高级网络安全分析师
Senior Cyber Security Analyst
关于 ENSEK
ENSEK 构建云原生 SaaS 软件,正在改变能源零售商的运营、创新和规模化管理方式。
我们帮助零售商降低运营成本,提高消费者计费准确性,并通过自动化和人工智能驱动的洞察力提升客户体验,所有这些都建立在现代云原生架构之上。
ENSEK 正处于一个令人兴奋的转折点,我们正快速扩展,迈向新的国际领域。如果你热衷于解决复杂的真实世界问题,并希望构建加速全球能源转型的现代技术,你将在我们这里感到如鱼得水。
职位简介
作为高级网络安全分析师,你将在安全运营中担任技术权威,负责设计、开发和持续改进我们的检测与响应能力。
你将主导重大安全事件的响应,推动基于威胁的检测工程,影响安全架构决策,并与安全、工程和平台团队的同事紧密合作,确保 ENSEK 在不断演变的威胁面前保持韧性。
这个职位结合了实际的技术专长与领导责任,提供指导初级分析师的机会,同时为公司整体的安全战略计划做出贡献。
主要职责:
- 通过管理高严重性安全事件的全流程,协调遏制和恢复活动,进行事后审查,并在 P1/P2 事件中担任高级技术负责人,主导安全事件响应。
- 通过设计、开发和优化 SIEM 检测,维护 MITRE ATT&CK 覆盖范围,提高检测效果,识别 ENSEK 安全监控环境中的漏洞,负责检测与响应能力。
- 通过与威胁与漏洞团队合作,实现威胁情报的运作,支持漏洞管理活动,并确保安全运营与 ENSEK 不断变化的威胁态势保持一致,推动基于威胁的安全运营。
- 通过开发操作手册、自动化响应工作流、警报增强功能和工具集成,提高安全自动化和运营效率,减少分析员的工作量并加快响应速度。
- 通过作为安全运营的主要升级点,指导分析师,支持威胁建模活动,并提供安全领导力和保障。
查看英文原文
About ENSEK
ENSEK builds the cloud‑native SaaS software that’s transforming how energy retailers operate, innovate and manage at scale.
We help retailers lower operating costs, improve billing accuracy for consumers, and enhance customer experience through automation and AI‑driven insight, all underpinned by modern, cloud‑native architecture.
ENSEK is at an exciting inflection point as we scale at pace towards new international horizons. If you’re driven by solving complex, real‑world problems and want to build modern technology that accelerates the global energy transition, you’ll feel right at home with us.
About the role
As a Senior Cyber Security Analyst, you'll act as a technical authority within Security Operations, owning the design, development and continuous improvement of our detection and response capabilities.
You'll lead the response to major security incidents, drive threat-informed detection engineering, influence security architecture decisions, and work closely with colleagues across Security, Engineering and Platform teams to ensure ENSEK remains resilient against evolving threats.
This role combines hands-on technical expertise with leadership responsibilities, offering the opportunity to mentor junior analysts while contributing to strategic security initiatives across the business.
Key responsibilities:
- Lead Security Incident Response by managing high-severity security incidents end-to-end, coordinating containment and recovery activities, conducting post-incident reviews, and acting as the senior technical lead during P1/P2 events.
- Own Detection & Response Capability through the design, development and optimisation of SIEM detections, maintaining MITRE ATT&CK coverage, improving detection effectiveness, and identifying gaps across ENSEK's security monitoring landscape.
- Drive Threat-Informed Security Operations by partnering with Threat & Vulnerability teams to operationalise threat intelligence, support vulnerability management activities, and ensure security operations remain aligned to ENSEK's evolving threat profile.
- Enhance Security Automation & Operational Efficiency through the development of playbooks, automated response workflows, alert enrichment capabilities, and tool integrations that reduce analyst effort and improve response times.
- Provide Security Leadership & Assurance by acting as the primary escalation point for Security Operations, mentoring analysts, supporting threat modelling activities, and providing security input into architectural and engineering decisions.
- Deliver Security Reporting & Compliance Support by owning operational metrics and performance reporting, communicating risk to stakeholders, and contributing evidence and control monitoring activities supporting ISO 27001, SOC 2 and NIS2 compliance requirements.
Key outcomes:
- Maintain an effective detection and response capability, continuously improving SIEM coverage, reducing false positives, and identifying gaps through MITRE ATT&CK aligned monitoring.
- Lead the successful resolution of security incidents, ensuring timely containment, clear stakeholder communication, thorough post-incident reviews, and implementation of lessons learned.
- Strengthen ENSEK's security posture by operationalising threat intelligence, supporting vulnerability remediation activities, and proactively identifying emerging risks.
- Improve operational efficiency through the development of security automation, response playbooks and workflow enhancements that reduce manual effort and accelerate investigation and response times.
- Increase security maturity across the organisation by providing security assurance to projects, supporting threat modelling activities, and embedding security monitoring requirements into new services and platforms.
- Contribute to a high-performing Security Operations function by mentoring analysts, delivering meaningful operational reporting, and supporting compliance obligations including ISO 27001, SOC 2 and NIS2.
Experience required:
- Proven experience operating within a Security Operations, Cyber Security Analyst, Security Engineer or Incident Response role, with responsibility for leading complex security investigations and major incident response activities.
- Strong hands-on experience with SIEM platforms, including detection engineering, alert tuning, correlation rule development, coverage mapping, and the continuous improvement of monitoring capabilities.
- Demonstrable experience leading security incidents from initial triage through to containment, recovery and post-incident review, including stakeholder management during high-severity events.
- Practical experience applying the MITRE ATT&CK framework to detection engineering, threat hunting, investigations, threat modelling, or security control assessment.
- Experience developing or supporting security automation and orchestration workflows, including the creation of playbooks, automated response actions, and integrations between security tools.
- Experience working with cloud security technologies, endpoint detection and response (EDR/MDR) solutions, threat intelligence, and vulnerability management processes within a modern technology environment.
- Strong communication skills with the ability to translate technical security risks, threats and vulnerabilities into clear, business-focused recommendations for both technical and non-technical stakeholders.
- Experience mentoring, coaching or providing technical leadership to junior analysts, helping to develop team capability through knowledge sharing, documentation and continuous improvement initiatives.
Company Benefits
- 25 days’ holiday + bank holidays
- Option to buy or sell 5 extra annual leave days per year
- Vitality Health Insurance, including private healthcare, virtual GP access, mental‑health support and wellbeing perks (50% off gym memberships-Virgin Active, Nuffield, PureGym)
- Pensionwith5% matched contribution
- Regular team‑wide and company‑wide events
- 2 volunteering days per year to give back
- Remote‑first working environment with offices in London and Nottingham
Originally posted on Himalayas