Security Analyst
AXA·London·United Kingdom·Networking & Systems Engineering
AXA is hiring a Security Analyst in London. Posted 2026-09-23; applications close 2026-11-22 (in 53 days).
Role details
About AXA:
AXA is a global leader in insurance and financial services, dedicated to helping customers protect what matters most to them. As the sixth-largest insurance company in the world, we provide a wide range of services, including health, car, home, and business insurance. We support millions of customers worldwide, helping them navigate life's uncertainties with confidence. AXA UK Support Functions look after our three customer-facing business units, providing the infrastructure and expertise to make sure we can be there for our customers.
Job Overview
We have a new opportunity for a Security Analyst to join our Proactive Security team in AXA UK to support our Breach and Attack Simulation (BAS) tooling. As part of AXA UK's Cyber Security function, you will move beyond simply identifying vulnerabilities in the traditional way—you'll play an active role in continuously challenging our defences using real-world attacker techniques.
This role sits at the intersection of technical depth and strategic impact, giving you exposure to complex and regulated environments. You’ll work with industry-leading frameworks, cutting-edge tooling, and experienced security professionals, building skills and credibility that will serve you throughout your career.
Key Responsibilities
- Reviewing threat intelligence feeds and penetration test findings to identify and prioritise use cases for Breach and Attack Simulation (BAS), ensuring our testing reflects the real-world threat landscape.
- Supporting penetration testing engagements by validating that scope is appropriate and that reports meet AXA's standards, gaining exposure to a wide variety of technical assessments.
- Reviewing remediation plans from penetration testing activity, ensuring proposed fixes genuinely address identified issues within acceptable timeframes, and subsequently verifying these fixes using BAS tooling.
- Reacting to BAS control test failures, investigating root causes, and raising targeted remediation requests with the appropriate technical teams.
- Producing clear, meaningful metrics and reports for executive steering groups, translating complex technical findings into actionable insight for senior audiences.
- Constantly looking for opportunities to sharpen, simplify, and scale our processes; your ideas will be welcomed and acted upon.
Work Arrangements
At AXA, we work smart, empowering our people to balance their time between home and the office in a way that works best for them, their team, and our customers. You will be required to work at least two days a week (40%) away from home, moving to three days a week (60%) from December 2026. Away from home means attending the office, visiting clients, or attending industry events.
We are also happy to consider flexible working arrangements, which you can discuss with Talent Acquisition.
Skills & Experience
- Prior hands-on technical penetration testing experience (internal, external, web application, cloud).
- A deep understanding of IT systems and vulnerabilities, ideally spanning cloud environments (AWS, Azure, GCP), infrastructure components such as web and application servers, firewalls, proxies, and operating systems, and application code security.
- Experience in cloud security engineering, architecture, or general IT infrastructure is advantageous.
- Strong analytical and problem-solving skills, with the ability to delve into technical detail.
- Confidence to challenge ambiguity and ask the right questions.
- A genuine curiosity about how systems can be broken and how to make them more resilient.
- Comfortable working with industry frameworks, including threat behaviour modelling (e.g., MITRE ATT&CK), vulnerability management (e.g., CVSS), penetration testing standards (e.g., CREST, CBEST, TIGER), and security frameworks (e.g., NIST, ISO 27001/27002).
- OSCP or equivalent practical penetration testing certification, or an MSc in Cyber Security or Information Technology is desirable but not essential.
How to Apply
To apply, click on the ‘Apply Now’ button. You will then need to log in or create a profile to submit your CV.
We are proud to be an Equal Opportunities Employer and do not discriminate against employees or potential employees based on protected characteristics. If you have a long-term condition or disability and require adjustments during the application or interview process, we are proud to offer access to the AXA Accessibility Concierge. For support, please send an email to lauren.standen@axa-insurance.co.uk.
More open roles at AXA
- AXA XL Intern – Distribution (Part-Time)
Hong Kong · 1d ago
- Underwriter I - Marine Liability & Ports
London · 12d ago
- Actuarial Intern
Hong Kong · 22d ago
- Distribution Training Specialist (Wealth Management)
Hong Kong · 2mo ago
- Broker Service Officer
Hong Kong · 4mo ago
Other open Networking & Systems Engineering roles
- Systems Administrator (New York)
D. E. Shaw · New York · 1mo ago
- Systems Engineering Intern (London) - Summer 2027
D. E. Shaw · London · 4mo ago
- Data Center Engineer
Tower Research Capital · Singapore · 3h ago
- ICIT Maintenance Engineer (USV)
ST Engineering · Singapore · 1d ago
- Assistant System Field Engineer
ST Engineering · Singapore · 1d ago
Applying to this role
This Security Analyst role at AXA runs through the firm's own careers portal and expects a CV and cover letter written specifically for the posting, not a portable submission carried across firms. Jorb AI's application agent tailors a CV and cover letter from your background to this posting and tracks the role alongside the rest of your applications.
Jorb AI tracks details for Security Analyst at AXA. Postings refresh hourly from primary careers pages. Job details mirror the firm's posting; the apply link goes directly to the source. Last refreshed 2026-09-30.
