Senior Information Security Analyst in London

Senior Information Security Analyst in London

London Full-Time 70000 - 85000 £ / year (est.) Home office (partial)
Nexus Jobs

At a Glance

  • Tasks: Lead cybersecurity efforts to protect vital information and systems in a global pharma company.
  • Company: Join a leading global company in the pharma sector with a strong focus on security.
  • Benefits: Competitive salary, remote work options, and opportunities for professional growth.
  • Other info: Dynamic remote work environment with excellent career advancement opportunities.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
  • Qualifications: 5-7 years in Information Security with strong analytical skills and relevant certifications.

The predicted salary is between 70000 - 85000 £ per year.

Our Client is a leading global company specialising in pharma products. They are looking to recruit a Senior Information Security Analyst with at least 5 to 7 years expertise in Technology Security.

The Senior Information Security Analyst is responsible for maintaining information security policies, architecture, technical standards, technical controls, security solutions, guidelines, procedures, and other elements necessary to maintain security posture. Responsible for assessing information risk and facilitating remediation of identified vulnerabilities & risks across the organization. Accountable for coordinating the execution of security measures to protect our computer infrastructure, information systems and to ensure the organization maintains an acceptable risk posture.

The Senior Information Security Analyst is highly engaged in risk management and mitigation, including evaluating vendor risk, examining vendor contracts for terms of service, understanding third-party risk, and data privacy issues. The analyst serves as an expert on cybersecurity protection, detection, response, and recovery. This individual is responsible for coordinating penetration testing and managing internal and external cybersecurity analysts to detect, mitigate, and analyze threats. Works closely with other teams to develop controls such as firewalls, business systems, data leakage protection systems, patching, encryption, vulnerability scanning, application code scanning, remediation as well as defining configuration for a variety of security tools. Prior experience in an international enterprise environment is essential.

Responsibilities:

  • Collaborate with IT teams for input and operational requirements to design and implement the company's overall cybersecurity strategy.
  • Identify and address security gaps discovered through ongoing monitoring of all information security controls and implement enhancements to security controls.
  • Manage access to elevated privileges accounts and audit activities to meet business and regulatory requirements.
  • Evaluate and/or implement cybersecurity solutions and controls to maintain confidentiality, integrity, and availability.
  • Actively participate in proofs-of-concept for new security technologies by developing selection criteria to identify appropriate security solutions to support strategic, operational needs, and security requirements.
  • Participate in the development and testing of the security incident response plan, act as the incident response leader.
  • Develop security, risk, and compliance reports and alerts.
  • Participate in the yearly review of policies and procedures to support information security, risk, and security compliance activities.
  • Participates in developing, testing, and implementation of disaster recovery procedures for the cybersecurity technology in place.
  • Manages cybersecurity projects to ensure that the delivery is on-time, within budget, and adopted to meet the company's information protection requirements.
  • Performs or coordinates internal security assessments, penetration tests, vulnerability scans, and assess organization cybersecurity maturity.
  • Complying with frameworks and regulations such as COBIT, NIST (800-53, cybersecurity), ISO, ITIL, PCI, GLBA, GDPR, HIPAA, and other data privacy and security standards and regulations.
  • Provides internal customer support via assigned tickets for security-related issues, while ensuring assignments are resolved within assigned SLA's.
  • Evaluate and implement CIS critical security controls where necessary.
  • Will provide input into cybersecurity strategic roadmap and annual budget.
  • Adhere to applicable change management policy and procedure.

Qualifications:

  • Bachelor's degree required; advanced degree highly desirable.
  • Candidates must possess significant analytical skills, which evolved from early academic training in Cybersecurity, Information Systems, Computer Science, or similar discipline.
  • Provides a documented work history that includes a minimum of 5-years experience in Information Security.
  • Proficiency in security framework models such as NIST, etc., implementing and auditing security measures, security response, and incident management.
  • Possess a working knowledge of Cisco network switches, routers, firewalls and VPN, network security, administration of DLP, antivirus/antimalware, IDS/IPS, SIEM, SMTP, Email security, AD, Group Policy, DNS, DHCP, and VLANs.
  • Experience with identity access management solutions, such as SAML/OATH.
  • Experience with HIDS and NIDS.
  • The ideal candidate possesses relevant information security or cybersecurity certifications.
  • Requires the ability to analyze and recommend changes to the security landscape where necessary to meet the information security objectives of the organization.
  • Participates in change management meetings and provides expert input to ensure security is maintained.
  • Knowledgeable in security best practices such as encryption, hashing, vulnerability scans, event log monitoring, intrusion detection and prevention, eDiscovery, and content filtering.
  • Ability to manage and continuously improve upon vulnerability management program.
  • Ability to propose solutions for closing identified vulnerabilities in the infrastructure.

Desired Qualifications:

  • Certified Information System Security Professional (CISSP), NIST Cybersecurity Framework (NCSF), Certified Cloud Security Professional (CCSP) and/or Certified Ethical Hacker (CEH).
  • Knowledge and experience with Microsoft Office and Visio.
  • Knowledge of WAN technologies including MPLS, SD WAN.
  • Knowledge of cloud providers security (AWS, GCP or Azure).
  • Prior experience managing Cisco ELA products including DNA, Firepower, ISE Management console, Umbrella, Cisco AMP for endpoints, Stealth watch, as well as Splunk, SolarWinds, Varonis and Darktrace.
  • Prior experience with Azure Rights management and Information protection highly desirable.
  • Project management skills are highly desirable.
  • Previous experience in a HIPAA/FDA regulated environment.

Competencies:

  • Motivation/Initiative: Motivated and curious, willing to ask questions, research issues, and take on challenging projects/assignments; creative, brings new ideas to the table, exhibits self-confidence. Position requires a strong achievement motivation and tenacity.
  • Administrative Skills: Possesses the ability to organize and follow-through on multiple tasks recognizes and attends to important details with accuracy and efficiency. Works to complete goals, tasks, and plans, anticipate potential problems and analyze alternative solutions.
  • Interpersonal Style: Develops/maintains effective working relationships; listens attentively to others; communicates ideas clearly (written & verbal); relates to people in an open/sincere manner; participates effectively in meetings; assists in finding solutions as well as identifying problems; communicates appropriately with supervisor, and co-workers. Able to influence other individuals and maintain calm and reliable demeanor in the face of challenges.
  • Self-Management: Adapts readily to changes in routine; works effectively in stressful situations; needs limited guidance and direction; is comfortable working in a fast-paced environment; is reliable and dependable; is results-oriented; maintains productivity and composure under pressure; views problems as opportunities to create solutions.
  • Thinking Skills: Diagnoses problems efficiently; gathers sufficient input before making decisions or plans; makes timely decisions, quickly determines sources of the problem, identifies information needed to solve a problem and analyzes alternative solutions, communicates issues and decisions effectively to the team.
  • Customer Orientation: Sensitive & responsive to internal customer needs; demonstrates skills in customer services and satisfaction; maintains a positive attitude, willing to listen to customer problems and seeks solutions; stays in tune with changing needs of customers.

This is a UK based role at the Central London offices of the Client, although for the foreseeable future you will be based at home and work remotely. The salary for this role will be in the range 70K - 85K.

Please do send your CV to us in Word format along with your salary and availability.

Senior Information Security Analyst in London employer: Nexus Jobs

Our client, a leading bank in Central London, offers an exceptional work environment that fosters innovation and professional growth. With a strong emphasis on employee development, the company provides comprehensive training opportunities and a collaborative culture that encourages teamwork and knowledge sharing. Employees enjoy a competitive salary package, flexible working arrangements post-probation, and the chance to make a significant impact in a dynamic financial services landscape.

Nexus Jobs

Contact Details:

Nexus Jobs Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Information Security Analyst in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Nexus Jobs, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Nexus Jobs

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Nexus Jobs. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Senior Information Security Analyst in London

Information Security Policies
Risk Management
Cybersecurity Protection
Penetration Testing
Vulnerability Scanning
Data Privacy Compliance
NIST Cybersecurity Framework

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Nexus Jobs insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Nexus Jobs that you’re committed to staying ahead in the game.

How to prepare for a job interview at Nexus Jobs

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Nexus Jobs to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Nexus Jobs.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.