Cyber Security Analyst

Cyber Security Analyst

Full-Time No working from home possible
T

At Thorntons Law, every moment matters. Join us as our Cyber Security Analyst and you’ll feel inspired. You’ll feel connected. You’ll feel like you belong. And it all begins from the moment you join us.

That’s because we’ve created a different kind of law firm. Here, you’ll build relationships with clients and colleagues that really last. You’ll help shape what happens now, and what comes next. And we’ll support and encourage you to be the best you can be.

This is what life at Thorntons is all about. And this is your moment to be part of it.

About the role

At Thorntons, protecting our people, clients, information and technology is essential to everything we do. As our Cyber Security Analyst, you’ll play an important role in helping keep the firm safe from cyber threats and information security risks.

You’ll work across security monitoring, vulnerability management, security technology and incident response, helping ensure our security controls operate effectively and continue to evolve as the threat landscape changes.

Working alongside our wider technology teams, security partners and colleagues across the firm, you’ll investigate security events, identify risks, support remediation and help promote strong security behaviours.

It’s about:

  • Security Monitoring & Incident Response – monitoring security alerts and events, carrying out initial investigation and triage, escalating incidents where required and supporting incident response activities, including evidence gathering and post-incident reviews.
  • Vulnerability & Security Controls – conducting vulnerability assessments, supporting remediation activities and monitoring progress; helping maintain secure configurations across endpoints, servers, cloud services and networks; and checking that security controls are operating effectively.
  • Security Technology & Administration – supporting the day-to-day operation and administration of security technologies including Microsoft Sentinel, Microsoft 365 security capabilities, endpoint protection, email security, multi-factor authentication, conditional access and identity protection.
  • Identity & Access Security – supporting access reviews, privileged access monitoring and other activities that help ensure appropriate and secure access to the firm’s systems and information.
  • Analysis & Continuous Improvement – analysing security data, producing reports and dashboards, identifying trends and helping to strengthen our security controls, monitoring capability and operational processes.
  • Documentation & Compliance – maintaining accurate procedures, knowledge articles and security records, while supporting audits, compliance reviews, evidence gathering and policy and standards reviews.
  • Security Awareness – supporting cyber security awareness campaigns and providing colleagues with practical guidance on security best practice and the safe use of technology.
  • Collaboration – working closely with infrastructure, service delivery, data and business teams, as well as suppliers and security partners, to resolve security issues and strengthen our overall cyber resilience.

What you’ll need

  • Strong analytical and problem-solving skills, with excellent attention to detail, accuracy and organisation, and the ability to investigate security alerts and events, identify potential risks and make appropriate decisions about escalation.
  • A good understanding of cyber security principles, controls and frameworks, with knowledge of vulnerability management, remediation and security best practice.
  • Knowledge of Microsoft 365 and Azure security capabilities and products, with familiarity with security monitoring, SIEM and endpoint protection technologies.
  • An understanding of identity and access management concepts, including access controls, privileged access and authentication technologies.
  • A sound understanding of networking, operating systems and cloud platforms, with the ability to apply this knowledge when investigating security issues.
  • Effective verbal and written communication skills, with the ability to explain security matters clearly to both technical and non-technical audiences, alongside a customer and service-focused approach and the ability to prioritise effectively in a fast-changing environment.
  • A proactive approach to learning, with a willingness to stay up to date with emerging threats, attack techniques and security technologies and continually develop your cyber security knowledge.
  • The ability to work collaboratively with technology teams, colleagues across the firm, suppliers and security partners to resolve issues, manage risk and support continuous improvement.
  • Someone who brings curiosity, accountability, attention to detail and a genuine desire to help make the firm more secure.

Why this role

  • Make a real difference – play an important role in protecting our people, clients, information and systems from an ever-changing cyber threat landscape.
  • Build your expertise – gain practical experience across security monitoring, vulnerability management, incident response, identity security and modern security technologies.
  • Work with modern security technology – develop your experience with Microsoft Sentinel, Microsoft 365 security capabilities, endpoint protection and cloud security.
  • Keep learning – stay close to emerging threats, attack techniques and new security capabilities while developing your technical skills.
  • Work across the firm – collaborate with talented colleagues across technology and the wider business, as well as specialist security partners and suppliers.
  • Help shape continuous improvement – contribute ideas and improvements that strengthen our security controls, processes and overall cyber resilience.

What we offer

We offer much more than just a competitive salary, and we’re committed to looking after our people in every way. Here’s just some of the benefits available:

  • 39 Days Annual Leave (includes 5 fixed public holidays)
  • Contributory Pension Scheme with salary exchange
  • Private Medical Insurance
  • Critical Illness Cover
  • Income Protection Cover
  • Group Life Assurance
  • Exceptional maternity, paternity, partner and adoption leave packages
  • Health care cash plan to support everyday health expenses
  • Free Legal fees for moving home and life planning
  • Cycle to Work Scheme
  • Retail Discounts
  • Hybrid Working

Access to a wide range of opportunities to build your expertise and advance your career, through courses, specialist accreditations, training, or business skills development.

Belonging

At Thorntons, we embrace diversity and are committed to creating a welcoming and inclusive workplace where everyone can thrive.

As a Disability Confident employer, we want to ensure that everyone has a positive experience when applying to join us. If you have a disability or are neurodivergent and need any adjustments during the recruitment process, just let us know — we’ll do everything we can to support you.

We work flexibly to meet the needs of our clients and our people. While not every role is the same, most offer a hybrid working pattern. We’ll work with you to agree the right arrangement that supports you, the role, and our clients.

Make the moment matter

If you’re looking to build your career in cyber security and make a real difference, this is the moment to take your next step.

#J-18808-Ljbffr

Cyber Security Analyst employer: Thorntons Law LLP

Join a leading Scottish law firm that prioritises employee well-being and professional growth, offering a competitive salary and generous leave. With flexible working options in Cupar, Forfar, or Perth, you will thrive in a supportive work culture that values client service and relationship building, making it an excellent place for meaningful and rewarding employment.

T

Contact Details:

Thorntons Law LLP Recruitment Team