Cyber Security Specialist

Role Summary

We are looking for an experienced Cybersecurity Specialist with 8-15 years of experience to strengthen our enterprise security posture. The role will be responsible for security monitoring, threat detection, vulnerability management, incident response, security architecture, risk management, and implementation of cybersecurity controls across infrastructure, applications, endpoints, networks, and cloud environments.

The position requires a hands-on security professional who can independently investigate complex security issues, lead remediation activities, work with infrastructure/application/cloud teams, and communicate security risks effectively to technical and business stakeholders.

The responsibilities are broadly aligned with cybersecurity work across areas such as systems security analysis, vulnerability analysis, defensive cybersecurity, incident response, threat analysis, and security management.

Key Responsibilities

  • Develop, implement, and continuously improve enterprise cybersecurity controls, processes, standards, and procedures.
  • Monitor and analyze security events using SIEM, EDR/XDR, IDS/IPS, Firewall, email security, and other security technologies.
  • Investigate and respond to cybersecurity incidents, including containment, eradication, recovery, and root-cause analysis.
  • Lead vulnerability management activities including vulnerability scanning, risk prioritization, remediation tracking, and validation.
  • Conduct security assessments of applications, infrastructure, networks, endpoints, cloud environments, and third-party services.
  • Analyze security alerts and threats using frameworks such as MITRE ATT&CK and industry threat intelligence.
  • Support development and maintenance of incident response plans, playbooks, and security operations procedures.
  • Identify security gaps and recommend appropriate technical and process improvements.
  • Work with infrastructure, network, cloud, DevOps, application, and engineering teams to implement security requirements.
  • Review security architecture and provide recommendations for secure design and implementation.
  • Support identity and access management, privileged access management, endpoint security, network security, and data protection initiatives.
  • Participate in security risk assessments, audits, compliance reviews, and remediation activities.
  • Define and monitor cybersecurity KPIs/KRIs and prepare management-level security reports.
  • Support security policies, standards, procedures, and control frameworks.
  • Evaluate new security technologies and recommend solutions based on business and security requirements.
  • Lead or mentor junior cybersecurity analysts and specialists.
  • Participate in security investigations and forensic analysis where required.
  • Stay current with emerging threats, vulnerabilities, attack techniques, and cybersecurity technologies.

Technical Skills

Security Operations

  • SIEM: Splunk, Microsoft Sentinel, QRadar, or equivalent
  • EDR/XDR: Microsoft Defender, CrowdStrike, SentinelOne, or equivalent
  • SOAR and security automation
  • IDS/IPS and network security monitoring
  • Security incident investigation and response
  • Threat intelligence and threat hunting
  • MITRE ATT&CK

Network & Infrastructure Security

  • Firewalls, VPN, proxies, WAF, IDS/IPS
  • TCP/IP, DNS, HTTP/HTTPS, SMTP and common network protocols
  • Network segmentation and secure network architecture
  • Windows and Linux security
  • Active Directory/Entra ID security
  • Endpoint hardening and security configuration

Cloud Security

  • Strong understanding of AWS/Azure/GCP security concepts
  • Cloud IAM and privileged access
  • Cloud network security
  • Security monitoring and logging
  • Container/Kubernetes security is an advantage
  • Cloud security posture management

Vulnerability & Security Assessment

  • Vulnerability assessment and remediation
  • Tools such as Tenable, Qualys, Rapid7, or equivalent
  • Penetration-testing concepts
  • Web/application security fundamentals
  • OWASP Top 10
  • Security configuration and hardening standards

Governance, Risk & Compliance

  • Risk assessment and treatment
  • Security policies and standards
  • Security audits and control assessments
  • NIST Cybersecurity Framework/NIST security controls
  • ISO 27001
  • SOC 2/PCI DSS/GDPR or applicable regulatory requirements
  • Third-party/vendor security assessments

Required Experience

  • 8-15 years of overall IT/security experience, with significant hands-on cybersecurity experience.
  • Strong experience in enterprise security operations, incident response, vulnerability management, or security engineering.
  • Experience working across multiple security domains such as network, endpoint, cloud, application, and identity security.
  • Demonstrated experience handling complex cybersecurity incidents and security investigations.
  • Experience working with security monitoring and vulnerability management platforms.
  • Experience collaborating with infrastructure, application, cloud, and engineering teams.
  • Experience leading security projects, initiatives, or technical workstreams.
  • Ability to independently assess security risks and recommend practical remediation.

Behavioural & Leadership Competencies

  • Strong analytical and problem-solving skills.
  • Ability to investigate complex technical issues under pressure.
  • Excellent written and verbal communication.
  • Ability to explain technical security risks to non-technical stakeholders.
  • Strong ownership and decision-making capability.
  • Ability to work independently and collaboratively across teams.
  • Strong documentation and reporting skills.
  • Continuous-learning mindset.
  • Ability to mentor and guide junior security professionals.
  • Strong understanding of business risk and security priorities.

Key Success Metrics

  • Reduction in critical/high-risk vulnerabilities and remediation SLA adherence.
  • Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
  • Security incident resolution and recurrence reduction.
  • Security control effectiveness.
  • Critical asset monitoring coverage.
  • Security compliance and audit findings.
  • Security posture improvements across cloud, infrastructure, applications, and endpoints.
  • Automation and operational efficiency improvements.

Job Details

Company
Sandhata Technologies Limited
Location
London, United Kingdom
Employment Type
Permanent
Salary
GBP 55,000 - 60,000 Annual
Posted