UK remote
Cyber Security Analyst
About this role
The role of Cyber Security Analyst is important to us. As part of our dedicated Cyber Security team, you will report to our Head of Cyber and be based from our Emperor Court office in Crewe, Cheshire. As a Cyber Security Analyst, you will play a key role in protecting systems, networks, and data against cyber threats. You will participate in threat detection and incident response efforts, support the development of security policies and controls, and work closely with stakeholders to ensure compliance and security best practice across the business.
You will also assist with maintaining and improving the company’s accredited Information Security Management System (ISMS), with a particular focus on ISO 27001 and Cyber Essentials Plus requirements. In addition, you will work collaboratively with the wider Cyber Security team to define and mature Security Operations Centre (SOC) processes, ensuring the effective day-to-day operations of security controls. This is an excellent opportunity for a seasoned professional to contribute to a high-performing Cyber Team in a fast-paced and evolving environment.
Your responsibilities day to day will be… Work closely with IT Operations teams and wider business functions to implement and optimise technologies and security controls that enhance the organisation's cyber security posture across internal and customer-facing platforms. Proactively identify cyber security risks, control deficiencies and opportunities for security improvement, making recommendations to reduce organisational risk.
Support the design, implementation and ongoing development of cloud-based infrastructure and services, ensuring security best practices are embedded by design. Collaborate with software development teams to ensure secure design principles and cyber security requirements are integrated throughout the Software Development Lifecycle (SDLC). Create, maintain and review cyber security policies, standards, procedures and technical documentation.
Monitor security events and alerts, conducting threat detection, investigation and incident response activities to minimise business impact. Perform vulnerability management activities, including vulnerability identification, risk assessment, remediation tracking and reporting. Conduct threat intelligence research, analysing emerging threats, vulnerabilities and attack techniques, and recommend appropriate security improvements.