Job Description : Security Analyst
Safeguarding Digital Assets, Ensuring Compliance, and Promoting Security Awareness
Role Overview :
The Security Analyst is responsible for protecting organisational information systems and data assets. The role involves coordinating audits, assessing and managing risks, monitoring access controls, and supporting compliance initiatives. The Security Analyst will work closely with IT, compliance, and audit teams to maintain robust security practices and respond effectively to security incidents.
Key Responsibilities
- Coordinate internal and external audits and facilitate timely resolution of audit findings.
- Conduct regular risk assessments of applications, networks, and systems; recommend mitigation strategies.
- Review and update security policies and procedures to align with regulatory and organisational standards.
- Hands-on experience in Security Operations Centre (SOC) environments, demonstrating the ability to coordinate and follow up on SOC activities and incident escalations.
- Proficiency in Vulnerability Assessment and Penetration Testing (VAPT) coordination, including scheduling, tracking remediation, and collaborating with relevant teams to ensure timely closure of findings.
- Strong analytical skills for interpreting security data, generating actionable insights, and supporting root cause analysis of incidents.
- Monitor and analyse access controls to prevent unauthorised activities.
- Perform vulnerability assessments and manage remediation processes.
- Respond to security incidents, conduct investigations, and document incident reports.
- Oversee web application security testing and ensure adherence to secure coding practices.
- Support compliance management with respect to relevant standards and regulations.
- Deliver security awareness training and promote a culture of cybersecurity across the organisation.
- Review and report security violations, recommending corrective actions.
- Assist with the implementation and monitoring of encryption, cloud security controls, and data protection measures.
- Provide risk and compliance support to IT and business teams as required.
- Participate in security testing of applications, networks, and cloud environments.
- Stay updated on emerging threats and evolving security technologies.
Required Skills and Qualifications
Bachelor’s degree in Computer Science, Information Technology, or a related discipline.Sound knowledge of application, network, and system security principles.Experience with vulnerability management, incident response, and risk assessment.Familiarity with web application security and cloud security controls.Understanding of encryption methods and secure data handling.Experience supporting compliance programs (e.g., ISO27001, ITIL).Ability to review and update security policies and procedures.Strong communication skills to deliver security training and awareness programs.Analytical thinking and attention to detail.Relevant certifications such as CISSP, CISM, CEH, or equivalent (preferred).Desired Experience
Minimum 5 years of experience in information security, cybersecurity, or a related field.Exposure to regulatory standards and compliance frameworks (ISO27001, ITIL).Hands-on experience with security tools for monitoring, testing, and incident management.Experience working in multi-disciplinary teams and supporting audit processes.