
Information Security Analyst
- Rocester, Staffordshire
- Permanent
- Full-time
- Day-to-day running and monitoring of Information Security systems - analyse and interpret outputs to identify security weaknesses and recommend continuous improvements.
- Be a key participant in or leader of large IT and business projects.
- Respond to Security Incidents, reports and alerts ensuring prompt containment and recovery.
- Plan and oversee regular security penetration testing against new and existing services to identify weaknesses and formulate plans and processes to minimise current and future risk.
- Conduct regular security risk reviews and manage security remediation activity, internally on new IT/Business projects and with third parties.
- Be the technical sign-off for all BAU Change Requests.
- Promote culture of 'secure by design' and facilitate appropriate activities to support and improve Information Security Awareness.
- Articulate risk in technical and non-technical terminology so that it can be interpreted by Group IT and business stakeholders.
- Seek out and exploit opportunities for improvement to the group's overall security posture.
- Passionate about cyber security and keeping up with the latest trends, threats and mitigations.
- You're adaptable - whilst this role requires some use of Security Toolsets and a Technical Mindset, you're not expected or required to be an expert in all areas but expected to have a solid understanding and grounding in security principals to adapt to the varied requirements.
- You have the ability to manage and use a wide variety of security software, systems, services and toolsets such as E-mail Security, EDR, NAC, IT/OT Segmentation, 365 etc along with an understanding of malware prevention, emerging threats, attacks and vulnerability management.
- You possess understanding of Information Security best practice for elements including workstations, servers, cloud, networking, architecture, common protocols and application security.
- You have the ability to confidently perform security audits, both internal and external (e.g., third party and supplier assurance) and ensure recommendations are followed for continuous improvement.
- You have strong Project Management skills - able to independently manage multiple projects, manage own workload, prioritise and meet tight deadlines.
- You have strong Incident Response Management skills including threat and vulnerability analysis.
- You have the ability to communicate business and technical risk to all levels of audience.
- You possess understanding of IT Service Management principles ideally ITIL.