Lead Information Security Analyst
- ABF Grocery
- Liverpool, United Kingdom
- Β£45,000 β Β£55,000
Overview of role
π Location: Liverpool, Merseyside
π° Salary: Β£45,000pa - Β£55,000pa
π’ Hybrid Working: On average 2 days in the office per week (subject to business requirements)
π Permanent
The Lead Security Analyst will join the GSC Security Team, helping to monitor, report, and manage security risks and ensure delivery of the solution or mitigating actions. The purpose of the role is to ensure Security is embedded in the culture of the businesses we support and ensure core security processes and standards are adhered to.
The role includes working closely with our central security function to manage common and wider reaching security and compliance issues. You will also have a level of responsibility for system security processes required to achieve compliance with current business and ABF standards ensuring risks to security are identified, reviewed and resolved. You will also facilitate the delivery of application patching and reporting across a number of business units.
β¨ Why Join Us?
We believe in rewarding our employees and providing a supportive work environment. Hereβs what youβll get:
β Competitive Benefits Package including:
πΌ Competitive Salary
π΄ Generous Leave β 25 days holiday + bank holidays
π Free Onsite Parking
π Employee Assistance Programme
π©Ί Health Scheme
π Holiday Purchase Scheme
π° Pension Scheme
π Onsite Shop
π Eyecare Vouchers
π΄ Cycle to Work Scheme
π Loyal Service Awards
π₯ Employee Referral Scheme
π Discounts on groceries, holidays and more.
Key Accountabilities
As the Lead Information Security Analyst you will:
βοΈ Help develop security roadmaps, risk assessments and mitigation plans.
βοΈ Review security risks and access controls, providing regular stakeholder updates.
βοΈ Maintain system security processes and compliance with business standards.
βοΈ Coordinate application patching across the business.
βοΈ Monitor vulnerabilities and work with system owners to implement appropriate controls.
βοΈ Investigate security incidents and potential indicators of compromise referred by the SOC or other sources.
βοΈ Work with central teams to strengthen the security of business applications.
βοΈ Ensure security is embedded throughout project design and delivery.
βοΈ Monitor and analyse security alerts received through tickets, phone calls and other channels.
βοΈ Build strong relationships across IS and the wider business, providing security advice and support.
βοΈ Improve security processes, controls and awareness across supported businesses.
βοΈ Implement and maintain security standards and operating procedures.
βοΈ Support the management and development of junior team members through work allocation, mentoring and performance support.
βοΈ Contribute to OT security initiatives, including asset visibility, network segmentation, vulnerability management, resilience reviews, site assessments and project security requirements.
The Right Person
We're looking for someone with:
βοΈ Strong knowledge of information and cyber security, including risk, vulnerabilities, monitoring, incident response, and identity and access management.
βοΈ Experience in an information or cyber security role covering governance, assurance and operational security.
βοΈ Knowledge of security controls and technologies, including MFA, Privileged Access Management, endpoint security, vulnerability management, SOC monitoring and cloud security.
βοΈ An understanding of Operational Technology security and cyber risk in manufacturing or operational environments.
βοΈ Excellent written and verbal communication skills, with the confidence to engage stakeholders at all levels.
βοΈ Strong analytical and problem-solving skills, including experience producing reports, risk assessments and process documentation.
βοΈ The ability to manage multiple priorities, adapt to change and proactively resolve issues.
βοΈ Experience mentoring colleagues and improving security awareness, processes and controls.
Skills
- Information Security
- Risk Management
- Compliance
- Vulnerability Management
- Security Monitoring
- Incident Response
- Patch Management









