At a Glance
- Tasks: Design and support cyber security controls to protect our IT environment.
- Company: Join a leading investment firm dedicated to cyber security excellence.
- Benefits: Competitive salary, flexible working, and opportunities for professional growth.
- Why this job: Make a real difference in safeguarding digital assets and enhancing security measures.
- Qualifications: 5+ years in a SOC environment with strong communication skills.
- Other info: Dynamic team atmosphere with a focus on innovation and continuous learning.
The predicted salary is between 36000 - 60000 £ per year.
The Cyber Security operation's function is responsible for the day-to-day provision of enterprise cyber security services to support the business. These services include all aspects of Cyber Risk Management, implementation and maintenance of technical security controls, vulnerability and patch management and operate effective incident management and cyber investigations. The department’s key objective is to ensure Insight Investment operates a safe, secure, and resilient IT environment that enables it to confidently go about its day-to-day activity.
The purpose of this role is to design new, mature existing and support the operation of cyber security controls and processes within Insight Investment in line with cyber security risks and the cyber security policies and standards. This includes Identity & Access Management (IAM), PAM security monitoring, cloud security, scheduled security checks, security monitoring working with the MSSP (SIEM and other), security incident management, pen-testing, vulnerability management and KRI/KPI reporting.
Role Responsibilities
- Developing a familiarity with new tools and best practices for security operations
- Defining, implementing and maintaining operational security processes
- Reviewing and maturing the Identity and Access Management process in line with industry best practice
- Reviewing incoming SOC requests/incidents
- Assisting in the investigation of SIEM alarms, reported by the MSSP and performing on call once a month
- Assisting in the operational support for the SIEM MSSP
- Helping to develop and fully document new SIEM use cases including how to respond to alarms
- Performing Cloud Security operations related checks
- Developing and maintaining operational Security KRIs/KPIs
- Maintaining technical documentation of operational security controls
- Providing 1/2nd line security incident response capabilities within the Insight SOC
- Creating schedules, writing up Pen-test findings from the report and following through mitigations/remediation plans
- Assisting in the development of new and changes to existing security policies and standards
- Supporting internal and external audits evidence gathering of cyber security
- Chairing Vulnerability management meetings and following through on reports and remediations with the tech teams. Performing risk analysis on when vulnerability management incidents
- Being integral to projects related to Security Operations
- Staying up to date with the latest threat intelligence and threat hunting methodologies to recommend improvements to current processes and security controls
- Performing DSAR requests
Experience Required
- 5 years+ experience in a SOC environment
- Strong communication and collaboration skills
- Fast high paced environment with the ability to work with strict timed deadlines
- Strong prioritisation and an ability to handle multi-tasking situations
- A positive and enthusiastic attitude to investigate and find solutions to security problems
- Hands on experience in the operation of security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, vulnerability management, etc.
- Technical working knowledge of security systems including:
- Network and application firewalls reviews and approvals
- IDS/IPS systems
- Web Proxies and Content Filtering
- Endpoint security including antivirus, host-based firewalls and execution control (Trend Micro an advantage)
- Authentication technologies (Active Directory)
- Network Access Management
- Privilege Access Management (CyberArk would be an advantage)
- VMWare including VDI
- Vulnerability Management tools. (Qualys VMDR, CSAM and/or Asset management would be an advantage)
- Endpoint Detection Response (EDR)
- Pen-test write up and remediation
- Forensics investigations
- Cloud security in MS Azure
Advantageous (not essential)
- Cloud Secrets Management (Cloud Vaults / Key Management & Rotation / MFA / Passwords)
- Scripting tool such as Python etc.
- API Security
Insight is committed to being an inclusive employer and encourages applications from all suitably qualified applicants irrespective of background, circumstances, age, disability, gender identity, ethnicity, religion or belief and sexual orientation.
Cyber Security Analyst in London employer: Insight Investment
Contact Detail:
Insight Investment Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Analyst in London
✨Tip Number 1
Network, network, network! Get out there and connect with professionals in the cyber security field. Attend industry events, join online forums, and don’t be shy about reaching out on LinkedIn. We all know that sometimes it’s not just what you know, but who you know!
✨Tip Number 2
Prepare for interviews like a pro! Research the company, understand their cyber security needs, and be ready to discuss how your experience aligns with their goals. We recommend practising common interview questions and even doing mock interviews with friends or mentors.
✨Tip Number 3
Showcase your skills! Create a portfolio of your work, including any projects, pen-test reports, or security incidents you've managed. This will give potential employers a tangible sense of what you can bring to the table. We love seeing practical examples of your expertise!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we’re always looking for passionate individuals who want to make a difference in the cyber security landscape. So, get your application in and let’s make it happen!
We think you need these skills to ace Cyber Security Analyst in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Cyber Security Analyst role. Highlight your experience in SOC environments and any relevant technical skills that match the job description. We want to see how your background aligns with our needs!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your skills can contribute to our mission at Insight Investment. Keep it engaging and personal – we love a good story!
Showcase Your Technical Skills: Don’t hold back on showcasing your technical expertise! Mention specific tools and systems you’ve worked with, like firewalls or SIEM solutions. We’re looking for hands-on experience, so let us know what you bring to the table.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our team at StudySmarter!
How to prepare for a job interview at Insight Investment
✨Know Your Cyber Security Basics
Make sure you brush up on the fundamentals of cyber security, especially the tools and processes mentioned in the job description. Familiarise yourself with concepts like Identity & Access Management, vulnerability management, and incident response. This will help you speak confidently about your experience and how it aligns with the role.
✨Showcase Your Problem-Solving Skills
Prepare to discuss specific examples where you've tackled security issues in the past. Think about times when you identified vulnerabilities or responded to incidents. Highlight your analytical skills and how you approach problem-solving in high-pressure situations, as this is crucial for a Cyber Security Analyst.
✨Stay Updated on Current Threats
Cyber security is always evolving, so make sure you're aware of the latest threats and trends. Research recent incidents or vulnerabilities that have made headlines. Being able to discuss these during your interview shows that you're proactive and passionate about staying informed in the field.
✨Prepare Questions for Them
Interviews are a two-way street, so come prepared with thoughtful questions about the company's security practices and culture. Ask about their approach to threat hunting or how they handle incident response. This not only shows your interest but also helps you gauge if the company is the right fit for you.