Lead Information Security Analyst required to join a well-established global technology company with a strong base in Edinburgh. This is a senior role within the Information Security team, combining hands-on security engineering with technical leadership, mentoring and the opportunity to influence how security is delivered across the organisation.
You'll work closely with Security and IT teams to assess risk, design and improve security controls, and implement practical solutions across a complex technology environment. The role is broad, covering areas such as vulnerability management, identity, network security, security operations and incident response, with a strong emphasis on hands-on technical security.
Alongside your technical responsibilities, you'll act as a senior point of reference for the wider security team, helping to mentor and develop colleagues, share best practice and provide technical direction on security initiatives.
There is also an emerging focus around AI security and governance, giving you the opportunity to help shape how new technologies are introduced and secured across the business.
The Company:
This is a long standing and highly respected player in the tech space, known for developing technology used by some of the world's most recognised companies. While you won't see their name in the spotlight, their work sits behind products used by millions of people around the world. With a reputation for engineering excellence and trusted partnerships at the highest levels, this business has quietly built a global footprint while keeping a down to earth, collaborative culture.
The Role:
This is a broad security role combining technical depth with leadership and influence. You'll operate as a senior individual contributor while also helping to guide and develop others within the Information Security team.
You'll work with infrastructure, engineering and security teams to understand the organisation's risk landscape and help design secure solutions that support the wider technology roadmap. This could involve reviewing architectures and configurations, improving security controls, assessing vulnerabilities or helping teams build security into new systems and services.
The role also has a strong operational element. You'll be involved in the evaluation and administration of enterprise security tooling across areas such as endpoint security, vulnerability management, logging and SIEM, as well as supporting detection, investigation and incident response when required.
You'll need to be comfortable moving between technical detail and wider business conversations, explaining security risks clearly and helping stakeholders understand the practical steps required to address them.
There is also an opportunity to contribute to the organisation's approach to AI security, including the risks associated with adopting AI technologies and how security monitoring, detection and response capabilities can evolve alongside them.
The environment is varied, covering enterprise technology, cloud, on-premise infrastructure, applications and research environments. It's therefore a role that should suit someone who enjoys solving different types of security problems and working across a broad technology landscape.
Key Responsibilities:
** Provide technical leadership across a broad range of Information Security and security engineering activities.
** Mentor and support other members of the Information Security team, sharing knowledge, best practice and technical expertise.
** Work closely with Security, IT and Engineering teams to identify security risks and improve the organisation's overall security posture.
** Assess and design secure infrastructure, architectures and processes in line with business and technology requirements.
** Develop and implement practical security requirements, controls, policies and procedures.
** Evaluate security controls and configurations across cloud, on-premise, hybrid, application environments
** Lead or contribute to vulnerability management, security assessments and risk-based remediation activity.
** Support detection and incident response activities, including investigation, containment and remediation.
** Evaluate, implement and administer enterprise security technologies across areas such as endpoint protection, vulnerability management and SIEM/logging.
** Work with infrastructure teams to embed security into new systems, services and technology initiatives.
** Contribute to threat-driven security initiatives and improvements to the organisation's monitoring and response capabilities.
** Help develop the organisation's approach to AI security, including policy, risk assessment and appropriate monitoring and controls.
** Produce clear reporting around security findings, risks, remediation and overall security posture for technical and senior stakeholders.
** Act as a senior security advisor to teams across the wider organisation, balancing security requirements with practical business needs.
Key Skills & Background:
** Significant experience across multiple areas of cybersecurity, ideally including security engineering, vulnerability management, incident response, IAM, network security and security operations.
** Strong hands-on experience designing and implementing secure solutions within a complex enterprise environment.
** Experience working closely with teams to improve security controls and configurations.
** Good knowledge of enterprise security tooling, particularly endpoint protection, vulnerability management and logging/SIEM platforms.
** Experience contributing to or leading incident response, security investigations and threat-driven security activity.
** Understanding of security risk and the ability to balance security requirements with wider business and technology priorities.
** Experience or understanding of AI security and governance would be advantageous.
** Knowledge of security frameworks including NIST CSF and ISO 27000, with an understanding of risk methodologies such as FAIR.
** Strong communication skills, with the ability to explain technical security issues clearly to both technical and non-technical stakeholders.
** Comfortable operating independently as a senior individual contributor while working collaboratively with globally distributed teams.
** Relevant certifications such as CISSP, SSCP or GCIA would be beneficial, but are not essential.
The company boasts one of the best offices in Edinburgh City Centre, offering a stunning, modern workspace that perfectly complements its dynamic and innovative culture. The office is equipped with great amenities, creating an environment that's not only comfortable but also designed to inspire collaboration and creativity.
This is a hybrid role, with a minimum of two days per week in the Edinburgh office. On top of this, the company offers a very competitive salary and a great benefits package including bonus and share scheme.
This is an opportunity to join a global technology business where Information Security is an important part of how the organisation operates. You'll have the scope to work across a broad range of security challenges, provide technical leadership to the wider team and influence how technology is secured across a global environment.
If this sounds of interest, please apply or reach out to Murray Simpson.
Cathcart Technology is acting as an Employment Agency in relation to this vacancy.
We can help you prepare interviews and offer some great tips to help candidates get the best possible start.
Process
Before we assess a candidate and put them forward, we’ll do a phone interview to get a better understanding of the type you’re looking for, your goals and plans.
Preparation
We know exacly what employers are looking, especially our clients, because they told us. We can help you prepare for the interview and shape up for meeting their team.
Branding
Personal branding is a term you may or may not be familiar with. In our connected world, it pays to be fully prepared for what happens when employees search your name.