At a Glance
- Tasks: Protect systems and data through proactive security measures and risk analysis.
- Company: Join KFC, a diverse and inclusive workplace that values your unique perspective.
- Benefits: Enjoy hybrid working, private healthcare, and generous pension contributions.
- Why this job: Make a real impact in cybersecurity while growing your skills in a supportive environment.
- Qualifications: Degree in IT or related field; relevant security certifications preferred.
- Other info: Flexible working hours and a culture that encourages personal growth.
The predicted salary is between 28800 - 48000 ÂŁ per year.
The Security Analyst is responsible for safeguarding the organization’s systems, data, and services through risk-based analysis, proactive security operations, and continuous improvement of controls. This mid-level role blends hands-on technical work (e.g., vulnerability management, endpoint/EDR, SIEM monitoring) with risk reporting, mitigation planning, and compliance alignment (e.g., ISO 27001, NIST CSF, CIS Controls, GDPR). The successful candidate will be self-motivated, detail-oriented, and adept at prioritizing workload based on quantified risk and business impact.
WHAT WILL YOU SPEND YOUR TIME DOING?
- Security Operations & Management (30%)
- Contribute to, maintain, and enforce security policies, procedures, and standards.
- Oversee security risk assessments, vulnerability scans, and penetration tests.
- Monitor and triage security alerts from SIEM/EDR tools; investigate events, determine root cause analysis, and coordinate remediation.
- Coordinate with IT teams to implement technical safeguards, including firewalls, encryption, identity and access controls.
- Progress awareness programs to educate employees on security best practices.
- Governance, Risk & Compliance (30%)
- Produce periodic risk reports and dashboards for leadership, highlighting trends, key risks, and recommended mitigations.
- Assist in policy/procedure development, secure baselines, and compliance evidence collection for audits.
- Contribute to risk assessments (systems, projects, suppliers), translating technical issues into business risk statements with likelihood/impact.
- Support control design and testing aligned to frameworks (ISO 27001 Annex A, NIST CSF, CIS Controls) and regulatory obligations (e.g., GDPR; PCI DSS if in scope).
- Hold clear authority to challenge priorities, influence sequencing of investment, and recommend funding decisions at enterprise level.
- Incident Response & Readiness (20%)
- Participate in incident response (IR) lifecycle: detection, analysis, containment, eradication, recovery, lessons learned.
- Maintain IR playbooks and run tabletop exercises; drive post-incident improvements and control tuning.
- Vulnerability & Patch Management (20%)
- Own scheduled vulnerability scans; analyze findings, assign risk scores, and produce remediation plans in partnership with Infrastructure/tech teams.
- Track patching SLAs, exceptions, and compensating controls; measure and report progress against risk-based targets.
- Validate remediation through rescanning and regression checks.
Working relationships:
- Cross functional teams within technology; this includes making them clear on the security standards in relation to the products they own and making sure any suppliers they managed are clear on expectations.
- Wider business teams: this includes awareness on security posture and best practice, including items such as password behaviour, device control and application screen (onboarding of SaaS solutions etc).
- Global teams; includes working with our Yum! partners to ensure global compliance, trends and alignment, directly with audit but indirectly with strategy and alignment to new process/tools.
Qualifications
- WHAT WE LOVE FROM YOU:
- Education/Certifications: Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent practical experience). Relevant certifications (one or more strongly preferred): CompTIA Security+, CySA+, SSCP, GIAC (e.g., GSEC/GCIH), AZ-500, MS-500, CCSK/CCSP, ISO 27001.
- Experience: Solid experience in a security analyst or similar role within IT security operations. Hands‑on experience with vulnerability management (scanning, analysis, and remediation coordination). Practical experience with endpoint security/EDR and SIEM alert triage and incident remediation. Demonstrated ability to produce risk reports and drive risk mitigation actions with cross‑functional teams. Exposure to incident response and security testing (e.g., assisting with pen tests, red team findings, or threat modeling). Familiarity with industry standards controls and regulations (e.g., NIST, CIS, GDPR, HIPAA). Familiarity with Directory Services (Active Directory and Entra ID) with emphasis on security. Good communication skills and the ability to collaborate effectively with diverse teams.
- Knowledge and Expertise:
- Risk & Compliance: Solid understanding of risk assessment methodologies, control frameworks (ISO 27001, NIST CSF, CIS Controls), and regulatory basics (GDPR; PCI DSS).
- Security Controls: Network, endpoint, identity, data protection, secure configuration, and logging/monitoring fundamentals.
- Cloud & Modern IT: Working knowledge of security in Microsoft 365, Azure (IAM, Conditional Access, Defender suite), and common SaaS platforms.
- Threat Landscape: Awareness of common attack vectors (phishing, ransomware, privilege misuse, misconfiguration) and defense‑in‑depth strategies.
- Skills:
- Analytical & Detail‑Oriented: Keen eye for anomalies; precise documentation and follow‑through.
- Communication: Clear written and verbal communication—translating technical detail into business‑friendly risk insights.
- Collaboration: Works well with Infrastructure, Application, and Business teams; influences without authority.
- Self‑Motivation: Proactive ownership; drives tasks to completion with minimal supervision.
- Process Discipline: Organizes workload, meets deadlines, and adheres to SLAs and standards.
- Ethics & Confidentiality: Handles sensitive information with discretion and integrity.
WHAT’S IN IT FOR YOU:
We offer benefits that make your life that little bit easier, because we know the juggle is real. From flexible, hybrid working and Live Well Days, we’ve created a package that supports the real you, in and out of work. You’ll get:
- Hybrid working from our Woking RSC (just 24 mins from London)
- Up to 11% company pension contributions
- 5 Live Well Days a year, just for you
- Bonus scheme linked to company & personal performance
- Private healthcare, Digital GP access & mental health coaching
- Enhanced parental leave and flexible return options
- And yes — 25% off the chicken
KEEPING IT REAL
We don’t hire staff — we hire people. People with real lives and aspirations, building real careers. Each of us has something special to add to the mix we call work, and we’ll always encourage you to add your perspective. See, at KFC, everyone’s welcome — whatever your background, and whatever future you’re creating. We’ll look out for you because you’re one of us, not because you work for us. We’ll invest in your potential, because it’s what we’ve always done. But most of all, we’ll give you the freedom to be you, wherever (and whoever) you happen to be.
KFC FOR EVERYONE:
Whoever you are and wherever you’re from, KFC is a place where you can bring the real you to work. Our promise is this: every person who applies to a role at KFC, regardless of age, background, ethnicity, gender, ability, religion or sexual orientation, will have an equal opportunity to work here. We don’t just welcome, we encourage applications from underrepresented groups from all industries. If you’d like any additional support with your application, have a disability or condition that may affect your performance during the recruitment process, or have any other requirements — just let us know. We’ll be there to help you be the real you.
READY?
We hope so. If you’re ready to be part of our community, now’s the time to apply. Worried you aren’t ticking all the boxes? Don’t - we’d still love to hear from you.
Security Analyst in Woking employer: KFC Corporation, Pizza Hut, LLC
Contact Detail:
KFC Corporation, Pizza Hut, LLC Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Analyst in Woking
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with current employees at KFC. A friendly chat can sometimes lead to opportunities that aren’t even advertised.
✨Tip Number 2
Show off your skills! If you’ve got hands-on experience with vulnerability management or SIEM tools, don’t be shy about it. Bring examples of your work to interviews to demonstrate your expertise.
✨Tip Number 3
Prepare for those tricky questions! Brush up on your knowledge of risk assessment methodologies and compliance standards like ISO 27001 and GDPR. Being able to discuss these confidently will set you apart.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen. Plus, you’ll be part of a community that values your unique perspective and potential.
We think you need these skills to ace Security Analyst in Woking
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Security Analyst role. Highlight your relevant experience in security operations, risk management, and compliance. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about security and how your background makes you a great fit for our team. Keep it engaging and personal – we love a bit of personality!
Showcase Your Technical Skills: Don’t forget to mention your hands-on experience with tools like SIEM, EDR, and vulnerability management. We’re keen on seeing how you’ve tackled real-world security challenges, so share specific examples!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our team at StudySmarter!
How to prepare for a job interview at KFC Corporation, Pizza Hut, LLC
✨Know Your Stuff
Make sure you brush up on your technical knowledge related to security operations, vulnerability management, and compliance frameworks like ISO 27001 and NIST CSF. Be ready to discuss specific tools you've used, such as SIEM or EDR systems, and how you've applied them in real-world scenarios.
✨Showcase Your Analytical Skills
Prepare to demonstrate your analytical abilities by discussing past experiences where you identified risks or vulnerabilities. Use concrete examples to illustrate how you approached these issues, the steps you took to mitigate them, and the outcomes of your actions.
✨Communicate Clearly
Since this role involves collaboration with various teams, practice explaining complex security concepts in simple terms. Think about how you can translate technical jargon into business-friendly language, especially when discussing risk reports or compliance requirements.
✨Be Proactive and Self-Motivated
Highlight your self-motivation by sharing instances where you took the initiative to improve security processes or educate colleagues on best practices. Employers love candidates who can drive tasks to completion with minimal supervision, so be sure to convey your proactive nature.