Security Testing Operations Analyst
Full Job Description
About the Role:
The Security Testing Operations Analyst plays a vital role in managing vulnerability management and offensive testing initiatives across the group, safeguarding the business against sophisticated cyber threats. This position involves collaborating with 3rd party vendors to meticulously plan and facilitate testing programs, including regulator-led Thread Intelligence Led Pen Testing (TLTP), Red Teaming, Social Engineering simulations, Bug Bounty programs, and external vulnerability scanning services, ensuring their efficient execution.
The ideal candidate will be a recognized authority on vulnerability impact and risk, capable of providing deep insights into root cause analysis and remediation strategies. This role necessitates close collaboration with internal technical teams, external stakeholders, Business Information Security Officers (BISOs), the Global Security Operations Center (GSOC), and other relevant entities.
A key responsibility will be to stay abreast of emerging cybersecurity thought leadership, proactively sharing innovative ideas to enhance our security posture and support informed risk decision-making that drives continuous security risk improvement.
Role Responsibilities & Key Accountabilities:
- Collaborate with external vendors to coordinate the timely delivery of testing requirements.
- Review vulnerability reports, validate reported issues, and triage them based on assessed risk.
- Support teams in understanding identified vulnerabilities and validate fixes through retesting.
- Coordinate remediation efforts by detailing necessary actions, assigning owners, and setting timelines, followed by appropriate follow-ups.
Qualifications & Experience:
- A Bachelor's Degree in a technology-related field or equivalent experience and cybersecurity certifications.
- Prior experience in Red Teaming, Penetration Testing, or Bug Bounty programs is highly advantageous.
- A strong understanding of enterprise IT system environments.
- Proficiency in identifying security vulnerabilities, common software engineering flaws, and applying Network Defense analytical models (e.g., Kill Chain, ATT&CK).
- Excellent verbal and written communication skills, along with strong presentation abilities.
- Demonstrated ability to thrive in a fast-paced environment as a problem-solver and barrier-breaker, possessing strong initiative.
Company
LSEG
London Stock Exchange Group (LSEG) is a distinguished international markets infrastructure business with a rich heritage of over 300 years, dedicated to earning client trust. Our legacy of customer-ce...