Security Operations Lead Analyst

FNZ

Security Operations Lead Analyst

£60000

FNZ, Edinburgh

  • Full time
  • Permanent
  • Onsite working

Posted 1 week ago, 7 May | Get your application in now before you miss out!

Closing date: Closing date not specified

job Ref: 9ae483c43e49496fb8cb95fc4d53b180

Full Job Description

You will be joining an experienced team and working to support some of the biggest financial services clients in the world.

Reporting directly to the Head of Cyber Fusion Centre, you will lead a team of analysts responsible for monitoring and responding to security incidents, implementing proactive measures, and ensuring the overall safety and integrity of our systems, networks, and data.

Team Responsibilities :

The team are responsible for :

Providing high quality and timely response to alerting.

Shift work covering 24 / 5 plus on-call weekend work

Incident resolution and triage resolve incidents as per agreed procedures and escalate internally to relevant teams to resolve any incidents outwith our remit.

Stakeholder Communication Triage incidents and manage stakeholder expectations for incident resolution.

Post Incident reviews evaluate the incident management response and recovery effort for major, critical and high priority incidents to provide continual improvement of our incident responses.

Specific Role Responsibilities

Responsible for the regional Incident response team.

Building the team

Fostering a great culture

Supporting and growing the team members in their career

Managing team rotas and absence

Knowledge sharing and mentoring

Incident Management : Lead and supervise a team of security analysts to promptly detect, investigate, and respond to security incidents.

Ensure the appropriate escalation procedures are followed when necessary and coordinate incident resolution efforts effectively.

Lead incident escalation and communication for internal and external stakeholders.

Use application management software and tools to collect agreed performance statistics.

Security Operations Center (SOC) Management : Manage day-to-day SOC operations, ensuring that monitoring activities are performed round-the-clock, and shift schedules are organized efficiently.

Security Incident Response : Develop and maintain an incident response plan, conduct periodic exercises to test the response readiness of the team, and continually enhance the incident response process.

Team Training and Development : Provide mentorship and training to security analysts, ensuring they are equipped with the necessary skills and knowledge to excel in their roles.

Security Incident Remediation : Coordinate with IT and infrastructure teams to implement necessary remediation actions following security incidents, including applying patches, updating configurations, or deploying new security measures.

Triage of alerts from FNZ Group systems

Lead post Incident reviews, helping to provide a continually improved service for our customers and stakeholders.

Define Standard Operating Procedures and playbooks to respond to incidents

Supporting development and enhancement of SIEM detection and playbooks

We are looking for a Security Operations Lead Analyst to join the Security Operations team. You will have knowledge of Information Technology concepts and have 3+ years experience in Security Operations in a commercial environment.

You will be excited to develop your knowledge and abilities in a global, complex organisation. You will be able to learn quickly and must be able to show how you develop yourself and your career., Bachelor's Degree or higher in Computer Science, Mathematics, Engineering, Physics or other Sciences or equivalent working experience.

  • Degree preferable in either Commerce or IT; (A-B + average) or equivalent;

  • Intermediate SQL skills;

  • Interest / familiarity with financial markets and products beneficial but not essential;


  • Excellent spoken and written English

    Experience of Incident Response (triage, classification, investigation, escalation)

    Knowledge of networking protocols and investigation (capture, Wireshark)

    Knowledge of Operating Systems, Databases and Applications (Windows, Linux, SQL, F5)

    Knowledge of SIEM tools (Splunk, Sentinel)

    Knowledge of EDR tools (Defender, Crowdstrike)

    Knowledge of security concepts (MITRE, Kill-Chain)

    Willing to work in shift patterns

    Nice to have :

    Written / spoken German

    At FNZ, our purpose is to make wealth management more accessible, bringing easier, fairer and more inclusive solutions to people worldwide.

    Here in the Global Information Security team, we work to protect the platforms that support investment solutions for over 20 million people.