Job Description Role Responsibilities Ensure the resilience, continuity and coordinated response of the bank during operational disruptions, crises or emergencies. This role is critical in safeguarding the bank's reputation, regulatory compliance and customer trust. The role provides enterprise-wide accountability for preparedness, command and control, escalation and cross-functional mobilisation, ensuring that Barclays can protect customers, colleagues, critical services and assets while sustaining confidence among the Board, regulators and external stakeholders. Lead the Joint Operations Centres (JOCs) that integrate business units, IT, risk, and compliance functions; align crisis response across local, regional, and global teams; and maintain real-time situational awareness and decision making support tools. Ensure there is compliance with regulatory expectations for crisis management and operational risk (e.g., from the FCA, PRA, or BIS); report to the Board Risk Committee and regulators on preparedness and incident outcomes; and support audits, reviews, and post incident reporting. Develop and maintain enterprise wide crisis management frameworks; lead incident response teams during disruptions (e.g., cyberattacks, system outages, financial shocks); coordinate with executive leadership, including the Global CISO, regulators, and external partners to manage crises effectively. Partner with the Resilience Lead and business leadership to sustain the delivery of critical services during and after disruption, aligning recovery priorities to customer, regulatory and enterprise outcomes. Ensure an effective framework is in place to deliver consistent internal and external communications in a crisis, including effective incident notification and escalation. Own the enterprise-wide communications approach across customers, colleagues, regulators and external partners, working with Legal, Corporate Affairs and supporting functions to manage reputational risk. Role Requirements Deep understanding of the Joint Operations Centres planning and operational processes that leads to seamless execution of operational incident management. Knowledge of crisis management frameworks (contingency planning, incident escalation and strategic oversight) and the ability to lead during high pressure, time sensitive situations. Technical understanding of physical and digital infrastructure, security and operational risks. The ability to interpret and act on real time intelligence and identify business impacts and ensure effective preparedness planning. Know how to implement knowledge management systems across all global locations to reduce information silos and support effective decision making. Understand the external landscape and dependencies this brings to the Bank - including the geo political landscape, navigating regulatory, sector wide and operational risks. Responds flexibly to unexpected and evolving events, maintaining composure and inspiring confidence through periods of significant uncertainty. Demonstrates a strong track record of implementing Group wide innovation and continuous improvement, embedding lessons from live incidents, post incident reviews and exercises into preparedness, response and recovery. Leads crisis leadership team meetings at Board and ExCo Level, also having the communication and influencing skills to conduct training activities with the same group. Management of enterprise wide risk crisis communications processes to ensure prompt consistent group wide communication to customers, colleagues and regulators. Have extensive experience in effective communications and be able to influence and negotiate across the 5 business divisions, globally and to the points of contact in the regions where there is a Barclays footprint. Lead and drive consistent communications with internal and external stakeholders such PR, legal and supporting functions to manage reputational risk. Managing Director Expectations To manage a large, complex or diverse function and take accountability for the strategic direction of the function to significantly strengthen successful and efficient businesses and contribute to the strategic initiatives of the Barclays Group. Lead and mentor high performing teams and embed a performance culture aligned to the values of the business. Or for an individual contributor, they lead organisation wide projects, act as a profound technical expert and thought leader, identifying new and innovative/ground breaking ways of working. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions. Drive and achieve overall success and / or competitiveness of a business division by influencing senior leaders and committees. Strategically assess and manage risks to protect the business division / function and growth. Influence company policy and develop functional procedures in conjunction with senior leaders / strategic positions across the business. Demonstrate interpretative thinking for innovative solutions in complex situations and conceptual thinking in completely new situations. Exercise management authority to make significant / complex business and strategic decisions that impact the Barclays Group, business division or function. Negotiate with and influence stakeholders at a senior level both internally and externally and foster growth for Barclays business. Mandated as the business division/ functional spokesperson or representative to external bodies and shapes the public image of Barclays. Demonstrate exceptional knowledge of how business divisions and functions integrate with the Group to achieve the overall business objectives alongside industry theories and practices within own discipline. Maintain broad and comprehensive functional expertise and significant product knowledge. Accountable for the control and governance agenda of the business division / function. Focus on the external environment, regulators, or advocacy groups to both monitor and influence on behalf of Barclays. All Senior Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L - Listen and be authentic E - Energise and inspire A - Align across the enterprise D - Develop others All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship - our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset - to Empower, Challenge and Drive - the operating manual for how we behave. Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. - Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. Our employees are self disciplined, hard working, curious, trustworthy, humble, and truthful. They make choices according to what is best for the team, they live for opportunities to collaborate and make a difference, and they make us the Top Workplace in the area.
Aug 26, 2026
Full time
Job Description Role Responsibilities Ensure the resilience, continuity and coordinated response of the bank during operational disruptions, crises or emergencies. This role is critical in safeguarding the bank's reputation, regulatory compliance and customer trust. The role provides enterprise-wide accountability for preparedness, command and control, escalation and cross-functional mobilisation, ensuring that Barclays can protect customers, colleagues, critical services and assets while sustaining confidence among the Board, regulators and external stakeholders. Lead the Joint Operations Centres (JOCs) that integrate business units, IT, risk, and compliance functions; align crisis response across local, regional, and global teams; and maintain real-time situational awareness and decision making support tools. Ensure there is compliance with regulatory expectations for crisis management and operational risk (e.g., from the FCA, PRA, or BIS); report to the Board Risk Committee and regulators on preparedness and incident outcomes; and support audits, reviews, and post incident reporting. Develop and maintain enterprise wide crisis management frameworks; lead incident response teams during disruptions (e.g., cyberattacks, system outages, financial shocks); coordinate with executive leadership, including the Global CISO, regulators, and external partners to manage crises effectively. Partner with the Resilience Lead and business leadership to sustain the delivery of critical services during and after disruption, aligning recovery priorities to customer, regulatory and enterprise outcomes. Ensure an effective framework is in place to deliver consistent internal and external communications in a crisis, including effective incident notification and escalation. Own the enterprise-wide communications approach across customers, colleagues, regulators and external partners, working with Legal, Corporate Affairs and supporting functions to manage reputational risk. Role Requirements Deep understanding of the Joint Operations Centres planning and operational processes that leads to seamless execution of operational incident management. Knowledge of crisis management frameworks (contingency planning, incident escalation and strategic oversight) and the ability to lead during high pressure, time sensitive situations. Technical understanding of physical and digital infrastructure, security and operational risks. The ability to interpret and act on real time intelligence and identify business impacts and ensure effective preparedness planning. Know how to implement knowledge management systems across all global locations to reduce information silos and support effective decision making. Understand the external landscape and dependencies this brings to the Bank - including the geo political landscape, navigating regulatory, sector wide and operational risks. Responds flexibly to unexpected and evolving events, maintaining composure and inspiring confidence through periods of significant uncertainty. Demonstrates a strong track record of implementing Group wide innovation and continuous improvement, embedding lessons from live incidents, post incident reviews and exercises into preparedness, response and recovery. Leads crisis leadership team meetings at Board and ExCo Level, also having the communication and influencing skills to conduct training activities with the same group. Management of enterprise wide risk crisis communications processes to ensure prompt consistent group wide communication to customers, colleagues and regulators. Have extensive experience in effective communications and be able to influence and negotiate across the 5 business divisions, globally and to the points of contact in the regions where there is a Barclays footprint. Lead and drive consistent communications with internal and external stakeholders such PR, legal and supporting functions to manage reputational risk. Managing Director Expectations To manage a large, complex or diverse function and take accountability for the strategic direction of the function to significantly strengthen successful and efficient businesses and contribute to the strategic initiatives of the Barclays Group. Lead and mentor high performing teams and embed a performance culture aligned to the values of the business. Or for an individual contributor, they lead organisation wide projects, act as a profound technical expert and thought leader, identifying new and innovative/ground breaking ways of working. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions. Drive and achieve overall success and / or competitiveness of a business division by influencing senior leaders and committees. Strategically assess and manage risks to protect the business division / function and growth. Influence company policy and develop functional procedures in conjunction with senior leaders / strategic positions across the business. Demonstrate interpretative thinking for innovative solutions in complex situations and conceptual thinking in completely new situations. Exercise management authority to make significant / complex business and strategic decisions that impact the Barclays Group, business division or function. Negotiate with and influence stakeholders at a senior level both internally and externally and foster growth for Barclays business. Mandated as the business division/ functional spokesperson or representative to external bodies and shapes the public image of Barclays. Demonstrate exceptional knowledge of how business divisions and functions integrate with the Group to achieve the overall business objectives alongside industry theories and practices within own discipline. Maintain broad and comprehensive functional expertise and significant product knowledge. Accountable for the control and governance agenda of the business division / function. Focus on the external environment, regulators, or advocacy groups to both monitor and influence on behalf of Barclays. All Senior Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L - Listen and be authentic E - Energise and inspire A - Align across the enterprise D - Develop others All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship - our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset - to Empower, Challenge and Drive - the operating manual for how we behave. Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. - Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. Our employees are self disciplined, hard working, curious, trustworthy, humble, and truthful. They make choices according to what is best for the team, they live for opportunities to collaborate and make a difference, and they make us the Top Workplace in the area.
About the company the company's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role As Safety & Security Counsel, EMEA, you will serve as the first-line legal advisor counseling on the full arc of keeping Claude and the company safe and secure: usage policy design and enforcement frameworks, safeguards R&D, misuse detection and response, sensitive escalations, threat intelligence, security incident response, product-related safety and security matters, and the company's safety and security-related regulatory and policy engagement. The issues are increasingly interdisciplinary and novel, and you will frequently be the one ideating and building a legally-relevant framework rather than simply applying one. Depending on interest and experience, you will own and shape an ever-growing portfolio of issue areas across Safeguards and Security. You will also contribute to the team's capacity building efforts, including by leveraging Claude. You will work collaboratively with other legal functions on cross-functional initiatives. This is an excellent opportunity for an experienced attorney who wants to do high-stakes, first-of-its-kind work at the center of responsible AI development and deployment, and to grow as a strategic product counsel and trusted crisis counselor in a fast-moving environment. Key responsibilities Partner with Safeguards (trust & safety) policy teams on the design and iteration of usage policies across harm areas (e.g., CBRNE, cyber, user wellbeing, scaled abuse and influence operations, and distillation), including how policies translate into detection and enforcement. Advise on policy enforcement frameworks such as account actions, appeals, enforcement systems and thresholds. Counsel on sensitive escalations and strategic response, including matters involving governments, law enforcement, regulators, and the press. Advise on safety and security threat intelligence investigations, bug bounty and red-team programs, and internal and external safety and security testing arrangements. Support safeguards and security engineering, ML, and data science teams on building new tooling and detection mechanisms, including as it relates to data governance and privacy related considerations. Serve as a first-line legal contact for safety and security incidents, providing real-time guidance during incident response and assessing notification and reporting obligations under applicable legal frameworks and contractual commitments. Build and maintain crisis management playbooks, escalation protocols, and self-serve legal guidance to enable legal resource scaling. Stay abreast of key policy and regulatory developments in AI safety and security, and policy-specific domains across relevant jurisdictions, and translate them into practical guidance for our evolving product suite. Minimum qualifications Qualification to practice law in England & Wales, or another relevant jurisdiction Experience advising on fast-moving, high-stakes matters such as investigations, regulatory matters, crisis management, or enforcement work Working knowledge of at least one of: trust & safety, cybersecurity, privacy, or platform regulation Legal drafting and writing skills demonstrated through policies, playbooks, escalation protocols, or written guidance for non-legal audiences Technical fluency sufficient to understand system architecture, data flows, and AI model behavior Experience coordinating multi-stakeholder responses to time-sensitive matters and translating legal analysis into clear actionable steps for technical and executive audiences Preferred qualifications 8+ years of relevant legal experience In-house (product counsel) experience at a technology company working on security and/or trust & safety issues, or law firm experience advising tech clients on regulatory investigations or enforcement matters Experience with content moderation, platform safety (including user wellbeing issues), and crisis management Facility working with very technical teams, including machine learning, safety and security research, infrastructure, and threat intelligence Familiarity with AI systems and machine learning concepts, or experience advising on novel technology products Strong judgment about risk assessment and decision-making under uncertainty A low-ego, hands-on working style and a commitment to doing right by users and the people affected by misuse of AI systems Application Deadline: 6pm PT on Friday September 11, 2026. We encourage all interested and qualified applicants to submit their materials before this date to ensure full consideration. Role-specific policy: For this role, we expect all staff to be able to work from our London office at least 3 days a week, though we encourage you to apply even if you might need some flexibility for an interim period of time. The annual compensation range for this role is listed below. For sales roles, the range provided is the role's On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role. Annual Salary: £165,000-£205,000 GBP LogisticsMinimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices. Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this. We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of your candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team. Your safety matters to us.
Aug 26, 2026
Full time
About the company the company's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role As Safety & Security Counsel, EMEA, you will serve as the first-line legal advisor counseling on the full arc of keeping Claude and the company safe and secure: usage policy design and enforcement frameworks, safeguards R&D, misuse detection and response, sensitive escalations, threat intelligence, security incident response, product-related safety and security matters, and the company's safety and security-related regulatory and policy engagement. The issues are increasingly interdisciplinary and novel, and you will frequently be the one ideating and building a legally-relevant framework rather than simply applying one. Depending on interest and experience, you will own and shape an ever-growing portfolio of issue areas across Safeguards and Security. You will also contribute to the team's capacity building efforts, including by leveraging Claude. You will work collaboratively with other legal functions on cross-functional initiatives. This is an excellent opportunity for an experienced attorney who wants to do high-stakes, first-of-its-kind work at the center of responsible AI development and deployment, and to grow as a strategic product counsel and trusted crisis counselor in a fast-moving environment. Key responsibilities Partner with Safeguards (trust & safety) policy teams on the design and iteration of usage policies across harm areas (e.g., CBRNE, cyber, user wellbeing, scaled abuse and influence operations, and distillation), including how policies translate into detection and enforcement. Advise on policy enforcement frameworks such as account actions, appeals, enforcement systems and thresholds. Counsel on sensitive escalations and strategic response, including matters involving governments, law enforcement, regulators, and the press. Advise on safety and security threat intelligence investigations, bug bounty and red-team programs, and internal and external safety and security testing arrangements. Support safeguards and security engineering, ML, and data science teams on building new tooling and detection mechanisms, including as it relates to data governance and privacy related considerations. Serve as a first-line legal contact for safety and security incidents, providing real-time guidance during incident response and assessing notification and reporting obligations under applicable legal frameworks and contractual commitments. Build and maintain crisis management playbooks, escalation protocols, and self-serve legal guidance to enable legal resource scaling. Stay abreast of key policy and regulatory developments in AI safety and security, and policy-specific domains across relevant jurisdictions, and translate them into practical guidance for our evolving product suite. Minimum qualifications Qualification to practice law in England & Wales, or another relevant jurisdiction Experience advising on fast-moving, high-stakes matters such as investigations, regulatory matters, crisis management, or enforcement work Working knowledge of at least one of: trust & safety, cybersecurity, privacy, or platform regulation Legal drafting and writing skills demonstrated through policies, playbooks, escalation protocols, or written guidance for non-legal audiences Technical fluency sufficient to understand system architecture, data flows, and AI model behavior Experience coordinating multi-stakeholder responses to time-sensitive matters and translating legal analysis into clear actionable steps for technical and executive audiences Preferred qualifications 8+ years of relevant legal experience In-house (product counsel) experience at a technology company working on security and/or trust & safety issues, or law firm experience advising tech clients on regulatory investigations or enforcement matters Experience with content moderation, platform safety (including user wellbeing issues), and crisis management Facility working with very technical teams, including machine learning, safety and security research, infrastructure, and threat intelligence Familiarity with AI systems and machine learning concepts, or experience advising on novel technology products Strong judgment about risk assessment and decision-making under uncertainty A low-ego, hands-on working style and a commitment to doing right by users and the people affected by misuse of AI systems Application Deadline: 6pm PT on Friday September 11, 2026. We encourage all interested and qualified applicants to submit their materials before this date to ensure full consideration. Role-specific policy: For this role, we expect all staff to be able to work from our London office at least 3 days a week, though we encourage you to apply even if you might need some flexibility for an interim period of time. The annual compensation range for this role is listed below. For sales roles, the range provided is the role's On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role. Annual Salary: £165,000-£205,000 GBP LogisticsMinimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices. Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this. We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of your candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team. Your safety matters to us.
About the RoleAs a Senior Cloud Security Analyst, you'll play a key role in protecting cloud infrastructure and services through proactive monitoring, threat detection and incident response. Working within a collaborative Security Operations function, you'll analyse security events, investigate emerging threats and help strengthen the organisation's overall cyber resilience.This role offers the opportunity to work across modern cloud platforms, partnering with infrastructure, engineering and application teams to improve security controls, enhance detection capabilities and support secure cloud operations.Key ResponsibilitiesMonitor and investigate security events across Azure, AWS and hybrid cloud environments using SIEM, CSPM and native cloud security services.Perform detailed triage of alerts to identify genuine threats, eliminate false positives and determine appropriate remediation actions.Lead or support investigations into cloud-based security incidents, ensuring timely containment, recovery and accurate documentation.Analyse authentication activity, privileged access events, API usage and configuration changes to identify suspicious behaviour and potential compromise.Work alongside Security Operations, Infrastructure and DevOps teams to coordinate effective responses to security incidents.Recommend improvements to detection logic, alert quality and monitoring coverage based on operational findings and emerging threats.Develop and maintain security use cases that improve visibility across cloud workloads and services.Contribute to threat hunting activities by identifying indicators of compromise and analysing attacker techniques.Produce clear technical reports and communicate investigation findings to both technical and non-technical stakeholders.Participate in security improvement initiatives, helping implement new technologies, processes and operational controls.Keep up to date with developments in cloud security, attacker methodologies and industry best practices to strengthen organisational security.Technical SkillsExperience in several of the following areas would be advantageous:Microsoft Azure SecurityAWS Security ServicesGoogle Cloud Platform (desirable)Microsoft SentinelKusto Query Language (KQL)CloudTrail, Azure Activity Logs and cloud audit loggingCloud Security Posture Management (CSPM)CrowdStrike Falcon Cloud SecurityMicrosoft Defender SuiteKubernetes security conceptsIdentity and Access Management (IAM)Privileged Access ManagementMicrosoft Entra ID (Azure AD)MITRE ATT&CK FrameworkThreat IntelligenceIncident ResponseThreat HuntingSIEM TechnologiesSecurity MonitoringSecurity Operations (SOC)Cloud Networking FundamentalsWhat You'll BringExperience working within a Security Operations Centre or Cloud Security environment.Strong analytical and investigative skills with the ability to prioritise and manage multiple security events.Confidence interpreting security telemetry and identifying indicators of malicious activity.Excellent problem-solving skills and the ability to make informed decisions during security incidents.Strong communication skills with the ability to present technical findings clearly.A collaborative approach to working with infrastructure, engineering and operational teams.A proactive mindset focused on continuous improvement and operational excellence.Desirable QualificationsMicrosoft SC-200Microsoft AZ-500AWS Certified Security - SpecialtyCertified Kubernetes Security Specialist (CKS)CompTIA Security+CISSPGIAC certificationsRelevant cloud or cyber security certifications To speak in absolute confidence about this opportunity please send an up-to-date CV via the link provided or contact Senior Recruitment Consultant Stuart Kennedy at MCS Group on or . Even if this position is not right for you, we may have others that are. Please visit MCS Group to view a wide selection of our current jobs.
Aug 26, 2026
Full time
About the RoleAs a Senior Cloud Security Analyst, you'll play a key role in protecting cloud infrastructure and services through proactive monitoring, threat detection and incident response. Working within a collaborative Security Operations function, you'll analyse security events, investigate emerging threats and help strengthen the organisation's overall cyber resilience.This role offers the opportunity to work across modern cloud platforms, partnering with infrastructure, engineering and application teams to improve security controls, enhance detection capabilities and support secure cloud operations.Key ResponsibilitiesMonitor and investigate security events across Azure, AWS and hybrid cloud environments using SIEM, CSPM and native cloud security services.Perform detailed triage of alerts to identify genuine threats, eliminate false positives and determine appropriate remediation actions.Lead or support investigations into cloud-based security incidents, ensuring timely containment, recovery and accurate documentation.Analyse authentication activity, privileged access events, API usage and configuration changes to identify suspicious behaviour and potential compromise.Work alongside Security Operations, Infrastructure and DevOps teams to coordinate effective responses to security incidents.Recommend improvements to detection logic, alert quality and monitoring coverage based on operational findings and emerging threats.Develop and maintain security use cases that improve visibility across cloud workloads and services.Contribute to threat hunting activities by identifying indicators of compromise and analysing attacker techniques.Produce clear technical reports and communicate investigation findings to both technical and non-technical stakeholders.Participate in security improvement initiatives, helping implement new technologies, processes and operational controls.Keep up to date with developments in cloud security, attacker methodologies and industry best practices to strengthen organisational security.Technical SkillsExperience in several of the following areas would be advantageous:Microsoft Azure SecurityAWS Security ServicesGoogle Cloud Platform (desirable)Microsoft SentinelKusto Query Language (KQL)CloudTrail, Azure Activity Logs and cloud audit loggingCloud Security Posture Management (CSPM)CrowdStrike Falcon Cloud SecurityMicrosoft Defender SuiteKubernetes security conceptsIdentity and Access Management (IAM)Privileged Access ManagementMicrosoft Entra ID (Azure AD)MITRE ATT&CK FrameworkThreat IntelligenceIncident ResponseThreat HuntingSIEM TechnologiesSecurity MonitoringSecurity Operations (SOC)Cloud Networking FundamentalsWhat You'll BringExperience working within a Security Operations Centre or Cloud Security environment.Strong analytical and investigative skills with the ability to prioritise and manage multiple security events.Confidence interpreting security telemetry and identifying indicators of malicious activity.Excellent problem-solving skills and the ability to make informed decisions during security incidents.Strong communication skills with the ability to present technical findings clearly.A collaborative approach to working with infrastructure, engineering and operational teams.A proactive mindset focused on continuous improvement and operational excellence.Desirable QualificationsMicrosoft SC-200Microsoft AZ-500AWS Certified Security - SpecialtyCertified Kubernetes Security Specialist (CKS)CompTIA Security+CISSPGIAC certificationsRelevant cloud or cyber security certifications To speak in absolute confidence about this opportunity please send an up-to-date CV via the link provided or contact Senior Recruitment Consultant Stuart Kennedy at MCS Group on or . Even if this position is not right for you, we may have others that are. Please visit MCS Group to view a wide selection of our current jobs.
Cyber Response & Recovery Manager Salary: £68,000-£80,000 + benefits Location : London Clearance: SC Eligible We are seeking an experienced Cyber Response & Recovery Manager to join a leading cyber security consultancy, helping organisations recover from major cyber incidents and strengthen their long-term resilience click apply for full job details
Aug 25, 2026
Full time
Cyber Response & Recovery Manager Salary: £68,000-£80,000 + benefits Location : London Clearance: SC Eligible We are seeking an experienced Cyber Response & Recovery Manager to join a leading cyber security consultancy, helping organisations recover from major cyber incidents and strengthen their long-term resilience click apply for full job details
Your Role: As a Cyber Security Specialist, you will work within a multi-disciplinary security team delivering a broad range of services, including threat detection and response, vulnerability scanning, dark web monitoring, social engineering assessments, and security reporting. You will act as a technical escalation point for complex security incidents, leading containment and remediation activitie click apply for full job details
Aug 25, 2026
Full time
Your Role: As a Cyber Security Specialist, you will work within a multi-disciplinary security team delivering a broad range of services, including threat detection and response, vulnerability scanning, dark web monitoring, social engineering assessments, and security reporting. You will act as a technical escalation point for complex security incidents, leading containment and remediation activitie click apply for full job details
ZeroFox seeks an Intelligence Analyst (Arabic Language) to join the ZeroFox Services and Analysis Team, you will collect information to identify threats, and generate intelligence to assess risk in relevance to client needs. Intelligence activities can include researching current and emerging threats issues covering physical security, cyber security, geopolitical, reputation risk and compliance issues. The Intelligence Analyst will have an investigative or analytical background and demonstrated exceptional analytic prowess in areas such as trend analysis and pattern recognition, using independent critical thinking and judgment to act, lead, initiate and/or recommend next steps. Discretion, teamwork, and creativity are a must. Key Responsibilities include: Learn and employ ZeroFox patented technology to identify and analyze relevant information collected from the Internet, based on client-specific criteria, to assemble relevant findings for daily intelligence and recurring reporting; Assist in customer care and all production aspects covering the range of assigned duties. Support and /or lead recurring deliverables and touchpoints (ad hoc / daily / weekly / monthly / quarterly and / or annual): Security/Incident Alerts Intelligence Reports Trend and summary reports Strategic assessments and reviews Client briefings Support collection enhancement with ongoing and proactive collaboration with Collection Management and 24x7 support. Dedication and willingness to provide support in response to ad hoc threats and periods of increased risk. This may entail on occasion: Ad hoc investigations and assessments Ancillary threat monitoring outside core business hours Proactive professional development through company trainings, industry certifications, and seeking new opportunities to maintain and grow relevant knowledge and skillsets. Identify and communicate enhancement opportunities and improvement ideas for the department's operations. Qualifying Requirements: Written and spoken fluency in Arabic Experience in open source and social media research, or investigations, typically obtained in 2-3 years; ability to connect the dots; Creativity in leveraging internet search techniques and methods; Ability to determine the credibility, value, significance, and relevancy of information from different data sources to produce clear, concise, and timely analytical products; Strong written and oral communication skills; comfortable with providing briefings and presentations. Experience producing short and long form reports, applying BLUF or similar models; Comfort working independently and in teams; Experience with some of the following: Social Media Platforms, blogs, IRC, Deep / Darkweb , and message boards; Ability to collect, authenticate, validate and document online evidence; Proficient with at least one online investigative tool, such as Whois, Ping, Traceroute, etc; Proficient in Google Suite of programs; Preferred Experience: Public or private sector experience as an analyst, researcher, investigator or consultant supporting a security, risk or due diligence function. Experience in conducting studies and making recommendations to identify threat vectors, threat actors, and threat trends Experience in briefing decision-makers and senior leaders; High degree of knowledge of Social Media Platforms, blogs, IRC, message boards, Deep/Darkweb; Knowledge of IPv4, IPv6, DNS records, E-mails Headers, P2P; Possession of excellent project/team leadership, development, and client relationship skills; Knowledge and familiarity with relevant threat landscapes or industry practice areas such as cybercrime, online fraud, physical/corporate security, activism, hacktivism, reputation risk, travel security, geopolitical or policy issues Bachelor's degree with relevant coursework Education / Training Requirements: Bachelor's Degree Benefits Competitive compensation Community-driven culture with employee events Generous time offComprehensive private insurance and EAP Fun, modern workspace Respectful and nourishing work environment, where every opinion is heard and everyone is encouraged to be an active part of the organizational culture Physical and Sensory Requirements: Mobility, walking, climbing, sitting, standing, reaching, bending, lifting (minimum of 10 lbs), fine eye-hand coordination, ability to read, write, listen and speak clearly, the ability to understand and follow written and oral instructions and directions, ability to travel =/
Aug 25, 2026
Full time
ZeroFox seeks an Intelligence Analyst (Arabic Language) to join the ZeroFox Services and Analysis Team, you will collect information to identify threats, and generate intelligence to assess risk in relevance to client needs. Intelligence activities can include researching current and emerging threats issues covering physical security, cyber security, geopolitical, reputation risk and compliance issues. The Intelligence Analyst will have an investigative or analytical background and demonstrated exceptional analytic prowess in areas such as trend analysis and pattern recognition, using independent critical thinking and judgment to act, lead, initiate and/or recommend next steps. Discretion, teamwork, and creativity are a must. Key Responsibilities include: Learn and employ ZeroFox patented technology to identify and analyze relevant information collected from the Internet, based on client-specific criteria, to assemble relevant findings for daily intelligence and recurring reporting; Assist in customer care and all production aspects covering the range of assigned duties. Support and /or lead recurring deliverables and touchpoints (ad hoc / daily / weekly / monthly / quarterly and / or annual): Security/Incident Alerts Intelligence Reports Trend and summary reports Strategic assessments and reviews Client briefings Support collection enhancement with ongoing and proactive collaboration with Collection Management and 24x7 support. Dedication and willingness to provide support in response to ad hoc threats and periods of increased risk. This may entail on occasion: Ad hoc investigations and assessments Ancillary threat monitoring outside core business hours Proactive professional development through company trainings, industry certifications, and seeking new opportunities to maintain and grow relevant knowledge and skillsets. Identify and communicate enhancement opportunities and improvement ideas for the department's operations. Qualifying Requirements: Written and spoken fluency in Arabic Experience in open source and social media research, or investigations, typically obtained in 2-3 years; ability to connect the dots; Creativity in leveraging internet search techniques and methods; Ability to determine the credibility, value, significance, and relevancy of information from different data sources to produce clear, concise, and timely analytical products; Strong written and oral communication skills; comfortable with providing briefings and presentations. Experience producing short and long form reports, applying BLUF or similar models; Comfort working independently and in teams; Experience with some of the following: Social Media Platforms, blogs, IRC, Deep / Darkweb , and message boards; Ability to collect, authenticate, validate and document online evidence; Proficient with at least one online investigative tool, such as Whois, Ping, Traceroute, etc; Proficient in Google Suite of programs; Preferred Experience: Public or private sector experience as an analyst, researcher, investigator or consultant supporting a security, risk or due diligence function. Experience in conducting studies and making recommendations to identify threat vectors, threat actors, and threat trends Experience in briefing decision-makers and senior leaders; High degree of knowledge of Social Media Platforms, blogs, IRC, message boards, Deep/Darkweb; Knowledge of IPv4, IPv6, DNS records, E-mails Headers, P2P; Possession of excellent project/team leadership, development, and client relationship skills; Knowledge and familiarity with relevant threat landscapes or industry practice areas such as cybercrime, online fraud, physical/corporate security, activism, hacktivism, reputation risk, travel security, geopolitical or policy issues Bachelor's degree with relevant coursework Education / Training Requirements: Bachelor's Degree Benefits Competitive compensation Community-driven culture with employee events Generous time offComprehensive private insurance and EAP Fun, modern workspace Respectful and nourishing work environment, where every opinion is heard and everyone is encouraged to be an active part of the organizational culture Physical and Sensory Requirements: Mobility, walking, climbing, sitting, standing, reaching, bending, lifting (minimum of 10 lbs), fine eye-hand coordination, ability to read, write, listen and speak clearly, the ability to understand and follow written and oral instructions and directions, ability to travel =/
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
Aug 25, 2026
Full time
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
BURGERS & FRIES AND INCREDIBLE CAREERS! We're the burger restaurant with the uncomplicated formula: burgers and fries cooked to perfection, with no frozen ingredients. And we've stuck to the same 'perfect and serve' philosophy since our family business began in 1986. These days, we're still just as much a family as we always have been. We have tons of integrity, we're enthusiastic. we're competitive and we just get it done - whatever the challenge. As Five Guys continues to evolve its restaurant technology landscape across multiple European markets, this role offers the opportunity to play a key leadership part in shaping how restaurant technology is run, supported, standardised and improved across the estate. Why this role matters This is a high-impact leadership role at an important point in the evolution of Five Guys' restaurant technology estate. It offers the opportunity to shape how restaurant technology is supported, governed and improved across multiple countries, while leading a team and strengthening operational resilience across the business. For the right person, this is a chance to combine technical depth, people leadership and practical delivery in a business where technology has a direct and visible impact on day-to-day performance. Role Summary This is a senior, hands-on IT leadership role responsible for the performance, stability and evolution of restaurant technology across the UK, France, Spain and Germany. It sits at the centre of a fast-paced, multi-country environment requiring strong judgement, pace and technical credibility. The role combines leadership, operational ownership and hands-on problem solving, with accountability for major incidents, technical standards, supplier performance and scalable solutions across the estate. With direct impact on revenue, operational resilience, rapid decision-making and practical leadership are critical. The role also plays a key part in standardising, documenting and improving restaurant technology, working closely with projects, architecture, cybersecurity, suppliers and in-country IT teams. Leadership & Team Management This is a key leadership position within the IT function, with line management responsibility for in-country IT Managers. The successful candidate will be expected to provide clear direction, build capability, create accountability and lead a high-performing team across multiple markets and cultures. Success in the role will depend not just on technical strength, but on the ability to lead people well, bring clarity in fast-moving situations and create a consistent, effective operating approach across the estate. Restaurant Operations & Escalation Own the operational stability of restaurant technology across all markets Lead the response to major incidents and critical service issues affecting restaurants Coordinate internal teams, suppliers and business stakeholders through to resolution Make timely, well-judged decisions in live operational situations Drive permanent root cause resolution rather than short-term workarounds Support and coach IT Managers in resolving high-impact or complex operational issues Hands-On Technical Ownership Bring strong technical credibility across restaurant technology, infrastructure and integrations Be willing to get into the detail personally when required to resolve critical issues Understand system behaviours, dependencies and failure points across POS, payments, networks, kiosks and related restaurant technologies Validate technical solutions, supplier configurations and delivery quality Apply sound judgement to distinguish between quick fixes, sustainable solutions and acceptable risk Experience with NCR Aloha or comparable restaurant / retail POS platforms is highly desirable, alongside broader familiarity with payment, kiosk, network and in-store technology environments Technical Solution Design Define and evolve standards for POS, kiosks, networks, CCTV and in-store technology Ensure solutions are scalable, supportable and operationally fit for a live restaurant environment Balance standardisation with real-world operational constraints across different markets Identify opportunities to simplify, improve and modernise the restaurant technology estate over time Work closely with project and architecture teams to ensure solutions are robust and ready for rollout Documentation & Handover to Projects Create clear, structured technical documentation covering designs, configurations, standards and use cases Ensure solutions are properly documented and operationally ready before rollout Build repeatable, well-governed handover processes into project delivery Capture knowledge, decisions and technical standards in a way that supports consistency across markets Help bring greater structure, clarity and repeatability to the function over time Standards & Consistency Drive consistency in restaurant technology standards across all countries Reduce unnecessary local variation and unsupported workarounds Balance control and standardisation with genuine local operational requirements Promote a clear, scalable operating model for restaurant technology across the estate Support a joined-up approach across markets while recognising cultural and operational differences Supplier & SLA Management Own technical supplier performance across restaurant technology services Hold vendors to account against SLAs and agreed service outcomes Challenge poor performance, weak solutions or avoidable service drift Work pragmatically with partners to improve resilience,
Aug 25, 2026
Full time
BURGERS & FRIES AND INCREDIBLE CAREERS! We're the burger restaurant with the uncomplicated formula: burgers and fries cooked to perfection, with no frozen ingredients. And we've stuck to the same 'perfect and serve' philosophy since our family business began in 1986. These days, we're still just as much a family as we always have been. We have tons of integrity, we're enthusiastic. we're competitive and we just get it done - whatever the challenge. As Five Guys continues to evolve its restaurant technology landscape across multiple European markets, this role offers the opportunity to play a key leadership part in shaping how restaurant technology is run, supported, standardised and improved across the estate. Why this role matters This is a high-impact leadership role at an important point in the evolution of Five Guys' restaurant technology estate. It offers the opportunity to shape how restaurant technology is supported, governed and improved across multiple countries, while leading a team and strengthening operational resilience across the business. For the right person, this is a chance to combine technical depth, people leadership and practical delivery in a business where technology has a direct and visible impact on day-to-day performance. Role Summary This is a senior, hands-on IT leadership role responsible for the performance, stability and evolution of restaurant technology across the UK, France, Spain and Germany. It sits at the centre of a fast-paced, multi-country environment requiring strong judgement, pace and technical credibility. The role combines leadership, operational ownership and hands-on problem solving, with accountability for major incidents, technical standards, supplier performance and scalable solutions across the estate. With direct impact on revenue, operational resilience, rapid decision-making and practical leadership are critical. The role also plays a key part in standardising, documenting and improving restaurant technology, working closely with projects, architecture, cybersecurity, suppliers and in-country IT teams. Leadership & Team Management This is a key leadership position within the IT function, with line management responsibility for in-country IT Managers. The successful candidate will be expected to provide clear direction, build capability, create accountability and lead a high-performing team across multiple markets and cultures. Success in the role will depend not just on technical strength, but on the ability to lead people well, bring clarity in fast-moving situations and create a consistent, effective operating approach across the estate. Restaurant Operations & Escalation Own the operational stability of restaurant technology across all markets Lead the response to major incidents and critical service issues affecting restaurants Coordinate internal teams, suppliers and business stakeholders through to resolution Make timely, well-judged decisions in live operational situations Drive permanent root cause resolution rather than short-term workarounds Support and coach IT Managers in resolving high-impact or complex operational issues Hands-On Technical Ownership Bring strong technical credibility across restaurant technology, infrastructure and integrations Be willing to get into the detail personally when required to resolve critical issues Understand system behaviours, dependencies and failure points across POS, payments, networks, kiosks and related restaurant technologies Validate technical solutions, supplier configurations and delivery quality Apply sound judgement to distinguish between quick fixes, sustainable solutions and acceptable risk Experience with NCR Aloha or comparable restaurant / retail POS platforms is highly desirable, alongside broader familiarity with payment, kiosk, network and in-store technology environments Technical Solution Design Define and evolve standards for POS, kiosks, networks, CCTV and in-store technology Ensure solutions are scalable, supportable and operationally fit for a live restaurant environment Balance standardisation with real-world operational constraints across different markets Identify opportunities to simplify, improve and modernise the restaurant technology estate over time Work closely with project and architecture teams to ensure solutions are robust and ready for rollout Documentation & Handover to Projects Create clear, structured technical documentation covering designs, configurations, standards and use cases Ensure solutions are properly documented and operationally ready before rollout Build repeatable, well-governed handover processes into project delivery Capture knowledge, decisions and technical standards in a way that supports consistency across markets Help bring greater structure, clarity and repeatability to the function over time Standards & Consistency Drive consistency in restaurant technology standards across all countries Reduce unnecessary local variation and unsupported workarounds Balance control and standardisation with genuine local operational requirements Promote a clear, scalable operating model for restaurant technology across the estate Support a joined-up approach across markets while recognising cultural and operational differences Supplier & SLA Management Own technical supplier performance across restaurant technology services Hold vendors to account against SLAs and agreed service outcomes Challenge poor performance, weak solutions or avoidable service drift Work pragmatically with partners to improve resilience,
Cyber Security Operations Manager Exeter REMOTE £800 per day Umbrella Initially 6-month contract Mon-Fri Certain Advantage is working in partnership with a leading public organisation seeking an SOC Manager to design, implement and continuously improve the departments Security Operations strategy, ensuring rapid detection, response and recovery from cyber threats and incidents click apply for full job details
Aug 25, 2026
Contractor
Cyber Security Operations Manager Exeter REMOTE £800 per day Umbrella Initially 6-month contract Mon-Fri Certain Advantage is working in partnership with a leading public organisation seeking an SOC Manager to design, implement and continuously improve the departments Security Operations strategy, ensuring rapid detection, response and recovery from cyber threats and incidents click apply for full job details
Isr Recruitment Limited
Eaglescliffe, County Durham
The Opportunity Our client is looking to appoint an experienced ICT Cyber & Information Security Manager to take responsibility for a broad range of cyber security, information security, risk and compliance activities across the organisation. This is a key role within the Information Security function, providing the opportunity to take ownership of security activities ranging from the ICT Annual Delivery Plan through to major business growth initiatives, including site transitions and acquisitions across the UK and internationally. You'll work closely with internal teams, senior stakeholders and external partners to strengthen the organisation's cyber and information security posture, manage risk and ensure compliance with relevant security standards and legislation. The successful candidate will combine strong technical security knowledge with excellent governance, risk management and stakeholder-management skills. Skills and Experience: Experience leading cyber security, information security and/or compliance activities within a medium-to-large enterprise environment. Strong experience managing an enterprise information/cyber security risk register. Strong practical knowledge of Information Security Management Systems (ISMS). Experience implementing, maintaining and continually improving an ISMS. Experience preparing for and participating in internal and external security audits. Strong knowledge of ISO 27002 and experience delivering against its requirements. Strong knowledge of Cyber Essentials / Cyber Essentials Plus. Experience working with NIST security frameworks. Knowledge of CAF / Cyber Assessment Framework and its application to organisational security. Understanding of NIS2, GDPR and the Data Protection Act. Strong understanding of cyber security risk, governance, controls and remediation. Qualifications Professional security qualifications such as the following would be highly desirable: CISSP / CISM / CISA ISO 27001/27002-related qualifications Other recognised cyber security, information assurance or risk-management certifications Role and Responsibilities: Act as a key pillar of the organisation's Information Security programme, driving and managing cyber and information security activities. Work collaboratively with internal teams and external partners to deliver security initiatives and improvements. Develop, review and rehearse incident response plans, ensuring the organisation is prepared to detect, investigate and respond effectively to cyber incidents and data breaches. Work with relevant teams to review, test and improve Business Continuity, Recovery Time Objective (RTO) and Recovery Time Strategy (RTS) arrangements. Conduct and support security risk assessments and vulnerability assessments to identify threats, vulnerabilities and areas for improvement. Develop and implement appropriate risk mitigation strategies. Manage and maintain ICT Cyber & Data Security Risk Registers, ensuring risks are appropriately assessed, owned, mitigated and reported. Review, develop, implement and maintain cyber security, information security, data protection and compliance policies. Monitor changes in the regulatory and threat landscape and assess their impact on the organisation. Ensure compliance with relevant legislation, regulations, frameworks and security standards, including GDPR, Data Protection Act, NIS2, NIST, Cyber Essentials and ISO 27002. Lead and coordinate information security metrics, reporting and management information. Support and oversee offensive security activities, vulnerability management and security testing. Maintain and continuously improve the organisation's Information Security Management System (ISMS). Lead or participate in internal and external security audits and assessments, including ISO 27002 and Cyber Essentials Plus. Provide security input into business change, technology projects, acquisitions, site transitions and other strategic initiatives. Work with stakeholders to embed security by design across ICT and wider business activities. Applications: To learn more about our established client and this newly created role working as a IT Security Manager for our client based in the Teesside / County Durham area (with excellent flexible/remote working options available); please call and speak with Edward Laing here at ISR Recruitment to learn more or please send through a copy of your latest CV and/or share your online business profile for a call back in the very strictest of confidence.
Aug 24, 2026
Full time
The Opportunity Our client is looking to appoint an experienced ICT Cyber & Information Security Manager to take responsibility for a broad range of cyber security, information security, risk and compliance activities across the organisation. This is a key role within the Information Security function, providing the opportunity to take ownership of security activities ranging from the ICT Annual Delivery Plan through to major business growth initiatives, including site transitions and acquisitions across the UK and internationally. You'll work closely with internal teams, senior stakeholders and external partners to strengthen the organisation's cyber and information security posture, manage risk and ensure compliance with relevant security standards and legislation. The successful candidate will combine strong technical security knowledge with excellent governance, risk management and stakeholder-management skills. Skills and Experience: Experience leading cyber security, information security and/or compliance activities within a medium-to-large enterprise environment. Strong experience managing an enterprise information/cyber security risk register. Strong practical knowledge of Information Security Management Systems (ISMS). Experience implementing, maintaining and continually improving an ISMS. Experience preparing for and participating in internal and external security audits. Strong knowledge of ISO 27002 and experience delivering against its requirements. Strong knowledge of Cyber Essentials / Cyber Essentials Plus. Experience working with NIST security frameworks. Knowledge of CAF / Cyber Assessment Framework and its application to organisational security. Understanding of NIS2, GDPR and the Data Protection Act. Strong understanding of cyber security risk, governance, controls and remediation. Qualifications Professional security qualifications such as the following would be highly desirable: CISSP / CISM / CISA ISO 27001/27002-related qualifications Other recognised cyber security, information assurance or risk-management certifications Role and Responsibilities: Act as a key pillar of the organisation's Information Security programme, driving and managing cyber and information security activities. Work collaboratively with internal teams and external partners to deliver security initiatives and improvements. Develop, review and rehearse incident response plans, ensuring the organisation is prepared to detect, investigate and respond effectively to cyber incidents and data breaches. Work with relevant teams to review, test and improve Business Continuity, Recovery Time Objective (RTO) and Recovery Time Strategy (RTS) arrangements. Conduct and support security risk assessments and vulnerability assessments to identify threats, vulnerabilities and areas for improvement. Develop and implement appropriate risk mitigation strategies. Manage and maintain ICT Cyber & Data Security Risk Registers, ensuring risks are appropriately assessed, owned, mitigated and reported. Review, develop, implement and maintain cyber security, information security, data protection and compliance policies. Monitor changes in the regulatory and threat landscape and assess their impact on the organisation. Ensure compliance with relevant legislation, regulations, frameworks and security standards, including GDPR, Data Protection Act, NIS2, NIST, Cyber Essentials and ISO 27002. Lead and coordinate information security metrics, reporting and management information. Support and oversee offensive security activities, vulnerability management and security testing. Maintain and continuously improve the organisation's Information Security Management System (ISMS). Lead or participate in internal and external security audits and assessments, including ISO 27002 and Cyber Essentials Plus. Provide security input into business change, technology projects, acquisitions, site transitions and other strategic initiatives. Work with stakeholders to embed security by design across ICT and wider business activities. Applications: To learn more about our established client and this newly created role working as a IT Security Manager for our client based in the Teesside / County Durham area (with excellent flexible/remote working options available); please call and speak with Edward Laing here at ISR Recruitment to learn more or please send through a copy of your latest CV and/or share your online business profile for a call back in the very strictest of confidence.
Position Summary As a SOC Shift Lead, you build on your solid experience as a SOC Analyst by supervising and guiding a team of SOC Analysts during your assigned shift. You ensure quality and consistency across all alerts and incidents handled by the team while serving as the primary point of escalation. In this role, you support team development, drive process improvements, and maintain clear, customer-centric communication with all stakeholders. You also lead quality assurance efforts and ensure that service-level agreements (SLAs) are met. Objectives & Key Results Key Responsibilities Shift Leadership and Team Coordination - You run shift operations, ensuring compliance with SLAs and maintaining high-quality incident handling. You set shift agendas, balance workloads, and promptly address any process or staffing issues. You also maintain effective, customer-centric communication with internal teams (including Security Optimisation and Engineering), customers, and their incident response partners Incident Triage and Investigation - You review and prioritise new alerts, taking initial ownership of high-priority or complex incidents, and ensure proper escalation to customers and Senior SOC Analysts. You make sound, data-driven decisions to facilitate effective triage, investigation, and escalation in line with operational standards Quality Assurance and Documentation - You conduct regular quality assurance (QA) of tickets to ensure SOC procedures and documentation standards are met, providing clear, constructive feedback to team members to improve technical skills and workflow consistency Collaboration and Mentorship - You mentor SOC Analysts in your team by offering regular, constructive feedback on triage processes and best practices. You encourage targeted training initiatives, including relevant certifications, to support career progression within the SOC Service Improvement - You contribute to ongoing service improvement through participation in supporting threat hunting activity led by Senior SOC Analysts, rule tuning, and process refinement initiatives. You assist in monthly reporting and post-incident reviews to drive improvements that reflect our commitment to transparent and reliable performance Required Qualifications & Experience You may be required to hold or obtain UK Non-Police Personnel Vetting (NPPV) and/or a Security Check (SC) clearance as part of this role Willingness to work towards or obtain intermediate cybersecurity certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst) Proficiency with SIEM platforms, endpoint security tools, and ticketing systems, with an ability to make clear, data-driven decisions under pressure Critical Competencies - Technical Fit Operating Systems - Possess detailed knowledge of Windows and Linux system architectures, with a clear understanding of how event logs (e.g., Windows Event Viewer, Syslog) reflect system security posture Networking and Protocols - Have a comprehensive understanding of TCP/IP, DNS, DCHP, VPNs, SSL/TLS, and network forensics concepts to validate network-based alerts and anomalies Cybersecurity Frameworks - Deeply understand and be able to articulate the elements of the MITRE ATT&CK framework, and Cyber Kill Chain; know how adversary tactics and techniques translate into observable indicators SIEM and Security Tools - Know the theoretical underpinnings of SIEM operations, including alert correlation, the design of automated detection rules, and the interpretation of aggregated security data Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence - how feeds are sourced, what constitutes actionable information, and how malware indicators are defined Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling Benefits At Claranet, we go the extra mile with our people-because we believe in building a workplace where everyone feels valued and supported. What makes us unique is Team Claranet , our internal community that supports causes close to our employees' hearts. We offer paid charity leave, support local charities across our offices, and host annual fundraising events, all backed by a dedicated committee. We're proud founding members of TC4RE (Technology Community for Racial Equality) working collectively to build a more diverse and inclusive tech industry. About Claranet Founded at the beginning of the dot com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries. Equal Opportunities Statement Diversity, equity and inclusion are at the heart of what we value as an organisation. Claranet is an equal opportunities employer and all qualified applicants will receive consideration for employment without regard to race, religion, sex, sexual orientation, age, disability or any other status protected by law. Our recruitment team are happy to support any reasonable adjustments that are needed within the recruitment process. Ready to take the next step in your career with Claranet? Click 'apply' - we can't wait to meet you! To view full job description please visit our careers page
Aug 24, 2026
Full time
Position Summary As a SOC Shift Lead, you build on your solid experience as a SOC Analyst by supervising and guiding a team of SOC Analysts during your assigned shift. You ensure quality and consistency across all alerts and incidents handled by the team while serving as the primary point of escalation. In this role, you support team development, drive process improvements, and maintain clear, customer-centric communication with all stakeholders. You also lead quality assurance efforts and ensure that service-level agreements (SLAs) are met. Objectives & Key Results Key Responsibilities Shift Leadership and Team Coordination - You run shift operations, ensuring compliance with SLAs and maintaining high-quality incident handling. You set shift agendas, balance workloads, and promptly address any process or staffing issues. You also maintain effective, customer-centric communication with internal teams (including Security Optimisation and Engineering), customers, and their incident response partners Incident Triage and Investigation - You review and prioritise new alerts, taking initial ownership of high-priority or complex incidents, and ensure proper escalation to customers and Senior SOC Analysts. You make sound, data-driven decisions to facilitate effective triage, investigation, and escalation in line with operational standards Quality Assurance and Documentation - You conduct regular quality assurance (QA) of tickets to ensure SOC procedures and documentation standards are met, providing clear, constructive feedback to team members to improve technical skills and workflow consistency Collaboration and Mentorship - You mentor SOC Analysts in your team by offering regular, constructive feedback on triage processes and best practices. You encourage targeted training initiatives, including relevant certifications, to support career progression within the SOC Service Improvement - You contribute to ongoing service improvement through participation in supporting threat hunting activity led by Senior SOC Analysts, rule tuning, and process refinement initiatives. You assist in monthly reporting and post-incident reviews to drive improvements that reflect our commitment to transparent and reliable performance Required Qualifications & Experience You may be required to hold or obtain UK Non-Police Personnel Vetting (NPPV) and/or a Security Check (SC) clearance as part of this role Willingness to work towards or obtain intermediate cybersecurity certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst) Proficiency with SIEM platforms, endpoint security tools, and ticketing systems, with an ability to make clear, data-driven decisions under pressure Critical Competencies - Technical Fit Operating Systems - Possess detailed knowledge of Windows and Linux system architectures, with a clear understanding of how event logs (e.g., Windows Event Viewer, Syslog) reflect system security posture Networking and Protocols - Have a comprehensive understanding of TCP/IP, DNS, DCHP, VPNs, SSL/TLS, and network forensics concepts to validate network-based alerts and anomalies Cybersecurity Frameworks - Deeply understand and be able to articulate the elements of the MITRE ATT&CK framework, and Cyber Kill Chain; know how adversary tactics and techniques translate into observable indicators SIEM and Security Tools - Know the theoretical underpinnings of SIEM operations, including alert correlation, the design of automated detection rules, and the interpretation of aggregated security data Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence - how feeds are sourced, what constitutes actionable information, and how malware indicators are defined Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling Benefits At Claranet, we go the extra mile with our people-because we believe in building a workplace where everyone feels valued and supported. What makes us unique is Team Claranet , our internal community that supports causes close to our employees' hearts. We offer paid charity leave, support local charities across our offices, and host annual fundraising events, all backed by a dedicated committee. We're proud founding members of TC4RE (Technology Community for Racial Equality) working collectively to build a more diverse and inclusive tech industry. About Claranet Founded at the beginning of the dot com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries. Equal Opportunities Statement Diversity, equity and inclusion are at the heart of what we value as an organisation. Claranet is an equal opportunities employer and all qualified applicants will receive consideration for employment without regard to race, religion, sex, sexual orientation, age, disability or any other status protected by law. Our recruitment team are happy to support any reasonable adjustments that are needed within the recruitment process. Ready to take the next step in your career with Claranet? Click 'apply' - we can't wait to meet you! To view full job description please visit our careers page
IT Cyber Security Specialist / Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team, supporting and continually improving cybersecurity across a global IT environment. Reporting to the Infrastructure Engineering Manager, you'll take ownership of cybersecurity controls and security architecture while working closely with Infrastructure Operations and other technology teams to identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across a complex infrastructure environment, identifying and mitigating security risks, supporting major cyber incidents and contributing to strategic security and infrastructure projects. You'll also help develop security awareness, business continuity capabilities and ongoing improvements to the firm's security controls. Key Responsibilities: Continuously review and improve the firm's cybersecurity posture from an infrastructure perspective and external security rating. Identify, assess and remediate vulnerabilities across hardware, software and infrastructure (Windows Server and Azure Cloud). Monitor emerging threats and lead or support Incident Response investigations and mitigation. Evaluate, test and recommend security enhancements, controls and threat prevention technologies. Identify security risks and exposures and develop measures to prevent future incidents. Lead CE+ accreditation and support security, risk and data protection requirements from a technical (Not GRC) perspective. Participate in and lead infrastructure lifecycle, security and technology projects. Provide 3rd Line / Major Incident support as a cybersecurity subject matter expert. Work with third-party suppliers and advise internal technical teams on security measures to resolve security and infrastructure issues. We're looking for experienced Cyber Security engineer with strong technical infrastructure knowledge and proven experience across incident response, threat monitoring and vulnerability management. You will possess: Extensive experience in a similar role blending Cyber Security with core Wintel Infrastructure and Azure cloud engineering. Strong knowledge of modern security architecture, threat prevention techniques and incident response. Strong Windows Server 2016/2019/2022 knowledge including Active Directory, DNS, DHCP, Intune, Group Policy, PKI, Entra and Azure SSO. Demonstrable experience across Cyber Security, Incident Response, Threat Monitoring and Vulnerability Management using tools such as MS Sentinel, MS Defender etc for threat hunting, vulnerability monitoring and security posture improvement. CISSP, CEH, CCNA Security, SC-100, SC200 or equivalent security certification. Experience designing, integrating and managing complex infrastructure and cloud solutions from a cyber security standpoint and advising technical infrastructure teams on security focussed designs and operations Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. Experience working with third-party providers across on-premise and cloud services. Strong planning skills and knowledge of ITIL processes and best practice. This is an excellent opportunity to join a highly regarded global organisation where you'll play a key role in strengthening cybersecurity across a complex international IT environment, combining hands-on security engineering, incident response and strategic infrastructure projects.
Aug 24, 2026
Full time
IT Cyber Security Specialist / Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team, supporting and continually improving cybersecurity across a global IT environment. Reporting to the Infrastructure Engineering Manager, you'll take ownership of cybersecurity controls and security architecture while working closely with Infrastructure Operations and other technology teams to identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across a complex infrastructure environment, identifying and mitigating security risks, supporting major cyber incidents and contributing to strategic security and infrastructure projects. You'll also help develop security awareness, business continuity capabilities and ongoing improvements to the firm's security controls. Key Responsibilities: Continuously review and improve the firm's cybersecurity posture from an infrastructure perspective and external security rating. Identify, assess and remediate vulnerabilities across hardware, software and infrastructure (Windows Server and Azure Cloud). Monitor emerging threats and lead or support Incident Response investigations and mitigation. Evaluate, test and recommend security enhancements, controls and threat prevention technologies. Identify security risks and exposures and develop measures to prevent future incidents. Lead CE+ accreditation and support security, risk and data protection requirements from a technical (Not GRC) perspective. Participate in and lead infrastructure lifecycle, security and technology projects. Provide 3rd Line / Major Incident support as a cybersecurity subject matter expert. Work with third-party suppliers and advise internal technical teams on security measures to resolve security and infrastructure issues. We're looking for experienced Cyber Security engineer with strong technical infrastructure knowledge and proven experience across incident response, threat monitoring and vulnerability management. You will possess: Extensive experience in a similar role blending Cyber Security with core Wintel Infrastructure and Azure cloud engineering. Strong knowledge of modern security architecture, threat prevention techniques and incident response. Strong Windows Server 2016/2019/2022 knowledge including Active Directory, DNS, DHCP, Intune, Group Policy, PKI, Entra and Azure SSO. Demonstrable experience across Cyber Security, Incident Response, Threat Monitoring and Vulnerability Management using tools such as MS Sentinel, MS Defender etc for threat hunting, vulnerability monitoring and security posture improvement. CISSP, CEH, CCNA Security, SC-100, SC200 or equivalent security certification. Experience designing, integrating and managing complex infrastructure and cloud solutions from a cyber security standpoint and advising technical infrastructure teams on security focussed designs and operations Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. Experience working with third-party providers across on-premise and cloud services. Strong planning skills and knowledge of ITIL processes and best practice. This is an excellent opportunity to join a highly regarded global organisation where you'll play a key role in strengthening cybersecurity across a complex international IT environment, combining hands-on security engineering, incident response and strategic infrastructure projects.
This position is being advertised by Alfa AI on behalf of Five Guys. Five Guys is hiring a senior cybersecurity leader to own cybersecurity across its European operations, reporting to the IT Director. This is a greenfield, hands-on role: you will define the cybersecurity strategy and roadmap, establish governance and risk reporting, create core policies and standards, and personally get involved in tooling, configuration, incident response and problem-solving where required. You will be responsible for improving security across Microsoft 365, Azure, endpoints and identity; building incident response, business continuity and disaster recovery capability; managing GDPR, PCI-DSS and ISO 27001 initiatives; strengthening supplier security; and providing clear cyber risk reporting to senior leadership. You will work closely with IT, infrastructure, project teams, operational stakeholders and external suppliers in a lean environment without a large internal security team. We are looking for someone who has built or significantly matured a cybersecurity function in a scaling or greenfield environment and can combine strategy with hands-on technical execution. You should be comfortable influencing senior stakeholders, prioritising risk, creating practical governance from scratch and operating independently. Location: London, with occasional UK and European travel.
Aug 24, 2026
Full time
This position is being advertised by Alfa AI on behalf of Five Guys. Five Guys is hiring a senior cybersecurity leader to own cybersecurity across its European operations, reporting to the IT Director. This is a greenfield, hands-on role: you will define the cybersecurity strategy and roadmap, establish governance and risk reporting, create core policies and standards, and personally get involved in tooling, configuration, incident response and problem-solving where required. You will be responsible for improving security across Microsoft 365, Azure, endpoints and identity; building incident response, business continuity and disaster recovery capability; managing GDPR, PCI-DSS and ISO 27001 initiatives; strengthening supplier security; and providing clear cyber risk reporting to senior leadership. You will work closely with IT, infrastructure, project teams, operational stakeholders and external suppliers in a lean environment without a large internal security team. We are looking for someone who has built or significantly matured a cybersecurity function in a scaling or greenfield environment and can combine strategy with hands-on technical execution. You should be comfortable influencing senior stakeholders, prioritising risk, creating practical governance from scratch and operating independently. Location: London, with occasional UK and European travel.
Howden Group Holdings in London is seeking a senior cyber claims leader to drive international strategy across non-UK/US markets, ensuring consistent incident response and client support. You will lead major incidents, develop best practices, build local capability, mentor teams, and partner with underwriting and wordings specialists to deliver coordinated global solutions. The role offers exposure to global projects, tender work, industry events, and ongoing education to advance Howden's cyber
Aug 24, 2026
Full time
Howden Group Holdings in London is seeking a senior cyber claims leader to drive international strategy across non-UK/US markets, ensuring consistent incident response and client support. You will lead major incidents, develop best practices, build local capability, mentor teams, and partner with underwriting and wordings specialists to deliver coordinated global solutions. The role offers exposure to global projects, tender work, industry events, and ongoing education to advance Howden's cyber
Who are we? Howden is a global insurance group with employee ownership at its heart. Together, we have pushed the boundaries of insurance. We are united by a shared passion and no-limits mindset, and our strength lies in our ability to collaborate as a powerful international team comprised of 24,000 employees spanning over 56 countries. People join Howden for many different reasons, but they stay for the same one: our culture. It's what sets us apart, and the reason our employees have been turning down headhunters for years. Whatever your priorities - work / life balance, career progression, sustainability, volunteering - you'll find like-minded people driving change at Howden. The Role This role leads the cyber claims function across Howden's international offices (outside the UK and US), supporting Howden's global cyber team. It is accountable for developing and implementing cyber claims strategy, best practice and capability across those offices, ensuring a consistent and effective approach to service delivery, incident response and client support. What you'll do Lead the development and implementation of international cyber claims strategy across jurisdictions outside the UK and US Act as the claims lead on major cyber incidents and cyber / technology insurance claims where required, acting as a referral point to support and supplement local expertise Establish and embed best practice approaches to cyber claims handling, both initial response and coverage, across global offices Build and oversee local cyber claims capability in key international markets to ensure consistency of service provision and standards, including supporting recruitment and development Provide technical guidance and act as a referral point to support and enhance local expertise, including delivering education and training to clients and colleagues Support colleagues on business tenders and represent the cyber claims function at industry events, presenting on technical and market topics internationally Respond to technical and claims-related queries from clients, markets and internal stakeholders Lead cyber claims data initiatives, working closely with data and analytics teams to improve insight and outcomes Contribute as a senior member of the global cyber team, supporting wider strategic and operating plans Collaborate with wordings specialists and UK and US cyber claims leads to ensure a coordinated global approach Who we're looking for Significant experience in cyber insurance claims, financial lines insurance claims, or cyber incident response within an international environment Proven experience developing and implementing claims strategy or best practice frameworks Experience supporting or overseeing cyber insurance claims, incident response or crisis management activity Demonstrated experience advising clients and internal stakeholders on complex insurance coverage and claims issues Experience working with global teams and navigating differing regulatory or market environments Track record of contributing to business development activity, including tenders and client presentations Experience working with data initiatives or using claims data to drive decision-making and improvement Experience collaborating with underwriting, wordings or specialist teams to deliver joined-up solutions What do we offer in return? A career that you define. At Howden, we value diversity - there is no one Howden type. Instead, we're looking for individuals who share the same values as us: Our successes have all come from someone brave enough to try something new We support each other in the small everyday moments and the bigger challenges We are determined to make a positive difference at work and beyond Reasonable adjustments We're committed to providing reasonable accommodations at Howden to ensure that our positions align well with your needs. Besides the usual adjustments such as software, IT, and office setups, we can also accommodate other changes such as flexible hours or hybrid working . Not all positions can accommodate changes to working hours or locations. Permanent Howden began in 1994, as just three people and a dog. Now there are 23,000 of us, and we're a leading global insurance group, managing $37bn of premiums for our clients. Our largest shareholder group is us - the people who work in the business - supported by three long-term, minority growth-equity partners who share our vision to build a business to last, one that will never be sold. The owner's mindset is something that's embedded in our culture; our people readily take ownership of their decisions, their actions, and their outputs. They're invested in every sense. And we all know that by working together to drive the business forward, everyone will benefit from the extraordinary results we can achieve.
Aug 24, 2026
Full time
Who are we? Howden is a global insurance group with employee ownership at its heart. Together, we have pushed the boundaries of insurance. We are united by a shared passion and no-limits mindset, and our strength lies in our ability to collaborate as a powerful international team comprised of 24,000 employees spanning over 56 countries. People join Howden for many different reasons, but they stay for the same one: our culture. It's what sets us apart, and the reason our employees have been turning down headhunters for years. Whatever your priorities - work / life balance, career progression, sustainability, volunteering - you'll find like-minded people driving change at Howden. The Role This role leads the cyber claims function across Howden's international offices (outside the UK and US), supporting Howden's global cyber team. It is accountable for developing and implementing cyber claims strategy, best practice and capability across those offices, ensuring a consistent and effective approach to service delivery, incident response and client support. What you'll do Lead the development and implementation of international cyber claims strategy across jurisdictions outside the UK and US Act as the claims lead on major cyber incidents and cyber / technology insurance claims where required, acting as a referral point to support and supplement local expertise Establish and embed best practice approaches to cyber claims handling, both initial response and coverage, across global offices Build and oversee local cyber claims capability in key international markets to ensure consistency of service provision and standards, including supporting recruitment and development Provide technical guidance and act as a referral point to support and enhance local expertise, including delivering education and training to clients and colleagues Support colleagues on business tenders and represent the cyber claims function at industry events, presenting on technical and market topics internationally Respond to technical and claims-related queries from clients, markets and internal stakeholders Lead cyber claims data initiatives, working closely with data and analytics teams to improve insight and outcomes Contribute as a senior member of the global cyber team, supporting wider strategic and operating plans Collaborate with wordings specialists and UK and US cyber claims leads to ensure a coordinated global approach Who we're looking for Significant experience in cyber insurance claims, financial lines insurance claims, or cyber incident response within an international environment Proven experience developing and implementing claims strategy or best practice frameworks Experience supporting or overseeing cyber insurance claims, incident response or crisis management activity Demonstrated experience advising clients and internal stakeholders on complex insurance coverage and claims issues Experience working with global teams and navigating differing regulatory or market environments Track record of contributing to business development activity, including tenders and client presentations Experience working with data initiatives or using claims data to drive decision-making and improvement Experience collaborating with underwriting, wordings or specialist teams to deliver joined-up solutions What do we offer in return? A career that you define. At Howden, we value diversity - there is no one Howden type. Instead, we're looking for individuals who share the same values as us: Our successes have all come from someone brave enough to try something new We support each other in the small everyday moments and the bigger challenges We are determined to make a positive difference at work and beyond Reasonable adjustments We're committed to providing reasonable accommodations at Howden to ensure that our positions align well with your needs. Besides the usual adjustments such as software, IT, and office setups, we can also accommodate other changes such as flexible hours or hybrid working . Not all positions can accommodate changes to working hours or locations. Permanent Howden began in 1994, as just three people and a dog. Now there are 23,000 of us, and we're a leading global insurance group, managing $37bn of premiums for our clients. Our largest shareholder group is us - the people who work in the business - supported by three long-term, minority growth-equity partners who share our vision to build a business to last, one that will never be sold. The owner's mindset is something that's embedded in our culture; our people readily take ownership of their decisions, their actions, and their outputs. They're invested in every sense. And we all know that by working together to drive the business forward, everyone will benefit from the extraordinary results we can achieve.
Senior Solutions Architect - Email & Collaboration Security - London UK Why This Role Exists The Email & Collaboration Security (ECS) product line sits at the intersection of some of the most consequential challenges in enterprise security today: AI-augmented threats, sprawling collaboration surfaces, multi-cloud delivery complexity, and the expectation that detection and response capabilities keep pace with a threat landscape that does not wait. This architecture is not greenfield. It carries two decades of accumulated product decisions, integration contracts, and operational constraints. The right candidate understands why that history matters before proposing how to move beyond it. Reasoning about legacy shape and evolutionary trajectory simultaneously is not optional; it is the job. The successful candidate will serve as connective tissue across product management, engineering, and the broader Architecture Leadership Team - turning customer and business problems into coherent, deliverable technical direction, and owning the decisions that give ECS engineering teams a stable foundation to move fast with quality. AI-First Ways of Working Mimecast is an AI-first engineering organisation. This is not a cultural aspiration - it is an operating expectation. The person in this role is expected to use AI tools as a genuine, daily part of how they work: for design exploration and iteration, documentation, analysis, prototyping, and research synthesis. This means having a real, practised opinion on where AI tooling accelerates quality decisions and where it introduces risk. It also means designing systems that incorporate AI components thoughtfully: understanding the implications of LLM integration, agent boundaries, prompt and data-contract stability, and evaluation coverage for AI-driven features. Candidates who treat AI tooling as optional or experimental are not the right fit for this role. The expectation is fluency and daily practice, not passing familiarity. The ECS Domain ECS covers the following product and capability areas: Email threat detection and prevention Email security efficacy Collaboration security DMARC analyzer Data platform and observability Analysis and Response End user application integration Internal operations enablement What You Will Do Lead from Problem Space, Not Solution Space The role engages at the problem-framing stage, not after requirements have already hardened into tickets. This means facilitating workshops with PMs, UX, and engineers to surface real customer constraints and articulate what good looks like in business and user terms before any technical shape is proposed. Own Integration Contracts as Product Artefacts The durable interfaces - APIs, event contracts, data schemas - that connect ECS capabilities to the broader Mimecast platform are first-class artefacts owned by this role. They outlast individual features, and the coordination work that makes integrations actually land across teams and time is part of the remit. Build the Architectural Context Engineering Teams Operate Inside ADRs, service interaction patterns, NFR targets, and data contracts are not documentation - they are the substrate that lets engineering teams and AI-assisted development workflows make consistent decisions at scale. The artefacts produced in this role are clear, reasoned, and durable. Govern Without Blocking Governance is a mechanism for alignment and acceleration, not gatekeeping. Structure and discipline are introduced where they reduce risk or improve quality - and removed where ceremony adds cost without value. The role engages the Chief Architect early, pushes back constructively when platform standards do not fit the ECS context, and helps teams close decisions with conviction rather than endless review. Reason About Cost and Unit Economics Infrastructure choices are sized, cost trajectories modelled for new architecture work, and unexpected spend is flagged with a proposed remediation. The frame is cost per outcome - per protected mailbox, per remediated incident - not just monthly AWS spend. Communicate at Every Altitude A one-page decision record that lands with engineers, a solution brief that holds up under senior architecture review, a strategy narrative that resonates with product and commercial leadership - this role operates across all of those registers. Whiteboard sessions produce actual decisions, not just richer ambiguity. What You Will Bring 10+ years building and operating production SaaS systems, with at least 3 years in a Senior Architect or equivalent role carrying product-shaping responsibility. A genuinely broad architectural lens - thinking about system shape, data flows, and organisational constraints rather than reaching for the nearest deep technical rabbit hole. Comfort operating across cloud-native patterns (AWS, Kafka, managed services, distributed event architectures) at high throughput - able to reason about trade-offs with confidence, without needing to be the most technically specialist person in the room. Product Understanding - Not Just Technical Understanding prior close collaboration with Product Managers and UX designers, with an understanding of jobs-to-be-done framing and a real opinion on what makes a product bet good - not just a technical bet. Genuine customer orientation: asking what problem the customer has before asking how to build the feature. Understanding of SaaS unit economics, the commercial implications of architectural choices, and how to reason about scale from a product perspective as well as a systems one. The Right Mindset for Complex, Inherited Systems An understanding of what twenty years of software history means in a production system - no assumption of greenfield, and no treatment of legacy as only debt; it is accumulated context. Structure and discipline as cognitive defaults, not imposed processes - thorough, well-reasoned artefacts, and a habit of leaving things clearer than they were found. An ability to connect dots across a large picture with many moving parts, make a call, and communicate it clearly - rather than waiting for certainty that will not arrive. Self-Direction and Strategic Initiative A proactive self-starter who identifies the right problems to work on without being told, and drives them to resolution. Comfortable acting independently within a set of principles, while keeping the right stakeholders informed and in sync - not seeking permission, but maintaining alignment. Thrives with ambiguity and treats it as a problem to be structured, not a reason to pause. Learning Orientation - Not Encyclopaedic Knowledge Able to reach a solution even without all the knowledge in front of them - a problem-solver who knows how to navigate to an answer, not a mnemonic database. AI tooling treated as a core capability multiplier, with a real daily practice in design work, documentation, research synthesis, and prototyping. Stays ahead of where the market and the technology are going, and brings that signal back into product and architecture decisions. Bonus Points Background in email security, threat detection, DLP, identity, or data platforms. Familiarity with agentic AI, MCP (Model Context Protocol), or LLM application architecture. Experience with eval design for AI features, product discovery practices, or data contract / data mesh approaches. Exposure to M365 or GWS integration patterns, SMTP relay architecture, or cloud-native security SaaS. What We Offer Impact: architecture decisions that protect millions of mailboxes and shape the technical direction of one of Mimecast's core product pillars. Voice: a direct working relationship with the Chief Architect and a genuine say in technology direction - not an advisory lane. Senior peers: a small, high-trust Architecture Leadership Team where everyone operates at a high level. Qualifications Bachelor's degree in Computer Science, Software Engineering, or a related field - or equivalent demonstrable experience. 10+ years of professional software engineering and architecture experience, with at least 3 years in a senior architecture or principal engineering role. A track record of product-shaping responsibility, not just technical delivery. Active, daily use of AI development tools in a professional setting - not experimentation, practice. Equal Opportunity Statement Mimecast is an equal opportunity employer committed to an inclusive and diverse workplace. Commitment to Diversity and Inclusion We're proud to be an Equal Opportunity and Aff We particularly welcome applicants from traditionally underrepresented groups. We consider everyone equally: your race, age, religion, sexual orientation, gender identity, ability, marital status, nationality, or any other protected characteristic won't affect your application. Due to certain obligations to our customers, an offer of employment will be subject to your successful completion of applicable background checks, conducted in accordance with local law. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. We save companies the embarrassment of awkward data slip ups by disrupting cybercriminal activity. We think fast, go big and always demand more. We work hard, deliver - and repeat. We grow with meaningful determination. And put success well within our reach. We empower each other, live by our values, and always deliver on our purpose . click apply for full job details
Aug 24, 2026
Full time
Senior Solutions Architect - Email & Collaboration Security - London UK Why This Role Exists The Email & Collaboration Security (ECS) product line sits at the intersection of some of the most consequential challenges in enterprise security today: AI-augmented threats, sprawling collaboration surfaces, multi-cloud delivery complexity, and the expectation that detection and response capabilities keep pace with a threat landscape that does not wait. This architecture is not greenfield. It carries two decades of accumulated product decisions, integration contracts, and operational constraints. The right candidate understands why that history matters before proposing how to move beyond it. Reasoning about legacy shape and evolutionary trajectory simultaneously is not optional; it is the job. The successful candidate will serve as connective tissue across product management, engineering, and the broader Architecture Leadership Team - turning customer and business problems into coherent, deliverable technical direction, and owning the decisions that give ECS engineering teams a stable foundation to move fast with quality. AI-First Ways of Working Mimecast is an AI-first engineering organisation. This is not a cultural aspiration - it is an operating expectation. The person in this role is expected to use AI tools as a genuine, daily part of how they work: for design exploration and iteration, documentation, analysis, prototyping, and research synthesis. This means having a real, practised opinion on where AI tooling accelerates quality decisions and where it introduces risk. It also means designing systems that incorporate AI components thoughtfully: understanding the implications of LLM integration, agent boundaries, prompt and data-contract stability, and evaluation coverage for AI-driven features. Candidates who treat AI tooling as optional or experimental are not the right fit for this role. The expectation is fluency and daily practice, not passing familiarity. The ECS Domain ECS covers the following product and capability areas: Email threat detection and prevention Email security efficacy Collaboration security DMARC analyzer Data platform and observability Analysis and Response End user application integration Internal operations enablement What You Will Do Lead from Problem Space, Not Solution Space The role engages at the problem-framing stage, not after requirements have already hardened into tickets. This means facilitating workshops with PMs, UX, and engineers to surface real customer constraints and articulate what good looks like in business and user terms before any technical shape is proposed. Own Integration Contracts as Product Artefacts The durable interfaces - APIs, event contracts, data schemas - that connect ECS capabilities to the broader Mimecast platform are first-class artefacts owned by this role. They outlast individual features, and the coordination work that makes integrations actually land across teams and time is part of the remit. Build the Architectural Context Engineering Teams Operate Inside ADRs, service interaction patterns, NFR targets, and data contracts are not documentation - they are the substrate that lets engineering teams and AI-assisted development workflows make consistent decisions at scale. The artefacts produced in this role are clear, reasoned, and durable. Govern Without Blocking Governance is a mechanism for alignment and acceleration, not gatekeeping. Structure and discipline are introduced where they reduce risk or improve quality - and removed where ceremony adds cost without value. The role engages the Chief Architect early, pushes back constructively when platform standards do not fit the ECS context, and helps teams close decisions with conviction rather than endless review. Reason About Cost and Unit Economics Infrastructure choices are sized, cost trajectories modelled for new architecture work, and unexpected spend is flagged with a proposed remediation. The frame is cost per outcome - per protected mailbox, per remediated incident - not just monthly AWS spend. Communicate at Every Altitude A one-page decision record that lands with engineers, a solution brief that holds up under senior architecture review, a strategy narrative that resonates with product and commercial leadership - this role operates across all of those registers. Whiteboard sessions produce actual decisions, not just richer ambiguity. What You Will Bring 10+ years building and operating production SaaS systems, with at least 3 years in a Senior Architect or equivalent role carrying product-shaping responsibility. A genuinely broad architectural lens - thinking about system shape, data flows, and organisational constraints rather than reaching for the nearest deep technical rabbit hole. Comfort operating across cloud-native patterns (AWS, Kafka, managed services, distributed event architectures) at high throughput - able to reason about trade-offs with confidence, without needing to be the most technically specialist person in the room. Product Understanding - Not Just Technical Understanding prior close collaboration with Product Managers and UX designers, with an understanding of jobs-to-be-done framing and a real opinion on what makes a product bet good - not just a technical bet. Genuine customer orientation: asking what problem the customer has before asking how to build the feature. Understanding of SaaS unit economics, the commercial implications of architectural choices, and how to reason about scale from a product perspective as well as a systems one. The Right Mindset for Complex, Inherited Systems An understanding of what twenty years of software history means in a production system - no assumption of greenfield, and no treatment of legacy as only debt; it is accumulated context. Structure and discipline as cognitive defaults, not imposed processes - thorough, well-reasoned artefacts, and a habit of leaving things clearer than they were found. An ability to connect dots across a large picture with many moving parts, make a call, and communicate it clearly - rather than waiting for certainty that will not arrive. Self-Direction and Strategic Initiative A proactive self-starter who identifies the right problems to work on without being told, and drives them to resolution. Comfortable acting independently within a set of principles, while keeping the right stakeholders informed and in sync - not seeking permission, but maintaining alignment. Thrives with ambiguity and treats it as a problem to be structured, not a reason to pause. Learning Orientation - Not Encyclopaedic Knowledge Able to reach a solution even without all the knowledge in front of them - a problem-solver who knows how to navigate to an answer, not a mnemonic database. AI tooling treated as a core capability multiplier, with a real daily practice in design work, documentation, research synthesis, and prototyping. Stays ahead of where the market and the technology are going, and brings that signal back into product and architecture decisions. Bonus Points Background in email security, threat detection, DLP, identity, or data platforms. Familiarity with agentic AI, MCP (Model Context Protocol), or LLM application architecture. Experience with eval design for AI features, product discovery practices, or data contract / data mesh approaches. Exposure to M365 or GWS integration patterns, SMTP relay architecture, or cloud-native security SaaS. What We Offer Impact: architecture decisions that protect millions of mailboxes and shape the technical direction of one of Mimecast's core product pillars. Voice: a direct working relationship with the Chief Architect and a genuine say in technology direction - not an advisory lane. Senior peers: a small, high-trust Architecture Leadership Team where everyone operates at a high level. Qualifications Bachelor's degree in Computer Science, Software Engineering, or a related field - or equivalent demonstrable experience. 10+ years of professional software engineering and architecture experience, with at least 3 years in a senior architecture or principal engineering role. A track record of product-shaping responsibility, not just technical delivery. Active, daily use of AI development tools in a professional setting - not experimentation, practice. Equal Opportunity Statement Mimecast is an equal opportunity employer committed to an inclusive and diverse workplace. Commitment to Diversity and Inclusion We're proud to be an Equal Opportunity and Aff We particularly welcome applicants from traditionally underrepresented groups. We consider everyone equally: your race, age, religion, sexual orientation, gender identity, ability, marital status, nationality, or any other protected characteristic won't affect your application. Due to certain obligations to our customers, an offer of employment will be subject to your successful completion of applicable background checks, conducted in accordance with local law. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. We save companies the embarrassment of awkward data slip ups by disrupting cybercriminal activity. We think fast, go big and always demand more. We work hard, deliver - and repeat. We grow with meaningful determination. And put success well within our reach. We empower each other, live by our values, and always deliver on our purpose . click apply for full job details
Ready to Own More Than the Ticket Queue? You've built solid 3rd Line infrastructure experience. You know how to get to the bottom of complex technical problems, understand the importance of security and you're ready for more ownership. This could be that step. Join Bulk , one of Europe's leading active nutrition brands, and take ownership across the infrastructure and cyber security environment supporting our fast-moving digital business. You'll work across cloud, networks, endpoints and security, strengthen our email security, help lead our upcoming Cyber Essentials project and tackle the security challenges that come with our rapidly evolving use of AI. We're ahead of the curve when it comes to building with AI, so you'll get extensive exposure to new tools, integrations and systems - with the freedom to get involved in other technical projects as the business evolves. If you're a strong 3rd Line Engineer with cyber security credentials who's ready to broaden your remit and take genuine ownership, we'd love to hear from you. The Role at a Glance IT Infrastructure & Cyber Security Engineer Colchester, Essex Hybrid - 3 Days Office / 2 Days Home Occasional out-of-hours working and travel to London will be required. Competitive Salary + Excellent Benefits Full Time Permanent Focus: Infrastructure Cyber Security Cloud AI Enablement Your Background / Skills: 3rd Line Engineering, IT Infrastructure, Cyber Security, Azure, Google Workspace, Networking, CrowdStrike, Cisco, VMware vSphere, Windows Server, Jamf, Intune, Incident Response, Cyber Essentials, AI Tooling Who We Are Bulk is on an incredible journey, with a mission to evolve from a manufacturing-led retailer into a destination brand for active nutrition. We're shaking up the sports nutrition industry through innovative products, disruptive marketing and bold digital thinking that encourages people to see our brand differently. We want passionate risk-takers. People who challenge our thinking, live and breathe digital and aren't afraid to find a better way of doing things. And as our technology continues to evolve - particularly through AI - we need the infrastructure and security behind it to evolve just as quickly. The Opportunity As our IT Infrastructure & Cyber Security Engineer, you'll take ownership of Bulk's infrastructure and cyber security environment, supported by our IT Service Desk Team Lead and wider team. This is a broad, hands-on technical role with some clear priorities. You'll help upgrade our email security, manage the security aspects of AI integration and take a leading role in our Cyber Essentials project next year. You'll also oversee infrastructure, security tooling, incident response, budgeting and contracting, while becoming a Tier 3 escalation point for complex issues that need deeper technical expertise. And we're not expecting you to walk through the door knowing every technology on our list. We're looking for someone with strong infrastructure foundations and genuine cyber security capability who can demonstrate experience across roughly 80% of our technical environment, with the curiosity and ability to pick up the rest. What You'll Be Doing Infrastructure • Manage and maintain Bulk s on-premise and cloud infrastructure, including Azure, Google Workspace, networks, firewalls and VPNs. • Ensure systems are secure, reliable, resilient and up to date. • Lead infrastructure projects from planning through to deployment, including budgets and contracts. • Provide Tier 3 support for complex issues and maintain clear technical documentation and handovers. • Support wider technical projects as business requirements evolve. Cyber Security • Develop and improve Bulk s security environment, with particular focus on email security. • Monitor, investigate and respond to security threats, incidents and data breaches. • Manage and optimise security technologies including SIEM, SOAR, EDR/MDR/XDR, CASB, ZTNA and SASE. • Lead Cyber Essentials activity and support wider compliance, including ISO 27001. • Assess vendor security and work with stakeholders to implement secure technology solutions. AI Tooling & Security • Support the secure adoption and scaling of AI tools across Bulk. • Manage AI platforms including Claude Code, GitHub Copilot, Codex-style tools, MCP servers, integrations and connectors. • Own user access, permissions and governance, applying least-privilege principles. • Support teams onboarding new AI technologies, balancing innovation and productivity with security and compliance. • Develop appropriate controls as agentic AI, MCP and connector-based technologies evolve. About You You're probably already operating at strong 3rd Line Engineer level and looking for the opportunity to take broader ownership across infrastructure and cyber security. You enjoy getting hands-on with technology, but you're also interested in the bigger picture - resilience, security, risk, projects and how technology can enable the business to move faster. You don't need to tick every technology box. Breadth, strong foundations and the ability to learn matter here. You'll likely bring: • Around 2-3 years' experience in a similar role, operating at 3rd Line Engineer level or equivalent. • At least one cyber security certification. • Hands-on experience across approximately 80% of the technologies and environments outlined within this advert. • Strong infrastructure experience spanning cloud and on-premise environments. • Good working knowledge of Azure, Google Workspace, networking, endpoint management and security. • Experience across technologies such as CrowdStrike, Cisco, VMware vSphere, Windows Server, Mac/Windows, Jamf, Intune, Automox and VPNs. • Strong security monitoring, incident response and threat-analysis knowledge, including IOC investigation and remediation. • Experience or knowledge of security frameworks and compliance, ideally including Cyber Essentials and ISO 27001. • The confidence and technical capability to handle complex Tier 3 escalations. • Strong problem-solving skills and a proactive approach to improving infrastructure and security. • Excellent communication skills and the confidence to work with colleagues, suppliers and senior leadership. • Willingness to undertake occasional out-of-hours work and travel to London. Even Better If You Bring • Hands-on experience administering AI coding or agent tools, including Claude Code, GitHub Copilot or Codex. • Experience configuring MCP servers, connectors, permissions and access controls. • Familiarity with emerging agentic AI infrastructure and its associated security considerations. • Experience working with Netskope. • Hands-on Netskope CASB/SSE experience covering areas such as SSL/TLS inspection, DLP, Zero Trust architecture, CASB policy design and SCIM-based provisioning. • ITIL or project management certification such as PRINCE2. • Additional cyber security certifications such as CISSP, CISM or CompTIA. Why Join Bulk ? This is a great opportunity if you're ready to move beyond traditional 3rd Line support and build broader experience across infrastructure, cyber security and AI. You'll have genuine ownership, support from the wider IT team and exposure to a broad technology landscape within a business that's actively embracing new ways of working. Because Bulk is already pushing ahead with AI, you'll also be solving security and infrastructure challenges that many businesses haven't encountered yet. You'll also enjoy: • Monthly Bulk Bank Benefits Allowance, including subsidised gym membership. • 60% discount on Bulk products. • Birthday day off. • PerkBox subscription. • Flexi Start. • Optional additional annual leave. • Teammate pension scheme. • Life Assurance. • Medicash. • Volunteering day. • Cycle to Work Scheme. • Enhanced maternity and paternity leave. • Workplace nursery scheme. • Fully stocked Bulk Pantry. • Happy Hour drinks fridge on Thursdays and Fridays. • Summer working hours. • Hybrid working - 3 days in the Colchester office / 2 days from home. Your Experience / Background / Previous Roles May Include 3rd Line Engineer, Senior 3rd Line Engineer, Infrastructure Engineer, IT Infrastructure Engineer, Infrastructure & Security Engineer, IT Security Engineer, Systems & Security Engineer, Senior IT Engineer, Cloud Infrastructure Engineer, Cyber Security Engineer or Infrastructure Support Engineer. Apply Now If you've built strong 3rd Line foundations and you're ready for a role where you can take genuine ownership across infrastructure, cyber security and emerging AI technology, we'd love to hear from you. Bring your technical breadth, security mindset and curiosity about what's coming next - and help build the resilient, secure technology foundation behind Bulk's continued growth. Bulk is an equal opportunities employer and is committed to building a diverse and inclusive team. We welcome applications regardless of age, disability, race, gender, religion, sexual orientation, education, neurodiversity or any other protected characteristic. Application notice We take your privacy seriously . click apply for full job details
Aug 24, 2026
Full time
Ready to Own More Than the Ticket Queue? You've built solid 3rd Line infrastructure experience. You know how to get to the bottom of complex technical problems, understand the importance of security and you're ready for more ownership. This could be that step. Join Bulk , one of Europe's leading active nutrition brands, and take ownership across the infrastructure and cyber security environment supporting our fast-moving digital business. You'll work across cloud, networks, endpoints and security, strengthen our email security, help lead our upcoming Cyber Essentials project and tackle the security challenges that come with our rapidly evolving use of AI. We're ahead of the curve when it comes to building with AI, so you'll get extensive exposure to new tools, integrations and systems - with the freedom to get involved in other technical projects as the business evolves. If you're a strong 3rd Line Engineer with cyber security credentials who's ready to broaden your remit and take genuine ownership, we'd love to hear from you. The Role at a Glance IT Infrastructure & Cyber Security Engineer Colchester, Essex Hybrid - 3 Days Office / 2 Days Home Occasional out-of-hours working and travel to London will be required. Competitive Salary + Excellent Benefits Full Time Permanent Focus: Infrastructure Cyber Security Cloud AI Enablement Your Background / Skills: 3rd Line Engineering, IT Infrastructure, Cyber Security, Azure, Google Workspace, Networking, CrowdStrike, Cisco, VMware vSphere, Windows Server, Jamf, Intune, Incident Response, Cyber Essentials, AI Tooling Who We Are Bulk is on an incredible journey, with a mission to evolve from a manufacturing-led retailer into a destination brand for active nutrition. We're shaking up the sports nutrition industry through innovative products, disruptive marketing and bold digital thinking that encourages people to see our brand differently. We want passionate risk-takers. People who challenge our thinking, live and breathe digital and aren't afraid to find a better way of doing things. And as our technology continues to evolve - particularly through AI - we need the infrastructure and security behind it to evolve just as quickly. The Opportunity As our IT Infrastructure & Cyber Security Engineer, you'll take ownership of Bulk's infrastructure and cyber security environment, supported by our IT Service Desk Team Lead and wider team. This is a broad, hands-on technical role with some clear priorities. You'll help upgrade our email security, manage the security aspects of AI integration and take a leading role in our Cyber Essentials project next year. You'll also oversee infrastructure, security tooling, incident response, budgeting and contracting, while becoming a Tier 3 escalation point for complex issues that need deeper technical expertise. And we're not expecting you to walk through the door knowing every technology on our list. We're looking for someone with strong infrastructure foundations and genuine cyber security capability who can demonstrate experience across roughly 80% of our technical environment, with the curiosity and ability to pick up the rest. What You'll Be Doing Infrastructure • Manage and maintain Bulk s on-premise and cloud infrastructure, including Azure, Google Workspace, networks, firewalls and VPNs. • Ensure systems are secure, reliable, resilient and up to date. • Lead infrastructure projects from planning through to deployment, including budgets and contracts. • Provide Tier 3 support for complex issues and maintain clear technical documentation and handovers. • Support wider technical projects as business requirements evolve. Cyber Security • Develop and improve Bulk s security environment, with particular focus on email security. • Monitor, investigate and respond to security threats, incidents and data breaches. • Manage and optimise security technologies including SIEM, SOAR, EDR/MDR/XDR, CASB, ZTNA and SASE. • Lead Cyber Essentials activity and support wider compliance, including ISO 27001. • Assess vendor security and work with stakeholders to implement secure technology solutions. AI Tooling & Security • Support the secure adoption and scaling of AI tools across Bulk. • Manage AI platforms including Claude Code, GitHub Copilot, Codex-style tools, MCP servers, integrations and connectors. • Own user access, permissions and governance, applying least-privilege principles. • Support teams onboarding new AI technologies, balancing innovation and productivity with security and compliance. • Develop appropriate controls as agentic AI, MCP and connector-based technologies evolve. About You You're probably already operating at strong 3rd Line Engineer level and looking for the opportunity to take broader ownership across infrastructure and cyber security. You enjoy getting hands-on with technology, but you're also interested in the bigger picture - resilience, security, risk, projects and how technology can enable the business to move faster. You don't need to tick every technology box. Breadth, strong foundations and the ability to learn matter here. You'll likely bring: • Around 2-3 years' experience in a similar role, operating at 3rd Line Engineer level or equivalent. • At least one cyber security certification. • Hands-on experience across approximately 80% of the technologies and environments outlined within this advert. • Strong infrastructure experience spanning cloud and on-premise environments. • Good working knowledge of Azure, Google Workspace, networking, endpoint management and security. • Experience across technologies such as CrowdStrike, Cisco, VMware vSphere, Windows Server, Mac/Windows, Jamf, Intune, Automox and VPNs. • Strong security monitoring, incident response and threat-analysis knowledge, including IOC investigation and remediation. • Experience or knowledge of security frameworks and compliance, ideally including Cyber Essentials and ISO 27001. • The confidence and technical capability to handle complex Tier 3 escalations. • Strong problem-solving skills and a proactive approach to improving infrastructure and security. • Excellent communication skills and the confidence to work with colleagues, suppliers and senior leadership. • Willingness to undertake occasional out-of-hours work and travel to London. Even Better If You Bring • Hands-on experience administering AI coding or agent tools, including Claude Code, GitHub Copilot or Codex. • Experience configuring MCP servers, connectors, permissions and access controls. • Familiarity with emerging agentic AI infrastructure and its associated security considerations. • Experience working with Netskope. • Hands-on Netskope CASB/SSE experience covering areas such as SSL/TLS inspection, DLP, Zero Trust architecture, CASB policy design and SCIM-based provisioning. • ITIL or project management certification such as PRINCE2. • Additional cyber security certifications such as CISSP, CISM or CompTIA. Why Join Bulk ? This is a great opportunity if you're ready to move beyond traditional 3rd Line support and build broader experience across infrastructure, cyber security and AI. You'll have genuine ownership, support from the wider IT team and exposure to a broad technology landscape within a business that's actively embracing new ways of working. Because Bulk is already pushing ahead with AI, you'll also be solving security and infrastructure challenges that many businesses haven't encountered yet. You'll also enjoy: • Monthly Bulk Bank Benefits Allowance, including subsidised gym membership. • 60% discount on Bulk products. • Birthday day off. • PerkBox subscription. • Flexi Start. • Optional additional annual leave. • Teammate pension scheme. • Life Assurance. • Medicash. • Volunteering day. • Cycle to Work Scheme. • Enhanced maternity and paternity leave. • Workplace nursery scheme. • Fully stocked Bulk Pantry. • Happy Hour drinks fridge on Thursdays and Fridays. • Summer working hours. • Hybrid working - 3 days in the Colchester office / 2 days from home. Your Experience / Background / Previous Roles May Include 3rd Line Engineer, Senior 3rd Line Engineer, Infrastructure Engineer, IT Infrastructure Engineer, Infrastructure & Security Engineer, IT Security Engineer, Systems & Security Engineer, Senior IT Engineer, Cloud Infrastructure Engineer, Cyber Security Engineer or Infrastructure Support Engineer. Apply Now If you've built strong 3rd Line foundations and you're ready for a role where you can take genuine ownership across infrastructure, cyber security and emerging AI technology, we'd love to hear from you. Bring your technical breadth, security mindset and curiosity about what's coming next - and help build the resilient, secure technology foundation behind Bulk's continued growth. Bulk is an equal opportunities employer and is committed to building a diverse and inclusive team. We welcome applications regardless of age, disability, race, gender, religion, sexual orientation, education, neurodiversity or any other protected characteristic. Application notice We take your privacy seriously . click apply for full job details
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Aug 23, 2026
Full time
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Aug 23, 2026
Full time
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Senior SecOps Engineer - Microsoft Security UK Predominantly Remote Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure Sentinel Microsoft Defender / Defender XDR Strong KQL / Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps / Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Aug 23, 2026
Full time
Senior SecOps Engineer - Microsoft Security UK Predominantly Remote Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure Sentinel Microsoft Defender / Defender XDR Strong KQL / Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps / Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.