DevSecOps Engineer - Azure / Application Security We're working with an established organisation looking to appoint an experienced DevSecOps Engineer to strengthen its Azure deployment and application security capabilities. This is a hands-on position combining Azure DevOps, cloud infrastructure and application security. You'll take ownership of CI/CD pipelines, Infrastructure-as-Code and security testing, while helping development teams embed secure practices throughout the software delivery lifecycle. The Role You'll be responsible for: Designing and maintaining CI/CD pipelines within Azure DevOps Deploying Azure applications and infrastructure using Terraform Supporting Azure services including App Services, AKS, Azure SQL, Storage, Key Vault, VNets, Private Endpoints and Front Door/WAF Introducing deployment practices such as blue/green releases, automated rollback and infrastructure drift detection Integrating SAST, DAST, dependency and container scanning into development pipelines Conducting web application security testing using Burp Suite, OWASP ZAP or similar tools Identifying and managing vulnerabilities against OWASP Top 10 and CVSS principles Implementing secrets detection, credential rotation and secure Key Vault practices Strengthening software supply-chain security through SBOM generation, dependency scanning and artefact signing Supporting API security testing, threat modelling and third-party penetration tests Configuring Azure-native security tooling, including Defender for Cloud, Azure Policy, Sentinel and Azure Monitor Enforcing identity and access controls across Entra ID, RBAC, Conditional Access and PIM Supporting compliance with frameworks such as Cyber Essentials Plus, ISO 27001 and GDPR Mentoring junior engineers and helping developers adopt secure coding and deployment practices What We're Looking For You'll need: Around three to five years' experience across DevOps, platform engineering or application security Strong hands-on experience with Microsoft Azure and Azure DevOps Proven experience securing web applications in a production environment Practical experience using Burp Suite for application security testing Experience with SonarQube or comparable SAST tooling Strong knowledge of OWASP Top 10, vulnerability management and remediation Experience building repeatable Azure deployments using Terraform Scripting ability with PowerShell, Python or Bash Experience implementing secrets detection and dependency/CVE remediation tooling The confidence to work independently, make risk-based decisions and support junior engineers Experience with Docker, Kubernetes/AKS, API security testing, threat modelling, SIEM tooling or software supply-chain security would be particularly useful. Relevant certifications such as AZ-500, AZ-400, Security+, CySA+, CEH or OSCP would also be beneficial, although practical experience is more important. This is an excellent opportunity for someone who enjoys working across cloud engineering and application security and wants genuine ownership over how secure software is built, tested and released. Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy. To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.
Aug 24, 2026
Full time
DevSecOps Engineer - Azure / Application Security We're working with an established organisation looking to appoint an experienced DevSecOps Engineer to strengthen its Azure deployment and application security capabilities. This is a hands-on position combining Azure DevOps, cloud infrastructure and application security. You'll take ownership of CI/CD pipelines, Infrastructure-as-Code and security testing, while helping development teams embed secure practices throughout the software delivery lifecycle. The Role You'll be responsible for: Designing and maintaining CI/CD pipelines within Azure DevOps Deploying Azure applications and infrastructure using Terraform Supporting Azure services including App Services, AKS, Azure SQL, Storage, Key Vault, VNets, Private Endpoints and Front Door/WAF Introducing deployment practices such as blue/green releases, automated rollback and infrastructure drift detection Integrating SAST, DAST, dependency and container scanning into development pipelines Conducting web application security testing using Burp Suite, OWASP ZAP or similar tools Identifying and managing vulnerabilities against OWASP Top 10 and CVSS principles Implementing secrets detection, credential rotation and secure Key Vault practices Strengthening software supply-chain security through SBOM generation, dependency scanning and artefact signing Supporting API security testing, threat modelling and third-party penetration tests Configuring Azure-native security tooling, including Defender for Cloud, Azure Policy, Sentinel and Azure Monitor Enforcing identity and access controls across Entra ID, RBAC, Conditional Access and PIM Supporting compliance with frameworks such as Cyber Essentials Plus, ISO 27001 and GDPR Mentoring junior engineers and helping developers adopt secure coding and deployment practices What We're Looking For You'll need: Around three to five years' experience across DevOps, platform engineering or application security Strong hands-on experience with Microsoft Azure and Azure DevOps Proven experience securing web applications in a production environment Practical experience using Burp Suite for application security testing Experience with SonarQube or comparable SAST tooling Strong knowledge of OWASP Top 10, vulnerability management and remediation Experience building repeatable Azure deployments using Terraform Scripting ability with PowerShell, Python or Bash Experience implementing secrets detection and dependency/CVE remediation tooling The confidence to work independently, make risk-based decisions and support junior engineers Experience with Docker, Kubernetes/AKS, API security testing, threat modelling, SIEM tooling or software supply-chain security would be particularly useful. Relevant certifications such as AZ-500, AZ-400, Security+, CySA+, CEH or OSCP would also be beneficial, although practical experience is more important. This is an excellent opportunity for someone who enjoys working across cloud engineering and application security and wants genuine ownership over how secure software is built, tested and released. Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy. To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.
Different Technologies Pty Ltd.
Cheltenham, Gloucestershire
Daintta are a rapidly growing, values-driven team of specialists who work with government clients across Cyber, Telecommunications and Data. We are seeking a talented and motivated Cyber Security Technical Security Consultant to join our team and contribute to our mission of protecting the UK through data-driven insights and solutions. As a technical Consultant, you will be expected to demonstrate versatility as you work closely with our public sector clients, governmental departments and project teams. You will be expected to help design, document, and build secure networks or systems: solving some of the UK's most exciting cyber security challenges. What's in it for you? You will be joining the company at Daintta "Consultant" grade. In addition to being rewarded fairly for your contribution to the business, you get to work in a dynamic organisation that is agile and responsive. A business that is growing fast and where you get to drive and shape the future. A place where you are respected by everyone and your voice is important. Somewhere where you can be innovative and creative. A place where you have the opportunity to learn about all aspects of business from marketing to sales, to delivery and business operations. Key Responsibilities Developing, justifying and implementing organisational and system security management strategies that address risk and control requirements, ensuring a UK Gov't Secure by Design approach Selecting, understanding and adapting/adopting appropriate security control frameworks Identifying security risk business and stakeholder security requirements and proposing proportionate assessment, design and implementation of secure systems to meet the requirements Performing threat modelling and risk assessments to develop a holistic picture of threat Ensuring security principles are applied during solution planning, design, test, deployment and operations to reduce risk and ensure compliance, including: Developing or supporting the development of secure solution designs to mitigate the risks posed by new technologies and business practices Supporting third-party and supply chain security assessments, including vendor due diligence, secure procurement, software supply chain risk and ongoing assurance of externally sourced technology Applying identity-led and zero trust security principles, including strong authentication, least privilege, contextual access control and segmentation of services, users and devices Defining and reviewing security assurance activities, including design assurance, verification, validation, vulnerability assessment, penetration testing inputs and interpretation of assurance evidence Developing and communicating corporate and domain information security policy, standards, guidelines and design guardrails Identifying and monitoring environmental and market trends and proactively assessing impact on business strategies, benefits and risks Assessing your client's' needs, understanding how their needs may differ from their wants, and appropriately managing stakeholder relationships Delivering high-quality work to agreed milestones, and adapting quickly to unfamiliar client environments. Supporting the technical aspects of client engagements, including pitches and presentations Helping to support & grow Daintta by actively inputting into the company strategy and helping to shape our future Representing us and our core values: Transparency, fairness and being daring. Skills/Knowledge You have relevant and recent practical experience in cyber security engineering, architecture, design or technical assurance, and can apply that knowledge credibly in client-facing consulting engagements You have worked in technical client deliveries across a range of cyber security related projects You understand technical controls and business risk You can demonstrate working-level experience in one or more of the following domains: Security Architecture; Security Operations; Identity & Access Management; Cloud, Infrastructure and Platform Security; Network and Connectivity Security; Application Security and DevSecOps; Data Security and Privacy; Governance, Risk & Compliance; You have experience embedding security into agile, DevSecOps and iterative delivery models, including design reviews, security requirements management and pragmatic risk treatment in fast-moving projects You have experience working with security control standards and frameworks e.g. ISO27001, NIST, NCSC guidance and NCSC CAF, JSP 440 or others You have demonstrable continuous personal development, supported by relevant certifications and accreditations You have good interpersonal skills at both the business and technical level You have UK security clearance at SC or above or are eligible and willing to go through clearance You have experience working with security controls within cloud-based infrastructure (e.g Azure, AWS, GCP). This may include design, configuration, or protective monitoring. Knowledge of digital identity and authentication systems Experience applying data classification, handling requirements, data residency and sovereignty considerations to solution design, particularly where sensitive, regulated or operationally critical data is involved Understanding of security risks and controls for AI-enabled systems, including data governance, access control, prompt injection, model misuse, third-party AI services and monitoring of sensitive data exposure Application and governance of fine grained access control and permissions Experience in UK Gov't public sector or defence Location? Hybrid, with 2-3 days working from Daintta office or on client site as required. We believe in supporting our people both professionally and personally. Here's what you can expect when you join us: Time Off: 25 days annual leave, plus bank holidays Up to 5 days annual training leave with a dedicated training budget Up to 3 days annual volunteering leave - give back to the community Competitive maternity, paternity, shared parental leave & compassionate leave Employee Assistance Programme - 24/7 support services £2,000 Flex Cash Allowance, paid pro-rata over the year Discretionary company awards and bonuses, based on performance and company targets Professional Development Up to £1,000 annual training budget (access to additional training and development budget via business case) Up to 5 days annual training leave 1 professional membership paid annually Up to £200 of additional IT budget for new joiners Free breakfast every Tuesday in the London office Fortnightly drinks - in London Regular social events, quizzes, and guest workshops Huckletree perks - including gym and restaurant discounts Employee referral programme Monthly breakfast club in our Cheltenham office Security Information Due to clients' requirements, all applications are strictly subject to security clearance requirements relevant to the role.
Aug 24, 2026
Full time
Daintta are a rapidly growing, values-driven team of specialists who work with government clients across Cyber, Telecommunications and Data. We are seeking a talented and motivated Cyber Security Technical Security Consultant to join our team and contribute to our mission of protecting the UK through data-driven insights and solutions. As a technical Consultant, you will be expected to demonstrate versatility as you work closely with our public sector clients, governmental departments and project teams. You will be expected to help design, document, and build secure networks or systems: solving some of the UK's most exciting cyber security challenges. What's in it for you? You will be joining the company at Daintta "Consultant" grade. In addition to being rewarded fairly for your contribution to the business, you get to work in a dynamic organisation that is agile and responsive. A business that is growing fast and where you get to drive and shape the future. A place where you are respected by everyone and your voice is important. Somewhere where you can be innovative and creative. A place where you have the opportunity to learn about all aspects of business from marketing to sales, to delivery and business operations. Key Responsibilities Developing, justifying and implementing organisational and system security management strategies that address risk and control requirements, ensuring a UK Gov't Secure by Design approach Selecting, understanding and adapting/adopting appropriate security control frameworks Identifying security risk business and stakeholder security requirements and proposing proportionate assessment, design and implementation of secure systems to meet the requirements Performing threat modelling and risk assessments to develop a holistic picture of threat Ensuring security principles are applied during solution planning, design, test, deployment and operations to reduce risk and ensure compliance, including: Developing or supporting the development of secure solution designs to mitigate the risks posed by new technologies and business practices Supporting third-party and supply chain security assessments, including vendor due diligence, secure procurement, software supply chain risk and ongoing assurance of externally sourced technology Applying identity-led and zero trust security principles, including strong authentication, least privilege, contextual access control and segmentation of services, users and devices Defining and reviewing security assurance activities, including design assurance, verification, validation, vulnerability assessment, penetration testing inputs and interpretation of assurance evidence Developing and communicating corporate and domain information security policy, standards, guidelines and design guardrails Identifying and monitoring environmental and market trends and proactively assessing impact on business strategies, benefits and risks Assessing your client's' needs, understanding how their needs may differ from their wants, and appropriately managing stakeholder relationships Delivering high-quality work to agreed milestones, and adapting quickly to unfamiliar client environments. Supporting the technical aspects of client engagements, including pitches and presentations Helping to support & grow Daintta by actively inputting into the company strategy and helping to shape our future Representing us and our core values: Transparency, fairness and being daring. Skills/Knowledge You have relevant and recent practical experience in cyber security engineering, architecture, design or technical assurance, and can apply that knowledge credibly in client-facing consulting engagements You have worked in technical client deliveries across a range of cyber security related projects You understand technical controls and business risk You can demonstrate working-level experience in one or more of the following domains: Security Architecture; Security Operations; Identity & Access Management; Cloud, Infrastructure and Platform Security; Network and Connectivity Security; Application Security and DevSecOps; Data Security and Privacy; Governance, Risk & Compliance; You have experience embedding security into agile, DevSecOps and iterative delivery models, including design reviews, security requirements management and pragmatic risk treatment in fast-moving projects You have experience working with security control standards and frameworks e.g. ISO27001, NIST, NCSC guidance and NCSC CAF, JSP 440 or others You have demonstrable continuous personal development, supported by relevant certifications and accreditations You have good interpersonal skills at both the business and technical level You have UK security clearance at SC or above or are eligible and willing to go through clearance You have experience working with security controls within cloud-based infrastructure (e.g Azure, AWS, GCP). This may include design, configuration, or protective monitoring. Knowledge of digital identity and authentication systems Experience applying data classification, handling requirements, data residency and sovereignty considerations to solution design, particularly where sensitive, regulated or operationally critical data is involved Understanding of security risks and controls for AI-enabled systems, including data governance, access control, prompt injection, model misuse, third-party AI services and monitoring of sensitive data exposure Application and governance of fine grained access control and permissions Experience in UK Gov't public sector or defence Location? Hybrid, with 2-3 days working from Daintta office or on client site as required. We believe in supporting our people both professionally and personally. Here's what you can expect when you join us: Time Off: 25 days annual leave, plus bank holidays Up to 5 days annual training leave with a dedicated training budget Up to 3 days annual volunteering leave - give back to the community Competitive maternity, paternity, shared parental leave & compassionate leave Employee Assistance Programme - 24/7 support services £2,000 Flex Cash Allowance, paid pro-rata over the year Discretionary company awards and bonuses, based on performance and company targets Professional Development Up to £1,000 annual training budget (access to additional training and development budget via business case) Up to 5 days annual training leave 1 professional membership paid annually Up to £200 of additional IT budget for new joiners Free breakfast every Tuesday in the London office Fortnightly drinks - in London Regular social events, quizzes, and guest workshops Huckletree perks - including gym and restaurant discounts Employee referral programme Monthly breakfast club in our Cheltenham office Security Information Due to clients' requirements, all applications are strictly subject to security clearance requirements relevant to the role.
Are you ready to redefine defence technology and lead innovative software solutions that truly make a difference? This is your chance to join a company at the forefront of pioneering advanced cryptographic and key management solutions. As a Chief Software Architect , you will lead and shape the software engineering strategy for advanced cyber and defence systems, overseeing a team of engineers across multiple high-security projects. The position focuses on defining software architectures, driving best-practice development processes, and ensuring collaboration across software, hardware, systems, and firmware teams to deliver secure, scalable, and high-quality solutions. The role requires deep expertise in embedded and application software development using technologies such as C/C++, Rust, Linux, and RTOS environments, alongside experience with DevSecOps, automated testing, and secure development standards. In addition to technical leadership, the architect will mentor engineers, support bids and proposals, influence organisational software standards, and contribute to the delivery of mission-critical defence technologies requiring DV security clearance. What You Will Do: - Provide technical leadership across multiple projects, ensuring optimal approaches, architecture, and tool chains are selected. - Collaborate with stakeholders to develop software requirements, architectures, and designs that meet system and security needs. - Work closely with software leads and project managers to create development plans that deliver value early to customers. - Mentor and coach software engineers, sharing knowledge and driving process improvements for technical excellence. - Specify, design, and review software using UML and SysML modelling tools, ensuring high-quality, modular, and compliant solutions. - Champion best practices in software development, including continuous integration, automated testing, and secure coding standards. What You Will Bring: - Advanced knowledge and experience in C/C++, Rust, or embedded product development, including RTOSes. - Expertise in software engineering practices, methodologies, and technology trends. - Proven track record of delivering complex software solutions to schedule while exceeding customer expectations. - Experience with tools such as version control systems, change control, bug tracking, and automated testing frameworks. - Familiarity with defence or high-assurance development standards, including coding standards like MISRA. This company is committed to delivering innovative solutions that empower decision-making at both tactical and strategic levels. As a Chief Software Architect , you will be instrumental in driving technical excellence and ensuring the success of critical programmes that protect lives and enhance global security. Your contributions will align with the company's values of trust, collaboration, and innovation, making a real impact in the defence industry. Location: The role is an onsite role in Maidenhead, offering good flexibility with working hours. Interested?: If you're ready to take your career to the next level and lead transformative software projects, apply now to become the Chief Software Architect . Don't miss the opportunity to make a difference in the future of defence technology. Your CV will be forwarded to Jonathan Lee Recruitment, a leading engineering and manufacturing recruitment consultancy established in 1978. The services advertised by Jonathan Lee Recruitment are those of an Employment Agency. In order for your CV to be processed effectively, please ensure your name, email address, phone number and location (post code OR town OR county, as a minimum) are included.
Aug 23, 2026
Full time
Are you ready to redefine defence technology and lead innovative software solutions that truly make a difference? This is your chance to join a company at the forefront of pioneering advanced cryptographic and key management solutions. As a Chief Software Architect , you will lead and shape the software engineering strategy for advanced cyber and defence systems, overseeing a team of engineers across multiple high-security projects. The position focuses on defining software architectures, driving best-practice development processes, and ensuring collaboration across software, hardware, systems, and firmware teams to deliver secure, scalable, and high-quality solutions. The role requires deep expertise in embedded and application software development using technologies such as C/C++, Rust, Linux, and RTOS environments, alongside experience with DevSecOps, automated testing, and secure development standards. In addition to technical leadership, the architect will mentor engineers, support bids and proposals, influence organisational software standards, and contribute to the delivery of mission-critical defence technologies requiring DV security clearance. What You Will Do: - Provide technical leadership across multiple projects, ensuring optimal approaches, architecture, and tool chains are selected. - Collaborate with stakeholders to develop software requirements, architectures, and designs that meet system and security needs. - Work closely with software leads and project managers to create development plans that deliver value early to customers. - Mentor and coach software engineers, sharing knowledge and driving process improvements for technical excellence. - Specify, design, and review software using UML and SysML modelling tools, ensuring high-quality, modular, and compliant solutions. - Champion best practices in software development, including continuous integration, automated testing, and secure coding standards. What You Will Bring: - Advanced knowledge and experience in C/C++, Rust, or embedded product development, including RTOSes. - Expertise in software engineering practices, methodologies, and technology trends. - Proven track record of delivering complex software solutions to schedule while exceeding customer expectations. - Experience with tools such as version control systems, change control, bug tracking, and automated testing frameworks. - Familiarity with defence or high-assurance development standards, including coding standards like MISRA. This company is committed to delivering innovative solutions that empower decision-making at both tactical and strategic levels. As a Chief Software Architect , you will be instrumental in driving technical excellence and ensuring the success of critical programmes that protect lives and enhance global security. Your contributions will align with the company's values of trust, collaboration, and innovation, making a real impact in the defence industry. Location: The role is an onsite role in Maidenhead, offering good flexibility with working hours. Interested?: If you're ready to take your career to the next level and lead transformative software projects, apply now to become the Chief Software Architect . Don't miss the opportunity to make a difference in the future of defence technology. Your CV will be forwarded to Jonathan Lee Recruitment, a leading engineering and manufacturing recruitment consultancy established in 1978. The services advertised by Jonathan Lee Recruitment are those of an Employment Agency. In order for your CV to be processed effectively, please ensure your name, email address, phone number and location (post code OR town OR county, as a minimum) are included.
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Aug 23, 2026
Full time
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Senior Security Architect (contractor)- Data Protection & Azure Cloud Security Rate: Flexible Duration: 1 year Hybrid working - 8 days onsite per month (Inside of IR35) We are looking for an experienced Senior Security Architect to join a major enterprise cybersecurity function, taking a leading role in the design and governance of security architecture across Data Protection and Cloud Security . This is a senior architecture position within a large, complex and highly regulated environment. You will work across business, technology, engineering, risk and security teams to ensure new applications, platforms and cloud solutions are designed securely from the outset. A major focus of the role will be enterprise data protection and Azure cloud security , including the architecture and governance of controls covering data classification, discovery, labelling, lifecycle management and protection of sensitive information. Key Responsibilities Lead the design and delivery of end-to-end security architecture across enterprise applications, platforms and cloud environments. Develop high-level security designs and translate business, technology and risk requirements into practical security architecture. Define and maintain security architecture principles, standards, patterns and reusable design guidance . Provide architecture governance and design assurance, challenging proposed solutions and ensuring security requirements are addressed throughout the delivery lifecycle. Act as a Subject Matter Expert for Data Protection and Cloud Security , providing technical guidance to architecture, engineering and business teams. Design and govern enterprise data protection and data security controls , including: Data discovery and inventory Data classification and sensitivity labelling Data Loss Prevention (DLP) Data governance Data retention and disposal Data lifecycle controls Protection of structured and unstructured information Encryption and access controls Support the secure design and adoption of Microsoft Azure , alongside AWS, SaaS and hybrid-cloud environments. Ensure appropriate security controls across applications, infrastructure, identities, networks and data. Translate cyber risks and regulatory requirements into appropriate security controls and non-functional requirements (NFRs) . Conduct and support security architecture reviews, threat/risk assessments and design validation. Work closely with Enterprise Architecture, Engineering, Cloud, DevSecOps, Risk, Compliance and CISO teams. Identify gaps within the existing security landscape and recommend improvements. Support secure technology adoption and major transformation initiatives. Essential Experience We are looking for candidates with strong experience across both Security Architecture and Data/Cloud Security . You should have: Significant experience as a Security Architect, Cyber Security Architect, Security Solution Architect or Enterprise Security Architect . Proven experience delivering end-to-end security architecture within large and complex organisations. Strong knowledge of security architecture governance, including standards, patterns, design reviews and architecture assurance . Strong Data Protection / Data Security Architecture experience. Experience with data classification, discovery, inventory, labelling, governance, retention/disposal and lifecycle controls. Understanding of security controls for both structured and unstructured data . Strong Microsoft Azure Security architecture experience. Good knowledge of AWS, SaaS and hybrid/multi-cloud security. Experience securing enterprise applications, infrastructure and cloud platforms. Understanding of IAM, Zero Trust, encryption, key management and access-control principles. Ability to translate risk assessments and regulatory requirements into technical security architecture. Experience working within regulatory frameworks such as GDPR, DORA, PCI-DSS, SOX and/or SWIFT CSP . Excellent communication skills with the ability to engage with senior stakeholders, architects, engineers, risk and compliance teams. Highly Desirable Experience with Microsoft Purview , particularly Information Protection, data classification, sensitivity labelling, DLP and information governance. Experience defining data-protection architecture across Azure and Microsoft 365 environments. Financial Services, Banking, Payments, Market Infrastructure or other highly regulated/critical infrastructure experience. Experience with security architecture frameworks such as SABSA, TOGAF or similar . Knowledge of DevSecOps and secure SDLC practices. Experience working within Agile delivery environments and across multiple release trains. Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, Azure Security/Architecture, CISM or equivalent . Rates depend on experience and client requirements
Aug 22, 2026
Contractor
Senior Security Architect (contractor)- Data Protection & Azure Cloud Security Rate: Flexible Duration: 1 year Hybrid working - 8 days onsite per month (Inside of IR35) We are looking for an experienced Senior Security Architect to join a major enterprise cybersecurity function, taking a leading role in the design and governance of security architecture across Data Protection and Cloud Security . This is a senior architecture position within a large, complex and highly regulated environment. You will work across business, technology, engineering, risk and security teams to ensure new applications, platforms and cloud solutions are designed securely from the outset. A major focus of the role will be enterprise data protection and Azure cloud security , including the architecture and governance of controls covering data classification, discovery, labelling, lifecycle management and protection of sensitive information. Key Responsibilities Lead the design and delivery of end-to-end security architecture across enterprise applications, platforms and cloud environments. Develop high-level security designs and translate business, technology and risk requirements into practical security architecture. Define and maintain security architecture principles, standards, patterns and reusable design guidance . Provide architecture governance and design assurance, challenging proposed solutions and ensuring security requirements are addressed throughout the delivery lifecycle. Act as a Subject Matter Expert for Data Protection and Cloud Security , providing technical guidance to architecture, engineering and business teams. Design and govern enterprise data protection and data security controls , including: Data discovery and inventory Data classification and sensitivity labelling Data Loss Prevention (DLP) Data governance Data retention and disposal Data lifecycle controls Protection of structured and unstructured information Encryption and access controls Support the secure design and adoption of Microsoft Azure , alongside AWS, SaaS and hybrid-cloud environments. Ensure appropriate security controls across applications, infrastructure, identities, networks and data. Translate cyber risks and regulatory requirements into appropriate security controls and non-functional requirements (NFRs) . Conduct and support security architecture reviews, threat/risk assessments and design validation. Work closely with Enterprise Architecture, Engineering, Cloud, DevSecOps, Risk, Compliance and CISO teams. Identify gaps within the existing security landscape and recommend improvements. Support secure technology adoption and major transformation initiatives. Essential Experience We are looking for candidates with strong experience across both Security Architecture and Data/Cloud Security . You should have: Significant experience as a Security Architect, Cyber Security Architect, Security Solution Architect or Enterprise Security Architect . Proven experience delivering end-to-end security architecture within large and complex organisations. Strong knowledge of security architecture governance, including standards, patterns, design reviews and architecture assurance . Strong Data Protection / Data Security Architecture experience. Experience with data classification, discovery, inventory, labelling, governance, retention/disposal and lifecycle controls. Understanding of security controls for both structured and unstructured data . Strong Microsoft Azure Security architecture experience. Good knowledge of AWS, SaaS and hybrid/multi-cloud security. Experience securing enterprise applications, infrastructure and cloud platforms. Understanding of IAM, Zero Trust, encryption, key management and access-control principles. Ability to translate risk assessments and regulatory requirements into technical security architecture. Experience working within regulatory frameworks such as GDPR, DORA, PCI-DSS, SOX and/or SWIFT CSP . Excellent communication skills with the ability to engage with senior stakeholders, architects, engineers, risk and compliance teams. Highly Desirable Experience with Microsoft Purview , particularly Information Protection, data classification, sensitivity labelling, DLP and information governance. Experience defining data-protection architecture across Azure and Microsoft 365 environments. Financial Services, Banking, Payments, Market Infrastructure or other highly regulated/critical infrastructure experience. Experience with security architecture frameworks such as SABSA, TOGAF or similar . Knowledge of DevSecOps and secure SDLC practices. Experience working within Agile delivery environments and across multiple release trains. Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, Azure Security/Architecture, CISM or equivalent . Rates depend on experience and client requirements
Cloud Security Consultant x 3 UK Wide Up to 100,000 + Benefits We are seeking experienced Cloud Security Consultants to join a growing cybersecurity practice delivering complex cloud security solutions across a range of enterprise and public sector environments You will play a key role in ensuring cloud environments are designed and deployed in line with security best practices, regulatory requirements, and modern security frameworks. You will be involved in designing secure cloud solutions, conducting security reviews, supporting cloud transformation initiatives, and advising stakeholders on how to manage security risks across cloud platforms. Key Responsibilities Support clients in developing enterprise security use cases aligned to their cloud strategy. Design and build security reference architectures across public, private, and hybrid cloud environments. Collaborate with technical teams on the architecture, design, and implementation of secure cloud solutions. Develop secure cloud architectures, governance frameworks, and security operating models. Protect cloud environments across network, application, identity, and data layers. Produce security, configuration, deployment, and DevSecOps models for cloud-based services. Conduct threat modelling exercises and security design reviews as part of secure-by-design initiatives. Required Skills & Experience Minimum 3 years' experience working as a Cloud Security Consultant, Cloud Security Architect, or similar security-focused consulting role. Experience supporting organisations with cloud security strategy and enterprise security use cases. Strong understanding of cloud security architecture principles. Experience designing secure public, private, and hybrid cloud environments. Knowledge of security governance, risk management, and compliance frameworks. Proven experience conducting threat modelling and security design reviews. Experience implementing secure-by-design principles. Familiarity with DevSecOps practices and secure deployment methodologies. Technical Experience Microsoft Azure Security AWS Security Google Cloud Platform (GCP) Security Identity & Access Management (IAM) Zero Trust Architecture Security Architecture & Governance DevSecOps Cloud Security Posture Management (CSPM) Security Automation & Orchestration Threat Modelling Secure Cloud Landing Zones
Aug 22, 2026
Full time
Cloud Security Consultant x 3 UK Wide Up to 100,000 + Benefits We are seeking experienced Cloud Security Consultants to join a growing cybersecurity practice delivering complex cloud security solutions across a range of enterprise and public sector environments You will play a key role in ensuring cloud environments are designed and deployed in line with security best practices, regulatory requirements, and modern security frameworks. You will be involved in designing secure cloud solutions, conducting security reviews, supporting cloud transformation initiatives, and advising stakeholders on how to manage security risks across cloud platforms. Key Responsibilities Support clients in developing enterprise security use cases aligned to their cloud strategy. Design and build security reference architectures across public, private, and hybrid cloud environments. Collaborate with technical teams on the architecture, design, and implementation of secure cloud solutions. Develop secure cloud architectures, governance frameworks, and security operating models. Protect cloud environments across network, application, identity, and data layers. Produce security, configuration, deployment, and DevSecOps models for cloud-based services. Conduct threat modelling exercises and security design reviews as part of secure-by-design initiatives. Required Skills & Experience Minimum 3 years' experience working as a Cloud Security Consultant, Cloud Security Architect, or similar security-focused consulting role. Experience supporting organisations with cloud security strategy and enterprise security use cases. Strong understanding of cloud security architecture principles. Experience designing secure public, private, and hybrid cloud environments. Knowledge of security governance, risk management, and compliance frameworks. Proven experience conducting threat modelling and security design reviews. Experience implementing secure-by-design principles. Familiarity with DevSecOps practices and secure deployment methodologies. Technical Experience Microsoft Azure Security AWS Security Google Cloud Platform (GCP) Security Identity & Access Management (IAM) Zero Trust Architecture Security Architecture & Governance DevSecOps Cloud Security Posture Management (CSPM) Security Automation & Orchestration Threat Modelling Secure Cloud Landing Zones
Staff Software Security Engineer Salary: Up to £135,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Staff Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Staff Software Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Software Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Staff Software Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £135,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Aug 20, 2026
Full time
Staff Software Security Engineer Salary: Up to £135,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Staff Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Staff Software Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Software Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Staff Software Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £135,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
A leading financial services firm in Greater London is hiring a Contract Cloud Security Consultant to support their Cyber Transformation Programme. The role involves ensuring security alignment with standards like NIST CSF 2.0, leading threat modelling and risk assessments, and promoting best security practices within a matrixed environment. Ideal candidates will have deep knowledge in DevSecOps, Azure IAM, and secure coding, including experience with Python. This position offers a hybrid work model.
Aug 15, 2026
Full time
A leading financial services firm in Greater London is hiring a Contract Cloud Security Consultant to support their Cyber Transformation Programme. The role involves ensuring security alignment with standards like NIST CSF 2.0, leading threat modelling and risk assessments, and promoting best security practices within a matrixed environment. Ideal candidates will have deep knowledge in DevSecOps, Azure IAM, and secure coding, including experience with Python. This position offers a hybrid work model.
Head of Security (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Head of Security (CISO) to lead and evolve our group-wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Qualifications Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Benefits Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
Aug 14, 2026
Full time
Head of Security (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Head of Security (CISO) to lead and evolve our group-wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Qualifications Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Benefits Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
Cloud Security Consultant A Global Financial Services firm requires a Contract Cloud Security Consultant to join their Cyber Transformation Programme consulting across Al, DevSecOps & Microsoft Security Suite. Travel: Hydbrid Location: London IT Security Cloud Consultant working in Al engineering and project teams, ensuring all deliverables align with security standards (e.g. NIST CSF 2.0) and protect information assets (Confidentiality, Integrity, Availability). Lead threat modelling, risk assessments, and secure coding initiatives (especially in Python and Azure environments) across the chatbot lifecycle and broader IT systems, mitigating vulnerabilities and ensuring compliance with data protection laws (e.g., GDPR). Establish, implement, and maintain security policies, standards, and operational controls; support audits, incident response, vulnerability remediation, and ensure effective use of security tooling (eg., Sentinel, Defender for Cloud, SIEM). Work closely with Operational Risk, DevOps, and Information Security teams to embed best practices into Agile delivery pipelines, balance stakeholder priorities, and drive the security agenda within a matrixed environment. Serve as the security point of contact for projects, leveraging deep knowledge in DevSecOps, Azure IAM, PKI, secure SDLC, and adversarial Al threats, while promoting a culture of continuous improvement and security awareness.
Aug 13, 2026
Full time
Cloud Security Consultant A Global Financial Services firm requires a Contract Cloud Security Consultant to join their Cyber Transformation Programme consulting across Al, DevSecOps & Microsoft Security Suite. Travel: Hydbrid Location: London IT Security Cloud Consultant working in Al engineering and project teams, ensuring all deliverables align with security standards (e.g. NIST CSF 2.0) and protect information assets (Confidentiality, Integrity, Availability). Lead threat modelling, risk assessments, and secure coding initiatives (especially in Python and Azure environments) across the chatbot lifecycle and broader IT systems, mitigating vulnerabilities and ensuring compliance with data protection laws (e.g., GDPR). Establish, implement, and maintain security policies, standards, and operational controls; support audits, incident response, vulnerability remediation, and ensure effective use of security tooling (eg., Sentinel, Defender for Cloud, SIEM). Work closely with Operational Risk, DevOps, and Information Security teams to embed best practices into Agile delivery pipelines, balance stakeholder priorities, and drive the security agenda within a matrixed environment. Serve as the security point of contact for projects, leveraging deep knowledge in DevSecOps, Azure IAM, PKI, secure SDLC, and adversarial Al threats, while promoting a culture of continuous improvement and security awareness.
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Aug 11, 2026
Full time
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
CBSbutler Holdings Limited trading as CBSbutler
Corsham, Wiltshire
PAM Architect +9 months + +DV cleared - current active clearance +Sole British nationals only due to the nature of the project +Hybrid working in Corsham +Inside IR35 + 500 - 550 a day Key Responsibilities Architect and deliver enterprise CyberArk PAM solutions , including PAS, CPM, PSM and PVWA Define privileged access, credential management, vaulting and session monitoring strategies Produce HLDs, LLDs, security architecture documentation and implementation runbooks Integrate CyberArk with Active Directory/LDAP, SIEM and ITSM platforms Conduct security assessments, gap analysis and remediation activities Provide PAM technical leadership, guidance and mentoring Work closely with customer and internal stakeholders, including on-site customer engagement Drive continuous improvement and innovation across the PAM capability Key Skills & Experience Proven experience as a PAM Architect or Senior PAM SME Strong hands-on CyberArk experience, ideally across PAS, CPM, PSM, PVWA and PTA Enterprise-scale PAM architecture and implementation experience Strong understanding of IAM, least privilege and privileged credential lifecycle management Experience with session isolation/recording and secure access controls Strong technical documentation and security architecture skills Knowledge of NIST, ISO 27001 or similar security frameworks Excellent stakeholder management and communication skills Experience of DevSecOps and secrets management would be advantageous If you'd like to discuss this PAM Architect in more detail, please send your updated CV to (url removed) and I will get in touch.
Aug 10, 2026
Contractor
PAM Architect +9 months + +DV cleared - current active clearance +Sole British nationals only due to the nature of the project +Hybrid working in Corsham +Inside IR35 + 500 - 550 a day Key Responsibilities Architect and deliver enterprise CyberArk PAM solutions , including PAS, CPM, PSM and PVWA Define privileged access, credential management, vaulting and session monitoring strategies Produce HLDs, LLDs, security architecture documentation and implementation runbooks Integrate CyberArk with Active Directory/LDAP, SIEM and ITSM platforms Conduct security assessments, gap analysis and remediation activities Provide PAM technical leadership, guidance and mentoring Work closely with customer and internal stakeholders, including on-site customer engagement Drive continuous improvement and innovation across the PAM capability Key Skills & Experience Proven experience as a PAM Architect or Senior PAM SME Strong hands-on CyberArk experience, ideally across PAS, CPM, PSM, PVWA and PTA Enterprise-scale PAM architecture and implementation experience Strong understanding of IAM, least privilege and privileged credential lifecycle management Experience with session isolation/recording and secure access controls Strong technical documentation and security architecture skills Knowledge of NIST, ISO 27001 or similar security frameworks Excellent stakeholder management and communication skills Experience of DevSecOps and secrets management would be advantageous If you'd like to discuss this PAM Architect in more detail, please send your updated CV to (url removed) and I will get in touch.
Chief Information Security Officer (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Chief Information Security Officer (CISO) to lead and evolve our group wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI-DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
Aug 07, 2026
Full time
Chief Information Security Officer (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Chief Information Security Officer (CISO) to lead and evolve our group wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI-DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
Cyber Security Engineer/Specialist Permanent Up to £80,000 (+ Benefits) Hybrid Working (2 3 days per week Onsite) Surrey Help Shape Enterprise Cyber Security on a Global Scale We're looking for an experienced Cyber Security Engineer/Specialist to join a global organisation where security is a genuine business priority, not simply a compliance exercise. This is an opportunity to play a key role in protecting a complex enterprise environment, helping to identify, assess and mitigate sophisticated cyber threats while influencing the organisation's long-term security strategy. Working alongside infrastructure, architecture and operational teams, you'll strengthen enterprise security capabilities, improve cyber resilience and help safeguard critical business systems across an international environment. If you're looking for a role where you can make a real impact while continuing to develop your career within a stable organisation, we'd love to hear from you. The Role This is an enterprise Cyber Security position focused on proactive threat mitigation, security improvement and risk reduction rather than purely operational support. You'll be responsible for strengthening the organisation's security posture through threat assessment, vulnerability management, incident response and continuous security improvement initiatives. Key responsibilities include: Enterprise Threat Management Identify, assess and mitigate cyber threats across enterprise infrastructure and business systems Conduct proactive threat assessments and vulnerability analysis Develop and implement security controls and remediation strategies Monitor emerging threats and recommend appropriate defensive measures Enhance threat detection, monitoring and incident response capabilities Develop and maintain incident response playbooks and operational procedures Work closely with third-party security providers during incidents and security assessments Security Engineering & Risk Support enterprise security architecture and secure design initiatives Contribute to cyber risk management and governance activities Assess third-party and supply chain security risks Support penetration testing, vulnerability management and security assurance programmes Produce meaningful security metrics and KPI reporting for stakeholders Ensure alignment with recognised security frameworks and regulatory requirements Security Improvement Collaborate with infrastructure, cloud and engineering teams to embed security best practice Participate in Red Team / Blue Team exercises and cyber resilience testing Support business continuity and disaster recovery planning Champion continuous improvement across the organisation's security capability Communicate technical security risks clearly to both technical and business stakeholders What You'll Bring We're looking for someone who enjoys solving complex security challenges within large enterprise environments. You'll ideally have: A minimum of 5 years' experience in Cyber Security or Information Security Strong experience protecting enterprise environments against modern cyber threats Experience designing and implementing security controls to reduce organisational risk Excellent knowledge of enterprise security technologies and security operations Experience with SIEM platforms, incident response and threat detection Strong understanding of vulnerability management and security remediation Experience working with recognised security frameworks including: NIST ISO 27001 CIS Controls Cyber Essentials Knowledge of MITRE ATT&CK, Cyber Kill Chain and modern threat intelligence methodologies Excellent analytical, troubleshooting and stakeholder management skills Technical Environment Experience with several of the following technologies would be advantageous: Microsoft Defender Splunk Qualys Azure Security AWS Microsoft 365 Security PowerShell Python Kubernetes Windows Server Linux SOAR platforms Data Loss Prevention (DLP) DevSecOps practices Experience with AI-driven threat detection technologies would also be beneficial. Qualifications Ideally you'll hold one of the following: CISSP (preferred) CISM GIAC Certification CEH However, we recognise that exceptional enterprise Cyber Security experience is just as valuable. If you've developed your expertise through hands-on experience and hold certifications such as CompTIA Security+ , we'd still be keen to hear from you. Ideal Background We'd particularly like to speak with professionals currently working as: Senior Cyber Security Engineer Cyber Security Engineer Information Security Engineer Security Operations Engineer Threat Detection Engineer Cyber Defence Engineer Blue Team Engineer Senior SOC Engineer Security Consultant Experience within large enterprise or global organisations would be highly desirable. Why Join? You'll become part of a collaborative Cyber Security team within a business that continues to invest heavily in technology and security. In return, you'll benefit from: Competitive salary up to £80,000 (+ benefits) Hybrid working (2 3 days onsite in Surrey) Exposure to enterprise-scale security technologies Opportunities to influence security strategy Ongoing investment in professional development and certifications Long-term career progression within a stable global organisation A supportive and collaborative working culture Ready to Make an Impact? If you're passionate about enterprise Cyber Security, enjoy solving complex security challenges and want to help shape the future of Cyber Security within a global organisation, we'd love to hear from you. If you are passionate about cybersecurity, threat management and strengthening enterprise security capabilities, we would love to hear from you.
Jul 31, 2026
Full time
Cyber Security Engineer/Specialist Permanent Up to £80,000 (+ Benefits) Hybrid Working (2 3 days per week Onsite) Surrey Help Shape Enterprise Cyber Security on a Global Scale We're looking for an experienced Cyber Security Engineer/Specialist to join a global organisation where security is a genuine business priority, not simply a compliance exercise. This is an opportunity to play a key role in protecting a complex enterprise environment, helping to identify, assess and mitigate sophisticated cyber threats while influencing the organisation's long-term security strategy. Working alongside infrastructure, architecture and operational teams, you'll strengthen enterprise security capabilities, improve cyber resilience and help safeguard critical business systems across an international environment. If you're looking for a role where you can make a real impact while continuing to develop your career within a stable organisation, we'd love to hear from you. The Role This is an enterprise Cyber Security position focused on proactive threat mitigation, security improvement and risk reduction rather than purely operational support. You'll be responsible for strengthening the organisation's security posture through threat assessment, vulnerability management, incident response and continuous security improvement initiatives. Key responsibilities include: Enterprise Threat Management Identify, assess and mitigate cyber threats across enterprise infrastructure and business systems Conduct proactive threat assessments and vulnerability analysis Develop and implement security controls and remediation strategies Monitor emerging threats and recommend appropriate defensive measures Enhance threat detection, monitoring and incident response capabilities Develop and maintain incident response playbooks and operational procedures Work closely with third-party security providers during incidents and security assessments Security Engineering & Risk Support enterprise security architecture and secure design initiatives Contribute to cyber risk management and governance activities Assess third-party and supply chain security risks Support penetration testing, vulnerability management and security assurance programmes Produce meaningful security metrics and KPI reporting for stakeholders Ensure alignment with recognised security frameworks and regulatory requirements Security Improvement Collaborate with infrastructure, cloud and engineering teams to embed security best practice Participate in Red Team / Blue Team exercises and cyber resilience testing Support business continuity and disaster recovery planning Champion continuous improvement across the organisation's security capability Communicate technical security risks clearly to both technical and business stakeholders What You'll Bring We're looking for someone who enjoys solving complex security challenges within large enterprise environments. You'll ideally have: A minimum of 5 years' experience in Cyber Security or Information Security Strong experience protecting enterprise environments against modern cyber threats Experience designing and implementing security controls to reduce organisational risk Excellent knowledge of enterprise security technologies and security operations Experience with SIEM platforms, incident response and threat detection Strong understanding of vulnerability management and security remediation Experience working with recognised security frameworks including: NIST ISO 27001 CIS Controls Cyber Essentials Knowledge of MITRE ATT&CK, Cyber Kill Chain and modern threat intelligence methodologies Excellent analytical, troubleshooting and stakeholder management skills Technical Environment Experience with several of the following technologies would be advantageous: Microsoft Defender Splunk Qualys Azure Security AWS Microsoft 365 Security PowerShell Python Kubernetes Windows Server Linux SOAR platforms Data Loss Prevention (DLP) DevSecOps practices Experience with AI-driven threat detection technologies would also be beneficial. Qualifications Ideally you'll hold one of the following: CISSP (preferred) CISM GIAC Certification CEH However, we recognise that exceptional enterprise Cyber Security experience is just as valuable. If you've developed your expertise through hands-on experience and hold certifications such as CompTIA Security+ , we'd still be keen to hear from you. Ideal Background We'd particularly like to speak with professionals currently working as: Senior Cyber Security Engineer Cyber Security Engineer Information Security Engineer Security Operations Engineer Threat Detection Engineer Cyber Defence Engineer Blue Team Engineer Senior SOC Engineer Security Consultant Experience within large enterprise or global organisations would be highly desirable. Why Join? You'll become part of a collaborative Cyber Security team within a business that continues to invest heavily in technology and security. In return, you'll benefit from: Competitive salary up to £80,000 (+ benefits) Hybrid working (2 3 days onsite in Surrey) Exposure to enterprise-scale security technologies Opportunities to influence security strategy Ongoing investment in professional development and certifications Long-term career progression within a stable global organisation A supportive and collaborative working culture Ready to Make an Impact? If you're passionate about enterprise Cyber Security, enjoy solving complex security challenges and want to help shape the future of Cyber Security within a global organisation, we'd love to hear from you. If you are passionate about cybersecurity, threat management and strengthening enterprise security capabilities, we would love to hear from you.
Cyber Security Manager Huddersfield Permanent Up to 75,000 plus out of hours pay 100% On-site On behalf of our private sector client, I'm on the lookout for a cyber security manager to help develop and deliver a cyber strategy. Ideally, I'm looking for experience in a cybersecurity leadership role or a strategic cyber role, but strong experience across traditional security cloud security or DevSecOps with the genuine ambition to progress into a strategic leadership role would also be feasible. The priority for this organisation is filling in any gaps in the current cyber security posture, to work with software delivery teams and enhance their security practices, and to implement cyber security best practice into their current cloud strategy (AWS predominantly, some Azure.) This is an all-rounder role that touches on all areas of cyber security and will require a hands-on technical knowledge, but will also come with the opportunity to craft and own a cyber strategy, and to grow out the cyber team with specialists covering off priority cyber and infosec domains. What this role involves: Review, develop, monitor and mature the overall cyber security strategy Using your judgement, growing out the cyber team in line with the strategy and its key priorities Enhance and drive the cloud security strategy pertaining to AWS and Azure Working with colleagues across software development, infrastructure, networks, data analysis and cloud - advising on cyber best practices Working with managed service providers and third-party security providers Overseeing alerts pulling through from their MSSP, alongside putting effective measures in place to enhance organisational security following pentests. Understanding what good looks like in cyber, and articulating this effectively with stakeholders across the business Working with external consultants on GRC activities What I'm looking for: Experience in a cybersecurity leadership role or a strategic cyber role would be ideal, but strong experience across cloud security or DevSecOps with the genuine ambition to progress into a strategic leadership role would also be feasible Whilst this role won't have you creating use-cases, runbooks and playbooks, you will need a hands-on understanding of commonplace cyber tools in order to face off to MSSPs, external providers and internal technical and non-technical colleagues Cloud security knowledge - AWS is the priority, Azure would also be useful GRC understanding - frameworks, best practice, policy development Ability to understand and properly react to pentest reports Ability to effectively communicate with technical and non-technical stakeholders up to board level Benefits A salary up to 75,000 National average pension Flexible hours Heavily subsidised on-site gym 25 days annual leave with buy and sell, plus bank holidays Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Jul 31, 2026
Full time
Cyber Security Manager Huddersfield Permanent Up to 75,000 plus out of hours pay 100% On-site On behalf of our private sector client, I'm on the lookout for a cyber security manager to help develop and deliver a cyber strategy. Ideally, I'm looking for experience in a cybersecurity leadership role or a strategic cyber role, but strong experience across traditional security cloud security or DevSecOps with the genuine ambition to progress into a strategic leadership role would also be feasible. The priority for this organisation is filling in any gaps in the current cyber security posture, to work with software delivery teams and enhance their security practices, and to implement cyber security best practice into their current cloud strategy (AWS predominantly, some Azure.) This is an all-rounder role that touches on all areas of cyber security and will require a hands-on technical knowledge, but will also come with the opportunity to craft and own a cyber strategy, and to grow out the cyber team with specialists covering off priority cyber and infosec domains. What this role involves: Review, develop, monitor and mature the overall cyber security strategy Using your judgement, growing out the cyber team in line with the strategy and its key priorities Enhance and drive the cloud security strategy pertaining to AWS and Azure Working with colleagues across software development, infrastructure, networks, data analysis and cloud - advising on cyber best practices Working with managed service providers and third-party security providers Overseeing alerts pulling through from their MSSP, alongside putting effective measures in place to enhance organisational security following pentests. Understanding what good looks like in cyber, and articulating this effectively with stakeholders across the business Working with external consultants on GRC activities What I'm looking for: Experience in a cybersecurity leadership role or a strategic cyber role would be ideal, but strong experience across cloud security or DevSecOps with the genuine ambition to progress into a strategic leadership role would also be feasible Whilst this role won't have you creating use-cases, runbooks and playbooks, you will need a hands-on understanding of commonplace cyber tools in order to face off to MSSPs, external providers and internal technical and non-technical colleagues Cloud security knowledge - AWS is the priority, Azure would also be useful GRC understanding - frameworks, best practice, policy development Ability to understand and properly react to pentest reports Ability to effectively communicate with technical and non-technical stakeholders up to board level Benefits A salary up to 75,000 National average pension Flexible hours Heavily subsidised on-site gym 25 days annual leave with buy and sell, plus bank holidays Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Lead Security Architect - Farnborough (Hybrid) - 100k - Highest Security Clearance Required Are you an experienced Security Architect looking to work on projects that genuinely make a difference? We're looking for a Lead Security Architect to join a growing engineering team delivering secure, mission-critical technology across highly regulated environments. This is an opportunity to work on complex programmes at the forefront of cloud, Kubernetes, DevSecOps and secure digital transformation, helping shape solutions that support critical government and defence capabilities. The Role As a Lead Security Architect, you'll provide technical leadership across multiple secure programmes, ensuring security is embedded throughout the delivery lifecycle. Working alongside Software Engineers, Infrastructure Engineers, DevSecOps specialists and Solution Architects, you'll design and assure secure architectures for both cloud and on-premise environments. You'll be responsible for: Leading security architecture across complex technical projects. Performing risk assessments using recognised methodologies such as NIST 800-53. Designing secure-by-design solutions for cloud-native and Kubernetes-based platforms. Producing security documentation including risk assessments, security policies, assurance artefacts and test plans. Advising technical teams on security controls, vulnerabilities and mitigation strategies. Supporting compliance with MOD security standards including JSP 604 and JSP 453. Working closely with stakeholders to ensure secure delivery throughout Agile development lifecycles. Providing strategic technical direction across security-focused initiatives. About You You'll be a confident Security Architect with experience designing secure solutions within highly regulated environments. You'll ideally have experience with: Security architecture and cyber security engineering. Risk management frameworks such as NIST 800-53. Secure-by-design methodologies. Cloud platforms including Azure and AWS. Kubernetes, Docker and container security. DevSecOps, CI/CD and Agile delivery practices. Authentication, cryptography, network security and endpoint protection. Producing security assurance documentation and technical reports. MOD or Defence security standards and accreditation processes. Working with secure or safety-critical systems. Exposure to technologies such as Apache Kafka, Apache NiFi, Node.js, TypeScript, MongoDB, AI or Machine Learning would also be beneficial. Security Clearance Due to the nature of the work, candidates must already hold, or be eligible to obtain, UK Security Clearance. Applicants should have the right to work in the UK and normally have lived in the UK continuously for at least five years. Lead Security Architect - Farnborough (Hybrid) - 100k - Highest Security Clearance Required
Jul 31, 2026
Full time
Lead Security Architect - Farnborough (Hybrid) - 100k - Highest Security Clearance Required Are you an experienced Security Architect looking to work on projects that genuinely make a difference? We're looking for a Lead Security Architect to join a growing engineering team delivering secure, mission-critical technology across highly regulated environments. This is an opportunity to work on complex programmes at the forefront of cloud, Kubernetes, DevSecOps and secure digital transformation, helping shape solutions that support critical government and defence capabilities. The Role As a Lead Security Architect, you'll provide technical leadership across multiple secure programmes, ensuring security is embedded throughout the delivery lifecycle. Working alongside Software Engineers, Infrastructure Engineers, DevSecOps specialists and Solution Architects, you'll design and assure secure architectures for both cloud and on-premise environments. You'll be responsible for: Leading security architecture across complex technical projects. Performing risk assessments using recognised methodologies such as NIST 800-53. Designing secure-by-design solutions for cloud-native and Kubernetes-based platforms. Producing security documentation including risk assessments, security policies, assurance artefacts and test plans. Advising technical teams on security controls, vulnerabilities and mitigation strategies. Supporting compliance with MOD security standards including JSP 604 and JSP 453. Working closely with stakeholders to ensure secure delivery throughout Agile development lifecycles. Providing strategic technical direction across security-focused initiatives. About You You'll be a confident Security Architect with experience designing secure solutions within highly regulated environments. You'll ideally have experience with: Security architecture and cyber security engineering. Risk management frameworks such as NIST 800-53. Secure-by-design methodologies. Cloud platforms including Azure and AWS. Kubernetes, Docker and container security. DevSecOps, CI/CD and Agile delivery practices. Authentication, cryptography, network security and endpoint protection. Producing security assurance documentation and technical reports. MOD or Defence security standards and accreditation processes. Working with secure or safety-critical systems. Exposure to technologies such as Apache Kafka, Apache NiFi, Node.js, TypeScript, MongoDB, AI or Machine Learning would also be beneficial. Security Clearance Due to the nature of the work, candidates must already hold, or be eligible to obtain, UK Security Clearance. Applicants should have the right to work in the UK and normally have lived in the UK continuously for at least five years. Lead Security Architect - Farnborough (Hybrid) - 100k - Highest Security Clearance Required
Cloud Security Consultant Up to 100,000 + Bonus + Excellent Benefits Location: UK Wide (Predominantly Remote) - London / Birmingham / Manchester / Newcaste / Glasglow Clearance: Active SC Clearance Required Secure the Cloud. Shape the Future! We're working with a global technology consultancy that's expanding its award-winning Cyber Security practice. They're looking for an experienced Cloud Security Consultant to help design and deliver secure cloud solutions for some of the UK's largest organisations. If you're passionate about cloud security, architecture and Secure by Design, this is an opportunity to work on high-profile transformation programmes using the latest cloud technologies. What You'll Be Doing Design secure architectures across AWS, Azure and hybrid cloud environments Develop cloud security strategies, governance and security standards Conduct threat modelling and security architecture reviews Embed security into cloud deployments through DevSecOps and automation Advise clients on best practice and modern cloud security technologies Collaborate with architects, engineers and security teams on large-scale cloud programmes What We're Looking For You'll have experience with several of the following: Cloud Security Architecture AWS, Azure and/or GCP Secure by Design & Threat Modelling Zero Trust principles DevSecOps & Infrastructure as Code Cloud Governance & IAM Relevant cloud security certifications (desirable) What's On Offer Up to 100,000 basic salary Performance bonus Excellent benefits package Predominantly remote working UK-wide office locations Industry-leading training and career progression Work on some of the UK's most exciting cloud transformation programmes Please Note Due to the nature of the work, active SC Clearance is required for this position. Interested? Apply today to learn more about this fantastic opportunity with one of the world's leading technology consultancies.
Jul 31, 2026
Full time
Cloud Security Consultant Up to 100,000 + Bonus + Excellent Benefits Location: UK Wide (Predominantly Remote) - London / Birmingham / Manchester / Newcaste / Glasglow Clearance: Active SC Clearance Required Secure the Cloud. Shape the Future! We're working with a global technology consultancy that's expanding its award-winning Cyber Security practice. They're looking for an experienced Cloud Security Consultant to help design and deliver secure cloud solutions for some of the UK's largest organisations. If you're passionate about cloud security, architecture and Secure by Design, this is an opportunity to work on high-profile transformation programmes using the latest cloud technologies. What You'll Be Doing Design secure architectures across AWS, Azure and hybrid cloud environments Develop cloud security strategies, governance and security standards Conduct threat modelling and security architecture reviews Embed security into cloud deployments through DevSecOps and automation Advise clients on best practice and modern cloud security technologies Collaborate with architects, engineers and security teams on large-scale cloud programmes What We're Looking For You'll have experience with several of the following: Cloud Security Architecture AWS, Azure and/or GCP Secure by Design & Threat Modelling Zero Trust principles DevSecOps & Infrastructure as Code Cloud Governance & IAM Relevant cloud security certifications (desirable) What's On Offer Up to 100,000 basic salary Performance bonus Excellent benefits package Predominantly remote working UK-wide office locations Industry-leading training and career progression Work on some of the UK's most exciting cloud transformation programmes Please Note Due to the nature of the work, active SC Clearance is required for this position. Interested? Apply today to learn more about this fantastic opportunity with one of the world's leading technology consultancies.
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London Secure SDLC SAST DAST Threat Modelling Cloud Security CI/CD Location: London (Hybrid - 8 days onsite per month) Contract: 12 Months + extension Rate: 500- 550 per day (Umbrella) The Opportunity We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment. Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely. This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment. Key Responsibilities Lead application security reviews across business-critical applications and cloud platforms. Conduct security architecture and secure design reviews. Perform application security risk assessments and define security requirements. Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies. Embed Secure SDLC principles into engineering teams. Integrate security tooling into CI/CD pipelines and DevSecOps processes. Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings. Work closely with development teams to prioritise vulnerability remediation. Define security testing requirements and support penetration testing activities. Produce security standards, technical guidance and best practice documentation. Act as the Application Security SME across multiple technology programmes. Essential Skills Application Security Secure Software Development Lifecycle (SSDLC) OWASP Top 10 Secure Coding Secure Design Reviews API Security REST APIs Microservices Security Application Security Risk Assessments Threat Modelling STRIDE MITRE ATT&CK Security Architecture Risk Assessments DevSecOps CI/CD Security GitHub Actions GitLab Jenkins Azure DevOps Security Automation Shift Left Security Security Testing SAST DAST SCA Vulnerability Management Penetration Testing Cloud Security AWS, Azure or GCP Kubernetes Docker Container Security Cloud Security Best Practices Security Tooling Experience with one or more of: Checkmarx Fortify SonarQube Veracode Semgrep Burp Suite OWASP ZAP Snyk Trivy Prisma Cloud Aqua Wiz Ideal Background You'll ideally have: 8+ years in Cyber Security Strong Application Security or DevSecOps experience Experience working directly with software engineering teams Experience embedding security into CI/CD pipelines Strong knowledge of Secure SDLC Experience conducting Threat Modelling sessions Excellent stakeholder management and communication skills Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment Contract Details 12-month contract 500- 600 per day (Umbrella) Hybrid working - 8 days onsite per month in London Immediate interview availability preferred Rates depend on experience and client requirements
Jul 31, 2026
Contractor
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London Secure SDLC SAST DAST Threat Modelling Cloud Security CI/CD Location: London (Hybrid - 8 days onsite per month) Contract: 12 Months + extension Rate: 500- 550 per day (Umbrella) The Opportunity We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment. Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely. This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment. Key Responsibilities Lead application security reviews across business-critical applications and cloud platforms. Conduct security architecture and secure design reviews. Perform application security risk assessments and define security requirements. Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies. Embed Secure SDLC principles into engineering teams. Integrate security tooling into CI/CD pipelines and DevSecOps processes. Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings. Work closely with development teams to prioritise vulnerability remediation. Define security testing requirements and support penetration testing activities. Produce security standards, technical guidance and best practice documentation. Act as the Application Security SME across multiple technology programmes. Essential Skills Application Security Secure Software Development Lifecycle (SSDLC) OWASP Top 10 Secure Coding Secure Design Reviews API Security REST APIs Microservices Security Application Security Risk Assessments Threat Modelling STRIDE MITRE ATT&CK Security Architecture Risk Assessments DevSecOps CI/CD Security GitHub Actions GitLab Jenkins Azure DevOps Security Automation Shift Left Security Security Testing SAST DAST SCA Vulnerability Management Penetration Testing Cloud Security AWS, Azure or GCP Kubernetes Docker Container Security Cloud Security Best Practices Security Tooling Experience with one or more of: Checkmarx Fortify SonarQube Veracode Semgrep Burp Suite OWASP ZAP Snyk Trivy Prisma Cloud Aqua Wiz Ideal Background You'll ideally have: 8+ years in Cyber Security Strong Application Security or DevSecOps experience Experience working directly with software engineering teams Experience embedding security into CI/CD pipelines Strong knowledge of Secure SDLC Experience conducting Threat Modelling sessions Excellent stakeholder management and communication skills Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment Contract Details 12-month contract 500- 600 per day (Umbrella) Hybrid working - 8 days onsite per month in London Immediate interview availability preferred Rates depend on experience and client requirements
As an M365 Consultant/Senior Consultant, you will help transform clients' cybersecurity posture by designing and implementing advanced Microsoft Threat Protection technologies. You will work directly with clients in a consulting capacity, supporting medium to large enterprise environments and contributing to robust Cyber Defence strategies across endpoints, identities, cloud, and collaboration platforms. Key Responsibilities Design and implement AV/EDR solutions (e.g., Microsoft Defender for Endpoint) to detect and respond to cyber threats across major operating systems. Protect email, messaging, and collaboration platforms from phishing, spear phishing, BEC, and identity-related attacks. Develop and maintain cyber defence use cases, correlation rules, and attack chain detections across disparate systems. Design, implement, and integrate SIEM solutions-particularly Microsoft Sentinel-into Security Operations. Perform threat hunting across endpoints, identities, networking, cloud, and collaboration platforms in the Microsoft ecosystem. Handle L2-level incidents leveraging Microsoft Sentinel and Microsoft Defender tools. Support incident response, triage, threat modelling, and vulnerability remediation within Azure-hosted environments. Create, run, and troubleshoot Azure Logic Apps, playbooks, and Sentinel automation components. Collaborate with business and security stakeholders to define and enhance security standards and improve security posture. . Technical Expertise Proven experience with Microsoft Sentinel (architecture, deployment, analytics rules, workbooks, playbooks); Microsoft Defender for Endpoint and Defender for Cloud; SIEM/SOC operations; Azure Logic Apps; vulnerability remediation; incident response. Threat Hunting & Detection Hands on experience using KQL, Microsoft Defender XDR, and threat intelligence sources to hunt threats and support investigations. Cyber Defence & Infrastructure Security Strong understanding of cyber defence concepts, infrastructure security, and troubleshooting across the Microsoft ecosystem. Methodology Familiarity with agile methodologies and backlog management. Collaboration & Communication Strong communication skills, ability to work with cross-functional teams, and experience in client-facing environments. Technologies Knowledge of Microsoft 365, Azure, Windows, Linux, and mobile operating systems. SC100 or equivalent desirable Characteristics for Success Consultative and collaborative mindset; strong relationship builder. Resilient, adaptable, intellectually curious. Passionate about Microsoft security technologies (M365 Threat Protection, Defender suite, O365, Identity). Problem solver, quality driven, self motivated, and innovative. At Avanade, we advance the world through the power of people and Microsoft. Join us to shape your skills and the future with bold ideas and innovative solutions. Our partnership with Microsoft and Accenture empowers you to unlock your full potential. Working at Avanade offers the chance to build a career path that suits your skills and interests and the freedom to be your authentic self. We are committed to your growth, well being, and success. This is where passion meets opportunity, technology meets humanity, and every challenge is a chance to make a genuine impact on colleagues, clients, and communities. Together, we do what matters.
Jul 30, 2026
Full time
As an M365 Consultant/Senior Consultant, you will help transform clients' cybersecurity posture by designing and implementing advanced Microsoft Threat Protection technologies. You will work directly with clients in a consulting capacity, supporting medium to large enterprise environments and contributing to robust Cyber Defence strategies across endpoints, identities, cloud, and collaboration platforms. Key Responsibilities Design and implement AV/EDR solutions (e.g., Microsoft Defender for Endpoint) to detect and respond to cyber threats across major operating systems. Protect email, messaging, and collaboration platforms from phishing, spear phishing, BEC, and identity-related attacks. Develop and maintain cyber defence use cases, correlation rules, and attack chain detections across disparate systems. Design, implement, and integrate SIEM solutions-particularly Microsoft Sentinel-into Security Operations. Perform threat hunting across endpoints, identities, networking, cloud, and collaboration platforms in the Microsoft ecosystem. Handle L2-level incidents leveraging Microsoft Sentinel and Microsoft Defender tools. Support incident response, triage, threat modelling, and vulnerability remediation within Azure-hosted environments. Create, run, and troubleshoot Azure Logic Apps, playbooks, and Sentinel automation components. Collaborate with business and security stakeholders to define and enhance security standards and improve security posture. . Technical Expertise Proven experience with Microsoft Sentinel (architecture, deployment, analytics rules, workbooks, playbooks); Microsoft Defender for Endpoint and Defender for Cloud; SIEM/SOC operations; Azure Logic Apps; vulnerability remediation; incident response. Threat Hunting & Detection Hands on experience using KQL, Microsoft Defender XDR, and threat intelligence sources to hunt threats and support investigations. Cyber Defence & Infrastructure Security Strong understanding of cyber defence concepts, infrastructure security, and troubleshooting across the Microsoft ecosystem. Methodology Familiarity with agile methodologies and backlog management. Collaboration & Communication Strong communication skills, ability to work with cross-functional teams, and experience in client-facing environments. Technologies Knowledge of Microsoft 365, Azure, Windows, Linux, and mobile operating systems. SC100 or equivalent desirable Characteristics for Success Consultative and collaborative mindset; strong relationship builder. Resilient, adaptable, intellectually curious. Passionate about Microsoft security technologies (M365 Threat Protection, Defender suite, O365, Identity). Problem solver, quality driven, self motivated, and innovative. At Avanade, we advance the world through the power of people and Microsoft. Join us to shape your skills and the future with bold ideas and innovative solutions. Our partnership with Microsoft and Accenture empowers you to unlock your full potential. Working at Avanade offers the chance to build a career path that suits your skills and interests and the freedom to be your authentic self. We are committed to your growth, well being, and success. This is where passion meets opportunity, technology meets humanity, and every challenge is a chance to make a genuine impact on colleagues, clients, and communities. Together, we do what matters.
Senior Cyber Security Analyst - Application Security / DevSecOps / Secure Design/ SAST, DAST - London Contract 12 Months Hybrid 8 Days onsite per month - the rest is remote working Inside of IR35 must use umbrella £600 per day We are supporting a leading international organisation in the search for a Senior Cyber Security Analyst to join a high-performing security engineering and assurance team click apply for full job details
May 29, 2026
Seasonal
Senior Cyber Security Analyst - Application Security / DevSecOps / Secure Design/ SAST, DAST - London Contract 12 Months Hybrid 8 Days onsite per month - the rest is remote working Inside of IR35 must use umbrella £600 per day We are supporting a leading international organisation in the search for a Senior Cyber Security Analyst to join a high-performing security engineering and assurance team click apply for full job details