Security Analyst

Company: AXA Group
Apply for the Security Analyst
Location: Bristol
Job Description:

Overview

In this role you join AXA UK’s Proactive Security team to advance Breach and Attack Simulation, challenging defences with real-world attacker techniques. You will translate threat intel and penetration testing findings into prioritized use cases, guide remediation, and communicate insights to senior audiences. You will operate in regulated environments using industry frameworks and cutting-edge tooling, contributing to the team’s security posture and your professional growth.

Pay / Benefits

  • hybrid work
  • flexible working arrangements
  • accessible interview process (AXA Accessibility Concierge)
  • equal opportunities employer
  • industry events attendance
  • career development opportunities

Responsibilities

  • Review threat intelligence feeds and penetration test findings to identify BAS use cases reflecting real-world threats
  • Support penetration testing engagements by ensuring appropriate scope and that reports meet AXA standards
  • Review remediation plans from pen tests and verify fixes via BAS tooling
  • Respond to BAS control test failures, investigate root causes and raise targeted remediation with technical teams
  • Produce clear metrics and executive-level reports translating findings into actionable insights
  • Identify opportunities to refine, simplify, and scale security processes

Key requirements

  • Hands-on technical penetration testing experience (internal, external, web, cloud)
  • Deep understanding of IT systems and vulnerabilities across cloud environments (AWS, Azure, GCP) and infrastructure components
  • Experience in cloud security engineering or IT infrastructure is advantageous
  • Strong analytical and problem-solving skills; ability to challenge ambiguity
  • Curiosity about breaking systems and improving resilience
  • Comfort with industry frameworks (MITRE ATT&CK, CVSS, CREST, CBEST, TIGER, NIST, ISO 27001/27002)
  • OSCP or equivalent certification or MSc in Cyber Security or IT is desirable but not essential
  • Analytical mindset
  • Problem-solving
  • Curiosity and willingness to challenge assumptions
  • Penetration testing (internal, external, web, cloud)
  • Threat intelligence analysis
  • Breach and Attack Simulation tooling

…

Posted: October 1st, 2026