Security Analyst

Overview

This role as a Cyber Security Analyst/Engineer involves enhancing the IT Security function of a growing transport organization as part of their security improvement program. The contractor will collaborate with an established IT Security team to manage security operations, incident response, vulnerability management, and risk assessment within a large enterprise environment.

Responsibilities

  • Utilize security tooling to identify, correlate, and contain suspicious events while recommending improvements.
  • Conduct deep-dive incident analyses across various data sources to investigate security logs against potential threats.
  • Perform proactive and reactive threat hunting to identify vulnerabilities.
  • Execute vulnerability and web application assessments, providing analysis and remedial recommendations.
  • Manage ongoing vulnerability mitigation efforts as part of standard operations.
  • Conduct risk analysis reviews, identify security gaps, and propose remediation options.
  • Onboard and review log sources into the SOC/SIEM, validating cyber incident alerts.
  • Produce reports on emerging risks and communicate threat information to stakeholders.

Requirements

  • At least 6 years of experience as a cybersecurity analyst/engineer.
  • Hands-on experience with Microsoft security platforms (Entra AD, AD Admin level).
  • Experienced with Microsoft O365 and CrowdStrike Next Gen Falcon at the admin level.
  • Proficient in Proofpoint email security and Qualys VMDR at the admin level.
  • Experience with ServiceNow ticket management and technical cyber security teams, ideally with SOC exposure.
  • Strong working knowledge of SIEM, vulnerability scanners, and various security technologies.
  • Familiarity with standards like MITRE ATT&CK, ISO27001, and NCSC Cyber Essentials.
  • Degree level education or equivalent experience along with relevant certifications such as CySA+ or CISSP.