Cyber Security Analyst
Summary
The Cyber Security Analyst supports and administers Data Loss Prevention (DLP) products, vulnerability management, and Atlassian technologies within BAE Systems' enterprise IT infrastructure. The role involves creating security policies, managing technical controls, and troubleshooting infrastructure issues in a hybrid work environment.
Job Title\: Cyber Security Analyst
Job Location\: Frimley or Preston. Hybrid - 1 day per week onsite. We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role.
Grade\: GG09
You’re expected to have completed 12 months in role prior to applying for an advertised vacancy and you should also discuss the internal opportunity with your line manager to ensure sustained business continuity and to further support your career development.
We know there may be exceptional individual circumstances that impact this, in the first instance please discuss this with your line manager.
If you don’t feel you can talk to your Line Manager, you can contact your HRBP.
PLEASE NOTE Should you be invited for interview; you acknowledge that the Recruitment team will contact you and your line manager regarding your application for this opportunity.
Role Description\:
This role is supporting and administering Data Loss Prevention (DLP) products within the enterprise environment. The role encompasses the design, creation, and maintenance of DLP security policies and rules. Other duties include supporting firewall rule governance, Atlassian technologies and Vulnerability Management. Working as part of a wider Cyber Security team, the role contributes to protecting BAE Systems UK's enterprise IT infrastructure against evolving cyber threats through the implementation, configuration, maintenance, and continuous improvement of cyber security technical controls and compensating security measures.
Key responsibilities include the installation, management, and support of security software toolsets, troubleshooting and resolving technical issues, and ensuring the effective operation of cyber technologies. A solid understanding of networking principles and protocols is required to support investigations, analysis, and problem resolution.
This role is focused on cyber security technology administration and control management and should not be considered a traditional Network Engineer or Security Operations Centre (SOC) Analyst position.
Core Duties\:
- Administer and maintain Data Loss Prevention (DLP) capabilities using data analysis supporting the organisation's data security strategy and regulatory requirements
- Support the design, implementation, tuning, and maintenance of DLP policies and rules to protect organisational data and prevent unauthorised disclosure
- Provide technical support across the Atlassian Stack, including Linux server administration, PostgreSQL database management, platform upgrades, configuration management, performance optimisation, troubleshooting, and maintaining a secure, highly available environment
- Configure, maintain, and manage vulnerability scanning platforms, including scanner administration, scan configuration, and the scheduling of authenticated and unauthenticated vulnerability assessments across enterprise environments
- Support firewall governance activities, including firewall rule reviews, change assessments, approval processes, and policy compliance checks
Essential Skills\:
- Has a background in IT support, with experience troubleshooting infrastructure, systems, and end-user services within an enterprise environment
- Analytical background with the ability to analyse and interpret large and complex data sets and articulate observations, conclusions and recommendations
- Knowledge of Linux technologies
- Proficiency in scripting using various API’s
- Appreciation of end user devices, server infrastructure, and network technologies
The Cyber Engineering team\:
You will be joining an expansion to an existing cyber engineering team, supporting additional requirements that sits within Enterprise IT, providing enterprise IT services across the UK businesses and internationally. You will participate in the creation of security solutions to provide enterprise security services, and maintain, develop, and communicate their associated roadmaps and standards through the full lifecycle of the service. This could also offer a natural progression route and the opportunity to develop further.
Why BAE Systems?
Here you’ll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work - this is a place where you can grow your career with confidence and be empowered to be your best. You’ll be recognised for your contribution and enjoy rewards tailored to what’s most important to you and your family - support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make.
We welcome applications from all suitably qualified people, who are BAE Systems employees and have been in their current role for 12 months or longer.
A place where everyone can thrive\:
We’re committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do.
Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks.