Group Cyber Security Operations Analyst
Summary
Join Arrow Global's central Group Information Security Team in Manchester to monitor and improve cyber security operations: triaging alerts from the SOC, email/web gateways and cloud security tools, managing the vulnerability lifecycle and pen-test findings, and producing threat intelligence and reporting across a Microsoft 365/Azure/AWS estate.
- Monitor outputs from security tools and services including the Security Operations Centre (SOC), email security gateways, web security gateways, vulnerability management platforms, cloud security solutions, and other security technologies.
- Review, investigate, and coordinate the remediation of security alerts, incidents, and threats in conjunction with local IT teams and third-party service providers.
- Support the Incident Detection and Response process, ensuring incidents are appropriately investigated, documented, escalated, and resolved.
- Manage and track the end-to-end vulnerability management lifecycle, including vulnerability identification, reporting, remediation tracking, and escalation of overdue findings.
- Coordinate internal and external penetration testing activities and ensure findings are appropriately tracked through to resolution.
- Support the management and continuous improvement of security controls including endpoint protection, email security, web security, identity and access management, cloud security, and code repository security controls.
- Work closely with local IT teams, Cyber Security partners, and third-party service providers to ensure security processes and standards are consistently implemented and maintained.
- Produce regular operational reports, dashboards, and management information relating to cyber security risks, incidents, vulnerabilities, and control effectiveness.
- Maintain awareness of emerging threats, vulnerabilities, attack techniques, Artificial Intelligence (AI) security risks, and industry best practices.
- Produce actionable threat intelligence summaries and recommendations for security and technology teams, drawing on emerging threats, vulnerabilities, and threat actor activity relevant to Arrow Global's operating environment.
- Support the development of new SOC use cases, detection logic, and response procedures to improve security operations maturity.
- Act as a cyber security subject matter expert on projects involving new technologies, security capabilities, mergers, acquisitions, and business integrations.
- Proven experience within a Cyber Security, Information Security, Infrastructure, or IT Operations role.
- Strong understanding of cyber security principles, technologies, and operational processes.
- Experience working with security monitoring platforms, security alerts, incidents, and vulnerability management processes.
- Knowledge of common security technologies including endpoint protection, email security, web security, identity and access management, vulnerability management, cloud security, and security monitoring solutions.
- Hands-on experience administering and supporting security technologies including SIEM, EDR, Secure Email Gateway (SEG), Secure Web Gateway (SWG), CASB, and vulnerability management platforms.
- Experience supporting Microsoft Entra ID security controls, including Conditional Access Policies and identity protection capabilities.
- Experience working with Security Operations Centres (SOC), Managed Security Service Providers (MSSP), or equivalent security service providers.
- Ability to analyse technical information and communicate findings clearly to technical and non-technical stakeholders.
- Effective prioritisation and organisational skills with the ability to manage multiple competing priorities.
- Strong analytical and problem-solving skills.
- Knowledge of cyber threat intelligence concepts, threat actor behaviours, and attack frameworks such as MITRE ATT&CK.
- Understanding of Microsoft 365, Azure, AWS, cloud environments, and associated cyber security risks.