Cyber Security Analyst
Job Title: Cybersecurity Analyst
Location: National Train Control Centre (NTCC), Heuston Station, Dublin 8
Job Type: Full Time
Department: Cybersecurity
Reports to: Cybersecurity Operations Manager
Job Summary:
We are seeking a capable and detail-oriented Cybersecurity analyst to help strengthen Iarnród Éireann’s cybersecurity posture. The successful candidate will support day-to-day operational security activities, risk assessments, and technical initiatives across IT, OT, and IoT environments. This role requires a strong understanding of threat management, asset oversight, and data protection best practices.
Reporting into the Security Operations Manager, the analyst will work closely with cross-functional teams to improve controls, support compliance efforts, and contribute to security-related projects and processes.
Key Responsibilities
Security Operations
- Monitor and triage security-related communications, including the cybersecurity mailbox
- Track, document, and follow up on incidents, requests, and alerts until resolution
- Conduct and support the investigation of suspected breaches or anomalous activity
Vulnerability Management
- Run scheduled vulnerability scans using industry tools (e.g., Qualys)
- Assist in remediation efforts through collaboration with IT teams and third-party vendors
- Monitor patching compliance for systems, applications, and endpoints.
Access Governance
- Conduct periodic audits for Privileged Access Management (PAM) and User Access Management (UAM)
- Review access to critical systems and flag inconsistencies or overprovisioned roles
Asset and Data Security
- Support the tracking and classification of digital assets within the enterprise
- Assist in safeguarding data across its lifecycle through appropriate technical and procedural controls
- Help enforce encryption, access controls, and secure configurations for critical assets.
Policy and Risk Support
- Assist in the development and implementation of information security policies and procedures
- Conduct risk assessments, identify areas of exposure, and recommend mitigations
- Contribute to audit preparation and compliance efforts with frameworks such as NIST, ISO 27001, and relevant regulatory standards.
Awareness and Collaboration
- Support security awareness campaigns, including phishing simulation programmes
- Liaise with internal teams (ICT, service providers, business units) to ensure a consistent approach to cybersecurity
- Communicate technical issues in a clear and concise manner to both technical and non-technical stakeholders.
Technology and Tools
- Maintain familiarity with endpoint protection tools (e.g., Microsoft Defender), vulnerability scanners, and monitoring solutions
- Stay informed about emerging threats and vulnerabilities, sharing relevant intelligence with the wider team
Qualifications and Experience
- Solid understanding of core networking protocols (e.g. TCP/IP, DNS, VPN), operating systems (Windows/Linux), and fundamental network security concepts
- Experience with common security tools such as firewalls, IDS/IPS, endpoint protection, and vulnerability scanners
- Familiarity with log and network data analysis to identify anomalies and vulnerabilities
- Hands-on experience in incident response, remediation, and basic penetration testing
- Good knowledge of encryption, authentication, and access control methods
- Proven ability to contribute to the development and execution of security policies and procedures
- Strong analytical and problem-solving skills with keen attention to detail
- Effective communicator with the ability to translate technical issues to non-technical stakeholders
- Experience working in cross-functional teams in a security-focused role
- Bachelor's or Master’s degree in Cybersecurity, Information Technology, Computer Science, or a related discipline
- Industry certifications such as CompTIA Security+, CEH, CISMP, or CISSP are advantageous
- 2–5 years of relevant experience in cybersecurity operations, data protection, or asset security management
This job description is not exhaustive and merely outlines the key duties and responsibilities of the position.