GENERAL JOB DESCRIPTION
The Security Analyst is responsible for supporting day-to-day operations and continuous improvement of the cybersecurity programme. This role acts as a trusted partner to technology, product and operations teams to ensure that cybersecurity risks are identified, assessed and managed throughout the development lifecycle and business operations. This position requires solid technical expertise and a strong understanding of information security principles, with hands-on experience in security tools and frameworks.
DUTIES & RESPONSIBILITIES
- Maintain the information security policies, standards, risk registers and KRIs.
- Conduct cybersecurity risk assessments for new technologies, projects and third-party services, and support risk treatment activities.
- Support implementation and enforcement of security policies and procedures.
- Support security reviews throughout the software development lifecycle, including the review of technology designs, security requirements and application security assessments.
- Support security assurance activities, including vulnerability assessments, penetration testing and control effectiveness reviews.
- Manage vulnerability management activities, such as scanning, prioritisation, tracking, reporting and validation of security findings.
- Monitor and investigate security alerts, events and incidents in coordination with MSSP/MDR partners, and support incident response and recovery activities.
- Liaise with internal stakeholders to support regulatory compliance and audit activities.
- Provide up-to-date cybersecurity awareness, training and guidance to the organisation to promote secure-by-design practices and strengthen the overall cybersecurity posture.
EDUCATION & TRAINING
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field
- Three to five years of experience in cybersecurity, with strong GRC foundation and exposure to cloud and application security preferred
- Experience in the financial industry is strongly preferred
- Strong communication and interpersonal skills
- Ability to work independently and as part of a team
- Strong analytical and problem-solving skills
- Individuals who enjoy being hands-on, have a growth mindset and thrive in a fast-paced environment are preferred
- Familiarity with cybersecurity frameworks and standards such as ISO 27001, NIST, CIS, and PCI-DSS
- Security certifications such as CISM, CEH, or other relevant certifications are preferred