Cyber Security Analyst
Listed on 2026-03-13
-
IT/Tech
Cybersecurity, Security Manager, IT Consultant
About The Company
Heathrow is renowned as one of the world's busiest and most iconic airports, serving as a vital hub for international travel and commerce. Known for its exceptional service, innovative infrastructure, and commitment to sustainability, Heathrow offers a dynamic environment where professionals can thrive. The organization prides itself on fostering a culture of safety, inclusivity, and continuous improvement, making it an inspiring place to build a career.
With a diverse workforce and a global outlook, Heathrow continuously strives to enhance the passenger experience while maintaining the highest standards of operational excellence.
The Role
The Cyber Security Analyst Linux Estate at Heathrow will play a crucial role in safeguarding the organization’s Linux infrastructure. As a key member of the Cyber Security Team, the successful candidate will be responsible for ensuring that the Linux estate is securely configured, designed, and operated in line with best practices, regulatory requirements, and risk management strategies. This role offers a unique opportunity to influence the security posture of a large, complex environment, working closely with Linux platform teams and broader IT stakeholders to embed security into every aspect of the infrastructure lifecycle.
The analyst will lead efforts in secure development, assessment, monitoring, automation, and fostering a security‑aware culture across the organization.
The ideal candidate will have a minimum of three years of relevant experience in cyber security, application security, secure development, or Dev Sec Ops . Practical experience working within software development environments and modern SDLC practices is essential. A strong understanding of application security principles, common vulnerabilities such as OWASP Top 10, and experience embedding security into CI/CD pipelines is required.
Familiarity with security tooling such as SAST, DAST, dependency scanning, and secrets detection is also important. Candidates should possess excellent stakeholder engagement skills and a collaborative mindset focused on enablement rather than control. Preferred qualifications include experience in Dev Sec Ops or agile delivery environments, exposure to cloud‑native development, knowledge of infrastructure‑as‑code, container security concepts, and experience supporting secure development in regulated or critical national infrastructure environments.
- Secure Development & SDLC Integration – Embed secure development practices across all stages of the SDLC, from design and build through to deployment and maintenance. Ensure security requirements, patterns, and controls are incorporated early into application and platform design. Promote and enable secure‑by‑design and security‑by‑default principles across the development community.
- Advisory & Assessment – Provide hands‑on security advisory support to software engineering teams, architects, and product owners. Conduct security design reviews, code assessments, and threat modeling activities. Assess development pipelines, tooling, and environments to identify security weaknesses and opportunities for improvement.
- Monitoring & Detection – Monitor development environments, repositories, and pipelines for poor security practices, exposed secrets, credentials, and misconfigurations. Support the identification, triage, and remediation of security findings in collaboration with development teams.
- Security Automation & Tooling – Design, implement, and maintain automated security checks within CI/CD pipelines, including static, dynamic, and dependency scanning. Enable consistent and scalable security controls through automation to reduce manual overhead and enhance developer experience. Collaborate with platform and tooling teams to integrate security capabilities into development ecosystems.
- Collaboration & Culture – Foster a collaborative, trust‑based relationship between the Cyber Security team and the development community. Act as a security champion, influencing ways of working and promoting security awareness and ownership within engineering teams. Build strong…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: