At a Glance
- Tasks: Join our team to manage cyber vulnerabilities and ensure robust security measures.
- Company: Be part of a globally recognised bank with over 10 million customers.
- Benefits: Enjoy a hybrid work model with flexibility and corporate perks.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
- Qualifications: Bachelor’s degree in Computer Science or Cyber Security; relevant certifications preferred.
- Other info: This is an 18-month fixed-term contract covering maternity leave.
The predicted salary is between 36000 - 60000 £ per year.
Cyber Vulnerability Management Analyst Fixed Term Contract (Maternity Cover) 18 months
Our Client is a globally recognised, successful bank who provide world-class services to various institutions and individuals. Offering a comprehensive range of retail and corporate financial services/products, this thriving business boasts over 10 million active customers in over 700 business locations.
Due to business requirements, we are now looking to acquire the services of an experienced Cyber Vulnerability Management Analyst.
Please note that this is a hybrid role with 3 days in the office and 2 days working from home.
Key Responsibilities:- Support the IT & Cyber Security Manager to plan and deliver our business strategy in line with our long-term goals.
- Deal with all remediation work in relation to identified vulnerabilities inclusive of patch testing and implementation within SLA.
- Work closely with all third-party vendors involved in the remediation process.
- Prepare the necessary MI/Dashboard reports for the relevant stakeholders.
- Alleviate the workload of the IT Service desk function when required.
- Perform daily assessment of vulnerabilities identified by internal and external scans.
- Evaluate, risk assess and rate the results of the scan, prioritise all vulnerabilities discovered and remediate/patch within the established remediation timeline(s)/SLA.
- Work closely with the SMEs/vendors of the relevant systems.
- Essential: Bachelor’s degree, preferably in Computer Science, Cyber Security or Cyber Security Professional Qualifications/Certifications.
- Desirable: General understanding of IT Security principles, standards and regulations (e.g. ISO 27001, NIST, CIS, PCI DSS and GDPR).
- CISM/CISSP.
- Patch Management Applications, EDR/XDR systems, Antivirus, NAC - Forescout.
- Vulnerability Scanning Tool e.g. Tenable One, Qualisys.
- Knowledge of vulnerability scoring systems (CVSS/CMSS).
- Incident/Response & Forensic Management Skills.
- IT Technical Admin Support - Azure, Oracle Cloud Infrastructure (OCI Cloud).
- Microsoft Windows Support & administration, CE+, ISO27001.
- Email and Information Security Filtering/Monitoring Solutions, Egress.
- Hands on experience on Linux and Mac Administration Support.
- Good understanding of Windows and Linux patching.
Cybersecurity Risk Analyst employer: The Curve Group
Contact Detail:
The Curve Group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cybersecurity Risk Analyst
✨Tip Number 1
Familiarise yourself with the specific tools and technologies mentioned in the job description, such as Tenable One and Qualys. Having hands-on experience or even a solid understanding of these tools can set you apart during discussions.
✨Tip Number 2
Network with professionals in the cybersecurity field, especially those who work in vulnerability management. Engaging with them on platforms like LinkedIn can provide insights into the role and may even lead to referrals.
✨Tip Number 3
Stay updated on the latest trends and threats in cybersecurity. Being knowledgeable about current vulnerabilities and how they are being addressed will demonstrate your commitment and expertise during interviews.
✨Tip Number 4
Prepare to discuss real-world scenarios where you've dealt with vulnerability assessments or patch management. Sharing specific examples can showcase your problem-solving skills and practical experience in the field.
We think you need these skills to ace Cybersecurity Risk Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in cybersecurity, particularly in vulnerability management and patching. Include specific examples of your work with cloud technologies like Azure or AWS, as well as any certifications you hold.
Craft a Strong Cover Letter: In your cover letter, express your enthusiasm for the role and the company. Mention how your skills align with the job requirements, especially your understanding of IT security principles and experience with vulnerability scanning tools.
Highlight Relevant Skills: When filling out your application, emphasise your knowledge of compliance standards such as ISO 27001 and NIST. Be sure to mention any hands-on experience with Linux and Mac administration, as well as your familiarity with incident response.
Proofread Your Application: Before submitting, carefully proofread your application for any spelling or grammatical errors. A polished application reflects your attention to detail, which is crucial in a cybersecurity role.
How to prepare for a job interview at The Curve Group
✨Showcase Your Technical Knowledge
Make sure to brush up on your understanding of cloud technologies like Azure and AWS, as well as vulnerability management tools such as Tenable One and Qualys. Be prepared to discuss how you've used these tools in past roles or projects.
✨Understand Compliance Standards
Familiarise yourself with key compliance standards relevant to the role, such as ISO 27001, NIST, and GDPR. Being able to articulate how these standards apply to cybersecurity practices will demonstrate your expertise and commitment to best practices.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Think about past experiences where you identified vulnerabilities and how you prioritised and remediated them. Use the STAR method (Situation, Task, Action, Result) to structure your answers.
✨Communicate Effectively with Stakeholders
Since the role involves preparing reports for stakeholders, practice explaining complex technical concepts in simple terms. This will show your ability to communicate effectively with both technical and non-technical audiences, which is crucial in a hybrid work environment.