Cyber Security Analyst

Portfolio Group Ltd
Manchester, UK
2 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
£45,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Amazon Web Services Apple Mac Systems ARM Architecture Microsoft Azure Cloud Computing Cyber Security Information Leak Prevention Data Loss Data Security DevOps Microsoft Office
+16 more
Network Intrusion Detection Systems Phishing Security Information and Event Management Cloud Platform System Data Classification Office365 Malware Microsoft InTune Cybercrime Nessus Microsoft Sentinel Cortex XSOAR Platform Casper Suite Splunk Blue Team (Cyber Security) Vulnerability Analysis

Job description

  • We deliver the day-to-day security operations of the InfoSec team and act as a first point of escalation and support for Junior and Graduate analysts.
  • We manage day-to-day security tickets, requests, and alerts through Halo ITSM, meeting SLAs and making full use of existing automation.
  • We monitor, triage, and investigate alerts within Palo Alto Cortex XSIAM, responding and escalating as required.
  • We respond to security incidents involving malware, data loss, phishing, or network intrusion, following established playbooks and incident response processes.
  • We manage email security operations across Mimecast and Abnormal, including releases, journal pulls, and reported-phishing investigations.
  • We monitor threat feeds and threat intelligence, applying relevant findings to the environment.
  • We maintain and tune detections, correlation rules, and Cortex XSOAR playbooks to reduce noise and improve response times.
  • We identify opportunities for automation and continual improvement across monitoring and response workflows.
  • We contribute to the development and upkeep of SOC processes, runbooks, and documentation.
  • We run and interpret vulnerability scans using Nessus, tracking remediation through to closure with the relevant teams.
  • We support endpoint security and patch compliance across the Windows and macOS estates, working with Intune, Jamf, Alectrona, and Cortex XDR.
  • We support and monitor the companys Data Loss Prevention controls within Microsoft Purview, and data classification through Azure Information Protection labelling.
  • We help maintain the evidence and controls that support the companys accreditations, including ISO/IEC 27001, 27017, and 27018, Cyber Essentials Plus, and SOC 2.
  • We learn and apply the principles of risk and information governance within the context of cyber security.
  • We work collaboratively with the wider IT team and business stakeholders to provide security and governance for existing and new services.
  • We communicate complex security concepts clearly to technical and non-technical audiences.
  • We support our colleagues across all regions and serve as a trusted resource on information and cyber security matters.

Technologies:

  • AWS
  • Azure
  • Cloud
  • ICT
  • Support
  • ITIL
  • ITSM
  • macOS
  • Microsoft 365
  • Network
  • Security
  • Splunk
  • Windows
  • Office 365
  • DevOps

Requirements

  • We have at least 2 years experience in a cyber security, SOC, or information security analyst role.
  • We have experience working within an ISO/IEC 27001 or equivalent accredited environment.
  • We are familiar with ITIL service management processes, particularly Incident, Request, Change, and Problem management.
  • We understand GDPR, data protection, and information governance.
  • We have hands-on experience with a SIEM platform such as Cortex XSIAM, Microsoft Sentinel, Splunk, or equivalent.
  • We have experience with, or a strong aptitude to learn, SOAR and automation tooling such as Cortex XSOAR.
  • We have experience with Endpoint Detection and Response tools such as Cortex XDR or an equivalent EDR/XDR platform.
  • We have experience with email security platforms such as O365, Mimecast, Abnormal, or equivalent.
  • We understand Data Loss Prevention and data classification, such as Microsoft Purview and Azure labelling, or equivalent.
  • We have experience with vulnerability scanning and management such as Nessus or equivalent.
  • We have working knowledge of endpoint management across Windows and macOS, including Intune and Jamf.
  • We have strong knowledge of cloud environments, including Microsoft Azure, AWS, and Microsoft 365.
  • We understand layered security, threat hunting, and incident response.
  • We hold a degree in a computer-related subject, or we have equivalent experience in cyber security.
  • We hold, or are actively working towards, relevant industry certifications such as SANS GCIH, EC-Council CEH, ISC2 SSCP, CompTIA CySA+, Blue Team Level 1, or Microsoft SC-200, and we are committed to continued professional development.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all