• Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
  • Sign in
  • Sign up
  • Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

60 jobs found

Email me jobs like this
Refine Search
Current Search
cyber threat and vulnerability management lead
Government Digital & Data
Head of Cyber Security Risk Management (Digital Identity) - Government Digital Service - G6
Government Digital & Data
Location Bristol, London, Manchester About the job Job summary This role will require the post holder to have SC clearance to start and may be required to undergo Developed Vetting (DV) once in post, therefore successful candidates will be expected to either hold this or be willing to undertake the DV clearance process once in post. More information on DV clearance is linked here The Government Digital Service (GDS) is the digital centre of government. We are responsible for setting, leading and delivering the vision for a modern digital government. Our priorities are to drive a modern digital government, by: joining up public sector services harnessing the power of AI for the public good strengthening and extending our digital and data public infrastructure elevating leadership and investing in talent funding for outcomes andprocuringfor growth and innovation committing to transparency and driving accountability We are home to the Incubator for Artificial Intelligence (I.AI), the world-leading GOV.UK and at the forefront of coordinating the UK's geospatial strategy and activity. We lead the Government Digital and Data function and champion the work of digital teams across government. We're part of the Department for Science, Innovation and Technology (DSIT) and employ more than 1,000 people all over the UK, with hubs in Manchester, London and Bristol. The Government Digital Service is where talent translates into impact. From your first day, you'll be working with some of the world's most highly-skilled digital professionals, all contributing their knowledge to make change on a national scale. Join us for rewarding work that makes a difference across the UK. You'll solve some of the nation's highest-priority digital challenges, helping millions of people access services they need Job description As Head of Cyber Security Risk Management for One Login and Digital Identity you will play a central role in protecting the UK's current and future digital identity ecosystem. At scale, One Login will be the front door for millions of users to access digital public services. Security, reliability and resilience are absolutely critical to delivering our mission. This is a high profile role, suited to an experienced security leader with a track record of setting direction and running security risk, governance and assurance for a complex area. As Head of Cyber Security Risk Management you will have oversight for the Digital Identity Cyber Information Assurance team, taking responsibility for the governance, risk management, compliance and 3rd party assurance. In addition, you will be responsible for: governance, risk and assurance leadership: building civil servant capability to run a mature, responsive cyber assurance team, working in collaboration with One Logins dedicated Security Operations, Security Design & Architecture, Pods (developer teams) and wider GDS and DSIT cyber teams. Work in partnership with GDS (Privacy, Information Assurance, Security Architecture, Cyber), GSG, CDIO Cyber, NCSC and other government departments governance, risk and assurance: lead design, implementation and operating of information security governance frameworks aligned to DSIT and regulatory context. Ensure the team provides independent information assurance across the One Login Programme but work closely with the GDS Infosec team for second line assurance. Build and lead the third party and supply chain assurance strategy. Maintain and innovate the current risk management board ensuring present risk positions are clearly communicated to the senior leadership team (SLT). multi tier assurance: work closely with the GDS Infosec Team to support 2nd line assurance. Build and manage an integrated governance process which has a unified risk perspective enabling both first and second line assurance to work on a common understanding of the risk posture. Drive proactive engagement across both teams to stop any siloed forming and make sure the risk development lifecycle is balanced. policy & standards: develop and maintain security policies, standards frameworks, and governance processes aligned to government and industry best practice for complex cloud-native environments assurance & remediation: drive security assurance activities across One Login programmes, suppliers, and operational services, including audits, assessments, and ensuring timely remediation within required SLOs stakeholder collaboration: build strong relationships with key stakeholders-including GDS (Privacy, Information Assurance, Security Architecture), GSG, CDIO Cyber, and NCSC-to embed security into delivery, architecture, procurement, and operational decision making compliance & frameworks: ensure all operations meet stringent UK Government security requirements by supporting regulatory and contractual compliance activities, including alignment to standards such as NIST, CAF, and GovAssure governance & reporting: establish and maintain operational metrics to produce clear, meaningful reporting and dashboards that measure the programme's threat posture and support executive decision making security culture leadership : working in close collaboration with the Head of Product Security and Head of Security Operations for One Login and the GDS CISO, take responsibility for embedding a robust security culture across the programme. Person specification We're interested in people who have experience and knowledge of most of the following: a strong track record of experience leading security governance, assurance, risk, or compliance functions, ideally for a Critical National Infrastructure (CNI) or comparable risk/profile/impact level product in-depth knowledge of government security standards, frameworks, and assurance approaches, with demonstrable success applying frameworks such as CAF, NIST 800-53, GovAssure, and Secure by Design Principles experience developing and implementing security policies and control frameworks in complex cloud-native environments and serverless architectures ability to communicate complex security concepts clearly and establish effective working relationships with key security stakeholders, including technical and non-technical specialists across organisational boundaries strong analytical, reporting, and risk management capabilities, including building governance dashboards and executive-level assurance reporting understanding of supplier assurance, vulnerability management, and experience integrating governance with security operational integration. hold recognised cyber security certifications such as CISSP, CISM, or CRISC
Aug 24, 2026
Full time
Location Bristol, London, Manchester About the job Job summary This role will require the post holder to have SC clearance to start and may be required to undergo Developed Vetting (DV) once in post, therefore successful candidates will be expected to either hold this or be willing to undertake the DV clearance process once in post. More information on DV clearance is linked here The Government Digital Service (GDS) is the digital centre of government. We are responsible for setting, leading and delivering the vision for a modern digital government. Our priorities are to drive a modern digital government, by: joining up public sector services harnessing the power of AI for the public good strengthening and extending our digital and data public infrastructure elevating leadership and investing in talent funding for outcomes andprocuringfor growth and innovation committing to transparency and driving accountability We are home to the Incubator for Artificial Intelligence (I.AI), the world-leading GOV.UK and at the forefront of coordinating the UK's geospatial strategy and activity. We lead the Government Digital and Data function and champion the work of digital teams across government. We're part of the Department for Science, Innovation and Technology (DSIT) and employ more than 1,000 people all over the UK, with hubs in Manchester, London and Bristol. The Government Digital Service is where talent translates into impact. From your first day, you'll be working with some of the world's most highly-skilled digital professionals, all contributing their knowledge to make change on a national scale. Join us for rewarding work that makes a difference across the UK. You'll solve some of the nation's highest-priority digital challenges, helping millions of people access services they need Job description As Head of Cyber Security Risk Management for One Login and Digital Identity you will play a central role in protecting the UK's current and future digital identity ecosystem. At scale, One Login will be the front door for millions of users to access digital public services. Security, reliability and resilience are absolutely critical to delivering our mission. This is a high profile role, suited to an experienced security leader with a track record of setting direction and running security risk, governance and assurance for a complex area. As Head of Cyber Security Risk Management you will have oversight for the Digital Identity Cyber Information Assurance team, taking responsibility for the governance, risk management, compliance and 3rd party assurance. In addition, you will be responsible for: governance, risk and assurance leadership: building civil servant capability to run a mature, responsive cyber assurance team, working in collaboration with One Logins dedicated Security Operations, Security Design & Architecture, Pods (developer teams) and wider GDS and DSIT cyber teams. Work in partnership with GDS (Privacy, Information Assurance, Security Architecture, Cyber), GSG, CDIO Cyber, NCSC and other government departments governance, risk and assurance: lead design, implementation and operating of information security governance frameworks aligned to DSIT and regulatory context. Ensure the team provides independent information assurance across the One Login Programme but work closely with the GDS Infosec team for second line assurance. Build and lead the third party and supply chain assurance strategy. Maintain and innovate the current risk management board ensuring present risk positions are clearly communicated to the senior leadership team (SLT). multi tier assurance: work closely with the GDS Infosec Team to support 2nd line assurance. Build and manage an integrated governance process which has a unified risk perspective enabling both first and second line assurance to work on a common understanding of the risk posture. Drive proactive engagement across both teams to stop any siloed forming and make sure the risk development lifecycle is balanced. policy & standards: develop and maintain security policies, standards frameworks, and governance processes aligned to government and industry best practice for complex cloud-native environments assurance & remediation: drive security assurance activities across One Login programmes, suppliers, and operational services, including audits, assessments, and ensuring timely remediation within required SLOs stakeholder collaboration: build strong relationships with key stakeholders-including GDS (Privacy, Information Assurance, Security Architecture), GSG, CDIO Cyber, and NCSC-to embed security into delivery, architecture, procurement, and operational decision making compliance & frameworks: ensure all operations meet stringent UK Government security requirements by supporting regulatory and contractual compliance activities, including alignment to standards such as NIST, CAF, and GovAssure governance & reporting: establish and maintain operational metrics to produce clear, meaningful reporting and dashboards that measure the programme's threat posture and support executive decision making security culture leadership : working in close collaboration with the Head of Product Security and Head of Security Operations for One Login and the GDS CISO, take responsibility for embedding a robust security culture across the programme. Person specification We're interested in people who have experience and knowledge of most of the following: a strong track record of experience leading security governance, assurance, risk, or compliance functions, ideally for a Critical National Infrastructure (CNI) or comparable risk/profile/impact level product in-depth knowledge of government security standards, frameworks, and assurance approaches, with demonstrable success applying frameworks such as CAF, NIST 800-53, GovAssure, and Secure by Design Principles experience developing and implementing security policies and control frameworks in complex cloud-native environments and serverless architectures ability to communicate complex security concepts clearly and establish effective working relationships with key security stakeholders, including technical and non-technical specialists across organisational boundaries strong analytical, reporting, and risk management capabilities, including building governance dashboards and executive-level assurance reporting understanding of supplier assurance, vulnerability management, and experience integrating governance with security operational integration. hold recognised cyber security certifications such as CISSP, CISM, or CRISC
Yolk Recruitment
Cyber Security Analyst
Yolk Recruitment
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Aug 23, 2026
Full time
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Rebel Recruitment Limited
Cyber Assurance Consultant
Rebel Recruitment Limited Nottingham, Nottinghamshire
Role: Cyber and Information Assurance Consultant Mid, Senior & Principal Levels Location: Nottingham / Remote-first Working Arrangement: Remote-first, with travel to Nottingham and customer sites as required Salary: £65,000 £120,000 Are you a cyber security or information assurance professional who enjoys working with customers, getting into complex problems and turning security risks into practical solutions? We re looking for Cyber and Information Assurance Consultants across Mid, Senior and Principal levels to join a growing team working on complex, high-assurance environments across defence, government and critical infrastructure. This is a consultancy-focused role, so you won t be sitting in a purely internal security position. You ll work directly with customers, technical teams and senior stakeholders to assess risk, understand threats and vulnerabilities, and provide clear recommendations on how security can be improved. You ll work across areas including cyber risk assessments, information assurance, security governance and secure-by-design. Depending on your level and experience, you could be reviewing solution designs, developing security cases, supporting accreditation and assurance activity, maintaining risk registers or helping shape security requirements across major programmes. You ll also work closely with architects, engineers, project teams, suppliers and customer security teams. A big part of the role will be taking technical evidence and security requirements and explaining what they actually mean from a risk and business perspective. You ll ideally have professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline, alongside experience contributing to security assessment or assurance work. You ll need to be comfortable producing clear security documentation and communicating with both technical and non-technical audiences. Knowledge of areas such as cyber risk management, security controls, threat and vulnerability assessment, security governance and risk acceptance is important. Experience with frameworks such as ISO 27001, ISO 27005, the NCSC Cyber Assessment Framework, NIST or MOD security standards would be beneficial. Experience within defence, government, critical infrastructure or another high-assurance environment would be particularly relevant. Experience with cloud security assurance, security architecture reviews, accreditation or secure information exchange would also be useful. The level you join at will depend on your experience, with opportunities available from Mid-level through to Principal. There is a clear progression route into senior consultancy, security architecture, cyber risk leadership and information assurance leadership, with support towards professional qualifications such as CISSP, CISM, CRISC and ISO 27001. The role is remote-first, although you ll need to be comfortable travelling to the Nottingham office and customer sites when required. Regular UK travel may form part of the role, with occasional international travel possible. If you re looking for a role where you can work on genuinely complex security challenges, have direct customer exposure and continue developing your career across cyber security and assurance, please apply now or get in touch to find out more. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Aug 23, 2026
Full time
Role: Cyber and Information Assurance Consultant Mid, Senior & Principal Levels Location: Nottingham / Remote-first Working Arrangement: Remote-first, with travel to Nottingham and customer sites as required Salary: £65,000 £120,000 Are you a cyber security or information assurance professional who enjoys working with customers, getting into complex problems and turning security risks into practical solutions? We re looking for Cyber and Information Assurance Consultants across Mid, Senior and Principal levels to join a growing team working on complex, high-assurance environments across defence, government and critical infrastructure. This is a consultancy-focused role, so you won t be sitting in a purely internal security position. You ll work directly with customers, technical teams and senior stakeholders to assess risk, understand threats and vulnerabilities, and provide clear recommendations on how security can be improved. You ll work across areas including cyber risk assessments, information assurance, security governance and secure-by-design. Depending on your level and experience, you could be reviewing solution designs, developing security cases, supporting accreditation and assurance activity, maintaining risk registers or helping shape security requirements across major programmes. You ll also work closely with architects, engineers, project teams, suppliers and customer security teams. A big part of the role will be taking technical evidence and security requirements and explaining what they actually mean from a risk and business perspective. You ll ideally have professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline, alongside experience contributing to security assessment or assurance work. You ll need to be comfortable producing clear security documentation and communicating with both technical and non-technical audiences. Knowledge of areas such as cyber risk management, security controls, threat and vulnerability assessment, security governance and risk acceptance is important. Experience with frameworks such as ISO 27001, ISO 27005, the NCSC Cyber Assessment Framework, NIST or MOD security standards would be beneficial. Experience within defence, government, critical infrastructure or another high-assurance environment would be particularly relevant. Experience with cloud security assurance, security architecture reviews, accreditation or secure information exchange would also be useful. The level you join at will depend on your experience, with opportunities available from Mid-level through to Principal. There is a clear progression route into senior consultancy, security architecture, cyber risk leadership and information assurance leadership, with support towards professional qualifications such as CISSP, CISM, CRISC and ISO 27001. The role is remote-first, although you ll need to be comfortable travelling to the Nottingham office and customer sites when required. Regular UK travel may form part of the role, with occasional international travel possible. If you re looking for a role where you can work on genuinely complex security challenges, have direct customer exposure and continue developing your career across cyber security and assurance, please apply now or get in touch to find out more. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Lead Software Security Engineer
United States Digital Space LLC
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Aug 23, 2026
Full time
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Comtecs Ltd
Cyber Security Engineer - MS Sentinel, Defender, SSO, PKI, SC-100/200, CISSP
Comtecs Ltd
IT Cyber Security Specialist / Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team, supporting and continually improving cybersecurity across a global IT environment. Reporting to the Infrastructure Engineering Manager, you'll take ownership of cybersecurity controls and security architecture while working closely with Infrastructure Operations and other technology teams to identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across a complex infrastructure environment, identifying and mitigating security risks, supporting major cyber incidents and contributing to strategic security and infrastructure projects. You'll also help develop security awareness, business continuity capabilities and ongoing improvements to the firm's security controls. Key Responsibilities: Continuously review and improve the firm's cybersecurity posture from an infrastructure perspective and external security rating. Identify, assess and remediate vulnerabilities across hardware, software and infrastructure (Windows Server and Azure Cloud). Monitor emerging threats and lead or support Incident Response investigations and mitigation. Evaluate, test and recommend security enhancements, controls and threat prevention technologies. Identify security risks and exposures and develop measures to prevent future incidents. Lead CE+ accreditation and support security, risk and data protection requirements from a technical (Not GRC) perspective. Participate in and lead infrastructure lifecycle, security and technology projects. Provide 3rd Line / Major Incident support as a cybersecurity subject matter expert. Work with third-party suppliers and advise internal technical teams on security measures to resolve security and infrastructure issues. We're looking for experienced Cyber Security engineer with strong technical infrastructure knowledge and proven experience across incident response, threat monitoring and vulnerability management. You will possess: Extensive experience in a similar role blending Cyber Security with core Wintel Infrastructure and Azure cloud engineering. Strong knowledge of modern security architecture, threat prevention techniques and incident response. Strong Windows Server 2016/2019/2022 knowledge including Active Directory, DNS, DHCP, Intune, Group Policy, PKI, Entra and Azure SSO. Demonstrable experience across Cyber Security, Incident Response, Threat Monitoring and Vulnerability Management using tools such as MS Sentinel, MS Defender etc for threat hunting, vulnerability monitoring and security posture improvement. CISSP, CEH, CCNA Security, SC-100, SC200 or equivalent security certification. Experience designing, integrating and managing complex infrastructure and cloud solutions from a cyber security standpoint and advising technical infrastructure teams on security focussed designs and operations Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. Experience working with third-party providers across on-premise and cloud services. Strong planning skills and knowledge of ITIL processes and best practice. This is an excellent opportunity to join a highly regarded global organisation where you'll play a key role in strengthening cybersecurity across a complex international IT environment, combining hands-on security engineering, incident response and strategic infrastructure projects.
Aug 22, 2026
Full time
IT Cyber Security Specialist / Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team, supporting and continually improving cybersecurity across a global IT environment. Reporting to the Infrastructure Engineering Manager, you'll take ownership of cybersecurity controls and security architecture while working closely with Infrastructure Operations and other technology teams to identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across a complex infrastructure environment, identifying and mitigating security risks, supporting major cyber incidents and contributing to strategic security and infrastructure projects. You'll also help develop security awareness, business continuity capabilities and ongoing improvements to the firm's security controls. Key Responsibilities: Continuously review and improve the firm's cybersecurity posture from an infrastructure perspective and external security rating. Identify, assess and remediate vulnerabilities across hardware, software and infrastructure (Windows Server and Azure Cloud). Monitor emerging threats and lead or support Incident Response investigations and mitigation. Evaluate, test and recommend security enhancements, controls and threat prevention technologies. Identify security risks and exposures and develop measures to prevent future incidents. Lead CE+ accreditation and support security, risk and data protection requirements from a technical (Not GRC) perspective. Participate in and lead infrastructure lifecycle, security and technology projects. Provide 3rd Line / Major Incident support as a cybersecurity subject matter expert. Work with third-party suppliers and advise internal technical teams on security measures to resolve security and infrastructure issues. We're looking for experienced Cyber Security engineer with strong technical infrastructure knowledge and proven experience across incident response, threat monitoring and vulnerability management. You will possess: Extensive experience in a similar role blending Cyber Security with core Wintel Infrastructure and Azure cloud engineering. Strong knowledge of modern security architecture, threat prevention techniques and incident response. Strong Windows Server 2016/2019/2022 knowledge including Active Directory, DNS, DHCP, Intune, Group Policy, PKI, Entra and Azure SSO. Demonstrable experience across Cyber Security, Incident Response, Threat Monitoring and Vulnerability Management using tools such as MS Sentinel, MS Defender etc for threat hunting, vulnerability monitoring and security posture improvement. CISSP, CEH, CCNA Security, SC-100, SC200 or equivalent security certification. Experience designing, integrating and managing complex infrastructure and cloud solutions from a cyber security standpoint and advising technical infrastructure teams on security focussed designs and operations Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. Experience working with third-party providers across on-premise and cloud services. Strong planning skills and knowledge of ITIL processes and best practice. This is an excellent opportunity to join a highly regarded global organisation where you'll play a key role in strengthening cybersecurity across a complex international IT environment, combining hands-on security engineering, incident response and strategic infrastructure projects.
Cyber Security Lead
慨正橡扯
Primary Details Time Type: Full time Worker Type: Employee Cyber Security Lead Location: London Type: Permanent, full time Hybrid role, happy to talk flexible working The Opportunity QBE Europe is recruiting a Cyber Security Lead to join our European Cyber Security team in our London office. The role has accountability across operational delivery and advisory capabilities within QBE's cyber services and value streams, with the opportunity to drive continuous improvement and transformational change in the way Cyber and information security risk is considered and mitigated across the core business, our programs and projects. The role works to make QBE safe, secure and resilient; working to continuously out pace and outsmart cyber threat faced by our business. This intellectually challenging and highly influential role is part of an enterprise wide Cyber Security capability, accountable for safeguarding QBE from increasingly sophisticated Cyber and information security threats. This is a highly collaborative role, requiring a sustained level of curiosity and a continuous ability to grow deep technical knowledge that translates into insight to solve root cause problems and supports strategic business outcomes. Having the right to work in the UK is a requirement for this role. QBE may consider sponsorship at its discretion. About QBE At QBE, we get to the heart of what matters for our customers. And we do it all with a human touch. We're an international insurer with more than 13,000 people working across 26 countries - which means we're big enough for your ambitions, yet small enough for you to make a real impact. It's an exciting time. We're building momentum towards our vision to become the most consistent and innovative risk partner. What if you could have a positive impact - at work and in the world? As part of the QBE team, you'll get to spend every day working with people who are passionate, talented and kind. Your new role Deliver an effective cyber and information security capability across QBE, partnering to deliver appropriate levels of engagement and risk mitigation. Develop the cyber and information security experience across QBE, building awareness and engendering healthy curiosity. Build strong collaborative relationships, providing advice and working together to identify and solve root cause problems; demonstrating great tenacity in reducing potential threats and risks. Take personal accountability for seeking out and identifying security weaknesses; seeing mitigation through to a secure conclusion. Drive Cyber engagement across QBE to ensure issues are identified, self reported and notified to key stakeholders. Act with integrity and transparency in threat and risk identification and problem solving. Role model the creation, innovation and negotiation of solutions and risk mitigation strategies; driving fast paced and agile behaviours. Drive the development, execution and assurance of an effective Cyber practice; including the adoption of relevant policy, standards, processes and templates. Manage and quality assure cyber service and outsourced security arrangements; ensuring delivery to SLAs, quality controls and alignment with QBE requirements. Drive collaboration and partnership across the QBE business value streams. Track compliance and security benefits to demonstrate impact and mitigation success. About You Demonstrates exceptional resilience and tenacity in managing and mitigating 24x7 cyber threats whilst successfully managing work life balance. Solution oriented. Problem solving mindset with the ability to see solutions through to delivery. Demonstrable ability to support the development of QBE cyber services and talent, building technical excellence and decision making confidence. Insightful and expert ability to consider where and how people or technology could be exploited; getting into the mindset of an adversary. Exceptional ability to get deeply technical and apply that skill to the business environment. Expertise in one or more of the following areas: Identity and Access Management, Data Security, Threat and Vulnerability Management, Third Party Risk, Cyber Security Infrastructure and Cyber Security Operations. Strong decision making ability when faced with complex and business critical threats. Excellent communication, negotiation and conflict management skills, with an ability to anticipate and pre empt potential obstacles; strong listening skills. Good ability to write and articulate, summarise and present complex problems and messages in a succinct and comprehensible manner. Exceptionally curious and enquiring mindset with a fast paced and agile personal drive to meet business needs. Benefits 30 days holiday a year with the option to buy up to 2 additional days. Flexible working - balancing work and life is important so our flexible working opportunities are open to all, including part time, job share and compressed hours. Pension - you are automatically enrolled into the QBE pension plan, which entitles you to receive employer contributions of 10% of your basic salary. Equal Employment Opportunity: QBE is an equal opportunity employer and is required to comply with equal employment opportunity legislation in each jurisdiction it operates. Application Close Date: 12/06/:59 PM
Aug 21, 2026
Full time
Primary Details Time Type: Full time Worker Type: Employee Cyber Security Lead Location: London Type: Permanent, full time Hybrid role, happy to talk flexible working The Opportunity QBE Europe is recruiting a Cyber Security Lead to join our European Cyber Security team in our London office. The role has accountability across operational delivery and advisory capabilities within QBE's cyber services and value streams, with the opportunity to drive continuous improvement and transformational change in the way Cyber and information security risk is considered and mitigated across the core business, our programs and projects. The role works to make QBE safe, secure and resilient; working to continuously out pace and outsmart cyber threat faced by our business. This intellectually challenging and highly influential role is part of an enterprise wide Cyber Security capability, accountable for safeguarding QBE from increasingly sophisticated Cyber and information security threats. This is a highly collaborative role, requiring a sustained level of curiosity and a continuous ability to grow deep technical knowledge that translates into insight to solve root cause problems and supports strategic business outcomes. Having the right to work in the UK is a requirement for this role. QBE may consider sponsorship at its discretion. About QBE At QBE, we get to the heart of what matters for our customers. And we do it all with a human touch. We're an international insurer with more than 13,000 people working across 26 countries - which means we're big enough for your ambitions, yet small enough for you to make a real impact. It's an exciting time. We're building momentum towards our vision to become the most consistent and innovative risk partner. What if you could have a positive impact - at work and in the world? As part of the QBE team, you'll get to spend every day working with people who are passionate, talented and kind. Your new role Deliver an effective cyber and information security capability across QBE, partnering to deliver appropriate levels of engagement and risk mitigation. Develop the cyber and information security experience across QBE, building awareness and engendering healthy curiosity. Build strong collaborative relationships, providing advice and working together to identify and solve root cause problems; demonstrating great tenacity in reducing potential threats and risks. Take personal accountability for seeking out and identifying security weaknesses; seeing mitigation through to a secure conclusion. Drive Cyber engagement across QBE to ensure issues are identified, self reported and notified to key stakeholders. Act with integrity and transparency in threat and risk identification and problem solving. Role model the creation, innovation and negotiation of solutions and risk mitigation strategies; driving fast paced and agile behaviours. Drive the development, execution and assurance of an effective Cyber practice; including the adoption of relevant policy, standards, processes and templates. Manage and quality assure cyber service and outsourced security arrangements; ensuring delivery to SLAs, quality controls and alignment with QBE requirements. Drive collaboration and partnership across the QBE business value streams. Track compliance and security benefits to demonstrate impact and mitigation success. About You Demonstrates exceptional resilience and tenacity in managing and mitigating 24x7 cyber threats whilst successfully managing work life balance. Solution oriented. Problem solving mindset with the ability to see solutions through to delivery. Demonstrable ability to support the development of QBE cyber services and talent, building technical excellence and decision making confidence. Insightful and expert ability to consider where and how people or technology could be exploited; getting into the mindset of an adversary. Exceptional ability to get deeply technical and apply that skill to the business environment. Expertise in one or more of the following areas: Identity and Access Management, Data Security, Threat and Vulnerability Management, Third Party Risk, Cyber Security Infrastructure and Cyber Security Operations. Strong decision making ability when faced with complex and business critical threats. Excellent communication, negotiation and conflict management skills, with an ability to anticipate and pre empt potential obstacles; strong listening skills. Good ability to write and articulate, summarise and present complex problems and messages in a succinct and comprehensible manner. Exceptionally curious and enquiring mindset with a fast paced and agile personal drive to meet business needs. Benefits 30 days holiday a year with the option to buy up to 2 additional days. Flexible working - balancing work and life is important so our flexible working opportunities are open to all, including part time, job share and compressed hours. Pension - you are automatically enrolled into the QBE pension plan, which entitles you to receive employer contributions of 10% of your basic salary. Equal Employment Opportunity: QBE is an equal opportunity employer and is required to comply with equal employment opportunity legislation in each jurisdiction it operates. Application Close Date: 12/06/:59 PM
Morgan Hunt Recruitment
Cyber Security Engineer
Morgan Hunt Recruitment
Cyber Security Engineer Housing Association 12-Month FTC Up to £65,000 Hybrid - Farringdon Morgan Hunt is delighted to be partnering with a leading Housing Association to recruit an experienced Cyber Security Engineer on an initial 12-month Fixed-Term Contract .This is an excellent opportunity for a hands-on security professional to join an established cyber security function and play a key role in strengthening the organisation's security capabilities across applications, infrastructure, networks, data and cloud platforms. The Role Working closely with the Cyber Security Manager and Senior Cyber Security Engineer , you will help design, implement and maintain the organisation's cyber security capabilities.You will have a broad remit across Microsoft security technologies, identity and access management, vulnerability management, incident response, SIEM/SOAR, threat hunting and cloud security , while also providing security advice to technology projects and supporting security-by-design principles. Key Responsibilities Design, implement and maintain cyber security solutions and capabilities. Administer and monitor Microsoft 365 security technologies , including Intune, Entra ID, Defender, Purview, Exchange Online, SharePoint and Teams. Support identity and access management, vulnerability management and security monitoring . Investigate and respond to security incidents, including SIEM/SOAR investigations and advanced threat hunting. Support security reviews, audits and annual penetration testing. Identify vulnerabilities, risks and opportunities to improve the organisation's security posture. Provide security advice to IT projects, ensuring security is embedded into solution design and technology decisions. Support and maintain alignment with Cyber Essentials Plus . Contribute to information security policies, procedures and standards. Work with internal teams and external partners to deliver security improvements. Keep up to date with emerging cyber security threats, vulnerabilities and industry best practice. About You We're looking for a Cyber Security Engineer with practical experience working within an information or cyber security environment.You should have: Strong knowledge of Microsoft Security technologies . Experience with Microsoft 365, Entra ID, Intune and Defender . Knowledge of SIEM/SOAR, vulnerability management and incident response . Understanding of cloud security and network security principles . Experience supporting security assessments, audits and penetration testing. Knowledge of security frameworks including NIST and Cyber Essentials . Understanding of ITIL processes, particularly Incident, Change and Problem Management. Strong communication and stakeholder management skills. The ability to work independently, manage competing priorities and solve complex security problems. Qualifications Essential: CompTIA Security+ or equivalent security experience. Desirable: Microsoft SC-200, SC-300 or SC-400 CEH CISSP CCNA Package & Working Arrangements Salary: Up to £65,000 per annum Contract: 12-month FTC Location: Farringdon, London Working pattern: Hybrid - 2 days per week in the office Benefits: 28 days holiday, Life Assurance, Pension (9%), and other benefits Sector: Housing / Not-for-Profit Morgan Hunt is a multi-award-winning recruitment business for interim, contract and temporary recruitment and acts as an Employment Agency in relation to permanent vacancies. Morgan Hunt is an equal opportunities employer. Job suitability is assessed on merit in accordance with the individual's skills, qualifications and abilities to perform the relevant duties required in a particular role.
Aug 21, 2026
Full time
Cyber Security Engineer Housing Association 12-Month FTC Up to £65,000 Hybrid - Farringdon Morgan Hunt is delighted to be partnering with a leading Housing Association to recruit an experienced Cyber Security Engineer on an initial 12-month Fixed-Term Contract .This is an excellent opportunity for a hands-on security professional to join an established cyber security function and play a key role in strengthening the organisation's security capabilities across applications, infrastructure, networks, data and cloud platforms. The Role Working closely with the Cyber Security Manager and Senior Cyber Security Engineer , you will help design, implement and maintain the organisation's cyber security capabilities.You will have a broad remit across Microsoft security technologies, identity and access management, vulnerability management, incident response, SIEM/SOAR, threat hunting and cloud security , while also providing security advice to technology projects and supporting security-by-design principles. Key Responsibilities Design, implement and maintain cyber security solutions and capabilities. Administer and monitor Microsoft 365 security technologies , including Intune, Entra ID, Defender, Purview, Exchange Online, SharePoint and Teams. Support identity and access management, vulnerability management and security monitoring . Investigate and respond to security incidents, including SIEM/SOAR investigations and advanced threat hunting. Support security reviews, audits and annual penetration testing. Identify vulnerabilities, risks and opportunities to improve the organisation's security posture. Provide security advice to IT projects, ensuring security is embedded into solution design and technology decisions. Support and maintain alignment with Cyber Essentials Plus . Contribute to information security policies, procedures and standards. Work with internal teams and external partners to deliver security improvements. Keep up to date with emerging cyber security threats, vulnerabilities and industry best practice. About You We're looking for a Cyber Security Engineer with practical experience working within an information or cyber security environment.You should have: Strong knowledge of Microsoft Security technologies . Experience with Microsoft 365, Entra ID, Intune and Defender . Knowledge of SIEM/SOAR, vulnerability management and incident response . Understanding of cloud security and network security principles . Experience supporting security assessments, audits and penetration testing. Knowledge of security frameworks including NIST and Cyber Essentials . Understanding of ITIL processes, particularly Incident, Change and Problem Management. Strong communication and stakeholder management skills. The ability to work independently, manage competing priorities and solve complex security problems. Qualifications Essential: CompTIA Security+ or equivalent security experience. Desirable: Microsoft SC-200, SC-300 or SC-400 CEH CISSP CCNA Package & Working Arrangements Salary: Up to £65,000 per annum Contract: 12-month FTC Location: Farringdon, London Working pattern: Hybrid - 2 days per week in the office Benefits: 28 days holiday, Life Assurance, Pension (9%), and other benefits Sector: Housing / Not-for-Profit Morgan Hunt is a multi-award-winning recruitment business for interim, contract and temporary recruitment and acts as an Employment Agency in relation to permanent vacancies. Morgan Hunt is an equal opportunities employer. Job suitability is assessed on merit in accordance with the individual's skills, qualifications and abilities to perform the relevant duties required in a particular role.
Senior Security Engineer
Data Science Festival
Staff Software Security Engineer Salary: Up to £135,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Staff Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Staff Software Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Software Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Staff Software Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £135,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Aug 20, 2026
Full time
Staff Software Security Engineer Salary: Up to £135,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Staff Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Staff Software Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Software Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Staff Software Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £135,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Everywhen, part of the Ardonagh Group
Threat Intelligence Lead
Everywhen, part of the Ardonagh Group
An exciting remote-based opportunity has arisen for a Threat Intelligence Lead to join our Technology team, reporting to the Chief Information Security Officer. You will design and lead the company's cyber threat intelligence (CTI), security testing and proactive threat-hunting programmes, helping to protect our customers, assets and brands across our global operations.Working closely with our internal and external security operations teams, you will anticipate, assess and mitigate threats. The intelligence you provide will support strategic decisions, incident response and continuous improvements to our cyber resilience. This pivotal Cyber Security role requires strong technical expertise, intelligence capability and commercial awareness within a regulated financial environment. What you will do as our Threat Intelligence Lead: This is an overview and not an exhaustive list of responsibilities. Collaborating with your Line Manager, you will develop your own objectives but focus on all of the following and more: Lead the development of our CTI function, establishing clear governance, processes, intelligence priorities and measurable outcomes. Represent the organisation in key external intelligence-sharing forums, including FS-ISAC, the NCSC's CiSP and relevant industry partnerships. Use the MITRE ATT&CK framework to identify and analyse attacker tactics, techniques and procedures and strengthen our detection capabilities. Develop the Proactive Threat Hunting Initiative, using intelligence and security tools to identify emerging threats, attack paths and vulnerabilities and security gaps. Oversee the collection and analysis of tactical, operational and strategic threat intelligence, with a particular focus on threats affecting insurance and financial services sectors. Proactively search for malicious activity, anomalies and emerging threats across enterprise networks, endpoints and cloud environments. Provide clear, actionable intelligence and threat landscaping briefings to senior leaders, Board committees and key stakeholders across the business. What are we looking for in our Threat Intelligence Lead? We're looking for an experienced Cyber Threat Intelligence professional who can combine their strong technical expertise with the ability to develop our CTI capability and turn complex intelligence into clear, actionable business insights. MITRE ATT&CK training/certification is essential . Experience developing Priority Intelligence Requirements (PIRs). Strong experience working closely with SOC, Incident Response, Vulnerability Management, Security Engineering and Risk. Experience managing the end-to-end intelligence lifecycle. Significant Cyber Threat Intelligence (CTI) or closely related cyber security experience. Strong experience analysing strategic, operational, and tactical threat intelligence. Practical experience with MITRE ATT&CK, threat actor profiling, IOC analysis, threat hunting and intelligence-led detection engineering. Evidence of leading/developing a CTI capability. Relevant professional certification such as GCTI, CRTIA, CPTIA, GIAC, or CISSP is desirable. In return you will be welcomed and supported by our Ardonagh family joining an organisation that cares about you as a person and your wellbeing. Some of the other benefits are: Holiday entitlement of 26 days plus bank holidays, increasing with length of service 35 hour working week Opportunity to progress your career across the entire Ardonagh family Award-winning learning & development offering and support to obtain professional qualifications to enhance your knowledge and career prospects Pension scheme for when you feel it's time to retire 24-hour Employee Assistance support for you and your family's physical and mental wellbeing Corporate perks such as discounted gym memberships, cinema tickets, shopping, Eyecare vouchers, cycle to work and much more One day paid volunteering to give back to our communities Ardonagh Community Trust (ACT) - raising funds for charity with donation matching in your local community The Spotlight Awards, where we celebrate the best of the Ardonagh Group and all the bright talent across our business. We offer genuine potential for both personal and professional development, come and be part of our story and help us shape our future. So, what are you waiting for? Apply today and one of our team will be in touch. INDX3 Everywhen is an equal opportunities employer, with a growing and thriving diversity, equity and inclusion strategy; we are committed to a working environment that is free from discrimination, is inclusive, and empowers our people to bring their whole self to work and reach their full potential. If your application is successful, we will conduct relevant employment checks prior to you commencing employment with us. These will include verifying your recent employment, address, credit history and a standard criminal record check. As an Everywhen colleague, you will be expected to uphold our values, act professionally and respectfully towards others, and contribute to a workplace where everyone is treated with dignity and respect. We expect all colleagues to help maintain an environment free from bullying, harassment, victimisation and other inappropriate behaviours, supporting our commitment to an inclusive and high-performing culture. Please note: We may close a vacancy prior to the publish end date if the required quality or number of applications has been received. Note to recruiters and employment agencies: We will not pay for unsolicited CVs from recruiters and employment agencies unless we have a signed agreement and have requested assistance, in writing, for a specific opening.
Aug 20, 2026
Full time
An exciting remote-based opportunity has arisen for a Threat Intelligence Lead to join our Technology team, reporting to the Chief Information Security Officer. You will design and lead the company's cyber threat intelligence (CTI), security testing and proactive threat-hunting programmes, helping to protect our customers, assets and brands across our global operations.Working closely with our internal and external security operations teams, you will anticipate, assess and mitigate threats. The intelligence you provide will support strategic decisions, incident response and continuous improvements to our cyber resilience. This pivotal Cyber Security role requires strong technical expertise, intelligence capability and commercial awareness within a regulated financial environment. What you will do as our Threat Intelligence Lead: This is an overview and not an exhaustive list of responsibilities. Collaborating with your Line Manager, you will develop your own objectives but focus on all of the following and more: Lead the development of our CTI function, establishing clear governance, processes, intelligence priorities and measurable outcomes. Represent the organisation in key external intelligence-sharing forums, including FS-ISAC, the NCSC's CiSP and relevant industry partnerships. Use the MITRE ATT&CK framework to identify and analyse attacker tactics, techniques and procedures and strengthen our detection capabilities. Develop the Proactive Threat Hunting Initiative, using intelligence and security tools to identify emerging threats, attack paths and vulnerabilities and security gaps. Oversee the collection and analysis of tactical, operational and strategic threat intelligence, with a particular focus on threats affecting insurance and financial services sectors. Proactively search for malicious activity, anomalies and emerging threats across enterprise networks, endpoints and cloud environments. Provide clear, actionable intelligence and threat landscaping briefings to senior leaders, Board committees and key stakeholders across the business. What are we looking for in our Threat Intelligence Lead? We're looking for an experienced Cyber Threat Intelligence professional who can combine their strong technical expertise with the ability to develop our CTI capability and turn complex intelligence into clear, actionable business insights. MITRE ATT&CK training/certification is essential . Experience developing Priority Intelligence Requirements (PIRs). Strong experience working closely with SOC, Incident Response, Vulnerability Management, Security Engineering and Risk. Experience managing the end-to-end intelligence lifecycle. Significant Cyber Threat Intelligence (CTI) or closely related cyber security experience. Strong experience analysing strategic, operational, and tactical threat intelligence. Practical experience with MITRE ATT&CK, threat actor profiling, IOC analysis, threat hunting and intelligence-led detection engineering. Evidence of leading/developing a CTI capability. Relevant professional certification such as GCTI, CRTIA, CPTIA, GIAC, or CISSP is desirable. In return you will be welcomed and supported by our Ardonagh family joining an organisation that cares about you as a person and your wellbeing. Some of the other benefits are: Holiday entitlement of 26 days plus bank holidays, increasing with length of service 35 hour working week Opportunity to progress your career across the entire Ardonagh family Award-winning learning & development offering and support to obtain professional qualifications to enhance your knowledge and career prospects Pension scheme for when you feel it's time to retire 24-hour Employee Assistance support for you and your family's physical and mental wellbeing Corporate perks such as discounted gym memberships, cinema tickets, shopping, Eyecare vouchers, cycle to work and much more One day paid volunteering to give back to our communities Ardonagh Community Trust (ACT) - raising funds for charity with donation matching in your local community The Spotlight Awards, where we celebrate the best of the Ardonagh Group and all the bright talent across our business. We offer genuine potential for both personal and professional development, come and be part of our story and help us shape our future. So, what are you waiting for? Apply today and one of our team will be in touch. INDX3 Everywhen is an equal opportunities employer, with a growing and thriving diversity, equity and inclusion strategy; we are committed to a working environment that is free from discrimination, is inclusive, and empowers our people to bring their whole self to work and reach their full potential. If your application is successful, we will conduct relevant employment checks prior to you commencing employment with us. These will include verifying your recent employment, address, credit history and a standard criminal record check. As an Everywhen colleague, you will be expected to uphold our values, act professionally and respectfully towards others, and contribute to a workplace where everyone is treated with dignity and respect. We expect all colleagues to help maintain an environment free from bullying, harassment, victimisation and other inappropriate behaviours, supporting our commitment to an inclusive and high-performing culture. Please note: We may close a vacancy prior to the publish end date if the required quality or number of applications has been received. Note to recruiters and employment agencies: We will not pay for unsolicited CVs from recruiters and employment agencies unless we have a signed agreement and have requested assistance, in writing, for a specific opening.
Cambridge University Press & Assessment
Security Assurance Lead
Cambridge University Press & Assessment Cambridge, Cambridgeshire
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role. We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working. This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment. Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement. Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure. Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery. Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported. Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST. Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders. Support incident preparedness, including investigations and exercises that test our ability to respond effectively. Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation. This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition. About You We are looking for someone with extensive knowledge of 5+ year experience in security testing and assurance and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks and (e.g. ISO 27001, NIST) and risk management practices. You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing. You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management. You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously. If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria: Development and maintained a supply chain risk register within a similar sized organisation Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure Experience of reporting risks to senior leadership For a detailed job description, please refer to the link at the bottom of the advert on our careers site. We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition. Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for. Rewards and benefits We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including: 28 days annual leave plus bank holidays Private medical and Permanent Health Insurance Discretionary annual bonus Group personal pension scheme Life assurance up to 4 x annual salary Green travel schemes Ready to pursue your potential? Apply now. We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2 nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after. The application and interview process consists of: 3 role related questions with brief answers A 15-minute screening call with the Hiring Manager. First stage virtual interview via MS Teams. Final stage interview: in-person at our offices in Cambridge. If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs. Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry. We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter. Why join us Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe - for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration. Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
Aug 18, 2026
Full time
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role. We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working. This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment. Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement. Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure. Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery. Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported. Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST. Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders. Support incident preparedness, including investigations and exercises that test our ability to respond effectively. Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation. This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition. About You We are looking for someone with extensive knowledge of 5+ year experience in security testing and assurance and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks and (e.g. ISO 27001, NIST) and risk management practices. You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing. You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management. You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously. If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria: Development and maintained a supply chain risk register within a similar sized organisation Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure Experience of reporting risks to senior leadership For a detailed job description, please refer to the link at the bottom of the advert on our careers site. We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition. Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for. Rewards and benefits We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including: 28 days annual leave plus bank holidays Private medical and Permanent Health Insurance Discretionary annual bonus Group personal pension scheme Life assurance up to 4 x annual salary Green travel schemes Ready to pursue your potential? Apply now. We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2 nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after. The application and interview process consists of: 3 role related questions with brief answers A 15-minute screening call with the Hiring Manager. First stage virtual interview via MS Teams. Final stage interview: in-person at our offices in Cambridge. If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs. Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry. We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter. Why join us Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe - for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration. Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
UK Biobank
Director of Information Security
UK Biobank Cheadle, Staffordshire
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
Aug 17, 2026
Full time
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
IS Platform and Security Supervisor
Harbour Energy
Since its creation in 2014, Harbour has grown to become one of the world's largest and most geographically diverse independent oil and gas companies. Today, Harbour is producing between 475,000 and 485,000 barrels of oil equivalent per day with significant production in Norway, the UK, Germany, Argentina and North Africa. Harbour benefits from competitive operating costs and resilient margins, and a broad set of growth options including near-infrastructure opportunities in Norway, unconventional scalable opportunities in Argentina and conventional offshore projects in Mexico and Indonesia. With low GHG emissions intensity and a leading CO2 storage position in Europe, Harbour remains committed to producing oil and gas safely and responsibly to help meet the world's energy needs. Harbour is headquartered in London with approximately 5,000 staff and contractors across its operations and offices. Ours is an inclusive workplace where individuals can bring their whole selves to their job and feel recognised for the value they add. We are committed to creating a genuinely inclusive and supportive working environment to ensure everyone has a positive experience at work. At Harbour Energy, we aim to recruit, retain and promote our people based on their unique skills, regardless of race, gender or background. We need excellent people to help shape and develop the future of our company. Could this be you? Purpose of Role The IS Platform and Security Supervisor ensures all environments are secure, compliant, resilient, and aligned with global IS/OT standards, while meeting business and operational requirements. The role oversees the IS platforms, the operational security, Operational Technology, and communications landscape within the Mexico BU. Acts as a point of coordination for BU IS/OT platforms and security working in line with corporate teams. Drive continuous improvement, cost optimisation, and service reliability across IT/OT platforms and communications. Critical Responsibilities (MAE/MATTE/HSES ) Ensure that all activities are carried out in a safe manner complying with all regulatory requirements, legislation and Harbour Energy HSES Procedures. Ethics and Compliance Responsibilities Ensure that all activities and behaviours are carried out in accordance with Harbour Energy's Ethics and Compliance Policies and Procedures and to complete any compulsory compliance training as required. Areas of Accountability, Responsibility and Competence Oversee and manage local infrastructure and cloud services, ensuring full compliance with global IS governance and security standards with focus on availability and performance. Lead local cyber security activities in close collaboration with Global IS Security teams ensuring hands on support and situational awareness during cyber security incidents. Maintain situational awareness and hands on response during incidents. Drive vulnerability management, patching, monitoring, and risk reduction across all supported platforms. Oversee OT systems supporting drilling, offshore, and real time operations ensuring secure integration between IT and OT environments and apply and enforce Global OT cyber security standards. Management of local IT and telecommunications networks including offshore operations. Manage and provide IT systems and facility services to the Mexico BU office including, but not limited to, access control and CCTV. Management of local suppliers to ensure high-quality and compliant service delivery. Support and manage local telecommunications management (internet lines, mobile phone contracts etc). Implementation and execution of local backup and DR concepts. Provide guidance and oversight to ensure technical solutions and procedures remain fit for purpose, secure, and up to date. Participate in audits and verifications of partners and contractors. Provide technical support to tenders and contracts as required. Participate in relevant projects related to IT/OT infrastructure and applications. Manage smaller projects and initiatives. Ensure IS infrastructure and security services are stable, resilient, and consistently meet or exceed agreed service levels. Vendors, partners, and internal teams are aligned, with clear accountability and proactive issue resolution. Processes, tools, and solutions are regularly reviewed and enhanced to drive efficiency, security, and business value. May be required for on call support. Technical Skills IS Security (security operations, security architecture, asset security, communications and network security monitoring.). Private and Public Cloud management, security, and monitoring (AWS, Azure, Google Cloud Platform etc.). Identity & Access Management (Active Directory, LDAP, SSO, MFA). Threat & vulnerability management (risk assessment, penetration testing, malware analysis etc.). Security standards such as ISO 27001, NIST, CIS Controls, SOC 2. Knowledge of OT Environments/Real-time data sources/drilling and rig operations. Commercial awareness, including budget tracking and cost control. Non-Technical Skills Communication skills for reporting of security incidents and providing guidance. Strong stakeholder management skills across business and technical audiences. Professional Experience Experience in prioritising workload, managing demand and delivering against agreed plans. Education Bachelor's degree in relevant field. Language Harbour Principles and Values Strong alignment with Harbour Energy's core values, behaviours, and commitment to operational excellence and integrity. Inclusive recruitment is a vital part of our diversity, equity and inclusion strategy. Whatever your background, if you feel you need an adjustment during our selection process to suit your needs, please let us know, and we will be happy to help.
Aug 15, 2026
Full time
Since its creation in 2014, Harbour has grown to become one of the world's largest and most geographically diverse independent oil and gas companies. Today, Harbour is producing between 475,000 and 485,000 barrels of oil equivalent per day with significant production in Norway, the UK, Germany, Argentina and North Africa. Harbour benefits from competitive operating costs and resilient margins, and a broad set of growth options including near-infrastructure opportunities in Norway, unconventional scalable opportunities in Argentina and conventional offshore projects in Mexico and Indonesia. With low GHG emissions intensity and a leading CO2 storage position in Europe, Harbour remains committed to producing oil and gas safely and responsibly to help meet the world's energy needs. Harbour is headquartered in London with approximately 5,000 staff and contractors across its operations and offices. Ours is an inclusive workplace where individuals can bring their whole selves to their job and feel recognised for the value they add. We are committed to creating a genuinely inclusive and supportive working environment to ensure everyone has a positive experience at work. At Harbour Energy, we aim to recruit, retain and promote our people based on their unique skills, regardless of race, gender or background. We need excellent people to help shape and develop the future of our company. Could this be you? Purpose of Role The IS Platform and Security Supervisor ensures all environments are secure, compliant, resilient, and aligned with global IS/OT standards, while meeting business and operational requirements. The role oversees the IS platforms, the operational security, Operational Technology, and communications landscape within the Mexico BU. Acts as a point of coordination for BU IS/OT platforms and security working in line with corporate teams. Drive continuous improvement, cost optimisation, and service reliability across IT/OT platforms and communications. Critical Responsibilities (MAE/MATTE/HSES ) Ensure that all activities are carried out in a safe manner complying with all regulatory requirements, legislation and Harbour Energy HSES Procedures. Ethics and Compliance Responsibilities Ensure that all activities and behaviours are carried out in accordance with Harbour Energy's Ethics and Compliance Policies and Procedures and to complete any compulsory compliance training as required. Areas of Accountability, Responsibility and Competence Oversee and manage local infrastructure and cloud services, ensuring full compliance with global IS governance and security standards with focus on availability and performance. Lead local cyber security activities in close collaboration with Global IS Security teams ensuring hands on support and situational awareness during cyber security incidents. Maintain situational awareness and hands on response during incidents. Drive vulnerability management, patching, monitoring, and risk reduction across all supported platforms. Oversee OT systems supporting drilling, offshore, and real time operations ensuring secure integration between IT and OT environments and apply and enforce Global OT cyber security standards. Management of local IT and telecommunications networks including offshore operations. Manage and provide IT systems and facility services to the Mexico BU office including, but not limited to, access control and CCTV. Management of local suppliers to ensure high-quality and compliant service delivery. Support and manage local telecommunications management (internet lines, mobile phone contracts etc). Implementation and execution of local backup and DR concepts. Provide guidance and oversight to ensure technical solutions and procedures remain fit for purpose, secure, and up to date. Participate in audits and verifications of partners and contractors. Provide technical support to tenders and contracts as required. Participate in relevant projects related to IT/OT infrastructure and applications. Manage smaller projects and initiatives. Ensure IS infrastructure and security services are stable, resilient, and consistently meet or exceed agreed service levels. Vendors, partners, and internal teams are aligned, with clear accountability and proactive issue resolution. Processes, tools, and solutions are regularly reviewed and enhanced to drive efficiency, security, and business value. May be required for on call support. Technical Skills IS Security (security operations, security architecture, asset security, communications and network security monitoring.). Private and Public Cloud management, security, and monitoring (AWS, Azure, Google Cloud Platform etc.). Identity & Access Management (Active Directory, LDAP, SSO, MFA). Threat & vulnerability management (risk assessment, penetration testing, malware analysis etc.). Security standards such as ISO 27001, NIST, CIS Controls, SOC 2. Knowledge of OT Environments/Real-time data sources/drilling and rig operations. Commercial awareness, including budget tracking and cost control. Non-Technical Skills Communication skills for reporting of security incidents and providing guidance. Strong stakeholder management skills across business and technical audiences. Professional Experience Experience in prioritising workload, managing demand and delivering against agreed plans. Education Bachelor's degree in relevant field. Language Harbour Principles and Values Strong alignment with Harbour Energy's core values, behaviours, and commitment to operational excellence and integrity. Inclusive recruitment is a vital part of our diversity, equity and inclusion strategy. Whatever your background, if you feel you need an adjustment during our selection process to suit your needs, please let us know, and we will be happy to help.
Saab UK
Cyber Security Manager
Saab UK Fareham, Hampshire
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Aug 11, 2026
Full time
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Reed Technology
Senior SOC Engineer
Reed Technology Basingstoke, Hampshire
Senior SOC Engineer - Hybrid Join a leading cyber security services organisation as a Senior SOC Engineer , taking ownership of the technology, automation, and engineering capabilities that support a modern Security Operations Centre (SOC). The Role You'll design, deploy, and enhance core SOC platforms including SIEM, XDR, SOAR, automation, and security tooling , driving improvements in threat detection, response, and operational efficiency. Working closely with operational teams, you'll support customer onboarding, develop automated workflows, and help shape the future direction of SOC engineering. Key Responsibilities Design, deploy and optimise SIEM, XDR and SOAR platforms. Build security automation, integrations, and response workflows. Develop log parsing, data normalisation and telemetry solutions. Lead technical onboarding and implementation projects. Act as an escalation point for complex security engineering issues. Mentor SOC analysts and engineers. Improve detection, response and operational processes through automation. Maintain engineering documentation, standards and best practices. Skills & Experience 3-5+ years' experience within a SOC or cyber security engineering environment. Strong experience with SIEM, SOAR and EDR/XDR technologies. Scripting and automation expertise (Python, Go, APIs). Experience with cloud platforms such as Azure, AWS or GCP. Knowledge of vulnerability management and threat intelligence integrations. Strong communication, analytical and problem-solving skills. Eligibility for UK security clearance desirable. What's on Offer 2 Days in the Office Per Month Exposure to a wide range of security environments and technologies. Opportunity to influence SOC strategy and engineering direction. Dedicated training, development, and lab environments. Competitive salary and comprehensive benefits package. Ideal for an experienced SOC Engineer looking to step into a senior, technically focused role with significant ownership, automation responsibilities, and career progression opportunities.
Jul 31, 2026
Full time
Senior SOC Engineer - Hybrid Join a leading cyber security services organisation as a Senior SOC Engineer , taking ownership of the technology, automation, and engineering capabilities that support a modern Security Operations Centre (SOC). The Role You'll design, deploy, and enhance core SOC platforms including SIEM, XDR, SOAR, automation, and security tooling , driving improvements in threat detection, response, and operational efficiency. Working closely with operational teams, you'll support customer onboarding, develop automated workflows, and help shape the future direction of SOC engineering. Key Responsibilities Design, deploy and optimise SIEM, XDR and SOAR platforms. Build security automation, integrations, and response workflows. Develop log parsing, data normalisation and telemetry solutions. Lead technical onboarding and implementation projects. Act as an escalation point for complex security engineering issues. Mentor SOC analysts and engineers. Improve detection, response and operational processes through automation. Maintain engineering documentation, standards and best practices. Skills & Experience 3-5+ years' experience within a SOC or cyber security engineering environment. Strong experience with SIEM, SOAR and EDR/XDR technologies. Scripting and automation expertise (Python, Go, APIs). Experience with cloud platforms such as Azure, AWS or GCP. Knowledge of vulnerability management and threat intelligence integrations. Strong communication, analytical and problem-solving skills. Eligibility for UK security clearance desirable. What's on Offer 2 Days in the Office Per Month Exposure to a wide range of security environments and technologies. Opportunity to influence SOC strategy and engineering direction. Dedicated training, development, and lab environments. Competitive salary and comprehensive benefits package. Ideal for an experienced SOC Engineer looking to step into a senior, technically focused role with significant ownership, automation responsibilities, and career progression opportunities.
Prime Personnel UK
Senior IT Security Analyst
Prime Personnel UK
Senior IT Security Analyst required to act as a senior technical contributor within a global cyber security team, owning selected cyber security domains end-to-end and driving practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions based on real-world attacker behaviour, and deliver measurable improvements to the organisation cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365 / Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve endpoint security controls. Used Zscaler ZIA/ZPA or equivalent secure web gateway, private access, zero trust or network access security technologies. Performed vulnerability assessment, exposure analysis or remediation prioritisation across enterprise technology environments. Applied threat intelligence, MITRE ATT&CK or exploitation-based evidence to prioritise mitigations. Supported or led cyber security investigations and incident response activities. Collaborated with infrastructure, cloud, application, identity and business teams to deliver security improvements. Used scripting, queries, automation or data analysis to improve security outcomes. Strong hands-on experience administering, tuning and operationalising CrowdStrike Falcon , including endpoint protection, EDR investigations, detection analysis and response workflows. Strong hands-on experience administering and supporting Zscaler ZIA and ZPA , including policy design, access control, traffic analysis and security troubleshooting. Practical experience leading or supporting vulnerability and exposure management programmes , including vulnerability analysis, risk-based prioritisation, remediation tracking and validation of control effectiveness. Strong knowledge of real-world attacker tactics, techniques and procedures (TTPs) and the ability to translate threat intelligence, attack paths and exploitation trends into actionable security improvements. Experience conducting security investigations and incident response activities, including alert triage, root cause analysis, containment, remediation and lessons learned. This is a hybrid role working 3 days a week in the London office and 2 days remotely.
Jul 31, 2026
Full time
Senior IT Security Analyst required to act as a senior technical contributor within a global cyber security team, owning selected cyber security domains end-to-end and driving practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions based on real-world attacker behaviour, and deliver measurable improvements to the organisation cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365 / Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve endpoint security controls. Used Zscaler ZIA/ZPA or equivalent secure web gateway, private access, zero trust or network access security technologies. Performed vulnerability assessment, exposure analysis or remediation prioritisation across enterprise technology environments. Applied threat intelligence, MITRE ATT&CK or exploitation-based evidence to prioritise mitigations. Supported or led cyber security investigations and incident response activities. Collaborated with infrastructure, cloud, application, identity and business teams to deliver security improvements. Used scripting, queries, automation or data analysis to improve security outcomes. Strong hands-on experience administering, tuning and operationalising CrowdStrike Falcon , including endpoint protection, EDR investigations, detection analysis and response workflows. Strong hands-on experience administering and supporting Zscaler ZIA and ZPA , including policy design, access control, traffic analysis and security troubleshooting. Practical experience leading or supporting vulnerability and exposure management programmes , including vulnerability analysis, risk-based prioritisation, remediation tracking and validation of control effectiveness. Strong knowledge of real-world attacker tactics, techniques and procedures (TTPs) and the ability to translate threat intelligence, attack paths and exploitation trends into actionable security improvements. Experience conducting security investigations and incident response activities, including alert triage, root cause analysis, containment, remediation and lessons learned. This is a hybrid role working 3 days a week in the London office and 2 days remotely.
Salt
Senior Application Security Consultant (SAST/DAST/OWASP )
Salt
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London Secure SDLC SAST DAST Threat Modelling Cloud Security CI/CD Location: London (Hybrid - 8 days onsite per month) Contract: 12 Months + extension Rate: 500- 550 per day (Umbrella) The Opportunity We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment. Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely. This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment. Key Responsibilities Lead application security reviews across business-critical applications and cloud platforms. Conduct security architecture and secure design reviews. Perform application security risk assessments and define security requirements. Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies. Embed Secure SDLC principles into engineering teams. Integrate security tooling into CI/CD pipelines and DevSecOps processes. Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings. Work closely with development teams to prioritise vulnerability remediation. Define security testing requirements and support penetration testing activities. Produce security standards, technical guidance and best practice documentation. Act as the Application Security SME across multiple technology programmes. Essential Skills Application Security Secure Software Development Lifecycle (SSDLC) OWASP Top 10 Secure Coding Secure Design Reviews API Security REST APIs Microservices Security Application Security Risk Assessments Threat Modelling STRIDE MITRE ATT&CK Security Architecture Risk Assessments DevSecOps CI/CD Security GitHub Actions GitLab Jenkins Azure DevOps Security Automation Shift Left Security Security Testing SAST DAST SCA Vulnerability Management Penetration Testing Cloud Security AWS, Azure or GCP Kubernetes Docker Container Security Cloud Security Best Practices Security Tooling Experience with one or more of: Checkmarx Fortify SonarQube Veracode Semgrep Burp Suite OWASP ZAP Snyk Trivy Prisma Cloud Aqua Wiz Ideal Background You'll ideally have: 8+ years in Cyber Security Strong Application Security or DevSecOps experience Experience working directly with software engineering teams Experience embedding security into CI/CD pipelines Strong knowledge of Secure SDLC Experience conducting Threat Modelling sessions Excellent stakeholder management and communication skills Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment Contract Details 12-month contract 500- 600 per day (Umbrella) Hybrid working - 8 days onsite per month in London Immediate interview availability preferred Rates depend on experience and client requirements
Jul 31, 2026
Contractor
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London Secure SDLC SAST DAST Threat Modelling Cloud Security CI/CD Location: London (Hybrid - 8 days onsite per month) Contract: 12 Months + extension Rate: 500- 550 per day (Umbrella) The Opportunity We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment. Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely. This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment. Key Responsibilities Lead application security reviews across business-critical applications and cloud platforms. Conduct security architecture and secure design reviews. Perform application security risk assessments and define security requirements. Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies. Embed Secure SDLC principles into engineering teams. Integrate security tooling into CI/CD pipelines and DevSecOps processes. Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings. Work closely with development teams to prioritise vulnerability remediation. Define security testing requirements and support penetration testing activities. Produce security standards, technical guidance and best practice documentation. Act as the Application Security SME across multiple technology programmes. Essential Skills Application Security Secure Software Development Lifecycle (SSDLC) OWASP Top 10 Secure Coding Secure Design Reviews API Security REST APIs Microservices Security Application Security Risk Assessments Threat Modelling STRIDE MITRE ATT&CK Security Architecture Risk Assessments DevSecOps CI/CD Security GitHub Actions GitLab Jenkins Azure DevOps Security Automation Shift Left Security Security Testing SAST DAST SCA Vulnerability Management Penetration Testing Cloud Security AWS, Azure or GCP Kubernetes Docker Container Security Cloud Security Best Practices Security Tooling Experience with one or more of: Checkmarx Fortify SonarQube Veracode Semgrep Burp Suite OWASP ZAP Snyk Trivy Prisma Cloud Aqua Wiz Ideal Background You'll ideally have: 8+ years in Cyber Security Strong Application Security or DevSecOps experience Experience working directly with software engineering teams Experience embedding security into CI/CD pipelines Strong knowledge of Secure SDLC Experience conducting Threat Modelling sessions Excellent stakeholder management and communication skills Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment Contract Details 12-month contract 500- 600 per day (Umbrella) Hybrid working - 8 days onsite per month in London Immediate interview availability preferred Rates depend on experience and client requirements
Vice President, Risk and Control - Digital Engineering
MUFG Bank, Ltd
Vice President, Risk and Control - Digital EngineeringApplylocations: Londontime type: Full timeposted on: Posted Todayjob requisition id: -WD Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.Join MUFG, where being inspired is expected and making a meaningful impact is rewarded. Accountable for defining, creating and governing the Digital Engineering Risk and Control strategy in accordance with the wider EMEA Technology IT Risk and Control vision and strategy and risk appetite Accountable for defining the Digital Engineering Solutions and Services risk appetite and framework in accordance with the overall Technology departments risk appetite and tolerance framework, managing the departments operational, regulatory and financial risk Define and evolve the Digital Engineering Services and Solutions Key Risk Indicators' and Controls and govern accordingly Present the department's risk landscape, providing proactive oversight and prioritisation to ensure timely closure of issue Run the departments Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of Digital Engineering Services and Solutions and the Extended Leadership Team Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress Primary contact for all risk, control and audit issues across all Digital Engineering Solutions and Services teams Provide assurance over the department's controls design and effectiveness, ensuring controls are proportionate and embedded in day to day department activity Provide proactive assurance around risk management through appropriate data driven monitoring and through the implementation of structured sampling techniques to validate that controls are functioning as intended before failure Educate and lead the Digital Engineering Staff defining best practice operations and governance in line with industry and company standards Work in partnership with the Digital Engineering Solutions and Services Product and Platform owners, challenging and advising on risk management for new products, processes and change programmes. Provide risk-based decision making, supporting the department to make informed, risk-based decisions by providing an aggregated view of risk exposures Run the departments Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of Digital Engineering Services and Solutions and the Extended Leadership Team Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department Responsible for managing Issue Management on behalf Digital Engineering Services and Solutions department Handle potential sensitive information relating to Cyber Security events and assessments on behalf of Digital Engineering Services and Solutions Work across all areas of the Digital Engineering Services and Solutions department to ensure the Digital Engineering Control & Governance team provides necessary support services, oversight function and governance capabilities to all other extended leadership teams and stakeholders. Responsible for building strong relationships across the Bank and Securities functions, underpinned by trust and the core values of the bank. Developing strong relationships with key stakeholders such as IT Risk & Control, Cyber Security, other technology pillars, Operational Risk, Internal Audit, Compliance and external parties where applicable A senior role, that plays a pivotal part in strengthening a proactive, inclusive risk culture leading with example of the right leadership, culture and behaviours that are required in the bank. KEY RESPONSIBILITIES Digital Engineering Solutions and Services Governance Oversee Digital Engineering Services and Solutions relationship with IT Risk and 3rd parties for all external audits and assessments. Oversee Digital Engineering Services and Solutions relationship with IT Risk for all internal audits which have an Infrastructure or Service Management aspect. Ensure strong governance, structures and processes are in place to support effective operational risk and control management across the department Accountable for managing Open Issues on behalf of the Digital Engineering Services and Solutions department, tracking and ensuring proactive remediation and timely Support Digital Engineering Solutions and Services extended leadership teams with creation/attestation of key controls against the Operational Risk Framework. Manage engagement with stakeholders to design, plan and deliver remediation actions for control deficiencies. Oversee risk identification and mitigation efforts, ensuring understanding of strategic goals Ensure departments adherence to internal policies and external regulatory requirement Manage complex risk related loss events, conducting root cause analysis, working with Product and Platform owners to develop response plans Perform applicable operational control checks across Infrastructure and engage with other areas of Technology when required Work in partnership with the departments Incident management and Threat and Vulnerability team to detect and address vulnerabilities Ensure that the team operates in a controlled manner in accordance with standards and procedures whilst adhering to all related security and compliance procedures In conjunction with IT Risk, Security and Control, ensure that all regulatory requirements are fully complied with, including SOX assessments and appropriate defences and controls are in place to deal with all cyber risks Execute risk governance across all Digital Engineering Solutions and Services verticals. Provide support to Digital Engineering Services and Solutions for pen test findings Produce and manage Digital Engineering Solutions and Services owned Key Risk Indicators. Support disaster recovery exercises, ensuring new services are documented and deployed with BCP/DR in mind Provide advisory assistance to IT Risk and Control relating to My Access Live (MaL) and Access Management processes, acting as input into review processes with particular emphasis on Digital Engineering related platforms Input into Incident Management Process where appropriate Support new applications as and when released to the business Escalate potential service issues to the Management Produce regular risk management data for Management. Chair the Departments Risk Oversight Committee Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department. Culture and Leadership Support development of team with a strong focus on building future capabilities Lead and champion MUFG's inclusive, diverse, and values-led culture while fostering a growth mindset to embrace new technologies, industry advancements, and innovative use cases Ensure appropriate risk awareness training is in place across the department to fulfil current and future requirements Lead and promote a dynamic, delivery driven culture that works alongside business units to provide responsive resolutions and value driven solutions Build and nurture strong relationships with internal and external stakeholders, including business teams, to promote collaboration, understand industry's best practices, and influence positive change across the organization Support location strategies prescribed from MUFG and enable transitions (where appropriate) seamlessly WORK EXPERIENCE Essential: Extensive experience leading and managing risk and control and teams across multiple regions within a within a regulated environment. Extensive proficiency in scenario analysis and developing mitigation strategies Experience representing risk and control on behalf of a large Technology department to an Executive level audience A strong track record of engaging credibly with Executives providing confident challenge and clear, decision ready insight. Experience of working alongside network, server, database, desktop; asset management and storage functions Experienced in dealing with vendors and third-party suppliers Strong track record of managing teams and building effective partnerships with peers Experience with comprehensive disaster recovery architecture and operations, including storage area network and redundant, highly available server and network architectures Experience with regulatory compliance issues as they apply to Infrastructure SKILLS AND EXPERIENCE Essential: Extensive experience leading a risk & control function in a financial services organisation. Extensive experience working with Risk Management tools e.g Open Pages Understanding of the COBIT, NIST 2 framework Extensive experience leading internal audit and external audit bodies. Proven track record of managing risk related issues for large departments, through the lifecycle of creation, reporting and remediation. Experience with industry-specific regulatory requirements and their impact on operational risk . click apply for full job details
Jul 30, 2026
Full time
Vice President, Risk and Control - Digital EngineeringApplylocations: Londontime type: Full timeposted on: Posted Todayjob requisition id: -WD Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.Join MUFG, where being inspired is expected and making a meaningful impact is rewarded. Accountable for defining, creating and governing the Digital Engineering Risk and Control strategy in accordance with the wider EMEA Technology IT Risk and Control vision and strategy and risk appetite Accountable for defining the Digital Engineering Solutions and Services risk appetite and framework in accordance with the overall Technology departments risk appetite and tolerance framework, managing the departments operational, regulatory and financial risk Define and evolve the Digital Engineering Services and Solutions Key Risk Indicators' and Controls and govern accordingly Present the department's risk landscape, providing proactive oversight and prioritisation to ensure timely closure of issue Run the departments Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of Digital Engineering Services and Solutions and the Extended Leadership Team Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress Primary contact for all risk, control and audit issues across all Digital Engineering Solutions and Services teams Provide assurance over the department's controls design and effectiveness, ensuring controls are proportionate and embedded in day to day department activity Provide proactive assurance around risk management through appropriate data driven monitoring and through the implementation of structured sampling techniques to validate that controls are functioning as intended before failure Educate and lead the Digital Engineering Staff defining best practice operations and governance in line with industry and company standards Work in partnership with the Digital Engineering Solutions and Services Product and Platform owners, challenging and advising on risk management for new products, processes and change programmes. Provide risk-based decision making, supporting the department to make informed, risk-based decisions by providing an aggregated view of risk exposures Run the departments Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of Digital Engineering Services and Solutions and the Extended Leadership Team Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department Responsible for managing Issue Management on behalf Digital Engineering Services and Solutions department Handle potential sensitive information relating to Cyber Security events and assessments on behalf of Digital Engineering Services and Solutions Work across all areas of the Digital Engineering Services and Solutions department to ensure the Digital Engineering Control & Governance team provides necessary support services, oversight function and governance capabilities to all other extended leadership teams and stakeholders. Responsible for building strong relationships across the Bank and Securities functions, underpinned by trust and the core values of the bank. Developing strong relationships with key stakeholders such as IT Risk & Control, Cyber Security, other technology pillars, Operational Risk, Internal Audit, Compliance and external parties where applicable A senior role, that plays a pivotal part in strengthening a proactive, inclusive risk culture leading with example of the right leadership, culture and behaviours that are required in the bank. KEY RESPONSIBILITIES Digital Engineering Solutions and Services Governance Oversee Digital Engineering Services and Solutions relationship with IT Risk and 3rd parties for all external audits and assessments. Oversee Digital Engineering Services and Solutions relationship with IT Risk for all internal audits which have an Infrastructure or Service Management aspect. Ensure strong governance, structures and processes are in place to support effective operational risk and control management across the department Accountable for managing Open Issues on behalf of the Digital Engineering Services and Solutions department, tracking and ensuring proactive remediation and timely Support Digital Engineering Solutions and Services extended leadership teams with creation/attestation of key controls against the Operational Risk Framework. Manage engagement with stakeholders to design, plan and deliver remediation actions for control deficiencies. Oversee risk identification and mitigation efforts, ensuring understanding of strategic goals Ensure departments adherence to internal policies and external regulatory requirement Manage complex risk related loss events, conducting root cause analysis, working with Product and Platform owners to develop response plans Perform applicable operational control checks across Infrastructure and engage with other areas of Technology when required Work in partnership with the departments Incident management and Threat and Vulnerability team to detect and address vulnerabilities Ensure that the team operates in a controlled manner in accordance with standards and procedures whilst adhering to all related security and compliance procedures In conjunction with IT Risk, Security and Control, ensure that all regulatory requirements are fully complied with, including SOX assessments and appropriate defences and controls are in place to deal with all cyber risks Execute risk governance across all Digital Engineering Solutions and Services verticals. Provide support to Digital Engineering Services and Solutions for pen test findings Produce and manage Digital Engineering Solutions and Services owned Key Risk Indicators. Support disaster recovery exercises, ensuring new services are documented and deployed with BCP/DR in mind Provide advisory assistance to IT Risk and Control relating to My Access Live (MaL) and Access Management processes, acting as input into review processes with particular emphasis on Digital Engineering related platforms Input into Incident Management Process where appropriate Support new applications as and when released to the business Escalate potential service issues to the Management Produce regular risk management data for Management. Chair the Departments Risk Oversight Committee Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department. Culture and Leadership Support development of team with a strong focus on building future capabilities Lead and champion MUFG's inclusive, diverse, and values-led culture while fostering a growth mindset to embrace new technologies, industry advancements, and innovative use cases Ensure appropriate risk awareness training is in place across the department to fulfil current and future requirements Lead and promote a dynamic, delivery driven culture that works alongside business units to provide responsive resolutions and value driven solutions Build and nurture strong relationships with internal and external stakeholders, including business teams, to promote collaboration, understand industry's best practices, and influence positive change across the organization Support location strategies prescribed from MUFG and enable transitions (where appropriate) seamlessly WORK EXPERIENCE Essential: Extensive experience leading and managing risk and control and teams across multiple regions within a within a regulated environment. Extensive proficiency in scenario analysis and developing mitigation strategies Experience representing risk and control on behalf of a large Technology department to an Executive level audience A strong track record of engaging credibly with Executives providing confident challenge and clear, decision ready insight. Experience of working alongside network, server, database, desktop; asset management and storage functions Experienced in dealing with vendors and third-party suppliers Strong track record of managing teams and building effective partnerships with peers Experience with comprehensive disaster recovery architecture and operations, including storage area network and redundant, highly available server and network architectures Experience with regulatory compliance issues as they apply to Infrastructure SKILLS AND EXPERIENCE Essential: Extensive experience leading a risk & control function in a financial services organisation. Extensive experience working with Risk Management tools e.g Open Pages Understanding of the COBIT, NIST 2 framework Extensive experience leading internal audit and external audit bodies. Proven track record of managing risk related issues for large departments, through the lifecycle of creation, reporting and remediation. Experience with industry-specific regulatory requirements and their impact on operational risk . click apply for full job details
Senior Cybersecurity Consultant
Ultramink Technologies
Lead security engagements for mid-market enterprises across Europe. You will conduct security assessments, design security architectures, and help clients build security programs that meet regulatory requirements without creating operational friction. Responsibilities Lead penetration testing and vulnerability assessment engagements Design security architectures for cloud-native and hybrid environments Develop security compliance programs (SOC 2, ISO 27001, GDPR) Conduct incident response planning and tabletop exercises Advise C-level executives on security strategy and risk management Requirements 8+ years in information security with consulting experience Deep expertise in penetration testing, vulnerability management, and threat modeling Knowledge of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI-DSS Experience with cloud security (AWS Security Hub, Azure Defender, or GCP Security Command Center) CISSP, OSCP, or equivalent certification Nice to Have Experience in financial services or healthcare security Red team or blue team experience in enterprise environments Familiarity with UK and EU regulatory requirements Competitive salary with annual performance bonuses Comprehensive health, dental, and vision insurance Company pension scheme with employer contribution Remote-first with optional office presence Annual learning budget for conferences, courses, and certifications Home office setup stipend Parental leave (16 weeks primary, 8 weeks secondary)
Jul 30, 2026
Full time
Lead security engagements for mid-market enterprises across Europe. You will conduct security assessments, design security architectures, and help clients build security programs that meet regulatory requirements without creating operational friction. Responsibilities Lead penetration testing and vulnerability assessment engagements Design security architectures for cloud-native and hybrid environments Develop security compliance programs (SOC 2, ISO 27001, GDPR) Conduct incident response planning and tabletop exercises Advise C-level executives on security strategy and risk management Requirements 8+ years in information security with consulting experience Deep expertise in penetration testing, vulnerability management, and threat modeling Knowledge of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI-DSS Experience with cloud security (AWS Security Hub, Azure Defender, or GCP Security Command Center) CISSP, OSCP, or equivalent certification Nice to Have Experience in financial services or healthcare security Red team or blue team experience in enterprise environments Familiarity with UK and EU regulatory requirements Competitive salary with annual performance bonuses Comprehensive health, dental, and vision insurance Company pension scheme with employer contribution Remote-first with optional office presence Annual learning budget for conferences, courses, and certifications Home office setup stipend Parental leave (16 weeks primary, 8 weeks secondary)
Hays Technology
Cyber Security Manager
Hays Technology City, Birmingham
650 - 750 per day (Inside IR35) Hybrid - 2-3 days on-site6-month initial contract (likely extension)Location: Birmingham (You must be able to travel to Birmingham for on-site work 2-3 days) We're working with a government client seeking an experienced Cybersecurity Manager to lead and mature their operational security capability across a modern hybrid estate.This is a hands-on leadership role where you'll combine technical depth with stakeholder engagement, driving security operations, incident response, and continuous improvement across infrastructure, cloud, and workplace environments. The Role You'll take ownership of cybersecurity operations, leading a small engineering team and working closely with an outsourced SOC/MSSP to ensure robust monitoring, response, and continuous improvement. Responsibilities Leading technical incident response (containment, eradication, recovery) and post-incident analysis Owning and improving security controls across endpoints, identity, networks, and cloud platforms Driving vulnerability management, patching, and remediation to agreed SLAs Managing SOC performance, alert triage, escalation, and threat intelligence integration Enforcing Identity & Access Management (IAM) policies, including conditional access and privileged access controls Leading disaster recovery planning and cyber incident readiness exercises Overseeing penetration testing and ensuring timely remediation of findings Providing audit and compliance evidence (e.g., ISO 27001, PCI DSS, CE+) Essential experience: Strong background in cybersecurity operations within complex environments Proven experience leading incident response and remediation activity Expertise in Microsoft 365 / Azure security and hybrid cloud environments Experience operating security tooling (EDR, SIEM, firewalls, identity platforms) at scale Solid understanding of frameworks such as ISO 27001, NCSC guidance, NIST CSF, MITRE ATT&CK Experience managing suppliers, SOC providers, and technical teams Desirable: Relevant certifications (e.g. CISSP, CISM, AZ-500, SC-200) Cyber Secu ty Manager PDF Experience working in Agile / DevOps environments Previous exposure to regulated or public sector environments What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now. If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
May 29, 2026
Contractor
650 - 750 per day (Inside IR35) Hybrid - 2-3 days on-site6-month initial contract (likely extension)Location: Birmingham (You must be able to travel to Birmingham for on-site work 2-3 days) We're working with a government client seeking an experienced Cybersecurity Manager to lead and mature their operational security capability across a modern hybrid estate.This is a hands-on leadership role where you'll combine technical depth with stakeholder engagement, driving security operations, incident response, and continuous improvement across infrastructure, cloud, and workplace environments. The Role You'll take ownership of cybersecurity operations, leading a small engineering team and working closely with an outsourced SOC/MSSP to ensure robust monitoring, response, and continuous improvement. Responsibilities Leading technical incident response (containment, eradication, recovery) and post-incident analysis Owning and improving security controls across endpoints, identity, networks, and cloud platforms Driving vulnerability management, patching, and remediation to agreed SLAs Managing SOC performance, alert triage, escalation, and threat intelligence integration Enforcing Identity & Access Management (IAM) policies, including conditional access and privileged access controls Leading disaster recovery planning and cyber incident readiness exercises Overseeing penetration testing and ensuring timely remediation of findings Providing audit and compliance evidence (e.g., ISO 27001, PCI DSS, CE+) Essential experience: Strong background in cybersecurity operations within complex environments Proven experience leading incident response and remediation activity Expertise in Microsoft 365 / Azure security and hybrid cloud environments Experience operating security tooling (EDR, SIEM, firewalls, identity platforms) at scale Solid understanding of frameworks such as ISO 27001, NCSC guidance, NIST CSF, MITRE ATT&CK Experience managing suppliers, SOC providers, and technical teams Desirable: Relevant certifications (e.g. CISSP, CISM, AZ-500, SC-200) Cyber Secu ty Manager PDF Experience working in Agile / DevOps environments Previous exposure to regulated or public sector environments What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now. If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Morgan McKinley
Senior Cyber Security & Network Analyst
Morgan McKinley Epsom, Surrey
Senior Cyber Security & Network Analyst The Opportunity in a Nutshell On behalf of our client, a leader in their industry , we are seeking a senior, hands-on technology professional with a deep foundation in Network Engineering (minimum 5-7 years of experience) coupled with strong Cyber Security expertise. This is not a purely monitoring role; the client requires an engineer who can lead from the front, physically and logically build infrastructure, and own complex technical projects from inception to completion. You will ensure the client's digital ecosystem remains resilient, highly performant, and securely aligned with evolving business objectives. Core Responsibilities As a senior technical anchor within the operations team, your daily focus will heavily lean into robust network engineering, system build-outs, and defensive security protocols: Infrastructure Installations & Kit Builds: Act as the technical lead for configuring, assembling, installing, and deploying new network and security hardware. Ensure all engineering documentation is immaculately maintained. Network Architecture Ownership: Maintain, optimize, and scale the client's Layer 2/3 environment, specifically managing Cisco Nexus routing, LAN/WAN frameworks, wireless networks, B2B links, and network load balancing solutions. Project Leadership: Spearhead mid-to-large scale infrastructure initiatives, ensuring deliverables are hit on time and within budget. You will be expected to demonstrate the tangible business value your technical decisions bring to the overall deployment process. Infrastructure Defense & Monitoring: Oversee next-generation Palo Alto firewalls, intrusion prevention systems, and data encryption protocols. Monitor SIEM platforms and threat feeds to isolate, investigate, and remediate digital vulnerabilities. Collaboration & Mentorship: Partner closely with internal technical squads and coordinate with external vendor partners. Provide coaching and technical advice to team members to foster a culture of continuous improvement. What The Client Is Looking For To thrive in this fast-paced environment, candidates must possess a blend of seasoned engineering experience and a structured, methodical approach to problem-solving. Technical Competencies: Minimum of 5-7 years of dedicated experience implementing, supporting, and developing complex L2/3 network architectures. Proven track record of leading and performing new network installations and physical/logical kit builds. Deep technical proficiency configuring and supporting L2/3 Cisco Nexus switching frameworks and Aruba Wi-Fi environments. Solid understanding of Network Load Balancing mechanisms and coordinating third-party Penetration Testing. Strong secondary expertise in Cyber Security, specifically administering Palo Alto Firewalls alongside their advanced next-gen service suites. Background utilizing Qualys Vulnerability Management tools and endpoint detection/remediation software. Previous experience navigating SOX compliance frameworks and handling fast-paced data environments is highly desirable. Application Requirement: Project Examples Our client values real-world execution. As part of your application, please be prepared to provide specific examples of projects where you led from the front on network or security kit deployments. We will look for details on:The scope of the hardware/software deployment you personally executed.The specific technical challenges you overcame during the installation or build phase.The tangible value and security/performance improvements your role brought to that process. Growth, Support & Culture Our client believes in empowering their people to reach their full potential. Joining this team means benefiting from: Structured Progression: Clear objective setting, tailored 1:1 mentorship sessions, and consistent coaching to elevate your architectural capabilities. Empowerment & Autonomy: An inclusive culture that grants ownership of meaningful outcomes and encourages exploration of development opportunities outside your immediate remit. A Collaborative Space: A supportive management philosophy designed to give employees the resources they need to excel while allowing them to bring their authentic selves to work every day.
May 25, 2026
Full time
Senior Cyber Security & Network Analyst The Opportunity in a Nutshell On behalf of our client, a leader in their industry , we are seeking a senior, hands-on technology professional with a deep foundation in Network Engineering (minimum 5-7 years of experience) coupled with strong Cyber Security expertise. This is not a purely monitoring role; the client requires an engineer who can lead from the front, physically and logically build infrastructure, and own complex technical projects from inception to completion. You will ensure the client's digital ecosystem remains resilient, highly performant, and securely aligned with evolving business objectives. Core Responsibilities As a senior technical anchor within the operations team, your daily focus will heavily lean into robust network engineering, system build-outs, and defensive security protocols: Infrastructure Installations & Kit Builds: Act as the technical lead for configuring, assembling, installing, and deploying new network and security hardware. Ensure all engineering documentation is immaculately maintained. Network Architecture Ownership: Maintain, optimize, and scale the client's Layer 2/3 environment, specifically managing Cisco Nexus routing, LAN/WAN frameworks, wireless networks, B2B links, and network load balancing solutions. Project Leadership: Spearhead mid-to-large scale infrastructure initiatives, ensuring deliverables are hit on time and within budget. You will be expected to demonstrate the tangible business value your technical decisions bring to the overall deployment process. Infrastructure Defense & Monitoring: Oversee next-generation Palo Alto firewalls, intrusion prevention systems, and data encryption protocols. Monitor SIEM platforms and threat feeds to isolate, investigate, and remediate digital vulnerabilities. Collaboration & Mentorship: Partner closely with internal technical squads and coordinate with external vendor partners. Provide coaching and technical advice to team members to foster a culture of continuous improvement. What The Client Is Looking For To thrive in this fast-paced environment, candidates must possess a blend of seasoned engineering experience and a structured, methodical approach to problem-solving. Technical Competencies: Minimum of 5-7 years of dedicated experience implementing, supporting, and developing complex L2/3 network architectures. Proven track record of leading and performing new network installations and physical/logical kit builds. Deep technical proficiency configuring and supporting L2/3 Cisco Nexus switching frameworks and Aruba Wi-Fi environments. Solid understanding of Network Load Balancing mechanisms and coordinating third-party Penetration Testing. Strong secondary expertise in Cyber Security, specifically administering Palo Alto Firewalls alongside their advanced next-gen service suites. Background utilizing Qualys Vulnerability Management tools and endpoint detection/remediation software. Previous experience navigating SOX compliance frameworks and handling fast-paced data environments is highly desirable. Application Requirement: Project Examples Our client values real-world execution. As part of your application, please be prepared to provide specific examples of projects where you led from the front on network or security kit deployments. We will look for details on:The scope of the hardware/software deployment you personally executed.The specific technical challenges you overcame during the installation or build phase.The tangible value and security/performance improvements your role brought to that process. Growth, Support & Culture Our client believes in empowering their people to reach their full potential. Joining this team means benefiting from: Structured Progression: Clear objective setting, tailored 1:1 mentorship sessions, and consistent coaching to elevate your architectural capabilities. Empowerment & Autonomy: An inclusive culture that grants ownership of meaningful outcomes and encourages exploration of development opportunities outside your immediate remit. A Collaborative Space: A supportive management philosophy designed to give employees the resources they need to excel while allowing them to bring their authentic selves to work every day.

Modal Window

  • Home
  • Contact
  • About Us
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • Facebook
  • Twitter
  • Google Plus
  • LinkedIn
Parent and Partner sites: IT Job Board | Jobs Near Me | RightTalent.co.uk | Quantity Surveyor jobs | Building Surveyor jobs | Construction Recruitment | Talent Recruiter | Construction Job Board | Property jobs | myJobsnearme.com | Jobs near me
© 2008-2026 Jobsite Jobs | Designed by Web Design Agency