• Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
  • Sign in
  • Sign up
  • Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

73 jobs found

Email me jobs like this
Refine Search
Current Search
cyber defence analyst
Cyber Defence Engineer
Plannedlink
West Midlands, United Kingdom Posted on 21/03/2025 The Cyber Defence Engineer will join agrowing security team responsible for the testing, implementation, deployment,maintenance, configuration and troubleshooting of the SOC's technology stack(hardware and software). The engineer will also assist with the continueddevelopment and maintenance of data pipelines and signature updates and theprofessional development of the system engineering team. Tasks: Perform systemadministration on specific cyber defence applications and systems to includeinstallation, configuration, maintenance, troubleshooting, backup, andrestoration. Manage system/serverresources including performance, capacity, availability, serviceability, andrecoverability. Diagnose and resolvecustomer reported system incidents, problems, and events to ensure continuingoperability. Coordinatewith Cyber Defence and CTI Analysts in the management and administration theupdating of ingested data flows, cyber use cases and signatures for specialisedcyber defence applications in response to new or observed threats. Manage the compilation,cataloguing, distribution, and retrieval of data from a range of enterprisenetworks and data sources. Implement and develop datamanagement standards, policies, requirements, and specifications. Analyse data sources toprovide actionable recommendations and facilitate data-gathering methods. Provide updates to the SOC Leads (Line Management,Team Leaders) on current SOC investigations and findings. Share knowledge, skills,and experience, by documenting SOC processes to aid to aid SOC maturity and trainingof new members of the data engineering team. Requirements Knowledge: A demonstrablenetworking background - experience in system administration. Knowledge of big datatechnologies and ecosystems (e.g. Apache NiFi). Knowledge of currentmarket and emerging tools in data analytical and SIEM platforms. Knowledgeof network security implementations (e.g., IDS, IPS, EDR), including theirfunction and placement in an enterprise network. Knowledgeof intrusion detection systems and signature development. Knowledge of front-endcollection systems, including network traffic collection, filtering, andselection. Knowledge of cyber security threats,vulnerabilities, and privacy principles. Working knowledge inconfigurating collection sensors for enterprise networks. Knowledgeof system administration concepts for operating systems such as but not limitedto Linux, Android, and Windows operating systems. Knowledge of cyberdefence and information security policies, procedures, and regulations. Knowledge of networksecurity architecture concepts including topology, protocols, components, andprinciples. Knowledgeof cyber incident response frameworks and handling methodologies. Knowledge of data backup andrecovery. Skills/Experience: Must-have - circa5 years + relevant experience. Must-have experience withEnterprise ICS/network architectures and technologies. Must-have experience withframeworks and technologies that support data-intensive distributedapplications. Must-have experience withmaintaining and administrating data analytical and SIEM platforms such asElastic. Must-have experience with problemsolving and analytical skills and able to collect information, analyse, report,and advise on evidence-based changes. Skillto apply cybersecurityand privacy principles to organizational requirements (relevant toconfidentiality, integrity, availability, authentication, non-repudiation). Stakeholder management - Expert ability tocommunicate to all levels of the organisation on technical, and non-technicallevel. Experience using hostand network-based IDS/IPS Experience using packetcapture solutions. Skill indeveloping and deploying signatures. Abilityto provide technical and service leadership to junior SOC Engineers(mentor/coach). DesirableQualifications/Certifications Red Hat SystemAdministration I & II (RH124/RH134). Knowledge of virtualisation technologiessuch as VMWare and HyperV. Proventrack record and experience in developing cyber security policies andprocedures, as well as successfully producing deliverables to meetorganisational objectives. Abilityto work calmly and effectively under pressure and have a can-do attitude. Broadcyber certifications or equivalent such as Cyber Foundation Pathway, CompTIA(N+, S+, CySA+), SANS (GSEC, GCIH, GMON, GCDA), Systems Administrations (ActiveDirectory), CISCO (CCNA, CCNP) and risk management. Working knowledge of Defence Joint Service Publications (440, 441,604).
Sep 23, 2026
Full time
West Midlands, United Kingdom Posted on 21/03/2025 The Cyber Defence Engineer will join agrowing security team responsible for the testing, implementation, deployment,maintenance, configuration and troubleshooting of the SOC's technology stack(hardware and software). The engineer will also assist with the continueddevelopment and maintenance of data pipelines and signature updates and theprofessional development of the system engineering team. Tasks: Perform systemadministration on specific cyber defence applications and systems to includeinstallation, configuration, maintenance, troubleshooting, backup, andrestoration. Manage system/serverresources including performance, capacity, availability, serviceability, andrecoverability. Diagnose and resolvecustomer reported system incidents, problems, and events to ensure continuingoperability. Coordinatewith Cyber Defence and CTI Analysts in the management and administration theupdating of ingested data flows, cyber use cases and signatures for specialisedcyber defence applications in response to new or observed threats. Manage the compilation,cataloguing, distribution, and retrieval of data from a range of enterprisenetworks and data sources. Implement and develop datamanagement standards, policies, requirements, and specifications. Analyse data sources toprovide actionable recommendations and facilitate data-gathering methods. Provide updates to the SOC Leads (Line Management,Team Leaders) on current SOC investigations and findings. Share knowledge, skills,and experience, by documenting SOC processes to aid to aid SOC maturity and trainingof new members of the data engineering team. Requirements Knowledge: A demonstrablenetworking background - experience in system administration. Knowledge of big datatechnologies and ecosystems (e.g. Apache NiFi). Knowledge of currentmarket and emerging tools in data analytical and SIEM platforms. Knowledgeof network security implementations (e.g., IDS, IPS, EDR), including theirfunction and placement in an enterprise network. Knowledgeof intrusion detection systems and signature development. Knowledge of front-endcollection systems, including network traffic collection, filtering, andselection. Knowledge of cyber security threats,vulnerabilities, and privacy principles. Working knowledge inconfigurating collection sensors for enterprise networks. Knowledgeof system administration concepts for operating systems such as but not limitedto Linux, Android, and Windows operating systems. Knowledge of cyberdefence and information security policies, procedures, and regulations. Knowledge of networksecurity architecture concepts including topology, protocols, components, andprinciples. Knowledgeof cyber incident response frameworks and handling methodologies. Knowledge of data backup andrecovery. Skills/Experience: Must-have - circa5 years + relevant experience. Must-have experience withEnterprise ICS/network architectures and technologies. Must-have experience withframeworks and technologies that support data-intensive distributedapplications. Must-have experience withmaintaining and administrating data analytical and SIEM platforms such asElastic. Must-have experience with problemsolving and analytical skills and able to collect information, analyse, report,and advise on evidence-based changes. Skillto apply cybersecurityand privacy principles to organizational requirements (relevant toconfidentiality, integrity, availability, authentication, non-repudiation). Stakeholder management - Expert ability tocommunicate to all levels of the organisation on technical, and non-technicallevel. Experience using hostand network-based IDS/IPS Experience using packetcapture solutions. Skill indeveloping and deploying signatures. Abilityto provide technical and service leadership to junior SOC Engineers(mentor/coach). DesirableQualifications/Certifications Red Hat SystemAdministration I & II (RH124/RH134). Knowledge of virtualisation technologiessuch as VMWare and HyperV. Proventrack record and experience in developing cyber security policies andprocedures, as well as successfully producing deliverables to meetorganisational objectives. Abilityto work calmly and effectively under pressure and have a can-do attitude. Broadcyber certifications or equivalent such as Cyber Foundation Pathway, CompTIA(N+, S+, CySA+), SANS (GSEC, GCIH, GMON, GCDA), Systems Administrations (ActiveDirectory), CISCO (CCNA, CCNP) and risk management. Working knowledge of Defence Joint Service Publications (440, 441,604).
Director / Principal, Geopolitical & Country Risk
PoliticalRiskJobs.com
Control Risks supports private equity and credit, infrastructure and real assets, real estate, sovereign wealth, and development and multilateral funds, with a range of consulting services. These include transaction-specific diligence, encompassing sector- or country-specific political and policy risk intelligence and advisory, as well as assessments focusing on financial crime, reputation and performance, material ESG factors, and cyber risks associated with an investment target and its management. We also provide broader proactive and reactive risk management services for our client's portfolio companies and assets. The successful candidate would join a leading geopolitical and political risk intelligence and advisory team, with over 100 analysts and consultants around the globe. Moreover, the successful applicant would be expected to work very closely with other practice areas in Control Risks, particularly with colleagues from our Intelligence & Investigations team. The role is central to delivering our growth objectives related to private markets investors with Europe coverage. This role is responsible for leading the implementation of our strategy with private markets investors in the UK and Western Europe more broadly to position Control Risks as a leading advisor on political, regulatory and policy risk to private market clients. Role Tasks And Responsibilities Client management and business development Refine and implement our private markets business development campaign to position Control Risks as a specialist provider of policy and regulatory diligence Identify and acquire new points of contact with new and existing clients, and manage these relationships to best meet our client's requirements for both transaction and portfolio company support. Achieving year-on-year growth in our client base, and increase the number, diversity and complexity of our mandates. Develop our relationships with industry associations and professional advisors, and evaluate the best events and networks to engage, to raise awareness of our brand and services among private market investors. Develop and maintain a public profile in the industry as an expert in your specialist field through public speaking and written thought leadership. Case and project work Ensure our proposals focus on our clients' requirements and our ability to meet them, and that our proposals stay ahead of the market by incorporating clients' feedback and service innovation. Lead more complicated engagements for private markets investors, drawing in Control Risks' expertise from different practices as required. Build and maintain policy/regulatory monitoring across priority jurisdictions, particularly the UK, and sectors relevant to our clients. Develop and manage a human source and subcontractor network to support the growth of the practice and the delivery of our work. Align closely with colleagues working on the region to expand our source and subcontractor networks to meet market demand. Working culture Foster an inclusive, collaborative environment between practice areas, offices and regions. Coordinate closely with the Head of Private Markets and Financial Sponsors, as well as other colleagues with a private markets investor remit. Ensure that pricing, margins, value of our work and strategic objectives regarding the buyer group are understood in the team to grow our client base and deliver on revenue and profit targets. Requirements Demonstrated experience advising investors on UK and EU policy and regulatory change and related commercial impacts, including a strong ability to communicate clear recommendations to clients, even under time pressure. Experience with supporting clients on highly regulated, policy-sensitive sectors, such as energy, infrastructure, defence, telecoms, healthcare/life sciences, financial services and/or digital technologies. Ability to source information on the evolution of policy, regulation and enforcement trends, to interpret regulation and enforcement guidance, including at draft stages and to translate findings into actionable intelligence for our clients. Access to a large network of reliable, credible sources in policy circles in the UK, specific European markets and/or Brussels. Achieving and sustaining trusted advisor relationships with senior-decision makers within the defined buyer group Identifying and growing new client relationships, and growing a practice area around this. Innovating services and successfully taking these to clients. Demonstrating in-depth knowledge and understanding of political, economic, societal, regulatory and technology trends affecting private markets investors and their risk considerations. Master's degree or equivalent 10 years of full-time professional experience in winning and delivering political risk or policy and regulatory focused advisory work Professional experience in private markets, investment banking, or corporate M&A Willingness to travel. Benefits Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarised in the full job offer. We operate a discretionary global bonus scheme that incentivises, and rewards individuals based on company and individual performance. Control Risks supports hybrid working arrangements, wherever possible, that emphasise the value of in-person time together - in the office and with our clients - while continuing to support flexible and remote working. As an equal opportunities employer, we encourage suitably qualified applicants from a wide range of backgrounds to apply and join us and are fully committed to equal treatment, free from discrimination, of all candidates throughout our recruitment process. If you require any reasonable adjustments to be made in order to participate fully in the interview process, please let us know and we will be happy to accommodate your needs.
Sep 23, 2026
Full time
Control Risks supports private equity and credit, infrastructure and real assets, real estate, sovereign wealth, and development and multilateral funds, with a range of consulting services. These include transaction-specific diligence, encompassing sector- or country-specific political and policy risk intelligence and advisory, as well as assessments focusing on financial crime, reputation and performance, material ESG factors, and cyber risks associated with an investment target and its management. We also provide broader proactive and reactive risk management services for our client's portfolio companies and assets. The successful candidate would join a leading geopolitical and political risk intelligence and advisory team, with over 100 analysts and consultants around the globe. Moreover, the successful applicant would be expected to work very closely with other practice areas in Control Risks, particularly with colleagues from our Intelligence & Investigations team. The role is central to delivering our growth objectives related to private markets investors with Europe coverage. This role is responsible for leading the implementation of our strategy with private markets investors in the UK and Western Europe more broadly to position Control Risks as a leading advisor on political, regulatory and policy risk to private market clients. Role Tasks And Responsibilities Client management and business development Refine and implement our private markets business development campaign to position Control Risks as a specialist provider of policy and regulatory diligence Identify and acquire new points of contact with new and existing clients, and manage these relationships to best meet our client's requirements for both transaction and portfolio company support. Achieving year-on-year growth in our client base, and increase the number, diversity and complexity of our mandates. Develop our relationships with industry associations and professional advisors, and evaluate the best events and networks to engage, to raise awareness of our brand and services among private market investors. Develop and maintain a public profile in the industry as an expert in your specialist field through public speaking and written thought leadership. Case and project work Ensure our proposals focus on our clients' requirements and our ability to meet them, and that our proposals stay ahead of the market by incorporating clients' feedback and service innovation. Lead more complicated engagements for private markets investors, drawing in Control Risks' expertise from different practices as required. Build and maintain policy/regulatory monitoring across priority jurisdictions, particularly the UK, and sectors relevant to our clients. Develop and manage a human source and subcontractor network to support the growth of the practice and the delivery of our work. Align closely with colleagues working on the region to expand our source and subcontractor networks to meet market demand. Working culture Foster an inclusive, collaborative environment between practice areas, offices and regions. Coordinate closely with the Head of Private Markets and Financial Sponsors, as well as other colleagues with a private markets investor remit. Ensure that pricing, margins, value of our work and strategic objectives regarding the buyer group are understood in the team to grow our client base and deliver on revenue and profit targets. Requirements Demonstrated experience advising investors on UK and EU policy and regulatory change and related commercial impacts, including a strong ability to communicate clear recommendations to clients, even under time pressure. Experience with supporting clients on highly regulated, policy-sensitive sectors, such as energy, infrastructure, defence, telecoms, healthcare/life sciences, financial services and/or digital technologies. Ability to source information on the evolution of policy, regulation and enforcement trends, to interpret regulation and enforcement guidance, including at draft stages and to translate findings into actionable intelligence for our clients. Access to a large network of reliable, credible sources in policy circles in the UK, specific European markets and/or Brussels. Achieving and sustaining trusted advisor relationships with senior-decision makers within the defined buyer group Identifying and growing new client relationships, and growing a practice area around this. Innovating services and successfully taking these to clients. Demonstrating in-depth knowledge and understanding of political, economic, societal, regulatory and technology trends affecting private markets investors and their risk considerations. Master's degree or equivalent 10 years of full-time professional experience in winning and delivering political risk or policy and regulatory focused advisory work Professional experience in private markets, investment banking, or corporate M&A Willingness to travel. Benefits Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarised in the full job offer. We operate a discretionary global bonus scheme that incentivises, and rewards individuals based on company and individual performance. Control Risks supports hybrid working arrangements, wherever possible, that emphasise the value of in-person time together - in the office and with our clients - while continuing to support flexible and remote working. As an equal opportunities employer, we encourage suitably qualified applicants from a wide range of backgrounds to apply and join us and are fully committed to equal treatment, free from discrimination, of all candidates throughout our recruitment process. If you require any reasonable adjustments to be made in order to participate fully in the interview process, please let us know and we will be happy to accommodate your needs.
AI & Automation Engineering, Global Security (Vice President)
Jefferies
Jefferies, the global investment banking firm, has served companies and investors for almost 60 years. Headquartered in New York with its European head office in London, the firm provides clients with capital markets and financial advisory services, institutional brokerage and securities research, and asset management. Jefferies provides research and execution services in equity, fixed income, foreign exchange, and a full range of investment banking services including underwriting, merger & acquisition, restructuring and recapitalisation and other advisory services, with businesses operating in the Americas, Europe and Asia. Company Jefferies, the global investment banking firm, has served companies and investors for almost 60 years. Headquartered in New York with its European head office in London, the firm provides clients with capital markets and financial advisory services, institutional brokerage and securities research, and asset management. Jefferies provides research and execution services in equity, fixed income, foreign exchange, and a full range of investment banking services including underwriting, merger & acquisition, restructuring and recapitalisation and other advisory services, with businesses operating in the Americas, Europe and Asia. Job Description Global Information Security is building internal engineering capability to apply generative AI and automation across the security function. This is a senior hands-on engineering role supporting both the Security Operations Centre and the wider security domains: identity, privileged access, network and cloud security, data protection, and vulnerability management. The position is London-anchored to provide global coverage across the APAC afternoon and Americas morning. This is an engineering role: we are looking for a software engineer who has shipped AI-backed systems in production and can own them as services. Key Responsibilities Design, build and operate AI-assisted automation services across the security function, owning them as production services with testing, monitoring, alerting, error handling and rollback. Deliver automation supporting security operations, including alert triage and enrichment, case summarisation, evidence collection, detection tuning, threat intelligence synthesis, and repetitive investigative workflows. Partner with pillar leads to deliver AI and automation capability across the wider security domains, including access review and certification support, entitlement analysis and role mining, privileged session analysis and PAM onboarding, posture finding triage, firewall and segmentation rule rationalisation, configuration drift detection, data classification and DLP event triage, and vulnerability prioritisation and contextualisation. Develop LLM and agent-based workflows integrated with SIEM, EDR, SOAR, IGA, PAM, CSPM, DLP, ticketing and threat intelligence platforms via supported APIs. Set the global AI Security and automation roadmap in partnership with the Head of Cyber Operations and pillar leads; arbitrate competing demand across domains and determine which workflows warrant automation and which do not. Establish engineering standards for AI-assisted tooling across the security organisation in partnership with the Head of App & AI Security, covering prompt and tool-definition review, agent permission scoping, and output validation. Engineer guardrails as a primary requirement: least-privilege service identities, human-in-the-loop checkpoints for consequential actions, full audit logging of agent decisions, and defences against prompt injection and tool-definition poisoning. Build reusable platform components, shared integration patterns, evaluation harnesses, prompt and tool libraries so capability compounds across domains rather than being rebuilt for each team. Define and report measures of effectiveness, including analyst and engineer time recovered, cycle time, and quality and error rates. Mentor engineers in the Pune capability centre as automation delivery scales and document to a standard supportable by a follow-the-sun team. Required Qualifications 8+ years professional software engineering with production ownership. Advanced Python, including asynchronous programming, API integration, automated testing and CI/CD. Demonstrated production experience building LLM-backed or agentic systems: retrieval, tool and function calling, orchestration, and evaluation or regression testing of non-deterministic outputs. Working knowledge of security operations tooling and workflow - SIEM, EDR, SOAR, case management, threat intelligence. Practical familiarity with at least two additional security domains from identity and access management, privileged access, network or cloud security, or data protection, with the demonstrated ability to learn new domains quickly. Cloud engineering experience (AWS or Azure), containerisation and infrastructure-as-code. Secure development practice: secrets management, least-privilege service identity, input validation, output encoding. Demonstrated delivery across multiple time zones for distributed stakeholders. Preferred Qualifications Financial services or comparable regulated industry experience, with working knowledge of audit, evidence and change-control requirements. Familiarity with agentic AI failure modes - prompt injection, tool poisoning, excessive agency - and current mitigations. Detection engineering exposure: detection-as-code, Sigma, MITRE ATT&CK mapping. Hands-on experience with enterprise IGA, PAM or CSPM platforms. Experience transitioning vendor-managed automation to internally owned capability. Open-source contribution, published research or conference speaking. Candidate Profile The successful candidate will operate with significant autonomy, translating problem statements into delivered capability without a pre-defined backlog. They will hold technical authority across regional teams and pillar leads, balance competing demand from multiple security domains, and be expected to make and defend judgments about where AI is and is not appropriate in a security workflow. About Us Jefferies is a leading global, full-service investment banking and capital markets firm that provides advisory, sales and trading, research, and wealth and asset management services. With more than 40 offices around the world, we offer insights and expertise to investors, companies, and governments. At Jefferies, we believe that diversity fosters creativity, innovation and thought leadership through the infusion of new ideas and perspectives. We have made a commitment to building a culture that provides opportunities for all employees regardless of our differences and supports a workforce that is reflective of the communities where we work and live. As a result, we are able to pool our collective insights and intelligence to provide fresh and innovative thinking for our clients. Jefferies is an equal employment opportunity employer, and takes affirmative action to ensure that all qualified applicants will receive consideration for employment without regard to race, creed, color, national origin, ancestry, religion, gender, pregnancy, age, physical or mental disability, marital status, sexual orientation, gender identity or expression, veteran or military status, genetic information, reproductive health decisions, or any other factor protected by applicable law. We are committed to hiring the most qualified applicants and complying with all federal, state, and local equal employment opportunity laws. As part of this commitment, Jefferies will extend reasonable accommodations to individuals with disabilities, as required by applicable law.
Sep 23, 2026
Full time
Jefferies, the global investment banking firm, has served companies and investors for almost 60 years. Headquartered in New York with its European head office in London, the firm provides clients with capital markets and financial advisory services, institutional brokerage and securities research, and asset management. Jefferies provides research and execution services in equity, fixed income, foreign exchange, and a full range of investment banking services including underwriting, merger & acquisition, restructuring and recapitalisation and other advisory services, with businesses operating in the Americas, Europe and Asia. Company Jefferies, the global investment banking firm, has served companies and investors for almost 60 years. Headquartered in New York with its European head office in London, the firm provides clients with capital markets and financial advisory services, institutional brokerage and securities research, and asset management. Jefferies provides research and execution services in equity, fixed income, foreign exchange, and a full range of investment banking services including underwriting, merger & acquisition, restructuring and recapitalisation and other advisory services, with businesses operating in the Americas, Europe and Asia. Job Description Global Information Security is building internal engineering capability to apply generative AI and automation across the security function. This is a senior hands-on engineering role supporting both the Security Operations Centre and the wider security domains: identity, privileged access, network and cloud security, data protection, and vulnerability management. The position is London-anchored to provide global coverage across the APAC afternoon and Americas morning. This is an engineering role: we are looking for a software engineer who has shipped AI-backed systems in production and can own them as services. Key Responsibilities Design, build and operate AI-assisted automation services across the security function, owning them as production services with testing, monitoring, alerting, error handling and rollback. Deliver automation supporting security operations, including alert triage and enrichment, case summarisation, evidence collection, detection tuning, threat intelligence synthesis, and repetitive investigative workflows. Partner with pillar leads to deliver AI and automation capability across the wider security domains, including access review and certification support, entitlement analysis and role mining, privileged session analysis and PAM onboarding, posture finding triage, firewall and segmentation rule rationalisation, configuration drift detection, data classification and DLP event triage, and vulnerability prioritisation and contextualisation. Develop LLM and agent-based workflows integrated with SIEM, EDR, SOAR, IGA, PAM, CSPM, DLP, ticketing and threat intelligence platforms via supported APIs. Set the global AI Security and automation roadmap in partnership with the Head of Cyber Operations and pillar leads; arbitrate competing demand across domains and determine which workflows warrant automation and which do not. Establish engineering standards for AI-assisted tooling across the security organisation in partnership with the Head of App & AI Security, covering prompt and tool-definition review, agent permission scoping, and output validation. Engineer guardrails as a primary requirement: least-privilege service identities, human-in-the-loop checkpoints for consequential actions, full audit logging of agent decisions, and defences against prompt injection and tool-definition poisoning. Build reusable platform components, shared integration patterns, evaluation harnesses, prompt and tool libraries so capability compounds across domains rather than being rebuilt for each team. Define and report measures of effectiveness, including analyst and engineer time recovered, cycle time, and quality and error rates. Mentor engineers in the Pune capability centre as automation delivery scales and document to a standard supportable by a follow-the-sun team. Required Qualifications 8+ years professional software engineering with production ownership. Advanced Python, including asynchronous programming, API integration, automated testing and CI/CD. Demonstrated production experience building LLM-backed or agentic systems: retrieval, tool and function calling, orchestration, and evaluation or regression testing of non-deterministic outputs. Working knowledge of security operations tooling and workflow - SIEM, EDR, SOAR, case management, threat intelligence. Practical familiarity with at least two additional security domains from identity and access management, privileged access, network or cloud security, or data protection, with the demonstrated ability to learn new domains quickly. Cloud engineering experience (AWS or Azure), containerisation and infrastructure-as-code. Secure development practice: secrets management, least-privilege service identity, input validation, output encoding. Demonstrated delivery across multiple time zones for distributed stakeholders. Preferred Qualifications Financial services or comparable regulated industry experience, with working knowledge of audit, evidence and change-control requirements. Familiarity with agentic AI failure modes - prompt injection, tool poisoning, excessive agency - and current mitigations. Detection engineering exposure: detection-as-code, Sigma, MITRE ATT&CK mapping. Hands-on experience with enterprise IGA, PAM or CSPM platforms. Experience transitioning vendor-managed automation to internally owned capability. Open-source contribution, published research or conference speaking. Candidate Profile The successful candidate will operate with significant autonomy, translating problem statements into delivered capability without a pre-defined backlog. They will hold technical authority across regional teams and pillar leads, balance competing demand from multiple security domains, and be expected to make and defend judgments about where AI is and is not appropriate in a security workflow. About Us Jefferies is a leading global, full-service investment banking and capital markets firm that provides advisory, sales and trading, research, and wealth and asset management services. With more than 40 offices around the world, we offer insights and expertise to investors, companies, and governments. At Jefferies, we believe that diversity fosters creativity, innovation and thought leadership through the infusion of new ideas and perspectives. We have made a commitment to building a culture that provides opportunities for all employees regardless of our differences and supports a workforce that is reflective of the communities where we work and live. As a result, we are able to pool our collective insights and intelligence to provide fresh and innovative thinking for our clients. Jefferies is an equal employment opportunity employer, and takes affirmative action to ensure that all qualified applicants will receive consideration for employment without regard to race, creed, color, national origin, ancestry, religion, gender, pregnancy, age, physical or mental disability, marital status, sexual orientation, gender identity or expression, veteran or military status, genetic information, reproductive health decisions, or any other factor protected by applicable law. We are committed to hiring the most qualified applicants and complying with all federal, state, and local equal employment opportunity laws. As part of this commitment, Jefferies will extend reasonable accommodations to individuals with disabilities, as required by applicable law.
A&O Shearman
Cyber Defence Analyst
A&O Shearman City, Belfast
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Analyst
A&O Shearman Carrickfergus, County Antrim
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Analyst
A&O Shearman Banbridge, County Down
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Analyst
A&O Shearman Hillsborough, County Down
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Analyst
A&O Shearman Neston, Cheshire
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Analyst
A&O Shearman Lisburn, County Antrim
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Analyst
A&O Shearman Dunmurry, Belfast
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Analyst
A&O Shearman Ballyclare, County Antrim
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Analyst
A&O Shearman Bangor, County Down
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Analyst
A&O Shearman Newtownabbey, County Antrim
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Analyst
A&O Shearman Drumgor, County Armagh
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Analyst
A&O Shearman Ballynahinch, County Down
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
A&O Shearman
Cyber Defence Analyst
A&O Shearman Holywood, County Down
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Sep 22, 2026
Full time
We have an exciting opportunity for a Cyber Defence Analyst to join our Information Security team , based in the A&O Shearman's Belfast office. Please note that weekend working is a requirement for this role, with exact shift patterns to be discussed at interview. All weekend hours are eligible for a premium payment, in addition to your base salary. What you will do Investigate escalations: Investigate and prioritise Level 2 escalated events and alerts which have been detected through Level 1 monitoring activities by the firm's MSSP to identify potential incidents. Escalate these events further to senior colleagues and appropriate stakeholders when necessary. Investigate potential cyber security and data loss incidents raised by firm employees and third parties, following the defined playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand-off incident response activities with the rest of the Belfast Cyber Defence team to other teams in different time-zones across the globe, as per our 24-7 follow-the-sun global model. Maintain awareness of current and emerging cyber threats, techniques, and procedures (TTPs) using threat intelligence insights from the Threat and Vulnerability Management team, applying this knowledge in daily operations. Tooling and Process Improvement: Assist with the implementation and enhancement of new and existing cyber defence tools and processes to maximise the effectiveness of the Cyber Defence function. Contribute to the maintenance and improvement of playbook and process documentation for Cyber Defence. Collaboration and Advisory: Collaborate with other areas of the firm (e.g. wider information security and IT teams) to improve the firm's security posture by implementing controls and fostering awareness. Advise business stakeholders on Cyber Defence, translating complex technical concepts into business-friendly language. What you will have At least 1+ years' experience in a security operations or similar technical security role. Operational-level experience in at least two of the following domains; Security engineering, Alert triaging, Rule writing, Incident response, Digital Forensics and Incident Response (DFIR), Threat intelligence and management, Vulnerability management, or Security control testing. In-depth understanding of Networking and routing protocols (e.g. TCP/IP) and services (e.g. DNS, SMTP). Cyber defence technologies and tooling, including: SIEM solutions Intrusion Detection/Prevention Systems (ID/PS) Threat and vulnerability management platforms Endpoint protection Firewalls Highly analytical mindset with strong problem-solving skills. Ability to interpret data flows, assess security events, and draw logical conclusions. Excellent written and verbal communication skills. Ability to collaborate effectively across technical and non-technical teams. High level of personal integrity and ethics, demonstrating an appropriate level of judgement. A genuine passion for continuous learning and development in cybersecurity, staying up-to-date with the latest developments, trends, and technologies in the field. You will stand out if you have Bachelor's degree in Information Security, Computer Science, Engineering, Technology, or a related field. Industry-recognised certifications such as: CISSP (Certified Information Systems Security Professional) CEH (Certified Ethical Hacker) CISM (Certified Information Security Manager) CompTIA Security+ Practical programming or scripting experience, particularly with: Python PowerShell NO AGENCIES PLEASE - A&O Shearman does not accept unsolicited CVs. For further information, please see our UK Recruitment Agency Policy and our commitment to direct sourcing here .
Purview Technical Consultant
Phoenix Software Limited Pocklington, Yorkshire
Overview of the role Phoenix is a leading UK IT solutions and managed service provider, with a deep specialism in the public sector. We work with organisations across government, healthcare, defence, public safety, education, housing, and the charity sector - helping them modernise with confidence across cloud, data and AI, cyber security, and managed services. Through strategic partnerships with the world's leading technology providers - and a trusted place on the major public sector frameworks - our work has a direct impact on the services that millions of people rely on every day. Due to continued growth, we are hiring a new Technical Consultant who specialises in Microsoft Cloud Security and more specifically in deploying solutions using Microsoft Purview. What will you be doing? Leading the design and implementation of related solutions for our customers. Assistingscoping and design workshops to understand customer challenges and propose solutions that meet their requirements. Writingpreand post-delivery documents including statements of works. Working closely with our project management team, ensuring project milestones and deadlines are met. Diagnosing and fixing technical challenges for our customers. Why should you apply? At Phoenix, our ambition is to be the UK's leading IT solutions and managed service provider - and we know that only happens because of our people. Cultureisn'tan afterthought here;it's the thing we work hardest on. We'reproud to be certified as a Great Place to Work , and to be recognised on their UK Best Workplaces lists for Women, Wellbeing, and Development. These aren't badgs we chase -they're the result of how we genuinely choose to treat each other, and how seriously we take our colleagues' careers, health, and lives outside of work. When you join Phoenix, you can expect: A culture built on trust and belonging:set out clearly in our Culture Blueprint, lived day-to-day, and reflected in our consistently strong colleague feedback. Real investment in your development:structured learning pathways, funded industry certifications, mentoring, and the encouragement to stretch into new areas. A workplace that takes wellbeing seriously:from mental health support and flexible working to active employee networks and a leadership team that listens. A commitment to equity and inclusion:where we actively work to make Phoenix a brilliant place to build a career, whoever you are. Work that matters:supporting the public sector organisations that keep the UK running, from government and healthcare to defence, public safety, education, housing, and the charities serving the most vulnerable in our communities. Working with the best of the industry:alongside genuine experts, and with strategic partnerships across the world's leading technology providers, you'll be at the front of the conversations shaping how UK public services modernise. We believe in encouraging, supporting, and skilling our people up so that you can be the very best you can be at work - and we'd love you to consider being part of it. Take a look at our Culture Blueprint to get a real sense of who we are. What are we looking for? The right person for this role already will be in a similar position and will have proven experienced designing and implementing Microsoft Purview solutions. Key Skills & Experience Experience as a Senior Support Engineer or as a Technical Consultant or internal technical specialist. Microsoft Purview (DLP /Sensitivity Labels / Data Life Cycle Management / Data Governance strategy). Entra ID - Identity and Access Management (Hybrid Identities). Entra ID - Security (Conditional Access, PIM, IDP, RBAC, M365 CIS/NCSC Best practices). Competent in designing and implementing complex related technology solutions for customers. Competent in developing design documentation and technical deliverables. Bonus - Microsoft Defender (for Endpoint, Office 365, Identity, Cloud Apps, Cloud). Microsoft Certifications Information Protection and Compliance Administrator Associate -SC-400/401 (Must have). Azure Security Administrator Associate - AZ-500 (Desirable). Identity and Access Administrator Associate -SC-300 (Desirable). Security Operations Analyst Associate -SC-200 (Desirable). Administrator Expert MS-102 (Desirable). Practical stuff Where is the role based? Primary location is our HQ in Pocklington (YO42) but this role can be remote with occasional visits to the HQ and to customers. How many interviews? Following a screen with the Recruitment Team you can expect a two-stage interview process, one online and one in-person. What are the benefits? You can read about the benefits on offer here. Important BPSS Check As part of our recruitment process due to the nature of the work we do, all employees are required to undertake a Baseline Personal Security Standard (BPSS) check. While some employees require further security clearance, the BPSS check is a must-have requirement and all offers of employment are conditional pending the passing of this check. Have you made it this far? Have you made it this far? If you're still reading, we think there's a strong chance you might be our kind of person. Here's the thing, though - research suggests that 60% of women and underrepresented people might have already talked themselves out of applying. Even if you don't check every box above, we want to encourage you to introduce yourself. We believe a diversity of perspectives and experiences makes a team stronger - and the stronger our team, the more successful we will be.
Sep 21, 2026
Full time
Overview of the role Phoenix is a leading UK IT solutions and managed service provider, with a deep specialism in the public sector. We work with organisations across government, healthcare, defence, public safety, education, housing, and the charity sector - helping them modernise with confidence across cloud, data and AI, cyber security, and managed services. Through strategic partnerships with the world's leading technology providers - and a trusted place on the major public sector frameworks - our work has a direct impact on the services that millions of people rely on every day. Due to continued growth, we are hiring a new Technical Consultant who specialises in Microsoft Cloud Security and more specifically in deploying solutions using Microsoft Purview. What will you be doing? Leading the design and implementation of related solutions for our customers. Assistingscoping and design workshops to understand customer challenges and propose solutions that meet their requirements. Writingpreand post-delivery documents including statements of works. Working closely with our project management team, ensuring project milestones and deadlines are met. Diagnosing and fixing technical challenges for our customers. Why should you apply? At Phoenix, our ambition is to be the UK's leading IT solutions and managed service provider - and we know that only happens because of our people. Cultureisn'tan afterthought here;it's the thing we work hardest on. We'reproud to be certified as a Great Place to Work , and to be recognised on their UK Best Workplaces lists for Women, Wellbeing, and Development. These aren't badgs we chase -they're the result of how we genuinely choose to treat each other, and how seriously we take our colleagues' careers, health, and lives outside of work. When you join Phoenix, you can expect: A culture built on trust and belonging:set out clearly in our Culture Blueprint, lived day-to-day, and reflected in our consistently strong colleague feedback. Real investment in your development:structured learning pathways, funded industry certifications, mentoring, and the encouragement to stretch into new areas. A workplace that takes wellbeing seriously:from mental health support and flexible working to active employee networks and a leadership team that listens. A commitment to equity and inclusion:where we actively work to make Phoenix a brilliant place to build a career, whoever you are. Work that matters:supporting the public sector organisations that keep the UK running, from government and healthcare to defence, public safety, education, housing, and the charities serving the most vulnerable in our communities. Working with the best of the industry:alongside genuine experts, and with strategic partnerships across the world's leading technology providers, you'll be at the front of the conversations shaping how UK public services modernise. We believe in encouraging, supporting, and skilling our people up so that you can be the very best you can be at work - and we'd love you to consider being part of it. Take a look at our Culture Blueprint to get a real sense of who we are. What are we looking for? The right person for this role already will be in a similar position and will have proven experienced designing and implementing Microsoft Purview solutions. Key Skills & Experience Experience as a Senior Support Engineer or as a Technical Consultant or internal technical specialist. Microsoft Purview (DLP /Sensitivity Labels / Data Life Cycle Management / Data Governance strategy). Entra ID - Identity and Access Management (Hybrid Identities). Entra ID - Security (Conditional Access, PIM, IDP, RBAC, M365 CIS/NCSC Best practices). Competent in designing and implementing complex related technology solutions for customers. Competent in developing design documentation and technical deliverables. Bonus - Microsoft Defender (for Endpoint, Office 365, Identity, Cloud Apps, Cloud). Microsoft Certifications Information Protection and Compliance Administrator Associate -SC-400/401 (Must have). Azure Security Administrator Associate - AZ-500 (Desirable). Identity and Access Administrator Associate -SC-300 (Desirable). Security Operations Analyst Associate -SC-200 (Desirable). Administrator Expert MS-102 (Desirable). Practical stuff Where is the role based? Primary location is our HQ in Pocklington (YO42) but this role can be remote with occasional visits to the HQ and to customers. How many interviews? Following a screen with the Recruitment Team you can expect a two-stage interview process, one online and one in-person. What are the benefits? You can read about the benefits on offer here. Important BPSS Check As part of our recruitment process due to the nature of the work we do, all employees are required to undertake a Baseline Personal Security Standard (BPSS) check. While some employees require further security clearance, the BPSS check is a must-have requirement and all offers of employment are conditional pending the passing of this check. Have you made it this far? Have you made it this far? If you're still reading, we think there's a strong chance you might be our kind of person. Here's the thing, though - research suggests that 60% of women and underrepresented people might have already talked themselves out of applying. Even if you don't check every box above, we want to encourage you to introduce yourself. We believe a diversity of perspectives and experiences makes a team stronger - and the stronger our team, the more successful we will be.
FDM Group
Technical Business Analyst
FDM Group Edinburgh, Midlothian
About The Role FDM is a global business and technology consultancy seeking a Technical Business Analyst to work for our client within the Financial Services sector. This is initially a 6-12 month contract with the potential to extend and will be a hybrid role that will be based in London, Edinburgh or Bristol. Our client is seeking a Technical Business Analyst who bridges business, technology, cyber security, fraud operations, data and risk teams. The role translates strategic outcomes and operational needs into clear product, data, control and engineering requirements for the Fraud & Security Value Stream. The role supports the design, implementation and continuous improvement of AI-enabled capabilities that strengthen fraud detection, cyber defence, security observability, operational resilience and AI governance. It maintains alignment between business priorities, delivery outcomes, control obligations and technical implementation throughout the lifecycle of each initiative. Responsibilities Analyse and document business, operational, regulatory and technical requirements. Facilitate workshops. Translate outcomes into ADO epics, features, user stories and acceptance criteria. Maintain end-to-end traceability and support prioritisation Identify and shape opportunities across threat detection, alert triage, investigation, case management, orchestration, fraud analytics, resilience and AI governance monitoring. Define workflows, business rules, exception handling, decision boundaries and human oversight. Define data requirements, authoritative sources, ownership, lineage, quality, access and retention needs. Produce mappings, dictionaries and data-flow views. Work with data and engineering teams to confirm readiness. Embed secure-by-design and responsible AI requirements. Document control, privacy, compliance, auditability, observability and governance-gate evidence. Support risk assessments and production-readiness reviews. Partner with architects, product leads, engineers and platform teams. Support backlog refinement, dependency management, sprint planning, testing, release and operational readiness. Maintain assumptions, risks, issues and decisions. Define baselines, outcomes and KPIs for fraud, cyber and operational use cases. Support benefits tracking, dashboards, post-implementation review and continuous improvement. About You At least five years of business analysis or technical business analysis experience. Experience delivering technology-enabled transformation. Experience translating complex business and control needs into technical requirements. Experience working in Agile or iterative delivery environments. Strong stakeholder management across business and technology teams. Experience supporting testing, operational readiness and adoption. Technical and Professional Skills Requirements elicitation and traceability. Process modelling and workshop facilitation. Data analysis, data mapping and integration concepts. API, cloud, analytics and security-monitoring concepts. Agile backlog management and testing methods. Risk, control and audit documentation. Clear written and executive communication Desirable Experience Experience in cyber security, fraud, risk, operational resilience or financial services. Experience delivering AI, machine learning, analytics or intelligent automation capabilities. Experience with cloud and data platforms, preferably Microsoft Azure. Knowledge of security operations, fraud operations, SIEM/XDR, case management or orchestration. Knowledge of responsible AI and AI governance practices. About Us FDM is an award-winning global leader in tech and business talent solutions, backed by more than 35 years of industry experience. We have centres across Europe, North America, and Asia-Pacific, and a global workforce of over 2500 employees. FDM has shown exponential growth throughout the years, firmly establishing itself as an award-winning employer, currently listed on the FTSE4Good Index and as a 2026 Financial Times UK 'Best Employer'. Diversity and Inclusion FDM Group is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, national origin, age, disability, veteran status or any other status protected by federal, provincial or local laws. Why join us Career coaching, mentoring and access to upskilling throughout your entire FDM career Assignments with global companies and opportunities to work abroad Opportunity to re-skill and up-skill into new areas, develop non-linear career paths and build a skillset within your field Annual leave and work-place pension
Sep 18, 2026
Full time
About The Role FDM is a global business and technology consultancy seeking a Technical Business Analyst to work for our client within the Financial Services sector. This is initially a 6-12 month contract with the potential to extend and will be a hybrid role that will be based in London, Edinburgh or Bristol. Our client is seeking a Technical Business Analyst who bridges business, technology, cyber security, fraud operations, data and risk teams. The role translates strategic outcomes and operational needs into clear product, data, control and engineering requirements for the Fraud & Security Value Stream. The role supports the design, implementation and continuous improvement of AI-enabled capabilities that strengthen fraud detection, cyber defence, security observability, operational resilience and AI governance. It maintains alignment between business priorities, delivery outcomes, control obligations and technical implementation throughout the lifecycle of each initiative. Responsibilities Analyse and document business, operational, regulatory and technical requirements. Facilitate workshops. Translate outcomes into ADO epics, features, user stories and acceptance criteria. Maintain end-to-end traceability and support prioritisation Identify and shape opportunities across threat detection, alert triage, investigation, case management, orchestration, fraud analytics, resilience and AI governance monitoring. Define workflows, business rules, exception handling, decision boundaries and human oversight. Define data requirements, authoritative sources, ownership, lineage, quality, access and retention needs. Produce mappings, dictionaries and data-flow views. Work with data and engineering teams to confirm readiness. Embed secure-by-design and responsible AI requirements. Document control, privacy, compliance, auditability, observability and governance-gate evidence. Support risk assessments and production-readiness reviews. Partner with architects, product leads, engineers and platform teams. Support backlog refinement, dependency management, sprint planning, testing, release and operational readiness. Maintain assumptions, risks, issues and decisions. Define baselines, outcomes and KPIs for fraud, cyber and operational use cases. Support benefits tracking, dashboards, post-implementation review and continuous improvement. About You At least five years of business analysis or technical business analysis experience. Experience delivering technology-enabled transformation. Experience translating complex business and control needs into technical requirements. Experience working in Agile or iterative delivery environments. Strong stakeholder management across business and technology teams. Experience supporting testing, operational readiness and adoption. Technical and Professional Skills Requirements elicitation and traceability. Process modelling and workshop facilitation. Data analysis, data mapping and integration concepts. API, cloud, analytics and security-monitoring concepts. Agile backlog management and testing methods. Risk, control and audit documentation. Clear written and executive communication Desirable Experience Experience in cyber security, fraud, risk, operational resilience or financial services. Experience delivering AI, machine learning, analytics or intelligent automation capabilities. Experience with cloud and data platforms, preferably Microsoft Azure. Knowledge of security operations, fraud operations, SIEM/XDR, case management or orchestration. Knowledge of responsible AI and AI governance practices. About Us FDM is an award-winning global leader in tech and business talent solutions, backed by more than 35 years of industry experience. We have centres across Europe, North America, and Asia-Pacific, and a global workforce of over 2500 employees. FDM has shown exponential growth throughout the years, firmly establishing itself as an award-winning employer, currently listed on the FTSE4Good Index and as a 2026 Financial Times UK 'Best Employer'. Diversity and Inclusion FDM Group is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, national origin, age, disability, veteran status or any other status protected by federal, provincial or local laws. Why join us Career coaching, mentoring and access to upskilling throughout your entire FDM career Assignments with global companies and opportunities to work abroad Opportunity to re-skill and up-skill into new areas, develop non-linear career paths and build a skillset within your field Annual leave and work-place pension
Senior SOC Analyst - DV Clearance
Salt Search
SOC Analyst (DV Cleared) Active UK Developed Vetting (DV) clearance required £70,000-£100,000 per annum 100% onsite (London, Manchester, Cheltenham, Ipswich) We are seeking an experienced SOC Analyst to join a high-security cyber defence team supporting critical national infrastructure and sensitive government programmes. This role requires a proactive security professional with strong monitoring, analysis, and incident triage capabilities within a Security Operations Centre environment. SOC Analyst - Key Responsibilities Monitor and analyse security alerts from SIEM and security tooling platforms Perform triage and investigation of security events and potential incidents Conduct threat hunting and identify indicators of compromise Escalate and coordinate incident response activities where required Analyse endpoint, network, and cloud security telemetry Develop and improve detection rules and use cases Produce detailed investigation and incident reports Collaborate with cyber threat intelligence and incident response teams Support continuous improvement of SOC processes and procedures SOC Analyst - Required Skills and Experience Active DV clearance Experience working within a SOC environment (Level 2 or Level 3 preferred) Strong knowledge of SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or ArcSight Understanding of network protocols, attack techniques, and cyber threat methodologies Experience investigating security incidents across Windows and Linux environments Knowledge of MITRE ATT&CK framework Familiarity with endpoint detection and response platforms We're hiring across multiple Cyber Security disciplines, if you are a specialist across Threat Hunting, Detection Engineering & Incident Response please do apply too! Rates depend on experience and client requirements
Sep 17, 2026
Full time
SOC Analyst (DV Cleared) Active UK Developed Vetting (DV) clearance required £70,000-£100,000 per annum 100% onsite (London, Manchester, Cheltenham, Ipswich) We are seeking an experienced SOC Analyst to join a high-security cyber defence team supporting critical national infrastructure and sensitive government programmes. This role requires a proactive security professional with strong monitoring, analysis, and incident triage capabilities within a Security Operations Centre environment. SOC Analyst - Key Responsibilities Monitor and analyse security alerts from SIEM and security tooling platforms Perform triage and investigation of security events and potential incidents Conduct threat hunting and identify indicators of compromise Escalate and coordinate incident response activities where required Analyse endpoint, network, and cloud security telemetry Develop and improve detection rules and use cases Produce detailed investigation and incident reports Collaborate with cyber threat intelligence and incident response teams Support continuous improvement of SOC processes and procedures SOC Analyst - Required Skills and Experience Active DV clearance Experience working within a SOC environment (Level 2 or Level 3 preferred) Strong knowledge of SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or ArcSight Understanding of network protocols, attack techniques, and cyber threat methodologies Experience investigating security incidents across Windows and Linux environments Knowledge of MITRE ATT&CK framework Familiarity with endpoint detection and response platforms We're hiring across multiple Cyber Security disciplines, if you are a specialist across Threat Hunting, Detection Engineering & Incident Response please do apply too! Rates depend on experience and client requirements
Certain Advantage
Cyber Security Engineer
Certain Advantage Stevenage, Hertfordshire
World Class Defence Organisation nased in Stevenage, Hertfordshire is currently looking to recruit a Cyber Security Engineer subcontractor on an initial 24 month contract. This position can start on a SC Security Clearance and will later on require DV Security Clearance. Rate: £92.11 per hour Location: Stevenage Hybrid / Remote working: Onsite 5 days per week Contract: 37 Hours per week Overtime: Hours worked over 37 hours per week will be calculated at 'time and a quarter' Duration: 24 Months (initially and then ongoing and long-term thereafter) IR35 status: Inside IR35 (Umbrella) Cyber Security Engineer Job Description: An opportunity has arisen in the Cyber Security Operations Centre (SOC) within Digital Excellence (DEX) UK for a Cyber Security Engineer. The successful applicant will lead on the technical aspects of ensuring cyber security appliance efficiency of tasks to support alert tuning, network visibility and log ingesting to relevant toolsets. They will advise on implementation of new tools and lead the updating and expansion of existing capabilities. Reporting to the Cyber Security Capability Manager, the Cyber Security Engineer will provide support by ensuring availability, readiness and resilience of cyber security tool sets within in scope environments. Responsibilities: We are looking for a Cyber Security Engineer to support the Cyber Security Capability Manager in ensuring Digital Excellence UK meets the challenges and demands of countering the Cyber Threat. To work with other UK Cyber Security members, the role will cover back-end refresh, playbook scripting and fault finding, Cyber Security tool upgrades, capability implementation, tool integration, data source on-boarding and investigation activity utilising a wide variety of security platforms including but not limited to; SIEM (Security Information Event Management), Network Packet Capture platform, Anti Malicious Code, Threat Detection technologies and platforms across the in-scope UK networks. The SOC Threat Detection Analyst key responsibilities are: Accountable for the effective mapping and topology of SOC toolsets including integrations and feeds between solutions Enriching the visibility and optimisation of SOC tools through data modelling and tuning Maintain the primary SOC toolsets, ensuring their availability, functionality and optimisation Responsible for the daily muster and availability of all cyber security technologies within in-scope environments Responsible for the accurate tracking of product lifecycle and advising management of EOL/EOS roadmaps Support the Cyber Security Capability Manager in the coordination, planning and execution of SOC appliance upgrades To support all cyber security pillars with new capability implementation and integration to existing solutions Implement cyber security tool changes and configuration ensuring efficient reporting into CAB and control boards To lead on playbook scripting activities ensuring they are well documented and tested. This includes fault finding and review of false positives To be the Subject Matter Expert (SME) on SOC connectivity and visibility across all in scope networks and infrastructure, ensuring connections and integrations are understood and documented with the Cyber Security Capability Manager To lead all activity of back-end refresh on cyber security appliances - including certificate updates, patch releases and software updates Responsible for attending DEX CAB and collating all impacting activities on cyber security alerting Responsible for attending DEX Incident and Issue red teams in support of root cause analysis - advising on cyber security changes which may impact other services Collaborate closely with DEX back office to maintain availability and efficiency of cyber security tools and recover any service outages or disruption Support the SOC in investigation activity utilising a wide variety of security platforms, creating custom searches, advanced queries or scripts in order to find the root cause or IOC of an alert Skillset/experience required: Strong coding and scripting background - PowerShell, Python & Regex Proven ability to work with APIs, including HTTP/S headers and responses, JSON Objects. Proven experience with Proxies administration and changes. Windows (SMB) and Nix (NFS) remote storage. IIS (Windows Web Server) Configuration, Active Directory/ LDAP (authentication). Experience with applying certificates, software updates and the steps involved for end-of-life refresh activity. Experience with VMware/ Hyper-V Virtual machines and virtual switches. Experience in setting up, implementing and maintenance of cyber security tooling. Experience with the creation, testing and maintenance of AI or machine learning technologies to assist with the optimisation of work flows or play books. Experience with SIEM (Security Information Event Management) technologies
Sep 16, 2026
Full time
World Class Defence Organisation nased in Stevenage, Hertfordshire is currently looking to recruit a Cyber Security Engineer subcontractor on an initial 24 month contract. This position can start on a SC Security Clearance and will later on require DV Security Clearance. Rate: £92.11 per hour Location: Stevenage Hybrid / Remote working: Onsite 5 days per week Contract: 37 Hours per week Overtime: Hours worked over 37 hours per week will be calculated at 'time and a quarter' Duration: 24 Months (initially and then ongoing and long-term thereafter) IR35 status: Inside IR35 (Umbrella) Cyber Security Engineer Job Description: An opportunity has arisen in the Cyber Security Operations Centre (SOC) within Digital Excellence (DEX) UK for a Cyber Security Engineer. The successful applicant will lead on the technical aspects of ensuring cyber security appliance efficiency of tasks to support alert tuning, network visibility and log ingesting to relevant toolsets. They will advise on implementation of new tools and lead the updating and expansion of existing capabilities. Reporting to the Cyber Security Capability Manager, the Cyber Security Engineer will provide support by ensuring availability, readiness and resilience of cyber security tool sets within in scope environments. Responsibilities: We are looking for a Cyber Security Engineer to support the Cyber Security Capability Manager in ensuring Digital Excellence UK meets the challenges and demands of countering the Cyber Threat. To work with other UK Cyber Security members, the role will cover back-end refresh, playbook scripting and fault finding, Cyber Security tool upgrades, capability implementation, tool integration, data source on-boarding and investigation activity utilising a wide variety of security platforms including but not limited to; SIEM (Security Information Event Management), Network Packet Capture platform, Anti Malicious Code, Threat Detection technologies and platforms across the in-scope UK networks. The SOC Threat Detection Analyst key responsibilities are: Accountable for the effective mapping and topology of SOC toolsets including integrations and feeds between solutions Enriching the visibility and optimisation of SOC tools through data modelling and tuning Maintain the primary SOC toolsets, ensuring their availability, functionality and optimisation Responsible for the daily muster and availability of all cyber security technologies within in-scope environments Responsible for the accurate tracking of product lifecycle and advising management of EOL/EOS roadmaps Support the Cyber Security Capability Manager in the coordination, planning and execution of SOC appliance upgrades To support all cyber security pillars with new capability implementation and integration to existing solutions Implement cyber security tool changes and configuration ensuring efficient reporting into CAB and control boards To lead on playbook scripting activities ensuring they are well documented and tested. This includes fault finding and review of false positives To be the Subject Matter Expert (SME) on SOC connectivity and visibility across all in scope networks and infrastructure, ensuring connections and integrations are understood and documented with the Cyber Security Capability Manager To lead all activity of back-end refresh on cyber security appliances - including certificate updates, patch releases and software updates Responsible for attending DEX CAB and collating all impacting activities on cyber security alerting Responsible for attending DEX Incident and Issue red teams in support of root cause analysis - advising on cyber security changes which may impact other services Collaborate closely with DEX back office to maintain availability and efficiency of cyber security tools and recover any service outages or disruption Support the SOC in investigation activity utilising a wide variety of security platforms, creating custom searches, advanced queries or scripts in order to find the root cause or IOC of an alert Skillset/experience required: Strong coding and scripting background - PowerShell, Python & Regex Proven ability to work with APIs, including HTTP/S headers and responses, JSON Objects. Proven experience with Proxies administration and changes. Windows (SMB) and Nix (NFS) remote storage. IIS (Windows Web Server) Configuration, Active Directory/ LDAP (authentication). Experience with applying certificates, software updates and the steps involved for end-of-life refresh activity. Experience with VMware/ Hyper-V Virtual machines and virtual switches. Experience in setting up, implementing and maintenance of cyber security tooling. Experience with the creation, testing and maintenance of AI or machine learning technologies to assist with the optimisation of work flows or play books. Experience with SIEM (Security Information Event Management) technologies

Modal Window

  • Home
  • Contact
  • About Us
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • Facebook
  • Twitter
  • Google Plus
  • LinkedIn
Parent and Partner sites: IT Job Board | Jobs Near Me | RightTalent.co.uk | Quantity Surveyor jobs | Building Surveyor jobs | Construction Recruitment | Talent Recruiter | Construction Job Board | Property jobs | myJobsnearme.com | Jobs near me
© 2008-2026 Jobsite Jobs | Designed by Web Design Agency