William Grant & Sons
Information & Cyber Security Specialist

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Information & Cyber Security Specialist
We are looking for an experienced Information & Cyber Security Specialist to join our newly integrated Cyber Security function. This role has a primary focus on security operations, incident investigation, detection engineering, vulnerability management and security automation and orchestration. It offers the opportunity to take meaningful ownership of operational security capabilities, influence how they develop and help shape a modern, intelligence-led and increasingly automated Cyber Security function.
Reporting into the Information & Cyber Security Leader, you will work hands-on with security technologies, investigations and improvement activity, while collaborating with colleagues across Cyber Security, Architecture, IT Operations, business teams and our external security providers. This is not a line management role. However, you will have the autonomy to shape assigned capabilities, improve how services operate, share your expertise and support the development of colleagues.
What We Can Offer You
- Competitive salary and benefits designed to promote employees' financial wellbeing
- Eligibility to participate in a bonus plan
- Generous holiday entitlement with an opportunity to ‘buy’ or ‘sell’ some holiday entitlement
- Private Healthcare and Doctor@Hand (remote GP service)
- Defined contribution pension plan
- Employee Assistance Programme offering support on various matters
- Life Assurance cover of eight times your annual basic salary
- Product allocation to enjoy our portfolio of brands
- Cycle to Work scheme with savings and cost spreading
- Opportunity to claim up to £1,000 per year for charity
- Learning resources to help you be your best self
Main Responsibilities
- Investigate security alerts and incidents using SIEM, XDR, identity, endpoint, email, network and cloud telemetry.
- Support the coordination of containment, eradication, and remediation activity, ensuring actions are understood, appropriately prioritised and completed.
- Develop, test and tune security detections, improve alert quality and help maintain visibility of detection coverage against relevant threats and attacker techniques.
- Take ownership of assigned security operations capabilities, identifying weaknesses, proposing improvements and seeing agreed work through to completion.
- Operate vulnerability management processes, including scanning, validation, threat-informed prioritisation, remediation coordination, exception escalation and closure assurance.
- Work with IT Operations, system owners and suppliers to ensure material vulnerabilities and security weaknesses are addressed within agreed timescales.
- Develop automation and orchestration that improve investigation, enrichment, triage, evidence collection, reporting and response workflows.
- Explore and implement appropriate uses of Microsoft Security Copilot, AI and SOAR technologies, ensuring automated activity remains controlled, auditable and subject to appropriate human review.
- Support the operation and improvement of Microsoft Defender, Microsoft Entra, Conditional Access, endpoint security, identity controls and other assigned security technologies.
- Create and maintain clear runbooks, technical procedures, investigation records, service documentation and operational evidence.
- Share knowledge with colleagues and provide practical coaching and quality support to the Information & Cyber Security Analyst.
- Contribute to wider information security, cyber risk, assurance, third-party security, governance and compliance activities as team priorities require.
- Participate in the Cyber Security on-call rota and support the response to significant out of hours cyber incidents.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Our Ideal Candidate
You will have strong hands-on cyber security experience and be comfortable taking an investigation or improvement activity from initial identification through to a clear outcome. You should be able to demonstrate experience in several of the following areas:
- Security incident investigation and response.
- SIEM or XDR investigation.
- Detection engineering and alert tuning.
- Vulnerability management.
- Endpoint, identity, email, network or cloud security.
- Analysing and correlating security telemetry.
- Incident-response procedures and playbooks.
- Security automation, orchestration or scripting.
- Working with a managed SOC, MDR or other external security partners.
- Translating technical findings into clear risks, decisions and actions.
You will also need:
- Strong analytical and investigative judgement.
- The ability to work independently and take ownership of assigned outcomes.
- A practical, delivery-focused approach and willingness to get involved.
- Clear written and verbal communication.
- Willingness to contribute outside your primary specialism when wider Cyber Security priorities require it.
- The existing right to work in the United Kingdom.
Desirable Experience
Experience in any of the following would be advantageous, but is not essential:
- Taegis XDR or MDR.
- Sophos security technologies.
- Microsoft Defender.
- Microsoft Entra and Conditional Access.
- Microsoft Security Copilot.
- Microsoft Sentinel.
- Threat hunting.
- Digital forensics and evidence handling.
- Security Architecture or design assurance.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
How We Work
Our Information Security and Security Operations teams have recently come together as one Cyber Security function. We are developing an integrated operating model covering governance, risk, protection, detection, incident response, resilience, automation and continuous improvement.
Each team member will have areas of expertise and ownership, but cross-skilling and collaboration are fundamental to how the team will operate. You will be encouraged to bring ideas, challenge existing ways of working and put your own stamp on the capabilities assigned to you. You must be willing to support colleagues, share knowledge and help get priority security work over the line as the new function develops.
WORKING ARRANGEMENTS
The role is based in Arete, Cumbernauld (G88 0HH) with an expected working pattern of four days on site and one day working from home. Occasional travel to other WG&S sites will be required. The successful candidate will participate in an out-of-hours call rota.
About William Grant & Sons
A HOME FOR RARE CHARACTERS
William Grant & Sons: a home where Rare Characters thrive.
We value every employee for their rare character, distinctive skills, experience and perspectives. Every one of our colleagues has a role to play in helping us to achieve our growth ambitions.
At William Grant & Sons, our vision is to be A home where rare characters thrive. We value all colleagues for their rare character, distinctive skills, experience and perspectives. Diversity & Inclusion is at the heart of how we do things at William Grant & Sons, fully aligned to our purpose and our company values. We strive to create an environment where we can all be our best and bring our whole selves to work.
OUR AGILE WORKING PHILOSOPHY
Our agile working philosophy is to “Have your best work day everyday”.
Built on trust, we empower our rare characters to have their best work day every day. Where flexibility and positive working experiences help employees to feel connected and release potential across our teams.
We are open to discussing possible agile/flexible working options as part of the recruitment process.
INCLUSIVE RECRUITMENT PROCESS
Diversity & Inclusion is at the heart of how we do things at William Grant & Sons, fully aligned to our purpose and our company values. We want to ensure that our recruitment process is inclusive.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills