Information Security Analyst

Posted 7 Days Ago
Be an Early Applicant
Nottingham, Nottinghamshire, England, GBR
In-Office
Mid level
Analytics
The Role
Hands-on security operations role: lead monitoring, triage, and incident response with an external SOC/MDR. Maintain CSPM/SAST/DAST tooling, manage vulnerability and penetration testing programs, perform internal security audits and ISO 27001 risk assessments, and produce findings, risk registers, and audit-ready reports.
Summary Generated by Built In

The role

This is a hands-on security operations role. You will be the primary practitioner resource within a small, specialist Cyber Security team of three, including the VP, responsible for day-to-day security monitoring, vulnerability management, incident response, and internal audit activity that keeps our security posture credible and improving. Hands-on delivery is the core expectation; this is not a governance or oversight position.

You will work closely with an external SOC and MDR provider, acting as the internal security practitioner against their outputs. The role also requires genuine compliance capability, you will contribute to internal audit and risk assessment cycles and support ISO 27001 compliance activity. You will provide ad-hoc expert input to the IT function where security judgement is needed, but this is not an IT role.

ONYX is a critical infrastructure business manufacturing IIoT devices for wind turbine monitoring. We operate globally, with customers and regulatory obligations spanning the EU, UK, US, Australia, Canada, India, and South Korea. Our Cyber Security function is small, expert, and operationally engaged, this role sits at the centre of that.

What you will be doing

  • Operating as the primary hands-on resource for security monitoring, triage, and incident response, working with the external SOC and MDR provider
  • Operating and maintaining security tooling, including CSPM, SAST, and DAST platforms, ensuring coverage, configuration, and outputs are maintained to a defined standard
  • Managing the vulnerability management programme, including coordination of internal and external penetration testing
  • Conducting internal security audits and risk assessments, producing findings reports and tracking remediation
  • Supporting ISO 27001 compliance activity, including contributing to control evidence and audit cycles
  • Producing clear written outputs -- findings reports, risk registers, policy updates -- to a good standard suitable for internal and external audit

What we are looking for

Essential:

  • 3-5 years of hands-on experience in an information security operations role
  • Practical experience operating and maintaining security tooling, including CSPM, SAST, and DAST platforms
  • Practical experience contributing to internal audits and risk assessments against ISO 27001 or a comparable framework (NIST CSF, SOC 2, Cyber Essentials Plus)
  • Experience working with external SOC or MDR providers
  • Strong written communication; able to produce findings reports and risk register entries to a good standard
  • Able to operate hands-on and independently in a small team

Desirable:

  • Experience in a regulated industry, particularly critical infrastructure, energy, or manufacturing
  • Familiarity with IEC 62443 or the EU Cyber Resilience Act
  • Relevant certification: CISSP, CISM, or equivalent; ISO 27001 Lead Auditor working towards or held
  • Experience with cloud security, particularly AWS

About ONYX

ONYX Insight is a growing technology and engineering organisation in the renewable energy sector. Our vision is to build a more efficient future by becoming the world's most innovative provider of predictive technology solutions. Our advanced sensing, software and analytics combined with our engineering experience are deployed on wind turbines around the world to maximise production and make turbines more reliable for longer, optimising energy production and supporting the global transition to renewable energy.

ONYX Insight is part of the Macquarie Group. Macquarie is a global financial services group operating in 34 markets in asset management, leasing and asset financing, market access, commodity trading, renewables development, specialist advisory services, capital raising and principal investment. The diversity of the Macquarie Group operations combined with a strong capital position and robust risk management framework has contributed to a 54 year-record of unbroken profitability.

For any further information, or to understand our products and services better, please feel free to look through our website: ONYX Insight Website

ONYX Insight are an equal opportunity employer and value diversity at our company. We do not discriminate based on race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Skills Required

  • 3-5 years hands-on experience in an information security operations role
  • Practical experience operating and maintaining security tooling, including CSPM, SAST, and DAST platforms
  • Practical experience contributing to internal audits and risk assessments against ISO 27001 or comparable frameworks (NIST CSF, SOC 2, Cyber Essentials Plus)
  • Experience working with external SOC or MDR providers
  • Strong written communication; able to produce findings reports and risk register entries suitable for audit
  • Able to operate hands-on and independently in a small team
  • Experience in a regulated industry, particularly critical infrastructure, energy, or manufacturing
  • Familiarity with IEC 62443 or the EU Cyber Resilience Act
  • Relevant certification: CISSP, CISM, or equivalent; ISO 27001 Lead Auditor working towards or held
  • Experience with cloud security, particularly AWS
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Nottingham
146 Employees
Year Founded: 2016

What We Do

We bring sensing, analytics and engineering together. Part of the bp family since 2017, ONYX Insight is an award-winning global, renewable, technology business. We bring unbiased predictive analytics underpinned by real-world engineering expertise to owners and operators of renewable energy assets via 7 global offices and 10 patents. We provide industry leading predictive analytics and wind turbine monitoring services underpinned by strong engineering expertise. Our solutions deliver increased energy production and reduced operations & maintenance costs, enabling wind turbine operators to minimise unplanned downtime and maximise investment returns.

Similar Jobs

Mastercard Logo Mastercard

Operations Analyst

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
London, Greater London, England, GBR
38800 Employees

bet365 Logo bet365

Information Security Analyst, Vulnerability Management

Digital Media • Gaming • Software • Esports • Automation
Hybrid
Manchester, Greater Manchester, England, GBR
10000 Employees

bet365 Logo bet365

Information Security Analyst, Vulnerability Management

Digital Media • Gaming • Software • Esports • Automation
Hybrid
Stoke-on-Trent, Staffordshire, England, GBR
10000 Employees
Hybrid
Bristol, England, GBR
736 Employees

Similar Companies Hiring

Northslope Thumbnail
Artificial Intelligence • Information Technology • Software • Analytics • Consulting • Generative AI
London, GB
100 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account