Cyber Security Ops Analyst
Posted 4 hours 1 minute ago by E-Frontiers
Job Specification
Job Title
Cyber Security Operations Analyst
Role PurposeThe Cyber Security Operations Analyst is a hands-on operational role responsible for the day-to-day monitoring, operation, and effectiveness of technical security controls across the organisation's ICT environment.
The role is focused on security monitoring, alert management, incident response, endpoint and platform security, vulnerability and patch management, and user security awareness. The successful candidate will ensure that security controls are operating effectively, security events are detected and triaged promptly, and incidents are responded to in accordance with established procedures.
While the primary focus is operational security, the role also supports Governance, Risk and Compliance (GRC) activities, including audits, security assessments, policy implementation, and compliance initiatives. The Cyber Security Operations Analyst will work collaboratively with ICT teams, third-party providers, and business stakeholders to strengthen the organisation's overall cyber resilience.
Key Responsibilities1. Security Operations & Monitoring
- Monitor and operate security technologies including SIEM, EDR/XDR, antivirus, email security, and cloud security platforms.
- Investigate, triage, and respond to security alerts, escalating confirmed incidents in accordance with incident response procedures.
- Support containment, remediation, and recovery activities during security incidents.
- Maintain accurate incident documentation, timelines, and evidential records.
- Participate in post-incident reviews and contribute to continuous improvement of security operations.
2. Vulnerability, Patch & Asset Management
- Support vulnerability scanning across infrastructure, cloud platforms, applications, and endpoints.
- Maintain accurate visibility of ICT assets and ensure systems are appropriately onboarded for vulnerability assessment.
- Review, prioritise, and track vulnerability findings while coordinating remediation with ICT teams and external suppliers.
- Validate remediation activities through rescanning and verification.
- Escalate overdue or critical vulnerabilities in accordance with agreed service levels.
- Monitor patch compliance and identify systems requiring remediation.
3. Endpoint, Platform & Security Control Management
- Support the deployment, configuration, and ongoing health of endpoint protection technologies, including EDR/XDR and antivirus solutions.
- Perform routine health checks to verify the effectiveness of security controls.
- Assist with the secure onboarding of new and modified systems, ensuring appropriate monitoring, logging, and protection are implemented.
- Identify security control failures, misconfigurations, or operational weaknesses and coordinate remediation activities.
4. Security Assurance, Awareness & Governance Support
- Support the delivery of security awareness programmes, phishing simulations, and user education initiatives.
- Assist with internal and external audits by gathering evidence and validating the effectiveness of security controls.
- Support penetration testing activities, including coordination, remediation tracking, and validation of findings.
- Provide operational cyber security support to ICT teams and business users.
- Provide cross-functional support across Security Operations and Governance, Risk and Compliance (GRC) activities during audits, incidents, and periods of increased operational demand.
Knowledge, Skills & Experience
Essential Experience
- 1-3 years' experience in a cyber security, ICT operations, or IT support role with security responsibilities.
- Practical experience of security operations, including threat detection, incident response, and vulnerability management.
- Experience using security technologies such as:
- SIEM platforms
- EDR/XDR solutions
- Firewalls
- Antivirus solutions
- Vulnerability scanning tools
- Good understanding of networking fundamentals and Windows/Linux operating systems.
- Knowledge of core cyber security principles and best practices.
- Familiarity with recognised security frameworks and standards such as ISO 27001, NIST Cybersecurity Framework, or equivalent.
- Experience working with operational security policies, procedures, and standards.
- Strong analytical, investigative, and troubleshooting skills.
- Ability to prioritise operational security issues in a fast-paced environment.
- Understanding of threat intelligence concepts and their application within security operations.
- Excellent written and verbal communication skills.
- Ability to communicate technical concepts clearly to non-technical stakeholders.
Desirable Experience
- Experience supporting security awareness or phishing simulation platforms.
- Experience within the public sector or other regulated environments.
- Experience working with third-party suppliers or managed security service providers (MSSPs).
Qualifications
Essential
- Relevant third-level qualification in Information Technology, Cyber Security, Computer Science, or a related discipline; or
- Equivalent industry-recognised technical certification.
Desirable Certifications
- CompTIA Security+
- ISO/IEC 27001 Lead Implementer or Lead Auditor
- Microsoft Security (SC) Certifications
- Microsoft Azure (AZ) Certifications
- ISC² certifications (eg SSCP, CISSP)
- ISACA certifications (eg CISA, CISM)
Key Competencies
The successful candidate will demonstrate:
- Strong analytical and problem-solving ability.
- A proactive and methodical approach to cyber security operations.
- Excellent attention to detail and organisational skills.
- The ability to manage competing priorities and respond effectively under pressure.
- Strong collaboration and relationship-building skills.
- A commitment to continuous learning and professional development.
- High standards of integrity, confidentiality, and professionalism.
Working Relationships
The Cyber Security Operations Analyst will work closely with:
- ICT Infrastructure and Service Delivery teams
- Governance, Risk and Compliance (GRC) colleagues
- Third-party security and technology providers
- Business users and stakeholders across the organisation
- Internal and external auditors