEM tools - Splunk, Rapid7, ELK, QRadar, etc.
A comprehensive knowledge of standard security products and technologies is required.
Windows and Linux operating systems and system administration.
Command line interfaces and scripting.
Competency with scripting is required, especially Lambda, Python, Bash or PowerShell.
Infrastructure as Code - Terraform.
Ability to triage, investigate, analyse, and contain information security events.
Analytical and problem-solving skills, with an ability to assimilate, analyse and correlate large amounts of data from various networks, operating systems, applications, security devices, logs, and alerts.
Hands-on experience with centrally managed information security tools such as Anti-Virus, EDR, SIEM, or SOAR.
Nice to have
Experience with security services in the AWS environment.
Working with a DevSecOps mindset.
Any of the following certs: AWS Cloud Practitioner, AWS Security, AWS Solutions Architect, AWS DevOps Engineer, BTL1, CompTIA Security+ or equivalent, would be advantageous.
Understanding of incident response and digital forensic techniques would be highly appreciated.
Minimum Experience
3+ years of experience in technical IT or security roles is required.
1+ years of experience in security-focused technical roles is required.
Required Competences
Confident, driven, and dynamic professional
Results orientation
Self-motivated, enthusiastic, positive, and the ultimate team player
Co-Working and Collaboration
Conflict resolution skills
Able to build a trustworthy relationship with internal and external stakeholders
Creating problem-solving approach and analytical skills
Ability to provide constructive feedback
Empathy skills, Communication (Active listening, conflict resolution), Inclusiveness