About Company
Admiral Group is one of the UK’s largest car insurance providers, with a strong presence across Europe and the US. Founded in Cardiff in 1993, we’ve grown into a FTSE 100 company with over 11,000 employees globally. While our roots are firmly in the insurance sector, our continued success is underpinned by cutting-edge technology and a relentless focus on data-driven insights and digital innovation. We pride ourselves on fostering a unique culture that encourages personal and professional growth, champions collaboration, and rewards hard work. Our technology division is a critical pillar of the business, constantly evolving to protect our vast digital landscape, safeguard customer data, and secure our intellectual property from increasingly sophisticated cyber threats. Joining Admiral means becoming part of a dynamic, supportive environment where your contributions directly impact the security and trust of millions of customers and the resilience of a global enterprise.
Job Description
We are seeking a highly motivated and skilled Remote Cyber Defence Analyst to join our esteemed Technology & Data division, operating from the vibrant tech hub of Cardiff, Wales. In this critical role, you will be instrumental in safeguarding Admiral Group’s extensive digital assets, sensitive customer data, and vital operational integrity against an ever-evolving and increasingly sophisticated threat landscape. As a key member of our remote cyber security team, you will be at the forefront of our proactive threat detection, rapid incident response, and continuous security improvement initiatives. Your primary responsibilities will involve the continuous monitoring, analysis, and interpretation of security information and event management (SIEM) systems, intrusion detection/prevention systems (IDPS), endpoint detection and response (EDR) tools, and other security tooling to identify, investigate, and remediate potential security incidents. You will be responsible for triaging security alerts, performing deep-dive forensic analysis when necessary, and collaborating closely with our Security Operations Centre (SOC), infrastructure, and development teams to implement effective countermeasures and remediation plans. This role goes beyond just reacting to threats; you will contribute significantly to enhancing our overall security posture, assisting in the development and implementation of robust defence strategies, and ensuring our operations adhere strictly to industry best practices, regulatory requirements, and internal security policies. You will be expected to stay current with the latest cybersecurity threats, trends, and technologies, actively participating in knowledge sharing and continuous improvement efforts within the team. This position demands a keen eye for detail, a strong analytical and problem-solving mindset, and the ability to work autonomously with a high degree of initiative, while also thriving within a collaborative, supportive team structure. If you are passionate about cybersecurity, possess a relentless curiosity, excel in a challenging and dynamic environment, and are committed to protecting critical infrastructure against advanced persistent threats, we invite you to bring your expertise to Admiral Group and help us shape the future of secure digital services for our millions of customers globally.
Key Responsibilities
- Monitor security systems (SIEM, IDPS, EDR) for anomalies, indicators of compromise (IoCs), and suspicious activities.
- Conduct in-depth analysis of security alerts and events, escalating genuine incidents as per defined procedures.
- Perform initial incident response activities, including containment, eradication, and recovery.
- Contribute to the investigation of security incidents, gathering forensic evidence and documenting findings.
- Develop and refine security playbooks, processes, and procedures to enhance incident response capabilities.
- Collaborate with IT and development teams to implement security controls and remediation actions.
- Stay abreast of the latest cybersecurity threats, vulnerabilities, and attack techniques.
- Participate in vulnerability management activities and security audits.
- Provide security awareness training and guidance to internal stakeholders.
- Contribute to continuous improvement of security tools, technologies, and practices.
Required Skills
- Proven experience in a Cyber Security Operations Centre (SOC) or similar defence role.
- Strong understanding of security principles, protocols, and technologies (firewalls, IDS/IPS, anti-virus, WAF).
- Proficiency with SIEM tools (e.g., Splunk, Microsoft Sentinel, LogRhythm) for log analysis and correlation.
- Experience with incident response methodologies and digital forensics fundamentals.
- Knowledge of common attack vectors and threat intelligence frameworks (e.g., MITRE ATT&CK).
- Familiarity with network protocols (TCP/IP, DNS, HTTP) and operating systems (Windows, Linux).
- Excellent analytical, problem-solving, and critical thinking skills.
- Strong verbal and written communication skills.
- Ability to work independently and as part of a distributed team.
Preferred Qualifications
- Bachelor's degree in Computer Science, Cyber Security, Information Technology, or a related field.
- Industry certifications such as CompTIA Security+, CySA+, GCIH, CEH, or equivalent.
- Experience with cloud security platforms (Azure, AWS, GCP).
- Scripting skills (e.g., Python, PowerShell) for automation and analysis.
- Knowledge of regulatory compliance frameworks (e.g., GDPR, PCI DSS).
- Experience with threat hunting techniques and tools.
Perks & Benefits
- Competitive salary and annual bonus scheme.
- Generous pension contribution.
- 25 days annual leave, plus bank holidays, with the option to buy or sell more.
- Private medical insurance.
- Comprehensive employee assistance program.
- Access to discounted Admiral Group products.
- Continuous learning and development opportunities, including support for professional certifications.
- Flexible working environment with a focus on work-life balance.
- Opportunities for career progression within a FTSE 100 company.
- A vibrant and inclusive company culture, even in a remote setting.
How to Apply
To apply for this exciting opportunity, please click the link below to visit our careers page. Search for ‘Cyber Defence Analyst’ or ‘Security Analyst’ and submit your resume and cover letter directly through our online application system. We look forward to reviewing your application!
