Skip to main content

Senior Cyber Security Analyst

Licensed sponsor London Area, United Kingdom Full-time Posted 1 hour ago

About Y TREE

We are a rapidly growing WealthTech business that is re-defining how individuals and families connect and engage with their money. We provide our clients with control over their personal finances, enhancing their ability to achieve their financial and life aspirations. We are harnessing sophisticated portfolio analytics, innovative behavioural psychology and cutting-edge UX/UI to create a revolutionary experience and transformational outcomes for our users. The business was founded in 2017 by three successful entrepreneurs and business-builders with diverse experiences and skill-sets in Technology, Corporate Advice and Investment Management and is backed by some of Europe’s leading investors.

Team Overview & The Role

The role will be part of the Technology team and will report into the CTO. This role will work closely with multiple Technology disciplines and other internal and external teams to establish a strong set of cyber controls for the Y TREE business.

This is a hands-on role with a wide range of responsibilities including monitoring, detection, response and remediation of security risks, threats and vulnerabilities. The ultimate goal is to holistically improve Y TREE’s security posture to meet the demands of its clients and its regulators. This is a great opportunity for the right individual to make their mark and support the growth of a scale-up organisation.

Core Responsibilities

  • Security Posture Improvement: Act as a hands-on Security Analyst, closely interacting with multiple technology disciplines to collectively improve the security posture of Y TREE’s technologies.
  • SOC Collaboration & Incident Response: Collaborate with an externally-managed SOC; act as the escalation point for Y TREE, triage and prioritise issues, manage the issue lifecycle, and lead incident response.
  • Vulnerability Management: Carry out security scanning; detect and manage vulnerabilities to resolution and reduce operational risks using commercial (CrowdStrike) and open-source technologies (Trivy) in AWS-hosted applications and infrastructure.
  • Monitoring & Mitigations: Manage security monitoring and alerts to understand attack vectors and introduce mitigations.
  • Automation & LLMs: Use tools and automation (including LLMs) to carry out common security operations tasks.
  • Routine Security Testing: Introduce and embed tools to enhance Y TREE’s internal capabilities for routine security testing activities, and monitor/enhance security on CI/CD pipelines (SAST, DAST and SCA testing).
  • Risk & Remediation Tracking: Maintain a register of security risks and remediations; work closely with Technology, Risk, and Compliance teams to track and close issues.
  • Certifications & Policies: Support Y TREE’s efforts in maintaining current cyber security certifications and achieving higher accreditations, while maintaining/enhancing policies, documentation, and reporting on cyber metrics.
  • Advocacy & Awareness: Elevate cyber security awareness across the organisation and champion best practices.
  • External Audits: Collaborate with external cyber security consultants for external reviews, audits and assessments.

What You Bring

  • Security Frameworks & Regulation: Experience with security-focused frameworks (e.g., CIS, NIST, ISO) and a track record of applying security controls in an FCA-regulated environment, with an understanding of key regulatory guidelines (e.g., GDPR, DORA).
  • Threat Detection & Cloud Security: Experience with intrusion detection, prevention, and management (e.g., SIEM) alongside vulnerability management on cloud systems and applications (ideally AWS and Kubernetes).
  • Incident & Penetration Expertise: Experience leading incident response and management, with familiarity in pen testing of applications and infrastructure.
  • Application Security: Familiarity with OWASP principles, web application security, security practices on native mobile apps (iOS and Android), and security-by-design principles.
  • Tooling & Threat Landscape: Familiarity with project management tools (Confluence, Jira, ServiceNow) and a good understanding of the threat landscape and risks from emerging technologies (like AI).
  • Leadership & Growth: Comfortable taking the lead when required, eager to learn, and passionate about technology with a drive for continuous professional development.
  • Mindset & Collaboration: An organised, meticulous, independent, and critical thinker who is an effective collaborator, open to feedback, and capable of identifying issues and building logical steps to overcome them.
  • Communication Skills: Excellent written and verbal English skills, able to clearly articulate thoughts and ideas during interpersonal communication within our community.

Bonus Points

  • Experience working in a Fintech or WealthTech domain.

Location & Ways of Working

  • Hybrid Model: London-based with a hybrid working policy requiring 2 days per week in our London office.

What We Offer (Benefits)

  • Health & Wellbeing: Private healthcare plan through Vitality (including 50% off premium gym memberships and an exclusive rewards programme) and support for your mental health through our employee assistance programme.
  • True Time Off: 25 days of annual leave per year where we expect you to turn your phone off and switch off; we never ask you to book leave for a doctor's appointment or to see your children's school plays.
  • Financial Future: 3% employer pension contribution as standard, with generous additional employer contributions if you choose to make contributions via salary sacrifice.
  • Environment: A welcoming, dog-friendly London office with appropriate spaces for varying needs, including breakout spaces and silent booths, alongside regular, well-balanced team socials.
  • Extra Perks: A range of family-friendly policies, support towards professional qualifications, electric car schemes, and more!

Similar sponsor-licensed roles

More roles in London Area, United Kingdom with active sponsor licences.