About this role
We are Lightsource bp – and we're on a mission to become a global leader in onshore renewables, anchored by our proven track record in solar development.
For over a decade we've been actively working to diversify the way our world is powered with sustainable and responsible renewable power. We work to safely deliver affordable, reliable, large-scale onshore renewable and energy storage solutions to help the world decarbonise.
Our growing business is constantly innovating and investing to help drive the energy transition. Our people and projects are focused on supporting long-term sustainable growth and energy security.
Lightsource bp operates with five core values: Safety, Integrity, Respect, Sustainability, and Drive.
We seek to attract and hire individuals who share our commitment to creating a safe workplace, uphold the highest standards of integrity, and demonstrate respect for colleagues, communities, and the environment. Our recruitment process promotes sustainability by valuing long-term growth and responsible practices, while seeking candidates with the drive to innovate and lead in the global energy transition.
Together, these values shape how we engage, assess, and welcome talent to join us in delivering transformational solar power solutions worldwide.
Lightsource bp was fully acquired by bp in 2024.
What you'll do (the role)
Summary
We are seeking a dynamic, hands-on Senior Cybersecurity Analyst to monitor cyber risk and lead the remediation of identified vulnerabilities across Lightsource bp's IT systems globally. You will be responsible for threat detection, investigation, and incident response, leveraging a modern security technology stack with a strong focus on the Microsoft Defender ecosystem. Working across multiple business areas and time zones, you will proactively hunt for security issues, assess emerging threats, and partner with infrastructure and support teams to strengthen our security posture and drive business cyber maturity.
Responsibilities of the Role
Continuously monitor the organization's security systems and infrastructure using SIEM, EDR, and related toolsets to detect signs of compromise and investigate security events to completion
Proactively conduct threat hunting using threat intelligence frameworks (MITRE ATT&CK, Cyber Kill Chain) and available security platforms to identify and mitigate emerging threats
Assess new and evolving cyber threats to the business, optimizing existing Microsoft Defender technologies and other security solutions to better counter identified risks
Identify vulnerabilities in systems and applications; collaborate with Infrastructure, Digital Workplace, and Support teams to prioritize, patch, and remediate issues in a timely manner
Manage core Security Operations (SecOps) tooling platforms, ensuring correct configuration, maximizing security value from existing investments, and maintaining high-quality configuration documentation
Communicate proactively with stakeholders across the business, providing clear technical and non-technical updates during investigations and escalations
Support the development, enforcement, and continuous improvement of cloud security policies, standards, and procedures in alignment with industry frameworks (NIST 2.0, CIS, NIS2) and regulations
Create and maintain security awareness training content and assist in its delivery to colleagues across the organization
Why you'll make a great member of the team
Experience & Knowledge Required
Experience
5+ years of professional experience in cybersecurity, with at least 2+ years in a Security Operations Center (SOC) or incident response role
Advanced proficiency with Microsoft Defender XDR and expert-level knowledge of Microsoft Sentinel, including KQL query writing and analytics rule development
Strong hands-on experience with Microsoft Defender for Endpoint, including policy configuration and threat investigation
Demonstrable experience responding to cyber threats and working in an Azure-focused cloud environment
Proven experience with the Cyber Kill Chain, MITRE ATT&CK, and other security defence and intelligence frameworks
Experience in stakeholder management and engagement at C-Suite level
Experience working for Critical National Infrastructure (CNI) organizations is desirable
Knowledge
Microsoft Security Stack: Defender XDR/Sentinel, Defender for Cloud, Defender for Cloud Apps, Defender EASM, Copilot for Security
Vulnerability Management: Defender XDR, Tenable IO/Nessus, Defender EASM
Data Governance & IDAM: Microsoft Purview (DLP and information governance), Entra ID, Conditional Access Policies
Device Management: Working understanding of Intune (MDM/MAM)
Networking/Firewalls: Exposure to Cisco Meraki and Fortinet FortiGate (desirable)
Regulatory & Compliance Frameworks: NIST 2.0 Cyber Security Framework (required); NIS2, NERC CIP, SOC2, and IEC 62443 OT standards (desirable)
ITIL Principles: Good understanding of ITIL principles and their application to IT service management
Information Security Technologies: Firewalls, intrusion detection systems, vulnerability assessment tools, logging solutions, gateway and endpoint security products, and authentication mechanisms
Operational Technology (OT) Cyber Security: Desirable but not required
Skills Required
Advanced threat detection, investigation, and incident response capabilities
Strong technical troubleshooting and problem-solving skills with ability to work across complex, global technology environments
Expert-level proficiency with Microsoft security tools and cloud-based security architectures
Excellent communication skills: ability to translate complex technical concepts for both technical and non-technical audiences
Proactive mindset with genuine enthusiasm for cybersecurity and drive to improve security posture
Ability to remain calm under pressure and manage multiple incidents and priorities
Cross-functional collaboration: ability to partner effectively with Infrastructure, Digital Workplace, Support, and business teams worldwide
Strong documentation and reporting skills for both technical and executive audiences
Subject matter expertise with proven ability to identify and champion security improvement opportunities
Education Required
Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field
Industry-recognized certification (one or more of the following):
Azure Security Engineer (AZ-500)
Certified Information Systems Security Professional (CISSP)
Certified Cyber Professional (CCP)
CompTIA Security+
GIAC Certified Incident Handler (GCIH)
GIAC Certified Intrusion Analyst (GCIA)
Additional Notes / Role-Specific Requirements
Working Environment
This is a global role supporting an expanding, geographically dispersed workforce and technology stack
You will interface regularly with multiple business areas across different time zones
You will work within a small, talented cybersecurity team and collaborate with a global IT organization
The role requires engagement with the convergence of IT and Operational Technology (OT) security, reflecting the evolving landscape of energy infrastructure protection
International regulatory compliance knowledge will be increasingly important as the organization scales across multiple jurisdiction
Why you'll want to work for us
Our company is a place where you can be yourself and grow, a place where your ideas and opinions matter.
Be you: We pride ourselves on being an inclusive community, where every individual is valued and treated with respect.
Be responsible: Our culture is driven by our core values – from operating safely to ensuring our projects are responsible.
Be recognized: Alongside a competitive salary, we offer a variety of benefits including annual bonus, retention bank, health insurance, pension and other local benefits.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in London →Why this fits a police background — match score 90/100
- Intelligence & OSINT
- Incident command & response
- Investigative casework
- Working to legislation & regulation
- Security operations
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |