Description
The IT Security Analyst will play a key role in strengthening Multimatic's security posture by managing vulnerability and threat management activities, supporting security operations, and leading remediation efforts across infrastructure and applications.
This role will work closely with the Manager, IT Security Operations, and broader IT teams to implement security controls, respond to incidents, and drive continuous improvements in the organisation's cybersecurity capabilities.
Key Responsibilities
Vulnerability & Threat Management
- Manage the full lifecycle of vulnerabilities, from identification to remediation and validation
- Recommend and track remediation actions from application and infrastructure security testing
- Continuously monitor CVSS databases and external threat intelligence sources
- Perform threat analysis, vulnerability assessments, and risk prioritization based on exposure and attack surface
- Maintain and enhance a formal Threat and Vulnerability Management Program
- Support and maintain an accurate CMDB / asset inventory
Security Operations & Incident Response
- Participate in and support incident detection, investigation, and response activities
- Analyze security alerts from SIEM, EDR, and other security tools
- Perform regular security assessments on assigned systems and environments
- Contribute to attack surface reduction efforts across infrastructure and applications
Security Engineering & Architecture
- Implement and manage preventive and detective security controls/tools
- Design and enhance secure architectures across infrastructure, platforms, and applications
- Support deployment and optimization of:
- SIEM
- Endpoint Detection & Response (EDR)
- Data Loss Prevention (DLP)
- Network security controls (IDS/IPS, firewalls)
- Collaborate with development and engineering teams to embed security into system design
Patch & Risk Management
- Enhance patching standards and processes across all assets:
- Operating systems, applications, mobile devices, network systems
- Conduct risk assessments and document findings in the risk register
- Provide regular reporting on vulnerabilities, remediation status, and risk posture
Collaboration & Governance
- Work closely with IT and security teams to understand data flows and system dependencies
- Partner with stakeholders to prioritize remediation actions
- Lead or contribute to security projects from design through deployment
- Ensure compliance with industry standards, internal policies, and customer requirements
Reporting & Intelligence
- Deliver regular reports on vulnerability trends, risks, and remediation progress
- Track evolving threat landscape and provide actionable intelligence
- Support development of a security intelligence capability
Qualifications Required
- 5+ years of experience in IT Security or Security Operations
- Strong experience in:
- Vulnerability management and threat analysis
- Network, OS, and application security
- Security tools (SIEM, EDR, IDS/IPS, DLP)
- Hands-on experience with:
- Vulnerability scanning and penetration testing tools
- Threat hunting and attack methodologies
- Strong knowledge of:
- TCP/IP and protocols (HTTP, HTTPS, SMTP, FTP, SNMP)
- Experience in incident response and security operations
- Proven ability to analyze security alerts and vulnerability data
- Bachelor's degree in Computer Science, MIS, or related field (or equivalent experience)
Desired Skills
- Infrastructure and server hardening
- Security architecture and design in complex environments
- Certificate and key management
- IT compliance and regulatory assessments
- Experience leading security projects and initiatives
- Strong documentation and communication skills
Certifications (Preferred)
- CISSP, SANS, or equivalent industry certifications
Key Competencies
- Strong analytical and problem-solving skills
- Ability to prioritize risks based on business impact
- Effective collaboration and stakeholder management
- Continuous learning mindset
- Leadership capability within security initiatives