What Information Security Analysts Jobs are in the United Kingdom?

Showing 5000+ Information Security Analysts jobs in the United Kingdom

OT Cyber Security Analyst

YO7 4JP North Yorkshire Drax remove_red_eye View All

Posted today

Job Viewed

Tap Again To Close

Job Description

OT Cyber Security Analyst
Full time, Permanent

Department – Cyber    
Location – Drax Power Station Selby OR Glasgow – hybrid working (3 days on site)

Closing date: 31 July

About the role:

We’re looking for an OT (Operational Technology) Cyber Analyst to join our Cyber Security Team and play a key role in ensuring the reliability and safety of UK critical national infrastructure.

As an OT Cyber Analyst, you’ll be responsible for monitoring, assessing, and securing Drax’s operational technology systems, including industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems, against cyber threats and vulnerabilities.

This role has is focussed on supporting our portfolio of generation assets, and therefore this role will require some travel to sites throughout the UK approximately 30% of the time.

Key areas of focus include: 

·    Cyber Tooling Deployment & Maintenance - Tooling is deployed to agreed project timelines, operates at performance baselines, and remains fully supported with no unplanned degradation to security monitoring capability.

·    Project Delivery Support - Provide cyber security SME support to OT and business projects, ensuring controls are designed, implemented and validated in line with Drax Policies and industry standards.

·    Compliance Assurance – Ensure audit and assurance activities are conducted thoroughly, with accurate findings, and that all required evidence is complete and delivered on time.

·    Stakeholder collaboration – Ensure stakeholder feedback is positive, cyber requirements are consistently embedded in project outputs, and governance processes are completed without delays.

Who we’re looking for:

To be successful in this role you’ll be able to demonstrate the following:

·    An understanding of Operational Technology (OT) environments, including Industrial Control Systems (ICS), SCADA, and plant networks is highly desirable but not required.  A genuine interest in OT environments coupled with the desire to learn and develop is most important.

·    Experience in deploying and supporting cyber security tooling such as security monitoring solutions (SIEM / logging platforms), network intrusion detection systems (IDS) and endpoint protection / EDR solutions.

·    Knowledge of networking and infrastructure e.g. network architectures, firewalls and network segmentation.

·    Knowledge of cyber security principles and frameworks such as NIS/CAF and IEC 62443.

Who we are:

We’re not just talking about making a difference, we’re making it happen. We generate dispatchable, renewable power and create stable energy in an uncertain world. Building on our proud heritage, we have ambition to become the global leader in sustainable biomass and carbon removals.

You’ll be joining our teams of practical doers, future thinkers and business champions. We’re enabling a zero carbon, lower cost energy future for all, and working hard to decarbonise the planet for generations to come.

Rewards and benefits:

As you help us to shape the future, we’ve shaped our rewards and benefits to help you thrive and support

your lifestyle. If successful in this role you’ll get:

·    A discretionary bonus depending on company performance

·    Private Healthcare

·    SAYE (Sharesave): discretionary scheme from time to time

·    Personal accident cover

·    Group personal pension plan where we’ll pay up to 10%

·    Holiday 25 days plus bank holidays

·    Reimbursement of the cost of your annual membership of one relevant and appropriate professional body

We’re committed to making a tangible impact on the climate challenge we all face. Drax is where your individual purpose can work alongside your career drive. We work as part of a team that shares a passion for doing what’s right for the future. With Drax you can shape your career and a future for generations to come.

Together, we make it happen.

At Drax, we’re committed to fostering an environment where everyone feels valued and respected, regardless of their role. To make this a reality, we actively work to better represent the communities we operate in, foster inclusion, and establish fair processes. Through these actions, we build the trust needed for all colleagues at Drax to contribute their perspectives and talents, no matter their background. Find out more about our approach here.

Talk to us about flexible working!

How to apply:

Think this role’s for you? Click the ‘apply now’ button to begin your Drax journey.

If you want to find out more about Drax, check out our LinkedIn page to see our latest news. 

We reserve the right to close roles early when the particular role and / or location has had sufficient applications.

Please note that any offer made will be subject to enhanced pre-employment checks.

#LI-HYBRID

Is this job a match or a miss?
Apply Now

Lead Information Security & GRC Specialist

London £80,000 - £100,000 Annually Zachary Daniels Recruitment

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

permanent

Lead Information Security & GRC Specialist

London (Hybrid, 3 days in office) | 80,000 - 100,000 + Benefits

We're partnering with a well-established organisation that's continuing to invest in its Technology and Information Security capability.

As the business continues to strengthen its security posture, they're looking for a hands-on Information Security & GRC Specialist to play a key role in developing and maturing their Information Security function.

This is an opportunity to join a collaborative technology team where you'll take ownership of Governance, Risk & Compliance activities, helping to build and continually improve the organisation's security maturity while working closely with stakeholders across Technology and the wider business.

The Opportunity

This is a hands-on role suited to someone who has successfully led, or played a significant role in, delivering an ISO 27001 certification programme.

You'll own and continually improve the Information Security Management System (ISMS), working closely with Technology, Infrastructure, Engineering and business stakeholders to embed security into projects, operational processes and supplier relationships.

You'll be responsible for identifying security gaps, driving remediation activities, coordinating internal and external audits, managing governance processes and ensuring the business continues to meet evolving regulatory and compliance requirements.

Key Responsibilities

  • Lead the ongoing development and continual improvement of the Information Security Management System (ISMS)
  • Drive ISO 27001 implementation, certification and ongoing compliance activities
  • Conduct security risk assessments and manage enterprise risk registers
  • Develop, review and maintain Information Security policies, standards and procedures
  • Coordinate internal and external audits, ensuring evidence is prepared and remediation actions are delivered
  • Lead third-party supplier assurance, vendor risk assessments and ongoing governance activities
  • Work closely with Technology, Infrastructure and Engineering teams to embed security into projects and operational processes
  • Support compliance with security frameworks including ISO 27001, NIST and NIS2
  • Produce governance reporting and communicate security risks and recommendations to senior stakeholders
  • Champion security awareness and continuous improvement across the organisation

About You

You'll be an experienced Information Security & GRC professional who enjoys delivering security improvements rather than simply overseeing them.

You'll have experience of:

  • Leading, or playing a significant role in, taking an organisation through ISO 27001 certification
  • Building, implementing and continually improving an Information Security Management System (ISMS)
  • Governance, Risk & Compliance (GRC)
  • Security risk assessments, risk registers and remediation planning
  • Internal and external audit preparation and certification readiness
  • Third-party supplier assurance and vendor risk management
  • Developing Information Security policies, standards and governance frameworks
  • Working with frameworks such as ISO 27001, NIST, NIS2 and Cyber Essentials
  • Collaborating with technical teams and business stakeholders to improve security maturity

Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer or ISO 27001 Lead Auditor would be highly desirable.

Package

  • 80,000-100,000 DOE
  • Hybrid Working 3 days in the London Office
  • Opportunity to shape and mature cyber governance
  • Exposure to enterprise security programmes
  • Excellent long-term career progression

Apply today with your most up-to-date CV!

BH36687

Is this job a match or a miss?
Apply Now

Senior GRC Cyber Security Analyst

London £70,000 - £85,000 Annually Zachary Daniels Recruitment

Posted today

Job Viewed

Tap Again To Close

Job Description

permanent

Senior GRC Cyber Security Analyst | London (Hybrid, 3 days in office) | 70,000-85,000 + Benefits

A growing international organisation is looking to strengthen its cyber security capability with the appointment of a Senior Cyber Security Analyst (Governance, Risk & Compliance).

This is a fantastic opportunity to join a developing security function where you'll play a key role in governance, risk management, regulatory compliance and information security assurance across the business.

The Opportunity

Working closely with the Director of Information Security, you'll help drive security governance, maintain compliance frameworks and provide clear security risk insight to stakeholders across the organisation.

This is a varied role offering exposure to security strategy, audits, supplier assurance and executive reporting within a complex technology environment.

Key Responsibilities

Governance & Compliance

  • Maintain Information Security policies, standards and procedures
  • Support compliance with ISO 27001, GDPR, NIS2 and related frameworks
  • Coordinate audit evidence and compliance activities
  • Maintain governance documentation and control frameworks

Risk Management

  • Maintain the Information Security Risk Register
  • Facilitate risk assessments with business stakeholders
  • Track remediation plans and improvement actions
  • Produce meaningful security reporting and dashboards

Third Party Assurance

  • Conduct supplier security assessments
  • Manage customer security questionnaires
  • Support third-party due diligence activities

Reporting & Security Awareness

  • Produce KPI and KRI reporting
  • Support executive and board reporting
  • Coordinate security awareness initiatives
  • Contribute to Business Continuity and Disaster Recovery activities

About You

You'll have previous experience within a Cyber Security Governance, Risk & Compliance function together with knowledge of:

  • ISO 27001
  • GDPR
  • NIS2
  • Risk Management
  • Security Policies & Standards
  • Audit & Compliance
  • Supplier Assurance
  • Microsoft 365

Relevant cyber security certifications would be advantageous but are not essential.

Package

  • 70,000-85,000 DOE
  • Hybrid Working 3 days in the London Office
  • Opportunity to shape and mature cyber governance
  • Exposure to enterprise security programmes
  • Excellent long-term career progression

Apply today with your most up-to-date CV!

BH36687

Is this job a match or a miss?
Apply Now

Cyber Security Analyst - Watford

Essex £55,000 - £60,000 Annually Morgan Philips Group

Posted 1 day ago

Job Viewed

Tap Again To Close

Job Description

permanent

Job specification for the position of : Cyber Security Analyst
Reporting to : IT Governance and Security Manager

***OFFICE BASED IN WATFORD - FIVE DAYS PER WEEK - NON-NEGOTIABLE***

Must have a British passport or ILR (Indefinite leave to remain) - ***no sponsorship available***


Purpose of the role :
The cyber security analyst is responsible for the day-to-day tasks which protect the business from cyber threats and attacks.

Based in Watford, at head office, this role gives an opportunity to contribute to cyber response and to identify cyber risks, helping IT to protect the company's systems.

Role overview :

  • working closely with the IT governance and security manager, contributing
    to cyber strategy
  • administering IT security systems
  • identifying, mitigating and escalating IT security incidents
  • identifying deviations from IT security standards
  • analysing logs and reporting relevant information
  • reporting trends and threats in e-mail and web traffic, as appropriate
  • analysing security information and producing relevant reports
  • administering and evaluating cyber security questionnaires
  • co-ordinating and scheduling penetration tests
  • managing third-party forensic investigations
  • completing cyber security posture-reporting
  • supporting excellent cyber security design, with the ability to contribute
    to good cyber security practices

In detail, the role will involve :

  • log-analysing
  • security posture-monitoring
  • Trellix antivirus-reporting and some EPO management tasks
  • secure physical and electronic destruction of sensitive data
  • helping the business to protect sensitive information (e.g. encrypting data)
  • educating and awareness through spam-testing; supporting the training teams
    with e-learning
  • monitoring public and third-party feeds for emerging cyber trends
  • performing cyber risk assessments
  • co-ordinating cyber security incidents
  • defining cyber policies and cyber standards
  • assessing third-party suppliers' cyber standards
  • keeping abreast of current and emerging threats

Skills required :

  • understanding log management (at an analysis level only):
    • Microsoft Windows and AD log structure
    • network system log, e.g. Cisco and Checkpoint
    • Office 365 and Defender security
    • knowledge of Splunk the SIEM platform
  • understanding of systems and integrity:
    • Netwrix security solutions administration, including AD Auditor and Change Tracker
    • Trellix and SkyHigh reporting and management, including Trellix antivirus-reporting and DLP using EPO
  • operational security and incident management:
    • experience of cyber security
    • quickly analysing data and making decisions on security threats

Salary and benefits :

  • competitive salary
  • 25 days' paid holiday (plus bank holidays) pro rata; head-office bonus scheme; free shares (after 18 months with the company); private medical insurance; contributory pension scheme

Please note you will receive an automated response advising you that we have received your CV.

Morgan Philips Group is a global talent solutions business that disrupts conventional thinking in executive search, recruitment and talent consulting. We operate in over 18 markets in Europe, North & South America, Asia, and the Middle East & Africa. We understand that the future is digital and social, so we embrace the latest technology, including video ads and CVs, as well as social recruiting. Our innovative services are tailored to the new world of work yet we do not lose sight of the fact that employees be they existing and potential are ultimately human beings.

We are committed to ensuring that all job applicants are treated equally, without discrimination because of gender, sexual orientation, marital or civil partner status, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief, disability or age.

Is this job a match or a miss?
Apply Now

Analyst (Cyber Security) or Senior Analyst (Cyber Security) - Durham

DH1 5LE Durham Durham University

Posted today

Job Viewed

Tap Again To Close

Job Description

Analyst (Cyber Security) or Senior Analyst (Cyber Security) - Durham

The Computing and Information Services (CIS) at Durham University seeks to appoint an Analyst (Cyber Security) into either a Grade 5 developmental role or (if the successful candidate already has the necessary skills) a Senior Analyst (Cyber Security) Grade 6 role.

The Computing and Information Services (CIS) has an annual operational budget in excess of 12m, multi-million pound programmes of change within year, and approximately 185 staff. The Senior Leadership Team report directly to the Chief Information Officer (CIO) with the following portfolios: Strategy and Change; Technical Services (TS); Information Services (IS), and Cyber Security. CIS work with departments across the university to provide academic, teaching and administrative services that underpin the day-to-day activities of the whole organisation. Details of the Digital Strategy and ongoing work can be found at Digital Strategy - Durham University

CIS is a friendly, but demanding department, where much is expected and can be achieved by competent, self-motivated individuals who are demonstrable in their teamwork ability. The department works in a hybrid capacity depending on the job role and individual personal requirements.

There is the opportunity to be appointed as either a Grade 5 Analyst (Cyber Security) in a development role or Grade 6 Senior Analyst (Cyber Security) depending on your skills and preferences. Job descriptions for each role can be found below:

*Please remember to specify on your application which role you would like to be considered for along with attaching both documents listed in the "What to submit" section below

Is this job a match or a miss?
Apply Now

Information Security & Resilience Consultant

London £450 - £500 Daily ARM

Posted 4 days ago

Job Viewed

Tap Again To Close

Job Description

contract

Information Security & Resilience Consultant - M&A

6-Month contract - Inside IR35 - up to 500 per day

Hybrid working - 2 days a week onsite - either London or Bradford based

We are seeking two highly skilled, hands-on Contract Information Security & Resilience Consultants to support several critical, high-priority strategic initiatives.

In this dual-role, you will be responsible for executing rigorous security due diligence on upcoming M&A activities, maintaining and maturing our Information Security Management System (ISMS) compliance frameworks, and driving our Business Continuity and Resilience programs.

Key Responsibilities

  1. M&A Security Due Diligence

Due Diligence Assessments: Conduct comprehensive cybersecurity risk assessments and security due diligence on target acquisition companies.

Control Evaluation: Review target company security controls, policies, third-party assurance reports (e.g., SOC 2, ISO certifications), and historical security incident logs.

Identify deal-impacting risks, quantify remediation effort (cost/timeline ranges), and advise on onboarding security priorities.

Integration Roadmapping: Identify risk areas and formulate actionable post-acquisition security integration roadmaps and transition plans.

  1. Information Security Standards & Compliance (ISO 27001 & SOC 2)

Framework Governance: Assess, maintain, and mature existing security frameworks aligned with ISO/IEC 27001 and SOC 2 Type II.

Develop and maintain information security policies, standards, and procedures aligned to these standards and business objectives.

Run security risk assessments, update risk registers, and drive risk treatment/remediation plans.

Remediation & Evidence: Identify control gaps, collaborate with internal system owners to implement remediation plans, and collect audit-ready evidence.

External Audits: Assist in preparing the business, staff, and control owners for upcoming external surveillance and compliance audits.

  1. Business Continuity & Disaster Recovery

Plan Development: Lead the review and update of Business Continuity Plans (BCPs) across key business departments

Impact Analysis: Facilitate Business Impact Analyses (BIAs) to identify critical business processes, evaluate upstream/downstream dependencies, and define Recovery Time Objectives (RTOs)

Testing & Exercises: Design and execute tabletop exercises and simulation tests to validate recovery strategy effectiveness

  1. Third-Party & Supplier Security

Perform vendor risk assessments, review security clauses, and ensure suppliers meet security and business continuity requirements.

Manage the relationship with our outsourced managed IT and information security suppliers

  1. Security Awareness & Stakeholder Management

Deliver security awareness initiatives and provide advisory support to projects and teams.

Communicate risks and recommendations clearly to leadership and non-technical stakeholders.

Required Skills & Experience

  • M&A Security Expertise: Proven track record of executing security due diligence on target entities during corporate acquisitions.
  • Compliance Mastery: Deep, hands-on experience implementing, auditing, or managing ISO 27001 and SOC 2 compliance programs.
  • Business Continuity Planning: Experience designing, updating, and testing Business Continuity frameworks (experience aligning with ISO 22301 is a plus)
  • Consultative Approach: Outstanding stakeholder management skills, with the ability to communicate complex security risks to business leads and M&A deal teams.

Disclaimer:

This vacancy is being advertised by either Advanced Resource Managers Limited, Advanced Resource Managers IT Limited or Advanced Resource Managers Engineering Limited ("ARM"). ARM is a specialist talent acquisition and management consultancy. We provide technical contingency recruitment and a portfolio of more complex resource solutions. Our specialist recruitment divisions cover the entire technical arena, including some of the most economically and strategically important industries in the UK and the world today. We will never send your CV without your permission. Where the role is marked as Outside IR35 in the advertisement this is subject to receipt of a final Status Determination Statement from the end Client and may be subject to change.

Is this job a match or a miss?
Apply Now

Cyber Security Specialist - Inverness

Inverness Capgemini

Posted today

Job Viewed

Tap Again To Close

Job Description

Cyber Security Specialist - Inverness Reference Code: -en_GBContract Type:PermanentProfessional Communities: Cybersecurity

About the job youre considering

Location: Secure Room, Inverness (On-site)

Working Hours: Mon -Fri 9.00am - 5.30pm

The Security TDA, Governance Risk, Compliance and Vulnerability Assessment Lead is responsible for leading governance, risk, compliance, vulnerability management assessment, and security design assurance across a complex, multi-technology environment. The role combines GRC operational leadership with cyber technical design, ensuring security-by-design aligned to ISO 27001, Cyber Essentials Plus and architecture standards.

Your role

Key Responsibilities

  • Security Architecture & Cyber TDA Leadership
  • Act as Cyber Technical Design Authority (TDA) for the account
  • Review and approve solution architectures
  • Define security reference architectures and patterns
  • Lead design governance forums
  • Provide security design sign-off and manage exceptions
  • Embed security-by-design in all solutions
  • Advise on IDAM, network, cloud and infrastructure security

Governance, Risk & Compliance (GRC)

  • Develop and maintain security policies aligned to ISO 27001 and Cyber Essentials Plus
  • Manage Security Risk Register, controls, RACI and RBAC model
  • Lead risk identification, assessment, treatment and reporting
  • Support audits and assurance activities
  • Contribute to Disaster Recovery, Business Continuity and security incident management, covering tracking, remediation, RCA, and reporting
  • Conduct assurance activities to validate control effectiveness
  • Produce regular reporting packs covering risk, compliance, audits, and incidents
  • Provide and update relevant Security Training material for account personnel.

Vulnerability Management

  • Review and triage vulnerability scans and penetration test reports
  • Prioritise vulnerabilities based on risk, impact, and contractual obligations
  • Coordinate remediation across technical teams, ensuring clear ownership and timely closure
  • Track vulnerabilities to distinguish new vs. existing issues
  • Provide remediation guidance and consultancy to stakeholders
  • Deliver reporting on remediation progress for internal and client consumption

Your skills and experience

Your skills and experience

Skills & Experience

  • Strong GRC and risk management experience
  • Familiarity with ISO27001, GDPR, NIST, and ITIL
  • Experience as Security Architect or TDA
  • Knowledge of Zero Trust and cloud security
  • Strong stakeholder communication skills
  • Ability to work in a secure, restricted-access environment

Additional Requirements

  • Based on-site in the Highlands
  • Eligibility for BPSS security clearance

We are a Disability Confident Employer

Capgemini is proud to be a Disability Confident Employer (Level 2) under the UK Governments Disability Confident scheme. As part of our commitment to inclusive recruitment, we will offer an interview to all candidates who:

  • Declare they have a disability, and
  • Meet the minimum essential criteria for the role.

Please opt in during the application process.

Baseline Personnel Security Standard (BPSS)

To be successfully appointed to this role you will need to undergo Make it real what does it mean for you?

Flexibility to work your way
You will be encouraged to have a positive work-life balance. Our hybrid-first way of working means we embed hybrid working in all that we do and make flexible working arrangements the day-to-day reality for our people. All UK employees are eligible to request flexible working arrangements.


Your wellbeing
Youd be joining an accredited Great Place to work for Wellbeing in 2024. Employee wellbeing is vitally important to us as an organisation. We see a healthy and happy workforce a critical component for us to achieve our organisational ambitions.
To help support wellbeing we have trained Mental Health Champions across each of our business areas, and we have invested in wellbeing apps such as Thrive and Peppy.

Shape your path
You will be empowered to explore, innovate, and progress. You will benefit from Capgeminis learning for life mindset, meaning you will have countless training and development opportunities from thinktanks to hackathons, and access to 250,000 courses with numerous external certifications from AWS, Microsoft, Harvard ManageMentor, Cybersecurity qualifications and much more.

Shared energy
Youll be bringing your unique skills and perspectives to the team, inspiring and taking inspiration from your teammates as you unlock value in everything you do. Youll be joining a professional community of experts, who have got your back and will support you, every step of the way.

Why should you consider Capgemini?

Growing clients businesses while building a more sustainable, more inclusive future is a tough ask. When you join Capgemini, youll join a thriving company and become part of a collective of free-thinkers, entrepreneurs and industry experts. We find new ways technology can help us reimagine whats possible. Its why, together, we seek out opportunities that will transform the worlds leading businesses, and its how youll gain the experiences and connections you need to shape your future. By learning from each other every day, sharing knowledge, and always pushing yourself to do better, youll build the skills you want. Youll use your skills to help our clients leverage technology to innovate and grow their business. So, it might not always be easy, but making the world a better place rarely is.

About Capgemini

Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organisations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2025 global revenues of 22.5 billion. Make it real |

Is this job a match or a miss?
Apply Now
Tap Again To Close

Job Description

permanent

The Role:

Salary: Market Leading Base + Bonus + Excellent Benefits
Location: London (hybrid working)

My client is a rapidly growing international main market listed organisation offering a range of solutions to the global Financial & Professional Services sector. As part of their exciting growth plans a new opportunity now exists for an experienced Cyber Security specialist to join their well established and growing technology team based in the London HQ.

You will join the team as a Cyber Security Analyst, providing day-to-day operational security coverage across their extensive toolset. Working closely with their Senior Cyber Security Engineer, you will maintain and administer key security platforms, support client-facing security assurance activities, and help strengthen the company's security posture ahead of ISO 27001 certification.

Responsibilities:
* Implement, manage and actively monitor security controls across email, web, endpoint and cloud environments.
* Monitor and respond to security incidents using advanced threat detection tools.
* Day-to-day administration of Netskope web filtering platform including website unblocks and policy updates.
* Day-to-day administration of Mimecast email filtering system including email review and release.
* Day-to-day administration of CyberArk identity and privileged access management tooling.
* Microsoft Purview administration including DLP policy monitoring, sensitivity labels, Discovery Searches and compliance alerts.
* Maintain and respond to security-related DDQs, keeping the security evidence library current.
* Assist with compliance activities and audits for ISO 27001, Cyber Essentials & Cyber Essentials Plus certification.
* Provide technical expertise on security best practices and risk mitigation.
* Collaborate with IT and business teams to ensure secure configuration and data protection.
* Participating in the out-of-hours support rota to provide cover for critical cyber incidents.

The Person:
* Previous hands-on experience with Mimecast (or similar email security platform), Crowdstrike (or similar EDR platform) and Microsoft Purview - data governance, DLP and compliance tooling are essential for success in the role.
* Hands-on experience with Netskope - web filtering, CASB and cloud security and/or CyberArk - identity and privileged access management would be highly desirable skills.
* Experience with Rapid7, InsightVM or InsightIDR for vulnerability management and SIEM would also be highly desirable.
* Experience of responding to security DDQs and maintaining security evidence.
* Experience supporting ISO 27001, Cyber Essentials and Cyber Essentials Plus.
* Strong understanding of UK cyber security regulations and frameworks.
* Experience working in an FCA-regulated or similarly governed environment.
* Experience with Microsoft Entra ID and identity governance, alongside familiarity with Microsoft Azure and M365 E5 security features.

This is a fantastic opportunity to join a prominent organisation at an exciting time with genuine opportunities for career development and progression. Alongside their compelling salary and bonus, they also offer a very generous pension contribution, private medical and the ability to 'buy and sell' holidays. The role is based from their London office, offering hybrid working with 3 days in the office, with travel to their other UK locations as and when required.

If you feel you have the qualities our client is seeking, please forward your CV and covering letter indicating your current package to Lee Rankin at GEM Partnership or for a discreet conversation call our Peterlee office.

GEM Partnership is acting as an employment agency on this vacancy.

Is this job a match or a miss?
Apply Now

Cyber Security Analyst

London £43,000 - £60,000 Annually Tria

Posted 4 days ago

Job Viewed

Tap Again To Close

Job Description

permanent

Cyber Security Analyst
Wembley - Hybrid with 2 days per week on site
43,000 - 60,000 DOE + Holiday + Pension

Excellent opportunity for an experienced Cyber Security Analyst or Security Engineer to join a large, enterprise environment where you'll play a key role in protecting critical infrastructure while continuing to develop your technical expertise across Microsoft Security, cloud technologies and next-generation security platforms.

This organisation is investing heavily in its cyber security capability, offering the opportunity to work with modern security technologies within a collaborative, values-led environment. With genuine commitment to professional development, you'll have the opportunity to benefit from funded industry certifications, including Palo Alto, alongside clear technical progression and exposure to a broad enterprise technology estate.

In this role you'll investigate and respond to cyber security incidents, working closely with an external Security Operations Centre (SOC) to monitor threats, manage vulnerability remediation and strengthen the organisation's security posture. You'll work across Microsoft Security, cloud and network technologies within a complex enterprise environment, making this an excellent opportunity for an experienced Cyber Security Analyst or Security Engineer looking to broaden their technical expertise and continue progressing their career through exposure to modern technologies and funded certifications.

This is a fantastic opportunity to join an organisation that genuinely invests in both its technology and its people, offering exposure to modern Microsoft security technologies, funded certifications and long-term technical progression within a supportive team.

The Role:
* Investigate, triage and respond to cyber security incidents across a complex Microsoft environment
* Monitor and manage security events using Microsoft Sentinel and Microsoft Defender XDR
* Drive vulnerability management and remediation across cloud, network and infrastructure environments
* Work closely with an external SOC and internal infrastructure teams to continuously improve the organisation's security posture
* Contribute to the ongoing development of security processes, controls and incident response capabilities

The Person:
* Experience in a Cyber Security Analyst, Security Engineer or Security Operations role
* Strong hands-on experience with Microsoft Security technologies, including Microsoft Sentinel and Defender XDR
* Experience investigating and responding to cyber security incidents in an enterprise environment
* Good understanding of cloud and network security principles
* Able to work collaboratively across infrastructure, networking and cloud teams whilst taking ownership of security issues
* Keen to continue developing technically through exposure to enterprise technologies and funded certifications, including Palo Alto

Is this job a match or a miss?
Apply Now

Cyber Security Analyst (Vulnerability Management) Grade 5 - Durham

DH1 5LE Durham Durham University

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

Cyber Security Analyst (Vulnerability Management) Grade 5 - Durham

The Role and the Department

The Computing and Information Services (CIS) has an annual operational budget in excess of 27m, including multi-million-pound programmes of change within year, and approximately 172 staff. The Senior Leadership Team report directly to the Chief Information Officer (CIO) with the following portfolios:
o Strategy and Change.
o Technical Services.
o Information Services.
o Cyber Security.

CIS work with departments across the university to provide academic, teaching and administrative services that underpin the day-to-day activities of the whole organisation. Details of the Digital Strategy and ongoing work can be found at Digital Strategy - Durham University

CIS is a friendly, but demanding department, where much is expected and can be achieved by competent, self-motivated individuals who are demonstrable in their teamwork and ability. The department works in a hybrid capacity, depending on the job role.

The CIS security team have many functions across the organisation including
o Help detect IT security vulnerabilities and assist system owners with appropriate remediation.
o Operate and improve security tools and protections, securing University networks, systems, users and assets from malicious activity.
o Working with colleagues and external partners to detect and respond to cyber security alerts, incidents and reports
o Respond rapidly and effectively to cyber security alerts and incidents, managing them in a professional manner.
o Keep up to date with security trends, threats and protective measures.
o Operate and improve cyber security processes and playbooks to ensure efficient and standardised activity.
o Share security best practice, principles and standards.
o Assist with activities to maintain the day-to-day operation and on-going development of Computing and Information Services (CIS) services and solutions.

Working Hours:
35 Hour Week

The University is piloting hybrid working and is flexible to remote working for this role. Flexibility to cover 8am-6pm and work out of hours may be required on occasion


Further information about the role and the responsibilities is at the bottom of this job description.

Is this job a match or a miss?
Apply Now