> Markdown version of [/jobs/ext/3288401-security-analyst](https://www.wearedevelopers.com/jobs/ext/3288401-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst - **Company:** AXA UK plc - **Location:** Bristol, UK - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Proxy Servers, Server Applications, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Software Vulnerability Management, Web Applications, Google Cloud, Cloud Platform System, Software Security, Mitre Att&ck, Firewalls (Computer Science), Information Technology - **Published:** September 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2a3f1308622b860e ## About the Role * Prior hands-on technical penetration testing experience (internal, external, web application, cloud) * A deep understanding of IT systems and vulnerabilities, ideally spanning cloud environments (AWS, Azure, GCP), infrastructure components such as web and application servers, firewalls, proxies and operating systems and application code security. * Experience in cloud security engineering, architecture or general IT infrastructure is advantageous. * Strong analytical and problem-solving skills, with the ability to dig into technical detail. * Confidence to challenge ambiguity and ask the right questions. * A genuine curiosity about how systems can be broken - and how to make them more resilient. * Comfortable working with industry frameworks, including threat behaviour modelling e.g. MITRE ATT&CK, Vulnerability management e.g. CVSS, Penetration testing standards e.g. CREST, CBEST, TIGER and Security frameworks e.g. NIST, ISO 27001/27002. * OSCP or equivalent practical penetration testing certification or an MSc in Cyber Security or Information Technology is desirable but not essential. ## Description * Reviewing threat intelligence feeds and penetration test findings to identify and prioritise use cases for Breach and Attack Simulation (BAS), ensuring our testing reflects the real-world threat landscape. * Supporting penetration testing engagements by validating that scope is appropriate and that reports meet AXA's standards, giving you a front-row seat to a wide variety of technical assessments. * Reviewing remediation plans arising from penetration testing activity, ensuring that proposed fixes will genuinely address identified issues within acceptable timeframes - and then verify that they do, using BAS tooling. * Reacting to BAS control test failures, investigating root causes, and raising targeted remediation requests with the right technical teams. * Producing clear, meaningful metrics and reports for executive steering groups, translating complex technical findings into actionable insight for senior audiences. * Constantly looking for opportunities to sharpen, simplify, and scale our processes - your ideas will be welcomed and acted upon. Work arrangements: At AXA we work smart, empowering our people to balance their time between home and the office in a way that works best for them, their team and our customers. You'll work at least two days a week (40%) away from home, moving to three days a week (60%) from December 2026. Away from home means attending the office, visiting clients or attending industry events. We're also happy to consider flexible working arrangements, which you can discuss with Talent Acquisition. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Exploring the Power of gRPC-Gateway for Writing RESTful Services](https://www.wearedevelopers.com/videos/2072-exploring-the-power-of-grpc-gateway-for-writing-restful-services) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)