At a Glance
- Tasks: Manage Cyber Security operations and ensure compliance across the organisation.
- Company: Join Volante, a fast-growing international underwriting group revolutionising the insurance model.
- Benefits: Enjoy competitive salary, pension, holiday, and private medical care.
- Why this job: Be part of a diverse team making a real impact in Cyber Security.
- Qualifications: Experience with Cyber Security Frameworks, especially NIST, and strong tech skills required.
- Other info: Opportunity for growth in a dynamic environment with a focus on innovation.
The predicted salary is between 36000 - 60000 £ per year.
About the team and the role: As part of the Technology Team, you will be responsible for Cyber Security across the organisation. Working with the business, system owners, suppliers, auditors and other third parties to ensure compliance and respond to audit requests in a highly regulated industry. This is a diverse role with responsibilities including all aspects of Cyber Security. Along with running and owning the processes and procedures of a Cyber Security Framework, you will also be expected to configure and monitor security tooling.
How you'll contribute: The role will initially be technology, BAU and audit administration focused, but will expand over time to encompass responsibility for the overall Cyber Security Framework. Immediate responsibilities include:
- Security configuration, alert actioning, vulnerability tracking, monitoring and other security related responsibilities for: Endpoint Devices, Microsoft 365, Microsoft Entra (Azure AD), Microsoft Azure, Salesforce Shield, SentinelOne, Z-scaler, Threatlocker and various other solutions across the estate.
- Remain up to date and advise on: Security Threats, Potential security issues, Technology capabilities.
- Own, manage and run the day-to-day security operations; examples include: Responding to alerts and events, Security backlog, observation tracking and progress of vulnerability resolution, Identity management and authorization processes, Internal audit and diary tracking, Track and authorise changes to Data Loss Protection Policies within the organisation, Running exercises for the BCP, DR and Incident Response Plans, creating playbooks and applying recommendations from the retrospectives, Policy exception tracking, auditing, authorization and reporting, Produce regular reporting to the CTO, COO and Executive Committee, Onboarding of new solutions into BAU, Coordinate annual Penetration Testing and Configuration Reviews, Tracking and management of gaps between our Risk Frameworks and solutions.
- Coordinate technology related audit and compliance requests, including: Liaise and coordinate the responses from other individuals/teams/functions/third parties, Respond to audit questions where possible, Track any remediation items and work with other teams to resolve, Auditing cloud assets and monitoring Shadow IT.
General responsibilities: Automation and outsourcing of standard processes, Supplier Management and Governance, Process development, Maintenance of the central solutions register and Enterprise Architecture assets, Small change/project management.
The role will grow to include: Example areas of responsibilities for the Cyber Security Framework include:
- Develop and Administer Cyber Security processes, for example Incident Response Plans.
- Continued development of our Cyber Security Framework and to continually improve our Cyber Security Posture.
- Administer standard artefacts, including Risk Appetite Statements, Cyber Strategy and the annual improvement program.
- Tracking and reporting on our NIST compliance.
- Support the continued development of company policies and staff handbook.
- Vulnerability Management, including tracking and reporting on vulnerabilities throughout the estate.
- Own the Cyber Security training programmes including the creation of manuals and advisory notices.
- Work with the CTO and other technology functions to improve technical security processes, for example, technical security frameworks in the software development lifecycle, threat modelling, solution security lifecycles.
Work with fellow IT functions to: Enhance existing Software Development Lifecycle processes to improve security, Perform Threat Modeling of new and existing solutions, Work with solution owners to apply the appropriate controls and put in place monitoring.
Skills: Develop and build relationships internally and externally with key business and technical stakeholders, Cyber Security Framework implementation, test and execution, Microsoft 365, Microsoft Entra and Microsoft Azure, Microsoft Office Suite, including Microsoft Excel, Powershell and Microsoft 365 automation technologies, Strong general working knowledge of technology and technology processes, Authoring of formal and regulated documentation (e.g. policies and procedures), Ability to influence key stakeholders, Implementation of automation, specifically with PowerShell or Microsoft 365 technologies.
Knowledge: Cyber Security Frameworks and other bodies, in particular NIST and NCSC/IASME/CE, IT Operation processes, e.g. ITIL, including Asset Management and Change Management, Understanding of the holistic approach to Cyber Security and how to apply that to model attack vectors and actors in relation to the requirements of the business, Understanding of the five functions of the NIST Cyber Security Framework, Security Operations and SIEM implementations, Understanding of the attack vectors, methods and actors in relation to Cyber security.
Experience: Working within Cyber Security Frameworks, specifically NIST, Worked for equivalent regulated organisations (FCA, PRA, etc), Owned and provided responses to auditor requests, Implementing/delivering the artefacts as outlined in the responsibilities.
Interview process: Teams call with the Talent Acquisition professional, Face to face interview at Volante with hiring manager, Face to face interview with HR.
What's in it for you? Competitive salary, Pension, Holiday, Private medical care.
About Us: Volante Global are an award winning, multi-class, international underwriting group, delivering niche, specialist (re)insurance products to a broad distribution network. Employing underwriters with a proven track record in Europe, the Middle East, Canada, and the USA, we have seen unprecedented growth since starting in 2018, growth that is set to continue over the next 3 – 5 years.
Diversity & Inclusion: Diversity and inclusion are part of the Volante DNA. As a global organisation we have diversity of ethnicity, religion, and gender throughout the organisation from the top down. We have a “Diversity from Adversity” program through which we offer employment opportunities to people coming from disadvantaged backgrounds, and we continue to explore how to further these initiatives.
Senior Cyber Security Analyst employer: ACRISURE
Contact Detail:
ACRISURE Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Cyber Security Analyst
✨Tip Number 1
Familiarise yourself with the specific Cyber Security Frameworks mentioned in the job description, particularly NIST. Understanding these frameworks will not only help you in interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the Cyber Security field, especially those who have experience in regulated industries like FCA or PRA. Engaging with them can provide insights into the role and may even lead to referrals.
✨Tip Number 3
Stay updated on the latest security threats and technologies relevant to the tools listed in the job description, such as Microsoft 365, Azure, and Salesforce Shield. This knowledge will be crucial during discussions in the interview process.
✨Tip Number 4
Prepare to discuss your experience with automation, particularly using PowerShell and Microsoft 365 technologies. Highlighting your ability to streamline processes will resonate well with the hiring team at Volante.
We think you need these skills to ace Senior Cyber Security Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in Cyber Security, particularly with frameworks like NIST. Emphasise your familiarity with tools mentioned in the job description, such as Microsoft 365, Azure, and Salesforce Shield.
Craft a Strong Cover Letter: In your cover letter, explain why you are passionate about Cyber Security and how your skills align with the responsibilities outlined in the job description. Mention specific experiences that demonstrate your ability to manage security operations and respond to audit requests.
Showcase Relevant Skills: Highlight your technical skills, especially in automation with PowerShell and Microsoft technologies. Include any experience with vulnerability management and incident response plans, as these are key aspects of the role.
Prepare for Interviews: Research common interview questions for Cyber Security roles and prepare examples from your past work that demonstrate your problem-solving abilities and experience with security frameworks. Be ready to discuss how you would handle specific security scenarios.
How to prepare for a job interview at ACRISURE
✨Understand the Cyber Security Frameworks
Familiarise yourself with key Cyber Security Frameworks, especially NIST and NCSC/IASME/CE. Be prepared to discuss how these frameworks apply to the role and how you can contribute to their implementation and execution.
✨Showcase Your Technical Skills
Highlight your experience with Microsoft 365, Azure, and any relevant security tools like SentinelOne or Z-scaler. Be ready to provide examples of how you've configured and monitored security tooling in previous roles.
✨Demonstrate Your Problem-Solving Abilities
Prepare to discuss specific instances where you've identified and resolved security vulnerabilities. Use the STAR method (Situation, Task, Action, Result) to structure your responses and showcase your analytical skills.
✨Build Relationships and Communicate Effectively
Emphasise your ability to develop relationships with stakeholders, both internally and externally. Be ready to discuss how you've collaborated with teams to address audit requests or compliance issues in the past.