> Markdown version of [/jobs/ext/346661-lead-it-security-analyst](https://www.wearedevelopers.com/jobs/ext/346661-lead-it-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead IT Security Analyst - **Company:** Culina - **Location:** Magna Park, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Identity and Access Management, Network Security, Security Information and Event Management, Technical Data Management Systems, Software Vulnerability Management, System Availability, Firewalls (Computer Science), CIS Benchmarks, Cyber Warfare, Vulnerability Analysis - **Published:** June 17, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=12dc5c03226e6f15 ## About the Role Do you have experience in SIEM?, * Strong technical expertise across cyber security operations, infrastructure, and threat management, with the ability to respond effectively to complex incidents. * Ability to lead and coordinate incident response and investigations, ensuring swift resolution and minimal business impact. * Proven capability to translate technical risks into practical solutions that balance security and operational needs. * Strong analytical mindset with the ability to identify vulnerabilities, assess threats, and prioritise actions effectively. * Skilled in communicating complex technical information clearly to both technical and non-technical stakeholders. * Ability to influence and collaborate across teams, acting as a trusted security advisor. * Demonstrated experience in mentoring and supporting junior team members, building overall team capability. * Proactive approach to continuous improvement, driving enhancements in tooling, processes, and controls. * Strong focus on security-by-design, ensuring robust security practices are embedded into all technology changes. * Resilient and adaptable, with the ability to operate effectively in a fast-paced, evolving threat landscape., * 3-5+ years' experience in IT security, cyber operations, SOC analysis, or similar technical security roles. * Strong understanding of core cyber security principles, including network security, cloud security, and infrastructure hardening. * Hands-on experience with key security technologies, including SIEM, EDR, firewalls, Identity & Access Management (IAM), and vulnerability scanning tools. * Proven experience in responding to cyber security incidents, including investigation, analysis, and remediation. * Familiarity with recognised security frameworks and standards such as ISO 27001, NIST Cybersecurity Framework (CSF), and CIS Controls. * Strong analytical, problem-solving, and troubleshooting skills, with the ability to interpret complex technical data. Desirable * Relevant industry certifications such as Security+, CySA+, AZ-500, CCNA Security, CEH, or equivalent. * Broader exposure to enterprise IT environment, including cloud platforms and hybrid infrastructures. * Experience working within structured security operations or SOC environments. ## Description The Lead IT Security Analyst is a senior technical specialist responsible for strengthening the organisation's cyber security across security operations, infrastructure protection, vulnerability management, and incident response. Reporting to the Head of IT Security, this role plays a critical part in ensuring the confidentiality, integrity, and availability of systems and data. Acting as a senior escalation point, the role provides technical leadership, drives continuous improvement, and ensures security is embedded into all technology change and transformation activities., Technical Security Operations * Act as the senior escalation point for security events across SIEM, EDR, firewalls, and network security tools. * Lead cyber incident response activities, including triage, containment, investigation, and root cause analysis. * Oversee day-to-day security operations and threat detection capabilities across the IT estate. * Ensure the effective configuration, tuning, and maturity of SOC/SIEM tooling and alerting. * Collaborate with managed security service providers to ensure high-quality and timely service delivery. Vulnerability & Threat Management * Lead the vulnerability management programme across infrastructure, cloud, and applications. * Coordinate remediation activities with IT and operational teams to reduce risk exposure. * Analyse threat intelligence to identify emerging threats and vulnerabilities. * Provide clear recommendations on prioritisation and implementation of security controls. Technical Design, Assurance & Architecture * Conduct security assessments of new solutions, infrastructure changes, and cloud deployment. * Support secure architecture reviews alongside IT architects and solution designers. * Ensure secure configuration standards (e.g. CIS Hardening) are implemented and maintained. * Review and strengthen access controls, identity management, and privileged access processes. Security Tooling & Control Maturity * Maintain and enhance core security technologies (SIEM, EDR, IAM, DLP, email security, vulnerability scanning, etc.). * Support the lifecycle management of security tools and platforms. * Evaluate and recommend new technologies to improve security capability and resilience. Continuous Improvement & Technical Leadership * Identify opportunities to strengthen technical controls and enhance overall security maturity. * Mentor and support the development of junior Security Analysts. * Contribute to the IT security roadmap and continuous improvement initiatives. Stakeholder Engagement * Act as a trusted technical advisor to infrastructure, cloud, networking, and service teams. * Provide regular updates, insights, and escalation support to the Head of IT Security. * Represent IT Security across projects, ensuring security-by-design principles are embedded. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)