
Location
Barbican Support Centre with Hybrid Working (One office day a week)
Hours
Full-Time, 37.5 hours per week
Salary
Negotiable, competitive salary depending on experience
About the Role
At Nuffield Health, everything we give our patients, members and customers would not be possible without you. Your passion, your warmth, and your drive to make a difference are at the heart of what we do. Whether it’s connecting health, helping the nation, transforming experiences, or building the career you want – we give you the support to do it all. Join our journey. It starts with you.
We are seeking an experienced and proactive Cyber Security Analyst to join our growing Cyber Security Operations practice. This fixed-term role (6 months initially with potential extension or permanent opportunity) offers the chance to develop your career working across a broad technology estate covering clinical and non-clinical applications related to fitness, wellbeing, and healthcare.
You will coordinate and lead incident response activities, working closely with internal teams and third-party partners to ensure effective containment and recovery. Your responsibilities will include analyzing endpoint, server, and network logs, performing vulnerability scans, identifying and remediating security vulnerabilities, and contributing to the ongoing improvement of cyber security detection and protection strategies.
Additional duties include supporting cyber risk assessments and assurance reviews, managing cyber security risks and mitigation plans, liaising with external organisations on IT security trends, and promoting cyber security awareness across the organisation through communication campaigns and tailored training.
At Nuffield Health, we want you to love coming to work, feeling healthy, happy, and valued. Our benefits package includes a range of fitness, lifestyle, health and wellbeing rewards such as free gym membership, health assessments, retail discounts, and pension options.
Experience
- Significant experience working within an in-house cyber security or SOC environment, including leading and coordinating security investigations.
- Proven incident response leadership experience covering triage, containment, eradication, recovery, and post-incident review.
- Proficiency with security tooling, analytics tuning, and reporting (e.g. Microsoft Sentinel SIEM, endpoint XDR, cloud & network).
- Confidence in writing SIEM queries.
- Experience in endpoint and network-based security detection, prevention, and investigations.
- Interest in threat intelligence and knowledge of threat hunting techniques.
- Experience supporting incident response engagements including threat containment, root cause analysis, and restoring operations.
- Familiarity with information and cyber security standards and frameworks such as ISO 27001, CAF, and MITRE ATT&CK.
- Experience writing policies, procedures, and user guidance for practical use.
- Experience working closely with Technology Service and Product Engineering teams to build and maintain a strong security posture.
About you
- Proactive and detail-oriented with strong analytical and problem-solving skills.
- Excellent communication skills with the ability to work collaboratively across teams.
- Passionate about cyber security and continuous improvement.
- Able to manage multiple priorities and work effectively under pressure.
- Committed to fostering a proactive security culture within the organisation.
Qualifications
- Relevant cyber security certifications or qualifications are desirable but not explicitly stated.
- Demonstrable knowledge of cyber security principles and best practices.
- Willingness to develop professionally and stay current with evolving cyber security trends and technologies.



