About this role
Salary: £58,000 - 98,000 per year
Requirements: At least 5–7 years of technology security expertise, including a documented minimum of 5 years of information security experience.Prior experience in an international enterprise environment.Bachelors degree in Cybersecurity, Information Systems, Computer Science, or a similar discipline; an advanced degree is highly desirable.Strong analytical skills and proficiency with security frameworks such as NIST, including implementing and auditing security measures, security response, and incident management.Working knowledge of Cisco network switches, routers, firewalls, VPNs, network security, DLP, antivirus/antimalware, IDS/IPS, SIEM, SMTP, email security, Active Directory, Group Policy, DNS, DHCP, and VLANs.Experience with identity and access management solutions such as SAML/OATH, and with HIDS and NIDS.Relevant information security or cybersecurity certifications are desirable.Knowledge of security best practices, including encryption, hashing, vulnerability scanning, event log monitoring, intrusion detection and prevention, eDiscovery, and content filtering.Ability to analyze the security landscape and recommend changes, manage and improve vulnerability management programs, and propose solutions to address infrastructure vulnerabilities.Desired qualifications include CISSP, NIST Cybersecurity Framework (NCSF), CCSP, and/or CEH certifications; Microsoft Office and Visio; WAN technologies such as MPLS and SD-WAN; and security knowledge of AWS, GCP, or Azure.Experience managing Cisco ELA products, including DNA, Firepower, ISE Management Console, Umbrella, Cisco AMP for Endpoints, and Stealthwatch, as well as Splunk, SolarWinds, Varonis, and Darktrace, is desirable.Experience with Azure Rights Management and Information Protection, project management, and a HIPAA/FDA-regulated environment is desirable.Strong initiative, organization, attention to detail, communication, teamwork, adaptability, stress tolerance, problem-solving, and internal customer service skills.Ability to work effectively in a fast-paced environment with limited guidance, maintain composure under pressure, and communicate issues and solutions clearly. Responsibilities: Collaborate with IT teams to design and implement our cybersecurity strategy, incorporating operational requirements.Maintain information security policies, architecture, technical standards, controls, solutions, guidelines, and procedures to support our security posture.Assess information risk, identify vulnerabilities and security gaps through ongoing monitoring, and facilitate remediation and control enhancements.Coordinate security measures to protect our computer infrastructure and information systems and maintain an acceptable risk posture.Manage elevated-privilege account access and audit activity to meet business and regulatory requirements.Evaluate, implement, and help improve cybersecurity solutions and controls that protect confidentiality, integrity, and availability.Participate in proofs of concept for security technologies and develop criteria for selecting solutions that meet strategic, operational, and security needs.Assess vendor and third-party risk, review vendor contract terms, and address data privacy considerations.Coordinate penetration testing and manage internal and external cybersecurity analysts to detect, mitigate, and analyze threats.Work with other teams to develop and configure security controls and tools, including firewalls, business systems, data leakage protection, patching, encryption, vulnerability scanning, application code scanning, and remediation solutions.Participate in developing and testing our security incident response plan and act as the incident response leader.Develop security, risk, and compliance reports and alerts, and participate in annual reviews of information security policies and procedures.Develop, test, and implement disaster recovery procedures for cybersecurity technology.Manage cybersecurity projects to deliver on time and within budget and ensure they meet our information protection requirements.Perform or coordinate internal security assessments, penetration tests, and vulnerability scans, and assess our cybersecurity maturity.Support compliance with applicable frameworks and regulations, including COBIT, NIST, ISO, ITIL, PCI, GLBA, GDPR, and HIPAA, as well as other data privacy and security standards.Respond to internal customer security-related support tickets and resolve assignments within applicable SLAs.Evaluate and implement CIS Critical Security Controls where appropriate, contribute to our cybersecurity strategic roadmap and annual budget, and follow applicable change management policies and procedures.Participate in change management meetings and provide expert input to help maintain security. Technologies: AWSActive DirectoryAzureCiscoGCPIncident ManagementSupportITILMPLSNetworkSAMLSecuritySplunkCloudNexusVPN More:
We are a leading global company specializing in pharmaceutical products. This is a permanent, full-time Senior Information Security Analyst role based at our Central London offices. For the foreseeable future, the role will be performed remotely from home. The salary is £70,000–£85,000.
last updated 40 week of 2026