Lead Information Security Analyst
Role details
Job location
Tech stack
Job description
We're looking for an experienced and passionate Lead Information Security Analyst to help safeguard our people, systems and operations.
This is more than a technical security role. It's an opportunity to lead cyber resilience across a critical national infrastructure organisation, shaping security strategy, influencing stakeholders at every level and protecting the services that our customers depend on every day.
Why this role matters
As our Lead Information Security Analyst, you'll play a pivotal role in strengthening EMR's cyber security capability. You'll lead security operations, manage incident response activities, develop security controls and drive a security-first culture across the business.
From threat hunting and vulnerability management to advising senior leaders on emerging risks, you'll be at the forefront of protecting our organisation from cyber threats while enabling innovation and business change.
What you'll be doing
- Leading and developing a team of Information Security Analysts
- Managing and optimising key security technologies including SIEM, XDR, anti-virus, email security and vulnerability management platforms
- Driving proactive threat hunting and threat intelligence activities
- Leading cyber incident response and working closely with Security Operations Centre partners
- Identifying, assessing and helping mitigate information security risks across the organisation
- Supporting security governance through ISO27001-aligned controls, policies and procedures
- Providing expert security advice on new technologies, projects and operational systems
- Supporting operational technology (OT) cyber security initiatives across our fleet and wider railway environment
- Promoting a positive security culture and increasing cyber awareness throughout EMR
- Producing insightful reporting, KPIs and trend analysis to inform decision-making at all levels
Requirements
Do you have experience in Information security?, You'll be an experienced cyber security professional who combines strong technical expertise with the ability to influence and engage stakeholders across the business., * Significant experience in a senior Information Security or Cyber Security role
- Strong knowledge of security operations, risk management and security governance
- Experience working with ISO27001 controls, policies and frameworks
- Hands-on experience with enterprise security technologies and security monitoring platforms
- Excellent analytical and problem-solving skills
- Strong communication skills with the ability to explain complex security concepts to both technical and non-technical audiences
- A proactive, organised and customer-focused approach
Professional certifications such as ISC2 CISSP and ISACA CISM are highly desirable.
Benefits & conditions
Pulled from the full job description
- Free or subsidised travel
- Annual leave
- Employee discount
- Company pension, * Competitive salary
- Defined Benefit Pension Scheme
- Free standard leisure travel on EMR, Transport UK and LNER services
- Friends and Family discounted travel on the EMR network
- 75% discount on national leisure rail travel for you, your partner and dependants
- Up to 32 days annual leave
- Ongoing professional development opportunities
- The chance to make a real impact within a critical public service organisation
Diversity & Inclusion
At EMR, we are committed to building a workforce that reflects the communities we serve.