Description
About the Opportunity
We are seeking an Information Security Analyst to support the protection of business systems, digital assets, and sensitive information against security threats. The successful candidate will help assess security risks, monitor potential incidents, review access controls, and improve the effectiveness of technical and procedural safeguards.
Working alongside IT operations, software engineering, risk, and compliance teams, you will contribute to security monitoring, vulnerability management, security assessments, and incident response. Your work will help strengthen the organisation’s security posture while supporting the availability, confidentiality, and integrity of its systems and data.
Experience in financial technology, digital banking, payment platforms, SaaS environments, or other data-sensitive industries is an advantage.
Key Responsibilities
- Monitor security events, investigate alerts, and support the assessment and escalation of potential security incidents.
- Assist with vulnerability assessments and coordinate the remediation of identified weaknesses.
- Review access permissions, user privileges, authentication controls, and account management procedures.
- Support the implementation and monitoring of security policies, standards, and technical controls.
- Analyse security logs and relevant system activity to identify suspicious behaviour and potential threats.
- Assist with incident response activities, including evidence collection, documentation, root-cause analysis, and follow-up actions.
- Participate in security risk assessments covering applications, infrastructure, cloud environments, and third-party services.
- Support security reviews of new systems, integrations, and technology changes.
- Contribute to endpoint protection, patch management, configuration reviews, and security awareness initiatives.
- Maintain accurate records of vulnerabilities, incidents, security exceptions, and remediation activities.
- Work with engineering teams to promote secure development practices and address application security findings.
- Assist with internal audits, security assurance activities, and evidence preparation for relevant standards or regulatory reviews.
- Contribute to improvements in security monitoring, incident handling, and operational resilience.
Required Qualifications
- Degree or equivalent practical experience in cybersecurity, information technology, computer science, information systems, or a related discipline.
- Experience in information security, IT operations, security monitoring, vulnerability management, or a related technical function.
- Understanding of network security, operating systems, identity and access management, and common cybersecurity threats.
- Familiarity with security logs, incident triage, vulnerability assessment tools, and endpoint security technologies.
- Knowledge of authentication methods, access control principles, encryption concepts, and secure configuration practices.
- Understanding of cloud security fundamentals and common security risks in modern application environments.
- Ability to investigate technical issues, document findings, and recommend proportionate corrective actions.
- Strong analytical thinking, attention to detail, and effective communication skills.
- Professional proficiency in English; Estonian language skills are an advantage.
Preferred Technical Experience
Experience with SIEM platforms, such as Microsoft Sentinel or Splunk, is beneficial. Familiarity with vulnerability scanners, EDR tools, cloud security monitoring, scripting with Python or PowerShell, and security incident management platforms will also be valued.
Knowledge of recognised frameworks and standards, including ISO/IEC 27001, NIST Cybersecurity Framework, and CIS Controls, is desirable. Relevant certifications such as Security+, SSCP, or equivalent practical training may strengthen an application.
Security and Compliance Context
The role supports the organisation’s wider security and compliance obligations, including appropriate protection of personal and confidential data. Depending on the business and systems involved, this may include GDPR requirements, internal security policies, contractual security commitments, and applicable financial-sector expectations.
You will help maintain appropriate technical evidence and documentation while collaborating with responsible stakeholders on risk treatment and control improvements.
What We Offer
- The opportunity to contribute directly to cybersecurity and information protection.
- Exposure to security monitoring, vulnerability management, incident response, and risk assessment.
- Collaboration with engineering, IT, compliance, and risk professionals.
- Opportunities to expand technical knowledge across cloud security and modern enterprise infrastructure.
- Competitive remuneration reflecting relevant experience and capabilities.
Ideal Candidate
The ideal candidate is investigative, security-conscious, and committed to continuous learning. You should be able to assess alerts methodically, distinguish confirmed issues from unverified indicators, and communicate technical findings in a clear and actionable manner. Professional discretion and respect for security procedures are essential.
Application Process
Please submit a current CV highlighting relevant security experience, technical tools, and professional training. Applicants may include details of security assessments, incident response work, or vulnerability management projects, provided no confidential information is disclosed.
Are you interested in this position?
Apply by clicking on the “Apply Now” Button below!
#JobsHubEstonia #GlobalRecrument
#CareerOpportunities #HiringNow
#JobSeekersNetwork #EstoniaJobs
#RecruitmentServices #EmploymentPortal.