The R&D team at Chainalysis is inspired by solving the hardest technical challenges and building products that establish trust in cryptocurrencies. We're a global organization that thrives on challenging work and doing it alongside exceptionally talented teammates. Our industry evolves rapidly, and our mission is to build a flexible, AI-driven platform that automates entity resolution, optimizes data labeling pipelines, and creates predictive models that identify illicit patterns before they accelerate. Our data and solutions have been used to solve some of the world's most high-profile criminal cases and grow consumer access to cryptocurrency safely. Now, by pairing the industry's most trusted blockchain data with agents that reason, investigate, and act, we help our customers scale their workflows as the cryptocurrency economy becomes increasingly mainstream. Chainalysis data has helped solve some of the world's highest-profile criminal and national-security cases and made it safer for people everywhere to access crypto. The Global Intelligence Team produces the attribution at the heart of that data - connecting on-chain activity to the real-world entities behind it, across the global crypto ecosystem. It's the intelligence data moat beneath every Chainalysis product, and what investigators, sanctions authorities, and national-security agencies rely on to follow the money and disrupt threats. Few threats test that mission harder than Iran. Through the IRGC and its Qods Force, a network of proxies and Shia militant groups, state-linked cyber actors, and a sprawling sanctions-evasion apparatus, the Islamic Republic has turned to cryptocurrency to raise, move, and launder value beyond the reach of the traditional financial system - from exchange-based sanctions evasion and crypto mining powered by subsidized energy, to oil- and commodity-for-crypto schemes, dual-use procurement, and the financing of proxies across the region. Making that activity visible on-chain is one of the most consequential problems in crypto intelligence today. As our Iran-focused intelligence analyst - the team's subject-matter expert on Iran and the IRGC - you'll own that problem end to end. This is a depth role: while our analysts cover the breadth of the crypto-services ecosystem, you'll go deep on a single, high-stakes domain - becoming the person, inside Chainalysis and increasingly across the industry, who understands how Iran and its proxies use crypto and can prove it on-chain. You'll own the attribution for Iran's crypto footprint, map how these networks actually operate, turn that into finished intelligence customers act on, and be the expert voice representing Chainalysis on Iran crypto threats. Who you'll work with You'll join a fast-moving, globally distributed team - analysts, threat-domain SMEs, data scientists, and engineers - collaborating across time zones, async and in real time. We move fast, hold each other to a high bar, and back each other up across regions. As the Iran SME, you'll be the single point of depth for the domain and a force multiplier for everyone working adjacent to it. In this role, you'll: Own Iran attribution end to end - the threat-actor entities, their definitions, and the accounts, addresses, and infrastructure they operate: Iranian exchanges and OTC/no-KYC networks, IRGC and IRGC-QF financing, Iranian proxy and Shia militant finance (e.g., Hezbollah, the Houthis, and Iraqi militias), sanctions-evasion infrastructure, Iranian ransomware and state-linked cyber operations, and oil-, commodity-, and procurement-for-crypto flows. Lead the attribution response to Iran-related sanctions events - when OFAC or allied authorities designate Iranian entities, actors, or infrastructure, drive the rapid, high-visibility on-chain attribution that turns those designations into coverage in our data, often against the clock. Map the networks on-chain - trace how Iranian actors raise, move, launder, and cash out value through Iranian VASPs, regional exchanges, mixers, no-KYC swaps, mining operations, and off-ramps, and keep that picture current as they adapt to pressure. Produce finished intelligence - advisory notes, customer and partner briefings, and contributions to flagship publications (the Crypto Crime Report and beyond) that make the Iran crypto threat legible and actionable. Be the named external expert - represent Chainalysis on Iran crypto threats at conferences, on panels, with the press, and in briefings to public- and private-sector partners. Help set the Iran collection agenda - surface what data we need on Iranian networks and feed those requirements into our collection process and priority intelligence requirements; you direct collection for the domain, but it runs through the team's apparatus and prioritization, not you alone. Translate typologies into detection - turn what you learn about Iranian methods into guidance that our products and our customers can operationalize. Build with AI - design and tune the automation that scales your analysis and the team's, and handle the hard cases automation can't. Level up the team - raise the bar on Iran and threat-finance tradecraft broadly, and partner closely with analysts, other SMEs, data science, and engineering. We're looking for candidates who have: Deep, demonstrable Iran expertise - real command of the IRGC and IRGC-Qods Force, Iran's proxy and Shia militant landscape, Iranian sanctions evasion, and/or Iran's illicit-finance and procurement systems. This is the core of the role, and we'll expect you to show it. On-chain tracing ability against Iranian targets - direct experience following Iranian crypto activity on-chain (Iranian exchanges, sanctions evasion, proxy or terror finance), or deep Iran threat-finance expertise paired with proven blockchain-tracing skill you can bring to bear here from day one. A national-security or threat-finance background - intelligence, sanctions, counter-threat-finance, or investigations, from the IC, Treasury/OFAC, law enforcement, the military, a think tank or research institution, or private-sector CTF/sanctions work. Regional fluency - a strong grasp of Iranian geopolitics, the proxy network, and regional financial flows. Farsi (or Arabic) language ability is a significant plus. Elite potential and a proven track record - exceptional aptitude, judgment, and work ethic; you've led hard problems end to end and you raise everyone around you. Excellent writing and communication - this is an outward-facing expert role; your intelligence has to land with analysts, customers, and senior audiences alike. AI-forward instincts - you build automation to scale your work and others', not just use it. Comfort working with data; blockchain forensics experience strongly preferred. 5+ years of relevant analytic, intelligence, or threat-finance experience for a Senior hire; 8+ years and recognized domain authority for a Staff hire. You might also have: Farsi language ability. Direct experience with OFAC sanctions, terror-finance designations, or the designation process. A record of published research or public speaking on Iran, sanctions evasion, or crypto threat finance. Familiarity with Iranian exchange infrastructure, crypto mining as a sanctions-evasion vector, or dual-use procurement networks. AI at Chainalysis AI is not a feature at Chainalysis - it is a new way of working. One that turns instructions into work done, and helps us move faster than the threats we're built to counter, and we expect our employees to take ownership of the output and ensure quality. As the world's most trusted blockchain analytics platform, Chainalysis sits at a rare intersection of proprietary data, regulatory relationships and crypto expertise that makes it uniquely placed to shape and lead the next era of AI-driven intelligence - and we expect everyone here, regardless of role, to be an active part of it. AI fluency is tied directly to how we measure performance and how we plan to win. There is no substitute for your own curiosity. We provide the tools, workflows, and space to experiment - but the expectation is that you develop these capabilities yourself, bring ideas, and collaborate across teams to reinvent the way work gets done. We are not using AI to do less. We are using it to do what was never possible before. About Chainalysis Chainalysis is the blockchain data platform, making it easy to connect the movement of digital assets to real-world services. Powered by deep blockchain data and AI, organizations can investigate illicit activity, manage risk exposure, and develop innovative market solutions built on the industry's most trusted blockchain intelligence. Our mission is to build trust in blockchains, blending safety and security with an unwavering commitment to growth and innovation. You belong here. At Chainalysis, we believe that diversity of experience and thought makes us stronger. With both customers and employees around the world, we are committed to ensuring our team reflects the unique communities around us. We're ensuring we keep learning by committing to continually revisit and reevaluate our diversity culture. We encourage applicants across any race, ethnicity, gender/gender expression, age, spirituality, ability, experience and more. If you need any accommodations to make our interview process more accessible to you due to a disability, don't hesitate to let us know. You can learn more here. We can't wait to meet you. . click apply for full job details
Aug 26, 2026
Full time
The R&D team at Chainalysis is inspired by solving the hardest technical challenges and building products that establish trust in cryptocurrencies. We're a global organization that thrives on challenging work and doing it alongside exceptionally talented teammates. Our industry evolves rapidly, and our mission is to build a flexible, AI-driven platform that automates entity resolution, optimizes data labeling pipelines, and creates predictive models that identify illicit patterns before they accelerate. Our data and solutions have been used to solve some of the world's most high-profile criminal cases and grow consumer access to cryptocurrency safely. Now, by pairing the industry's most trusted blockchain data with agents that reason, investigate, and act, we help our customers scale their workflows as the cryptocurrency economy becomes increasingly mainstream. Chainalysis data has helped solve some of the world's highest-profile criminal and national-security cases and made it safer for people everywhere to access crypto. The Global Intelligence Team produces the attribution at the heart of that data - connecting on-chain activity to the real-world entities behind it, across the global crypto ecosystem. It's the intelligence data moat beneath every Chainalysis product, and what investigators, sanctions authorities, and national-security agencies rely on to follow the money and disrupt threats. Few threats test that mission harder than Iran. Through the IRGC and its Qods Force, a network of proxies and Shia militant groups, state-linked cyber actors, and a sprawling sanctions-evasion apparatus, the Islamic Republic has turned to cryptocurrency to raise, move, and launder value beyond the reach of the traditional financial system - from exchange-based sanctions evasion and crypto mining powered by subsidized energy, to oil- and commodity-for-crypto schemes, dual-use procurement, and the financing of proxies across the region. Making that activity visible on-chain is one of the most consequential problems in crypto intelligence today. As our Iran-focused intelligence analyst - the team's subject-matter expert on Iran and the IRGC - you'll own that problem end to end. This is a depth role: while our analysts cover the breadth of the crypto-services ecosystem, you'll go deep on a single, high-stakes domain - becoming the person, inside Chainalysis and increasingly across the industry, who understands how Iran and its proxies use crypto and can prove it on-chain. You'll own the attribution for Iran's crypto footprint, map how these networks actually operate, turn that into finished intelligence customers act on, and be the expert voice representing Chainalysis on Iran crypto threats. Who you'll work with You'll join a fast-moving, globally distributed team - analysts, threat-domain SMEs, data scientists, and engineers - collaborating across time zones, async and in real time. We move fast, hold each other to a high bar, and back each other up across regions. As the Iran SME, you'll be the single point of depth for the domain and a force multiplier for everyone working adjacent to it. In this role, you'll: Own Iran attribution end to end - the threat-actor entities, their definitions, and the accounts, addresses, and infrastructure they operate: Iranian exchanges and OTC/no-KYC networks, IRGC and IRGC-QF financing, Iranian proxy and Shia militant finance (e.g., Hezbollah, the Houthis, and Iraqi militias), sanctions-evasion infrastructure, Iranian ransomware and state-linked cyber operations, and oil-, commodity-, and procurement-for-crypto flows. Lead the attribution response to Iran-related sanctions events - when OFAC or allied authorities designate Iranian entities, actors, or infrastructure, drive the rapid, high-visibility on-chain attribution that turns those designations into coverage in our data, often against the clock. Map the networks on-chain - trace how Iranian actors raise, move, launder, and cash out value through Iranian VASPs, regional exchanges, mixers, no-KYC swaps, mining operations, and off-ramps, and keep that picture current as they adapt to pressure. Produce finished intelligence - advisory notes, customer and partner briefings, and contributions to flagship publications (the Crypto Crime Report and beyond) that make the Iran crypto threat legible and actionable. Be the named external expert - represent Chainalysis on Iran crypto threats at conferences, on panels, with the press, and in briefings to public- and private-sector partners. Help set the Iran collection agenda - surface what data we need on Iranian networks and feed those requirements into our collection process and priority intelligence requirements; you direct collection for the domain, but it runs through the team's apparatus and prioritization, not you alone. Translate typologies into detection - turn what you learn about Iranian methods into guidance that our products and our customers can operationalize. Build with AI - design and tune the automation that scales your analysis and the team's, and handle the hard cases automation can't. Level up the team - raise the bar on Iran and threat-finance tradecraft broadly, and partner closely with analysts, other SMEs, data science, and engineering. We're looking for candidates who have: Deep, demonstrable Iran expertise - real command of the IRGC and IRGC-Qods Force, Iran's proxy and Shia militant landscape, Iranian sanctions evasion, and/or Iran's illicit-finance and procurement systems. This is the core of the role, and we'll expect you to show it. On-chain tracing ability against Iranian targets - direct experience following Iranian crypto activity on-chain (Iranian exchanges, sanctions evasion, proxy or terror finance), or deep Iran threat-finance expertise paired with proven blockchain-tracing skill you can bring to bear here from day one. A national-security or threat-finance background - intelligence, sanctions, counter-threat-finance, or investigations, from the IC, Treasury/OFAC, law enforcement, the military, a think tank or research institution, or private-sector CTF/sanctions work. Regional fluency - a strong grasp of Iranian geopolitics, the proxy network, and regional financial flows. Farsi (or Arabic) language ability is a significant plus. Elite potential and a proven track record - exceptional aptitude, judgment, and work ethic; you've led hard problems end to end and you raise everyone around you. Excellent writing and communication - this is an outward-facing expert role; your intelligence has to land with analysts, customers, and senior audiences alike. AI-forward instincts - you build automation to scale your work and others', not just use it. Comfort working with data; blockchain forensics experience strongly preferred. 5+ years of relevant analytic, intelligence, or threat-finance experience for a Senior hire; 8+ years and recognized domain authority for a Staff hire. You might also have: Farsi language ability. Direct experience with OFAC sanctions, terror-finance designations, or the designation process. A record of published research or public speaking on Iran, sanctions evasion, or crypto threat finance. Familiarity with Iranian exchange infrastructure, crypto mining as a sanctions-evasion vector, or dual-use procurement networks. AI at Chainalysis AI is not a feature at Chainalysis - it is a new way of working. One that turns instructions into work done, and helps us move faster than the threats we're built to counter, and we expect our employees to take ownership of the output and ensure quality. As the world's most trusted blockchain analytics platform, Chainalysis sits at a rare intersection of proprietary data, regulatory relationships and crypto expertise that makes it uniquely placed to shape and lead the next era of AI-driven intelligence - and we expect everyone here, regardless of role, to be an active part of it. AI fluency is tied directly to how we measure performance and how we plan to win. There is no substitute for your own curiosity. We provide the tools, workflows, and space to experiment - but the expectation is that you develop these capabilities yourself, bring ideas, and collaborate across teams to reinvent the way work gets done. We are not using AI to do less. We are using it to do what was never possible before. About Chainalysis Chainalysis is the blockchain data platform, making it easy to connect the movement of digital assets to real-world services. Powered by deep blockchain data and AI, organizations can investigate illicit activity, manage risk exposure, and develop innovative market solutions built on the industry's most trusted blockchain intelligence. Our mission is to build trust in blockchains, blending safety and security with an unwavering commitment to growth and innovation. You belong here. At Chainalysis, we believe that diversity of experience and thought makes us stronger. With both customers and employees around the world, we are committed to ensuring our team reflects the unique communities around us. We're ensuring we keep learning by committing to continually revisit and reevaluate our diversity culture. We encourage applicants across any race, ethnicity, gender/gender expression, age, spirituality, ability, experience and more. If you need any accommodations to make our interview process more accessible to you due to a disability, don't hesitate to let us know. You can learn more here. We can't wait to meet you. . click apply for full job details
About The Role You will own a defined portfolio of top-tier global MSSPs (excluding GSI/Big 4 relationships). These are security specialist firms operating at scale - running 24 7 SOCs, delivering managed threat intelligence, and integrating platform grade tooling into their service stack. This is not a transactional sales role. It is a strategic ecosystem play - and you will build it from first principles. Also, this is an Individual Contributor role. What You'll Do At Cyble MSSP Ecosystem Strategy Map and prioritise the top 100 global MSSPs by region, security maturity, and GTM fit - identifying those actively building or scaling CTI, DRPS, ASM, and CSPM led managed services. Define a structured, tiered MSSP engagement playbook covering acquisition, activation, ramp, and expansion - with clear milestones for each stage. Maintain deep competitive intelligence on MSSP buying behaviour, vendor preferences, and integration strategies across US, Europe, and beyond. Identify white space across the MSSP landscape where Cyble can displace incumbents or expand adjacent to existing relationships. Partnership Development & Structuring Own the full MSSP partner lifecycle - executive introduction, solution scoping, commercial structuring, legal execution, technical onboarding, and co sell activation. Design scalable partnership models: co sell, white label/OEM, embedded API integration, resell, and managed services enablement frameworks. Work directly with MSSP SOC leads, security practice heads, and CTO level stakeholders to architect integrations that embed Cyble capabilities into live delivery workflows. Drive co branded joint offerings, shared GTM materials, and partner specific use case packaging for CTI as a Service, DRPS, EASM, CSPM, and MDR augmentation. Revenue Ownership & Pipeline Own MSSP sourced ARR targets - accountable for pipeline creation, deal progression, and revenue conversion across your portfolio. Develop multi year strategic account plans for named MSSP partners with expansion paths tied to customer seat growth, additional modules, and geographic scale. Drive Cyble's footprint within MSSP customer bases through joint GTM initiatives, shared pipeline, and influenced revenue programmes. Build commercial structures that work for both Cyble and MSSP economics - including tiered pricing, consumption based licensing, and usage aligned models. Executive Engagement & Market Presence Build and sustain C level relationships with MSSP alliance leaders, CEOs, CISOs, SOC heads, and service delivery executives. Represent Cyble at Tier 1 global cybersecurity events, MSSP focused forums, RSA, GSX, Black Hat, and regional partner summits. Act as the authoritative Cyble voice in MSSP conversations - articulating platform value across threat intelligence, dark web, digital risk, and surface management domains. Cross Functional Alignment Work closely with Product, Threat Intelligence, Engineering, and Marketing to feed MSSP requirements into roadmap and enablement priorities. Collaborate with internal sales teams to ensure clean handoffs, account coverage clarity, and alignment on named MSSP accounts. Provide structured quarterly reporting on MSSP ecosystem health, partner performance, and market intelligence to senior leadership. What You'll Need Ideal Candidate Profile: You have spent your career at the intersection of cybersecurity and strategic partnerships - building programmes, not just managing accounts. You understand how MSSPs buy, what makes integrations stick, and how to construct commercial relationships that drive durable revenue. Experience 12-18+ years in cybersecurity enterprise sales, MSSP alliances, or strategic partnerships - with at least 5 years in a partner led or channel leadership capacity. Demonstrable track record of building and scaling MSSP co sell or managed security platform partnerships across US and/or European markets. Deep familiarity with MSSP commercial models - resell, OEM, white label, co delivery - and the internal economics that drive partner decisions. Hands on experience negotiating and structuring complex, multi year partnership agreements with security focused service providers. Proven success operating as a senior IC: high autonomy, high accountability, minimal reliance on organisational infrastructure. Why This Role? Build it your way - You inherit no playbook. The global MSSP ecosystem is yours to map, prioritise, and activate. Real revenue ownership - Full ARR accountability, not influenced attribution. Your number, your call. Executive visibility - Direct line to Cyble senior leadership. Your MSSP strategy shapes global GTM decisions. Product that wins - AI native, analyst grade intelligence platform that MSSPs actively seek. Your job is to structure the relationship and scale the revenue. Why Cyble? Competitive base salary, OTE, and equity participation Work alongside a globally recognised threat intelligence platform with proven enterprise and government traction Collaborate with a leadership team that has deep cybersecurity operator experience and a genuine partner first conviction About Cyble Cyble is an AI native cybersecurity company delivering best in class threat intelligence, dark web monitoring, and attack surface management to enterprises and governments worldwide. Backed by leading investors and recognised by Gartner (Challenger -Gartner MQ), Forrester, and Frost, Cyble operates across North America, EMEA, and APAC through a partner first go to market motion. Cyble is an equal opportunity employer. We welcome applicants of all backgrounds, identities, and experiences. To learn more visit:
Aug 26, 2026
Full time
About The Role You will own a defined portfolio of top-tier global MSSPs (excluding GSI/Big 4 relationships). These are security specialist firms operating at scale - running 24 7 SOCs, delivering managed threat intelligence, and integrating platform grade tooling into their service stack. This is not a transactional sales role. It is a strategic ecosystem play - and you will build it from first principles. Also, this is an Individual Contributor role. What You'll Do At Cyble MSSP Ecosystem Strategy Map and prioritise the top 100 global MSSPs by region, security maturity, and GTM fit - identifying those actively building or scaling CTI, DRPS, ASM, and CSPM led managed services. Define a structured, tiered MSSP engagement playbook covering acquisition, activation, ramp, and expansion - with clear milestones for each stage. Maintain deep competitive intelligence on MSSP buying behaviour, vendor preferences, and integration strategies across US, Europe, and beyond. Identify white space across the MSSP landscape where Cyble can displace incumbents or expand adjacent to existing relationships. Partnership Development & Structuring Own the full MSSP partner lifecycle - executive introduction, solution scoping, commercial structuring, legal execution, technical onboarding, and co sell activation. Design scalable partnership models: co sell, white label/OEM, embedded API integration, resell, and managed services enablement frameworks. Work directly with MSSP SOC leads, security practice heads, and CTO level stakeholders to architect integrations that embed Cyble capabilities into live delivery workflows. Drive co branded joint offerings, shared GTM materials, and partner specific use case packaging for CTI as a Service, DRPS, EASM, CSPM, and MDR augmentation. Revenue Ownership & Pipeline Own MSSP sourced ARR targets - accountable for pipeline creation, deal progression, and revenue conversion across your portfolio. Develop multi year strategic account plans for named MSSP partners with expansion paths tied to customer seat growth, additional modules, and geographic scale. Drive Cyble's footprint within MSSP customer bases through joint GTM initiatives, shared pipeline, and influenced revenue programmes. Build commercial structures that work for both Cyble and MSSP economics - including tiered pricing, consumption based licensing, and usage aligned models. Executive Engagement & Market Presence Build and sustain C level relationships with MSSP alliance leaders, CEOs, CISOs, SOC heads, and service delivery executives. Represent Cyble at Tier 1 global cybersecurity events, MSSP focused forums, RSA, GSX, Black Hat, and regional partner summits. Act as the authoritative Cyble voice in MSSP conversations - articulating platform value across threat intelligence, dark web, digital risk, and surface management domains. Cross Functional Alignment Work closely with Product, Threat Intelligence, Engineering, and Marketing to feed MSSP requirements into roadmap and enablement priorities. Collaborate with internal sales teams to ensure clean handoffs, account coverage clarity, and alignment on named MSSP accounts. Provide structured quarterly reporting on MSSP ecosystem health, partner performance, and market intelligence to senior leadership. What You'll Need Ideal Candidate Profile: You have spent your career at the intersection of cybersecurity and strategic partnerships - building programmes, not just managing accounts. You understand how MSSPs buy, what makes integrations stick, and how to construct commercial relationships that drive durable revenue. Experience 12-18+ years in cybersecurity enterprise sales, MSSP alliances, or strategic partnerships - with at least 5 years in a partner led or channel leadership capacity. Demonstrable track record of building and scaling MSSP co sell or managed security platform partnerships across US and/or European markets. Deep familiarity with MSSP commercial models - resell, OEM, white label, co delivery - and the internal economics that drive partner decisions. Hands on experience negotiating and structuring complex, multi year partnership agreements with security focused service providers. Proven success operating as a senior IC: high autonomy, high accountability, minimal reliance on organisational infrastructure. Why This Role? Build it your way - You inherit no playbook. The global MSSP ecosystem is yours to map, prioritise, and activate. Real revenue ownership - Full ARR accountability, not influenced attribution. Your number, your call. Executive visibility - Direct line to Cyble senior leadership. Your MSSP strategy shapes global GTM decisions. Product that wins - AI native, analyst grade intelligence platform that MSSPs actively seek. Your job is to structure the relationship and scale the revenue. Why Cyble? Competitive base salary, OTE, and equity participation Work alongside a globally recognised threat intelligence platform with proven enterprise and government traction Collaborate with a leadership team that has deep cybersecurity operator experience and a genuine partner first conviction About Cyble Cyble is an AI native cybersecurity company delivering best in class threat intelligence, dark web monitoring, and attack surface management to enterprises and governments worldwide. Backed by leading investors and recognised by Gartner (Challenger -Gartner MQ), Forrester, and Frost, Cyble operates across North America, EMEA, and APAC through a partner first go to market motion. Cyble is an equal opportunity employer. We welcome applicants of all backgrounds, identities, and experiences. To learn more visit:
Loxam are currently recruiting an IT SOC Analyst to join our IT Security team at our Head Office in Lutterworth. The SOC Analyst - Tier 1 role will be part of the LOXAM Security Operations Centre, reporting to the Director of Security Operations. The SOC Analyst - Tier 1 primary role will be to monitor, detect, contain, and eradicate cyber threats that could impact regular business operations click apply for full job details
Aug 26, 2026
Full time
Loxam are currently recruiting an IT SOC Analyst to join our IT Security team at our Head Office in Lutterworth. The SOC Analyst - Tier 1 role will be part of the LOXAM Security Operations Centre, reporting to the Director of Security Operations. The SOC Analyst - Tier 1 primary role will be to monitor, detect, contain, and eradicate cyber threats that could impact regular business operations click apply for full job details
Business Change Analyst: £43,083 Business Change Manager: £53,000 Senior Business Change Manager: £68,745 All roles attract a Concessionary Payment of £2,758 to £3,144, depending on role. Flexible working: We support part-time working of at least 30 hours per week, compressed hours and job shares and flexible start and finish times. Working from home arrangements will be considered where possible and agreed in line with both personal circumstances and business needs. Due to the sensitive nature of these roles, opportunities to work from home are limited. GCHQ is an intelligence, cyber, and security agency with a mission to keep the UK safe. We use cutting-edge technology, ingenuity, and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners MI5 and MI6, we protect the UK from terrorism, cyber-attacks, and espionage. At GCHQ, you'll do varied and fascinating work in a supportive and inclusive environment that puts the emphasis on teamwork. This is an opportunity to join a collaborative Business Change team delivering a wide range of transformation initiatives across the organisation - from technology implementation and structural reorganisation to cultural change and operating model redesign. At the heart of this work, the role involves helping teams understand not just what is changing, but why - and what it will take to make it successful. Working closely with stakeholders across the business, you'll bring a people-focused perspective to ensure that new systems, structures, and ways of working are understood, adopted, and deliver their intended benefits. The scope of your role will reflect your level of experience. You might be building your capability by supporting elements of a larger programme, delivering smaller scale change, or already leading complex initiatives and advising on the best way forward. At the most senior level, you'll operate as a trusted partner to the business, shaping how change is approached, influencing senior stakeholders, and guiding the organisation through its most challenging transformation. Across all levels, variety is a constant. You'll move between different types of change, teams, and priorities, often at pace, requiring you to adapt your approach and apply the right tools and techniques for each situation. It's about understanding context, people, and outcomes, and responding accordingly. So, what about you? You'll bring experience of delivering business change in a professional environment, along with the judgement to know that no two initiatives are ever quite the same. You're comfortable adapting your approach to suit the context, the people involved, and the outcomes you're trying to achieve. You may be building your experience by contributing to change delivery, or owning smaller initiatives, or already leading complex programmes and advising stakeholders at scale. At the most senior level, you'll be confident influencing decision-making and shaping how change is approached across an organisation. What matters most is how you work. You collaborate naturally, communicate clearly, and build effective relationships across teams. You're curious about different ways of delivering change, open to learning from others, and willing to share your own experience. You're also comfortable working in an environment where priorities can shift, adapting quickly and staying focused on what will deliver the greatest impact. You'll also hold, or be willing to work towards, a recognised Business Change qualification such as APMG or Prosci, with experience across areas such as technology, organisational design, culture, or operating model change. Beyond the role itself, you'll share our values of integrity and respect, along with a collaborative and creative approach, and be motivated by the opportunity to use your expertise to make a positive difference to the UK. At GCHQ diversity and inclusion are critical to our mission. We therefore welcome and encourage applications from everyone, including those from groups that are under-represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio-economic backgrounds. Find out more about our culture, working environment and diversity on our website . To find out more and apply, please visit our website by clicking APPLY NOW. To be eligible to apply, you must be a British Citizen. If you hold dual nationality, of which one component is British, you will nonetheless be considered. Candidates must normally have been resident in the UK for seven out of the last ten years. This is particularly important if you were born outside the UK. You can apply at the age of 17; however, if successful, you will not be offered a start date before your 18th birthday. There is no upper age limit. Full eligibility details can be found on our website .
Aug 26, 2026
Full time
Business Change Analyst: £43,083 Business Change Manager: £53,000 Senior Business Change Manager: £68,745 All roles attract a Concessionary Payment of £2,758 to £3,144, depending on role. Flexible working: We support part-time working of at least 30 hours per week, compressed hours and job shares and flexible start and finish times. Working from home arrangements will be considered where possible and agreed in line with both personal circumstances and business needs. Due to the sensitive nature of these roles, opportunities to work from home are limited. GCHQ is an intelligence, cyber, and security agency with a mission to keep the UK safe. We use cutting-edge technology, ingenuity, and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners MI5 and MI6, we protect the UK from terrorism, cyber-attacks, and espionage. At GCHQ, you'll do varied and fascinating work in a supportive and inclusive environment that puts the emphasis on teamwork. This is an opportunity to join a collaborative Business Change team delivering a wide range of transformation initiatives across the organisation - from technology implementation and structural reorganisation to cultural change and operating model redesign. At the heart of this work, the role involves helping teams understand not just what is changing, but why - and what it will take to make it successful. Working closely with stakeholders across the business, you'll bring a people-focused perspective to ensure that new systems, structures, and ways of working are understood, adopted, and deliver their intended benefits. The scope of your role will reflect your level of experience. You might be building your capability by supporting elements of a larger programme, delivering smaller scale change, or already leading complex initiatives and advising on the best way forward. At the most senior level, you'll operate as a trusted partner to the business, shaping how change is approached, influencing senior stakeholders, and guiding the organisation through its most challenging transformation. Across all levels, variety is a constant. You'll move between different types of change, teams, and priorities, often at pace, requiring you to adapt your approach and apply the right tools and techniques for each situation. It's about understanding context, people, and outcomes, and responding accordingly. So, what about you? You'll bring experience of delivering business change in a professional environment, along with the judgement to know that no two initiatives are ever quite the same. You're comfortable adapting your approach to suit the context, the people involved, and the outcomes you're trying to achieve. You may be building your experience by contributing to change delivery, or owning smaller initiatives, or already leading complex programmes and advising stakeholders at scale. At the most senior level, you'll be confident influencing decision-making and shaping how change is approached across an organisation. What matters most is how you work. You collaborate naturally, communicate clearly, and build effective relationships across teams. You're curious about different ways of delivering change, open to learning from others, and willing to share your own experience. You're also comfortable working in an environment where priorities can shift, adapting quickly and staying focused on what will deliver the greatest impact. You'll also hold, or be willing to work towards, a recognised Business Change qualification such as APMG or Prosci, with experience across areas such as technology, organisational design, culture, or operating model change. Beyond the role itself, you'll share our values of integrity and respect, along with a collaborative and creative approach, and be motivated by the opportunity to use your expertise to make a positive difference to the UK. At GCHQ diversity and inclusion are critical to our mission. We therefore welcome and encourage applications from everyone, including those from groups that are under-represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio-economic backgrounds. Find out more about our culture, working environment and diversity on our website . To find out more and apply, please visit our website by clicking APPLY NOW. To be eligible to apply, you must be a British Citizen. If you hold dual nationality, of which one component is British, you will nonetheless be considered. Candidates must normally have been resident in the UK for seven out of the last ten years. This is particularly important if you were born outside the UK. You can apply at the age of 17; however, if successful, you will not be offered a start date before your 18th birthday. There is no upper age limit. Full eligibility details can be found on our website .
About the job Job summary Discover a career in your hands at HMRC. Whether you're seeking purpose, growth, or a workplace that gives you a true sense of belonging, hear from some of our employees as they share their story about what it's really like to work at HMRC. Visit our YouTube channel to watch the full series and come and discover your potential. Our team is rapidly growing as we invest in new technologies and capabilities, and we are in search of enthusiastic individuals who can help us in achieving our mission. We are continually improving the service we give to our customers and, in line with this, we are creating a new response and management team within the HMRC Fraud Prevention Centre. The Fraud Prevention Centre (FPC) is a strategic capability within HMRC Security, designed to safeguard customers and the organisation against identity-related fraud and emerging threats. Its mission is built on three interconnected pillars: Protection, Detection, and Response, all underpinned by advanced threat intelligence and customer support. The Centre operates across multiple functional areas, including Proactive Protection, Customer Support & Response, and Strategy & Advisory, to deliver a holistic approach to fraud prevention. Job description We're looking for a proactive and analytical professional to support HMRC's fight against identity fraud. You'll help lead data-driven investigations into suspicious activity related to identity verification and authentication services, while working with the team and partners, acting as a key contributor in a team that supports customers and provides insight into identity fraud activity and proactive searching for threats. This is an exciting opportunity to make a real difference, working in a dynamic and evolving environment. Person specification Manipulate and analyse large data sets and investigate suspicious activity. Learn, develop, and apply methods using data analytics techniques such as data mining, data matching, clustering analysis and outlier detection. Use basic scripting languages to develop visualisations and automate effective searches to build a growing analytical suite of capabilities that you can operate efficiently. Have strong communication skills and be able to demonstrate working across business and technical domains. You will have excellent interpersonal skills. Apply your knowledge of security and fraud risks to digital services. Support and deputise for the senior analysts, producing clear, insightful reports and presentations for senior stakeholders. You will be confident working in an environment that may flex its focus in response to emerging issues and have a delivery focus. You will be eager to learn and widen your experience in different areas of identity work. You will use your experience of scripting, for example SPL, Python, SQL, KQL to proactively search and discover anomalies. Be flexible and enthusiastic whilst working with some ambiguity as the team forms, grows and matures. Support senior managers in the reporting of metrics and support the wider aims of the HMRC Security Identity Team. Identify process improvement areas. Essential Criteria Knowledge of fraud detection techniques, including behavioural analysis and anomaly detection and investigation and OSINT (Open Source Intelligence) methods. Data analysis skills and experience with large data sets, with proficiency scripting complex queries in analysis environments. Solid technical understanding of web and API services (e.g. cookies, IP addresses, authentication processes) and threats to those services from cybercrime actors and tools. Experience using Security Information and Event Management (SIEM) platforms, preferably in a security operations setting. A sound understanding of Identity, Verification and Authentication principles. Desirable Criteria A degree in Data Analysis, Data Science, Information Security, Cyber Security, or other Cyber qualifications eg SANS, or at least previous experience in a relevant cyber role. Proven experience in fraud detection, cyber security, or threat intelligence within a large organisation. Active use of at least one of the following: Python, SQL, KQL, SPL. Important Additional Information The successful candidate may be required to apply for Developed Vetting (DV) clearance level once in post but must already hold or be willing to obtain Security Check (SC) clearance level before starting the role. Further Location Information Please ensure that you only apply for a location that you are willing and able to work from, as we will only make one offer of employment. Any additional notes included in a 'Further Location Preferences (optional)' field within the application form, will not be considered. Please be aware that you cannot change your location preference after submitting your application. Office closures For more information on where you might be working, review this information on our locations. If your location preference is for one of the following sites, it's important to note that these are not long-term sites for HMRC and we will require you to move to a new building in the future, subject to our location strategy and the applicable employee policies at that time. These sites are: Benton Park View, Newcastle - moving to Pilgrims Quarter, Newcastle Telford Plaza, Telford - moving to Parkside Court, Telford Trinity Bridge House, Salford - moving to an alternative office in Manchester/ Salford You will be given more information about what this means at the job offer stage. Leeds Locations Moves Adjustment Payment will be available for this role, provided the successful applicant is a current HMRC colleague in Bradford and meets the eligibility requirements outlined in the HMRC's Moves Adjustment Payment guidance. Benefits Alongside your salary of £37,682, HM Revenue and Customs contributes £10,916 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window). HMRC operates both Flexible and Hybrid Working policies, allowing you to balance your work and personal commitments. We welcome applications from those who need to work a more flexible arrangement and will agree to requests where possible, considering our operational and customer service needs. We offer a generous leave allowance, starting at 25 days and increasing by a day for every year of qualifying service up to a maximum of 30 days. Pension - We make contributions to our colleagues' Alpha pension equal to at least 28.97% of their salary. Family friendly policies. Personal support. Coaching and development. To find out more about HMRC benefits and find out what it's really like to work for HMRC hear from our insiders or visit Thinking of joining the Civil Service Things you need to know Artificial intelligence Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use. Selection process details This vacancy is using Success Profiles (opens in a new window), and will assess your Strengths and Experience. How to Apply As part of the application process, you will be asked to provide the following: A name-blind CV including your job history, previous experiences and qualifications. Qualifications are not mandatory for this role. A 750-word Personal Statement. Your Personal Statement should be used to describe how your skills and experience would be suitable for the advertised role, making reference to the Essential Criteria and Person Specification outlined in the advert. Please complete a separate statement (Max 250 words) for the Desirable Criteria where applicable. This is not essential for the role but may be considered by the vacancy-holder where candidates have the same scores at interview. Further details around what this will entail are listed on the application form. Prior to applications being sifted candidates will be asked to complete an additional IKM assessment. Candidates will be sent details of the assessment once the advert has closed. This assessment is a pass or fail and only those who pass will be considered at the sift stage. Sift In the event of a large number of applications being received, an initial sift may be held on your CV. At full sift your CV and your Personal Statement will be assessed, with the successful candidates being invited to interview. We may also raise the score required at any stage of the process if we receive a high number of applications. Interview During the panel interview, your experience will be assessed, and you will be asked strength-based questions to also explore what you enjoy and your motivations relevant to the job role. This is an example of a strengths-based question: . click apply for full job details
Aug 26, 2026
Full time
About the job Job summary Discover a career in your hands at HMRC. Whether you're seeking purpose, growth, or a workplace that gives you a true sense of belonging, hear from some of our employees as they share their story about what it's really like to work at HMRC. Visit our YouTube channel to watch the full series and come and discover your potential. Our team is rapidly growing as we invest in new technologies and capabilities, and we are in search of enthusiastic individuals who can help us in achieving our mission. We are continually improving the service we give to our customers and, in line with this, we are creating a new response and management team within the HMRC Fraud Prevention Centre. The Fraud Prevention Centre (FPC) is a strategic capability within HMRC Security, designed to safeguard customers and the organisation against identity-related fraud and emerging threats. Its mission is built on three interconnected pillars: Protection, Detection, and Response, all underpinned by advanced threat intelligence and customer support. The Centre operates across multiple functional areas, including Proactive Protection, Customer Support & Response, and Strategy & Advisory, to deliver a holistic approach to fraud prevention. Job description We're looking for a proactive and analytical professional to support HMRC's fight against identity fraud. You'll help lead data-driven investigations into suspicious activity related to identity verification and authentication services, while working with the team and partners, acting as a key contributor in a team that supports customers and provides insight into identity fraud activity and proactive searching for threats. This is an exciting opportunity to make a real difference, working in a dynamic and evolving environment. Person specification Manipulate and analyse large data sets and investigate suspicious activity. Learn, develop, and apply methods using data analytics techniques such as data mining, data matching, clustering analysis and outlier detection. Use basic scripting languages to develop visualisations and automate effective searches to build a growing analytical suite of capabilities that you can operate efficiently. Have strong communication skills and be able to demonstrate working across business and technical domains. You will have excellent interpersonal skills. Apply your knowledge of security and fraud risks to digital services. Support and deputise for the senior analysts, producing clear, insightful reports and presentations for senior stakeholders. You will be confident working in an environment that may flex its focus in response to emerging issues and have a delivery focus. You will be eager to learn and widen your experience in different areas of identity work. You will use your experience of scripting, for example SPL, Python, SQL, KQL to proactively search and discover anomalies. Be flexible and enthusiastic whilst working with some ambiguity as the team forms, grows and matures. Support senior managers in the reporting of metrics and support the wider aims of the HMRC Security Identity Team. Identify process improvement areas. Essential Criteria Knowledge of fraud detection techniques, including behavioural analysis and anomaly detection and investigation and OSINT (Open Source Intelligence) methods. Data analysis skills and experience with large data sets, with proficiency scripting complex queries in analysis environments. Solid technical understanding of web and API services (e.g. cookies, IP addresses, authentication processes) and threats to those services from cybercrime actors and tools. Experience using Security Information and Event Management (SIEM) platforms, preferably in a security operations setting. A sound understanding of Identity, Verification and Authentication principles. Desirable Criteria A degree in Data Analysis, Data Science, Information Security, Cyber Security, or other Cyber qualifications eg SANS, or at least previous experience in a relevant cyber role. Proven experience in fraud detection, cyber security, or threat intelligence within a large organisation. Active use of at least one of the following: Python, SQL, KQL, SPL. Important Additional Information The successful candidate may be required to apply for Developed Vetting (DV) clearance level once in post but must already hold or be willing to obtain Security Check (SC) clearance level before starting the role. Further Location Information Please ensure that you only apply for a location that you are willing and able to work from, as we will only make one offer of employment. Any additional notes included in a 'Further Location Preferences (optional)' field within the application form, will not be considered. Please be aware that you cannot change your location preference after submitting your application. Office closures For more information on where you might be working, review this information on our locations. If your location preference is for one of the following sites, it's important to note that these are not long-term sites for HMRC and we will require you to move to a new building in the future, subject to our location strategy and the applicable employee policies at that time. These sites are: Benton Park View, Newcastle - moving to Pilgrims Quarter, Newcastle Telford Plaza, Telford - moving to Parkside Court, Telford Trinity Bridge House, Salford - moving to an alternative office in Manchester/ Salford You will be given more information about what this means at the job offer stage. Leeds Locations Moves Adjustment Payment will be available for this role, provided the successful applicant is a current HMRC colleague in Bradford and meets the eligibility requirements outlined in the HMRC's Moves Adjustment Payment guidance. Benefits Alongside your salary of £37,682, HM Revenue and Customs contributes £10,916 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window). HMRC operates both Flexible and Hybrid Working policies, allowing you to balance your work and personal commitments. We welcome applications from those who need to work a more flexible arrangement and will agree to requests where possible, considering our operational and customer service needs. We offer a generous leave allowance, starting at 25 days and increasing by a day for every year of qualifying service up to a maximum of 30 days. Pension - We make contributions to our colleagues' Alpha pension equal to at least 28.97% of their salary. Family friendly policies. Personal support. Coaching and development. To find out more about HMRC benefits and find out what it's really like to work for HMRC hear from our insiders or visit Thinking of joining the Civil Service Things you need to know Artificial intelligence Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use. Selection process details This vacancy is using Success Profiles (opens in a new window), and will assess your Strengths and Experience. How to Apply As part of the application process, you will be asked to provide the following: A name-blind CV including your job history, previous experiences and qualifications. Qualifications are not mandatory for this role. A 750-word Personal Statement. Your Personal Statement should be used to describe how your skills and experience would be suitable for the advertised role, making reference to the Essential Criteria and Person Specification outlined in the advert. Please complete a separate statement (Max 250 words) for the Desirable Criteria where applicable. This is not essential for the role but may be considered by the vacancy-holder where candidates have the same scores at interview. Further details around what this will entail are listed on the application form. Prior to applications being sifted candidates will be asked to complete an additional IKM assessment. Candidates will be sent details of the assessment once the advert has closed. This assessment is a pass or fail and only those who pass will be considered at the sift stage. Sift In the event of a large number of applications being received, an initial sift may be held on your CV. At full sift your CV and your Personal Statement will be assessed, with the successful candidates being invited to interview. We may also raise the score required at any stage of the process if we receive a high number of applications. Interview During the panel interview, your experience will be assessed, and you will be asked strength-based questions to also explore what you enjoy and your motivations relevant to the job role. This is an example of a strengths-based question: . click apply for full job details
About the RoleAs a Senior Cloud Security Analyst, you'll play a key role in protecting cloud infrastructure and services through proactive monitoring, threat detection and incident response. Working within a collaborative Security Operations function, you'll analyse security events, investigate emerging threats and help strengthen the organisation's overall cyber resilience.This role offers the opportunity to work across modern cloud platforms, partnering with infrastructure, engineering and application teams to improve security controls, enhance detection capabilities and support secure cloud operations.Key ResponsibilitiesMonitor and investigate security events across Azure, AWS and hybrid cloud environments using SIEM, CSPM and native cloud security services.Perform detailed triage of alerts to identify genuine threats, eliminate false positives and determine appropriate remediation actions.Lead or support investigations into cloud-based security incidents, ensuring timely containment, recovery and accurate documentation.Analyse authentication activity, privileged access events, API usage and configuration changes to identify suspicious behaviour and potential compromise.Work alongside Security Operations, Infrastructure and DevOps teams to coordinate effective responses to security incidents.Recommend improvements to detection logic, alert quality and monitoring coverage based on operational findings and emerging threats.Develop and maintain security use cases that improve visibility across cloud workloads and services.Contribute to threat hunting activities by identifying indicators of compromise and analysing attacker techniques.Produce clear technical reports and communicate investigation findings to both technical and non-technical stakeholders.Participate in security improvement initiatives, helping implement new technologies, processes and operational controls.Keep up to date with developments in cloud security, attacker methodologies and industry best practices to strengthen organisational security.Technical SkillsExperience in several of the following areas would be advantageous:Microsoft Azure SecurityAWS Security ServicesGoogle Cloud Platform (desirable)Microsoft SentinelKusto Query Language (KQL)CloudTrail, Azure Activity Logs and cloud audit loggingCloud Security Posture Management (CSPM)CrowdStrike Falcon Cloud SecurityMicrosoft Defender SuiteKubernetes security conceptsIdentity and Access Management (IAM)Privileged Access ManagementMicrosoft Entra ID (Azure AD)MITRE ATT&CK FrameworkThreat IntelligenceIncident ResponseThreat HuntingSIEM TechnologiesSecurity MonitoringSecurity Operations (SOC)Cloud Networking FundamentalsWhat You'll BringExperience working within a Security Operations Centre or Cloud Security environment.Strong analytical and investigative skills with the ability to prioritise and manage multiple security events.Confidence interpreting security telemetry and identifying indicators of malicious activity.Excellent problem-solving skills and the ability to make informed decisions during security incidents.Strong communication skills with the ability to present technical findings clearly.A collaborative approach to working with infrastructure, engineering and operational teams.A proactive mindset focused on continuous improvement and operational excellence.Desirable QualificationsMicrosoft SC-200Microsoft AZ-500AWS Certified Security - SpecialtyCertified Kubernetes Security Specialist (CKS)CompTIA Security+CISSPGIAC certificationsRelevant cloud or cyber security certifications To speak in absolute confidence about this opportunity please send an up-to-date CV via the link provided or contact Senior Recruitment Consultant Stuart Kennedy at MCS Group on or . Even if this position is not right for you, we may have others that are. Please visit MCS Group to view a wide selection of our current jobs.
Aug 26, 2026
Full time
About the RoleAs a Senior Cloud Security Analyst, you'll play a key role in protecting cloud infrastructure and services through proactive monitoring, threat detection and incident response. Working within a collaborative Security Operations function, you'll analyse security events, investigate emerging threats and help strengthen the organisation's overall cyber resilience.This role offers the opportunity to work across modern cloud platforms, partnering with infrastructure, engineering and application teams to improve security controls, enhance detection capabilities and support secure cloud operations.Key ResponsibilitiesMonitor and investigate security events across Azure, AWS and hybrid cloud environments using SIEM, CSPM and native cloud security services.Perform detailed triage of alerts to identify genuine threats, eliminate false positives and determine appropriate remediation actions.Lead or support investigations into cloud-based security incidents, ensuring timely containment, recovery and accurate documentation.Analyse authentication activity, privileged access events, API usage and configuration changes to identify suspicious behaviour and potential compromise.Work alongside Security Operations, Infrastructure and DevOps teams to coordinate effective responses to security incidents.Recommend improvements to detection logic, alert quality and monitoring coverage based on operational findings and emerging threats.Develop and maintain security use cases that improve visibility across cloud workloads and services.Contribute to threat hunting activities by identifying indicators of compromise and analysing attacker techniques.Produce clear technical reports and communicate investigation findings to both technical and non-technical stakeholders.Participate in security improvement initiatives, helping implement new technologies, processes and operational controls.Keep up to date with developments in cloud security, attacker methodologies and industry best practices to strengthen organisational security.Technical SkillsExperience in several of the following areas would be advantageous:Microsoft Azure SecurityAWS Security ServicesGoogle Cloud Platform (desirable)Microsoft SentinelKusto Query Language (KQL)CloudTrail, Azure Activity Logs and cloud audit loggingCloud Security Posture Management (CSPM)CrowdStrike Falcon Cloud SecurityMicrosoft Defender SuiteKubernetes security conceptsIdentity and Access Management (IAM)Privileged Access ManagementMicrosoft Entra ID (Azure AD)MITRE ATT&CK FrameworkThreat IntelligenceIncident ResponseThreat HuntingSIEM TechnologiesSecurity MonitoringSecurity Operations (SOC)Cloud Networking FundamentalsWhat You'll BringExperience working within a Security Operations Centre or Cloud Security environment.Strong analytical and investigative skills with the ability to prioritise and manage multiple security events.Confidence interpreting security telemetry and identifying indicators of malicious activity.Excellent problem-solving skills and the ability to make informed decisions during security incidents.Strong communication skills with the ability to present technical findings clearly.A collaborative approach to working with infrastructure, engineering and operational teams.A proactive mindset focused on continuous improvement and operational excellence.Desirable QualificationsMicrosoft SC-200Microsoft AZ-500AWS Certified Security - SpecialtyCertified Kubernetes Security Specialist (CKS)CompTIA Security+CISSPGIAC certificationsRelevant cloud or cyber security certifications To speak in absolute confidence about this opportunity please send an up-to-date CV via the link provided or contact Senior Recruitment Consultant Stuart Kennedy at MCS Group on or . Even if this position is not right for you, we may have others that are. Please visit MCS Group to view a wide selection of our current jobs.
eDiscovery Senior Technical Project Manager London/hybrid (but remote from UK could be considered for an exceptional person) The Firm: Highly reputable international Legal Practice undergoing expansion in the eDiscovery Practice. The Role: Provide the eDiscovery team with technical, strategic and practical know how on eDiscovery services. Successfully deliver and assist others in the delivery of eDiscovery projects. Assist with the management of the eDiscovery team The Individual: Have proven experience of successfully supporting projects with all aspects of eDiscovery processes. Experience of using eDiscovery products such as Relativity, Reveal, Disco, Axcelerate, Nuix, and also know or happy to learn Sharedo or Opus2. You will be very technically adept and if not a Relativity Master be well on your way with an understanding across the tool and other tools (mentioned above). Delivery: Accountable for ensuring quality control process is adhered to in delivery of all services Ensure your Manager is made aware of all tasks, projects and the approach to delivery is discussed and confirmed with them Create recommendations, project plans, cost estimates, procedures and specifications, ensuring quotes are provided and instructions are agreed in writing Data processing of material received in various formats including native and load file mapping and ingestion, as well as exception handling Setup and customisation of Relativity , running searches and culling data, creating review batches, customising coding templates, creating user roles and related permission settings Carry out native and load file productions according to specifications Resolve 1st line support queries and work with our 2nd & 3rd line support to ensure technical issues are resolved Be a reference point for service issues, escalating any complaints from the Practice immediately to the team Manager and working with the Manager to address these Ensure defensible processes and data security procedures are adhered to at all times Administration of software and hardware used by the eDiscovery team Responsible for the successful end-to-end delivery of eDiscovery projects, including processing data, creating productions for disclosure/investigation, leveraging TAR functionality, Early Case Assessment tools. Also GenAI solutions, eBundling and case management solutions Keep up to date with developments by attending seminars and presentations on relevant services and technology, ensuring knowledge is shared and training is provided to all team members About Brimstone Consulting: We specialise in finding highly qualified staff in the following areas: E-Discovery and Digital Forensics; Payments; Fraud - (AML/CTF, Investigation, CFE s etc.); Risk - (Credit, Regulatory, Liquidity, Market, Analysts-SAS, SPSS etc.); Compliance/Corporate Governance ; IT - (full SDLC- BA s PM s , Architects, Developers etc.); Big Data and Data Analytics - (MI/BI/CI); InfoSec and Cyber Crime; Audit; Accountancy and Finance Brimstone Consulting acts as an employment agency (permanent) and as an employment business (temporary) - a free and confidential service to candidates. Brimstone Consulting is an equal opportunities employer. Due to time constraints we can only reply to applicants that match our clients specifications. Our Data Protection number: ZA(phone number removed)
Aug 26, 2026
Full time
eDiscovery Senior Technical Project Manager London/hybrid (but remote from UK could be considered for an exceptional person) The Firm: Highly reputable international Legal Practice undergoing expansion in the eDiscovery Practice. The Role: Provide the eDiscovery team with technical, strategic and practical know how on eDiscovery services. Successfully deliver and assist others in the delivery of eDiscovery projects. Assist with the management of the eDiscovery team The Individual: Have proven experience of successfully supporting projects with all aspects of eDiscovery processes. Experience of using eDiscovery products such as Relativity, Reveal, Disco, Axcelerate, Nuix, and also know or happy to learn Sharedo or Opus2. You will be very technically adept and if not a Relativity Master be well on your way with an understanding across the tool and other tools (mentioned above). Delivery: Accountable for ensuring quality control process is adhered to in delivery of all services Ensure your Manager is made aware of all tasks, projects and the approach to delivery is discussed and confirmed with them Create recommendations, project plans, cost estimates, procedures and specifications, ensuring quotes are provided and instructions are agreed in writing Data processing of material received in various formats including native and load file mapping and ingestion, as well as exception handling Setup and customisation of Relativity , running searches and culling data, creating review batches, customising coding templates, creating user roles and related permission settings Carry out native and load file productions according to specifications Resolve 1st line support queries and work with our 2nd & 3rd line support to ensure technical issues are resolved Be a reference point for service issues, escalating any complaints from the Practice immediately to the team Manager and working with the Manager to address these Ensure defensible processes and data security procedures are adhered to at all times Administration of software and hardware used by the eDiscovery team Responsible for the successful end-to-end delivery of eDiscovery projects, including processing data, creating productions for disclosure/investigation, leveraging TAR functionality, Early Case Assessment tools. Also GenAI solutions, eBundling and case management solutions Keep up to date with developments by attending seminars and presentations on relevant services and technology, ensuring knowledge is shared and training is provided to all team members About Brimstone Consulting: We specialise in finding highly qualified staff in the following areas: E-Discovery and Digital Forensics; Payments; Fraud - (AML/CTF, Investigation, CFE s etc.); Risk - (Credit, Regulatory, Liquidity, Market, Analysts-SAS, SPSS etc.); Compliance/Corporate Governance ; IT - (full SDLC- BA s PM s , Architects, Developers etc.); Big Data and Data Analytics - (MI/BI/CI); InfoSec and Cyber Crime; Audit; Accountancy and Finance Brimstone Consulting acts as an employment agency (permanent) and as an employment business (temporary) - a free and confidential service to candidates. Brimstone Consulting is an equal opportunities employer. Due to time constraints we can only reply to applicants that match our clients specifications. Our Data Protection number: ZA(phone number removed)
Cyber Security Analyst - Contract - Hybrid / Cardiff VIQU have partnered with an NHS organisation who are seeking an experienced Cyber Security Analyst to support a busy security team during a period of increased demand. The successful Cyber Security Analyst will focus on monitoring and investigating security alerts, responding to incidents, supporting vulnerability management activities, and helping maintain a secure Microsoft-based environment, with particular emphasis on Microsoft Sentinel. Role Responsibilities: Monitor, investigate and respond to security alerts and incidents within Microsoft Sentinel. Manage cyber security tickets, service requests and day-to-day operational security activities. Analyse suspicious activity and escalate potential threats where appropriate. Support vulnerability management and remediation activities across the organisation. Assist with incident response, security investigations and cyber improvement initiatives. Work closely with end users to provide security advice and support. Key Skills & Experience Required: Previous experience working as a Cyber Security Analyst. Strong experience using Microsoft Sentinel for alert monitoring, investigation and incident management. Good understanding of Microsoft security technologies, including Microsoft Defender and Microsoft 365 security controls. Experience investigating cyber incidents such as phishing attacks, malware, account compromise and suspicious user activity. Familiarity with vulnerability management tools such as Nessus or similar platforms. Understanding of core security principles including threat detection, risk management and incident response. Strong communication skills and the ability to explain technical issues to both technical and non-technical stakeholders. Role Details: Job Role: Cyber Security Analyst Contract: 2 months initial contract (with potential for extension) Location: Hybrid - Cardiff Rate: £240 per day Inside IR35 Apply now to speak with VIQU IT in confidence. Or reach out to Suzie Stone via the VIQU IT website. Do you know someone great? We'll thank you with up to £1,000 if your referral is successful (terms apply). For more exciting roles and opportunities like this, please follow us on IT Recruitment.
Aug 26, 2026
Full time
Cyber Security Analyst - Contract - Hybrid / Cardiff VIQU have partnered with an NHS organisation who are seeking an experienced Cyber Security Analyst to support a busy security team during a period of increased demand. The successful Cyber Security Analyst will focus on monitoring and investigating security alerts, responding to incidents, supporting vulnerability management activities, and helping maintain a secure Microsoft-based environment, with particular emphasis on Microsoft Sentinel. Role Responsibilities: Monitor, investigate and respond to security alerts and incidents within Microsoft Sentinel. Manage cyber security tickets, service requests and day-to-day operational security activities. Analyse suspicious activity and escalate potential threats where appropriate. Support vulnerability management and remediation activities across the organisation. Assist with incident response, security investigations and cyber improvement initiatives. Work closely with end users to provide security advice and support. Key Skills & Experience Required: Previous experience working as a Cyber Security Analyst. Strong experience using Microsoft Sentinel for alert monitoring, investigation and incident management. Good understanding of Microsoft security technologies, including Microsoft Defender and Microsoft 365 security controls. Experience investigating cyber incidents such as phishing attacks, malware, account compromise and suspicious user activity. Familiarity with vulnerability management tools such as Nessus or similar platforms. Understanding of core security principles including threat detection, risk management and incident response. Strong communication skills and the ability to explain technical issues to both technical and non-technical stakeholders. Role Details: Job Role: Cyber Security Analyst Contract: 2 months initial contract (with potential for extension) Location: Hybrid - Cardiff Rate: £240 per day Inside IR35 Apply now to speak with VIQU IT in confidence. Or reach out to Suzie Stone via the VIQU IT website. Do you know someone great? We'll thank you with up to £1,000 if your referral is successful (terms apply). For more exciting roles and opportunities like this, please follow us on IT Recruitment.
At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive. Our Employees: Are valued and empowered, collaborative and team oriented, innovative in their approach and passionate about their work. They are reliable, trustworthy and open with a high level of integrity. They value diversity, are inclusive and are committed to a global mindset. Opportunity Are you looking to take the next step in your career in People Operations? As a People Operations Analyst II, you will be a key contributor to our people operations processes. This is a unique opportunity to help shape and define our People & Culture Shared Services function globally. Through your day-to-day practical experience, you will support administrative and general functions for our employees while leveraging your relevant experience to elevate our global mobility and employee lifecycle workflows. This role is offered on an initial fixed-term basis for 6 months. At F5, we provide a wonderful opportunity for you to apply your expertise in a multinational company across various functions. Our People Operations team collaborates in a supportive environment, offering development opportunities that will provide a stepping stone for a continued, impactful career in People & Culture. Job Summary Independently performs a broad range of People & Culture services for Employees and Shared Services partners. Embeds low-code optimisation and basic data interpretation to accelerate standard employee lifecycle workflows, while serving as a key player in shaping F5's global People & Culture Shared Services. Primary Responsibilities Administer People processes related to employee lifecycle events such as promotions, transfers, and terminations. Create, maintain, and deliver the paperwork and logistics required for the new hire set-up process and the leaver process. Generate employment contracts and prepare change in terms and conditions letters for employees. Manage employee data changes in the People & Culture systems (Workday & ServiceNow). Ensure adherence to company standards and maintain accurate employee data. Maintain electronic and hard-copy files for our employees in accordance with the file management and retention policy. Manage Leave of Absences in the region, such as paternity, maternity, and short-term sickness. Serve as a first point of contact for resolving common employee questions or issues. Provide information for the monthly payroll process. Assist the People & Culture Team with raising purchase orders and the invoice approval process. Utilise low-code / no-code automation tools (e.g., Power Automate, AI agents) to simplify repetitive administrative workflows within the immediate team. Coordinate recurring programs, including training compliance and policy acknowledgements. Assist in quarterly policy reviews and updates in ConvergePoint. Provide support for local and global projects, offering insights into designated territories. Support the business in managing contractors, including extensions and terminations. Uphold F5's Business Code of Ethics and promptly report violations of the Code or other company policies. Knowledge, Skills, and Abilities Proven experience in People & Culture Shared Services and global mobility/immigration, particularly within the EMEA region. Collaborates on assignments and problems of minimally complex scope, using judgment to select a course of action within described guidelines under moderate supervision. Anticipates subtle obstacles or problems and takes timely steps to minimise their impact. Working knowledge of the ServiceNow HRSD agent role; manages many aspects of work within ServiceNow, including responding to customer inquiries and managing complex experiences like onboarding, utilising auto-generated case summaries. Experienced with tools and systems that support People Operations activities. Displays a functional automation mindset; capable of identifying manual tasks ready for technological optimisation and reading basic data visualisations to make operational recommendations. Ability to assist with People reporting and audit requests by interpreting structured data sets. Strong ability to communicate basic concepts and exchange technical ideas and content clearly and concisely with technical and non-technical audiences. Ability to provide timely responses to advisory questions for employees and managers and resolve escalations from the People Operations team. Prioritises competing demands quickly and effectively. Receives minimal instruction on day-to-day work and general instructions on new assignments. Physical Demands and Work Environment Duties are performed in a normal office environment while sitting at a desk or computer table. Duties require the ability to use a computer, communicate by telephone, and read printed material. Duties may require working outside normal working hours for quarter- or year-end close or special projects (evenings and weekends). The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change. Please note that F5 only contacts candidates through F5 email address (ending or auto email notification from Workday (ending with Equal Employment Opportunity It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting . Hybrid Employees within 30 commutable miles of an F5 office are required to work from the office a minimum of 30 business days per quarter. Remote Primarily work from designated home location but can come into an F5 office to work or travel to an offsite location as needed. About F5 Together, we're building a better digital world. Founded in 1996, F5 is a global leader in application delivery and security. Our premier platform helps customers secure and deliver every app, API, and piece of infrastructure across all environments. Backed by over three decades of expertise and 553 patents, our solutions protect against threats while ensuring fast, reliable digital experiences. With over 6,400 employees, we serve more than 23,000 customers in over 170 countries. To continue this work, we need people like you-the best minds in the industry. We're committed to a unique, human-first culture that encourages authenticity, prioritizes diversity and inclusion, and fosters the growth and success of our employees.
Aug 25, 2026
Full time
At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive. Our Employees: Are valued and empowered, collaborative and team oriented, innovative in their approach and passionate about their work. They are reliable, trustworthy and open with a high level of integrity. They value diversity, are inclusive and are committed to a global mindset. Opportunity Are you looking to take the next step in your career in People Operations? As a People Operations Analyst II, you will be a key contributor to our people operations processes. This is a unique opportunity to help shape and define our People & Culture Shared Services function globally. Through your day-to-day practical experience, you will support administrative and general functions for our employees while leveraging your relevant experience to elevate our global mobility and employee lifecycle workflows. This role is offered on an initial fixed-term basis for 6 months. At F5, we provide a wonderful opportunity for you to apply your expertise in a multinational company across various functions. Our People Operations team collaborates in a supportive environment, offering development opportunities that will provide a stepping stone for a continued, impactful career in People & Culture. Job Summary Independently performs a broad range of People & Culture services for Employees and Shared Services partners. Embeds low-code optimisation and basic data interpretation to accelerate standard employee lifecycle workflows, while serving as a key player in shaping F5's global People & Culture Shared Services. Primary Responsibilities Administer People processes related to employee lifecycle events such as promotions, transfers, and terminations. Create, maintain, and deliver the paperwork and logistics required for the new hire set-up process and the leaver process. Generate employment contracts and prepare change in terms and conditions letters for employees. Manage employee data changes in the People & Culture systems (Workday & ServiceNow). Ensure adherence to company standards and maintain accurate employee data. Maintain electronic and hard-copy files for our employees in accordance with the file management and retention policy. Manage Leave of Absences in the region, such as paternity, maternity, and short-term sickness. Serve as a first point of contact for resolving common employee questions or issues. Provide information for the monthly payroll process. Assist the People & Culture Team with raising purchase orders and the invoice approval process. Utilise low-code / no-code automation tools (e.g., Power Automate, AI agents) to simplify repetitive administrative workflows within the immediate team. Coordinate recurring programs, including training compliance and policy acknowledgements. Assist in quarterly policy reviews and updates in ConvergePoint. Provide support for local and global projects, offering insights into designated territories. Support the business in managing contractors, including extensions and terminations. Uphold F5's Business Code of Ethics and promptly report violations of the Code or other company policies. Knowledge, Skills, and Abilities Proven experience in People & Culture Shared Services and global mobility/immigration, particularly within the EMEA region. Collaborates on assignments and problems of minimally complex scope, using judgment to select a course of action within described guidelines under moderate supervision. Anticipates subtle obstacles or problems and takes timely steps to minimise their impact. Working knowledge of the ServiceNow HRSD agent role; manages many aspects of work within ServiceNow, including responding to customer inquiries and managing complex experiences like onboarding, utilising auto-generated case summaries. Experienced with tools and systems that support People Operations activities. Displays a functional automation mindset; capable of identifying manual tasks ready for technological optimisation and reading basic data visualisations to make operational recommendations. Ability to assist with People reporting and audit requests by interpreting structured data sets. Strong ability to communicate basic concepts and exchange technical ideas and content clearly and concisely with technical and non-technical audiences. Ability to provide timely responses to advisory questions for employees and managers and resolve escalations from the People Operations team. Prioritises competing demands quickly and effectively. Receives minimal instruction on day-to-day work and general instructions on new assignments. Physical Demands and Work Environment Duties are performed in a normal office environment while sitting at a desk or computer table. Duties require the ability to use a computer, communicate by telephone, and read printed material. Duties may require working outside normal working hours for quarter- or year-end close or special projects (evenings and weekends). The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change. Please note that F5 only contacts candidates through F5 email address (ending or auto email notification from Workday (ending with Equal Employment Opportunity It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting . Hybrid Employees within 30 commutable miles of an F5 office are required to work from the office a minimum of 30 business days per quarter. Remote Primarily work from designated home location but can come into an F5 office to work or travel to an offsite location as needed. About F5 Together, we're building a better digital world. Founded in 1996, F5 is a global leader in application delivery and security. Our premier platform helps customers secure and deliver every app, API, and piece of infrastructure across all environments. Backed by over three decades of expertise and 553 patents, our solutions protect against threats while ensuring fast, reliable digital experiences. With over 6,400 employees, we serve more than 23,000 customers in over 170 countries. To continue this work, we need people like you-the best minds in the industry. We're committed to a unique, human-first culture that encourages authenticity, prioritizes diversity and inclusion, and fosters the growth and success of our employees.
At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive. Our Employees: Are valued and empowered, collaborative and team oriented, innovative in their approach and passionate about their work. They are reliable, trustworthy and open with a high level of integrity. They value diversity, are inclusive and are committed to a global mindset. Opportunity Are you looking to take the next step in your career in People Operations? As a People Operations Analyst II, you will be a key contributor to our people operations processes. This is a unique opportunity to help shape and define our People & Culture Shared Services function globally. Through your day-to-day practical experience, you will support administrative and general functions for our employees while leveraging your relevant experience to elevate our global mobility and employee lifecycle workflows. This role is offered on an initial fixed-term basis for 6 months. At F5, we provide a wonderful opportunity for you to apply your expertise in a multinational company across various functions. Our People Operations team collaborates in a supportive environment, offering development opportunities that will provide a stepping stone for a continued, impactful career in People & Culture. Job Summary Independently performs a broad range of People & Culture services for Employees and Shared Services partners. Embeds low-code optimisation and basic data interpretation to accelerate standard employee lifecycle workflows, while serving as a key player in shaping F5's global People & Culture Shared Services. Primary Responsibilities Administer People processes related to employee lifecycle events such as promotions, transfers, and terminations. Create, maintain, and deliver the paperwork and logistics required for the new hire set-up process and the leaver process. Generate employment contracts and prepare change in terms and conditions letters for employees. Manage employee data changes in the People & Culture systems (Workday & ServiceNow). Ensure adherence to company standards and maintain accurate employee data. Maintain electronic and hard-copy files for our employees in accordance with the file management and retention policy. Manage Leave of Absences in the region, such as paternity, maternity, and short-term sickness. Serve as a first point of contact for resolving common employee questions or issues. Provide information for the monthly payroll process. Assist the People & Culture Team with raising purchase orders and the invoice approval process. Utilise low-code / no-code automation tools (e.g., Power Automate, AI agents) to simplify repetitive administrative workflows within the immediate team. Coordinate recurring programs, including training compliance and policy acknowledgements. Assist in quarterly policy reviews and updates in ConvergePoint. Provide support for local and global projects, offering insights into designated territories. Support the business in managing contractors, including extensions and terminations. Uphold F5's Business Code of Ethics and promptly report violations of the Code or other company policies. Knowledge, Skills, and Abilities Proven experience in People & Culture Shared Services and global mobility/immigration, particularly within the EMEA region. Collaborates on assignments and problems of minimally complex scope, using judgment to select a course of action within described guidelines under moderate supervision. Anticipates subtle obstacles or problems and takes timely steps to minimise their impact. Working knowledge of the ServiceNow HRSD agent role; manages many aspects of work within ServiceNow, including responding to customer inquiries and managing complex experiences like onboarding, utilising auto-generated case summaries. Experienced with tools and systems that support People Operations activities. Displays a functional automation mindset; capable of identifying manual tasks ready for technological optimisation and reading basic data visualisations to make operational recommendations. Ability to assist with People reporting and audit requests by interpreting structured data sets. Strong ability to communicate basic concepts and exchange technical ideas and content clearly and concisely with technical and non-technical audiences. Ability to provide timely responses to advisory questions for employees and managers and resolve escalations from the People Operations team. Prioritises competing demands quickly and effectively. Receives minimal instruction on day-to-day work and general instructions on new assignments. Physical Demands and Work Environment Duties are performed in a normal office environment while sitting at a desk or computer table. Duties require the ability to use a computer, communicate by telephone, and read printed material. Duties may require working outside normal working hours for quarter- or year-end close or special projects (evenings and weekends). The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change. Please note that F5 only contacts candidates through F5 email address (ending or auto email notification from Workday (ending with Equal Employment Opportunity It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting . Hybrid Employees within 30 commutable miles of an F5 office are required to work from the office a minimum of 30 business days per quarter. Remote Primarily work from designated home location but can come into an F5 office to work or travel to an offsite location as needed. About F5 Together, we're building a better digital world. Founded in 1996, F5 is a global leader in application delivery and security. Our premier platform helps customers secure and deliver every app, API, and piece of infrastructure across all environments. Backed by over three decades of expertise and 553 patents, our solutions protect against threats while ensuring fast, reliable digital experiences. With over 6,400 employees, we serve more than 23,000 customers in over 170 countries. To continue this work, we need people like you-the best minds in the industry. We're committed to a unique, human-first culture that encourages authenticity, prioritizes diversity and inclusion, and fosters the growth and success of our employees.
Aug 25, 2026
Full time
At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive. Our Employees: Are valued and empowered, collaborative and team oriented, innovative in their approach and passionate about their work. They are reliable, trustworthy and open with a high level of integrity. They value diversity, are inclusive and are committed to a global mindset. Opportunity Are you looking to take the next step in your career in People Operations? As a People Operations Analyst II, you will be a key contributor to our people operations processes. This is a unique opportunity to help shape and define our People & Culture Shared Services function globally. Through your day-to-day practical experience, you will support administrative and general functions for our employees while leveraging your relevant experience to elevate our global mobility and employee lifecycle workflows. This role is offered on an initial fixed-term basis for 6 months. At F5, we provide a wonderful opportunity for you to apply your expertise in a multinational company across various functions. Our People Operations team collaborates in a supportive environment, offering development opportunities that will provide a stepping stone for a continued, impactful career in People & Culture. Job Summary Independently performs a broad range of People & Culture services for Employees and Shared Services partners. Embeds low-code optimisation and basic data interpretation to accelerate standard employee lifecycle workflows, while serving as a key player in shaping F5's global People & Culture Shared Services. Primary Responsibilities Administer People processes related to employee lifecycle events such as promotions, transfers, and terminations. Create, maintain, and deliver the paperwork and logistics required for the new hire set-up process and the leaver process. Generate employment contracts and prepare change in terms and conditions letters for employees. Manage employee data changes in the People & Culture systems (Workday & ServiceNow). Ensure adherence to company standards and maintain accurate employee data. Maintain electronic and hard-copy files for our employees in accordance with the file management and retention policy. Manage Leave of Absences in the region, such as paternity, maternity, and short-term sickness. Serve as a first point of contact for resolving common employee questions or issues. Provide information for the monthly payroll process. Assist the People & Culture Team with raising purchase orders and the invoice approval process. Utilise low-code / no-code automation tools (e.g., Power Automate, AI agents) to simplify repetitive administrative workflows within the immediate team. Coordinate recurring programs, including training compliance and policy acknowledgements. Assist in quarterly policy reviews and updates in ConvergePoint. Provide support for local and global projects, offering insights into designated territories. Support the business in managing contractors, including extensions and terminations. Uphold F5's Business Code of Ethics and promptly report violations of the Code or other company policies. Knowledge, Skills, and Abilities Proven experience in People & Culture Shared Services and global mobility/immigration, particularly within the EMEA region. Collaborates on assignments and problems of minimally complex scope, using judgment to select a course of action within described guidelines under moderate supervision. Anticipates subtle obstacles or problems and takes timely steps to minimise their impact. Working knowledge of the ServiceNow HRSD agent role; manages many aspects of work within ServiceNow, including responding to customer inquiries and managing complex experiences like onboarding, utilising auto-generated case summaries. Experienced with tools and systems that support People Operations activities. Displays a functional automation mindset; capable of identifying manual tasks ready for technological optimisation and reading basic data visualisations to make operational recommendations. Ability to assist with People reporting and audit requests by interpreting structured data sets. Strong ability to communicate basic concepts and exchange technical ideas and content clearly and concisely with technical and non-technical audiences. Ability to provide timely responses to advisory questions for employees and managers and resolve escalations from the People Operations team. Prioritises competing demands quickly and effectively. Receives minimal instruction on day-to-day work and general instructions on new assignments. Physical Demands and Work Environment Duties are performed in a normal office environment while sitting at a desk or computer table. Duties require the ability to use a computer, communicate by telephone, and read printed material. Duties may require working outside normal working hours for quarter- or year-end close or special projects (evenings and weekends). The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change. Please note that F5 only contacts candidates through F5 email address (ending or auto email notification from Workday (ending with Equal Employment Opportunity It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting . Hybrid Employees within 30 commutable miles of an F5 office are required to work from the office a minimum of 30 business days per quarter. Remote Primarily work from designated home location but can come into an F5 office to work or travel to an offsite location as needed. About F5 Together, we're building a better digital world. Founded in 1996, F5 is a global leader in application delivery and security. Our premier platform helps customers secure and deliver every app, API, and piece of infrastructure across all environments. Backed by over three decades of expertise and 553 patents, our solutions protect against threats while ensuring fast, reliable digital experiences. With over 6,400 employees, we serve more than 23,000 customers in over 170 countries. To continue this work, we need people like you-the best minds in the industry. We're committed to a unique, human-first culture that encourages authenticity, prioritizes diversity and inclusion, and fosters the growth and success of our employees.
Job Title: Business Analysis and Onboarding Specialist Location: Manchester, Glasgow, or Ipswich (Hybrid: 3 days office / 2 days remote) Contract Duration: 6 Months The Role We are seeking an experienced Business Analyst and Onboarding Specialist to support the analysis, onboarding, and migration of critical applications across complex estates. Sitting between architecture, delivery teams, and application owners, you will help turn complex application landscapes into clear, actionable plans that enable delivery teams to make informed migration decisions. Key Responsibilities Gather, validate, and maintain accurate application data and inventories. Identify application patterns, groupings, and technical dependencies. Collaborate closely with architects to assess current-state environments and target solutions. Engage application owners and technical teams to resolve data gaps and unknowns. Support application onboarding into agreed target platforms while tracking risks, blockers, and decisions. Provide clear, concise status updates and delivery reporting to stakeholders. What We Are Looking For Strong business analysis skills with proven experience in application portfolios, migrations, or onboarding activities. Proven ability to organize large amounts of complex information and translate it into practical actions. Excellent communication skills, with the ability to confidently engage architects, engineers, and business stakeholders. Exceptional attention to detail and a highly collaborative, inclusive approach to problem-solving. Experience in cyber security, Identity and Access Management (IAM), infrastructure, or regulated environments is highly advantageous. If interested please reply with your CV to or call me at . Randstad Technologies is acting as an Employment Business in relation to this vacancy.
Aug 25, 2026
Full time
Job Title: Business Analysis and Onboarding Specialist Location: Manchester, Glasgow, or Ipswich (Hybrid: 3 days office / 2 days remote) Contract Duration: 6 Months The Role We are seeking an experienced Business Analyst and Onboarding Specialist to support the analysis, onboarding, and migration of critical applications across complex estates. Sitting between architecture, delivery teams, and application owners, you will help turn complex application landscapes into clear, actionable plans that enable delivery teams to make informed migration decisions. Key Responsibilities Gather, validate, and maintain accurate application data and inventories. Identify application patterns, groupings, and technical dependencies. Collaborate closely with architects to assess current-state environments and target solutions. Engage application owners and technical teams to resolve data gaps and unknowns. Support application onboarding into agreed target platforms while tracking risks, blockers, and decisions. Provide clear, concise status updates and delivery reporting to stakeholders. What We Are Looking For Strong business analysis skills with proven experience in application portfolios, migrations, or onboarding activities. Proven ability to organize large amounts of complex information and translate it into practical actions. Excellent communication skills, with the ability to confidently engage architects, engineers, and business stakeholders. Exceptional attention to detail and a highly collaborative, inclusive approach to problem-solving. Experience in cyber security, Identity and Access Management (IAM), infrastructure, or regulated environments is highly advantageous. If interested please reply with your CV to or call me at . Randstad Technologies is acting as an Employment Business in relation to this vacancy.
Salesforce Analyst / Administrator - Cyber Security Hybrid UK Excellent salary + Excellent Benefits + Flexible Hybrid Working Looking for a Salesforce role where you can make a real impact? Join a rapidly growing cyber security company and play a key role in shaping and optimising a business-critical Salesforce environment click apply for full job details
Aug 25, 2026
Full time
Salesforce Analyst / Administrator - Cyber Security Hybrid UK Excellent salary + Excellent Benefits + Flexible Hybrid Working Looking for a Salesforce role where you can make a real impact? Join a rapidly growing cyber security company and play a key role in shaping and optimising a business-critical Salesforce environment click apply for full job details
ZeroFOX seeks an Intelligence Analyst (Arabic Language) to join the ZeroFox Services and Analysis Team. You will collect information to identify threats and generate intelligence for client needs, covering physical security, cyber, geopolitical, and reputation risk. The role requires independent critical thinking, teamwork, and discretion. Responsibilities include producing intelligence reports, briefings, trend analyses, and client touchpoints.
Aug 25, 2026
Full time
ZeroFOX seeks an Intelligence Analyst (Arabic Language) to join the ZeroFox Services and Analysis Team. You will collect information to identify threats and generate intelligence for client needs, covering physical security, cyber, geopolitical, and reputation risk. The role requires independent critical thinking, teamwork, and discretion. Responsibilities include producing intelligence reports, briefings, trend analyses, and client touchpoints.
ZeroFox seeks an Intelligence Analyst (Arabic Language) to join the ZeroFox Services and Analysis Team, you will collect information to identify threats, and generate intelligence to assess risk in relevance to client needs. Intelligence activities can include researching current and emerging threats issues covering physical security, cyber security, geopolitical, reputation risk and compliance issues. The Intelligence Analyst will have an investigative or analytical background and demonstrated exceptional analytic prowess in areas such as trend analysis and pattern recognition, using independent critical thinking and judgment to act, lead, initiate and/or recommend next steps. Discretion, teamwork, and creativity are a must. Key Responsibilities include: Learn and employ ZeroFox patented technology to identify and analyze relevant information collected from the Internet, based on client-specific criteria, to assemble relevant findings for daily intelligence and recurring reporting; Assist in customer care and all production aspects covering the range of assigned duties. Support and /or lead recurring deliverables and touchpoints (ad hoc / daily / weekly / monthly / quarterly and / or annual): Security/Incident Alerts Intelligence Reports Trend and summary reports Strategic assessments and reviews Client briefings Support collection enhancement with ongoing and proactive collaboration with Collection Management and 24x7 support. Dedication and willingness to provide support in response to ad hoc threats and periods of increased risk. This may entail on occasion: Ad hoc investigations and assessments Ancillary threat monitoring outside core business hours Proactive professional development through company trainings, industry certifications, and seeking new opportunities to maintain and grow relevant knowledge and skillsets. Identify and communicate enhancement opportunities and improvement ideas for the department's operations. Qualifying Requirements: Written and spoken fluency in Arabic Experience in open source and social media research, or investigations, typically obtained in 2-3 years; ability to connect the dots; Creativity in leveraging internet search techniques and methods; Ability to determine the credibility, value, significance, and relevancy of information from different data sources to produce clear, concise, and timely analytical products; Strong written and oral communication skills; comfortable with providing briefings and presentations. Experience producing short and long form reports, applying BLUF or similar models; Comfort working independently and in teams; Experience with some of the following: Social Media Platforms, blogs, IRC, Deep / Darkweb , and message boards; Ability to collect, authenticate, validate and document online evidence; Proficient with at least one online investigative tool, such as Whois, Ping, Traceroute, etc; Proficient in Google Suite of programs; Preferred Experience: Public or private sector experience as an analyst, researcher, investigator or consultant supporting a security, risk or due diligence function. Experience in conducting studies and making recommendations to identify threat vectors, threat actors, and threat trends Experience in briefing decision-makers and senior leaders; High degree of knowledge of Social Media Platforms, blogs, IRC, message boards, Deep/Darkweb; Knowledge of IPv4, IPv6, DNS records, E-mails Headers, P2P; Possession of excellent project/team leadership, development, and client relationship skills; Knowledge and familiarity with relevant threat landscapes or industry practice areas such as cybercrime, online fraud, physical/corporate security, activism, hacktivism, reputation risk, travel security, geopolitical or policy issues Bachelor's degree with relevant coursework Education / Training Requirements: Bachelor's Degree Benefits Competitive compensation Community-driven culture with employee events Generous time offComprehensive private insurance and EAP Fun, modern workspace Respectful and nourishing work environment, where every opinion is heard and everyone is encouraged to be an active part of the organizational culture Physical and Sensory Requirements: Mobility, walking, climbing, sitting, standing, reaching, bending, lifting (minimum of 10 lbs), fine eye-hand coordination, ability to read, write, listen and speak clearly, the ability to understand and follow written and oral instructions and directions, ability to travel =/
Aug 25, 2026
Full time
ZeroFox seeks an Intelligence Analyst (Arabic Language) to join the ZeroFox Services and Analysis Team, you will collect information to identify threats, and generate intelligence to assess risk in relevance to client needs. Intelligence activities can include researching current and emerging threats issues covering physical security, cyber security, geopolitical, reputation risk and compliance issues. The Intelligence Analyst will have an investigative or analytical background and demonstrated exceptional analytic prowess in areas such as trend analysis and pattern recognition, using independent critical thinking and judgment to act, lead, initiate and/or recommend next steps. Discretion, teamwork, and creativity are a must. Key Responsibilities include: Learn and employ ZeroFox patented technology to identify and analyze relevant information collected from the Internet, based on client-specific criteria, to assemble relevant findings for daily intelligence and recurring reporting; Assist in customer care and all production aspects covering the range of assigned duties. Support and /or lead recurring deliverables and touchpoints (ad hoc / daily / weekly / monthly / quarterly and / or annual): Security/Incident Alerts Intelligence Reports Trend and summary reports Strategic assessments and reviews Client briefings Support collection enhancement with ongoing and proactive collaboration with Collection Management and 24x7 support. Dedication and willingness to provide support in response to ad hoc threats and periods of increased risk. This may entail on occasion: Ad hoc investigations and assessments Ancillary threat monitoring outside core business hours Proactive professional development through company trainings, industry certifications, and seeking new opportunities to maintain and grow relevant knowledge and skillsets. Identify and communicate enhancement opportunities and improvement ideas for the department's operations. Qualifying Requirements: Written and spoken fluency in Arabic Experience in open source and social media research, or investigations, typically obtained in 2-3 years; ability to connect the dots; Creativity in leveraging internet search techniques and methods; Ability to determine the credibility, value, significance, and relevancy of information from different data sources to produce clear, concise, and timely analytical products; Strong written and oral communication skills; comfortable with providing briefings and presentations. Experience producing short and long form reports, applying BLUF or similar models; Comfort working independently and in teams; Experience with some of the following: Social Media Platforms, blogs, IRC, Deep / Darkweb , and message boards; Ability to collect, authenticate, validate and document online evidence; Proficient with at least one online investigative tool, such as Whois, Ping, Traceroute, etc; Proficient in Google Suite of programs; Preferred Experience: Public or private sector experience as an analyst, researcher, investigator or consultant supporting a security, risk or due diligence function. Experience in conducting studies and making recommendations to identify threat vectors, threat actors, and threat trends Experience in briefing decision-makers and senior leaders; High degree of knowledge of Social Media Platforms, blogs, IRC, message boards, Deep/Darkweb; Knowledge of IPv4, IPv6, DNS records, E-mails Headers, P2P; Possession of excellent project/team leadership, development, and client relationship skills; Knowledge and familiarity with relevant threat landscapes or industry practice areas such as cybercrime, online fraud, physical/corporate security, activism, hacktivism, reputation risk, travel security, geopolitical or policy issues Bachelor's degree with relevant coursework Education / Training Requirements: Bachelor's Degree Benefits Competitive compensation Community-driven culture with employee events Generous time offComprehensive private insurance and EAP Fun, modern workspace Respectful and nourishing work environment, where every opinion is heard and everyone is encouraged to be an active part of the organizational culture Physical and Sensory Requirements: Mobility, walking, climbing, sitting, standing, reaching, bending, lifting (minimum of 10 lbs), fine eye-hand coordination, ability to read, write, listen and speak clearly, the ability to understand and follow written and oral instructions and directions, ability to travel =/
Threat Hunting & Detection Engineering Analyst Location: UK (Hybrid) Salary: Competitive + Excellent Benefits Threat Hunting & Detection Engineering Analyst A leading global technology consultancy is looking to hire a Threat Hunting & Detection Engineering Analyst to join its growing Cyber Security practice click apply for full job details
Aug 25, 2026
Full time
Threat Hunting & Detection Engineering Analyst Location: UK (Hybrid) Salary: Competitive + Excellent Benefits Threat Hunting & Detection Engineering Analyst A leading global technology consultancy is looking to hire a Threat Hunting & Detection Engineering Analyst to join its growing Cyber Security practice click apply for full job details
This is a self-funded career programme with a guaranteed job on completion or 100% of your course fees back Train. Certify. Get Hired. Are you looking to start a career in Cyber Security but don't know where to begin? With cyber threats continuing to rise, organisations across the UK are actively investing in cyber security talent. . click apply for full job details
Aug 25, 2026
Full time
This is a self-funded career programme with a guaranteed job on completion or 100% of your course fees back Train. Certify. Get Hired. Are you looking to start a career in Cyber Security but don't know where to begin? With cyber threats continuing to rise, organisations across the UK are actively investing in cyber security talent. . click apply for full job details
Position Summary As a SOC Shift Lead, you build on your solid experience as a SOC Analyst by supervising and guiding a team of SOC Analysts during your assigned shift. You ensure quality and consistency across all alerts and incidents handled by the team while serving as the primary point of escalation. In this role, you support team development, drive process improvements, and maintain clear, customer-centric communication with all stakeholders. You also lead quality assurance efforts and ensure that service-level agreements (SLAs) are met. Objectives & Key Results Key Responsibilities Shift Leadership and Team Coordination - You run shift operations, ensuring compliance with SLAs and maintaining high-quality incident handling. You set shift agendas, balance workloads, and promptly address any process or staffing issues. You also maintain effective, customer-centric communication with internal teams (including Security Optimisation and Engineering), customers, and their incident response partners Incident Triage and Investigation - You review and prioritise new alerts, taking initial ownership of high-priority or complex incidents, and ensure proper escalation to customers and Senior SOC Analysts. You make sound, data-driven decisions to facilitate effective triage, investigation, and escalation in line with operational standards Quality Assurance and Documentation - You conduct regular quality assurance (QA) of tickets to ensure SOC procedures and documentation standards are met, providing clear, constructive feedback to team members to improve technical skills and workflow consistency Collaboration and Mentorship - You mentor SOC Analysts in your team by offering regular, constructive feedback on triage processes and best practices. You encourage targeted training initiatives, including relevant certifications, to support career progression within the SOC Service Improvement - You contribute to ongoing service improvement through participation in supporting threat hunting activity led by Senior SOC Analysts, rule tuning, and process refinement initiatives. You assist in monthly reporting and post-incident reviews to drive improvements that reflect our commitment to transparent and reliable performance Required Qualifications & Experience You may be required to hold or obtain UK Non-Police Personnel Vetting (NPPV) and/or a Security Check (SC) clearance as part of this role Willingness to work towards or obtain intermediate cybersecurity certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst) Proficiency with SIEM platforms, endpoint security tools, and ticketing systems, with an ability to make clear, data-driven decisions under pressure Critical Competencies - Technical Fit Operating Systems - Possess detailed knowledge of Windows and Linux system architectures, with a clear understanding of how event logs (e.g., Windows Event Viewer, Syslog) reflect system security posture Networking and Protocols - Have a comprehensive understanding of TCP/IP, DNS, DCHP, VPNs, SSL/TLS, and network forensics concepts to validate network-based alerts and anomalies Cybersecurity Frameworks - Deeply understand and be able to articulate the elements of the MITRE ATT&CK framework, and Cyber Kill Chain; know how adversary tactics and techniques translate into observable indicators SIEM and Security Tools - Know the theoretical underpinnings of SIEM operations, including alert correlation, the design of automated detection rules, and the interpretation of aggregated security data Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence - how feeds are sourced, what constitutes actionable information, and how malware indicators are defined Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling Benefits At Claranet, we go the extra mile with our people-because we believe in building a workplace where everyone feels valued and supported. What makes us unique is Team Claranet , our internal community that supports causes close to our employees' hearts. We offer paid charity leave, support local charities across our offices, and host annual fundraising events, all backed by a dedicated committee. We're proud founding members of TC4RE (Technology Community for Racial Equality) working collectively to build a more diverse and inclusive tech industry. About Claranet Founded at the beginning of the dot com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries. Equal Opportunities Statement Diversity, equity and inclusion are at the heart of what we value as an organisation. Claranet is an equal opportunities employer and all qualified applicants will receive consideration for employment without regard to race, religion, sex, sexual orientation, age, disability or any other status protected by law. Our recruitment team are happy to support any reasonable adjustments that are needed within the recruitment process. Ready to take the next step in your career with Claranet? Click 'apply' - we can't wait to meet you! To view full job description please visit our careers page
Aug 24, 2026
Full time
Position Summary As a SOC Shift Lead, you build on your solid experience as a SOC Analyst by supervising and guiding a team of SOC Analysts during your assigned shift. You ensure quality and consistency across all alerts and incidents handled by the team while serving as the primary point of escalation. In this role, you support team development, drive process improvements, and maintain clear, customer-centric communication with all stakeholders. You also lead quality assurance efforts and ensure that service-level agreements (SLAs) are met. Objectives & Key Results Key Responsibilities Shift Leadership and Team Coordination - You run shift operations, ensuring compliance with SLAs and maintaining high-quality incident handling. You set shift agendas, balance workloads, and promptly address any process or staffing issues. You also maintain effective, customer-centric communication with internal teams (including Security Optimisation and Engineering), customers, and their incident response partners Incident Triage and Investigation - You review and prioritise new alerts, taking initial ownership of high-priority or complex incidents, and ensure proper escalation to customers and Senior SOC Analysts. You make sound, data-driven decisions to facilitate effective triage, investigation, and escalation in line with operational standards Quality Assurance and Documentation - You conduct regular quality assurance (QA) of tickets to ensure SOC procedures and documentation standards are met, providing clear, constructive feedback to team members to improve technical skills and workflow consistency Collaboration and Mentorship - You mentor SOC Analysts in your team by offering regular, constructive feedback on triage processes and best practices. You encourage targeted training initiatives, including relevant certifications, to support career progression within the SOC Service Improvement - You contribute to ongoing service improvement through participation in supporting threat hunting activity led by Senior SOC Analysts, rule tuning, and process refinement initiatives. You assist in monthly reporting and post-incident reviews to drive improvements that reflect our commitment to transparent and reliable performance Required Qualifications & Experience You may be required to hold or obtain UK Non-Police Personnel Vetting (NPPV) and/or a Security Check (SC) clearance as part of this role Willingness to work towards or obtain intermediate cybersecurity certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst) Proficiency with SIEM platforms, endpoint security tools, and ticketing systems, with an ability to make clear, data-driven decisions under pressure Critical Competencies - Technical Fit Operating Systems - Possess detailed knowledge of Windows and Linux system architectures, with a clear understanding of how event logs (e.g., Windows Event Viewer, Syslog) reflect system security posture Networking and Protocols - Have a comprehensive understanding of TCP/IP, DNS, DCHP, VPNs, SSL/TLS, and network forensics concepts to validate network-based alerts and anomalies Cybersecurity Frameworks - Deeply understand and be able to articulate the elements of the MITRE ATT&CK framework, and Cyber Kill Chain; know how adversary tactics and techniques translate into observable indicators SIEM and Security Tools - Know the theoretical underpinnings of SIEM operations, including alert correlation, the design of automated detection rules, and the interpretation of aggregated security data Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence - how feeds are sourced, what constitutes actionable information, and how malware indicators are defined Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling Benefits At Claranet, we go the extra mile with our people-because we believe in building a workplace where everyone feels valued and supported. What makes us unique is Team Claranet , our internal community that supports causes close to our employees' hearts. We offer paid charity leave, support local charities across our offices, and host annual fundraising events, all backed by a dedicated committee. We're proud founding members of TC4RE (Technology Community for Racial Equality) working collectively to build a more diverse and inclusive tech industry. About Claranet Founded at the beginning of the dot com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries. Equal Opportunities Statement Diversity, equity and inclusion are at the heart of what we value as an organisation. Claranet is an equal opportunities employer and all qualified applicants will receive consideration for employment without regard to race, religion, sex, sexual orientation, age, disability or any other status protected by law. Our recruitment team are happy to support any reasonable adjustments that are needed within the recruitment process. Ready to take the next step in your career with Claranet? Click 'apply' - we can't wait to meet you! To view full job description please visit our careers page
Senior Cyber Security Risk & Assurance Consultant - Product Risk (PBRA) (CONTRACTOR) - London Duration: 1 year contract Hybrid Working - 8 days onsite per month - the rest is remote working About the Team The Product-Based Risk Assessment (PBRA) service conducts recurring security assessments of applications, services, and technologies to identify emerging threats, evaluate control effectiveness, and drive remediation that strengthens The clients cyber resilience. The team supports business and technology stakeholders by assessing cyber security risks and ensuring alignment with The Banks security standards and risk appetite. Key Accountabilities Product-Based Risk Assessments Lead end-to-end Product-Based Risk Assessments (PBRA) for critical applications, platforms, and technology services. Analyse application architectures, business processes, information flows, and supporting infrastructure. Identify and assess cyber threats, vulnerabilities, control weaknesses, and potential business impacts. Evaluate the design and effectiveness of security controls using clients security frameworks and standards. Assess residual risks and propose actionable remediation plans. Security Risk Analysis Perform security risk assessments using recognised methodologies and industry frameworks. Evaluate risks related to infrastructure, software, cloud services, networks, third-party integrations, and information assets. Contribute to threat modelling and attack surface analysis activities. Support technology-focused assessments such as cloud, AI, and emerging technology evaluations. Stakeholder Engagement Act as the primary security assessment contact for business and IT stakeholders. Facilitate workshops, interviews, and assessment review sessions. Challenge assumptions and provide expert security guidance to delivery and operations teams. Build trusted relationships across CISO, CTO, Architecture, Risk Management, and Engineering teams. Reporting & Governance Produce high-quality assessment reports, risk summaries, and executive-level communications. Present findings and recommendations to senior management and governance bodies. Track remediation plans and risk treatment activities through closure. Support internal and external audit activities as required. Continuous Improvement Contribute to the evolution of the PBRA service, methodologies, tools, and operating model. Help drive the transition toward data-enabled and automated security assessment capabilities. Identify opportunities to improve efficiency, consistency, and risk coverage across assessments. Support knowledge sharing and mentoring of junior analysts. Required Skills & Experience Technical Skills Strong understanding of cybersecurity principles, controls, and risk management practices. Knowledge of application security, cloud security, infrastructure security, and network security. Experience conducting security assessments, threat modelling, or risk analyses. Familiarity with industry frameworks and standards such as: NIST Cyber Security Framework ISO 27001 CIS Controls Secure Controls Framework (SCF) DORA ANSSI EBIOS RM OWASP Professional Experience Minimum 7 years of experience in Information Security, Cyber Risk, Security Assurance, or Security Architecture. Experience leading complex security assessments across large technology environments. Experience working with senior business and technology stakeholders. Strong report-writing and presentation skills. Personal Competencies Strong analytical and critical-thinking capabilities. Excellent communication and stakeholder management skills. Ability to challenge constructively and influence decision-making. Self-driven with strong ownership and accountability. Pragmatic, risk-based mindset. Comfortable operating in a complex, regulated environment. Please do send across to me the most up to date CV to (url removed) Rates depend on experience and client requirements
Aug 23, 2026
Contractor
Senior Cyber Security Risk & Assurance Consultant - Product Risk (PBRA) (CONTRACTOR) - London Duration: 1 year contract Hybrid Working - 8 days onsite per month - the rest is remote working About the Team The Product-Based Risk Assessment (PBRA) service conducts recurring security assessments of applications, services, and technologies to identify emerging threats, evaluate control effectiveness, and drive remediation that strengthens The clients cyber resilience. The team supports business and technology stakeholders by assessing cyber security risks and ensuring alignment with The Banks security standards and risk appetite. Key Accountabilities Product-Based Risk Assessments Lead end-to-end Product-Based Risk Assessments (PBRA) for critical applications, platforms, and technology services. Analyse application architectures, business processes, information flows, and supporting infrastructure. Identify and assess cyber threats, vulnerabilities, control weaknesses, and potential business impacts. Evaluate the design and effectiveness of security controls using clients security frameworks and standards. Assess residual risks and propose actionable remediation plans. Security Risk Analysis Perform security risk assessments using recognised methodologies and industry frameworks. Evaluate risks related to infrastructure, software, cloud services, networks, third-party integrations, and information assets. Contribute to threat modelling and attack surface analysis activities. Support technology-focused assessments such as cloud, AI, and emerging technology evaluations. Stakeholder Engagement Act as the primary security assessment contact for business and IT stakeholders. Facilitate workshops, interviews, and assessment review sessions. Challenge assumptions and provide expert security guidance to delivery and operations teams. Build trusted relationships across CISO, CTO, Architecture, Risk Management, and Engineering teams. Reporting & Governance Produce high-quality assessment reports, risk summaries, and executive-level communications. Present findings and recommendations to senior management and governance bodies. Track remediation plans and risk treatment activities through closure. Support internal and external audit activities as required. Continuous Improvement Contribute to the evolution of the PBRA service, methodologies, tools, and operating model. Help drive the transition toward data-enabled and automated security assessment capabilities. Identify opportunities to improve efficiency, consistency, and risk coverage across assessments. Support knowledge sharing and mentoring of junior analysts. Required Skills & Experience Technical Skills Strong understanding of cybersecurity principles, controls, and risk management practices. Knowledge of application security, cloud security, infrastructure security, and network security. Experience conducting security assessments, threat modelling, or risk analyses. Familiarity with industry frameworks and standards such as: NIST Cyber Security Framework ISO 27001 CIS Controls Secure Controls Framework (SCF) DORA ANSSI EBIOS RM OWASP Professional Experience Minimum 7 years of experience in Information Security, Cyber Risk, Security Assurance, or Security Architecture. Experience leading complex security assessments across large technology environments. Experience working with senior business and technology stakeholders. Strong report-writing and presentation skills. Personal Competencies Strong analytical and critical-thinking capabilities. Excellent communication and stakeholder management skills. Ability to challenge constructively and influence decision-making. Self-driven with strong ownership and accountability. Pragmatic, risk-based mindset. Comfortable operating in a complex, regulated environment. Please do send across to me the most up to date CV to (url removed) Rates depend on experience and client requirements
Systems Engineer - (phone number removed) - £35.94/hr umbrella rate Do you have a proven experience as a Systems Engineer across the entire lifecycle in complex environments such as electrical/electronic, software, or mechatronics? Are you ready to elevate your career as a Systems Engineer? This is your chance to work on cutting-edge projects within an inspiring environment that champions innovation and excellence. This company is seeking talented individuals with real-world systems engineering experience to shape the future of their products and services. If you thrive in industries such as automotive, aerospace, defence, or rail and are passionate about delivering impactful solutions, this role is perfect for you. What You Will Do: - Develop and maintain systems engineering competence within your team, ensuring high-quality standards. - Author robust requirements that meet quality benchmarks and regulatory compliance. - Gather end-user needs and concerns to refine processes and methods. - Collaborate with business analysts to create efficient and compliant processes. - Identify key performance indicators for systems engineering processes and track progress. - Guide the development of tools, training, and methods to support systems engineering principles. What You Will Bring: - Proven experience as a Systems Engineer across the entire lifecycle in complex environments such as electrical/electronic, software, or mechatronics. - Hands-on application of Systems Engineering tools like IBM DOORS, Rhapsody, or Catia Magic. - Expertise in requirements management aligned with Systems Engineering processes. - Real-world experience in process and method development for systems engineering. - Knowledge of system modelling, functional safety practices, and cyber security. Your contributions as a Systems Engineer will be instrumental in driving innovation and excellence within this company. By bringing your skills and expertise, you will play a key role in delivering solutions that align with industry standards and exceed expectations. Location: This position is based in Gaydon, a hub of engineering excellence and innovation. Interested?: Don't miss this opportunity to become a vital part of a forward-thinking team. Apply now to take the next step in your career as a Systems Engineer. Let's make innovation happen together! This role is Inside IR35. Your CV will be forwarded to Jonathan Lee Recruitment, a leading engineering and manufacturing recruitment consultancy established in 1978. The services advertised by Jonathan Lee Recruitment are those of an Employment Agency. In order for your CV to be processed effectively, please ensure your name, email address, phone number and location (post code OR town OR county, as a minimum) are included.
Aug 23, 2026
Contractor
Systems Engineer - (phone number removed) - £35.94/hr umbrella rate Do you have a proven experience as a Systems Engineer across the entire lifecycle in complex environments such as electrical/electronic, software, or mechatronics? Are you ready to elevate your career as a Systems Engineer? This is your chance to work on cutting-edge projects within an inspiring environment that champions innovation and excellence. This company is seeking talented individuals with real-world systems engineering experience to shape the future of their products and services. If you thrive in industries such as automotive, aerospace, defence, or rail and are passionate about delivering impactful solutions, this role is perfect for you. What You Will Do: - Develop and maintain systems engineering competence within your team, ensuring high-quality standards. - Author robust requirements that meet quality benchmarks and regulatory compliance. - Gather end-user needs and concerns to refine processes and methods. - Collaborate with business analysts to create efficient and compliant processes. - Identify key performance indicators for systems engineering processes and track progress. - Guide the development of tools, training, and methods to support systems engineering principles. What You Will Bring: - Proven experience as a Systems Engineer across the entire lifecycle in complex environments such as electrical/electronic, software, or mechatronics. - Hands-on application of Systems Engineering tools like IBM DOORS, Rhapsody, or Catia Magic. - Expertise in requirements management aligned with Systems Engineering processes. - Real-world experience in process and method development for systems engineering. - Knowledge of system modelling, functional safety practices, and cyber security. Your contributions as a Systems Engineer will be instrumental in driving innovation and excellence within this company. By bringing your skills and expertise, you will play a key role in delivering solutions that align with industry standards and exceed expectations. Location: This position is based in Gaydon, a hub of engineering excellence and innovation. Interested?: Don't miss this opportunity to become a vital part of a forward-thinking team. Apply now to take the next step in your career as a Systems Engineer. Let's make innovation happen together! This role is Inside IR35. Your CV will be forwarded to Jonathan Lee Recruitment, a leading engineering and manufacturing recruitment consultancy established in 1978. The services advertised by Jonathan Lee Recruitment are those of an Employment Agency. In order for your CV to be processed effectively, please ensure your name, email address, phone number and location (post code OR town OR county, as a minimum) are included.
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Aug 23, 2026
Full time
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.