Cyber Security Test Analyst
LET’S CUT STRAIGHT TO IT
At Severn Trent, our people are at the heart of everything we do. We’re in the top 5% of utility companies worldwide when it comes to employee engagement and ranked as a Top 50 UK Employer on Glassdoor. Join us in making a positive impact on the environment and our communities, while being valued and supported in a truly inclusive workplace.
If you want to do more, because you care, we want you on our team.
LET’S TELL YOU MORE
We’re looking to recruit a Cyber Security Test Analyst who will be responsible for systematically finding and validating any information security vulnerabilities Within Severn Trent Water. You’ll be attempting to penetrate a computer system, application or network on behalf of its owners for the purpose of finding security vulnerabilities that could be exploited by malicious hackers.
In a role as exciting as it sounds, you’ll plan, create, and deliver quality test scenarios, scripts, and execution of scripts to ensure the highest quality outputs using both manual and automated best practices. They will be responsible for providing timely and relevant updates to appropriate stakeholders and decision makers and communicate test findings to help improve the cybersecurity posture.
In this diverse and challenging role, you’ll need to use all your people and technical skills, to work under considerable pressure in a fast paced, regulated environment covering IT and Operational Technology systems across 300+ Severn Trent sites.
Key Accountabilities in the role will be:-
- Plan, create, and deliver quality test scenarios, scripts, and execution of scripts to ensure the highest quality outputs using both manual and automated best practices.
- Be responsible for providing timely and relevant updates to appropriate stakeholders and decision makers and communicate test findings and find solutions to help improve the cybersecurity posture.
- Perform reconnaissance and information collection on the target environment or attack surface. Create hypotheses for analytics and testing of threat data. Analyse data from threat and vulnerability feeds and analyse data for applicability to the organization
- Identify potential weaknesses and vulnerabilities on assets (i.e., end points, applications, API’s , devices, users). Validate weaknesses via exploitation and reports their findings.
- Validate IT security controls and business systems for cybersecurity best practices and recommend changes to enhance cyber resilience and reduce risks, where applicable. Conduct root cause analysis and investigations to advise on prevention mechanisms.
- Conduct computer forensic analysis, data recovery, eDiscovery, and other IT investigative work.
You'll be based at our Severn Trent Centre Head Office in Coventry. You’ll work within our newly formed Assurance & Testing team . With this being such a critical role, we’re looking for someone who can join us 37 hours a week, Monday to Friday.
HOW WE WORK
You'll join a caring culture that collaborates to achieve, grow, and develop. Our employee engagement scores are among the highest globally in energy and utilities. That’s why, we value in-person moments to keep our culture alive but also understand the flexibility working from home can bring. So, you'll usually find us in the office, but working from home is supported, when you need it.
WHAT WE’RE LOOKING FOR
We’ll be looking for you to have experience in cybersecurity, including a good familiarity with relevant penetration and intrusion techniques and attack vectors. A working knowledge of cloud security concepts and best practices, as well as the security features and capabilities of major cloud platforms such as Azure and AWS will stand you in good stead to succeed in the role.
Alongside this, we’ll want you to have experience with offensive tools such as: Metaspoit, BurpSuite, Kali Linux, Cobalt Strike, Mimikatz or a similar tools and have technical experience in system security vulnerabilities and remediation techniques, network, and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, etc.).
As a test analyst within Cyber Security, you’ll be expected to have knowledge of the such things as NIST, CIS controls, OWASP Top 10, ISO 27001/2, Payment Card Industry Data Security Standard (PCI-DSS) and General Data Protection Regulation (GDPR).
Skills and experience are important, but character, positivity, and a caring attitude matter too. We welcome people from all walks of life and celebrate individuality as we know diverse minds, experiences and backgrounds help us to learn and better serve our communities. We seek people who get involved, want to be part of something bigger, and make a difference because they care.
HOW WE’LL REWARD AND CARE FOR YOU IN RETURN
It's not just a job; it's a career. We offer benefits that reward great work and award-winning training to help you reach your potential. Plus, you'll contribute to the environment and community too. Here are some of our favourites:
- 28 days holiday + bank holidays (and the ability to buy/ sell up to 5 days per year). Annual leave rises to 28 days after 5 years of service.
- Annual bonus scheme (of up to £2,250 per annum based on company performance)
- Leading pension scheme – we will double your contribution (up to 15% when you contribute 7.5%)
- Family friendly policies (including, a year off fully paid maternity and adoption leave)
- Sharesave – the chance to buy Severn Trent Plc shares at a discounted rate
- Dedicated training and development with our ‘Academy’
- Electric vehicle scheme and retail offers
- Two volunteering days per year
LET’S GO
We can't wait to hear from you! Have an updated CV ready and spare five minutes to apply. We'll let you know the outcome after the closing date, so keep an eye on your phone and emails.