NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Analyst in United Kingdom
17 hours agoBe an early applicant
Apply with autofill
Apply with autofill
Gandwukeurope·17 hours ago
17 hours agoBe an early applicant

Cyber Security Analyst

Southampton, United KingdomMid · 2-5 yearsSecurity Analyst

Sign up free to see how well your resume matches this role.

Boost your chances at gandwukeurope

How you compare FREE

?
Your scoreYour score: not yet known
→
47
Top 10%Top 10%: 47 out of 100

Top 10% of NextRaise users matched against Security Analyst roles in United Kingdom.

Must-have skills for this role

  • cyber security
  • incident response
  • network security
  • firewalls

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Perform day-to-day monitoring and proactive management of cyber security systems, alerts and associated components.
  • Triage, investigate and coordinate the resolution of security incidents, escalating material risks in line with the incident and major incident processes.
  • Act as a central point of contact for operational cyber security activity and provide clear updates to technical teams, stakeholders and management.
  • Maintain appropriate incident records, evidence, lessons learned and follow-up actions.
  • Configure, maintain and support security controls across the Freightliner estate, including firewalls, secure web gateways/content filtering, endpoint protection, VPN and remote access, email security, identity and access controls, vulnerability management and security monitoring platforms.
  • Support secure configuration, operational health, tuning and lifecycle management of security technologies across on-premises, cloud and SaaS environments.
  • Plan, test and implement upgrades and service improvements to existing cyber security services and associated infrastructure.
  • Use scripting and automation where appropriate to improve consistency, response times, reporting and operational efficiency.
  • Operate a continuous vulnerability assessment process, coordinate remediation with system owners and track risks through to closure or formal acceptance.
  • Audit systems, cloud services and applications for secure configuration and alignment with approved standards and baselines.
  • Coordinate and support annual security assessments, penetration tests, audits and assurance activities, ensuring that findings have clear owners and remediation plans.
  • Contribute technical evidence and subject-matter support for security policies, risk assessments, compliance obligations and internal governance reporting.

What they're looking for

  • Significant hands-on experience supporting complex IT, network or cyber security environments; typically gained over five years in relevant technical roles.
  • Strong understanding of cyber security principles across infrastructure, networks, endpoints, cloud services, identity and applications.
  • Practical knowledge of TCP/IP, firewalls, VPN technologies, DNS, DHCP, certificates and SSL/TLS.
  • Experience with vulnerability scanning, secure configuration assessment, remediation tracking and risk-based prioritisation.
  • Understanding of common attack techniques, security monitoring, incident response and recognised application security risks such as the OWASP Top 10.
  • Good understanding of the NIS / NIST Cybersecurity Framework (NIST CSF) and its practical application to identifying, protecting, detecting, responding to and recovering from cyber security risks.
  • Understanding of the Network and Information Systems (NIS) Regulations and the technical, operational and organisational measures required to support compliance.
  • Experience working towards Cyber Essentials
  • Ability to produce and maintain security policies, standards, procedures, control documentation and evidence for audits, assurance reviews and accreditation activities.
  • Ability to interpret technical security information, investigate issues methodically and translate findings into clear, proportionate actions.
  • Champions security and drives awareness throughout the company
  • Willingness and ability to participate in ad hoc out-of-hours support where required.

Nice to have

  • Experience administering security capabilities within Microsoft Azure, Microsoft 365, Microsoft Entra ID, Microsoft Defender and/or Microsoft Sentinel.
  • Experience of SIEM, endpoint detection and response, secure web gateway, email security, network security and privileged access technologies.
  • Relevant current certifications such as Microsoft Security, Compliance and Identity, Azure, CompTIA Security+, CISSP, SSCP, CCNA Security or Palo Alto Networks certifications.
  • ITIL Foundation certification or practical experience working within an IT service management framework.
  • Experience in a regulated, safety-critical, transport, logistics or multi-site operational environment.
  • Experience supporting NIS compliance, security audits, assurance reviews, accreditation activities or certification programmes.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Together, we move what matters 

We are at the start of something powerful. Heavy Haul Rail was created with a simple but transformative belief: the UK deserves a smarter, cleaner, more resilient freight future. And we have the opportunity to build it.   

Every role in this business carries purpose. Whether you work in operational delivery, driving trains, engineering, or business support, the work you do contributes directly to reducing emissions, easing road congestion, strengthening supply chains and powering British industry. This is meaningful work, with real impact. 

Who we are 

Previously operating as Freightliner’s Heavy Haul business, we are now an independent company following CMA CGM Group’s acquisition of Freightliner UK’s Intermodal Logistics business in January 2026. 

Heavy Haul Rail is the UK’s next-generation rail freight partner built for a sector ready to evolve. We believe it’s time to move differently. Congested roads, rising emissions, fragile supply chains. These aren’t just logistical challenges; they’re environmental and economic wake-up calls. We’re here to lead the modal shift, helping businesses transition from road to rail with confidence, clarity, and measurable impact.  

We move 17 million tonnes of freight a year for customers in the industrial, energy and construction markets.  The company operates 95 locomotives and over 1000 wagons.  Heavy Haul Rail’s team of 950 supports customer deliveries to over 100 locations across the UK, running 250 trains per week. 

Heavy Haul Rail also supports the renewal and maintenance of the rail infrastructure and supports passenger train operators and rolling stock companies, including the provision of drivers and route conducting services. 

But none of this happens without us, its people. 

Purpose of the Role 

The Cyber Security Analyst is a technically focused, operational security role that combines elements of cyber security, network security and systems administration. The role supports the IT Systems Manager in ensuring that Freightliner IT services protect the confidentiality, integrity and availability of systems and data, while meeting recognised good-practice principles and applicable regulatory requirements. 

The post holder is responsible for overseeing the monitoring, investigating, supporting and improving operational cyber security controls across the Freightliner estate. The role works closely with infrastructure, applications, service delivery, project and business teams, as well as approved third parties and wider group IT functions. 

Main Duties and Responsibilities 

Security operations and incident response 

  • Perform day-to-day monitoring and proactive management of cyber security systems, alerts and associated components. 

  • Triage, investigate and coordinate the resolution of security incidents, escalating material risks in line with the incident and major incident processes. 

  • Act as a central point of contact for operational cyber security activity and provide clear updates to technical teams, stakeholders and management. 

  • Maintain appropriate incident records, evidence, lessons learned and follow-up actions. 

Security platforms and technical controls 

  • Configure, maintain and support security controls across the Freightliner estate, including firewalls, secure web gateways/content filtering, endpoint protection, VPN and remote access, email security, identity and access controls, vulnerability management and security monitoring platforms. 

  • Support secure configuration, operational health, tuning and lifecycle management of security technologies across on-premises, cloud and SaaS environments. 

  • Plan, test and implement upgrades and service improvements to existing cyber security services and associated infrastructure. 

  • Use scripting and automation where appropriate to improve consistency, response times, reporting and operational efficiency. 

Vulnerability, assurance and compliance 

  • Operate a continuous vulnerability assessment process, coordinate remediation with system owners and track risks through to closure or formal acceptance. 

  • Audit systems, cloud services and applications for secure configuration and alignment with approved standards and baselines. 

  • Coordinate and support annual security assessments, penetration tests, audits and assurance activities, ensuring that findings have clear owners and remediation plans. 

  • Contribute technical evidence and subject-matter support for security policies, risk assessments, compliance obligations and internal governance reporting. 

  • Support compliance, assurance and accreditation activities by collecting evidence, maintaining control documentation and coordinating remediation actions. 

  • Maintain accurate and auditable records of security controls, risks, exceptions, assessments and security-related decisions. 

  • Coordinate the alignment of security controls and processes with the NIST Cybersecurity Framework and applicable requirements under the Network and Information Systems (NIS) Regulations. 

Projects, guidance and documentation 

  • Provide practical security guidance to projects, technical teams and business application owners throughout the service lifecycle. 

  • Review proposed technical changes and designs, identify cyber security risks and recommend proportionate controls. 

  • Create and maintain technical procedures, operational runbooks, support documentation and security training or awareness materials. 

  • Build effective working relationships across IT and the wider business and liaise with suppliers or partners when required. 

Key Job Requirements 

Essential experience and knowledge 

  • Significant hands-on experience supporting complex IT, network or cyber security environments; typically gained over five years in relevant technical roles. 

  • Strong understanding of cyber security principles across infrastructure, networks, endpoints, cloud services, identity and applications. 

  • Practical knowledge of TCP/IP, firewalls, VPN technologies, DNS, DHCP, certificates and SSL/TLS. 

  • Experience with vulnerability scanning, secure configuration assessment, remediation tracking and risk-based prioritisation. 

  • Understanding of common attack techniques, security monitoring, incident response and recognised application security risks such as the OWASP Top 10. 

  • Good understanding of the NIS/NIST Cybersecurity Framework (NIST CSF) and its practical application to identifying, protecting, detecting, responding to and recovering from cyber security risks. 

  • Understanding of the Network and Information Systems (NIS) Regulations and the technical, operational and organisational measures required to support compliance. 

  • Experience working towards Cyber Essentials 

  • Ability to produce and maintain security policies, standards, procedures, control documentation and evidence for audits, assurance reviews and accreditation activities. 

  • Ability to interpret technical security information, investigate issues methodically and translate findings into clear, proportionate actions. 

  • Champions security and drives awareness throughout the company  

  • Willingness and ability to participate in ad hoc out-of-hours support where required. 

Desirable experience and qualifications 

  • Experience administering security capabilities within Microsoft Azure, Microsoft 365, Microsoft Entra ID, Microsoft Defender and/or Microsoft Sentinel. 

  • Experience of SIEM, endpoint detection and response, secure web gateway, email security, network security and privileged access technologies. 

  • Relevant current certifications such as Microsoft Security, Compliance and Identity, Azure, CompTIA Security+, CISSP, SSCP, CCNA Security or Palo Alto Networks certifications. 

  • ITIL Foundation certification or practical experience working within an IT service management framework. 

  • Experience in a regulated, safety-critical, transport, logistics or multi-site operational environment. 

  • Experience supporting NIS compliance, security audits, assurance reviews, accreditation activities or certification programmes. 

Behavioural Competencies 

  • Communicates clearly and professionally, including the ability to explain complex technical issues to non-technical colleagues. 

  • Works calmly and effectively in a fast-paced environment, including during incidents and periods of operational pressure. 

  • Prioritises work effectively, manages competing demands and delivers agreed actions to deadlines. 

  • Uses initiative, sound judgement and a structured, methodical approach to problem solving. 

  • Demonstrates strong attention to detail while maintaining awareness of wider business and operational priorities. 

  • Works collaboratively as a natural team player and encourages effective interaction across technical and business teams. 

  • Demonstrates integrity, discretion and personal accountability when handling sensitive information and security matters. 

  • Maintains a commitment to continuous learning and keeps technical knowledge current as threats and technologies evolve. 

  • Takes ownership, drives improvements and changes within the security field throughout the business  

Why Join Us? 

Here, you’re not one small part of a big machine. You’re a key contributor with national significance and real-world impact. We want our colleagues to feel proud of the work they do, connected to our mission and empowered to shape the future of this business. As part of Heavy Haul Rail, you can expect: 

  • Purpose that matters. Your work contributes to a cleaner, more efficient freight industry. 

  • Opportunity to shape what’s next. We’re new, agile and ready to do things differently, your ideas help build our future. 

  • A team that moves forward together. Collaboration, respect and shared ambition define how we work. 

  • A commitment to excellence. We deliver with pride, precision and professionalism. 

  • Room to grow. Your development fuels our momentum. 

Our perks and benefits 

Our people are our most important asset. We strive to empower our employees, ensuring they are trained and competent, fit for work, always informed, and completely engaged in our culture that places safety and wellbeing firmly at the heart of everything we do.  

We are looking for the most committed and reliable individuals who possess the knowledge, skills and experience needed for their roles. In return we can offer considerable career progression, and a rewarding career in an award-winning team alongside:  

  • Competitive pay 

  • Fantastic final-salary pension scheme after an initial qualifying period  

  • Enhanced maternity & paternity pay 

  • Opportunities for ongoing training and development. 

  • Access to the company's life assurance scheme  

  • A range of benefits to make your own so you can get the most of your work and home life which will also help save you money and hassle. From reimbursement on health treatments, to savings on new cars. 

 

We know where we’re heading. We know why it matters. Now, it’s time to move, to make it real, together. 

For queries contact careers@heavyhaulrail.co.uk 

 

Shaping tomorrow. Starting today  

The future we want to build won’t happen on its own, we have to move it forward, together. Heavy Haul Rail has the purpose, the ambition and the opportunity to reshape how Britain moves. Whatever our roles, we are collaborators, creators and custodians of a better future. This journey starts with what we choose to do today, tomorrow and every day after that. 

Our values are: 

  • Make Every Mile Matter: We act with intention and responsibility, knowing our work shapes a cleaner, stronger future for the UK. 

  • Build Boldly: We use our entrepreneurial spirit to challenge legacy thinking and design better ways forward, for our customers, our industry and each other. 

  • We move as one: We collaborate with trust, respect and shared momentum, because progress is a team sport. 

  • Deliver with certainty: We stand behind our work. We’re reliable, precise and accountable in everything we do. 

  • Fuelling The Future: We invest in our people and our potential, championing learning, curiosity and continuous improvement. with confidence, clarity, and measurable impact.

Company

Gandwukeurope
Southampton, United Kingdom

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Gandwukeurope's careers site·first seen 22 Sept 2026·last verified 22 Sept 2026·How we source jobs

Similar jobs

  • Cyber Security Analyst at MotorwayLondon, United Kingdom–match not yet calculated
  • Digital Forensics & Incident Response Analyst at MaerskMaidenhead, United Kingdom–match not yet calculated
  • Security Analyst - Up to £450 per day at Cloud Bridge Tech RecruitmentLondon, United Kingdom–match not yet calculated
  • SOC Reporter at EurofinsWarrington, United Kingdom–match not yet calculated
  • Information Security Analyst at g-massLondon, United Kingdom–match not yet calculated

Browse more jobs

  • Security Analyst jobs in United Kingdom
  • Security Engineer jobs in United Kingdom
  • Penetration Tester jobs in United Kingdom
  • Cloud Security Engineer jobs in United Kingdom
  • Security Analyst jobs in United States
  • Security Analyst jobs in India