Overview
IT Security Analyst – Monument Place
At GTR, cybersecurity sits at the core of how we protect our people, platforms, and customers. As an IT Security Analyst, you’ll play a hands-on role in strengthening our security posture—supporting daily security operations while helping shape resilient, compliant, and future-ready systems. This is a role for someone who enjoys solving problems, responding to real threats, and continuously improving how security is delivered across the organisation.
What you’ll be doing
-
Detecting & responding to threats
Monitor security platforms to identify, analyse, and contain suspicious activity, determine root causes, and drive continuous improvement. -
Investigating incidents & hunting threats
Perform in-depth incident analysis and proactive threat hunting to stay ahead of emerging risks. -
Managing vulnerabilities
Conduct vulnerability scans and web application assessments, track remediation, and validate fixes. -
Reducing security risk
Review systems and infrastructure for security gaps and define clear remediation strategies. -
Improving security operations
Onboard log sources into SOC/SIEM tools, validate alerts, and refine detection capabilities. -
Driving best practices & compliance
Support alignment with CIS Benchmarks, ISO27001, and NCSC Cyber Essentials. -
Collaborating across teams
Work closely with IT, engineering, and the wider business to embed security-by-design and share knowledge. -
Maintaining operational excellence
Manage incident tickets, support ITIL-based problem management, and keep security documentation accurate and up to date. -
Automating where possible
Contribute to scripting and automation initiatives to improve efficiency and consistency.
What you’ll bring
-
Hands-on cybersecurity experience
Proven background in technical security roles, including incident response, monitoring, and risk management. -
Strong analytical & prioritisation skills
Ability to assess risk, triage incidents effectively, and resolve issues in high-pressure situations. -
Clear communication
Confidence explaining technical security concepts to non-technical stakeholders at all levels. -
Framework & standards knowledge
Familiarity with MITRE ATT&CK, NIST/NIS-R, ISO standards, and security best practices. -
Technical breadth
Experience across Microsoft platforms, identity and access management, endpoint protection, and cloud security. -
A security-first mindset
Curiosity about emerging threats, a commitment to continuous learning, and a proactive approach to improving security posture. -
Relevant certifications (desirable)
CySA+, CISSP, Microsoft certifications, ITIL v4, or similar.
IMPORTANT: Before applying for this role, please make sure you have the right to work in the country where the role is based. Unless it clearly stipulates within in the job advert above that the hiring company is looking to or able to sponsor applicants it is deemed that the hiring employer will only consider applications from those able to comply with and work in the country where the role is based.













