> Markdown version of [/jobs/ext/3284257-information-cyber-security-specialist-cloned-on-22-09-26-12-05-14](https://www.wearedevelopers.com/jobs/ext/3284257-information-cyber-security-specialist-cloned-on-22-09-26-12-05-14). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information & Cyber Security Specialist cloned on 22-09-26 12:05:14 - **Company:** William Grant and Sons Ltd - **Location:** Cumbernauld, UK (Remote available) - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Data Analysis, Microsoft Antivirus, Cloud Computing Security, Cyber Security, Digital Forensics, Information Technology Operations, Intrusion Detection and Prevention, Microsoft Security Essentials, Azure Active Directory, Security Information and Event Management, Software Vulnerability Management, Cybercrime, Microsoft Sentinel, Security Orchestration, Automation & Response - **Published:** September 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=23fd66882fa355c6 ## About the Role You will have strong hands-on cyber security experience and be comfortable taking an investigation or improvement activity from initial identification through to a clear outcome. You should be able to demonstrate experience in several of the following areas: * Security incident investigation and response. * SIEM or XDR investigation. * Detection engineering and alert tuning. [CH1] * Vulnerability management. * Endpoint, identity, email, network or cloud security. * Analysing and correlating security telemetry. * Incident-response procedures and playbooks. * Security automation, orchestration or scripting. [CH2] * Working with a managed SOC, MDR or other external security partners. * Translating technical findings into clear risks, decisions and actions. You will also need: * Strong analytical and investigative judgement. * The ability to work independently and take ownership of assigned outcomes. * A practical, delivery-focused approach and willingness to get involved. * Clear written and verbal communication. * Willingness to contribute outside your primary specialism when wider Cyber Security priorities require it. * The existing right to work in the United Kingdom. DESIRABLE EXPERIENCE Experience in any of the following would be advantageous, but is not essential: * Taegis XDR or MDR. * Sophos security technologies. * Microsoft Defender. * Microsoft Entra and Conditional Access. * Microsoft Security Copilot. * Microsoft Sentinel. * Threat hunting. * Digital forensics and evidence handling. * Security Architecture or design assurance. ## Description Reporting into the Information & Cyber Security Leader, you will work hands-on with security technologies, investigations and improvement activity, while collaborating with colleagues across Cyber Security, Architecture, IT Operations, business teams and our external security providers. This is not a line management role. However, you will have the autonomy to shape assigned capabilities, improve how services operate, share your expertise and support the development of colleagues., * Support the coordination of containment, eradication, and remediation activity, ensuring actions are understood, appropriately prioritised and completed. * Develop, test and tune security detections, improve alert quality and help maintain visibility of detection coverage against relevant threats and attacker techniques. * Take ownership of assigned security operations capabilities, identifying weaknesses, proposing improvements and seeing agreed work through to completion. * Operate vulnerability management processes, including scanning, validation, threat-informed prioritisation, remediation coordination, exception escalation and closure assurance. * Work with IT Operations, system owners and suppliers to ensure material vulnerabilities and security weaknesses are addressed within agreed timescales. * Develop automation and orchestration that improve investigation, enrichment, triage, evidence collection, reporting and response workflows. * Explore and implement appropriate uses of Microsoft Security Copilot, AI and SOAR technologies, ensuring automated activity remains controlled, auditable and subject to appropriate human review. * Support the operation and improvement of Microsoft Defender, Microsoft Entra, Conditional Access, endpoint security, identity controls and other assigned security technologies. * Create and maintain clear runbooks, technical procedures, investigation records, service documentation and operational evidence. * Share knowledge with colleagues and provide practical coaching and quality support to the Information & Cyber Security Analyst. * Contribute to wider information security, cyber risk, assurance, third-party security, governance and compliance activities as team priorities require. * Participate in the Cyber Security on-call rota and support the response to significant out of hours cyber incidents., Our Information Security and Security Operations teams have recently come together as one Cyber Security function. We are developing an integrated operating model covering governance, risk, protection, detection, incident response, resilience, automation and continuous improvement. Each team member will have areas of expertise and ownership, but cross-skilling and collaboration are fundamental to how the team will operate. You will be encouraged to bring ideas, challenge existing ways of working and put your own stamp on the capabilities assigned to you. You must be willing to support colleagues, share knowledge and help get priority security work over the line as the new function develops. WORKING ARRANGEMENTS The role is based in Arete, Cumbernauld (G88 0HH) with an expected working pattern of four days on site and one day working from home. Occasional travel to other WG&S sites will be required. The successful candidate will participate in an out-of-hours call rota.