Job Description
Job Location:  Woolpit
Additional Location Information: 
Salary:  £33270
Contract type:  Permanent
Posting End Date:  09/10/2026

 

At BUUK Infrastructure, our vision is to be the leading utility partner to accelerate the UK towards net zero for all our customers. Our group of companies has been the major drive for change and innovation over 30 years. 

We provide a supportive environment that is committed to enabling our people to be the best – ensuring they feel proud to be themselves and part of BUUK Infrastructure.

We are looking for a Graduate Cyber Security Analyst who would like to help us reach our mission to “earn customer loyalty and drive business growth by providing consistently excellent service”.

 

(The graduate scheme follows a three-stage interview process. Candidates who are successful at the telephone interview stage will be invited to attend an Assessment Centre at our head office in Woolpit, Suffolk on Thursday 3rd December. Please note that this is currently the only Assessment Centre scheduled). 

Purpose of this role

The Graduate Cyber Security Analyst is an entry-level development role within ICT – Information Security, reporting to the Information Security Manager. The role is designed for a recent graduate who wants to build a career in cyber security, information governance, data protection and/or risk management. 

Working under the guidance of experienced colleagues, the postholder will support operational security, projects, governance, risk, compliance and data-protection activities. The role will provide structured exposure to technical and non-technical security disciplines, enabling the graduate to build core knowledge, practical experience and professional confidence.

The Information Security team protects organisational information assets, supports legal and regulatory compliance, manages cyber risk, responds to security incidents, delivers security improvements and helps embed secure practices throughout the business.

Your key responsibilities are

Assist with vulnerability-management activities across infrastructure, cloud services, applications and end-user devices.

Support security monitoring, alert triage, investigation and threat-research activities under appropriate supervision.

Assist with information security incident investigation, evidence gathering, documentation and follow-up actions.

Support security testing, control validation and remediation activity.

Help maintain security technologies, procedures, reports, metrics and management information.

Work collaboratively with project managers, business stakeholders and the PMO to support secure delivery of technology and business change.

Assist with security reviews of new systems, applications, cloud services and technologies.

Help document security requirements, actions, risks and decisions throughout project lifecycles.

Support reviews of AI, machine learning and emerging technologies to identify security, privacy, governance and risk considerations.

Support Data Protection Impact Assessments, privacy reviews and GDPR compliance activities.

Assist with personal-data breach investigations, information classification and data-handling guidance.

Support supplier and third-party security and privacy assessments.

Contribute to data governance and information-management initiatives.

Support information security risk assessments and gain experience of risk-management methods.

Assist with risk registers, action tracking, policies, standards, procedures and guidance.

Assist with evidence gathering and administration supporting ISO 27001, internal governance, regulatory compliance, audits and assurance.

Support business continuity, disaster recovery, security awareness and governance reporting.

Complete structured objectives and rotations across security operations, cyber risk, privacy, governance, projects and awareness.

Work with an assigned manager and experienced colleagues through coaching, mentoring and regular development reviews.

Undertake formal training and study towards agreed role-relevant certifications.

Participate in security forums, practical exercises, investigations, projects and continual-improvement initiatives.

Travel between company locations may be required.

Standby or out-of-hours support is not initially expected but may be reviewed as capability develops.

Qualifications

Bachelor's degree in Cyber Security, Computer Science, Information Technology, Digital Forensics, Information Systems or another relevant technology-related discipline.

Or

An equivalent qualification with a demonstrable interest in cyber and information security.

Experience/Knowledge

Understanding of fundamental cyber security principles.

Basic knowledge of computer networking concepts and protocols.

Understanding of Microsoft Windows and/or Linux operating systems.

Awareness of common cyber threats and attack techniques.

Basic understanding of privacy, data protection, governance and risk concepts.

Evidence of interest in cyber security through study, projects, placements, volunteering, professional communities or independent learning.

No previous full-time cyber security experience is required.

Abilities/Skills

Strong analytical and problem-solving potential.

Clear written and verbal communication.

Good organisation, time management and attention to detail.

Ability to communicate with technical and non-technical colleagues.

Curiosity and enthusiasm for technology and security.

Integrity, professionalism and respect for confidential information.

Willingness to ask questions, receive feedback and learn from experienced colleagues.

Ownership of assigned work and commitment to completing agreed actions.

Ability to work collaboratively across varied technical and business subject areas.

Desirable

Placement year, internship, part-time work or project experience in a technology-related environment.

Knowledge of Microsoft 365, Azure, Microsoft Sentinel, Microsoft Defender or Microsoft Entra ID.

Familiarity with scripting or automation using PowerShell or Python.

Awareness of UK GDPR and data-protection legislation.

Exposure to cyber security tools, labs, capture-the-flag exercises or university/personal security projects.

Awareness of ISO 27001, risk-management or governance concepts.

Progress towards, or interest in, certifications such as ISC2 Certified in Cybersecurity, CompTIA Security+, SC-900, SC-200 or ISO 27001 Foundation.

Conditions of Employment

What can you expect from us

Cost of living annual pay review.

Company pension contributions up to 10% if employees contribute 5%.

33 days holiday including bank holidays with the ability to purchase an additional 2 weeks.

Enhanced maternity, paternity and adoption pay.

To say thank you, each time you successfully refer someone you will receive a referral payment of £1000 (net of tax).

Hybrid working for eligible roles.

Development opportunities to reach your career aspirations.

 

BUUK has an award-winning culture. We care about your wellbeing and safety as we all deserve the right to go home safe, every day. We are proud to be an equal opportunity employer, we respect each other and advocate for equity, diversity and inclusion in all we do.

Research shows that women and people from different underrepresented backgrounds often only apply for a job if they meet 100% of the listed qualifications. If you would like to be a part of our team and you meet many, but not all our requirements for this role, please apply. You can also ask us about flexible working options.

Please note we reserve the right to close the role early. Therefore, if you're interested in this role, we encourage you to apply as soon as possible.

#BUUK

What's the best thing about BUUK?

We asked our people.

 

From the supportive culture and opportunities to grow, to the great friends and chocolate brownies, our people tell us what they love most about working at BUUK.

 

We all matter.

Find out about our supportive culture.

 

Hear how our shared sense of mutual respect and belonging underpins out culture and supports us all.