The role of Cyber Security Analyst is important to us.
As part of our dedicated Cyber Security team, you will report to our Head of Cyber and be based from our Emperor Court office in Crewe, Cheshire.
As a Cyber Security Analyst, you will play a key role in protecting systems, networks, and data against cyber threats. You will participate in threat detection and incident response efforts, support the development of security policies and controls, and work closely with stakeholders to ensure compliance and security best practice across the business.
You will also assist with maintaining and improving the company's accredited Information Security Management System (ISMS), with a particular focus on ISO 27001 and Cyber Essentials Plus requirements.
In addition, you will work collaboratively with the wider Cyber Security team to define and mature Security Operations Centre (SOC) processes, ensuring the effective day-to-day operations of security controls.
This is an excellent opportunity for a seasoned professional to contribute to a high-performing Cyber Team in a fast-paced and evolving environment.
Your responsibilities day to day will be...
- Work closely with IT Operations teams and wider business functions to implement and optimise technologies and security controls that enhance the organisation's cyber security posture across internal and customer-facing platforms.
- Proactively identify cyber security risks, control deficiencies and opportunities for security improvement, making recommendations to reduce organisational risk.
- Support the design, implementation and ongoing development of cloud-based infrastructure and services, ensuring security best practices are embedded by design.
- Collaborate with software development teams to ensure secure design principles and cyber security requirements are integrated throughout the Software Development Lifecycle (SDLC).
- Create, maintain and review cyber security policies, standards, procedures and technical documentation.
- Monitor security events and alerts, conducting threat detection, investigation and incident response activities to minimise business impact.
- Perform vulnerability management activities, including vulnerability identification, risk assessment, remediation tracking and reporting.
- Conduct threat intelligence research, analysing emerging threats, vulnerabilities and attack techniques, and recommend appropriate security improvements.
- Work with third-party security vendors, managed service providers and consultants to support security operations, resolve issues and implement security enhancements.
- Lead cyber security projects and initiatives aimed at improving the organisation's security capability, resilience and compliance posture.
- Contribute to the development and maintenance of security monitoring, detection and response capabilities across the organisation.
- Assist with security risk assessments, audits, compliance activities, and the implementation of security controls aligned to recognised frameworks and standards.
- Commitment to keeping up to date with emerging technologies
What do we expect of you?
Technical knowledge and skills:
- Strong technical knowledge of cyber security and its practical application across technology environments.
- Good understanding of application security and experience working with development teams to promote secure development practices.
- Experience with Vulnerability Management, penetration testing and security assessments, including prioritising and driving remediation.
- Experience with EDR, NDR and SIEM technologies, including security monitoring, alert investigation and response.
- Understanding of cyber incident response, including triage, investigation, containment and recovery.
- Knowledge of Cyber Essentials, Cyber Essentials Plus and ISO 27001.
- Good understanding of operating systems, infrastructure and networking, including Windows and Linux environments, servers, virtualisation, databases, web servers, TCP/IP, DNS, firewalls and common infrastructure security controls.
- Good understanding of cloud security, preferably AWS, including IAM, logging, monitoring and configuration.
- Understanding of DLP, data security and open-source/software supply-chain risk.
- Good understanding of network security, WAFs, IAM and secure architecture principles.
- Understanding of Red Teaming, Continuous Adversarial Testing and Vulnerability Disclosure Programmes.
- Understanding of Cyber Threat Intelligence, phishing, social engineering and insider risk management.
- Good understanding of MITRE ATT&CK and NIST Cybersecurity Frameworks.
- Strong analytical and problem-solving skills, with the ability to investigate technical security issues and recommend appropriate actions.
- Ability to produce clear technical documentation, reports and security recommendations.
- Ability to communicate effectively with technical and non-technical stakeholders.
- Understanding of ITIL/service management principles and the ability to manage and prioritise multiple activities.
- Commitment to keeping up to date with emerging technologies