> Markdown version of [/jobs/ext/2321290-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/2321290-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** ONYX Insight - **Location:** Nottingham, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Cloud Computing Security, Cyber Security, OnyX for Mac, Software Vulnerability Management, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 11, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=ef21ec32970705e4 ## About the Role * 3-5 years of hands-on experience in an information security operations role * Practical experience operating and maintaining security tooling, including CSPM, SAST, and DAST platforms * Practical experience contributing to internal audits and risk assessments against ISO 27001 or a comparable framework (NIST CSF, SOC 2, Cyber Essentials Plus) * Experience working with external SOC or MDR providers * Strong written communication; able to produce findings reports and risk register entries to a good standard * Able to operate hands-on and independently in a small team Desirable: * Experience in a regulated industry, particularly critical infrastructure, energy, or manufacturing * Familiarity with IEC 62443 or the EU Cyber Resilience Act * Relevant certification: CISSP, CISM, or equivalent; ISO 27001 Lead Auditor working towards or held * Experience with cloud security, particularly AWS ## Description This is a hands-on security operations role. You will be the primary practitioner resource within a small, specialist Cyber Security team of three, including the VP, responsible for day-to-day security monitoring, vulnerability management, incident response, and internal audit activity that keeps our security posture credible and improving. Hands-on delivery is the core expectation; this is not a governance or oversight position. You will work closely with an external SOC and MDR provider, acting as the internal security practitioner against their outputs. The role also requires genuine compliance capability, you will contribute to internal audit and risk assessment cycles and support ISO 27001 compliance activity. You will provide ad-hoc expert input to the IT function where security judgement is needed, but this is not an IT role. ONYX is a critical infrastructure business manufacturing IIoT devices for wind turbine monitoring. We operate globally, with customers and regulatory obligations spanning the EU, UK, US, Australia, Canada, India, and South Korea. Our Cyber Security function is small, expert, and operationally engaged, this role sits at the centre of that. What you will be doing * Operating as the primary hands-on resource for security monitoring, triage, and incident response, working with the external SOC and MDR provider * Operating and maintaining security tooling, including CSPM, SAST, and DAST platforms, ensuring coverage, configuration, and outputs are maintained to a defined standard * Managing the vulnerability management programme, including coordination of internal and external penetration testing * Conducting internal security audits and risk assessments, producing findings reports and tracking remediation * Supporting ISO 27001 compliance activity, including contributing to control evidence and audit cycles Producing clear written outputs - findings reports, risk registers, policy updates * - to a good standard suitable for internal and external audit ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)