Overview
In this role you will protect systems, networks and data for a rail freight and logistics business. You’ll operate security controls, investigate incidents, and coordinate remediation across on-premise, cloud and SaaS environments. You’ll work with infrastructure, applications and service delivery teams to support compliance and security improvements. This role offers hands-on security work with a clear impact on risk reduction and regulatory alignment.
Pay / Benefits
- Hybrid working
- 25 days’ holiday plus bank holidays
- Company pension and life assurance
- Cycle to Work scheme
- Ongoing training and career development
- Employee Assistance Programme and wellbeing support
Responsibilities
- Monitor security systems and investigate alerts to drive incident resolution
- Configure, maintain and support security technologies across on-prem, cloud and SaaS
- Support firewalls, VPNs, endpoint protection, email security, IAM and vulnerability management
- Coordinate vulnerability assessments and track remediation with system owners
- Review systems and cloud services for secure configurations and standards alignment
- Support penetration tests, assurance reviews and accreditation activities
- Contribute security policy evidence and documentation for risk assessments and compliance
- Provide practical security guidance to technical teams and stakeholders
- Identify opportunities to improve security services through upgrades and automation
- Maintain alignment with the NIST Cybersecurity Framework and NIS Regulations
Key requirements
- Hands-on experience in complex IT, network or cyber security environments
- Practical knowledge of TCP/IP, firewalls, VPNs, DNS, DHCP, certificates and SSL/TLS
- Experience with vulnerability scanning and remediation tracking
- Understanding of common attack techniques, security monitoring and incident response
- Knowledge of OWASP Top 10 and cyber security principles
- Understanding of NIST Cybersecurity Framework and NIS Regulations
- Experience working towards Cyber Essentials
- Ability to maintain security policies, procedures and audit evidence
- Methodical issue investigation, risk prioritisation and clear communication
- Willingness to support occasional out-of-hours work
- Collaboration with technical teams and stakeholders
- Clear communication of findings and risks
- Prioritisation and time management
- TCP/IP, firewalls, VPNs, DNS, DHCP, certificates, SSL/TLS
- Vulnerability scanning and secure configuration assessments
- Security monitoring and incident response
…
