Cyber Threat and Vulnerability Analyst
Requisition ID: R10044001
-
Category: Information Technology
-
Location: Cheltenham, Gloucestershire, United Kingdom
-
Citizenship Required: United Kingdom Citizenship
-
Clearance Type: Developed Vetting (DV)
-
Telecommute: Yes-May consider hybrid teleworking for this position
-
Travel Required: No
-
Positions Available: 1
The UK Cyber Threat and Vulnerability Analyst (TVA) identifies and manages weaknesses and cyber threats in networks and software based on solid research of the emerging threat landscape as it pertains to our IT footprint in the UK and then takes measures to strengthen security within our IT systems.
The primary purpose of this role is to use expert knowledge of offensive cyber to research and analyse existing and potential future cyber threats, reporting their findings and cyber intelligence to business leaders to support counter activities in the prevention and risk mitigation of attacks from cybercriminals.
This role will also work with the NG Corporate Vulnerability Team and the Regional IT patching teams to maintain all vulnerability or threat management solutions, ensuring that all assets and systems are scanned for vulnerabilities regularly. This role will ensure that any findings are brought to the attention of the business and will work within the cybersecurity function to prioritize and remediate threats liaising with other parts of the organisation to assure remediation is carried out in accordance with policy.
NGUK Ltd has a varied portfolio of contract types and customers and the NGUKL Threat and Vulnerability Analyst will work to the UK Cyber Security Manager who has overall responsibility for the prevention and response to cyber security threats.Â
Threat Analysis
- Monitor and analyse external and internal cyber threats to assess risk.
- Analyse the likelihood of emerging threats and what the potential impact could be to the organization.
- Consolidate cyber threat intelligence feeds and sources.
- Analyse internal and external risks and security controls to assure existing security posture.
- Deliver intelligence and performance reports and make recommendations to the business to enable the effective mitigation and remediation efforts.
- Provide requirements to influence threat mitigation strategies.
- Provide threat intelligence support to cybersecurity teams during security events.
Vulnerability Management
- Collaborate with the corporate vulnerability scanning team to conduct vulnerability scans for the UK on prem and Cloud environments.
- Co-ordinate responses to dealing with critical vulnerabilities.
- Review and analysing vulnerability data to identify trends and patterns and risks to the business.
- Advising employees responsible for remediation on best practice remediation.
- Influence the development of vulnerability management standards and security policies.
- Operate vulnerability management processes, suggesting applicable change controls, and security exceptions.
- Continually improve vulnerability reporting and monitoring solutions.
- Maintain and update process guides and assist with reporting to leadership and service stakeholders.
- Perform risk-based technical assessments on technical vulnerabilities.
Event/Incident Response
- Assist and support the manager in event/incident handling and investigations.
- Support the Critical Incident Management process for cyber related events.
- Ensure the NGUKL Security Incident Management process is followed for the timely identification, evaluation and recording of compliance matters and information security risks, escalating as required.
Essential criteria:
To fulfil the requirements of this job, the post-holder must have:
- Significant experience of threat and vulnerability management in the UK Defence or commercial sector.
- Track record of working within an IT security infrastructure (network and servers) and services, including Cloud computing
- A formal qualification in cyber security (CISSP, CCSP or other).
- Experience working with different security tooling / vendors (AWS, Microsoft, Azure, Cisco etc).
- Applicants must be able to hold and maintain UK Government clearances
- Current UK driving licence.
Desirable criteria:
- Understanding of ISO27001 Security Frameworks.
- GIAC Enterprise Vulnerability Assessor Certification | Cybersecurity Certification
- GIAC Cyber Threat Intelligence Certification | Cybersecurity Certification
- GIAC Security Operations Certification | Cybersecurity Certification
Additional information:
- Travel requirements: Occasional UK travel may be required to attend team/customer meetings and training activities
- Northrop Grumman offer Hybrid working, please speak to us at application stage to see what is possible
- Clearance requirements: Post-holder must hold and maintain UK Government Security Clearance
Apply Now
What's great about
Northrop Grumman
- Be part of a culture that thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work.
- Use your skills to build and deliver innovative tech solutions that protect the world and shape a better future.
- Enjoy benefits like work-life balance, education assistance and paid time off.
Did you know?
Northrop Grumman leads the industry team for NASA’s James Webb Space Telescope, the largest, most complex and powerful space telescope ever built. Launched in December 2021, the telescope incorporates innovative design, advanced technology, and groundbreaking engineering, and will fundamentally alter our understanding of the universe.
- Administrative Services
- Business Development
- Business Management
- Communications
- Engineering
- Environmental
- Facilities/Real Estate
- Flight Operations
- Global Supply Chain
- Health & Safety
- Human Resources
- Information Technology
- Legal and Regulatory
- Manufacturing and Production
- Mission and Quality Assurance
- Non-CJCS
- Program Management
- Research and Sciences
- Security
- Technical Support
- alabama
- alaska
- arizona
- arkansas
- california
- colorado
- connecticut
- delaware
- district of columbia
- florida
- georgia
- hawaii
- idaho
- illinois
- indiana
- iowa
- kansas
- kentucky
- louisiana
- maine
- maryland
- massachusetts
- michigan
- minnesota
- mississippi
- missouri
- montana
- nebraska
- nevada
- new hampshire
- new jersey
- new mexico
- new york
- north carolina
- north dakota
- ohio
- oklahoma
- oregon
- pennsylvania
- rhode island
- south carolina
- south dakota
- tennessee
- texas
- utah
- vermont
- virginia
- virgin islands
- washington
- west virginia
- wisconsin
- wyoming
- APO AE, Riyadh
- Al Udeid, Ad Dawhah
- Albuquerque, New Mexico
- Alice Springs, Northern Territory
- Amberley, Queensland
- Anchorage, Alaska
- Annapolis, Maryland
- Annapolis Junction, Maryland
- Apopka, Florida
- Arlington, Virginia
- Arlington Heights, Illinois
- Aurora, Colorado
- Australia-Fortitude Valley, Queensland
- Azusa, California
- Baltimore, Maryland
- Beale AFB, California
- Beavercreek, Ohio
- Bellevue, Nebraska
- Beltsville, Maryland
- Bethpage, New York
- Bloomington, Minnesota
- Boulder, Colorado
- Buffalo, New York
- Camarillo, California
- Cape Canaveral, Florida
- Chandler, Arizona
- Chantilly, Virginia
- Charlotte, North Carolina
- Charlottesville, Virginia
- Cheltenham, Gloucestershire
- Cheyenne, Wyoming
- Cincinnati, Ohio
- Clearfield, Utah
- Colorado Springs, Colorado
- Commerce, California
- Corinne, Utah
- Dallastown, Pennsylvania
- Davis Monthan AFB, Arizona
- Devens, Massachusetts
- Dulles, Virginia
- East Hartford, Connecticut
- Edwards AFB, California
- El Segundo, California
- Elk River, Minnesota
- Elkridge, Maryland
- Elkton, Maryland
- Emerado, North Dakota
- Fairbairn, Australian Capital Territory
- Fairfax, Virginia
- Falls Church, Virginia
- Fareham, Hampshire
- Fort Carson, Colorado
- Fort Gordon, Georgia
- Fort Greely, Alaska
- Fort Hood, Texas
- Fort Leavenworth, Kansas
- Fort Riley, Kansas
- Fort Rucker, Alabama
- Fort Worth, Texas
- Fortitude Valley, Queensland
- Gilbert, Arizona
- Goleta, California
- Great Falls, Montana
- Harrogate, North Yorkshire
- Helena, Montana
- Herndon, Virginia
- Hill AFB, Utah
- Hollywood, Maryland
- Hopkinton, Massachusetts
- Houston, Texas
- Huntsville, Alabama
- Hurlburt Field, Florida
- Irving, Texas
- Iuka, Mississippi
- Jacksonville, Florida
- Kennedy Space Center, Florida
- Kettering, Ohio
- Kirtland AFB, New Mexico
- Lake Charles, Louisiana
- Langley AFB, Virginia
- Lanham, Maryland
- Lemoore, California
- Linthicum, Maryland
- London, London
- Los Angeles, California
- Madison, Alabama
- Magna, Utah
- Manchester, Manchester
- Manhattan Beach, California
- McClellan, California
- McLean, Virginia
- Melbourne, Florida
- Mesa, Arizona
- Middle River, Maryland
- Middletown, Rhode Island
- Minot, North Dakota
- Mojave, California
- Monterey, California
- Moody AFB, Georgia
- Morrisville, North Carolina
- Moss Point, Mississippi
- Nashua, New Hampshire
- Naval Station Mayport, Florida
- Nellis AFB, Nevada
- New Church, Virginia
- New Malden, London
- New Town, North Dakota
- New York, New York
- Newport, Rhode Island
- Newport News, Virginia
- Norfolk, Virginia
- Northridge, California
- Ocean Springs, Mississippi
- Offutt AFB, Nebraska
- Ogden, Utah
- Oklahoma City, Oklahoma
- Orlando, Florida
- Oxnard, California
- Palm Beach Gardens, Florida
- Palmdale, California
- Panama City, Florida
- Patrick AFB, Florida
- Patuxent River, Maryland
- Philadelphia, Pennsylvania
- Pinkenba, Queensland
- Plymouth, Minnesota
- Point Mugu, California
- Port Hueneme, California
- Radford, Virginia
- Redondo Beach, California
- Redstone Arsenal, Alabama
- Richmond, New South Wales
- Ridgecrest, California
- Riyadh, Riyadh
- Rocket Center, West Virginia
- Rolling Meadows, Illinois
- Rome, New York
- Ronkonkoma, New York
- Roy, Utah
- Sacheon, Gyeongsangnam-do
- Saint Augustine, Florida
- Saint Charles, Missouri
- Saint Rose, Louisiana
- Salt Lake City, Utah
- San Antonio, Texas
- San Diego, California
- San Jose, California
- Santa Maria, California
- Santa Rosa, California
- Schriever AFB, Colorado
- Sierra Vista, Arizona
- Signal Hill, California
- Springfield Central, Queensland
- Stafford, Virginia
- Sterling, Virginia
- Suffolk, Virginia
- Sunnyvale, California
- Sykesville, Maryland
- Symonston, Australian Capital Territory
- Tampa, Florida
- Tinker AFB, Oklahoma
- Tucson, Arizona
- United Kingdom-Home Based, London
- Unknown, Virginia
- Unknown City, Alabama
- Unknown City, Alaska
- Unknown City, Arizona
- Unknown City, California
- Unknown City, District of Columbia
- Unknown City, Florida
- Unknown City, Guam
- Unknown City, Maryland
- Unknown City, Michigan
- Unknown City, Minnesota
- Unknown City, Nevada
- Unknown City, New Jersey
- Unknown City, New Mexico
- Unknown City, Oklahoma
- Unknown City, Texas
- Unknown City, Utah
- Unknown City, Virginia
- Unknown City, Washington
- Vandenberg AFB, California
- Ventura, California
- Walpole, Massachusetts
- Warner Robins, Georgia
- Warrenton, Virginia
- West Hampton Beach, New York
- White Sands, New Mexico
- Whiteman AFB, Missouri
- Wichita, Kansas
- Williamtown, New South Wales
- Woodland Hills, California
- Wright-Patterson AFB, Ohio
- Yigo, Guam
- Yorktown, Virginia
- Yuma, Arizona