About the job I44 - Security Analyst (104)
About the Role
We are seeking an experienced Security Analyst to join the IT Risk & Security team, reporting to the Security Operations Manager.
The role will be responsible for administering and maintaining key security technologies, including Web Application Firewall (WAF), Intrusion Prevention System (IPS), and Database Activity Monitoring (DAM) solutions.
You will monitor and investigate security alerts, system logs, and suspicious activities, working closely with internal teams and external SOC partners to identify, contain, and remediate cybersecurity threats. You will also serve as a hands-on first responder for security incidents across cloud, on-premises, and hybrid environments.
Key Responsibilities
- Administer, maintain, configure, and troubleshoot WAF, IPS, and DAM security solutions.
- Onboard internet-facing applications to WAF and critical databases to DAM for security monitoring.
- Monitor, analyse, and investigate security alerts, logs, traffic anomalies, and potentially malicious activities.
- Perform hands-on triage and investigation of cybersecurity incidents across cloud, on-premises, and hybrid environments.
- Collaborate with internal teams and external SOC providers on incident investigation, containment, remediation, and closure.
- Use SIEM, analytics, data visualisation, automation, AI, and machine learning capabilities to correlate security data, identify patterns, and support investigations.
- Analyse network and application traffic against established baselines to identify anomalies, root causes, indicators of compromise, and potential attack paths.
- Continuously monitor and track security events and requests raised by SOC teams, systems, and users through to closure.
- Support security readiness exercises, including Red Team exercises, tabletop exercises, and cyber-range simulations.
- Apply ethical-hacking and vulnerability assessment knowledge to identify potential threats and security weaknesses.
- Prepare weekly, monthly, and quarterly security operations metrics, statistics, and management reports.
- Manage vendor maintenance and support arrangements for security systems, including supporting ITQ/RFP and vendor-management processes.
- Stay current with emerging cyber threats, vulnerabilities, attack techniques, and security technologies.
- Support other cybersecurity projects and operational activities as required.
Requirements
- 3–5 years of relevant cybersecurity experience, including approximately 3 years of hands-on experience administering and investigating WAF, IPS and/or DAM solutions within a medium-to-large enterprise.
- Experience within a financial institution or regulated environment is preferred.
- Hands-on WAF experience covering application and DNS-zone onboarding, policies and rules, certificate lifecycle management, bot/DDoS controls, attack analysis, tuning, and troubleshooting.
- Practical IPS experience covering inline prevention, signatures, severity and actions, policy tuning, traffic analysis, and investigation of exploitation attempts. Experience with firewall-integrated IPS is advantageous.
- DAM experience covering database onboarding, agents/log sources, security policies, privileged and anomalous activity monitoring, and database-access investigations across cloud and on-premises environments.
- Strong security investigation skills, including analysis of security events, network/application logs, HTTP/S traffic, and packet-level data.
- Ability to correlate multiple data sources, identify Indicators of Compromise (IOCs) and attack paths, determine root causes, and document investigation findings.
- Strong technical understanding of TCP/IP, DNS, TLS, HTTP/S, APIs, web application architecture, databases, firewalls, VPNs, and common cyberattack techniques, including the OWASP Top 10.
- Experience with SIEM platforms, ticketing/case-management systems, detection tuning, incident response processes, and MITRE ATT&CK.
- Ability to use scripting, analytics, automation, or AI-assisted tools to process security data, enrich investigations, identify patterns, and automate repeatable operational activities.
- Familiarity with security governance processes covering change, access, configuration, incident, evidence, and vendor management.
- Knowledge of MAS Technology Risk Management (TRM), Cyber Hygiene requirements, NIST Cybersecurity Framework, and other relevant security standards is advantageous.
Qualifications & Certifications
- Diploma or Degree in Cybersecurity, Information Technology, Computer Science, or a related discipline, or equivalent practical experience.
- Relevant certifications such as CISSP, GCIH, GCIA, CEH, CSA, or vendor-specific WAF/IPS/DAM certifications are advantageous.
Key Competencies
Strong analytical judgement, attention to detail, ownership, documentation, and communication skills. The successful candidate should be able to clearly explain technical security findings, collaborate effectively across technical and business teams, and remain effective during time-sensitive cybersecurity incidents.