• Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
  • Sign in
  • Sign up
  • Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

97 jobs found

Email me jobs like this
Refine Search
Current Search
cyber security vulnerability management lead
Corriculo Ltd
Cyber Security Engineer, Cloud Security, SIEM, Incident Response, COR7555
Corriculo Ltd Oxford, Oxfordshire
Cyber Security Engineer, Cloud Security, SIEM, Incident Response, COR7555 An exciting opportunity has arisen for a Cyber Security Engineer to join a growing technology company based in Oxfordshire, working on a hybrid basis. This is a hands-on role focused on strengthening cyber security across cloud platforms, applications and business systems. Working closely with the CIO and development teams, the Cyber Security Engineer will play a key role in improving cloud security, incident response, vulnerability management, security monitoring and secure development practices, helping to enhance the organisation's overall cyber resilience. The company develops innovative software solutions for customers operating within highly regulated sectors and continues to experience significant international growth. This role offers excellent autonomy, exposure to senior leadership and genuine long-term progression as the organisation continues to expand. What's required of the Cyber Security Engineer? Proven hands-on experience within Cyber Security Engineering or Security Operations Experience with cloud security across AWS, Azure or GCP Experience with SIEM, EDR/XDR and security monitoring technologies Strong knowledge of vulnerability management and remediation Experience responding to and investigating security incidents Good understanding of network security technologies including Firewalls, IDS/IPS, WAF and VPNs Knowledge of secure software development, application security and OWASP principles Experience working with Identity & Access Management (IAM) Knowledge of security frameworks such as ISO27001, NIST or NIS2 Experience within regulated environments would be advantageous, with exposure to DORA, CMMC or similar frameworks beneficial What Next? If you're a Cyber Security Engineer looking for a varied, hands-on position where you can influence security across cloud, applications and infrastructure while developing towards future cyber security leadership, apply today to learn more! Cyber Security Engineer, Cloud Security, SIEM Corriculo Ltd acts as an employment agency and an employment business.
Aug 25, 2026
Full time
Cyber Security Engineer, Cloud Security, SIEM, Incident Response, COR7555 An exciting opportunity has arisen for a Cyber Security Engineer to join a growing technology company based in Oxfordshire, working on a hybrid basis. This is a hands-on role focused on strengthening cyber security across cloud platforms, applications and business systems. Working closely with the CIO and development teams, the Cyber Security Engineer will play a key role in improving cloud security, incident response, vulnerability management, security monitoring and secure development practices, helping to enhance the organisation's overall cyber resilience. The company develops innovative software solutions for customers operating within highly regulated sectors and continues to experience significant international growth. This role offers excellent autonomy, exposure to senior leadership and genuine long-term progression as the organisation continues to expand. What's required of the Cyber Security Engineer? Proven hands-on experience within Cyber Security Engineering or Security Operations Experience with cloud security across AWS, Azure or GCP Experience with SIEM, EDR/XDR and security monitoring technologies Strong knowledge of vulnerability management and remediation Experience responding to and investigating security incidents Good understanding of network security technologies including Firewalls, IDS/IPS, WAF and VPNs Knowledge of secure software development, application security and OWASP principles Experience working with Identity & Access Management (IAM) Knowledge of security frameworks such as ISO27001, NIST or NIS2 Experience within regulated environments would be advantageous, with exposure to DORA, CMMC or similar frameworks beneficial What Next? If you're a Cyber Security Engineer looking for a varied, hands-on position where you can influence security across cloud, applications and infrastructure while developing towards future cyber security leadership, apply today to learn more! Cyber Security Engineer, Cloud Security, SIEM Corriculo Ltd acts as an employment agency and an employment business.
Isr Recruitment Limited
ICT Cyber and Information Security Manager
Isr Recruitment Limited Eaglescliffe, County Durham
The Opportunity Our client is looking to appoint an experienced ICT Cyber & Information Security Manager to take responsibility for a broad range of cyber security, information security, risk and compliance activities across the organisation. This is a key role within the Information Security function, providing the opportunity to take ownership of security activities ranging from the ICT Annual Delivery Plan through to major business growth initiatives, including site transitions and acquisitions across the UK and internationally. You'll work closely with internal teams, senior stakeholders and external partners to strengthen the organisation's cyber and information security posture, manage risk and ensure compliance with relevant security standards and legislation. The successful candidate will combine strong technical security knowledge with excellent governance, risk management and stakeholder-management skills. Skills and Experience: Experience leading cyber security, information security and/or compliance activities within a medium-to-large enterprise environment. Strong experience managing an enterprise information/cyber security risk register. Strong practical knowledge of Information Security Management Systems (ISMS). Experience implementing, maintaining and continually improving an ISMS. Experience preparing for and participating in internal and external security audits. Strong knowledge of ISO 27002 and experience delivering against its requirements. Strong knowledge of Cyber Essentials / Cyber Essentials Plus. Experience working with NIST security frameworks. Knowledge of CAF / Cyber Assessment Framework and its application to organisational security. Understanding of NIS2, GDPR and the Data Protection Act. Strong understanding of cyber security risk, governance, controls and remediation. Qualifications Professional security qualifications such as the following would be highly desirable: CISSP / CISM / CISA ISO 27001/27002-related qualifications Other recognised cyber security, information assurance or risk-management certifications Role and Responsibilities: Act as a key pillar of the organisation's Information Security programme, driving and managing cyber and information security activities. Work collaboratively with internal teams and external partners to deliver security initiatives and improvements. Develop, review and rehearse incident response plans, ensuring the organisation is prepared to detect, investigate and respond effectively to cyber incidents and data breaches. Work with relevant teams to review, test and improve Business Continuity, Recovery Time Objective (RTO) and Recovery Time Strategy (RTS) arrangements. Conduct and support security risk assessments and vulnerability assessments to identify threats, vulnerabilities and areas for improvement. Develop and implement appropriate risk mitigation strategies. Manage and maintain ICT Cyber & Data Security Risk Registers, ensuring risks are appropriately assessed, owned, mitigated and reported. Review, develop, implement and maintain cyber security, information security, data protection and compliance policies. Monitor changes in the regulatory and threat landscape and assess their impact on the organisation. Ensure compliance with relevant legislation, regulations, frameworks and security standards, including GDPR, Data Protection Act, NIS2, NIST, Cyber Essentials and ISO 27002. Lead and coordinate information security metrics, reporting and management information. Support and oversee offensive security activities, vulnerability management and security testing. Maintain and continuously improve the organisation's Information Security Management System (ISMS). Lead or participate in internal and external security audits and assessments, including ISO 27002 and Cyber Essentials Plus. Provide security input into business change, technology projects, acquisitions, site transitions and other strategic initiatives. Work with stakeholders to embed security by design across ICT and wider business activities. Applications: To learn more about our established client and this newly created role working as a IT Security Manager for our client based in the Teesside / County Durham area (with excellent flexible/remote working options available); please call and speak with Edward Laing here at ISR Recruitment to learn more or please send through a copy of your latest CV and/or share your online business profile for a call back in the very strictest of confidence.
Aug 24, 2026
Full time
The Opportunity Our client is looking to appoint an experienced ICT Cyber & Information Security Manager to take responsibility for a broad range of cyber security, information security, risk and compliance activities across the organisation. This is a key role within the Information Security function, providing the opportunity to take ownership of security activities ranging from the ICT Annual Delivery Plan through to major business growth initiatives, including site transitions and acquisitions across the UK and internationally. You'll work closely with internal teams, senior stakeholders and external partners to strengthen the organisation's cyber and information security posture, manage risk and ensure compliance with relevant security standards and legislation. The successful candidate will combine strong technical security knowledge with excellent governance, risk management and stakeholder-management skills. Skills and Experience: Experience leading cyber security, information security and/or compliance activities within a medium-to-large enterprise environment. Strong experience managing an enterprise information/cyber security risk register. Strong practical knowledge of Information Security Management Systems (ISMS). Experience implementing, maintaining and continually improving an ISMS. Experience preparing for and participating in internal and external security audits. Strong knowledge of ISO 27002 and experience delivering against its requirements. Strong knowledge of Cyber Essentials / Cyber Essentials Plus. Experience working with NIST security frameworks. Knowledge of CAF / Cyber Assessment Framework and its application to organisational security. Understanding of NIS2, GDPR and the Data Protection Act. Strong understanding of cyber security risk, governance, controls and remediation. Qualifications Professional security qualifications such as the following would be highly desirable: CISSP / CISM / CISA ISO 27001/27002-related qualifications Other recognised cyber security, information assurance or risk-management certifications Role and Responsibilities: Act as a key pillar of the organisation's Information Security programme, driving and managing cyber and information security activities. Work collaboratively with internal teams and external partners to deliver security initiatives and improvements. Develop, review and rehearse incident response plans, ensuring the organisation is prepared to detect, investigate and respond effectively to cyber incidents and data breaches. Work with relevant teams to review, test and improve Business Continuity, Recovery Time Objective (RTO) and Recovery Time Strategy (RTS) arrangements. Conduct and support security risk assessments and vulnerability assessments to identify threats, vulnerabilities and areas for improvement. Develop and implement appropriate risk mitigation strategies. Manage and maintain ICT Cyber & Data Security Risk Registers, ensuring risks are appropriately assessed, owned, mitigated and reported. Review, develop, implement and maintain cyber security, information security, data protection and compliance policies. Monitor changes in the regulatory and threat landscape and assess their impact on the organisation. Ensure compliance with relevant legislation, regulations, frameworks and security standards, including GDPR, Data Protection Act, NIS2, NIST, Cyber Essentials and ISO 27002. Lead and coordinate information security metrics, reporting and management information. Support and oversee offensive security activities, vulnerability management and security testing. Maintain and continuously improve the organisation's Information Security Management System (ISMS). Lead or participate in internal and external security audits and assessments, including ISO 27002 and Cyber Essentials Plus. Provide security input into business change, technology projects, acquisitions, site transitions and other strategic initiatives. Work with stakeholders to embed security by design across ICT and wider business activities. Applications: To learn more about our established client and this newly created role working as a IT Security Manager for our client based in the Teesside / County Durham area (with excellent flexible/remote working options available); please call and speak with Edward Laing here at ISR Recruitment to learn more or please send through a copy of your latest CV and/or share your online business profile for a call back in the very strictest of confidence.
Fazer Recruitment
Senior SOC Engineer
Fazer Recruitment Cardiff, South Glamorgan
Senior SOC Engineer - Remote Location: Home-based - two days a month in the office (SE location) all travel paid Salary: Up to £70,000 Type: Permanent, full time Hours: Monday to Friday, 9:00am - 5:30pm - no shifts, no on-call This is a genuinely home-based role. Two days a month on site in Basingstoke, with travel and expenses covered in full. The role This is a build role, not a monitoring one. You'll be the engineer behind the SOC - designing and running the Microsoft security platform the analysts depend on. If you've spent time in a SOC wishing you could fix the tooling rather than work around it, this is that job. You'll join an established Security Operations team as new headcount, reporting to the Lead SOC Engineer. This is a managed security service provider, so you'll see a far wider range of customer environments and problems than any single in-house SOC would give you - and you'll lead the engineering side of onboarding new customers onto the platform. What you'll be doing Designing and maintaining the SIEM and XDR platform - data ingestion, log parsing and normalisation, retention, performance Writing and tuning detections in KQL, and building automation to cut manual analyst effort Scripting custom connectors and integrations across the security toolset Leading the technical onboarding of new customers alongside SOC Operations Acting as senior escalation for complex engineering issues Supporting and mentoring engineers and analysts across the team What we're looking for Around 3-5 years in a Security Operations Centre in an engineering or platform capacity Strong Microsoft Sentinel experience, with confident KQL Hands-on with Microsoft Defender and the wider Microsoft security stack - Intune, Entra ID, Defender for Endpoint Exposure to endpoint tooling such as CrowdStrike, Carbon Black or Darktrace Scripting in Python or PowerShell for automation and log analysis Some vulnerability management experience - Tenable, Rapid7, Qualys or similar Automation and orchestration exposure - Logic Apps, Cortex XSOAR or similar - is welcome but not essential Eligible for UK SC or DV security clearance - essential Experience at an MSSP, MDR provider or security reseller is a real advantage, though we're equally happy to hear from strong in-house SOC engineers. You don't need every tool on this list. Strong Sentinel and KQL with a willingness to develop the rest is enough. What's on offer Up to £65,000 depending on experience Fully home-based, with two paid trips a month to Basingstoke Genuine 9-to-5 - no shift rota, no on-call New headcount in a growing team Access to lab environments, cyber ranges and hands-on training labs Certification and training support with a clear technical progression path Exposure to enterprise security estates across multiple industries How to apply Apply through Reed with an up-to-date CV, or get in touch for a confidential conversation. Fazer Recruitment is acting as an employment agency in relation to this vacancy.
Aug 24, 2026
Full time
Senior SOC Engineer - Remote Location: Home-based - two days a month in the office (SE location) all travel paid Salary: Up to £70,000 Type: Permanent, full time Hours: Monday to Friday, 9:00am - 5:30pm - no shifts, no on-call This is a genuinely home-based role. Two days a month on site in Basingstoke, with travel and expenses covered in full. The role This is a build role, not a monitoring one. You'll be the engineer behind the SOC - designing and running the Microsoft security platform the analysts depend on. If you've spent time in a SOC wishing you could fix the tooling rather than work around it, this is that job. You'll join an established Security Operations team as new headcount, reporting to the Lead SOC Engineer. This is a managed security service provider, so you'll see a far wider range of customer environments and problems than any single in-house SOC would give you - and you'll lead the engineering side of onboarding new customers onto the platform. What you'll be doing Designing and maintaining the SIEM and XDR platform - data ingestion, log parsing and normalisation, retention, performance Writing and tuning detections in KQL, and building automation to cut manual analyst effort Scripting custom connectors and integrations across the security toolset Leading the technical onboarding of new customers alongside SOC Operations Acting as senior escalation for complex engineering issues Supporting and mentoring engineers and analysts across the team What we're looking for Around 3-5 years in a Security Operations Centre in an engineering or platform capacity Strong Microsoft Sentinel experience, with confident KQL Hands-on with Microsoft Defender and the wider Microsoft security stack - Intune, Entra ID, Defender for Endpoint Exposure to endpoint tooling such as CrowdStrike, Carbon Black or Darktrace Scripting in Python or PowerShell for automation and log analysis Some vulnerability management experience - Tenable, Rapid7, Qualys or similar Automation and orchestration exposure - Logic Apps, Cortex XSOAR or similar - is welcome but not essential Eligible for UK SC or DV security clearance - essential Experience at an MSSP, MDR provider or security reseller is a real advantage, though we're equally happy to hear from strong in-house SOC engineers. You don't need every tool on this list. Strong Sentinel and KQL with a willingness to develop the rest is enough. What's on offer Up to £65,000 depending on experience Fully home-based, with two paid trips a month to Basingstoke Genuine 9-to-5 - no shift rota, no on-call New headcount in a growing team Access to lab environments, cyber ranges and hands-on training labs Certification and training support with a clear technical progression path Exposure to enterprise security estates across multiple industries How to apply Apply through Reed with an up-to-date CV, or get in touch for a confidential conversation. Fazer Recruitment is acting as an employment agency in relation to this vacancy.
Circle Recruitment
Programme Manager
Circle Recruitment
Programme Manager - Cyber Security and Operations 6 Months £90k FTC or £550/Day Inside IR35 London or Southampton Our client is looking for an experienced Programme Manager with a strong background in Cyber Security and Security Operations to lead complex programmes and drive the successful delivery of security capabilities into live operational environments. The Programme Manager role will be an initial 6 month contract, and can be offered as either a FTC with a salary of between £80k - £90k, or day rate contract between £500 - £550/Day Inside IR35 on an umbrella solution. The role can be based in either London or Southamptom, and will be a mix of office and remote based working - ideally 1-2 days per week in the office. The Role As a Programme Manager, our client expects you to take ownership of complex Cyber Security and Security Operations programmes, bringing together cyber specialists, technology teams, operational stakeholders and suppliers to deliver measurable security outcomes. You will provide the structure, governance and leadership required to take security initiatives from strategy and design through implementation, transition and into business-as-usual operations. This is a senior, client-facing role requiring strong programme leadership combined with a practical understanding of how modern Security Operations capabilities are designed, implemented and operated. What You'll Do Lead complex Security Operations and Cyber Security transformation programmes from mobilisation through to operational delivery. Establish programme plans, governance frameworks, milestones, dependencies and success measures. Coordinate delivery across Cyber Security, SOC, Infrastructure, Cloud, IAM, Network and Service Management teams. Drive the implementation and enhancement of Security Operations capabilities, including SOC, SIEM, detection and response, vulnerability management and incident response. Manage the transition of new security capabilities into live operational services. Work closely with security architects and technical teams to ensure delivery aligns with security strategy and architecture. Manage dependencies across internal teams, clients, technology vendors and third-party suppliers. Own programme risks, issues, assumptions and dependencies, ensuring appropriate escalation and resolution. Manage programme budgets, resources, forecasts and commercial commitments. What Our Client Is Looking For Programme & Security Operations Experience Significant experience leading complex Cyber Security programmes within enterprise environments. Strong understanding of Security Operations and the delivery of operational cyber capabilities. Experience delivering programmes involving areas such as SOC, SIEM, incident response, threat detection, vulnerability management, security tooling or security service transformation. Proven experience transitioning security capabilities from project delivery into BAU operations. Strong programme governance, planning, financial management and risk management capability. Experience managing multiple workstreams, technical dependencies and third-party suppliers. Good understanding of cloud, infrastructure, networking, identity and security technologies. Experience working with managed security service providers and technology vendors would be advantageous. Our client is looking for someone who can combine strategic programme leadership with a practical understanding of Cyber Security and Security Operations, ensuring complex security initiatives translate into effective, sustainable operational capabilities. If you are interested in the above, hit the Apply now button! Programme Manager, Programme Management, Security Operations, Programme Manager, Cyber, Programme Manager, Security, Programme Manager, Programme Manager Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter and LinkedIn - Circle Recruitment.
Aug 24, 2026
Full time
Programme Manager - Cyber Security and Operations 6 Months £90k FTC or £550/Day Inside IR35 London or Southampton Our client is looking for an experienced Programme Manager with a strong background in Cyber Security and Security Operations to lead complex programmes and drive the successful delivery of security capabilities into live operational environments. The Programme Manager role will be an initial 6 month contract, and can be offered as either a FTC with a salary of between £80k - £90k, or day rate contract between £500 - £550/Day Inside IR35 on an umbrella solution. The role can be based in either London or Southamptom, and will be a mix of office and remote based working - ideally 1-2 days per week in the office. The Role As a Programme Manager, our client expects you to take ownership of complex Cyber Security and Security Operations programmes, bringing together cyber specialists, technology teams, operational stakeholders and suppliers to deliver measurable security outcomes. You will provide the structure, governance and leadership required to take security initiatives from strategy and design through implementation, transition and into business-as-usual operations. This is a senior, client-facing role requiring strong programme leadership combined with a practical understanding of how modern Security Operations capabilities are designed, implemented and operated. What You'll Do Lead complex Security Operations and Cyber Security transformation programmes from mobilisation through to operational delivery. Establish programme plans, governance frameworks, milestones, dependencies and success measures. Coordinate delivery across Cyber Security, SOC, Infrastructure, Cloud, IAM, Network and Service Management teams. Drive the implementation and enhancement of Security Operations capabilities, including SOC, SIEM, detection and response, vulnerability management and incident response. Manage the transition of new security capabilities into live operational services. Work closely with security architects and technical teams to ensure delivery aligns with security strategy and architecture. Manage dependencies across internal teams, clients, technology vendors and third-party suppliers. Own programme risks, issues, assumptions and dependencies, ensuring appropriate escalation and resolution. Manage programme budgets, resources, forecasts and commercial commitments. What Our Client Is Looking For Programme & Security Operations Experience Significant experience leading complex Cyber Security programmes within enterprise environments. Strong understanding of Security Operations and the delivery of operational cyber capabilities. Experience delivering programmes involving areas such as SOC, SIEM, incident response, threat detection, vulnerability management, security tooling or security service transformation. Proven experience transitioning security capabilities from project delivery into BAU operations. Strong programme governance, planning, financial management and risk management capability. Experience managing multiple workstreams, technical dependencies and third-party suppliers. Good understanding of cloud, infrastructure, networking, identity and security technologies. Experience working with managed security service providers and technology vendors would be advantageous. Our client is looking for someone who can combine strategic programme leadership with a practical understanding of Cyber Security and Security Operations, ensuring complex security initiatives translate into effective, sustainable operational capabilities. If you are interested in the above, hit the Apply now button! Programme Manager, Programme Management, Security Operations, Programme Manager, Cyber, Programme Manager, Security, Programme Manager, Programme Manager Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter and LinkedIn - Circle Recruitment.
Comtecs Ltd
Cyber Security Engineer - MS Sentinel, Defender, SSO, PKI, SC-100/200, CISSP
Comtecs Ltd
IT Cyber Security Specialist / Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team, supporting and continually improving cybersecurity across a global IT environment. Reporting to the Infrastructure Engineering Manager, you'll take ownership of cybersecurity controls and security architecture while working closely with Infrastructure Operations and other technology teams to identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across a complex infrastructure environment, identifying and mitigating security risks, supporting major cyber incidents and contributing to strategic security and infrastructure projects. You'll also help develop security awareness, business continuity capabilities and ongoing improvements to the firm's security controls. Key Responsibilities: Continuously review and improve the firm's cybersecurity posture from an infrastructure perspective and external security rating. Identify, assess and remediate vulnerabilities across hardware, software and infrastructure (Windows Server and Azure Cloud). Monitor emerging threats and lead or support Incident Response investigations and mitigation. Evaluate, test and recommend security enhancements, controls and threat prevention technologies. Identify security risks and exposures and develop measures to prevent future incidents. Lead CE+ accreditation and support security, risk and data protection requirements from a technical (Not GRC) perspective. Participate in and lead infrastructure lifecycle, security and technology projects. Provide 3rd Line / Major Incident support as a cybersecurity subject matter expert. Work with third-party suppliers and advise internal technical teams on security measures to resolve security and infrastructure issues. We're looking for experienced Cyber Security engineer with strong technical infrastructure knowledge and proven experience across incident response, threat monitoring and vulnerability management. You will possess: Extensive experience in a similar role blending Cyber Security with core Wintel Infrastructure and Azure cloud engineering. Strong knowledge of modern security architecture, threat prevention techniques and incident response. Strong Windows Server 2016/2019/2022 knowledge including Active Directory, DNS, DHCP, Intune, Group Policy, PKI, Entra and Azure SSO. Demonstrable experience across Cyber Security, Incident Response, Threat Monitoring and Vulnerability Management using tools such as MS Sentinel, MS Defender etc for threat hunting, vulnerability monitoring and security posture improvement. CISSP, CEH, CCNA Security, SC-100, SC200 or equivalent security certification. Experience designing, integrating and managing complex infrastructure and cloud solutions from a cyber security standpoint and advising technical infrastructure teams on security focussed designs and operations Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. Experience working with third-party providers across on-premise and cloud services. Strong planning skills and knowledge of ITIL processes and best practice. This is an excellent opportunity to join a highly regarded global organisation where you'll play a key role in strengthening cybersecurity across a complex international IT environment, combining hands-on security engineering, incident response and strategic infrastructure projects.
Aug 24, 2026
Full time
IT Cyber Security Specialist / Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team, supporting and continually improving cybersecurity across a global IT environment. Reporting to the Infrastructure Engineering Manager, you'll take ownership of cybersecurity controls and security architecture while working closely with Infrastructure Operations and other technology teams to identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across a complex infrastructure environment, identifying and mitigating security risks, supporting major cyber incidents and contributing to strategic security and infrastructure projects. You'll also help develop security awareness, business continuity capabilities and ongoing improvements to the firm's security controls. Key Responsibilities: Continuously review and improve the firm's cybersecurity posture from an infrastructure perspective and external security rating. Identify, assess and remediate vulnerabilities across hardware, software and infrastructure (Windows Server and Azure Cloud). Monitor emerging threats and lead or support Incident Response investigations and mitigation. Evaluate, test and recommend security enhancements, controls and threat prevention technologies. Identify security risks and exposures and develop measures to prevent future incidents. Lead CE+ accreditation and support security, risk and data protection requirements from a technical (Not GRC) perspective. Participate in and lead infrastructure lifecycle, security and technology projects. Provide 3rd Line / Major Incident support as a cybersecurity subject matter expert. Work with third-party suppliers and advise internal technical teams on security measures to resolve security and infrastructure issues. We're looking for experienced Cyber Security engineer with strong technical infrastructure knowledge and proven experience across incident response, threat monitoring and vulnerability management. You will possess: Extensive experience in a similar role blending Cyber Security with core Wintel Infrastructure and Azure cloud engineering. Strong knowledge of modern security architecture, threat prevention techniques and incident response. Strong Windows Server 2016/2019/2022 knowledge including Active Directory, DNS, DHCP, Intune, Group Policy, PKI, Entra and Azure SSO. Demonstrable experience across Cyber Security, Incident Response, Threat Monitoring and Vulnerability Management using tools such as MS Sentinel, MS Defender etc for threat hunting, vulnerability monitoring and security posture improvement. CISSP, CEH, CCNA Security, SC-100, SC200 or equivalent security certification. Experience designing, integrating and managing complex infrastructure and cloud solutions from a cyber security standpoint and advising technical infrastructure teams on security focussed designs and operations Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. Experience working with third-party providers across on-premise and cloud services. Strong planning skills and knowledge of ITIL processes and best practice. This is an excellent opportunity to join a highly regarded global organisation where you'll play a key role in strengthening cybersecurity across a complex international IT environment, combining hands-on security engineering, incident response and strategic infrastructure projects.
Big Red Recruitment
Penetration Tester
Big Red Recruitment
We are seeking a Penetration Tester to join a growing Offensive Security team within a specialist cyber security consultancy. This is an exciting opportunity to join at a time of significant investment and growth, helping to strengthen existing testing services while contributing to the development of new capabilities across areas such as Red Teaming, Operational Technology (OT), Threat-Led Security Testing and emerging technologies. The successful candidate will play a key role in delivering penetration testing engagements, supporting process improvement initiatives, and helping to build a scalable and mature testing function. This position offers excellent opportunities for professional development, certification support and future progression into senior or leadership positions. JOB ROLE - PENETRATION TESTER LOCATION - LONDON (OCCASIONAL ON-SITE WORK) SALARY - £40,000-£45,000 + BENEFITS Key Responsibilities Conduct vulnerability assessments and penetration testing engagements across: Internal infrastructure External infrastructure Web applications Networks and systems Perform configuration and build reviews using recognised security frameworks and benchmarks. Produce clear, concise and actionable technical reports detailing findings, risk ratings and remediation recommendations. Utilise industry-standard security testing tools including Burp Suite, Nessus, Metasploit, Nmap, Wireshark and related technologies. Work directly with clients and stakeholders, presenting findings and providing remediation guidance where required. Support the continuous improvement of testing methodologies, processes and documentation. Assist in creating and maintaining standard operating procedures, testing guides and knowledge-sharing materials. Collaborate with wider cyber security teams to support service development and research initiatives. Contribute to research and development activities across new security testing disciplines and technologies. Participate in occasional out-of-hours and on-site engagements where client requirements dictate. Required Skills & Experience Minimum 2 years' experience in penetration testing, vulnerability assessment or offensive security. Experience conducting: Internal and external infrastructure testing Web application security testing Security assessments and audits Vulnerability identification and validation Strong understanding of networking concepts, protocols, routing and firewall technologies. Experience working with Windows, Linux and macOS environments. Familiarity with security assessment tools such as: Burp Suite Nessus Metasploit Nmap Wireshark Experience producing high-quality technical reports and client-facing documentation. Excellent communication and stakeholder management skills. Strong organisational skills and ability to manage workload independently. Comfortable working in a consultancy or client-facing environment. Eligible to obtain UK Security Clearance. Desirable Skills & Certifications CREST CRT, CPSA, CCT or equivalent certification. OSCP or similar offensive security qualification. Cyber Scheme accreditation. CHECK Team Member status.
Aug 24, 2026
Full time
We are seeking a Penetration Tester to join a growing Offensive Security team within a specialist cyber security consultancy. This is an exciting opportunity to join at a time of significant investment and growth, helping to strengthen existing testing services while contributing to the development of new capabilities across areas such as Red Teaming, Operational Technology (OT), Threat-Led Security Testing and emerging technologies. The successful candidate will play a key role in delivering penetration testing engagements, supporting process improvement initiatives, and helping to build a scalable and mature testing function. This position offers excellent opportunities for professional development, certification support and future progression into senior or leadership positions. JOB ROLE - PENETRATION TESTER LOCATION - LONDON (OCCASIONAL ON-SITE WORK) SALARY - £40,000-£45,000 + BENEFITS Key Responsibilities Conduct vulnerability assessments and penetration testing engagements across: Internal infrastructure External infrastructure Web applications Networks and systems Perform configuration and build reviews using recognised security frameworks and benchmarks. Produce clear, concise and actionable technical reports detailing findings, risk ratings and remediation recommendations. Utilise industry-standard security testing tools including Burp Suite, Nessus, Metasploit, Nmap, Wireshark and related technologies. Work directly with clients and stakeholders, presenting findings and providing remediation guidance where required. Support the continuous improvement of testing methodologies, processes and documentation. Assist in creating and maintaining standard operating procedures, testing guides and knowledge-sharing materials. Collaborate with wider cyber security teams to support service development and research initiatives. Contribute to research and development activities across new security testing disciplines and technologies. Participate in occasional out-of-hours and on-site engagements where client requirements dictate. Required Skills & Experience Minimum 2 years' experience in penetration testing, vulnerability assessment or offensive security. Experience conducting: Internal and external infrastructure testing Web application security testing Security assessments and audits Vulnerability identification and validation Strong understanding of networking concepts, protocols, routing and firewall technologies. Experience working with Windows, Linux and macOS environments. Familiarity with security assessment tools such as: Burp Suite Nessus Metasploit Nmap Wireshark Experience producing high-quality technical reports and client-facing documentation. Excellent communication and stakeholder management skills. Strong organisational skills and ability to manage workload independently. Comfortable working in a consultancy or client-facing environment. Eligible to obtain UK Security Clearance. Desirable Skills & Certifications CREST CRT, CPSA, CCT or equivalent certification. OSCP or similar offensive security qualification. Cyber Scheme accreditation. CHECK Team Member status.
Government Digital & Data
Head of Cyber Security Risk Management (Digital Identity) - Government Digital Service - G6
Government Digital & Data
Location Bristol, London, Manchester About the job Job summary This role will require the post holder to have SC clearance to start and may be required to undergo Developed Vetting (DV) once in post, therefore successful candidates will be expected to either hold this or be willing to undertake the DV clearance process once in post. More information on DV clearance is linked here The Government Digital Service (GDS) is the digital centre of government. We are responsible for setting, leading and delivering the vision for a modern digital government. Our priorities are to drive a modern digital government, by: joining up public sector services harnessing the power of AI for the public good strengthening and extending our digital and data public infrastructure elevating leadership and investing in talent funding for outcomes andprocuringfor growth and innovation committing to transparency and driving accountability We are home to the Incubator for Artificial Intelligence (I.AI), the world-leading GOV.UK and at the forefront of coordinating the UK's geospatial strategy and activity. We lead the Government Digital and Data function and champion the work of digital teams across government. We're part of the Department for Science, Innovation and Technology (DSIT) and employ more than 1,000 people all over the UK, with hubs in Manchester, London and Bristol. The Government Digital Service is where talent translates into impact. From your first day, you'll be working with some of the world's most highly-skilled digital professionals, all contributing their knowledge to make change on a national scale. Join us for rewarding work that makes a difference across the UK. You'll solve some of the nation's highest-priority digital challenges, helping millions of people access services they need Job description As Head of Cyber Security Risk Management for One Login and Digital Identity you will play a central role in protecting the UK's current and future digital identity ecosystem. At scale, One Login will be the front door for millions of users to access digital public services. Security, reliability and resilience are absolutely critical to delivering our mission. This is a high profile role, suited to an experienced security leader with a track record of setting direction and running security risk, governance and assurance for a complex area. As Head of Cyber Security Risk Management you will have oversight for the Digital Identity Cyber Information Assurance team, taking responsibility for the governance, risk management, compliance and 3rd party assurance. In addition, you will be responsible for: governance, risk and assurance leadership: building civil servant capability to run a mature, responsive cyber assurance team, working in collaboration with One Logins dedicated Security Operations, Security Design & Architecture, Pods (developer teams) and wider GDS and DSIT cyber teams. Work in partnership with GDS (Privacy, Information Assurance, Security Architecture, Cyber), GSG, CDIO Cyber, NCSC and other government departments governance, risk and assurance: lead design, implementation and operating of information security governance frameworks aligned to DSIT and regulatory context. Ensure the team provides independent information assurance across the One Login Programme but work closely with the GDS Infosec team for second line assurance. Build and lead the third party and supply chain assurance strategy. Maintain and innovate the current risk management board ensuring present risk positions are clearly communicated to the senior leadership team (SLT). multi tier assurance: work closely with the GDS Infosec Team to support 2nd line assurance. Build and manage an integrated governance process which has a unified risk perspective enabling both first and second line assurance to work on a common understanding of the risk posture. Drive proactive engagement across both teams to stop any siloed forming and make sure the risk development lifecycle is balanced. policy & standards: develop and maintain security policies, standards frameworks, and governance processes aligned to government and industry best practice for complex cloud-native environments assurance & remediation: drive security assurance activities across One Login programmes, suppliers, and operational services, including audits, assessments, and ensuring timely remediation within required SLOs stakeholder collaboration: build strong relationships with key stakeholders-including GDS (Privacy, Information Assurance, Security Architecture), GSG, CDIO Cyber, and NCSC-to embed security into delivery, architecture, procurement, and operational decision making compliance & frameworks: ensure all operations meet stringent UK Government security requirements by supporting regulatory and contractual compliance activities, including alignment to standards such as NIST, CAF, and GovAssure governance & reporting: establish and maintain operational metrics to produce clear, meaningful reporting and dashboards that measure the programme's threat posture and support executive decision making security culture leadership : working in close collaboration with the Head of Product Security and Head of Security Operations for One Login and the GDS CISO, take responsibility for embedding a robust security culture across the programme. Person specification We're interested in people who have experience and knowledge of most of the following: a strong track record of experience leading security governance, assurance, risk, or compliance functions, ideally for a Critical National Infrastructure (CNI) or comparable risk/profile/impact level product in-depth knowledge of government security standards, frameworks, and assurance approaches, with demonstrable success applying frameworks such as CAF, NIST 800-53, GovAssure, and Secure by Design Principles experience developing and implementing security policies and control frameworks in complex cloud-native environments and serverless architectures ability to communicate complex security concepts clearly and establish effective working relationships with key security stakeholders, including technical and non-technical specialists across organisational boundaries strong analytical, reporting, and risk management capabilities, including building governance dashboards and executive-level assurance reporting understanding of supplier assurance, vulnerability management, and experience integrating governance with security operational integration. hold recognised cyber security certifications such as CISSP, CISM, or CRISC
Aug 24, 2026
Full time
Location Bristol, London, Manchester About the job Job summary This role will require the post holder to have SC clearance to start and may be required to undergo Developed Vetting (DV) once in post, therefore successful candidates will be expected to either hold this or be willing to undertake the DV clearance process once in post. More information on DV clearance is linked here The Government Digital Service (GDS) is the digital centre of government. We are responsible for setting, leading and delivering the vision for a modern digital government. Our priorities are to drive a modern digital government, by: joining up public sector services harnessing the power of AI for the public good strengthening and extending our digital and data public infrastructure elevating leadership and investing in talent funding for outcomes andprocuringfor growth and innovation committing to transparency and driving accountability We are home to the Incubator for Artificial Intelligence (I.AI), the world-leading GOV.UK and at the forefront of coordinating the UK's geospatial strategy and activity. We lead the Government Digital and Data function and champion the work of digital teams across government. We're part of the Department for Science, Innovation and Technology (DSIT) and employ more than 1,000 people all over the UK, with hubs in Manchester, London and Bristol. The Government Digital Service is where talent translates into impact. From your first day, you'll be working with some of the world's most highly-skilled digital professionals, all contributing their knowledge to make change on a national scale. Join us for rewarding work that makes a difference across the UK. You'll solve some of the nation's highest-priority digital challenges, helping millions of people access services they need Job description As Head of Cyber Security Risk Management for One Login and Digital Identity you will play a central role in protecting the UK's current and future digital identity ecosystem. At scale, One Login will be the front door for millions of users to access digital public services. Security, reliability and resilience are absolutely critical to delivering our mission. This is a high profile role, suited to an experienced security leader with a track record of setting direction and running security risk, governance and assurance for a complex area. As Head of Cyber Security Risk Management you will have oversight for the Digital Identity Cyber Information Assurance team, taking responsibility for the governance, risk management, compliance and 3rd party assurance. In addition, you will be responsible for: governance, risk and assurance leadership: building civil servant capability to run a mature, responsive cyber assurance team, working in collaboration with One Logins dedicated Security Operations, Security Design & Architecture, Pods (developer teams) and wider GDS and DSIT cyber teams. Work in partnership with GDS (Privacy, Information Assurance, Security Architecture, Cyber), GSG, CDIO Cyber, NCSC and other government departments governance, risk and assurance: lead design, implementation and operating of information security governance frameworks aligned to DSIT and regulatory context. Ensure the team provides independent information assurance across the One Login Programme but work closely with the GDS Infosec team for second line assurance. Build and lead the third party and supply chain assurance strategy. Maintain and innovate the current risk management board ensuring present risk positions are clearly communicated to the senior leadership team (SLT). multi tier assurance: work closely with the GDS Infosec Team to support 2nd line assurance. Build and manage an integrated governance process which has a unified risk perspective enabling both first and second line assurance to work on a common understanding of the risk posture. Drive proactive engagement across both teams to stop any siloed forming and make sure the risk development lifecycle is balanced. policy & standards: develop and maintain security policies, standards frameworks, and governance processes aligned to government and industry best practice for complex cloud-native environments assurance & remediation: drive security assurance activities across One Login programmes, suppliers, and operational services, including audits, assessments, and ensuring timely remediation within required SLOs stakeholder collaboration: build strong relationships with key stakeholders-including GDS (Privacy, Information Assurance, Security Architecture), GSG, CDIO Cyber, and NCSC-to embed security into delivery, architecture, procurement, and operational decision making compliance & frameworks: ensure all operations meet stringent UK Government security requirements by supporting regulatory and contractual compliance activities, including alignment to standards such as NIST, CAF, and GovAssure governance & reporting: establish and maintain operational metrics to produce clear, meaningful reporting and dashboards that measure the programme's threat posture and support executive decision making security culture leadership : working in close collaboration with the Head of Product Security and Head of Security Operations for One Login and the GDS CISO, take responsibility for embedding a robust security culture across the programme. Person specification We're interested in people who have experience and knowledge of most of the following: a strong track record of experience leading security governance, assurance, risk, or compliance functions, ideally for a Critical National Infrastructure (CNI) or comparable risk/profile/impact level product in-depth knowledge of government security standards, frameworks, and assurance approaches, with demonstrable success applying frameworks such as CAF, NIST 800-53, GovAssure, and Secure by Design Principles experience developing and implementing security policies and control frameworks in complex cloud-native environments and serverless architectures ability to communicate complex security concepts clearly and establish effective working relationships with key security stakeholders, including technical and non-technical specialists across organisational boundaries strong analytical, reporting, and risk management capabilities, including building governance dashboards and executive-level assurance reporting understanding of supplier assurance, vulnerability management, and experience integrating governance with security operational integration. hold recognised cyber security certifications such as CISSP, CISM, or CRISC
Yolk Recruitment
Cyber Security Analyst
Yolk Recruitment
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Aug 23, 2026
Full time
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Rebel Recruitment Limited
Cyber Assurance Consultant
Rebel Recruitment Limited Nottingham, Nottinghamshire
Role: Cyber and Information Assurance Consultant Mid, Senior & Principal Levels Location: Nottingham / Remote-first Working Arrangement: Remote-first, with travel to Nottingham and customer sites as required Salary: £65,000 £120,000 Are you a cyber security or information assurance professional who enjoys working with customers, getting into complex problems and turning security risks into practical solutions? We re looking for Cyber and Information Assurance Consultants across Mid, Senior and Principal levels to join a growing team working on complex, high-assurance environments across defence, government and critical infrastructure. This is a consultancy-focused role, so you won t be sitting in a purely internal security position. You ll work directly with customers, technical teams and senior stakeholders to assess risk, understand threats and vulnerabilities, and provide clear recommendations on how security can be improved. You ll work across areas including cyber risk assessments, information assurance, security governance and secure-by-design. Depending on your level and experience, you could be reviewing solution designs, developing security cases, supporting accreditation and assurance activity, maintaining risk registers or helping shape security requirements across major programmes. You ll also work closely with architects, engineers, project teams, suppliers and customer security teams. A big part of the role will be taking technical evidence and security requirements and explaining what they actually mean from a risk and business perspective. You ll ideally have professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline, alongside experience contributing to security assessment or assurance work. You ll need to be comfortable producing clear security documentation and communicating with both technical and non-technical audiences. Knowledge of areas such as cyber risk management, security controls, threat and vulnerability assessment, security governance and risk acceptance is important. Experience with frameworks such as ISO 27001, ISO 27005, the NCSC Cyber Assessment Framework, NIST or MOD security standards would be beneficial. Experience within defence, government, critical infrastructure or another high-assurance environment would be particularly relevant. Experience with cloud security assurance, security architecture reviews, accreditation or secure information exchange would also be useful. The level you join at will depend on your experience, with opportunities available from Mid-level through to Principal. There is a clear progression route into senior consultancy, security architecture, cyber risk leadership and information assurance leadership, with support towards professional qualifications such as CISSP, CISM, CRISC and ISO 27001. The role is remote-first, although you ll need to be comfortable travelling to the Nottingham office and customer sites when required. Regular UK travel may form part of the role, with occasional international travel possible. If you re looking for a role where you can work on genuinely complex security challenges, have direct customer exposure and continue developing your career across cyber security and assurance, please apply now or get in touch to find out more. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Aug 23, 2026
Full time
Role: Cyber and Information Assurance Consultant Mid, Senior & Principal Levels Location: Nottingham / Remote-first Working Arrangement: Remote-first, with travel to Nottingham and customer sites as required Salary: £65,000 £120,000 Are you a cyber security or information assurance professional who enjoys working with customers, getting into complex problems and turning security risks into practical solutions? We re looking for Cyber and Information Assurance Consultants across Mid, Senior and Principal levels to join a growing team working on complex, high-assurance environments across defence, government and critical infrastructure. This is a consultancy-focused role, so you won t be sitting in a purely internal security position. You ll work directly with customers, technical teams and senior stakeholders to assess risk, understand threats and vulnerabilities, and provide clear recommendations on how security can be improved. You ll work across areas including cyber risk assessments, information assurance, security governance and secure-by-design. Depending on your level and experience, you could be reviewing solution designs, developing security cases, supporting accreditation and assurance activity, maintaining risk registers or helping shape security requirements across major programmes. You ll also work closely with architects, engineers, project teams, suppliers and customer security teams. A big part of the role will be taking technical evidence and security requirements and explaining what they actually mean from a risk and business perspective. You ll ideally have professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline, alongside experience contributing to security assessment or assurance work. You ll need to be comfortable producing clear security documentation and communicating with both technical and non-technical audiences. Knowledge of areas such as cyber risk management, security controls, threat and vulnerability assessment, security governance and risk acceptance is important. Experience with frameworks such as ISO 27001, ISO 27005, the NCSC Cyber Assessment Framework, NIST or MOD security standards would be beneficial. Experience within defence, government, critical infrastructure or another high-assurance environment would be particularly relevant. Experience with cloud security assurance, security architecture reviews, accreditation or secure information exchange would also be useful. The level you join at will depend on your experience, with opportunities available from Mid-level through to Principal. There is a clear progression route into senior consultancy, security architecture, cyber risk leadership and information assurance leadership, with support towards professional qualifications such as CISSP, CISM, CRISC and ISO 27001. The role is remote-first, although you ll need to be comfortable travelling to the Nottingham office and customer sites when required. Regular UK travel may form part of the role, with occasional international travel possible. If you re looking for a role where you can work on genuinely complex security challenges, have direct customer exposure and continue developing your career across cyber security and assurance, please apply now or get in touch to find out more. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Lead Software Security Engineer
United States Digital Space LLC
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Aug 23, 2026
Full time
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Cyber Security Lead
慨正橡扯
Primary Details Time Type: Full time Worker Type: Employee Cyber Security Lead Location: London Type: Permanent, full time Hybrid role, happy to talk flexible working The Opportunity QBE Europe is recruiting a Cyber Security Lead to join our European Cyber Security team in our London office. The role has accountability across operational delivery and advisory capabilities within QBE's cyber services and value streams, with the opportunity to drive continuous improvement and transformational change in the way Cyber and information security risk is considered and mitigated across the core business, our programs and projects. The role works to make QBE safe, secure and resilient; working to continuously out pace and outsmart cyber threat faced by our business. This intellectually challenging and highly influential role is part of an enterprise wide Cyber Security capability, accountable for safeguarding QBE from increasingly sophisticated Cyber and information security threats. This is a highly collaborative role, requiring a sustained level of curiosity and a continuous ability to grow deep technical knowledge that translates into insight to solve root cause problems and supports strategic business outcomes. Having the right to work in the UK is a requirement for this role. QBE may consider sponsorship at its discretion. About QBE At QBE, we get to the heart of what matters for our customers. And we do it all with a human touch. We're an international insurer with more than 13,000 people working across 26 countries - which means we're big enough for your ambitions, yet small enough for you to make a real impact. It's an exciting time. We're building momentum towards our vision to become the most consistent and innovative risk partner. What if you could have a positive impact - at work and in the world? As part of the QBE team, you'll get to spend every day working with people who are passionate, talented and kind. Your new role Deliver an effective cyber and information security capability across QBE, partnering to deliver appropriate levels of engagement and risk mitigation. Develop the cyber and information security experience across QBE, building awareness and engendering healthy curiosity. Build strong collaborative relationships, providing advice and working together to identify and solve root cause problems; demonstrating great tenacity in reducing potential threats and risks. Take personal accountability for seeking out and identifying security weaknesses; seeing mitigation through to a secure conclusion. Drive Cyber engagement across QBE to ensure issues are identified, self reported and notified to key stakeholders. Act with integrity and transparency in threat and risk identification and problem solving. Role model the creation, innovation and negotiation of solutions and risk mitigation strategies; driving fast paced and agile behaviours. Drive the development, execution and assurance of an effective Cyber practice; including the adoption of relevant policy, standards, processes and templates. Manage and quality assure cyber service and outsourced security arrangements; ensuring delivery to SLAs, quality controls and alignment with QBE requirements. Drive collaboration and partnership across the QBE business value streams. Track compliance and security benefits to demonstrate impact and mitigation success. About You Demonstrates exceptional resilience and tenacity in managing and mitigating 24x7 cyber threats whilst successfully managing work life balance. Solution oriented. Problem solving mindset with the ability to see solutions through to delivery. Demonstrable ability to support the development of QBE cyber services and talent, building technical excellence and decision making confidence. Insightful and expert ability to consider where and how people or technology could be exploited; getting into the mindset of an adversary. Exceptional ability to get deeply technical and apply that skill to the business environment. Expertise in one or more of the following areas: Identity and Access Management, Data Security, Threat and Vulnerability Management, Third Party Risk, Cyber Security Infrastructure and Cyber Security Operations. Strong decision making ability when faced with complex and business critical threats. Excellent communication, negotiation and conflict management skills, with an ability to anticipate and pre empt potential obstacles; strong listening skills. Good ability to write and articulate, summarise and present complex problems and messages in a succinct and comprehensible manner. Exceptionally curious and enquiring mindset with a fast paced and agile personal drive to meet business needs. Benefits 30 days holiday a year with the option to buy up to 2 additional days. Flexible working - balancing work and life is important so our flexible working opportunities are open to all, including part time, job share and compressed hours. Pension - you are automatically enrolled into the QBE pension plan, which entitles you to receive employer contributions of 10% of your basic salary. Equal Employment Opportunity: QBE is an equal opportunity employer and is required to comply with equal employment opportunity legislation in each jurisdiction it operates. Application Close Date: 12/06/:59 PM
Aug 21, 2026
Full time
Primary Details Time Type: Full time Worker Type: Employee Cyber Security Lead Location: London Type: Permanent, full time Hybrid role, happy to talk flexible working The Opportunity QBE Europe is recruiting a Cyber Security Lead to join our European Cyber Security team in our London office. The role has accountability across operational delivery and advisory capabilities within QBE's cyber services and value streams, with the opportunity to drive continuous improvement and transformational change in the way Cyber and information security risk is considered and mitigated across the core business, our programs and projects. The role works to make QBE safe, secure and resilient; working to continuously out pace and outsmart cyber threat faced by our business. This intellectually challenging and highly influential role is part of an enterprise wide Cyber Security capability, accountable for safeguarding QBE from increasingly sophisticated Cyber and information security threats. This is a highly collaborative role, requiring a sustained level of curiosity and a continuous ability to grow deep technical knowledge that translates into insight to solve root cause problems and supports strategic business outcomes. Having the right to work in the UK is a requirement for this role. QBE may consider sponsorship at its discretion. About QBE At QBE, we get to the heart of what matters for our customers. And we do it all with a human touch. We're an international insurer with more than 13,000 people working across 26 countries - which means we're big enough for your ambitions, yet small enough for you to make a real impact. It's an exciting time. We're building momentum towards our vision to become the most consistent and innovative risk partner. What if you could have a positive impact - at work and in the world? As part of the QBE team, you'll get to spend every day working with people who are passionate, talented and kind. Your new role Deliver an effective cyber and information security capability across QBE, partnering to deliver appropriate levels of engagement and risk mitigation. Develop the cyber and information security experience across QBE, building awareness and engendering healthy curiosity. Build strong collaborative relationships, providing advice and working together to identify and solve root cause problems; demonstrating great tenacity in reducing potential threats and risks. Take personal accountability for seeking out and identifying security weaknesses; seeing mitigation through to a secure conclusion. Drive Cyber engagement across QBE to ensure issues are identified, self reported and notified to key stakeholders. Act with integrity and transparency in threat and risk identification and problem solving. Role model the creation, innovation and negotiation of solutions and risk mitigation strategies; driving fast paced and agile behaviours. Drive the development, execution and assurance of an effective Cyber practice; including the adoption of relevant policy, standards, processes and templates. Manage and quality assure cyber service and outsourced security arrangements; ensuring delivery to SLAs, quality controls and alignment with QBE requirements. Drive collaboration and partnership across the QBE business value streams. Track compliance and security benefits to demonstrate impact and mitigation success. About You Demonstrates exceptional resilience and tenacity in managing and mitigating 24x7 cyber threats whilst successfully managing work life balance. Solution oriented. Problem solving mindset with the ability to see solutions through to delivery. Demonstrable ability to support the development of QBE cyber services and talent, building technical excellence and decision making confidence. Insightful and expert ability to consider where and how people or technology could be exploited; getting into the mindset of an adversary. Exceptional ability to get deeply technical and apply that skill to the business environment. Expertise in one or more of the following areas: Identity and Access Management, Data Security, Threat and Vulnerability Management, Third Party Risk, Cyber Security Infrastructure and Cyber Security Operations. Strong decision making ability when faced with complex and business critical threats. Excellent communication, negotiation and conflict management skills, with an ability to anticipate and pre empt potential obstacles; strong listening skills. Good ability to write and articulate, summarise and present complex problems and messages in a succinct and comprehensible manner. Exceptionally curious and enquiring mindset with a fast paced and agile personal drive to meet business needs. Benefits 30 days holiday a year with the option to buy up to 2 additional days. Flexible working - balancing work and life is important so our flexible working opportunities are open to all, including part time, job share and compressed hours. Pension - you are automatically enrolled into the QBE pension plan, which entitles you to receive employer contributions of 10% of your basic salary. Equal Employment Opportunity: QBE is an equal opportunity employer and is required to comply with equal employment opportunity legislation in each jurisdiction it operates. Application Close Date: 12/06/:59 PM
Senior Security Engineer
Data Science Festival
Staff Software Security Engineer Salary: Up to £135,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Staff Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Staff Software Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Software Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Staff Software Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £135,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Aug 20, 2026
Full time
Staff Software Security Engineer Salary: Up to £135,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Staff Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Staff Software Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Software Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Staff Software Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £135,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Cambridge University Press & Assessment
Security Assurance Lead
Cambridge University Press & Assessment Cambridge, Cambridgeshire
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role. We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working. This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment. Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement. Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure. Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery. Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported. Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST. Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders. Support incident preparedness, including investigations and exercises that test our ability to respond effectively. Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation. This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition. About You We are looking for someone with extensive knowledge of 5+ year experience in security testing and assurance and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks and (e.g. ISO 27001, NIST) and risk management practices. You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing. You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management. You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously. If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria: Development and maintained a supply chain risk register within a similar sized organisation Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure Experience of reporting risks to senior leadership For a detailed job description, please refer to the link at the bottom of the advert on our careers site. We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition. Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for. Rewards and benefits We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including: 28 days annual leave plus bank holidays Private medical and Permanent Health Insurance Discretionary annual bonus Group personal pension scheme Life assurance up to 4 x annual salary Green travel schemes Ready to pursue your potential? Apply now. We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2 nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after. The application and interview process consists of: 3 role related questions with brief answers A 15-minute screening call with the Hiring Manager. First stage virtual interview via MS Teams. Final stage interview: in-person at our offices in Cambridge. If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs. Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry. We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter. Why join us Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe - for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration. Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
Aug 18, 2026
Full time
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role. We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working. This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment. Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement. Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure. Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery. Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported. Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST. Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders. Support incident preparedness, including investigations and exercises that test our ability to respond effectively. Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation. This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition. About You We are looking for someone with extensive knowledge of 5+ year experience in security testing and assurance and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks and (e.g. ISO 27001, NIST) and risk management practices. You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing. You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management. You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously. If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria: Development and maintained a supply chain risk register within a similar sized organisation Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure Experience of reporting risks to senior leadership For a detailed job description, please refer to the link at the bottom of the advert on our careers site. We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition. Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for. Rewards and benefits We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including: 28 days annual leave plus bank holidays Private medical and Permanent Health Insurance Discretionary annual bonus Group personal pension scheme Life assurance up to 4 x annual salary Green travel schemes Ready to pursue your potential? Apply now. We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2 nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after. The application and interview process consists of: 3 role related questions with brief answers A 15-minute screening call with the Hiring Manager. First stage virtual interview via MS Teams. Final stage interview: in-person at our offices in Cambridge. If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs. Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry. We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter. Why join us Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe - for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration. Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
UK Biobank
Director of Information Security
UK Biobank Cheadle, Staffordshire
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
Aug 17, 2026
Full time
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
IS Platform and Security Supervisor
Harbour Energy
Since its creation in 2014, Harbour has grown to become one of the world's largest and most geographically diverse independent oil and gas companies. Today, Harbour is producing between 475,000 and 485,000 barrels of oil equivalent per day with significant production in Norway, the UK, Germany, Argentina and North Africa. Harbour benefits from competitive operating costs and resilient margins, and a broad set of growth options including near-infrastructure opportunities in Norway, unconventional scalable opportunities in Argentina and conventional offshore projects in Mexico and Indonesia. With low GHG emissions intensity and a leading CO2 storage position in Europe, Harbour remains committed to producing oil and gas safely and responsibly to help meet the world's energy needs. Harbour is headquartered in London with approximately 5,000 staff and contractors across its operations and offices. Ours is an inclusive workplace where individuals can bring their whole selves to their job and feel recognised for the value they add. We are committed to creating a genuinely inclusive and supportive working environment to ensure everyone has a positive experience at work. At Harbour Energy, we aim to recruit, retain and promote our people based on their unique skills, regardless of race, gender or background. We need excellent people to help shape and develop the future of our company. Could this be you? Purpose of Role The IS Platform and Security Supervisor ensures all environments are secure, compliant, resilient, and aligned with global IS/OT standards, while meeting business and operational requirements. The role oversees the IS platforms, the operational security, Operational Technology, and communications landscape within the Mexico BU. Acts as a point of coordination for BU IS/OT platforms and security working in line with corporate teams. Drive continuous improvement, cost optimisation, and service reliability across IT/OT platforms and communications. Critical Responsibilities (MAE/MATTE/HSES ) Ensure that all activities are carried out in a safe manner complying with all regulatory requirements, legislation and Harbour Energy HSES Procedures. Ethics and Compliance Responsibilities Ensure that all activities and behaviours are carried out in accordance with Harbour Energy's Ethics and Compliance Policies and Procedures and to complete any compulsory compliance training as required. Areas of Accountability, Responsibility and Competence Oversee and manage local infrastructure and cloud services, ensuring full compliance with global IS governance and security standards with focus on availability and performance. Lead local cyber security activities in close collaboration with Global IS Security teams ensuring hands on support and situational awareness during cyber security incidents. Maintain situational awareness and hands on response during incidents. Drive vulnerability management, patching, monitoring, and risk reduction across all supported platforms. Oversee OT systems supporting drilling, offshore, and real time operations ensuring secure integration between IT and OT environments and apply and enforce Global OT cyber security standards. Management of local IT and telecommunications networks including offshore operations. Manage and provide IT systems and facility services to the Mexico BU office including, but not limited to, access control and CCTV. Management of local suppliers to ensure high-quality and compliant service delivery. Support and manage local telecommunications management (internet lines, mobile phone contracts etc). Implementation and execution of local backup and DR concepts. Provide guidance and oversight to ensure technical solutions and procedures remain fit for purpose, secure, and up to date. Participate in audits and verifications of partners and contractors. Provide technical support to tenders and contracts as required. Participate in relevant projects related to IT/OT infrastructure and applications. Manage smaller projects and initiatives. Ensure IS infrastructure and security services are stable, resilient, and consistently meet or exceed agreed service levels. Vendors, partners, and internal teams are aligned, with clear accountability and proactive issue resolution. Processes, tools, and solutions are regularly reviewed and enhanced to drive efficiency, security, and business value. May be required for on call support. Technical Skills IS Security (security operations, security architecture, asset security, communications and network security monitoring.). Private and Public Cloud management, security, and monitoring (AWS, Azure, Google Cloud Platform etc.). Identity & Access Management (Active Directory, LDAP, SSO, MFA). Threat & vulnerability management (risk assessment, penetration testing, malware analysis etc.). Security standards such as ISO 27001, NIST, CIS Controls, SOC 2. Knowledge of OT Environments/Real-time data sources/drilling and rig operations. Commercial awareness, including budget tracking and cost control. Non-Technical Skills Communication skills for reporting of security incidents and providing guidance. Strong stakeholder management skills across business and technical audiences. Professional Experience Experience in prioritising workload, managing demand and delivering against agreed plans. Education Bachelor's degree in relevant field. Language Harbour Principles and Values Strong alignment with Harbour Energy's core values, behaviours, and commitment to operational excellence and integrity. Inclusive recruitment is a vital part of our diversity, equity and inclusion strategy. Whatever your background, if you feel you need an adjustment during our selection process to suit your needs, please let us know, and we will be happy to help.
Aug 15, 2026
Full time
Since its creation in 2014, Harbour has grown to become one of the world's largest and most geographically diverse independent oil and gas companies. Today, Harbour is producing between 475,000 and 485,000 barrels of oil equivalent per day with significant production in Norway, the UK, Germany, Argentina and North Africa. Harbour benefits from competitive operating costs and resilient margins, and a broad set of growth options including near-infrastructure opportunities in Norway, unconventional scalable opportunities in Argentina and conventional offshore projects in Mexico and Indonesia. With low GHG emissions intensity and a leading CO2 storage position in Europe, Harbour remains committed to producing oil and gas safely and responsibly to help meet the world's energy needs. Harbour is headquartered in London with approximately 5,000 staff and contractors across its operations and offices. Ours is an inclusive workplace where individuals can bring their whole selves to their job and feel recognised for the value they add. We are committed to creating a genuinely inclusive and supportive working environment to ensure everyone has a positive experience at work. At Harbour Energy, we aim to recruit, retain and promote our people based on their unique skills, regardless of race, gender or background. We need excellent people to help shape and develop the future of our company. Could this be you? Purpose of Role The IS Platform and Security Supervisor ensures all environments are secure, compliant, resilient, and aligned with global IS/OT standards, while meeting business and operational requirements. The role oversees the IS platforms, the operational security, Operational Technology, and communications landscape within the Mexico BU. Acts as a point of coordination for BU IS/OT platforms and security working in line with corporate teams. Drive continuous improvement, cost optimisation, and service reliability across IT/OT platforms and communications. Critical Responsibilities (MAE/MATTE/HSES ) Ensure that all activities are carried out in a safe manner complying with all regulatory requirements, legislation and Harbour Energy HSES Procedures. Ethics and Compliance Responsibilities Ensure that all activities and behaviours are carried out in accordance with Harbour Energy's Ethics and Compliance Policies and Procedures and to complete any compulsory compliance training as required. Areas of Accountability, Responsibility and Competence Oversee and manage local infrastructure and cloud services, ensuring full compliance with global IS governance and security standards with focus on availability and performance. Lead local cyber security activities in close collaboration with Global IS Security teams ensuring hands on support and situational awareness during cyber security incidents. Maintain situational awareness and hands on response during incidents. Drive vulnerability management, patching, monitoring, and risk reduction across all supported platforms. Oversee OT systems supporting drilling, offshore, and real time operations ensuring secure integration between IT and OT environments and apply and enforce Global OT cyber security standards. Management of local IT and telecommunications networks including offshore operations. Manage and provide IT systems and facility services to the Mexico BU office including, but not limited to, access control and CCTV. Management of local suppliers to ensure high-quality and compliant service delivery. Support and manage local telecommunications management (internet lines, mobile phone contracts etc). Implementation and execution of local backup and DR concepts. Provide guidance and oversight to ensure technical solutions and procedures remain fit for purpose, secure, and up to date. Participate in audits and verifications of partners and contractors. Provide technical support to tenders and contracts as required. Participate in relevant projects related to IT/OT infrastructure and applications. Manage smaller projects and initiatives. Ensure IS infrastructure and security services are stable, resilient, and consistently meet or exceed agreed service levels. Vendors, partners, and internal teams are aligned, with clear accountability and proactive issue resolution. Processes, tools, and solutions are regularly reviewed and enhanced to drive efficiency, security, and business value. May be required for on call support. Technical Skills IS Security (security operations, security architecture, asset security, communications and network security monitoring.). Private and Public Cloud management, security, and monitoring (AWS, Azure, Google Cloud Platform etc.). Identity & Access Management (Active Directory, LDAP, SSO, MFA). Threat & vulnerability management (risk assessment, penetration testing, malware analysis etc.). Security standards such as ISO 27001, NIST, CIS Controls, SOC 2. Knowledge of OT Environments/Real-time data sources/drilling and rig operations. Commercial awareness, including budget tracking and cost control. Non-Technical Skills Communication skills for reporting of security incidents and providing guidance. Strong stakeholder management skills across business and technical audiences. Professional Experience Experience in prioritising workload, managing demand and delivering against agreed plans. Education Bachelor's degree in relevant field. Language Harbour Principles and Values Strong alignment with Harbour Energy's core values, behaviours, and commitment to operational excellence and integrity. Inclusive recruitment is a vital part of our diversity, equity and inclusion strategy. Whatever your background, if you feel you need an adjustment during our selection process to suit your needs, please let us know, and we will be happy to help.
Saab UK
Cyber Security Manager
Saab UK Fareham, Hampshire
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Aug 11, 2026
Full time
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Reed Technology
Senior SOC Engineer
Reed Technology Basingstoke, Hampshire
Senior SOC Engineer - Hybrid Join a leading cyber security services organisation as a Senior SOC Engineer , taking ownership of the technology, automation, and engineering capabilities that support a modern Security Operations Centre (SOC). The Role You'll design, deploy, and enhance core SOC platforms including SIEM, XDR, SOAR, automation, and security tooling , driving improvements in threat detection, response, and operational efficiency. Working closely with operational teams, you'll support customer onboarding, develop automated workflows, and help shape the future direction of SOC engineering. Key Responsibilities Design, deploy and optimise SIEM, XDR and SOAR platforms. Build security automation, integrations, and response workflows. Develop log parsing, data normalisation and telemetry solutions. Lead technical onboarding and implementation projects. Act as an escalation point for complex security engineering issues. Mentor SOC analysts and engineers. Improve detection, response and operational processes through automation. Maintain engineering documentation, standards and best practices. Skills & Experience 3-5+ years' experience within a SOC or cyber security engineering environment. Strong experience with SIEM, SOAR and EDR/XDR technologies. Scripting and automation expertise (Python, Go, APIs). Experience with cloud platforms such as Azure, AWS or GCP. Knowledge of vulnerability management and threat intelligence integrations. Strong communication, analytical and problem-solving skills. Eligibility for UK security clearance desirable. What's on Offer 2 Days in the Office Per Month Exposure to a wide range of security environments and technologies. Opportunity to influence SOC strategy and engineering direction. Dedicated training, development, and lab environments. Competitive salary and comprehensive benefits package. Ideal for an experienced SOC Engineer looking to step into a senior, technically focused role with significant ownership, automation responsibilities, and career progression opportunities.
Jul 31, 2026
Full time
Senior SOC Engineer - Hybrid Join a leading cyber security services organisation as a Senior SOC Engineer , taking ownership of the technology, automation, and engineering capabilities that support a modern Security Operations Centre (SOC). The Role You'll design, deploy, and enhance core SOC platforms including SIEM, XDR, SOAR, automation, and security tooling , driving improvements in threat detection, response, and operational efficiency. Working closely with operational teams, you'll support customer onboarding, develop automated workflows, and help shape the future direction of SOC engineering. Key Responsibilities Design, deploy and optimise SIEM, XDR and SOAR platforms. Build security automation, integrations, and response workflows. Develop log parsing, data normalisation and telemetry solutions. Lead technical onboarding and implementation projects. Act as an escalation point for complex security engineering issues. Mentor SOC analysts and engineers. Improve detection, response and operational processes through automation. Maintain engineering documentation, standards and best practices. Skills & Experience 3-5+ years' experience within a SOC or cyber security engineering environment. Strong experience with SIEM, SOAR and EDR/XDR technologies. Scripting and automation expertise (Python, Go, APIs). Experience with cloud platforms such as Azure, AWS or GCP. Knowledge of vulnerability management and threat intelligence integrations. Strong communication, analytical and problem-solving skills. Eligibility for UK security clearance desirable. What's on Offer 2 Days in the Office Per Month Exposure to a wide range of security environments and technologies. Opportunity to influence SOC strategy and engineering direction. Dedicated training, development, and lab environments. Competitive salary and comprehensive benefits package. Ideal for an experienced SOC Engineer looking to step into a senior, technically focused role with significant ownership, automation responsibilities, and career progression opportunities.
Hays Technology
Penetration Testing Specialist
Hays Technology Rogerstone, Gwent
Penetration Testing Specialist Permanent - 71k - 82k + strong benefits Location: Hybrid - South Wales Your new company: I am looking to recruit a Penetration Testing Specialist to join a leader in the utilities space. The business has been investing into their cyber security and IT estate and are continuing to grow and enhance their security posture. The company has a strong reputation, and we have placed numerous people into careers there, with strong feedback. The role responsibilities: This is an interesting time to join the company. Lots of investment into their IT, OT, and Cyber Security functions over the last few years, with ongoing investment and growth happening. This is a key role. They're looking for someone who's inquisitive, experienced, and willing to safely get access into almost anything. Key parts of the role: Define and manage the penetration testing schedule. Conduct internal penetration testing of applications and systems Manage external vendors providing penetration services and arrange and schedule their work. Proactively research vulnerabilities in external and internal-facing systems and infrastructure (IT and OT) Social engineering Proactively research internal and external information leakage that may assist malicious actors in preparing for or executing an attack Prepare detailed reporting on vulnerabilities and the remedial actions recommended Accurately quantify discovered vulnerabilities in risk terms. You will need: Strong understanding of penetration testing principles, methodologies and tooling with proven experience of delivering infrastructure and application penetration tests safely and efficiently Strong understanding of safe approaches required for OT testing and proven experience of OT security assurance testing Strong understanding of attacker TTPs & vulnerability assessment Strong understanding of security risk assessment and risk management concepts and approaches Ability to work on your own initiative and to think "outside the box" Experience with operational technology in the utilities sector or other industrial CNI environments will be highly advantageous Excellent communication and interpersonal skills. Ability to obtain UK Security Clearance CREST / CHECK certification (essential) What you'll get in return: Salary of between 71k- 82k Hybrid working 2/3 days in South Wales per week Possible bonus 5% pension contribution from you, the company pays 10% Enhanced pay for parental leave And more! Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Jul 31, 2026
Full time
Penetration Testing Specialist Permanent - 71k - 82k + strong benefits Location: Hybrid - South Wales Your new company: I am looking to recruit a Penetration Testing Specialist to join a leader in the utilities space. The business has been investing into their cyber security and IT estate and are continuing to grow and enhance their security posture. The company has a strong reputation, and we have placed numerous people into careers there, with strong feedback. The role responsibilities: This is an interesting time to join the company. Lots of investment into their IT, OT, and Cyber Security functions over the last few years, with ongoing investment and growth happening. This is a key role. They're looking for someone who's inquisitive, experienced, and willing to safely get access into almost anything. Key parts of the role: Define and manage the penetration testing schedule. Conduct internal penetration testing of applications and systems Manage external vendors providing penetration services and arrange and schedule their work. Proactively research vulnerabilities in external and internal-facing systems and infrastructure (IT and OT) Social engineering Proactively research internal and external information leakage that may assist malicious actors in preparing for or executing an attack Prepare detailed reporting on vulnerabilities and the remedial actions recommended Accurately quantify discovered vulnerabilities in risk terms. You will need: Strong understanding of penetration testing principles, methodologies and tooling with proven experience of delivering infrastructure and application penetration tests safely and efficiently Strong understanding of safe approaches required for OT testing and proven experience of OT security assurance testing Strong understanding of attacker TTPs & vulnerability assessment Strong understanding of security risk assessment and risk management concepts and approaches Ability to work on your own initiative and to think "outside the box" Experience with operational technology in the utilities sector or other industrial CNI environments will be highly advantageous Excellent communication and interpersonal skills. Ability to obtain UK Security Clearance CREST / CHECK certification (essential) What you'll get in return: Salary of between 71k- 82k Hybrid working 2/3 days in South Wales per week Possible bonus 5% pension contribution from you, the company pays 10% Enhanced pay for parental leave And more! Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Creideas
Part-Time Infrastructure & Cyber Security Consultant
Creideas Thame, Oxfordshire
Part-Time Infrastructure & Cyber Security Consultant 2/3 Days Per Week 3 Month Contract 600 - 850 per day Remote AWS Migration Project Creideas are currently partnered with a Cyber Security client who require a part-time Infrastructure & Security Consultant on an initial 3 month basis, with potential to extend or convert to permanent. This is a crucial hire as you help guide their client through a migration from traditional data centres to AWS, whilst also collaborating with the CISO, sharing suggestions based on your observations, assisting the Infrastructure & Security Engineers where needed, building relationships, and ultimately helping with their strategic vision. This is a part-time role, likely for 2 or 3 days per week for an initial 3 month period. The role is mostly remote, with very occasional catch ups with the team face to face. Infrastructure & Cyber Security Consultant Responsibilities Lead their migration from data centres to AWS Combine your skills as an Infrastructure & Security Team Lead and AWS migration Project Lead as they transition from traditional data centres to AWS for their co-located Infrastructure stack (virtualised + physical equipment) Support a small team of Engineers, working as an escalation point and guide throughout Work closely with the CISO, understanding their position, sharing observations, performing security review, and assisting with the overall strategy Provide skills across SIEM, EDR, and Vulnerability Management tools. Vendor agnostic but SentinelOne and/or Microsoft Security experience would be advantageous Infrastructure & Cyber Security Consultant Skills Previous experience leading a DC to AWS migration Capable of leading teams and providing mentorship Experience working in an Advisory capacity SentinelOne experience (advantageous, not essential) Microsoft Security experience (advantageous, not essential) Sonar experience (advantageous, not essential)
Jul 31, 2026
Full time
Part-Time Infrastructure & Cyber Security Consultant 2/3 Days Per Week 3 Month Contract 600 - 850 per day Remote AWS Migration Project Creideas are currently partnered with a Cyber Security client who require a part-time Infrastructure & Security Consultant on an initial 3 month basis, with potential to extend or convert to permanent. This is a crucial hire as you help guide their client through a migration from traditional data centres to AWS, whilst also collaborating with the CISO, sharing suggestions based on your observations, assisting the Infrastructure & Security Engineers where needed, building relationships, and ultimately helping with their strategic vision. This is a part-time role, likely for 2 or 3 days per week for an initial 3 month period. The role is mostly remote, with very occasional catch ups with the team face to face. Infrastructure & Cyber Security Consultant Responsibilities Lead their migration from data centres to AWS Combine your skills as an Infrastructure & Security Team Lead and AWS migration Project Lead as they transition from traditional data centres to AWS for their co-located Infrastructure stack (virtualised + physical equipment) Support a small team of Engineers, working as an escalation point and guide throughout Work closely with the CISO, understanding their position, sharing observations, performing security review, and assisting with the overall strategy Provide skills across SIEM, EDR, and Vulnerability Management tools. Vendor agnostic but SentinelOne and/or Microsoft Security experience would be advantageous Infrastructure & Cyber Security Consultant Skills Previous experience leading a DC to AWS migration Capable of leading teams and providing mentorship Experience working in an Advisory capacity SentinelOne experience (advantageous, not essential) Microsoft Security experience (advantageous, not essential) Sonar experience (advantageous, not essential)
Prime Personnel UK
Senior IT Security Analyst
Prime Personnel UK
Senior IT Security Analyst required to act as a senior technical contributor within a global cyber security team, owning selected cyber security domains end-to-end and driving practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions based on real-world attacker behaviour, and deliver measurable improvements to the organisation cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365 / Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve endpoint security controls. Used Zscaler ZIA/ZPA or equivalent secure web gateway, private access, zero trust or network access security technologies. Performed vulnerability assessment, exposure analysis or remediation prioritisation across enterprise technology environments. Applied threat intelligence, MITRE ATT&CK or exploitation-based evidence to prioritise mitigations. Supported or led cyber security investigations and incident response activities. Collaborated with infrastructure, cloud, application, identity and business teams to deliver security improvements. Used scripting, queries, automation or data analysis to improve security outcomes. Strong hands-on experience administering, tuning and operationalising CrowdStrike Falcon , including endpoint protection, EDR investigations, detection analysis and response workflows. Strong hands-on experience administering and supporting Zscaler ZIA and ZPA , including policy design, access control, traffic analysis and security troubleshooting. Practical experience leading or supporting vulnerability and exposure management programmes , including vulnerability analysis, risk-based prioritisation, remediation tracking and validation of control effectiveness. Strong knowledge of real-world attacker tactics, techniques and procedures (TTPs) and the ability to translate threat intelligence, attack paths and exploitation trends into actionable security improvements. Experience conducting security investigations and incident response activities, including alert triage, root cause analysis, containment, remediation and lessons learned. This is a hybrid role working 3 days a week in the London office and 2 days remotely.
Jul 31, 2026
Full time
Senior IT Security Analyst required to act as a senior technical contributor within a global cyber security team, owning selected cyber security domains end-to-end and driving practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions based on real-world attacker behaviour, and deliver measurable improvements to the organisation cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365 / Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve endpoint security controls. Used Zscaler ZIA/ZPA or equivalent secure web gateway, private access, zero trust or network access security technologies. Performed vulnerability assessment, exposure analysis or remediation prioritisation across enterprise technology environments. Applied threat intelligence, MITRE ATT&CK or exploitation-based evidence to prioritise mitigations. Supported or led cyber security investigations and incident response activities. Collaborated with infrastructure, cloud, application, identity and business teams to deliver security improvements. Used scripting, queries, automation or data analysis to improve security outcomes. Strong hands-on experience administering, tuning and operationalising CrowdStrike Falcon , including endpoint protection, EDR investigations, detection analysis and response workflows. Strong hands-on experience administering and supporting Zscaler ZIA and ZPA , including policy design, access control, traffic analysis and security troubleshooting. Practical experience leading or supporting vulnerability and exposure management programmes , including vulnerability analysis, risk-based prioritisation, remediation tracking and validation of control effectiveness. Strong knowledge of real-world attacker tactics, techniques and procedures (TTPs) and the ability to translate threat intelligence, attack paths and exploitation trends into actionable security improvements. Experience conducting security investigations and incident response activities, including alert triage, root cause analysis, containment, remediation and lessons learned. This is a hybrid role working 3 days a week in the London office and 2 days remotely.

Modal Window

  • Home
  • Contact
  • About Us
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • Facebook
  • Twitter
  • Google Plus
  • LinkedIn
Parent and Partner sites: IT Job Board | Jobs Near Me | RightTalent.co.uk | Quantity Surveyor jobs | Building Surveyor jobs | Construction Recruitment | Talent Recruiter | Construction Job Board | Property jobs | myJobsnearme.com | Jobs near me
© 2008-2026 Jobsite Jobs | Designed by Web Design Agency