West Midlands, United Kingdom Posted on 21/03/2025 The Cyber Defence Engineer will join agrowing security team responsible for the testing, implementation, deployment,maintenance, configuration and troubleshooting of the SOC's technology stack(hardware and software). The engineer will also assist with the continueddevelopment and maintenance of data pipelines and signature updates and theprofessional development of the system engineering team. Tasks: Perform systemadministration on specific cyber defence applications and systems to includeinstallation, configuration, maintenance, troubleshooting, backup, andrestoration. Manage system/serverresources including performance, capacity, availability, serviceability, andrecoverability. Diagnose and resolvecustomer reported system incidents, problems, and events to ensure continuingoperability. Coordinatewith Cyber Defence and CTI Analysts in the management and administration theupdating of ingested data flows, cyber use cases and signatures for specialisedcyber defence applications in response to new or observed threats. Manage the compilation,cataloguing, distribution, and retrieval of data from a range of enterprisenetworks and data sources. Implement and develop datamanagement standards, policies, requirements, and specifications. Analyse data sources toprovide actionable recommendations and facilitate data-gathering methods. Provide updates to the SOC Leads (Line Management,Team Leaders) on current SOC investigations and findings. Share knowledge, skills,and experience, by documenting SOC processes to aid to aid SOC maturity and trainingof new members of the data engineering team. Requirements Knowledge: A demonstrablenetworking background - experience in system administration. Knowledge of big datatechnologies and ecosystems (e.g. Apache NiFi). Knowledge of currentmarket and emerging tools in data analytical and SIEM platforms. Knowledgeof network security implementations (e.g., IDS, IPS, EDR), including theirfunction and placement in an enterprise network. Knowledgeof intrusion detection systems and signature development. Knowledge of front-endcollection systems, including network traffic collection, filtering, andselection. Knowledge of cyber security threats,vulnerabilities, and privacy principles. Working knowledge inconfigurating collection sensors for enterprise networks. Knowledgeof system administration concepts for operating systems such as but not limitedto Linux, Android, and Windows operating systems. Knowledge of cyberdefence and information security policies, procedures, and regulations. Knowledge of networksecurity architecture concepts including topology, protocols, components, andprinciples. Knowledgeof cyber incident response frameworks and handling methodologies. Knowledge of data backup andrecovery. Skills/Experience: Must-have - circa5 years + relevant experience. Must-have experience withEnterprise ICS/network architectures and technologies. Must-have experience withframeworks and technologies that support data-intensive distributedapplications. Must-have experience withmaintaining and administrating data analytical and SIEM platforms such asElastic. Must-have experience with problemsolving and analytical skills and able to collect information, analyse, report,and advise on evidence-based changes. Skillto apply cybersecurityand privacy principles to organizational requirements (relevant toconfidentiality, integrity, availability, authentication, non-repudiation). Stakeholder management - Expert ability tocommunicate to all levels of the organisation on technical, and non-technicallevel. Experience using hostand network-based IDS/IPS Experience using packetcapture solutions. Skill indeveloping and deploying signatures. Abilityto provide technical and service leadership to junior SOC Engineers(mentor/coach). DesirableQualifications/Certifications Red Hat SystemAdministration I & II (RH124/RH134). Knowledge of virtualisation technologiessuch as VMWare and HyperV. Proventrack record and experience in developing cyber security policies andprocedures, as well as successfully producing deliverables to meetorganisational objectives. Abilityto work calmly and effectively under pressure and have a can-do attitude. Broadcyber certifications or equivalent such as Cyber Foundation Pathway, CompTIA(N+, S+, CySA+), SANS (GSEC, GCIH, GMON, GCDA), Systems Administrations (ActiveDirectory), CISCO (CCNA, CCNP) and risk management. Working knowledge of Defence Joint Service Publications (440, 441,604).
Sep 23, 2026
Full time
West Midlands, United Kingdom Posted on 21/03/2025 The Cyber Defence Engineer will join agrowing security team responsible for the testing, implementation, deployment,maintenance, configuration and troubleshooting of the SOC's technology stack(hardware and software). The engineer will also assist with the continueddevelopment and maintenance of data pipelines and signature updates and theprofessional development of the system engineering team. Tasks: Perform systemadministration on specific cyber defence applications and systems to includeinstallation, configuration, maintenance, troubleshooting, backup, andrestoration. Manage system/serverresources including performance, capacity, availability, serviceability, andrecoverability. Diagnose and resolvecustomer reported system incidents, problems, and events to ensure continuingoperability. Coordinatewith Cyber Defence and CTI Analysts in the management and administration theupdating of ingested data flows, cyber use cases and signatures for specialisedcyber defence applications in response to new or observed threats. Manage the compilation,cataloguing, distribution, and retrieval of data from a range of enterprisenetworks and data sources. Implement and develop datamanagement standards, policies, requirements, and specifications. Analyse data sources toprovide actionable recommendations and facilitate data-gathering methods. Provide updates to the SOC Leads (Line Management,Team Leaders) on current SOC investigations and findings. Share knowledge, skills,and experience, by documenting SOC processes to aid to aid SOC maturity and trainingof new members of the data engineering team. Requirements Knowledge: A demonstrablenetworking background - experience in system administration. Knowledge of big datatechnologies and ecosystems (e.g. Apache NiFi). Knowledge of currentmarket and emerging tools in data analytical and SIEM platforms. Knowledgeof network security implementations (e.g., IDS, IPS, EDR), including theirfunction and placement in an enterprise network. Knowledgeof intrusion detection systems and signature development. Knowledge of front-endcollection systems, including network traffic collection, filtering, andselection. Knowledge of cyber security threats,vulnerabilities, and privacy principles. Working knowledge inconfigurating collection sensors for enterprise networks. Knowledgeof system administration concepts for operating systems such as but not limitedto Linux, Android, and Windows operating systems. Knowledge of cyberdefence and information security policies, procedures, and regulations. Knowledge of networksecurity architecture concepts including topology, protocols, components, andprinciples. Knowledgeof cyber incident response frameworks and handling methodologies. Knowledge of data backup andrecovery. Skills/Experience: Must-have - circa5 years + relevant experience. Must-have experience withEnterprise ICS/network architectures and technologies. Must-have experience withframeworks and technologies that support data-intensive distributedapplications. Must-have experience withmaintaining and administrating data analytical and SIEM platforms such asElastic. Must-have experience with problemsolving and analytical skills and able to collect information, analyse, report,and advise on evidence-based changes. Skillto apply cybersecurityand privacy principles to organizational requirements (relevant toconfidentiality, integrity, availability, authentication, non-repudiation). Stakeholder management - Expert ability tocommunicate to all levels of the organisation on technical, and non-technicallevel. Experience using hostand network-based IDS/IPS Experience using packetcapture solutions. Skill indeveloping and deploying signatures. Abilityto provide technical and service leadership to junior SOC Engineers(mentor/coach). DesirableQualifications/Certifications Red Hat SystemAdministration I & II (RH124/RH134). Knowledge of virtualisation technologiessuch as VMWare and HyperV. Proventrack record and experience in developing cyber security policies andprocedures, as well as successfully producing deliverables to meetorganisational objectives. Abilityto work calmly and effectively under pressure and have a can-do attitude. Broadcyber certifications or equivalent such as Cyber Foundation Pathway, CompTIA(N+, S+, CySA+), SANS (GSEC, GCIH, GMON, GCDA), Systems Administrations (ActiveDirectory), CISCO (CCNA, CCNP) and risk management. Working knowledge of Defence Joint Service Publications (440, 441,604).
Control Risks supports private equity and credit, infrastructure and real assets, real estate, sovereign wealth, and development and multilateral funds, with a range of consulting services. These include transaction-specific diligence, encompassing sector- or country-specific political and policy risk intelligence and advisory, as well as assessments focusing on financial crime, reputation and performance, material ESG factors, and cyber risks associated with an investment target and its management. We also provide broader proactive and reactive risk management services for our client's portfolio companies and assets. The successful candidate would join a leading geopolitical and political risk intelligence and advisory team, with over 100 analysts and consultants around the globe. Moreover, the successful applicant would be expected to work very closely with other practice areas in Control Risks, particularly with colleagues from our Intelligence & Investigations team. The role is central to delivering our growth objectives related to private markets investors with Europe coverage. This role is responsible for leading the implementation of our strategy with private markets investors in the UK and Western Europe more broadly to position Control Risks as a leading advisor on political, regulatory and policy risk to private market clients. Role Tasks And Responsibilities Client management and business development Refine and implement our private markets business development campaign to position Control Risks as a specialist provider of policy and regulatory diligence Identify and acquire new points of contact with new and existing clients, and manage these relationships to best meet our client's requirements for both transaction and portfolio company support. Achieving year-on-year growth in our client base, and increase the number, diversity and complexity of our mandates. Develop our relationships with industry associations and professional advisors, and evaluate the best events and networks to engage, to raise awareness of our brand and services among private market investors. Develop and maintain a public profile in the industry as an expert in your specialist field through public speaking and written thought leadership. Case and project work Ensure our proposals focus on our clients' requirements and our ability to meet them, and that our proposals stay ahead of the market by incorporating clients' feedback and service innovation. Lead more complicated engagements for private markets investors, drawing in Control Risks' expertise from different practices as required. Build and maintain policy/regulatory monitoring across priority jurisdictions, particularly the UK, and sectors relevant to our clients. Develop and manage a human source and subcontractor network to support the growth of the practice and the delivery of our work. Align closely with colleagues working on the region to expand our source and subcontractor networks to meet market demand. Working culture Foster an inclusive, collaborative environment between practice areas, offices and regions. Coordinate closely with the Head of Private Markets and Financial Sponsors, as well as other colleagues with a private markets investor remit. Ensure that pricing, margins, value of our work and strategic objectives regarding the buyer group are understood in the team to grow our client base and deliver on revenue and profit targets. Requirements Demonstrated experience advising investors on UK and EU policy and regulatory change and related commercial impacts, including a strong ability to communicate clear recommendations to clients, even under time pressure. Experience with supporting clients on highly regulated, policy-sensitive sectors, such as energy, infrastructure, defence, telecoms, healthcare/life sciences, financial services and/or digital technologies. Ability to source information on the evolution of policy, regulation and enforcement trends, to interpret regulation and enforcement guidance, including at draft stages and to translate findings into actionable intelligence for our clients. Access to a large network of reliable, credible sources in policy circles in the UK, specific European markets and/or Brussels. Achieving and sustaining trusted advisor relationships with senior-decision makers within the defined buyer group Identifying and growing new client relationships, and growing a practice area around this. Innovating services and successfully taking these to clients. Demonstrating in-depth knowledge and understanding of political, economic, societal, regulatory and technology trends affecting private markets investors and their risk considerations. Master's degree or equivalent 10 years of full-time professional experience in winning and delivering political risk or policy and regulatory focused advisory work Professional experience in private markets, investment banking, or corporate M&A Willingness to travel. Benefits Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarised in the full job offer. We operate a discretionary global bonus scheme that incentivises, and rewards individuals based on company and individual performance. Control Risks supports hybrid working arrangements, wherever possible, that emphasise the value of in-person time together - in the office and with our clients - while continuing to support flexible and remote working. As an equal opportunities employer, we encourage suitably qualified applicants from a wide range of backgrounds to apply and join us and are fully committed to equal treatment, free from discrimination, of all candidates throughout our recruitment process. If you require any reasonable adjustments to be made in order to participate fully in the interview process, please let us know and we will be happy to accommodate your needs.
Sep 23, 2026
Full time
Control Risks supports private equity and credit, infrastructure and real assets, real estate, sovereign wealth, and development and multilateral funds, with a range of consulting services. These include transaction-specific diligence, encompassing sector- or country-specific political and policy risk intelligence and advisory, as well as assessments focusing on financial crime, reputation and performance, material ESG factors, and cyber risks associated with an investment target and its management. We also provide broader proactive and reactive risk management services for our client's portfolio companies and assets. The successful candidate would join a leading geopolitical and political risk intelligence and advisory team, with over 100 analysts and consultants around the globe. Moreover, the successful applicant would be expected to work very closely with other practice areas in Control Risks, particularly with colleagues from our Intelligence & Investigations team. The role is central to delivering our growth objectives related to private markets investors with Europe coverage. This role is responsible for leading the implementation of our strategy with private markets investors in the UK and Western Europe more broadly to position Control Risks as a leading advisor on political, regulatory and policy risk to private market clients. Role Tasks And Responsibilities Client management and business development Refine and implement our private markets business development campaign to position Control Risks as a specialist provider of policy and regulatory diligence Identify and acquire new points of contact with new and existing clients, and manage these relationships to best meet our client's requirements for both transaction and portfolio company support. Achieving year-on-year growth in our client base, and increase the number, diversity and complexity of our mandates. Develop our relationships with industry associations and professional advisors, and evaluate the best events and networks to engage, to raise awareness of our brand and services among private market investors. Develop and maintain a public profile in the industry as an expert in your specialist field through public speaking and written thought leadership. Case and project work Ensure our proposals focus on our clients' requirements and our ability to meet them, and that our proposals stay ahead of the market by incorporating clients' feedback and service innovation. Lead more complicated engagements for private markets investors, drawing in Control Risks' expertise from different practices as required. Build and maintain policy/regulatory monitoring across priority jurisdictions, particularly the UK, and sectors relevant to our clients. Develop and manage a human source and subcontractor network to support the growth of the practice and the delivery of our work. Align closely with colleagues working on the region to expand our source and subcontractor networks to meet market demand. Working culture Foster an inclusive, collaborative environment between practice areas, offices and regions. Coordinate closely with the Head of Private Markets and Financial Sponsors, as well as other colleagues with a private markets investor remit. Ensure that pricing, margins, value of our work and strategic objectives regarding the buyer group are understood in the team to grow our client base and deliver on revenue and profit targets. Requirements Demonstrated experience advising investors on UK and EU policy and regulatory change and related commercial impacts, including a strong ability to communicate clear recommendations to clients, even under time pressure. Experience with supporting clients on highly regulated, policy-sensitive sectors, such as energy, infrastructure, defence, telecoms, healthcare/life sciences, financial services and/or digital technologies. Ability to source information on the evolution of policy, regulation and enforcement trends, to interpret regulation and enforcement guidance, including at draft stages and to translate findings into actionable intelligence for our clients. Access to a large network of reliable, credible sources in policy circles in the UK, specific European markets and/or Brussels. Achieving and sustaining trusted advisor relationships with senior-decision makers within the defined buyer group Identifying and growing new client relationships, and growing a practice area around this. Innovating services and successfully taking these to clients. Demonstrating in-depth knowledge and understanding of political, economic, societal, regulatory and technology trends affecting private markets investors and their risk considerations. Master's degree or equivalent 10 years of full-time professional experience in winning and delivering political risk or policy and regulatory focused advisory work Professional experience in private markets, investment banking, or corporate M&A Willingness to travel. Benefits Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarised in the full job offer. We operate a discretionary global bonus scheme that incentivises, and rewards individuals based on company and individual performance. Control Risks supports hybrid working arrangements, wherever possible, that emphasise the value of in-person time together - in the office and with our clients - while continuing to support flexible and remote working. As an equal opportunities employer, we encourage suitably qualified applicants from a wide range of backgrounds to apply and join us and are fully committed to equal treatment, free from discrimination, of all candidates throughout our recruitment process. If you require any reasonable adjustments to be made in order to participate fully in the interview process, please let us know and we will be happy to accommodate your needs.
Jefferies, the global investment banking firm, has served companies and investors for almost 60 years. Headquartered in New York with its European head office in London, the firm provides clients with capital markets and financial advisory services, institutional brokerage and securities research, and asset management. Jefferies provides research and execution services in equity, fixed income, foreign exchange, and a full range of investment banking services including underwriting, merger & acquisition, restructuring and recapitalisation and other advisory services, with businesses operating in the Americas, Europe and Asia. Company Jefferies, the global investment banking firm, has served companies and investors for almost 60 years. Headquartered in New York with its European head office in London, the firm provides clients with capital markets and financial advisory services, institutional brokerage and securities research, and asset management. Jefferies provides research and execution services in equity, fixed income, foreign exchange, and a full range of investment banking services including underwriting, merger & acquisition, restructuring and recapitalisation and other advisory services, with businesses operating in the Americas, Europe and Asia. Job Description Global Information Security is building internal engineering capability to apply generative AI and automation across the security function. This is a senior hands-on engineering role supporting both the Security Operations Centre and the wider security domains: identity, privileged access, network and cloud security, data protection, and vulnerability management. The position is London-anchored to provide global coverage across the APAC afternoon and Americas morning. This is an engineering role: we are looking for a software engineer who has shipped AI-backed systems in production and can own them as services. Key Responsibilities Design, build and operate AI-assisted automation services across the security function, owning them as production services with testing, monitoring, alerting, error handling and rollback. Deliver automation supporting security operations, including alert triage and enrichment, case summarisation, evidence collection, detection tuning, threat intelligence synthesis, and repetitive investigative workflows. Partner with pillar leads to deliver AI and automation capability across the wider security domains, including access review and certification support, entitlement analysis and role mining, privileged session analysis and PAM onboarding, posture finding triage, firewall and segmentation rule rationalisation, configuration drift detection, data classification and DLP event triage, and vulnerability prioritisation and contextualisation. Develop LLM and agent-based workflows integrated with SIEM, EDR, SOAR, IGA, PAM, CSPM, DLP, ticketing and threat intelligence platforms via supported APIs. Set the global AI Security and automation roadmap in partnership with the Head of Cyber Operations and pillar leads; arbitrate competing demand across domains and determine which workflows warrant automation and which do not. Establish engineering standards for AI-assisted tooling across the security organisation in partnership with the Head of App & AI Security, covering prompt and tool-definition review, agent permission scoping, and output validation. Engineer guardrails as a primary requirement: least-privilege service identities, human-in-the-loop checkpoints for consequential actions, full audit logging of agent decisions, and defences against prompt injection and tool-definition poisoning. Build reusable platform components, shared integration patterns, evaluation harnesses, prompt and tool libraries so capability compounds across domains rather than being rebuilt for each team. Define and report measures of effectiveness, including analyst and engineer time recovered, cycle time, and quality and error rates. Mentor engineers in the Pune capability centre as automation delivery scales and document to a standard supportable by a follow-the-sun team. Required Qualifications 8+ years professional software engineering with production ownership. Advanced Python, including asynchronous programming, API integration, automated testing and CI/CD. Demonstrated production experience building LLM-backed or agentic systems: retrieval, tool and function calling, orchestration, and evaluation or regression testing of non-deterministic outputs. Working knowledge of security operations tooling and workflow - SIEM, EDR, SOAR, case management, threat intelligence. Practical familiarity with at least two additional security domains from identity and access management, privileged access, network or cloud security, or data protection, with the demonstrated ability to learn new domains quickly. Cloud engineering experience (AWS or Azure), containerisation and infrastructure-as-code. Secure development practice: secrets management, least-privilege service identity, input validation, output encoding. Demonstrated delivery across multiple time zones for distributed stakeholders. Preferred Qualifications Financial services or comparable regulated industry experience, with working knowledge of audit, evidence and change-control requirements. Familiarity with agentic AI failure modes - prompt injection, tool poisoning, excessive agency - and current mitigations. Detection engineering exposure: detection-as-code, Sigma, MITRE ATT&CK mapping. Hands-on experience with enterprise IGA, PAM or CSPM platforms. Experience transitioning vendor-managed automation to internally owned capability. Open-source contribution, published research or conference speaking. Candidate Profile The successful candidate will operate with significant autonomy, translating problem statements into delivered capability without a pre-defined backlog. They will hold technical authority across regional teams and pillar leads, balance competing demand from multiple security domains, and be expected to make and defend judgments about where AI is and is not appropriate in a security workflow. About Us Jefferies is a leading global, full-service investment banking and capital markets firm that provides advisory, sales and trading, research, and wealth and asset management services. With more than 40 offices around the world, we offer insights and expertise to investors, companies, and governments. At Jefferies, we believe that diversity fosters creativity, innovation and thought leadership through the infusion of new ideas and perspectives. We have made a commitment to building a culture that provides opportunities for all employees regardless of our differences and supports a workforce that is reflective of the communities where we work and live. As a result, we are able to pool our collective insights and intelligence to provide fresh and innovative thinking for our clients. Jefferies is an equal employment opportunity employer, and takes affirmative action to ensure that all qualified applicants will receive consideration for employment without regard to race, creed, color, national origin, ancestry, religion, gender, pregnancy, age, physical or mental disability, marital status, sexual orientation, gender identity or expression, veteran or military status, genetic information, reproductive health decisions, or any other factor protected by applicable law. We are committed to hiring the most qualified applicants and complying with all federal, state, and local equal employment opportunity laws. As part of this commitment, Jefferies will extend reasonable accommodations to individuals with disabilities, as required by applicable law.
Sep 23, 2026
Full time
Jefferies, the global investment banking firm, has served companies and investors for almost 60 years. Headquartered in New York with its European head office in London, the firm provides clients with capital markets and financial advisory services, institutional brokerage and securities research, and asset management. Jefferies provides research and execution services in equity, fixed income, foreign exchange, and a full range of investment banking services including underwriting, merger & acquisition, restructuring and recapitalisation and other advisory services, with businesses operating in the Americas, Europe and Asia. Company Jefferies, the global investment banking firm, has served companies and investors for almost 60 years. Headquartered in New York with its European head office in London, the firm provides clients with capital markets and financial advisory services, institutional brokerage and securities research, and asset management. Jefferies provides research and execution services in equity, fixed income, foreign exchange, and a full range of investment banking services including underwriting, merger & acquisition, restructuring and recapitalisation and other advisory services, with businesses operating in the Americas, Europe and Asia. Job Description Global Information Security is building internal engineering capability to apply generative AI and automation across the security function. This is a senior hands-on engineering role supporting both the Security Operations Centre and the wider security domains: identity, privileged access, network and cloud security, data protection, and vulnerability management. The position is London-anchored to provide global coverage across the APAC afternoon and Americas morning. This is an engineering role: we are looking for a software engineer who has shipped AI-backed systems in production and can own them as services. Key Responsibilities Design, build and operate AI-assisted automation services across the security function, owning them as production services with testing, monitoring, alerting, error handling and rollback. Deliver automation supporting security operations, including alert triage and enrichment, case summarisation, evidence collection, detection tuning, threat intelligence synthesis, and repetitive investigative workflows. Partner with pillar leads to deliver AI and automation capability across the wider security domains, including access review and certification support, entitlement analysis and role mining, privileged session analysis and PAM onboarding, posture finding triage, firewall and segmentation rule rationalisation, configuration drift detection, data classification and DLP event triage, and vulnerability prioritisation and contextualisation. Develop LLM and agent-based workflows integrated with SIEM, EDR, SOAR, IGA, PAM, CSPM, DLP, ticketing and threat intelligence platforms via supported APIs. Set the global AI Security and automation roadmap in partnership with the Head of Cyber Operations and pillar leads; arbitrate competing demand across domains and determine which workflows warrant automation and which do not. Establish engineering standards for AI-assisted tooling across the security organisation in partnership with the Head of App & AI Security, covering prompt and tool-definition review, agent permission scoping, and output validation. Engineer guardrails as a primary requirement: least-privilege service identities, human-in-the-loop checkpoints for consequential actions, full audit logging of agent decisions, and defences against prompt injection and tool-definition poisoning. Build reusable platform components, shared integration patterns, evaluation harnesses, prompt and tool libraries so capability compounds across domains rather than being rebuilt for each team. Define and report measures of effectiveness, including analyst and engineer time recovered, cycle time, and quality and error rates. Mentor engineers in the Pune capability centre as automation delivery scales and document to a standard supportable by a follow-the-sun team. Required Qualifications 8+ years professional software engineering with production ownership. Advanced Python, including asynchronous programming, API integration, automated testing and CI/CD. Demonstrated production experience building LLM-backed or agentic systems: retrieval, tool and function calling, orchestration, and evaluation or regression testing of non-deterministic outputs. Working knowledge of security operations tooling and workflow - SIEM, EDR, SOAR, case management, threat intelligence. Practical familiarity with at least two additional security domains from identity and access management, privileged access, network or cloud security, or data protection, with the demonstrated ability to learn new domains quickly. Cloud engineering experience (AWS or Azure), containerisation and infrastructure-as-code. Secure development practice: secrets management, least-privilege service identity, input validation, output encoding. Demonstrated delivery across multiple time zones for distributed stakeholders. Preferred Qualifications Financial services or comparable regulated industry experience, with working knowledge of audit, evidence and change-control requirements. Familiarity with agentic AI failure modes - prompt injection, tool poisoning, excessive agency - and current mitigations. Detection engineering exposure: detection-as-code, Sigma, MITRE ATT&CK mapping. Hands-on experience with enterprise IGA, PAM or CSPM platforms. Experience transitioning vendor-managed automation to internally owned capability. Open-source contribution, published research or conference speaking. Candidate Profile The successful candidate will operate with significant autonomy, translating problem statements into delivered capability without a pre-defined backlog. They will hold technical authority across regional teams and pillar leads, balance competing demand from multiple security domains, and be expected to make and defend judgments about where AI is and is not appropriate in a security workflow. About Us Jefferies is a leading global, full-service investment banking and capital markets firm that provides advisory, sales and trading, research, and wealth and asset management services. With more than 40 offices around the world, we offer insights and expertise to investors, companies, and governments. At Jefferies, we believe that diversity fosters creativity, innovation and thought leadership through the infusion of new ideas and perspectives. We have made a commitment to building a culture that provides opportunities for all employees regardless of our differences and supports a workforce that is reflective of the communities where we work and live. As a result, we are able to pool our collective insights and intelligence to provide fresh and innovative thinking for our clients. Jefferies is an equal employment opportunity employer, and takes affirmative action to ensure that all qualified applicants will receive consideration for employment without regard to race, creed, color, national origin, ancestry, religion, gender, pregnancy, age, physical or mental disability, marital status, sexual orientation, gender identity or expression, veteran or military status, genetic information, reproductive health decisions, or any other factor protected by applicable law. We are committed to hiring the most qualified applicants and complying with all federal, state, and local equal employment opportunity laws. As part of this commitment, Jefferies will extend reasonable accommodations to individuals with disabilities, as required by applicable law.
Overview of the role Phoenix is a leading UK IT solutions and managed service provider, with a deep specialism in the public sector. We work with organisations across government, healthcare, defence, public safety, education, housing, and the charity sector - helping them modernise with confidence across cloud, data and AI, cyber security, and managed services. Through strategic partnerships with the world's leading technology providers - and a trusted place on the major public sector frameworks - our work has a direct impact on the services that millions of people rely on every day. Due to continued growth, we are hiring a new Technical Consultant who specialises in Microsoft Cloud Security and more specifically in deploying solutions using Microsoft Purview. What will you be doing? Leading the design and implementation of related solutions for our customers. Assistingscoping and design workshops to understand customer challenges and propose solutions that meet their requirements. Writingpreand post-delivery documents including statements of works. Working closely with our project management team, ensuring project milestones and deadlines are met. Diagnosing and fixing technical challenges for our customers. Why should you apply? At Phoenix, our ambition is to be the UK's leading IT solutions and managed service provider - and we know that only happens because of our people. Cultureisn'tan afterthought here;it's the thing we work hardest on. We'reproud to be certified as a Great Place to Work , and to be recognised on their UK Best Workplaces lists for Women, Wellbeing, and Development. These aren't badgs we chase -they're the result of how we genuinely choose to treat each other, and how seriously we take our colleagues' careers, health, and lives outside of work. When you join Phoenix, you can expect: A culture built on trust and belonging:set out clearly in our Culture Blueprint, lived day-to-day, and reflected in our consistently strong colleague feedback. Real investment in your development:structured learning pathways, funded industry certifications, mentoring, and the encouragement to stretch into new areas. A workplace that takes wellbeing seriously:from mental health support and flexible working to active employee networks and a leadership team that listens. A commitment to equity and inclusion:where we actively work to make Phoenix a brilliant place to build a career, whoever you are. Work that matters:supporting the public sector organisations that keep the UK running, from government and healthcare to defence, public safety, education, housing, and the charities serving the most vulnerable in our communities. Working with the best of the industry:alongside genuine experts, and with strategic partnerships across the world's leading technology providers, you'll be at the front of the conversations shaping how UK public services modernise. We believe in encouraging, supporting, and skilling our people up so that you can be the very best you can be at work - and we'd love you to consider being part of it. Take a look at our Culture Blueprint to get a real sense of who we are. What are we looking for? The right person for this role already will be in a similar position and will have proven experienced designing and implementing Microsoft Purview solutions. Key Skills & Experience Experience as a Senior Support Engineer or as a Technical Consultant or internal technical specialist. Microsoft Purview (DLP /Sensitivity Labels / Data Life Cycle Management / Data Governance strategy). Entra ID - Identity and Access Management (Hybrid Identities). Entra ID - Security (Conditional Access, PIM, IDP, RBAC, M365 CIS/NCSC Best practices). Competent in designing and implementing complex related technology solutions for customers. Competent in developing design documentation and technical deliverables. Bonus - Microsoft Defender (for Endpoint, Office 365, Identity, Cloud Apps, Cloud). Microsoft Certifications Information Protection and Compliance Administrator Associate -SC-400/401 (Must have). Azure Security Administrator Associate - AZ-500 (Desirable). Identity and Access Administrator Associate -SC-300 (Desirable). Security Operations Analyst Associate -SC-200 (Desirable). Administrator Expert MS-102 (Desirable). Practical stuff Where is the role based? Primary location is our HQ in Pocklington (YO42) but this role can be remote with occasional visits to the HQ and to customers. How many interviews? Following a screen with the Recruitment Team you can expect a two-stage interview process, one online and one in-person. What are the benefits? You can read about the benefits on offer here. Important BPSS Check As part of our recruitment process due to the nature of the work we do, all employees are required to undertake a Baseline Personal Security Standard (BPSS) check. While some employees require further security clearance, the BPSS check is a must-have requirement and all offers of employment are conditional pending the passing of this check. Have you made it this far? Have you made it this far? If you're still reading, we think there's a strong chance you might be our kind of person. Here's the thing, though - research suggests that 60% of women and underrepresented people might have already talked themselves out of applying. Even if you don't check every box above, we want to encourage you to introduce yourself. We believe a diversity of perspectives and experiences makes a team stronger - and the stronger our team, the more successful we will be.
Sep 21, 2026
Full time
Overview of the role Phoenix is a leading UK IT solutions and managed service provider, with a deep specialism in the public sector. We work with organisations across government, healthcare, defence, public safety, education, housing, and the charity sector - helping them modernise with confidence across cloud, data and AI, cyber security, and managed services. Through strategic partnerships with the world's leading technology providers - and a trusted place on the major public sector frameworks - our work has a direct impact on the services that millions of people rely on every day. Due to continued growth, we are hiring a new Technical Consultant who specialises in Microsoft Cloud Security and more specifically in deploying solutions using Microsoft Purview. What will you be doing? Leading the design and implementation of related solutions for our customers. Assistingscoping and design workshops to understand customer challenges and propose solutions that meet their requirements. Writingpreand post-delivery documents including statements of works. Working closely with our project management team, ensuring project milestones and deadlines are met. Diagnosing and fixing technical challenges for our customers. Why should you apply? At Phoenix, our ambition is to be the UK's leading IT solutions and managed service provider - and we know that only happens because of our people. Cultureisn'tan afterthought here;it's the thing we work hardest on. We'reproud to be certified as a Great Place to Work , and to be recognised on their UK Best Workplaces lists for Women, Wellbeing, and Development. These aren't badgs we chase -they're the result of how we genuinely choose to treat each other, and how seriously we take our colleagues' careers, health, and lives outside of work. When you join Phoenix, you can expect: A culture built on trust and belonging:set out clearly in our Culture Blueprint, lived day-to-day, and reflected in our consistently strong colleague feedback. Real investment in your development:structured learning pathways, funded industry certifications, mentoring, and the encouragement to stretch into new areas. A workplace that takes wellbeing seriously:from mental health support and flexible working to active employee networks and a leadership team that listens. A commitment to equity and inclusion:where we actively work to make Phoenix a brilliant place to build a career, whoever you are. Work that matters:supporting the public sector organisations that keep the UK running, from government and healthcare to defence, public safety, education, housing, and the charities serving the most vulnerable in our communities. Working with the best of the industry:alongside genuine experts, and with strategic partnerships across the world's leading technology providers, you'll be at the front of the conversations shaping how UK public services modernise. We believe in encouraging, supporting, and skilling our people up so that you can be the very best you can be at work - and we'd love you to consider being part of it. Take a look at our Culture Blueprint to get a real sense of who we are. What are we looking for? The right person for this role already will be in a similar position and will have proven experienced designing and implementing Microsoft Purview solutions. Key Skills & Experience Experience as a Senior Support Engineer or as a Technical Consultant or internal technical specialist. Microsoft Purview (DLP /Sensitivity Labels / Data Life Cycle Management / Data Governance strategy). Entra ID - Identity and Access Management (Hybrid Identities). Entra ID - Security (Conditional Access, PIM, IDP, RBAC, M365 CIS/NCSC Best practices). Competent in designing and implementing complex related technology solutions for customers. Competent in developing design documentation and technical deliverables. Bonus - Microsoft Defender (for Endpoint, Office 365, Identity, Cloud Apps, Cloud). Microsoft Certifications Information Protection and Compliance Administrator Associate -SC-400/401 (Must have). Azure Security Administrator Associate - AZ-500 (Desirable). Identity and Access Administrator Associate -SC-300 (Desirable). Security Operations Analyst Associate -SC-200 (Desirable). Administrator Expert MS-102 (Desirable). Practical stuff Where is the role based? Primary location is our HQ in Pocklington (YO42) but this role can be remote with occasional visits to the HQ and to customers. How many interviews? Following a screen with the Recruitment Team you can expect a two-stage interview process, one online and one in-person. What are the benefits? You can read about the benefits on offer here. Important BPSS Check As part of our recruitment process due to the nature of the work we do, all employees are required to undertake a Baseline Personal Security Standard (BPSS) check. While some employees require further security clearance, the BPSS check is a must-have requirement and all offers of employment are conditional pending the passing of this check. Have you made it this far? Have you made it this far? If you're still reading, we think there's a strong chance you might be our kind of person. Here's the thing, though - research suggests that 60% of women and underrepresented people might have already talked themselves out of applying. Even if you don't check every box above, we want to encourage you to introduce yourself. We believe a diversity of perspectives and experiences makes a team stronger - and the stronger our team, the more successful we will be.
About The Role FDM is a global business and technology consultancy seeking a Technical Business Analyst to work for our client within the Financial Services sector. This is initially a 6-12 month contract with the potential to extend and will be a hybrid role that will be based in London, Edinburgh or Bristol. Our client is seeking a Technical Business Analyst who bridges business, technology, cyber security, fraud operations, data and risk teams. The role translates strategic outcomes and operational needs into clear product, data, control and engineering requirements for the Fraud & Security Value Stream. The role supports the design, implementation and continuous improvement of AI-enabled capabilities that strengthen fraud detection, cyber defence, security observability, operational resilience and AI governance. It maintains alignment between business priorities, delivery outcomes, control obligations and technical implementation throughout the lifecycle of each initiative. Responsibilities Analyse and document business, operational, regulatory and technical requirements. Facilitate workshops. Translate outcomes into ADO epics, features, user stories and acceptance criteria. Maintain end-to-end traceability and support prioritisation Identify and shape opportunities across threat detection, alert triage, investigation, case management, orchestration, fraud analytics, resilience and AI governance monitoring. Define workflows, business rules, exception handling, decision boundaries and human oversight. Define data requirements, authoritative sources, ownership, lineage, quality, access and retention needs. Produce mappings, dictionaries and data-flow views. Work with data and engineering teams to confirm readiness. Embed secure-by-design and responsible AI requirements. Document control, privacy, compliance, auditability, observability and governance-gate evidence. Support risk assessments and production-readiness reviews. Partner with architects, product leads, engineers and platform teams. Support backlog refinement, dependency management, sprint planning, testing, release and operational readiness. Maintain assumptions, risks, issues and decisions. Define baselines, outcomes and KPIs for fraud, cyber and operational use cases. Support benefits tracking, dashboards, post-implementation review and continuous improvement. About You At least five years of business analysis or technical business analysis experience. Experience delivering technology-enabled transformation. Experience translating complex business and control needs into technical requirements. Experience working in Agile or iterative delivery environments. Strong stakeholder management across business and technology teams. Experience supporting testing, operational readiness and adoption. Technical and Professional Skills Requirements elicitation and traceability. Process modelling and workshop facilitation. Data analysis, data mapping and integration concepts. API, cloud, analytics and security-monitoring concepts. Agile backlog management and testing methods. Risk, control and audit documentation. Clear written and executive communication Desirable Experience Experience in cyber security, fraud, risk, operational resilience or financial services. Experience delivering AI, machine learning, analytics or intelligent automation capabilities. Experience with cloud and data platforms, preferably Microsoft Azure. Knowledge of security operations, fraud operations, SIEM/XDR, case management or orchestration. Knowledge of responsible AI and AI governance practices. About Us FDM is an award-winning global leader in tech and business talent solutions, backed by more than 35 years of industry experience. We have centres across Europe, North America, and Asia-Pacific, and a global workforce of over 2500 employees. FDM has shown exponential growth throughout the years, firmly establishing itself as an award-winning employer, currently listed on the FTSE4Good Index and as a 2026 Financial Times UK 'Best Employer'. Diversity and Inclusion FDM Group is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, national origin, age, disability, veteran status or any other status protected by federal, provincial or local laws. Why join us Career coaching, mentoring and access to upskilling throughout your entire FDM career Assignments with global companies and opportunities to work abroad Opportunity to re-skill and up-skill into new areas, develop non-linear career paths and build a skillset within your field Annual leave and work-place pension
Sep 18, 2026
Full time
About The Role FDM is a global business and technology consultancy seeking a Technical Business Analyst to work for our client within the Financial Services sector. This is initially a 6-12 month contract with the potential to extend and will be a hybrid role that will be based in London, Edinburgh or Bristol. Our client is seeking a Technical Business Analyst who bridges business, technology, cyber security, fraud operations, data and risk teams. The role translates strategic outcomes and operational needs into clear product, data, control and engineering requirements for the Fraud & Security Value Stream. The role supports the design, implementation and continuous improvement of AI-enabled capabilities that strengthen fraud detection, cyber defence, security observability, operational resilience and AI governance. It maintains alignment between business priorities, delivery outcomes, control obligations and technical implementation throughout the lifecycle of each initiative. Responsibilities Analyse and document business, operational, regulatory and technical requirements. Facilitate workshops. Translate outcomes into ADO epics, features, user stories and acceptance criteria. Maintain end-to-end traceability and support prioritisation Identify and shape opportunities across threat detection, alert triage, investigation, case management, orchestration, fraud analytics, resilience and AI governance monitoring. Define workflows, business rules, exception handling, decision boundaries and human oversight. Define data requirements, authoritative sources, ownership, lineage, quality, access and retention needs. Produce mappings, dictionaries and data-flow views. Work with data and engineering teams to confirm readiness. Embed secure-by-design and responsible AI requirements. Document control, privacy, compliance, auditability, observability and governance-gate evidence. Support risk assessments and production-readiness reviews. Partner with architects, product leads, engineers and platform teams. Support backlog refinement, dependency management, sprint planning, testing, release and operational readiness. Maintain assumptions, risks, issues and decisions. Define baselines, outcomes and KPIs for fraud, cyber and operational use cases. Support benefits tracking, dashboards, post-implementation review and continuous improvement. About You At least five years of business analysis or technical business analysis experience. Experience delivering technology-enabled transformation. Experience translating complex business and control needs into technical requirements. Experience working in Agile or iterative delivery environments. Strong stakeholder management across business and technology teams. Experience supporting testing, operational readiness and adoption. Technical and Professional Skills Requirements elicitation and traceability. Process modelling and workshop facilitation. Data analysis, data mapping and integration concepts. API, cloud, analytics and security-monitoring concepts. Agile backlog management and testing methods. Risk, control and audit documentation. Clear written and executive communication Desirable Experience Experience in cyber security, fraud, risk, operational resilience or financial services. Experience delivering AI, machine learning, analytics or intelligent automation capabilities. Experience with cloud and data platforms, preferably Microsoft Azure. Knowledge of security operations, fraud operations, SIEM/XDR, case management or orchestration. Knowledge of responsible AI and AI governance practices. About Us FDM is an award-winning global leader in tech and business talent solutions, backed by more than 35 years of industry experience. We have centres across Europe, North America, and Asia-Pacific, and a global workforce of over 2500 employees. FDM has shown exponential growth throughout the years, firmly establishing itself as an award-winning employer, currently listed on the FTSE4Good Index and as a 2026 Financial Times UK 'Best Employer'. Diversity and Inclusion FDM Group is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, national origin, age, disability, veteran status or any other status protected by federal, provincial or local laws. Why join us Career coaching, mentoring and access to upskilling throughout your entire FDM career Assignments with global companies and opportunities to work abroad Opportunity to re-skill and up-skill into new areas, develop non-linear career paths and build a skillset within your field Annual leave and work-place pension
SOC Analyst (DV Cleared) Active UK Developed Vetting (DV) clearance required £70,000-£100,000 per annum 100% onsite (London, Manchester, Cheltenham, Ipswich) We are seeking an experienced SOC Analyst to join a high-security cyber defence team supporting critical national infrastructure and sensitive government programmes. This role requires a proactive security professional with strong monitoring, analysis, and incident triage capabilities within a Security Operations Centre environment. SOC Analyst - Key Responsibilities Monitor and analyse security alerts from SIEM and security tooling platforms Perform triage and investigation of security events and potential incidents Conduct threat hunting and identify indicators of compromise Escalate and coordinate incident response activities where required Analyse endpoint, network, and cloud security telemetry Develop and improve detection rules and use cases Produce detailed investigation and incident reports Collaborate with cyber threat intelligence and incident response teams Support continuous improvement of SOC processes and procedures SOC Analyst - Required Skills and Experience Active DV clearance Experience working within a SOC environment (Level 2 or Level 3 preferred) Strong knowledge of SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or ArcSight Understanding of network protocols, attack techniques, and cyber threat methodologies Experience investigating security incidents across Windows and Linux environments Knowledge of MITRE ATT&CK framework Familiarity with endpoint detection and response platforms We're hiring across multiple Cyber Security disciplines, if you are a specialist across Threat Hunting, Detection Engineering & Incident Response please do apply too! Rates depend on experience and client requirements
Sep 17, 2026
Full time
SOC Analyst (DV Cleared) Active UK Developed Vetting (DV) clearance required £70,000-£100,000 per annum 100% onsite (London, Manchester, Cheltenham, Ipswich) We are seeking an experienced SOC Analyst to join a high-security cyber defence team supporting critical national infrastructure and sensitive government programmes. This role requires a proactive security professional with strong monitoring, analysis, and incident triage capabilities within a Security Operations Centre environment. SOC Analyst - Key Responsibilities Monitor and analyse security alerts from SIEM and security tooling platforms Perform triage and investigation of security events and potential incidents Conduct threat hunting and identify indicators of compromise Escalate and coordinate incident response activities where required Analyse endpoint, network, and cloud security telemetry Develop and improve detection rules and use cases Produce detailed investigation and incident reports Collaborate with cyber threat intelligence and incident response teams Support continuous improvement of SOC processes and procedures SOC Analyst - Required Skills and Experience Active DV clearance Experience working within a SOC environment (Level 2 or Level 3 preferred) Strong knowledge of SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or ArcSight Understanding of network protocols, attack techniques, and cyber threat methodologies Experience investigating security incidents across Windows and Linux environments Knowledge of MITRE ATT&CK framework Familiarity with endpoint detection and response platforms We're hiring across multiple Cyber Security disciplines, if you are a specialist across Threat Hunting, Detection Engineering & Incident Response please do apply too! Rates depend on experience and client requirements
World Class Defence Organisation nased in Stevenage, Hertfordshire is currently looking to recruit a Cyber Security Engineer subcontractor on an initial 24 month contract. This position can start on a SC Security Clearance and will later on require DV Security Clearance. Rate: £92.11 per hour Location: Stevenage Hybrid / Remote working: Onsite 5 days per week Contract: 37 Hours per week Overtime: Hours worked over 37 hours per week will be calculated at 'time and a quarter' Duration: 24 Months (initially and then ongoing and long-term thereafter) IR35 status: Inside IR35 (Umbrella) Cyber Security Engineer Job Description: An opportunity has arisen in the Cyber Security Operations Centre (SOC) within Digital Excellence (DEX) UK for a Cyber Security Engineer. The successful applicant will lead on the technical aspects of ensuring cyber security appliance efficiency of tasks to support alert tuning, network visibility and log ingesting to relevant toolsets. They will advise on implementation of new tools and lead the updating and expansion of existing capabilities. Reporting to the Cyber Security Capability Manager, the Cyber Security Engineer will provide support by ensuring availability, readiness and resilience of cyber security tool sets within in scope environments. Responsibilities: We are looking for a Cyber Security Engineer to support the Cyber Security Capability Manager in ensuring Digital Excellence UK meets the challenges and demands of countering the Cyber Threat. To work with other UK Cyber Security members, the role will cover back-end refresh, playbook scripting and fault finding, Cyber Security tool upgrades, capability implementation, tool integration, data source on-boarding and investigation activity utilising a wide variety of security platforms including but not limited to; SIEM (Security Information Event Management), Network Packet Capture platform, Anti Malicious Code, Threat Detection technologies and platforms across the in-scope UK networks. The SOC Threat Detection Analyst key responsibilities are: Accountable for the effective mapping and topology of SOC toolsets including integrations and feeds between solutions Enriching the visibility and optimisation of SOC tools through data modelling and tuning Maintain the primary SOC toolsets, ensuring their availability, functionality and optimisation Responsible for the daily muster and availability of all cyber security technologies within in-scope environments Responsible for the accurate tracking of product lifecycle and advising management of EOL/EOS roadmaps Support the Cyber Security Capability Manager in the coordination, planning and execution of SOC appliance upgrades To support all cyber security pillars with new capability implementation and integration to existing solutions Implement cyber security tool changes and configuration ensuring efficient reporting into CAB and control boards To lead on playbook scripting activities ensuring they are well documented and tested. This includes fault finding and review of false positives To be the Subject Matter Expert (SME) on SOC connectivity and visibility across all in scope networks and infrastructure, ensuring connections and integrations are understood and documented with the Cyber Security Capability Manager To lead all activity of back-end refresh on cyber security appliances - including certificate updates, patch releases and software updates Responsible for attending DEX CAB and collating all impacting activities on cyber security alerting Responsible for attending DEX Incident and Issue red teams in support of root cause analysis - advising on cyber security changes which may impact other services Collaborate closely with DEX back office to maintain availability and efficiency of cyber security tools and recover any service outages or disruption Support the SOC in investigation activity utilising a wide variety of security platforms, creating custom searches, advanced queries or scripts in order to find the root cause or IOC of an alert Skillset/experience required: Strong coding and scripting background - PowerShell, Python & Regex Proven ability to work with APIs, including HTTP/S headers and responses, JSON Objects. Proven experience with Proxies administration and changes. Windows (SMB) and Nix (NFS) remote storage. IIS (Windows Web Server) Configuration, Active Directory/ LDAP (authentication). Experience with applying certificates, software updates and the steps involved for end-of-life refresh activity. Experience with VMware/ Hyper-V Virtual machines and virtual switches. Experience in setting up, implementing and maintenance of cyber security tooling. Experience with the creation, testing and maintenance of AI or machine learning technologies to assist with the optimisation of work flows or play books. Experience with SIEM (Security Information Event Management) technologies
Sep 16, 2026
Full time
World Class Defence Organisation nased in Stevenage, Hertfordshire is currently looking to recruit a Cyber Security Engineer subcontractor on an initial 24 month contract. This position can start on a SC Security Clearance and will later on require DV Security Clearance. Rate: £92.11 per hour Location: Stevenage Hybrid / Remote working: Onsite 5 days per week Contract: 37 Hours per week Overtime: Hours worked over 37 hours per week will be calculated at 'time and a quarter' Duration: 24 Months (initially and then ongoing and long-term thereafter) IR35 status: Inside IR35 (Umbrella) Cyber Security Engineer Job Description: An opportunity has arisen in the Cyber Security Operations Centre (SOC) within Digital Excellence (DEX) UK for a Cyber Security Engineer. The successful applicant will lead on the technical aspects of ensuring cyber security appliance efficiency of tasks to support alert tuning, network visibility and log ingesting to relevant toolsets. They will advise on implementation of new tools and lead the updating and expansion of existing capabilities. Reporting to the Cyber Security Capability Manager, the Cyber Security Engineer will provide support by ensuring availability, readiness and resilience of cyber security tool sets within in scope environments. Responsibilities: We are looking for a Cyber Security Engineer to support the Cyber Security Capability Manager in ensuring Digital Excellence UK meets the challenges and demands of countering the Cyber Threat. To work with other UK Cyber Security members, the role will cover back-end refresh, playbook scripting and fault finding, Cyber Security tool upgrades, capability implementation, tool integration, data source on-boarding and investigation activity utilising a wide variety of security platforms including but not limited to; SIEM (Security Information Event Management), Network Packet Capture platform, Anti Malicious Code, Threat Detection technologies and platforms across the in-scope UK networks. The SOC Threat Detection Analyst key responsibilities are: Accountable for the effective mapping and topology of SOC toolsets including integrations and feeds between solutions Enriching the visibility and optimisation of SOC tools through data modelling and tuning Maintain the primary SOC toolsets, ensuring their availability, functionality and optimisation Responsible for the daily muster and availability of all cyber security technologies within in-scope environments Responsible for the accurate tracking of product lifecycle and advising management of EOL/EOS roadmaps Support the Cyber Security Capability Manager in the coordination, planning and execution of SOC appliance upgrades To support all cyber security pillars with new capability implementation and integration to existing solutions Implement cyber security tool changes and configuration ensuring efficient reporting into CAB and control boards To lead on playbook scripting activities ensuring they are well documented and tested. This includes fault finding and review of false positives To be the Subject Matter Expert (SME) on SOC connectivity and visibility across all in scope networks and infrastructure, ensuring connections and integrations are understood and documented with the Cyber Security Capability Manager To lead all activity of back-end refresh on cyber security appliances - including certificate updates, patch releases and software updates Responsible for attending DEX CAB and collating all impacting activities on cyber security alerting Responsible for attending DEX Incident and Issue red teams in support of root cause analysis - advising on cyber security changes which may impact other services Collaborate closely with DEX back office to maintain availability and efficiency of cyber security tools and recover any service outages or disruption Support the SOC in investigation activity utilising a wide variety of security platforms, creating custom searches, advanced queries or scripts in order to find the root cause or IOC of an alert Skillset/experience required: Strong coding and scripting background - PowerShell, Python & Regex Proven ability to work with APIs, including HTTP/S headers and responses, JSON Objects. Proven experience with Proxies administration and changes. Windows (SMB) and Nix (NFS) remote storage. IIS (Windows Web Server) Configuration, Active Directory/ LDAP (authentication). Experience with applying certificates, software updates and the steps involved for end-of-life refresh activity. Experience with VMware/ Hyper-V Virtual machines and virtual switches. Experience in setting up, implementing and maintenance of cyber security tooling. Experience with the creation, testing and maintenance of AI or machine learning technologies to assist with the optimisation of work flows or play books. Experience with SIEM (Security Information Event Management) technologies
Advantage Resourcing UK Ltd
Stevenage, Hertfordshire
World Class Defence Organisation is currently looking to recruit a Cyber Security Engineer subcontractor on an initial 24 month contract. People from a background working as a Cyber Security Engineer, SOC Engineer, SOC Analyst, Senior SOC Analyst, Cyber Security Analyst, Security Operations Engineer, SIEM Engineer, SIEM Analyst, Threat Detection Engineer, Security Infrastructure Engineer would be well suited to this position. Rate:£92.11 per hour Location: Stevenage Hybrid / Remote working:Onsite 5 days per week Contract:37 Hours per week Overtime:Hours worked over 37 hours per week will be calculated at 'time and a quarter' Duration:24 Months (initially and then ongoing and long-term thereafter) IR35 status:Inside IR35 (Umbrella) Cyber Security Engineer Job Description: An opportunity has arisen in the Cyber Security Operations Centre (SOC) within Digital Excellence (DEX) UK for a Cyber Security Engineer. The successful applicant will lead on the technical aspects of ensuring cyber security appliance efficiency of tasks to support alert tuning, network visibility and log ingesting to relevant toolsets. They will advise on implementation of new tools and lead the updating and expansion of existing capabilities. Reporting to the Cyber Security Capability Manager, the Cyber Security Engineer will provide support by ensuring availability, readiness and resilience of cyber security tool sets within in scope environments. Responsibilities: We are looking for a Cyber Security Engineer to support the Cyber Security Capability Manager in ensuring Digital Excellence UK meets the challenges and demands of countering the Cyber Threat. To work with other UK Cyber Security members, the role will cover back-end refresh, playbook scripting and fault finding, Cyber Security tool upgrades, capability implementation, tool integration, data source on-boarding and investigation activity utilising a wide variety of security platforms including but not limited to; SIEM (Security Information Event Management), Network Packet Capture platform, Anti Malicious Code, Threat Detection technologies and platforms across the in-scope UK networks. Accountable for the effective mapping and topology of SOC toolsets including integrations and feeds between solutions Enriching the visibility and optimisation of SOC tools through data modelling and tuning Maintain the primary SOC toolsets, ensuring their availability, functionality and optimisation Responsible for the daily muster and availability of all cyber security technologies within in-scope environments Responsible for the accurate tracking of product lifecycle and advising management of EOL/EOS roadmaps Support the Cyber Security Capability Manager in the coordination, planning and execution of SOC appliance upgrades To support all cyber security pillars with new capability implementation and integration to existing solutions Implement cyber security tool changes and configuration ensuring efficient reporting into CAB and control boards To lead on playbook scripting activities ensuring they are well documented and tested. This includes fault finding and review of false positives To be the Subject Matter Expert (SME) on SOC connectivity and visibility across all in scope networks and infrastructure, ensuring connections and integrations are understood and documented with the Cyber Security Capability Manager To lead all activity of back-end refresh on cyber security appliances - including certificate updates, patch releases and software updates Responsible for attending DEX CAB and collating all impacting activities on cyber security alerting Responsible for attending DEX Incident and Issue red teams in support of root cause analysis - advising on cyber security changes which may impact other services Collaborate closely with DEX back office to maintain availability and efficiency of cyber security tools and recover any service outages or disruption Support the SOC in investigation activity utilising a wide variety of security platforms, creating custom searches, advanced queries or scripts in order to find the root cause or IOC of an alert Skillset/experience required: Strong coding and scripting background - PowerShell, Python & Regex Proven ability to work with APIs, including HTTP/S headers and responses, JSON Objects. Proven experience with Proxies administration and changes. Windows (SMB) and Nix (NFS) remote storage. IIS (Windows Web Server) Configuration, Active Directory/ LDAP (authentication). Experience with applying certificates, software updates and the steps involved for end-of-life refresh activity. Experience with VMware/ Hyper-V Virtual machines and virtual switches. Experience in setting up, implementing and maintenance of cyber security tooling. Experience with the creation, testing and maintenance of AI or machine learning technologies to assist with the optimisation of work flows or play books. Experience with SIEM (Security Information Event Management) technologies
Aug 30, 2026
Full time
World Class Defence Organisation is currently looking to recruit a Cyber Security Engineer subcontractor on an initial 24 month contract. People from a background working as a Cyber Security Engineer, SOC Engineer, SOC Analyst, Senior SOC Analyst, Cyber Security Analyst, Security Operations Engineer, SIEM Engineer, SIEM Analyst, Threat Detection Engineer, Security Infrastructure Engineer would be well suited to this position. Rate:£92.11 per hour Location: Stevenage Hybrid / Remote working:Onsite 5 days per week Contract:37 Hours per week Overtime:Hours worked over 37 hours per week will be calculated at 'time and a quarter' Duration:24 Months (initially and then ongoing and long-term thereafter) IR35 status:Inside IR35 (Umbrella) Cyber Security Engineer Job Description: An opportunity has arisen in the Cyber Security Operations Centre (SOC) within Digital Excellence (DEX) UK for a Cyber Security Engineer. The successful applicant will lead on the technical aspects of ensuring cyber security appliance efficiency of tasks to support alert tuning, network visibility and log ingesting to relevant toolsets. They will advise on implementation of new tools and lead the updating and expansion of existing capabilities. Reporting to the Cyber Security Capability Manager, the Cyber Security Engineer will provide support by ensuring availability, readiness and resilience of cyber security tool sets within in scope environments. Responsibilities: We are looking for a Cyber Security Engineer to support the Cyber Security Capability Manager in ensuring Digital Excellence UK meets the challenges and demands of countering the Cyber Threat. To work with other UK Cyber Security members, the role will cover back-end refresh, playbook scripting and fault finding, Cyber Security tool upgrades, capability implementation, tool integration, data source on-boarding and investigation activity utilising a wide variety of security platforms including but not limited to; SIEM (Security Information Event Management), Network Packet Capture platform, Anti Malicious Code, Threat Detection technologies and platforms across the in-scope UK networks. Accountable for the effective mapping and topology of SOC toolsets including integrations and feeds between solutions Enriching the visibility and optimisation of SOC tools through data modelling and tuning Maintain the primary SOC toolsets, ensuring their availability, functionality and optimisation Responsible for the daily muster and availability of all cyber security technologies within in-scope environments Responsible for the accurate tracking of product lifecycle and advising management of EOL/EOS roadmaps Support the Cyber Security Capability Manager in the coordination, planning and execution of SOC appliance upgrades To support all cyber security pillars with new capability implementation and integration to existing solutions Implement cyber security tool changes and configuration ensuring efficient reporting into CAB and control boards To lead on playbook scripting activities ensuring they are well documented and tested. This includes fault finding and review of false positives To be the Subject Matter Expert (SME) on SOC connectivity and visibility across all in scope networks and infrastructure, ensuring connections and integrations are understood and documented with the Cyber Security Capability Manager To lead all activity of back-end refresh on cyber security appliances - including certificate updates, patch releases and software updates Responsible for attending DEX CAB and collating all impacting activities on cyber security alerting Responsible for attending DEX Incident and Issue red teams in support of root cause analysis - advising on cyber security changes which may impact other services Collaborate closely with DEX back office to maintain availability and efficiency of cyber security tools and recover any service outages or disruption Support the SOC in investigation activity utilising a wide variety of security platforms, creating custom searches, advanced queries or scripts in order to find the root cause or IOC of an alert Skillset/experience required: Strong coding and scripting background - PowerShell, Python & Regex Proven ability to work with APIs, including HTTP/S headers and responses, JSON Objects. Proven experience with Proxies administration and changes. Windows (SMB) and Nix (NFS) remote storage. IIS (Windows Web Server) Configuration, Active Directory/ LDAP (authentication). Experience with applying certificates, software updates and the steps involved for end-of-life refresh activity. Experience with VMware/ Hyper-V Virtual machines and virtual switches. Experience in setting up, implementing and maintenance of cyber security tooling. Experience with the creation, testing and maintenance of AI or machine learning technologies to assist with the optimisation of work flows or play books. Experience with SIEM (Security Information Event Management) technologies
World Class Defence Organisation is currently looking to recruit a Cyber Security Engineer subcontractor on an initial 24 month contract. People from a background working as a Cyber Security Engineer, SOC Engineer, SOC Analyst, Senior SOC Analyst, Cyber Security Analyst, Security Operations Engineer, SIEM Engineer, SIEM Analyst, Threat Detection Engineer, Security Infrastructure Engineer would be well suited to this position. Rate: £92.11 per hour Location: Stevenage Hybrid / Remote working: Onsite 5 days per week Contract: 37 Hours per week Overtime: Hours worked over 37 hours per week will be calculated at 'time and a quarter' Duration: 24 Months (initially and then ongoing and long-term thereafter) IR35 status: Inside IR35 (Umbrella) Cyber Security Engineer Job Description: An opportunity has arisen in the Cyber Security Operations Centre (SOC) within Digital Excellence (DEX) UK for a Cyber Security Engineer. The successful applicant will lead on the technical aspects of ensuring cyber security appliance efficiency of tasks to support alert tuning, network visibility and log ingesting to relevant toolsets. They will advise on implementation of new tools and lead the updating and expansion of existing capabilities. Reporting to the Cyber Security Capability Manager, the Cyber Security Engineer will provide support by ensuring availability, readiness and resilience of cyber security tool sets within in scope environments. Responsibilities: We are looking for a Cyber Security Engineer to support the Cyber Security Capability Manager in ensuring Digital Excellence UK meets the challenges and demands of countering the Cyber Threat. To work with other UK Cyber Security members, the role will cover back-end refresh, playbook scripting and fault finding, Cyber Security tool upgrades, capability implementation, tool integration, data source on-boarding and investigation activity utilising a wide variety of security platforms including but not limited to; SIEM (Security Information Event Management), Network Packet Capture platform, Anti Malicious Code, Threat Detection technologies and platforms across the in-scope UK networks. The SOC Threat Detection Analyst key responsibilities are: Accountable for the effective mapping and topology of SOC toolsets including integrations and feeds between solutions Enriching the visibility and optimisation of SOC tools through data modelling and tuning Maintain the primary SOC toolsets, ensuring their availability, functionality and optimisation Responsible for the daily muster and availability of all cyber security technologies within in-scope environments Responsible for the accurate tracking of product lifecycle and advising management of EOL/EOS roadmaps Support the Cyber Security Capability Manager in the coordination, planning and execution of SOC appliance upgrades To support all cyber security pillars with new capability implementation and integration to existing solutions Implement cyber security tool changes and configuration ensuring efficient reporting into CAB and control boards To lead on playbook scripting activities ensuring they are well documented and tested. This includes fault finding and review of false positives To be the Subject Matter Expert (SME) on SOC connectivity and visibility across all in scope networks and infrastructure, ensuring connections and integrations are understood and documented with the Cyber Security Capability Manager To lead all activity of back-end refresh on cyber security appliances - including certificate updates, patch releases and software updates Responsible for attending DEX CAB and collating all impacting activities on cyber security alerting Responsible for attending DEX Incident and Issue red teams in support of root cause analysis - advising on cyber security changes which may impact other services Collaborate closely with DEX back office to maintain availability and efficiency of cyber security tools and recover any service outages or disruption Support the SOC in investigation activity utilising a wide variety of security platforms, creating custom searches, advanced queries or scripts in order to find the root cause or IOC of an alert Skillset/experience required: Strong coding and scripting background - PowerShell, Python & Regex Proven ability to work with APIs, including HTTP/S headers and responses, JSON Objects. Proven experience with Proxies administration and changes. Windows (SMB) and Nix (NFS) remote storage. IIS (Windows Web Server) Configuration, Active Directory/ LDAP (authentication). Experience with applying certificates, software updates and the steps involved for end-of-life refresh activity. Experience with VMware/ Hyper-V Virtual machines and virtual switches. Experience in setting up, implementing and maintenance of cyber security tooling. Experience with the creation, testing and maintenance of AI or machine learning technologies to assist with the optimisation of work flows or play books. Experience with SIEM (Security Information Event Management) technologies
Aug 29, 2026
Full time
World Class Defence Organisation is currently looking to recruit a Cyber Security Engineer subcontractor on an initial 24 month contract. People from a background working as a Cyber Security Engineer, SOC Engineer, SOC Analyst, Senior SOC Analyst, Cyber Security Analyst, Security Operations Engineer, SIEM Engineer, SIEM Analyst, Threat Detection Engineer, Security Infrastructure Engineer would be well suited to this position. Rate: £92.11 per hour Location: Stevenage Hybrid / Remote working: Onsite 5 days per week Contract: 37 Hours per week Overtime: Hours worked over 37 hours per week will be calculated at 'time and a quarter' Duration: 24 Months (initially and then ongoing and long-term thereafter) IR35 status: Inside IR35 (Umbrella) Cyber Security Engineer Job Description: An opportunity has arisen in the Cyber Security Operations Centre (SOC) within Digital Excellence (DEX) UK for a Cyber Security Engineer. The successful applicant will lead on the technical aspects of ensuring cyber security appliance efficiency of tasks to support alert tuning, network visibility and log ingesting to relevant toolsets. They will advise on implementation of new tools and lead the updating and expansion of existing capabilities. Reporting to the Cyber Security Capability Manager, the Cyber Security Engineer will provide support by ensuring availability, readiness and resilience of cyber security tool sets within in scope environments. Responsibilities: We are looking for a Cyber Security Engineer to support the Cyber Security Capability Manager in ensuring Digital Excellence UK meets the challenges and demands of countering the Cyber Threat. To work with other UK Cyber Security members, the role will cover back-end refresh, playbook scripting and fault finding, Cyber Security tool upgrades, capability implementation, tool integration, data source on-boarding and investigation activity utilising a wide variety of security platforms including but not limited to; SIEM (Security Information Event Management), Network Packet Capture platform, Anti Malicious Code, Threat Detection technologies and platforms across the in-scope UK networks. The SOC Threat Detection Analyst key responsibilities are: Accountable for the effective mapping and topology of SOC toolsets including integrations and feeds between solutions Enriching the visibility and optimisation of SOC tools through data modelling and tuning Maintain the primary SOC toolsets, ensuring their availability, functionality and optimisation Responsible for the daily muster and availability of all cyber security technologies within in-scope environments Responsible for the accurate tracking of product lifecycle and advising management of EOL/EOS roadmaps Support the Cyber Security Capability Manager in the coordination, planning and execution of SOC appliance upgrades To support all cyber security pillars with new capability implementation and integration to existing solutions Implement cyber security tool changes and configuration ensuring efficient reporting into CAB and control boards To lead on playbook scripting activities ensuring they are well documented and tested. This includes fault finding and review of false positives To be the Subject Matter Expert (SME) on SOC connectivity and visibility across all in scope networks and infrastructure, ensuring connections and integrations are understood and documented with the Cyber Security Capability Manager To lead all activity of back-end refresh on cyber security appliances - including certificate updates, patch releases and software updates Responsible for attending DEX CAB and collating all impacting activities on cyber security alerting Responsible for attending DEX Incident and Issue red teams in support of root cause analysis - advising on cyber security changes which may impact other services Collaborate closely with DEX back office to maintain availability and efficiency of cyber security tools and recover any service outages or disruption Support the SOC in investigation activity utilising a wide variety of security platforms, creating custom searches, advanced queries or scripts in order to find the root cause or IOC of an alert Skillset/experience required: Strong coding and scripting background - PowerShell, Python & Regex Proven ability to work with APIs, including HTTP/S headers and responses, JSON Objects. Proven experience with Proxies administration and changes. Windows (SMB) and Nix (NFS) remote storage. IIS (Windows Web Server) Configuration, Active Directory/ LDAP (authentication). Experience with applying certificates, software updates and the steps involved for end-of-life refresh activity. Experience with VMware/ Hyper-V Virtual machines and virtual switches. Experience in setting up, implementing and maintenance of cyber security tooling. Experience with the creation, testing and maintenance of AI or machine learning technologies to assist with the optimisation of work flows or play books. Experience with SIEM (Security Information Event Management) technologies
Roke, Roke Manor, Romsey, Hampshire, United Kingdom Roke, Semaphore House, Fareham, Hampshire, United Kingdom Job Description Great ideas come from different minds. That's why we bring together engineers, scientists, analysts, and creatives from every background - and give them the trust, tools, and freedom to make a difference. What connects us is the mission: solving meaningful problems and building capability that protects what matters most. And as the challenges evolve, so do we - working on the technologies that will shape tomorrow, not just today. Roke is a UK technology company with a long heritage of helping customers address complex national security, defence and public safety challenges. Roke brings together mission insight, engineering expertise, data science, cyber, AI, communications and specialist technology to anticipate, build and protect against evolving threats. An opportunity exists for a Commercial Manager - Defence (Languard) within the Roke Commercial team at an important stage in Roke's evolution in the Reignite Roke era, as the business strengthens customer focus, creates clearer routes to growth and aligns commercial support more closely with Revenue & Growth, Technology & Innovation, Global Services and Products. The Commercial Manager - Defence (Languard) will support delivery of commercial services to the Defence business function, working closely with the Head of Commercial - Defence and the wider Revenue & Growth Defence team. The role will provide commercial support from early opportunity shaping, customer engagement and bid activity through contract negotiation, acceptance, delivery and in-service contract management. Summary of the Role The Commercial Manager - Defence (Languard) will provide robust, proactive and pragmatic commercial management for opportunities, contracts, campaigns, products, services and customer engagements within the Defence business function. The role will support Roke's Reignite Roke growth strategy by helping the business convert opportunities into well-structured, compliant and commercially sound contracts, while maintaining an appropriate balance between customer focus, business growth, risk management, governance and contractual discipline. The successful candidate will operate with clarity, pace and attention to detail, building positive working relationships with internal bid, delivery, finance, technology, account and programme teams, as well as external customers, partners and suppliers. The role will also contribute to commercial continuous improvement, knowledge sharing and the practical adoption of approved IT tools and AI-enabled ways of working to improve the quality, consistency and speed of commercial support. Job Purpose and Key Responsibilities Provide commercial management support to the Languard area within Revenue & Growth Defence, including customer engagement, opportunity qualification, bidding, contract negotiation, contract acceptance and in-service contract management. Support Roke's Reignite Roke growth strategy by delivering commercially sound support to Defence account growth, sales campaigns, products, services and IP exploitation opportunities. Draft, review, negotiate and implement contracts and other commercial agreements, including confidentiality agreements, teaming agreements, subcontracting arrangements, licence agreements and similar documents. Support bids, quotations and applications to UK local and national Government bodies, Ministry of Defence and Crown Commercial Service frameworks or other relevant contracting mechanisms. Provide commercial support to international opportunities where required, including overseas product or managed services sales, IP exploitation, collaboration arrangements and associated commercial structures, with due consideration to trade compliance obligations. Undertake commercial, financial, contractual and business risk and opportunity management during opportunity shaping, bidding, contract negotiation, contract delivery and in-service contract management. Work closely with Revenue & Growth Defence, delivery, finance and technical teams to convert quotations and bids into orders, maintaining customer focus through diligent and accurate contract administration. Support the establishment and management of relationships with business sales partners, working with Roke Trade Compliance Team, including review, approval, support and monitoring of adherence to Company and Chemring Group policies and business governance requirements. Ensure compliance with Roke and Chemring policies, procedures and governance requirements, including appropriate process tailoring and escalation where required. Proactively identify opportunities to improve commercial processes, templates, ways of working and knowledge sharing, supporting the objective of making Roke easier to do business with while maintaining appropriate governance, compliance and risk management. Promote and use approved IT tools and AI-enabled ways of working to improve commercial productivity, consistency, quality of output and responsiveness. Provide guidance, coaching and commercial support to colleagues in the Commercial team and other functions in the course of the role. Support other Defence or non-Defence business areas as reasonably required, consistent with the job holder's experience, capability and business need. Undertake such other reasonable duties, commensurate with the job holder's experience and qualifications, as may be required for the smooth operation of the business. Education and Qualifications Educated in a Business or Legal based discipline, preferably to degree level, or able to demonstrate equivalent relevant industry experience. Existing knowledge of UK Government contracting frameworks and mechanisms would be an advantage. High level of computer literacy is essential, including confident use of Microsoft Office, Teams, collaborative working tools and approved business systems. Knowledge, Skills and Experience Demonstrable experience in a relevant commercial, contracts, procurement, business management or related role. Experience working with UK Ministry of Defence, UK Government customers or Defence-sector contracting environments. Knowledge and understanding of commercial and Defence terms and conditions, with the ability to review, negotiate and implement a variety of contract types. Experience of UK HMG, Crown Commercial Service frameworks, Dynamic Purchasing Systems or similar public sector procurement routes would be an advantage. Proven ability to support or lead contract negotiations with government and non-government customers, partners and suppliers. Ability to draft, negotiate and implement contracts, change requests and commercial agreements with excellent attention to detail. Competence in contractual costing, contingencies, provisions, milestone planning, payment planning, contractual risk management and contract negotiation. Experience supporting bid submissions, commercial risk reviews, pricing submissions, cashflow planning and payment plan development in collaboration with finance teams. Experience of international business, overseas product or service sales, IP exploitation, performance bonds, guarantees or letters of credit would be advantageous, particularly in a Defence context. Highly organised, with the ability to maintain focus, manage priorities and deliver quality outputs under pressure. Able to work to deadlines and act as a positive influence in achieving team and business goals. Confident communicator with strong written and verbal communication skills, able to interact effectively with colleagues, customers, partners and suppliers at all levels. Ability to use, promote and improve IT tooling and approved AI-enabled ways of working to support commercial productivity, process improvement, knowledge sharing and continuous improvement. Willingness to travel on business where required, including occasional overseas travel if necessary. Why You Should Join Us We offer a competitive salary and access to a number of additional flexible benefits, which will cover Health and Wellbeing, Savings and Protection & Life, Leisure and Entertainment. Roke has a great community of groups with shared interests. These enable people to share ideas and be passionate about tools, technologies & techniques, which interest them. We are committed to a policy of Equal Opportunity, Diversity and Inclusion. Our working environment is friendly, creative and inclusive and support a diverse work-force and those with additional needs. Security Due to the nature of this position, the successful candidate will be submitted for and will need to pass UK SC security clearance, if not held already. As a result, the candidate should have resided in the UK for the last five years for SC clearance purposes. The Next Step Roke, Roke Manor, Romsey, Hampshire, United Kingdom, Roke, Semaphore House, Fareham, Hampshire, United Kingdom
Aug 28, 2026
Full time
Roke, Roke Manor, Romsey, Hampshire, United Kingdom Roke, Semaphore House, Fareham, Hampshire, United Kingdom Job Description Great ideas come from different minds. That's why we bring together engineers, scientists, analysts, and creatives from every background - and give them the trust, tools, and freedom to make a difference. What connects us is the mission: solving meaningful problems and building capability that protects what matters most. And as the challenges evolve, so do we - working on the technologies that will shape tomorrow, not just today. Roke is a UK technology company with a long heritage of helping customers address complex national security, defence and public safety challenges. Roke brings together mission insight, engineering expertise, data science, cyber, AI, communications and specialist technology to anticipate, build and protect against evolving threats. An opportunity exists for a Commercial Manager - Defence (Languard) within the Roke Commercial team at an important stage in Roke's evolution in the Reignite Roke era, as the business strengthens customer focus, creates clearer routes to growth and aligns commercial support more closely with Revenue & Growth, Technology & Innovation, Global Services and Products. The Commercial Manager - Defence (Languard) will support delivery of commercial services to the Defence business function, working closely with the Head of Commercial - Defence and the wider Revenue & Growth Defence team. The role will provide commercial support from early opportunity shaping, customer engagement and bid activity through contract negotiation, acceptance, delivery and in-service contract management. Summary of the Role The Commercial Manager - Defence (Languard) will provide robust, proactive and pragmatic commercial management for opportunities, contracts, campaigns, products, services and customer engagements within the Defence business function. The role will support Roke's Reignite Roke growth strategy by helping the business convert opportunities into well-structured, compliant and commercially sound contracts, while maintaining an appropriate balance between customer focus, business growth, risk management, governance and contractual discipline. The successful candidate will operate with clarity, pace and attention to detail, building positive working relationships with internal bid, delivery, finance, technology, account and programme teams, as well as external customers, partners and suppliers. The role will also contribute to commercial continuous improvement, knowledge sharing and the practical adoption of approved IT tools and AI-enabled ways of working to improve the quality, consistency and speed of commercial support. Job Purpose and Key Responsibilities Provide commercial management support to the Languard area within Revenue & Growth Defence, including customer engagement, opportunity qualification, bidding, contract negotiation, contract acceptance and in-service contract management. Support Roke's Reignite Roke growth strategy by delivering commercially sound support to Defence account growth, sales campaigns, products, services and IP exploitation opportunities. Draft, review, negotiate and implement contracts and other commercial agreements, including confidentiality agreements, teaming agreements, subcontracting arrangements, licence agreements and similar documents. Support bids, quotations and applications to UK local and national Government bodies, Ministry of Defence and Crown Commercial Service frameworks or other relevant contracting mechanisms. Provide commercial support to international opportunities where required, including overseas product or managed services sales, IP exploitation, collaboration arrangements and associated commercial structures, with due consideration to trade compliance obligations. Undertake commercial, financial, contractual and business risk and opportunity management during opportunity shaping, bidding, contract negotiation, contract delivery and in-service contract management. Work closely with Revenue & Growth Defence, delivery, finance and technical teams to convert quotations and bids into orders, maintaining customer focus through diligent and accurate contract administration. Support the establishment and management of relationships with business sales partners, working with Roke Trade Compliance Team, including review, approval, support and monitoring of adherence to Company and Chemring Group policies and business governance requirements. Ensure compliance with Roke and Chemring policies, procedures and governance requirements, including appropriate process tailoring and escalation where required. Proactively identify opportunities to improve commercial processes, templates, ways of working and knowledge sharing, supporting the objective of making Roke easier to do business with while maintaining appropriate governance, compliance and risk management. Promote and use approved IT tools and AI-enabled ways of working to improve commercial productivity, consistency, quality of output and responsiveness. Provide guidance, coaching and commercial support to colleagues in the Commercial team and other functions in the course of the role. Support other Defence or non-Defence business areas as reasonably required, consistent with the job holder's experience, capability and business need. Undertake such other reasonable duties, commensurate with the job holder's experience and qualifications, as may be required for the smooth operation of the business. Education and Qualifications Educated in a Business or Legal based discipline, preferably to degree level, or able to demonstrate equivalent relevant industry experience. Existing knowledge of UK Government contracting frameworks and mechanisms would be an advantage. High level of computer literacy is essential, including confident use of Microsoft Office, Teams, collaborative working tools and approved business systems. Knowledge, Skills and Experience Demonstrable experience in a relevant commercial, contracts, procurement, business management or related role. Experience working with UK Ministry of Defence, UK Government customers or Defence-sector contracting environments. Knowledge and understanding of commercial and Defence terms and conditions, with the ability to review, negotiate and implement a variety of contract types. Experience of UK HMG, Crown Commercial Service frameworks, Dynamic Purchasing Systems or similar public sector procurement routes would be an advantage. Proven ability to support or lead contract negotiations with government and non-government customers, partners and suppliers. Ability to draft, negotiate and implement contracts, change requests and commercial agreements with excellent attention to detail. Competence in contractual costing, contingencies, provisions, milestone planning, payment planning, contractual risk management and contract negotiation. Experience supporting bid submissions, commercial risk reviews, pricing submissions, cashflow planning and payment plan development in collaboration with finance teams. Experience of international business, overseas product or service sales, IP exploitation, performance bonds, guarantees or letters of credit would be advantageous, particularly in a Defence context. Highly organised, with the ability to maintain focus, manage priorities and deliver quality outputs under pressure. Able to work to deadlines and act as a positive influence in achieving team and business goals. Confident communicator with strong written and verbal communication skills, able to interact effectively with colleagues, customers, partners and suppliers at all levels. Ability to use, promote and improve IT tooling and approved AI-enabled ways of working to support commercial productivity, process improvement, knowledge sharing and continuous improvement. Willingness to travel on business where required, including occasional overseas travel if necessary. Why You Should Join Us We offer a competitive salary and access to a number of additional flexible benefits, which will cover Health and Wellbeing, Savings and Protection & Life, Leisure and Entertainment. Roke has a great community of groups with shared interests. These enable people to share ideas and be passionate about tools, technologies & techniques, which interest them. We are committed to a policy of Equal Opportunity, Diversity and Inclusion. Our working environment is friendly, creative and inclusive and support a diverse work-force and those with additional needs. Security Due to the nature of this position, the successful candidate will be submitted for and will need to pass UK SC security clearance, if not held already. As a result, the candidate should have resided in the UK for the last five years for SC clearance purposes. The Next Step Roke, Roke Manor, Romsey, Hampshire, United Kingdom, Roke, Semaphore House, Fareham, Hampshire, United Kingdom
Senior Technology Risk AnalystApplylocations: London, UKtime type: Full timeposted on: Posted Todayjob requisition id: R17061 Job Title Senior Technology Risk Analyst Job Description We collaborate with clients across Europe, Asia, Australia and North America, specialising in risks associated with Life, Critical Illness, Income Protection, Hospital Cash and Longevity products. Our clients are insurance or reinsurance companies looking for a new and innovative approach to taking risks.With the security and financial strength of a parent company that has been around for over 145 years and a mutual holding company as our ultimate parent, we are not constrained by short-term thinking; therefore, allowing us to be free to pursue the right course for our clients and our business.Underlying our philosophy is an intelligent approach to taking risks. By recruiting top quality staff and investing in the latest analytical technologies, we believe we are well placed to make those decisions. The Role We have an exciting permanent opportunity available within the Division Centre Technology Risk team, based out of our London office.This role is suited to an experienced professional seeking to deepen their expertise in Technology Risk within a global organisation. You will play a key role in delivering risk management activities, providing subject matter expertise, and driving improvements across technology, risk frameworks, and emerging areas such as AI.Primary responsibilities will include providing technology risk subject matter expertise, support and guidance to the global Technology team, specifically:• Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Analyse and manage incidents and operational events, identify root causes and systemic control weaknesses using data analytics, and drive action plans to completion with effective monitoring, escalation, and senior management reporting, focusing on optimisation and efficiency. • Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Helping to define and maintain key risk indicators, including exploring automated data feeds and AI-driven insights, assisting in the preparation of reporting to divisional senior Technology management, Operational Risk & Resilience, and the Operational Risk Management Committee. • Participating in working groups on specific technology risk topics (e.g. cyber, IT asset management, data management and governance), including the safe adoption of emerging technologies such as AI. • Providing SME input and support to the Technology team with regards to risks, issues and operational events logged in our GRC platform, including opportunities to enhance data quality and workflow automation. • Supporting Technology by acting as a point of contact and "bridge" between them and other lines of defence, such as Operational Risk, Internal Audit, and External Audit. • Driving the modernisation of technology risk processes through the use of automation, data analytics and AI-enabled solutions (e.g. process automation, intelligent risk assessments, enhanced reporting). • Identifying opportunities to improve efficiency, scalability and consistency of risk processes, and supporting the design and implementation of solutions where appropriate. • Supporting client engagement teams through responding to technical due diligence requests from current and potential clients. • Performing risk assessments of new technologies entering the environment, including AI/ML solutions, ensuring that risks are identified and appropriate controls are in place. Skills, Knowledge & Experience Required- Minimum 4 years' experience of working within a risk / audit function - A solid understanding of current technology capabilities, including AI/ML concepts and their associated risks, and a keen interest in staying abreast of emerging technology trends (e.g. AI, automation, quantum computing). - Knowledge of and experience of implementing leading Technology risk framework and practices e.g. ISO27001, COBIT, NIST and supporting methodologies. - Experience or demonstrable interest in applying data analytics, automation, or AI tools to improve risk management processes and reporting. - Ability to manage own time and to work to strict deadlines - Strong organisational, analytical and stakeholder management skills - Detail oriented and well-organised with ability to work independently - Experienced in collaborating at all levels of an enterprise - Effective written and verbal communication from technical team direction to senior management presentations - Experience with undertaking RCSA or similar risk and controls assessments / audits - Creativity and initiative in work product, positive and helpful attitude proposing solutions to resolve problems - Ability to work flexibly to support colleagues that operate out of multiple locations / time-zones - Proficiency in using standard work environment software, such as Microsoft Office Suite Desired - Risk/IT professional certification such as CISA, CRISC, CPA, CISM, Six Sigma - Experience of working within the Insurance / Reinsurance industries - Degree within an IT related or similar discipline - Understanding of GRC platforms (e.g. Archer) - Comfortable operating in a dynamic, evolving environment with competing priorities - Confidence working with incomplete information and forming reasoned risk based conclusions - Experience applying judgement over checklist driven compliance, with an ability to prioritise risk proportionately - Exposure to AI governance, model risk management, or emerging regulatory expectations relating to AI Working For Pacific Life Re Every person in our global team is valued for the unique qualities they bring to our business and we seek to build their expertise and support their individual ambitions at every step. Of course, we take our work seriously and we know our team can operate under great pressure. We work hard and thrive on achievement, but we also know how to have fun and relax too. We regularly host a range of team building days to strengthen our team's connection with each other and reflect on their successes.Providing employees with a healthy work-life balance is very important to our culture. We have a wide range of employee benefits and we host regular social activities and well being initiatives. We are also committed to supporting our employee's involvement in their communities, by actively fundraising, hosting charity events and overseeing volunteering opportunities. Benefits (Only for Permanent and Fixed Term Employees) Leave 25 days of annual leave with option to buy/sell more days Adoption and fertility leave Generous enhanced parental leaveHealthcare Comprehensive private insurance coverage for employee and dependents Group Life Insurance coverage of 9x basic annual salary and Group Income Protection up to 75% of basic annual salary Optical benefitsSavings & Retirement 15% combined employee/employer contributionsWellness Subsidized gym membership Access to Employee Assistance Program Cycle to Work and Electric Car Salary Sacrifice Scheme Time off for volunteering Charitable matching of employee donations You Can Be Who You Are We are committed to a culture of diversity and inclusion that embraces the authenticity of all employees, partners and communities. We support all employees to thrive and achieve their fullest potential.As part of our commitment to diversity and inclusion, we will provide reasonable adjustments during the recruitment process to ensure equal access to applicants with disabilities. Please contact us about your needs so that we can discuss these with you to make sure that suitable adjustments are made, where possible. Pacific Life Re Values Please click here to view our company values
May 29, 2026
Full time
Senior Technology Risk AnalystApplylocations: London, UKtime type: Full timeposted on: Posted Todayjob requisition id: R17061 Job Title Senior Technology Risk Analyst Job Description We collaborate with clients across Europe, Asia, Australia and North America, specialising in risks associated with Life, Critical Illness, Income Protection, Hospital Cash and Longevity products. Our clients are insurance or reinsurance companies looking for a new and innovative approach to taking risks.With the security and financial strength of a parent company that has been around for over 145 years and a mutual holding company as our ultimate parent, we are not constrained by short-term thinking; therefore, allowing us to be free to pursue the right course for our clients and our business.Underlying our philosophy is an intelligent approach to taking risks. By recruiting top quality staff and investing in the latest analytical technologies, we believe we are well placed to make those decisions. The Role We have an exciting permanent opportunity available within the Division Centre Technology Risk team, based out of our London office.This role is suited to an experienced professional seeking to deepen their expertise in Technology Risk within a global organisation. You will play a key role in delivering risk management activities, providing subject matter expertise, and driving improvements across technology, risk frameworks, and emerging areas such as AI.Primary responsibilities will include providing technology risk subject matter expertise, support and guidance to the global Technology team, specifically:• Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Analyse and manage incidents and operational events, identify root causes and systemic control weaknesses using data analytics, and drive action plans to completion with effective monitoring, escalation, and senior management reporting, focusing on optimisation and efficiency. • Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Helping to define and maintain key risk indicators, including exploring automated data feeds and AI-driven insights, assisting in the preparation of reporting to divisional senior Technology management, Operational Risk & Resilience, and the Operational Risk Management Committee. • Participating in working groups on specific technology risk topics (e.g. cyber, IT asset management, data management and governance), including the safe adoption of emerging technologies such as AI. • Providing SME input and support to the Technology team with regards to risks, issues and operational events logged in our GRC platform, including opportunities to enhance data quality and workflow automation. • Supporting Technology by acting as a point of contact and "bridge" between them and other lines of defence, such as Operational Risk, Internal Audit, and External Audit. • Driving the modernisation of technology risk processes through the use of automation, data analytics and AI-enabled solutions (e.g. process automation, intelligent risk assessments, enhanced reporting). • Identifying opportunities to improve efficiency, scalability and consistency of risk processes, and supporting the design and implementation of solutions where appropriate. • Supporting client engagement teams through responding to technical due diligence requests from current and potential clients. • Performing risk assessments of new technologies entering the environment, including AI/ML solutions, ensuring that risks are identified and appropriate controls are in place. Skills, Knowledge & Experience Required- Minimum 4 years' experience of working within a risk / audit function - A solid understanding of current technology capabilities, including AI/ML concepts and their associated risks, and a keen interest in staying abreast of emerging technology trends (e.g. AI, automation, quantum computing). - Knowledge of and experience of implementing leading Technology risk framework and practices e.g. ISO27001, COBIT, NIST and supporting methodologies. - Experience or demonstrable interest in applying data analytics, automation, or AI tools to improve risk management processes and reporting. - Ability to manage own time and to work to strict deadlines - Strong organisational, analytical and stakeholder management skills - Detail oriented and well-organised with ability to work independently - Experienced in collaborating at all levels of an enterprise - Effective written and verbal communication from technical team direction to senior management presentations - Experience with undertaking RCSA or similar risk and controls assessments / audits - Creativity and initiative in work product, positive and helpful attitude proposing solutions to resolve problems - Ability to work flexibly to support colleagues that operate out of multiple locations / time-zones - Proficiency in using standard work environment software, such as Microsoft Office Suite Desired - Risk/IT professional certification such as CISA, CRISC, CPA, CISM, Six Sigma - Experience of working within the Insurance / Reinsurance industries - Degree within an IT related or similar discipline - Understanding of GRC platforms (e.g. Archer) - Comfortable operating in a dynamic, evolving environment with competing priorities - Confidence working with incomplete information and forming reasoned risk based conclusions - Experience applying judgement over checklist driven compliance, with an ability to prioritise risk proportionately - Exposure to AI governance, model risk management, or emerging regulatory expectations relating to AI Working For Pacific Life Re Every person in our global team is valued for the unique qualities they bring to our business and we seek to build their expertise and support their individual ambitions at every step. Of course, we take our work seriously and we know our team can operate under great pressure. We work hard and thrive on achievement, but we also know how to have fun and relax too. We regularly host a range of team building days to strengthen our team's connection with each other and reflect on their successes.Providing employees with a healthy work-life balance is very important to our culture. We have a wide range of employee benefits and we host regular social activities and well being initiatives. We are also committed to supporting our employee's involvement in their communities, by actively fundraising, hosting charity events and overseeing volunteering opportunities. Benefits (Only for Permanent and Fixed Term Employees) Leave 25 days of annual leave with option to buy/sell more days Adoption and fertility leave Generous enhanced parental leaveHealthcare Comprehensive private insurance coverage for employee and dependents Group Life Insurance coverage of 9x basic annual salary and Group Income Protection up to 75% of basic annual salary Optical benefitsSavings & Retirement 15% combined employee/employer contributionsWellness Subsidized gym membership Access to Employee Assistance Program Cycle to Work and Electric Car Salary Sacrifice Scheme Time off for volunteering Charitable matching of employee donations You Can Be Who You Are We are committed to a culture of diversity and inclusion that embraces the authenticity of all employees, partners and communities. We support all employees to thrive and achieve their fullest potential.As part of our commitment to diversity and inclusion, we will provide reasonable adjustments during the recruitment process to ensure equal access to applicants with disabilities. Please contact us about your needs so that we can discuss these with you to make sure that suitable adjustments are made, where possible. Pacific Life Re Values Please click here to view our company values
Senior Technology Risk AnalystApplylocations: London, UKtime type: Full timeposted on: Posted Todayjob requisition id: R17061 Job Title Senior Technology Risk Analyst Job Description We collaborate with clients across Europe, Asia, Australia and North America, specialising in risks associated with Life, Critical Illness, Income Protection, Hospital Cash and Longevity products. Our clients are insurance or reinsurance companies looking for a new and innovative approach to taking risks.With the security and financial strength of a parent company that has been around for over 145 years and a mutual holding company as our ultimate parent, we are not constrained by short-term thinking; therefore, allowing us to be free to pursue the right course for our clients and our business.Underlying our philosophy is an intelligent approach to taking risks. By recruiting top quality staff and investing in the latest analytical technologies, we believe we are well placed to make those decisions. The Role We have an exciting permanent opportunity available within the Division Centre Technology Risk team, based out of our London office.This role is suited to an experienced professional seeking to deepen their expertise in Technology Risk within a global organisation. You will play a key role in delivering risk management activities, providing subject matter expertise, and driving improvements across technology, risk frameworks, and emerging areas such as AI.Primary responsibilities will include providing technology risk subject matter expertise, support and guidance to the global Technology team, specifically:• Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Analyse and manage incidents and operational events, identify root causes and systemic control weaknesses using data analytics, and drive action plans to completion with effective monitoring, escalation, and senior management reporting, focusing on optimisation and efficiency. • Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Helping to define and maintain key risk indicators, including exploring automated data feeds and AI-driven insights, assisting in the preparation of reporting to divisional senior Technology management, Operational Risk & Resilience, and the Operational Risk Management Committee. • Participating in working groups on specific technology risk topics (e.g. cyber, IT asset management, data management and governance), including the safe adoption of emerging technologies such as AI. • Providing SME input and support to the Technology team with regards to risks, issues and operational events logged in our GRC platform, including opportunities to enhance data quality and workflow automation. • Supporting Technology by acting as a point of contact and "bridge" between them and other lines of defence, such as Operational Risk, Internal Audit, and External Audit. • Driving the modernisation of technology risk processes through the use of automation, data analytics and AI-enabled solutions (e.g. process automation, intelligent risk assessments, enhanced reporting). • Identifying opportunities to improve efficiency, scalability and consistency of risk processes, and supporting the design and implementation of solutions where appropriate. • Supporting client engagement teams through responding to technical due diligence requests from current and potential clients. • Performing risk assessments of new technologies entering the environment, including AI/ML solutions, ensuring that risks are identified and appropriate controls are in place. Skills, Knowledge & Experience Required- Minimum 4 years' experience of working within a risk / audit function - A solid understanding of current technology capabilities, including AI/ML concepts and their associated risks, and a keen interest in staying abreast of emerging technology trends (e.g. AI, automation, quantum computing). - Knowledge of and experience of implementing leading Technology risk framework and practices e.g. ISO27001, COBIT, NIST and supporting methodologies. - Experience or demonstrable interest in applying data analytics, automation, or AI tools to improve risk management processes and reporting. - Ability to manage own time and to work to strict deadlines - Strong organisational, analytical and stakeholder management skills - Detail oriented and well-organised with ability to work independently - Experienced in collaborating at all levels of an enterprise - Effective written and verbal communication from technical team direction to senior management presentations - Experience with undertaking RCSA or similar risk and controls assessments / audits - Creativity and initiative in work product, positive and helpful attitude proposing solutions to resolve problems - Ability to work flexibly to support colleagues that operate out of multiple locations / time-zones - Proficiency in using standard work environment software, such as Microsoft Office Suite Desired - Risk/IT professional certification such as CISA, CRISC, CPA, CISM, Six Sigma - Experience of working within the Insurance / Reinsurance industries - Degree within an IT related or similar discipline - Understanding of GRC platforms (e.g. Archer) - Comfortable operating in a dynamic, evolving environment with competing priorities - Confidence working with incomplete information and forming reasoned risk based conclusions - Experience applying judgement over checklist driven compliance, with an ability to prioritise risk proportionately - Exposure to AI governance, model risk management, or emerging regulatory expectations relating to AI Working For Pacific Life Re Every person in our global team is valued for the unique qualities they bring to our business and we seek to build their expertise and support their individual ambitions at every step. Of course, we take our work seriously and we know our team can operate under great pressure. We work hard and thrive on achievement, but we also know how to have fun and relax too. We regularly host a range of team building days to strengthen our team's connection with each other and reflect on their successes.Providing employees with a healthy work-life balance is very important to our culture. We have a wide range of employee benefits and we host regular social activities and well being initiatives. We are also committed to supporting our employee's involvement in their communities, by actively fundraising, hosting charity events and overseeing volunteering opportunities. Benefits (Only for Permanent and Fixed Term Employees) Leave 25 days of annual leave with option to buy/sell more days Adoption and fertility leave Generous enhanced parental leaveHealthcare Comprehensive private insurance coverage for employee and dependents Group Life Insurance coverage of 9x basic annual salary and Group Income Protection up to 75% of basic annual salary Optical benefitsSavings & Retirement 15% combined employee/employer contributionsWellness Subsidized gym membership Access to Employee Assistance Program Cycle to Work and Electric Car Salary Sacrifice Scheme Time off for volunteering Charitable matching of employee donations You Can Be Who You Are We are committed to a culture of diversity and inclusion that embraces the authenticity of all employees, partners and communities. We support all employees to thrive and achieve their fullest potential.As part of our commitment to diversity and inclusion, we will provide reasonable adjustments during the recruitment process to ensure equal access to applicants with disabilities. Please contact us about your needs so that we can discuss these with you to make sure that suitable adjustments are made, where possible. Pacific Life Re Values Please click here to view our company values
May 29, 2026
Full time
Senior Technology Risk AnalystApplylocations: London, UKtime type: Full timeposted on: Posted Todayjob requisition id: R17061 Job Title Senior Technology Risk Analyst Job Description We collaborate with clients across Europe, Asia, Australia and North America, specialising in risks associated with Life, Critical Illness, Income Protection, Hospital Cash and Longevity products. Our clients are insurance or reinsurance companies looking for a new and innovative approach to taking risks.With the security and financial strength of a parent company that has been around for over 145 years and a mutual holding company as our ultimate parent, we are not constrained by short-term thinking; therefore, allowing us to be free to pursue the right course for our clients and our business.Underlying our philosophy is an intelligent approach to taking risks. By recruiting top quality staff and investing in the latest analytical technologies, we believe we are well placed to make those decisions. The Role We have an exciting permanent opportunity available within the Division Centre Technology Risk team, based out of our London office.This role is suited to an experienced professional seeking to deepen their expertise in Technology Risk within a global organisation. You will play a key role in delivering risk management activities, providing subject matter expertise, and driving improvements across technology, risk frameworks, and emerging areas such as AI.Primary responsibilities will include providing technology risk subject matter expertise, support and guidance to the global Technology team, specifically:• Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Analyse and manage incidents and operational events, identify root causes and systemic control weaknesses using data analytics, and drive action plans to completion with effective monitoring, escalation, and senior management reporting, focusing on optimisation and efficiency. • Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Helping to define and maintain key risk indicators, including exploring automated data feeds and AI-driven insights, assisting in the preparation of reporting to divisional senior Technology management, Operational Risk & Resilience, and the Operational Risk Management Committee. • Participating in working groups on specific technology risk topics (e.g. cyber, IT asset management, data management and governance), including the safe adoption of emerging technologies such as AI. • Providing SME input and support to the Technology team with regards to risks, issues and operational events logged in our GRC platform, including opportunities to enhance data quality and workflow automation. • Supporting Technology by acting as a point of contact and "bridge" between them and other lines of defence, such as Operational Risk, Internal Audit, and External Audit. • Driving the modernisation of technology risk processes through the use of automation, data analytics and AI-enabled solutions (e.g. process automation, intelligent risk assessments, enhanced reporting). • Identifying opportunities to improve efficiency, scalability and consistency of risk processes, and supporting the design and implementation of solutions where appropriate. • Supporting client engagement teams through responding to technical due diligence requests from current and potential clients. • Performing risk assessments of new technologies entering the environment, including AI/ML solutions, ensuring that risks are identified and appropriate controls are in place. Skills, Knowledge & Experience Required- Minimum 4 years' experience of working within a risk / audit function - A solid understanding of current technology capabilities, including AI/ML concepts and their associated risks, and a keen interest in staying abreast of emerging technology trends (e.g. AI, automation, quantum computing). - Knowledge of and experience of implementing leading Technology risk framework and practices e.g. ISO27001, COBIT, NIST and supporting methodologies. - Experience or demonstrable interest in applying data analytics, automation, or AI tools to improve risk management processes and reporting. - Ability to manage own time and to work to strict deadlines - Strong organisational, analytical and stakeholder management skills - Detail oriented and well-organised with ability to work independently - Experienced in collaborating at all levels of an enterprise - Effective written and verbal communication from technical team direction to senior management presentations - Experience with undertaking RCSA or similar risk and controls assessments / audits - Creativity and initiative in work product, positive and helpful attitude proposing solutions to resolve problems - Ability to work flexibly to support colleagues that operate out of multiple locations / time-zones - Proficiency in using standard work environment software, such as Microsoft Office Suite Desired - Risk/IT professional certification such as CISA, CRISC, CPA, CISM, Six Sigma - Experience of working within the Insurance / Reinsurance industries - Degree within an IT related or similar discipline - Understanding of GRC platforms (e.g. Archer) - Comfortable operating in a dynamic, evolving environment with competing priorities - Confidence working with incomplete information and forming reasoned risk based conclusions - Experience applying judgement over checklist driven compliance, with an ability to prioritise risk proportionately - Exposure to AI governance, model risk management, or emerging regulatory expectations relating to AI Working For Pacific Life Re Every person in our global team is valued for the unique qualities they bring to our business and we seek to build their expertise and support their individual ambitions at every step. Of course, we take our work seriously and we know our team can operate under great pressure. We work hard and thrive on achievement, but we also know how to have fun and relax too. We regularly host a range of team building days to strengthen our team's connection with each other and reflect on their successes.Providing employees with a healthy work-life balance is very important to our culture. We have a wide range of employee benefits and we host regular social activities and well being initiatives. We are also committed to supporting our employee's involvement in their communities, by actively fundraising, hosting charity events and overseeing volunteering opportunities. Benefits (Only for Permanent and Fixed Term Employees) Leave 25 days of annual leave with option to buy/sell more days Adoption and fertility leave Generous enhanced parental leaveHealthcare Comprehensive private insurance coverage for employee and dependents Group Life Insurance coverage of 9x basic annual salary and Group Income Protection up to 75% of basic annual salary Optical benefitsSavings & Retirement 15% combined employee/employer contributionsWellness Subsidized gym membership Access to Employee Assistance Program Cycle to Work and Electric Car Salary Sacrifice Scheme Time off for volunteering Charitable matching of employee donations You Can Be Who You Are We are committed to a culture of diversity and inclusion that embraces the authenticity of all employees, partners and communities. We support all employees to thrive and achieve their fullest potential.As part of our commitment to diversity and inclusion, we will provide reasonable adjustments during the recruitment process to ensure equal access to applicants with disabilities. Please contact us about your needs so that we can discuss these with you to make sure that suitable adjustments are made, where possible. Pacific Life Re Values Please click here to view our company values
A fantastic MSP based in the West End are currently looking for a Tier 1 Cyber Security SOC Support Analyst to join our expanding UK based Service Desk team. The ideal candidate would be someone that is already in a similar role and has minimum of 1-year experience. You must have a years experience working for an MSP and managing corporate clients. Fantastic Benefits Hours : 7.5 hours a day on a fortnightly shift pattern (8am to 4.30pm or 9am to 5.30pm or 9.30am to 6pm) Holidays : 20 days per year, plus bank holidays. After 3 years continuous service, an extra day annual leave up to 25 days. Benefits : Competitive Package Offered - Gym membership, Vitality at Work Business rewards & benefits, Cycle to Work scheme, quarterly team nights out/events, monthly games night with pizzasand breakfast on Wednesdays! As a Tier 1 SOC Support Analyst, you will be primarily responsible for monitoring systems and making the initial response to any flags or alerts that come in via support tickets or telephone tickets. One of the key responsibilities is also to review and categorise potential threats in order of priorityand dismiss any false alarms, whilst also gathering information and escalating the most urgent threats to Escalations Management Team. Essential Experience Preference given to candidates with MSP background Minimum 1 years proven experience in a Tier 1 Cyber Security SOC Support Analyst role Working knowledge of Microsoft Defender XDR and Microsoft Sentinel SIEM technologies Working knowledge of Microsoft Defender suite including Endpoint Detection and Response Understanding of key Microsoft 365 Cloud Technologies from a threat landscape perspective Essential Certification/Working towards SC-200 Microsoft Certified: Security Operations Analyst Associate OR SC-900 Microsoft Certified: Security Compliance and Identity Fundamentals Personal Skills Highly Motivated Can do attitude Attention to detail Excellent communication Proven client service skills Ability to work under pressure Willingness to work flexibly as required Good telephone etiquette Main Tasks and Responsibilities Provide triage and first line of defence for all cyber security incidents within the organisation and as part of our Managed Security Service Take ownership and provide remedial actions to ensure that Cyber Security Threats are mitigated as per Playbooks provided by the Cyber Security Team or escalate incidents to Escalations Management Team for further information/support Manage technical and stakeholder incident reporting via concise communications Manage client communication channels during an active incident Liaise with third party service suppliers where necessary, logging tickets and act as a central point of contact for active incident Provide operational support to wider Cyber Security Team on security incidents Provide a professional and customer-focused service through the life cycle of each ticket; manage customer expectations by keeping customer informed of progress. If you'd like to be part of this dynamic team please email me your CV ASAP!
May 25, 2026
Full time
A fantastic MSP based in the West End are currently looking for a Tier 1 Cyber Security SOC Support Analyst to join our expanding UK based Service Desk team. The ideal candidate would be someone that is already in a similar role and has minimum of 1-year experience. You must have a years experience working for an MSP and managing corporate clients. Fantastic Benefits Hours : 7.5 hours a day on a fortnightly shift pattern (8am to 4.30pm or 9am to 5.30pm or 9.30am to 6pm) Holidays : 20 days per year, plus bank holidays. After 3 years continuous service, an extra day annual leave up to 25 days. Benefits : Competitive Package Offered - Gym membership, Vitality at Work Business rewards & benefits, Cycle to Work scheme, quarterly team nights out/events, monthly games night with pizzasand breakfast on Wednesdays! As a Tier 1 SOC Support Analyst, you will be primarily responsible for monitoring systems and making the initial response to any flags or alerts that come in via support tickets or telephone tickets. One of the key responsibilities is also to review and categorise potential threats in order of priorityand dismiss any false alarms, whilst also gathering information and escalating the most urgent threats to Escalations Management Team. Essential Experience Preference given to candidates with MSP background Minimum 1 years proven experience in a Tier 1 Cyber Security SOC Support Analyst role Working knowledge of Microsoft Defender XDR and Microsoft Sentinel SIEM technologies Working knowledge of Microsoft Defender suite including Endpoint Detection and Response Understanding of key Microsoft 365 Cloud Technologies from a threat landscape perspective Essential Certification/Working towards SC-200 Microsoft Certified: Security Operations Analyst Associate OR SC-900 Microsoft Certified: Security Compliance and Identity Fundamentals Personal Skills Highly Motivated Can do attitude Attention to detail Excellent communication Proven client service skills Ability to work under pressure Willingness to work flexibly as required Good telephone etiquette Main Tasks and Responsibilities Provide triage and first line of defence for all cyber security incidents within the organisation and as part of our Managed Security Service Take ownership and provide remedial actions to ensure that Cyber Security Threats are mitigated as per Playbooks provided by the Cyber Security Team or escalate incidents to Escalations Management Team for further information/support Manage technical and stakeholder incident reporting via concise communications Manage client communication channels during an active incident Liaise with third party service suppliers where necessary, logging tickets and act as a central point of contact for active incident Provide operational support to wider Cyber Security Team on security incidents Provide a professional and customer-focused service through the life cycle of each ticket; manage customer expectations by keeping customer informed of progress. If you'd like to be part of this dynamic team please email me your CV ASAP!
A fantastic MSP based in the West End are currently looking for a Tier 1 Cyber Security SOC Support Analyst to join our expanding UK based Service Desk team. The ideal candidate would be someone that is already in a similar role and has minimum of 1-year experience. You must have a years experience working for an MSP and managing corporate clients. Fantastic Benefits Hours : 7.5 hours a day on a fortnightly shift pattern (8am to 4.30pm or 9am to 5.30pm or 9.30am to 6pm) Holidays : 20 days per year, plus bank holidays. After 3 years continuous service, an extra day annual leave up to 25 days. Benefits : Competitive Package Offered - Gym membership, Vitality at Work Business rewards & benefits, Cycle to Work scheme, quarterly team nights out/events, monthly games night with pizzasand breakfast on Wednesdays! As a Tier 1 SOC Support Analyst, you will be primarily responsible for monitoring systems and making the initial response to any flags or alerts that come in via support tickets or telephone tickets. One of the key responsibilities is also to review and categorise potential threats in order of priorityand dismiss any false alarms, whilst also gathering information and escalating the most urgent threats to Escalations Management Team. Essential Experience Preference given to candidates with MSP background Minimum 1 years proven experience in a Tier 1 Cyber Security SOC Support Analyst role Working knowledge of Microsoft Defender XDR and Microsoft Sentinel SIEM technologies Working knowledge of Microsoft Defender suite including Endpoint Detection and Response Understanding of key Microsoft 365 Cloud Technologies from a threat landscape perspective Essential Certification/Working towards SC-200 Microsoft Certified: Security Operations Analyst Associate OR SC-900 Microsoft Certified: Security Compliance and Identity Fundamentals Personal Skills Highly Motivated Can do attitude Attention to detail Excellent communication Proven client service skills Ability to work under pressure Willingness to work flexibly as required Good telephone etiquette Main Tasks and Responsibilities Provide triage and first line of defence for all cyber security incidents within the organisation and as part of our Managed Security Service Take ownership and provide remedial actions to ensure that Cyber Security Threats are mitigated as per Playbooks provided by the Cyber Security Team or escalate incidents to Escalations Management Team for further information/support Manage technical and stakeholder incident reporting via concise communications Manage client communication channels during an active incident Liaise with third party service suppliers where necessary, logging tickets and act as a central point of contact for active incident Provide operational support to wider Cyber Security Team on security incidents Provide a professional and customer-focused service through the life cycle of each ticket; manage customer expectations by keeping customer informed of progress. If you'd like to be part of this dynamic team please email me your CV ASAP!
May 24, 2026
Full time
A fantastic MSP based in the West End are currently looking for a Tier 1 Cyber Security SOC Support Analyst to join our expanding UK based Service Desk team. The ideal candidate would be someone that is already in a similar role and has minimum of 1-year experience. You must have a years experience working for an MSP and managing corporate clients. Fantastic Benefits Hours : 7.5 hours a day on a fortnightly shift pattern (8am to 4.30pm or 9am to 5.30pm or 9.30am to 6pm) Holidays : 20 days per year, plus bank holidays. After 3 years continuous service, an extra day annual leave up to 25 days. Benefits : Competitive Package Offered - Gym membership, Vitality at Work Business rewards & benefits, Cycle to Work scheme, quarterly team nights out/events, monthly games night with pizzasand breakfast on Wednesdays! As a Tier 1 SOC Support Analyst, you will be primarily responsible for monitoring systems and making the initial response to any flags or alerts that come in via support tickets or telephone tickets. One of the key responsibilities is also to review and categorise potential threats in order of priorityand dismiss any false alarms, whilst also gathering information and escalating the most urgent threats to Escalations Management Team. Essential Experience Preference given to candidates with MSP background Minimum 1 years proven experience in a Tier 1 Cyber Security SOC Support Analyst role Working knowledge of Microsoft Defender XDR and Microsoft Sentinel SIEM technologies Working knowledge of Microsoft Defender suite including Endpoint Detection and Response Understanding of key Microsoft 365 Cloud Technologies from a threat landscape perspective Essential Certification/Working towards SC-200 Microsoft Certified: Security Operations Analyst Associate OR SC-900 Microsoft Certified: Security Compliance and Identity Fundamentals Personal Skills Highly Motivated Can do attitude Attention to detail Excellent communication Proven client service skills Ability to work under pressure Willingness to work flexibly as required Good telephone etiquette Main Tasks and Responsibilities Provide triage and first line of defence for all cyber security incidents within the organisation and as part of our Managed Security Service Take ownership and provide remedial actions to ensure that Cyber Security Threats are mitigated as per Playbooks provided by the Cyber Security Team or escalate incidents to Escalations Management Team for further information/support Manage technical and stakeholder incident reporting via concise communications Manage client communication channels during an active incident Liaise with third party service suppliers where necessary, logging tickets and act as a central point of contact for active incident Provide operational support to wider Cyber Security Team on security incidents Provide a professional and customer-focused service through the life cycle of each ticket; manage customer expectations by keeping customer informed of progress. If you'd like to be part of this dynamic team please email me your CV ASAP!
SOC Analyst Daily Rate: Inside IR35 Location: Sheffield Job Type: Hybrid (2-3 days on-site) Join our Cyber Defence Centre (CDC) as a SOC Analyst. This is a crucial hands-on operational role within Security Operations, focused on incident detection, investigation, and response. You will play a pivotal role in ensuring effective monitoring, triage, and response to security events, while also driving continuous improvement and detection engineering initiatives. Day-to-day of the role: Incident Detection & Response: Investigate and respond to security incidents and alerts escalated from Tier 1 / Tier 2 SOC. Perform in-depth analysis and triage of security events, identifying threats and determining impact. Support high-severity incident response as required, working closely with Incident Responders. Operational Monitoring: Manage and resolve security tickets within agreed SLAs. Review alerts from multiple security tools and platforms. Ensure accurate documentation and tracking of incidents within ServiceNow. Detection Engineering: Contribute to detection engineering activities on a rotational basis. Develop and tune detection rules to improve alert quality and reduce false positives. Write and optimise queries (e.g., KQL) across SIEM platforms. Collaboration & Support: Work closely with internal teams and third-party providers to investigate and resolve incidents. Support MSSP interactions and escalations where required. Participate in incident bridge calls during major incidents. Continuous Improvement: Identify lessons learned from incidents and contribute to improving processes and controls. Provide feedback on detection gaps and opportunities for enhancement. Focus on delivering value from incidents, not just ticket closure. Required Skills & Qualifications: Core Experience: Proven experience working within a SOC environment (Tier 2 / Tier 3 preferred). Strong background in incident investigation and response. Experience handling escalated alerts and security tickets. Technical Skills: Experience with SIEM platforms (e.g., Microsoft Sentinel). Experience with EDR/XDR tools (e.g., CrowdStrike). ServiceNow or similar ITSM/SecOps platforms. Ability to write and optimise KQL queries (essential). Knowledge of scripting/query languages (e.g., Falcon Query Language) is advantageous. Analytical Capability: Strong investigative and problem-solving skills. Ability to correlate data across multiple sources. Understanding of common attack techniques and threat vectors. Soft Skills: Strong communication and collaboration skills. Ability to work effectively in a fast-paced operational environment. Proactive mindset with focus on continuous improvement and quality outcomes. To apply for this SOC Analyst position, please submit your CV and a member of the Talent Team will be in touch.
May 23, 2026
Contractor
SOC Analyst Daily Rate: Inside IR35 Location: Sheffield Job Type: Hybrid (2-3 days on-site) Join our Cyber Defence Centre (CDC) as a SOC Analyst. This is a crucial hands-on operational role within Security Operations, focused on incident detection, investigation, and response. You will play a pivotal role in ensuring effective monitoring, triage, and response to security events, while also driving continuous improvement and detection engineering initiatives. Day-to-day of the role: Incident Detection & Response: Investigate and respond to security incidents and alerts escalated from Tier 1 / Tier 2 SOC. Perform in-depth analysis and triage of security events, identifying threats and determining impact. Support high-severity incident response as required, working closely with Incident Responders. Operational Monitoring: Manage and resolve security tickets within agreed SLAs. Review alerts from multiple security tools and platforms. Ensure accurate documentation and tracking of incidents within ServiceNow. Detection Engineering: Contribute to detection engineering activities on a rotational basis. Develop and tune detection rules to improve alert quality and reduce false positives. Write and optimise queries (e.g., KQL) across SIEM platforms. Collaboration & Support: Work closely with internal teams and third-party providers to investigate and resolve incidents. Support MSSP interactions and escalations where required. Participate in incident bridge calls during major incidents. Continuous Improvement: Identify lessons learned from incidents and contribute to improving processes and controls. Provide feedback on detection gaps and opportunities for enhancement. Focus on delivering value from incidents, not just ticket closure. Required Skills & Qualifications: Core Experience: Proven experience working within a SOC environment (Tier 2 / Tier 3 preferred). Strong background in incident investigation and response. Experience handling escalated alerts and security tickets. Technical Skills: Experience with SIEM platforms (e.g., Microsoft Sentinel). Experience with EDR/XDR tools (e.g., CrowdStrike). ServiceNow or similar ITSM/SecOps platforms. Ability to write and optimise KQL queries (essential). Knowledge of scripting/query languages (e.g., Falcon Query Language) is advantageous. Analytical Capability: Strong investigative and problem-solving skills. Ability to correlate data across multiple sources. Understanding of common attack techniques and threat vectors. Soft Skills: Strong communication and collaboration skills. Ability to work effectively in a fast-paced operational environment. Proactive mindset with focus on continuous improvement and quality outcomes. To apply for this SOC Analyst position, please submit your CV and a member of the Talent Team will be in touch.
SOC Analyst (Level 1 / Level 2) Milton Keynes On-site DV-Clear 24/7 rota, 12 hr shifts £600 - £650 a day inside IR35 DOE Pigment Consulting is a bold and disruptive digitally-enabled transformation consultancy delivering impactful change across Central Government & Defence. Due to continued success across our Cyber Security portfolio, we are currently seeking DV-Cleared SOC Analysts to jo click apply for full job details
May 22, 2026
Contractor
SOC Analyst (Level 1 / Level 2) Milton Keynes On-site DV-Clear 24/7 rota, 12 hr shifts £600 - £650 a day inside IR35 DOE Pigment Consulting is a bold and disruptive digitally-enabled transformation consultancy delivering impactful change across Central Government & Defence. Due to continued success across our Cyber Security portfolio, we are currently seeking DV-Cleared SOC Analysts to jo click apply for full job details
Cyber Security Engineer up to £60,000 Bromley, Kent Permanent Full-Time We are looking for Two Cyber Security Engineers to play a key, hands-on role in protecting our organisation from cyber threats. This is an operational security role, ideal for someone who enjoys investigating incidents, working across multiple security platforms, and making a tangible impact on an organisation's cyber resilience. You will sit at the heart of our cyber defence operations, working daily with technologies including Microsoft O365 Defender, Entra ID, Intune, Rapid7 SIEM, and Sophos Antivirus. You'll be responsible for monitoring security events, investigating suspicious activity, responding to incidents, and continuously improving our security posture. This is a genuinely hands-on cyber security role with real responsibility and impact; you will have exposure to a broad security tooling landscape and real-world incidents. At Foresters we are a supportive, collaborative working environment and you will have on-going opportunities to develop your technical skills and grow within cyber security What you will do: Security Monitoring & Incident Response Actively monitor alerts and telemetry across endpoints, identities, email, and cloud services using Rapid7 SIEM, Microsoft Defender, and Sophos AV. Investigate suspected cyber attacks including malware infections, phishing campaigns, identity compromise, and unauthorised access attempts. Perform triage, root cause analysis, containment, and remediation of security incidents. Lead or support incident response activities in line with internal policies and procedures. Escalate significant incidents appropriately and provide clear, timely updates to stakeholders. Threat Detection & Prevention Proactively identify emerging threats, vulnerabilities, and attack patterns affecting the organisation. Tune and optimise security tools to reduce false positives and improve detection accuracy. Implement, manage, and maintain endpoint protection and security policies. Support vulnerability management activities, including remediation planning and risk tracking. Security Operations & Continuous Improvement Maintain and enhance security monitoring rules, alerts, and dashboards. Contribute to the development and maintenance of security runbooks and incident response playbooks. Support security audits, compliance activities, and risk assessments. Actively contribute to improving the organisation's overall cyber security maturity. Collaboration & Communication Work closely with IT, infrastructure, and service desk teams to resolve security-related issues. Produce clear, structured technical and non-technical incident reports. Identify trends in phishing or risky user behaviour and support security awareness initiatives. Assist with security-related projects and new technology deployments. Working hours are 40 hours a week Monday to Friday. Start times are flexible from 7.30am to 9.30am. After a successful training period there is flexibility to work from home for 1 day a week. What we require: Experience in a Cyber Security Engineer, SOC Analyst, or similar security-focused role. Hands-on experience with Microsoft Defender (Endpoint and/or O365 security). Experience using Rapid7 SIEM or a comparable SIEM platform for alerting and investigations. Experience managing or supporting Sophos Antivirus or other endpoint protection solutions. Strong understanding of common cyber threats, attack vectors, and incident response processes. Ability to analyse logs, alerts, and endpoint activity to determine scope, impact, and root cause. Good working knowledge of Windows environments and basic networking concepts. Strong documentation, reporting, and communication skills. Practical experience with security tools such as IDS/IPS, Metasploit, Nexpose, Nmap, Nessus, Wireshark, L0phtCrack, John the Ripper, or similar. Familiarity with recognised information security frameworks such as ISO 27001 and the NIST Cybersecurity Framework. What we offer you: Basic salary up to £60000 per annum Discretionary annual bonus dependent on your performance and company performance provided you are employed on bonus payment date. Annual holiday allowance of 25 days holiday plus bank holidays Life Assurance (based on pensionable earnings) Generous contributory Pension scheme 1 days paid charitable workday Employee Assistance Programme About us Foresters Financial is not your typical financial services provider. Those who join our purpose-driven organisation enjoy a culture of collaboration, creativity, and mutual respect and are challenged to do their best to make a difference every day. We help everyday families achieve their financial goals and make a lasting difference in their lives and communities. What we do We help everyday families achieve their financial goals and make a lasting difference in their lives and communities. We will continue to do this by employing enthusiastic and talented Financial Advisers working across the country and equally talented people to be based at our Head Office in Bromley.
May 22, 2026
Full time
Cyber Security Engineer up to £60,000 Bromley, Kent Permanent Full-Time We are looking for Two Cyber Security Engineers to play a key, hands-on role in protecting our organisation from cyber threats. This is an operational security role, ideal for someone who enjoys investigating incidents, working across multiple security platforms, and making a tangible impact on an organisation's cyber resilience. You will sit at the heart of our cyber defence operations, working daily with technologies including Microsoft O365 Defender, Entra ID, Intune, Rapid7 SIEM, and Sophos Antivirus. You'll be responsible for monitoring security events, investigating suspicious activity, responding to incidents, and continuously improving our security posture. This is a genuinely hands-on cyber security role with real responsibility and impact; you will have exposure to a broad security tooling landscape and real-world incidents. At Foresters we are a supportive, collaborative working environment and you will have on-going opportunities to develop your technical skills and grow within cyber security What you will do: Security Monitoring & Incident Response Actively monitor alerts and telemetry across endpoints, identities, email, and cloud services using Rapid7 SIEM, Microsoft Defender, and Sophos AV. Investigate suspected cyber attacks including malware infections, phishing campaigns, identity compromise, and unauthorised access attempts. Perform triage, root cause analysis, containment, and remediation of security incidents. Lead or support incident response activities in line with internal policies and procedures. Escalate significant incidents appropriately and provide clear, timely updates to stakeholders. Threat Detection & Prevention Proactively identify emerging threats, vulnerabilities, and attack patterns affecting the organisation. Tune and optimise security tools to reduce false positives and improve detection accuracy. Implement, manage, and maintain endpoint protection and security policies. Support vulnerability management activities, including remediation planning and risk tracking. Security Operations & Continuous Improvement Maintain and enhance security monitoring rules, alerts, and dashboards. Contribute to the development and maintenance of security runbooks and incident response playbooks. Support security audits, compliance activities, and risk assessments. Actively contribute to improving the organisation's overall cyber security maturity. Collaboration & Communication Work closely with IT, infrastructure, and service desk teams to resolve security-related issues. Produce clear, structured technical and non-technical incident reports. Identify trends in phishing or risky user behaviour and support security awareness initiatives. Assist with security-related projects and new technology deployments. Working hours are 40 hours a week Monday to Friday. Start times are flexible from 7.30am to 9.30am. After a successful training period there is flexibility to work from home for 1 day a week. What we require: Experience in a Cyber Security Engineer, SOC Analyst, or similar security-focused role. Hands-on experience with Microsoft Defender (Endpoint and/or O365 security). Experience using Rapid7 SIEM or a comparable SIEM platform for alerting and investigations. Experience managing or supporting Sophos Antivirus or other endpoint protection solutions. Strong understanding of common cyber threats, attack vectors, and incident response processes. Ability to analyse logs, alerts, and endpoint activity to determine scope, impact, and root cause. Good working knowledge of Windows environments and basic networking concepts. Strong documentation, reporting, and communication skills. Practical experience with security tools such as IDS/IPS, Metasploit, Nexpose, Nmap, Nessus, Wireshark, L0phtCrack, John the Ripper, or similar. Familiarity with recognised information security frameworks such as ISO 27001 and the NIST Cybersecurity Framework. What we offer you: Basic salary up to £60000 per annum Discretionary annual bonus dependent on your performance and company performance provided you are employed on bonus payment date. Annual holiday allowance of 25 days holiday plus bank holidays Life Assurance (based on pensionable earnings) Generous contributory Pension scheme 1 days paid charitable workday Employee Assistance Programme About us Foresters Financial is not your typical financial services provider. Those who join our purpose-driven organisation enjoy a culture of collaboration, creativity, and mutual respect and are challenged to do their best to make a difference every day. We help everyday families achieve their financial goals and make a lasting difference in their lives and communities. What we do We help everyday families achieve their financial goals and make a lasting difference in their lives and communities. We will continue to do this by employing enthusiastic and talented Financial Advisers working across the country and equally talented people to be based at our Head Office in Bromley.
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
May 20, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Profectus Recruitment
Stratford-upon-avon, Warwickshire
Senior Digital Forensic Analyst Location: Stratford upon Avon (on-site) Salary: Competitive plus benefits Profectus Recruitment are working with a leading Digital Forensics and Cyber Investigations organisation to recruit a Senior Digital Forensic Analyst. This is a fantastic opportunity to join a highly respected forensic investigations team, supporting complex digital investigations across computer and mobile device examinations within a secure, quality driven environment. The Role You will be responsible for delivering high quality digital forensic investigations and reporting across a variety of client cases, while supporting laboratory operations, peer review activities and continuous improvement initiatives. Key Responsibilities Conduct digital forensic investigations across computers and mobile devices • Complete complex forensic examinations and produce detailed technical reports • Support defence and bespoke forensic investigations • Carry out peer reviews of forensic casework • Assist with client meetings and technical scoping discussions • Deliver internal and external training where required • Support quality, validation and auditing processes within the laboratory Skills & Experience Required Strong experience within Digital Forensics investigations • Excellent knowledge of forensic methodologies and industry best practice • Experience with leading forensic examination tools and software • Understanding of ACPO guidelines, ISO17025 and FSR standards • Strong analytical and problem solving skills • Excellent attention to detail and report writing ability • Ability to work independently and manage multiple investigations Additional Requirements Degree in Digital Forensics, Computer Science or related discipline preferred • Full UK driving licence • Minimum 5 years UK residency due to vetting requirements • Ability to pass security clearance procedures This role would suit candidates working as a Digital Forensic Analyst, Cyber Forensics Investigator, Mobile Device Examiner, Computer Forensic Analyst, eDiscovery Analyst or Cyber Investigations Specialist.
May 20, 2026
Full time
Senior Digital Forensic Analyst Location: Stratford upon Avon (on-site) Salary: Competitive plus benefits Profectus Recruitment are working with a leading Digital Forensics and Cyber Investigations organisation to recruit a Senior Digital Forensic Analyst. This is a fantastic opportunity to join a highly respected forensic investigations team, supporting complex digital investigations across computer and mobile device examinations within a secure, quality driven environment. The Role You will be responsible for delivering high quality digital forensic investigations and reporting across a variety of client cases, while supporting laboratory operations, peer review activities and continuous improvement initiatives. Key Responsibilities Conduct digital forensic investigations across computers and mobile devices • Complete complex forensic examinations and produce detailed technical reports • Support defence and bespoke forensic investigations • Carry out peer reviews of forensic casework • Assist with client meetings and technical scoping discussions • Deliver internal and external training where required • Support quality, validation and auditing processes within the laboratory Skills & Experience Required Strong experience within Digital Forensics investigations • Excellent knowledge of forensic methodologies and industry best practice • Experience with leading forensic examination tools and software • Understanding of ACPO guidelines, ISO17025 and FSR standards • Strong analytical and problem solving skills • Excellent attention to detail and report writing ability • Ability to work independently and manage multiple investigations Additional Requirements Degree in Digital Forensics, Computer Science or related discipline preferred • Full UK driving licence • Minimum 5 years UK residency due to vetting requirements • Ability to pass security clearance procedures This role would suit candidates working as a Digital Forensic Analyst, Cyber Forensics Investigator, Mobile Device Examiner, Computer Forensic Analyst, eDiscovery Analyst or Cyber Investigations Specialist.
SOC Analyst - Farnborough, UK Salary up to £60,000 depending on experience, plus shift allowance Onsite role, shift work (4 on / 4 off) Must be eligible for SC clearance About the company Our client operates a growing Security Operations Centre delivering cyber defence services to organisations across a range of industries, from critical infrastructure to complex enterprise environments. The team focuses on high-quality detection, investigation and continuous improvement, rather than alert-only monitoring. Due to continued growth, they are looking for a SOC Analyst to strengthen their operations and help mature their security services. The benefits Shift allowance 25 days annual leave, with the option to buy additional days Health cash plan Life assurance Pension scheme The SOC Analyst role As a SOC Analyst, you will play a key part in protecting client environments by monitoring, investigating and responding to security events. Working as part of a 24/7 onsite SOC, you will handle incidents, contribute to detection improvements, and produce clear reporting for a range of audiences. This is a hands-on role offering exposure to diverse technologies and real cyber threats. SOC Analyst essential skills Experience working in a Security Operations Centre environment Hands-on experience with Microsoft Sentinel and Splunk Knowledge of the MITRE ATT&CK framework Understanding of networks and systems, including TCP/IP, firewalls, VPNs and endpoint security Strong analytical and problem-solving skills Ability to produce clear reports for technical and non-technical stakeholders Eligibility for SC Clearance Desirable skills Scripting or programming experience (Python, PowerShell, Bash, Perl or C++) Experience with additional SIEM tools such as QRadar Cyber security certifications such as Security+, CEH, CPSA or CREST Please either apply through this advert or emailing me directly via . For further information please call me: . By applying for this role, you give express consent for us to process and submit (subject to required skills) your application to our client in conjunction with this vacancy only. KEY SKILLS: SOC Analyst, Security Operations Centre, Microsoft Sentinel, Splunk, SIEM, Incident Response, MITRE ATT and CK, Networking, SC Clearance, NSD
May 20, 2026
Full time
SOC Analyst - Farnborough, UK Salary up to £60,000 depending on experience, plus shift allowance Onsite role, shift work (4 on / 4 off) Must be eligible for SC clearance About the company Our client operates a growing Security Operations Centre delivering cyber defence services to organisations across a range of industries, from critical infrastructure to complex enterprise environments. The team focuses on high-quality detection, investigation and continuous improvement, rather than alert-only monitoring. Due to continued growth, they are looking for a SOC Analyst to strengthen their operations and help mature their security services. The benefits Shift allowance 25 days annual leave, with the option to buy additional days Health cash plan Life assurance Pension scheme The SOC Analyst role As a SOC Analyst, you will play a key part in protecting client environments by monitoring, investigating and responding to security events. Working as part of a 24/7 onsite SOC, you will handle incidents, contribute to detection improvements, and produce clear reporting for a range of audiences. This is a hands-on role offering exposure to diverse technologies and real cyber threats. SOC Analyst essential skills Experience working in a Security Operations Centre environment Hands-on experience with Microsoft Sentinel and Splunk Knowledge of the MITRE ATT&CK framework Understanding of networks and systems, including TCP/IP, firewalls, VPNs and endpoint security Strong analytical and problem-solving skills Ability to produce clear reports for technical and non-technical stakeholders Eligibility for SC Clearance Desirable skills Scripting or programming experience (Python, PowerShell, Bash, Perl or C++) Experience with additional SIEM tools such as QRadar Cyber security certifications such as Security+, CEH, CPSA or CREST Please either apply through this advert or emailing me directly via . For further information please call me: . By applying for this role, you give express consent for us to process and submit (subject to required skills) your application to our client in conjunction with this vacancy only. KEY SKILLS: SOC Analyst, Security Operations Centre, Microsoft Sentinel, Splunk, SIEM, Incident Response, MITRE ATT and CK, Networking, SC Clearance, NSD