IT Security Operations & Assurance Analyst
Oliver James Associates Ltd.
IT Security Operations & Assurance Analyst
London | Hybrid - three days per week in the office | Permanent
A leading international law firm is seeking an experienced IT Security Operations & Assurance Analyst to join its close-knit Information Security team.
This is a varied role combining hands-on security operations and incident response with security engineering, vulnerability management and assurance. You will act as a key escalation point for security alerts, while helping to improve the firm's monitoring capabilities, processes, controls and overall cyber resilience.
Key responsibilities:
- Investigating, containing and supporting the resolution of security alerts and incidents
- Acting as an escalation point for the firm's Managed Security Service Provider
- Reviewing and refining security detections to improve threat visibility and reduce false positives
- Monitoring threat intelligence sources and assessing emerging cyber risks
- Supporting vulnerability identification, prioritisation, remediation and reporting
- Identifying opportunities to improve security monitoring, analytics, automation, tools and processes
- Supporting supplier security assessments, internal and external audits and client assurance requests
- Helping maintain compliance with ISO 27001 and other regulatory, legal and client requirements
- Working with wider Technology teams to improve security controls and operational effectiveness
- Producing documentation and sharing security knowledge across the firm
The successful candidate will have:
- Experience within security operations, a SOC, information security or a broader technical IT environment
- Strong security monitoring, investigation and incident response capabilities
- A broad understanding of operating systems, endpoint security, networking, identity and access management, and modern authentication
- Experience with technologies such as EDR, SIEM, vulnerability management platforms and MSSPs
- An inquisitive mindset, sound judgement and the confidence to investigate when something does not appear right
- Strong communication skills and the ability to engage effectively with technical and non-technical stakeholders
- The ability to work independently, manage competing priorities and take ownership of security matters
- A collaborative approach and genuine interest in continually developing security knowledge
Experience working with CrowdStrike, Microsoft Defender or within a professional-services or legal environment would be beneficial, but is not essential. This opportuni
#J-18808-LjbffrReference: WJ-766_22052644