Security Analyst (Infrastructure)
Bath, England, United Kingdom
Job Description
The Security Analyst is responsible for ensuring the security and integrity of the organization's IT infrastructure by managing patching and vulnerability remediation for both physical and virtual environments. This role involves the proactive identification, assessment, and mitigation of security vulnerabilities across Windows servers, endpoints, and Azure environments. The Security Analyst will work closely with Architecture and Infrastructure teams to implement effective security controls, deploy critical patches, and maintain compliance with industry standards, while minimizing risks to business operations and ensuring continuous system protection.
Responsibilities:
- Plan, test, and deploy patches to Windows servers and endpoints to address known vulnerabilities and ensure compliance with security policies. Manage patching windows and downtime coordination with various business units to minimize disruption during updates.
- Monitor patch management systems to ensure all systems are up to date and protected from security threats.
- Collaborate with Cyber and Infrastructure teams to apply security hardening to Windows systems, both physical and virtual.
- Develop and enforce security policies related to patching, endpoint security, and vulnerability management. Ensuring compliance with industry standards such as ISO, NIST, CIS.
- Investigate and resolve vulnerabilities identified during routine scans or incidents, implementing remediation plans.
- Maintain accurate documentation of remediation activities and patching schedules for audit and compliance purposes
- Assist in incident response by applying emergency patches and remediations to affected systems when necessary.
- Contribute to disaster recovery and business continuity plans by ensuring systems are protected and vulnerabilities are mitigated.
- From time to time the Security Analyst will be expected to be available outside normal UK working hours to support IT emergencies.
- From time to time the Security Analyst will be expected to take on other duties that are congruent with the responsibilities of the role.
Qualifications
- Strong knowledge of Windows server and endpoint management including patching processes, configurations, and security hardening.
- Experience with vulnerability management tools (e.g., Nessus, Qualys) for conducting vulnerability assessments and prioritizing remediation efforts.
- Hands-on experience in patch management systems (e.g., SCCM, WSUS, and Azure Update Management) for deploying patches in both on-premises and Azure environments.
- Proficiency in cloud security (particularly Azure), including managing Azure Security Center, NSGs, firewalls, and automated patching processes using Infrastructure as Code (IaC).
- Solid understanding of network security concepts, including firewalls, routers, and network device hardening.
- Experience with security frameworks and best practices such as NIST, ISO, or CIS for ensuring compliance in patching and vulnerability management.
- Incident response and remediation skills, particularly in applying emergency patches and resolving vulnerabilities quickly and effectively.
- Automation and scripting capabilities (e.g., PowerShell, Python) to streamline patching, vulnerability scans, and remediation tasks.
- Strong analytical and problem-solving skills to assess and mitigate security risks across both physical and virtual environments.
- Ability to develop and maintain technical documentation, including patching schedules, remediation plans, and compliance reports.
- Aligned to Rotork’s values and promotes an inclusive approach.
- Excellent written English skills.
Additional Information
Rotork is the market-leading global flow control and instrumentation company, helping our customers manage the flow or liquids, gases and powders across many industries worldwide.
Our purpose is Keeping the World Flowing for Future Generations.
For over sixty years, the world has relied on us to create the things that keep everything moving. From oil and gas to water and shipping, pharmaceuticals and food- these are the flows on which our modern world depends.
Today we're respected and admired for our people, performance and products. Our success flows from our commitment to engineering excellence, and that's what we will always pursue, safely and sustainably.
Rotork is going through an exciting period of change and growth, building on our existing market success. It's a great time to join us and make an impact in shaping the future of our business.
#LI-Hybrid
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Automation Azure Cloud Compliance Endpoint security Firewalls Incident response IT infrastructure Nessus Network security NIST PowerShell Python Qualys Scripting Vulnerabilities Vulnerability management Vulnerability scans Windows
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.