Security Analyst

AXA UK

West of England

Hybrid

GBP 60,000 - 90,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Accessibility Concierge
Flexible working arrangements
Hybrid work model

Job summary

AXA UK is seeking a Security Analyst to join the Proactive Security team and support Breach and Attack Simulation tooling. The role focuses on challenging defences using attacker techniques within regulated environments, utilising MITRE ATT&CK, CREST, CBEST, TIGER and ISO frameworks.

You will work with cutting-edge tooling and experienced security professionals, building skills for a future in cyber security across cloud and on-premises environments.

Qualifications

  • Hands-on technical penetration testing experience (internal, external, web, cloud).
  • Deep understanding of IT systems and vulnerabilities across cloud environments and on-prem components.
  • Experience in cloud security engineering or IT infrastructure is advantageous.
  • Strong analytical and problem-solving skills; ability to dig into technical details.
  • Comfortable challenging ambiguity and asking the right questions.

Responsibilities

  • Review threat intelligence feeds and testing findings to prioritise BAS use cases.
  • Support penetration testing engagements and validate scope and reports.
  • Review remediation plans and verify fixes with BAS tooling.
  • Investigate BAS control test failures and raise remediation requests.
  • Produce clear metrics and reports for executive steering groups.
  • Identify opportunities to sharpen, simplify and scale processes.

Skills

Penetration testing
Cloud security
Threat modelling
MITRE ATT&CK
Security frameworks
Analytical skills
Communication
OSCP/ MSc desirable

Education

OSCP or equivalent
MSc in Cyber Security or IT (desirable)

Tools

AWS
Azure
GCP

Job description

About AXA

AXA is a global leader in insurance and financial services, dedicated to helping customers protect what matters most to them. As the sixth-largest insurance company in the world, we provide a wide range of services, including health, car, home, and business insurance. We support millions of customers worldwide, helping them navigate life's uncertainties with confidence.

AXA UK Support Functions look after our three customer-facing business units, providing the infrastructure and expertise to make sure we can be there for our customers.

Job overview

We have a new opportunity for a Security Analyst to join our Proactive Security team in AXA UK to support our Breach and Attack Simulation tooling. As part of AXA UK's Cyber Security function, you'll move beyond simply identifying vulnerabilities in the traditional way - you'll play an active role in continuously challenging our defences using real-world attacker techniques. This role sits at the intersection of technical depth and strategic impact, giving you exposure to complex and regulated environments. You'll work with industry-leading frameworks, cutting-edge tooling and experienced security professionals - building skills and credibility that will serve you throughout your career.

Key responsibilities
  • Reviewing threat intelligence feeds and penetration test findings to identify and prioritise use cases for Breach and Attack Simulation (BAS), ensuring our testing reflects the real-world threat landscape.
  • Supporting penetration testing engagements by validating that scope is appropriate and that reports meet AXA's standards, giving you a front-row seat to a wide variety of technical assessments.
  • Reviewing remediation plans arising from penetration testing activity, ensuring that proposed fixes will genuinely address identified issues within acceptable timeframes - and then verify that they do, using BAS tooling.
  • Reacting to BAS control test failures, investigating root causes, and raising targeted remediation requests with the right technical teams.
  • Producing clear, meaningful metrics and reports for executive steering groups, translating complex technical findings into actionable insight for senior audiences.
  • Constantly looking for opportunities to sharpen, simplify, and scale our processes - your ideas will be welcomed and acted upon.
Work arrangements

At AXA we work smart, empowering our people to balance their time between home and the office in a way that works best for them, their team and our customers. You'll work at least two days a week (40%) away from home, moving to three days a week (60%) from December 2026. Away from home means attending the office, visiting clients or attending industry events. We're also happy to consider flexible working arrangements, which you can discuss with Talent Acquisition.

Your skills & experience
  • Prior hands-on technical penetration testing experience (internal, external, web application, cloud)
  • A deep understanding of IT systems and vulnerabilities, ideally spanning cloud environments (AWS, Azure, GCP), infrastructure components such as web and application servers, firewalls, proxies and operating systems and application code security.
  • Experience in cloud security engineering, architecture or general IT infrastructure is advantageous.
  • Strong analytical and problem-solving skills, with the ability to dig into technical detail.
  • Confidence to challenge ambiguity and ask the right questions.
  • A genuine curiosity about how systems can be broken - and how to make them more resilient.
  • Comfortable working with industry frameworks, including threat behaviour modelling e.g. MITRE ATT&CK, Vulnerability management e.g. CVSS, Penetration testing standards e.g. CREST, CBEST, TIGER and Security frameworks e.g. NIST, ISO 27001/27002.
  • OSCP or equivalent practical penetration testing certification or an MSc in Cyber Security or Information Technology is desirable but not essential.

We're proud to be an Equal Opportunities Employer and don't discriminate against employees or potential employees based on protected characteristics. If you have a long-term condition or disability and require adjustments during the application or interview process, we're proud to offer access to the AXA Accessibility Concierge.

#LI-Hybrid

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

AXA Group • West of England, Greater London

On-site
GBP 55,000 - 90,000
Security Analyst
Security Analyst

AXA UK • Greater London

Hybrid
GBP 70,000 - 95,000
Proactive Security Analyst: Breach & Attack Simulation
Proactive Security Analyst: Breach & Attack Simulation

AXA UK • Greater London

Hybrid
GBP 70,000 - 95,000
Proactive Security Analyst - Breach & Attack Simulation
Proactive Security Analyst - Breach & Attack Simulation

AXA Group • West of England, Greater London

Hybrid
GBP 55,000 - 90,000
Incident Response Analyst
Incident Response Analyst

AXA UK • Bolton

Hybrid
GBP 45,000 - 60,000
Incident Response Analyst
Incident Response Analyst

AXA UK • West of England

Hybrid
GBP 55,000 - 75,000
Flexible working
Incident Response Analyst
Incident Response Analyst

AXA UK • Leeds

Hybrid
GBP 60,000 - 85,000
Incident Response Analyst
Incident Response Analyst

AXA UK • Royal Tunbridge Wells

Hybrid
GBP 45,000 - 65,000
Incident Response Analyst
Incident Response Analyst

AXA UK • Ipswich

Hybrid
GBP 55,000 - 75,000
Proactive Security Analyst: BAS & Threat Intelligence
Proactive Security Analyst: BAS & Threat Intelligence

AXA UK • West of England

Hybrid
GBP 60,000 - 90,000
Accessibility Concierge
Flexible working arrangements
Hybrid work model