Senior/Principal Penetration Tester / Experienced Red Team Consultant Testing Team United Kingdom Remote working options Full Time About the role Rootshell Security is seeking an experienced Senior / Principal Penetration Tester / Red Team Consultant to join our rapidly expanding Offensive Security team. This role is suited to a highly capable security professional with extensive experience delivering complex penetration testing and adversary simulation engagements across a range of sectors, including critical national infrastructure, financial services, and government organisations. You will be responsible for delivering advanced Red Team operations, intelligence-led security assessments, and bespoke attack simulations that help our clients understand their true resilience against modern threat actors. The position involves a combination of remote engagements and on site client activities across the United Kingdom. Rootshell Security is an equal opportunity employer. We welcome and encourage diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability or veteran status. Please do not apply if you are based outside the UK and/or are not eligible to apply for UK Security Clearance. Role responsibilities Lead and deliver advanced penetration testing and Red Team engagements Conduct intelligence-led adversary emulation and attack simulation exercises Deliver engagements aligned to recognised frameworks including TIBER-EU, CBEST, DORA, GBEST and STAR-FS Perform threat led security assessments against complex enterprise environments Develop Red Team infrastructure, tooling, attack paths and operational plans Conduct phishing, social engineering and physical assessment activities where authorised Support pre sales activities including technical scoping and solution design Produce high-quality technical reports and executive level findings Contribute to the development of Rootshell Security methodologies, research and innovation Skills we are looking for Mandatory Requirements Must be eligible to apply for UK Security Clearance Must be permanently based within the United Kingdom Must have several years of provable commercial experience delivering Red Team engagements Excellent working knowledge of the MITRE ATT&CK Framework Demonstrable experience delivering engagements aligned to TIBER-EU, CBEST, DORA and other threat led testing frameworks Strong knowledge of adversary emulation, attack path development and operational security Excellent report writing and client communication skills Strong network, infrastructure, Active Directory and cloud attack experience Experience operating against Azure, AWS and hybrid enterprise environments Certifications Must hold or have previously held a recognised Red Team certification demonstrating advanced offensive security capability, Typically CREST or CyberScheme Currently holds or has held Team Leader certifications in either Infrastructure and/or Applications Currently holds professional title of Principal / Chartered or would be eligible to apply Social engineering and phishing operation experience Physical intrusion testing experience Threat intelligence and Purple Team experience Malware analysis or custom tooling development Experience briefing senior stakeholders and board level audiences Proficiency in Python, PowerShell or C# development Company benefits Long-term career progression opportunities Continuous technical and non-technical training Regular attendance at industry conferences, events and community meetups Exposure to a diverse range of engagements across multiple sectors Dedicated research and innovation time Opportunity to influence Rootshell's offensive security capabilities and methodologies Mentoring and career development from senior leadership Recognition and reward for innovation, technical excellence and client impact Equality, Diversity, and Inclusion at Rootshell Security We are committed to fostering an inclusive and diverse workplace where everyone is valued and respected. We believe that a diverse team drives innovation and excellence, and we welcome applications from individuals of all backgrounds, experiences, and perspectives. As a proud holder of the Bronze Award under the Defence Employer Recognition Scheme (ERS), we actively support the Armed Forces community, aligning with the principles of the Armed Forces Covenant. We recognise the valuable skills and experiences that service personnel, reservists, and veterans bring to the workplace and encourage them to apply. Rootshell Security is an equal opportunities employer. We do not discriminate based on age, disability, gender, gender identity, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sexual orientation, or any other characteristic protected by law. If you require any reasonable adjustments during the recruitment process, please let us know-we are happy to support you.
Aug 20, 2026
Full time
Senior/Principal Penetration Tester / Experienced Red Team Consultant Testing Team United Kingdom Remote working options Full Time About the role Rootshell Security is seeking an experienced Senior / Principal Penetration Tester / Red Team Consultant to join our rapidly expanding Offensive Security team. This role is suited to a highly capable security professional with extensive experience delivering complex penetration testing and adversary simulation engagements across a range of sectors, including critical national infrastructure, financial services, and government organisations. You will be responsible for delivering advanced Red Team operations, intelligence-led security assessments, and bespoke attack simulations that help our clients understand their true resilience against modern threat actors. The position involves a combination of remote engagements and on site client activities across the United Kingdom. Rootshell Security is an equal opportunity employer. We welcome and encourage diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability or veteran status. Please do not apply if you are based outside the UK and/or are not eligible to apply for UK Security Clearance. Role responsibilities Lead and deliver advanced penetration testing and Red Team engagements Conduct intelligence-led adversary emulation and attack simulation exercises Deliver engagements aligned to recognised frameworks including TIBER-EU, CBEST, DORA, GBEST and STAR-FS Perform threat led security assessments against complex enterprise environments Develop Red Team infrastructure, tooling, attack paths and operational plans Conduct phishing, social engineering and physical assessment activities where authorised Support pre sales activities including technical scoping and solution design Produce high-quality technical reports and executive level findings Contribute to the development of Rootshell Security methodologies, research and innovation Skills we are looking for Mandatory Requirements Must be eligible to apply for UK Security Clearance Must be permanently based within the United Kingdom Must have several years of provable commercial experience delivering Red Team engagements Excellent working knowledge of the MITRE ATT&CK Framework Demonstrable experience delivering engagements aligned to TIBER-EU, CBEST, DORA and other threat led testing frameworks Strong knowledge of adversary emulation, attack path development and operational security Excellent report writing and client communication skills Strong network, infrastructure, Active Directory and cloud attack experience Experience operating against Azure, AWS and hybrid enterprise environments Certifications Must hold or have previously held a recognised Red Team certification demonstrating advanced offensive security capability, Typically CREST or CyberScheme Currently holds or has held Team Leader certifications in either Infrastructure and/or Applications Currently holds professional title of Principal / Chartered or would be eligible to apply Social engineering and phishing operation experience Physical intrusion testing experience Threat intelligence and Purple Team experience Malware analysis or custom tooling development Experience briefing senior stakeholders and board level audiences Proficiency in Python, PowerShell or C# development Company benefits Long-term career progression opportunities Continuous technical and non-technical training Regular attendance at industry conferences, events and community meetups Exposure to a diverse range of engagements across multiple sectors Dedicated research and innovation time Opportunity to influence Rootshell's offensive security capabilities and methodologies Mentoring and career development from senior leadership Recognition and reward for innovation, technical excellence and client impact Equality, Diversity, and Inclusion at Rootshell Security We are committed to fostering an inclusive and diverse workplace where everyone is valued and respected. We believe that a diverse team drives innovation and excellence, and we welcome applications from individuals of all backgrounds, experiences, and perspectives. As a proud holder of the Bronze Award under the Defence Employer Recognition Scheme (ERS), we actively support the Armed Forces community, aligning with the principles of the Armed Forces Covenant. We recognise the valuable skills and experiences that service personnel, reservists, and veterans bring to the workplace and encourage them to apply. Rootshell Security is an equal opportunities employer. We do not discriminate based on age, disability, gender, gender identity, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sexual orientation, or any other characteristic protected by law. If you require any reasonable adjustments during the recruitment process, please let us know-we are happy to support you.
ServiceNow Developer UK Wide Flexible Working (1 day per week in one of their UK offices) SC Clearance Eligible British Nationals and eligible for UK Security Clearance (SC). 65-75,000 + Benefits + Career Progression I'm currently partnering with a leading UK technology and digital transformation consultancy that is rapidly growing their ServiceNow practice and are looking for an experienced ServiceNow Developer to deliver enterprise-scale transformation programmes across a range of industries. What You'll Do Lead the design, development and implementation of ServiceNow solutions. Work closely with architects, platform owners and stakeholders to deliver best-practice solutions. Develop integrations using IntegrationHub, REST/SOAP APIs and MID Servers. Conduct code reviews, technical assessments and platform optimisation. Mentor consultants and developers while contributing to practice growth and innovation. What You'll Bring Strong ServiceNow development and implementation experience. Expertise in one or more areas: ITSM, ITOM, ITAM, CSM, HRSD, SPM, SecOps or IRM. Strong knowledge of JavaScript, Glide API, Flow Designer, IntegrationHub, Service Portal, UI Builder and REST/SOAP APIs. Experience working in enterprise, managed service or consulting environments. Agile delivery experience and excellent stakeholder management skills. Desirable Discovery & Service Mapping Performance Analytics & Reporting Experience integrating with Microsoft 365, Azure, Active Directory, Jira or SAP Self-hosted or domain-separated ServiceNow environments Please note: Due to the nature of the projects, candidates must be British Nationals and eligible for UK Security Clearance (SC). Please note you will receive an automated response advising you that we have received your CV. Morgan Philips Group is a global talent solutions business that disrupts conventional thinking in executive search, recruitment and talent consulting. We operate in over 18 markets in Europe, North & South America, Asia, and the Middle East & Africa. We understand that the future is digital and social, so we embrace the latest technology, including video ads and CVs, as well as social recruiting. Our innovative services are tailored to the new world of work yet we do not lose sight of the fact that employees be they existing and potential are ultimately human beings. We are committed to ensuring that all job applicants are treated equally, without discrimination because of gender, sexual orientation, marital or civil partner status, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief, disability or age.
Aug 17, 2026
Full time
ServiceNow Developer UK Wide Flexible Working (1 day per week in one of their UK offices) SC Clearance Eligible British Nationals and eligible for UK Security Clearance (SC). 65-75,000 + Benefits + Career Progression I'm currently partnering with a leading UK technology and digital transformation consultancy that is rapidly growing their ServiceNow practice and are looking for an experienced ServiceNow Developer to deliver enterprise-scale transformation programmes across a range of industries. What You'll Do Lead the design, development and implementation of ServiceNow solutions. Work closely with architects, platform owners and stakeholders to deliver best-practice solutions. Develop integrations using IntegrationHub, REST/SOAP APIs and MID Servers. Conduct code reviews, technical assessments and platform optimisation. Mentor consultants and developers while contributing to practice growth and innovation. What You'll Bring Strong ServiceNow development and implementation experience. Expertise in one or more areas: ITSM, ITOM, ITAM, CSM, HRSD, SPM, SecOps or IRM. Strong knowledge of JavaScript, Glide API, Flow Designer, IntegrationHub, Service Portal, UI Builder and REST/SOAP APIs. Experience working in enterprise, managed service or consulting environments. Agile delivery experience and excellent stakeholder management skills. Desirable Discovery & Service Mapping Performance Analytics & Reporting Experience integrating with Microsoft 365, Azure, Active Directory, Jira or SAP Self-hosted or domain-separated ServiceNow environments Please note: Due to the nature of the projects, candidates must be British Nationals and eligible for UK Security Clearance (SC). Please note you will receive an automated response advising you that we have received your CV. Morgan Philips Group is a global talent solutions business that disrupts conventional thinking in executive search, recruitment and talent consulting. We operate in over 18 markets in Europe, North & South America, Asia, and the Middle East & Africa. We understand that the future is digital and social, so we embrace the latest technology, including video ads and CVs, as well as social recruiting. Our innovative services are tailored to the new world of work yet we do not lose sight of the fact that employees be they existing and potential are ultimately human beings. We are committed to ensuring that all job applicants are treated equally, without discrimination because of gender, sexual orientation, marital or civil partner status, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief, disability or age.
CBSbutler Holdings Limited trading as CBSbutler
Corsham, Wiltshire
PAM Architect +9 months + +DV cleared - current active clearance +Sole British nationals only due to the nature of the project +Hybrid working in Corsham +Inside IR35 + 500 - 550 a day Key Responsibilities Architect and deliver enterprise CyberArk PAM solutions , including PAS, CPM, PSM and PVWA Define privileged access, credential management, vaulting and session monitoring strategies Produce HLDs, LLDs, security architecture documentation and implementation runbooks Integrate CyberArk with Active Directory/LDAP, SIEM and ITSM platforms Conduct security assessments, gap analysis and remediation activities Provide PAM technical leadership, guidance and mentoring Work closely with customer and internal stakeholders, including on-site customer engagement Drive continuous improvement and innovation across the PAM capability Key Skills & Experience Proven experience as a PAM Architect or Senior PAM SME Strong hands-on CyberArk experience, ideally across PAS, CPM, PSM, PVWA and PTA Enterprise-scale PAM architecture and implementation experience Strong understanding of IAM, least privilege and privileged credential lifecycle management Experience with session isolation/recording and secure access controls Strong technical documentation and security architecture skills Knowledge of NIST, ISO 27001 or similar security frameworks Excellent stakeholder management and communication skills Experience of DevSecOps and secrets management would be advantageous If you'd like to discuss this PAM Architect in more detail, please send your updated CV to (url removed) and I will get in touch.
Aug 10, 2026
Contractor
PAM Architect +9 months + +DV cleared - current active clearance +Sole British nationals only due to the nature of the project +Hybrid working in Corsham +Inside IR35 + 500 - 550 a day Key Responsibilities Architect and deliver enterprise CyberArk PAM solutions , including PAS, CPM, PSM and PVWA Define privileged access, credential management, vaulting and session monitoring strategies Produce HLDs, LLDs, security architecture documentation and implementation runbooks Integrate CyberArk with Active Directory/LDAP, SIEM and ITSM platforms Conduct security assessments, gap analysis and remediation activities Provide PAM technical leadership, guidance and mentoring Work closely with customer and internal stakeholders, including on-site customer engagement Drive continuous improvement and innovation across the PAM capability Key Skills & Experience Proven experience as a PAM Architect or Senior PAM SME Strong hands-on CyberArk experience, ideally across PAS, CPM, PSM, PVWA and PTA Enterprise-scale PAM architecture and implementation experience Strong understanding of IAM, least privilege and privileged credential lifecycle management Experience with session isolation/recording and secure access controls Strong technical documentation and security architecture skills Knowledge of NIST, ISO 27001 or similar security frameworks Excellent stakeholder management and communication skills Experience of DevSecOps and secrets management would be advantageous If you'd like to discuss this PAM Architect in more detail, please send your updated CV to (url removed) and I will get in touch.
The role: We are looking for a Cloud Infrastructure Analyst to join our IT department in Bristol. At Simmons & Simmons, technology is central to delivering exceptional client service. We are seeking a talented and motivated Cloud Infrastructure Analyst to join our Platforms team and help build, automate and operate the Azure platform underpinning our applications and services. This is a hands-on engineering role focused on designing and delivering secure, scalable and resilient cloud solutions in Microsoft Azure, using Infrastructure as Code and CI/CD automation as the default approach. You will work closely with architects, security and application teams to implement cloud platform patterns and enable delivery teams to deploy safely and consistently. What will you do: Azure Infrastructure as Code (IaC) & CI/CD automation Build, deploy, and maintain Azure infrastructure using IaC (Bicep and/or Terraform) with peer review and version control. Strong familiarity working in IaC and pipelines to ensure quality, security and adherence to baseline standards. Cloud reliability, operations & incident/problem support (engineering-led) Act as an escalation point for complex Azure platform issues; troubleshoot, perform root cause analysis, and implement sustainable fixes (automation over repeated manual intervention). Monitor and improve platform health using Azure observability tooling (e.g., Azure Monitor, Log Analytics/KQL, Application Insights, Science Logic), and improve alerting and diagnostics. Plan and implement operational improvements such as performance tuning, resource optimisation and resilience enhancements, aligned to service expectations. Any experience working within the Agile framework using Scrum. Security, compliance & governance Embed security controls and compliance checks into delivery pipelines (DevSecOps approach), ensuring cloud systems are configured securely and remain compliant. Contribute to platform governance initiatives such as naming/tagging conventions, logging standards, Key Vault/secret patterns, and controlled change via Github Push/Pull requests. Work closely with Security and CISO stakeholders and the wider networks team to maintain a strong and compliant security posture across our Azure public cloud subscription. Delivery collaboration & technical project contribution Collaborate with stakeholders, architects and engineers to translate requirements into Azure designs and deliver working solutions. Contribute to planning and execution of cloud-focused initiatives, identifying risks and dependencies early and supporting smooth transition into support. Maintain clear technical documentation (design notes, runbooks, standard operating procedures) in the team s knowledge base. What we are looking for: The role deliberately covers a relatively broad brief of technologies, targeted at enabling effective communication and efficient working practices. We would expect the role holder to be able to demonstrate a skill base that spans a range of the following topics and, where necessary, to demonstrate the aptitude and desire to develop to meet the entire brief. Knowledge of a range of enterprise IT application technologies, including a demonstrated track record in operating and administering or working with infrastructure applications as part of the: Microsoft Application Stack such as Exchange 365; Active Directory, AD connect, Azure site recovery (ASR), Azure Virtual Desktop (AVD) and Azure SQL. Experience of working with VMware vSphere, HPE Servers & Storage, upgrades and maintenance procedures. Hands-on experience engineering solutions in Microsoft Azure, including a solid understanding of Azure IaaS and PaaS services (e.g., VMs, Storage, App Services, Front Door, API Management, Azure Functions, Azure SQL, Azure Networking). Strong experience with PowerShell scripting and Infrastructure as Code in either (Bicep and/or Terraform; ARM knowledge acceptable where relevant). Practical experience with Azure DevOps (Pipelines, Repos, CI/CD concepts) and Git-based version control. Azure networking knowledge including VNETs, vWAN, ExpressRoute, VPN gateways, hub-and-spoke, and traffic management concepts. Azure security fundamentals including Managed Identities, Key Vault, Conditional Access, Defender for Cloud/Security Centre. Strong scripting capability in PowerShell (and/or Bash), and the ability to automate operational tasks and deployments. Strong troubleshooting mindset: diagnosing complex issues and driving them to resolution with appropriate escalation and RCA. Clear communication skills, including the ability to explain technical topics in plain English in a professional services environment. Preferably either: 5-years relevant experience working in a similar role, or a qualification in Computer Science or Engineering or Microsoft accredited Azure Certifications (e.g., Azure Administrator / DevOps / Cloud Engineering) and relevant experience working in a similar role. Excellent Knowledge of Microsoft Azure and Windows Stack. Career Level: The career level assigned to this role is level 3. The career level framework provides a formal structure for the business services functions at the firm. The framework, which ranges from level 1 to level 7, clearly defines the responsibilities, skills and competencies required at each level. Here at Simmons & Simmons: At Simmons, we are proud of our collaborative, open and non-hierarchical culture, where everyone is treated with respect and dignity and the wellbeing of our people is paramount. Our dynamic minds work as one integrated team, partnering with leading organisations on inspirational and thought-provoking projects that matter. From day one, irrespective of job title, qualification or background, everyone s voice is heard, and you are encouraged to have an enquiring mind and share ideas that drive the firm forward. Through innovative learning and development opportunities, you will have a platform to excel, exceed your career ambitions, and achieve things you never thought possible. Some key information: We offer a competitive package including bonuses dependant on role/level, private medical insurance and pension contribution. Our global skills academy provides our people, regardless of their role and location, with excellent learning opportunities (including live workshops, podcasts, short videos and practical learning experiences). We have adopted a hybrid working approach with a requirement for a minimum of three days in the office with flexibility dependant on role/team/client demands. We are proud to rank as a Times Top 50 Employer for Gender Equality, a Stonewall Top Global Employer, and a Top 75 Employer for Social Mobility. We have a range of social and sports committees, summer and winter parties and monthly get togethers. We have a range of diversity networks to connect people and celebrate our differences which is integral to our inclusive culture. All UK offices have their own artwork collections including Damien Hirst and Tracey Emin pieces in the London office. We have a long-standing history in supporting the art community especially up-and-coming artists. We have recently introduced a Strategic Advisory Council which is a mix of associates and business services who will propose strategic initiatives that align with our firm's mission and support the delivery of our business plan, shaping the future of our next-generation law firm. Our in-house generative AI tool, Percy, won the Innovation in Automation and AI Tools category at the 2024 FT Innovative Lawyers Europe Awards. This achievement highlights our commitment to technological innovation and client service. We have been commended in The Times Best Law Firms 2026 across three categories: construction, employment, and intellectual property. Our profile is highly positive, highlighting our sector specialisms and notable case and transactional work. Equal opportunities: We are committed to fostering equality, diversity and inclusion within our firm and to ensuring equal employment opportunities. We believe that this commitment creates a vibrant and rewarding work environment. We are therefore committed to: Upholding equal opportunities, regardless of race, ethnicity, religion, belief, age, disability, sexual orientation, sex, gender reassignment, gender identity, marital status, or pregnancy, including maternity and paternity. This commitment extends to addressing any instances of perceived or associative discrimination and harassment. We also ensure fair treatment during recruitment and selection processes for those who are serving or have served in the armed forces, along with their families. Accommodating requests for flexible working arrangements whenever possible. We encourage you to discuss your needs with us if this is something you require. Making our roles accessible to individuals with diverse abilities. If you need any reasonable adjustments during the recruitment process, please let us know so we can meet your needs. We offer a range of employee networks to support our colleagues. More information about these networks can be found in the D&I Information booklet that candidates are sent when invited to interview. . click apply for full job details
May 26, 2026
Full time
The role: We are looking for a Cloud Infrastructure Analyst to join our IT department in Bristol. At Simmons & Simmons, technology is central to delivering exceptional client service. We are seeking a talented and motivated Cloud Infrastructure Analyst to join our Platforms team and help build, automate and operate the Azure platform underpinning our applications and services. This is a hands-on engineering role focused on designing and delivering secure, scalable and resilient cloud solutions in Microsoft Azure, using Infrastructure as Code and CI/CD automation as the default approach. You will work closely with architects, security and application teams to implement cloud platform patterns and enable delivery teams to deploy safely and consistently. What will you do: Azure Infrastructure as Code (IaC) & CI/CD automation Build, deploy, and maintain Azure infrastructure using IaC (Bicep and/or Terraform) with peer review and version control. Strong familiarity working in IaC and pipelines to ensure quality, security and adherence to baseline standards. Cloud reliability, operations & incident/problem support (engineering-led) Act as an escalation point for complex Azure platform issues; troubleshoot, perform root cause analysis, and implement sustainable fixes (automation over repeated manual intervention). Monitor and improve platform health using Azure observability tooling (e.g., Azure Monitor, Log Analytics/KQL, Application Insights, Science Logic), and improve alerting and diagnostics. Plan and implement operational improvements such as performance tuning, resource optimisation and resilience enhancements, aligned to service expectations. Any experience working within the Agile framework using Scrum. Security, compliance & governance Embed security controls and compliance checks into delivery pipelines (DevSecOps approach), ensuring cloud systems are configured securely and remain compliant. Contribute to platform governance initiatives such as naming/tagging conventions, logging standards, Key Vault/secret patterns, and controlled change via Github Push/Pull requests. Work closely with Security and CISO stakeholders and the wider networks team to maintain a strong and compliant security posture across our Azure public cloud subscription. Delivery collaboration & technical project contribution Collaborate with stakeholders, architects and engineers to translate requirements into Azure designs and deliver working solutions. Contribute to planning and execution of cloud-focused initiatives, identifying risks and dependencies early and supporting smooth transition into support. Maintain clear technical documentation (design notes, runbooks, standard operating procedures) in the team s knowledge base. What we are looking for: The role deliberately covers a relatively broad brief of technologies, targeted at enabling effective communication and efficient working practices. We would expect the role holder to be able to demonstrate a skill base that spans a range of the following topics and, where necessary, to demonstrate the aptitude and desire to develop to meet the entire brief. Knowledge of a range of enterprise IT application technologies, including a demonstrated track record in operating and administering or working with infrastructure applications as part of the: Microsoft Application Stack such as Exchange 365; Active Directory, AD connect, Azure site recovery (ASR), Azure Virtual Desktop (AVD) and Azure SQL. Experience of working with VMware vSphere, HPE Servers & Storage, upgrades and maintenance procedures. Hands-on experience engineering solutions in Microsoft Azure, including a solid understanding of Azure IaaS and PaaS services (e.g., VMs, Storage, App Services, Front Door, API Management, Azure Functions, Azure SQL, Azure Networking). Strong experience with PowerShell scripting and Infrastructure as Code in either (Bicep and/or Terraform; ARM knowledge acceptable where relevant). Practical experience with Azure DevOps (Pipelines, Repos, CI/CD concepts) and Git-based version control. Azure networking knowledge including VNETs, vWAN, ExpressRoute, VPN gateways, hub-and-spoke, and traffic management concepts. Azure security fundamentals including Managed Identities, Key Vault, Conditional Access, Defender for Cloud/Security Centre. Strong scripting capability in PowerShell (and/or Bash), and the ability to automate operational tasks and deployments. Strong troubleshooting mindset: diagnosing complex issues and driving them to resolution with appropriate escalation and RCA. Clear communication skills, including the ability to explain technical topics in plain English in a professional services environment. Preferably either: 5-years relevant experience working in a similar role, or a qualification in Computer Science or Engineering or Microsoft accredited Azure Certifications (e.g., Azure Administrator / DevOps / Cloud Engineering) and relevant experience working in a similar role. Excellent Knowledge of Microsoft Azure and Windows Stack. Career Level: The career level assigned to this role is level 3. The career level framework provides a formal structure for the business services functions at the firm. The framework, which ranges from level 1 to level 7, clearly defines the responsibilities, skills and competencies required at each level. Here at Simmons & Simmons: At Simmons, we are proud of our collaborative, open and non-hierarchical culture, where everyone is treated with respect and dignity and the wellbeing of our people is paramount. Our dynamic minds work as one integrated team, partnering with leading organisations on inspirational and thought-provoking projects that matter. From day one, irrespective of job title, qualification or background, everyone s voice is heard, and you are encouraged to have an enquiring mind and share ideas that drive the firm forward. Through innovative learning and development opportunities, you will have a platform to excel, exceed your career ambitions, and achieve things you never thought possible. Some key information: We offer a competitive package including bonuses dependant on role/level, private medical insurance and pension contribution. Our global skills academy provides our people, regardless of their role and location, with excellent learning opportunities (including live workshops, podcasts, short videos and practical learning experiences). We have adopted a hybrid working approach with a requirement for a minimum of three days in the office with flexibility dependant on role/team/client demands. We are proud to rank as a Times Top 50 Employer for Gender Equality, a Stonewall Top Global Employer, and a Top 75 Employer for Social Mobility. We have a range of social and sports committees, summer and winter parties and monthly get togethers. We have a range of diversity networks to connect people and celebrate our differences which is integral to our inclusive culture. All UK offices have their own artwork collections including Damien Hirst and Tracey Emin pieces in the London office. We have a long-standing history in supporting the art community especially up-and-coming artists. We have recently introduced a Strategic Advisory Council which is a mix of associates and business services who will propose strategic initiatives that align with our firm's mission and support the delivery of our business plan, shaping the future of our next-generation law firm. Our in-house generative AI tool, Percy, won the Innovation in Automation and AI Tools category at the 2024 FT Innovative Lawyers Europe Awards. This achievement highlights our commitment to technological innovation and client service. We have been commended in The Times Best Law Firms 2026 across three categories: construction, employment, and intellectual property. Our profile is highly positive, highlighting our sector specialisms and notable case and transactional work. Equal opportunities: We are committed to fostering equality, diversity and inclusion within our firm and to ensuring equal employment opportunities. We believe that this commitment creates a vibrant and rewarding work environment. We are therefore committed to: Upholding equal opportunities, regardless of race, ethnicity, religion, belief, age, disability, sexual orientation, sex, gender reassignment, gender identity, marital status, or pregnancy, including maternity and paternity. This commitment extends to addressing any instances of perceived or associative discrimination and harassment. We also ensure fair treatment during recruitment and selection processes for those who are serving or have served in the armed forces, along with their families. Accommodating requests for flexible working arrangements whenever possible. We encourage you to discuss your needs with us if this is something you require. Making our roles accessible to individuals with diverse abilities. If you need any reasonable adjustments during the recruitment process, please let us know so we can meet your needs. We offer a range of employee networks to support our colleagues. More information about these networks can be found in the D&I Information booklet that candidates are sent when invited to interview. . click apply for full job details
The role: We are looking for a Senior Cloud Infrastructure Analyst to join our IT department in Bristol. At Simmons & Simmons, technology is central to delivering exceptional client service. We are seeking a talented and motivated Senior Cloud Infrastructure Analyst to join our Platforms team and help build, automate and operate the Azure platform underpinning our applications and services. This is a hands-on engineering role focused on designing and delivering secure, scalable and resilient cloud solutions in Microsoft Azure, using Infrastructure as Code and CI/CD automation as the default approach. You will work closely with architects, security and application teams to implement cloud platform patterns and enable delivery teams to deploy safely and consistently. You will be required to act as senior technical authority within the platforms team, supporting decision-making, mentoring engineers, and shaping the Azure roadmap. What will you do: Azure Infrastructure as Code (IaC) & CI/CD automation Build, deploy, and maintain Azure infrastructure using IaC (Bicep and/or Terraform) with peer review and version control. Strong familiarity working in IaC and pipelines to ensure quality, security and adherence to baseline standards. Cloud reliability, operations & incident/problem support (engineering-led) Act as a senior escalation point for complex Azure platform incidents; leading to troubleshoot, perform root cause analysis, and implement sustainable fixes (automation over repeated manual intervention). Monitor and improve platform health using Azure observability tooling (e.g., Azure Monitor, Log Analytics/KQL, Application Insights, Science Logic), and improve alerting and diagnostics. Lead reliability and resilience improvements such as such as performance tuning, resource optimisation, cost optimization using FinOps and provide availability enhancements, aligned to our service- level expectations. A senior analyst is expected to be a point of contact and escalation at all times, taking ownership of incident management, while providing 3rd & 4th level and technical support. Any experience working within the Agile framework using Scrum. Security, compliance & governance Embed security controls and compliance checks into delivery pipelines (DevSecOps approach), ensuring cloud systems are configured securely and remain compliant. Contribute to platform governance initiatives such as naming/tagging conventions, logging standards, Key Vault/secret patterns, and controlled change via Github Push/Pull requests. Work closely with Security and CISO stakeholders and the wider networks team to maintain a strong and compliant security posture across our Azure public cloud. What we are looking for: The role deliberately covers a relatively broad brief of technologies, targeted at enabling effective communication and efficient working practices. We would expect the role holder to be able to demonstrate a skill base that spans a range of the following topics and, where necessary, to demonstrate the aptitude and desire to develop to meet the entire brief. Knowledge of a range of enterprise IT application technologies, including a demonstrated track record in operating and administering or working with infrastructure applications as part of the: Microsoft Application Stack such as Exchange 365; Active Directory, AD connect, Azure site recovery (ASR) and Azure Virtual Desktop (AVD) and Azure SQL. Experience of working with VMware vSphere, HPE Servers & Storage, upgrades and maintenance procedures. Hands-on experience engineering solutions in Microsoft Azure, including a solid understanding of Azure IaaS and PaaS services (e.g., VMs, Storage, App Services, Front Door, API Management, Azure Functions, Azure SQL, Azure Networking). Strong experience with Infrastructure as Code in either (Bicep and/or Terraform; ARM knowledge acceptable where relevant). Practical experience with Azure DevOps (Pipelines, Repos, CI/CD concepts) and Git-based version control. Azure networking knowledge including VNETs, vWAN, ExpressRoute, VPN gateways, hub-and-spoke, and traffic management concepts. Azure security fundamentals including Managed Identities, Key Vault, Conditional Access, Defender for Cloud/Security Centre. Strong scripting capability in PowerShell (and/or Bash), and the ability to automate operational tasks and deployments. Strong troubleshooting mindset: diagnosing complex issues and driving them to resolution with appropriate escalation and RCA. Clear communication skills, including the ability to explain technical topics in plain English in a professional services environment. A Strong problem-solver with proactive, engineering-led mindset. Self-motivated technical lead and mentor. Comfortable working as a senior engineer in a collaborative, geographically diverse and inclusive team. Preferably either: 5-years relevant experience working in a similar role, or a qualification in Computer Science or Engineering or Microsoft accredited Azure Certifications (e.g., Azure Administrator / DevOps / Cloud Engineering) and relevant experience working in a similar role. Excellent Knowledge of the Azure and Windows Stack. Career Level: The career level assigned to this role is level 3. The career level framework provides a formal structure for the business services functions at the firm. The framework, which ranges from level 1 to level 7, clearly defines the responsibilities, skills and competencies required at each level. Here at Simmons & Simmons: At Simmons, we are proud of our collaborative, open and non-hierarchical culture, where everyone is treated with respect and dignity and the wellbeing of our people is paramount. Our dynamic minds work as one integrated team, partnering with leading organisations on inspirational and thought-provoking projects that matter. From day one, irrespective of job title, qualification or background, everyone s voice is heard, and you are encouraged to have an enquiring mind and share ideas that drive the firm forward. Through innovative learning and development opportunities, you will have a platform to excel, exceed your career ambitions, and achieve things you never thought possible. Some key information: We offer a competitive package including bonuses dependant on role/level, private medical insurance and pension contribution. Our global skills academy provides our people, regardless of their role and location, with excellent learning opportunities (including live workshops, podcasts, short videos and practical learning experiences). We have adopted a hybrid working approach with a requirement for a minimum of three days in the office with flexibility dependant on role/team/client demands. We are proud to rank as a Times Top 50 Employer for Gender Equality, a Stonewall Top Global Employer, and a Top 75 Employer for Social Mobility. We have a range of social and sports committees, summer and winter parties and monthly get togethers. We have a range of diversity networks to connect people and celebrate our differences which is integral to our inclusive culture. All UK offices have their own artwork collections including Damien Hirst and Tracey Emin pieces in the London office. We have a long-standing history in supporting the art community especially up-and-coming artists. We have recently introduced a Strategic Advisory Council which is a mix of associates and business services who will propose strategic initiatives that align with our firm's mission and support the delivery of our business plan, shaping the future of our next-generation law firm. Our in-house generative AI tool, Percy, won the Innovation in Automation and AI Tools category at the 2024 FT Innovative Lawyers Europe Awards. This achievement highlights our commitment to technological innovation and client service. We have been commended in The Times Best Law Firms 2026 across three categories: construction, employment, and intellectual property. Our profile is highly positive, highlighting our sector specialisms and notable case and transactional work. Equal opportunities: We are committed to fostering equality, diversity and inclusion within our firm and to ensuring equal employment opportunities. We believe that this commitment creates a vibrant and rewarding work environment. We are therefore committed to: Upholding equal opportunities, regardless of race, ethnicity, religion, belief, age, disability, sexual orientation, sex, gender reassignment, gender identity, marital status, or pregnancy, including maternity and paternity. This commitment extends to addressing any instances of perceived or associative discrimination and harassment. We also ensure fair treatment during recruitment and selection processes for those who are serving or have served in the armed forces, along with their families. Accommodating requests for flexible working arrangements whenever possible. We encourage you to discuss your needs with us if this is something you require. Making our roles accessible to individuals with diverse abilities. If you need any reasonable adjustments during the recruitment process, please let us know so we can meet your needs. We offer a range of employee networks to support our colleagues . click apply for full job details
May 26, 2026
Full time
The role: We are looking for a Senior Cloud Infrastructure Analyst to join our IT department in Bristol. At Simmons & Simmons, technology is central to delivering exceptional client service. We are seeking a talented and motivated Senior Cloud Infrastructure Analyst to join our Platforms team and help build, automate and operate the Azure platform underpinning our applications and services. This is a hands-on engineering role focused on designing and delivering secure, scalable and resilient cloud solutions in Microsoft Azure, using Infrastructure as Code and CI/CD automation as the default approach. You will work closely with architects, security and application teams to implement cloud platform patterns and enable delivery teams to deploy safely and consistently. You will be required to act as senior technical authority within the platforms team, supporting decision-making, mentoring engineers, and shaping the Azure roadmap. What will you do: Azure Infrastructure as Code (IaC) & CI/CD automation Build, deploy, and maintain Azure infrastructure using IaC (Bicep and/or Terraform) with peer review and version control. Strong familiarity working in IaC and pipelines to ensure quality, security and adherence to baseline standards. Cloud reliability, operations & incident/problem support (engineering-led) Act as a senior escalation point for complex Azure platform incidents; leading to troubleshoot, perform root cause analysis, and implement sustainable fixes (automation over repeated manual intervention). Monitor and improve platform health using Azure observability tooling (e.g., Azure Monitor, Log Analytics/KQL, Application Insights, Science Logic), and improve alerting and diagnostics. Lead reliability and resilience improvements such as such as performance tuning, resource optimisation, cost optimization using FinOps and provide availability enhancements, aligned to our service- level expectations. A senior analyst is expected to be a point of contact and escalation at all times, taking ownership of incident management, while providing 3rd & 4th level and technical support. Any experience working within the Agile framework using Scrum. Security, compliance & governance Embed security controls and compliance checks into delivery pipelines (DevSecOps approach), ensuring cloud systems are configured securely and remain compliant. Contribute to platform governance initiatives such as naming/tagging conventions, logging standards, Key Vault/secret patterns, and controlled change via Github Push/Pull requests. Work closely with Security and CISO stakeholders and the wider networks team to maintain a strong and compliant security posture across our Azure public cloud. What we are looking for: The role deliberately covers a relatively broad brief of technologies, targeted at enabling effective communication and efficient working practices. We would expect the role holder to be able to demonstrate a skill base that spans a range of the following topics and, where necessary, to demonstrate the aptitude and desire to develop to meet the entire brief. Knowledge of a range of enterprise IT application technologies, including a demonstrated track record in operating and administering or working with infrastructure applications as part of the: Microsoft Application Stack such as Exchange 365; Active Directory, AD connect, Azure site recovery (ASR) and Azure Virtual Desktop (AVD) and Azure SQL. Experience of working with VMware vSphere, HPE Servers & Storage, upgrades and maintenance procedures. Hands-on experience engineering solutions in Microsoft Azure, including a solid understanding of Azure IaaS and PaaS services (e.g., VMs, Storage, App Services, Front Door, API Management, Azure Functions, Azure SQL, Azure Networking). Strong experience with Infrastructure as Code in either (Bicep and/or Terraform; ARM knowledge acceptable where relevant). Practical experience with Azure DevOps (Pipelines, Repos, CI/CD concepts) and Git-based version control. Azure networking knowledge including VNETs, vWAN, ExpressRoute, VPN gateways, hub-and-spoke, and traffic management concepts. Azure security fundamentals including Managed Identities, Key Vault, Conditional Access, Defender for Cloud/Security Centre. Strong scripting capability in PowerShell (and/or Bash), and the ability to automate operational tasks and deployments. Strong troubleshooting mindset: diagnosing complex issues and driving them to resolution with appropriate escalation and RCA. Clear communication skills, including the ability to explain technical topics in plain English in a professional services environment. A Strong problem-solver with proactive, engineering-led mindset. Self-motivated technical lead and mentor. Comfortable working as a senior engineer in a collaborative, geographically diverse and inclusive team. Preferably either: 5-years relevant experience working in a similar role, or a qualification in Computer Science or Engineering or Microsoft accredited Azure Certifications (e.g., Azure Administrator / DevOps / Cloud Engineering) and relevant experience working in a similar role. Excellent Knowledge of the Azure and Windows Stack. Career Level: The career level assigned to this role is level 3. The career level framework provides a formal structure for the business services functions at the firm. The framework, which ranges from level 1 to level 7, clearly defines the responsibilities, skills and competencies required at each level. Here at Simmons & Simmons: At Simmons, we are proud of our collaborative, open and non-hierarchical culture, where everyone is treated with respect and dignity and the wellbeing of our people is paramount. Our dynamic minds work as one integrated team, partnering with leading organisations on inspirational and thought-provoking projects that matter. From day one, irrespective of job title, qualification or background, everyone s voice is heard, and you are encouraged to have an enquiring mind and share ideas that drive the firm forward. Through innovative learning and development opportunities, you will have a platform to excel, exceed your career ambitions, and achieve things you never thought possible. Some key information: We offer a competitive package including bonuses dependant on role/level, private medical insurance and pension contribution. Our global skills academy provides our people, regardless of their role and location, with excellent learning opportunities (including live workshops, podcasts, short videos and practical learning experiences). We have adopted a hybrid working approach with a requirement for a minimum of three days in the office with flexibility dependant on role/team/client demands. We are proud to rank as a Times Top 50 Employer for Gender Equality, a Stonewall Top Global Employer, and a Top 75 Employer for Social Mobility. We have a range of social and sports committees, summer and winter parties and monthly get togethers. We have a range of diversity networks to connect people and celebrate our differences which is integral to our inclusive culture. All UK offices have their own artwork collections including Damien Hirst and Tracey Emin pieces in the London office. We have a long-standing history in supporting the art community especially up-and-coming artists. We have recently introduced a Strategic Advisory Council which is a mix of associates and business services who will propose strategic initiatives that align with our firm's mission and support the delivery of our business plan, shaping the future of our next-generation law firm. Our in-house generative AI tool, Percy, won the Innovation in Automation and AI Tools category at the 2024 FT Innovative Lawyers Europe Awards. This achievement highlights our commitment to technological innovation and client service. We have been commended in The Times Best Law Firms 2026 across three categories: construction, employment, and intellectual property. Our profile is highly positive, highlighting our sector specialisms and notable case and transactional work. Equal opportunities: We are committed to fostering equality, diversity and inclusion within our firm and to ensuring equal employment opportunities. We believe that this commitment creates a vibrant and rewarding work environment. We are therefore committed to: Upholding equal opportunities, regardless of race, ethnicity, religion, belief, age, disability, sexual orientation, sex, gender reassignment, gender identity, marital status, or pregnancy, including maternity and paternity. This commitment extends to addressing any instances of perceived or associative discrimination and harassment. We also ensure fair treatment during recruitment and selection processes for those who are serving or have served in the armed forces, along with their families. Accommodating requests for flexible working arrangements whenever possible. We encourage you to discuss your needs with us if this is something you require. Making our roles accessible to individuals with diverse abilities. If you need any reasonable adjustments during the recruitment process, please let us know so we can meet your needs. We offer a range of employee networks to support our colleagues . click apply for full job details
Kenneth Brian Associates are recruiting for an IT Manager to join a well-established organisation in the professional services industry. This will be a standalone IT role within the organisation so the candidate will need to be happy to get stuck into all aspects of IT. The organisation work with a MSP for technical support, however you will be dealing with all day to day IT which could be anything from simple to advanced technical support, managing external IT providers and working on various IT projects and system improvements. Please note - This role will be predominantly office based in Coulsdon however there may be rare occasions you will need to travel to the organisations smaller offices. Key responsibilities include: Providing 1st 2nd and some 3rd line support across the business Supporting internal employees with any technical issues they may encounter whether that be hardware, software or connection issues Managing Microsoft Azure, Active Directory and Office 365 environments Supporting servers, virtual environments, networking, and security systems Managing DNS, DHCP, routers, switches, firewalls and VoIP systems Working alongside the MSP for escalated IT issues Lead and support IT projects, upgrades, migrations and process improvements Experience required: Previous hands on experience working within an Infrastructure environment, for an SME organisation Strong Microsoft cloud and infrastructure knowledge VoIP systems experience as well as Active Directory Experience working within a Microsoft 365 environment Excellent communication skills, able to support a variety of users Solid networking and troubleshooting skills This is an excellent opportunity for a proactive IT professional looking for a varied and technically hands-on position within a supportive business environment.
May 24, 2026
Full time
Kenneth Brian Associates are recruiting for an IT Manager to join a well-established organisation in the professional services industry. This will be a standalone IT role within the organisation so the candidate will need to be happy to get stuck into all aspects of IT. The organisation work with a MSP for technical support, however you will be dealing with all day to day IT which could be anything from simple to advanced technical support, managing external IT providers and working on various IT projects and system improvements. Please note - This role will be predominantly office based in Coulsdon however there may be rare occasions you will need to travel to the organisations smaller offices. Key responsibilities include: Providing 1st 2nd and some 3rd line support across the business Supporting internal employees with any technical issues they may encounter whether that be hardware, software or connection issues Managing Microsoft Azure, Active Directory and Office 365 environments Supporting servers, virtual environments, networking, and security systems Managing DNS, DHCP, routers, switches, firewalls and VoIP systems Working alongside the MSP for escalated IT issues Lead and support IT projects, upgrades, migrations and process improvements Experience required: Previous hands on experience working within an Infrastructure environment, for an SME organisation Strong Microsoft cloud and infrastructure knowledge VoIP systems experience as well as Active Directory Experience working within a Microsoft 365 environment Excellent communication skills, able to support a variety of users Solid networking and troubleshooting skills This is an excellent opportunity for a proactive IT professional looking for a varied and technically hands-on position within a supportive business environment.
Are you a highly skilled technical consultant with a wealth of experience across a multitude of technologies looking for an exciting new challenge within an MSP? The Company Krome Technologies is a dynamic, people first technology consultancy delivering a wide portfolio of IT services and solutions across all industry sectors. Our clients range from high-street names to growing SME's. Our core focus is assisting them with achieving their business goals through relevant and forward-thinking technology solutions.With passion, integrity and with proven success, we work closely with our clients as a trusted business partner, advising on how, with appropriate technology advancements, we can help them achieve their current and projected business needs.Our talented people drive us forward, and we believe in encouraging a strong company culture of Community, Confidence and Integrity. The Role Due to continued and exciting growth within the business, a role has emerged for a Senior Third Line IT Support Engineer / Technical Consultant to join our highly skilled technical team.As a Senior Third Line IT Engineer, you will be working on a variety of projects as well as assisting other technical teams with any third line escalations that arise using good general experience across a range of subjects until resolution is reached. You will be liaising with clients and vendors to ensure a positive communication flow.It will also be your function to assist the junior team with mentoring on both technical and process matters.This is a Monday to Friday role 9:00am - 5:00pm based at Krome's HQ in Chertsey (Surrey). Once probation has been successfully completed, there will be the opportunity to work 3 days per week in the office and 2 days flexible working (depending on client/business needs). However, our Consultants also work on secondments, so availability to work in Chertsey but also to travel to London and other international client locations is required. Requirements • Good background in a generalist 3rd Line Technical Support Engineer / Consulting role• Experience as a client-facing SME proposing technical solutions• Solid experience with and the ability to deploy & configure at least some of the following: Microsoft Product Set (Windows Server, Active Directory, SQL, Exchange, Azure, Entra-ID, M365, Autopilot, Intune etc)• TCP/IP networking and troubleshooting• Virtualisation (Ideally with Hyper-V and integration with Azure), SANs and other related technologies• Backup Product Sets such as Veeam and Azure Backup• Firewall technologies such as Palo Alto• Leading migration projects• Strong documentation skills eg. PCI Compliance, ISO27001 etc• Great communication skills (in person and via telephone) - excellent written and spoken English is essential• Personable, with the ability to build rapport with multiple teams of IT technicians. The candidate will be required to integrate within both the Krome technical team and client IT departments• The successful candidate will be a punctual and thorough worker, with astute attention to detail• Any IT qualifications will be an advantage but not essential • This role will be based at our HQ in Chertsey (Surrey) so living in close proximity to the office will be a distinct advantage • Valid UK driving licence is essential The Package £40,000 - £55,000+ Basic (depending on experience) Benefits • 4% Employer Pension Contribution• Flexible Annual Leave Package (25 days, plus Bank Holidays, increasing with Length of Service)• Electric Vehicle (EV) Salary Sacrifice Scheme• Employee Assistance Programme• Private Medical Insurance (applicable after 5 years' service)• Learning and Development Programme, aimed to support Career Progression• Monthly Employee Recognition Awards (Extra Days Holiday or Amazon Voucher Rewards)• Long Service Recognition Awards for 5, 10, 15 years+• Complimentary Breakfast Available (8am - 9am Mon to Fri)• Complimentary Tea/Coffee and Fresh Fruit Available All-day• Fully Stocked Soft Drinks/Beer/Wine Fridge for Friday After Work Drinks• Discounted Corporate Gym Membership• Cycle to Work Scheme• Shower Facilities • Free Private Car Park• Staff Break Out Room with Pool Table• Modern, Open Plan, Office Environment• Regular Company-Funded Social Events • Company-Funded (Voluntary) Participation in our Charity Events• Electric Vehicle Charging Points are available at our Chertsey Head Office Inclusion & Diversity Krome Technologies is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive work environment free from discrimination, where all employees are treated with dignity and respect. All aspects of employment at Krome including the decision to hire, promote, discipline, or discharge, will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, colour, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, or veteran status.Krome Technologies is committed to protecting the privacy and security of all personal information that we process in order to provide services to our clients. For specific information on how Krome Technologies protects personal information online, please see the Krome Technologies Privacy Policy on our website. You may have experience of the following: Third Line Support Engineer, Senior IT Support Engineer, Technical Consultant, IT Infrastructure Engineer, Senior Systems Engineer, MSP Engineer, IT Solutions Consultant, 3rd Line Infrastructure Consultant, Senior Network Engineer, Cloud and Infrastructure Engineer.REF-
May 23, 2026
Full time
Are you a highly skilled technical consultant with a wealth of experience across a multitude of technologies looking for an exciting new challenge within an MSP? The Company Krome Technologies is a dynamic, people first technology consultancy delivering a wide portfolio of IT services and solutions across all industry sectors. Our clients range from high-street names to growing SME's. Our core focus is assisting them with achieving their business goals through relevant and forward-thinking technology solutions.With passion, integrity and with proven success, we work closely with our clients as a trusted business partner, advising on how, with appropriate technology advancements, we can help them achieve their current and projected business needs.Our talented people drive us forward, and we believe in encouraging a strong company culture of Community, Confidence and Integrity. The Role Due to continued and exciting growth within the business, a role has emerged for a Senior Third Line IT Support Engineer / Technical Consultant to join our highly skilled technical team.As a Senior Third Line IT Engineer, you will be working on a variety of projects as well as assisting other technical teams with any third line escalations that arise using good general experience across a range of subjects until resolution is reached. You will be liaising with clients and vendors to ensure a positive communication flow.It will also be your function to assist the junior team with mentoring on both technical and process matters.This is a Monday to Friday role 9:00am - 5:00pm based at Krome's HQ in Chertsey (Surrey). Once probation has been successfully completed, there will be the opportunity to work 3 days per week in the office and 2 days flexible working (depending on client/business needs). However, our Consultants also work on secondments, so availability to work in Chertsey but also to travel to London and other international client locations is required. Requirements • Good background in a generalist 3rd Line Technical Support Engineer / Consulting role• Experience as a client-facing SME proposing technical solutions• Solid experience with and the ability to deploy & configure at least some of the following: Microsoft Product Set (Windows Server, Active Directory, SQL, Exchange, Azure, Entra-ID, M365, Autopilot, Intune etc)• TCP/IP networking and troubleshooting• Virtualisation (Ideally with Hyper-V and integration with Azure), SANs and other related technologies• Backup Product Sets such as Veeam and Azure Backup• Firewall technologies such as Palo Alto• Leading migration projects• Strong documentation skills eg. PCI Compliance, ISO27001 etc• Great communication skills (in person and via telephone) - excellent written and spoken English is essential• Personable, with the ability to build rapport with multiple teams of IT technicians. The candidate will be required to integrate within both the Krome technical team and client IT departments• The successful candidate will be a punctual and thorough worker, with astute attention to detail• Any IT qualifications will be an advantage but not essential • This role will be based at our HQ in Chertsey (Surrey) so living in close proximity to the office will be a distinct advantage • Valid UK driving licence is essential The Package £40,000 - £55,000+ Basic (depending on experience) Benefits • 4% Employer Pension Contribution• Flexible Annual Leave Package (25 days, plus Bank Holidays, increasing with Length of Service)• Electric Vehicle (EV) Salary Sacrifice Scheme• Employee Assistance Programme• Private Medical Insurance (applicable after 5 years' service)• Learning and Development Programme, aimed to support Career Progression• Monthly Employee Recognition Awards (Extra Days Holiday or Amazon Voucher Rewards)• Long Service Recognition Awards for 5, 10, 15 years+• Complimentary Breakfast Available (8am - 9am Mon to Fri)• Complimentary Tea/Coffee and Fresh Fruit Available All-day• Fully Stocked Soft Drinks/Beer/Wine Fridge for Friday After Work Drinks• Discounted Corporate Gym Membership• Cycle to Work Scheme• Shower Facilities • Free Private Car Park• Staff Break Out Room with Pool Table• Modern, Open Plan, Office Environment• Regular Company-Funded Social Events • Company-Funded (Voluntary) Participation in our Charity Events• Electric Vehicle Charging Points are available at our Chertsey Head Office Inclusion & Diversity Krome Technologies is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive work environment free from discrimination, where all employees are treated with dignity and respect. All aspects of employment at Krome including the decision to hire, promote, discipline, or discharge, will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, colour, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, or veteran status.Krome Technologies is committed to protecting the privacy and security of all personal information that we process in order to provide services to our clients. For specific information on how Krome Technologies protects personal information online, please see the Krome Technologies Privacy Policy on our website. You may have experience of the following: Third Line Support Engineer, Senior IT Support Engineer, Technical Consultant, IT Infrastructure Engineer, Senior Systems Engineer, MSP Engineer, IT Solutions Consultant, 3rd Line Infrastructure Consultant, Senior Network Engineer, Cloud and Infrastructure Engineer.REF-
Job Advertisement: M365 Identity & Integration Engineer Location: Leeds, 2 days per week in the office, Working Pattern: Via Umbrella Company Contract Length: 6 months Are you ready to embark on an exciting journey with a leading financial institution? Our client is seeking a talented M365 Identity & Integration Engineer to join their dynamic team! If you are passionate about technology and enjoy tackling challenges, this is the opportunity for you! Role Overview: As the M365 Identity & Integration Engineer, you will play a crucial role in the technical integration and ongoing operation of applications across the Workplace Technology portfolio. Your hands-on expertise will ensure that new and existing applications align with identity, security, governance, and operational processes. Get ready to collaborate with various teams, including Microsoft 365, Cyber Security, and Service Operations, to deliver secure and supportable solutions! Key Responsibilities: Lead Application Integration: Oversee the technical onboarding of applications from design to BAU support. Secure Integrations: Design and implement integrations with corporate services, including Entra ID/Active Directory and SSO (SAML, OIDC, OAuth). Collaborate with Stakeholders: Understand functional requirements and translate them into practical technical designs. Ensure Monitoring: Integrate applications with internal monitoring and support processes before go-live. SSO Support: Implement and support SSO integrations via Entra ID, managing app registrations and troubleshooting. Apply Security Controls: Enforce organizational standards, including Conditional Access, MFA, and secure account management. Support Security Assurance: Assist in architecture reviews, supplier security assessments, and remediation actions. Operational Artefacts: Produce and maintain support models, runbooks, and onboarding checklists. Technical Escalation Point: Act as a go-to for complex incidents related to authentication and access. Collaboration Across Teams: Work with platform teams to deliver cohesive solutions. Continuous Improvement: Identify and propose enhancements for integration and operational processes. Essential Skills & Experience: Strong experience with Microsoft Entra ID (Azure AD), including SSO and app registrations. Proficiency in Conditional Access/MFA design and operational troubleshooting. Understanding of identity governance concepts (RBAC, least privilege). Expertise in integrating SaaS platforms within regulated environments. Exceptional troubleshooting skills across authentication flows and related technologies. Nice-to-Have (Highly Desirable): Experience with Cisco Spaces or similar platforms. Familiarity with workplace analytics and data governance. Knowledge of Microsoft 365 services and integration points. Basic scripting/automation skills (PowerShell preferred). Desirable Qualifications: Relevant industry certifications (e.g., Microsoft Identity/Security/Azure fundamentals). ITIL v4 Foundation or equivalent service management certification. Experience with security frameworks like ISO27001 or Cyber Essentials Plus. If you're ready to take your career to the next level and contribute to a leading financial institution, we want to hear from you! Apply now and become a key player in shaping the future of Workplace Technology! Our client is committed to diversity and inclusion and encourages applications from all qualified candidates. Pontoon is an employment consultancy. We put expertise, energy, and enthusiasm into improving everyone's chance of being part of the workplace. We respect and appreciate people of all ethnicities, generations, religious beliefs, sexual orientations, gender identities, and more. We do this by showcasing their talents, skills, and unique experience in an inclusive environment that helps them thrive. If you require reasonable adjustments at any stage, please let us know and we will be happy to support you.
May 22, 2026
Contractor
Job Advertisement: M365 Identity & Integration Engineer Location: Leeds, 2 days per week in the office, Working Pattern: Via Umbrella Company Contract Length: 6 months Are you ready to embark on an exciting journey with a leading financial institution? Our client is seeking a talented M365 Identity & Integration Engineer to join their dynamic team! If you are passionate about technology and enjoy tackling challenges, this is the opportunity for you! Role Overview: As the M365 Identity & Integration Engineer, you will play a crucial role in the technical integration and ongoing operation of applications across the Workplace Technology portfolio. Your hands-on expertise will ensure that new and existing applications align with identity, security, governance, and operational processes. Get ready to collaborate with various teams, including Microsoft 365, Cyber Security, and Service Operations, to deliver secure and supportable solutions! Key Responsibilities: Lead Application Integration: Oversee the technical onboarding of applications from design to BAU support. Secure Integrations: Design and implement integrations with corporate services, including Entra ID/Active Directory and SSO (SAML, OIDC, OAuth). Collaborate with Stakeholders: Understand functional requirements and translate them into practical technical designs. Ensure Monitoring: Integrate applications with internal monitoring and support processes before go-live. SSO Support: Implement and support SSO integrations via Entra ID, managing app registrations and troubleshooting. Apply Security Controls: Enforce organizational standards, including Conditional Access, MFA, and secure account management. Support Security Assurance: Assist in architecture reviews, supplier security assessments, and remediation actions. Operational Artefacts: Produce and maintain support models, runbooks, and onboarding checklists. Technical Escalation Point: Act as a go-to for complex incidents related to authentication and access. Collaboration Across Teams: Work with platform teams to deliver cohesive solutions. Continuous Improvement: Identify and propose enhancements for integration and operational processes. Essential Skills & Experience: Strong experience with Microsoft Entra ID (Azure AD), including SSO and app registrations. Proficiency in Conditional Access/MFA design and operational troubleshooting. Understanding of identity governance concepts (RBAC, least privilege). Expertise in integrating SaaS platforms within regulated environments. Exceptional troubleshooting skills across authentication flows and related technologies. Nice-to-Have (Highly Desirable): Experience with Cisco Spaces or similar platforms. Familiarity with workplace analytics and data governance. Knowledge of Microsoft 365 services and integration points. Basic scripting/automation skills (PowerShell preferred). Desirable Qualifications: Relevant industry certifications (e.g., Microsoft Identity/Security/Azure fundamentals). ITIL v4 Foundation or equivalent service management certification. Experience with security frameworks like ISO27001 or Cyber Essentials Plus. If you're ready to take your career to the next level and contribute to a leading financial institution, we want to hear from you! Apply now and become a key player in shaping the future of Workplace Technology! Our client is committed to diversity and inclusion and encourages applications from all qualified candidates. Pontoon is an employment consultancy. We put expertise, energy, and enthusiasm into improving everyone's chance of being part of the workplace. We respect and appreciate people of all ethnicities, generations, religious beliefs, sexual orientations, gender identities, and more. We do this by showcasing their talents, skills, and unique experience in an inclusive environment that helps them thrive. If you require reasonable adjustments at any stage, please let us know and we will be happy to support you.
Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures-and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive. What You'll Do The Principal IAM Engineer is the senior technical authority for identity services, responsible for designing, implementing, and governing enterprise-wide IAM capabilities across workforce, partner, and customer identities. This role combines deep hands-on engineering with architecture and leadership, driving the modernization of authentication, authorization, identity lifecycle, and privileged access controls across our cloud and on-prem environments. Responsibilities: Own the end to end technical delivery of IAM services, including identity lifecycle management, authentication, authorization, SSO, and privileged access controls, ensuring they are secure, scalable, and highly available. Lead design sessions, collaborating with Entrprise Architecture, and implementation of IAM integrations for SaaS, on prem, and AWS cloud platforms, including federation (SAML, OIDC, OAuth), MFA, and Passwordless capabilities. Serve as the primary escalation point for complex IAM engineering issues; perform root cause analysis and drive long term remediation and hardening of IAM platforms and related services. Partner with security architecture, infrastructure, application, and HR/IT teams to align IAM solutions with enterprise security strategy, compliance obligations, and business objectives. Define IAM engineering standards, patterns, and reference architectures; guide other engineers in implementing secure onboarding patterns for applications into IGA, PAM, and SSO platforms. Lead modernization initiatives. Contribute to audits, risk assessments, and regulatory reviews by providing technical evidence, designing compensating controls, and closing identified IAM control gaps. Mentor and coach IAM engineers and analysts, promoting engineering excellence, documentation discipline, and a culture of continuous learning and improvement. What You'll Bring 10+ years of experience in information security or infrastructure engineering, with at least 5 years of hands-on-keyboard experience with core IAM platforms. Deep expertise with the majority of our IAM stack Strong hands-on experience with Microsoft Entra ID and Active Directory as foundational directory services, and extensive experience implementing federation protocols (SAML, OIDC, OAuth2). Proven track record designing and implementing IAM solutions in hybrid multi-cloud environments, including the automation of provisioning, access reviews, and RBAC/ABAC models. Experience with secrets management solutions. Proficiency in at least one scripting or programming language (such as PowerShell, Python, or Java) to automate tasks and build custom connectors for our IAM tools. Excellent communication skills with the ability to translate complex technical concepts related to our IAM ecosystem for both technical and non-technical stakeholders. Exceptional sense of ownership and the ability to work with a limited set of requirements. Highly advanced ability to breakdown work to deliver value incrementally. Experience leading large-scale IAM programs. Prior responsibility as a technical lead or architect for IAM, including mentoring teams and influencing roadmaps beyond direct reporting lines. Demonstrated ability to balance security, usability, and operational efficiency, with a strong bias toward automation and measurable risk reduction. Define and lead the implementation of the organization's security strategy, with a focus on Cloud Security, Identity Access Management, and all other aspects of Cybersecurity Oversee the deployment of IAM solutions across both on-premise and cloud environments, ensuring they meet the highest standards of security. Lead the most complex security assessments, including threat modeling, red teaming, and cloud security reviews. Collaborate with executive leadership to ensure that security initiatives align with the organization's strategic goals and risk appetite. Act as the technical lead for large-scale security projects, coordinating cross-functional teams to ensure successful delivery. Architect and implement solutions across workforce IAM, PAM, and customer IAM ecosystems. Provide thought leadership in adopting passwordless authentication, passkeys, adaptive MFA, and AI-driven access orchestration strategies Engineer integrations with Agentic AI tools for intelligent decisioning, policy enforcement, and autonomous identity lifecycle operations. Develop and implement automated provisioning/deprovisioning workflows Ensure integration of IAM with cloud platforms (Azure, AWS, GCP) and SaaS applications. Mentor and develop the skills of senior security engineers, fostering a culture of continuous improvement and innovation. Technical Experience Must-Have: Privileged Access management (CyberArk) Authentication/AuthN (Okta) Federated Identity (EntraID) Cloud Identity (AWS, GCP, Azure) Automation (terraform, codex, claude) Application SSO (OIDC, SAML) Identity Governance (Sailpoint, Okta, Veza) Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify.
May 21, 2026
Full time
Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures-and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive. What You'll Do The Principal IAM Engineer is the senior technical authority for identity services, responsible for designing, implementing, and governing enterprise-wide IAM capabilities across workforce, partner, and customer identities. This role combines deep hands-on engineering with architecture and leadership, driving the modernization of authentication, authorization, identity lifecycle, and privileged access controls across our cloud and on-prem environments. Responsibilities: Own the end to end technical delivery of IAM services, including identity lifecycle management, authentication, authorization, SSO, and privileged access controls, ensuring they are secure, scalable, and highly available. Lead design sessions, collaborating with Entrprise Architecture, and implementation of IAM integrations for SaaS, on prem, and AWS cloud platforms, including federation (SAML, OIDC, OAuth), MFA, and Passwordless capabilities. Serve as the primary escalation point for complex IAM engineering issues; perform root cause analysis and drive long term remediation and hardening of IAM platforms and related services. Partner with security architecture, infrastructure, application, and HR/IT teams to align IAM solutions with enterprise security strategy, compliance obligations, and business objectives. Define IAM engineering standards, patterns, and reference architectures; guide other engineers in implementing secure onboarding patterns for applications into IGA, PAM, and SSO platforms. Lead modernization initiatives. Contribute to audits, risk assessments, and regulatory reviews by providing technical evidence, designing compensating controls, and closing identified IAM control gaps. Mentor and coach IAM engineers and analysts, promoting engineering excellence, documentation discipline, and a culture of continuous learning and improvement. What You'll Bring 10+ years of experience in information security or infrastructure engineering, with at least 5 years of hands-on-keyboard experience with core IAM platforms. Deep expertise with the majority of our IAM stack Strong hands-on experience with Microsoft Entra ID and Active Directory as foundational directory services, and extensive experience implementing federation protocols (SAML, OIDC, OAuth2). Proven track record designing and implementing IAM solutions in hybrid multi-cloud environments, including the automation of provisioning, access reviews, and RBAC/ABAC models. Experience with secrets management solutions. Proficiency in at least one scripting or programming language (such as PowerShell, Python, or Java) to automate tasks and build custom connectors for our IAM tools. Excellent communication skills with the ability to translate complex technical concepts related to our IAM ecosystem for both technical and non-technical stakeholders. Exceptional sense of ownership and the ability to work with a limited set of requirements. Highly advanced ability to breakdown work to deliver value incrementally. Experience leading large-scale IAM programs. Prior responsibility as a technical lead or architect for IAM, including mentoring teams and influencing roadmaps beyond direct reporting lines. Demonstrated ability to balance security, usability, and operational efficiency, with a strong bias toward automation and measurable risk reduction. Define and lead the implementation of the organization's security strategy, with a focus on Cloud Security, Identity Access Management, and all other aspects of Cybersecurity Oversee the deployment of IAM solutions across both on-premise and cloud environments, ensuring they meet the highest standards of security. Lead the most complex security assessments, including threat modeling, red teaming, and cloud security reviews. Collaborate with executive leadership to ensure that security initiatives align with the organization's strategic goals and risk appetite. Act as the technical lead for large-scale security projects, coordinating cross-functional teams to ensure successful delivery. Architect and implement solutions across workforce IAM, PAM, and customer IAM ecosystems. Provide thought leadership in adopting passwordless authentication, passkeys, adaptive MFA, and AI-driven access orchestration strategies Engineer integrations with Agentic AI tools for intelligent decisioning, policy enforcement, and autonomous identity lifecycle operations. Develop and implement automated provisioning/deprovisioning workflows Ensure integration of IAM with cloud platforms (Azure, AWS, GCP) and SaaS applications. Mentor and develop the skills of senior security engineers, fostering a culture of continuous improvement and innovation. Technical Experience Must-Have: Privileged Access management (CyberArk) Authentication/AuthN (Okta) Federated Identity (EntraID) Cloud Identity (AWS, GCP, Azure) Automation (terraform, codex, claude) Application SSO (OIDC, SAML) Identity Governance (Sailpoint, Okta, Veza) Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify.
Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures-and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive. What You'll Do The Principal IAM Engineer is the senior technical authority for identity services, responsible for designing, implementing, and governing enterprise-wide IAM capabilities across workforce, partner, and customer identities. This role combines deep hands-on engineering with architecture and leadership, driving the modernization of authentication, authorization, identity lifecycle, and privileged access controls across our cloud and on-prem environments. Responsibilities: Own the end to end technical delivery of IAM services, including identity lifecycle management, authentication, authorization, SSO, and privileged access controls, ensuring they are secure, scalable, and highly available. Lead design sessions, collaborating with Entrprise Architecture, and implementation of IAM integrations for SaaS, on prem, and AWS cloud platforms, including federation (SAML, OIDC, OAuth), MFA, and Passwordless capabilities. Serve as the primary escalation point for complex IAM engineering issues; perform root cause analysis and drive long term remediation and hardening of IAM platforms and related services. Partner with security architecture, infrastructure, application, and HR/IT teams to align IAM solutions with enterprise security strategy, compliance obligations, and business objectives. Define IAM engineering standards, patterns, and reference architectures; guide other engineers in implementing secure onboarding patterns for applications into IGA, PAM, and SSO platforms. Lead modernization initiatives. Contribute to audits, risk assessments, and regulatory reviews by providing technical evidence, designing compensating controls, and closing identified IAM control gaps. Mentor and coach IAM engineers and analysts, promoting engineering excellence, documentation discipline, and a culture of continuous learning and improvement. What You'll Bring 10+ years of experience in information security or infrastructure engineering, with at least 5 years of hands-on-keyboard experience with core IAM platforms. Deep expertise with the majority of our IAM stack Strong hands-on experience with Microsoft Entra ID and Active Directory as foundational directory services, and extensive experience implementing federation protocols (SAML, OIDC, OAuth2). Proven track record designing and implementing IAM solutions in hybrid multi-cloud environments, including the automation of provisioning, access reviews, and RBAC/ABAC models. Experience with secrets management solutions. Proficiency in at least one scripting or programming language (such as PowerShell, Python, or Java) to automate tasks and build custom connectors for our IAM tools. Excellent communication skills with the ability to translate complex technical concepts related to our IAM ecosystem for both technical and non-technical stakeholders. Exceptional sense of ownership and the ability to work with a limited set of requirements. Highly advanced ability to breakdown work to deliver value incrementally. Experience leading large-scale IAM programs. Prior responsibility as a technical lead or architect for IAM, including mentoring teams and influencing roadmaps beyond direct reporting lines. Demonstrated ability to balance security, usability, and operational efficiency, with a strong bias toward automation and measurable risk reduction. Define and lead the implementation of the organization's security strategy, with a focus on Cloud Security, Identity Access Management, and all other aspects of Cybersecurity Oversee the deployment of IAM solutions across both on-premise and cloud environments, ensuring they meet the highest standards of security. Lead the most complex security assessments, including threat modeling, red teaming, and cloud security reviews. Collaborate with executive leadership to ensure that security initiatives align with the organization's strategic goals and risk appetite. Act as the technical lead for large-scale security projects, coordinating cross-functional teams to ensure successful delivery. Architect and implement solutions across workforce IAM, PAM, and customer IAM ecosystems. Provide thought leadership in adopting passwordless authentication, passkeys, adaptive MFA, and AI-driven access orchestration strategies Engineer integrations with Agentic AI tools for intelligent decisioning, policy enforcement, and autonomous identity lifecycle operations. Develop and implement automated provisioning/deprovisioning workflows Ensure integration of IAM with cloud platforms (Azure, AWS, GCP) and SaaS applications. Mentor and develop the skills of senior security engineers, fostering a culture of continuous improvement and innovation. Technical Experience Must-Have: Privileged Access management (CyberArk) Authentication/AuthN (Okta) Federated Identity (EntraID) Cloud Identity (AWS, GCP, Azure) Automation (terraform, codex, claude) Application SSO (OIDC, SAML) Identity Governance (Sailpoint, Okta, Veza) Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify.
May 21, 2026
Full time
Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures-and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive. What You'll Do The Principal IAM Engineer is the senior technical authority for identity services, responsible for designing, implementing, and governing enterprise-wide IAM capabilities across workforce, partner, and customer identities. This role combines deep hands-on engineering with architecture and leadership, driving the modernization of authentication, authorization, identity lifecycle, and privileged access controls across our cloud and on-prem environments. Responsibilities: Own the end to end technical delivery of IAM services, including identity lifecycle management, authentication, authorization, SSO, and privileged access controls, ensuring they are secure, scalable, and highly available. Lead design sessions, collaborating with Entrprise Architecture, and implementation of IAM integrations for SaaS, on prem, and AWS cloud platforms, including federation (SAML, OIDC, OAuth), MFA, and Passwordless capabilities. Serve as the primary escalation point for complex IAM engineering issues; perform root cause analysis and drive long term remediation and hardening of IAM platforms and related services. Partner with security architecture, infrastructure, application, and HR/IT teams to align IAM solutions with enterprise security strategy, compliance obligations, and business objectives. Define IAM engineering standards, patterns, and reference architectures; guide other engineers in implementing secure onboarding patterns for applications into IGA, PAM, and SSO platforms. Lead modernization initiatives. Contribute to audits, risk assessments, and regulatory reviews by providing technical evidence, designing compensating controls, and closing identified IAM control gaps. Mentor and coach IAM engineers and analysts, promoting engineering excellence, documentation discipline, and a culture of continuous learning and improvement. What You'll Bring 10+ years of experience in information security or infrastructure engineering, with at least 5 years of hands-on-keyboard experience with core IAM platforms. Deep expertise with the majority of our IAM stack Strong hands-on experience with Microsoft Entra ID and Active Directory as foundational directory services, and extensive experience implementing federation protocols (SAML, OIDC, OAuth2). Proven track record designing and implementing IAM solutions in hybrid multi-cloud environments, including the automation of provisioning, access reviews, and RBAC/ABAC models. Experience with secrets management solutions. Proficiency in at least one scripting or programming language (such as PowerShell, Python, or Java) to automate tasks and build custom connectors for our IAM tools. Excellent communication skills with the ability to translate complex technical concepts related to our IAM ecosystem for both technical and non-technical stakeholders. Exceptional sense of ownership and the ability to work with a limited set of requirements. Highly advanced ability to breakdown work to deliver value incrementally. Experience leading large-scale IAM programs. Prior responsibility as a technical lead or architect for IAM, including mentoring teams and influencing roadmaps beyond direct reporting lines. Demonstrated ability to balance security, usability, and operational efficiency, with a strong bias toward automation and measurable risk reduction. Define and lead the implementation of the organization's security strategy, with a focus on Cloud Security, Identity Access Management, and all other aspects of Cybersecurity Oversee the deployment of IAM solutions across both on-premise and cloud environments, ensuring they meet the highest standards of security. Lead the most complex security assessments, including threat modeling, red teaming, and cloud security reviews. Collaborate with executive leadership to ensure that security initiatives align with the organization's strategic goals and risk appetite. Act as the technical lead for large-scale security projects, coordinating cross-functional teams to ensure successful delivery. Architect and implement solutions across workforce IAM, PAM, and customer IAM ecosystems. Provide thought leadership in adopting passwordless authentication, passkeys, adaptive MFA, and AI-driven access orchestration strategies Engineer integrations with Agentic AI tools for intelligent decisioning, policy enforcement, and autonomous identity lifecycle operations. Develop and implement automated provisioning/deprovisioning workflows Ensure integration of IAM with cloud platforms (Azure, AWS, GCP) and SaaS applications. Mentor and develop the skills of senior security engineers, fostering a culture of continuous improvement and innovation. Technical Experience Must-Have: Privileged Access management (CyberArk) Authentication/AuthN (Okta) Federated Identity (EntraID) Cloud Identity (AWS, GCP, Azure) Automation (terraform, codex, claude) Application SSO (OIDC, SAML) Identity Governance (Sailpoint, Okta, Veza) Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify.
Robert Half Technology are assisting a market leading financial services organisation to recruit a CyberArk SME on a contract basis. Hybrid working - London based (1 day per week onsite). June 2026 start through to the end of 2026. Role The CyberArk SME will plan, test, and implement major CyberArk platform releases and upgrades, including annual version upgrades (e.g. 14.x to 15.x). Plan, test, and implement monthly operating system patching for CyberArk Vault servers in line with internal patching schedules. Test and coordinate monthly patching activities across CyberArk underlying infrastructure with internal infrastructure and patching teams. Deploy CyberArk security patches to remediate critical vulnerabilities identified in CyberArk advisories. Maintain existing CyberArk integrations including SCIM integration with Saviynt and telemetry integration with Power BI. Support and maintain existing deployed CyberArk connectors and collaborate with permanent teams to deliver configuration changes and onboarding activities. Create up to 10 custom CPM and PSM connectors annually to support new platforms and applications. Drive the adoption and embeddedness of CyberArk controls across the organisation. Utilise CyberArk Discovery, PTA, Splunk dashboards, CrowdStrike, Saviynt and other repositories to identify privileged accounts not currently under CyberArk management. Produce monthly metrics and reporting covering privileged account coverage across CMDB assets, Active Directory, and LDAP environments. Drive BAU onboarding activities to close identified gaps across existing platform types. Create detailed technical documentation including HLDs, LLDs, Safe Design documents, Runbooks, Test Plans and BAU handover documentation. Deploy and integrate CyberArk CP/CCP platforms into pre-production and production environments. Install and configure CP agents on PoC and candidate servers. Define and deploy processes for end-to-end SSH key lifecycle management including rotation. Create and manage Safes, Platforms and application authentication configurations within CyberArk. Conduct discovery and assessment activities for application service accounts, SSH keys, certificates, and secrets across production and pre-production environments. Define remediation and treatment plans for secrets management including CP/CCP adoption, PKI, mTLS and SPIFFE approaches. Deliver monitoring, hypercare, prioritisation, and remediation planning activities for secrets onboarding initiatives. Profile The CyberArk SME will have strong experience administering and engineering CyberArk PAM solutions within enterprise-scale environments. Expert-level knowledge of CyberArk components including Vault, CPM, PSM, CP, CCP, PTA and Discovery. Experience planning and delivering CyberArk upgrades, patching, and vulnerability remediation activities. Strong understanding of privileged access management, secrets management, SSH key management, and certificate-based authentication. Experience integrating CyberArk with enterprise tooling including Saviynt, Splunk, CrowdStrike, Power BI, Active Directory and LDAP. Proven experience creating custom CPM and PSM connectors. Strong knowledge of Linux and Windows server administration and infrastructure patching processes. Experience producing technical documentation including HLDs, LLDs, test plans and operational runbooks. Excellent stakeholder engagement and communication skills with the ability to collaborate across technical and business teams. CyberArk Sentry certification or above highly desirable. Company Market leading financial services organisation with offices in London Hybrid working - 1 day per week onsite Salary & Benefits The salary range/rates of pay is dependent upon your experience, qualifications or training. Robert Half Ltd acts as an employment business for temporary positions and an employment agency for permanent positions. Robert Half is committed to diversity, equity and inclusion. Suitable candidates with equivalent qualifications and more or less experience can apply. Rates of pay and salary ranges are dependent upon your experience, qualifications and training. If you wish to apply, please read our Privacy Notice describing how we may process, disclose and store your personal data:
May 21, 2026
Contractor
Robert Half Technology are assisting a market leading financial services organisation to recruit a CyberArk SME on a contract basis. Hybrid working - London based (1 day per week onsite). June 2026 start through to the end of 2026. Role The CyberArk SME will plan, test, and implement major CyberArk platform releases and upgrades, including annual version upgrades (e.g. 14.x to 15.x). Plan, test, and implement monthly operating system patching for CyberArk Vault servers in line with internal patching schedules. Test and coordinate monthly patching activities across CyberArk underlying infrastructure with internal infrastructure and patching teams. Deploy CyberArk security patches to remediate critical vulnerabilities identified in CyberArk advisories. Maintain existing CyberArk integrations including SCIM integration with Saviynt and telemetry integration with Power BI. Support and maintain existing deployed CyberArk connectors and collaborate with permanent teams to deliver configuration changes and onboarding activities. Create up to 10 custom CPM and PSM connectors annually to support new platforms and applications. Drive the adoption and embeddedness of CyberArk controls across the organisation. Utilise CyberArk Discovery, PTA, Splunk dashboards, CrowdStrike, Saviynt and other repositories to identify privileged accounts not currently under CyberArk management. Produce monthly metrics and reporting covering privileged account coverage across CMDB assets, Active Directory, and LDAP environments. Drive BAU onboarding activities to close identified gaps across existing platform types. Create detailed technical documentation including HLDs, LLDs, Safe Design documents, Runbooks, Test Plans and BAU handover documentation. Deploy and integrate CyberArk CP/CCP platforms into pre-production and production environments. Install and configure CP agents on PoC and candidate servers. Define and deploy processes for end-to-end SSH key lifecycle management including rotation. Create and manage Safes, Platforms and application authentication configurations within CyberArk. Conduct discovery and assessment activities for application service accounts, SSH keys, certificates, and secrets across production and pre-production environments. Define remediation and treatment plans for secrets management including CP/CCP adoption, PKI, mTLS and SPIFFE approaches. Deliver monitoring, hypercare, prioritisation, and remediation planning activities for secrets onboarding initiatives. Profile The CyberArk SME will have strong experience administering and engineering CyberArk PAM solutions within enterprise-scale environments. Expert-level knowledge of CyberArk components including Vault, CPM, PSM, CP, CCP, PTA and Discovery. Experience planning and delivering CyberArk upgrades, patching, and vulnerability remediation activities. Strong understanding of privileged access management, secrets management, SSH key management, and certificate-based authentication. Experience integrating CyberArk with enterprise tooling including Saviynt, Splunk, CrowdStrike, Power BI, Active Directory and LDAP. Proven experience creating custom CPM and PSM connectors. Strong knowledge of Linux and Windows server administration and infrastructure patching processes. Experience producing technical documentation including HLDs, LLDs, test plans and operational runbooks. Excellent stakeholder engagement and communication skills with the ability to collaborate across technical and business teams. CyberArk Sentry certification or above highly desirable. Company Market leading financial services organisation with offices in London Hybrid working - 1 day per week onsite Salary & Benefits The salary range/rates of pay is dependent upon your experience, qualifications or training. Robert Half Ltd acts as an employment business for temporary positions and an employment agency for permanent positions. Robert Half is committed to diversity, equity and inclusion. Suitable candidates with equivalent qualifications and more or less experience can apply. Rates of pay and salary ranges are dependent upon your experience, qualifications and training. If you wish to apply, please read our Privacy Notice describing how we may process, disclose and store your personal data:
Senior Security Engineer, reporting to the IT Security Officer, you will work as part of a 3-person IT Security team. As the Senior Security Engineer, you should have at least 5 years security team leadership and project management. You will implement and maintain robust security systems and protocols across the IT infrastructure. You will conduct risk assessments and vulnerability scans, mitigate vulnerabilities identified in penetration testing, and implement preventative measures to protect against cyber threats. You will monitor the security infrastructure and detect and respond to potential threats. You will mentor and develop the IT security engineer and collaborate with the IT team to ensure compliance with security standards and best practices; you will essentially be a key technical leader in safeguarding sensitive data and systems. Key Responsibilities/Duties Manage the Secure Web Gateway Manage the Email Security Gateway Carry out vulnerability scans, identify risks, and remediation. Manage the perimeter and VPN firewalls. Manage MFA and SSO. Manage MDM\MAM and Conditional Access Manage security certificates and keys. Deliver Cyber Security Awareness Training Remediate vulnerabilities and weaknesses identified during penetration testing.Experience - EssentialThe successful candidate will have a good working knowledge and experience in managing the majority of the following technology stack CrowdStrike EDR Mimecast Mail Security Gateway Duo Okta Rapid7 IVM, Tenable IO or Nessus Palo Alto Firewalls and Panorama InTune and Conditional Access Entra ID, Purview, Defender, Active Directory, DNS, GPOExperience - DesiredExperience using the following technology stack would be advantageous; understanding the principles is required. Cisco Secure Access Cisco Umbrella Cisco ASA Digicert Certificates and Microsoft Certificate Services Ivanti patching Kali Linux (NMAP, Metasploit, BurpSuite, John etc) Microsoft Purview Candidate Profile Desired Education: CISM, CISSP, OSCP or other penetration testing qualifications. Industry: Financial services, SOC, Pentesting is desirable Personal Skills: Excellent inter-personal, written and verbal communication skills The ability to handle multiple priorities, tasks and projects simultaneously Clear and precise verbal and written communication Ability to deliver presentations to staff Cross functional influence, engagement and collaboration skills Location and Hours The position is usually based in our London Head Office, which is currently located in High Holborn. Hours: The team works on a shift pattern to ensure cover from : (0730 to 1630 (2 days working from home), and 0830 to 1730 (3 days working in the office There will be periods of the weekend and out-of-hours work.
May 21, 2026
Full time
Senior Security Engineer, reporting to the IT Security Officer, you will work as part of a 3-person IT Security team. As the Senior Security Engineer, you should have at least 5 years security team leadership and project management. You will implement and maintain robust security systems and protocols across the IT infrastructure. You will conduct risk assessments and vulnerability scans, mitigate vulnerabilities identified in penetration testing, and implement preventative measures to protect against cyber threats. You will monitor the security infrastructure and detect and respond to potential threats. You will mentor and develop the IT security engineer and collaborate with the IT team to ensure compliance with security standards and best practices; you will essentially be a key technical leader in safeguarding sensitive data and systems. Key Responsibilities/Duties Manage the Secure Web Gateway Manage the Email Security Gateway Carry out vulnerability scans, identify risks, and remediation. Manage the perimeter and VPN firewalls. Manage MFA and SSO. Manage MDM\MAM and Conditional Access Manage security certificates and keys. Deliver Cyber Security Awareness Training Remediate vulnerabilities and weaknesses identified during penetration testing.Experience - EssentialThe successful candidate will have a good working knowledge and experience in managing the majority of the following technology stack CrowdStrike EDR Mimecast Mail Security Gateway Duo Okta Rapid7 IVM, Tenable IO or Nessus Palo Alto Firewalls and Panorama InTune and Conditional Access Entra ID, Purview, Defender, Active Directory, DNS, GPOExperience - DesiredExperience using the following technology stack would be advantageous; understanding the principles is required. Cisco Secure Access Cisco Umbrella Cisco ASA Digicert Certificates and Microsoft Certificate Services Ivanti patching Kali Linux (NMAP, Metasploit, BurpSuite, John etc) Microsoft Purview Candidate Profile Desired Education: CISM, CISSP, OSCP or other penetration testing qualifications. Industry: Financial services, SOC, Pentesting is desirable Personal Skills: Excellent inter-personal, written and verbal communication skills The ability to handle multiple priorities, tasks and projects simultaneously Clear and precise verbal and written communication Ability to deliver presentations to staff Cross functional influence, engagement and collaboration skills Location and Hours The position is usually based in our London Head Office, which is currently located in High Holborn. Hours: The team works on a shift pattern to ensure cover from : (0730 to 1630 (2 days working from home), and 0830 to 1730 (3 days working in the office There will be periods of the weekend and out-of-hours work.
Cyber Security Specialist 12-month contract£500-550 per dayOutside IR35 Hybrid - Edinburgh (1-2 days per week onsite) We are currently recruiting for an experienced Cyber Security Specialist to join a busy digital transformation environment on a 12-month contract. This role will play a key part in ensuring robust cyber security practices are embedded across new and evolving digital services. Working as part of a dedicated cyber security function, you will provide specialist advice and guidance across the full service lifecycle, supporting projects from initial scoping through to go-live and ongoing operational readiness. Key responsibilities: Provide cyber security advice and guidance to digital and transformation projects throughout their lifecycle. Support early-stage scoping and risk assessment activities for new and evolving services. Interpret security policies, standards, and accreditation requirements to define appropriate controls. Conduct threat modelling and risk assessments to identify and mitigate vulnerabilities. Review solution architecture and detailed designs to ensure alignment with security requirements. Maintain and document security design assessments for new services. Carry out hands-on security checks (e.g. configuration reviews), and coordinate independent penetration testing. Provide recommendations to support stage gate reviews and go-live decisions. Own and manage all security-related delivery evidence required for project assurance. Contribute to the development of secure operational processes, including SecOps practices and automation. Key requirements: Strong experience in cyber security and risk assessment within enterprise-scale digital environments. Proven track record of contributing to the secure delivery of new digital services. Good understanding of current cyber threat landscape, security standards, and best practice. Experience working within agile delivery teams alongside internal stakeholders and third-party suppliers. Ability to take ownership of security deliverables and drive them through to completion. Strong communication skills, with the ability to translate technical risks and controls to non-technical stakeholders. Technical experience across: Enterprise security tooling such as email filtering, antivirus, firewalls, WAF, and Microsoft Defender Security testing approaches including SAST and DAST Enterprise platforms including Active Directory, PKI, SCCM, Microsoft 365, and Azure (including Entra and Intune) Virtualisation and operating systems, including Windows Server and Hyper-V Cloud environments, particularly Microsoft Azure Application platforms such as Microsoft Dynamics and Power Platform Desirable experience: Experience working with Azure, Microsoft Dynamics, and Power Platform environments Experience managing external penetration testing activities Relevant certifications (e.g. MCSE, ITIL) or equivalent experience This is an excellent opportunity to join a high-profile programme, contributing to secure and resilient service delivery within a complex and evolving environment. For more information or to express interest, please get in touch. This role requires someone onsite 1-2 days per week in the Edinburgh office. Guidant, Carbon60, Lorien & SRG - The Impellam Group Portfolio are acting as an Employment Business in relation to this vacancy.
May 20, 2026
Contractor
Cyber Security Specialist 12-month contract£500-550 per dayOutside IR35 Hybrid - Edinburgh (1-2 days per week onsite) We are currently recruiting for an experienced Cyber Security Specialist to join a busy digital transformation environment on a 12-month contract. This role will play a key part in ensuring robust cyber security practices are embedded across new and evolving digital services. Working as part of a dedicated cyber security function, you will provide specialist advice and guidance across the full service lifecycle, supporting projects from initial scoping through to go-live and ongoing operational readiness. Key responsibilities: Provide cyber security advice and guidance to digital and transformation projects throughout their lifecycle. Support early-stage scoping and risk assessment activities for new and evolving services. Interpret security policies, standards, and accreditation requirements to define appropriate controls. Conduct threat modelling and risk assessments to identify and mitigate vulnerabilities. Review solution architecture and detailed designs to ensure alignment with security requirements. Maintain and document security design assessments for new services. Carry out hands-on security checks (e.g. configuration reviews), and coordinate independent penetration testing. Provide recommendations to support stage gate reviews and go-live decisions. Own and manage all security-related delivery evidence required for project assurance. Contribute to the development of secure operational processes, including SecOps practices and automation. Key requirements: Strong experience in cyber security and risk assessment within enterprise-scale digital environments. Proven track record of contributing to the secure delivery of new digital services. Good understanding of current cyber threat landscape, security standards, and best practice. Experience working within agile delivery teams alongside internal stakeholders and third-party suppliers. Ability to take ownership of security deliverables and drive them through to completion. Strong communication skills, with the ability to translate technical risks and controls to non-technical stakeholders. Technical experience across: Enterprise security tooling such as email filtering, antivirus, firewalls, WAF, and Microsoft Defender Security testing approaches including SAST and DAST Enterprise platforms including Active Directory, PKI, SCCM, Microsoft 365, and Azure (including Entra and Intune) Virtualisation and operating systems, including Windows Server and Hyper-V Cloud environments, particularly Microsoft Azure Application platforms such as Microsoft Dynamics and Power Platform Desirable experience: Experience working with Azure, Microsoft Dynamics, and Power Platform environments Experience managing external penetration testing activities Relevant certifications (e.g. MCSE, ITIL) or equivalent experience This is an excellent opportunity to join a high-profile programme, contributing to secure and resilient service delivery within a complex and evolving environment. For more information or to express interest, please get in touch. This role requires someone onsite 1-2 days per week in the Edinburgh office. Guidant, Carbon60, Lorien & SRG - The Impellam Group Portfolio are acting as an Employment Business in relation to this vacancy.
A Senior Cloud Security Engineer is required to join an industry leading organisation in the energy sector, a genuinely global business with operations spanning multiple continents, thousands of employees. This is a permanent, full-time role that is based in Aberdeen (hybrid but can be slightly flexible on location) The opportunity This is a great chance to join a well-established IT Security team at a point where there's real work to be done. With a broad cloud estate spanning IaaS, PaaS, and SaaS, including a significant Azure and M365 footprint, cloud security here isn't a tick-box exercise. You'll have genuine scope to shape the direction of travel, the support of a capable team and managed service partners, and the backing of senior leadership who take security seriously. What you'll be doing You'll design and deploy cloud security solutions across the organisation's IaaS, PaaS, and SaaS estate, while helping develop and maintain security policies and procedures. Day to day this means conducting assessments and audits, identifying risks, maintaining security controls within Azure Active Directory and Microsoft 365, and playing an active role in incident response, including post-incident reviews and proposing engineering improvements. You'll also support cloud security tooling and platforms, contribute to change management forums, and help mentor colleagues across the wider IT function, all while keeping a close eye on the evolving threat landscape and bringing proactive recommendations to the team. You'll ideally have most of the following Extensive experience with cloud technologies, with Microsoft Azure being the priority A solid background in delivering Information Security in a modern digital environment Experience with Microsoft 365, Azure Active Directory, and ideally Microsoft Purview Scripting capability in PowerShell Familiarity with frameworks including NIST CSF, ISO27001, and GDPR Security certifications such as CISSP or CISM (advantageous) Azure certifications such as AZ-500 or SC-300 (advantageous) Don't worry if you don't tick every single box. If you have a strong security engineering background and genuine cloud experience, it's definitely worth a conversation. Why this role? The company is at an interesting point in its cloud security maturity. There's real work to be done, real problems to solve, and real scope to shape policy, tooling, and ways of working for the long term. This isn't a role where you'll be maintaining the status quo; you'll be actively contributing to how cloud security evolves across a major global organisation. What's on offer A competitive salary , strong benefits package , and hybrid working in Aberdeen (4 days in office - possibly some flexibility on location ). The chance to work in a senior, visible security engineering role within a business operating at real scale, and the opportunity to leave your mark on the cloud security strategy of a globally recognised organisation. If this sounds like the kind of role you've been looking for, please apply or get in touch with Matt MacAlpine at Cathcart Technology. Cathcart Technology is acting as an Employment Agency in relation to this vacancy.
May 20, 2026
Full time
A Senior Cloud Security Engineer is required to join an industry leading organisation in the energy sector, a genuinely global business with operations spanning multiple continents, thousands of employees. This is a permanent, full-time role that is based in Aberdeen (hybrid but can be slightly flexible on location) The opportunity This is a great chance to join a well-established IT Security team at a point where there's real work to be done. With a broad cloud estate spanning IaaS, PaaS, and SaaS, including a significant Azure and M365 footprint, cloud security here isn't a tick-box exercise. You'll have genuine scope to shape the direction of travel, the support of a capable team and managed service partners, and the backing of senior leadership who take security seriously. What you'll be doing You'll design and deploy cloud security solutions across the organisation's IaaS, PaaS, and SaaS estate, while helping develop and maintain security policies and procedures. Day to day this means conducting assessments and audits, identifying risks, maintaining security controls within Azure Active Directory and Microsoft 365, and playing an active role in incident response, including post-incident reviews and proposing engineering improvements. You'll also support cloud security tooling and platforms, contribute to change management forums, and help mentor colleagues across the wider IT function, all while keeping a close eye on the evolving threat landscape and bringing proactive recommendations to the team. You'll ideally have most of the following Extensive experience with cloud technologies, with Microsoft Azure being the priority A solid background in delivering Information Security in a modern digital environment Experience with Microsoft 365, Azure Active Directory, and ideally Microsoft Purview Scripting capability in PowerShell Familiarity with frameworks including NIST CSF, ISO27001, and GDPR Security certifications such as CISSP or CISM (advantageous) Azure certifications such as AZ-500 or SC-300 (advantageous) Don't worry if you don't tick every single box. If you have a strong security engineering background and genuine cloud experience, it's definitely worth a conversation. Why this role? The company is at an interesting point in its cloud security maturity. There's real work to be done, real problems to solve, and real scope to shape policy, tooling, and ways of working for the long term. This isn't a role where you'll be maintaining the status quo; you'll be actively contributing to how cloud security evolves across a major global organisation. What's on offer A competitive salary , strong benefits package , and hybrid working in Aberdeen (4 days in office - possibly some flexibility on location ). The chance to work in a senior, visible security engineering role within a business operating at real scale, and the opportunity to leave your mark on the cloud security strategy of a globally recognised organisation. If this sounds like the kind of role you've been looking for, please apply or get in touch with Matt MacAlpine at Cathcart Technology. Cathcart Technology is acting as an Employment Agency in relation to this vacancy.
Systems Consultant (3rd Line / Infrastructure) - Hybrid Working - £55,000! Role : Systems Consultant Location : London (Hybrid - 3 days onsite / 2 days remote) Salary : £45,000 - £50,000 (DOE) A highly respected London-based Managed Service Provider is looking for a Systems Consultant / 3rd Line Infrastructure Engineer to join their growing Infrastructure Services team. This role is ideal for an experienced 2nd or 3rd Line Engineer within an MSP who wants to move into a more consultative, customer-facing infrastructure position, working with modern cloud-first and security-led environments. You'll play a key role in supporting and improving client infrastructure while developing deeper expertise across Microsoft cloud, security, and enterprise infrastructure technologies. The Role As a Systems Consultant, you'll operate as a senior escalation point within the infrastructure team, supporting complex technical environments across multiple clients. You'll work closely with Service Desk, Professional Services, and Account Management teams to ensure the stability, security, and scalability of client IT environments. This position also offers the opportunity to develop into a technical authority or future infrastructure architect within a fast-growing MSP. Key Responsibilities Act as a 3rd line escalation point for complex infrastructure incidentsTroubleshoot and resolve business-critical technical issues, including root cause analysisSupport and contribute to major incident management and post-incident reviewsDeliver proactive infrastructure improvements, including monitoring, patching, and optimisationProvide technical oversight for changes, upgrades, and infrastructure improvementsContribute to automation, platform standardisation, and service improvementsSupport security posture, backup, business continuity, and disaster recovery solutionsDevelop into a Subject Matter Expert (SME) for key technologies and vendor platformsProvide mentorship and guidance to 1st and 2nd Line engineersMaintain clear technical documentation and communicate effectively with customersOccasional client site visits may be required for workshops, escalations, or technical meetings. Technical Environment You'll be working across modern cloud and infrastructure technologies, including:Microsoft 365Microsoft Azure (IaaS, identity, networking, security)Windows ServerActive Directory / Entra IDGroup PolicyVirtualisation (VMware / Hyper-V)Advanced networking (VPNs, routing, switching, firewalls)Backup & disaster recovery platformsAutomation & scriptingCyber security technologies and controls Experience Required 2-3+ years in a 2nd / 3rd Line or Infrastructure roleExperience working within an MSP or multi-client IT environmentStrong troubleshooting and root cause analysis skillsComfortable supporting complex infrastructure environmentsExperience across Microsoft cloud and on-prem infrastructure Desirable Skills Microsoft certifications (e.g. Azure Administrator - AZ-104)Experience with Microsoft 365 administration and identity servicesExposure to AWS or Google CloudExperience with RMM and PSA toolsKnowledge of backup platforms (e.g. Veeam, Datto)Exposure to SIEM / SOC toolsUnderstanding of AI tools such as Microsoft 365 CopilotLinux administration experience The client is looking to fill this opportunity immediately, so please apply ASAP or feel free to drop me an email with any questions to . com. SER-IN
May 20, 2026
Full time
Systems Consultant (3rd Line / Infrastructure) - Hybrid Working - £55,000! Role : Systems Consultant Location : London (Hybrid - 3 days onsite / 2 days remote) Salary : £45,000 - £50,000 (DOE) A highly respected London-based Managed Service Provider is looking for a Systems Consultant / 3rd Line Infrastructure Engineer to join their growing Infrastructure Services team. This role is ideal for an experienced 2nd or 3rd Line Engineer within an MSP who wants to move into a more consultative, customer-facing infrastructure position, working with modern cloud-first and security-led environments. You'll play a key role in supporting and improving client infrastructure while developing deeper expertise across Microsoft cloud, security, and enterprise infrastructure technologies. The Role As a Systems Consultant, you'll operate as a senior escalation point within the infrastructure team, supporting complex technical environments across multiple clients. You'll work closely with Service Desk, Professional Services, and Account Management teams to ensure the stability, security, and scalability of client IT environments. This position also offers the opportunity to develop into a technical authority or future infrastructure architect within a fast-growing MSP. Key Responsibilities Act as a 3rd line escalation point for complex infrastructure incidentsTroubleshoot and resolve business-critical technical issues, including root cause analysisSupport and contribute to major incident management and post-incident reviewsDeliver proactive infrastructure improvements, including monitoring, patching, and optimisationProvide technical oversight for changes, upgrades, and infrastructure improvementsContribute to automation, platform standardisation, and service improvementsSupport security posture, backup, business continuity, and disaster recovery solutionsDevelop into a Subject Matter Expert (SME) for key technologies and vendor platformsProvide mentorship and guidance to 1st and 2nd Line engineersMaintain clear technical documentation and communicate effectively with customersOccasional client site visits may be required for workshops, escalations, or technical meetings. Technical Environment You'll be working across modern cloud and infrastructure technologies, including:Microsoft 365Microsoft Azure (IaaS, identity, networking, security)Windows ServerActive Directory / Entra IDGroup PolicyVirtualisation (VMware / Hyper-V)Advanced networking (VPNs, routing, switching, firewalls)Backup & disaster recovery platformsAutomation & scriptingCyber security technologies and controls Experience Required 2-3+ years in a 2nd / 3rd Line or Infrastructure roleExperience working within an MSP or multi-client IT environmentStrong troubleshooting and root cause analysis skillsComfortable supporting complex infrastructure environmentsExperience across Microsoft cloud and on-prem infrastructure Desirable Skills Microsoft certifications (e.g. Azure Administrator - AZ-104)Experience with Microsoft 365 administration and identity servicesExposure to AWS or Google CloudExperience with RMM and PSA toolsKnowledge of backup platforms (e.g. Veeam, Datto)Exposure to SIEM / SOC toolsUnderstanding of AI tools such as Microsoft 365 CopilotLinux administration experience The client is looking to fill this opportunity immediately, so please apply ASAP or feel free to drop me an email with any questions to . com. SER-IN
CREST Certified Penetration Tester (CRT) £50-60k Remote We're partnered with a well-established cyber security organisation that's continuing to invest heavily into its offensive security capability following sustained client growth across both commercial and regulated environments. As part of that growth, they're looking to hire a CREST-certified Penetration Tester to join a collaborative testing team delivering security assessments across a broad range of technologies and customer environments. This role would suit someone with around 2-3 years of hands-on penetration testing experience who is looking to continue developing within a highly technical and supportive environment. Salary: £50-60k DOE Working Structure: Remote with onsite client visits occasionally Security Clearance: Beneficial but not required (SC/DV) Certifications: CREST CRT, OSCP (Essential) The Role: You'll be involved in delivering: Web application penetration testing Infrastructure and internal network testing External vulnerability assessments Active Directory and privilege escalation testing Cloud security assessments across Azure/AWS Security reporting and remediation discussions with clients You'll work closely with senior testers and technical leads, gaining exposure to a wide variety of technologies, environments and engagement types. What They're Looking For: CREST Registered Tester (CRT) certification essential OSCP Certification Around 2-3 years of penetration testing experience Strong understanding of web application and infrastructure testing methodologies Experience with tools such as Burp Suite, Nmap, Nessus, Metasploit, etc. Understanding of OWASP Top 10 and common attack vectors Strong report writing and communication skills Consultancy/client-facing experience beneficial Additional certifications such as CPSA or cloud security certifications would be advantageous. If you're a CRT-certified Penetration Tester looking to continue developing your offensive security career within a strong technical environment, please apply or reach out for a confidential conversation. Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy. To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.
May 19, 2026
Full time
CREST Certified Penetration Tester (CRT) £50-60k Remote We're partnered with a well-established cyber security organisation that's continuing to invest heavily into its offensive security capability following sustained client growth across both commercial and regulated environments. As part of that growth, they're looking to hire a CREST-certified Penetration Tester to join a collaborative testing team delivering security assessments across a broad range of technologies and customer environments. This role would suit someone with around 2-3 years of hands-on penetration testing experience who is looking to continue developing within a highly technical and supportive environment. Salary: £50-60k DOE Working Structure: Remote with onsite client visits occasionally Security Clearance: Beneficial but not required (SC/DV) Certifications: CREST CRT, OSCP (Essential) The Role: You'll be involved in delivering: Web application penetration testing Infrastructure and internal network testing External vulnerability assessments Active Directory and privilege escalation testing Cloud security assessments across Azure/AWS Security reporting and remediation discussions with clients You'll work closely with senior testers and technical leads, gaining exposure to a wide variety of technologies, environments and engagement types. What They're Looking For: CREST Registered Tester (CRT) certification essential OSCP Certification Around 2-3 years of penetration testing experience Strong understanding of web application and infrastructure testing methodologies Experience with tools such as Burp Suite, Nmap, Nessus, Metasploit, etc. Understanding of OWASP Top 10 and common attack vectors Strong report writing and communication skills Consultancy/client-facing experience beneficial Additional certifications such as CPSA or cloud security certifications would be advantageous. If you're a CRT-certified Penetration Tester looking to continue developing your offensive security career within a strong technical environment, please apply or reach out for a confidential conversation. Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy. To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.
The Role at a Glance: Senior IT Support Engineer Windsor or East Berkshire Based + Travel Across Berkshire, Hampshire, Surrey & West London £38,000 - £40,000 Plus Benefits inc. 20 days holiday + Public Holidays + Birthday Off, Pension Scheme, Generous Mileage Allowance About Us Active IT is a growing IT consultancy providing managed services and project delivery to SMEs and preparatory schools across the South East. We pride ourselves on a flexible, bespoke approach, working closely with each client to design and deliver the right technical solution for their business. With over twenty years of experience behind us, we combine the responsiveness of a small team with the depth of a mature consultancy. The Opportunity We are looking for an experienced and motivated Senior IT Support Engineer to join our technical delivery team. You will represent Active IT on site at client locations across Berkshire, Hampshire, Surrey and West London, as well as supporting in house and remote project work from our Windsor head office. This is a varied role that will suit someone who enjoys problem solving, building relationships with clients, and working across a broad range of modern technologies. You will be exposed to everything from day to day support and infrastructure projects through to cyber security, cloud migrations and network deployments. What We Are Looking For You will need to demonstrate strong technical ability alongside excellent communication and customer service skills. The ideal candidate will be based in or around East Berkshire. A full UK driving licence and your own transport are essential, as you will be travelling to client sites regularly. A generous mileage allowance is paid for all business travel. All successful candidates will be required to pass an Enhanced DBS check. We are looking for someone with at least five years of customer facing experience and a minimum of two years in a commercial IT support or projects role. A degree or relevant technical qualification is preferred, and recent Microsoft certifications will be highly regarded. Required Technical Skills • Windows Server and 2025 • Microsoft 365 advanced administration, including Exchange Online, SharePoint and Teams • Mobile device management, including Microsoft Intune and Endpoint Manager • Microsoft Entra ID (formerly Azure AD), Conditional Access and MFA • Active Directory, Group Policy and hybrid identity • Hyper V and VMware virtualisation • Windows, macOS and iPadOS desktop and device support • DNS and DHCP • Networking fundamentals: firewalls, routing, NAT, VLANs and switching • Wi Fi technologies, including UniFi or equivalent enterprise platforms • Firewall management, ideally SonicWall or similar • VPN technologies, including SSL and site to site • PC and laptop hardware diagnostics and build Desirable Skills • Jamf Pro or Jamf School for Apple device management • Microsoft Azure infrastructure and administration • Apple Business Manager and Apple School Manager • Google Workspace and Chrome device management • DNS filtering platforms such as DNSFilter or Cisco Umbrella • Backup and disaster recovery solutions, including Datto, Veeam or Microsoft 365 backup • Cyber Essentials and Cyber Essentials Plus experience • Safeguarding technologies used in education, such as Senso or Classroom Cloud • VoIP and cloud telephony platforms Qualifications Any of the following would be an advantage: • Degree level IT qualification or equivalent demonstrable industry experience • Microsoft 365 Certified: Modern Desktop Administrator, Endpoint Administrator or Identity and Access Administrator • Microsoft Azure Fundamentals (AZ 900) or Administrator (AZ 104) • Jamf Certified Associate or Jamf Certified Tech • CompTIA Network+ or Security+ General Requirements • Two or more years in a client facing, hands on technical role • Excellent verbal and written communication skills • Positive, can do attitude with the confidence to engage stakeholders at all levels • Genuine passion for IT and technology • Five or more GCSEs including English • Smart, professional appearance The Package • £38,000 to £40,000 per annum, depending on experience • Contributory pension scheme • Generous mileage allowance for business travel • 20 days annual leave plus UK public holidays • Your birthday off as an additional day of leave • Ongoing training and certification support • Friendly, collaborative team environment Apply today and be part of a team using technology to drive real-world sustainability impact. Application notice We take your privacy seriously. As you might expect you may be contacted by email, text or telephone. Your data is processed by our talent partner RR (Recruitment Revolution) on the basis of their legitimate interests in fulfilling the recruitment process. Please refer to their Data Privacy Policy & Notice on their website for further details.
May 18, 2026
Full time
The Role at a Glance: Senior IT Support Engineer Windsor or East Berkshire Based + Travel Across Berkshire, Hampshire, Surrey & West London £38,000 - £40,000 Plus Benefits inc. 20 days holiday + Public Holidays + Birthday Off, Pension Scheme, Generous Mileage Allowance About Us Active IT is a growing IT consultancy providing managed services and project delivery to SMEs and preparatory schools across the South East. We pride ourselves on a flexible, bespoke approach, working closely with each client to design and deliver the right technical solution for their business. With over twenty years of experience behind us, we combine the responsiveness of a small team with the depth of a mature consultancy. The Opportunity We are looking for an experienced and motivated Senior IT Support Engineer to join our technical delivery team. You will represent Active IT on site at client locations across Berkshire, Hampshire, Surrey and West London, as well as supporting in house and remote project work from our Windsor head office. This is a varied role that will suit someone who enjoys problem solving, building relationships with clients, and working across a broad range of modern technologies. You will be exposed to everything from day to day support and infrastructure projects through to cyber security, cloud migrations and network deployments. What We Are Looking For You will need to demonstrate strong technical ability alongside excellent communication and customer service skills. The ideal candidate will be based in or around East Berkshire. A full UK driving licence and your own transport are essential, as you will be travelling to client sites regularly. A generous mileage allowance is paid for all business travel. All successful candidates will be required to pass an Enhanced DBS check. We are looking for someone with at least five years of customer facing experience and a minimum of two years in a commercial IT support or projects role. A degree or relevant technical qualification is preferred, and recent Microsoft certifications will be highly regarded. Required Technical Skills • Windows Server and 2025 • Microsoft 365 advanced administration, including Exchange Online, SharePoint and Teams • Mobile device management, including Microsoft Intune and Endpoint Manager • Microsoft Entra ID (formerly Azure AD), Conditional Access and MFA • Active Directory, Group Policy and hybrid identity • Hyper V and VMware virtualisation • Windows, macOS and iPadOS desktop and device support • DNS and DHCP • Networking fundamentals: firewalls, routing, NAT, VLANs and switching • Wi Fi technologies, including UniFi or equivalent enterprise platforms • Firewall management, ideally SonicWall or similar • VPN technologies, including SSL and site to site • PC and laptop hardware diagnostics and build Desirable Skills • Jamf Pro or Jamf School for Apple device management • Microsoft Azure infrastructure and administration • Apple Business Manager and Apple School Manager • Google Workspace and Chrome device management • DNS filtering platforms such as DNSFilter or Cisco Umbrella • Backup and disaster recovery solutions, including Datto, Veeam or Microsoft 365 backup • Cyber Essentials and Cyber Essentials Plus experience • Safeguarding technologies used in education, such as Senso or Classroom Cloud • VoIP and cloud telephony platforms Qualifications Any of the following would be an advantage: • Degree level IT qualification or equivalent demonstrable industry experience • Microsoft 365 Certified: Modern Desktop Administrator, Endpoint Administrator or Identity and Access Administrator • Microsoft Azure Fundamentals (AZ 900) or Administrator (AZ 104) • Jamf Certified Associate or Jamf Certified Tech • CompTIA Network+ or Security+ General Requirements • Two or more years in a client facing, hands on technical role • Excellent verbal and written communication skills • Positive, can do attitude with the confidence to engage stakeholders at all levels • Genuine passion for IT and technology • Five or more GCSEs including English • Smart, professional appearance The Package • £38,000 to £40,000 per annum, depending on experience • Contributory pension scheme • Generous mileage allowance for business travel • 20 days annual leave plus UK public holidays • Your birthday off as an additional day of leave • Ongoing training and certification support • Friendly, collaborative team environment Apply today and be part of a team using technology to drive real-world sustainability impact. Application notice We take your privacy seriously. As you might expect you may be contacted by email, text or telephone. Your data is processed by our talent partner RR (Recruitment Revolution) on the basis of their legitimate interests in fulfilling the recruitment process. Please refer to their Data Privacy Policy & Notice on their website for further details.
CHECK Team Leader Penetration Tester Security Cleared £80-90k Remote We're working with a leading cyber security consultancy looking to grow their penetration testing capability with the addition of a CHECK Team Leader (CTL) This is an opportunity to join one of the UK's largest CHECK-accredited, security-cleared testing environments, delivering high-impact testing across complex and highly secure customer estates. The role is primarily remote, with occasional onsite client engagements as required. Salary: £80-90,000 DOE Work Structure: Remote (with UK client visits) Security Clearance: Active or previously held DV clearance is essential. The Role: You'll be responsible for delivering high-quality penetration testing across a range of environments, while acting as a senior technical presence within the team. Engagements will include: Infrastructure penetration testing Web application testing Internal and external network testing Active Directory / privilege escalation assessments Cloud security testing Red team style activities and security assessments CHECK-based testing within highly secure environments You'll also be involved in scoping engagements, supporting clients through remediation discussions, and contributing to the continued growth and quality of the testing practice. What We're Looking For: Current CHECK Team Leader (CTL) certification Active DV clearance OR previously held DV clearance Strong hands-on penetration testing experience across infrastructure and applications Experience delivering testing within secure/government or high-assurance environments Strong client-facing communication skills Ability to write high-quality technical reports and communicate risk clearly Background working within a consultancy or dedicated security testing environment preferred Additional certifications such as CRT/CCT, OSCP, OSCE or similar are highly advantageous. If this sounds like you, apply now for immediate consideration. Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy. To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.
May 18, 2026
Full time
CHECK Team Leader Penetration Tester Security Cleared £80-90k Remote We're working with a leading cyber security consultancy looking to grow their penetration testing capability with the addition of a CHECK Team Leader (CTL) This is an opportunity to join one of the UK's largest CHECK-accredited, security-cleared testing environments, delivering high-impact testing across complex and highly secure customer estates. The role is primarily remote, with occasional onsite client engagements as required. Salary: £80-90,000 DOE Work Structure: Remote (with UK client visits) Security Clearance: Active or previously held DV clearance is essential. The Role: You'll be responsible for delivering high-quality penetration testing across a range of environments, while acting as a senior technical presence within the team. Engagements will include: Infrastructure penetration testing Web application testing Internal and external network testing Active Directory / privilege escalation assessments Cloud security testing Red team style activities and security assessments CHECK-based testing within highly secure environments You'll also be involved in scoping engagements, supporting clients through remediation discussions, and contributing to the continued growth and quality of the testing practice. What We're Looking For: Current CHECK Team Leader (CTL) certification Active DV clearance OR previously held DV clearance Strong hands-on penetration testing experience across infrastructure and applications Experience delivering testing within secure/government or high-assurance environments Strong client-facing communication skills Ability to write high-quality technical reports and communicate risk clearly Background working within a consultancy or dedicated security testing environment preferred Additional certifications such as CRT/CCT, OSCP, OSCE or similar are highly advantageous. If this sounds like you, apply now for immediate consideration. Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy. To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.
MERITUS are recruiting for a Security Architect to join our client supporting critical Central Government and Defence programmes, delivering secure, resilient, and high-quality architecture solutions across complex enterprise and cloud environments. SECURITY ARCHITECT - 10 MONTH CONTRACT - £900 PER DAY (OUTSIDE IR35) - ANDOVER - SC CLEARANCE REQUIRED As a Security Architect, you will play a key role in designing and assuring secure technology solutions across large-scale programmes within highly regulated environments. You will work closely with engineering, architecture, delivery, and client teams to ensure security is embedded throughout the full solution lifecycle, applying secure-by-design principles and modern cyber security best practice. This is an excellent opportunity for an experienced Security Architect with expertise across enterprise security architecture, cloud security, DevSecOps, secure software development, and risk management within government or defence sectors. Key Responsibilities: Lead security architecture activities across complex projects and programmes within Central Government and Defence environments. Design and assure secure enterprise, cloud, hybrid, and on-premises architectures aligned to business and technical requirements. Collaborate with multidisciplinary teams to ensure security considerations are embedded across the entire delivery lifecycle. Conduct security threat modelling, risk assessments, and security architecture reviews for critical systems and services. Develop and maintain security reference architectures, standards, principles, and best practices. Support IT Health Checks (ITHC), penetration testing exercises, and remediation activities. Provide technical security leadership and governance across development, integration, and delivery teams. Work with customers, stakeholders, and accreditors to define security requirements and advise on risk mitigation strategies. Ensure adherence to security frameworks, regulatory requirements, and industry standards including GDPR, OWASP, and NCSC principles. Support the design and implementation of DevSecOps pipelines, secure CI/CD processes, and automated security tooling. Contribute to enterprise security strategy, architecture governance, and continuous improvement initiatives. Support business development activities including bids, proposals, pre-sales engagements, and client demonstrations. Identify emerging cyber security trends, technologies, vulnerabilities, and assess their relevance to customer solutions. Provide mentoring, leadership, and guidance to junior architects and engineering teams. Communicate complex security concepts effectively to both technical and non-technical stakeholders. Skills & Experience: Proven experience working as a Security Architect within Central Government, Defence, or highly regulated environments. Strong understanding of enterprise security architecture principles, methodologies, and frameworks. Hands-on experience performing threat modelling, security risk assessments, and secure solution assurance. Experience designing secure cloud and hybrid architectures using Microsoft Azure and/or AWS. Strong understanding of DevSecOps, CI/CD security, and secure software development lifecycle (SSDLC) practices. Knowledge of secure architecture patterns, secure web application development, and API security. Experience implementing and governing security controls aligned to OWASP, NCSC Cloud Security Principles, and GDPR. Strong understanding of authentication and authorisation technologies including SAML, OAuth2, OpenID Connect, Active Directory, ADFS, and LDAP. Experience supporting penetration testing, vulnerability remediation, and IT Health Check activities. Experience working with multidisciplinary Agile delivery teams across complex technical programmes. Ability to engage with senior stakeholders and communicate security risks and architectural decisions clearly. Strong understanding of enterprise integration, infrastructure, and data security principles. Got your attention? If you believe that you have the skills and experience for this Security Architect opportunity, then please get in touch. We also offer a referral scheme for any candidates whose details are passed to us that we successfully place. For further information, please contact the MERITUS team today.
May 17, 2026
Contractor
MERITUS are recruiting for a Security Architect to join our client supporting critical Central Government and Defence programmes, delivering secure, resilient, and high-quality architecture solutions across complex enterprise and cloud environments. SECURITY ARCHITECT - 10 MONTH CONTRACT - £900 PER DAY (OUTSIDE IR35) - ANDOVER - SC CLEARANCE REQUIRED As a Security Architect, you will play a key role in designing and assuring secure technology solutions across large-scale programmes within highly regulated environments. You will work closely with engineering, architecture, delivery, and client teams to ensure security is embedded throughout the full solution lifecycle, applying secure-by-design principles and modern cyber security best practice. This is an excellent opportunity for an experienced Security Architect with expertise across enterprise security architecture, cloud security, DevSecOps, secure software development, and risk management within government or defence sectors. Key Responsibilities: Lead security architecture activities across complex projects and programmes within Central Government and Defence environments. Design and assure secure enterprise, cloud, hybrid, and on-premises architectures aligned to business and technical requirements. Collaborate with multidisciplinary teams to ensure security considerations are embedded across the entire delivery lifecycle. Conduct security threat modelling, risk assessments, and security architecture reviews for critical systems and services. Develop and maintain security reference architectures, standards, principles, and best practices. Support IT Health Checks (ITHC), penetration testing exercises, and remediation activities. Provide technical security leadership and governance across development, integration, and delivery teams. Work with customers, stakeholders, and accreditors to define security requirements and advise on risk mitigation strategies. Ensure adherence to security frameworks, regulatory requirements, and industry standards including GDPR, OWASP, and NCSC principles. Support the design and implementation of DevSecOps pipelines, secure CI/CD processes, and automated security tooling. Contribute to enterprise security strategy, architecture governance, and continuous improvement initiatives. Support business development activities including bids, proposals, pre-sales engagements, and client demonstrations. Identify emerging cyber security trends, technologies, vulnerabilities, and assess their relevance to customer solutions. Provide mentoring, leadership, and guidance to junior architects and engineering teams. Communicate complex security concepts effectively to both technical and non-technical stakeholders. Skills & Experience: Proven experience working as a Security Architect within Central Government, Defence, or highly regulated environments. Strong understanding of enterprise security architecture principles, methodologies, and frameworks. Hands-on experience performing threat modelling, security risk assessments, and secure solution assurance. Experience designing secure cloud and hybrid architectures using Microsoft Azure and/or AWS. Strong understanding of DevSecOps, CI/CD security, and secure software development lifecycle (SSDLC) practices. Knowledge of secure architecture patterns, secure web application development, and API security. Experience implementing and governing security controls aligned to OWASP, NCSC Cloud Security Principles, and GDPR. Strong understanding of authentication and authorisation technologies including SAML, OAuth2, OpenID Connect, Active Directory, ADFS, and LDAP. Experience supporting penetration testing, vulnerability remediation, and IT Health Check activities. Experience working with multidisciplinary Agile delivery teams across complex technical programmes. Ability to engage with senior stakeholders and communicate security risks and architectural decisions clearly. Strong understanding of enterprise integration, infrastructure, and data security principles. Got your attention? If you believe that you have the skills and experience for this Security Architect opportunity, then please get in touch. We also offer a referral scheme for any candidates whose details are passed to us that we successfully place. For further information, please contact the MERITUS team today.
Are you a Lead Infrastructure Engineer ready to take ownership of a high-performing infrastructure team delivering secure, mission-critical services? Sopra Steria is delivering a major greenfield programme for the Defence sector, building and integrating infrastructure and applications within highly secure environments. This is a rare opportunity to lead technical delivery on a nationally significant programme where the work you do has real purpose, scale, and impact. We are looking for an experienced Lead Infrastructure Engineer to oversee the day-to-day technical operations of the Windows infrastructure team, reporting to the Head of Operating Systems. You will combine hands-on technical expertise with people leadership, helping to shape team capability, improve service quality, and ensure the successful delivery of infrastructure services and project outcomes. This role would suit someone with strong Wintel and VMware experience, ideally gained within Defence, MoD, government, or similarly secure and regulated environments. This role is full time on site in the Hertfordshire area. What you will be doing: Lead, manage, and mentor the Windows infrastructure team, building capability and developing a strong SME structure. Oversee day-to-day technical operations, ensuring services are delivered in line with SLAs, governance, and security requirements. Support project delivery across solution design, estimation, detailed design, implementation, and service transition. Provide technical leadership across Wintel, VMware, virtualisation, messaging, file and print, thin client, and core infrastructure services. Work closely with architects, solution designers, project managers, and stakeholders to validate solutions, provide recommendations, and report progress. Maintain high-quality technical documentation, operational procedures, and governance artefacts to support consistent delivery. What you will bring: Strong experience leading infrastructure teams within complex enterprise or secure environments. Expert knowledge of Wintel infrastructure technologies, including Windows Server, Active Directory, Group Policy, DNS, DHCP, and core platform services. Hands-on experience with VMware, virtualisation, hardware, messaging, file and print, and thin client environments. Proven experience supporting infrastructure projects from design and estimation through to implementation and operational handover. Strong service management experience, including working to demanding SLAs, governance, compliance, and change control processes. Ability to lead, mentor, and influence technical teams while building trusted relationships with stakeholders. It would be great if you had: Experience working in Defence, MoD, government, or other highly regulated environments. PRINCE2, PMI, ITIL, Microsoft, VMware, or other relevant technical certifications. Experience contributing to pre-sales, bids, technical assurance, or service improvement activity. Exposure to automation, monitoring, backup, storage, or wider infrastructure tooling. If you are interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Full-time, Permanent Location: Hertfordshire Security Clearance Level: Eligible for Developed Vetting (DV) Internal Recruiter: Josh Salary: Competitive, based on experience Benefits: £5,400 car allowance, 3% cash fund, 25 days annual leave with the option to buy additional days, health cash plan, life assurance, pension Loved reading about this job and want to know more about us? Sopra Steria's Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.
May 13, 2026
Full time
Are you a Lead Infrastructure Engineer ready to take ownership of a high-performing infrastructure team delivering secure, mission-critical services? Sopra Steria is delivering a major greenfield programme for the Defence sector, building and integrating infrastructure and applications within highly secure environments. This is a rare opportunity to lead technical delivery on a nationally significant programme where the work you do has real purpose, scale, and impact. We are looking for an experienced Lead Infrastructure Engineer to oversee the day-to-day technical operations of the Windows infrastructure team, reporting to the Head of Operating Systems. You will combine hands-on technical expertise with people leadership, helping to shape team capability, improve service quality, and ensure the successful delivery of infrastructure services and project outcomes. This role would suit someone with strong Wintel and VMware experience, ideally gained within Defence, MoD, government, or similarly secure and regulated environments. This role is full time on site in the Hertfordshire area. What you will be doing: Lead, manage, and mentor the Windows infrastructure team, building capability and developing a strong SME structure. Oversee day-to-day technical operations, ensuring services are delivered in line with SLAs, governance, and security requirements. Support project delivery across solution design, estimation, detailed design, implementation, and service transition. Provide technical leadership across Wintel, VMware, virtualisation, messaging, file and print, thin client, and core infrastructure services. Work closely with architects, solution designers, project managers, and stakeholders to validate solutions, provide recommendations, and report progress. Maintain high-quality technical documentation, operational procedures, and governance artefacts to support consistent delivery. What you will bring: Strong experience leading infrastructure teams within complex enterprise or secure environments. Expert knowledge of Wintel infrastructure technologies, including Windows Server, Active Directory, Group Policy, DNS, DHCP, and core platform services. Hands-on experience with VMware, virtualisation, hardware, messaging, file and print, and thin client environments. Proven experience supporting infrastructure projects from design and estimation through to implementation and operational handover. Strong service management experience, including working to demanding SLAs, governance, compliance, and change control processes. Ability to lead, mentor, and influence technical teams while building trusted relationships with stakeholders. It would be great if you had: Experience working in Defence, MoD, government, or other highly regulated environments. PRINCE2, PMI, ITIL, Microsoft, VMware, or other relevant technical certifications. Experience contributing to pre-sales, bids, technical assurance, or service improvement activity. Exposure to automation, monitoring, backup, storage, or wider infrastructure tooling. If you are interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Full-time, Permanent Location: Hertfordshire Security Clearance Level: Eligible for Developed Vetting (DV) Internal Recruiter: Josh Salary: Competitive, based on experience Benefits: £5,400 car allowance, 3% cash fund, 25 days annual leave with the option to buy additional days, health cash plan, life assurance, pension Loved reading about this job and want to know more about us? Sopra Steria's Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.