IT Security Analyst

IT Security Analyst

Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
Withersworldwide

At a Glance

  • Tasks: Monitor and investigate security alerts, support incident response, and improve security operations.
  • Company: Join Withers, a law firm dedicated to integrity, collaboration, and high performance.
  • Benefits: Enjoy flexible working, competitive benefits, and a supportive environment for growth.
  • Other info: Hybrid work model with opportunities for professional development and career advancement.
  • Why this job: Make a real impact in cybersecurity while working with innovative teams across the globe.
  • Qualifications: 3+ years in cyber security with strong communication and technical skills.

The predicted salary is between 63000 - 77000 £ per year.

About Withers

A law firm focused on people, performance, and collaboration.

For the past 130 years, we have supported some of the world's most remarkable people and organizations at defining moments in their lives. 40% of our business comes from Europe, 40% from the US and 20% from Asia and we are one profit sharing partnership globally.

We are united in our commitment to integrity, quality and collaboration.

We have a culture of high performance and deliver excellent service consistently across the firm.

We provide tailored solutions built on trust and partner with our clients to achieve their goals.

Many of our clients are shaping the future and creating solutions to tackle some of the world's most difficult problems. It makes for a fascinating and challenging practice.

Our role is to get to know each individual client, find out where they want to be, and help them to get there – whether they are building a business, buying a home or protecting and defending their interests.

To meet their unique needs we are exceptionally collaborative, working together across teams and time zones.

And we are agile – focusing on strategy rather than rigid ideas and traditional hierarchy.

Join us to be part of a team that is always looking to the future. Where initiative, big ideas and bold moves are always encouraged. Where you can truly be yourself.

What are we looking for?

We are looking for an experienced IT Security Analyst to support security operations across the firm's global technology estate.

The successful candidate should have practical experience working with modern enterprise security platforms covering endpoint detection and response, extended detection and response, cloud security, threat monitoring, behavioural analytics and vulnerability management, and be comfortable engaging with IT teams, senior stakeholders and third-party vendors.

Experience in a medium to large, multi-site professional services environment is desirable.

Strong written and verbal communication skills are essential, including the ability to explain technical security matters clearly to legal, business and IT stakeholders.

The role requires good judgement, personal organization, professionalism and the ability to prioritise effectively under pressure.

A pragmatic, service-focused approach is essential.

  • Areas of focus and responsibilities
  • Monitor, triage and investigate security alerts across the firm's security monitoring and response platforms, including suspicious activity, root cause analysis and proportionate remediation.
  • Support incident response activities, including containment, eradication, recovery, evidence preservation and clear documentation of findings and actions.
  • Maintain and improve security monitoring, detection rules, alert workflows, operational playbooks, procedures and management reporting.
  • Assist with vulnerability management, supplier and client due diligence returns, audit responses, evidence gathering and compliance monitoring against policies, standards and regulatory or client requirements.
  • Provide practical, risk-based security advice for change advisory matters, projects, cloud services, new technologies and internal security queries.
  • Support disaster recovery, business continuity and resilience testing
  • Work with colleagues across all offices to support a consistent global approach to security operations, incident response and alignment with the firm's security standards and risk appetite.
  • Maintain current knowledge of supported technologies, emerging cyber threats and security best practice.

This list of duties and responsibilities is not exhaustive.

It is intended to describe the general content of, and requirements for the performance of this job, and as such, the role may also include the undertaking of additional tasks as required.

Skills and attributes

  • 3+ years' experience in cyber security, security operations, incident response or a related technology role, ideally within a medium to large professional services environment.
  • Practical experience of security monitoring, alert triage, threat detection, incident response, business email compromise, suspicious user activity and vulnerability management.
  • Hands-on experience with modern security operations tooling, including SIEM/XDR, endpoint protection, cloud security, email security, data loss prevention, information protection, behavioural analytics and vulnerability management platforms
  • Good understanding of identity, access and cloud security, including Entra ID, MFA, Conditional Access, privileged access, Saa S logging, endpoint telemetry, evidence preservation and audit trails.
  • Awareness of common attack techniques and frameworks, including MITRE ATT&CK, and relevant security, privacy and assurance frameworks such as ISO 27001, NIST CSF, Cyber Essentials and GDPR.
  • Ability to manage security findings through to remediation, including prioritisation, risk acceptance, progress tracking and clear incident, risk and management reporting.
  • Most important is a desire to learn, develop and help keep the firm secure, resilient and trusted by its clients.
  • The Essentials
  • 9.30am to 5.30pm with reasonable out-of-hours flexibility required for urgent security incidents, investigations and response activities as part of the security team
  • Hybrid working policy with a minimum of 2 days per week worked in the office
  • 12 week probation period
  • 4 week notice period
  • Flexible benefits package including pension, private medical, season ticket loan, subsidised gym memberships, lifestyle discount scheme, on site café.
  • Information for Recruitment Agencies

Withers endeavours to recruit and fill vacancies directly.

However, when we do need to engage with agencies, Withers operates a preferred supplier list and will not be accepting unsolicited applications from non-PSL agencies for this role.

Equal Opportunities Employment Statement

It is the policy of Withers to provide equal opportunities for all employees in relation to recruitment, training and promotion.

Decisions in these areas will be made only by reference to the requirements of the job and shall not be influenced by any consideration of age, disability, gender reassignment, marriage or civil partnership, pregnancy or maternity, race including colour, nationality and ethnic and national origin, religion or belief, sex or sexual orientation.

#J-18808-Ljbffr

IT Security Analyst employer: Withersworldwide

Withersworldwide is an exceptional employer located in the vibrant city of London, offering a dynamic work culture that values detail-oriented professionals. Employees benefit from comprehensive training and development opportunities, fostering personal and professional growth while working alongside experienced partners in a supportive environment. The company's commitment to work-life balance, along with its focus on compliance and client satisfaction, makes it a rewarding place for those seeking meaningful employment in the finance and risk sector.

Withersworldwide

Contact Details:

Withersworldwide Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land IT Security Analyst

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Withersworldwide, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Withersworldwide

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Withersworldwide. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace IT Security Analyst

Cyber Security
Security Operations
Incident Response
Threat Detection
Vulnerability Management
SIEM/XDR
Endpoint Protection

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Withersworldwide insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Withersworldwide that you’re committed to staying ahead in the game.

How to prepare for a job interview at Withersworldwide

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Withersworldwide to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Withersworldwide.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.