• Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
  • Sign in
  • Sign up
  • Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

162 jobs found

Email me jobs like this
Refine Search
Current Search
cyber incident response lead
Insider Risk Manager
Kingfisher plc
We'reKingfisher, A team made up of over 70,000 passionate people who bring Kingfisher - and all our other brands: B&Q, Screwfix, Brico Depot, Castorama and Koctasto life. Guided by our purpose Better Homes. Better Lives. For Everyone. We believe a better world starts with better homes, and we work every day to make that a reality. Join us and help shape the future of home improvement. As our Insider Risk Manager, you'll play a critical role in protecting Kingfisher's data, systems and people from internal security risks. Working across Information Security, Technology, Legal, Privacy and People teams, you'll help identify, assess and reduce risks relating to inappropriate access, data loss, misuse of privileged access and compromised accounts. This is an opportunity to shape and mature Kingfisher's insider risk capability, driving both technical controls and colleague awareness to support the safe and responsible use of technology across the organisation. In doing so, you'll help protect our customers, colleagues and business while supporting our purpose of Better Homes, Better Lives, For Everyone. Develop and continuously improve Kingfisher's insider risk programme across people, process, data and technology controls. Identify, assess and mitigate insider risk scenarios, including data leakage, policy breaches, inappropriate access and compromised accounts. Partner with Information Security, Technology and business teams to strengthen preventative controls, monitoring and data protection measures. Deliver targeted awareness, communications and training activities that promote secure behaviours across the organisation. Support phishing simulations and other colleague-focused security initiatives, providing insight and recommendations for improvement. Coordinate the triage, investigation and escalation of suspected insider risk events, ensuring appropriate governance and confidentiality. Produce meaningful reporting and insights to identify trends, measure control effectiveness and inform security improvements. Experience within information security, cyber risk, insider risk, data protection, security operations or a similar risk-focused environment. Strong understanding of insider risk scenarios, including data loss, privileged access misuse, policy violations and account compromise. Experience supporting investigations, incident response, risk assessments or security monitoring activities. Ability to analyse data, security alerts and behavioural trends to identify risks and control gaps. Strong stakeholder management and communication skills, with the ability to explain complex security topics to technical and non-technical audiences. Knowledge of frameworks and standards such as ISO 27001, NIST, CIS Controls, GDPR or equivalent would be beneficial. How We Work We believe in flexibility and balance. Our hybrid model blends home working for focus with time spent connecting and collaborating - whether in our offices or at offsite locations. On average, around 60% of your time will involve in-person collaboration. We value the perspectives new team members bring and encourage you to apply - even if youdon'tmeet 100% of the requirements. We also offer a competitive benefits package and plenty of opportunities to stretch and grow your career.Scroll down below to find out more aboutour benefits. Diversity & Inclusion Our customers come from allwalks of life- and so do we.We'recommitted to ensuring all colleagues, future colleagues, and applicants are treated equally, regardless of age, gender, marital or civil partnership status, ethnicity, culture, religion, belief, political opinion, disability, gender identity, gender expression, or sexual orientation. What we offer. Private Health Care Opportunity to receive up to family level cover with AXA. Join within three months of starting or at annual renewal in April. (This benefit is subject to Benefit In Kind taxation). Kingfisher Pension Scheme Immediate eligibility through auto-enrolment. Contribute 8% to receive a max 14% from the Company. 25 Days' Holiday 25 days per annum plus bank holidays as stated in your contract (pro rated for part time colleagues). Staff Discount 20% discount at B&Q and Screwfix. Eligible after 3 months service. Kingfisher Share Incentive Plan (SIP) Share ownership in a tax efficient way. Save between £10 to £150 per month. Join at any time once three months service is reached. Life Assurance x4 Salary plus benefit equal to value of your Retirement Account (if an active member of KPS-MP) or x1 Salary if not active member. Bonus Competitive bonus scheme that aligns to work level of role. Kingfisher Share Save Save with the option to buy Kingfisher plc shares at the end of a 3 or 5 year period. Offered annually. Three months service is required at the annual invitation date, normally in October. Our Behaviours At Kingfisher, we are united by our 6 core behaviours Constantly improving our customer experience Acting with humanity and care Be curious Thriving on learning, thinking beyond the obvious Be inclusive Acting inclusively in diverse teams to achieve together Be agile Working with trust, pace and agility Be accountable Championing the plan to deliver results and growth Our employees know us best. We wouldn't be Kingfisher without them. So, we want to share what they think with you. Development and progression is a high priority at Kingfisher, I've always felt well supported. I'm proud to work for Kingfisher, I've had great opportunities that have enabled me to contribute to an exciting forward-thinking company. Training & Development There are so many ways you can grow, learn, and develop here at Kingfisher. At whatever pace suits you. Conversations with senior leaders Resources and tools to help you grow Improving without instruments to help you learn is near impossible. That's why we make sure you have everything at your fingertips to find exactly what you need to keep growing. Initiatives that measure development With plans that ask you what you want to achieve and when you want to achieve them by, tracking progress and keeping development at the forefront of conversation is easy. Find your path The scale of group functions within Kingfisher is huge. That means you have the chance to build different career paths within multiple areas of the organisation. Sharing is caring We aren't selfish here at Kingfisher. Whatever your level of experience, you'll work with colleagues who are always welcoming and ready to share their knowledge whenever you need it. Reach for the stars So your ambitions are high? Good thing we have opportunities to find experiences in line with more senior roles and responsibilities. Here, you can evolve your career, no matter your level. Why Kingfisher We're an innovative, international retailer on a journey to actively make a difference. Always striving to take that next step. You can be part of the difference. From bottom to top you can progress in a collaborative environment. So, why not Kingfisher?
Aug 27, 2026
Full time
We'reKingfisher, A team made up of over 70,000 passionate people who bring Kingfisher - and all our other brands: B&Q, Screwfix, Brico Depot, Castorama and Koctasto life. Guided by our purpose Better Homes. Better Lives. For Everyone. We believe a better world starts with better homes, and we work every day to make that a reality. Join us and help shape the future of home improvement. As our Insider Risk Manager, you'll play a critical role in protecting Kingfisher's data, systems and people from internal security risks. Working across Information Security, Technology, Legal, Privacy and People teams, you'll help identify, assess and reduce risks relating to inappropriate access, data loss, misuse of privileged access and compromised accounts. This is an opportunity to shape and mature Kingfisher's insider risk capability, driving both technical controls and colleague awareness to support the safe and responsible use of technology across the organisation. In doing so, you'll help protect our customers, colleagues and business while supporting our purpose of Better Homes, Better Lives, For Everyone. Develop and continuously improve Kingfisher's insider risk programme across people, process, data and technology controls. Identify, assess and mitigate insider risk scenarios, including data leakage, policy breaches, inappropriate access and compromised accounts. Partner with Information Security, Technology and business teams to strengthen preventative controls, monitoring and data protection measures. Deliver targeted awareness, communications and training activities that promote secure behaviours across the organisation. Support phishing simulations and other colleague-focused security initiatives, providing insight and recommendations for improvement. Coordinate the triage, investigation and escalation of suspected insider risk events, ensuring appropriate governance and confidentiality. Produce meaningful reporting and insights to identify trends, measure control effectiveness and inform security improvements. Experience within information security, cyber risk, insider risk, data protection, security operations or a similar risk-focused environment. Strong understanding of insider risk scenarios, including data loss, privileged access misuse, policy violations and account compromise. Experience supporting investigations, incident response, risk assessments or security monitoring activities. Ability to analyse data, security alerts and behavioural trends to identify risks and control gaps. Strong stakeholder management and communication skills, with the ability to explain complex security topics to technical and non-technical audiences. Knowledge of frameworks and standards such as ISO 27001, NIST, CIS Controls, GDPR or equivalent would be beneficial. How We Work We believe in flexibility and balance. Our hybrid model blends home working for focus with time spent connecting and collaborating - whether in our offices or at offsite locations. On average, around 60% of your time will involve in-person collaboration. We value the perspectives new team members bring and encourage you to apply - even if youdon'tmeet 100% of the requirements. We also offer a competitive benefits package and plenty of opportunities to stretch and grow your career.Scroll down below to find out more aboutour benefits. Diversity & Inclusion Our customers come from allwalks of life- and so do we.We'recommitted to ensuring all colleagues, future colleagues, and applicants are treated equally, regardless of age, gender, marital or civil partnership status, ethnicity, culture, religion, belief, political opinion, disability, gender identity, gender expression, or sexual orientation. What we offer. Private Health Care Opportunity to receive up to family level cover with AXA. Join within three months of starting or at annual renewal in April. (This benefit is subject to Benefit In Kind taxation). Kingfisher Pension Scheme Immediate eligibility through auto-enrolment. Contribute 8% to receive a max 14% from the Company. 25 Days' Holiday 25 days per annum plus bank holidays as stated in your contract (pro rated for part time colleagues). Staff Discount 20% discount at B&Q and Screwfix. Eligible after 3 months service. Kingfisher Share Incentive Plan (SIP) Share ownership in a tax efficient way. Save between £10 to £150 per month. Join at any time once three months service is reached. Life Assurance x4 Salary plus benefit equal to value of your Retirement Account (if an active member of KPS-MP) or x1 Salary if not active member. Bonus Competitive bonus scheme that aligns to work level of role. Kingfisher Share Save Save with the option to buy Kingfisher plc shares at the end of a 3 or 5 year period. Offered annually. Three months service is required at the annual invitation date, normally in October. Our Behaviours At Kingfisher, we are united by our 6 core behaviours Constantly improving our customer experience Acting with humanity and care Be curious Thriving on learning, thinking beyond the obvious Be inclusive Acting inclusively in diverse teams to achieve together Be agile Working with trust, pace and agility Be accountable Championing the plan to deliver results and growth Our employees know us best. We wouldn't be Kingfisher without them. So, we want to share what they think with you. Development and progression is a high priority at Kingfisher, I've always felt well supported. I'm proud to work for Kingfisher, I've had great opportunities that have enabled me to contribute to an exciting forward-thinking company. Training & Development There are so many ways you can grow, learn, and develop here at Kingfisher. At whatever pace suits you. Conversations with senior leaders Resources and tools to help you grow Improving without instruments to help you learn is near impossible. That's why we make sure you have everything at your fingertips to find exactly what you need to keep growing. Initiatives that measure development With plans that ask you what you want to achieve and when you want to achieve them by, tracking progress and keeping development at the forefront of conversation is easy. Find your path The scale of group functions within Kingfisher is huge. That means you have the chance to build different career paths within multiple areas of the organisation. Sharing is caring We aren't selfish here at Kingfisher. Whatever your level of experience, you'll work with colleagues who are always welcoming and ready to share their knowledge whenever you need it. Reach for the stars So your ambitions are high? Good thing we have opportunities to find experiences in line with more senior roles and responsibilities. Here, you can evolve your career, no matter your level. Why Kingfisher We're an innovative, international retailer on a journey to actively make a difference. Always striving to take that next step. You can be part of the difference. From bottom to top you can progress in a collaborative environment. So, why not Kingfisher?
Corriculo Ltd
Cyber Security Engineer, Cloud Security, SIEM, Incident Response, COR7555
Corriculo Ltd Oxford, Oxfordshire
Cyber Security Engineer, Cloud Security, SIEM, Incident Response, COR7555 An exciting opportunity has arisen for a Cyber Security Engineer to join a growing technology company based in Oxfordshire, working on a hybrid basis. This is a hands-on role focused on strengthening cyber security across cloud platforms, applications and business systems. Working closely with the CIO and development teams, the Cyber Security Engineer will play a key role in improving cloud security, incident response, vulnerability management, security monitoring and secure development practices, helping to enhance the organisation's overall cyber resilience. The company develops innovative software solutions for customers operating within highly regulated sectors and continues to experience significant international growth. This role offers excellent autonomy, exposure to senior leadership and genuine long-term progression as the organisation continues to expand. What's required of the Cyber Security Engineer? Proven hands-on experience within Cyber Security Engineering or Security Operations Experience with cloud security across AWS, Azure or GCP Experience with SIEM, EDR/XDR and security monitoring technologies Strong knowledge of vulnerability management and remediation Experience responding to and investigating security incidents Good understanding of network security technologies including Firewalls, IDS/IPS, WAF and VPNs Knowledge of secure software development, application security and OWASP principles Experience working with Identity & Access Management (IAM) Knowledge of security frameworks such as ISO27001, NIST or NIS2 Experience within regulated environments would be advantageous, with exposure to DORA, CMMC or similar frameworks beneficial What Next? If you're a Cyber Security Engineer looking for a varied, hands-on position where you can influence security across cloud, applications and infrastructure while developing towards future cyber security leadership, apply today to learn more! Cyber Security Engineer, Cloud Security, SIEM Corriculo Ltd acts as an employment agency and an employment business.
Aug 27, 2026
Full time
Cyber Security Engineer, Cloud Security, SIEM, Incident Response, COR7555 An exciting opportunity has arisen for a Cyber Security Engineer to join a growing technology company based in Oxfordshire, working on a hybrid basis. This is a hands-on role focused on strengthening cyber security across cloud platforms, applications and business systems. Working closely with the CIO and development teams, the Cyber Security Engineer will play a key role in improving cloud security, incident response, vulnerability management, security monitoring and secure development practices, helping to enhance the organisation's overall cyber resilience. The company develops innovative software solutions for customers operating within highly regulated sectors and continues to experience significant international growth. This role offers excellent autonomy, exposure to senior leadership and genuine long-term progression as the organisation continues to expand. What's required of the Cyber Security Engineer? Proven hands-on experience within Cyber Security Engineering or Security Operations Experience with cloud security across AWS, Azure or GCP Experience with SIEM, EDR/XDR and security monitoring technologies Strong knowledge of vulnerability management and remediation Experience responding to and investigating security incidents Good understanding of network security technologies including Firewalls, IDS/IPS, WAF and VPNs Knowledge of secure software development, application security and OWASP principles Experience working with Identity & Access Management (IAM) Knowledge of security frameworks such as ISO27001, NIST or NIS2 Experience within regulated environments would be advantageous, with exposure to DORA, CMMC or similar frameworks beneficial What Next? If you're a Cyber Security Engineer looking for a varied, hands-on position where you can influence security across cloud, applications and infrastructure while developing towards future cyber security leadership, apply today to learn more! Cyber Security Engineer, Cloud Security, SIEM Corriculo Ltd acts as an employment agency and an employment business.
Cyber Intelligence Director
JPMorgan Chase & Co.
Join us to make a real impact by protecting our firm and its supply chain from evolving cyber threats. You will drive innovation and collaborate with global teams, shaping the future of cybersecurity intelligence. We value your expertise and offer opportunities for growth and mobility. As part of our team, you'll help safeguard our clients and data while advancing your career. Experience a supportive culture where your contributions matter. As a Cyber Intelligence Director (Executive Director) at JPMorganChase within the EMEA Threat Intelligence team, you will identify and analyze external cyber threats to protect our firm's interests. You will collaborate with teams in North America and APAC, prioritizing intelligence streams and allocating resources for maximum impact. Your role enables secure business initiatives and strengthens our threat detection and response capabilities. You will help shape policies and frameworks that drive our cybersecurity strategy. We foster a collaborative and innovative environment where your leadership will make a difference. Job Responsibilities Identifies and assess complex global and industry-specific cyber threats Analyses cybersecurity intelligence and threat assessment data to inform risk management Partners with incident response teams to share findings and collaborate on investigations Develops and implement operational plans and strategic projects for threat detection and response Ensures alignment of threat intelligence initiatives with organizational strategies Influences and implement policies, processes, and frameworks for threat intelligence Supports brand protection, fraud prevention, and malware analysis Collaborates with global cyber intelligence teams to drive prioritization of intelligence streams Allocates resources to maximize team impact Communicates complex cybersecurity concepts to technical and non-technical stakeholders Leverages tools, including AI and LLM, to maximize efficiencies Required Qualifications, Capabilities, and Skills Expert level experience in cybersecurity, with a focus on threat intelligence, incident response, and risk management. Significant knowledge and experience in advanced intelligence analysis techniques, security research, and Open-Source Intelligence (OSINT) to proactively identify and assess potential risks. Knowledge of SIEM tools such as Splunk will be beneficial to your day to day work. Demonstrated ability to effectively convey complex cybersecurity concepts to both technical and non-technical senior stakeholders. Demonstrated ability to leverage tools, including AI and LLM tools, to maximize efficiencies. Preferred Qualifications, Capabilities, and Skills Familiarity with intelligence analysis tools and vendors is highly preferred.
Aug 27, 2026
Full time
Join us to make a real impact by protecting our firm and its supply chain from evolving cyber threats. You will drive innovation and collaborate with global teams, shaping the future of cybersecurity intelligence. We value your expertise and offer opportunities for growth and mobility. As part of our team, you'll help safeguard our clients and data while advancing your career. Experience a supportive culture where your contributions matter. As a Cyber Intelligence Director (Executive Director) at JPMorganChase within the EMEA Threat Intelligence team, you will identify and analyze external cyber threats to protect our firm's interests. You will collaborate with teams in North America and APAC, prioritizing intelligence streams and allocating resources for maximum impact. Your role enables secure business initiatives and strengthens our threat detection and response capabilities. You will help shape policies and frameworks that drive our cybersecurity strategy. We foster a collaborative and innovative environment where your leadership will make a difference. Job Responsibilities Identifies and assess complex global and industry-specific cyber threats Analyses cybersecurity intelligence and threat assessment data to inform risk management Partners with incident response teams to share findings and collaborate on investigations Develops and implement operational plans and strategic projects for threat detection and response Ensures alignment of threat intelligence initiatives with organizational strategies Influences and implement policies, processes, and frameworks for threat intelligence Supports brand protection, fraud prevention, and malware analysis Collaborates with global cyber intelligence teams to drive prioritization of intelligence streams Allocates resources to maximize team impact Communicates complex cybersecurity concepts to technical and non-technical stakeholders Leverages tools, including AI and LLM, to maximize efficiencies Required Qualifications, Capabilities, and Skills Expert level experience in cybersecurity, with a focus on threat intelligence, incident response, and risk management. Significant knowledge and experience in advanced intelligence analysis techniques, security research, and Open-Source Intelligence (OSINT) to proactively identify and assess potential risks. Knowledge of SIEM tools such as Splunk will be beneficial to your day to day work. Demonstrated ability to effectively convey complex cybersecurity concepts to both technical and non-technical senior stakeholders. Demonstrated ability to leverage tools, including AI and LLM tools, to maximize efficiencies. Preferred Qualifications, Capabilities, and Skills Familiarity with intelligence analysis tools and vendors is highly preferred.
Head of Information Security
jobr.pro
About Moneybox At Moneybox, our mission is to give everyone the means to get more out of life. We're guided by our belief that wealth isn't about the money, it's about the means to more - more freedom, opportunities, possibilities, and peace of mind. Moneybox is an award winning wealth management platform, helping over one and a half million people build wealth throughout their lives, whether they're saving and investing, buying their first home, or planning for retirement. Job Brief Moneybox is looking for a Head of Information Security to lead and mature our information security function. Reporting to the Engineering Director, this role will own Moneybox's Information Security Programme and be accountable for reducing security risk across our people, systems, products and third party ecosystem as the business continues to scale. This is a hands on leadership role. The successful candidate will need to think strategically, set direction and influence senior stakeholders whilst also being close enough to the detail to get things done. We are looking for someone who can build a small, high performing and nimble security function, using technology, automation and AI to increase the breadth, quality and pace of what the team can achieve. The role will suit an experienced information security leader who is pragmatic, commercially aware and focused on reducing meaningful risk, not creating unnecessary bureaucracy or replicating a big bank security model. What you'll do Owning and delivering Moneybox's information security strategy, roadmap and operating model. Leading the ongoing development of Moneybox's Information Security Programme, using NIST CSF as the practical risk management framework while aligning with ISO 27001 for governance, control maturity and assurance. Reducing real security risk across Moneybox's technology estate, people processes, suppliers and products. Building a small, effective and high leverage security function that uses technology, automation and AI to scale its impact. Providing clear, practical security leadership to senior stakeholders, including regular reporting on security posture, risks, incidents and priorities. Making proportionate, risk based decisions that support business growth while protecting customers and the organisation. Developing, maintaining and embedding practical information security policies, standards and procedures. Leading security awareness and training programmes that improve behaviours and strengthen Moneybox's security culture. Owning Moneybox's security incident response framework, ensuring the business is prepared to identify, contain, respond to and recover from security incidents effectively. Overseeing vulnerability management, including scanning, remediation, patching and risk based prioritisation. Leading third party security risk management for key vendors, partners and technology providers. Defining and tracking security metrics that focus on risk reduction and meaningful outcomes, not vanity reporting. Partnering with Engineering and Product teams to ensure security is built into systems, services and ways of working. Monitoring emerging threats, regulatory expectations and industry practice, then applying them pragmatically to Moneybox's environment. Continuously improving the security function without adding unnecessary complexity or bureaucracy. Who you are A strategic but hands on information security leader. A doer who is comfortable owning outcomes directly, not just delegating, advising or writing papers. Pragmatic and risk led with strong judgement on where security effort will have the greatest impact. Comfortable working in a small, nimble team where leverage comes from focus, automation, technology and strong prioritisation. Able to separate meaningful security risk from theoretical or low value control activity. Commercially aware, with the ability to balance security, customer experience, regulation and delivery. Clear and concise with senior stakeholders, able to translate security issues into business impact. Collaborative and able to influence across Engineering, Compliance, Legal, Product, Workplace Technology and the wider business. Strong understanding of current and emerging threats, and how to manage them proportionately in a fast moving organisation. Interested in how AI and automation can improve security operations, assurance, monitoring, reporting and decision making. Motivated by building a high quality security function that fits Moneybox, rather than importing a large enterprise or big bank model. Experience & Skills Proven experience leading or significantly contributing to an information security function. Strong working knowledge of risk based security management and the NIST Cyber Security Framework. Experience developing and delivering information security strategy, roadmaps, policies and controls. Practical knowledge of security technologies and business systems, including identity and access management, SIEM, endpoint security, cloud security, vulnerability management and remote working technologies. Experience using technology, automation or AI to improve security outcomes or operational efficiency. Experience managing security risk in cloud based environments, ideally including Azure. Strong understanding of third party security risk management. Experience with incident response planning, testing and improvement. Experience reporting security risks, controls and metrics to senior management. Strong communication skills, with the ability to translate technical security issues into clear business risks, recommendations and trade offs for senior stakeholders. Good understanding of financial services security, risk and regulatory expectations. Demonstrated leadership skills with the ability to influence, collaborate and drive change across teams. Excellent written and spoken English. Relevant professional certifications such as CISSP, CISM or CRISC are desirable, but practical judgement and delivery experience matter more. What's in it for you Opportunity to join a fast growing, award winning and super ambitious company. Work with a friendly team of highly motivated individuals. Be in an environment where you are listened to and can actually have an impact. Thriving collaborative and inclusive company culture. Competitive remuneration package. Company pension scheme. Company bonus scheme. Hybrid working environment. Home office furniture allowance. Personal annual learning and development budget. Private medical insurance. Health cash plan (cashback on visits to the dentist & opticians etc). Cycle to work scheme. Wellhub subscription to a variety of gyms and wellbeing apps. Enhanced parental pay & leave. 25 days holiday + bank holidays with additional days added with length of service. This is a hybrid role. Our office is in London, by the Oxo Tower. Our Commitment to DE&I At Moneybox, we promote, support and celebrate inclusion, diversity and equity for all, so that everyone can bring their full selves to work. We believe that diversity drives innovation, and that if our team is representative of our community of customers, we can better support their needs. To ensure our recruitment processes provide an equal opportunity for all applicants to succeed, we encourage you to let us know if there are any adjustments that we can make. We are open minded and always willing to go the extra mile to ensure all applicants can present their full self and potential. Working Policy We have a hybrid policy that includes 2 days from our London office and 3 from home. If the role states it is either hybrid or remote candidates must be based within the UK. Visa Sponsorship At this time we cannot offer visa sponsorship for this role and we cannot consider overseas applications. Please read before you apply! Please note if offered a position, the offer is conditional and subject to the receipt of satisfactory pre employment checks which we will conduct such as criminal record and adverse credit history checks. As a regulated financial business, an adverse financial history could impact your suitability for the role. If you are aware of anything that could affect your suitability for the role, please let us know in advance. Data Protection By sending us your application you acknowledge and agree to Moneybox using your personal data as described below. We collect applicants' personal data to manage our recruitment related activities. Consequently, we may use your personal data to evaluate your application, to select and shortlist applicants, to set up and conduct interviews and tests, to evaluate and assess the results, and as is otherwise needed in the recruitment process generally. We do not share your personal data with unauthorised third parties.
Aug 27, 2026
Full time
About Moneybox At Moneybox, our mission is to give everyone the means to get more out of life. We're guided by our belief that wealth isn't about the money, it's about the means to more - more freedom, opportunities, possibilities, and peace of mind. Moneybox is an award winning wealth management platform, helping over one and a half million people build wealth throughout their lives, whether they're saving and investing, buying their first home, or planning for retirement. Job Brief Moneybox is looking for a Head of Information Security to lead and mature our information security function. Reporting to the Engineering Director, this role will own Moneybox's Information Security Programme and be accountable for reducing security risk across our people, systems, products and third party ecosystem as the business continues to scale. This is a hands on leadership role. The successful candidate will need to think strategically, set direction and influence senior stakeholders whilst also being close enough to the detail to get things done. We are looking for someone who can build a small, high performing and nimble security function, using technology, automation and AI to increase the breadth, quality and pace of what the team can achieve. The role will suit an experienced information security leader who is pragmatic, commercially aware and focused on reducing meaningful risk, not creating unnecessary bureaucracy or replicating a big bank security model. What you'll do Owning and delivering Moneybox's information security strategy, roadmap and operating model. Leading the ongoing development of Moneybox's Information Security Programme, using NIST CSF as the practical risk management framework while aligning with ISO 27001 for governance, control maturity and assurance. Reducing real security risk across Moneybox's technology estate, people processes, suppliers and products. Building a small, effective and high leverage security function that uses technology, automation and AI to scale its impact. Providing clear, practical security leadership to senior stakeholders, including regular reporting on security posture, risks, incidents and priorities. Making proportionate, risk based decisions that support business growth while protecting customers and the organisation. Developing, maintaining and embedding practical information security policies, standards and procedures. Leading security awareness and training programmes that improve behaviours and strengthen Moneybox's security culture. Owning Moneybox's security incident response framework, ensuring the business is prepared to identify, contain, respond to and recover from security incidents effectively. Overseeing vulnerability management, including scanning, remediation, patching and risk based prioritisation. Leading third party security risk management for key vendors, partners and technology providers. Defining and tracking security metrics that focus on risk reduction and meaningful outcomes, not vanity reporting. Partnering with Engineering and Product teams to ensure security is built into systems, services and ways of working. Monitoring emerging threats, regulatory expectations and industry practice, then applying them pragmatically to Moneybox's environment. Continuously improving the security function without adding unnecessary complexity or bureaucracy. Who you are A strategic but hands on information security leader. A doer who is comfortable owning outcomes directly, not just delegating, advising or writing papers. Pragmatic and risk led with strong judgement on where security effort will have the greatest impact. Comfortable working in a small, nimble team where leverage comes from focus, automation, technology and strong prioritisation. Able to separate meaningful security risk from theoretical or low value control activity. Commercially aware, with the ability to balance security, customer experience, regulation and delivery. Clear and concise with senior stakeholders, able to translate security issues into business impact. Collaborative and able to influence across Engineering, Compliance, Legal, Product, Workplace Technology and the wider business. Strong understanding of current and emerging threats, and how to manage them proportionately in a fast moving organisation. Interested in how AI and automation can improve security operations, assurance, monitoring, reporting and decision making. Motivated by building a high quality security function that fits Moneybox, rather than importing a large enterprise or big bank model. Experience & Skills Proven experience leading or significantly contributing to an information security function. Strong working knowledge of risk based security management and the NIST Cyber Security Framework. Experience developing and delivering information security strategy, roadmaps, policies and controls. Practical knowledge of security technologies and business systems, including identity and access management, SIEM, endpoint security, cloud security, vulnerability management and remote working technologies. Experience using technology, automation or AI to improve security outcomes or operational efficiency. Experience managing security risk in cloud based environments, ideally including Azure. Strong understanding of third party security risk management. Experience with incident response planning, testing and improvement. Experience reporting security risks, controls and metrics to senior management. Strong communication skills, with the ability to translate technical security issues into clear business risks, recommendations and trade offs for senior stakeholders. Good understanding of financial services security, risk and regulatory expectations. Demonstrated leadership skills with the ability to influence, collaborate and drive change across teams. Excellent written and spoken English. Relevant professional certifications such as CISSP, CISM or CRISC are desirable, but practical judgement and delivery experience matter more. What's in it for you Opportunity to join a fast growing, award winning and super ambitious company. Work with a friendly team of highly motivated individuals. Be in an environment where you are listened to and can actually have an impact. Thriving collaborative and inclusive company culture. Competitive remuneration package. Company pension scheme. Company bonus scheme. Hybrid working environment. Home office furniture allowance. Personal annual learning and development budget. Private medical insurance. Health cash plan (cashback on visits to the dentist & opticians etc). Cycle to work scheme. Wellhub subscription to a variety of gyms and wellbeing apps. Enhanced parental pay & leave. 25 days holiday + bank holidays with additional days added with length of service. This is a hybrid role. Our office is in London, by the Oxo Tower. Our Commitment to DE&I At Moneybox, we promote, support and celebrate inclusion, diversity and equity for all, so that everyone can bring their full selves to work. We believe that diversity drives innovation, and that if our team is representative of our community of customers, we can better support their needs. To ensure our recruitment processes provide an equal opportunity for all applicants to succeed, we encourage you to let us know if there are any adjustments that we can make. We are open minded and always willing to go the extra mile to ensure all applicants can present their full self and potential. Working Policy We have a hybrid policy that includes 2 days from our London office and 3 from home. If the role states it is either hybrid or remote candidates must be based within the UK. Visa Sponsorship At this time we cannot offer visa sponsorship for this role and we cannot consider overseas applications. Please read before you apply! Please note if offered a position, the offer is conditional and subject to the receipt of satisfactory pre employment checks which we will conduct such as criminal record and adverse credit history checks. As a regulated financial business, an adverse financial history could impact your suitability for the role. If you are aware of anything that could affect your suitability for the role, please let us know in advance. Data Protection By sending us your application you acknowledge and agree to Moneybox using your personal data as described below. We collect applicants' personal data to manage our recruitment related activities. Consequently, we may use your personal data to evaluate your application, to select and shortlist applicants, to set up and conduct interviews and tests, to evaluate and assess the results, and as is otherwise needed in the recruitment process generally. We do not share your personal data with unauthorised third parties.
Anson McCade
SOC Shift Lead
Anson McCade City, London
SOC Shift Lead Location: London (Onsite, 24/7 Shift Pattern) Salary: Up to £84,000 (depending on experience) + 25% Shift Premium We're looking for an experienced SOC Shift Lead to join a high-performing cyber security operations team supporting critical, secure infrastructure in a 24/7 environment. This is an opportunity to lead incident response activities, mentor analysts, and play a key role in pr click apply for full job details
Aug 26, 2026
Full time
SOC Shift Lead Location: London (Onsite, 24/7 Shift Pattern) Salary: Up to £84,000 (depending on experience) + 25% Shift Premium We're looking for an experienced SOC Shift Lead to join a high-performing cyber security operations team supporting critical, secure infrastructure in a 24/7 environment. This is an opportunity to lead incident response activities, mentor analysts, and play a key role in pr click apply for full job details
Vice President, Risk and Control - Digital Engineering
MUFG Bank, Ltd
Vice President, Risk and Control - Digital EngineeringApplylocations: Londontime type: Full timeposted on: Posted Todayjob requisition id: -WD Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.Join MUFG, where being inspired is expected and making a meaningful impact is rewarded. Accountable for defining, creating and governing the Digital Engineering Risk and Control strategy in accordance with the wider EMEA Technology IT Risk and Control vision and strategy and risk appetite Accountable for defining the Digital Engineering Solutions and Services risk appetite and framework in accordance with the overall Technology departments risk appetite and tolerance framework, managing the departments operational, regulatory and financial risk Define and evolve the Digital Engineering Services and Solutions Key Risk Indicators' and Controls and govern accordingly Present the department's risk landscape, providing proactive oversight and prioritisation to ensure timely closure of issue Run the departments Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of Digital Engineering Services and Solutions and the Extended Leadership Team Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress Primary contact for all risk, control and audit issues across all Digital Engineering Solutions and Services teams Provide assurance over the department's controls design and effectiveness, ensuring controls are proportionate and embedded in day to day department activity Provide proactive assurance around risk management through appropriate data driven monitoring and through the implementation of structured sampling techniques to validate that controls are functioning as intended before failure Educate and lead the Digital Engineering Staff defining best practice operations and governance in line with industry and company standards Work in partnership with the Digital Engineering Solutions and Services Product and Platform owners, challenging and advising on risk management for new products, processes and change programmes. Provide risk-based decision making, supporting the department to make informed, risk-based decisions by providing an aggregated view of risk exposures Run the departments Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of Digital Engineering Services and Solutions and the Extended Leadership Team Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department Responsible for managing Issue Management on behalf Digital Engineering Services and Solutions department Handle potential sensitive information relating to Cyber Security events and assessments on behalf of Digital Engineering Services and Solutions Work across all areas of the Digital Engineering Services and Solutions department to ensure the Digital Engineering Control & Governance team provides necessary support services, oversight function and governance capabilities to all other extended leadership teams and stakeholders. Responsible for building strong relationships across the Bank and Securities functions, underpinned by trust and the core values of the bank. Developing strong relationships with key stakeholders such as IT Risk & Control, Cyber Security, other technology pillars, Operational Risk, Internal Audit, Compliance and external parties where applicable A senior role, that plays a pivotal part in strengthening a proactive, inclusive risk culture leading with example of the right leadership, culture and behaviours that are required in the bank. KEY RESPONSIBILITIES Digital Engineering Solutions and Services Governance Oversee Digital Engineering Services and Solutions relationship with IT Risk and 3rd parties for all external audits and assessments. Oversee Digital Engineering Services and Solutions relationship with IT Risk for all internal audits which have an Infrastructure or Service Management aspect. Ensure strong governance, structures and processes are in place to support effective operational risk and control management across the department Accountable for managing Open Issues on behalf of the Digital Engineering Services and Solutions department, tracking and ensuring proactive remediation and timely Support Digital Engineering Solutions and Services extended leadership teams with creation/attestation of key controls against the Operational Risk Framework. Manage engagement with stakeholders to design, plan and deliver remediation actions for control deficiencies. Oversee risk identification and mitigation efforts, ensuring understanding of strategic goals Ensure departments adherence to internal policies and external regulatory requirement Manage complex risk related loss events, conducting root cause analysis, working with Product and Platform owners to develop response plans Perform applicable operational control checks across Infrastructure and engage with other areas of Technology when required Work in partnership with the departments Incident management and Threat and Vulnerability team to detect and address vulnerabilities Ensure that the team operates in a controlled manner in accordance with standards and procedures whilst adhering to all related security and compliance procedures In conjunction with IT Risk, Security and Control, ensure that all regulatory requirements are fully complied with, including SOX assessments and appropriate defences and controls are in place to deal with all cyber risks Execute risk governance across all Digital Engineering Solutions and Services verticals. Provide support to Digital Engineering Services and Solutions for pen test findings Produce and manage Digital Engineering Solutions and Services owned Key Risk Indicators. Support disaster recovery exercises, ensuring new services are documented and deployed with BCP/DR in mind Provide advisory assistance to IT Risk and Control relating to My Access Live (MaL) and Access Management processes, acting as input into review processes with particular emphasis on Digital Engineering related platforms Input into Incident Management Process where appropriate Support new applications as and when released to the business Escalate potential service issues to the Management Produce regular risk management data for Management. Chair the Departments Risk Oversight Committee Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department. Culture and Leadership Support development of team with a strong focus on building future capabilities Lead and champion MUFG's inclusive, diverse, and values-led culture while fostering a growth mindset to embrace new technologies, industry advancements, and innovative use cases Ensure appropriate risk awareness training is in place across the department to fulfil current and future requirements Lead and promote a dynamic, delivery driven culture that works alongside business units to provide responsive resolutions and value driven solutions Build and nurture strong relationships with internal and external stakeholders, including business teams, to promote collaboration, understand industry's best practices, and influence positive change across the organization Support location strategies prescribed from MUFG and enable transitions (where appropriate) seamlessly WORK EXPERIENCE Essential: Extensive experience leading and managing risk and control and teams across multiple regions within a within a regulated environment. Extensive proficiency in scenario analysis and developing mitigation strategies Experience representing risk and control on behalf of a large Technology department to an Executive level audience A strong track record of engaging credibly with Executives providing confident challenge and clear, decision ready insight. Experience of working alongside network, server, database, desktop; asset management and storage functions Experienced in dealing with vendors and third-party suppliers Strong track record of managing teams and building effective partnerships with peers Experience with comprehensive disaster recovery architecture and operations, including storage area network and redundant, highly available server and network architectures Experience with regulatory compliance issues as they apply to Infrastructure SKILLS AND EXPERIENCE Essential: Extensive experience leading a risk & control function in a financial services organisation. Extensive experience working with Risk Management tools e.g Open Pages Understanding of the COBIT, NIST 2 framework Extensive experience leading internal audit and external audit bodies. Proven track record of managing risk related issues for large departments, through the lifecycle of creation, reporting and remediation. Experience with industry-specific regulatory requirements and their impact on operational risk . click apply for full job details
Aug 26, 2026
Full time
Vice President, Risk and Control - Digital EngineeringApplylocations: Londontime type: Full timeposted on: Posted Todayjob requisition id: -WD Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.Join MUFG, where being inspired is expected and making a meaningful impact is rewarded. Accountable for defining, creating and governing the Digital Engineering Risk and Control strategy in accordance with the wider EMEA Technology IT Risk and Control vision and strategy and risk appetite Accountable for defining the Digital Engineering Solutions and Services risk appetite and framework in accordance with the overall Technology departments risk appetite and tolerance framework, managing the departments operational, regulatory and financial risk Define and evolve the Digital Engineering Services and Solutions Key Risk Indicators' and Controls and govern accordingly Present the department's risk landscape, providing proactive oversight and prioritisation to ensure timely closure of issue Run the departments Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of Digital Engineering Services and Solutions and the Extended Leadership Team Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress Primary contact for all risk, control and audit issues across all Digital Engineering Solutions and Services teams Provide assurance over the department's controls design and effectiveness, ensuring controls are proportionate and embedded in day to day department activity Provide proactive assurance around risk management through appropriate data driven monitoring and through the implementation of structured sampling techniques to validate that controls are functioning as intended before failure Educate and lead the Digital Engineering Staff defining best practice operations and governance in line with industry and company standards Work in partnership with the Digital Engineering Solutions and Services Product and Platform owners, challenging and advising on risk management for new products, processes and change programmes. Provide risk-based decision making, supporting the department to make informed, risk-based decisions by providing an aggregated view of risk exposures Run the departments Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of Digital Engineering Services and Solutions and the Extended Leadership Team Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department Responsible for managing Issue Management on behalf Digital Engineering Services and Solutions department Handle potential sensitive information relating to Cyber Security events and assessments on behalf of Digital Engineering Services and Solutions Work across all areas of the Digital Engineering Services and Solutions department to ensure the Digital Engineering Control & Governance team provides necessary support services, oversight function and governance capabilities to all other extended leadership teams and stakeholders. Responsible for building strong relationships across the Bank and Securities functions, underpinned by trust and the core values of the bank. Developing strong relationships with key stakeholders such as IT Risk & Control, Cyber Security, other technology pillars, Operational Risk, Internal Audit, Compliance and external parties where applicable A senior role, that plays a pivotal part in strengthening a proactive, inclusive risk culture leading with example of the right leadership, culture and behaviours that are required in the bank. KEY RESPONSIBILITIES Digital Engineering Solutions and Services Governance Oversee Digital Engineering Services and Solutions relationship with IT Risk and 3rd parties for all external audits and assessments. Oversee Digital Engineering Services and Solutions relationship with IT Risk for all internal audits which have an Infrastructure or Service Management aspect. Ensure strong governance, structures and processes are in place to support effective operational risk and control management across the department Accountable for managing Open Issues on behalf of the Digital Engineering Services and Solutions department, tracking and ensuring proactive remediation and timely Support Digital Engineering Solutions and Services extended leadership teams with creation/attestation of key controls against the Operational Risk Framework. Manage engagement with stakeholders to design, plan and deliver remediation actions for control deficiencies. Oversee risk identification and mitigation efforts, ensuring understanding of strategic goals Ensure departments adherence to internal policies and external regulatory requirement Manage complex risk related loss events, conducting root cause analysis, working with Product and Platform owners to develop response plans Perform applicable operational control checks across Infrastructure and engage with other areas of Technology when required Work in partnership with the departments Incident management and Threat and Vulnerability team to detect and address vulnerabilities Ensure that the team operates in a controlled manner in accordance with standards and procedures whilst adhering to all related security and compliance procedures In conjunction with IT Risk, Security and Control, ensure that all regulatory requirements are fully complied with, including SOX assessments and appropriate defences and controls are in place to deal with all cyber risks Execute risk governance across all Digital Engineering Solutions and Services verticals. Provide support to Digital Engineering Services and Solutions for pen test findings Produce and manage Digital Engineering Solutions and Services owned Key Risk Indicators. Support disaster recovery exercises, ensuring new services are documented and deployed with BCP/DR in mind Provide advisory assistance to IT Risk and Control relating to My Access Live (MaL) and Access Management processes, acting as input into review processes with particular emphasis on Digital Engineering related platforms Input into Incident Management Process where appropriate Support new applications as and when released to the business Escalate potential service issues to the Management Produce regular risk management data for Management. Chair the Departments Risk Oversight Committee Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department. Culture and Leadership Support development of team with a strong focus on building future capabilities Lead and champion MUFG's inclusive, diverse, and values-led culture while fostering a growth mindset to embrace new technologies, industry advancements, and innovative use cases Ensure appropriate risk awareness training is in place across the department to fulfil current and future requirements Lead and promote a dynamic, delivery driven culture that works alongside business units to provide responsive resolutions and value driven solutions Build and nurture strong relationships with internal and external stakeholders, including business teams, to promote collaboration, understand industry's best practices, and influence positive change across the organization Support location strategies prescribed from MUFG and enable transitions (where appropriate) seamlessly WORK EXPERIENCE Essential: Extensive experience leading and managing risk and control and teams across multiple regions within a within a regulated environment. Extensive proficiency in scenario analysis and developing mitigation strategies Experience representing risk and control on behalf of a large Technology department to an Executive level audience A strong track record of engaging credibly with Executives providing confident challenge and clear, decision ready insight. Experience of working alongside network, server, database, desktop; asset management and storage functions Experienced in dealing with vendors and third-party suppliers Strong track record of managing teams and building effective partnerships with peers Experience with comprehensive disaster recovery architecture and operations, including storage area network and redundant, highly available server and network architectures Experience with regulatory compliance issues as they apply to Infrastructure SKILLS AND EXPERIENCE Essential: Extensive experience leading a risk & control function in a financial services organisation. Extensive experience working with Risk Management tools e.g Open Pages Understanding of the COBIT, NIST 2 framework Extensive experience leading internal audit and external audit bodies. Proven track record of managing risk related issues for large departments, through the lifecycle of creation, reporting and remediation. Experience with industry-specific regulatory requirements and their impact on operational risk . click apply for full job details
VP, Legal Counsel - Data Privacy, Digital & Technology
LGBT Great
Position Overview PIMCO is seeking a Vice President, Legal Counsel with deep expertise in data privacy, digital and technology regulation to join our EMEA Legal team. In this role, you will provide specialist legal guidance on a broad range of data, privacy, digital and technology matters across the EMEA region. You will partner closely with Legal, IT, Compliance, Risk and business stakeholders to ensure PIMCO's growing operations meet evolving regulatory requirements. This is a strategic position requiring strong subject matter expertise, commercial judgment, and the ability to influence legal and operational strategy in an increasingly digital environment. Responsibilities Data Privacy & GDPR Compliance Advise on GDPR and EU/UK privacy requirements across all EMEA business activities. Guide teams on lawful data processing, data subject rights, crossborder transfers and data breach reporting. Support responses to data subject access requests and ensure alignment with internal privacy policies. Technology, Outsourcing & Vendor Arrangements Advise on Data/IT/Tech outsourcing and thirdparty risk requirements. Negotiate and review cloud, IT and technology vendor agreements, including data protection and security terms. AI, Digital Innovation & Emerging Technologies Provide legal guidance on AI frameworks, including EU AI Act implications. Support the safe deployment of AIdriven tools and digital capabilities across the firm. Digital & Technology Regulatory Requirements Monitor and interpret emerging EU/UK regulations relating to data, digital services, fintech, operational resilience and cybersecurity. Advise on implementation programmes and ensure PIMCO's global practices align with local regulatory expectations. Business & Technology Change Projects Partner with project teams on IT upgrades, digital transformation, operational changes and AI rollouts. Identify and address legal and regulatory considerations across privacy, digital, cybersecurity and outsourcing domains. Cybersecurity & Incident Response Advise on cybersecurity legal obligations and internal policies. Support breach response, regulatory notifications, client communications and incident remediation. Lead on legal aspects of fraudulent incidents (e.g., website or email impersonation scams). EMEA Regional Coverage Act as the regional expert on data, digital and technology laws. Manage external counsel relationships and contribute to global initiatives by bringing an EMEA perspective. Required Qualifications Qualified Lawyer with strong academic credentials (UK or relevant EMEA jurisdiction). 3+ years PQE in data protection, technology law, IT/cybersecurity or related fields, including substantial GDPR work. Deep expertise in EU/UK privacy frameworks (GDPR, Data Protection Act, e-Privacy, international transfers). Strong understanding of AI, cybersecurity and technology regulations, including the EU AI Act. Excellent drafting and negotiation skills, especially for DPAs, outsourcing agreements and IT vendor contracts. Strong analytical capability to navigate complex and emerging digital regulatory issues. Excellent communication skills, with the ability to distil complex requirements for business and technical teams and present to senior audiences. Clientservice mindset, proactive, responsive and able to work independently within a collaborative legal team. Preferred Experience Experience within financial services or asset management (inhouse or advisory) is highly desirable. Prior inhouse legal counsel experience. Exposure to multijurisdictional regulatory implementations or crossborder projects. Why Join PIMCO Data and technology innovation are increasingly central to financial services. This role offers the opportunity to support PIMCO's expanding business, shape digital transformation initiatives, and contribute to the firm's reputation for operational excellence. Equal Employment Opportunity and Affimative Action Statement PIMCO recruits and hires qualified candidates without regard to race, national origin, ancestry, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), sexual orientation, gender (including gender identity and expression), age, military or veteran status, disability (physical or mental), any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity and affirmative action, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other basis such as medical condition, or marital status under applicable laws. Applicants with Disabilities PIMCO is an Equal Employment Opportunity/Affirmative Action employer. We provide reasonable accommodation for qualified individuals with disabilities, including veterans, in job application procedures. If you have any difficulty using our online system due to a disability and you would like to request an accommodation, you may contact us at and leave a message. This is a dedicated line designed exclusively to assist job seekers with disabilities to apply online. Only messages left for this purpose will be considered. A response to your request may take up to two business days.
Aug 26, 2026
Full time
Position Overview PIMCO is seeking a Vice President, Legal Counsel with deep expertise in data privacy, digital and technology regulation to join our EMEA Legal team. In this role, you will provide specialist legal guidance on a broad range of data, privacy, digital and technology matters across the EMEA region. You will partner closely with Legal, IT, Compliance, Risk and business stakeholders to ensure PIMCO's growing operations meet evolving regulatory requirements. This is a strategic position requiring strong subject matter expertise, commercial judgment, and the ability to influence legal and operational strategy in an increasingly digital environment. Responsibilities Data Privacy & GDPR Compliance Advise on GDPR and EU/UK privacy requirements across all EMEA business activities. Guide teams on lawful data processing, data subject rights, crossborder transfers and data breach reporting. Support responses to data subject access requests and ensure alignment with internal privacy policies. Technology, Outsourcing & Vendor Arrangements Advise on Data/IT/Tech outsourcing and thirdparty risk requirements. Negotiate and review cloud, IT and technology vendor agreements, including data protection and security terms. AI, Digital Innovation & Emerging Technologies Provide legal guidance on AI frameworks, including EU AI Act implications. Support the safe deployment of AIdriven tools and digital capabilities across the firm. Digital & Technology Regulatory Requirements Monitor and interpret emerging EU/UK regulations relating to data, digital services, fintech, operational resilience and cybersecurity. Advise on implementation programmes and ensure PIMCO's global practices align with local regulatory expectations. Business & Technology Change Projects Partner with project teams on IT upgrades, digital transformation, operational changes and AI rollouts. Identify and address legal and regulatory considerations across privacy, digital, cybersecurity and outsourcing domains. Cybersecurity & Incident Response Advise on cybersecurity legal obligations and internal policies. Support breach response, regulatory notifications, client communications and incident remediation. Lead on legal aspects of fraudulent incidents (e.g., website or email impersonation scams). EMEA Regional Coverage Act as the regional expert on data, digital and technology laws. Manage external counsel relationships and contribute to global initiatives by bringing an EMEA perspective. Required Qualifications Qualified Lawyer with strong academic credentials (UK or relevant EMEA jurisdiction). 3+ years PQE in data protection, technology law, IT/cybersecurity or related fields, including substantial GDPR work. Deep expertise in EU/UK privacy frameworks (GDPR, Data Protection Act, e-Privacy, international transfers). Strong understanding of AI, cybersecurity and technology regulations, including the EU AI Act. Excellent drafting and negotiation skills, especially for DPAs, outsourcing agreements and IT vendor contracts. Strong analytical capability to navigate complex and emerging digital regulatory issues. Excellent communication skills, with the ability to distil complex requirements for business and technical teams and present to senior audiences. Clientservice mindset, proactive, responsive and able to work independently within a collaborative legal team. Preferred Experience Experience within financial services or asset management (inhouse or advisory) is highly desirable. Prior inhouse legal counsel experience. Exposure to multijurisdictional regulatory implementations or crossborder projects. Why Join PIMCO Data and technology innovation are increasingly central to financial services. This role offers the opportunity to support PIMCO's expanding business, shape digital transformation initiatives, and contribute to the firm's reputation for operational excellence. Equal Employment Opportunity and Affimative Action Statement PIMCO recruits and hires qualified candidates without regard to race, national origin, ancestry, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), sexual orientation, gender (including gender identity and expression), age, military or veteran status, disability (physical or mental), any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity and affirmative action, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other basis such as medical condition, or marital status under applicable laws. Applicants with Disabilities PIMCO is an Equal Employment Opportunity/Affirmative Action employer. We provide reasonable accommodation for qualified individuals with disabilities, including veterans, in job application procedures. If you have any difficulty using our online system due to a disability and you would like to request an accommodation, you may contact us at and leave a message. This is a dedicated line designed exclusively to assist job seekers with disabilities to apply online. Only messages left for this purpose will be considered. A response to your request may take up to two business days.
Senior Cybersecurity & Data Privacy Counsel
Jobtailor
PayPal is seeking an experienced in-house Senior Counsel to provide clear, pragmatic legal advice to support business strategy while managing legal risk in a fast paced environment. You will lead complex incident responses, coordinate with multi-jurisdictional regulators, and ensure compliance with ICO, FCA, EU authorities, and US requirements, helping the enterprise deliver secure digital services.
Aug 26, 2026
Full time
PayPal is seeking an experienced in-house Senior Counsel to provide clear, pragmatic legal advice to support business strategy while managing legal risk in a fast paced environment. You will lead complex incident responses, coordinate with multi-jurisdictional regulators, and ensure compliance with ICO, FCA, EU authorities, and US requirements, helping the enterprise deliver secure digital services.
Security Incident Management Lead
Jobtailor
Overview Own and evolve the end-to-end Security Incident Management process, ensuring it is clear, effective, and embedded across teams Develop, maintain, and improve incident playbooks, workflows, and procedures, keeping them aligned to threat, risk, and operational needs Design and run the annual security incident exercise schedule, covering low level tabletop exercises through to complex, cross-team simulations Lead the planning and execution of exercises, ensuring clear objectives, measurable outcomes, and actionable improvements Use lessons learned from incidents and exercises to drive continuous improvement in response capability and resilience Act as the senior escalation point for priority incidents, providing leadership, coordination, and decision support when required Support incident triage and routing across SIM, Major Incident Management (MIM), and Cyber Support Services (CSS) Own the Monthly SIM review and reporting, providing clear insight, trends, and recommendations to stakeholders Requirements Proven experience building, leading and maturing cyber security incident management capability within a complex, global organisation More than 5 years' operating at a senior level in security / incident management, with credibility gained in large, complex, global organisations Strong track record of defining and improving end-to-end security incident management frameworks, not just operating within them Extensive experience designing and delivering security incident response exercises, from large-scale, multi-team simulations to smaller cross team tabletop exercise Demonstrable experience embedding playbooks, processes and governance across operational teams, driving consistency and maturity Ability to translate lessons learned, threat intelligence and industry best practice into tangible improvements in capability and resilience Comfortable providing decisive leadership during live cyber incidents when required, while maintaining a focus on improving the overall operating model Strong stakeholder management, able to work across technical and non-technical teams and bring alignment in a matrix environment Experience driving continuous improvement at pace, identifying gaps, challenging existing approaches and delivering measurable outcomes
Aug 26, 2026
Full time
Overview Own and evolve the end-to-end Security Incident Management process, ensuring it is clear, effective, and embedded across teams Develop, maintain, and improve incident playbooks, workflows, and procedures, keeping them aligned to threat, risk, and operational needs Design and run the annual security incident exercise schedule, covering low level tabletop exercises through to complex, cross-team simulations Lead the planning and execution of exercises, ensuring clear objectives, measurable outcomes, and actionable improvements Use lessons learned from incidents and exercises to drive continuous improvement in response capability and resilience Act as the senior escalation point for priority incidents, providing leadership, coordination, and decision support when required Support incident triage and routing across SIM, Major Incident Management (MIM), and Cyber Support Services (CSS) Own the Monthly SIM review and reporting, providing clear insight, trends, and recommendations to stakeholders Requirements Proven experience building, leading and maturing cyber security incident management capability within a complex, global organisation More than 5 years' operating at a senior level in security / incident management, with credibility gained in large, complex, global organisations Strong track record of defining and improving end-to-end security incident management frameworks, not just operating within them Extensive experience designing and delivering security incident response exercises, from large-scale, multi-team simulations to smaller cross team tabletop exercise Demonstrable experience embedding playbooks, processes and governance across operational teams, driving consistency and maturity Ability to translate lessons learned, threat intelligence and industry best practice into tangible improvements in capability and resilience Comfortable providing decisive leadership during live cyber incidents when required, while maintaining a focus on improving the overall operating model Strong stakeholder management, able to work across technical and non-technical teams and bring alignment in a matrix environment Experience driving continuous improvement at pace, identifying gaps, challenging existing approaches and delivering measurable outcomes
Managing Director - Global Head of Crisis Management and JOC
3761 Barclays - BX - UK
Job Description Role Responsibilities Ensure the resilience, continuity and coordinated response of the bank during operational disruptions, crises or emergencies. This role is critical in safeguarding the bank's reputation, regulatory compliance and customer trust. The role provides enterprise-wide accountability for preparedness, command and control, escalation and cross-functional mobilisation, ensuring that Barclays can protect customers, colleagues, critical services and assets while sustaining confidence among the Board, regulators and external stakeholders. Lead the Joint Operations Centres (JOCs) that integrate business units, IT, risk, and compliance functions; align crisis response across local, regional, and global teams; and maintain real-time situational awareness and decision making support tools. Ensure there is compliance with regulatory expectations for crisis management and operational risk (e.g., from the FCA, PRA, or BIS); report to the Board Risk Committee and regulators on preparedness and incident outcomes; and support audits, reviews, and post incident reporting. Develop and maintain enterprise wide crisis management frameworks; lead incident response teams during disruptions (e.g., cyberattacks, system outages, financial shocks); coordinate with executive leadership, including the Global CISO, regulators, and external partners to manage crises effectively. Partner with the Resilience Lead and business leadership to sustain the delivery of critical services during and after disruption, aligning recovery priorities to customer, regulatory and enterprise outcomes. Ensure an effective framework is in place to deliver consistent internal and external communications in a crisis, including effective incident notification and escalation. Own the enterprise-wide communications approach across customers, colleagues, regulators and external partners, working with Legal, Corporate Affairs and supporting functions to manage reputational risk. Role Requirements Deep understanding of the Joint Operations Centres planning and operational processes that leads to seamless execution of operational incident management. Knowledge of crisis management frameworks (contingency planning, incident escalation and strategic oversight) and the ability to lead during high pressure, time sensitive situations. Technical understanding of physical and digital infrastructure, security and operational risks. The ability to interpret and act on real time intelligence and identify business impacts and ensure effective preparedness planning. Know how to implement knowledge management systems across all global locations to reduce information silos and support effective decision making. Understand the external landscape and dependencies this brings to the Bank - including the geo political landscape, navigating regulatory, sector wide and operational risks. Responds flexibly to unexpected and evolving events, maintaining composure and inspiring confidence through periods of significant uncertainty. Demonstrates a strong track record of implementing Group wide innovation and continuous improvement, embedding lessons from live incidents, post incident reviews and exercises into preparedness, response and recovery. Leads crisis leadership team meetings at Board and ExCo Level, also having the communication and influencing skills to conduct training activities with the same group. Management of enterprise wide risk crisis communications processes to ensure prompt consistent group wide communication to customers, colleagues and regulators. Have extensive experience in effective communications and be able to influence and negotiate across the 5 business divisions, globally and to the points of contact in the regions where there is a Barclays footprint. Lead and drive consistent communications with internal and external stakeholders such PR, legal and supporting functions to manage reputational risk. Managing Director Expectations To manage a large, complex or diverse function and take accountability for the strategic direction of the function to significantly strengthen successful and efficient businesses and contribute to the strategic initiatives of the Barclays Group. Lead and mentor high performing teams and embed a performance culture aligned to the values of the business. Or for an individual contributor, they lead organisation wide projects, act as a profound technical expert and thought leader, identifying new and innovative/ground breaking ways of working. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions. Drive and achieve overall success and / or competitiveness of a business division by influencing senior leaders and committees. Strategically assess and manage risks to protect the business division / function and growth. Influence company policy and develop functional procedures in conjunction with senior leaders / strategic positions across the business. Demonstrate interpretative thinking for innovative solutions in complex situations and conceptual thinking in completely new situations. Exercise management authority to make significant / complex business and strategic decisions that impact the Barclays Group, business division or function. Negotiate with and influence stakeholders at a senior level both internally and externally and foster growth for Barclays business. Mandated as the business division/ functional spokesperson or representative to external bodies and shapes the public image of Barclays. Demonstrate exceptional knowledge of how business divisions and functions integrate with the Group to achieve the overall business objectives alongside industry theories and practices within own discipline. Maintain broad and comprehensive functional expertise and significant product knowledge. Accountable for the control and governance agenda of the business division / function. Focus on the external environment, regulators, or advocacy groups to both monitor and influence on behalf of Barclays. All Senior Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L - Listen and be authentic E - Energise and inspire A - Align across the enterprise D - Develop others All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship - our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset - to Empower, Challenge and Drive - the operating manual for how we behave. Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. - Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. Our employees are self disciplined, hard working, curious, trustworthy, humble, and truthful. They make choices according to what is best for the team, they live for opportunities to collaborate and make a difference, and they make us the Top Workplace in the area.
Aug 26, 2026
Full time
Job Description Role Responsibilities Ensure the resilience, continuity and coordinated response of the bank during operational disruptions, crises or emergencies. This role is critical in safeguarding the bank's reputation, regulatory compliance and customer trust. The role provides enterprise-wide accountability for preparedness, command and control, escalation and cross-functional mobilisation, ensuring that Barclays can protect customers, colleagues, critical services and assets while sustaining confidence among the Board, regulators and external stakeholders. Lead the Joint Operations Centres (JOCs) that integrate business units, IT, risk, and compliance functions; align crisis response across local, regional, and global teams; and maintain real-time situational awareness and decision making support tools. Ensure there is compliance with regulatory expectations for crisis management and operational risk (e.g., from the FCA, PRA, or BIS); report to the Board Risk Committee and regulators on preparedness and incident outcomes; and support audits, reviews, and post incident reporting. Develop and maintain enterprise wide crisis management frameworks; lead incident response teams during disruptions (e.g., cyberattacks, system outages, financial shocks); coordinate with executive leadership, including the Global CISO, regulators, and external partners to manage crises effectively. Partner with the Resilience Lead and business leadership to sustain the delivery of critical services during and after disruption, aligning recovery priorities to customer, regulatory and enterprise outcomes. Ensure an effective framework is in place to deliver consistent internal and external communications in a crisis, including effective incident notification and escalation. Own the enterprise-wide communications approach across customers, colleagues, regulators and external partners, working with Legal, Corporate Affairs and supporting functions to manage reputational risk. Role Requirements Deep understanding of the Joint Operations Centres planning and operational processes that leads to seamless execution of operational incident management. Knowledge of crisis management frameworks (contingency planning, incident escalation and strategic oversight) and the ability to lead during high pressure, time sensitive situations. Technical understanding of physical and digital infrastructure, security and operational risks. The ability to interpret and act on real time intelligence and identify business impacts and ensure effective preparedness planning. Know how to implement knowledge management systems across all global locations to reduce information silos and support effective decision making. Understand the external landscape and dependencies this brings to the Bank - including the geo political landscape, navigating regulatory, sector wide and operational risks. Responds flexibly to unexpected and evolving events, maintaining composure and inspiring confidence through periods of significant uncertainty. Demonstrates a strong track record of implementing Group wide innovation and continuous improvement, embedding lessons from live incidents, post incident reviews and exercises into preparedness, response and recovery. Leads crisis leadership team meetings at Board and ExCo Level, also having the communication and influencing skills to conduct training activities with the same group. Management of enterprise wide risk crisis communications processes to ensure prompt consistent group wide communication to customers, colleagues and regulators. Have extensive experience in effective communications and be able to influence and negotiate across the 5 business divisions, globally and to the points of contact in the regions where there is a Barclays footprint. Lead and drive consistent communications with internal and external stakeholders such PR, legal and supporting functions to manage reputational risk. Managing Director Expectations To manage a large, complex or diverse function and take accountability for the strategic direction of the function to significantly strengthen successful and efficient businesses and contribute to the strategic initiatives of the Barclays Group. Lead and mentor high performing teams and embed a performance culture aligned to the values of the business. Or for an individual contributor, they lead organisation wide projects, act as a profound technical expert and thought leader, identifying new and innovative/ground breaking ways of working. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions. Drive and achieve overall success and / or competitiveness of a business division by influencing senior leaders and committees. Strategically assess and manage risks to protect the business division / function and growth. Influence company policy and develop functional procedures in conjunction with senior leaders / strategic positions across the business. Demonstrate interpretative thinking for innovative solutions in complex situations and conceptual thinking in completely new situations. Exercise management authority to make significant / complex business and strategic decisions that impact the Barclays Group, business division or function. Negotiate with and influence stakeholders at a senior level both internally and externally and foster growth for Barclays business. Mandated as the business division/ functional spokesperson or representative to external bodies and shapes the public image of Barclays. Demonstrate exceptional knowledge of how business divisions and functions integrate with the Group to achieve the overall business objectives alongside industry theories and practices within own discipline. Maintain broad and comprehensive functional expertise and significant product knowledge. Accountable for the control and governance agenda of the business division / function. Focus on the external environment, regulators, or advocacy groups to both monitor and influence on behalf of Barclays. All Senior Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L - Listen and be authentic E - Energise and inspire A - Align across the enterprise D - Develop others All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship - our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset - to Empower, Challenge and Drive - the operating manual for how we behave. Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. - Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. Our employees are self disciplined, hard working, curious, trustworthy, humble, and truthful. They make choices according to what is best for the team, they live for opportunities to collaborate and make a difference, and they make us the Top Workplace in the area.
Safety & Security Counsel, EMEA
United States Digital Space LLC
About the company the company's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role As Safety & Security Counsel, EMEA, you will serve as the first-line legal advisor counseling on the full arc of keeping Claude and the company safe and secure: usage policy design and enforcement frameworks, safeguards R&D, misuse detection and response, sensitive escalations, threat intelligence, security incident response, product-related safety and security matters, and the company's safety and security-related regulatory and policy engagement. The issues are increasingly interdisciplinary and novel, and you will frequently be the one ideating and building a legally-relevant framework rather than simply applying one. Depending on interest and experience, you will own and shape an ever-growing portfolio of issue areas across Safeguards and Security. You will also contribute to the team's capacity building efforts, including by leveraging Claude. You will work collaboratively with other legal functions on cross-functional initiatives. This is an excellent opportunity for an experienced attorney who wants to do high-stakes, first-of-its-kind work at the center of responsible AI development and deployment, and to grow as a strategic product counsel and trusted crisis counselor in a fast-moving environment. Key responsibilities Partner with Safeguards (trust & safety) policy teams on the design and iteration of usage policies across harm areas (e.g., CBRNE, cyber, user wellbeing, scaled abuse and influence operations, and distillation), including how policies translate into detection and enforcement. Advise on policy enforcement frameworks such as account actions, appeals, enforcement systems and thresholds. Counsel on sensitive escalations and strategic response, including matters involving governments, law enforcement, regulators, and the press. Advise on safety and security threat intelligence investigations, bug bounty and red-team programs, and internal and external safety and security testing arrangements. Support safeguards and security engineering, ML, and data science teams on building new tooling and detection mechanisms, including as it relates to data governance and privacy related considerations. Serve as a first-line legal contact for safety and security incidents, providing real-time guidance during incident response and assessing notification and reporting obligations under applicable legal frameworks and contractual commitments. Build and maintain crisis management playbooks, escalation protocols, and self-serve legal guidance to enable legal resource scaling. Stay abreast of key policy and regulatory developments in AI safety and security, and policy-specific domains across relevant jurisdictions, and translate them into practical guidance for our evolving product suite. Minimum qualifications Qualification to practice law in England & Wales, or another relevant jurisdiction Experience advising on fast-moving, high-stakes matters such as investigations, regulatory matters, crisis management, or enforcement work Working knowledge of at least one of: trust & safety, cybersecurity, privacy, or platform regulation Legal drafting and writing skills demonstrated through policies, playbooks, escalation protocols, or written guidance for non-legal audiences Technical fluency sufficient to understand system architecture, data flows, and AI model behavior Experience coordinating multi-stakeholder responses to time-sensitive matters and translating legal analysis into clear actionable steps for technical and executive audiences Preferred qualifications 8+ years of relevant legal experience In-house (product counsel) experience at a technology company working on security and/or trust & safety issues, or law firm experience advising tech clients on regulatory investigations or enforcement matters Experience with content moderation, platform safety (including user wellbeing issues), and crisis management Facility working with very technical teams, including machine learning, safety and security research, infrastructure, and threat intelligence Familiarity with AI systems and machine learning concepts, or experience advising on novel technology products Strong judgment about risk assessment and decision-making under uncertainty A low-ego, hands-on working style and a commitment to doing right by users and the people affected by misuse of AI systems Application Deadline: 6pm PT on Friday September 11, 2026. We encourage all interested and qualified applicants to submit their materials before this date to ensure full consideration. Role-specific policy: For this role, we expect all staff to be able to work from our London office at least 3 days a week, though we encourage you to apply even if you might need some flexibility for an interim period of time. The annual compensation range for this role is listed below. For sales roles, the range provided is the role's On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role. Annual Salary: £165,000-£205,000 GBP LogisticsMinimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices. Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this. We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of your candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team. Your safety matters to us.
Aug 26, 2026
Full time
About the company the company's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role As Safety & Security Counsel, EMEA, you will serve as the first-line legal advisor counseling on the full arc of keeping Claude and the company safe and secure: usage policy design and enforcement frameworks, safeguards R&D, misuse detection and response, sensitive escalations, threat intelligence, security incident response, product-related safety and security matters, and the company's safety and security-related regulatory and policy engagement. The issues are increasingly interdisciplinary and novel, and you will frequently be the one ideating and building a legally-relevant framework rather than simply applying one. Depending on interest and experience, you will own and shape an ever-growing portfolio of issue areas across Safeguards and Security. You will also contribute to the team's capacity building efforts, including by leveraging Claude. You will work collaboratively with other legal functions on cross-functional initiatives. This is an excellent opportunity for an experienced attorney who wants to do high-stakes, first-of-its-kind work at the center of responsible AI development and deployment, and to grow as a strategic product counsel and trusted crisis counselor in a fast-moving environment. Key responsibilities Partner with Safeguards (trust & safety) policy teams on the design and iteration of usage policies across harm areas (e.g., CBRNE, cyber, user wellbeing, scaled abuse and influence operations, and distillation), including how policies translate into detection and enforcement. Advise on policy enforcement frameworks such as account actions, appeals, enforcement systems and thresholds. Counsel on sensitive escalations and strategic response, including matters involving governments, law enforcement, regulators, and the press. Advise on safety and security threat intelligence investigations, bug bounty and red-team programs, and internal and external safety and security testing arrangements. Support safeguards and security engineering, ML, and data science teams on building new tooling and detection mechanisms, including as it relates to data governance and privacy related considerations. Serve as a first-line legal contact for safety and security incidents, providing real-time guidance during incident response and assessing notification and reporting obligations under applicable legal frameworks and contractual commitments. Build and maintain crisis management playbooks, escalation protocols, and self-serve legal guidance to enable legal resource scaling. Stay abreast of key policy and regulatory developments in AI safety and security, and policy-specific domains across relevant jurisdictions, and translate them into practical guidance for our evolving product suite. Minimum qualifications Qualification to practice law in England & Wales, or another relevant jurisdiction Experience advising on fast-moving, high-stakes matters such as investigations, regulatory matters, crisis management, or enforcement work Working knowledge of at least one of: trust & safety, cybersecurity, privacy, or platform regulation Legal drafting and writing skills demonstrated through policies, playbooks, escalation protocols, or written guidance for non-legal audiences Technical fluency sufficient to understand system architecture, data flows, and AI model behavior Experience coordinating multi-stakeholder responses to time-sensitive matters and translating legal analysis into clear actionable steps for technical and executive audiences Preferred qualifications 8+ years of relevant legal experience In-house (product counsel) experience at a technology company working on security and/or trust & safety issues, or law firm experience advising tech clients on regulatory investigations or enforcement matters Experience with content moderation, platform safety (including user wellbeing issues), and crisis management Facility working with very technical teams, including machine learning, safety and security research, infrastructure, and threat intelligence Familiarity with AI systems and machine learning concepts, or experience advising on novel technology products Strong judgment about risk assessment and decision-making under uncertainty A low-ego, hands-on working style and a commitment to doing right by users and the people affected by misuse of AI systems Application Deadline: 6pm PT on Friday September 11, 2026. We encourage all interested and qualified applicants to submit their materials before this date to ensure full consideration. Role-specific policy: For this role, we expect all staff to be able to work from our London office at least 3 days a week, though we encourage you to apply even if you might need some flexibility for an interim period of time. The annual compensation range for this role is listed below. For sales roles, the range provided is the role's On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role. Annual Salary: £165,000-£205,000 GBP LogisticsMinimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices. Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this. We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of your candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team. Your safety matters to us.
MCS Group
Senior Cloud Security Analyst
MCS Group City, Belfast
About the RoleAs a Senior Cloud Security Analyst, you'll play a key role in protecting cloud infrastructure and services through proactive monitoring, threat detection and incident response. Working within a collaborative Security Operations function, you'll analyse security events, investigate emerging threats and help strengthen the organisation's overall cyber resilience.This role offers the opportunity to work across modern cloud platforms, partnering with infrastructure, engineering and application teams to improve security controls, enhance detection capabilities and support secure cloud operations.Key ResponsibilitiesMonitor and investigate security events across Azure, AWS and hybrid cloud environments using SIEM, CSPM and native cloud security services.Perform detailed triage of alerts to identify genuine threats, eliminate false positives and determine appropriate remediation actions.Lead or support investigations into cloud-based security incidents, ensuring timely containment, recovery and accurate documentation.Analyse authentication activity, privileged access events, API usage and configuration changes to identify suspicious behaviour and potential compromise.Work alongside Security Operations, Infrastructure and DevOps teams to coordinate effective responses to security incidents.Recommend improvements to detection logic, alert quality and monitoring coverage based on operational findings and emerging threats.Develop and maintain security use cases that improve visibility across cloud workloads and services.Contribute to threat hunting activities by identifying indicators of compromise and analysing attacker techniques.Produce clear technical reports and communicate investigation findings to both technical and non-technical stakeholders.Participate in security improvement initiatives, helping implement new technologies, processes and operational controls.Keep up to date with developments in cloud security, attacker methodologies and industry best practices to strengthen organisational security.Technical SkillsExperience in several of the following areas would be advantageous:Microsoft Azure SecurityAWS Security ServicesGoogle Cloud Platform (desirable)Microsoft SentinelKusto Query Language (KQL)CloudTrail, Azure Activity Logs and cloud audit loggingCloud Security Posture Management (CSPM)CrowdStrike Falcon Cloud SecurityMicrosoft Defender SuiteKubernetes security conceptsIdentity and Access Management (IAM)Privileged Access ManagementMicrosoft Entra ID (Azure AD)MITRE ATT&CK FrameworkThreat IntelligenceIncident ResponseThreat HuntingSIEM TechnologiesSecurity MonitoringSecurity Operations (SOC)Cloud Networking FundamentalsWhat You'll BringExperience working within a Security Operations Centre or Cloud Security environment.Strong analytical and investigative skills with the ability to prioritise and manage multiple security events.Confidence interpreting security telemetry and identifying indicators of malicious activity.Excellent problem-solving skills and the ability to make informed decisions during security incidents.Strong communication skills with the ability to present technical findings clearly.A collaborative approach to working with infrastructure, engineering and operational teams.A proactive mindset focused on continuous improvement and operational excellence.Desirable QualificationsMicrosoft SC-200Microsoft AZ-500AWS Certified Security - SpecialtyCertified Kubernetes Security Specialist (CKS)CompTIA Security+CISSPGIAC certificationsRelevant cloud or cyber security certifications To speak in absolute confidence about this opportunity please send an up-to-date CV via the link provided or contact Senior Recruitment Consultant Stuart Kennedy at MCS Group on or . Even if this position is not right for you, we may have others that are. Please visit MCS Group to view a wide selection of our current jobs.
Aug 26, 2026
Full time
About the RoleAs a Senior Cloud Security Analyst, you'll play a key role in protecting cloud infrastructure and services through proactive monitoring, threat detection and incident response. Working within a collaborative Security Operations function, you'll analyse security events, investigate emerging threats and help strengthen the organisation's overall cyber resilience.This role offers the opportunity to work across modern cloud platforms, partnering with infrastructure, engineering and application teams to improve security controls, enhance detection capabilities and support secure cloud operations.Key ResponsibilitiesMonitor and investigate security events across Azure, AWS and hybrid cloud environments using SIEM, CSPM and native cloud security services.Perform detailed triage of alerts to identify genuine threats, eliminate false positives and determine appropriate remediation actions.Lead or support investigations into cloud-based security incidents, ensuring timely containment, recovery and accurate documentation.Analyse authentication activity, privileged access events, API usage and configuration changes to identify suspicious behaviour and potential compromise.Work alongside Security Operations, Infrastructure and DevOps teams to coordinate effective responses to security incidents.Recommend improvements to detection logic, alert quality and monitoring coverage based on operational findings and emerging threats.Develop and maintain security use cases that improve visibility across cloud workloads and services.Contribute to threat hunting activities by identifying indicators of compromise and analysing attacker techniques.Produce clear technical reports and communicate investigation findings to both technical and non-technical stakeholders.Participate in security improvement initiatives, helping implement new technologies, processes and operational controls.Keep up to date with developments in cloud security, attacker methodologies and industry best practices to strengthen organisational security.Technical SkillsExperience in several of the following areas would be advantageous:Microsoft Azure SecurityAWS Security ServicesGoogle Cloud Platform (desirable)Microsoft SentinelKusto Query Language (KQL)CloudTrail, Azure Activity Logs and cloud audit loggingCloud Security Posture Management (CSPM)CrowdStrike Falcon Cloud SecurityMicrosoft Defender SuiteKubernetes security conceptsIdentity and Access Management (IAM)Privileged Access ManagementMicrosoft Entra ID (Azure AD)MITRE ATT&CK FrameworkThreat IntelligenceIncident ResponseThreat HuntingSIEM TechnologiesSecurity MonitoringSecurity Operations (SOC)Cloud Networking FundamentalsWhat You'll BringExperience working within a Security Operations Centre or Cloud Security environment.Strong analytical and investigative skills with the ability to prioritise and manage multiple security events.Confidence interpreting security telemetry and identifying indicators of malicious activity.Excellent problem-solving skills and the ability to make informed decisions during security incidents.Strong communication skills with the ability to present technical findings clearly.A collaborative approach to working with infrastructure, engineering and operational teams.A proactive mindset focused on continuous improvement and operational excellence.Desirable QualificationsMicrosoft SC-200Microsoft AZ-500AWS Certified Security - SpecialtyCertified Kubernetes Security Specialist (CKS)CompTIA Security+CISSPGIAC certificationsRelevant cloud or cyber security certifications To speak in absolute confidence about this opportunity please send an up-to-date CV via the link provided or contact Senior Recruitment Consultant Stuart Kennedy at MCS Group on or . Even if this position is not right for you, we may have others that are. Please visit MCS Group to view a wide selection of our current jobs.
Cyber Response & Recovery Manager
Circle Group
Cyber Response & Recovery Manager Salary: £68,000-£80,000 + benefits Location : London Clearance: SC Eligible We are seeking an experienced Cyber Response & Recovery Manager to join a leading cyber security consultancy, helping organisations recover from major cyber incidents and strengthen their long-term resilience click apply for full job details
Aug 25, 2026
Full time
Cyber Response & Recovery Manager Salary: £68,000-£80,000 + benefits Location : London Clearance: SC Eligible We are seeking an experienced Cyber Response & Recovery Manager to join a leading cyber security consultancy, helping organisations recover from major cyber incidents and strengthen their long-term resilience click apply for full job details
Intelligence Analyst - Arabic
ZeroFox
ZeroFox seeks an Intelligence Analyst (Arabic Language) to join the ZeroFox Services and Analysis Team, you will collect information to identify threats, and generate intelligence to assess risk in relevance to client needs. Intelligence activities can include researching current and emerging threats issues covering physical security, cyber security, geopolitical, reputation risk and compliance issues. The Intelligence Analyst will have an investigative or analytical background and demonstrated exceptional analytic prowess in areas such as trend analysis and pattern recognition, using independent critical thinking and judgment to act, lead, initiate and/or recommend next steps. Discretion, teamwork, and creativity are a must. Key Responsibilities include: Learn and employ ZeroFox patented technology to identify and analyze relevant information collected from the Internet, based on client-specific criteria, to assemble relevant findings for daily intelligence and recurring reporting; Assist in customer care and all production aspects covering the range of assigned duties. Support and /or lead recurring deliverables and touchpoints (ad hoc / daily / weekly / monthly / quarterly and / or annual): Security/Incident Alerts Intelligence Reports Trend and summary reports Strategic assessments and reviews Client briefings Support collection enhancement with ongoing and proactive collaboration with Collection Management and 24x7 support. Dedication and willingness to provide support in response to ad hoc threats and periods of increased risk. This may entail on occasion: Ad hoc investigations and assessments Ancillary threat monitoring outside core business hours Proactive professional development through company trainings, industry certifications, and seeking new opportunities to maintain and grow relevant knowledge and skillsets. Identify and communicate enhancement opportunities and improvement ideas for the department's operations. Qualifying Requirements: Written and spoken fluency in Arabic Experience in open source and social media research, or investigations, typically obtained in 2-3 years; ability to connect the dots; Creativity in leveraging internet search techniques and methods; Ability to determine the credibility, value, significance, and relevancy of information from different data sources to produce clear, concise, and timely analytical products; Strong written and oral communication skills; comfortable with providing briefings and presentations. Experience producing short and long form reports, applying BLUF or similar models; Comfort working independently and in teams; Experience with some of the following: Social Media Platforms, blogs, IRC, Deep / Darkweb , and message boards; Ability to collect, authenticate, validate and document online evidence; Proficient with at least one online investigative tool, such as Whois, Ping, Traceroute, etc; Proficient in Google Suite of programs; Preferred Experience: Public or private sector experience as an analyst, researcher, investigator or consultant supporting a security, risk or due diligence function. Experience in conducting studies and making recommendations to identify threat vectors, threat actors, and threat trends Experience in briefing decision-makers and senior leaders; High degree of knowledge of Social Media Platforms, blogs, IRC, message boards, Deep/Darkweb; Knowledge of IPv4, IPv6, DNS records, E-mails Headers, P2P; Possession of excellent project/team leadership, development, and client relationship skills; Knowledge and familiarity with relevant threat landscapes or industry practice areas such as cybercrime, online fraud, physical/corporate security, activism, hacktivism, reputation risk, travel security, geopolitical or policy issues Bachelor's degree with relevant coursework Education / Training Requirements: Bachelor's Degree Benefits Competitive compensation Community-driven culture with employee events Generous time offComprehensive private insurance and EAP Fun, modern workspace Respectful and nourishing work environment, where every opinion is heard and everyone is encouraged to be an active part of the organizational culture Physical and Sensory Requirements: Mobility, walking, climbing, sitting, standing, reaching, bending, lifting (minimum of 10 lbs), fine eye-hand coordination, ability to read, write, listen and speak clearly, the ability to understand and follow written and oral instructions and directions, ability to travel =/
Aug 25, 2026
Full time
ZeroFox seeks an Intelligence Analyst (Arabic Language) to join the ZeroFox Services and Analysis Team, you will collect information to identify threats, and generate intelligence to assess risk in relevance to client needs. Intelligence activities can include researching current and emerging threats issues covering physical security, cyber security, geopolitical, reputation risk and compliance issues. The Intelligence Analyst will have an investigative or analytical background and demonstrated exceptional analytic prowess in areas such as trend analysis and pattern recognition, using independent critical thinking and judgment to act, lead, initiate and/or recommend next steps. Discretion, teamwork, and creativity are a must. Key Responsibilities include: Learn and employ ZeroFox patented technology to identify and analyze relevant information collected from the Internet, based on client-specific criteria, to assemble relevant findings for daily intelligence and recurring reporting; Assist in customer care and all production aspects covering the range of assigned duties. Support and /or lead recurring deliverables and touchpoints (ad hoc / daily / weekly / monthly / quarterly and / or annual): Security/Incident Alerts Intelligence Reports Trend and summary reports Strategic assessments and reviews Client briefings Support collection enhancement with ongoing and proactive collaboration with Collection Management and 24x7 support. Dedication and willingness to provide support in response to ad hoc threats and periods of increased risk. This may entail on occasion: Ad hoc investigations and assessments Ancillary threat monitoring outside core business hours Proactive professional development through company trainings, industry certifications, and seeking new opportunities to maintain and grow relevant knowledge and skillsets. Identify and communicate enhancement opportunities and improvement ideas for the department's operations. Qualifying Requirements: Written and spoken fluency in Arabic Experience in open source and social media research, or investigations, typically obtained in 2-3 years; ability to connect the dots; Creativity in leveraging internet search techniques and methods; Ability to determine the credibility, value, significance, and relevancy of information from different data sources to produce clear, concise, and timely analytical products; Strong written and oral communication skills; comfortable with providing briefings and presentations. Experience producing short and long form reports, applying BLUF or similar models; Comfort working independently and in teams; Experience with some of the following: Social Media Platforms, blogs, IRC, Deep / Darkweb , and message boards; Ability to collect, authenticate, validate and document online evidence; Proficient with at least one online investigative tool, such as Whois, Ping, Traceroute, etc; Proficient in Google Suite of programs; Preferred Experience: Public or private sector experience as an analyst, researcher, investigator or consultant supporting a security, risk or due diligence function. Experience in conducting studies and making recommendations to identify threat vectors, threat actors, and threat trends Experience in briefing decision-makers and senior leaders; High degree of knowledge of Social Media Platforms, blogs, IRC, message boards, Deep/Darkweb; Knowledge of IPv4, IPv6, DNS records, E-mails Headers, P2P; Possession of excellent project/team leadership, development, and client relationship skills; Knowledge and familiarity with relevant threat landscapes or industry practice areas such as cybercrime, online fraud, physical/corporate security, activism, hacktivism, reputation risk, travel security, geopolitical or policy issues Bachelor's degree with relevant coursework Education / Training Requirements: Bachelor's Degree Benefits Competitive compensation Community-driven culture with employee events Generous time offComprehensive private insurance and EAP Fun, modern workspace Respectful and nourishing work environment, where every opinion is heard and everyone is encouraged to be an active part of the organizational culture Physical and Sensory Requirements: Mobility, walking, climbing, sitting, standing, reaching, bending, lifting (minimum of 10 lbs), fine eye-hand coordination, ability to read, write, listen and speak clearly, the ability to understand and follow written and oral instructions and directions, ability to travel =/
Certain Advantage
Cyber Security Operations Manager
Certain Advantage Exeter, Devon
Cyber Security Operations Manager Exeter REMOTE £800 per day Umbrella Initially 6-month contract Mon-Fri Certain Advantage is working in partnership with a leading public organisation seeking an SOC Manager to design, implement and continuously improve the departments Security Operations strategy, ensuring rapid detection, response and recovery from cyber threats and incidents click apply for full job details
Aug 25, 2026
Contractor
Cyber Security Operations Manager Exeter REMOTE £800 per day Umbrella Initially 6-month contract Mon-Fri Certain Advantage is working in partnership with a leading public organisation seeking an SOC Manager to design, implement and continuously improve the departments Security Operations strategy, ensuring rapid detection, response and recovery from cyber threats and incidents click apply for full job details
Isr Recruitment Limited
ICT Cyber and Information Security Manager
Isr Recruitment Limited Eaglescliffe, County Durham
The Opportunity Our client is looking to appoint an experienced ICT Cyber & Information Security Manager to take responsibility for a broad range of cyber security, information security, risk and compliance activities across the organisation. This is a key role within the Information Security function, providing the opportunity to take ownership of security activities ranging from the ICT Annual Delivery Plan through to major business growth initiatives, including site transitions and acquisitions across the UK and internationally. You'll work closely with internal teams, senior stakeholders and external partners to strengthen the organisation's cyber and information security posture, manage risk and ensure compliance with relevant security standards and legislation. The successful candidate will combine strong technical security knowledge with excellent governance, risk management and stakeholder-management skills. Skills and Experience: Experience leading cyber security, information security and/or compliance activities within a medium-to-large enterprise environment. Strong experience managing an enterprise information/cyber security risk register. Strong practical knowledge of Information Security Management Systems (ISMS). Experience implementing, maintaining and continually improving an ISMS. Experience preparing for and participating in internal and external security audits. Strong knowledge of ISO 27002 and experience delivering against its requirements. Strong knowledge of Cyber Essentials / Cyber Essentials Plus. Experience working with NIST security frameworks. Knowledge of CAF / Cyber Assessment Framework and its application to organisational security. Understanding of NIS2, GDPR and the Data Protection Act. Strong understanding of cyber security risk, governance, controls and remediation. Qualifications Professional security qualifications such as the following would be highly desirable: CISSP / CISM / CISA ISO 27001/27002-related qualifications Other recognised cyber security, information assurance or risk-management certifications Role and Responsibilities: Act as a key pillar of the organisation's Information Security programme, driving and managing cyber and information security activities. Work collaboratively with internal teams and external partners to deliver security initiatives and improvements. Develop, review and rehearse incident response plans, ensuring the organisation is prepared to detect, investigate and respond effectively to cyber incidents and data breaches. Work with relevant teams to review, test and improve Business Continuity, Recovery Time Objective (RTO) and Recovery Time Strategy (RTS) arrangements. Conduct and support security risk assessments and vulnerability assessments to identify threats, vulnerabilities and areas for improvement. Develop and implement appropriate risk mitigation strategies. Manage and maintain ICT Cyber & Data Security Risk Registers, ensuring risks are appropriately assessed, owned, mitigated and reported. Review, develop, implement and maintain cyber security, information security, data protection and compliance policies. Monitor changes in the regulatory and threat landscape and assess their impact on the organisation. Ensure compliance with relevant legislation, regulations, frameworks and security standards, including GDPR, Data Protection Act, NIS2, NIST, Cyber Essentials and ISO 27002. Lead and coordinate information security metrics, reporting and management information. Support and oversee offensive security activities, vulnerability management and security testing. Maintain and continuously improve the organisation's Information Security Management System (ISMS). Lead or participate in internal and external security audits and assessments, including ISO 27002 and Cyber Essentials Plus. Provide security input into business change, technology projects, acquisitions, site transitions and other strategic initiatives. Work with stakeholders to embed security by design across ICT and wider business activities. Applications: To learn more about our established client and this newly created role working as a IT Security Manager for our client based in the Teesside / County Durham area (with excellent flexible/remote working options available); please call and speak with Edward Laing here at ISR Recruitment to learn more or please send through a copy of your latest CV and/or share your online business profile for a call back in the very strictest of confidence.
Aug 24, 2026
Full time
The Opportunity Our client is looking to appoint an experienced ICT Cyber & Information Security Manager to take responsibility for a broad range of cyber security, information security, risk and compliance activities across the organisation. This is a key role within the Information Security function, providing the opportunity to take ownership of security activities ranging from the ICT Annual Delivery Plan through to major business growth initiatives, including site transitions and acquisitions across the UK and internationally. You'll work closely with internal teams, senior stakeholders and external partners to strengthen the organisation's cyber and information security posture, manage risk and ensure compliance with relevant security standards and legislation. The successful candidate will combine strong technical security knowledge with excellent governance, risk management and stakeholder-management skills. Skills and Experience: Experience leading cyber security, information security and/or compliance activities within a medium-to-large enterprise environment. Strong experience managing an enterprise information/cyber security risk register. Strong practical knowledge of Information Security Management Systems (ISMS). Experience implementing, maintaining and continually improving an ISMS. Experience preparing for and participating in internal and external security audits. Strong knowledge of ISO 27002 and experience delivering against its requirements. Strong knowledge of Cyber Essentials / Cyber Essentials Plus. Experience working with NIST security frameworks. Knowledge of CAF / Cyber Assessment Framework and its application to organisational security. Understanding of NIS2, GDPR and the Data Protection Act. Strong understanding of cyber security risk, governance, controls and remediation. Qualifications Professional security qualifications such as the following would be highly desirable: CISSP / CISM / CISA ISO 27001/27002-related qualifications Other recognised cyber security, information assurance or risk-management certifications Role and Responsibilities: Act as a key pillar of the organisation's Information Security programme, driving and managing cyber and information security activities. Work collaboratively with internal teams and external partners to deliver security initiatives and improvements. Develop, review and rehearse incident response plans, ensuring the organisation is prepared to detect, investigate and respond effectively to cyber incidents and data breaches. Work with relevant teams to review, test and improve Business Continuity, Recovery Time Objective (RTO) and Recovery Time Strategy (RTS) arrangements. Conduct and support security risk assessments and vulnerability assessments to identify threats, vulnerabilities and areas for improvement. Develop and implement appropriate risk mitigation strategies. Manage and maintain ICT Cyber & Data Security Risk Registers, ensuring risks are appropriately assessed, owned, mitigated and reported. Review, develop, implement and maintain cyber security, information security, data protection and compliance policies. Monitor changes in the regulatory and threat landscape and assess their impact on the organisation. Ensure compliance with relevant legislation, regulations, frameworks and security standards, including GDPR, Data Protection Act, NIS2, NIST, Cyber Essentials and ISO 27002. Lead and coordinate information security metrics, reporting and management information. Support and oversee offensive security activities, vulnerability management and security testing. Maintain and continuously improve the organisation's Information Security Management System (ISMS). Lead or participate in internal and external security audits and assessments, including ISO 27002 and Cyber Essentials Plus. Provide security input into business change, technology projects, acquisitions, site transitions and other strategic initiatives. Work with stakeholders to embed security by design across ICT and wider business activities. Applications: To learn more about our established client and this newly created role working as a IT Security Manager for our client based in the Teesside / County Durham area (with excellent flexible/remote working options available); please call and speak with Edward Laing here at ISR Recruitment to learn more or please send through a copy of your latest CV and/or share your online business profile for a call back in the very strictest of confidence.
Claranet Limited
SOC Shift Lead
Claranet Limited Leeds, Yorkshire
Position Summary As a SOC Shift Lead, you build on your solid experience as a SOC Analyst by supervising and guiding a team of SOC Analysts during your assigned shift. You ensure quality and consistency across all alerts and incidents handled by the team while serving as the primary point of escalation. In this role, you support team development, drive process improvements, and maintain clear, customer-centric communication with all stakeholders. You also lead quality assurance efforts and ensure that service-level agreements (SLAs) are met. Objectives & Key Results Key Responsibilities Shift Leadership and Team Coordination - You run shift operations, ensuring compliance with SLAs and maintaining high-quality incident handling. You set shift agendas, balance workloads, and promptly address any process or staffing issues. You also maintain effective, customer-centric communication with internal teams (including Security Optimisation and Engineering), customers, and their incident response partners Incident Triage and Investigation - You review and prioritise new alerts, taking initial ownership of high-priority or complex incidents, and ensure proper escalation to customers and Senior SOC Analysts. You make sound, data-driven decisions to facilitate effective triage, investigation, and escalation in line with operational standards Quality Assurance and Documentation - You conduct regular quality assurance (QA) of tickets to ensure SOC procedures and documentation standards are met, providing clear, constructive feedback to team members to improve technical skills and workflow consistency Collaboration and Mentorship - You mentor SOC Analysts in your team by offering regular, constructive feedback on triage processes and best practices. You encourage targeted training initiatives, including relevant certifications, to support career progression within the SOC Service Improvement - You contribute to ongoing service improvement through participation in supporting threat hunting activity led by Senior SOC Analysts, rule tuning, and process refinement initiatives. You assist in monthly reporting and post-incident reviews to drive improvements that reflect our commitment to transparent and reliable performance Required Qualifications & Experience You may be required to hold or obtain UK Non-Police Personnel Vetting (NPPV) and/or a Security Check (SC) clearance as part of this role Willingness to work towards or obtain intermediate cybersecurity certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst) Proficiency with SIEM platforms, endpoint security tools, and ticketing systems, with an ability to make clear, data-driven decisions under pressure Critical Competencies - Technical Fit Operating Systems - Possess detailed knowledge of Windows and Linux system architectures, with a clear understanding of how event logs (e.g., Windows Event Viewer, Syslog) reflect system security posture Networking and Protocols - Have a comprehensive understanding of TCP/IP, DNS, DCHP, VPNs, SSL/TLS, and network forensics concepts to validate network-based alerts and anomalies Cybersecurity Frameworks - Deeply understand and be able to articulate the elements of the MITRE ATT&CK framework, and Cyber Kill Chain; know how adversary tactics and techniques translate into observable indicators SIEM and Security Tools - Know the theoretical underpinnings of SIEM operations, including alert correlation, the design of automated detection rules, and the interpretation of aggregated security data Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence - how feeds are sourced, what constitutes actionable information, and how malware indicators are defined Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling Benefits At Claranet, we go the extra mile with our people-because we believe in building a workplace where everyone feels valued and supported. What makes us unique is Team Claranet , our internal community that supports causes close to our employees' hearts. We offer paid charity leave, support local charities across our offices, and host annual fundraising events, all backed by a dedicated committee. We're proud founding members of TC4RE (Technology Community for Racial Equality) working collectively to build a more diverse and inclusive tech industry. About Claranet Founded at the beginning of the dot com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries. Equal Opportunities Statement Diversity, equity and inclusion are at the heart of what we value as an organisation. Claranet is an equal opportunities employer and all qualified applicants will receive consideration for employment without regard to race, religion, sex, sexual orientation, age, disability or any other status protected by law. Our recruitment team are happy to support any reasonable adjustments that are needed within the recruitment process. Ready to take the next step in your career with Claranet? Click 'apply' - we can't wait to meet you! To view full job description please visit our careers page
Aug 24, 2026
Full time
Position Summary As a SOC Shift Lead, you build on your solid experience as a SOC Analyst by supervising and guiding a team of SOC Analysts during your assigned shift. You ensure quality and consistency across all alerts and incidents handled by the team while serving as the primary point of escalation. In this role, you support team development, drive process improvements, and maintain clear, customer-centric communication with all stakeholders. You also lead quality assurance efforts and ensure that service-level agreements (SLAs) are met. Objectives & Key Results Key Responsibilities Shift Leadership and Team Coordination - You run shift operations, ensuring compliance with SLAs and maintaining high-quality incident handling. You set shift agendas, balance workloads, and promptly address any process or staffing issues. You also maintain effective, customer-centric communication with internal teams (including Security Optimisation and Engineering), customers, and their incident response partners Incident Triage and Investigation - You review and prioritise new alerts, taking initial ownership of high-priority or complex incidents, and ensure proper escalation to customers and Senior SOC Analysts. You make sound, data-driven decisions to facilitate effective triage, investigation, and escalation in line with operational standards Quality Assurance and Documentation - You conduct regular quality assurance (QA) of tickets to ensure SOC procedures and documentation standards are met, providing clear, constructive feedback to team members to improve technical skills and workflow consistency Collaboration and Mentorship - You mentor SOC Analysts in your team by offering regular, constructive feedback on triage processes and best practices. You encourage targeted training initiatives, including relevant certifications, to support career progression within the SOC Service Improvement - You contribute to ongoing service improvement through participation in supporting threat hunting activity led by Senior SOC Analysts, rule tuning, and process refinement initiatives. You assist in monthly reporting and post-incident reviews to drive improvements that reflect our commitment to transparent and reliable performance Required Qualifications & Experience You may be required to hold or obtain UK Non-Police Personnel Vetting (NPPV) and/or a Security Check (SC) clearance as part of this role Willingness to work towards or obtain intermediate cybersecurity certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst) Proficiency with SIEM platforms, endpoint security tools, and ticketing systems, with an ability to make clear, data-driven decisions under pressure Critical Competencies - Technical Fit Operating Systems - Possess detailed knowledge of Windows and Linux system architectures, with a clear understanding of how event logs (e.g., Windows Event Viewer, Syslog) reflect system security posture Networking and Protocols - Have a comprehensive understanding of TCP/IP, DNS, DCHP, VPNs, SSL/TLS, and network forensics concepts to validate network-based alerts and anomalies Cybersecurity Frameworks - Deeply understand and be able to articulate the elements of the MITRE ATT&CK framework, and Cyber Kill Chain; know how adversary tactics and techniques translate into observable indicators SIEM and Security Tools - Know the theoretical underpinnings of SIEM operations, including alert correlation, the design of automated detection rules, and the interpretation of aggregated security data Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence - how feeds are sourced, what constitutes actionable information, and how malware indicators are defined Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling Benefits At Claranet, we go the extra mile with our people-because we believe in building a workplace where everyone feels valued and supported. What makes us unique is Team Claranet , our internal community that supports causes close to our employees' hearts. We offer paid charity leave, support local charities across our offices, and host annual fundraising events, all backed by a dedicated committee. We're proud founding members of TC4RE (Technology Community for Racial Equality) working collectively to build a more diverse and inclusive tech industry. About Claranet Founded at the beginning of the dot com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries. Equal Opportunities Statement Diversity, equity and inclusion are at the heart of what we value as an organisation. Claranet is an equal opportunities employer and all qualified applicants will receive consideration for employment without regard to race, religion, sex, sexual orientation, age, disability or any other status protected by law. Our recruitment team are happy to support any reasonable adjustments that are needed within the recruitment process. Ready to take the next step in your career with Claranet? Click 'apply' - we can't wait to meet you! To view full job description please visit our careers page
Comtecs Ltd
Cyber Security Engineer - MS Sentinel, Defender, SSO, PKI, SC-100/200, CISSP
Comtecs Ltd
IT Cyber Security Specialist / Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team, supporting and continually improving cybersecurity across a global IT environment. Reporting to the Infrastructure Engineering Manager, you'll take ownership of cybersecurity controls and security architecture while working closely with Infrastructure Operations and other technology teams to identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across a complex infrastructure environment, identifying and mitigating security risks, supporting major cyber incidents and contributing to strategic security and infrastructure projects. You'll also help develop security awareness, business continuity capabilities and ongoing improvements to the firm's security controls. Key Responsibilities: Continuously review and improve the firm's cybersecurity posture from an infrastructure perspective and external security rating. Identify, assess and remediate vulnerabilities across hardware, software and infrastructure (Windows Server and Azure Cloud). Monitor emerging threats and lead or support Incident Response investigations and mitigation. Evaluate, test and recommend security enhancements, controls and threat prevention technologies. Identify security risks and exposures and develop measures to prevent future incidents. Lead CE+ accreditation and support security, risk and data protection requirements from a technical (Not GRC) perspective. Participate in and lead infrastructure lifecycle, security and technology projects. Provide 3rd Line / Major Incident support as a cybersecurity subject matter expert. Work with third-party suppliers and advise internal technical teams on security measures to resolve security and infrastructure issues. We're looking for experienced Cyber Security engineer with strong technical infrastructure knowledge and proven experience across incident response, threat monitoring and vulnerability management. You will possess: Extensive experience in a similar role blending Cyber Security with core Wintel Infrastructure and Azure cloud engineering. Strong knowledge of modern security architecture, threat prevention techniques and incident response. Strong Windows Server 2016/2019/2022 knowledge including Active Directory, DNS, DHCP, Intune, Group Policy, PKI, Entra and Azure SSO. Demonstrable experience across Cyber Security, Incident Response, Threat Monitoring and Vulnerability Management using tools such as MS Sentinel, MS Defender etc for threat hunting, vulnerability monitoring and security posture improvement. CISSP, CEH, CCNA Security, SC-100, SC200 or equivalent security certification. Experience designing, integrating and managing complex infrastructure and cloud solutions from a cyber security standpoint and advising technical infrastructure teams on security focussed designs and operations Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. Experience working with third-party providers across on-premise and cloud services. Strong planning skills and knowledge of ITIL processes and best practice. This is an excellent opportunity to join a highly regarded global organisation where you'll play a key role in strengthening cybersecurity across a complex international IT environment, combining hands-on security engineering, incident response and strategic infrastructure projects.
Aug 24, 2026
Full time
IT Cyber Security Specialist / Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team, supporting and continually improving cybersecurity across a global IT environment. Reporting to the Infrastructure Engineering Manager, you'll take ownership of cybersecurity controls and security architecture while working closely with Infrastructure Operations and other technology teams to identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across a complex infrastructure environment, identifying and mitigating security risks, supporting major cyber incidents and contributing to strategic security and infrastructure projects. You'll also help develop security awareness, business continuity capabilities and ongoing improvements to the firm's security controls. Key Responsibilities: Continuously review and improve the firm's cybersecurity posture from an infrastructure perspective and external security rating. Identify, assess and remediate vulnerabilities across hardware, software and infrastructure (Windows Server and Azure Cloud). Monitor emerging threats and lead or support Incident Response investigations and mitigation. Evaluate, test and recommend security enhancements, controls and threat prevention technologies. Identify security risks and exposures and develop measures to prevent future incidents. Lead CE+ accreditation and support security, risk and data protection requirements from a technical (Not GRC) perspective. Participate in and lead infrastructure lifecycle, security and technology projects. Provide 3rd Line / Major Incident support as a cybersecurity subject matter expert. Work with third-party suppliers and advise internal technical teams on security measures to resolve security and infrastructure issues. We're looking for experienced Cyber Security engineer with strong technical infrastructure knowledge and proven experience across incident response, threat monitoring and vulnerability management. You will possess: Extensive experience in a similar role blending Cyber Security with core Wintel Infrastructure and Azure cloud engineering. Strong knowledge of modern security architecture, threat prevention techniques and incident response. Strong Windows Server 2016/2019/2022 knowledge including Active Directory, DNS, DHCP, Intune, Group Policy, PKI, Entra and Azure SSO. Demonstrable experience across Cyber Security, Incident Response, Threat Monitoring and Vulnerability Management using tools such as MS Sentinel, MS Defender etc for threat hunting, vulnerability monitoring and security posture improvement. CISSP, CEH, CCNA Security, SC-100, SC200 or equivalent security certification. Experience designing, integrating and managing complex infrastructure and cloud solutions from a cyber security standpoint and advising technical infrastructure teams on security focussed designs and operations Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. Experience working with third-party providers across on-premise and cloud services. Strong planning skills and knowledge of ITIL processes and best practice. This is an excellent opportunity to join a highly regarded global organisation where you'll play a key role in strengthening cybersecurity across a complex international IT environment, combining hands-on security engineering, incident response and strategic infrastructure projects.
We Love Alfa
Senior Cybersecurity Lead
We Love Alfa City Of Westminster, London
This position is being advertised by Alfa AI on behalf of Five Guys. Five Guys is hiring a senior cybersecurity leader to own cybersecurity across its European operations, reporting to the IT Director. This is a greenfield, hands-on role: you will define the cybersecurity strategy and roadmap, establish governance and risk reporting, create core policies and standards, and personally get involved in tooling, configuration, incident response and problem-solving where required. You will be responsible for improving security across Microsoft 365, Azure, endpoints and identity; building incident response, business continuity and disaster recovery capability; managing GDPR, PCI-DSS and ISO 27001 initiatives; strengthening supplier security; and providing clear cyber risk reporting to senior leadership. You will work closely with IT, infrastructure, project teams, operational stakeholders and external suppliers in a lean environment without a large internal security team. We are looking for someone who has built or significantly matured a cybersecurity function in a scaling or greenfield environment and can combine strategy with hands-on technical execution. You should be comfortable influencing senior stakeholders, prioritising risk, creating practical governance from scratch and operating independently. Location: London, with occasional UK and European travel.
Aug 24, 2026
Full time
This position is being advertised by Alfa AI on behalf of Five Guys. Five Guys is hiring a senior cybersecurity leader to own cybersecurity across its European operations, reporting to the IT Director. This is a greenfield, hands-on role: you will define the cybersecurity strategy and roadmap, establish governance and risk reporting, create core policies and standards, and personally get involved in tooling, configuration, incident response and problem-solving where required. You will be responsible for improving security across Microsoft 365, Azure, endpoints and identity; building incident response, business continuity and disaster recovery capability; managing GDPR, PCI-DSS and ISO 27001 initiatives; strengthening supplier security; and providing clear cyber risk reporting to senior leadership. You will work closely with IT, infrastructure, project teams, operational stakeholders and external suppliers in a lean environment without a large internal security team. We are looking for someone who has built or significantly matured a cybersecurity function in a scaling or greenfield environment and can combine strategy with hands-on technical execution. You should be comfortable influencing senior stakeholders, prioritising risk, creating practical governance from scratch and operating independently. Location: London, with occasional UK and European travel.
Global Head of Cyber Claims & Strategy
Howden Group Holdings
Howden Group Holdings in London is seeking a senior cyber claims leader to drive international strategy across non-UK/US markets, ensuring consistent incident response and client support. You will lead major incidents, develop best practices, build local capability, mentor teams, and partner with underwriting and wordings specialists to deliver coordinated global solutions. The role offers exposure to global projects, tender work, industry events, and ongoing education to advance Howden's cyber
Aug 24, 2026
Full time
Howden Group Holdings in London is seeking a senior cyber claims leader to drive international strategy across non-UK/US markets, ensuring consistent incident response and client support. You will lead major incidents, develop best practices, build local capability, mentor teams, and partner with underwriting and wordings specialists to deliver coordinated global solutions. The role offers exposure to global projects, tender work, industry events, and ongoing education to advance Howden's cyber

Modal Window

  • Home
  • Contact
  • About Us
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • Facebook
  • Twitter
  • Google Plus
  • LinkedIn
Parent and Partner sites: IT Job Board | Jobs Near Me | RightTalent.co.uk | Quantity Surveyor jobs | Building Surveyor jobs | Construction Recruitment | Talent Recruiter | Construction Job Board | Property jobs | myJobsnearme.com | Jobs near me
© 2008-2026 Jobsite Jobs | Designed by Web Design Agency