Cyber Security Analyst

Company: East West Railway Company
Apply for the Cyber Security Analyst
Location: Milton Keynes
Job Description:

Overview

In this role you help strengthen East West Rail’s cyber resilience by using the Microsoft security stack to prevent, detect, and respond to threats. You will work with the SOC to monitor activity, contribute to risk-based assurance, and support IT operations. You’ll translate security concerns into clear documentation and KPIs for decision-makers. This is a chance to shape secure, scalable infrastructure for a major public-project environment. You will partner with cross-functional teams to embed security into daily operations and stakeholder communications.

Pay / Benefits

  • Competitive salary
  • Up to 12% employer pension contribution
  • 36 days annual leave + option to buy 2 extra days
  • 2 volunteering days
  • Enhanced family-friendly policies
  • Life assurance (4x salary)

Responsibilities

  • Support the Cyber Lead in delivering the IT Cyber Strategy
  • Handle DSARs and FoI requests with Legal
  • Operate Microsoft Security Stack (Defender, Purview, Entra, etc.) and work with SOC on monitoring
  • Maintain high-quality configuration, standards, and procedures documentation
  • Gather KPIs for reporting to the SIRO
  • Respond to cyber incidents and conduct root cause analyses
  • Contribute to cyber communications for the business
  • Conduct internal phishing simulations and support IT assurance activities
  • Arrange third-party assurance (e.g., penetration testing) and ensure standards alignment
  • Adhere to Health and Safety principles and promote cost-conscious, innovative approaches
  • Model EWR’s vision and Ways of Working, supporting others in doing the same

Key requirements

  • Background in cyber security, information security, IT operations, or related discipline
  • Experience with Microsoft Security Stack (Defender, Purview, Entra, Sentinel, Intune) or equivalent
  • Experience investigating and resolving security alerts, incidents, vulnerabilities, or control issues
  • Understanding of common cybersecurity risks and controls (phishing, malware, data loss, access control, secure configuration)
  • Ability to document processes, configurations, decisions clearly
  • Analytical, problem-solving, and evidence-based reasoning
  • Effective communication to both technical and non-technical audiences
  • Proactive, collaborative, service-oriented approach and flexibility to support wider IT activity
  • proactive
  • collaborative
  • service-oriented
  • Microsoft Defender
  • Purview
  • Entra

…

Posted: September 30th, 2026