Description:
A fantastic opportunity for a Security Analyst to join a highly innovative software company delivering complex enterprise security solutions to a broad range of organisations. This role is focused on ensuring operational security across the current and future IT estate, providing a first‑line response to security events and maintaining strong protection throughout the organisation. You will drive ongoing service improvements and uphold security standards, coordinating and maintaining the processes and documentation required for ISO and Cyber Essentials Plus certification.
Location: Leicester – hybrid working (minimum 2 days on-site, with occasional travel to customer sites). Easier if you drive, with public transport options from central Leicester, Rugby and Market Harborough
Requirements for Security Analyst:
- At least 3+ years of commercial experience working in a Security Analyst or similar role within enterprise software environments
- Strong technical expertise and hands‑on experience across Microsoft Entra and Identity, the Microsoft Defender suite, Microsoft Sentinel, and Microsoft Purview.
- Proven ability to manage compliance with ISO 27001 controls and to coordinate the Cyber Essentials recertification process.
- Strong reporting skills with the ability to present effectively to C‑Suite leaders
- Strong understanding of the end‑to‑end vulnerability‑scanning lifecycle and the effective management of penetration testing activities.
- Excellent security awareness with a proactive approach to continuous improvement
- Eligible and willing to undergo security clearance vetting
Responsibilities for Security Analyst:
- Manage and improve overall security posture, monitor alerts, assess risks, and coordinate remediation activities while implementing key security technologies
- Oversee identity and access management across Entra, Azure, Intune, Jira, AWS and SaaS platforms, maintaining Conditional Access, MFA, PIM and Identity Protection
- Implement and maintain Microsoft Sentinel, Purview and the Defender suite
- Manage the vulnerability‑scanning lifecycle and coordinate penetration‑testing activities
- Maintain security and sharing controls across email, SharePoint, OneDrive and Teams, including DLP, sensitivity labels, encryption and removable‑media controls
- Manage phishing‑simulation programmes and support security‑awareness training
- Support ISO 27001, Cyber Essentials and Cyber Essentials Plus compliance and audits
- Produce security reports and metrics for leadership
- Lead incident‑response processes and follow‑up activities
- Conduct vendor and third‑party security assessments
What the role offers:
- Opportunity to work on complex, high-impact security solutions within a specialist technical environment
- Exposure to a wide range of enterprise technologies and challenging projects
- Join a collaborative and highly skilled team with strong technical expertise and a supportive culture