> Markdown version of [/jobs/ext/1326718-senior-cyber-security-analyst](https://www.wearedevelopers.com/jobs/ext/1326718-senior-cyber-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Security Analyst - **Company:** Lightsource BP - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Data Analysis, Authentication Protocols, Microsoft Azure, Cloud Computing, Cloud Computing Security, Configuration Management, CompTIA Security+, Cyber Security, Data Governance, Database Queries, Intrusion Detection and Prevention, Intrusion Detection Systems, Information Systems Security Architecture Professional, Microsoft Security Essentials, Kusto Query Language, Security Information and Event Management, Software Vulnerability Management, Mitre Att&ck, Firewalls (Computer Science), Microsoft InTune, Azure Security Center, Information Technology, Cybercrime, Nessus, Microsoft Sentinel, Operational Systems, Fortinet, Service Stack, Vulnerability Analysis - **Published:** July 18, 2026 - **Apply:** https://dejobs.org/x/x/054F2704367B4B00B8737946849FFC55/job/ ## About the Role * 5+ years of professional experience in cybersecurity, with at least 2+ years in a Security Operations Center (SOC) or incident response role * Advanced proficiency with Microsoft Defender XDR and expert-level knowledge of Microsoft Sentinel, including KQL query writing and analytics rule development * Strong hands-on experience with Microsoft Defender for Endpoint, including policy configuration and threat investigation * Demonstrable experience responding to cyber threats and working in an Azure-focused cloud environment * Proven experience with the Cyber Kill Chain, MITRE ATT&CK, and other security defence and intelligence frameworks * Experience in stakeholder management and engagement at C-Suite level * Experience working for Critical National Infrastructure (CNI) organizations is desirable Knowledge: * Microsoft Security Stack: Defender XDR/Sentinel, Defender for Cloud, Defender for Cloud Apps, Defender EASM, Copilot for Security * Vulnerability Management: Defender XDR, Tenable IO/Nessus, Defender EASM * Data Governance & IDAM: Microsoft Purview (DLP and information governance), Entra ID, Conditional Access Policies * Device Management: Working understanding of Intune (MDM/MAM) * Networking/Firewalls: Exposure to Cisco Meraki and Fortinet FortiGate (desirable) * Regulatory & Compliance Frameworks: NIST 2.0 Cyber Security Framework (required); NIS2, NERC CIP, SOC2, and IEC 62443 OT standards (desirable) * ITIL Principles: Good understanding of ITIL principles and their application to IT service management * Information Security Technologies: Firewalls, intrusion detection systems, vulnerability assessment tools, logging solutions, gateway and endpoint security products, and authentication mechanisms * Operational Technology (OT) Cyber Security: Desirable but not required, * Advanced threat detection, investigation, and incident response capabilities * Strong technical troubleshooting and problem-solving skills with ability to work across complex, global technology environments * Expert-level proficiency with Microsoft security tools and cloud-based security architectures * Excellent communication skills: ability to translate complex technical concepts for both technical and non-technical audiences * Proactive mindset with genuine enthusiasm for cybersecurity and drive to improve security posture * Ability to remain calm under pressure and manage multiple incidents and priorities * Cross-functional collaboration: ability to partner effectively with Infrastructure, Digital Workplace, Support, and business teams worldwide * Strong documentation and reporting skills for both technical and executive audiences * Subject matter expertise with proven ability to identify and champion security improvement opportunities Education Required * Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field * Industry-recognized certification (one or more of the following): * Azure Security Engineer (AZ-500) * Certified Information Systems Security Professional (CISSP) * Certified Cyber Professional (CCP) * CompTIA Security+ GIAC Certified Incident Handler (GCIH) * GIAC Certified Intrusion Analyst (GCIA) ## Description We are seeking a dynamic, hands-on Senior Cybersecurity Analyst to monitor cyber risk and lead the remediation of identified vulnerabilities across Lightsource bp's IT systems globally. You will be responsible for threat detection, investigation, and incident response, leveraging a modern security technology stack with a strong focus on the Microsoft Defender ecosystem. Working across multiple business areas and time zones, you will proactively hunt for security issues, assess emerging threats, and partner with infrastructure and support teams to strengthen our security posture and drive business cyber maturity., * Continuously monitor the organization's security systems and infrastructure using SIEM, EDR, and related toolsets to detect signs of compromise and investigate security events to completion * Proactively conduct threat hunting using threat intelligence frameworks (MITRE ATT&CK, Cyber Kill Chain) and available security platforms to identify and mitigate emerging threats * Assess new and evolving cyber threats to the business, optimizing existing Microsoft Defender technologies and other security solutions to better counter identified risks * Identify vulnerabilities in systems and applications; collaborate with Infrastructure, Digital Workplace, and Support teams to prioritize, patch, and remediate issues in a timely manner * Manage core Security Operations (SecOps) tooling platforms, ensuring correct configuration, maximizing security value from existing investments, and maintaining high-quality configuration documentation * Communicate proactively with stakeholders across the business, providing clear technical and non-technical updates during investigations and escalations * Support the development, enforcement, and continuous improvement of cloud security policies, standards, and procedures in alignment with industry frameworks (NIST 2.0, CIS, NIS2) and regulations * Create and maintain security awareness training content and assist in its delivery to colleagues across the organization, * This is a global role supporting an expanding, geographically dispersed workforce and technology stack * You will interface regularly with multiple business areas across different time zones * You will work within a small, talented cybersecurity team and collaborate with a global IT organization * The role requires engagement with the convergence of IT and Operational Technology (OT) security, reflecting the evolving landscape of energy infrastructure protection * International regulatory compliance knowledge will be increasingly important as the organization scales across multiple jurisdiction Why you'll want to work for us Our company is a place where you can be yourself and grow, a place where your ideas and opinions matter. Be you: We pride ourselves on being an inclusive community, where every individual is valued and treated with respect. Be responsible: Our culture is driven by our core values - from operating safely to ensuring our projects are responsible. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [WeAreDevelopers LIVE - Back to CODE100](https://www.wearedevelopers.com/videos/1909-wearedevelopers-live-back-to-code100) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)