IT Security Analyst – Incident Response & Vulnerability Management

Operations Resources
Cardiff, Cymru / Wales, CF10 2AF, United Kingdom
Last month
Job Type
Permanent
Work Pattern
Full-time
Work Location
Hybrid
Seniority
Senior
Education
Degree
Posted
30 Apr 2026 (Last month)

Benefits

Participation in on-call rota

Job TitleLevel 3 Security Analyst – Incident Response & Vulnerability Management

DepartmentService Delivery / Security

Reporting ToSecurity Lead / Service Delivery Manager

Operates under the direction of the Incident Manager during security incidents

LocationUK (Hybrid) Office in Cardiff 1-2 days per week, regular client site travel.

Working PatternMonday to Friday with participation in the on-call Security and Major Incident rota as required

Role Purpose

The Level 3 Security Analyst is responsible for the technical investigation, containment, remediation, and resolution of IT security incidents and vulnerabilities across a complex, multi-site customer estate supported by “the MSP”.

The role acts as a senior technical authority for security incidents, working alongside Incident Management, Infrastructure, Network, and Application teams to ensure security issues are resolved end-to-end, correctly documented, and do not reoccur.

Key Accountabilities – Security Incident Investigation & Response

Act as the technical lead for the investigation of security incidents across supported platforms.

Investigate malware, ransomware, account compromise, unauthorised access, suspicious activity, and security misconfiguration.

Perform detailed root cause analysis across endpoint, identity, network, and application layers.

Advise the Incident Manager on incident scope, impact, containment, eradication strategy, and recovery validation.

Drive incidents through to full technical resolution, not temporary mitigation.

Key Accountabilities – Vulnerability Management

Investigate vulnerabilities identified via scanning platforms, endpoint and cloud tooling, supplier disclosures, and audit activity.

Assess risk based on exploitability, exposure, and operational impact.

Own remediation actions end-to-end, coordinating with Infrastructure, Network, and third-party suppliers.

Validate remediation and ensure appropriate evidence is captured for assurance and audit.

Platforms & Technology Scope

End-user devices including Windows, macOS, tablets, and peripherals.

Microsoft 365 including Entra ID, Exchange, SharePoint, Defender, and endpoint protection.

Identity and Access Management including privileged and service accounts.

On-premises and cloud-hosted servers.

Network infrastructure including firewalls, switches, wireless, and WAN connectivity.

Cloud-hosted and supplier-managed applications.

Documentation, Audit & Continuous Improvement

Produce clear, technically accurate documentation covering incidents, root cause analysis, and corrective actions.

Support governance, customer assurance, and audit requirements.

Contribute to post-incident reviews and lessons learned.

Identify recurring issues and recommend long-term improvements.

Ensure incidents and vulnerabilities are correctly logged and tracked within ITSM systems.

Collaboration & Escalation

Work closely with Incident Managers, Security specialists, and Level 3 Infrastructure and Network teams.

Act as a senior escalation point for Level 1 and Level 2 teams.

Engage third-party suppliers to progress investigation and remediation.

Participate in out-of-hours response as required.

Knowledge, Skills & Experience – Essential

Proven experience in a Level 3 or Senior Security Analyst or Incident Response role.

Hands-on experience investigating and resolving incidents across endpoints, identity platforms, networks, and cloud services.

Strong understanding of malware and ransomware response, identity compromise, and vulnerability remediation.

Experience working within formal Security Incident and Major Incident processes.

Strong written documentation and stakeholder communication skills.

Knowledge, Skills & Experience – Desirable

Experience supporting multi-site or operationally sensitive environments.

Familiarity with Defender, SIEM, EDR, and vulnerability management tools.

Understanding of regulated or PCI-adjacent environments.

Relevant security certifications or equivalent experience.

Behavioural Competencies

Takes ownership from detection through to resolution.

Investigates thoroughly and challenges incomplete fixes.

Calm, methodical, and decisive during live incidents.

Understands operational and business impact.

Professional and confident when engaging customers and suppliers.

Decision Making & Authority

Makes technical decisions relating to investigation, containment, and remediation of security incidents.

Escalates risk and decision points appropriately to Incident Management and Service Delivery leadership.

Key Interfaces

Incident Management

Security Operations

Infrastructure and Network Services

Third-party suppliers

Customer stakeholders via structured incident communications

Related Jobs

View all jobs

Senior Cyber Security Analyst

Picture More Ec1A1Bb, EC1A 1BB, United Kingdom
£80,000 – £90,000 pa Hybrid

Cyber Security Analyst

Precise Placements Ec2A4Bt, EC2A 4BT, United Kingdom
£55,000 – £66,000 pa Remote

Senior Cyber Security Analyst, Professional Services, CompTIA, SIEM, ISO27001, Part

Carrington Recruitment Solutions Ec2M4Yf, EC2M 4YF, United Kingdom
£80,000 – £90,000 pa Remote

Cybersecurity Analyst

Ryder Reid Legal London, United Kingdom
Remote

Senior Cyber Security Analyst

HAYS Specialist Recruitment Bolton, United Kingdom
£45,000 – £55,000 pa Hybrid

Cyber Security Engineer

Required IT Br11Aa, BR1 1AA, United Kingdom
£55,000 – £60,000 pa Hybrid

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cyber Security Jobs in the UK (2026 Guide)

Where to advertise cyber security jobs UK in 2026: the specialist boards, communities and channels that reach offensive, defensive and GRC security talent. The candidate pool is small, heavily vetted and in high demand across government, financial services, critical national infrastructure and the private sector simultaneously. Many of the strongest candidates hold active security clearances, are not actively job-searching through general platforms, and move primarily through specialist networks and trusted referrals. General job boards reach a broad audience but lack the specificity that security professionals expect. Specialist platforms, government-affiliated channels and cleared candidate networks each serve a different part of the market. This guide, published by CybersecurityJobs.tech, covers where to advertise cyber security roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cyber Security Jobs UK 2026: What to Expect Over the Next 3 Years

Cyber Security Jobs UK 2026: roles, salaries and the threat intelligence, cloud security and zero-trust hiring trends shaping UK cyber careers. Cyber security is one of the few sectors where demand for talent has never once dipped. Every major technological shift of the past decade — cloud migration, remote working, AI adoption, the proliferation of connected devices — has expanded the attack surface that security professionals are expected to defend. And every expansion of that attack surface has generated more jobs. But the cyber security jobs market of 2026 is not simply a larger version of what it was three years ago. It is a structurally different market. The threats have evolved, the technologies used to combat them have changed, the regulatory environment has tightened considerably, and the roles being created reflect all of that. A job seeker who understands only the cyber security landscape of 2023 is already working with an outdated map. The candidates who will thrive over the next three years are those who understand where the sector is heading — which specialisms are attracting the most investment, which technologies are reshaping defensive and offensive security practice, and how the definition of a cyber security professional is broadening well beyond the traditional image of a network defender in a SOC. This article breaks down what the UK cyber security jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.