• Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
  • Sign in
  • Sign up
  • Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

90 jobs found

Email me jobs like this
Refine Search
Current Search
cyber security vulnerability management lead
Head of Information Security
jobr.pro
About Moneybox At Moneybox, our mission is to give everyone the means to get more out of life. We're guided by our belief that wealth isn't about the money, it's about the means to more - more freedom, opportunities, possibilities, and peace of mind. Moneybox is an award winning wealth management platform, helping over one and a half million people build wealth throughout their lives, whether they're saving and investing, buying their first home, or planning for retirement. Job Brief Moneybox is looking for a Head of Information Security to lead and mature our information security function. Reporting to the Engineering Director, this role will own Moneybox's Information Security Programme and be accountable for reducing security risk across our people, systems, products and third party ecosystem as the business continues to scale. This is a hands on leadership role. The successful candidate will need to think strategically, set direction and influence senior stakeholders whilst also being close enough to the detail to get things done. We are looking for someone who can build a small, high performing and nimble security function, using technology, automation and AI to increase the breadth, quality and pace of what the team can achieve. The role will suit an experienced information security leader who is pragmatic, commercially aware and focused on reducing meaningful risk, not creating unnecessary bureaucracy or replicating a big bank security model. What you'll do Owning and delivering Moneybox's information security strategy, roadmap and operating model. Leading the ongoing development of Moneybox's Information Security Programme, using NIST CSF as the practical risk management framework while aligning with ISO 27001 for governance, control maturity and assurance. Reducing real security risk across Moneybox's technology estate, people processes, suppliers and products. Building a small, effective and high leverage security function that uses technology, automation and AI to scale its impact. Providing clear, practical security leadership to senior stakeholders, including regular reporting on security posture, risks, incidents and priorities. Making proportionate, risk based decisions that support business growth while protecting customers and the organisation. Developing, maintaining and embedding practical information security policies, standards and procedures. Leading security awareness and training programmes that improve behaviours and strengthen Moneybox's security culture. Owning Moneybox's security incident response framework, ensuring the business is prepared to identify, contain, respond to and recover from security incidents effectively. Overseeing vulnerability management, including scanning, remediation, patching and risk based prioritisation. Leading third party security risk management for key vendors, partners and technology providers. Defining and tracking security metrics that focus on risk reduction and meaningful outcomes, not vanity reporting. Partnering with Engineering and Product teams to ensure security is built into systems, services and ways of working. Monitoring emerging threats, regulatory expectations and industry practice, then applying them pragmatically to Moneybox's environment. Continuously improving the security function without adding unnecessary complexity or bureaucracy. Who you are A strategic but hands on information security leader. A doer who is comfortable owning outcomes directly, not just delegating, advising or writing papers. Pragmatic and risk led with strong judgement on where security effort will have the greatest impact. Comfortable working in a small, nimble team where leverage comes from focus, automation, technology and strong prioritisation. Able to separate meaningful security risk from theoretical or low value control activity. Commercially aware, with the ability to balance security, customer experience, regulation and delivery. Clear and concise with senior stakeholders, able to translate security issues into business impact. Collaborative and able to influence across Engineering, Compliance, Legal, Product, Workplace Technology and the wider business. Strong understanding of current and emerging threats, and how to manage them proportionately in a fast moving organisation. Interested in how AI and automation can improve security operations, assurance, monitoring, reporting and decision making. Motivated by building a high quality security function that fits Moneybox, rather than importing a large enterprise or big bank model. Experience & Skills Proven experience leading or significantly contributing to an information security function. Strong working knowledge of risk based security management and the NIST Cyber Security Framework. Experience developing and delivering information security strategy, roadmaps, policies and controls. Practical knowledge of security technologies and business systems, including identity and access management, SIEM, endpoint security, cloud security, vulnerability management and remote working technologies. Experience using technology, automation or AI to improve security outcomes or operational efficiency. Experience managing security risk in cloud based environments, ideally including Azure. Strong understanding of third party security risk management. Experience with incident response planning, testing and improvement. Experience reporting security risks, controls and metrics to senior management. Strong communication skills, with the ability to translate technical security issues into clear business risks, recommendations and trade offs for senior stakeholders. Good understanding of financial services security, risk and regulatory expectations. Demonstrated leadership skills with the ability to influence, collaborate and drive change across teams. Excellent written and spoken English. Relevant professional certifications such as CISSP, CISM or CRISC are desirable, but practical judgement and delivery experience matter more. What's in it for you Opportunity to join a fast growing, award winning and super ambitious company. Work with a friendly team of highly motivated individuals. Be in an environment where you are listened to and can actually have an impact. Thriving collaborative and inclusive company culture. Competitive remuneration package. Company pension scheme. Company bonus scheme. Hybrid working environment. Home office furniture allowance. Personal annual learning and development budget. Private medical insurance. Health cash plan (cashback on visits to the dentist & opticians etc). Cycle to work scheme. Wellhub subscription to a variety of gyms and wellbeing apps. Enhanced parental pay & leave. 25 days holiday + bank holidays with additional days added with length of service. This is a hybrid role. Our office is in London, by the Oxo Tower. Our Commitment to DE&I At Moneybox, we promote, support and celebrate inclusion, diversity and equity for all, so that everyone can bring their full selves to work. We believe that diversity drives innovation, and that if our team is representative of our community of customers, we can better support their needs. To ensure our recruitment processes provide an equal opportunity for all applicants to succeed, we encourage you to let us know if there are any adjustments that we can make. We are open minded and always willing to go the extra mile to ensure all applicants can present their full self and potential. Working Policy We have a hybrid policy that includes 2 days from our London office and 3 from home. If the role states it is either hybrid or remote candidates must be based within the UK. Visa Sponsorship At this time we cannot offer visa sponsorship for this role and we cannot consider overseas applications. Please read before you apply! Please note if offered a position, the offer is conditional and subject to the receipt of satisfactory pre employment checks which we will conduct such as criminal record and adverse credit history checks. As a regulated financial business, an adverse financial history could impact your suitability for the role. If you are aware of anything that could affect your suitability for the role, please let us know in advance. Data Protection By sending us your application you acknowledge and agree to Moneybox using your personal data as described below. We collect applicants' personal data to manage our recruitment related activities. Consequently, we may use your personal data to evaluate your application, to select and shortlist applicants, to set up and conduct interviews and tests, to evaluate and assess the results, and as is otherwise needed in the recruitment process generally. We do not share your personal data with unauthorised third parties.
Aug 27, 2026
Full time
About Moneybox At Moneybox, our mission is to give everyone the means to get more out of life. We're guided by our belief that wealth isn't about the money, it's about the means to more - more freedom, opportunities, possibilities, and peace of mind. Moneybox is an award winning wealth management platform, helping over one and a half million people build wealth throughout their lives, whether they're saving and investing, buying their first home, or planning for retirement. Job Brief Moneybox is looking for a Head of Information Security to lead and mature our information security function. Reporting to the Engineering Director, this role will own Moneybox's Information Security Programme and be accountable for reducing security risk across our people, systems, products and third party ecosystem as the business continues to scale. This is a hands on leadership role. The successful candidate will need to think strategically, set direction and influence senior stakeholders whilst also being close enough to the detail to get things done. We are looking for someone who can build a small, high performing and nimble security function, using technology, automation and AI to increase the breadth, quality and pace of what the team can achieve. The role will suit an experienced information security leader who is pragmatic, commercially aware and focused on reducing meaningful risk, not creating unnecessary bureaucracy or replicating a big bank security model. What you'll do Owning and delivering Moneybox's information security strategy, roadmap and operating model. Leading the ongoing development of Moneybox's Information Security Programme, using NIST CSF as the practical risk management framework while aligning with ISO 27001 for governance, control maturity and assurance. Reducing real security risk across Moneybox's technology estate, people processes, suppliers and products. Building a small, effective and high leverage security function that uses technology, automation and AI to scale its impact. Providing clear, practical security leadership to senior stakeholders, including regular reporting on security posture, risks, incidents and priorities. Making proportionate, risk based decisions that support business growth while protecting customers and the organisation. Developing, maintaining and embedding practical information security policies, standards and procedures. Leading security awareness and training programmes that improve behaviours and strengthen Moneybox's security culture. Owning Moneybox's security incident response framework, ensuring the business is prepared to identify, contain, respond to and recover from security incidents effectively. Overseeing vulnerability management, including scanning, remediation, patching and risk based prioritisation. Leading third party security risk management for key vendors, partners and technology providers. Defining and tracking security metrics that focus on risk reduction and meaningful outcomes, not vanity reporting. Partnering with Engineering and Product teams to ensure security is built into systems, services and ways of working. Monitoring emerging threats, regulatory expectations and industry practice, then applying them pragmatically to Moneybox's environment. Continuously improving the security function without adding unnecessary complexity or bureaucracy. Who you are A strategic but hands on information security leader. A doer who is comfortable owning outcomes directly, not just delegating, advising or writing papers. Pragmatic and risk led with strong judgement on where security effort will have the greatest impact. Comfortable working in a small, nimble team where leverage comes from focus, automation, technology and strong prioritisation. Able to separate meaningful security risk from theoretical or low value control activity. Commercially aware, with the ability to balance security, customer experience, regulation and delivery. Clear and concise with senior stakeholders, able to translate security issues into business impact. Collaborative and able to influence across Engineering, Compliance, Legal, Product, Workplace Technology and the wider business. Strong understanding of current and emerging threats, and how to manage them proportionately in a fast moving organisation. Interested in how AI and automation can improve security operations, assurance, monitoring, reporting and decision making. Motivated by building a high quality security function that fits Moneybox, rather than importing a large enterprise or big bank model. Experience & Skills Proven experience leading or significantly contributing to an information security function. Strong working knowledge of risk based security management and the NIST Cyber Security Framework. Experience developing and delivering information security strategy, roadmaps, policies and controls. Practical knowledge of security technologies and business systems, including identity and access management, SIEM, endpoint security, cloud security, vulnerability management and remote working technologies. Experience using technology, automation or AI to improve security outcomes or operational efficiency. Experience managing security risk in cloud based environments, ideally including Azure. Strong understanding of third party security risk management. Experience with incident response planning, testing and improvement. Experience reporting security risks, controls and metrics to senior management. Strong communication skills, with the ability to translate technical security issues into clear business risks, recommendations and trade offs for senior stakeholders. Good understanding of financial services security, risk and regulatory expectations. Demonstrated leadership skills with the ability to influence, collaborate and drive change across teams. Excellent written and spoken English. Relevant professional certifications such as CISSP, CISM or CRISC are desirable, but practical judgement and delivery experience matter more. What's in it for you Opportunity to join a fast growing, award winning and super ambitious company. Work with a friendly team of highly motivated individuals. Be in an environment where you are listened to and can actually have an impact. Thriving collaborative and inclusive company culture. Competitive remuneration package. Company pension scheme. Company bonus scheme. Hybrid working environment. Home office furniture allowance. Personal annual learning and development budget. Private medical insurance. Health cash plan (cashback on visits to the dentist & opticians etc). Cycle to work scheme. Wellhub subscription to a variety of gyms and wellbeing apps. Enhanced parental pay & leave. 25 days holiday + bank holidays with additional days added with length of service. This is a hybrid role. Our office is in London, by the Oxo Tower. Our Commitment to DE&I At Moneybox, we promote, support and celebrate inclusion, diversity and equity for all, so that everyone can bring their full selves to work. We believe that diversity drives innovation, and that if our team is representative of our community of customers, we can better support their needs. To ensure our recruitment processes provide an equal opportunity for all applicants to succeed, we encourage you to let us know if there are any adjustments that we can make. We are open minded and always willing to go the extra mile to ensure all applicants can present their full self and potential. Working Policy We have a hybrid policy that includes 2 days from our London office and 3 from home. If the role states it is either hybrid or remote candidates must be based within the UK. Visa Sponsorship At this time we cannot offer visa sponsorship for this role and we cannot consider overseas applications. Please read before you apply! Please note if offered a position, the offer is conditional and subject to the receipt of satisfactory pre employment checks which we will conduct such as criminal record and adverse credit history checks. As a regulated financial business, an adverse financial history could impact your suitability for the role. If you are aware of anything that could affect your suitability for the role, please let us know in advance. Data Protection By sending us your application you acknowledge and agree to Moneybox using your personal data as described below. We collect applicants' personal data to manage our recruitment related activities. Consequently, we may use your personal data to evaluate your application, to select and shortlist applicants, to set up and conduct interviews and tests, to evaluate and assess the results, and as is otherwise needed in the recruitment process generally. We do not share your personal data with unauthorised third parties.
Customer Success Manager
OneClickComply
LocationSunderland, United Kingdom# Customer Success Manager at OneClickComplyLocationSunderland, United KingdomSalary£32500 - £60000 /yearJob TypeFull-timeDate PostedApril 30th, 2026Apply NowOneClickComply is changing how businesses think about cybersecurity compliance. We've built a platform that automates the hard parts - technical control implementation, policy generation, continuous monitoring, and real-time audit evidence - so that achieving certifications like ISO 27001, SOC 2, Cyber Essentials, and CIS v8 takes weeks instead of months. We work with a growing network of audit and enablement partners and serve clients across every industry who need to prove they take security seriously.We're a small, fast-moving team where your ideas don't get lost in layers of hierarchy. If you've ever been frustrated by how unnecessarily painful compliance can be, you'll understand exactly why we exist. The Opportunity This role puts you right at the heart of the client experience. You'll own the post-sale relationship across every channel - live chat, phone, video calls, and email - making sure every customer gets real, measurable value from our platform and feels genuinely supported from their very first onboarding call through to renewal and beyond.You'll be the person our clients turn to when they need help navigating the platform, understanding where they are on their compliance journey, or figuring out what comes next. When they need deeper technical guidance, you'll bring in our Security Compliance Specialists. When they're ready for penetration testing or a formal audit, you'll make the introductions to the right enablement partners. You're the thread that ties the whole experience together.This isn't a passive support role. You'll have genuine influence over how we onboard, engage, and grow our client base - and over the direction of the customer success function as we scale. There's also a real financial incentive to grow accounts: with a base salary of £32,500 plus uncapped commission on upsells, your OTE will be in the region of £60,000. What You'll Be Doing Owning the client relationship across every touchpoint. You'll manage a portfolio of B2B accounts, providing responsive, high-quality support via live chat, telephone, email, and scheduled video calls. You'll be the consistent, trusted point of contact that clients know they can rely on - whether it's a quick question on chat or a detailed walkthrough over the phone. Running onboarding that sets clients up for success . You'll lead onboarding calls and implementation sessions for every new client, walking them through platform configuration, control setup, dashboards, and integrations. You'll build and refine onboarding playbooks so that every client's first experience is smooth, structured, and confidence-building. Working hand in hand with our Security Compliance Specialists . You'll be the first point of contact for clients, triaging their needs and bringing in our Compliance Advisory team when deeper technical or framework-specific expertise is required. You'll stay close to those conversations so you always understand where each client is on their journey and can follow up effectively. Connecting clients with the right enablement partners . When clients are ready for penetration testing, vulnerability assessments, formal audits, or other specialist services, you'll make warm introductions to our network of trusted enablement partners - including penetration testers, auditors, and certification bodies. You'll coordinate scheduling, manage expectations on both sides, and make sure the handoff is seamless. Delivering webinars and group enablement . You'll plan and host regular webinars covering platform features, compliance best practices, framework updates, and tips for getting the most from OneClickComply. These sessions will help scale your impact beyond one-to-one interactions and position us as a trusted voice in the compliance space. Conducting regular check-ins and business reviews . You'll run quarterly business reviews with key accounts, track adoption metrics and health scores, and make sure every client has a clear path to their compliance goals. You'll stay ahead of churn risk by spotting disengagement early and acting on it. Driving upsell and expansion revenue . You'll identify opportunities to expand accounts - whether that's additional frameworks, more seats, or premium services - and you'll be rewarded for it. Commission on successful upsells forms a meaningful part of your compensation, so the better your clients do, the better you do. Being the voice of the customer internally . You'll work closely with product, engineering, and sales to relay what clients are asking for, where they're getting stuck, and what would make the biggest difference to their experience. Your insights will directly shape the roadmap. Writing support articles and client-facing content . You'll build out our knowledge base by writing clear, practical support articles, how-to guides, and FAQs that help clients self-serve and get to value faster. You'll also produce walkthrough videos, best-practice materials, and webinar follow-up content - reducing inbound support volume and giving every client the resources to succeed on their own terms. What We're Looking For You'll have at least 2 years of experience in a customer success, account management, or client-facing role within a B2B SaaS environment. This is a firm requirement - we need someone who already understands the rhythms of SaaS onboarding, adoption, renewal cycles, and the metrics that matter.You're confident and personable on the phone and on camera. You're the kind of person who can jump from a live chat conversation to an onboarding call to a webinar and bring the same energy and clarity to each. You build relationships quickly and earn trust by being organised, proactive, and genuinely helpful.You're a strong writer. Whether it's a support article, a follow-up email, or a webinar script, you can take something complex and make it clear and practical without dumbing it down.You're comfortable having strategic conversations with senior stakeholders and equally happy rolling up your sleeves for a hands-on platform walkthrough with an end user. You've got a track record of identifying and closing upsell or expansion opportunities, and you're motivated by a compensation model that rewards you for growing accounts.Experience in cybersecurity, compliance, GRC, or RegTech is a strong plus but not essential - if you're a quick learner with a genuine curiosity about the space, we'll get you up to speed. Familiarity with frameworks like ISO 27001, SOC 2, or Cyber Essentials is a bonus.You'll thrive here if you're naturally data-minded, comfortable using CRM and CS tools to manage your book of business, and energised by the challenge of building processes in a company that's still defining them. Compensation £32,500 base salary plus uncapped commission on upsell and expansion revenue, with on-target earnings (OTE) in the region of £60,000. Your earning potential grows as your accounts grow. Why Join Us You'll be joining at a stage where you can genuinely shape how customer success works at OneClickComply. Your understanding of what clients need won't just improve retention - it will directly influence how the product evolves. There's no red tape, no death by committee. Just a team that cares about making compliance less painful for everyone. The Benefits We've put together a benefits package that we think goes well beyond what you'd expect from a company our size. Your health and wellbeing come first. You and your family get 24/7 access to GP appointments and prescriptions, unlimited telephone, face-to-face, and video counselling, virtual physiotherapy, and unlimited eye testing. You'll also have access to virtual gym classes and discounted
Aug 26, 2026
Full time
LocationSunderland, United Kingdom# Customer Success Manager at OneClickComplyLocationSunderland, United KingdomSalary£32500 - £60000 /yearJob TypeFull-timeDate PostedApril 30th, 2026Apply NowOneClickComply is changing how businesses think about cybersecurity compliance. We've built a platform that automates the hard parts - technical control implementation, policy generation, continuous monitoring, and real-time audit evidence - so that achieving certifications like ISO 27001, SOC 2, Cyber Essentials, and CIS v8 takes weeks instead of months. We work with a growing network of audit and enablement partners and serve clients across every industry who need to prove they take security seriously.We're a small, fast-moving team where your ideas don't get lost in layers of hierarchy. If you've ever been frustrated by how unnecessarily painful compliance can be, you'll understand exactly why we exist. The Opportunity This role puts you right at the heart of the client experience. You'll own the post-sale relationship across every channel - live chat, phone, video calls, and email - making sure every customer gets real, measurable value from our platform and feels genuinely supported from their very first onboarding call through to renewal and beyond.You'll be the person our clients turn to when they need help navigating the platform, understanding where they are on their compliance journey, or figuring out what comes next. When they need deeper technical guidance, you'll bring in our Security Compliance Specialists. When they're ready for penetration testing or a formal audit, you'll make the introductions to the right enablement partners. You're the thread that ties the whole experience together.This isn't a passive support role. You'll have genuine influence over how we onboard, engage, and grow our client base - and over the direction of the customer success function as we scale. There's also a real financial incentive to grow accounts: with a base salary of £32,500 plus uncapped commission on upsells, your OTE will be in the region of £60,000. What You'll Be Doing Owning the client relationship across every touchpoint. You'll manage a portfolio of B2B accounts, providing responsive, high-quality support via live chat, telephone, email, and scheduled video calls. You'll be the consistent, trusted point of contact that clients know they can rely on - whether it's a quick question on chat or a detailed walkthrough over the phone. Running onboarding that sets clients up for success . You'll lead onboarding calls and implementation sessions for every new client, walking them through platform configuration, control setup, dashboards, and integrations. You'll build and refine onboarding playbooks so that every client's first experience is smooth, structured, and confidence-building. Working hand in hand with our Security Compliance Specialists . You'll be the first point of contact for clients, triaging their needs and bringing in our Compliance Advisory team when deeper technical or framework-specific expertise is required. You'll stay close to those conversations so you always understand where each client is on their journey and can follow up effectively. Connecting clients with the right enablement partners . When clients are ready for penetration testing, vulnerability assessments, formal audits, or other specialist services, you'll make warm introductions to our network of trusted enablement partners - including penetration testers, auditors, and certification bodies. You'll coordinate scheduling, manage expectations on both sides, and make sure the handoff is seamless. Delivering webinars and group enablement . You'll plan and host regular webinars covering platform features, compliance best practices, framework updates, and tips for getting the most from OneClickComply. These sessions will help scale your impact beyond one-to-one interactions and position us as a trusted voice in the compliance space. Conducting regular check-ins and business reviews . You'll run quarterly business reviews with key accounts, track adoption metrics and health scores, and make sure every client has a clear path to their compliance goals. You'll stay ahead of churn risk by spotting disengagement early and acting on it. Driving upsell and expansion revenue . You'll identify opportunities to expand accounts - whether that's additional frameworks, more seats, or premium services - and you'll be rewarded for it. Commission on successful upsells forms a meaningful part of your compensation, so the better your clients do, the better you do. Being the voice of the customer internally . You'll work closely with product, engineering, and sales to relay what clients are asking for, where they're getting stuck, and what would make the biggest difference to their experience. Your insights will directly shape the roadmap. Writing support articles and client-facing content . You'll build out our knowledge base by writing clear, practical support articles, how-to guides, and FAQs that help clients self-serve and get to value faster. You'll also produce walkthrough videos, best-practice materials, and webinar follow-up content - reducing inbound support volume and giving every client the resources to succeed on their own terms. What We're Looking For You'll have at least 2 years of experience in a customer success, account management, or client-facing role within a B2B SaaS environment. This is a firm requirement - we need someone who already understands the rhythms of SaaS onboarding, adoption, renewal cycles, and the metrics that matter.You're confident and personable on the phone and on camera. You're the kind of person who can jump from a live chat conversation to an onboarding call to a webinar and bring the same energy and clarity to each. You build relationships quickly and earn trust by being organised, proactive, and genuinely helpful.You're a strong writer. Whether it's a support article, a follow-up email, or a webinar script, you can take something complex and make it clear and practical without dumbing it down.You're comfortable having strategic conversations with senior stakeholders and equally happy rolling up your sleeves for a hands-on platform walkthrough with an end user. You've got a track record of identifying and closing upsell or expansion opportunities, and you're motivated by a compensation model that rewards you for growing accounts.Experience in cybersecurity, compliance, GRC, or RegTech is a strong plus but not essential - if you're a quick learner with a genuine curiosity about the space, we'll get you up to speed. Familiarity with frameworks like ISO 27001, SOC 2, or Cyber Essentials is a bonus.You'll thrive here if you're naturally data-minded, comfortable using CRM and CS tools to manage your book of business, and energised by the challenge of building processes in a company that's still defining them. Compensation £32,500 base salary plus uncapped commission on upsell and expansion revenue, with on-target earnings (OTE) in the region of £60,000. Your earning potential grows as your accounts grow. Why Join Us You'll be joining at a stage where you can genuinely shape how customer success works at OneClickComply. Your understanding of what clients need won't just improve retention - it will directly influence how the product evolves. There's no red tape, no death by committee. Just a team that cares about making compliance less painful for everyone. The Benefits We've put together a benefits package that we think goes well beyond what you'd expect from a company our size. Your health and wellbeing come first. You and your family get 24/7 access to GP appointments and prescriptions, unlimited telephone, face-to-face, and video counselling, virtual physiotherapy, and unlimited eye testing. You'll also have access to virtual gym classes and discounted
Vice President, Risk and Control - Digital Engineering
MUFG Bank, Ltd
Vice President, Risk and Control - Digital EngineeringApplylocations: Londontime type: Full timeposted on: Posted Todayjob requisition id: -WD Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.Join MUFG, where being inspired is expected and making a meaningful impact is rewarded. Accountable for defining, creating and governing the Digital Engineering Risk and Control strategy in accordance with the wider EMEA Technology IT Risk and Control vision and strategy and risk appetite Accountable for defining the Digital Engineering Solutions and Services risk appetite and framework in accordance with the overall Technology departments risk appetite and tolerance framework, managing the departments operational, regulatory and financial risk Define and evolve the Digital Engineering Services and Solutions Key Risk Indicators' and Controls and govern accordingly Present the department's risk landscape, providing proactive oversight and prioritisation to ensure timely closure of issue Run the departments Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of Digital Engineering Services and Solutions and the Extended Leadership Team Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress Primary contact for all risk, control and audit issues across all Digital Engineering Solutions and Services teams Provide assurance over the department's controls design and effectiveness, ensuring controls are proportionate and embedded in day to day department activity Provide proactive assurance around risk management through appropriate data driven monitoring and through the implementation of structured sampling techniques to validate that controls are functioning as intended before failure Educate and lead the Digital Engineering Staff defining best practice operations and governance in line with industry and company standards Work in partnership with the Digital Engineering Solutions and Services Product and Platform owners, challenging and advising on risk management for new products, processes and change programmes. Provide risk-based decision making, supporting the department to make informed, risk-based decisions by providing an aggregated view of risk exposures Run the departments Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of Digital Engineering Services and Solutions and the Extended Leadership Team Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department Responsible for managing Issue Management on behalf Digital Engineering Services and Solutions department Handle potential sensitive information relating to Cyber Security events and assessments on behalf of Digital Engineering Services and Solutions Work across all areas of the Digital Engineering Services and Solutions department to ensure the Digital Engineering Control & Governance team provides necessary support services, oversight function and governance capabilities to all other extended leadership teams and stakeholders. Responsible for building strong relationships across the Bank and Securities functions, underpinned by trust and the core values of the bank. Developing strong relationships with key stakeholders such as IT Risk & Control, Cyber Security, other technology pillars, Operational Risk, Internal Audit, Compliance and external parties where applicable A senior role, that plays a pivotal part in strengthening a proactive, inclusive risk culture leading with example of the right leadership, culture and behaviours that are required in the bank. KEY RESPONSIBILITIES Digital Engineering Solutions and Services Governance Oversee Digital Engineering Services and Solutions relationship with IT Risk and 3rd parties for all external audits and assessments. Oversee Digital Engineering Services and Solutions relationship with IT Risk for all internal audits which have an Infrastructure or Service Management aspect. Ensure strong governance, structures and processes are in place to support effective operational risk and control management across the department Accountable for managing Open Issues on behalf of the Digital Engineering Services and Solutions department, tracking and ensuring proactive remediation and timely Support Digital Engineering Solutions and Services extended leadership teams with creation/attestation of key controls against the Operational Risk Framework. Manage engagement with stakeholders to design, plan and deliver remediation actions for control deficiencies. Oversee risk identification and mitigation efforts, ensuring understanding of strategic goals Ensure departments adherence to internal policies and external regulatory requirement Manage complex risk related loss events, conducting root cause analysis, working with Product and Platform owners to develop response plans Perform applicable operational control checks across Infrastructure and engage with other areas of Technology when required Work in partnership with the departments Incident management and Threat and Vulnerability team to detect and address vulnerabilities Ensure that the team operates in a controlled manner in accordance with standards and procedures whilst adhering to all related security and compliance procedures In conjunction with IT Risk, Security and Control, ensure that all regulatory requirements are fully complied with, including SOX assessments and appropriate defences and controls are in place to deal with all cyber risks Execute risk governance across all Digital Engineering Solutions and Services verticals. Provide support to Digital Engineering Services and Solutions for pen test findings Produce and manage Digital Engineering Solutions and Services owned Key Risk Indicators. Support disaster recovery exercises, ensuring new services are documented and deployed with BCP/DR in mind Provide advisory assistance to IT Risk and Control relating to My Access Live (MaL) and Access Management processes, acting as input into review processes with particular emphasis on Digital Engineering related platforms Input into Incident Management Process where appropriate Support new applications as and when released to the business Escalate potential service issues to the Management Produce regular risk management data for Management. Chair the Departments Risk Oversight Committee Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department. Culture and Leadership Support development of team with a strong focus on building future capabilities Lead and champion MUFG's inclusive, diverse, and values-led culture while fostering a growth mindset to embrace new technologies, industry advancements, and innovative use cases Ensure appropriate risk awareness training is in place across the department to fulfil current and future requirements Lead and promote a dynamic, delivery driven culture that works alongside business units to provide responsive resolutions and value driven solutions Build and nurture strong relationships with internal and external stakeholders, including business teams, to promote collaboration, understand industry's best practices, and influence positive change across the organization Support location strategies prescribed from MUFG and enable transitions (where appropriate) seamlessly WORK EXPERIENCE Essential: Extensive experience leading and managing risk and control and teams across multiple regions within a within a regulated environment. Extensive proficiency in scenario analysis and developing mitigation strategies Experience representing risk and control on behalf of a large Technology department to an Executive level audience A strong track record of engaging credibly with Executives providing confident challenge and clear, decision ready insight. Experience of working alongside network, server, database, desktop; asset management and storage functions Experienced in dealing with vendors and third-party suppliers Strong track record of managing teams and building effective partnerships with peers Experience with comprehensive disaster recovery architecture and operations, including storage area network and redundant, highly available server and network architectures Experience with regulatory compliance issues as they apply to Infrastructure SKILLS AND EXPERIENCE Essential: Extensive experience leading a risk & control function in a financial services organisation. Extensive experience working with Risk Management tools e.g Open Pages Understanding of the COBIT, NIST 2 framework Extensive experience leading internal audit and external audit bodies. Proven track record of managing risk related issues for large departments, through the lifecycle of creation, reporting and remediation. Experience with industry-specific regulatory requirements and their impact on operational risk . click apply for full job details
Aug 26, 2026
Full time
Vice President, Risk and Control - Digital EngineeringApplylocations: Londontime type: Full timeposted on: Posted Todayjob requisition id: -WD Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.Join MUFG, where being inspired is expected and making a meaningful impact is rewarded. Accountable for defining, creating and governing the Digital Engineering Risk and Control strategy in accordance with the wider EMEA Technology IT Risk and Control vision and strategy and risk appetite Accountable for defining the Digital Engineering Solutions and Services risk appetite and framework in accordance with the overall Technology departments risk appetite and tolerance framework, managing the departments operational, regulatory and financial risk Define and evolve the Digital Engineering Services and Solutions Key Risk Indicators' and Controls and govern accordingly Present the department's risk landscape, providing proactive oversight and prioritisation to ensure timely closure of issue Run the departments Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of Digital Engineering Services and Solutions and the Extended Leadership Team Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress Primary contact for all risk, control and audit issues across all Digital Engineering Solutions and Services teams Provide assurance over the department's controls design and effectiveness, ensuring controls are proportionate and embedded in day to day department activity Provide proactive assurance around risk management through appropriate data driven monitoring and through the implementation of structured sampling techniques to validate that controls are functioning as intended before failure Educate and lead the Digital Engineering Staff defining best practice operations and governance in line with industry and company standards Work in partnership with the Digital Engineering Solutions and Services Product and Platform owners, challenging and advising on risk management for new products, processes and change programmes. Provide risk-based decision making, supporting the department to make informed, risk-based decisions by providing an aggregated view of risk exposures Run the departments Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of Digital Engineering Services and Solutions and the Extended Leadership Team Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department Responsible for managing Issue Management on behalf Digital Engineering Services and Solutions department Handle potential sensitive information relating to Cyber Security events and assessments on behalf of Digital Engineering Services and Solutions Work across all areas of the Digital Engineering Services and Solutions department to ensure the Digital Engineering Control & Governance team provides necessary support services, oversight function and governance capabilities to all other extended leadership teams and stakeholders. Responsible for building strong relationships across the Bank and Securities functions, underpinned by trust and the core values of the bank. Developing strong relationships with key stakeholders such as IT Risk & Control, Cyber Security, other technology pillars, Operational Risk, Internal Audit, Compliance and external parties where applicable A senior role, that plays a pivotal part in strengthening a proactive, inclusive risk culture leading with example of the right leadership, culture and behaviours that are required in the bank. KEY RESPONSIBILITIES Digital Engineering Solutions and Services Governance Oversee Digital Engineering Services and Solutions relationship with IT Risk and 3rd parties for all external audits and assessments. Oversee Digital Engineering Services and Solutions relationship with IT Risk for all internal audits which have an Infrastructure or Service Management aspect. Ensure strong governance, structures and processes are in place to support effective operational risk and control management across the department Accountable for managing Open Issues on behalf of the Digital Engineering Services and Solutions department, tracking and ensuring proactive remediation and timely Support Digital Engineering Solutions and Services extended leadership teams with creation/attestation of key controls against the Operational Risk Framework. Manage engagement with stakeholders to design, plan and deliver remediation actions for control deficiencies. Oversee risk identification and mitigation efforts, ensuring understanding of strategic goals Ensure departments adherence to internal policies and external regulatory requirement Manage complex risk related loss events, conducting root cause analysis, working with Product and Platform owners to develop response plans Perform applicable operational control checks across Infrastructure and engage with other areas of Technology when required Work in partnership with the departments Incident management and Threat and Vulnerability team to detect and address vulnerabilities Ensure that the team operates in a controlled manner in accordance with standards and procedures whilst adhering to all related security and compliance procedures In conjunction with IT Risk, Security and Control, ensure that all regulatory requirements are fully complied with, including SOX assessments and appropriate defences and controls are in place to deal with all cyber risks Execute risk governance across all Digital Engineering Solutions and Services verticals. Provide support to Digital Engineering Services and Solutions for pen test findings Produce and manage Digital Engineering Solutions and Services owned Key Risk Indicators. Support disaster recovery exercises, ensuring new services are documented and deployed with BCP/DR in mind Provide advisory assistance to IT Risk and Control relating to My Access Live (MaL) and Access Management processes, acting as input into review processes with particular emphasis on Digital Engineering related platforms Input into Incident Management Process where appropriate Support new applications as and when released to the business Escalate potential service issues to the Management Produce regular risk management data for Management. Chair the Departments Risk Oversight Committee Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department. Culture and Leadership Support development of team with a strong focus on building future capabilities Lead and champion MUFG's inclusive, diverse, and values-led culture while fostering a growth mindset to embrace new technologies, industry advancements, and innovative use cases Ensure appropriate risk awareness training is in place across the department to fulfil current and future requirements Lead and promote a dynamic, delivery driven culture that works alongside business units to provide responsive resolutions and value driven solutions Build and nurture strong relationships with internal and external stakeholders, including business teams, to promote collaboration, understand industry's best practices, and influence positive change across the organization Support location strategies prescribed from MUFG and enable transitions (where appropriate) seamlessly WORK EXPERIENCE Essential: Extensive experience leading and managing risk and control and teams across multiple regions within a within a regulated environment. Extensive proficiency in scenario analysis and developing mitigation strategies Experience representing risk and control on behalf of a large Technology department to an Executive level audience A strong track record of engaging credibly with Executives providing confident challenge and clear, decision ready insight. Experience of working alongside network, server, database, desktop; asset management and storage functions Experienced in dealing with vendors and third-party suppliers Strong track record of managing teams and building effective partnerships with peers Experience with comprehensive disaster recovery architecture and operations, including storage area network and redundant, highly available server and network architectures Experience with regulatory compliance issues as they apply to Infrastructure SKILLS AND EXPERIENCE Essential: Extensive experience leading a risk & control function in a financial services organisation. Extensive experience working with Risk Management tools e.g Open Pages Understanding of the COBIT, NIST 2 framework Extensive experience leading internal audit and external audit bodies. Proven track record of managing risk related issues for large departments, through the lifecycle of creation, reporting and remediation. Experience with industry-specific regulatory requirements and their impact on operational risk . click apply for full job details
Bensons for Beds
Infrastructure and Network Manager
Bensons for Beds Accrington, Lancashire
We are seeking an experienced and motivated Infrastructure and Network Manager to lead the management, security, and continuous improvement of our IT infrastructure and network services. This is an exciting opportunity to join a supportive team and play a key role in ensuring reliable, secure, and high-performing technology across the organisation. Main Responsibilities for Infrastructure and Network Manager Roles Managing and maintaining the organisation's IT infrastructure, networks, servers, systems, and cloud services Leading the design, implementation, and support of secure and resilient network solutions Monitoring infrastructure performance, availability, capacity, and security to identify and resolve issues proactively Managing network technologies including LAN, WAN, Wi-Fi, firewalls, VPNs, switching, and routing Overseeing infrastructure upgrades, system improvements, installations, and technology change programmes Developing and maintaining IT infrastructure, network, disaster recovery, and business continuity plans Managing suppliers, technology partners, service agreements, and infrastructure-related budgets Ensuring systems and networks comply with information security policies, data protection requirements, and industry best practice Leading the investigation and resolution of complex infrastructure and network incidents Maintaining accurate technical documentation, asset records, configurations, and operational procedures Providing technical leadership, guidance, and support to IT colleagues and wider teams Supporting the development and implementation of IT policies, standards, and service improvement plans Infrastructure and Network Manager Skills and Experience Required Proven experience managing IT infrastructure, networks, and technical services in a complex organisation Strong knowledge of network architecture, TCP/IP, DNS, DHCP, VPNs, firewalls, routing, switching, and wireless technologies Experience with server technologies, virtualisation, cloud platforms, backup solutions, and monitoring tools Knowledge of infrastructure security, vulnerability management, access controls, and cyber security principles Experience managing technical projects, suppliers, budgets, and service delivery Ability to troubleshoot complex technical issues and provide effective solutions Strong communication, leadership, organisation, and stakeholder management skills Ability to prioritise workloads, manage competing deadlines, and remain calm under pressure Relevant technical qualifications or certifications, such as Microsoft, Cisco, ITIL, or equivalent experience, are desirable Key Benefits of Working in Our IT Team Competitive salary and benefits package Supportive and inclusive working environment Opportunities for professional development, training, and career progression Access to the latest infrastructure, networking, and cloud technologies Life Assurance and pension contributions Employee wellbeing support and other company benefits Working Hours and Location Full-time position Working hours are generally Monday to Friday - 3 days per week on site Some flexibility may be required to support planned maintenance, infrastructure changes, or critical incidents Occasional on-call or out-of-hours support may be required Hybrid or office-based working options may be available, depending on business requirements Some travel to company sites or supplier locations is required Apply Now for Your Next Infrastructure and Network Manager Job If you are an experienced IT infrastructure and network professional with a passion for reliable, secure, and innovative technology services, apply today. We welcome applications from all backgrounds and are committed to creating an inclusive workplace where everyone can contribute and succeed.
Aug 26, 2026
Full time
We are seeking an experienced and motivated Infrastructure and Network Manager to lead the management, security, and continuous improvement of our IT infrastructure and network services. This is an exciting opportunity to join a supportive team and play a key role in ensuring reliable, secure, and high-performing technology across the organisation. Main Responsibilities for Infrastructure and Network Manager Roles Managing and maintaining the organisation's IT infrastructure, networks, servers, systems, and cloud services Leading the design, implementation, and support of secure and resilient network solutions Monitoring infrastructure performance, availability, capacity, and security to identify and resolve issues proactively Managing network technologies including LAN, WAN, Wi-Fi, firewalls, VPNs, switching, and routing Overseeing infrastructure upgrades, system improvements, installations, and technology change programmes Developing and maintaining IT infrastructure, network, disaster recovery, and business continuity plans Managing suppliers, technology partners, service agreements, and infrastructure-related budgets Ensuring systems and networks comply with information security policies, data protection requirements, and industry best practice Leading the investigation and resolution of complex infrastructure and network incidents Maintaining accurate technical documentation, asset records, configurations, and operational procedures Providing technical leadership, guidance, and support to IT colleagues and wider teams Supporting the development and implementation of IT policies, standards, and service improvement plans Infrastructure and Network Manager Skills and Experience Required Proven experience managing IT infrastructure, networks, and technical services in a complex organisation Strong knowledge of network architecture, TCP/IP, DNS, DHCP, VPNs, firewalls, routing, switching, and wireless technologies Experience with server technologies, virtualisation, cloud platforms, backup solutions, and monitoring tools Knowledge of infrastructure security, vulnerability management, access controls, and cyber security principles Experience managing technical projects, suppliers, budgets, and service delivery Ability to troubleshoot complex technical issues and provide effective solutions Strong communication, leadership, organisation, and stakeholder management skills Ability to prioritise workloads, manage competing deadlines, and remain calm under pressure Relevant technical qualifications or certifications, such as Microsoft, Cisco, ITIL, or equivalent experience, are desirable Key Benefits of Working in Our IT Team Competitive salary and benefits package Supportive and inclusive working environment Opportunities for professional development, training, and career progression Access to the latest infrastructure, networking, and cloud technologies Life Assurance and pension contributions Employee wellbeing support and other company benefits Working Hours and Location Full-time position Working hours are generally Monday to Friday - 3 days per week on site Some flexibility may be required to support planned maintenance, infrastructure changes, or critical incidents Occasional on-call or out-of-hours support may be required Hybrid or office-based working options may be available, depending on business requirements Some travel to company sites or supplier locations is required Apply Now for Your Next Infrastructure and Network Manager Job If you are an experienced IT infrastructure and network professional with a passion for reliable, secure, and innovative technology services, apply today. We welcome applications from all backgrounds and are committed to creating an inclusive workplace where everyone can contribute and succeed.
UK Biobank
Director of Information Security
UK Biobank Cheadle, Staffordshire
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
Aug 25, 2026
Full time
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
Isr Recruitment Limited
ICT Cyber and Information Security Manager
Isr Recruitment Limited Eaglescliffe, County Durham
The Opportunity Our client is looking to appoint an experienced ICT Cyber & Information Security Manager to take responsibility for a broad range of cyber security, information security, risk and compliance activities across the organisation. This is a key role within the Information Security function, providing the opportunity to take ownership of security activities ranging from the ICT Annual Delivery Plan through to major business growth initiatives, including site transitions and acquisitions across the UK and internationally. You'll work closely with internal teams, senior stakeholders and external partners to strengthen the organisation's cyber and information security posture, manage risk and ensure compliance with relevant security standards and legislation. The successful candidate will combine strong technical security knowledge with excellent governance, risk management and stakeholder-management skills. Skills and Experience: Experience leading cyber security, information security and/or compliance activities within a medium-to-large enterprise environment. Strong experience managing an enterprise information/cyber security risk register. Strong practical knowledge of Information Security Management Systems (ISMS). Experience implementing, maintaining and continually improving an ISMS. Experience preparing for and participating in internal and external security audits. Strong knowledge of ISO 27002 and experience delivering against its requirements. Strong knowledge of Cyber Essentials / Cyber Essentials Plus. Experience working with NIST security frameworks. Knowledge of CAF / Cyber Assessment Framework and its application to organisational security. Understanding of NIS2, GDPR and the Data Protection Act. Strong understanding of cyber security risk, governance, controls and remediation. Qualifications Professional security qualifications such as the following would be highly desirable: CISSP / CISM / CISA ISO 27001/27002-related qualifications Other recognised cyber security, information assurance or risk-management certifications Role and Responsibilities: Act as a key pillar of the organisation's Information Security programme, driving and managing cyber and information security activities. Work collaboratively with internal teams and external partners to deliver security initiatives and improvements. Develop, review and rehearse incident response plans, ensuring the organisation is prepared to detect, investigate and respond effectively to cyber incidents and data breaches. Work with relevant teams to review, test and improve Business Continuity, Recovery Time Objective (RTO) and Recovery Time Strategy (RTS) arrangements. Conduct and support security risk assessments and vulnerability assessments to identify threats, vulnerabilities and areas for improvement. Develop and implement appropriate risk mitigation strategies. Manage and maintain ICT Cyber & Data Security Risk Registers, ensuring risks are appropriately assessed, owned, mitigated and reported. Review, develop, implement and maintain cyber security, information security, data protection and compliance policies. Monitor changes in the regulatory and threat landscape and assess their impact on the organisation. Ensure compliance with relevant legislation, regulations, frameworks and security standards, including GDPR, Data Protection Act, NIS2, NIST, Cyber Essentials and ISO 27002. Lead and coordinate information security metrics, reporting and management information. Support and oversee offensive security activities, vulnerability management and security testing. Maintain and continuously improve the organisation's Information Security Management System (ISMS). Lead or participate in internal and external security audits and assessments, including ISO 27002 and Cyber Essentials Plus. Provide security input into business change, technology projects, acquisitions, site transitions and other strategic initiatives. Work with stakeholders to embed security by design across ICT and wider business activities. Applications: To learn more about our established client and this newly created role working as a IT Security Manager for our client based in the Teesside / County Durham area (with excellent flexible/remote working options available); please call and speak with Edward Laing here at ISR Recruitment to learn more or please send through a copy of your latest CV and/or share your online business profile for a call back in the very strictest of confidence.
Aug 24, 2026
Full time
The Opportunity Our client is looking to appoint an experienced ICT Cyber & Information Security Manager to take responsibility for a broad range of cyber security, information security, risk and compliance activities across the organisation. This is a key role within the Information Security function, providing the opportunity to take ownership of security activities ranging from the ICT Annual Delivery Plan through to major business growth initiatives, including site transitions and acquisitions across the UK and internationally. You'll work closely with internal teams, senior stakeholders and external partners to strengthen the organisation's cyber and information security posture, manage risk and ensure compliance with relevant security standards and legislation. The successful candidate will combine strong technical security knowledge with excellent governance, risk management and stakeholder-management skills. Skills and Experience: Experience leading cyber security, information security and/or compliance activities within a medium-to-large enterprise environment. Strong experience managing an enterprise information/cyber security risk register. Strong practical knowledge of Information Security Management Systems (ISMS). Experience implementing, maintaining and continually improving an ISMS. Experience preparing for and participating in internal and external security audits. Strong knowledge of ISO 27002 and experience delivering against its requirements. Strong knowledge of Cyber Essentials / Cyber Essentials Plus. Experience working with NIST security frameworks. Knowledge of CAF / Cyber Assessment Framework and its application to organisational security. Understanding of NIS2, GDPR and the Data Protection Act. Strong understanding of cyber security risk, governance, controls and remediation. Qualifications Professional security qualifications such as the following would be highly desirable: CISSP / CISM / CISA ISO 27001/27002-related qualifications Other recognised cyber security, information assurance or risk-management certifications Role and Responsibilities: Act as a key pillar of the organisation's Information Security programme, driving and managing cyber and information security activities. Work collaboratively with internal teams and external partners to deliver security initiatives and improvements. Develop, review and rehearse incident response plans, ensuring the organisation is prepared to detect, investigate and respond effectively to cyber incidents and data breaches. Work with relevant teams to review, test and improve Business Continuity, Recovery Time Objective (RTO) and Recovery Time Strategy (RTS) arrangements. Conduct and support security risk assessments and vulnerability assessments to identify threats, vulnerabilities and areas for improvement. Develop and implement appropriate risk mitigation strategies. Manage and maintain ICT Cyber & Data Security Risk Registers, ensuring risks are appropriately assessed, owned, mitigated and reported. Review, develop, implement and maintain cyber security, information security, data protection and compliance policies. Monitor changes in the regulatory and threat landscape and assess their impact on the organisation. Ensure compliance with relevant legislation, regulations, frameworks and security standards, including GDPR, Data Protection Act, NIS2, NIST, Cyber Essentials and ISO 27002. Lead and coordinate information security metrics, reporting and management information. Support and oversee offensive security activities, vulnerability management and security testing. Maintain and continuously improve the organisation's Information Security Management System (ISMS). Lead or participate in internal and external security audits and assessments, including ISO 27002 and Cyber Essentials Plus. Provide security input into business change, technology projects, acquisitions, site transitions and other strategic initiatives. Work with stakeholders to embed security by design across ICT and wider business activities. Applications: To learn more about our established client and this newly created role working as a IT Security Manager for our client based in the Teesside / County Durham area (with excellent flexible/remote working options available); please call and speak with Edward Laing here at ISR Recruitment to learn more or please send through a copy of your latest CV and/or share your online business profile for a call back in the very strictest of confidence.
Comtecs Ltd
Cyber Security Engineer - MS Sentinel, Defender, SSO, PKI, SC-100/200, CISSP
Comtecs Ltd
IT Cyber Security Specialist / Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team, supporting and continually improving cybersecurity across a global IT environment. Reporting to the Infrastructure Engineering Manager, you'll take ownership of cybersecurity controls and security architecture while working closely with Infrastructure Operations and other technology teams to identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across a complex infrastructure environment, identifying and mitigating security risks, supporting major cyber incidents and contributing to strategic security and infrastructure projects. You'll also help develop security awareness, business continuity capabilities and ongoing improvements to the firm's security controls. Key Responsibilities: Continuously review and improve the firm's cybersecurity posture from an infrastructure perspective and external security rating. Identify, assess and remediate vulnerabilities across hardware, software and infrastructure (Windows Server and Azure Cloud). Monitor emerging threats and lead or support Incident Response investigations and mitigation. Evaluate, test and recommend security enhancements, controls and threat prevention technologies. Identify security risks and exposures and develop measures to prevent future incidents. Lead CE+ accreditation and support security, risk and data protection requirements from a technical (Not GRC) perspective. Participate in and lead infrastructure lifecycle, security and technology projects. Provide 3rd Line / Major Incident support as a cybersecurity subject matter expert. Work with third-party suppliers and advise internal technical teams on security measures to resolve security and infrastructure issues. We're looking for experienced Cyber Security engineer with strong technical infrastructure knowledge and proven experience across incident response, threat monitoring and vulnerability management. You will possess: Extensive experience in a similar role blending Cyber Security with core Wintel Infrastructure and Azure cloud engineering. Strong knowledge of modern security architecture, threat prevention techniques and incident response. Strong Windows Server 2016/2019/2022 knowledge including Active Directory, DNS, DHCP, Intune, Group Policy, PKI, Entra and Azure SSO. Demonstrable experience across Cyber Security, Incident Response, Threat Monitoring and Vulnerability Management using tools such as MS Sentinel, MS Defender etc for threat hunting, vulnerability monitoring and security posture improvement. CISSP, CEH, CCNA Security, SC-100, SC200 or equivalent security certification. Experience designing, integrating and managing complex infrastructure and cloud solutions from a cyber security standpoint and advising technical infrastructure teams on security focussed designs and operations Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. Experience working with third-party providers across on-premise and cloud services. Strong planning skills and knowledge of ITIL processes and best practice. This is an excellent opportunity to join a highly regarded global organisation where you'll play a key role in strengthening cybersecurity across a complex international IT environment, combining hands-on security engineering, incident response and strategic infrastructure projects.
Aug 24, 2026
Full time
IT Cyber Security Specialist / Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team, supporting and continually improving cybersecurity across a global IT environment. Reporting to the Infrastructure Engineering Manager, you'll take ownership of cybersecurity controls and security architecture while working closely with Infrastructure Operations and other technology teams to identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across a complex infrastructure environment, identifying and mitigating security risks, supporting major cyber incidents and contributing to strategic security and infrastructure projects. You'll also help develop security awareness, business continuity capabilities and ongoing improvements to the firm's security controls. Key Responsibilities: Continuously review and improve the firm's cybersecurity posture from an infrastructure perspective and external security rating. Identify, assess and remediate vulnerabilities across hardware, software and infrastructure (Windows Server and Azure Cloud). Monitor emerging threats and lead or support Incident Response investigations and mitigation. Evaluate, test and recommend security enhancements, controls and threat prevention technologies. Identify security risks and exposures and develop measures to prevent future incidents. Lead CE+ accreditation and support security, risk and data protection requirements from a technical (Not GRC) perspective. Participate in and lead infrastructure lifecycle, security and technology projects. Provide 3rd Line / Major Incident support as a cybersecurity subject matter expert. Work with third-party suppliers and advise internal technical teams on security measures to resolve security and infrastructure issues. We're looking for experienced Cyber Security engineer with strong technical infrastructure knowledge and proven experience across incident response, threat monitoring and vulnerability management. You will possess: Extensive experience in a similar role blending Cyber Security with core Wintel Infrastructure and Azure cloud engineering. Strong knowledge of modern security architecture, threat prevention techniques and incident response. Strong Windows Server 2016/2019/2022 knowledge including Active Directory, DNS, DHCP, Intune, Group Policy, PKI, Entra and Azure SSO. Demonstrable experience across Cyber Security, Incident Response, Threat Monitoring and Vulnerability Management using tools such as MS Sentinel, MS Defender etc for threat hunting, vulnerability monitoring and security posture improvement. CISSP, CEH, CCNA Security, SC-100, SC200 or equivalent security certification. Experience designing, integrating and managing complex infrastructure and cloud solutions from a cyber security standpoint and advising technical infrastructure teams on security focussed designs and operations Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. Experience working with third-party providers across on-premise and cloud services. Strong planning skills and knowledge of ITIL processes and best practice. This is an excellent opportunity to join a highly regarded global organisation where you'll play a key role in strengthening cybersecurity across a complex international IT environment, combining hands-on security engineering, incident response and strategic infrastructure projects.
Yolk Recruitment
Cyber Security Analyst
Yolk Recruitment
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Aug 23, 2026
Full time
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Rebel Recruitment Limited
Cyber Assurance Consultant
Rebel Recruitment Limited Nottingham, Nottinghamshire
Role: Cyber and Information Assurance Consultant Mid, Senior & Principal Levels Location: Nottingham / Remote-first Working Arrangement: Remote-first, with travel to Nottingham and customer sites as required Salary: £65,000 £120,000 Are you a cyber security or information assurance professional who enjoys working with customers, getting into complex problems and turning security risks into practical solutions? We re looking for Cyber and Information Assurance Consultants across Mid, Senior and Principal levels to join a growing team working on complex, high-assurance environments across defence, government and critical infrastructure. This is a consultancy-focused role, so you won t be sitting in a purely internal security position. You ll work directly with customers, technical teams and senior stakeholders to assess risk, understand threats and vulnerabilities, and provide clear recommendations on how security can be improved. You ll work across areas including cyber risk assessments, information assurance, security governance and secure-by-design. Depending on your level and experience, you could be reviewing solution designs, developing security cases, supporting accreditation and assurance activity, maintaining risk registers or helping shape security requirements across major programmes. You ll also work closely with architects, engineers, project teams, suppliers and customer security teams. A big part of the role will be taking technical evidence and security requirements and explaining what they actually mean from a risk and business perspective. You ll ideally have professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline, alongside experience contributing to security assessment or assurance work. You ll need to be comfortable producing clear security documentation and communicating with both technical and non-technical audiences. Knowledge of areas such as cyber risk management, security controls, threat and vulnerability assessment, security governance and risk acceptance is important. Experience with frameworks such as ISO 27001, ISO 27005, the NCSC Cyber Assessment Framework, NIST or MOD security standards would be beneficial. Experience within defence, government, critical infrastructure or another high-assurance environment would be particularly relevant. Experience with cloud security assurance, security architecture reviews, accreditation or secure information exchange would also be useful. The level you join at will depend on your experience, with opportunities available from Mid-level through to Principal. There is a clear progression route into senior consultancy, security architecture, cyber risk leadership and information assurance leadership, with support towards professional qualifications such as CISSP, CISM, CRISC and ISO 27001. The role is remote-first, although you ll need to be comfortable travelling to the Nottingham office and customer sites when required. Regular UK travel may form part of the role, with occasional international travel possible. If you re looking for a role where you can work on genuinely complex security challenges, have direct customer exposure and continue developing your career across cyber security and assurance, please apply now or get in touch to find out more. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Aug 23, 2026
Full time
Role: Cyber and Information Assurance Consultant Mid, Senior & Principal Levels Location: Nottingham / Remote-first Working Arrangement: Remote-first, with travel to Nottingham and customer sites as required Salary: £65,000 £120,000 Are you a cyber security or information assurance professional who enjoys working with customers, getting into complex problems and turning security risks into practical solutions? We re looking for Cyber and Information Assurance Consultants across Mid, Senior and Principal levels to join a growing team working on complex, high-assurance environments across defence, government and critical infrastructure. This is a consultancy-focused role, so you won t be sitting in a purely internal security position. You ll work directly with customers, technical teams and senior stakeholders to assess risk, understand threats and vulnerabilities, and provide clear recommendations on how security can be improved. You ll work across areas including cyber risk assessments, information assurance, security governance and secure-by-design. Depending on your level and experience, you could be reviewing solution designs, developing security cases, supporting accreditation and assurance activity, maintaining risk registers or helping shape security requirements across major programmes. You ll also work closely with architects, engineers, project teams, suppliers and customer security teams. A big part of the role will be taking technical evidence and security requirements and explaining what they actually mean from a risk and business perspective. You ll ideally have professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline, alongside experience contributing to security assessment or assurance work. You ll need to be comfortable producing clear security documentation and communicating with both technical and non-technical audiences. Knowledge of areas such as cyber risk management, security controls, threat and vulnerability assessment, security governance and risk acceptance is important. Experience with frameworks such as ISO 27001, ISO 27005, the NCSC Cyber Assessment Framework, NIST or MOD security standards would be beneficial. Experience within defence, government, critical infrastructure or another high-assurance environment would be particularly relevant. Experience with cloud security assurance, security architecture reviews, accreditation or secure information exchange would also be useful. The level you join at will depend on your experience, with opportunities available from Mid-level through to Principal. There is a clear progression route into senior consultancy, security architecture, cyber risk leadership and information assurance leadership, with support towards professional qualifications such as CISSP, CISM, CRISC and ISO 27001. The role is remote-first, although you ll need to be comfortable travelling to the Nottingham office and customer sites when required. Regular UK travel may form part of the role, with occasional international travel possible. If you re looking for a role where you can work on genuinely complex security challenges, have direct customer exposure and continue developing your career across cyber security and assurance, please apply now or get in touch to find out more. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Lead Software Security Engineer
United States Digital Space LLC
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Aug 23, 2026
Full time
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Cyber Security Lead
慨正橡扯
Primary Details Time Type: Full time Worker Type: Employee Cyber Security Lead Location: London Type: Permanent, full time Hybrid role, happy to talk flexible working The Opportunity QBE Europe is recruiting a Cyber Security Lead to join our European Cyber Security team in our London office. The role has accountability across operational delivery and advisory capabilities within QBE's cyber services and value streams, with the opportunity to drive continuous improvement and transformational change in the way Cyber and information security risk is considered and mitigated across the core business, our programs and projects. The role works to make QBE safe, secure and resilient; working to continuously out pace and outsmart cyber threat faced by our business. This intellectually challenging and highly influential role is part of an enterprise wide Cyber Security capability, accountable for safeguarding QBE from increasingly sophisticated Cyber and information security threats. This is a highly collaborative role, requiring a sustained level of curiosity and a continuous ability to grow deep technical knowledge that translates into insight to solve root cause problems and supports strategic business outcomes. Having the right to work in the UK is a requirement for this role. QBE may consider sponsorship at its discretion. About QBE At QBE, we get to the heart of what matters for our customers. And we do it all with a human touch. We're an international insurer with more than 13,000 people working across 26 countries - which means we're big enough for your ambitions, yet small enough for you to make a real impact. It's an exciting time. We're building momentum towards our vision to become the most consistent and innovative risk partner. What if you could have a positive impact - at work and in the world? As part of the QBE team, you'll get to spend every day working with people who are passionate, talented and kind. Your new role Deliver an effective cyber and information security capability across QBE, partnering to deliver appropriate levels of engagement and risk mitigation. Develop the cyber and information security experience across QBE, building awareness and engendering healthy curiosity. Build strong collaborative relationships, providing advice and working together to identify and solve root cause problems; demonstrating great tenacity in reducing potential threats and risks. Take personal accountability for seeking out and identifying security weaknesses; seeing mitigation through to a secure conclusion. Drive Cyber engagement across QBE to ensure issues are identified, self reported and notified to key stakeholders. Act with integrity and transparency in threat and risk identification and problem solving. Role model the creation, innovation and negotiation of solutions and risk mitigation strategies; driving fast paced and agile behaviours. Drive the development, execution and assurance of an effective Cyber practice; including the adoption of relevant policy, standards, processes and templates. Manage and quality assure cyber service and outsourced security arrangements; ensuring delivery to SLAs, quality controls and alignment with QBE requirements. Drive collaboration and partnership across the QBE business value streams. Track compliance and security benefits to demonstrate impact and mitigation success. About You Demonstrates exceptional resilience and tenacity in managing and mitigating 24x7 cyber threats whilst successfully managing work life balance. Solution oriented. Problem solving mindset with the ability to see solutions through to delivery. Demonstrable ability to support the development of QBE cyber services and talent, building technical excellence and decision making confidence. Insightful and expert ability to consider where and how people or technology could be exploited; getting into the mindset of an adversary. Exceptional ability to get deeply technical and apply that skill to the business environment. Expertise in one or more of the following areas: Identity and Access Management, Data Security, Threat and Vulnerability Management, Third Party Risk, Cyber Security Infrastructure and Cyber Security Operations. Strong decision making ability when faced with complex and business critical threats. Excellent communication, negotiation and conflict management skills, with an ability to anticipate and pre empt potential obstacles; strong listening skills. Good ability to write and articulate, summarise and present complex problems and messages in a succinct and comprehensible manner. Exceptionally curious and enquiring mindset with a fast paced and agile personal drive to meet business needs. Benefits 30 days holiday a year with the option to buy up to 2 additional days. Flexible working - balancing work and life is important so our flexible working opportunities are open to all, including part time, job share and compressed hours. Pension - you are automatically enrolled into the QBE pension plan, which entitles you to receive employer contributions of 10% of your basic salary. Equal Employment Opportunity: QBE is an equal opportunity employer and is required to comply with equal employment opportunity legislation in each jurisdiction it operates. Application Close Date: 12/06/:59 PM
Aug 21, 2026
Full time
Primary Details Time Type: Full time Worker Type: Employee Cyber Security Lead Location: London Type: Permanent, full time Hybrid role, happy to talk flexible working The Opportunity QBE Europe is recruiting a Cyber Security Lead to join our European Cyber Security team in our London office. The role has accountability across operational delivery and advisory capabilities within QBE's cyber services and value streams, with the opportunity to drive continuous improvement and transformational change in the way Cyber and information security risk is considered and mitigated across the core business, our programs and projects. The role works to make QBE safe, secure and resilient; working to continuously out pace and outsmart cyber threat faced by our business. This intellectually challenging and highly influential role is part of an enterprise wide Cyber Security capability, accountable for safeguarding QBE from increasingly sophisticated Cyber and information security threats. This is a highly collaborative role, requiring a sustained level of curiosity and a continuous ability to grow deep technical knowledge that translates into insight to solve root cause problems and supports strategic business outcomes. Having the right to work in the UK is a requirement for this role. QBE may consider sponsorship at its discretion. About QBE At QBE, we get to the heart of what matters for our customers. And we do it all with a human touch. We're an international insurer with more than 13,000 people working across 26 countries - which means we're big enough for your ambitions, yet small enough for you to make a real impact. It's an exciting time. We're building momentum towards our vision to become the most consistent and innovative risk partner. What if you could have a positive impact - at work and in the world? As part of the QBE team, you'll get to spend every day working with people who are passionate, talented and kind. Your new role Deliver an effective cyber and information security capability across QBE, partnering to deliver appropriate levels of engagement and risk mitigation. Develop the cyber and information security experience across QBE, building awareness and engendering healthy curiosity. Build strong collaborative relationships, providing advice and working together to identify and solve root cause problems; demonstrating great tenacity in reducing potential threats and risks. Take personal accountability for seeking out and identifying security weaknesses; seeing mitigation through to a secure conclusion. Drive Cyber engagement across QBE to ensure issues are identified, self reported and notified to key stakeholders. Act with integrity and transparency in threat and risk identification and problem solving. Role model the creation, innovation and negotiation of solutions and risk mitigation strategies; driving fast paced and agile behaviours. Drive the development, execution and assurance of an effective Cyber practice; including the adoption of relevant policy, standards, processes and templates. Manage and quality assure cyber service and outsourced security arrangements; ensuring delivery to SLAs, quality controls and alignment with QBE requirements. Drive collaboration and partnership across the QBE business value streams. Track compliance and security benefits to demonstrate impact and mitigation success. About You Demonstrates exceptional resilience and tenacity in managing and mitigating 24x7 cyber threats whilst successfully managing work life balance. Solution oriented. Problem solving mindset with the ability to see solutions through to delivery. Demonstrable ability to support the development of QBE cyber services and talent, building technical excellence and decision making confidence. Insightful and expert ability to consider where and how people or technology could be exploited; getting into the mindset of an adversary. Exceptional ability to get deeply technical and apply that skill to the business environment. Expertise in one or more of the following areas: Identity and Access Management, Data Security, Threat and Vulnerability Management, Third Party Risk, Cyber Security Infrastructure and Cyber Security Operations. Strong decision making ability when faced with complex and business critical threats. Excellent communication, negotiation and conflict management skills, with an ability to anticipate and pre empt potential obstacles; strong listening skills. Good ability to write and articulate, summarise and present complex problems and messages in a succinct and comprehensible manner. Exceptionally curious and enquiring mindset with a fast paced and agile personal drive to meet business needs. Benefits 30 days holiday a year with the option to buy up to 2 additional days. Flexible working - balancing work and life is important so our flexible working opportunities are open to all, including part time, job share and compressed hours. Pension - you are automatically enrolled into the QBE pension plan, which entitles you to receive employer contributions of 10% of your basic salary. Equal Employment Opportunity: QBE is an equal opportunity employer and is required to comply with equal employment opportunity legislation in each jurisdiction it operates. Application Close Date: 12/06/:59 PM
Senior Security Engineer
Data Science Festival
Staff Software Security Engineer Salary: Up to £135,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Staff Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Staff Software Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Software Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Staff Software Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £135,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Aug 20, 2026
Full time
Staff Software Security Engineer Salary: Up to £135,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Staff Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Staff Software Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Software Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Staff Software Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £135,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Cambridge University Press & Assessment
Security Assurance Lead
Cambridge University Press & Assessment Cambridge, Cambridgeshire
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role. We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working. This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment. Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement. Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure. Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery. Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported. Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST. Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders. Support incident preparedness, including investigations and exercises that test our ability to respond effectively. Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation. This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition. About You We are looking for someone with extensive knowledge of 5+ year experience in security testing and assurance and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks and (e.g. ISO 27001, NIST) and risk management practices. You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing. You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management. You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously. If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria: Development and maintained a supply chain risk register within a similar sized organisation Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure Experience of reporting risks to senior leadership For a detailed job description, please refer to the link at the bottom of the advert on our careers site. We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition. Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for. Rewards and benefits We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including: 28 days annual leave plus bank holidays Private medical and Permanent Health Insurance Discretionary annual bonus Group personal pension scheme Life assurance up to 4 x annual salary Green travel schemes Ready to pursue your potential? Apply now. We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2 nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after. The application and interview process consists of: 3 role related questions with brief answers A 15-minute screening call with the Hiring Manager. First stage virtual interview via MS Teams. Final stage interview: in-person at our offices in Cambridge. If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs. Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry. We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter. Why join us Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe - for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration. Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
Aug 18, 2026
Full time
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role. We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working. This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment. Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement. Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure. Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery. Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported. Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST. Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders. Support incident preparedness, including investigations and exercises that test our ability to respond effectively. Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation. This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition. About You We are looking for someone with extensive knowledge of 5+ year experience in security testing and assurance and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks and (e.g. ISO 27001, NIST) and risk management practices. You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing. You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management. You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously. If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria: Development and maintained a supply chain risk register within a similar sized organisation Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure Experience of reporting risks to senior leadership For a detailed job description, please refer to the link at the bottom of the advert on our careers site. We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition. Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for. Rewards and benefits We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including: 28 days annual leave plus bank holidays Private medical and Permanent Health Insurance Discretionary annual bonus Group personal pension scheme Life assurance up to 4 x annual salary Green travel schemes Ready to pursue your potential? Apply now. We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2 nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after. The application and interview process consists of: 3 role related questions with brief answers A 15-minute screening call with the Hiring Manager. First stage virtual interview via MS Teams. Final stage interview: in-person at our offices in Cambridge. If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs. Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry. We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter. Why join us Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe - for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration. Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
Saab UK
Cyber Security Manager
Saab UK Fareham, Hampshire
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Aug 11, 2026
Full time
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Hays Technology
Penetration Testing Specialist
Hays Technology Rogerstone, Gwent
Penetration Testing Specialist Permanent - 71k - 82k + strong benefits Location: Hybrid - South Wales Your new company: I am looking to recruit a Penetration Testing Specialist to join a leader in the utilities space. The business has been investing into their cyber security and IT estate and are continuing to grow and enhance their security posture. The company has a strong reputation, and we have placed numerous people into careers there, with strong feedback. The role responsibilities: This is an interesting time to join the company. Lots of investment into their IT, OT, and Cyber Security functions over the last few years, with ongoing investment and growth happening. This is a key role. They're looking for someone who's inquisitive, experienced, and willing to safely get access into almost anything. Key parts of the role: Define and manage the penetration testing schedule. Conduct internal penetration testing of applications and systems Manage external vendors providing penetration services and arrange and schedule their work. Proactively research vulnerabilities in external and internal-facing systems and infrastructure (IT and OT) Social engineering Proactively research internal and external information leakage that may assist malicious actors in preparing for or executing an attack Prepare detailed reporting on vulnerabilities and the remedial actions recommended Accurately quantify discovered vulnerabilities in risk terms. You will need: Strong understanding of penetration testing principles, methodologies and tooling with proven experience of delivering infrastructure and application penetration tests safely and efficiently Strong understanding of safe approaches required for OT testing and proven experience of OT security assurance testing Strong understanding of attacker TTPs & vulnerability assessment Strong understanding of security risk assessment and risk management concepts and approaches Ability to work on your own initiative and to think "outside the box" Experience with operational technology in the utilities sector or other industrial CNI environments will be highly advantageous Excellent communication and interpersonal skills. Ability to obtain UK Security Clearance CREST / CHECK certification (essential) What you'll get in return: Salary of between 71k- 82k Hybrid working 2/3 days in South Wales per week Possible bonus 5% pension contribution from you, the company pays 10% Enhanced pay for parental leave And more! Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Jul 31, 2026
Full time
Penetration Testing Specialist Permanent - 71k - 82k + strong benefits Location: Hybrid - South Wales Your new company: I am looking to recruit a Penetration Testing Specialist to join a leader in the utilities space. The business has been investing into their cyber security and IT estate and are continuing to grow and enhance their security posture. The company has a strong reputation, and we have placed numerous people into careers there, with strong feedback. The role responsibilities: This is an interesting time to join the company. Lots of investment into their IT, OT, and Cyber Security functions over the last few years, with ongoing investment and growth happening. This is a key role. They're looking for someone who's inquisitive, experienced, and willing to safely get access into almost anything. Key parts of the role: Define and manage the penetration testing schedule. Conduct internal penetration testing of applications and systems Manage external vendors providing penetration services and arrange and schedule their work. Proactively research vulnerabilities in external and internal-facing systems and infrastructure (IT and OT) Social engineering Proactively research internal and external information leakage that may assist malicious actors in preparing for or executing an attack Prepare detailed reporting on vulnerabilities and the remedial actions recommended Accurately quantify discovered vulnerabilities in risk terms. You will need: Strong understanding of penetration testing principles, methodologies and tooling with proven experience of delivering infrastructure and application penetration tests safely and efficiently Strong understanding of safe approaches required for OT testing and proven experience of OT security assurance testing Strong understanding of attacker TTPs & vulnerability assessment Strong understanding of security risk assessment and risk management concepts and approaches Ability to work on your own initiative and to think "outside the box" Experience with operational technology in the utilities sector or other industrial CNI environments will be highly advantageous Excellent communication and interpersonal skills. Ability to obtain UK Security Clearance CREST / CHECK certification (essential) What you'll get in return: Salary of between 71k- 82k Hybrid working 2/3 days in South Wales per week Possible bonus 5% pension contribution from you, the company pays 10% Enhanced pay for parental leave And more! Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Creideas
Part-Time Infrastructure & Cyber Security Consultant
Creideas Thame, Oxfordshire
Part-Time Infrastructure & Cyber Security Consultant 2/3 Days Per Week 3 Month Contract 600 - 850 per day Remote AWS Migration Project Creideas are currently partnered with a Cyber Security client who require a part-time Infrastructure & Security Consultant on an initial 3 month basis, with potential to extend or convert to permanent. This is a crucial hire as you help guide their client through a migration from traditional data centres to AWS, whilst also collaborating with the CISO, sharing suggestions based on your observations, assisting the Infrastructure & Security Engineers where needed, building relationships, and ultimately helping with their strategic vision. This is a part-time role, likely for 2 or 3 days per week for an initial 3 month period. The role is mostly remote, with very occasional catch ups with the team face to face. Infrastructure & Cyber Security Consultant Responsibilities Lead their migration from data centres to AWS Combine your skills as an Infrastructure & Security Team Lead and AWS migration Project Lead as they transition from traditional data centres to AWS for their co-located Infrastructure stack (virtualised + physical equipment) Support a small team of Engineers, working as an escalation point and guide throughout Work closely with the CISO, understanding their position, sharing observations, performing security review, and assisting with the overall strategy Provide skills across SIEM, EDR, and Vulnerability Management tools. Vendor agnostic but SentinelOne and/or Microsoft Security experience would be advantageous Infrastructure & Cyber Security Consultant Skills Previous experience leading a DC to AWS migration Capable of leading teams and providing mentorship Experience working in an Advisory capacity SentinelOne experience (advantageous, not essential) Microsoft Security experience (advantageous, not essential) Sonar experience (advantageous, not essential)
Jul 31, 2026
Full time
Part-Time Infrastructure & Cyber Security Consultant 2/3 Days Per Week 3 Month Contract 600 - 850 per day Remote AWS Migration Project Creideas are currently partnered with a Cyber Security client who require a part-time Infrastructure & Security Consultant on an initial 3 month basis, with potential to extend or convert to permanent. This is a crucial hire as you help guide their client through a migration from traditional data centres to AWS, whilst also collaborating with the CISO, sharing suggestions based on your observations, assisting the Infrastructure & Security Engineers where needed, building relationships, and ultimately helping with their strategic vision. This is a part-time role, likely for 2 or 3 days per week for an initial 3 month period. The role is mostly remote, with very occasional catch ups with the team face to face. Infrastructure & Cyber Security Consultant Responsibilities Lead their migration from data centres to AWS Combine your skills as an Infrastructure & Security Team Lead and AWS migration Project Lead as they transition from traditional data centres to AWS for their co-located Infrastructure stack (virtualised + physical equipment) Support a small team of Engineers, working as an escalation point and guide throughout Work closely with the CISO, understanding their position, sharing observations, performing security review, and assisting with the overall strategy Provide skills across SIEM, EDR, and Vulnerability Management tools. Vendor agnostic but SentinelOne and/or Microsoft Security experience would be advantageous Infrastructure & Cyber Security Consultant Skills Previous experience leading a DC to AWS migration Capable of leading teams and providing mentorship Experience working in an Advisory capacity SentinelOne experience (advantageous, not essential) Microsoft Security experience (advantageous, not essential) Sonar experience (advantageous, not essential)
Salt
Senior Application Security Consultant (SAST/DAST/OWASP )
Salt
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London Secure SDLC SAST DAST Threat Modelling Cloud Security CI/CD Location: London (Hybrid - 8 days onsite per month) Contract: 12 Months + extension Rate: 500- 550 per day (Umbrella) The Opportunity We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment. Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely. This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment. Key Responsibilities Lead application security reviews across business-critical applications and cloud platforms. Conduct security architecture and secure design reviews. Perform application security risk assessments and define security requirements. Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies. Embed Secure SDLC principles into engineering teams. Integrate security tooling into CI/CD pipelines and DevSecOps processes. Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings. Work closely with development teams to prioritise vulnerability remediation. Define security testing requirements and support penetration testing activities. Produce security standards, technical guidance and best practice documentation. Act as the Application Security SME across multiple technology programmes. Essential Skills Application Security Secure Software Development Lifecycle (SSDLC) OWASP Top 10 Secure Coding Secure Design Reviews API Security REST APIs Microservices Security Application Security Risk Assessments Threat Modelling STRIDE MITRE ATT&CK Security Architecture Risk Assessments DevSecOps CI/CD Security GitHub Actions GitLab Jenkins Azure DevOps Security Automation Shift Left Security Security Testing SAST DAST SCA Vulnerability Management Penetration Testing Cloud Security AWS, Azure or GCP Kubernetes Docker Container Security Cloud Security Best Practices Security Tooling Experience with one or more of: Checkmarx Fortify SonarQube Veracode Semgrep Burp Suite OWASP ZAP Snyk Trivy Prisma Cloud Aqua Wiz Ideal Background You'll ideally have: 8+ years in Cyber Security Strong Application Security or DevSecOps experience Experience working directly with software engineering teams Experience embedding security into CI/CD pipelines Strong knowledge of Secure SDLC Experience conducting Threat Modelling sessions Excellent stakeholder management and communication skills Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment Contract Details 12-month contract 500- 600 per day (Umbrella) Hybrid working - 8 days onsite per month in London Immediate interview availability preferred Rates depend on experience and client requirements
Jul 31, 2026
Contractor
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London Secure SDLC SAST DAST Threat Modelling Cloud Security CI/CD Location: London (Hybrid - 8 days onsite per month) Contract: 12 Months + extension Rate: 500- 550 per day (Umbrella) The Opportunity We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment. Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely. This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment. Key Responsibilities Lead application security reviews across business-critical applications and cloud platforms. Conduct security architecture and secure design reviews. Perform application security risk assessments and define security requirements. Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies. Embed Secure SDLC principles into engineering teams. Integrate security tooling into CI/CD pipelines and DevSecOps processes. Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings. Work closely with development teams to prioritise vulnerability remediation. Define security testing requirements and support penetration testing activities. Produce security standards, technical guidance and best practice documentation. Act as the Application Security SME across multiple technology programmes. Essential Skills Application Security Secure Software Development Lifecycle (SSDLC) OWASP Top 10 Secure Coding Secure Design Reviews API Security REST APIs Microservices Security Application Security Risk Assessments Threat Modelling STRIDE MITRE ATT&CK Security Architecture Risk Assessments DevSecOps CI/CD Security GitHub Actions GitLab Jenkins Azure DevOps Security Automation Shift Left Security Security Testing SAST DAST SCA Vulnerability Management Penetration Testing Cloud Security AWS, Azure or GCP Kubernetes Docker Container Security Cloud Security Best Practices Security Tooling Experience with one or more of: Checkmarx Fortify SonarQube Veracode Semgrep Burp Suite OWASP ZAP Snyk Trivy Prisma Cloud Aqua Wiz Ideal Background You'll ideally have: 8+ years in Cyber Security Strong Application Security or DevSecOps experience Experience working directly with software engineering teams Experience embedding security into CI/CD pipelines Strong knowledge of Secure SDLC Experience conducting Threat Modelling sessions Excellent stakeholder management and communication skills Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment Contract Details 12-month contract 500- 600 per day (Umbrella) Hybrid working - 8 days onsite per month in London Immediate interview availability preferred Rates depend on experience and client requirements
Senior Cybersecurity Consultant
Ultramink Technologies
Lead security engagements for mid-market enterprises across Europe. You will conduct security assessments, design security architectures, and help clients build security programs that meet regulatory requirements without creating operational friction. Responsibilities Lead penetration testing and vulnerability assessment engagements Design security architectures for cloud-native and hybrid environments Develop security compliance programs (SOC 2, ISO 27001, GDPR) Conduct incident response planning and tabletop exercises Advise C-level executives on security strategy and risk management Requirements 8+ years in information security with consulting experience Deep expertise in penetration testing, vulnerability management, and threat modeling Knowledge of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI-DSS Experience with cloud security (AWS Security Hub, Azure Defender, or GCP Security Command Center) CISSP, OSCP, or equivalent certification Nice to Have Experience in financial services or healthcare security Red team or blue team experience in enterprise environments Familiarity with UK and EU regulatory requirements Competitive salary with annual performance bonuses Comprehensive health, dental, and vision insurance Company pension scheme with employer contribution Remote-first with optional office presence Annual learning budget for conferences, courses, and certifications Home office setup stipend Parental leave (16 weeks primary, 8 weeks secondary)
Jul 30, 2026
Full time
Lead security engagements for mid-market enterprises across Europe. You will conduct security assessments, design security architectures, and help clients build security programs that meet regulatory requirements without creating operational friction. Responsibilities Lead penetration testing and vulnerability assessment engagements Design security architectures for cloud-native and hybrid environments Develop security compliance programs (SOC 2, ISO 27001, GDPR) Conduct incident response planning and tabletop exercises Advise C-level executives on security strategy and risk management Requirements 8+ years in information security with consulting experience Deep expertise in penetration testing, vulnerability management, and threat modeling Knowledge of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI-DSS Experience with cloud security (AWS Security Hub, Azure Defender, or GCP Security Command Center) CISSP, OSCP, or equivalent certification Nice to Have Experience in financial services or healthcare security Red team or blue team experience in enterprise environments Familiarity with UK and EU regulatory requirements Competitive salary with annual performance bonuses Comprehensive health, dental, and vision insurance Company pension scheme with employer contribution Remote-first with optional office presence Annual learning budget for conferences, courses, and certifications Home office setup stipend Parental leave (16 weeks primary, 8 weeks secondary)
Hays Technology
Cyber Security Manager
Hays Technology City, Birmingham
650 - 750 per day (Inside IR35) Hybrid - 2-3 days on-site6-month initial contract (likely extension)Location: Birmingham (You must be able to travel to Birmingham for on-site work 2-3 days) We're working with a government client seeking an experienced Cybersecurity Manager to lead and mature their operational security capability across a modern hybrid estate.This is a hands-on leadership role where you'll combine technical depth with stakeholder engagement, driving security operations, incident response, and continuous improvement across infrastructure, cloud, and workplace environments. The Role You'll take ownership of cybersecurity operations, leading a small engineering team and working closely with an outsourced SOC/MSSP to ensure robust monitoring, response, and continuous improvement. Responsibilities Leading technical incident response (containment, eradication, recovery) and post-incident analysis Owning and improving security controls across endpoints, identity, networks, and cloud platforms Driving vulnerability management, patching, and remediation to agreed SLAs Managing SOC performance, alert triage, escalation, and threat intelligence integration Enforcing Identity & Access Management (IAM) policies, including conditional access and privileged access controls Leading disaster recovery planning and cyber incident readiness exercises Overseeing penetration testing and ensuring timely remediation of findings Providing audit and compliance evidence (e.g., ISO 27001, PCI DSS, CE+) Essential experience: Strong background in cybersecurity operations within complex environments Proven experience leading incident response and remediation activity Expertise in Microsoft 365 / Azure security and hybrid cloud environments Experience operating security tooling (EDR, SIEM, firewalls, identity platforms) at scale Solid understanding of frameworks such as ISO 27001, NCSC guidance, NIST CSF, MITRE ATT&CK Experience managing suppliers, SOC providers, and technical teams Desirable: Relevant certifications (e.g. CISSP, CISM, AZ-500, SC-200) Cyber Secu ty Manager PDF Experience working in Agile / DevOps environments Previous exposure to regulated or public sector environments What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now. If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
May 29, 2026
Contractor
650 - 750 per day (Inside IR35) Hybrid - 2-3 days on-site6-month initial contract (likely extension)Location: Birmingham (You must be able to travel to Birmingham for on-site work 2-3 days) We're working with a government client seeking an experienced Cybersecurity Manager to lead and mature their operational security capability across a modern hybrid estate.This is a hands-on leadership role where you'll combine technical depth with stakeholder engagement, driving security operations, incident response, and continuous improvement across infrastructure, cloud, and workplace environments. The Role You'll take ownership of cybersecurity operations, leading a small engineering team and working closely with an outsourced SOC/MSSP to ensure robust monitoring, response, and continuous improvement. Responsibilities Leading technical incident response (containment, eradication, recovery) and post-incident analysis Owning and improving security controls across endpoints, identity, networks, and cloud platforms Driving vulnerability management, patching, and remediation to agreed SLAs Managing SOC performance, alert triage, escalation, and threat intelligence integration Enforcing Identity & Access Management (IAM) policies, including conditional access and privileged access controls Leading disaster recovery planning and cyber incident readiness exercises Overseeing penetration testing and ensuring timely remediation of findings Providing audit and compliance evidence (e.g., ISO 27001, PCI DSS, CE+) Essential experience: Strong background in cybersecurity operations within complex environments Proven experience leading incident response and remediation activity Expertise in Microsoft 365 / Azure security and hybrid cloud environments Experience operating security tooling (EDR, SIEM, firewalls, identity platforms) at scale Solid understanding of frameworks such as ISO 27001, NCSC guidance, NIST CSF, MITRE ATT&CK Experience managing suppliers, SOC providers, and technical teams Desirable: Relevant certifications (e.g. CISSP, CISM, AZ-500, SC-200) Cyber Secu ty Manager PDF Experience working in Agile / DevOps environments Previous exposure to regulated or public sector environments What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now. If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Teleperformance
Systems Engineer - Grade B2
Teleperformance Clevedon, Somerset
Hello, Thank you for your interested in our L2-L3 Systems Engineer position here at Teleperformance UK. We're looking for a self-driven and proactive Systems Engineer (Level 2-3) with a genuine passion for technology and problem-solving. This role is ideal for someone who thrives in dynamic environments, takes ownership of their work, and brings solid experience primarily with Microsoft infrastructure and cloud solutions. You'll be part of a team that values initiative, continuous learning, and delivering robust technical solutions that support our evolving business needs. Please note, that we are eager to get to know you even if you don't fully "tick all the boxes" on the desired skill list below. We value a can-do attitude and desire to learn and actively participate within the team Hours: Full-time 37.5 hours per week, Monday to Friday, office hours, although some weekend and out-of-hour work may be required to assist business needs. The successful candidate may be expected to join an on-call rota. Contract Term: Permanent The Role Participate in the maintenance, monitoring, implementation and decommission of IT systems, including servers, storage and hardware; and provide professional support and knowledge of Teleperformance systems to internal business units and clients. They will submit recommendations for system improvements, including security, to IT management team and help maintain the optimal operational environment of the Teleperformance IT Systems. O bjectives of the role Support and improve operational IT systems, implement new and decommission old solutions Provide 2 nd - 3 rd Line support for IT systems, infrastructure and Cloud technologies Help design new solutions, based on operational requirements knowledge of the following IT components/Solutions: Windows Server 2016+, AD Domain Services, DHCP, DNS, Azure, GPO, VMWare, Hyper-V (desires), Exchange, M365, Email Filtering & Web Filtering (desired), MECM/TANIUM (desired), Veeam Backup, overall AV Solutions (Trend, Falcon CS), Monitoring & DEX platforms such as SolarWinds, ControlUp, Splunk, Strong Hardware proficiency (Ex: Synergy, Nimble, Brocade, Service BAU requests. Securing systems to Cyber Essentials, PCI DSS and ISO27000 standards through audits, vulnerability scanning and remediation Documentation, creation, update and keeping to date. Assist in the migration from, consolidation of and/or decommission of legacy systems The Ideal Candidate Personal competencies At least 3-5 years IT Systems Team / 3 rd Line Infrastructure Support experience Strong troubleshooting, analytical and support skills Organised, efficient and able to prioritise tasks / plan own time Strong communication skills both verbal and written Be able to think 'out of the box', providing creative ideas and solutions Team player and driven by success, aiming for quality service Experience in a Call Centre environment or similar would be advantageous Required skills SC clearance / SC clearance capable is a big advantage. Windows Server 2016+, configuration, administration and support Hardware support, including racking / (un)racking Microsoft Azure Services Conditional access knowledge is desirable Other cloud platforms are desirable Windows Domain Services - AD Services, DHCP, DNS, Sites & Services Experience with VMware and some Hyper-V Other Hypervisors are desirable Experience with MECM is desirable Experience with Tanium is desirable Experience with Anti-Malware solutions, e.g. Falcon CS System Monitoring and centralized logging, e.g. SolarWinds, Splunk, ControlUp, Chronicle Windows Terminal Server / RDS desirable Linux administration desirable Knowledge and experience of Role Based Access MS Azure Associate/Expert desirable Teleperformance is a worldwide leader in multichannel customer experience management. We are experts in the call centre services industry and add value to our client's service by delivering great customer service and solutions on their behalf. We've been providing superior customer care for leading brands throughout the world since 1978 and every year we interact with more than 35% of the world's population.
May 28, 2026
Full time
Hello, Thank you for your interested in our L2-L3 Systems Engineer position here at Teleperformance UK. We're looking for a self-driven and proactive Systems Engineer (Level 2-3) with a genuine passion for technology and problem-solving. This role is ideal for someone who thrives in dynamic environments, takes ownership of their work, and brings solid experience primarily with Microsoft infrastructure and cloud solutions. You'll be part of a team that values initiative, continuous learning, and delivering robust technical solutions that support our evolving business needs. Please note, that we are eager to get to know you even if you don't fully "tick all the boxes" on the desired skill list below. We value a can-do attitude and desire to learn and actively participate within the team Hours: Full-time 37.5 hours per week, Monday to Friday, office hours, although some weekend and out-of-hour work may be required to assist business needs. The successful candidate may be expected to join an on-call rota. Contract Term: Permanent The Role Participate in the maintenance, monitoring, implementation and decommission of IT systems, including servers, storage and hardware; and provide professional support and knowledge of Teleperformance systems to internal business units and clients. They will submit recommendations for system improvements, including security, to IT management team and help maintain the optimal operational environment of the Teleperformance IT Systems. O bjectives of the role Support and improve operational IT systems, implement new and decommission old solutions Provide 2 nd - 3 rd Line support for IT systems, infrastructure and Cloud technologies Help design new solutions, based on operational requirements knowledge of the following IT components/Solutions: Windows Server 2016+, AD Domain Services, DHCP, DNS, Azure, GPO, VMWare, Hyper-V (desires), Exchange, M365, Email Filtering & Web Filtering (desired), MECM/TANIUM (desired), Veeam Backup, overall AV Solutions (Trend, Falcon CS), Monitoring & DEX platforms such as SolarWinds, ControlUp, Splunk, Strong Hardware proficiency (Ex: Synergy, Nimble, Brocade, Service BAU requests. Securing systems to Cyber Essentials, PCI DSS and ISO27000 standards through audits, vulnerability scanning and remediation Documentation, creation, update and keeping to date. Assist in the migration from, consolidation of and/or decommission of legacy systems The Ideal Candidate Personal competencies At least 3-5 years IT Systems Team / 3 rd Line Infrastructure Support experience Strong troubleshooting, analytical and support skills Organised, efficient and able to prioritise tasks / plan own time Strong communication skills both verbal and written Be able to think 'out of the box', providing creative ideas and solutions Team player and driven by success, aiming for quality service Experience in a Call Centre environment or similar would be advantageous Required skills SC clearance / SC clearance capable is a big advantage. Windows Server 2016+, configuration, administration and support Hardware support, including racking / (un)racking Microsoft Azure Services Conditional access knowledge is desirable Other cloud platforms are desirable Windows Domain Services - AD Services, DHCP, DNS, Sites & Services Experience with VMware and some Hyper-V Other Hypervisors are desirable Experience with MECM is desirable Experience with Tanium is desirable Experience with Anti-Malware solutions, e.g. Falcon CS System Monitoring and centralized logging, e.g. SolarWinds, Splunk, ControlUp, Chronicle Windows Terminal Server / RDS desirable Linux administration desirable Knowledge and experience of Role Based Access MS Azure Associate/Expert desirable Teleperformance is a worldwide leader in multichannel customer experience management. We are experts in the call centre services industry and add value to our client's service by delivering great customer service and solutions on their behalf. We've been providing superior customer care for leading brands throughout the world since 1978 and every year we interact with more than 35% of the world's population.

Modal Window

  • Home
  • Contact
  • About Us
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • Facebook
  • Twitter
  • Google Plus
  • LinkedIn
Parent and Partner sites: IT Job Board | Jobs Near Me | RightTalent.co.uk | Quantity Surveyor jobs | Building Surveyor jobs | Construction Recruitment | Talent Recruiter | Construction Job Board | Property jobs | myJobsnearme.com | Jobs near me
© 2008-2026 Jobsite Jobs | Designed by Web Design Agency