Cyber Security Analyst
On-sitePeterborough, England, United Kingdom
Job Summary
Monitor security alerts, logs, and events across SIEM, EDR/XDR, Microsoft Defender, and network monitoring tools to support timely incident response, containment, remediation, and post-incident reviews. Maintain the vulnerability management programme by scanning, prioritizing, tracking remediation, and reporting exceptions while supporting ISMS, ISO 27001, Cyber Essentials Plus, and PCI DSS governance activities. Produce clear security reports, metrics, and updates for operational, management, and governance forums, and assist with audits, supplier assurance, access governance, and business continuity testing. Collaborate with IT, Compliance, HR, and the wider business to embed a strong security culture and escalate material risks as required.
Required Qualifications
- Good working knowledge of cyber security principles, common attack vectors, security controls and defence-in-depth practices
- Experience investigating security alerts, phishing attempts, malware events, suspicious sign-ins, endpoint risks or similar incidents
- Experience with security tooling such as SIEM, EDR/XDR, vulnerability management, endpoint protection, identity protection, cloud security or email security controls
- Understanding of Microsoft security technologies including Microsoft Defender, Microsoft Sentinel, Microsoft Purview and Microsoft Entra, or the ability to develop capability quickly
- Ability to assess risk, prioritise remediation, document findings clearly and communicate technical issues to non-technical stakeholders
- Working knowledge of UK information security, privacy and assurance requirements including GDPR, the UK Data Protection Act, ISO 27001 and Cyber Essentials Plus
- Strong collaboration skills and the ability to work effectively with IT, Compliance, HR, suppliers, security providers and business stakeholders
- Minimum of 2 years' experience in cyber security, information security, IT infrastructure, IT operations or a related technical role
- Practical understanding of networking, operating systems, cloud platforms, identity services and security technologies
- Experience supporting security operations, incident investigation, vulnerability management, risk assessment, audit activity, supplier assurance or compliance evidence gathering
Desired Qualifications
- A relevant degree is desirable but equivalent practical experience will be considered
- A foundation-level cyber or information security certification is desirable, such as CISMP, CompTIA Security+, ISO 27001 Foundation or a Microsoft Security certification
- Experience in professional services or another regulated environment
- Experience with Microsoft Defender, Sentinel, Purview, Entra or Azure security controls
- Experience supporting security awareness campaigns, phishing simulations, supplier assurance, client security questionnaires, dashboards or security metrics
- Familiarity with ISO 22301, business continuity, disaster recovery, operational resilience or ITIL 4
- Advanced or role-specific certifications such as Microsoft SC-200, SC-300, SC-400, AZ-500, ISO 27001 Lead Auditor, ISO 27001 Lead Implementer or CISSP would be advantageous where supported by practical experience
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.