IT Security Operations & Assurance Analyst
Oliver James Associates
In this role you will help safeguard a leading international law firm by handling hands-on security operations, incident response and assurance activities. You will work within the Information Security team to enhance threat detection, monitoring and resilience across the firm. You will act as a key escalation point for alerts and MSSP interactions, shaping controls, processes and compliance, including ISO 27001. This hybrid London role offers varied challenges and opportunities to influence security across a professional services environment.
Responsibilities- Investigate, contain and support resolution of security alerts and incidents
- Escalate and coordinate with the Managed Security Service Provider
- Review and refine detections to improve threat visibility and reduce false positives
- Monitor threat intel sources and assess emerging cyber risks
- Support vulnerability identification, prioritisation, remediation and reporting
- Identify opportunities to improve monitoring, analytics, automation, tools and processes
- Support supplier security assessments, audits and client assurance requests
- Maintain compliance with ISO 27001 and other regulatory/client requirements
- Collaborate with Technology teams to enhance security controls and operational effectiveness
- Produce documentation and share security knowledge across the firm
- Experience in security operations, SOC, information security or related IT environment
- Strong monitoring, investigation and incident response capabilities
- Broad understanding of operating systems, endpoint security, networking, IAM and modern authentication
- Experience with EDR, SIEM, vulnerability management platforms and MSSPs
- Inquisitive mindset, sound judgment and ability to investigate anomalies
- Strong communication skills with technical and non-technical stakeholders
- Ability to work independently, manage priorities and own security matters
- Collaborative approach and commitment to developing security knowledge
- Experience with CrowdStrike or Microsoft Defender is beneficial but not essential
- strong communication
- collaborative
- independent ownership
- EDR
- SIEM
- vulnerability management
Reference: WJ-747_30191022