Hollybank Trustees Ltd
High Wycombe, Buckinghamshire
Saepio is seeking a Director of Managed & Professional Services to lead our delivery functions, including a growing Penetration Testing business. You will oversee Professional Services and Managed Services, driving growth, developing offerings, and ensuring high-quality, repeatable services for customers. You'll align with Sales, Solutions and customers, manage commercial performance, and develop your teams with ongoing professional development and certifications in a fast-changing cyber
Aug 25, 2026
Full time
Saepio is seeking a Director of Managed & Professional Services to lead our delivery functions, including a growing Penetration Testing business. You will oversee Professional Services and Managed Services, driving growth, developing offerings, and ensuring high-quality, repeatable services for customers. You'll align with Sales, Solutions and customers, manage commercial performance, and develop your teams with ongoing professional development and certifications in a fast-changing cyber
Hollybank Trustees Ltd
High Wycombe, Buckinghamshire
As we continue to grow, we're looking for a Director of Managed & Professional Services to lead our technical delivery functions, including our growing Penetration Testing business. You'll lead our Professional Services team and Managed Services, with responsibility for developing our services, growing the penetration testing business, identifying new opportunities and building high-performing teams. This is a senior, commercially focused role, working closely with Sales, Solutions, customers and technical teams to drive growth while maintaining the high-quality service and standards our customers expect from Saepio. What you'll be doing? Lead and develop the Professional Services and Managed Services functions, ensuring both teams deliver consistently high-quality services while fostering a culture of collaboration, accountability and continuous improvement. Own the growth and development of the Penetration Testing business, including strategy, people, delivery, customers, commercial performance and identifying new opportunities, services and markets. Drive the development of our Professional Services portfolio, building scalable and repeatable offerings across areas such as penetration testing, email security, EDR/MDR, Network/SSE/SASE and Cloud, while identifying opportunities to use automation and AI to improve efficiency. Work closely with Sales, Solutions, customers, vendors and partners to develop propositions, take our capabilities to market, understand customer challenges and identify opportunities to grow existing and new customer relationships. Own the successful delivery and commercial performance of the functions, overseeing project delivery, utilisation, revenue, margins, pipeline, customer retention and Managed Services renewals. Develop our people and technical capabilities, ensuring team members maintain relevant certifications, build their skills and expertise, and that Saepio remains aligned with the evolving cyber security market. What are we looking for? We're looking for an experienced, commercially minded services leader who understands both the technical and commercial sides of cyber security. You'll be confident leading technical teams, developing customer-focused services and identifying opportunities for growth. You'll be organised, proactive and comfortable working in a fast-moving environment, with a genuine interest in emerging technology, AI and automation and how they can improve the way we work. Our Requirements 10+ years' experience in Professional Services, Cyber Security, Penetration Testing or a related technology services environment, including team management. Strong understanding of the Professional Services model, ideally with experience leading a penetration testing or security consultancy function. Proven commercial experience, including revenue growth, utilisation, margins, pipeline and/or customer retention, with experience developing and taking new services or propositions to market. Strong customer and stakeholder management skills, with the ability to build effective relationships with technical and senior stakeholders and communicate confidently at all levels. Strong leadership, organisational and people management skills, with a genuine interest in developing technical teams and managing multiple priorities in a fast-moving environment. Other skills/qualifications - (Desirable, not mandatory) Penetration Testing & Cyber Security: Experience leading a penetration testing team or business, with a strong understanding of penetration testing services and the wider cyber security consulting market. Industry & Relationships: Relevant cyber security/industry certifications and experience developing strategic customer and vendor relationships, ideally within a managed security services environment. Innovation & Efficiency: Experience using automation and AI to improve service delivery, efficiency and scalability. About Saepio Cyber security isn't an add-on to IT. It's a specialist discipline. That's why modern UK organisations separate the teams who run systems from those who protect them. And it's why they choose Saepio. We're one of the UK's most recognised cyber specialists and an NCSC Assured Service Provider, working with over 1,000 organisations who trust us to help them: Cut through noise and see their real risk Align policy, people and technology into one coherent strategy Mature security operations without adding unnecessary complexity Build cyber resilience that stands up to real-world pressure We partner with the most advanced security platforms in the market and deliver high-impact events, campaigns and thought leadership that place Saepio at the centre of the UK cyber conversation. What do we offer Having a happy and healthy team provides the foundation for our energy and drive 25 days annual leave + an extra day for each year of service (up to 30 days) plus additional half days for a 'Duvet morning' and your birthday (FTE) BUPA Premium Health Insurance £0 excess covering pre-existing conditions Critical Illness Cover Royal London Pension Plan Strong learning and development culture to help you excel International incentive trips for high performers Fantastic social events e.g. Family Fun Day, Quarterly socials, Festive Party Quarterly company-wide recognition events e.g. lunch at Michelin star restaurants To be eligible for this role, you must have the right to work in the UK on a permanent basis (e.g., Indefinite Leave to Remain or UK/EU Settled Status). Unfortunately, we are unable to provide visa sponsorship at this time.
Aug 25, 2026
Full time
As we continue to grow, we're looking for a Director of Managed & Professional Services to lead our technical delivery functions, including our growing Penetration Testing business. You'll lead our Professional Services team and Managed Services, with responsibility for developing our services, growing the penetration testing business, identifying new opportunities and building high-performing teams. This is a senior, commercially focused role, working closely with Sales, Solutions, customers and technical teams to drive growth while maintaining the high-quality service and standards our customers expect from Saepio. What you'll be doing? Lead and develop the Professional Services and Managed Services functions, ensuring both teams deliver consistently high-quality services while fostering a culture of collaboration, accountability and continuous improvement. Own the growth and development of the Penetration Testing business, including strategy, people, delivery, customers, commercial performance and identifying new opportunities, services and markets. Drive the development of our Professional Services portfolio, building scalable and repeatable offerings across areas such as penetration testing, email security, EDR/MDR, Network/SSE/SASE and Cloud, while identifying opportunities to use automation and AI to improve efficiency. Work closely with Sales, Solutions, customers, vendors and partners to develop propositions, take our capabilities to market, understand customer challenges and identify opportunities to grow existing and new customer relationships. Own the successful delivery and commercial performance of the functions, overseeing project delivery, utilisation, revenue, margins, pipeline, customer retention and Managed Services renewals. Develop our people and technical capabilities, ensuring team members maintain relevant certifications, build their skills and expertise, and that Saepio remains aligned with the evolving cyber security market. What are we looking for? We're looking for an experienced, commercially minded services leader who understands both the technical and commercial sides of cyber security. You'll be confident leading technical teams, developing customer-focused services and identifying opportunities for growth. You'll be organised, proactive and comfortable working in a fast-moving environment, with a genuine interest in emerging technology, AI and automation and how they can improve the way we work. Our Requirements 10+ years' experience in Professional Services, Cyber Security, Penetration Testing or a related technology services environment, including team management. Strong understanding of the Professional Services model, ideally with experience leading a penetration testing or security consultancy function. Proven commercial experience, including revenue growth, utilisation, margins, pipeline and/or customer retention, with experience developing and taking new services or propositions to market. Strong customer and stakeholder management skills, with the ability to build effective relationships with technical and senior stakeholders and communicate confidently at all levels. Strong leadership, organisational and people management skills, with a genuine interest in developing technical teams and managing multiple priorities in a fast-moving environment. Other skills/qualifications - (Desirable, not mandatory) Penetration Testing & Cyber Security: Experience leading a penetration testing team or business, with a strong understanding of penetration testing services and the wider cyber security consulting market. Industry & Relationships: Relevant cyber security/industry certifications and experience developing strategic customer and vendor relationships, ideally within a managed security services environment. Innovation & Efficiency: Experience using automation and AI to improve service delivery, efficiency and scalability. About Saepio Cyber security isn't an add-on to IT. It's a specialist discipline. That's why modern UK organisations separate the teams who run systems from those who protect them. And it's why they choose Saepio. We're one of the UK's most recognised cyber specialists and an NCSC Assured Service Provider, working with over 1,000 organisations who trust us to help them: Cut through noise and see their real risk Align policy, people and technology into one coherent strategy Mature security operations without adding unnecessary complexity Build cyber resilience that stands up to real-world pressure We partner with the most advanced security platforms in the market and deliver high-impact events, campaigns and thought leadership that place Saepio at the centre of the UK cyber conversation. What do we offer Having a happy and healthy team provides the foundation for our energy and drive 25 days annual leave + an extra day for each year of service (up to 30 days) plus additional half days for a 'Duvet morning' and your birthday (FTE) BUPA Premium Health Insurance £0 excess covering pre-existing conditions Critical Illness Cover Royal London Pension Plan Strong learning and development culture to help you excel International incentive trips for high performers Fantastic social events e.g. Family Fun Day, Quarterly socials, Festive Party Quarterly company-wide recognition events e.g. lunch at Michelin star restaurants To be eligible for this role, you must have the right to work in the UK on a permanent basis (e.g., Indefinite Leave to Remain or UK/EU Settled Status). Unfortunately, we are unable to provide visa sponsorship at this time.
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Aug 23, 2026
Full time
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Company: Global Retail Company Position: Infrastructure Specialist Contract: 1-year fixed term contract Location: London (Hybrid) Salary: 60 000 GBP + 10% Bonus Job responsibilities: 1. Retail Store Expansion & Operations New Store Delivery: Lead and execute the end-to-end technical infrastructure setup for new store openings, refits, relocations, and brand pop-ups across Europe. This includes configuring and deploying POS hardware, network printers, scanners, mobile tablets, and payment terminals. Store Network Connectivity: Deploy and optimize local in-store networks, focusing on stable retail WiFi, localized LAN environments, and secure SD-WAN configurations. L2/L3 Incident Resolution: Serve as the final escalation point for in-store technology failures, proactively monitoring uptime and troubleshooting device, data feed, and connectivity drops to minimize commercial downtime. 2. Warehouse Tech Readiness & 3PL Coordination Logistics Network Engineering: Act as the primary technical point of contact during third-party logistics (3PL) partner onboarding, warehouse moves, and facility expansions. Secure Environment Bridging: Establish and maintain secure, high-availability VPN tunnels and SD-WAN routing paths between our core network and external 3PL environments. RF & Hardware Onboarding: Configure and manage localized warehouse hardware, including RF guns, industrial handheld scanners, barcode label printers, and dedicated logistics VLANs. Network Security Guardrails: Manage firewall rules, routing rules, and strict IP whitelisting to ensure 3PL integrations align with corporate cybersecurity frameworks. 3. Core Enterprise Infrastructure & SAP Backing Network Architecture Management: Oversee and scale EMEA-wide network routing, switching, firewalls, and enterprise identity management systems. SAP Technical Prerequisites: Manage critical infrastructure prerequisites that fuel our SAP-centric strategy, including network print routing, RFC endpoints, secure connectivity paths, and POS-to-ERP transaction queues. Global Architecture Alignment: Partner closely with global architecture units to ensure European implementations conform to standard global design baselines. 4. Information Security, Governance & Compliance Endpoint Protection: Enforce corporate cybersecurity standards across all endpoints using modern Identity Lifecycle mechanisms (Entra ID/Azure AD) and device compliance tools (Microsoft Intune/MDM). Threat & Risk Management: Monitor, identify, and remediate environment vulnerabilities. Support penetration testing schedules, deploy Multi-Factor Authentication (MFA), and maintain device encryption policies. Data Protection Compliance: Ensure all localized retail systems and warehouse practices comply directly with GDPR, IT General Controls (ITGC), and corporate data breach prevention playbooks. 5. Office IT Operations & Service Delivery Corporate Workplace Operations: Manage daily IT infrastructure across EMEA offices and showrooms, covering corporate hardware lifecycles (Windows/MacOS), M365 systems, conferencing technology, and automated onboarding/offboarding workflows. Vendor SLA Management: Manage local and regional hardware vendors, telecom partners, field support agencies, and POS providers, holding them accountable to strict ticket resolution timelines via ServiceNow. Asset Management & Playbooks: Build and update detailed IT asset registers alongside infrastructure configurations, store deployment playbooks, and standardized troubleshooting runbooks. Experience 10+ years of progressive, hands-on experience in IT Infrastructure, Network Engineering, and Technical Operations roles. Sector Background: Documented experience supporting multi-site environments within Retail, Fashion, Logistics/Supply Chain, or Fast-Paced Hospitality brands. Store Tech Fluency: Expert understanding of physical retail tech stacks, including modern POS ecosystems, network payment routing, mobile registers, and store-wide coverage WiFi deployment. 3PL/Logistics Coordination: Proven success collaborating with external 3PL logistics operators to set up network configurations, firewalls, IP whitelisting, and specialized warehouse devices. Modern Device Governance: Mastery of endpoint management through Microsoft Intune / MDM solutions and user access lifecycles inside Entra ID (Azure AD). SAP Connectivity Awareness: Direct exposure to managing network prerequisites for SAP integration feeds, document printing routing, and stable system-to-system connections. Highly Desirable Certifications: Cisco CCNA, CompTIA Network+, Microsoft 365/Intune certifications, or ITIL foundational framework knowledge. We regret to inform applicants that only shortlisted candidates will be notified. Thank you for understanding.
Aug 23, 2026
Contractor
Company: Global Retail Company Position: Infrastructure Specialist Contract: 1-year fixed term contract Location: London (Hybrid) Salary: 60 000 GBP + 10% Bonus Job responsibilities: 1. Retail Store Expansion & Operations New Store Delivery: Lead and execute the end-to-end technical infrastructure setup for new store openings, refits, relocations, and brand pop-ups across Europe. This includes configuring and deploying POS hardware, network printers, scanners, mobile tablets, and payment terminals. Store Network Connectivity: Deploy and optimize local in-store networks, focusing on stable retail WiFi, localized LAN environments, and secure SD-WAN configurations. L2/L3 Incident Resolution: Serve as the final escalation point for in-store technology failures, proactively monitoring uptime and troubleshooting device, data feed, and connectivity drops to minimize commercial downtime. 2. Warehouse Tech Readiness & 3PL Coordination Logistics Network Engineering: Act as the primary technical point of contact during third-party logistics (3PL) partner onboarding, warehouse moves, and facility expansions. Secure Environment Bridging: Establish and maintain secure, high-availability VPN tunnels and SD-WAN routing paths between our core network and external 3PL environments. RF & Hardware Onboarding: Configure and manage localized warehouse hardware, including RF guns, industrial handheld scanners, barcode label printers, and dedicated logistics VLANs. Network Security Guardrails: Manage firewall rules, routing rules, and strict IP whitelisting to ensure 3PL integrations align with corporate cybersecurity frameworks. 3. Core Enterprise Infrastructure & SAP Backing Network Architecture Management: Oversee and scale EMEA-wide network routing, switching, firewalls, and enterprise identity management systems. SAP Technical Prerequisites: Manage critical infrastructure prerequisites that fuel our SAP-centric strategy, including network print routing, RFC endpoints, secure connectivity paths, and POS-to-ERP transaction queues. Global Architecture Alignment: Partner closely with global architecture units to ensure European implementations conform to standard global design baselines. 4. Information Security, Governance & Compliance Endpoint Protection: Enforce corporate cybersecurity standards across all endpoints using modern Identity Lifecycle mechanisms (Entra ID/Azure AD) and device compliance tools (Microsoft Intune/MDM). Threat & Risk Management: Monitor, identify, and remediate environment vulnerabilities. Support penetration testing schedules, deploy Multi-Factor Authentication (MFA), and maintain device encryption policies. Data Protection Compliance: Ensure all localized retail systems and warehouse practices comply directly with GDPR, IT General Controls (ITGC), and corporate data breach prevention playbooks. 5. Office IT Operations & Service Delivery Corporate Workplace Operations: Manage daily IT infrastructure across EMEA offices and showrooms, covering corporate hardware lifecycles (Windows/MacOS), M365 systems, conferencing technology, and automated onboarding/offboarding workflows. Vendor SLA Management: Manage local and regional hardware vendors, telecom partners, field support agencies, and POS providers, holding them accountable to strict ticket resolution timelines via ServiceNow. Asset Management & Playbooks: Build and update detailed IT asset registers alongside infrastructure configurations, store deployment playbooks, and standardized troubleshooting runbooks. Experience 10+ years of progressive, hands-on experience in IT Infrastructure, Network Engineering, and Technical Operations roles. Sector Background: Documented experience supporting multi-site environments within Retail, Fashion, Logistics/Supply Chain, or Fast-Paced Hospitality brands. Store Tech Fluency: Expert understanding of physical retail tech stacks, including modern POS ecosystems, network payment routing, mobile registers, and store-wide coverage WiFi deployment. 3PL/Logistics Coordination: Proven success collaborating with external 3PL logistics operators to set up network configurations, firewalls, IP whitelisting, and specialized warehouse devices. Modern Device Governance: Mastery of endpoint management through Microsoft Intune / MDM solutions and user access lifecycles inside Entra ID (Azure AD). SAP Connectivity Awareness: Direct exposure to managing network prerequisites for SAP integration feeds, document printing routing, and stable system-to-system connections. Highly Desirable Certifications: Cisco CCNA, CompTIA Network+, Microsoft 365/Intune certifications, or ITIL foundational framework knowledge. We regret to inform applicants that only shortlisted candidates will be notified. Thank you for understanding.
SRT Marine Systems plc
Gloucester, Gloucestershire
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high-quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Product Security Engineer to help ensure security is properly built into our products from the ground up - in the designs we choose, the code we write, and the way our software is developed, tested and delivered. This is a hands-on role embedded within our product development teams. You as a Product Security Engineer will work day-to-day with software developers, testers and product owners to improve the security of what we build and how we build it, and to make sure security has a clear voice when product priorities are set. The role is a dedicated security role focused on the security of how we develop our products. It combines technical depth - reviewing designs and code, threat modelling, assessing risk pragmatically - with the credibility and communication skills to bring experienced developers along. It offers a genuine opportunity to grow into the leadership of our product security capability, and we welcome ambitious candidates ready to step up into a security specialism from a strong software engineering background. The role of Product Security Engineer is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, with good flexibility for Hybrid working. Responsibilities - Product Security Engineer - not exhaustive: Champion security within our product development teams, providing a clear day-to-day voice for security in design, code and backlog decisions. Embed secure development practices across the software development lifecycle, including secure coding standards, code review, testing, CI/CD and related controls. Carry out threat modelling, secure design reviews and technical risk assessments for new and existing product capabilities, so that security is designed in from the start. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside feature delivery and other technical work. Support vulnerability remediation, including root cause analysis and long-term fixes. Track the security of third-party components and dependencies within our products, and lead our response when new vulnerabilities and supply-chain incidents emerge. Ensure security features and fixes are properly represented in product roadmap, backlog and design decisions, working with product owners and engineering leadership. Work with our external security partners to arrange and act on penetration testing and security assessments of our products. Contribute to security standards, metrics and ways of working that improve product security maturity over time. Support wider assurance and certification activity, including ISO 27001 or other relevant standards, with evidence of how our softwareis securely built. Requirements - Product Security Engineer - not exhaustive: A strong software engineering background, with the technical depth to read code, review designs and engage credibly with experienced developers. Experience of, or a strong demonstrable specialism in, application security or secure software engineering in a software-led environment. Practical experience applying security across the software development lifecycle, including areas such as threat modelling, secure coding, testing, vulnerability management and secure delivery. Good understanding of how product and development teams operate, including how security considerations are balanced alongside product delivery. The judgement to assess exploitability and business impact pragmatically. Strong communication skills, with the ability to turn technical security concerns into clear, actionable decisions that developers respect. The ambition to make security your dedicated focus and to grow with the role as we build our product security capability. Familiarity with recognised standards, frameworks or certifications such as OWASP, CSSLP, ISO 27001 or similar would be helpful. Experience in a product, platform or SaaS business. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Aug 22, 2026
Full time
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high-quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Product Security Engineer to help ensure security is properly built into our products from the ground up - in the designs we choose, the code we write, and the way our software is developed, tested and delivered. This is a hands-on role embedded within our product development teams. You as a Product Security Engineer will work day-to-day with software developers, testers and product owners to improve the security of what we build and how we build it, and to make sure security has a clear voice when product priorities are set. The role is a dedicated security role focused on the security of how we develop our products. It combines technical depth - reviewing designs and code, threat modelling, assessing risk pragmatically - with the credibility and communication skills to bring experienced developers along. It offers a genuine opportunity to grow into the leadership of our product security capability, and we welcome ambitious candidates ready to step up into a security specialism from a strong software engineering background. The role of Product Security Engineer is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, with good flexibility for Hybrid working. Responsibilities - Product Security Engineer - not exhaustive: Champion security within our product development teams, providing a clear day-to-day voice for security in design, code and backlog decisions. Embed secure development practices across the software development lifecycle, including secure coding standards, code review, testing, CI/CD and related controls. Carry out threat modelling, secure design reviews and technical risk assessments for new and existing product capabilities, so that security is designed in from the start. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside feature delivery and other technical work. Support vulnerability remediation, including root cause analysis and long-term fixes. Track the security of third-party components and dependencies within our products, and lead our response when new vulnerabilities and supply-chain incidents emerge. Ensure security features and fixes are properly represented in product roadmap, backlog and design decisions, working with product owners and engineering leadership. Work with our external security partners to arrange and act on penetration testing and security assessments of our products. Contribute to security standards, metrics and ways of working that improve product security maturity over time. Support wider assurance and certification activity, including ISO 27001 or other relevant standards, with evidence of how our softwareis securely built. Requirements - Product Security Engineer - not exhaustive: A strong software engineering background, with the technical depth to read code, review designs and engage credibly with experienced developers. Experience of, or a strong demonstrable specialism in, application security or secure software engineering in a software-led environment. Practical experience applying security across the software development lifecycle, including areas such as threat modelling, secure coding, testing, vulnerability management and secure delivery. Good understanding of how product and development teams operate, including how security considerations are balanced alongside product delivery. The judgement to assess exploitability and business impact pragmatically. Strong communication skills, with the ability to turn technical security concerns into clear, actionable decisions that developers respect. The ambition to make security your dedicated focus and to grow with the role as we build our product security capability. Familiarity with recognised standards, frameworks or certifications such as OWASP, CSSLP, ISO 27001 or similar would be helpful. Experience in a product, platform or SaaS business. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high-quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Product Security Engineer to help ensure security is properly built into our products from the ground up - in the designs we choose, the code we write, and the way our software is developed, tested and delivered. This is a hands-on role embedded within our product development teams. You as a Product Security Engineer will work day-to-day with software developers, testers and product owners to improve the security of what we build and how we build it, and to make sure security has a clear voice when product priorities are set. The role is a dedicated security role focused on the security of how we develop our products. It combines technical depth - reviewing designs and code, threat modelling, assessing risk pragmatically - with the credibility and communicationskills to bring experienced developers along. It offers a genuine opportunity to grow into the leadership of our product security capability, and we welcome ambitious candidates ready to step up into a security specialism from a strong software engineering background. The role of Product Security Engineer is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, with good flexibility for Hybrid working. Responsibilities - Product Security Engineer - not exhaustive: Champion security within our product development teams, providing a clear day-to-day voice for security in design, code and backlog decisions. Embed secure development practices across the software development lifecycle, including secure coding standards, code review, testing, CI/CD and related controls. Carry out threat modelling, secure design reviews and technical risk assessments for new and existing product capabilities, so that security is designed in from the start. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside feature delivery and other technical work. Support vulnerability remediation, including root cause analysis and long-term fixes. Track the security of third-party components and dependencies within our products, and lead our response when new vulnerabilities and supply-chain incidents emerge. Ensure security features and fixes are properly represented in product roadmap, backlog and design decisions, working with product owners and engineering leadership. Work with our external security partners to arrange and act on penetration testing and security assessments of our products. Contribute to security standards, metrics and ways of working that improve product security maturity over time. Support wider assurance and certification activity, including ISO 27001 or other relevant standards, with evidence of how our software issecurely built. Requirements - Product Security Engineer - not exhaustive: A strong software engineering background, with the technical depth to read code, review designs and engage credibly with experienced developers. Experience of, or a strong demonstrable specialism in, application security or secure software engineering in a software-led environment. Practical experience applying security across the software development lifecycle, including areas such as threat modelling, secure coding, testing, vulnerability management and secure delivery. Good understanding of how product and development teams operate, including how security considerations are balanced alongside product delivery. The judgement to assess exploitability and business impact pragmatically. Strong communication skills, with the ability to turn technical security concerns into clear, actionable decisions that developers respect. The ambition to make security your dedicated focus and to grow with the role as we build our product security capability. Familiarity with recognised standards, frameworks or certifications such as OWASP, CSSLP, ISO 27001 or similar would be helpful. Experience in a product, platform or SaaS business. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Aug 22, 2026
Full time
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high-quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Product Security Engineer to help ensure security is properly built into our products from the ground up - in the designs we choose, the code we write, and the way our software is developed, tested and delivered. This is a hands-on role embedded within our product development teams. You as a Product Security Engineer will work day-to-day with software developers, testers and product owners to improve the security of what we build and how we build it, and to make sure security has a clear voice when product priorities are set. The role is a dedicated security role focused on the security of how we develop our products. It combines technical depth - reviewing designs and code, threat modelling, assessing risk pragmatically - with the credibility and communicationskills to bring experienced developers along. It offers a genuine opportunity to grow into the leadership of our product security capability, and we welcome ambitious candidates ready to step up into a security specialism from a strong software engineering background. The role of Product Security Engineer is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, with good flexibility for Hybrid working. Responsibilities - Product Security Engineer - not exhaustive: Champion security within our product development teams, providing a clear day-to-day voice for security in design, code and backlog decisions. Embed secure development practices across the software development lifecycle, including secure coding standards, code review, testing, CI/CD and related controls. Carry out threat modelling, secure design reviews and technical risk assessments for new and existing product capabilities, so that security is designed in from the start. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside feature delivery and other technical work. Support vulnerability remediation, including root cause analysis and long-term fixes. Track the security of third-party components and dependencies within our products, and lead our response when new vulnerabilities and supply-chain incidents emerge. Ensure security features and fixes are properly represented in product roadmap, backlog and design decisions, working with product owners and engineering leadership. Work with our external security partners to arrange and act on penetration testing and security assessments of our products. Contribute to security standards, metrics and ways of working that improve product security maturity over time. Support wider assurance and certification activity, including ISO 27001 or other relevant standards, with evidence of how our software issecurely built. Requirements - Product Security Engineer - not exhaustive: A strong software engineering background, with the technical depth to read code, review designs and engage credibly with experienced developers. Experience of, or a strong demonstrable specialism in, application security or secure software engineering in a software-led environment. Practical experience applying security across the software development lifecycle, including areas such as threat modelling, secure coding, testing, vulnerability management and secure delivery. Good understanding of how product and development teams operate, including how security considerations are balanced alongside product delivery. The judgement to assess exploitability and business impact pragmatically. Strong communication skills, with the ability to turn technical security concerns into clear, actionable decisions that developers respect. The ambition to make security your dedicated focus and to grow with the role as we build our product security capability. Familiarity with recognised standards, frameworks or certifications such as OWASP, CSSLP, ISO 27001 or similar would be helpful. Experience in a product, platform or SaaS business. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high-quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Product Security Engineer to help ensure security is properly built into our products from the ground up - in the designs we choose, the code we write, and the way our software is developed, tested and delivered. This is a hands-on role embedded within our product development teams. You as a Product Security Engineer will work day-to-day with software developers, testers and product owners to improve the security of what we build and how we build it, and to make sure security has a clear voice when product priorities are set. The role is a dedicated security role focused on the security of how we develop our products. It combines technical depth - reviewing designs and code, threat modelling, assessing risk pragmatically - with the credibility and communication skills to bring experienced developers along. It offers a genuine opportunity to grow into the leadership of our product security capability, and we welcome ambitious candidates ready to step up into a security specialism from a strong software engineering background. The role of Product Security Engineer is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, with good flexibility for Hybrid working. Responsibilities - Product Security Engineer - not exhaustive: Champion security within our product development teams, providing a clear day-to-day voice for security in design, code and backlog decisions. Embed secure development practices across the software development lifecycle, including secure coding standards, code review, testing, CI/CD and related controls. Carry out threat modelling, secure design reviews and technical risk assessments for new and existing product capabilities, so that security is designed in from the start. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside feature delivery and other technical work. Support vulnerability remediation, including root cause analysis and long-term fixes. Track the security of third-party components and dependencies within our products, and lead our response when new vulnerabilities and supply-chain incidents emerge. Ensure security features and fixes are properly represented in product roadmap, backlog and design decisions, working with product owners and engineering leadership. Work with our external security partners to arrange and act on penetration testing and security assessments of our products. Contribute to security standards, metrics and ways of working that improve product security maturity over time. Support wider assurance and certification activity, including ISO 27001 or other relevant standards, with evidence of how our softwareis securely built. Requirements - Product Security Engineer - not exhaustive: A strong software engineering background, with the technical depth to read code, review designs and engage credibly with experienced developers. Experience of, or a strong demonstrable specialism in, application security or secure software engineering in a software-led environment. Practical experience applying security across the software development lifecycle, including areas such as threat modelling, secure coding, testing, vulnerability management and secure delivery. Good understanding of how product and development teams operate, including how security considerations are balanced alongside product delivery. The judgement to assess exploitability and business impact pragmatically. Strong communication skills, with the ability to turn technical security concerns into clear, actionable decisions that developers respect. The ambition to make security your dedicated focus and to grow with the role as we build our product security capability. Familiarity with recognised standards, frameworks or certifications such as OWASP, CSSLP, ISO 27001 or similar would be helpful. Experience in a product, platform or SaaS business. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Aug 22, 2026
Full time
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high-quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Product Security Engineer to help ensure security is properly built into our products from the ground up - in the designs we choose, the code we write, and the way our software is developed, tested and delivered. This is a hands-on role embedded within our product development teams. You as a Product Security Engineer will work day-to-day with software developers, testers and product owners to improve the security of what we build and how we build it, and to make sure security has a clear voice when product priorities are set. The role is a dedicated security role focused on the security of how we develop our products. It combines technical depth - reviewing designs and code, threat modelling, assessing risk pragmatically - with the credibility and communication skills to bring experienced developers along. It offers a genuine opportunity to grow into the leadership of our product security capability, and we welcome ambitious candidates ready to step up into a security specialism from a strong software engineering background. The role of Product Security Engineer is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, with good flexibility for Hybrid working. Responsibilities - Product Security Engineer - not exhaustive: Champion security within our product development teams, providing a clear day-to-day voice for security in design, code and backlog decisions. Embed secure development practices across the software development lifecycle, including secure coding standards, code review, testing, CI/CD and related controls. Carry out threat modelling, secure design reviews and technical risk assessments for new and existing product capabilities, so that security is designed in from the start. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside feature delivery and other technical work. Support vulnerability remediation, including root cause analysis and long-term fixes. Track the security of third-party components and dependencies within our products, and lead our response when new vulnerabilities and supply-chain incidents emerge. Ensure security features and fixes are properly represented in product roadmap, backlog and design decisions, working with product owners and engineering leadership. Work with our external security partners to arrange and act on penetration testing and security assessments of our products. Contribute to security standards, metrics and ways of working that improve product security maturity over time. Support wider assurance and certification activity, including ISO 27001 or other relevant standards, with evidence of how our softwareis securely built. Requirements - Product Security Engineer - not exhaustive: A strong software engineering background, with the technical depth to read code, review designs and engage credibly with experienced developers. Experience of, or a strong demonstrable specialism in, application security or secure software engineering in a software-led environment. Practical experience applying security across the software development lifecycle, including areas such as threat modelling, secure coding, testing, vulnerability management and secure delivery. Good understanding of how product and development teams operate, including how security considerations are balanced alongside product delivery. The judgement to assess exploitability and business impact pragmatically. Strong communication skills, with the ability to turn technical security concerns into clear, actionable decisions that developers respect. The ambition to make security your dedicated focus and to grow with the role as we build our product security capability. Familiarity with recognised standards, frameworks or certifications such as OWASP, CSSLP, ISO 27001 or similar would be helpful. Experience in a product, platform or SaaS business. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Product Security Engineer Luton 6-month contract Paying up to Circa 93p/h (Inside IR35) Please note - Due to the nature of the work, you'll be required to hold a high level of UK Security Clearance Overview : As the Product Security Engineer /Lead security Engineer, you'll take responsibility for all security aspects of product design, development, verification and maintenance through all phases of the product lifecycle. The role will focus on undertaking security risk assessments, preparing security risk mitigation plans, deriving security requirements and working closely and directly with product development teams to design, implement and maintain appropriate security controls and the production of wider security artefacts. Responsibilities : Production of Security Management Plans, work package descriptions and cost estimates in support of product bids, services and proposals. Undertaking security risk assessments, risk mitigation plans, mitigation gap analysis and preparation of security management documentation for system assurance. Defining product security requirements, advising development teams on bespoke implementations for product security control implementations and overseeing product development activities. Liaison with internal and external security assurance authorities to desmontrate product compliance against recognised UK and wider frameworks. Driving collaborative working with external security authorities such as the NCSC to provide underwriting of security solutions. Understanding and management of security activities within development, testing and manufacturing environments. Advising development teams on suitable platform lockdown and configurations, and supporting penetration test activities. Analysing penetration test results and preparation of remedial action plans. Identify, communicate and drive through life security management, including but not limited to obsolescence planning, vulnerability and patch management for all products within area of responsibility. Lead security incident management teams during incident/crisis situations in conjunction with Head of Product Security for EW/FCA. Review, maintain and participate corporate product security policies. Deliver product security training to project engineering teams. Essential Skills & Experience Experience in the development of besoke product-based security solutions for a military and/or commercial products and systems. Graduate degree in relevant engineering, computing or related scientific discipline, and/or evidence of further professional study. Full membership of an NCSC recognised professional security body organisation (i.e. CIISec, ISC2 or ISACA). Recent experience and demonstratable knowledge of live and legacy UK/EU/NATO information security standards and frameworks, including the UK MOD Secure by Design framework, GovS 007, HMG IS1&2, ISO27001, NIST SP800-30/37/53, UK MOD Information Security related JSPs, EU CRA and US DoD information security policies. Practical experience of producing technical assurance documentation such as Key Management Plans, Testing Security Instructions, Security Operating Procedures and Security Cases. Knowledge of current cryptographic technologies and key management systems. Understanding of Model Based System Engineering (MBSE) and how Product Security directly inputs into the process. Knowledge and understanding of bespoke product-specific Operating Systems, Firmware and Software security controls and how to apply them. Knowledge of Quantum Cryptography & Quantum Key management. Experience or knowledge of existing threat intelligence sources. Knowledge of NATO security policy, risk management and Accreditation. Disclaimer: This vacancy is being advertised by either Advanced Resource Managers Limited, Advanced Resource Managers IT Limited or Advanced Resource Managers Engineering Limited ("ARM"). ARM is a specialist talent acquisition and management consultancy. We provide technical contingency recruitment and a portfolio of more complex resource solutions. Our specialist recruitment divisions cover the entire technical arena, including some of the most economically and strategically important industries in the UK and the world today. We will never send your CV without your permission. Where the role is marked as Outside IR35 in the advertisement this is subject to receipt of a final Status Determination Statement from the end Client and may be subject to change.
Aug 22, 2026
Contractor
Product Security Engineer Luton 6-month contract Paying up to Circa 93p/h (Inside IR35) Please note - Due to the nature of the work, you'll be required to hold a high level of UK Security Clearance Overview : As the Product Security Engineer /Lead security Engineer, you'll take responsibility for all security aspects of product design, development, verification and maintenance through all phases of the product lifecycle. The role will focus on undertaking security risk assessments, preparing security risk mitigation plans, deriving security requirements and working closely and directly with product development teams to design, implement and maintain appropriate security controls and the production of wider security artefacts. Responsibilities : Production of Security Management Plans, work package descriptions and cost estimates in support of product bids, services and proposals. Undertaking security risk assessments, risk mitigation plans, mitigation gap analysis and preparation of security management documentation for system assurance. Defining product security requirements, advising development teams on bespoke implementations for product security control implementations and overseeing product development activities. Liaison with internal and external security assurance authorities to desmontrate product compliance against recognised UK and wider frameworks. Driving collaborative working with external security authorities such as the NCSC to provide underwriting of security solutions. Understanding and management of security activities within development, testing and manufacturing environments. Advising development teams on suitable platform lockdown and configurations, and supporting penetration test activities. Analysing penetration test results and preparation of remedial action plans. Identify, communicate and drive through life security management, including but not limited to obsolescence planning, vulnerability and patch management for all products within area of responsibility. Lead security incident management teams during incident/crisis situations in conjunction with Head of Product Security for EW/FCA. Review, maintain and participate corporate product security policies. Deliver product security training to project engineering teams. Essential Skills & Experience Experience in the development of besoke product-based security solutions for a military and/or commercial products and systems. Graduate degree in relevant engineering, computing or related scientific discipline, and/or evidence of further professional study. Full membership of an NCSC recognised professional security body organisation (i.e. CIISec, ISC2 or ISACA). Recent experience and demonstratable knowledge of live and legacy UK/EU/NATO information security standards and frameworks, including the UK MOD Secure by Design framework, GovS 007, HMG IS1&2, ISO27001, NIST SP800-30/37/53, UK MOD Information Security related JSPs, EU CRA and US DoD information security policies. Practical experience of producing technical assurance documentation such as Key Management Plans, Testing Security Instructions, Security Operating Procedures and Security Cases. Knowledge of current cryptographic technologies and key management systems. Understanding of Model Based System Engineering (MBSE) and how Product Security directly inputs into the process. Knowledge and understanding of bespoke product-specific Operating Systems, Firmware and Software security controls and how to apply them. Knowledge of Quantum Cryptography & Quantum Key management. Experience or knowledge of existing threat intelligence sources. Knowledge of NATO security policy, risk management and Accreditation. Disclaimer: This vacancy is being advertised by either Advanced Resource Managers Limited, Advanced Resource Managers IT Limited or Advanced Resource Managers Engineering Limited ("ARM"). ARM is a specialist talent acquisition and management consultancy. We provide technical contingency recruitment and a portfolio of more complex resource solutions. Our specialist recruitment divisions cover the entire technical arena, including some of the most economically and strategically important industries in the UK and the world today. We will never send your CV without your permission. Where the role is marked as Outside IR35 in the advertisement this is subject to receipt of a final Status Determination Statement from the end Client and may be subject to change.
Coalfire is seeking a Senior Consultant to join their cybersecurity team in the United Kingdom. The role involves performing penetration testing on client applications and supporting infrastructure. You'll collaborate with project teams to assess security risks and deliver high-quality reports. With a flexible work model, you'll be part of a culture that prioritizes personal and professional growth. This position requires strong technical skills, at least 4 years of experience in application security or consulting, and expertise in various penetration testing methodologies.
Aug 22, 2026
Full time
Coalfire is seeking a Senior Consultant to join their cybersecurity team in the United Kingdom. The role involves performing penetration testing on client applications and supporting infrastructure. You'll collaborate with project teams to assess security risks and deliver high-quality reports. With a flexible work model, you'll be part of a culture that prioritizes personal and professional growth. This position requires strong technical skills, at least 4 years of experience in application security or consulting, and expertise in various penetration testing methodologies.
Senior/Principal Penetration Tester / Experienced Red Team Consultant Testing Team United Kingdom Remote working options Full Time About the role Rootshell Security is seeking an experienced Senior / Principal Penetration Tester / Red Team Consultant to join our rapidly expanding Offensive Security team. This role is suited to a highly capable security professional with extensive experience delivering complex penetration testing and adversary simulation engagements across a range of sectors, including critical national infrastructure, financial services, and government organisations. You will be responsible for delivering advanced Red Team operations, intelligence-led security assessments, and bespoke attack simulations that help our clients understand their true resilience against modern threat actors. The position involves a combination of remote engagements and on site client activities across the United Kingdom. Rootshell Security is an equal opportunity employer. We welcome and encourage diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability or veteran status. Please do not apply if you are based outside the UK and/or are not eligible to apply for UK Security Clearance. Role responsibilities Lead and deliver advanced penetration testing and Red Team engagements Conduct intelligence-led adversary emulation and attack simulation exercises Deliver engagements aligned to recognised frameworks including TIBER-EU, CBEST, DORA, GBEST and STAR-FS Perform threat led security assessments against complex enterprise environments Develop Red Team infrastructure, tooling, attack paths and operational plans Conduct phishing, social engineering and physical assessment activities where authorised Support pre sales activities including technical scoping and solution design Produce high-quality technical reports and executive level findings Contribute to the development of Rootshell Security methodologies, research and innovation Skills we are looking for Mandatory Requirements Must be eligible to apply for UK Security Clearance Must be permanently based within the United Kingdom Must have several years of provable commercial experience delivering Red Team engagements Excellent working knowledge of the MITRE ATT&CK Framework Demonstrable experience delivering engagements aligned to TIBER-EU, CBEST, DORA and other threat led testing frameworks Strong knowledge of adversary emulation, attack path development and operational security Excellent report writing and client communication skills Strong network, infrastructure, Active Directory and cloud attack experience Experience operating against Azure, AWS and hybrid enterprise environments Certifications Must hold or have previously held a recognised Red Team certification demonstrating advanced offensive security capability, Typically CREST or CyberScheme Currently holds or has held Team Leader certifications in either Infrastructure and/or Applications Currently holds professional title of Principal / Chartered or would be eligible to apply Social engineering and phishing operation experience Physical intrusion testing experience Threat intelligence and Purple Team experience Malware analysis or custom tooling development Experience briefing senior stakeholders and board level audiences Proficiency in Python, PowerShell or C# development Company benefits Long-term career progression opportunities Continuous technical and non-technical training Regular attendance at industry conferences, events and community meetups Exposure to a diverse range of engagements across multiple sectors Dedicated research and innovation time Opportunity to influence Rootshell's offensive security capabilities and methodologies Mentoring and career development from senior leadership Recognition and reward for innovation, technical excellence and client impact Equality, Diversity, and Inclusion at Rootshell Security We are committed to fostering an inclusive and diverse workplace where everyone is valued and respected. We believe that a diverse team drives innovation and excellence, and we welcome applications from individuals of all backgrounds, experiences, and perspectives. As a proud holder of the Bronze Award under the Defence Employer Recognition Scheme (ERS), we actively support the Armed Forces community, aligning with the principles of the Armed Forces Covenant. We recognise the valuable skills and experiences that service personnel, reservists, and veterans bring to the workplace and encourage them to apply. Rootshell Security is an equal opportunities employer. We do not discriminate based on age, disability, gender, gender identity, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sexual orientation, or any other characteristic protected by law. If you require any reasonable adjustments during the recruitment process, please let us know-we are happy to support you.
Aug 20, 2026
Full time
Senior/Principal Penetration Tester / Experienced Red Team Consultant Testing Team United Kingdom Remote working options Full Time About the role Rootshell Security is seeking an experienced Senior / Principal Penetration Tester / Red Team Consultant to join our rapidly expanding Offensive Security team. This role is suited to a highly capable security professional with extensive experience delivering complex penetration testing and adversary simulation engagements across a range of sectors, including critical national infrastructure, financial services, and government organisations. You will be responsible for delivering advanced Red Team operations, intelligence-led security assessments, and bespoke attack simulations that help our clients understand their true resilience against modern threat actors. The position involves a combination of remote engagements and on site client activities across the United Kingdom. Rootshell Security is an equal opportunity employer. We welcome and encourage diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability or veteran status. Please do not apply if you are based outside the UK and/or are not eligible to apply for UK Security Clearance. Role responsibilities Lead and deliver advanced penetration testing and Red Team engagements Conduct intelligence-led adversary emulation and attack simulation exercises Deliver engagements aligned to recognised frameworks including TIBER-EU, CBEST, DORA, GBEST and STAR-FS Perform threat led security assessments against complex enterprise environments Develop Red Team infrastructure, tooling, attack paths and operational plans Conduct phishing, social engineering and physical assessment activities where authorised Support pre sales activities including technical scoping and solution design Produce high-quality technical reports and executive level findings Contribute to the development of Rootshell Security methodologies, research and innovation Skills we are looking for Mandatory Requirements Must be eligible to apply for UK Security Clearance Must be permanently based within the United Kingdom Must have several years of provable commercial experience delivering Red Team engagements Excellent working knowledge of the MITRE ATT&CK Framework Demonstrable experience delivering engagements aligned to TIBER-EU, CBEST, DORA and other threat led testing frameworks Strong knowledge of adversary emulation, attack path development and operational security Excellent report writing and client communication skills Strong network, infrastructure, Active Directory and cloud attack experience Experience operating against Azure, AWS and hybrid enterprise environments Certifications Must hold or have previously held a recognised Red Team certification demonstrating advanced offensive security capability, Typically CREST or CyberScheme Currently holds or has held Team Leader certifications in either Infrastructure and/or Applications Currently holds professional title of Principal / Chartered or would be eligible to apply Social engineering and phishing operation experience Physical intrusion testing experience Threat intelligence and Purple Team experience Malware analysis or custom tooling development Experience briefing senior stakeholders and board level audiences Proficiency in Python, PowerShell or C# development Company benefits Long-term career progression opportunities Continuous technical and non-technical training Regular attendance at industry conferences, events and community meetups Exposure to a diverse range of engagements across multiple sectors Dedicated research and innovation time Opportunity to influence Rootshell's offensive security capabilities and methodologies Mentoring and career development from senior leadership Recognition and reward for innovation, technical excellence and client impact Equality, Diversity, and Inclusion at Rootshell Security We are committed to fostering an inclusive and diverse workplace where everyone is valued and respected. We believe that a diverse team drives innovation and excellence, and we welcome applications from individuals of all backgrounds, experiences, and perspectives. As a proud holder of the Bronze Award under the Defence Employer Recognition Scheme (ERS), we actively support the Armed Forces community, aligning with the principles of the Armed Forces Covenant. We recognise the valuable skills and experiences that service personnel, reservists, and veterans bring to the workplace and encourage them to apply. Rootshell Security is an equal opportunities employer. We do not discriminate based on age, disability, gender, gender identity, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sexual orientation, or any other characteristic protected by law. If you require any reasonable adjustments during the recruitment process, please let us know-we are happy to support you.
Our Vision & Products EverAI - Building the Future of AI Companionship One of the Top 15 Largest & Fastest-Growing AI Companies in the World 50 Million Users in 2 years - Help Us Reach 100M first, 500M next At EverAI, we're shaping what it means to connect with AI. With 50 million users and counting, we're not just building products - we're creating entirely new categories. Our flagship product is the world's largest AI companionship platform, redefining relationships for millions. It is governed by our proprietary moderation system, EverGuard - an internal AI designed to ensure everything we build is safe, ethical, and human-first. And we're only just getting started! Our Team We are an enthusiastic, passionate and hardworking team of 100 people. Our founding team has strong entrepreneurial experience building and scaling web products from 0 to IPO. Alexis Soulopoulos CEO 10+ years in Tech Executive Leadership Co-Founder Mad Paws Holdings (from 0 to IPO) Forbes 30 under 30 + Deloitte TechFast50 '22 & '23 Michael Monin Co-founder & CTO 10+ years as CTO / COO (web2/web3), 3 years in AI/LLM Serial-entrepreneur: MTK Digital (exited / 0->$20m revenue) and Zipchat (AI Chatbot for E-commerce brands) Thomas Lacroix Co-founder & CMO 8+ years in Customer Acquisition & E-commerce Growth Serial-entrepreneur: Curatible (sold to Blackstone) and MTK Digital (exited / 0->$20m revenue) Maruša Fasano CFO/Legal 25+ years in Finance, Strategy, M&A Ex-CFO/M& (exited to Blackstone) Ex-President of the (exited) (exited) Your Role As a Security Engineer, you will take ownership of protecting our product, our users, and our collaborators as we scale a fast-growing AI dating platform. You'll work hands-on across application security, risk & compliance, and security awareness (plus keeping an eye on AI-specific threats as our product line evolves). Given the nature of our product (AI-generated content, including NSFW) you'll play a key role in keeping both our systems and our users safe, with real ownership from day one. This is a hands-on role reporting directly to the Security Lead, with regular check-ins on priorities. Key Responsibilities Application Security Perform weekly code reviews to catch vulnerabilities before they ship Track, prioritize, and drive remediation of security vulnerabilities across the stack Coordinate external security audits and penetration tests, and follow through on findings Governance, Risk & Compliance (GRC) Maintain and evolve our risk register, mapping all company services and prioritizing what's exposed Support audit follow-up and keep GRC documentation up to date Security Awareness Communicate new threats to the team, document findings, and broadcast security updates company-wide Run phishing simulations and security training (via Riot) Monitoring & Coverage Own the monitoring of security channels and alerts, including weekend coverage, so nothing goes unanswered IT & Access Management Set up and secure new employee devices (MDM), manage access provisioning/deprovisioning AI Security Monitoring Keep an eye on emerging attack techniques targeting generative AI (prompt injection, jailbreaks, content filter bypass) Track security incidents and vulnerabilities disclosed by the third-party AI providers we rely on Your Qualifications Hard Skills Solid experience in application security (code review, vulnerability management) Experience coordinating or conducting penetration tests / security audits Comfortable shipping code and working with Git/GitHub workflows Scripting/automation skills Bonus: familiarity with AI/LLM security concepts (prompt injection, jailbreaking, adversarial testing) - this is still an emerging field, so curiosity matters more than proven experience Soft Skills Strong communication & collaborative skills (perfectly fluent in English) Goal-orientated, ownership and commitment Doer mindset - we are moving fast and we need people who can find the right balance between executing, planning and strategy Humble - willing to learn, open to feedback - you are comfortable working in an environment with products that are based on uncensored models and content Why EverAI? Exponential Growth: From 50M users in 2 years, to 100M next - and 500M beyond Track Record of Category-Creating Innovation: We consistently launch world-first AI applications - setting the pace, not following it Global Impact: Top-tier user growth, real-world adoption, and cultural relevance Proven Leadership: A senior team that's launched, scaled, and exited & IPO'd multiple scale ups - now fully focused on reshaping AI companionship Elite Remote Team: 100% remote and built to win - world-class talent from Tier 1 tech companies, with a culture of ownership, velocity, and radical creativity Ethical Core: Our AI ecosystem is governed by EverGuard, our proprietary AI moderation technology, ensuring responsible development at scale What We Offer Contract Type: We prefer B2B, but we're flexible, what matters is long-term commitment and impact Work From Anywhere: Fully remote. Choose the environment where you do your best work Paid Time Off: 4 weeks (20 working days) of PTO per year to recharge and reset Annual Gathering: A yearly in-person meetup to connect, brainstorm, and celebrate wins together Health & Wellness Support: Monthly allowance of100 USD for health insurance expenses & access to unlimited 1:1 sessions with psychologists and lifestyle experts through OpenUp (also available to up to three of your family members) Co-Working Space Budget: Work from a co-working space up to twice per month (35 EUR / 40 USD per visit) to stay inspired and connected Learning Budget: Dedicated funds to support your professional growth: courses, books, conferences, events, or certifications Company Laptop & Equipment: Laptop provided + monitor budget up to 250 USD + keyboard/mouse/mic/headphones budget up to 150 USD AI Tools Access: Premium access to ChatGPT, Cursor, Hugging Face, Claude Code, and any other tool needed to excel at your job, power your ideas and workflows Compensation: Our salary ranges are set based on role level, scope, location, and market data, and applied consistently regardless of candidate background or negotiation history. The final offer within the published range reflects assessed experience and scope Top Tier Talent Is Our Multiplier We're a fully remote group of A-players from Tier 1 tech, led by an exec team who've launched, scaled, and exited multiple companies. We move fast, and care deeply about what we build - and who we build it with. We're looking for exceptional talent ready to ship & distribute world-first AI products at scale, fast, and co-create with us this category-defining business.
Aug 19, 2026
Full time
Our Vision & Products EverAI - Building the Future of AI Companionship One of the Top 15 Largest & Fastest-Growing AI Companies in the World 50 Million Users in 2 years - Help Us Reach 100M first, 500M next At EverAI, we're shaping what it means to connect with AI. With 50 million users and counting, we're not just building products - we're creating entirely new categories. Our flagship product is the world's largest AI companionship platform, redefining relationships for millions. It is governed by our proprietary moderation system, EverGuard - an internal AI designed to ensure everything we build is safe, ethical, and human-first. And we're only just getting started! Our Team We are an enthusiastic, passionate and hardworking team of 100 people. Our founding team has strong entrepreneurial experience building and scaling web products from 0 to IPO. Alexis Soulopoulos CEO 10+ years in Tech Executive Leadership Co-Founder Mad Paws Holdings (from 0 to IPO) Forbes 30 under 30 + Deloitte TechFast50 '22 & '23 Michael Monin Co-founder & CTO 10+ years as CTO / COO (web2/web3), 3 years in AI/LLM Serial-entrepreneur: MTK Digital (exited / 0->$20m revenue) and Zipchat (AI Chatbot for E-commerce brands) Thomas Lacroix Co-founder & CMO 8+ years in Customer Acquisition & E-commerce Growth Serial-entrepreneur: Curatible (sold to Blackstone) and MTK Digital (exited / 0->$20m revenue) Maruša Fasano CFO/Legal 25+ years in Finance, Strategy, M&A Ex-CFO/M& (exited to Blackstone) Ex-President of the (exited) (exited) Your Role As a Security Engineer, you will take ownership of protecting our product, our users, and our collaborators as we scale a fast-growing AI dating platform. You'll work hands-on across application security, risk & compliance, and security awareness (plus keeping an eye on AI-specific threats as our product line evolves). Given the nature of our product (AI-generated content, including NSFW) you'll play a key role in keeping both our systems and our users safe, with real ownership from day one. This is a hands-on role reporting directly to the Security Lead, with regular check-ins on priorities. Key Responsibilities Application Security Perform weekly code reviews to catch vulnerabilities before they ship Track, prioritize, and drive remediation of security vulnerabilities across the stack Coordinate external security audits and penetration tests, and follow through on findings Governance, Risk & Compliance (GRC) Maintain and evolve our risk register, mapping all company services and prioritizing what's exposed Support audit follow-up and keep GRC documentation up to date Security Awareness Communicate new threats to the team, document findings, and broadcast security updates company-wide Run phishing simulations and security training (via Riot) Monitoring & Coverage Own the monitoring of security channels and alerts, including weekend coverage, so nothing goes unanswered IT & Access Management Set up and secure new employee devices (MDM), manage access provisioning/deprovisioning AI Security Monitoring Keep an eye on emerging attack techniques targeting generative AI (prompt injection, jailbreaks, content filter bypass) Track security incidents and vulnerabilities disclosed by the third-party AI providers we rely on Your Qualifications Hard Skills Solid experience in application security (code review, vulnerability management) Experience coordinating or conducting penetration tests / security audits Comfortable shipping code and working with Git/GitHub workflows Scripting/automation skills Bonus: familiarity with AI/LLM security concepts (prompt injection, jailbreaking, adversarial testing) - this is still an emerging field, so curiosity matters more than proven experience Soft Skills Strong communication & collaborative skills (perfectly fluent in English) Goal-orientated, ownership and commitment Doer mindset - we are moving fast and we need people who can find the right balance between executing, planning and strategy Humble - willing to learn, open to feedback - you are comfortable working in an environment with products that are based on uncensored models and content Why EverAI? Exponential Growth: From 50M users in 2 years, to 100M next - and 500M beyond Track Record of Category-Creating Innovation: We consistently launch world-first AI applications - setting the pace, not following it Global Impact: Top-tier user growth, real-world adoption, and cultural relevance Proven Leadership: A senior team that's launched, scaled, and exited & IPO'd multiple scale ups - now fully focused on reshaping AI companionship Elite Remote Team: 100% remote and built to win - world-class talent from Tier 1 tech companies, with a culture of ownership, velocity, and radical creativity Ethical Core: Our AI ecosystem is governed by EverGuard, our proprietary AI moderation technology, ensuring responsible development at scale What We Offer Contract Type: We prefer B2B, but we're flexible, what matters is long-term commitment and impact Work From Anywhere: Fully remote. Choose the environment where you do your best work Paid Time Off: 4 weeks (20 working days) of PTO per year to recharge and reset Annual Gathering: A yearly in-person meetup to connect, brainstorm, and celebrate wins together Health & Wellness Support: Monthly allowance of100 USD for health insurance expenses & access to unlimited 1:1 sessions with psychologists and lifestyle experts through OpenUp (also available to up to three of your family members) Co-Working Space Budget: Work from a co-working space up to twice per month (35 EUR / 40 USD per visit) to stay inspired and connected Learning Budget: Dedicated funds to support your professional growth: courses, books, conferences, events, or certifications Company Laptop & Equipment: Laptop provided + monitor budget up to 250 USD + keyboard/mouse/mic/headphones budget up to 150 USD AI Tools Access: Premium access to ChatGPT, Cursor, Hugging Face, Claude Code, and any other tool needed to excel at your job, power your ideas and workflows Compensation: Our salary ranges are set based on role level, scope, location, and market data, and applied consistently regardless of candidate background or negotiation history. The final offer within the published range reflects assessed experience and scope Top Tier Talent Is Our Multiplier We're a fully remote group of A-players from Tier 1 tech, led by an exec team who've launched, scaled, and exited multiple companies. We move fast, and care deeply about what we build - and who we build it with. We're looking for exceptional talent ready to ship & distribute world-first AI products at scale, fast, and co-create with us this category-defining business.
Cambridge University Press & Assessment
Cambridge, Cambridgeshire
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role. We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working. This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment. Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement. Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure. Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery. Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported. Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST. Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders. Support incident preparedness, including investigations and exercises that test our ability to respond effectively. Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation. This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition. About You We are looking for someone with extensive knowledge of 5+ year experience in security testing and assurance and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks and (e.g. ISO 27001, NIST) and risk management practices. You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing. You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management. You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously. If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria: Development and maintained a supply chain risk register within a similar sized organisation Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure Experience of reporting risks to senior leadership For a detailed job description, please refer to the link at the bottom of the advert on our careers site. We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition. Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for. Rewards and benefits We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including: 28 days annual leave plus bank holidays Private medical and Permanent Health Insurance Discretionary annual bonus Group personal pension scheme Life assurance up to 4 x annual salary Green travel schemes Ready to pursue your potential? Apply now. We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2 nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after. The application and interview process consists of: 3 role related questions with brief answers A 15-minute screening call with the Hiring Manager. First stage virtual interview via MS Teams. Final stage interview: in-person at our offices in Cambridge. If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs. Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry. We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter. Why join us Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe - for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration. Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
Aug 18, 2026
Full time
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role. We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working. This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment. Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement. Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure. Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery. Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported. Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST. Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders. Support incident preparedness, including investigations and exercises that test our ability to respond effectively. Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation. This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition. About You We are looking for someone with extensive knowledge of 5+ year experience in security testing and assurance and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks and (e.g. ISO 27001, NIST) and risk management practices. You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing. You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management. You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously. If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria: Development and maintained a supply chain risk register within a similar sized organisation Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure Experience of reporting risks to senior leadership For a detailed job description, please refer to the link at the bottom of the advert on our careers site. We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition. Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for. Rewards and benefits We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including: 28 days annual leave plus bank holidays Private medical and Permanent Health Insurance Discretionary annual bonus Group personal pension scheme Life assurance up to 4 x annual salary Green travel schemes Ready to pursue your potential? Apply now. We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2 nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after. The application and interview process consists of: 3 role related questions with brief answers A 15-minute screening call with the Hiring Manager. First stage virtual interview via MS Teams. Final stage interview: in-person at our offices in Cambridge. If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs. Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry. We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter. Why join us Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe - for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration. Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Aug 11, 2026
Full time
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement. As an Assessments & Exercises Vice President in the Penetration Testing team, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology. As part of the team, your primary responsibility will be performing hands on penetration testing of some of JPMC's most critical applications, platforms, and the perimeter. You will work with application developers to not only understand root cause and mitigate vulnerabilities, but also to identify where vulnerabilities can be identified earlier in the SDLC. Successful candidates are expected to demonstrate an eagerness to learn, the drive to excel, excellent technical knowledge of security concepts and proven expertise in penetration testing. Job responsibilities Design and execute testing and simulations - such as penetration tests and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm's strategy and compliance with regulatory requirements Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation Collaborate closely with cross-functional teams to develop comprehensive assessment reports - including detailed findings, risk assessments, and remediation recommendations - making data-driven decisions that encourage continuous improvement Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations. Apply this knowledge to enhance the firm's assessment strategy and risk management. Engage with peers and industry groups that share threat intelligence analytics Required qualifications, capabilities, and skills 5+ years of experience in conducting manual penetration tests against a wide variety of applications and technologies including web, mobile and thick clients, internal and external facing infrastructures, cloud Foundational knowledge of cybersecurity organization practices, operations, risk management processes, principles, architectural requirements, engineering and threats and vulnerabilities, including incident response methodologies Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels Preferred qualifications, capabilities, and skills Experience in testing Public cloud environments like AWS, Azure and GCP with proficiency in at least one platform. Experience in reverse engineering standalone, thick client and mobile applications. Proficiency in security concepts for both Windows and Unix-like Operating Systems. Experience in source code review and/or building software with multiple programming languages (i.e. Python, Java, Rust, etc.). Certifications like CREST (CRT, CCT), OSCP, OSCE, GXPN, GRE. ABOUT US J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives. We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation. ABOUT THE TEAM Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.
Aug 08, 2026
Full time
Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement. As an Assessments & Exercises Vice President in the Penetration Testing team, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology. As part of the team, your primary responsibility will be performing hands on penetration testing of some of JPMC's most critical applications, platforms, and the perimeter. You will work with application developers to not only understand root cause and mitigate vulnerabilities, but also to identify where vulnerabilities can be identified earlier in the SDLC. Successful candidates are expected to demonstrate an eagerness to learn, the drive to excel, excellent technical knowledge of security concepts and proven expertise in penetration testing. Job responsibilities Design and execute testing and simulations - such as penetration tests and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm's strategy and compliance with regulatory requirements Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation Collaborate closely with cross-functional teams to develop comprehensive assessment reports - including detailed findings, risk assessments, and remediation recommendations - making data-driven decisions that encourage continuous improvement Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations. Apply this knowledge to enhance the firm's assessment strategy and risk management. Engage with peers and industry groups that share threat intelligence analytics Required qualifications, capabilities, and skills 5+ years of experience in conducting manual penetration tests against a wide variety of applications and technologies including web, mobile and thick clients, internal and external facing infrastructures, cloud Foundational knowledge of cybersecurity organization practices, operations, risk management processes, principles, architectural requirements, engineering and threats and vulnerabilities, including incident response methodologies Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels Preferred qualifications, capabilities, and skills Experience in testing Public cloud environments like AWS, Azure and GCP with proficiency in at least one platform. Experience in reverse engineering standalone, thick client and mobile applications. Proficiency in security concepts for both Windows and Unix-like Operating Systems. Experience in source code review and/or building software with multiple programming languages (i.e. Python, Java, Rust, etc.). Certifications like CREST (CRT, CCT), OSCP, OSCE, GXPN, GRE. ABOUT US J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives. We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation. ABOUT THE TEAM Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.
Penetration Testing Specialist Permanent - £71k - £82k + strong benefits Location: Hybrid - South Wales Your new company: I am looking to recruit a Penetration Testing Specialist to join a leader in the utilities space. The business has been investing into their cyber security and IT estate and are continuing to grow and enhance their security posture click apply for full job details
Aug 01, 2026
Full time
Penetration Testing Specialist Permanent - £71k - £82k + strong benefits Location: Hybrid - South Wales Your new company: I am looking to recruit a Penetration Testing Specialist to join a leader in the utilities space. The business has been investing into their cyber security and IT estate and are continuing to grow and enhance their security posture click apply for full job details
Head of IT Operations Hounslow, London (Heathrow) - Fully On-Site 85,000 - 95,000 (c. 90,000) + Benefits Our client is a well-established, privately owned logistics and supply chain business, providing warehousing, fulfilment and distribution services to a broad client base. The business has an excellent track record of growth and continues to scale across its multi-site operation. We're recruiting a Head of IT Operations to own the reliability, security and day-to-day operation of the company's IT environment across all sites. This is a genuinely strategic role (not a helpdesk or ticketing function) covering infrastructure, networks, cyber-security, resilience and end-user support, distinct from the company's separate software/platform engineering team. Reporting into senior leadership, you'll take ownership of: Infrastructure, network & hardware lifecycle across all sites Cyber-security strategy, risk & compliance (including ISO frameworks and penetration testing) System uptime, resilience & business continuity / disaster recovery Cloud infrastructure strategy and future technology roadmap End-user IT support and service standards Vendor management and IT operational budget Building and leading a dependable, well-organised IT operations team What We're Looking For Senior experience leading IT operations, infrastructure and security in a mission-critical, multi-site environment Strong knowledge of networks, cloud infrastructure and cyber-security A proven track record running dependable, well-governed IT operations Experience in multi-site, warehouse or operational environments is an advantage Exposure to ISO frameworks / formal security certifications is an advantage You will be based full-time on-site at the company's Hounslow, London office (close to Heathrow), Monday to Friday, with occasional travel to the business's other UK and European sites. This is a hands-on role in a fast-paced, live operational business - full-time office presence is essential. This is a genuine leadership opportunity in a high-growth business, with a clear path to Director-level as the role and impact grow over time. You'll have real influence over IT strategy and be a key partner to the senior leadership team - not simply managing a support desk. Suitable candidates may have experience as: Head of IT, IT Director, Head of IT Infrastructure, IT Infrastructure Manager, Head of IT Operations, IT Operations Manager, IT Operations Director, Head of Infrastructure & Security, Group IT Manager, Head of IT Services, IT Service Delivery Manager, Head of Technology Operations, Network & Infrastructure Manager, IT Manager. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate 1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
Jul 31, 2026
Full time
Head of IT Operations Hounslow, London (Heathrow) - Fully On-Site 85,000 - 95,000 (c. 90,000) + Benefits Our client is a well-established, privately owned logistics and supply chain business, providing warehousing, fulfilment and distribution services to a broad client base. The business has an excellent track record of growth and continues to scale across its multi-site operation. We're recruiting a Head of IT Operations to own the reliability, security and day-to-day operation of the company's IT environment across all sites. This is a genuinely strategic role (not a helpdesk or ticketing function) covering infrastructure, networks, cyber-security, resilience and end-user support, distinct from the company's separate software/platform engineering team. Reporting into senior leadership, you'll take ownership of: Infrastructure, network & hardware lifecycle across all sites Cyber-security strategy, risk & compliance (including ISO frameworks and penetration testing) System uptime, resilience & business continuity / disaster recovery Cloud infrastructure strategy and future technology roadmap End-user IT support and service standards Vendor management and IT operational budget Building and leading a dependable, well-organised IT operations team What We're Looking For Senior experience leading IT operations, infrastructure and security in a mission-critical, multi-site environment Strong knowledge of networks, cloud infrastructure and cyber-security A proven track record running dependable, well-governed IT operations Experience in multi-site, warehouse or operational environments is an advantage Exposure to ISO frameworks / formal security certifications is an advantage You will be based full-time on-site at the company's Hounslow, London office (close to Heathrow), Monday to Friday, with occasional travel to the business's other UK and European sites. This is a hands-on role in a fast-paced, live operational business - full-time office presence is essential. This is a genuine leadership opportunity in a high-growth business, with a clear path to Director-level as the role and impact grow over time. You'll have real influence over IT strategy and be a key partner to the senior leadership team - not simply managing a support desk. Suitable candidates may have experience as: Head of IT, IT Director, Head of IT Infrastructure, IT Infrastructure Manager, Head of IT Operations, IT Operations Manager, IT Operations Director, Head of Infrastructure & Security, Group IT Manager, Head of IT Services, IT Service Delivery Manager, Head of Technology Operations, Network & Infrastructure Manager, IT Manager. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate 1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
Ultramink Technologies is seeking a seasoned professional to lead security engagements for mid-market enterprises across Europe. The role involves conducting security assessments, designing security architectures, and helping clients build security programs that align with regulatory requirements. The ideal candidate will have over 8 years of experience in information security and will possess deep expertise in penetration testing and compliance frameworks like SOC 2 and GDPR. The position offers a remote-first work model with various benefits.
Jul 31, 2026
Full time
Ultramink Technologies is seeking a seasoned professional to lead security engagements for mid-market enterprises across Europe. The role involves conducting security assessments, designing security architectures, and helping clients build security programs that align with regulatory requirements. The ideal candidate will have over 8 years of experience in information security and will possess deep expertise in penetration testing and compliance frameworks like SOC 2 and GDPR. The position offers a remote-first work model with various benefits.
Penetration Testing Specialist Permanent - 71k - 82k + strong benefits Location: Hybrid - South Wales Your new company: I am looking to recruit a Penetration Testing Specialist to join a leader in the utilities space. The business has been investing into their cyber security and IT estate and are continuing to grow and enhance their security posture. The company has a strong reputation, and we have placed numerous people into careers there, with strong feedback. The role responsibilities: This is an interesting time to join the company. Lots of investment into their IT, OT, and Cyber Security functions over the last few years, with ongoing investment and growth happening. This is a key role. They're looking for someone who's inquisitive, experienced, and willing to safely get access into almost anything. Key parts of the role: Define and manage the penetration testing schedule. Conduct internal penetration testing of applications and systems Manage external vendors providing penetration services and arrange and schedule their work. Proactively research vulnerabilities in external and internal-facing systems and infrastructure (IT and OT) Social engineering Proactively research internal and external information leakage that may assist malicious actors in preparing for or executing an attack Prepare detailed reporting on vulnerabilities and the remedial actions recommended Accurately quantify discovered vulnerabilities in risk terms. You will need: Strong understanding of penetration testing principles, methodologies and tooling with proven experience of delivering infrastructure and application penetration tests safely and efficiently Strong understanding of safe approaches required for OT testing and proven experience of OT security assurance testing Strong understanding of attacker TTPs & vulnerability assessment Strong understanding of security risk assessment and risk management concepts and approaches Ability to work on your own initiative and to think "outside the box" Experience with operational technology in the utilities sector or other industrial CNI environments will be highly advantageous Excellent communication and interpersonal skills. Ability to obtain UK Security Clearance CREST / CHECK certification (essential) What you'll get in return: Salary of between 71k- 82k Hybrid working 2/3 days in South Wales per week Possible bonus 5% pension contribution from you, the company pays 10% Enhanced pay for parental leave And more! Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Jul 31, 2026
Full time
Penetration Testing Specialist Permanent - 71k - 82k + strong benefits Location: Hybrid - South Wales Your new company: I am looking to recruit a Penetration Testing Specialist to join a leader in the utilities space. The business has been investing into their cyber security and IT estate and are continuing to grow and enhance their security posture. The company has a strong reputation, and we have placed numerous people into careers there, with strong feedback. The role responsibilities: This is an interesting time to join the company. Lots of investment into their IT, OT, and Cyber Security functions over the last few years, with ongoing investment and growth happening. This is a key role. They're looking for someone who's inquisitive, experienced, and willing to safely get access into almost anything. Key parts of the role: Define and manage the penetration testing schedule. Conduct internal penetration testing of applications and systems Manage external vendors providing penetration services and arrange and schedule their work. Proactively research vulnerabilities in external and internal-facing systems and infrastructure (IT and OT) Social engineering Proactively research internal and external information leakage that may assist malicious actors in preparing for or executing an attack Prepare detailed reporting on vulnerabilities and the remedial actions recommended Accurately quantify discovered vulnerabilities in risk terms. You will need: Strong understanding of penetration testing principles, methodologies and tooling with proven experience of delivering infrastructure and application penetration tests safely and efficiently Strong understanding of safe approaches required for OT testing and proven experience of OT security assurance testing Strong understanding of attacker TTPs & vulnerability assessment Strong understanding of security risk assessment and risk management concepts and approaches Ability to work on your own initiative and to think "outside the box" Experience with operational technology in the utilities sector or other industrial CNI environments will be highly advantageous Excellent communication and interpersonal skills. Ability to obtain UK Security Clearance CREST / CHECK certification (essential) What you'll get in return: Salary of between 71k- 82k Hybrid working 2/3 days in South Wales per week Possible bonus 5% pension contribution from you, the company pays 10% Enhanced pay for parental leave And more! Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Graduate Cyber Security Consultant & Penetration Tester Location: Bristol, UK (Office-based) Type: Full-Time About Us We are working with a leading UK technology firm providing specialist consultancy across high-impact and critical sectors. They are looking to onboard an ambitious graduate to join their expert team, offering full training and direct mentorship from industry leaders. The Role This entry-level position is designed for recent graduates looking to launch a career in cybersecurity. You will work on site at the Bristol office, assisting clients in identifying, mitigating, and managing security risks while receiving structured development to accelerate your growth. Key Responsibilities Conduct security assessments, vulnerability scans, and supervised penetration testing. Analyze technical risks and produce detailed reports with actionable recommendations. Communicate findings and security advice clearly to clients. Assist with incident response procedures and stay up to date with compliance standards. Continuously expand your knowledge of emerging cybersecurity tools and techniques. What We're Looking For Education: A Bachelor s degree, preferably in a STEM discipline. Skills: Strong analytical, problem-solving, and communication skills. Mindset: A strong passion for information security and a high willingness to learn. Bonus: Relevant certifications or internships are a plus, but not required. What s on Offer Competitive salary and performance incentives Mentorship, career guidance, and funding for professional certifications Hands-on experience with advanced tools on challenging projects A collaborative and supportive team environment
Jul 31, 2026
Full time
Graduate Cyber Security Consultant & Penetration Tester Location: Bristol, UK (Office-based) Type: Full-Time About Us We are working with a leading UK technology firm providing specialist consultancy across high-impact and critical sectors. They are looking to onboard an ambitious graduate to join their expert team, offering full training and direct mentorship from industry leaders. The Role This entry-level position is designed for recent graduates looking to launch a career in cybersecurity. You will work on site at the Bristol office, assisting clients in identifying, mitigating, and managing security risks while receiving structured development to accelerate your growth. Key Responsibilities Conduct security assessments, vulnerability scans, and supervised penetration testing. Analyze technical risks and produce detailed reports with actionable recommendations. Communicate findings and security advice clearly to clients. Assist with incident response procedures and stay up to date with compliance standards. Continuously expand your knowledge of emerging cybersecurity tools and techniques. What We're Looking For Education: A Bachelor s degree, preferably in a STEM discipline. Skills: Strong analytical, problem-solving, and communication skills. Mindset: A strong passion for information security and a high willingness to learn. Bonus: Relevant certifications or internships are a plus, but not required. What s on Offer Competitive salary and performance incentives Mentorship, career guidance, and funding for professional certifications Hands-on experience with advanced tools on challenging projects A collaborative and supportive team environment
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London Secure SDLC SAST DAST Threat Modelling Cloud Security CI/CD Location: London (Hybrid - 8 days onsite per month) Contract: 12 Months + extension Rate: 500- 550 per day (Umbrella) The Opportunity We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment. Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely. This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment. Key Responsibilities Lead application security reviews across business-critical applications and cloud platforms. Conduct security architecture and secure design reviews. Perform application security risk assessments and define security requirements. Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies. Embed Secure SDLC principles into engineering teams. Integrate security tooling into CI/CD pipelines and DevSecOps processes. Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings. Work closely with development teams to prioritise vulnerability remediation. Define security testing requirements and support penetration testing activities. Produce security standards, technical guidance and best practice documentation. Act as the Application Security SME across multiple technology programmes. Essential Skills Application Security Secure Software Development Lifecycle (SSDLC) OWASP Top 10 Secure Coding Secure Design Reviews API Security REST APIs Microservices Security Application Security Risk Assessments Threat Modelling STRIDE MITRE ATT&CK Security Architecture Risk Assessments DevSecOps CI/CD Security GitHub Actions GitLab Jenkins Azure DevOps Security Automation Shift Left Security Security Testing SAST DAST SCA Vulnerability Management Penetration Testing Cloud Security AWS, Azure or GCP Kubernetes Docker Container Security Cloud Security Best Practices Security Tooling Experience with one or more of: Checkmarx Fortify SonarQube Veracode Semgrep Burp Suite OWASP ZAP Snyk Trivy Prisma Cloud Aqua Wiz Ideal Background You'll ideally have: 8+ years in Cyber Security Strong Application Security or DevSecOps experience Experience working directly with software engineering teams Experience embedding security into CI/CD pipelines Strong knowledge of Secure SDLC Experience conducting Threat Modelling sessions Excellent stakeholder management and communication skills Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment Contract Details 12-month contract 500- 600 per day (Umbrella) Hybrid working - 8 days onsite per month in London Immediate interview availability preferred Rates depend on experience and client requirements
Jul 31, 2026
Contractor
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London Secure SDLC SAST DAST Threat Modelling Cloud Security CI/CD Location: London (Hybrid - 8 days onsite per month) Contract: 12 Months + extension Rate: 500- 550 per day (Umbrella) The Opportunity We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment. Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely. This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment. Key Responsibilities Lead application security reviews across business-critical applications and cloud platforms. Conduct security architecture and secure design reviews. Perform application security risk assessments and define security requirements. Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies. Embed Secure SDLC principles into engineering teams. Integrate security tooling into CI/CD pipelines and DevSecOps processes. Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings. Work closely with development teams to prioritise vulnerability remediation. Define security testing requirements and support penetration testing activities. Produce security standards, technical guidance and best practice documentation. Act as the Application Security SME across multiple technology programmes. Essential Skills Application Security Secure Software Development Lifecycle (SSDLC) OWASP Top 10 Secure Coding Secure Design Reviews API Security REST APIs Microservices Security Application Security Risk Assessments Threat Modelling STRIDE MITRE ATT&CK Security Architecture Risk Assessments DevSecOps CI/CD Security GitHub Actions GitLab Jenkins Azure DevOps Security Automation Shift Left Security Security Testing SAST DAST SCA Vulnerability Management Penetration Testing Cloud Security AWS, Azure or GCP Kubernetes Docker Container Security Cloud Security Best Practices Security Tooling Experience with one or more of: Checkmarx Fortify SonarQube Veracode Semgrep Burp Suite OWASP ZAP Snyk Trivy Prisma Cloud Aqua Wiz Ideal Background You'll ideally have: 8+ years in Cyber Security Strong Application Security or DevSecOps experience Experience working directly with software engineering teams Experience embedding security into CI/CD pipelines Strong knowledge of Secure SDLC Experience conducting Threat Modelling sessions Excellent stakeholder management and communication skills Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment Contract Details 12-month contract 500- 600 per day (Umbrella) Hybrid working - 8 days onsite per month in London Immediate interview availability preferred Rates depend on experience and client requirements