Senior Cyber Security Analyst

Senior Cyber Security Analyst

Lightsource bp | Greater London, ENG, GB

Posted 19 days ago

Apply Now

Description

We are Lightsource bp – andwe'reon a mission to become a global leader in onshore renewables, anchored by our proventrack recordin solar development.

For over a decadewe'vebeen actively working to diversify the way our world is powered with sustainable and responsible renewable power. We work to safely deliver affordable, reliable, large-scale onshore renewable and energy storage solutions to help the world decarbonise.

Our growing business is constantly innovating and investing to help drive the energy transition. Our people and projects are focused on supporting long‑term sustainable growth and energy security.

Lightsource bp operates with five core values:Safety,Integrity,Respect,Sustainability, andDrive.

Weseekto attract and hire individuals who share our commitment to creating a safe workplace, uphold the highest standards of integrity, anddemonstraterespect for colleagues, communities, and the environment. Our recruitment process promotes sustainability by valuing long‑term growth and responsible practices, while seeking candidates with the drive to innovate and lead in the global energy transition.

Together, these values shape how we engage, assess, and welcome talent to join us in delivering transformational solar power solutions worldwide.

Lightsource bp was fullyacquiredby bp in 2024.

Whatyou'lldo (the role)

Summary

We areseekinga dynamic, hands‑onSenior Cybersecurity Analysttomonitorcyber risk and lead the remediation ofidentifiedvulnerabilities across Lightsource bp's IT systems globally. You willbe responsible forthreat detection, investigation, and incident response,leveraginga modern security technology stack with a strong focus on the Microsoft Defender ecosystem. Working across multiple business areas and time zones, you will proactively hunt for security issues, assess emerging threats, and partner with infrastructure and support teams to strengthen our security posture and drive business cyber maturity.

Responsibilities of the Role

Continuouslymonitorthe organization's security systems and infrastructure using SIEM, EDR, and related toolsets to detect signs of compromise and investigate security events to completion

Proactively conduct threat hunting using threat intelligence frameworks (MITRE ATT&CK, Cyber Kill Chain) and available security platforms toidentifyand mitigate emerging threats

Assess new and evolving cyber threats to the business,optimizingexisting Microsoft Defender technologies and other security solutions to better counteridentifiedrisks

Identifyvulnerabilities in systems and applications; collaborate with Infrastructure, Digital Workplace, and Support teams to prioritize, patch, and remediate issuesin a timely manner

Manage core Security Operations (SecOps) tooling platforms, ensuring correct configuration, maximizing security value from existing investments, andmaintaininghigh-quality configuration documentation

Communicate proactively with stakeholders across the business, providing clear technical and non-technical updates during investigations and escalations

Support the development, enforcement, and continuous improvement of cloud security policies, standards, and procedures in alignment with industry frameworks (NIST 2.0, CIS, NIS2) and regulations

Create andmaintainsecurity awareness training content andassistin its delivery to colleagues across the organization

Whyyou'llmake a great member of the team

Experience & Knowledge Required

Experience:

5+ years of professional experience in cybersecurity, with at least 2+ years in a Security OperationsCenter(SOC) or incident response role

Advancedproficiencywith Microsoft Defender XDR and expert-level knowledge of Microsoft Sentinel, including KQL query writing and analytics rule development

Strong hands‑on experience with Microsoft Defender for Endpoint, including policy configuration and threat investigation

Demonstrable experience responding to cyber threats and working in an Azure-focused cloud environment

Proven experience with the Cyber Kill Chain, MITRE ATT&CK, and other securitydefenceand intelligence frameworks

Experience in stakeholder management and engagement at C‑Suite level

Experience working for Critical National Infrastructure (CNI) organizations is desirable

Knowledge:

Vulnerability Management:Defender XDR, Tenable IO/Nessus, Defender EASM

Data Governance & IDAM:Microsoft Purview (DLP and information governance), Entra ID, Conditional Access Policies

Device Management:Working understanding of Intune (MDM/MAM)

Networking/Firewalls:Exposure to Cisco Meraki and Fortinet FortiGate (desirable)

Regulatory & Compliance Frameworks:NIST 2.0 Cyber Security Framework (required); NIS2, NERC CIP, SOC2, and IEC 62443 OT standards (desirable)

ITIL Principles:Good understanding of ITIL principles and their application to IT service management

Information Security Technologies:Firewalls, intrusion detection systems, vulnerability assessment tools, logging solutions, gateway and endpoint security products, and authentication mechanisms

Operational Technology (OT) Cyber Security:Desirable but notrequired

Skills Required

Advanced threat detection, investigation, and incident response capabilities

Strong technical troubleshooting and problem‑solving skills with ability to work across complex, global technology environments

Expert‑levelproficiencywith Microsoft security tools and cloud‑based security architectures

Excellent communication skills: ability to translate complex technical concepts for both technical and non‑technical audiences

Proactive mindset with genuine enthusiasm for cybersecurity and drive to improve security posture

Ability to remain calm under pressure and manage multiple incidents and priorities

Cross‑functional collaboration: ability to partner effectively with Infrastructure, Digital Workplace, Support, and business teams worldwide

Strong documentation and reporting skills for both technical and executive audiences

Subject matterexpertisewith proven ability toidentifyand champion security improvement opportunities

Education Required

Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field

Industry‑recognized certification (one or more of the following):

Azure Security Engineer (AZ-500)

Certified Information Systems Security Professional (CISSP)

Certified Cyber Professional (CCP)

CompTIA Security+

GIAC Certified Incident Handler (GCIH)

GIAC Certified Intrusion Analyst (GCIA)

Additional Notes / Role‑Specific Requirements

This is aglobal rolesupporting an expanding, geographically dispersedworkforceand technology stack

You willinterface regularly withmultiple business areas across different time zones

You will work within a small, talented cybersecurity team and collaborate with a global IT organization

The role requires engagement with the convergence of IT and Operational Technology (OT) security, reflecting the evolving landscape of energy infrastructure protection

International regulatory compliance knowledge will be increasingly important as the organization scales across multiplejurisdiction

Why you'll want to work for us

Our company is a place where you can be yourself and grow, a place where your ideas and opinions matter.

Be you

We pride ourselves on being an inclusive community, where every individual is valued and treated with respect.

Be responsible

Our culture is driven by our core values – fromoperatingsafely to ensuring our projects are responsible.

Be recognized

Alongside a competitive salary, we offer a variety of benefits including annual bonus, retention bank, health insurance,pensionand other local benefits.

  • annual bonus
  • retention bank
  • health insurance
  • pensionand other local benefits

Be inspired

Beyond your day‑to‑day working life at Lightsource bp,there'sa variety of initiatives that will contribute to your own personal development. These include our charitable causes, supporting our solar honey project, or volunteering on our VIBES committee to name a few.

Our core values

Lightsource bptruly caresabout creating a sustainable future through safe,responsibleand meaningful low carbon energy projects. Our core values of Safety, Integrity, Respect, Sustainability and Drive are the guiding principles for everything we do.

For further information on our career opportunities and life at Lightsource bp, please visithttps://www.lightsourcebp.com/careers/

Whyyou'll want to stay with us

At Lightsource bp,you'llwork within agile, cross‑functional teams where diverse perspectives come together. Our security team is part of a broader digital transformation driving the energy transition – your work directly protects critical renewable energy infrastructure.

Your career growth is our priority and a shared journey. We are committed to developing talent from within and prepare you for career advancement so you can shape a fulfilling and lasting journey here. As a Senior Analyst,you'llhave opportunities to mentor junior team members, lead security initiatives, and grow into leadership roles.

In today's fast-changing world, a learning mindset is essential and therefore we proactively support upskilling to help you push your skill boundaries and stay ahead in your field, so you can not only keep pace with change but confidently shape a brighter future. We encourage certification advancement and provide access to professional development resources to support your growth in cybersecurity.

#J-18808-Ljbffr