Cyber Security Operations Analyst at University of Bath

February 2, 2024

Job Description

We are seeking a Cyber Security Operations Analyst to join our Digital, Data & Technology Group.

About the role 

The Security Operations Analyst is part of a team responsible for a broad range of cyber security tasks and activities including management and operation of the University’s Security Operations Centre (SOC), operating and applying security controls in line with standard frameworks – ISO 27001, NIST CSF, Cyber Essentials and facilitating risk-based decision making to ensure maintenance of security posture. 

You will be responsible for undertaking all aspects of security operations, including responding to and resolving security events and incidents, identifying vulnerabilities, deploying mitigation tactics and escalating where appropriate, safe-guarding sensitive information from unauthorised access and generally maintaining security posture in line with the University’s risk appetite. 

Additionally, you will undertake risk assessments and perform horison scanning ensuring that the University control environment is optimally configured to respond to the latest threats to maintain resilience and continuity of service across key systems, services and infrastructure. 

You will be expected to review security processes, systems and capabilities that affect the security of our most critical assets. You will proactively work with colleagues to identify areas of weakness and exposures and create recommendations for continual improvement. 

As appropriate, you will take part in change approval boards, oversee the security elements of delivering new products and services into live University environments and work closely with vendors. 

This role is offered on a full time (36.5 hours per week) permanent basis.

About you 

  • A broad of knowledge of security risk and assurance practices including detailed knowledge of security controls frameworks: ISO 27001/Cyber Essentials/NIST CSF/NIS/CIS Top 20/OWASP.
  • Experience of regulatory and compliance responsibilities for universities, including GDPR, DPA, PCI DSS, Ofsted. 
  • A broad technical knowledge of various tools, how to operate and maintain them, interpret the output and apply the recommendations. 
  • Excellent practical experience and knowledge of measuring performance and effectiveness of security controls to reduce incidents, safeguard sensitive data and improve overall security posture.
  • Knowledge and understanding of reducing risk and exposure across third parties and throughout the supply chain.

Location