At a Glance
- Tasks: Lead vulnerability management and enhance security across teams.
- Company: Join LSEG, a global leader in financial markets and data services.
- Benefits: Enjoy healthcare, retirement planning, paid volunteering days, and wellbeing initiatives.
- Why this job: Be part of a dynamic culture that values individuality and sustainability.
- Qualifications: Bachelor's degree in Computer Science or related field; 5 years in cybersecurity required.
- Other info: Mentorship opportunities available for junior analysts.
The predicted salary is between 43200 - 72000 £ per year.
The Principal Security Analyst will be responsible for guiding and handling the Vulnerability Management (VM) Plan, ensuring the coordination, monitoring, and support of activities related to VM, Cloud Security, Pen Testing, security patching, and remediation management. This role requires a strategic problem solver with advanced technical skills and the ability to mentor junior analysts while collaborating across various teams to enhance the organisation’s security posture.
Key Responsibilities:
- Vulnerability Management: In-depth knowledge of vulnerability management, the vulnerability life cycle stages.
- Technical Remediation: Through understanding of remediation concepts/frameworks pertaining to vulnerabilities.
- Vulnerability Exception: Solid grasp of vulnerability exception processes, exception assessment processes, and compensating security controls.
- Partner Engagement: Excellent partner leadership skills working with various levels of management/non-management colleagues within technology and business departments within LSEG.
- Roadmap Development: Provide input, prepare, and update the VM roadmap. Develop, maintain, and publish project plans and operation schedules.
- Reporting: Provide status reports to Cyber Security leadership on VM metrics, key risk indicators, trends, and compliance.
- Solution Proposals: Propose VM concepts and solutions, prepare presentations, and coordinate vendor demonstrations.
- Standard Operating Procedures (SOPs): Create and maintain SOPs for VM, providing technical knowledge to operations and production support teams.
- Configuration Control: Maintain configuration control of VM hardware, systems, and application software. Coordinate upgrades and maintenance activities on VM tools.
- Collaboration: Work closely with Vulnerability Assessment & Pen Testing teams to analyse results and threat feeds, reacting appropriately to security weaknesses or vulnerabilities.
- Technical Documentation: Prepare and maintain user documentation of the VM programme, including requirements, architecture designs, network topology, applications, and application security designs.
- Policy Collaboration: Collaborate on Information Security policies, standards, and baselines, contributing to compliance measurement efforts.
- Governance Reporting: Collaborate on and provide VM results and metrics for consistent reporting for governance purposes. Coordinate remediation plans and activities.
- Planning: Help develop a long-term VM strategy (3-5 years) addressing global information security needs, identifying current state, gaps, and opportunities.
- Mentorship: Mentor and guide junior analysts, providing technical leadership and encouraging a culture of continuous learning and improvement.
Technical Requirements:
- Advanced Knowledge: Deep understanding of VM tools and technologies, including but not limited to Nessus, Qualys, and Rapid7.
- Cloud Security: Extensive experience with cloud security platforms (e.g., AWS, Azure, Google Cloud) and their security configurations.
- Pen Testing: Proficient in penetration testing methodologies and tools such as Metasploit, Burp Suite, and OWASP ZAP.
- Security Patching: Expertise in security patching processes and tools, including WSUS, SCCM, and automated patch management solutions.
- Scripting and Automation: Solid skills in scripting languages (e.g., Python, PowerShell) for automation of security tasks and processes.
- Network Security: In-depth knowledge of network security principles, including firewalls, IDS/IPS, and network segmentation.
- Compliance: Familiarity with regulatory compliance requirements (e.g., GDPR, HIPAA) and industry standards (e.g., ISO 27001, NIST).
Qualifications:
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- 5 years of experience in cybersecurity, with a focus on vulnerability management and cloud security.
- Relevant certifications such as CISSP, CISM, or CEH.
- Excellent analytical and problem-solving skills.
- Good communication and presentation skills.
- Ability to work closely with multi-functional teams.
Preferred Qualifications:
- Experience with advanced threat detection and response tools.
- Knowledge of secure software development practices and DevSecOps or equivalent experience.
- Experience in mentoring and developing junior team members.
LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth. Our values of Integrity, Partnership, Excellence and Change underpin our purpose and set the standard for everything we do, every day. Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce. You will be part of a collaborative and creative culture where we encourage new ideas and are committed to sustainability across our global business.
Principal Security Analyst employer: London Stock Exchange Group
Contact Detail:
London Stock Exchange Group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Principal Security Analyst
✨Tip Number 1
Familiarise yourself with the latest trends in vulnerability management and cloud security. Being well-versed in tools like Nessus, Qualys, and Rapid7 will not only boost your confidence but also demonstrate your commitment to staying updated in this fast-paced field.
✨Tip Number 2
Network with professionals in the cybersecurity field, especially those who work in vulnerability management. Attend industry conferences or webinars to connect with potential colleagues and learn about their experiences, which can provide valuable insights into the role.
✨Tip Number 3
Prepare to discuss your experience with mentoring junior analysts during interviews. Highlight specific examples of how you've guided others in technical concepts or problem-solving, as this is a key aspect of the Principal Security Analyst role.
✨Tip Number 4
Showcase your ability to collaborate across teams by preparing examples of past projects where you worked with different departments. This will illustrate your partner engagement skills and your capacity to enhance an organisation's security posture.
We think you need these skills to ace Principal Security Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in vulnerability management, cloud security, and penetration testing. Use specific examples that demonstrate your technical skills and leadership abilities.
Craft a Strong Cover Letter: In your cover letter, express your passion for cybersecurity and how your background aligns with the role of Principal Security Analyst. Mention your experience mentoring junior analysts and collaborating across teams.
Highlight Technical Skills: Clearly list your technical skills related to VM tools, cloud security platforms, and scripting languages. Be specific about your proficiency with tools like Nessus, Qualys, and Metasploit.
Showcase Problem-Solving Abilities: Provide examples in your application that illustrate your analytical and problem-solving skills. Discuss how you've successfully addressed vulnerabilities or improved security processes in previous roles.
How to prepare for a job interview at London Stock Exchange Group
✨Showcase Your Technical Expertise
As a Principal Security Analyst, you'll need to demonstrate your in-depth knowledge of vulnerability management tools and cloud security platforms. Be prepared to discuss specific tools like Nessus or AWS, and share examples of how you've used them in past roles.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Think about past experiences where you had to manage vulnerabilities or lead a team through a security incident, and be ready to explain your thought process and the outcomes.
✨Emphasise Your Mentorship Skills
This role involves mentoring junior analysts, so highlight any previous experience you have in training or guiding others. Share specific examples of how you've helped team members grow their skills and contributed to a culture of continuous learning.
✨Demonstrate Strong Communication Skills
You'll need to collaborate with various teams and present complex information clearly. Practice explaining technical concepts in simple terms, and prepare to discuss how you've effectively communicated security risks and solutions to non-technical stakeholders.