Cyber Security Analyst

Novia Financial plc

Bath

On-site

GBP 55,000 - 75,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Novia Financial plc is seeking a Cyber Security Analyst in Bath to join our information security team. The role focuses on protecting systems, data, and business operations, working with stakeholders, SOC, IT and vendors to maintain a robust ISO 27001ISMS.

You will develop policy, implement controls, monitor events, manage vulnerabilities and support audit activities across cloud and on‑prem environments, ensuring secure-by-design practices across projects.

Qualifications

  • 3+ years' experience in a cyber security role.
  • Experience with Microsoft 365, Entra ID, Purview, endpoint security, SIEM, and vulnerability management.
  • Experience in incident response and security monitoring.
  • Knowledge of ISO 27001, GDPR, and financial services regulatory requirements.
  • Advanced security certifications such as CISSP, CISM, CCSP, GIAC, or equivalent.
  • Experience conducting security assessments, technical reviews, and supporting audit activities.

Responsibilities

  • Work with the Head of Information Security to develop policy and strategy in line with the group’s vision.
  • Help implement security controls to protect systems, networks, applications, and customer data.
  • Monitor security events and respond to cyber incidents, ensuring threats are detected, contained, and remediated.
  • Oversee and monitor vulnerabilities and security patching, coordinating remediation with IT and business teams.
  • Oversee and monitor cloud and on-premises environments, including Microsoft 365, Entra ID, servers, endpoints, and network infrastructure.
  • Support regulatory and compliance requirements such as FCA, GDPR, ISO 27001, and other industry standards.
  • Conduct security assessments and testing, including configuration reviews, penetration test remediation, and risk assessments.
  • Provide security advice to projects and technology teams, ensuring secure-by-design principles are applied.
  • Develop and improve security monitoring, automation, and detection capabilities to enhance cyber resilience.

Skills

Cyber security experience
Incident response
Security monitoring
ISO 27001/GDPR knowledge
Regulatory compliance
Stakeholder communication

Education

CISSP/CISM/CCSP/GIAC or equivalent

Tools

Microsoft 365
Entra ID
Purview
Endpoint security
SIEM
Vulnerability management
KQL
JSON

Job description

The Cyber Security Analyst is responsible for helping us to secure our systems and protect our key stakeholders, IT infrastructure, information assets and business operations.

Reporting to the Head of Information Security, the successful candidate will work with key business stakeholders, SOC, IT and 3rd party vendors, to ensure that we operate a robust Cyber Security infrastructure and ISO27001 ISMS that, is highly effective in protecting the business, in line with our commitment to clients and our regulatory obligations.

Key Responsibilities:
  • Working with the Head of Information Security to develop policy and strategy in line with the group’s vision.
  • Help implement security controls to protect systems, networks, applications, and customer data.
  • Monitor security events and respond to cyber incidents, ensuring threats are detected, contained, and remediated.
  • Oversee and monitor vulnerabilities and security patching, coordinating remediation with IT and business teams.
  • Oversee and monitor cloud and on-premises environments, including Microsoft 365, Entra ID, servers, endpoints, and network infrastructure.
  • Support regulatory and compliance requirements such as FCA, GDPR, ISO 27001, and other industry standards.
  • Conduct security assessments and testing, including configuration reviews, penetration test remediation, and risk assessments.
  • Provide security advice to projects and technology teams, ensuring secure-by-design principles are applied.
  • Develop and improve security monitoring, automation, and detection capabilities to enhance cyber resilience.
Specialist Skills, Qualifications and Experience:
Essential:
  • 3+ years' experience in a cyber security role.
  • Experience with Microsoft 365, Entra ID, Purview, endpoint security, SIEM, and vulnerability management.
  • Experience in incident response and security monitoring.
  • Knowledge of ISO 27001, GDPR, and financial services regulatory requirements.
  • Advanced security certifications such as CISSP, CISM, CCSP, GIAC, or equivalent.
  • Experience conducting security assessments, technical reviews, and supporting audit activities.
Desirable:
  • Experience with cloud security, security automation, and security architecture.
  • Knowledge of FCA, PRA, DORA, and cyber resilience requirements.
  • Experience mentoring junior engineers or leading technical security projects.
  • Experience working with SIEM, EDR, vulnerability management, and identity and access management solutions.
  • Knowledge of Microsoft Purview, DLP policy creation and reporting
  • Knowledge of KQL and JSON for queries and automation
Core Competencies
  • Analytical & Problem-Solving Skills: Ability to assess complex security issues and develop practical, risk-based solutions.
  • Communication & Stakeholder Management: Ability to explain security risks and recommendations to both technical and non-technical audiences.
  • Business Focus: The motivation and ability to always apply good financial practice and company procedures.
  • Operational Excellence: Continually delivering and improving excellence for all clients and customers.
  • Client and Customer Focus: Add value to client/customer, adhere to Treating Customers Fairly principles, and operate as a true business partner.
  • Communication: Communicate clearly and concisely, tailoring content and style, with ability to make a positive impression on others.
  • Expert Knowledge: Consistent application of professional or specialist knowledge and skills; takes opportunities to contribute to policy and best practice.
  • Working with others: Working successfully with others and building a network of good relationships to achieve shared goals.
  • Performance Focus: Demonstrate energy and enthusiasm, takes ownership, delivers results and improves personal performance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst
Cyber Security Analyst

Arcus Search • Greater London

Hybrid
GBP 70,000 - 110,000
Cyber Security Analyst
Cyber Security Analyst

SmartestEnergy Business Limited • Ipswich

Hybrid
GBP 60,000 - 100,000
Flexible Working
Global Impact
Commitment to Diversity and Inclusion
IT Security Analyst
IT Security Analyst

Castle Employment • Beverley

On-site
GBP 40,000 - 65,000
Cyber Security Analyst/Lead
Cyber Security Analyst/Lead

Chambers & Partners • Greater London

Hybrid
GBP 90,000 - 130,000
Cyber Security Analyst
Cyber Security Analyst

SmartestEnergy • Ipswich

On-site
GBP 50,000 - 75,000
Flexible Working
Diversity and Inclusion Commitment
Cyber Security Engineer
Cyber Security Engineer

Castle Employment Group • Driffield

On-site
GBP 55,000 - 75,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 40,000 - 60,000
Cyber Security Analyst
Cyber Security Analyst

Synapri • Greater London

Hybrid
GBP 50,000 - 70,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 60,000 - 80,000
Information Security Manager
Information Security Manager

British Land • Greater London

Hybrid
GBP 90,000 - 130,000