We are looking for an experienced Cyber Security Analyst to join our team in Peterborough to help protect Carter Jonas’s systems, data, and information assets. The role combines hands-on security operations with vulnerability management, incident response, cyber risk, governance, assurance and continual improvement of the organisation’s security posture. The post holder will work with IT, Compliance, HR, suppliers and the wider business to monitor threats, manage vulnerabilities, support security assurance and help embed a strong security culture.
Our IT team are primarily based in our Peterborough office and pride themselves on having a friendly and inclusive culture, with plenty of opportunities to get involved in office life, including social events, charity initiatives, volunteering opportunities and team activities throughout the year.
We offer a highly competitive salary and benefits package, including a range of flexible benefits designed to support your individual needs and lifestyle. Benefits include the option to purchase additional annual leave, health cash plans, a cycle-to-work scheme and much more. We are also committed to supporting flexible and agile working arrangements, helping our people achieve a positive work-life balance.
Main tasks:
Monitor security alerts, logs and events across key platforms including SIEM, EDR/XDR, Microsoft Defender, Microsoft Sentinel, email security, cloud security and network monitoring tools.- Support timely incident response, containment, remediation, recovery and post-incident review activity with internal teams and third-party providers.
- Maintain the vulnerability management programme, including scanning, prioritisation, remediation tracking, exceptions and reporting.
- Support the ISMS, ISO 27001, Cyber Essentials Plus, PCI DSS and relevant security governance, risk and compliance activity.
- Maintain security risk, non-conformance, improvement and information asset records, escalating material risks or decisions as required.
- Support audits, supplier assurance, project security reviews, access governance, data protection activity and business continuity testing.
- Produce clear security reports, metrics and updates for operational, management and governance forums, and support awareness activity across the business. Essential knowledge, skills and experience
- Maintain a good working knowledge of cyber security principles, common attack vectors, security controls and defence-in-depth practices.
What will it take to be successful?
You'll have experience in cyber security or a related technical field, with a strong understanding of networks, cloud platforms, identity services, and security technologies. You'll be confident supporting incident response, vulnerability management, risk and compliance activities, and security operations.
Experience with Microsoft security solutions such as Defender, Sentinel, Purview, Entra, and Azure is desirable. Knowledge of security awareness training, phishing simulations, supplier assurance, and security reporting would be an advantage.