Mid-Level Insider Threat Management Analyst

UK - Macclesfield, United Kingdom

AstraZeneca

AstraZeneca is a global, science-led biopharmaceutical business and our innovative medicines are used by millions of patients worldwide.

View all jobs at AstraZeneca

Apply now Apply later

Mid-Level Insider Threat Management Analyst

Macclesfield

AstraZeneca is a global, innovation-driven pharmaceutical business that focuses on the discovery, development, and commercialization of prescription medicines for some of the world’s most serious disease. 

But we’re more than one of the world’s leading pharmaceutical companies. 

At AstraZeneca, we 're dedicated to being a Great Place to Work. Where you are empowered to push the boundaries of science and unleash your ambitious spirit. There’s no better place to make a difference to securing medicine, patients, and society. An inclusive culture that champions diversity and collaboration, AstraZeneca is always committed to lifelong learning, growth, and development. 

The Enterprise Technology Services Team

The Enterprise Technology Services (ETS) team is accountable for all Security, IT Operations, Infrastructure, and End User Services and Technologies. This group will ensure that our IT Services are seamless and secure, and that technology is delivered in an efficient, effective, and agile way, with a strong focus on experience. It’s a dynamic and challenging environment to work in – but that’s why we like it. There are countless opportunities to learn and grow, whether that’s exploring new technologies in hackathons, or transforming the roles and work of colleagues, forever. This is your chance to be part of a team that has the backing to innovate, disrupt an industry and change lives.  

Introduction To Role

Cybersecurity Defence Operations (CSDO), which sits within ETS, is fundamental to enterprise information security and responsible for detecting, analysing, and responding to real or potential security incidents. The Insider Threat Management (ITM) Analyst specializes in the collection and analysis of incidents to proactively identify and mitigate potential data breaches at AstraZeneca. The ITM function empowers operational decision-makers to a) respond more effectively to data incidents through informed decision-making and b) implement measures to mitigate or close gaps in defence, thereby preventing data breaches from occurring in the first place. 

Accountabilities

Utilize the SIEM solution to analyse incidents from diverse sources, generating actionable insights including rapid alerts, dashboards, and reports. 

Monitor and Investigate alerts generated by ITM systems to support investigations to determine the root cause and severity of potential data breaches. 

Continuously monitor user activities and data transfer patterns to detect any deviations from normal behaviour that may indicate insider threat activities. 

Implement anomaly detection mechanisms to automatically identify suspicious user behaviour and generate alerts for further investigation. 

Collaborate with relevant support teams to gather data to support investigations into potential security incidents, insider threat, data loss and legal discovery requests. 

Generate reports and metrics on ITM incidents, trends, and effectiveness of controls for management and stakeholders. 

Essential Skills & Experience

  • Significant experience in Insider Threat Management 

  • Degree in Information Security, Cyber Security (or relevant experience)

  • Familiarity with Security Technologies (Endpoint Detection, SIEM, Office 365 product etc.) 

  • Familiarity with Data Loss Prevention (DLP) and Insider Threat Management tools such as ZScaler, Microsoft Purview, Amazon Macie etc. 

  • Adaptability and a willingness to learn new technologies and methodologies to stay ahead of evolving threats and prevention strategies. 

  • Integrity and professionalism in handling sensitive information and maintaining confidentiality throughout investigations and incident response activities. 

  • Superb communication and interpersonal skills to collaborate effectively with cross-functional teams and communicate technical concepts to non-technical audiences/key partners. 

  • A natural curiosity towards investigative analysis, with a proactive approach to uncovering potential incidents and proclivity to delve deeper into the root causes of security incidents, enabling comprehensive understanding and effective resolution. 

  • Excellent written and verbal communication skills

Desirable Skills & Experience

  • A background in either Cybersecurity Operations, eDiscovery, DLP, or Access Management  

  • Experience with DLP controls and collaboration with stakeholders to develop and implement new DLP policies and procedures tailored to organizational requirements. 

When we put unexpected teams in the same room, we unleash bold thinking with the power to inspire life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.

At AstraZeneca when we see an opportunity for change, we seize it and make it happen, because any opportunity no matter how small, can be the start of something big. Protecting the people, processes, and technologies required to develop and deliver life-changing medicines is about being entrepreneurial - finding those moments and recognizing their potential. Join us on our journey of building a new kind of organization to reset expectations of what cybersecurity can look like. This means we’re opening new ways to work, pioneering cutting edge methods, and bringing unexpected teams together. 

Ready to make an impact?

Apply now!

Date Posted

07-Feb-2025

Closing Date

21-Feb-2025

Our mission is to build an inclusive and equitable environment. We want people to feel they belong at AstraZeneca and Alexion, starting with our recruitment process. We welcome and consider applications from all qualified candidates, regardless of characteristics. We offer reasonable adjustments/accommodations to help all candidates to perform at their best. If you have a need for any adjustments/accommodations, please complete the section in the application form.
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Agile Incident response SIEM

Perks/benefits: Career development Flex hours Team events

Region: Europe
Country: United Kingdom

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.