We are looking for an experienced Security Analyst to join our Cybersecurity team. The role focuses on threat detection and incident response, vulnerability management, cloud and identity security, and compliance support across our enterprise infrastructure.
You will monitor and investigate security alerts, coordinate vulnerability remediation, support PCI-DSS and SOC 2 compliance, and work closely with infrastructure, engineering, and compliance teams.
Key Responsibilities
- Monitor and triage security alerts across GCP, Okta, endpoint security, and cloud security platforms.
- Investigate authentication anomalies, suspicious activity, account compromise, and potential security incidents.
- Analyse Windows security events and GCP security activity, including IAM and service account changes.
- Document investigations, determine true/false positives, and escalate critical incidents as required.
- Follow and improve established incident response playbooks.
- Coordinate monthly PCI vulnerability management using tools such as Rapid7 Nexpose/InsightVM and Orca Security.
- Create and manage JIRA tickets for vulnerability remediation and track findings through closure.
- Work with Infrastructure and Platform teams on patching, remediation, and SLA tracking.
- Support SAST/DAST and application security initiatives.
- Support PCI-DSS and SOC 2 Type II compliance activities, audits, and evidence collection.
- Assist with third-party risk management, including vendor security assessments and review of SOC 2 and penetration testing reports.

