Senior Attack Surface Remediation Analyst

  • Santander UK
  • Milton Keynes, UK
  • Sep 10, 2024
Full Time

Job Description

Senior Attack Surface Remediation Analyst

Country: United Kingdom

Interested in part-time, job-share or flexible working? We want to talk to you!

Join our community.

We are looking for an enthusiastic person that has a firm grasp on vulnerability basics, experience with vulnerability management tools and their implementation, as well as an eye for detail and structure.

You will play a critical role in proactively identifying and mitigating potential security risks and vulnerabilities in systems, applications, and networks, to prevent unauthorized access, data breaches, and other security incidents.

The difference you’ll make:

  • Managing deliverables which are closely coordinated with and integrated across all UK CISO functions for strategy development, continuous learning and awareness
  • Delivering solutions to reduce the attack surface of UK assets from analysis of cyber metrics
  • Reporting of detailed findings, exploitation procedures and mitigation techniques and to effectively communicate with stakeholders
  • Providing regular updates to stakeholders at all levels
  • Ensuring continuous operations for core capabilities: threat identification and monitoring, vulnerability lifecycle, critical vulnerability triage and risk reporting
  • Analysing cyber metrics to identify, prioritise and remediate root cause to reduce attack surface

What you’ll bring:

  • Ability to design and execute scenario-based tests tailored to the firm’s infrastructure and practices
  • Project management (technical) experience preferably within cyber security
  • Experience in application vulnerability assessment and management, able to accurately assess the potential impacts of security flaws and involve technical teams accordingly
  • Understanding of vulnerability analysis in the context of the most common infrastructure models (on-prem DC infrastructure & DMZ, cloud IaaS/PaaS, Enterprise SaaS)
  • Ability to manage external service providers and internal customers in the context of a high-pressure environment towards positive security outcomes
  • Knowledge of common vulnerabilities and exposures (CVEs), common attack vectors, and security best practices

It would also be nice for you to have:

  • Enterprise solutions architecture practitioner, aware of best practice patterns, deviations, and compensatory controls
  • Relevant industry certifications highly desirable e.g. ISACA, (ISC)², GIAC etc or equivelent
  • Understanding of security configuration baselines to comply with CIS Benchmarks and similar requirements
  • Stay up-to-date with the latest trends and developments in the field of cybersecurity, specifically related to attack surface reduction techniques

What else you need to know:

This role is based in Milton Keynes.

We want our people to thrive at work and home, and also be able to deliver the best outcomes for our customers and to help each other develop. To support this, we offer site-based contracts with a hybrid working pattern and our expected level of attendance in an office is at least 12 days per month (pro-rata for part-time roles).

If you apply for this role in this location, it’s important you consider your travelling distance, time and cost from your home to the office location.

We’re happy to discuss specific working patterns and arrangement within this hybrid approach during the recruitment process.

If you’re interested in this role but with part time hours or a job-share we would still love to hear from you and discuss these.

Application process

If your application is successful a member of our recruitment team will be in touch. We will arrange a short call with you to learn more about you and what you are looking for from your next career move, as well as answer any questions you have about working in the Santander tech team. If both sides agree we will send your CV to the hiring manager to review. For this position, the interview process will be :–

1st Stage – Technical Interview – this will a 30min technical interview with one of the team

2nd Stage – A one-hour formal interview where we will ask both technical and competency-based questions. This can be done virtually or face to face depending on your situation

If there’s anything we can do in the recruitment process to help you achieve your best, please let us know.

Inclusion

At Santander we’re creating a thriving workplace where all colleagues feel they belong and are supported to succeed.  We all help to make Santander a workplace that celebrates diversity and attracts, retains and develops the most talented and committed people through living our values of Simple, Personal, and Fair.

How we’ll reward you.

As well as a competitive salary, you’ll enjoy a benefits package that you can tailor to your needs.

  • Eligible for a discretionary performance-related annual bonus
  • We put 8% of salary into your pension, even if you don’t contribute yourself. We’ll pay in up to 12.5% of salary, if you contribute as well, and you can take some of our contribution in cash if you prefer
  • 30 days’ holiday plus bank holidays, which increases to 31 days after 5yrs service, with the option to purchase up to 5 contractual days per year
  • £6,000 car allowance per year
  • Company funded individual private medical insurance
  • Voluntary healthcare benefits at discounted rates such as private medical insurance for your family, dental insurance, and health assessments
  • Protection for you and your family, with company-funded death-in-service benefit and income protection insurance, and the option to take advantage of discounted rates for additional life assurance and critical illness cover
  • Share in Santander’s success by saving or investing in our share plans 
  • As a Santander UK employee, you are able to request staff versions of our products like our Edge Current Accounts and Credit Cards with no fees, as well as apply to many other deals and discounts in Santander products and services

Learn more about our benefits and family friendly policies

What to do next:-

If this sounds like a role you’re interested in, then please apply.

If there’s anything we can do in the recruitment process to help you achieve your best, get in touch. Whether it’s a copy of our application form in another format or additional assistance, we’re available through telephone, email, or face to face. You can contact us at [email protected] or call 0870 414 9080.