Information & Cyber Security Specialist

Scotch Whisky

Cumbernauld

On-site

GBP 55,000 - 90,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Private Healthcare
Doctor@Hand (remote GP)
Cycle to Work
Life Assurance
Pension plan
Employee Assistance Programme
Product allocation
Learning resources

Job summary

Scotch Whisky is seeking an experienced Information & Cyber Security Specialist to join our integrated Cyber Security function. The role centers on security operations, incident investigation, detection engineering, vulnerability management and automation, with scope to shape capabilities.

Based in Arete, Cumbernauld (G88 0HH), the role operates four days on site and one day from home, with on-call involvement for significant incidents.

Qualifications

  • Strong analytical and investigative judgement.
  • Ability to work independently and own outcomes.
  • Clear written and verbal communication.
  • Willingness to contribute beyond primary specialism.

Responsibilities

  • Investigate security alerts and incidents using SIEM, XDR, identity, endpoint, email, network and cloud telemetry.
  • Coordinate containment, eradication and remediation activities with priorities.
  • Develop, test and tune detections; improve alert quality and coverage.
  • Own security operations capabilities; drive improvements and best practices.
  • Oversee vulnerability management including scanning, prioritisation and remediation.
  • Create runbooks and documentation for investigations and operational evidence.
  • Work with IT Operations and external partners to address weaknesses.
  • Develop automation and orchestration to improve investigation workflows.
  • Participate in on-call rota and respond to major incidents.

Skills

Incident investigation
SIEM/XDR
Detection engineering
Vulnerability management
Endpoint security
Identity security
Cloud security
Automation
Orchestration
Microsoft Defender

Tools

Microsoft Defender
Microsoft Entra
Conditional Access
SOAR

Job description

We are looking for an experienced Information & Cyber Security Specialist to join our newly integrated Cyber Security function. This role has a primary focus on security operations, incident investigation, detection engineering, vulnerability management and security automation and orchestration. It offers the opportunity to take meaningful ownership of operational security capabilities, influence how they develop and help shape a modern, intelligence-led and increasingly automated Cyber Security function.

Reporting into the Information & Cyber Security Leader, you will work hands-on with security technologies, investigations and improvement activity, while collaborating with colleagues across Cyber Security, Architecture, IT Operations, business teams and our external security providers. This is not a line management role. However, you will have the autonomy to shape assigned capabilities, improve how services operate, share your expertise and support the development of colleagues.

Key responsibilities
  • Investigate security alerts and incidents using SIEM, XDR, identity, endpoint, email, network and cloud telemetry.
  • Support the coordination of containment, eradication, and remediation activity, ensuring actions are understood, appropriately prioritised and completed.
  • Develop, test and tune security detections, improve alert quality and help maintain visibility of detection coverage against relevant threats and attacker techniques.
  • Take ownership of assigned security operations capabilities, identifying weaknesses, proposing improvements and seeing agreed work through to completion.
  • Operate vulnerability management processes, including scanning, validation, threat-informed prioritisation, remediation coordination, exception escalation and closure assurance.
  • Work with IT Operations, system owners and suppliers to ensure material vulnerabilities and security weaknesses are addressed within agreed timescales.
  • Develop automation and orchestration that improve investigation, enrichment, triage, evidence collection, reporting and response workflows.
  • Explore and implement appropriate uses of Microsoft Security Copilot, AI and SOAR technologies, ensuring automated activity remains controlled, auditable and subject to appropriate human review.
  • Support the operation and improvement of Microsoft Defender, Microsoft Entra, Conditional Access, endpoint security, identity controls and other assigned security technologies.
  • Create and maintain clear runbooks, technical procedures, investigation records, service documentation and operational evidence.
  • Share knowledge with colleagues and provide practical coaching and quality support to the Information & Cyber Security Analyst.
  • Contribute to wider information security, cyber risk, assurance, third-party security, governance and compliance activities as team priorities require.
  • Participate in the Cyber Security on-call rota and support the response to significant out of hours cyber incidents.
About you

You will have strong hands-on cyber security experience and be comfortable taking an investigation or improvement activity from initial identification through to a clear outcome. You should be able to demonstrate experience in several of the following areas:

  • Security incident investigation and response.
  • SIEM or XDR investigation.
  • Detection engineering and alert tuning. [CH1]
  • Vulnerability management.
  • Endpoint, identity, email, network or cloud security.
  • Analysing and correlating security telemetry.
  • Incident-response procedures and playbooks.
  • Security automation, orchestration or scripting. [CH2]
  • Working with a managed SOC, MDR or other external security partners.
  • Translating technical findings into clear risks, decisions and actions.

You will also need:

  • Strong analytical and investigative judgement.
  • The ability to work independently and take ownership of assigned outcomes.
  • A practical, delivery-focused approach and willingness to get involved.
  • Clear written and verbal communication.
  • Willingness to contribute outside your primary specialism when wider Cyber Security priorities require it.
  • The existing right to work in the United Kingdom.

DESIRABLE EXPERIENCE

Experience in any of the following would be advantageous, but is not essential:

  • Taegis XDR or MDR.
  • Sophos security technologies.
  • Microsoft Defender.
  • Microsoft Entra and Conditional Access.
  • Microsoft Security Copilot.
  • Microsoft Sentinel.
  • Threat hunting.
  • Digital forensics and evidence handling.
  • Security Architecture or design assurance.

HOW WE WORK

Our Information Security and Security Operations teams have recently come together as one Cyber Security function. We are developing an integrated operating model covering governance, risk, protection, detection, incident response, resilience, automation and continuous improvement.

Each team member will have areas of expertise and ownership, but cross-skilling and collaboration are fundamental to how the team will operate. You will be encouraged to bring ideas, challenge existing ways of working and put your own stamp on the capabilities assigned to you. You must be willing to support colleagues, share knowledge and help get priority security work over the line as the new function develops.

WORKING ARRANGEMENTS

The role is based in Arete, Cumbernauld (G88 0HH) with an expected working pattern of four days on site and one day working from home. Occasional travel to other WG&S sites will be required. The successful candidate will participate in an out-of-hours call rota.

Reward and benefits
  • We offer a competitive salary and benefits which are designed to promote our employees financial wellbeing. Employees are also eligible to participate in a bonus plan.
  • Our employees enjoy a generous holiday entitlement and an opportunity to ‘buy’ or ‘sell’ some holiday entitlement.
  • Private Healthcare and Doctor@Hand (remote GP service).
  • Our employees can join a defined contribution pension plan. Employees contribute either 4% or 5% of salary, the company contributes 8% or 10% depending on the employee contribution. Employee contributions can be made through salary sacrifice.
  • Our Employee Assistance Programme offers practical, impartial support on everyday matters ranging from medical, financial and legal to home and family issues.
  • Our Life Assurance cover is a multiple of eight times your annual basic salary.
  • Product allocation so that you can enjoy our fantastic portfolio of brands.
  • Our Cycle to Work scheme allows you to hire a bike for an agreed length of time, and then snap it up for a fraction of its original value. All while making savings (at least 25%) and spreading the cost.
  • Every employee has the opportunity to claim up to £1,000 per year for a charity or charities for which they have raised money, volunteered their time or personally donated.
  • Learning resources to help you be your best self.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

Doherty Associates • Greater London

On-site
GBP 30,000 - 42,000
34 days annual leave
Private medical insurance
Company Pension
+1
Security Analyst
Security Analyst

Doherty Associates • City Of London

On-site
GBP 35,000 - 52,000
Performance bonus
34 days annual leave
Private medical insurance
+2
Head of Cyber Security and Productivity Solutions
Head of Cyber Security and Productivity Solutions

M+C Saatchi UK • Greater London

On-site
GBP 120,000 - 180,000
Cultural stimulation allowance – £250 per person per year
Half days off before bank holidays
Emergency care days for dependants
+5
Senior Security Consultant
Senior Security Consultant

ITC Secure • Greater London

Hybrid
GBP 70,000 - 90,000
25 days annual leave
Private health insurance
Enhanced maternity and paternity leave
+2
Senior Cyber Analyst
Senior Cyber Analyst

Methods Business and Digital Technology • Greater London

Hybrid
GBP 70,000 - 110,000
Flexible Working
Wellness Programme
Pension
+4
Senior Cyber Analyst
Senior Cyber Analyst

Methods • Greater London

On-site
GBP 90,000 - 130,000
Autonomy to develop
Flexible working
Private medical insurance
+1
Lead Cyber Security Engineer
Lead Cyber Security Engineer

SThree • Glasgow

Hybrid
GBP 60,000 - 85,000
Hybrid working model
28 days holiday allowance
Private healthcare
Security Analyst
Security Analyst

Doherty • Greater London

Hybrid
GBP 32,000 - 42,000
Basic salary + performance bonus
34 days annual leave
Private medical insurance
+3
IT Security Analyst
IT Security Analyst

Menzies LLP • Woking

On-site
GBP 42,000 - 58,000
Career Development
Private medical cover
Pension matching
+2
Cyber Security Analyst
Cyber Security Analyst

AWD online • West of England

Hybrid
GBP 27,000 - 30,000
Training & Development
25 days holiday
Company pension
+6