Thorntons Law LLP
Cyber Security Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
CYBER SECURITY ANALYST
DUNDEE OR EDINBURGH
At Thorntons Law, every moment matters. Join us as our Cyber Security Analyst and you’ll feel inspired. You’ll feel connected. You’ll feel like you belong. And it all begins from the moment you join us.
That’s because we’ve created a different kind of law firm. Here, you’ll build relationships with clients and colleagues that really last. You’ll help shape what happens now, and what comes next. And we’ll support and encourage you to be the best you can be.
This is what life at Thorntons is all about. And this is your moment to be part of it.
About the role
At Thorntons, protecting our people, clients, information and technology is essential to everything we do. As our Cyber Security Analyst, you’ll play an important role in helping keep the firm safe from cyber threats and information security risks.
You’ll work across security monitoring, vulnerability management, security technology and incident response, helping ensure our security controls operate effectively and continue to evolve as the threat landscape changes.
Working alongside our wider technology teams, security partners and colleagues across the firm, you’ll investigate security events, identify risks, support remediation and help promote strong security behaviours.
It’s about:
- Security Monitoring & Incident Response – monitoring security alerts and events, carrying out initial investigation and triage, escalating incidents where required and supporting incident response activities, including evidence gathering and post-incident reviews.
- Vulnerability & Security Controls – conducting vulnerability assessments, supporting remediation activities and monitoring progress; helping maintain secure configurations across endpoints, servers, cloud services and networks; and checking that security controls are operating effectively.
- Security Technology & Administration – supporting the day-to-day operation and administration of security technologies including Microsoft Sentinel, Microsoft 365 security capabilities, endpoint protection, email security, multi-factor authentication, conditional access and identity protection.
- Identity & Access Security – supporting access reviews, privileged access monitoring and other activities that help ensure appropriate and secure access to the firm’s systems and information.
- Analysis & Continuous Improvement – analysing security data, producing reports and dashboards, identifying trends and helping to strengthen our security controls, monitoring capability and operational processes.
- Documentation & Compliance – maintaining accurate procedures, knowledge articles and security records, while supporting audits, compliance reviews, evidence gathering and policy and standards reviews.
- Security Awareness – supporting cyber security awareness campaigns and providing colleagues with practical guidance on security best practice and the safe use of technology.
- Collaboration – working closely with infrastructure, service delivery, data and business teams, as well as suppliers and security partners, to resolve security issues and strengthen our overall cyber resilience.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What you’ll need
We’re looking for:
- Strong analytical and problem-solving skills, with excellent attention to detail, accuracy and organisation, and the ability to investigate security alerts and events, identify potential risks and make appropriate decisions about escalation.
- A good understanding of cyber security principles, controls and frameworks, with knowledge of vulnerability management, remediation and security best practice.
- Knowledge of Microsoft 365 and Azure security capabilities and products, with familiarity with security monitoring, SIEM and endpoint protection technologies.
- An understanding of identity and access management concepts, including access controls, privileged access and authentication technologies.
- A sound understanding of networking, operating systems and cloud platforms, with the ability to apply this knowledge when investigating security issues.
- Effective verbal and written communication skills, with the ability to explain security matters clearly to both technical and non-technical audiences, alongside a customer and service-focused approach and the ability to prioritise effectively in a fast-changing environment.
- A proactive approach to learning, with a willingness to stay up to date with emerging threats, attack techniques and security technologies and continually develop your cyber security knowledge.
- The ability to work collaboratively with technology teams, colleagues across the firm, suppliers and security partners to resolve issues, manage risk and support continuous improvement.
- Someone who brings curiosity, accountability, attention to detail and a genuine desire to help make the firm more secure.
Why this role
- Make a real difference – play an important role in protecting our people, clients, information and systems from an ever-changing cyber threat landscape.
- Build your expertise – gain practical experience across security monitoring, vulnerability management, incident response, identity security and modern security technologies.
- Work with modern security technology – develop your experience with Microsoft Sentinel, Microsoft 365 security capabilities, endpoint protection and cloud security.
- Keep learning – stay close to emerging threats, attack techniques and new security capabilities while developing your technical skills.
- Work across the firm – collaborate with talented colleagues across technology and the wider business, as well as specialist security partners and suppliers.
- Help shape continuous improvement – contribute ideas and improvements that strengthen our security controls, processes and overall cyber resilience.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
What we offer
We offer much more than just a competitive salary, and we’re committed to looking after our people in every way. Here’s just some of the benefits available:
Benefits
- 39 Days Annual Leave (includes 5 fixed public holidays)
- Contributory Pension Scheme with salary exchange
- Private Medical Insurance
- Critical Illness Cover
- Income Protection Cover
- Group Life Assurance
- Exceptional maternity, paternity, partner and adoption leave packages
- Assisted Conception & IVF Leave
- Health care cash plan to support everyday health expenses
- 24-hour wellbeing support
- Free Legal fees for moving home and life planning
- Cycle to Work Scheme
- Gym Discounts
- Retail Discounts
- Hybrid Working
Professional development
Access to a wide range of opportunities to build your expertise and advance your career, through courses, specialist accreditations, training, or business skills development.
Belonging
At Thorntons, we embrace diversity and are committed to creating a welcoming and inclusive workplace where everyone can thrive.
As a Disability Confident employer, we want to ensure that everyone has a positive experience when applying to join us. If you have a disability or are neurodivergent and need any adjustments during the recruitment process, just let us know — we’ll do everything we can to support you.
We work flexibly to meet the needs of our clients and our people. While not every role is the same, most offer a hybrid working pattern. We’ll work with you to agree the right arrangement that supports you, the role, and our clients.
Make the moment matter
If you’re looking to build your career in cyber security and make a real difference, this is the moment to take your next step.
All you need to do is apply by 30th September and we’ll be in touch.
Please note that we may close this vacancy early if we receive a high volume of applications, so we encourage you to apply as soon as possible.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location