Enable job alerts via email!

Cyber Security Analyst

Leonardo SpA

Bristol

Hybrid

GBP 40,000 - 60,000

Full time

Today
Be an early applicant

Job summary

A leading aerospace and defense firm seeks a Cyber Security Analyst in Bristol to enhance its monitoring and incident handling services. You will collaborate closely with teams on security incidents, requiring strong cyber security experience and communication skills. Join us for a rewarding career with ample opportunities for professional growth in a dynamic environment.

Benefits

Generous leave
Pension scheme
Mental health support
Online courses access
Flexible benefits

Qualifications

  • Excellent communication skills required.
  • Experience in Cyber Security, especially Incident Response.
  • Ability to work independently and in a team.

Responsibilities

  • Monitor and handle security incidents within SLAs.
  • Advise on incident containment and mitigation measures.
  • Perform proactive analysis of current threats.

Skills

Communication
Cyber Security experience
SIEM experience
IT security knowledge
Analytical skills
Organizational skills
Teamwork
Motivation to learn

Education

SANS SEC 503
SANS SEC 504
SANS SEC 508
SANS SEC 511

Tools

LogRhythm
Arcsight
Splunk
Snort
Job description
Job Description

Your impact

We're looking for a Cyber Security Analyst to join the ARCHANGEL™ Protective Monitoring (ProMon) Team. ARCHANGEL™ delivers specialist technical cyber security services to a range of clients across a variety of industries including construction, government, defence and aerospace. The ARCHANGEL™ ProMon Team sits within the Bristol Service Operations Centre (SOC) and is responsible for providing thorough initial investigation into anomalous network activity that may lead to potential security incidents. Beyond ARCHANGEL™, Leonardo and its Cyber Security division are a world leader in safety-through-technology, providing tailored solutions for customers in public administration, public safety and security, critical infrastructure, services, transport, post and logistics. You will be joining our highly skilled team at our Bristol site. This is a great opportunity to bring your talents and form an integral part of Leonardo's future. We can help you develop your skills and offer great opportunities to develop and grow, so why not join us! At Leonardo, we believe that our employees work best when they are able to achieve balance between work and other aspects of life and so that you can enjoy the great city of Bristol! That's why we are committed to designing policies and developing a working environment that promote the benefits and well-being of all our employees.

Responsibilities
  • Provide monitoring, alerting and incident handling services within the SOC in line with SLAs and within the 24/7/365 shift pattern
  • Act as the initial analytical reference point for identifying and then quantifying the nature and extent of security incident and offer initial professional advice relating to possible business impact in order to reduce both the Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)
  • Advise on incident containment measures through recommended initial actions to customers in collaboration with the Incident Response (IR) Team
  • Provide advice relating to potential mitigation measures in order to prevent, or limit future reoccurrence in collaboration with the Incident Response (IR) Team
  • Have an understanding of Incident Response, Cyber Kill Chain, Threat Modelling and pertinent Attack Vectors
  • Have a collaborative working ethos in order to work across the team in order toto create pertinent Playbooks, Use Cases ,etc
  • Perform proactive analysis across client networks by staying abreast of current threats and trends
  • Develop and maintain a credible knowledge of current and emerging threats likely to affect the Integrity of the managed service you are protecting.
  • Review reoccurring false positive firings and assist in the tuning of SIEM and IDS rules to reduce false positives and maintain good security alerting.
  • Ensure all operational incidents, on-going tickets and relevant information is handed over to the oncoming shift in an effective and efficient manner, using the shift handover process and documentation (HOTO)
  • When required assist in the creation of reporting for management and clients on security incidents and threat intelligence trends.
What you'll bring
  • Be able to excellently communicate at all levels, working with customers is a must, so we need you to be able to let them know what's going on
  • Experience in Cyber Security, e.g. Protective Monitoring, Incident Response, Security Engineering
  • SIEM (LogRhythm, Arcsight, Splunk, etc) & IDS (Snort) experience
  • Have a sound knowledge of IT security best practice, common attack types & detection / prevention methods
  • Demonstrate experience of analysing & interpreting system, security & application logs in order to diagnose faults & spot abnormal behaviours
  • Have great organisational skills & attention to detail
  • Ability to work independently & as part of a team
  • Highly motivated, with the aptitude to learn new skills
  • Ability to work within a Hybrid Remote Working shift pattern covering 24/7/365 operations
  • Occasional travel may be required

These additional skills will also help:

  • SANS SEC 503 Intrusion Detection in Depth or equivalent
  • SANS SEC 504 Incident Handling, Hacker Tools and Techniques or equivalent
  • SANS SEC 508 Advanced Incident Response, Threat Hunting, and Digital Forensics or equivalent
  • SANS SEC 511 Continuous Monitoring and Security Operations or equivalent
  • Exposure to IT service management best practices such as ITIL
  • Knowledge of standards & guidelines such as ISO27001,GDPR principles and GPG-13.
  • Threat Intelligence experience
  • Report Writing
Security Clearance

This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). For more information and guidance please visit: https://careers.uk.leonardo.com/gb/en/security-and-vetting

Why join us

At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we're here to help you thrive.

  • Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year.
  • Secure your Future: Benefit from our award-winning pension scheme with up to 15% employer contribution.
  • Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks championing inclusion and diversity (Enable, Pride, Equalise, Armed Forces, Carers, Wellbeing and Ethnicity).
  • Rewarding Performance: All employees at management level and below are eligible for our bonus scheme.
  • Never Stop Learning: Free access to 4,000+ online courses via Coursera and LinkedIn Learning.
  • Refer a friend: Receive a financial reward through our referral programme.
  • Tailored Perks: Spend up to £500 annually on flexible benefits including private healthcare, dental, family cover, tech & lifestyle discounts, gym memberships and more.
  • Flexible working: Flexible hours with hybrid working options. For part time opportunities, please talk to us about what might be possible for this role.

For a full list of our company benefits please visit our website.

Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team-they are key contributors to shaping innovation, advancing technology, and enhancing global safety.

At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know.

Be part of something bigger - apply now!

Primary Location

GB - Bristol - Coldharbour Lane

Contract Type

Permanent

Hybrid Working

Onsite

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.