IT Security Operations & Assurance Analyst
London | Hybrid – three days per week in the office | Permanent
A leading international law firm is seeking an experienced IT Security Operations & Assurance Analyst to join its close-knit Information Security team.
This is a varied role combining hands-on security operations and incident response with security engineering, vulnerability management and assurance. You will act as a key escalation point for security alerts, while helping to improve the firm’s monitoring capabilities, processes, controls and overall cyber resilience.
Key responsibilities:
* Investigating, containing and supporting the resolution of security alerts and incidents
* Acting as an escalation point for the firm’s Managed Security Service Provider
* Reviewing and refining security detections to improve threat visibility and reduce false positives
* Monitoring threat intelligence sources and assessing emerging cyber risks
* Supporting vulnerability identification, prioritisation, remediation and reporting
* Identifying opportunities to improve security monitoring, analytics, automation, tools and processes
* Supporting supplier security assessments, internal and external audits and client assurance requests
* Helping maintain compliance with ISO 27001 and other regulatory, legal and client requirements
* Working with wider Technology teams to improve security controls and operational effectiveness
* Producing documentation and sharing security knowledge across the firm
The successful candidate will have:
* Experience within security operations, a SOC, information security or a broader technical IT environment
* Strong security monitoring, investigation and incident response capabilities
* A broad understanding of operating systems, endpoint security, networking, identity and access management, and modern authentication
* Experience with technologies such as EDR, SIEM, vulnerability management platforms and MSSPs
* An inquisitive mindset, sound judgement and the confidence to investigate when something does not appear right
* Strong communication skills and the ability to engage effectively with technical and non-technical stakeholders
* The ability to work independently, manage competing priorities and take ownership of security matters
* A collaborative approach and genuine interest in continually developing security knowledge
Experience working with CrowdStrike, Microsoft Defender or within a professional-services or legal environment would be beneficial, but is not essential.
This opportuni
