Senior Cyber Security Analyst
Role details
Job location
Tech stack
Job description
We are seeking a dynamic, hands-on Senior Cybersecurity Analyst to monitor cyber risk and lead the remediation of identified vulnerabilities across Lightsource bp's IT systems globally. You will be responsible for threat detection, investigation, and incident response, leveraging a modern security technology stack with a strong focus on the Microsoft Defender ecosystem. Working across multiple business areas and time zones, you will proactively hunt for security issues, assess emerging threats, and partner with infrastructure and support teams to strengthen our security posture and drive business cyber maturity., * Continuously monitor the organization's security systems and infrastructure using SIEM, EDR, and related toolsets to detect signs of compromise and investigate security events to completion
- Proactively conduct threat hunting using threat intelligence frameworks (MITRE ATT&CK, Cyber Kill Chain) and available security platforms to identify and mitigate emerging threats
- Assess new and evolving cyber threats to the business, optimizing existing Microsoft Defender technologies and other security solutions to better counter identified risks
- Identify vulnerabilities in systems and applications; collaborate with Infrastructure, Digital Workplace, and Support teams to prioritize, patch, and remediate issues in a timely manner
- Manage core Security Operations (SecOps) tooling platforms, ensuring correct configuration, maximizing security value from existing investments, and maintaining high-quality configuration documentation
- Communicate proactively with stakeholders across the business, providing clear technical and non-technical updates during investigations and escalations
- Support the development, enforcement, and continuous improvement of cloud security policies, standards, and procedures in alignment with industry frameworks (NIST 2.0, CIS, NIS2) and regulations
- Create and maintain security awareness training content and assist in its delivery to colleagues across the organization, * This is a global role supporting an expanding, geographically dispersed workforce and technology stack
- You will interface regularly with multiple business areas across different time zones
- You will work within a small, talented cybersecurity team and collaborate with a global IT organization
- The role requires engagement with the convergence of IT and Operational Technology (OT) security, reflecting the evolving landscape of energy infrastructure protection
- International regulatory compliance knowledge will be increasingly important as the organization scales across multiple jurisdiction
Why you'll want to work for us
Our company is a place where you can be yourself and grow, a place where your ideas and opinions matter.
Be you: We pride ourselves on being an inclusive community, where every individual is valued and treated with respect.
Be responsible: Our culture is driven by our core values - from operating safely to ensuring our projects are responsible.
Requirements
- 5+ years of professional experience in cybersecurity, with at least 2+ years in a Security Operations Center (SOC) or incident response role
- Advanced proficiency with Microsoft Defender XDR and expert-level knowledge of Microsoft Sentinel, including KQL query writing and analytics rule development
- Strong hands-on experience with Microsoft Defender for Endpoint, including policy configuration and threat investigation
- Demonstrable experience responding to cyber threats and working in an Azure-focused cloud environment
- Proven experience with the Cyber Kill Chain, MITRE ATT&CK, and other security defence and intelligence frameworks
- Experience in stakeholder management and engagement at C-Suite level
- Experience working for Critical National Infrastructure (CNI) organizations is desirable
Knowledge:
- Microsoft Security Stack: Defender XDR/Sentinel, Defender for Cloud, Defender for Cloud Apps, Defender EASM, Copilot for Security
- Vulnerability Management: Defender XDR, Tenable IO/Nessus, Defender EASM
- Data Governance & IDAM: Microsoft Purview (DLP and information governance), Entra ID, Conditional Access Policies
- Device Management: Working understanding of Intune (MDM/MAM)
- Networking/Firewalls: Exposure to Cisco Meraki and Fortinet FortiGate (desirable)
- Regulatory & Compliance Frameworks: NIST 2.0 Cyber Security Framework (required); NIS2, NERC CIP, SOC2, and IEC 62443 OT standards (desirable)
- ITIL Principles: Good understanding of ITIL principles and their application to IT service management
- Information Security Technologies: Firewalls, intrusion detection systems, vulnerability assessment tools, logging solutions, gateway and endpoint security products, and authentication mechanisms
- Operational Technology (OT) Cyber Security: Desirable but not required, * Advanced threat detection, investigation, and incident response capabilities
- Strong technical troubleshooting and problem-solving skills with ability to work across complex, global technology environments
- Expert-level proficiency with Microsoft security tools and cloud-based security architectures
- Excellent communication skills: ability to translate complex technical concepts for both technical and non-technical audiences
- Proactive mindset with genuine enthusiasm for cybersecurity and drive to improve security posture
- Ability to remain calm under pressure and manage multiple incidents and priorities
- Cross-functional collaboration: ability to partner effectively with Infrastructure, Digital Workplace, Support, and business teams worldwide
- Strong documentation and reporting skills for both technical and executive audiences
- Subject matter expertise with proven ability to identify and champion security improvement opportunities
Education Required
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field
- Industry-recognized certification (one or more of the following):
- Azure Security Engineer (AZ-500)
- Certified Information Systems Security Professional (CISSP)
- Certified Cyber Professional (CCP)
- CompTIA Security+ GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
Benefits & conditions
Be recognized: Alongside a competitive salary, we offer a variety of benefits including annual bonus, retention bank, health insurance, pension and other local benefits.