Information Security Analyst

ONYX Insight

Nottingham

Hybrid

GBP 50,000 - 80,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

ONYX Insight is seeking a hands-on Security Operations professional to lead day-to-day monitoring, vulnerability management, incident response, and internal audit activities within a small specialist team. You will coordinate with an external SOC/MDR and contribute to ISO 27001 compliance while avoiding governance-only duties.

The role sits in a growing IIoT context with global responsibilities and regulatory considerations across multiple regions, focusing on practical security delivery and

Qualifications

  • 3-5 years of hands-on information security operations experience.
  • Practical experience maintaining CSPM, SAST, and DAST tooling.
  • Experience contributing to ISO 27001 or equivalent risk assessments.
  • Experience working with external SOC or MDR providers.
  • Strong written communication with ability to produce findings and risk entries.
  • Hands-on, independent worker in a small team.

Responsibilities

  • Operate as the primary hands-on resource for security monitoring, triage, and incident response.
  • Maintain CSPM, SAST, and DAST tooling to defined standards.
  • Coordinate vulnerability management and internal/external penetration testing.
  • Conduct internal security audits and risk assessments with findings reports.
  • Support ISO 27001 compliance activity including audit evidence.
  • Produce audit-ready outputs: risk registers and policy updates.

Skills

Security operations
CSPM tooling
SAST
DAST
ISO27001 risk assessments
SOC/MDR collaboration

Education

CISSP
CISM
ISO27001 Lead Auditor
IEC 62443

Tools

AWS

Job description

The role

This is a hands-on security operations role. You will be the primary practitioner resource within a small, specialist Cyber Security team of three, including the VP, responsible for day-to-day security monitoring, vulnerability management, incident response, and internal audit activity that keeps our security posture credible and improving. Hands-on delivery is the core expectation; this is not a governance or oversight position.

You will work closely with an external SOC and MDR provider, acting as the internal security practitioner against their outputs. The role also requires genuine compliance capability, you will contribute to internal audit and risk assessment cycles and support ISO 27001 compliance activity. You will provide ad-hoc expert input to the IT function where security judgement is needed, but this is not an IT role.

ONYX is a critical infrastructure business manufacturing IIoT devices for wind turbine monitoring. We operate globally, with customers and regulatory obligations spanning the EU, UK, US, Australia, Canada, India, and South Korea. Our Cyber Security function is small, expert, and operationally engaged, this role sits at the centre of that.

What you will be doing
  • Operating as the primary hands-on resource for security monitoring, triage, and incident response, working with the external SOC and MDR provider
  • Operating and maintaining security tooling, including CSPM, SAST, and DAST platforms, ensuring coverage, configuration, and outputs are maintained to a defined standard
  • Managing the vulnerability management programme, including coordination of internal and external penetration testing
  • Conducting internal security audits and risk assessments, producing findings reports and tracking remediation
  • Supporting ISO 27001 compliance activity, including contributing to control evidence and audit cycles
  • Producing clear written outputs -- findings reports, risk registers, policy updates -- to a good standard suitable for internal and external audit
What we are looking for
Essential:
  • 3-5 years of hands-on experience in an information security operations role
  • Practical experience operating and maintaining security tooling, including CSPM, SAST, and DAST platforms
  • Practical experience contributing to internal audits and risk assessments against ISO 27001 or a comparable framework (NIST CSF, SOC 2, Cyber Essentials Plus)
  • Experience working with external SOC or MDR providers
  • Strong written communication; able to produce findings reports and risk register entries to a good standard
  • Able to operate hands-on and independently in a small team
Desirable:
  • Experience in a regulated industry, particularly critical infrastructure, energy, or manufacturing
  • Familiarity with IEC 62443 or the EU Cyber Resilience Act
  • Relevant certification: CISSP, CISM, or equivalent; ISO 27001 Lead Auditor working towards or held
  • Experience with cloud security, particularly AWS
About ONYX

ONYX Insight is a growing technology and engineering organisation in the renewable energy sector. Our vision is to build a more efficient future by becoming the world's most innovative provider of predictive technology solutions. Our advanced sensing, software and analytics combined with our engineering experience are deployed on wind turbines around the world to maximise production and make turbines more reliable for longer, optimising energy production and supporting the global transition to renewable energy.

ONYX Insight is part of the Macquarie Group. Macquarie is a global financial services group operating in 34 markets in asset management, leasing and asset financing, market access, commodity trading, renewables development, specialist advisory services, capital raising and principal investment. The diversity of the Macquarie Group operations combined with a strong capital position and robust risk management framework has contributed to a 54 year-record of unbroken profitability.

For any further information, or to understand our products and services better, please feel free to look through our website: ONYX Insight Website

ONYX Insight are an equal opportunity employer and value diversity at our company. We do not discriminate based on race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Quality Lead - Hardware Engineering
Quality Lead - Hardware Engineering

ONYX Insight • Nottingham

On-site
GBP 70,000 - 120,000
Hands-On Security Ops Analyst: ISO 27001 & Vulnerability Mgmt
Hands-On Security Ops Analyst: ISO 27001 & Vulnerability Mgmt

ONYX Insight • Nottingham

Hybrid
GBP 50,000 - 80,000
Graduate Engineer
Graduate Engineer

Onyx-Insight-1 • Nottingham

On-site
GBP 24,000 - 32,000
Field Engineer
Field Engineer

ONYX Insight • Nottingham

On-site
GBP 30,000 - 45,000
Career development opportunities
Work with cutting-edge technology
Opportunity to make an impact in renewable energy
Graduate Engineer
Graduate Engineer

ONYX Insight • Nottingham

On-site
GBP 26,000 - 34,000
Wind Turbine Technician - Borescope
Wind Turbine Technician - Borescope

ONYX Insight • Nottingham

Hybrid
GBP 32,000 - 52,000
Logistics/Shipping Coordinator
Logistics/Shipping Coordinator

Onyx-Insight-1 • Nottingham

On-site
GBP 28,000 - 38,000
Security Operations Manager
Security Operations Manager

Artificial Labs • Harrow

On-site
GBP 90,000 - 130,000
Private medical insurance
Income protection insurance
Life insurance 4x base salary
+3
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Lightsource bp • Greater London

On-site
GBP 70,000 - 100,000
Finance Analyst
Finance Analyst

ONYX Insight • Nottingham

On-site
GBP 40,000 - 55,000