At a Glance
- Tasks: Monitor and analyse security information in a cloud-first environment.
- Company: Join the National Wealth Fund, shaping the UK's financial future.
- Benefits: Competitive salary, hybrid working, and unique learning opportunities.
- Other info: Diverse and inclusive workplace with excellent career growth potential.
- Why this job: Gain hands-on experience with cutting-edge security technologies and make a real impact.
- Qualifications: Experience in information security operations and knowledge of Microsoft 365.
The predicted salary is between 30000 - 35000 £ per year.
At the National Wealth Fund, our mission is to swiftly and effectively mobilise trusted sector insights and investment expertise to unlock billions in private finance for projects across the United Kingdom. Providing £27.8bn of capital and an expanded mandate, we are ready to help the market invest with confidence, continue to drive forward the Government's growth ambitions.
We are looking for skilled and results-oriented individuals who are motivated to help us build the National Wealth Fund into an industry-leading institution.
Job PurposeSupport NWF’s IT Risk & Security function by monitoring and analysing security information across a cloud-first, SaaS-enabled environment. Working under the direction of the IT Risk & Security Lead and/or Senior Analysts, help identify threats and vulnerabilities across Microsoft 365 (including Defender, Entra ID, Purview and Copilot) and wider SaaS services, and support the operation and continuous improvement of effective security controls. Provide information security services including incident triage and response support, risk and compliance reporting, and security administration activities.
This is a hands-on role supporting NWF’s security operations and governance activities. On a typical day you will be monitoring and triaging alerts and investigations in Microsoft 365 (including Defender), responding to general security support queries and service requests from colleagues, and supporting the coordination of incidents (logging, evidence capture, timelines and follow-ups). You will also spend time producing clear status updates and metrics, keeping documentation and runbooks up to date, and helping the team apply security controls across Entra ID, Purview, Copilot and wider SaaS services. The role works closely with IT colleagues and suppliers, escalating risks and issues to the IT Risk & Security Lead / Senior Analyst and helping to track remediation through to completion.
This role is designed to build practical, in-demand security skills through day-to-day exposure to modern, cloud-first technology and ways of working. You’ll work with and learn from experienced security colleagues, developing confidence in incident support, governance, and the application of security controls. You will gain hands-on experience across Microsoft 365 security capabilities (including Defender, Entra ID and Purview) and develop an understanding of how Copilot and wider SaaS services can be adopted securely. There will be opportunities to contribute to continuous improvement (e.g., improving runbooks, reporting, automation ideas and control checklists), and to support relevant training and certifications aligned to the role.
Location: Hybrid working with a minimum of 3 days per week in the Leeds office.Deadline to Apply: 1st July 2026. Early submission is encouraged, and applications will be reviewed on an ongoing basis.Salary: £30,000 - £35,000
Core Responsibilities:
- Provide support to NWF’s IT Risk & Security function, working under the direction of the IT Risk & Security Lead and/or Senior Analyst.
- Monitor and triage security alerts and events (primarily across Microsoft 365, including Defender); investigate and escalate in line with documented procedures.
- Support security incident management activities, including logging, evidence capture, timelines, communication support, and post-incident reporting.
- Respond to security support requests from colleagues (e.g., advice on secure ways of working, suspected phishing/malicious content, access and sharing questions, and Copilot/M365 security queries), resolving where appropriate and escalating in line with agreed processes.
- Assist with operational security administration tasks within agreed permissions and processes (e.g., user/guest access controls, Entra ID-related activities, and policy/configuration checks as directed).
- Support the use of Microsoft Purview capabilities (e.g., information protection / sensitivity labels, data governance tasks) and help track exceptions, issues, and actions.
- Support security-by-design / change activities by completing defined checks (e.g., review of SaaS onboarding requests, configuration questionnaires, or control checklists) and escalating risks/concerns.
- Track and support remediation actions arising from incidents, risk assessments, vulnerability findings, supplier assurance, and audit activity; follow up and report progress.
- Help maintain and improve security documentation (procedures, runbooks, knowledge articles) so standard processes are repeatable and auditable.
- Support the maintenance of information security governance artefacts (e.g., risk registers, control attestations, evidence packs) and produce accurate metrics and status reporting.
- Assist with internal and external audit requests by collating evidence and coordinating responses with relevant teams and third parties.
- Support operational security tasks such as phishing reporting/analysis, user guidance, and handling suspected malicious emails in line with policy.
- Maintain awareness of emerging threats and relevant M365 / cloud security features (including Copilot-related security considerations) and share practical improvements with the team.
Essential
- Practical experience supporting information security operations and/or information security risk management activities.
- Working knowledge of Microsoft 365 and cloud concepts, with an interest in the security capabilities across Defender, Entra ID, Purview and related services.
- Experience handling security alerts, incidents, or service requests using defined processes (including logging, triage, investigation support, escalation, and reporting).
- Understanding of common security control areas (identity and access management, endpoint/email security, data protection, logging/monitoring, and vulnerability management).
- Comfortable working with data to produce clear insights, metrics, and reporting (e.g., trends, KPIs, and action tracking).
- Working knowledge of security frameworks/standards and how controls are evidenced (e.g., NIST, ISO 27001, Cyber Essentials).
- Strong written and verbal communication skills, including the ability to document procedures and explain risk/issues in a clear, non-technical way.
- Good investigative and problem-solving skills, attention to detail, and ability to manage workload and escalate appropriately.
Desirable
- Hands-on experience with Microsoft security tooling such as Microsoft Defender, Entra ID, Purview, and/or related security admin centres.
- Awareness of security considerations and controls for Copilot and GenAI features in Microsoft 365 (e.g., permissions, data access, and information protection).
- Understanding of data protection responsibilities and practical application (including UK GDPR).
- Experience supporting SaaS onboarding / supplier assurance activities (e.g., security questionnaires, evidence collation, tracking remediation actions).
- Relevant professional qualification or certification (e.g., Security+, SSCP, SC-900, AZ-900, or similar).
- Experience in a regulated environment and/or familiarity with audit and compliance expectations.
Strong communication and engagement skills, with the ability to work effectively with technical and non-technical stakeholders. Collaborative approach and ability to build effective working relationships across IT, suppliers, and the wider business. Self-motivated and organised, with a continuous improvement mindset and comfort working to objectives and deadlines. Comfortable taking direction, asking questions, and escalating issues appropriately.
A career with us offers a unique opportunity to make a lasting impact and work on cutting-edge technologies that will drive the UK’s future. We value diversity in our people and inclusion is at the heart of what we do. We offer competitive benefits and unique learning opportunities from combining both private and public sector skills and experience.
Please note, referencing and background checks are carried out for all roles here at the National Wealth Fund.
The National Wealth Fund encourages a diverse workforce and welcomes applications from all suitably qualified people. Inclusion is at the heart of what the Fund does. Diversity in the Fund's people and their ideas will be vital to the National Wealth Fund's success. Appointments will be made on merit, with regard to maintaining the breadth of experience and expertise required and reflecting diversity in the broadest sense, to embrace different perspectives, characteristics and experience, as well as being broadly representative of the nations and regions of the UK. Our roles are open to full-time, part-time or job-share applicants. Job-share applicants should supply individual CVs and a joint cover letter submitted with both applications. As part of our standard hiring process, please be informed that a background check will be conducted for successful candidates in accordance with our company policy and industry best practices. Please note, that successful candidates will be offered a salary that is appropriate to their relevant experience and performance during the selection process.
IT Analyst, Information Security in Leeds employer: National Wealth Fund Limited
The National Wealth Fund is an exceptional employer, offering a dynamic work environment in the heart of Leeds, where innovation meets public service. With a strong commitment to employee growth, we provide unique learning opportunities and support for professional certifications, all while fostering a culture of diversity and inclusion. Join us to make a meaningful impact on the UK's future through cutting-edge technology and collaborative teamwork.
Contact Details:
National Wealth Fund Limited Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land IT Analyst, Information Security in Leeds
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including National Wealth Fund Limited, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through National Wealth Fund Limited
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at National Wealth Fund Limited. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace IT Analyst, Information Security in Leeds
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at National Wealth Fund Limited insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to National Wealth Fund Limited that you’re committed to staying ahead in the game.
How to prepare for a job interview at National Wealth Fund Limited
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at National Wealth Fund Limited to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at National Wealth Fund Limited.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.