Information & Cyber Security Specialist
Listed on 2026-09-27
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Network Security, Security Management & Operations
We are looking for an experienced Information & Cyber Security Specialist to join our newly integrated Cyber Security function. This role has a primary focus on security operations, incident investigation, detection engineering, vulnerability management and security automation and orchestration. It offers the opportunity to take meaningful ownership of operational security capabilities, influence how they develop and help shape a modern, intelligence-led and increasingly automated Cyber Security function.
Reporting into the Information & Cyber Security Leader, you will work hands-on with security technologies, investigations and improvement activity, while collaborating with colleagues across Cyber Security, Architecture, IT Operations, business teams and our external security providers. This is not a line management role. However, you will have the autonomy to shape assigned capabilities, improve how services operate, share your expertise and support the development of colleagues.
Keyresponsibilities
- Investigate security alerts and incidents using SIEM, XDR, identity, endpoint, email, network and cloud telemetry.
- Support the coordination of containment, eradication, and remediation activity, ensuring actions are understood, appropriately prioritised and completed.
- Develop, test and tune security detections, improve alert quality and help maintain visibility of detection coverage against relevant threats and attacker techniques.
- Take ownership of assigned security operations capabilities, identifying weaknesses, proposing improvements and seeing agreed work through to completion.
- Operate vulnerability management processes, including scanning, validation, threat-informed prioritisation, remediation coordination, exception escalation and closure assurance.
- Work with IT Operations, system owners and suppliers to ensure material vulnerabilities and security weaknesses are addressed within agreed timescales.
- Develop automation and orchestration that improve investigation, enrichment, triage, evidence collection, reporting and response workflows.
- Explore and implement appropriate uses of Microsoft Security Copilot, AI and SOAR technologies, ensuring automated activity remains controlled, auditable and subject to appropriate human review.
- Support the operation and improvement of Microsoft Defender, Microsoft Entra, Conditional Access, endpoint security, identity controls and other assigned security technologies.
- Create and maintain clear runbooks, technical procedures, investigation records, service documentation and operational evidence.
- Share knowledge with colleagues and provide practical coaching and quality support to the Information & Cyber Security Analyst.
- Contribute to wider information security, cyber risk, assurance, third-party security, governance and compliance activities as team priorities require.
- Participate in the Cyber Security on-call rota and support the response to significant out of hours cyber incidents.
You will have strong hands-on cyber security experience and be comfortable taking an investigation or improvement activity from initial identification through to a clear outcome. You should be able to demonstrate experience in several of the following areas:
- Security incident investigation and response.
- SIEM or XDR investigation.
- Detection engineering and alert tuning. [CH1]
- Vulnerability management.
- Endpoint, identity, email, network or cloud security.
- Analysing and correlating security telemetry.
- Incident-response procedures and playbooks.
- Security automation, orchestration or scripting. [CH2]
- Working with a managed SOC, MDR or other external security partners.
- Translating technical findings into clear risks, decisions and actions.
You will also need:
- Strong analytical and investigative judgement.
- The ability to work independently and take ownership of assigned outcomes.
- A practical, delivery-focused approach and willingness to get involved.
- Clear written and verbal communication.
- Willingness to contribute outside your primary specialism when wider Cyber Security priorities require it.
- The existing right to work in the United Kingdom.
DESIRABLE EXPERIENCE
Experience in any of the following would be advantageous, but is not essential:
- Taegis XDR or MDR.
- Sophos security technologies.
- Microsoft Defender.
- Microsoft Entra and Conditional Access.
- Microsoft Security Copilot.
- Microsoft Sentinel.
- Threat hunting.
- Digital forensics and evidence handling.
- Security Architecture or design assurance.
HOW WE WORK
Our Information Security and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).