×
Register Here to Apply for Jobs or Post Jobs. X

Cyber Security Analyst

Job in Bristol, Bristol County, BS1, England, UK
Listing for: 慨正橡扯
Full Time position
Listed on 2026-06-03
Job specializations:
  • IT/Tech
    Cybersecurity, Security Manager
Salary/Wage Range or Industry Benchmark: 60000 - 80000 GBP Yearly GBP 60000.00 80000.00 YEAR
Job Description & How to Apply Below

Job Description

We're looking for a Cyber Security Analyst to join the ARCHANGEL™ Protective Monitoring (Pro Mon) Team. ARCHANGEL™ delivers specialist technical cyber security services to a range of clients across a variety of industries including construction, government, defence and aerospace.

The ARCHANGEL™ Pro Mon Team sits within the Bristol Service Operations Centre (SOC) and is responsible for providing thorough initial investigation into anomalous network activity that may lead to potential security incidents.

Beyond ARCHANGEL™, Leonardo and its Cyber & Security Solutions division are a world leader in safety-through-technology, providing tailored solutions for customers in public administration, public safety and security, critical infrastructure, services, transport, post and logistics.

You will be joining our highly skilled team at our Bristol site. This is a great opportunity to bring your talents and form an integral part of Leonardo's future. We can help you develop your skills and offer great opportunities to develop and grow, so why not join us!

At Leonardo, we believe that our employees work best when they are able to achieve balance between work and other aspects of life and so that you can enjoy the great city of Bristol! That's why we are committed to designing policies and developing a working environment that promote the benefits and well‑being of all our employees.

What you will do as a Cyber Security Analyst

So let's get down to what you will do!

  • Provide monitoring, alerting and incident handling services within the SOC in line with SLAs
  • Act as the initial analytical reference point for identifying and then quantifying the nature and extent of security incident and offer initial professional advice relating to possible business impact in order to reduce both the Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)
  • Advise on incident containment measures through recommended initial actions to customers in collaboration with the Incident Response (IR) Team
  • Provide advice relating to potential mitigation measures in order to prevent, or limit future reoccurrence in collaboration with the Incident Response (IR) Team
  • Perform proactive analysis across client networks by staying abreast of current threats and trends
  • Develop and maintain a credible knowledge of current and emerging threats likely to affect the Integrity of the managed service you are protecting
  • Review reoccurring false positive firings and assist in the tuning of SIEM and IDS rules to reduce false positives and maintain good security alerting
  • Create reporting for management and clients on security incidents and threat intelligence trends
What you’ll bring
  • Ability to excellently communicate at all levels – working with customers is a must, so we need you to be able to let them know what's going on
  • Experience in Cyber Security, e.g. Protective Monitoring, Incident Response, Security Engineering
  • SIEM (Log Rhythm, Arcsight, Splunk, etc) & IDS (Snort) experience
  • Have a sound knowledge of IT security best practice, common attack types & detection / prevention methods
  • Have an understanding of Incident Response, Cyber Kill Chain, Threat Modelling and pertinent Attack Vectors
  • Have a collaborative working ethos in order to work across the team to create pertinent Playbooks, Use Cases ,etc
  • Demonstrate experience of analysing & interpreting system, security & application logs in order to diagnose faults & spot abnormal behaviours
  • Have great organisational skills & attention to detail
  • Ability to work independently & as part of a team
  • Highly motivated, with the aptitude to learn new skills
Additional skills
  • SANS SEC 503 Intrusion Detection in Depth or equivalent
  • SANS SEC 504 Incident Handling, Hacker Tools and Techniques or equivalent
  • SANS SEC 508 Advanced Incident Response, Threat Hunting, and Digital Forensics or equivalent
  • SANS SEC 511 Continuous Monitoring and Security Operations or equivalent
  • Exposure to IT service management best practices such as ITIL
  • Knowledge of standards & guidelines such as ISO
    27001,GDPR principles and GPG-13.
  • Threat Intelligence experience
  • Report Writing
Security Clearance

This role is subject to pre‑employment screening…

Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary