Cyber Security Analyst
Salary: £45,000 - 45,000 per year
Requirements:- We have at least 2 years experience in a cyber security, SOC, or information security analyst role.
- We have experience working within an ISO/IEC 27001 or equivalent accredited environment.
- We are familiar with ITIL service management processes, particularly Incident, Request, Change, and Problem management.
- We understand GDPR, data protection, and information governance.
- We have hands-on experience with a SIEM platform such as Cortex XSIAM, Microsoft Sentinel, Splunk, or equivalent.
- We have experience with, or a strong aptitude to learn, SOAR and automation tooling such as Cortex XSOAR.
- We have experience with Endpoint Detection and Response tools such as Cortex XDR or an equivalent EDR/XDR platform.
- We have experience with email security platforms such as O365, Mimecast, Abnormal, or equivalent.
- We understand Data Loss Prevention and data classification, such as Microsoft Purview and Azure labelling, or equivalent.
- We have experience with vulnerability scanning and management such as Nessus or equivalent.
- We have working knowledge of endpoint management across Windows and macOS, including Intune and Jamf.
- We have strong knowledge of cloud environments, including Microsoft Azure, AWS, and Microsoft 365.
- We understand layered security, threat hunting, and incident response.
- We hold a degree in a computer-related subject, or we have equivalent experience in cyber security.
- We hold, or are actively working towards, relevant industry certifications such as SANS GCIH, EC-Council CEH, ISC2 SSCP, CompTIA CySA+, Blue Team Level 1, or Microsoft SC-200, and we are committed to continued professional development.
- We deliver the day-to-day security operations of the InfoSec team and act as a first point of escalation and support for Junior and Graduate analysts.
- We manage day-to-day security tickets, requests, and alerts through Halo ITSM, meeting SLAs and making full use of existing automation.
- We monitor, triage, and investigate alerts within Palo Alto Cortex XSIAM, responding and escalating as required.
- We respond to security incidents involving malware, data loss, phishing, or network intrusion, following established playbooks and incident response processes.
- We manage email security operations across Mimecast and Abnormal, including releases, journal pulls, and reported-phishing investigations.
- We monitor threat feeds and threat intelligence, applying relevant findings to the environment.
- We maintain and tune detections, correlation rules, and Cortex XSOAR playbooks to reduce noise and improve response times.
- We identify opportunities for automation and continual improvement across monitoring and response workflows.
- We contribute to the development and upkeep of SOC processes, runbooks, and documentation.
- We run and interpret vulnerability scans using Nessus, tracking remediation through to closure with the relevant teams.
- We support endpoint security and patch compliance across the Windows and macOS estates, working with Intune, Jamf, Alectrona, and Cortex XDR.
- We support and monitor the companys Data Loss Prevention controls within Microsoft Purview, and data classification through Azure Information Protection labelling.
- We help maintain the evidence and controls that support the companys accreditations, including ISO/IEC 27001, 27017, and 27018, Cyber Essentials Plus, and SOC 2.
- We learn and apply the principles of risk and information governance within the context of cyber security.
- We work collaboratively with the wider IT team and business stakeholders to provide security and governance for existing and new services.
- We communicate complex security concepts clearly to technical and non-technical audiences.
- We support our colleagues across all regions and serve as a trusted resource on information and cyber security matters.
- AWS
- Azure
- Cloud
- ICT
- Support
- ITIL
- ITSM
- macOS
- Microsoft 365
- Network
- Security
- Splunk
- Windows
- Office 365
- DevOps
More:
We are a growing ICT Department and InfoSec team based in our Manchester Head Office, working in a dynamic and fast-paced environment with new challenges every day. We have rationalised our infrastructure and established a modern, cloud-first security stack, making it an exciting time to join us as we mature our detection, response, and automation capabilities across a global estate. We offer a range of benefits including 25 days holiday plus bank holidays, a day off for your birthday, Health Shield Cash Plan, Cycle to Work Scheme, Train Season Ticket Scheme, Profit Share Scheme, a contributory company pension scheme, and access to our Employee Assistance Programme. We value collaboration, professional development, and a consistent approach to information and cyber security across the business.
last updated 36 week of 2026