Skip to main content

Associate Cyber Security Analyst

  • Monitor and correlate log sources in Splunk SIEM through custom SPL queries mapped to MITRE ATT&CK techniques, detecting and escalating security incidents across critical airport infrastructure

  • Scan the organisation-wide application inventory to identify vulnerable versions, correlating them against published security advisories and classifying them by exploitability and criticality before reporting them to the owning teams for patching

  • Analyse EDR telemetry in Cisco AMP during alert investigations, applying host isolation and IOC-based blocking

  • Analyse email headers, attachments and embedded URLs through Cisco ESA and Beamsec, pushing confirmed IOCs to organisation-wide blocking to detect and neutralise phishing and BEC attempts