- Company Name
- Pharmaxo Healthcare
- Job Title
- Senior Cyber Security Specialist
- Job Description
-
**Job Title**
Senior Cyber Security Specialist
**Role Summary**
Lead the Cyber Security Team’s operations and governance in the UK, acting as the primary technical escalation point for all security incidents. Deliver end‑to‑end security operations and Governance, Risk & Compliance (GRC) across the organization, ensuring alignment with UK regulatory requirements and the Corporate Cyber Security Program.
**Expectations**
- 5–7 years of proven experience in security operations, threat detection/management, security engineering, or incident response.
- Demonstrated ability to manage complex security incidents and provide technical escalation.
- Strong knowledge of UK cyber security regulations, compliance frameworks, and industry best practices.
**Key Responsibilities**
- **Security Operations** – Monitor, analyze, and respond to security alerts across SIEM, IDS/IPS, and SOAR platforms; conduct root‑cause analysis and remediation.
- **Incident Management** – Lead incident response, coordinate with cross‑functional teams, maintain incident logs, and produce post‑incident reports.
- **Threat & Vulnerability Management** – Identify, assess, and prioritize vulnerabilities; coordinate patching, configuration hardening, and vulnerability remediation.
- **Governance, Risk & Compliance (GRC)** – Develop, maintain, and audit security policies, standards and procedures; support ISO 27001, NIST CSF, GDPR and UK‑specific compliance initiatives.
- **Security Architecture & Controls** – Design and implement technical controls to mitigate identified risks; evaluate new security technologies for deployment.
- **Stakeholder Collaboration** – Liaise with IT, Legal, and Business units to embed security considerations into projects, vendor assessments, and system changes.
- **Continuous Improvement** – Conduct periodic security reviews, key performance indicator (KPI) reporting, and recommend enhancements to the security posture.
**Required Skills**
- Hands‑on experience with SIEM, IDS/IPS, SOAR, vulnerability scanners, firewalls, endpoint protection and network monitoring tools.
- Deep understanding of threat intelligence, attack lifecycle (MITRE ATT&CK), incident response frameworks, and cyber threat modeling.
- Proficiency in risk assessment methodologies, GRC tools and compliance frameworks (ISO 27001, NIST CSF, GDPR, UK cyber laws).
- Strong analytical, problem‑solving and troubleshooting abilities.
- Excellent communication skills for technical and non‑technical audiences; ability to produce clear documentation and incident reports.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity or a related field (or equivalent professional experience).
- Professional certifications are highly preferred: CISSP, CISM, CRISC, CISA, CEH, or equivalent senior‑level security credentials.
---