DF Capital

Graduate Cybersecurity Analyst

DF Capital · Manchester, England, United Kingdom

Financial Services · 51-200 employees

7 h ago
Junior (0-2 yrs) Full-time United Kingdom
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Junior Cyber Security Analyst will monitor security alerts, assist with incident investigations, and support the secure configuration of cloud and SaaS environments. They will also contribute to vulnerability remediation, AI security guidance, and the maintenance of security documentation.

What they look for

Cyber security Vulnerability management Incident response Cloud security SaaS security Identity and access management Endpoint security Networking fundamentals PowerShell Python SQL KQL Risk assessment Data protection Technical documentation Communication

Requirements

Candidates should have a degree, apprenticeship, or equivalent experience in a relevant technical discipline along with foundational knowledge of operating systems and networking. Strong analytical skills, a willingness to learn, and the ability to communicate technical risks to non-technical stakeholders are essential.

Benefits

Private medical insurance 10% Employer pension contribution 30-day annual leave Free gym membership Discretionary annual bonus Discretionary share awards Life assurance Income protection Save as you earn share acquisition scheme Tax efficient salary sacrifice scheme for bicycles and electric vehicles 4 days of paid volunteering leave

Full description

We’re DF Capital – a specialist bank providing award-winning commercial finance, retail finance, and savings products to consumers and small businesses.

Based in Manchester, we serve thousands of customers across the UK and into Europe, supporting their ambitions with tailored financial solutions.

We help our customers realise their ambitions by doing things differently – combining the agility and innovation of a specialist lender with the security and service standards of a regulated bank. Whether it’s flexible lending structures or straightforward savings options, we focus on what matters most to our customers.

In 2025, we launched DF Capital Retail Finance – a subsidiary of DF Capital Bank Limited – to offer specialist hire purchase solutions to retail customers.

Our goal is simple: to do the absolute best for our customers, our communities, and each other.

The Role:

The Junior Cyber Security Analyst will help protect DF Capital’s users, devices, cloud services, SaaS platforms and data. The role combines hands-on systems support with cyber security monitoring, secure configuration, vulnerability management, incident response support and emerging AI security controls. It is designed as a development role: strong foundational IT knowledge is expected, but the successful candidate may be fresh from university or early in their career, if they demonstrate the right security mindset, analytical ability and willingness to learn.

 

  • Monitor and triage alerts from security tooling, endpoint controls, identity platforms, cloud services and SaaS applications, escalating where required.
  • Assist with incident investigation by gathering evidence, checking user/device activity, reviewing logs, documenting actions and supporting containment steps.
  • Maintain accurate service desk and security incident records, ensuring decisions, evidence and follow-up actions are captured clearly.
  • Support strong identity hygiene, including MFA, conditional access, privileged access, joiner/mover/leaver controls and least-privilege access reviews.
  • Assist with endpoint security activities covering device health, encryption, patching, anti-malware/EDR status and secure configuration exceptions.
  • Help identify unusual access patterns, risky sign-ins and account misuse, working with the wider IT team and suppliers to remediate issues.
  • Support secure operation of cloud and SaaS environments by helping review configuration, access, logging, alerting and supplier security evidence.
  • Assist wider IT team with vulnerability remediation, secure configuration baselines and operational resilience activities.
  • Maintain documentation for cloud and SaaS security controls, including asset ownership, logging coverage, support contacts and escalation paths.
  • Support safe adoption of AI-enabled tools by helping assess data protection, prompt/data leakage, access control, model governance and supplier assurance considerations.
  • Assist with monitoring and control activities relating to sensitive data, data classification, data retention and inappropriate sharing of company information.
  • Contribute to AI security guidance, awareness material and practical checks that help colleagues use approved AI tools safely and responsibly.
  • Track vulnerabilities, misconfigurations and control gaps through to remediation, ensuring owners, priorities, evidence and exceptions are documented.
  • Support audit, Cyber Essentials Plus, ITGC, penetration testing and supplier assurance evidence gathering where required.
  • Create and maintain clear, usable procedures, runbooks, knowledge articles and technical notes for both IT colleagues and non-technical stakeholders.
  • Support cyber awareness initiatives, new starter cyber induction and practical guidance for employees on phishing, passwords, AI usage and secure working.
  • Communicate technical information in a clear, calm and approachable way, avoiding unnecessary jargon.
  • Develop a strong understanding of DF Capital’s business, risk appetite and regulatory environment so technical recommendations are proportionate and business aware.

 

At the very heart of every DF Capital employee is a shared identity and belief in what we are and what we do. It’s about how we see ourselves and what is important to us. You will live our brand values. As such you will be an approachable, empathetic problem solver, with exemplary communications skills. You will avoid the use of unnecessary jargon and display an adaptable, “can-do” attitude.

Essential skills, knowledge and behaviours

  • Degree, apprenticeship, placement experience or equivalent self-directed learning in cyber security, computer science, information technology, cloud, networking or a related discipline.
  • Good foundational understanding of operating systems, especially Windows, with awareness of Linux being beneficial.
  • Understanding of networking fundamentals such as DNS, DHCP, TCP/IP, VPNs, firewalls, web protocols and common authentication flows.
  • Awareness of core cyber security concepts including confidentiality, integrity, availability, phishing, malware, ransomware, vulnerability management, MFA, least privilege and secure configuration.
  • Basic understanding of cloud services, preferably Microsoft Azure and/or AWS, including identity, access, logging and shared responsibility principles.
  • Interest in AI security, including safe use of generative AI, data leakage, prompt injection, model governance, third-party AI tooling and responsible adoption of AI in business processes.
  • Ability to use or learn scripting/querying for investigation and automation, such as PowerShell, Python, SQL or KQL-style log queries.
  • Strong analytical mindset with the ability to investigate issues logically, document evidence and know when to escalate.
  • Clear written and verbal communication skills, including the ability to explain technical risk to non-technical colleagues.
  • High integrity, discretion and respect for confidentiality when handling security events, user information and sensitive business data.
  • Strong sense of ownership, attention to detail and ability to follow tasks through to completion.
  • Willingness to learn new technologies and maintain current knowledge of the cyber threat landscape.

 

Desirable skills and experience• Exposure to Microsoft 365 security, Entra ID, Defender, Intune, Sentinel, CrowdStrike, Arctic Wolf, vulnerability management platforms or similar tooling.

  • Familiarity with security alerts, log review, threat intelligence, incident playbooks, phishing analysis or endpoint investigation.
  • Understanding of regulatory and assurance expectations relevant to financial services, such as GDPR, operational resilience, Cyber Essentials Plus, ITGC or supplier assurance.
  • Experience supporting service desk, application support, cloud administration, infrastructure operations or technical project delivery.
  • Relevant certifications or active study towards certifications such as CompTIA Security+, Network+, Microsoft SC-900, AZ-900, AWS Cloud Practitioner or equivalent.
  • Private medical insurance for you and your partner
  • 10% Employer pension contribution
  • 30-day annual leave entitlement plus Bank/Public Holidays
  • Free Gym Membership
  • Discretionary annual bonus
  • Discretionary share awards
  • Life Assurance
  • Income Protection
  • Save As You Earn company share acquisition scheme
  • Tax efficient salary sacrifice scheme to obtain bicycles and electric vehicles
  • 4 days of paid Volunteering leave to support our local communities and causes important to you
  • A world class workspace; high-end, modern, and sophisticated office bursting with tech located in the creative district of Manchester.