Requirements
Candidates should have a strong interest in cybersecurity with foundational knowledge of Windows, Linux, networking, and cloud concepts. Experience or familiarity with SIEM platforms, vulnerability scanning, and security operations is highly desirable.
Job Description
About the role
CACI is looking for a Junior Blue Team Analyst to join the Infrastructure Cloud & Security Team in the Technology department, which is CACI’s central IT team.
Key responsibilities
Security Monitoring & Incident Detection Security Monitoring & Incident Detection
- Monitor security alerts and events from Microsoft Sentinel and other security tools.
- Perform initial triage of security incidents and escalate where required.
- Investigate suspicious activity across cloud, network, endpoint and identity platforms.
- Support security incident response and evidence gathering activities.
- Document security incidents, findings and lessons learned.
Threat Detection & Analysis
- Review logs from AWS, Azure, Windows, Linux, Check Point and Cisco platforms.
- Assist in identifying indicators of compromise and malicious behaviour.
- Support development and tuning of SIEM detection rules and alerting.
- Contribute to threat hunting exercises and security investigations.
Vulnerability Management
- Assist with vulnerability scanning and remediation tracking.
- Validate remediation activities completed by infrastructure teams.
- Help identify recurring security weaknesses and improvement opportunities.
- Produce reports on vulnerability trends and remediation progress.
Cloud Security
- Support monitoring of AWS and Azure security controls.
- Review security findings from native cloud security services.
- Assist with implementation of security best practices for cloud workloads.
- Help maintain secure configurations and access controls.
Security Operations
- Assist with identity and access management reviews.
- Support privileged access monitoring and auditing activities.
- Help maintain security documentation, standards and procedures.
- Participate in security testing activities and support remediation efforts.
Compliance & Governance
- Assist in maintaining ISO27001 policies, procedures and evidence.
- Support internal and external audits.
- Help maintain asset inventories and security records.
- Contribute to risk assessments and security reviews.
Collaboration
- Work closely with infrastructure, cloud, networking and support teams.
- Provide security guidance to colleagues where appropriate.
- Participate in security awareness and continuous improvement initiatives.
Skills & experience
Essential Skills & Experience
Technical Knowledge
- Good understanding of Windows and Active Directory.
- Basic understanding of Linux administration.
- Understanding of networking fundamentals including TCP/IP, routing, DNS, VPNs and firewalls.
- Understanding of common cybersecurity concepts, threats and attack techniques.
- Familiarity with cloud concepts in AWS and/or Azure.
- Understanding of authentication, MFA and access control principles.
Security Operations
- Experience using or studying SIEM platforms such as Microsoft Sentinel.
- Understanding of security monitoring and incident management processes.
- Ability to analyse logs and investigate alerts.
- Awareness of vulnerability management practices.
Analytical Skills
- Strong troubleshooting and problem-solving skills.
- Ability to investigate issues methodically.
- Good attention to detail.
- Ability to document findings clearly.
Behavioural Skills
- Desire to build a career in cybersecurity.
- Strong communication and interpersonal skills.
- Ability to work as part of a team.
- Customer-focused approach.
- Willingness to learn new technologies and security techniques.
Desirable Skills & Experience
- Experience with Microsoft Sentinel.
- Exposure to AWS security services.
- Exposure to Azure security services.
- Experience with Check Point firewalls.
- Experience with Cisco networking technologies.
- Experience working in an ISO27001 environment.
- Experience with PowerShell, Python or scripting.
- Knowledge of MITRE ATT&CK.
- Knowledge of threat hunting methodologies.
- Experience with security tooling such as Defender, EDR, vulnerability scanners or email security platforms.
Qualifications
Essential
- Demonstrable interest in cybersecurity through study, projects or work experience.
Desirable
- Security+
- SC-200 (Microsoft Security Operations Analyst)
- SC-900 (Microsoft Security, Compliance and Identity Fundamentals)
- AWS Cloud Practitioner
- Azure Fundamentals (AZ-900)
- ISC2 CC/SSCP
- Related degree or other qualifications
Equal Opportunities:
CACI is proud to be an equal opportunities employer. Embracing the diversity of our people, we are on a journey to build a truly inclusive work environment where no one is treated less favourably due to ethnic origin, age, sex, gender identity, veteran status, religion or belief, sexual orientation, marital status, and disability or health condition, actively working to prevent discrimination.
As a Disability Confident employer, we will;
- Provide reasonable adjustments in the recruitment process where requested (contact a member of the recruitment team on 020 7602 6000 to discuss individual requirements further)
- Offer people with health conditions and disabilities, meeting the minimum criteria for a role an interview.
- Our people are unique and we encourage and support them to be confident in contributing to our inclusion journey.