IT Security Analyst

Withersworldwide

Greater London

On-site

GBP 45,000 - 65,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Pension
Private medical insurance
Season ticket loan
Gym memberships subsidy
Lifestyle discount scheme
On-site café

Job summary

Withers seeks an experienced IT Security Analyst to support security operations across the firm’s global technology estate. The successful candidate will work on endpoint detection, cloud security, threat monitoring and vulnerability management, engaging with IT teams, senior stakeholders and vendors.

Experience in a medium to large professional services environment is desirable, with strong communication skills to explain complex security topics to non-technical audiences.

Qualifications

  • 3+ years' experience in cyber security, security operations or a related technology role.
  • Experience in security monitoring, alert triage, threat detection and incident response.
  • Hands-on experience with SIEM/XDR, endpoint protection, cloud security and data loss prevention.
  • Ability to explain technical security matters clearly to legal, business and IT stakeholders.

Responsibilities

  • Monitor, triage and investigate security alerts across the firm’s security platforms and perform root cause analysis.
  • Support incident response activities including containment, eradication, recovery and evidence preservation.
  • Maintain and improve security monitoring, detection rules, alert workflows and runbooks.
  • Assist with vulnerability management, due diligence, audit responses and compliance monitoring.
  • Provide risk-based security advice for changes, cloud services and new technologies.
  • Support disaster recovery and business resilience testing.
  • Collaborate across offices to align with security standards and risk appetite.
  • Keep up-to-date with technologies, threats and security best practices.

Skills

Cyber security
Incident response
Security operations
Identity & cloud security
MITRE ATTACK

Job description

About Withers

A law firm focused on people, performance, and collaboration.

For the past 130 years, we have supported some of the world's most remarkable people and organizations at defining moments in their lives. 40% of our business comes from Europe, 40% from the US and 20% from Asia and we are one profit sharing partnership globally.

We are united in our commitment to integrity, quality and collaboration. We have a culture of high performance and deliver excellent service consistently across the firm. We provide tailored solutions built on trust and partner with our clients to achieve their goals.

Many of our clients are shaping the future and creating solutions to tackle some of the world's most difficult problems. It makes for a fascinating and challenging practice.

Our role is to get to know each individual client, find out where they want to be, and help them to get there – whether they are building a business, buying a home or protecting and defending their interests.

To meet their unique needs we are exceptionally collaborative, working together across teams and time zones. And we are agile – focusing on strategy rather than rigid ideas and traditional hierarchy.

Join us to be part of a team that is always looking to the future. Where initiative, big ideas and bold moves are always encouraged. Where you can truly be yourself.

What are we looking for?

We are looking for an experienced IT Security Analyst to support security operations across the firm's global technology estate. The successful candidate should have practical experience working with modern enterprise security platforms covering endpoint detection and response, extended detection and response, cloud security, threat monitoring, behavioural analytics and vulnerability management, and be comfortable engaging with IT teams, senior stakeholders and third-party vendors.

Experience in a medium to large, multi-site professional services environment is desirable. Strong written and verbal communication skills are essential, including the ability to explain technical security matters clearly to legal, business and IT stakeholders.

The role requires good judgement, personal organization, professionalism and the ability to prioritise effectively under pressure. A pragmatic, service-focused approach is essential.

Areas of focus and responsibilities
  • Monitor, triage and investigate security alerts across the firm's security monitoring and response platforms, including suspicious activity, root cause analysis and proportionate remediation.
  • Support incident response activities, including containment, eradication, recovery, evidence preservation and clear documentation of findings and actions.
  • Maintain and improve security monitoring, detection rules, alert workflows, operational playbooks, procedures and management reporting.
  • Assist with vulnerability management, supplier and client due diligence returns, audit responses, evidence gathering and compliance monitoring against policies, standards and regulatory or client requirements.
  • Provide practical, risk-based security advice for change advisory matters, projects, cloud services, new technologies and internal security queries.
  • Support disaster recovery, business continuity and resilience testing
  • Work with colleagues across all offices to support a consistent global approach to security operations, incident response and alignment with the firm's security standards and risk appetite.
  • Maintain current knowledge of supported technologies, emerging cyber threats and security best practice.

This list of duties and responsibilities is not exhaustive. It is intended to describe the general content of, and requirements for the performance of this job, and as such, the role may also include the undertaking of additional tasks as required.

Skills and attributes
  • 3+ years' experience in cyber security, security operations, incident response or a related technology role, ideally within a medium to large professional services environment.
  • Practical experience of security monitoring, alert triage, threat detection, incident response, business email compromise, suspicious user activity and vulnerability management.
  • Hands-on experience with modern security operations tooling, including SIEM/XDR, endpoint protection, cloud security, email security, data loss prevention, information protection, behavioural analytics and vulnerability management platforms
  • Good understanding of identity, access and cloud security, including Entra ID, MFA, Conditional Access, privileged access, SaaS logging, endpoint telemetry, evidence preservation and audit trails.
  • Awareness of common attack techniques and frameworks, including MITRE ATT&CK, and relevant security, privacy and assurance frameworks such as ISO 27001, NIST CSF, Cyber Essentials and GDPR.
  • Ability to manage security findings through to remediation, including prioritisation, risk acceptance, progress tracking and clear incident, risk and management reporting.
  • Most important is a desire to learn, develop and help keep the firm secure, resilient and trusted by its clients.
The Essentials
  • 9.30am to 5.30pm with reasonable out-of-hours flexibility required for urgent security incidents, investigations and response activities as part of the security team
  • Hybrid working policy with a minimum of 2 days per week worked in the office
  • 12 week probation period
  • 4 week notice period
  • Flexible benefits package including pension, private medical, season ticket loan, subsidised gym memberships, lifestyle discount scheme, on site café.
Information for Recruitment Agencies

Withers endeavours to recruit and fill vacancies directly. However, when we do need to engage with agencies, Withers operates a preferred supplier list and will not be accepting unsolicited applications from non-PSL agencies for this role.

Equal Opportunities Employment Statement

It is the policy of Withers to provide equal opportunities for all employees in relation to recruitment, training and promotion. Decisions in these areas will be made only by reference to the requirements of the job and shall not be influenced by any consideration of age, disability, gender reassignment, marriage or civil partnership, pregnancy or maternity, race including colour, nationality and ethnic and national origin, religion or belief, sex or sexual orientation.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Analyst
IT Security Analyst

Withers • Greater London

On-site
GBP 50,000 - 70,000
Pension
Private medical
Season ticket loan
+3
IT Service Desk Team Leader
IT Service Desk Team Leader

Withers • Greater London

Hybrid
GBP 42,000 - 62,000
Pension
Private medical insurance
Season ticket loan
+2
Client Relationship Coordinator (Client Onboarding & Invoicing)
Client Relationship Coordinator (Client Onboarding & Invoicing)

Withers • Greater London

On-site
GBP 35,000 - 48,000
IT Technical Systems Analyst (EUC Team)
IT Technical Systems Analyst (EUC Team)

Withersworldwide • City of Westminster

On-site
GBP 60,000 - 90,000
Information Security Analyst - Security Operations Centre
Information Security Analyst - Security Operations Centre

PA Consulting Group • West of England

Hybrid
GBP 60,000 - 90,000
Health and lifestyle perks
25 days annual leave
Generous pension
+4
IT Security Analyst
IT Security Analyst

Witherslack Group • Bolton

On-site
GBP 35,000 - 45,000
Ongoing professional development
7 weeks’ holiday
Flexible benefits package
+2
Security Engineer - 6 month FTC
Security Engineer - 6 month FTC

Walkers • Greater London

Hybrid
GBP 25,000 - 36,000
Red Team Security Specialist
Red Team Security Specialist

SmartRecruiters, Inc. • Greater London

Hybrid
GBP 90,000 - 130,000
Information Security Analyst - Security Operations Centre
Information Security Analyst - Security Operations Centre

SmartRecruiters, Inc. • Royston

Hybrid
GBP 55,000 - 75,000
Health and lifestyle perks
25 days annual leave (plus a bonus ½)
Generous pension
+4
Senior Security Engineer - 6 month FTC
Senior Security Engineer - 6 month FTC

Walkers • Greater London

Hybrid
GBP 90,000 - 120,000