At a Glance
- Tasks: Monitor cyber risks and lead vulnerability remediation across global IT systems.
- Company: Join Lightsource bp, a leader in renewable energy and solar development.
- Benefits: Enjoy competitive salary, health benefits, and opportunities for professional growth.
- Other info: Collaborate with a talented team in a dynamic, global environment.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technology.
- Qualifications: 5+ years in cybersecurity, with strong skills in Microsoft Defender and incident response.
The predicted salary is between 60000 - 80000 £ per year.
About Lightsource bp
Lightsource bp is a global renewable energy company focused on onshore solar development and large‑scale energy storage solutions.
What you’ll do (the role)
Summary : We are seeking a dynamic, hands‑on Senior Cybersecurity Analyst to monitor cyber risk and lead the remediation of identified vulnerabilities across Lightsource bp’s IT systems globally.
You will be responsible for threat detection, investigation, and incident response, leveraging a modern security technology stack with a strong focus on the Microsoft Defender ecosystem.
Working across multiple business areas and time zones, you will proactively hunt for security issues, assess emerging threats, and partner with infrastructure and support teams to strengthen our security posture and drive business cyber maturity.
Responsibilities
- Continuously monitor the organization’s security systems and infrastructure using SIEM, EDR, and related toolsets to detect signs of compromise and investigate security events to completion.
- Proactively conduct threat hunting using threat intelligence frameworks (MITRE ATT&CK, Cyber Kill Chain) and available security platforms to identify and mitigate emerging threats.
- Assess new and evolving cyber threats to the business, optimizing existing Microsoft Defender technologies and other security solutions to better counter identified risks.
- Identify vulnerabilities in systems and applications; collaborate with Infrastructure, Digital Workplace, and Support teams to prioritize, patch, and remediate issues in a timely manner.
- Manage core Security Operations (Sec Ops) tooling platforms, ensuring correct configuration, maximizing security value from existing investments, and maintaining high‑quality configuration documentation.
- Communicate proactively with stakeholders across the business, providing clear technical and non‑technical updates during investigations and escalations.
- Support the development, enforcement, and continuous improvement of cloud security policies, standards, and procedures in alignment with industry frameworks (NIST 2.0, CIS, NIS2) and regulations.
- Create and maintain security awareness training content and assist in its delivery to colleagues across the organization.
Experience
- 5+ years of professional experience in cybersecurity, with at least 2+ years in a Security Operations Center (SOC) or incident response role.
- Advanced proficiency with Microsoft Defender XDR and expert‑level knowledge of Microsoft Sentinel, including KQL query writing and analytics rule development.
- Strong hands‑on experience with Microsoft Defender for Endpoint, including policy configuration and threat investigation.
- Demonstrable experience responding to cyber threats and working in an Azure‑focused cloud environment.
- Proven experience with the Cyber Kill Chain, MITRE ATT&CK, and other security defence and intelligence frameworks.
- Experience in stakeholder management and engagement at C‑Suite level.
- Experience working for Critical National Infrastructure (CNI) organizations is desirable.
- Knowledge
- Microsoft Security Stack: Defender XDR/Sentinel, Defender for Cloud, Defender for Cloud Apps, Defender EASM, Copilot for Security.
- Vulnerability Management: Defender XDR, Tenable IO/Nessus, Defender EASM.
- Data Governance & IDAM: Microsoft Purview (DLP and information governance), Entra ID, Conditional Access Policies.
- Device Management: Working understanding of Intune (MDM/MAM).
- Networking/Firewalls: Exposure to Cisco Meraki and Fortinet Forti Gate (desirable).
- Regulatory & Compliance Frameworks: NIST 2.0 Cyber Security Framework (required); NIS2, NERC CIP, SOC2, and IEC 62443 OT standards (desirable).
- ITIL Principles: Good understanding of ITIL principles and their application to IT service management.
- Information
- Security
Technologies: Firewalls, intrusion detection systems, vulnerability assessment tools, logging solutions, gateway and endpoint security products, and authentication mechanisms.
- Operational Technology (OT) Cyber Security: Desirable but not required.
Skills
- Advanced threat detection, investigation, and incident response capabilities.
- Strong technical troubleshooting and problem‑solving skills with ability to work across complex, global technology environments.
- Expert‑level proficiency with Microsoft security tools and cloud‑based security architectures.
- Excellent communication skills: ability to translate complex technical concepts for both technical and non‑technical audiences.
- Proactive mindset with genuine enthusiasm for cybersecurity and drive to improve security posture.
- Ability to remain calm under pressure and manage multiple incidents and priorities.
- Cross‑functional collaboration: ability to partner effectively with Infrastructure, Digital Workplace, Support, and business teams worldwide.
- Strong documentation and reporting skills for both technical and executive audiences.
- Subject‑matter expertise with proven ability to identify and champion security improvement opportunities.
Education
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related field.
- Industry‑recognized certifications (choose one or more): Azure Security Engineer (AZ‑500), Certified Information Systems Security Professional (CISSP), Certified Cyber Professional (CCP), Comp TIA Security+, GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA).
- Additional Notes / Role‑Specific Requirements
- This is a global role supporting an expanding, geographically dispersed workforce and technology stack.
- You will interface regularly with multiple business areas across different time zones.
- You will work within a small, talented cybersecurity team and collaborate with a global IT organization.
- The role requires engagement with the convergence of IT and Operational Technology (OT) security, reflecting the evolving landscape of energy infrastructure protection.
- International regulatory compliance knowledge will be increasingly important as the organisation scales across multiple jurisdictions.
- #J-18808-Ljbffr
Senior Cyber Security Analyst employer: Lightsource
Lightsource is an exceptional employer that fosters a vibrant work culture in Belfast, where creativity and collaboration thrive. As a Sales Consultant, you will benefit from working in a design-led environment with opportunities for professional growth, while engaging with a diverse range of clients and projects. The company prioritises employee development and offers a supportive atmosphere that encourages innovation and excellence in client service.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Cyber Security Analyst
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Lightsource, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Lightsource
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Lightsource. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Cyber Security Analyst
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Lightsource insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Lightsource that you’re committed to staying ahead in the game.
How to prepare for a job interview at Lightsource
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Lightsource to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Lightsource.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.