Cyber Security Analyst in Yeovil

Cyber Security Analyst in Yeovil

Yeovil Full-Time 40000 - 50000 £ / year (est.) No working from home possible
Leonardo SpA

At a Glance

  • Tasks: Join our team to monitor and respond to cyber security incidents.
  • Company: Be part of Leonardo, a global leader in Aerospace, Defence, and Security.
  • Benefits: Enjoy flexible leave, a great pension scheme, and access to mental health support.
  • Other info: Join a diverse team committed to innovation and global safety.
  • Why this job: Make a real impact in protecting clients from cyber threats while developing your skills.
  • Qualifications: Experience in Cyber Security and excellent communication skills are essential.

The predicted salary is between 40000 - 50000 £ per year.

We're looking for a Cyber Security Analyst to join the ARCHANGEL™ Protective Monitoring (ProMon) Team. ARCHANGEL™ delivers specialist technical cyber security services to a range of clients across a variety of industries including construction, government, defence and aerospace. The Team is responsible for providing thorough initial investigation into anomalous network activity that may lead to potential security incidents.

Beyond ARCHANGEL™, Leonardo and its Cyber Security division are a world leader in safety-through-technology, providing tailored solutions for customers in public administration, public safety and security, critical infrastructure, services, transport, post and logistics. You will be joining our highly skilled team working at our Yeovil site Monday-Friday. This is a great opportunity to bring your talents and form an integral part of Leonardo's future. We can help you develop your skills and offer great opportunities to develop and grow, so why not join us.

What you'll do:

  • Provide monitoring, alerting and incident handling services within the SOC in line with SLAs.
  • Act as the initial analytical reference point for identifying and then quantifying the nature and extent of security incidents and offer initial professional advice relating to possible business impact in order to reduce both the Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
  • Advise on incident containment measures through recommended initial actions to customers in collaboration with the Incident Response (IR) Team.
  • Provide advice relating to potential mitigation measures in order to prevent, or limit future reoccurrence in collaboration with the Incident Response (IR) Team.
  • Have an understanding of Incident Response, Cyber Kill Chain, Threat Modelling and pertinent Attack Vectors.
  • Have a collaborative working ethos in order to work across the team in order to create pertinent Playbooks, Use Cases, etc.
  • Perform proactive analysis across client networks by staying abreast of current threats and trends.
  • Develop and maintain a credible knowledge of current and emerging threats likely to affect the Integrity of the managed service you are protecting.
  • Review reoccurring false positive firings and assist in the tuning of SIEM and IDS rules to reduce false positives and maintain good security alerting.
  • Creation of reporting for management and clients on security incidents and threat intelligence trends.

What you'll bring:

  • Be able to excellently communicate at all levels, working with customers is a must, so we need you to be able to let them know what's going on.
  • Experience in Cyber Security, e.g. Protective Monitoring, Incident Response, Security Engineering SIEM (LogRhythm, Arcsight, Splunk, etc) & IDS (Snort) experience.
  • Have a sound knowledge of IT security best practice, common attack types & detection/prevention methods.
  • Demonstrate experience of analysing & interpreting system, security & application logs in order to diagnose faults & spot abnormal behaviours.
  • Have great organisational skills & attention to detail.
  • Ability to work independently & as part of a team.
  • Highly motivated, with the aptitude to learn new skills.

These additional skills will also help:

  • SANS SEC 503 Intrusion Detection in Depth or equivalent.
  • SANS SEC 504 Incident Handling, Hacker Tools and Techniques or equivalent.
  • SANS SEC 508 Advanced Incident Response, Threat Hunting, and Digital Forensics or equivalent.
  • SANS SEC 511 Continuous Monitoring and Security Operations or equivalent.
  • Exposure to IT service management best practices such as ITIL.
  • Knowledge of standards & guidelines such as ISO27001, GDPR principles and GPG-13.
  • Threat Intelligence experience.
  • Report Writing.

Security Clearance:

This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV).

Why join us:

  • Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year.
  • Secure your Future: Benefit from our award-winning pension scheme with up to 15% employer contribution.
  • Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks championing inclusion and diversity.
  • Rewarding Performance: All employees at management level and below are eligible for our bonus scheme.
  • Never Stop Learning: Free access to 4,000+ online courses via Coursera and LinkedIn Learning.
  • Refer a friend: Receive a financial reward through our referral programme.
  • Tailored Perks: Spend up to £500 annually on flexible benefits including private healthcare, dental, family cover, tech & lifestyle discounts, gym memberships and more.

Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team—they are key contributors to shaping innovation, advancing technology, and enhancing global safety. At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know. Be part of something bigger - apply now!

Cyber Security Analyst in Yeovil employer: Leonardo SpA

At Leonardo, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation. Our Yeovil site provides a supportive environment where Cyber Security Analysts can thrive, with access to extensive training resources, generous leave policies, and a commitment to employee wellbeing. Join us to be part of a global leader in Aerospace, Defence, and Security, where your contributions will shape the future of technology and safety.

Leonardo SpA

Contact Details:

Leonardo SpA Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Security Analyst in Yeovil

Tip Number 1

Network like a pro! Attend industry events, webinars, or local meetups to connect with other cyber security enthusiasts. You never know who might have the inside scoop on job openings or can introduce you to someone at Leonardo.

Tip Number 2

Show off your skills! Create a personal project or contribute to open-source initiatives related to cyber security. This not only boosts your portfolio but also demonstrates your passion and expertise to potential employers.

Tip Number 3

Prepare for interviews by brushing up on common cyber security scenarios and incident response strategies. Practice articulating your thought process clearly, as communication is key in this field—especially when working with clients.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are genuinely interested in joining our team at Leonardo.

We think you need these skills to ace Cyber Security Analyst in Yeovil

Cyber Security
Protective Monitoring
Incident Response
Security Engineering
SIEM (LogRhythm, Arcsight, Splunk)
IDS (Snort)
IT Security Best Practices

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Cyber Security Analyst role. Highlight relevant experience, especially in Protective Monitoring and Incident Response, and don’t forget to mention any specific tools like SIEM or IDS that you’ve worked with.

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your skills align with our needs. Be sure to mention your understanding of the Cyber Kill Chain and any relevant certifications.

Show Off Your Communication Skills:Since communication is key in this role, make sure your application reflects your ability to convey complex information clearly. Use straightforward language and structure your application logically to demonstrate your organisational skills.

Apply Through Our Website:We encourage you to apply through our website for the best chance of success. It’s super easy, and you’ll be able to see all the details about the role and our company benefits while you’re at it!

How to prepare for a job interview at Leonardo SpA

Know Your Cyber Security Basics

Before the interview, brush up on your knowledge of IT security best practices, common attack types, and detection methods. Be ready to discuss how you would handle specific incidents and what measures you would recommend to mitigate risks.

Familiarise Yourself with Tools

Make sure you’re comfortable discussing SIEM tools like LogRhythm, Arcsight, or Splunk, as well as IDS systems like Snort. If you have experience tuning these tools to reduce false positives, be prepared to share those examples during the interview.

Showcase Your Communication Skills

Since communication is key in this role, practice explaining complex cyber security concepts in simple terms. Think about how you would explain a security incident to a non-technical client and be ready to demonstrate your ability to convey information clearly.

Prepare for Scenario-Based Questions

Expect scenario-based questions where you’ll need to analyse a hypothetical security incident. Practice articulating your thought process, from identifying the issue to recommending containment measures, and how you would collaborate with the Incident Response Team.