Description:
We're looking for an IT Security Analyst to join our IT Security team and play a key role in strengthening our cyber security capability across the Group.
This is an exciting opportunity for someone with a passion for cyber security, security awareness and continuous improvement. You'll work closely with colleagues across IT and the wider business, helping to drive a strong security culture while supporting security operations, threat intelligence activities and governance initiatives.
What You'll Be Doing
As our IT Security Analyst, you'll support the IT Security Manager in delivering and enhancing Wates' cyber security programme by:
- Supporting security operations, incident investigations and response activities.
- Working with the Security Operations Centre (SOC) to analyse threats and security alerts.
- Conducting threat intelligence research and identifying emerging cyber risks, adversary tactics and indicators of compromise.
- Utilising Microsoft security technologies, including Microsoft Defender XDR and associated Defender products, to support investigations and remediation activities.
- Leading the development and delivery of engaging cyber security awareness campaigns and phishing simulations using KnowBe4 providing regular compliance reporting
- Creating awareness content across a range of channels including email, intranet, social platforms, posters and face-to-face sessions.
- Supporting the development and maintenance of cyber security standards and procedures.
- Improving operational security processes including access management, vulnerability management and incident management.
- Producing meaningful security reports, dashboards and metrics for technical and non-technical stakeholders.
- Promoting a positive security culture across the organisation through collaboration, communication and education.
Essential
What We're Looking For
- Demonstrable experience developing and managing security awareness programmes, including phishing simulations and user engagement initiatives, with a good understanding of managing complex groups, targeted training initiatives and producing regular compliance reports for management.
- Strong understanding of recognised security frameworks and standards particularly Cyber Essentials
- Knowledge of cyber threat intelligence concepts including IOCs, TTPs and threat analysis.
- Experience working with SOC teams, managed service providers or security operations functions.
- Knowledge of Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Identity and Defender for Cloud Apps.
- Excellent written and verbal communication skills, with the ability to engage both technical and non-technical audiences.
- Strong analytical and problem-solving skills.
- Self-motivated, organised and able to manage competing priorities.
Desirable
- Experience within the construction, built environment, government or defence sectors.
- Bachelor's degree in Computer Science, Cyber Security, Information Assurance or a related discipline.
- Industry certifications such as ISC2, CompTIA Security+ or GIAC qualifications.