**This role will be based on site in Stockley Park 5 days per week**
The Role:
Reporting to the IT Security Lead, the Analyst will support in ensuring that Accord's systems are secure, compliant and resilient.
This role will include, but not be limited to:
- Incident Response: Monitor, investigate and respond to Security events across the organisation
- Firewall Management: Configure, audit and tune network and web application firewall rules
- Web/DNS filtering: Administer and optimise the organisations web security gateway to block malicious websites and content
- Vulnerability Management: Conduct regular vulnerability scans on networks, systems and devices. Tracking remediation activities from findings through to closure
- Phishing Simulation and User Awareness Training: Designing, coordinating and conducting phishing simulation campaigns as part the security awareness programme
- Security Reporting: Prepare and deliver regular security reports, summarising key metrics
- Documentation & Compliance: Maintain clear documentation of security incidents, investigation findings, configuration changes. Creation and updating of internal playbooks and knowledge base articles
- System Hardening: Apply and verify security baselines on servers and endpoints and proactively suggest improvements where applicable
- Continuous Improvement: Stay up to date with latest cybersecurity threats, trends, defensive techniques and vulnerabilities. Proactively suggest improvements to security monitoring, configurations and processes to enhance the organisations Security Posture
The Person:
- Formal training or demonstrable experience in information security, computer science, or a closely related IT discipline.
- CompTIA Security+ certification (or equivalent practical knowledge and experience).
- Experience supporting security operations activities, including monitoring alerts, basic investigation, and assisting in incident response.
- Working knowledge of Microsoft security technologies such as Defender for Endpoint, Defender for Office 365, and Azure AD / Entra ID.
- Understanding of firewall and web security principles, with practical exposure to managing or tuning network and web filtering rules.
- Familiarity with vulnerability management processes — running scans, reviewing findings, and tracking remediation.
- Awareness of phishing simulation and awareness training approaches and their role in improving organisational resilience.
- Working toward recognised professional certifications such as Microsoft SC-200, AZ-500, or CompTIA CySA+.
- Experience using SIEM or EDR platforms (e.g. Microsoft Sentinel, Splunk, or equivalent) for monitoring and investigation.
- Exposure to vulnerability scanning tools such as Nessus, Qualys, or Defender Vulnerability Management.
- Basic scripting or automation capability (PowerShell or Python).
- Awareness of Cyber Essentials Plus, ISO 27001, or similar frameworks.
- Experience gained in a technical support, IT operations, or SOC environment.
The Rewards:
In return, we offer a competitive salary and rewards package (including holiday, bonus and pension scheme). Not to mention the opportunity to genuinely make a difference in a new and dynamic role within a progressive and expanding business, at an exciting time of growing international reach