
Senior Security Analyst
- ISO 27001
- Devops
- AWS
- EC2
- IAM
- RDS
- Vulnerability Management
- Tenable
- Snyk
- triage
- Jamf
- MacOS
- Microsoft Intune
- Windows
- GuardDuty
- Incident Response
- SOC2
- Intune
- Network Security
- IaC
- CI/CD
- CISSP
- GDPR
- NIST
KEY RESPONSIBILITIESÂ Â
The Senior Technical Security Analyst: Â
•    Support the ongoing operation of the ISO 27001-aligned Information Security Management System (ISMS), including evidence collection, control implementation, and audit readiness.Â
•      Work with DevOps and cloud teams to implement and monitor security controls across AWS infrastructure and services (e.g., EC2, IAM, S3, RDS).Â
•      Manage and operationalise vulnerability management using tools like Tenable, AWS Inspector, and Snyk: schedule scans, triage findings, and track remediation efforts.Â
•      Administer and ensure compliance of endpoints using Jamf (macOS) and Microsoft Intune (Windows).Â
•      Monitor alerts and findings from AWS-native tools (e.g., GuardDuty, Security Hub) and assist in coordinating incident response activities.Â
•      Produce and maintain management reports and dashboards detailing:Â
•      Vulnerability status and trendsÂ
•      ISMS control effectivenessÂ
•      Endpoint security complianceÂ
•      Audit readiness and risk treatment statusÂ
•      Support maintenance of ISMS documentation, including SoA, risk assessments, corrective actions, and control mapping.Â
•      Participate in internal and external audits by preparing evidence and delivering technical walkthroughs.Â
•      Support policy implementation, training activities, and DevOps-aligned security processes.Â
•      Prepare the organisation for also achieving SOC 2 certificationÂ
•      Specify and implement security and compliance protocols for Alchemy SaaS productsÂ
•      Begin to identify and work with tooling and partners to initiate the creation of a hybrid external/internal SOC.Â
•      Contribute to incident response testing and post-incident reviews when applicable.Â
•      Sets a positive example throughout the organization for quality and responsibilityÂ
•      Prepares all necessary project documentation and processes to enable ongoing support of Alchemy’s software productsÂ
Â
The above list is not exhaustive, and you may be asked to undertake reasonable additional duties/ projects by Management.Â
Â
SELECTION CRITERIAÂ
Â
Your Behaviors:Â
Â
•      Detail-oriented and thorough, especially in documenting controls , reporting and audit evidence.Â
•      Collaborative and approachable—able to work cross-functionally with engineering, DevOps, and IT.Â
•      Proactive and self-driven, with a strong sense of ownership over technical security operations.Â
•      Clear communicator—able to explain security concepts to both technical and non-technical stakeholders.Â
•      Analytical mindset—adept at identifying patterns, prioritising risks, and suggesting practical mitigation strategies.Â
•      Organised and efficient, with the ability to manage multiple workstreams and deadlines in a compliance-focused environment.Â
•      Confident – You embrace having open and candid discussions with individuals at all levels both internally and with the ClientÂ
•      Decisive – you have a keen sense of prioritization and make intelligent decisions independentlyÂ
•      Motivated – You are a self-starter with the ability to work independently under light supervisionÂ
•      Reliable - You’re the person stakeholders and peers always want to work withÂ
•      Compassionate - You understand that people are at the core of success Â
•      Data driven – Information is your friend; you love to use facts and evidence to help ensure success for the team and our customersÂ
Â
Â
Qualifications, Knowledge, Skills and ExperienceÂ
Â
ESSENTIAL:Â
•      Bachelor’s degree in Information Security, Computer Science, or a related field or significant alternative relevant technical security industry experience.Â
•      5+ years of hands-on experience in technical security roles in a SaaS coontext, with a focus on ISO 27001, SOC, AWS, and vulnerability management.Â
•      At least 2 years team lead experience in a 24x7 global SOCÂ
•      Experience with AWS security tools and services in a production SaaS environment.Â
•      Experience with Tenable and/or similar tools for vulnerability management.Â
•      Familiarity with Jamf and Intune for endpoint compliance and hardening.Â
•      Good understanding of network security fundamentals, including cloud networking, segmentation, firewalls, and VPNs.Â
•      Ability to generate and present clear and actionable security and compliance reports to stakeholders.Â
•      Experience with DevOps tools, infrastructure-as-code, and CI/CD pipelines.Â
Â
DESIRABLE:Â
Â
•      CISSPÂ
•      PECB ISO 27001 Lead Implementer or Auditor certification.Â
•      AWS Certified Security – Specialty or equivalent AWS certification.Â
•      Awareness of GDPR, NIST and related standards.Â
Senior Security Analyst · Alchemy