Senior IT Security Analyst
Listed on 2026-07-10
-
IT/Tech
Cybersecurity, Information Security
Role Purpose
The postholder provides advanced technical security analysis, leads complex investigations, improves the maturity of security controls and advises stakeholders on cyber risk. The role combines hands‑on security operations with control ownership, specialist guidance, assurance and continual improvement.
Role Scope and LevelSenior technical practitioner with authority to lead complex operational security work within agreed governance. Responsible for risk‑based recommendations, improvement of procedures and subject‑matter advice for incidents, vulnerabilities, identity controls, data protection and security tooling. Expected to coach colleagues, influence technical teams and translate threat, control and risk information into clear management updates. Focuses on control maturity, assurance quality, repeatable processes and measurable reduction of cybersecurity risk.
Key Responsibilities- Security operations leadership
Lead complex security investigations across endpoint, network, identity, email, cloud and application data sources.
Define triage criteria, alert handling standards, escalation paths and quality checks for security operations.
Review high‑impact alerts and incidents, ensure proportional response and remove barriers to containment and remediation.
Develop and improve detection logic, playbooks, dashboards and operational procedures.
- Incident response leadership
Coordinate response to significant cybersecurity incidents in line with the incident management process.
Lead technical analysis for malware, phishing, credential compromise, insider risk, data exposure, privilege misuse and suspicious network activity.
Ensure evidence handling, incident timelines, decisions, lessons learned and remediation actions are complete and auditable.
Produce post‑incident reviews and track corrective actions through to closure.
- Risk, governance and assurance
Translate technical findings into risk statements, control weaknesses and prioritised remediation plans.
Support risk assessment, risk acceptance, audit and assurance activity with clear evidence and professional judgement.
Advise on relevant information security legislation.
Contribute to security standards, control testing, supplier assurance and management reporting.
- Data Loss Prevention and Multi‑Factor Authentication control ownership
Own or act as technical lead for Data Loss Prevention (DLP) monitoring, rule tuning, alert quality, exception handling and escalation.
Own or act as technical lead for Multi‑Factor Authentication (MFA) control performance, exception governance, break‑glass account checks, privileged access enforcement and conditional access design.
Analyse DLP and MFA trends to identify control gaps, user behaviour issues, data handling risks and improvement opportunities.
Ensure control documentation, operating procedures and evidence packs are complete, current and aligned to policy.
- Vulnerability, threat and configuration management
Lead vulnerability prioritisation using exploitability, asset criticality, exposure and business impact.
Challenge and support remediation plans for high‑risk vulnerabilities, insecure configurations and unsupported systems.
Develop recurring reporting on vulnerability trends, control gaps and remediation performance.
Use threat intelligence to improve detection, hardening and risk prioritisation.
- Security architecture and technical assurance
Review proposed changes, projects and new services for security risks and control requirements.
Advise on secure design for identity, endpoint, network, cloud, logging, data protection and resilience controls.
Validate that logging, monitoring, access control, encryption, backup and recovery requirements are included in project delivery.
Recommend improvements to security tooling and integration, including automation where proportionate.
- Metrics, reporting and continual improvement
Produce clear management information on incidents, vulnerabilities, DLP, MFA, control exceptions, detection coverage and remediation performance.
Define Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) for security operations and control assurance.
Identify process inefficiencies,…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: