Role Overview
The Lead IT Security Analyst is a senior technical specialist responsible for strengthening the organisation’s cyber security across security operations, infrastructure protection, vulnerability management, and incident response.
Reporting to the Head of IT Security, this role plays a critical part in ensuring the confidentiality, integrity, and availability of systems and data. Acting as a senior escalation point, the role provides technical leadership, drives continuous improvement, and ensures security is embedded into all technology change and transformation activities.
Key Responsibilities
Technical Security Operations
- Act as the senior escalation point for security events across SIEM, EDR, firewalls, and network security tools.
- Lead cyber incident response activities, including triage, containment, investigation, and root cause analysis.
- Oversee day-to-day security operations and threat detection capabilities across the IT estate.
- Ensure the effective configuration, tuning, and maturity of SOC/SIEM tooling and alerting.
- Collaborate with managed security service providers to ensure high-quality and timely service delivery.
Vulnerability & Threat Management
- Lead the vulnerability management programme across infrastructure, cloud, and applications.
- Coordinate remediation activities with IT and operational teams to reduce risk exposure.
- Analyse threat intelligence to identify emerging threats and vulnerabilities.
- Provide clear recommendations on prioritisation and implementation of security controls.
Technical Design, Assurance & Architecture
- Conduct security assessments of new solutions, infrastructure changes, and cloud deployment.
- Support secure architecture reviews alongside IT architects and solution designers.
- Ensure secure configuration standards (e.g. CIS Hardening) are implemented and maintained.
- Review and strengthen access controls, identity management, and privileged access processes.
Security Tooling & Control Maturity
- Maintain and enhance core security technologies (SIEM, EDR, IAM, DLP, email security, vulnerability scanning, etc.).
- Support the lifecycle management of security tools and platforms.
- Evaluate and recommend new technologies to improve security capability and resilience.
Continuous Improvement & Technical Leadership
- Identify opportunities to strengthen technical controls and enhance overall security maturity.
- Mentor and support the development of junior Security Analysts.
- Contribute to the IT security roadmap and continuous improvement initiatives.
Stakeholder Engagement
- Act as a trusted technical advisor to infrastructure, cloud, networking, and service teams.
- Provide regular updates, insights, and escalation support to the Head of IT Security.
- Represent IT Security across projects, ensuring security-by-design principles are embedded.
Keys to Success
- Strong technical expertise across cyber security operations, infrastructure, and threat management, with the ability to respond effectively to complex incidents.
- Ability to lead and coordinate incident response and investigations, ensuring swift resolution and minimal business impact.
- Proven capability to translate technical risks into practical solutions that balance security and operational needs.
- Strong analytical mindset with the ability to identify vulnerabilities, assess threats, and prioritise actions effectively.
- Skilled in communicating complex technical information clearly to both technical and non-technical stakeholders.
- Ability to influence and collaborate across teams, acting as a trusted security advisor.
- Demonstrated experience in mentoring and supporting junior team members, building overall team capability.
- Proactive approach to continuous improvement, driving enhancements in tooling, processes, and controls.
- Strong focus on security-by-design, ensuring robust security practices are embedded into all technology changes.
- Resilient and adaptable, with the ability to operate effectively in a fast-paced, evolving threat landscape.