It's fun to work in a company where people truly BELIEVE in what they're doing!
1. Security monitoring and alert triage
- Monitor Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), anti-malware, email security, web security and cloud security alerts.
- Validate, triage and prioritise security events using agreed playbooks, business impact and risk context.
- Create accurate incident records, preserve relevant evidence and escalate incidents through the agreed incident management process.
- Support containment, eradication and recovery activities under the direction of the incident owner.
2. Incident response and operational support
- Follow documented incident response procedures for malware, phishing, account compromise, data exposure, suspicious network activity and lost or stolen devices.
- Assist with post-incident actions, including evidence capture, timeline building, lessons learned and remediation tracking.
- Maintain security operations knowledge base articles and playbooks for repeatable response tasks.
3. Vulnerability and configuration management
- Run or support scheduled vulnerability scanning across servers, endpoints, network devices, applications and cloud services.
- Validate scan findings, remove false positives where evidence supports this, assign remediation tickets and monitor progress against agreed service levels.
- Support secure configuration checks against approved baselines, including endpoint hardening, logging configuration and privileged account controls.
- Provide clear remediation guidance to infrastructure, application and service teams.
4. Identity, access, Data Loss Prevention and Multi-Factor Authentication
- Support identity and access management processes, including joiners, movers, leavers, privileged access reviews and evidence collection for access recertification.
- Monitor and investigate Data Loss Prevention (DLP) alerts, applying agreed classification, privacy and escalation rules.
- Support Multi-Factor Authentication (MFA) administration, user enrolment, exception handling, break-glass access checks and failed authentication investigations.
- Assist with user access investigations where suspected compromise, misuse or policy breach is identified.
5. Security controls and tooling
- Operate security tools in line with documented procedures and change controls.
- Support maintenance of alert rules, watchlists, endpoint policies, email filtering rules and data protection controls under approved guidance.
- Record control issues, service defects and improvement opportunities.
- Carry out routine security checks for backup alerts, logging gaps, certificate expiry, secure configuration and monitoring coverage.
6. Policy, compliance and assurance support
- Gather evidence for audits, risk assessments, supplier checks and compliance reviews.
- Apply relevant internal policies, standards and data handling requirements.
- Support regular checks against security standards, control requirements and business processes.
- Identify policy exceptions or control gaps and raise them through the agreed risk management process.
7. Awareness and stakeholder support
- Provide practical security advice to users and technical teams.
- Support phishing exercises, security awareness activities and targeted communications.
- Explain security requirements in a clear, proportionate and helpful way.
- Promote secure behaviours, including reporting suspicious activity, protecting credentials and handling sensitive data correctly.
8. Reporting and documentation
- Maintain accurate incident, alert, remediation and evidence records.
- Prepare routine operational reports on alerts, incidents, vulnerabilities, Data Loss Prevention (DLP), Multi-Factor Authentication (MFA), control exceptions and remediation progress.
- Contribute to dashboards and management information using agreed metrics.
- Keep procedures, playbooks and technical notes up to date.
Qualifications
- Bachelor Degree in Computer Science, Information Technology, Cybersecurity, or related fields.
- At least 1–2 years of experience in IT governance, IT audit, risk, or compliance
- Experience in cybersecurity risk assessment, threat modeling, control testing, or security governance.
- Good command of spoken and written in English.
- Strong analytical and problem-solving skills
- Good documentation and report-writing abilities
- Attention to detail and organizational skills