About the Role
The Senior Information Security Analyst provides technical leadership within the Firm’s global Security Operations (SOC) team, focusing on monitoring, detection, response, and threat hunting to enhance the Firm's security posture.
Responsibilities
- Operate and manage security incidents and requests to SLA guidelines, acting as an intermediate escalation point for complex investigations.
- Monitor, triage and investigate alerts across endpoints, cloud, identity, email and network telemetry, reviewing and escalating unusual event behavior.
- Lead structured incident response aligned to a recognized lifecycle, including containment, eradication, recovery, evidence preservation and digital forensic analysis as authorized.
- Triage and remediate phishing, vishing and impersonation attacks in a timely and efficient manner as the risk dictates.
- Configure and tune appropriate security parameters in monitoring systems and act as a technical point of escalation for alerted issues.
- Conduct proactive, hypothesis-driven threat hunting on a scheduled basis to identify adversary activity not surfaced by existing detections.
- Design, test, tune and maintain detection rules and use cases (e.g. Sigma / KQL), and map detection coverage to the MITRE ATT&CK framework to identify and close detection gaps.
- Maintain technical awareness of adversary tradecraft, emerging attack techniques and threat intelligence relevant to the legal sector, translating these into new or improved detections.
- Develop and maintain security automation and orchestration (SOAR) playbooks to streamline incident response and automate repetitive operational tasks.
- Use AI-assisted detection, triage and investigation tooling effectively, and critically validate, tune and quality-assure AI-generated findings and recommendations.
- Act as a technical mentor for junior and peer analysts, supporting skills development and succession planning within the region.
- Take ownership of one or more SOC processes, functions or technologies globally, ensuring their continued maintenance and improvement.
- Assist with development and maintenance of SOC playbooks, runbooks, monitoring configuration and standard operating procedures, identifying improvements and reporting on incidents.
Requirements
- Technical bachelor’s degree or equivalent IT / Information Security experience.
- At least 5 years’ experience working within security operations or Information Security infrastructure, or a strong vocation and demonstrable transferable experience from another technical discipline.
- Proven ability to adapt quickly to emerging threats or new information, shifting focus as needed.
- Demonstrated expertise in Microsoft 365 Defender and Microsoft Sentinel for detecting, investigating and responding to suspicious and anomalous activity.
- Strong knowledge of core security technologies (firewalls, IDS/IPS, EDR, SIEM) and of structured incident-response methodologies (e.g. NIST).
- Working knowledge of endpoint security and monitoring infrastructure (EDR, DLP, removable-media encryption) and of cloud-based web and email security solutions (e.g. Zscaler, Mimecast, Proofpoint, Cisco).
- Ability to triage and remediate phishing and impersonation attacks in a timely and efficient manner as the risk dictates.
- Experience working with a service management tool (e.g. ServiceNow).
- Demonstrable, in-depth expertise in at least one of the following domains: Identity & Access, Cloud Security, Windows & Linux Operating Systems, or Security Automation & Detection Engineering.
- Solid working knowledge across the remainder of the specified domains (Identity & Access, Cloud Security, Windows & Linux Operating Systems, Security Automation & Detection Engineering).
Skills
- Microsoft 365 Defender
- Microsoft Sentinel
- Firewalls
- IDS/IPS
- EDR
- SIEM
- NIST
- Endpoint security
- DLP
- Removable-media encryption
- Zscaler
- Mimecast
- Proofpoint
- Cisco
- ServiceNow
- Active Directory
- Entra ID / Azure AD
- Conditional access
- Privileged access
- Authentication protocols
- Identity threat detection and response (ITDR)
- Azure
- AWS
- GCP
- Cloud logging and telemetry
- Posture signals
- Cloud-native detection and response
- Windows forensics
- Linux forensics
- Event log analysis
- Audit analysis
- Process investigation
- Memory investigation
- OS hardening
- PowerShell scripting
- Python scripting
- SOAR playbook development
- Detection engineering
- Sigma
- KQL
Location
- Global
Work Type
- Full-time
Experience Level
- Senior
- At least 5 years
Education Level
- Technical bachelor’s degree or equivalent IT / Information Security experience
Benefits
- Access to three medical insurance plans
- Dental insurance
- Vision insurance
- Life insurance
- Disability insurance
- Pre-tax benefits such as health savings and flexible spending accounts
- 401(k) savings plan
- Profit-sharing plans
- Fertility benefits
- Commuter benefits
- Student loan assistance refinancing options
- Competitive paid time off plan (minimum of 20 days)
- Generous paid maternity leave
- Paid paternity leave (parental leave) (minimum of 14 weeks)
- Child care support through a back-up care program
- 11 Firm holidays
About the Company
- Norton Rose Fulbright is a highly regarded global law firm with over 3,000 lawyers and 3,000 business services professionals across 50 offices worldwide.
- The firm provides a full range of legal services to leading corporations and financial institutions operating in key markets and sectors.
- Norton Rose Fulbright consistently receives recognition from Great Place to Work and Top Workplaces.
- The firm's culture embraces ambition, development, and shared success, with teams collaborating across regions and valuing new ideas.
- The Security Operations (SOC) team is a dedicated sub-team of Global Information Security responsible for near-24x7 monitoring, detection, and response to security incidents.
- The wider Information Security function ensures the overall effectiveness of the control framework and manages security incidents, adhering to ISO/IEC 27001.
- This business uses E-Verify in its hiring practices to achieve a lawful workforce.
Equal Opportunity
- Norton Rose Fulbright US LLP is an Equal Opportunity Employer and complies with all applicable federal laws and their implementing regulations.
- Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status.
- Norton Rose Fulbright is committed to providing reasonable accommodation as an Equal Opportunity Employer to applicants with disabilities.
- Norton Rose Fulbright US LLP will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant.
