ENSEK Logo

ENSEK

Senior Cyber Security Analyst

Posted 22 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United Kingdom
Senior level
Remote
Hiring Remotely in United Kingdom
Senior level
Leads security operations by managing major incidents, engineering SIEM detections, applying MITRE ATT&CK, developing automated response workflows, and improving threat-informed monitoring. Partners with engineering and platform teams on cloud security, vulnerability management, threat modeling, and security architecture. Provides technical leadership, mentors analysts, reports operational metrics, and supports ISO 27001, SOC 2, and NIS2 compliance.
The summary above was generated by AI

About ENSEK
ENSEK builds the cloud‑native SaaS software that’s transforming how energy retailers operate, innovate and manage at scale.

We help retailers lower operating costs, improve billing accuracy for consumers, and enhance customer experience through automation and AI‑driven insight, all underpinned by modern, cloud‑native architecture.

ENSEK is at an exciting inflection point as we scale at pace towards new international horizons. If you’re driven by solving complex, real‑world problems and want to build modern technology that accelerates the global energy transition, you’ll feel right at home with us.

About the role

As a Senior Cyber Security Analyst, you'll act as a technical authority within Security Operations, owning the design, development and continuous improvement of our detection and response capabilities.

You'll lead the response to major security incidents, drive threat-informed detection engineering, influence security architecture decisions, and work closely with colleagues across Security, Engineering and Platform teams to ensure ENSEK remains resilient against evolving threats.

This role combines hands-on technical expertise with leadership responsibilities, offering the opportunity to mentor junior analysts while contributing to strategic security initiatives across the business.

Key responsibilities:
  • Lead Security Incident Response by managing high-severity security incidents end-to-end, coordinating containment and recovery activities, conducting post-incident reviews, and acting as the senior technical lead during P1/P2 events.

  • Own Detection & Response Capability through the design, development and optimisation of SIEM detections, maintaining MITRE ATT&CK coverage, improving detection effectiveness, and identifying gaps across ENSEK's security monitoring landscape.

  • Drive Threat-Informed Security Operations by partnering with Threat & Vulnerability teams to operationalise threat intelligence, support vulnerability management activities, and ensure security operations remain aligned to ENSEK's evolving threat profile.

  • Enhance Security Automation & Operational Efficiency through the development of playbooks, automated response workflows, alert enrichment capabilities, and tool integrations that reduce analyst effort and improve response times.

  • Provide Security Leadership & Assurance by acting as the primary escalation point for Security Operations, mentoring analysts, supporting threat modelling activities, and providing security input into architectural and engineering decisions.

  • Deliver Security Reporting & Compliance Support by owning operational metrics and performance reporting, communicating risk to stakeholders, and contributing evidence and control monitoring activities supporting ISO 27001, SOC 2 and NIS2 compliance requirements.

Key outcomes:
  • Maintain an effective detection and response capability, continuously improving SIEM coverage, reducing false positives, and identifying gaps through MITRE ATT&CK aligned monitoring.

  • Lead the successful resolution of security incidents, ensuring timely containment, clear stakeholder communication, thorough post-incident reviews, and implementation of lessons learned.

  • Strengthen ENSEK's security posture by operationalising threat intelligence, supporting vulnerability remediation activities, and proactively identifying emerging risks.

  • Improve operational efficiency through the development of security automation, response playbooks and workflow enhancements that reduce manual effort and accelerate investigation and response times.

  • Increase security maturity across the organisation by providing security assurance to projects, supporting threat modelling activities, and embedding security monitoring requirements into new services and platforms.

  • Contribute to a high-performing Security Operations function by mentoring analysts, delivering meaningful operational reporting, and supporting compliance obligations including ISO 27001, SOC 2 and NIS2.

Experience required:
  • Proven experience operating within a Security Operations, Cyber Security Analyst, Security Engineer or Incident Response role, with responsibility for leading complex security investigations and major incident response activities.

  • Strong hands-on experience with SIEM platforms, including detection engineering, alert tuning, correlation rule development, coverage mapping, and the continuous improvement of monitoring capabilities.

  • Demonstrable experience leading security incidents from initial triage through to containment, recovery and post-incident review, including stakeholder management during high-severity events.

  • Practical experience applying the MITRE ATT&CK framework to detection engineering, threat hunting, investigations, threat modelling, or security control assessment.

  • Experience developing or supporting security automation and orchestration workflows, including the creation of playbooks, automated response actions, and integrations between security tools.

  • Experience working with cloud security technologies, endpoint detection and response (EDR/MDR) solutions, threat intelligence, and vulnerability management processes within a modern technology environment.

  • Strong communication skills with the ability to translate technical security risks, threats and vulnerabilities into clear, business-focused recommendations for both technical and non-technical stakeholders.

  • Experience mentoring, coaching or providing technical leadership to junior analysts, helping to develop team capability through knowledge sharing, documentation and continuous improvement initiatives.

Company Benefits
  • 25 days’ holiday + bank holidays

  • Option to buy or sell 5 extra annual leave days per year

  • Vitality Health Insurance, including private healthcare, virtual GP access, mental‑health support and wellbeing perks (50% off gym memberships -Virgin Active, Nuffield, PureGym)

  • Pension with 5% matched contribution

  • Regular team‑wide and company‑wide events

  • 2 volunteering days per year to give back

  • Remote‑first working environment with offices in London and Nottingham

Similar Jobs

An Hour Ago
Remote or Hybrid
United Kingdom
Senior level
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead research and production development of generative AI and large language model systems for cybersecurity. Architect model strategies, training and deployment approaches, establish evaluation standards, mentor scientists, guide technical initiatives, and collaborate with senior leadership. Build scalable AI systems, apply advanced deep learning research, publish findings, and drive innovations from research to production.
Top Skills: Cloud TechnologiesDeep LearningDeep Learning FrameworksGenerative AiGpu ComputingLarge Language Models (Llms)Python
An Hour Ago
Remote or Hybrid
United Kingdom
Mid level
Mid level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Analyze large-scale security telemetry, threat intelligence, endpoint, and detection data to identify trends, anomalies, and emerging threats. Build dashboards, reports, data pipelines, and KPI frameworks using SQL, Python, LogScale, or similar tools. Collaborate with data engineering, product, and engineering teams to ensure data quality and translate complex findings into actionable insights for technical and non-technical stakeholders.
Top Skills: Graph DatabasesLogscaleLookerMitre Att&CkPower BIPythonRSIEMSQLTableau
3 Hours Ago
In-Office or Remote
London, Greater London, England, GBR
Entry level
Entry level
Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Cybersecurity • Data Privacy
Partners with defence account executives to sell Rubrik’s data resilience and cybersecurity solutions to UK defence and public-sector customers. Leads technical discovery, architecture, demonstrations, proofs of concept, business-case development, opportunity qualification, and customer and partner advisory activities. Builds pipeline across new and existing accounts while translating infrastructure, cloud, backup, recovery, and security needs into mission-focused outcomes.
Top Skills: Amazon Web Services (Aws)Backup And RecoveryCyber ResilienceEnterprise Data CentresAzureRubrik Security Cloud

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account