Information Security Analyst
The Information Security Analyst plays a key role in delivering the organisation's information security roadmap by combining technical expertise with cross-functional collaboration. This role is responsible for supporting day-to-day security operations, including security monitoring, threat detection, incident response, and the continuous improvement of security processes and capabilities.
Working in a dynamic and fast-paced environment, the analyst serves as a security subject matter expert, providing technical guidance, consultancy, and security advice to projects and business stakeholders. Leveraging experience in Information Security, the analyst proactively identifies threats, enhances detection capabilities, and helps strengthen the organisation's overall security posture while ensuring the consistent delivery of security services. The role blends hands-on technical responsibilities with business engagement, including supporting security initiatives, developing and optimising monitoring and detection capabilities, participating in incident response activities, and collaborating closely with teams across Security Architecture, Governance, Risk & Compliance (GRC), Security Engineering, and IT to implement and maintain effective security controls.
- Partner with technical and project teams to gather operational security requirements and ensure security is embedded throughout delivery.
- Support the implementation, operation, and continuous improvement of security monitoring, logging, and alerting capabilities.
- Develop, tune, and maintain detection rules and use cases to improve threat visibility while reducing false positives.
- Collaborate with Delivery, Product, and Planning teams to help shape security priorities and contribute to the security roadmap.
- Support the vulnerability management lifecycle by validating findings, assisting with remediation prioritisation, and verifying remediation activities.
- Perform proactive threat hunting across endpoint, identity, cloud, and network telemetry to identify emerging threats before they trigger alerts.
- Deploy, maintain, and optimise Web Application Firewall (WAF) policies, investigating web-based attacks and enhancing application protection.
- Investigate security events across endpoints, identities, networks, cloud platforms, and applications using EDR/XDR, SIEM, and cloud-native security tools.
- Monitor and investigate security events across AWS environments, supporting the organisation's cloud security operations.
- Identify opportunities to automate repetitive security processes and contribute to the development of SOAR playbooks and security automation initiatives.
- Participate in all phases of the incident response lifecycle, including detection, analysis, containment, eradication, recovery, and post-incident reviews.
- Produce high-quality technical documentation, incident reports, and lessons learned to drive continuous improvement.
- Collaborate with Product Owners, Delivery teams, and business stakeholders to define operational security requirements.
- Contribute to the development and continuous improvement of operational processes, playbooks, and standard operating procedures.
- Assess the effectiveness and coverage of logging, monitoring, alerting, and detection capabilities, identifying opportunities for enhancement.
- Work closely with Security Architecture, Security Engineering, and Governance, Risk & Compliance (GRC) teams to strengthen enterprise-wide security capabilities.
- Consume and analyse threat intelligence, translating relevant intelligence into actionable detections, hunting activities, and preventive controls.
- Participate in security reviews for new technologies, projects, and services, providing operational security recommendations.
- Support the development of operational metrics, reporting, and dashboards to measure the effectiveness of monitoring, detection, and incident response capabilities.
- Hands-on experience working within Information Security Operations. (required)
- Practical experience supporting Security Operations Centre (SOC) and Incident Response functions. (required)
- Experience administering, tuning, and maintaining Web Application Firewall (WAF) technologies. (required)
- Experience investigating and responding to security incidents using established incident response methodologies. (required)
- Proven experience performing proactive threat hunting using SIEM, EDR/XDR, cloud, and identity telemetry. (required)
- Experience working with enterprise SIEM platforms such as Splunk. (required)
- Experience with Microsoft Defender for Endpoint or equivalent Endpoint Detection and Response (EDR/XDR) technologies. (required)
- Experience monitoring and investigating security events within AWS environments. (required)
- Strong understanding of security monitoring, detection engineering, and alert optimisation. (required)
- Experience writing and troubleshooting SIEM queries using SPL, KQL, or equivalent query languages. (required)
- Experience analysing logs from endpoint, identity, network, cloud, and application sources. (required)
- Good understanding of identity and access security, including Microsoft Entra ID and Active Directory. (required)
- Strong knowledge of common attack techniques, adversary behaviours, and the MITRE ATT&CK framework. (required)
- Solid understanding of networking fundamentals, including DNS, HTTP/S, TLS, and authentication protocols. (required)
- Familiarity with email security technologies including SPF, DKIM, and DMARC. (required)
- Understanding of security methodologies, industry best practices, and recognised frameworks. (required)
- Knowledge of security and risk frameworks such as NIST 800 and ISO 27001. (required)
- Strong communication skills with the ability to engage effectively with both technical and non-technical stakeholders. (required)
- An understanding of how business priorities, regulatory requirements, and technical constraints influence cybersecurity decisions. (required)
- Experience with SOAR platforms and security orchestration or automation. (nice-to-have)
- Scripting or automation experience using PowerShell, Python, or similar languages. (nice-to-have)
- Experience modelling threats and risks and recommending appropriate security controls. (nice-to-have)
- Experience working in regulated, critical, or highly available operational environments. (nice-to-have)
- Exposure to Infrastructure as Code (Terraform), DevSecOps practices, or cloud-native security tooling. (nice-to-have)
- Experience working with Threat Intelligence Platforms (TIPs) and malware analysis tools. (nice-to-have)
- Industry certifications such as CompTIA Security+, Microsoft SC-200, GCIH, GCIA, or equivalent. (preferred)
- Hybrid work model
- Free parking in the building + free electric car charging
- Broad collective health insurance (with options for family members and extensions)
- Birthday gift + day off during your birthday month
- Refer a friend - bonus or gift card
- HitechZone membership
- Gifts on holidays and life events
- Ten Bis
888 is one of the world's leading online betting and gaming brands, operated by the London-listed group Evoke plc (formerly 888 Holdings). Founded in 1997, the business runs the 888casino, 888poker and 888sport brands and, after acquiring William Hill's international operations in 2022, became part of one of the largest online gambling groups in the world. It is headquartered in Gibraltar, with major operational hubs in Leeds, London, Malta, Bucharest, Sofia and Tel Aviv. The company develops much of its own gaming technology and operates across regulated markets in the UK, Europe, the Americas and Africa.
