Spectrum IT Recruitment
Milton Keynes, Buckinghamshire
SOC Engineer - Cyber Security Operations Up to £45,000 We're looking for a hands-on SOC Engineer to join a highly skilled Cyber Security Operations team, supporting customers across sectors including finance, manufacturing, utilities and retail. Your work will involve helping maintain security tooling, improve visibility, support incident response and automate security operations across critical infrastructure. The Role Operate, maintain and tune security monitoring and alerting platforms. Manage and optimise log ingestion and telemetry pipelines. Work with SOC Analysts to develop detection rules, alerts and playbooks. Support security incident investigation, response and containment. Automate repetitive SOC processes using scripting and automation. Onboard new systems and infrastructure into SOC monitoring. Support internal and customer cyber security engineering requirements. Maintain accurate technical documentation and operational procedures. Work with engineering teams to embed security monitoring into new infrastructure and services. Key Skills We're looking for experience across: Security monitoring, detection and response tooling PowerShell, Python or Bash Networking fundamentals - TCP/IP, DNS, firewalls and proxies Windows and Linux systems Log collection, monitoring and telemetry SOC, NOC or other 24/7 operational environments Detection logic, alert tuning and security playbooks Hybrid infrastructure - on-premises and cloud Security frameworks or structured detection methodologies About You You'll be a reliable, technically focused SOC Engineer with: Strong troubleshooting and analytical skills A proactive approach to security operations The ability to work effectively under pressure Good communication and documentation skills Flexibility to participate in an out-of-hours on-call rota The ability to obtain Security Clearance (SC) This is an excellent opportunity to join a technically strong SOC where you'll work across security engineering, detection, automation and incident response, while gaining exposure to a diverse range of enterprise environments. Spectrum IT Recruitment (South) Limited is acting as an Employment Agency in relation to this vacancy.
Aug 24, 2026
Full time
SOC Engineer - Cyber Security Operations Up to £45,000 We're looking for a hands-on SOC Engineer to join a highly skilled Cyber Security Operations team, supporting customers across sectors including finance, manufacturing, utilities and retail. Your work will involve helping maintain security tooling, improve visibility, support incident response and automate security operations across critical infrastructure. The Role Operate, maintain and tune security monitoring and alerting platforms. Manage and optimise log ingestion and telemetry pipelines. Work with SOC Analysts to develop detection rules, alerts and playbooks. Support security incident investigation, response and containment. Automate repetitive SOC processes using scripting and automation. Onboard new systems and infrastructure into SOC monitoring. Support internal and customer cyber security engineering requirements. Maintain accurate technical documentation and operational procedures. Work with engineering teams to embed security monitoring into new infrastructure and services. Key Skills We're looking for experience across: Security monitoring, detection and response tooling PowerShell, Python or Bash Networking fundamentals - TCP/IP, DNS, firewalls and proxies Windows and Linux systems Log collection, monitoring and telemetry SOC, NOC or other 24/7 operational environments Detection logic, alert tuning and security playbooks Hybrid infrastructure - on-premises and cloud Security frameworks or structured detection methodologies About You You'll be a reliable, technically focused SOC Engineer with: Strong troubleshooting and analytical skills A proactive approach to security operations The ability to work effectively under pressure Good communication and documentation skills Flexibility to participate in an out-of-hours on-call rota The ability to obtain Security Clearance (SC) This is an excellent opportunity to join a technically strong SOC where you'll work across security engineering, detection, automation and incident response, while gaining exposure to a diverse range of enterprise environments. Spectrum IT Recruitment (South) Limited is acting as an Employment Agency in relation to this vacancy.
Senior SOC Engineer - Remote Location: Home-based - two days a month in the office (SE location) all travel paid Salary: Up to £70,000 Type: Permanent, full time Hours: Monday to Friday, 9:00am - 5:30pm - no shifts, no on-call This is a genuinely home-based role. Two days a month on site in Basingstoke, with travel and expenses covered in full. The role This is a build role, not a monitoring one. You'll be the engineer behind the SOC - designing and running the Microsoft security platform the analysts depend on. If you've spent time in a SOC wishing you could fix the tooling rather than work around it, this is that job. You'll join an established Security Operations team as new headcount, reporting to the Lead SOC Engineer. This is a managed security service provider, so you'll see a far wider range of customer environments and problems than any single in-house SOC would give you - and you'll lead the engineering side of onboarding new customers onto the platform. What you'll be doing Designing and maintaining the SIEM and XDR platform - data ingestion, log parsing and normalisation, retention, performance Writing and tuning detections in KQL, and building automation to cut manual analyst effort Scripting custom connectors and integrations across the security toolset Leading the technical onboarding of new customers alongside SOC Operations Acting as senior escalation for complex engineering issues Supporting and mentoring engineers and analysts across the team What we're looking for Around 3-5 years in a Security Operations Centre in an engineering or platform capacity Strong Microsoft Sentinel experience, with confident KQL Hands-on with Microsoft Defender and the wider Microsoft security stack - Intune, Entra ID, Defender for Endpoint Exposure to endpoint tooling such as CrowdStrike, Carbon Black or Darktrace Scripting in Python or PowerShell for automation and log analysis Some vulnerability management experience - Tenable, Rapid7, Qualys or similar Automation and orchestration exposure - Logic Apps, Cortex XSOAR or similar - is welcome but not essential Eligible for UK SC or DV security clearance - essential Experience at an MSSP, MDR provider or security reseller is a real advantage, though we're equally happy to hear from strong in-house SOC engineers. You don't need every tool on this list. Strong Sentinel and KQL with a willingness to develop the rest is enough. What's on offer Up to £65,000 depending on experience Fully home-based, with two paid trips a month to Basingstoke Genuine 9-to-5 - no shift rota, no on-call New headcount in a growing team Access to lab environments, cyber ranges and hands-on training labs Certification and training support with a clear technical progression path Exposure to enterprise security estates across multiple industries How to apply Apply through Reed with an up-to-date CV, or get in touch for a confidential conversation. Fazer Recruitment is acting as an employment agency in relation to this vacancy.
Aug 24, 2026
Full time
Senior SOC Engineer - Remote Location: Home-based - two days a month in the office (SE location) all travel paid Salary: Up to £70,000 Type: Permanent, full time Hours: Monday to Friday, 9:00am - 5:30pm - no shifts, no on-call This is a genuinely home-based role. Two days a month on site in Basingstoke, with travel and expenses covered in full. The role This is a build role, not a monitoring one. You'll be the engineer behind the SOC - designing and running the Microsoft security platform the analysts depend on. If you've spent time in a SOC wishing you could fix the tooling rather than work around it, this is that job. You'll join an established Security Operations team as new headcount, reporting to the Lead SOC Engineer. This is a managed security service provider, so you'll see a far wider range of customer environments and problems than any single in-house SOC would give you - and you'll lead the engineering side of onboarding new customers onto the platform. What you'll be doing Designing and maintaining the SIEM and XDR platform - data ingestion, log parsing and normalisation, retention, performance Writing and tuning detections in KQL, and building automation to cut manual analyst effort Scripting custom connectors and integrations across the security toolset Leading the technical onboarding of new customers alongside SOC Operations Acting as senior escalation for complex engineering issues Supporting and mentoring engineers and analysts across the team What we're looking for Around 3-5 years in a Security Operations Centre in an engineering or platform capacity Strong Microsoft Sentinel experience, with confident KQL Hands-on with Microsoft Defender and the wider Microsoft security stack - Intune, Entra ID, Defender for Endpoint Exposure to endpoint tooling such as CrowdStrike, Carbon Black or Darktrace Scripting in Python or PowerShell for automation and log analysis Some vulnerability management experience - Tenable, Rapid7, Qualys or similar Automation and orchestration exposure - Logic Apps, Cortex XSOAR or similar - is welcome but not essential Eligible for UK SC or DV security clearance - essential Experience at an MSSP, MDR provider or security reseller is a real advantage, though we're equally happy to hear from strong in-house SOC engineers. You don't need every tool on this list. Strong Sentinel and KQL with a willingness to develop the rest is enough. What's on offer Up to £65,000 depending on experience Fully home-based, with two paid trips a month to Basingstoke Genuine 9-to-5 - no shift rota, no on-call New headcount in a growing team Access to lab environments, cyber ranges and hands-on training labs Certification and training support with a clear technical progression path Exposure to enterprise security estates across multiple industries How to apply Apply through Reed with an up-to-date CV, or get in touch for a confidential conversation. Fazer Recruitment is acting as an employment agency in relation to this vacancy.
Position Summary As a SOC Shift Lead, you build on your solid experience as a SOC Analyst by supervising and guiding a team of SOC Analysts during your assigned shift. You ensure quality and consistency across all alerts and incidents handled by the team while serving as the primary point of escalation. In this role, you support team development, drive process improvements, and maintain clear, customer-centric communication with all stakeholders. You also lead quality assurance efforts and ensure that service-level agreements (SLAs) are met. Objectives & Key Results Key Responsibilities Shift Leadership and Team Coordination - You run shift operations, ensuring compliance with SLAs and maintaining high-quality incident handling. You set shift agendas, balance workloads, and promptly address any process or staffing issues. You also maintain effective, customer-centric communication with internal teams (including Security Optimisation and Engineering), customers, and their incident response partners Incident Triage and Investigation - You review and prioritise new alerts, taking initial ownership of high-priority or complex incidents, and ensure proper escalation to customers and Senior SOC Analysts. You make sound, data-driven decisions to facilitate effective triage, investigation, and escalation in line with operational standards Quality Assurance and Documentation - You conduct regular quality assurance (QA) of tickets to ensure SOC procedures and documentation standards are met, providing clear, constructive feedback to team members to improve technical skills and workflow consistency Collaboration and Mentorship - You mentor SOC Analysts in your team by offering regular, constructive feedback on triage processes and best practices. You encourage targeted training initiatives, including relevant certifications, to support career progression within the SOC Service Improvement - You contribute to ongoing service improvement through participation in supporting threat hunting activity led by Senior SOC Analysts, rule tuning, and process refinement initiatives. You assist in monthly reporting and post-incident reviews to drive improvements that reflect our commitment to transparent and reliable performance Required Qualifications & Experience You may be required to hold or obtain UK Non-Police Personnel Vetting (NPPV) and/or a Security Check (SC) clearance as part of this role Willingness to work towards or obtain intermediate cybersecurity certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst) Proficiency with SIEM platforms, endpoint security tools, and ticketing systems, with an ability to make clear, data-driven decisions under pressure Critical Competencies - Technical Fit Operating Systems - Possess detailed knowledge of Windows and Linux system architectures, with a clear understanding of how event logs (e.g., Windows Event Viewer, Syslog) reflect system security posture Networking and Protocols - Have a comprehensive understanding of TCP/IP, DNS, DCHP, VPNs, SSL/TLS, and network forensics concepts to validate network-based alerts and anomalies Cybersecurity Frameworks - Deeply understand and be able to articulate the elements of the MITRE ATT&CK framework, and Cyber Kill Chain; know how adversary tactics and techniques translate into observable indicators SIEM and Security Tools - Know the theoretical underpinnings of SIEM operations, including alert correlation, the design of automated detection rules, and the interpretation of aggregated security data Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence - how feeds are sourced, what constitutes actionable information, and how malware indicators are defined Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling Benefits At Claranet, we go the extra mile with our people-because we believe in building a workplace where everyone feels valued and supported. What makes us unique is Team Claranet , our internal community that supports causes close to our employees' hearts. We offer paid charity leave, support local charities across our offices, and host annual fundraising events, all backed by a dedicated committee. We're proud founding members of TC4RE (Technology Community for Racial Equality) working collectively to build a more diverse and inclusive tech industry. About Claranet Founded at the beginning of the dot com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries. Equal Opportunities Statement Diversity, equity and inclusion are at the heart of what we value as an organisation. Claranet is an equal opportunities employer and all qualified applicants will receive consideration for employment without regard to race, religion, sex, sexual orientation, age, disability or any other status protected by law. Our recruitment team are happy to support any reasonable adjustments that are needed within the recruitment process. Ready to take the next step in your career with Claranet? Click 'apply' - we can't wait to meet you! To view full job description please visit our careers page
Aug 24, 2026
Full time
Position Summary As a SOC Shift Lead, you build on your solid experience as a SOC Analyst by supervising and guiding a team of SOC Analysts during your assigned shift. You ensure quality and consistency across all alerts and incidents handled by the team while serving as the primary point of escalation. In this role, you support team development, drive process improvements, and maintain clear, customer-centric communication with all stakeholders. You also lead quality assurance efforts and ensure that service-level agreements (SLAs) are met. Objectives & Key Results Key Responsibilities Shift Leadership and Team Coordination - You run shift operations, ensuring compliance with SLAs and maintaining high-quality incident handling. You set shift agendas, balance workloads, and promptly address any process or staffing issues. You also maintain effective, customer-centric communication with internal teams (including Security Optimisation and Engineering), customers, and their incident response partners Incident Triage and Investigation - You review and prioritise new alerts, taking initial ownership of high-priority or complex incidents, and ensure proper escalation to customers and Senior SOC Analysts. You make sound, data-driven decisions to facilitate effective triage, investigation, and escalation in line with operational standards Quality Assurance and Documentation - You conduct regular quality assurance (QA) of tickets to ensure SOC procedures and documentation standards are met, providing clear, constructive feedback to team members to improve technical skills and workflow consistency Collaboration and Mentorship - You mentor SOC Analysts in your team by offering regular, constructive feedback on triage processes and best practices. You encourage targeted training initiatives, including relevant certifications, to support career progression within the SOC Service Improvement - You contribute to ongoing service improvement through participation in supporting threat hunting activity led by Senior SOC Analysts, rule tuning, and process refinement initiatives. You assist in monthly reporting and post-incident reviews to drive improvements that reflect our commitment to transparent and reliable performance Required Qualifications & Experience You may be required to hold or obtain UK Non-Police Personnel Vetting (NPPV) and/or a Security Check (SC) clearance as part of this role Willingness to work towards or obtain intermediate cybersecurity certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst) Proficiency with SIEM platforms, endpoint security tools, and ticketing systems, with an ability to make clear, data-driven decisions under pressure Critical Competencies - Technical Fit Operating Systems - Possess detailed knowledge of Windows and Linux system architectures, with a clear understanding of how event logs (e.g., Windows Event Viewer, Syslog) reflect system security posture Networking and Protocols - Have a comprehensive understanding of TCP/IP, DNS, DCHP, VPNs, SSL/TLS, and network forensics concepts to validate network-based alerts and anomalies Cybersecurity Frameworks - Deeply understand and be able to articulate the elements of the MITRE ATT&CK framework, and Cyber Kill Chain; know how adversary tactics and techniques translate into observable indicators SIEM and Security Tools - Know the theoretical underpinnings of SIEM operations, including alert correlation, the design of automated detection rules, and the interpretation of aggregated security data Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence - how feeds are sourced, what constitutes actionable information, and how malware indicators are defined Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling Benefits At Claranet, we go the extra mile with our people-because we believe in building a workplace where everyone feels valued and supported. What makes us unique is Team Claranet , our internal community that supports causes close to our employees' hearts. We offer paid charity leave, support local charities across our offices, and host annual fundraising events, all backed by a dedicated committee. We're proud founding members of TC4RE (Technology Community for Racial Equality) working collectively to build a more diverse and inclusive tech industry. About Claranet Founded at the beginning of the dot com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries. Equal Opportunities Statement Diversity, equity and inclusion are at the heart of what we value as an organisation. Claranet is an equal opportunities employer and all qualified applicants will receive consideration for employment without regard to race, religion, sex, sexual orientation, age, disability or any other status protected by law. Our recruitment team are happy to support any reasonable adjustments that are needed within the recruitment process. Ready to take the next step in your career with Claranet? Click 'apply' - we can't wait to meet you! To view full job description please visit our careers page
We're looking for an experienced SOC Manager to lead and develop a Security Operations capability within a high-profile public sector environment. This is a strategic leadership role, ideal for someone with a strong background in cyber security operations, incident response, and SOC service delivery. Key Responsibilities Lead and manage an established Security Operations Centre (SOC) Develop and deliver the SOC strategy and operational roadmap Oversee incident management and security monitoring capabilities Drive threat intelligence and cyber threat assessment activities Manage cyber security tools and operational technologies Build and maintain relationships with MSSPs, vendors, and technology partners Effectively plan and deploy resources to meet business objectives Essential Skills & Experience Proven experience as a SOC Manager (applications from SOC Analysts will not be considered) Strong leadership and people management experience In-depth knowledge of incident management processes Experience delivering effective security monitoring and threat intelligence capabilities Hands-on experience managing cyber security tools and technologies Experience working with external vendors and Managed Security Service Providers (MSSPs) Desirable CISSP, CISM or equivalent cyber security certification Cloud security experience (AWS and/or Azure) ITIL Foundation or equivalent Details Remote (occasional travel may be required) Up to £850/day (Umbrella) Active SC Clearance is essential - applicants must already hold valid SC clearance to be considered. If you're an experienced SC Cleared SOC Manager looking for your next contract opportunity, we'd love to hear from you.
Aug 24, 2026
Full time
We're looking for an experienced SOC Manager to lead and develop a Security Operations capability within a high-profile public sector environment. This is a strategic leadership role, ideal for someone with a strong background in cyber security operations, incident response, and SOC service delivery. Key Responsibilities Lead and manage an established Security Operations Centre (SOC) Develop and deliver the SOC strategy and operational roadmap Oversee incident management and security monitoring capabilities Drive threat intelligence and cyber threat assessment activities Manage cyber security tools and operational technologies Build and maintain relationships with MSSPs, vendors, and technology partners Effectively plan and deploy resources to meet business objectives Essential Skills & Experience Proven experience as a SOC Manager (applications from SOC Analysts will not be considered) Strong leadership and people management experience In-depth knowledge of incident management processes Experience delivering effective security monitoring and threat intelligence capabilities Hands-on experience managing cyber security tools and technologies Experience working with external vendors and Managed Security Service Providers (MSSPs) Desirable CISSP, CISM or equivalent cyber security certification Cloud security experience (AWS and/or Azure) ITIL Foundation or equivalent Details Remote (occasional travel may be required) Up to £850/day (Umbrella) Active SC Clearance is essential - applicants must already hold valid SC clearance to be considered. If you're an experienced SC Cleared SOC Manager looking for your next contract opportunity, we'd love to hear from you.
About the job Job summary Discover a career in your hands at HMRC. Whether you're seeking purpose, growth, or a workplace that gives you a true sense of belonging, hear from some of our employees as they share their story about what it's really like to work at HMRC. Visit our YouTube channel to watch the full series and come and discover your potential. Our team is rapidly growing as we invest in new technologies and capabilities, and we are in search of enthusiastic individuals who can help us in achieving our mission. We are continually improving the service we give to our customers and, in line with this, we are creating a new response and management team within the HMRC Fraud Prevention Centre. The Fraud Prevention Centre (FPC) is a strategic capability within HMRC Security, designed to safeguard customers and the organisation against identity-related fraud and emerging threats. Its mission is built on three interconnected pillars: Protection, Detection, and Response, all underpinned by advanced threat intelligence and customer support. The Centre operates across multiple functional areas, including Proactive Protection, Customer Support & Response, and Strategy & Advisory, to deliver a holistic approach to fraud prevention. Job description We're looking for a proactive and analytical professional to support HMRC's fight against identity fraud. You'll help lead data-driven investigations into suspicious activity related to identity verification and authentication services, while working with the team and partners, acting as a key contributor in a team that supports customers and provides insight into identity fraud activity and proactive searching for threats. This is an exciting opportunity to make a real difference, working in a dynamic and evolving environment. Person specification Manipulate and analyse large data sets and investigate suspicious activity. Learn, develop, and apply methods using data analytics techniques such as data mining, data matching, clustering analysis and outlier detection. Use basic scripting languages to develop visualisations and automate effective searches to build a growing analytical suite of capabilities that you can operate efficiently. Have strong communication skills and be able to demonstrate working across business and technical domains. You will have excellent interpersonal skills. Apply your knowledge of security and fraud risks to digital services. Support and deputise for the senior analysts, producing clear, insightful reports and presentations for senior stakeholders. You will be confident working in an environment that may flex its focus in response to emerging issues and have a delivery focus. You will be eager to learn and widen your experience in different areas of identity work. You will use your experience of scripting, for example SPL, Python, SQL, KQL to proactively search and discover anomalies. Be flexible and enthusiastic whilst working with some ambiguity as the team forms, grows and matures. Support senior managers in the reporting of metrics and support the wider aims of the HMRC Security Identity Team. Identify process improvement areas. Essential Criteria Knowledge of fraud detection techniques, including behavioural analysis and anomaly detection and investigation and OSINT (Open Source Intelligence) methods. Data analysis skills and experience with large data sets, with proficiency scripting complex queries in analysis environments. Solid technical understanding of web and API services (e.g. cookies, IP addresses, authentication processes) and threats to those services from cybercrime actors and tools. Experience using Security Information and Event Management (SIEM) platforms, preferably in a security operations setting. A sound understanding of Identity, Verification and Authentication principles. Desirable Criteria A degree in Data Analysis, Data Science, Information Security, Cyber Security, or other Cyber qualifications eg SANS, or at least previous experience in a relevant cyber role. Proven experience in fraud detection, cyber security, or threat intelligence within a large organisation. Active use of at least one of the following: Python, SQL, KQL, SPL. Important Additional Information The successful candidate may be required to apply for Developed Vetting (DV) clearance level once in post but must already hold or be willing to obtain Security Check (SC) clearance level before starting the role. Further Location Information Please ensure that you only apply for a location that you are willing and able to work from, as we will only make one offer of employment. Any additional notes included in a 'Further Location Preferences (optional)' field within the application form, will not be considered. Please be aware that you cannot change your location preference after submitting your application. Office closures For more information on where you might be working, review this information on our locations. If your location preference is for one of the following sites, it's important to note that these are not long-term sites for HMRC and we will require you to move to a new building in the future, subject to our location strategy and the applicable employee policies at that time. These sites are: Benton Park View, Newcastle - moving to Pilgrims Quarter, Newcastle Telford Plaza, Telford - moving to Parkside Court, Telford Trinity Bridge House, Salford - moving to an alternative office in Manchester/ Salford You will be given more information about what this means at the job offer stage. Leeds Locations Moves Adjustment Payment will be available for this role, provided the successful applicant is a current HMRC colleague in Bradford and meets the eligibility requirements outlined in the HMRC's Moves Adjustment Payment guidance. Benefits Alongside your salary of £37,682, HM Revenue and Customs contributes £10,916 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window). HMRC operates both Flexible and Hybrid Working policies, allowing you to balance your work and personal commitments. We welcome applications from those who need to work a more flexible arrangement and will agree to requests where possible, considering our operational and customer service needs. We offer a generous leave allowance, starting at 25 days and increasing by a day for every year of qualifying service up to a maximum of 30 days. Pension - We make contributions to our colleagues' Alpha pension equal to at least 28.97% of their salary. Family friendly policies. Personal support. Coaching and development. To find out more about HMRC benefits and find out what it's really like to work for HMRC hear from our insiders or visit Thinking of joining the Civil Service Things you need to know Artificial intelligence Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use. Selection process details This vacancy is using Success Profiles (opens in a new window), and will assess your Strengths and Experience. How to Apply As part of the application process, you will be asked to provide the following: A name-blind CV including your job history, previous experiences and qualifications. Qualifications are not mandatory for this role. A 750-word Personal Statement. Your Personal Statement should be used to describe how your skills and experience would be suitable for the advertised role, making reference to the Essential Criteria and Person Specification outlined in the advert. Please complete a separate statement (Max 250 words) for the Desirable Criteria where applicable. This is not essential for the role but may be considered by the vacancy-holder where candidates have the same scores at interview. Further details around what this will entail are listed on the application form. Prior to applications being sifted candidates will be asked to complete an additional IKM assessment. Candidates will be sent details of the assessment once the advert has closed. This assessment is a pass or fail and only those who pass will be considered at the sift stage. Sift In the event of a large number of applications being received, an initial sift may be held on your CV. At full sift your CV and your Personal Statement will be assessed, with the successful candidates being invited to interview. We may also raise the score required at any stage of the process if we receive a high number of applications. Interview During the panel interview, your experience will be assessed, and you will be asked strength-based questions to also explore what you enjoy and your motivations relevant to the job role. This is an example of a strengths-based question: . click apply for full job details
Aug 24, 2026
Full time
About the job Job summary Discover a career in your hands at HMRC. Whether you're seeking purpose, growth, or a workplace that gives you a true sense of belonging, hear from some of our employees as they share their story about what it's really like to work at HMRC. Visit our YouTube channel to watch the full series and come and discover your potential. Our team is rapidly growing as we invest in new technologies and capabilities, and we are in search of enthusiastic individuals who can help us in achieving our mission. We are continually improving the service we give to our customers and, in line with this, we are creating a new response and management team within the HMRC Fraud Prevention Centre. The Fraud Prevention Centre (FPC) is a strategic capability within HMRC Security, designed to safeguard customers and the organisation against identity-related fraud and emerging threats. Its mission is built on three interconnected pillars: Protection, Detection, and Response, all underpinned by advanced threat intelligence and customer support. The Centre operates across multiple functional areas, including Proactive Protection, Customer Support & Response, and Strategy & Advisory, to deliver a holistic approach to fraud prevention. Job description We're looking for a proactive and analytical professional to support HMRC's fight against identity fraud. You'll help lead data-driven investigations into suspicious activity related to identity verification and authentication services, while working with the team and partners, acting as a key contributor in a team that supports customers and provides insight into identity fraud activity and proactive searching for threats. This is an exciting opportunity to make a real difference, working in a dynamic and evolving environment. Person specification Manipulate and analyse large data sets and investigate suspicious activity. Learn, develop, and apply methods using data analytics techniques such as data mining, data matching, clustering analysis and outlier detection. Use basic scripting languages to develop visualisations and automate effective searches to build a growing analytical suite of capabilities that you can operate efficiently. Have strong communication skills and be able to demonstrate working across business and technical domains. You will have excellent interpersonal skills. Apply your knowledge of security and fraud risks to digital services. Support and deputise for the senior analysts, producing clear, insightful reports and presentations for senior stakeholders. You will be confident working in an environment that may flex its focus in response to emerging issues and have a delivery focus. You will be eager to learn and widen your experience in different areas of identity work. You will use your experience of scripting, for example SPL, Python, SQL, KQL to proactively search and discover anomalies. Be flexible and enthusiastic whilst working with some ambiguity as the team forms, grows and matures. Support senior managers in the reporting of metrics and support the wider aims of the HMRC Security Identity Team. Identify process improvement areas. Essential Criteria Knowledge of fraud detection techniques, including behavioural analysis and anomaly detection and investigation and OSINT (Open Source Intelligence) methods. Data analysis skills and experience with large data sets, with proficiency scripting complex queries in analysis environments. Solid technical understanding of web and API services (e.g. cookies, IP addresses, authentication processes) and threats to those services from cybercrime actors and tools. Experience using Security Information and Event Management (SIEM) platforms, preferably in a security operations setting. A sound understanding of Identity, Verification and Authentication principles. Desirable Criteria A degree in Data Analysis, Data Science, Information Security, Cyber Security, or other Cyber qualifications eg SANS, or at least previous experience in a relevant cyber role. Proven experience in fraud detection, cyber security, or threat intelligence within a large organisation. Active use of at least one of the following: Python, SQL, KQL, SPL. Important Additional Information The successful candidate may be required to apply for Developed Vetting (DV) clearance level once in post but must already hold or be willing to obtain Security Check (SC) clearance level before starting the role. Further Location Information Please ensure that you only apply for a location that you are willing and able to work from, as we will only make one offer of employment. Any additional notes included in a 'Further Location Preferences (optional)' field within the application form, will not be considered. Please be aware that you cannot change your location preference after submitting your application. Office closures For more information on where you might be working, review this information on our locations. If your location preference is for one of the following sites, it's important to note that these are not long-term sites for HMRC and we will require you to move to a new building in the future, subject to our location strategy and the applicable employee policies at that time. These sites are: Benton Park View, Newcastle - moving to Pilgrims Quarter, Newcastle Telford Plaza, Telford - moving to Parkside Court, Telford Trinity Bridge House, Salford - moving to an alternative office in Manchester/ Salford You will be given more information about what this means at the job offer stage. Leeds Locations Moves Adjustment Payment will be available for this role, provided the successful applicant is a current HMRC colleague in Bradford and meets the eligibility requirements outlined in the HMRC's Moves Adjustment Payment guidance. Benefits Alongside your salary of £37,682, HM Revenue and Customs contributes £10,916 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window). HMRC operates both Flexible and Hybrid Working policies, allowing you to balance your work and personal commitments. We welcome applications from those who need to work a more flexible arrangement and will agree to requests where possible, considering our operational and customer service needs. We offer a generous leave allowance, starting at 25 days and increasing by a day for every year of qualifying service up to a maximum of 30 days. Pension - We make contributions to our colleagues' Alpha pension equal to at least 28.97% of their salary. Family friendly policies. Personal support. Coaching and development. To find out more about HMRC benefits and find out what it's really like to work for HMRC hear from our insiders or visit Thinking of joining the Civil Service Things you need to know Artificial intelligence Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use. Selection process details This vacancy is using Success Profiles (opens in a new window), and will assess your Strengths and Experience. How to Apply As part of the application process, you will be asked to provide the following: A name-blind CV including your job history, previous experiences and qualifications. Qualifications are not mandatory for this role. A 750-word Personal Statement. Your Personal Statement should be used to describe how your skills and experience would be suitable for the advertised role, making reference to the Essential Criteria and Person Specification outlined in the advert. Please complete a separate statement (Max 250 words) for the Desirable Criteria where applicable. This is not essential for the role but may be considered by the vacancy-holder where candidates have the same scores at interview. Further details around what this will entail are listed on the application form. Prior to applications being sifted candidates will be asked to complete an additional IKM assessment. Candidates will be sent details of the assessment once the advert has closed. This assessment is a pass or fail and only those who pass will be considered at the sift stage. Sift In the event of a large number of applications being received, an initial sift may be held on your CV. At full sift your CV and your Personal Statement will be assessed, with the successful candidates being invited to interview. We may also raise the score required at any stage of the process if we receive a high number of applications. Interview During the panel interview, your experience will be assessed, and you will be asked strength-based questions to also explore what you enjoy and your motivations relevant to the job role. This is an example of a strengths-based question: . click apply for full job details
Senior Cyber Security Risk & Assurance Consultant - Product Risk (PBRA) (CONTRACTOR) - London Duration: 1 year contract Hybrid Working - 8 days onsite per month - the rest is remote working About the Team The Product-Based Risk Assessment (PBRA) service conducts recurring security assessments of applications, services, and technologies to identify emerging threats, evaluate control effectiveness, and drive remediation that strengthens The clients cyber resilience. The team supports business and technology stakeholders by assessing cyber security risks and ensuring alignment with The Banks security standards and risk appetite. Key Accountabilities Product-Based Risk Assessments Lead end-to-end Product-Based Risk Assessments (PBRA) for critical applications, platforms, and technology services. Analyse application architectures, business processes, information flows, and supporting infrastructure. Identify and assess cyber threats, vulnerabilities, control weaknesses, and potential business impacts. Evaluate the design and effectiveness of security controls using clients security frameworks and standards. Assess residual risks and propose actionable remediation plans. Security Risk Analysis Perform security risk assessments using recognised methodologies and industry frameworks. Evaluate risks related to infrastructure, software, cloud services, networks, third-party integrations, and information assets. Contribute to threat modelling and attack surface analysis activities. Support technology-focused assessments such as cloud, AI, and emerging technology evaluations. Stakeholder Engagement Act as the primary security assessment contact for business and IT stakeholders. Facilitate workshops, interviews, and assessment review sessions. Challenge assumptions and provide expert security guidance to delivery and operations teams. Build trusted relationships across CISO, CTO, Architecture, Risk Management, and Engineering teams. Reporting & Governance Produce high-quality assessment reports, risk summaries, and executive-level communications. Present findings and recommendations to senior management and governance bodies. Track remediation plans and risk treatment activities through closure. Support internal and external audit activities as required. Continuous Improvement Contribute to the evolution of the PBRA service, methodologies, tools, and operating model. Help drive the transition toward data-enabled and automated security assessment capabilities. Identify opportunities to improve efficiency, consistency, and risk coverage across assessments. Support knowledge sharing and mentoring of junior analysts. Required Skills & Experience Technical Skills Strong understanding of cybersecurity principles, controls, and risk management practices. Knowledge of application security, cloud security, infrastructure security, and network security. Experience conducting security assessments, threat modelling, or risk analyses. Familiarity with industry frameworks and standards such as: NIST Cyber Security Framework ISO 27001 CIS Controls Secure Controls Framework (SCF) DORA ANSSI EBIOS RM OWASP Professional Experience Minimum 7 years of experience in Information Security, Cyber Risk, Security Assurance, or Security Architecture. Experience leading complex security assessments across large technology environments. Experience working with senior business and technology stakeholders. Strong report-writing and presentation skills. Personal Competencies Strong analytical and critical-thinking capabilities. Excellent communication and stakeholder management skills. Ability to challenge constructively and influence decision-making. Self-driven with strong ownership and accountability. Pragmatic, risk-based mindset. Comfortable operating in a complex, regulated environment. Please do send across to me the most up to date CV to (url removed) Rates depend on experience and client requirements
Aug 23, 2026
Contractor
Senior Cyber Security Risk & Assurance Consultant - Product Risk (PBRA) (CONTRACTOR) - London Duration: 1 year contract Hybrid Working - 8 days onsite per month - the rest is remote working About the Team The Product-Based Risk Assessment (PBRA) service conducts recurring security assessments of applications, services, and technologies to identify emerging threats, evaluate control effectiveness, and drive remediation that strengthens The clients cyber resilience. The team supports business and technology stakeholders by assessing cyber security risks and ensuring alignment with The Banks security standards and risk appetite. Key Accountabilities Product-Based Risk Assessments Lead end-to-end Product-Based Risk Assessments (PBRA) for critical applications, platforms, and technology services. Analyse application architectures, business processes, information flows, and supporting infrastructure. Identify and assess cyber threats, vulnerabilities, control weaknesses, and potential business impacts. Evaluate the design and effectiveness of security controls using clients security frameworks and standards. Assess residual risks and propose actionable remediation plans. Security Risk Analysis Perform security risk assessments using recognised methodologies and industry frameworks. Evaluate risks related to infrastructure, software, cloud services, networks, third-party integrations, and information assets. Contribute to threat modelling and attack surface analysis activities. Support technology-focused assessments such as cloud, AI, and emerging technology evaluations. Stakeholder Engagement Act as the primary security assessment contact for business and IT stakeholders. Facilitate workshops, interviews, and assessment review sessions. Challenge assumptions and provide expert security guidance to delivery and operations teams. Build trusted relationships across CISO, CTO, Architecture, Risk Management, and Engineering teams. Reporting & Governance Produce high-quality assessment reports, risk summaries, and executive-level communications. Present findings and recommendations to senior management and governance bodies. Track remediation plans and risk treatment activities through closure. Support internal and external audit activities as required. Continuous Improvement Contribute to the evolution of the PBRA service, methodologies, tools, and operating model. Help drive the transition toward data-enabled and automated security assessment capabilities. Identify opportunities to improve efficiency, consistency, and risk coverage across assessments. Support knowledge sharing and mentoring of junior analysts. Required Skills & Experience Technical Skills Strong understanding of cybersecurity principles, controls, and risk management practices. Knowledge of application security, cloud security, infrastructure security, and network security. Experience conducting security assessments, threat modelling, or risk analyses. Familiarity with industry frameworks and standards such as: NIST Cyber Security Framework ISO 27001 CIS Controls Secure Controls Framework (SCF) DORA ANSSI EBIOS RM OWASP Professional Experience Minimum 7 years of experience in Information Security, Cyber Risk, Security Assurance, or Security Architecture. Experience leading complex security assessments across large technology environments. Experience working with senior business and technology stakeholders. Strong report-writing and presentation skills. Personal Competencies Strong analytical and critical-thinking capabilities. Excellent communication and stakeholder management skills. Ability to challenge constructively and influence decision-making. Self-driven with strong ownership and accountability. Pragmatic, risk-based mindset. Comfortable operating in a complex, regulated environment. Please do send across to me the most up to date CV to (url removed) Rates depend on experience and client requirements
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Aug 23, 2026
Full time
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Senior SecOps Engineer - Microsoft Security UK Predominantly Remote Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure Sentinel Microsoft Defender / Defender XDR Strong KQL / Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps / Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Aug 23, 2026
Full time
Senior SecOps Engineer - Microsoft Security UK Predominantly Remote Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure Sentinel Microsoft Defender / Defender XDR Strong KQL / Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps / Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Hiscox Underwriting Group Services Ltd (HUGS)
City, York
Job Type: Permanent. Build a brilliant future with Hiscox. Role: Global Category Manager. Reporting to: Head of Business Services Sourcing. Position Overview Following a period of rapid growth, Hiscox has around 3,000 employees across a number of business units and countries and is deploying a new platform Hiscox Marketplace for procurement, vendor management and payments across all regions. It is an exciting time to be joining Hiscox. With sponsorship from the Board, Procurement has a key role in supporting the delivery of the Fit for 10X program, a plan to ensure Hiscox is best placed for significant expansion over the next 5 years. The Global Category Manager (Legal Services and Insurance) will lead the end to end category strategy, sourcing and commercial governance for legal services spend as well as the Insurance policies for the Hiscox Group (notably Cyber, Professional Indemnity and Directors and Officers). The role delivers measurable value through cost optimisation, demand management, service quality and innovation, while ensuring compliance with internal policies and applicable regulations. The role will be supported with Category Analysts based in Lisbon. The role will establish relationships with stakeholders across the UK and Europe/US to ensure that procurement is aligned to deliver the benefits of Hiscox Marketplace and the Fit For 10X business objectives. Where sourcing activity is material, high profile or high risk then the Global Category Manager will lead the procurement activity from market analysis through to contract signature. They will also provide advice and support to the business when managing vendors on a day to day basis. The role will be accountable for improving spend management in the Legal Services and Group Insurance categories as well as contributing to Group procurement strategy, supporting the use of Hiscox Marketplace the global procurement platform used across the business in all regions and to provide consistent and professional procurement practice. As well as maintaining and developing the Global Category Plans for Legal Services. Responsibilities Category Strategy: Develop and maintain a multi year category strategy and pipeline aligned to business priorities, demand management, and financial plans. Team Contribution: Coach junior colleagues, share best practice, and contribute to procurement standards, playbooks and training. Stakeholders: Maintain good working relationships with key stakeholders in Finance, London Market, UK Retail, US and Europe by providing expertise on contracts and Statements of Work. Influence demand, shape requirements, and drive adherence to sourcing and spend control processes via the use of the Legal Services panel and other supplier panels as appropriate. Sourcing & Tendering: Plan and execute end to end sourcing activities (RFI/RFP/RFQ/Spot Bid), evaluation, negotiation and contract award in line with governance requirements. Commercial Leadership: Negotiate commercials (rates, discounts, value adds, KPIs, gainshare), define statements of work (SoWs), and ensure clear deliverables and acceptance criteria. Hiscox Marketplace: embed the use of Hiscox Marketplace and policies as required to deploy best practice based processes. Contracting & Compliance: Use of A.I. and partner with Legal and Risk to implement appropriate contractual terms (IP, confidentiality, data protection, liability, conflicts of interest, anti bribery) and ensure policy compliance. Governance: Implement appropriate controls for legal services engagements (SoW approvals, rate cards, time & materials governance, change control, and invoice validation). Supplier Management: Own strategic supplier relationships, QBRs, performance scorecards, continuous improvement plans, and issue resolution/escalations. Reporting: Use of A.I. to undertake and input into the creation of procurement MI as required and reporting such as savings and volumes of requests. Carry out any other tasks or requirements as required by Hiscox from time to time. Required Skills Commercial acumen: Strong negotiation skills; able to structure deals, manage risk/reward, and agree measurable outcomes. Analytical capability: Rate benchmarking, total cost of ownership thinking, financial modelling, and data driven decision making. Stakeholder influence: Credible at senior levels; able to challenge constructively and build alignment across competing priorities. Supplier relationship management: Balances partnership and performance; manages escalations with pace and professionalism. Contract literacy: Strong understanding of key legal services contract terms (IP, confidentiality, data protection, conflicts, liability, audit rights). Project management: Plans and executes sourcing projects to deadlines; manages evaluation, governance and approvals. Communication: Clear, concise written and verbal communication; able to present recommendations and business cases. Integrity and judgement: Applies strong ethical standards; manages confidential information appropriately. Necessary: Strong leadership skills across matrix structures. Team player at executive level: collaborate with Business Units and functional partners in Finance, and Operations across the Hiscox Business Units. Solid operational management and general business skills to project manage business teams to support delivery of procurement activity as required. Excellent communication skills in order to get the 'voice of the internal customer' and to understand the company culture and how to best communicate procurement's value to it. Qualifications and Training Degree (or equivalent experience) in business, procurement, finance, law or a related discipline. Professional procurement qualification preferred (e.g., CIPS Level 5/6 or equivalent). Desirable Contract management qualification and/or relevant compliance training (e.g., anti bribery, modern slavery, data protection). Negotiation Training. Diversity and flexible working We are committed to diversity and creating a truly inclusive culture, which we believe drives success. Hybrid working is encouraged to support a healthy work life balance; it is set by the team rather than the business to enable you to manage your own personal work life balance. This best of both worlds; structure and sociability on one hand, and independence and flexibility on the other.
Aug 22, 2026
Full time
Job Type: Permanent. Build a brilliant future with Hiscox. Role: Global Category Manager. Reporting to: Head of Business Services Sourcing. Position Overview Following a period of rapid growth, Hiscox has around 3,000 employees across a number of business units and countries and is deploying a new platform Hiscox Marketplace for procurement, vendor management and payments across all regions. It is an exciting time to be joining Hiscox. With sponsorship from the Board, Procurement has a key role in supporting the delivery of the Fit for 10X program, a plan to ensure Hiscox is best placed for significant expansion over the next 5 years. The Global Category Manager (Legal Services and Insurance) will lead the end to end category strategy, sourcing and commercial governance for legal services spend as well as the Insurance policies for the Hiscox Group (notably Cyber, Professional Indemnity and Directors and Officers). The role delivers measurable value through cost optimisation, demand management, service quality and innovation, while ensuring compliance with internal policies and applicable regulations. The role will be supported with Category Analysts based in Lisbon. The role will establish relationships with stakeholders across the UK and Europe/US to ensure that procurement is aligned to deliver the benefits of Hiscox Marketplace and the Fit For 10X business objectives. Where sourcing activity is material, high profile or high risk then the Global Category Manager will lead the procurement activity from market analysis through to contract signature. They will also provide advice and support to the business when managing vendors on a day to day basis. The role will be accountable for improving spend management in the Legal Services and Group Insurance categories as well as contributing to Group procurement strategy, supporting the use of Hiscox Marketplace the global procurement platform used across the business in all regions and to provide consistent and professional procurement practice. As well as maintaining and developing the Global Category Plans for Legal Services. Responsibilities Category Strategy: Develop and maintain a multi year category strategy and pipeline aligned to business priorities, demand management, and financial plans. Team Contribution: Coach junior colleagues, share best practice, and contribute to procurement standards, playbooks and training. Stakeholders: Maintain good working relationships with key stakeholders in Finance, London Market, UK Retail, US and Europe by providing expertise on contracts and Statements of Work. Influence demand, shape requirements, and drive adherence to sourcing and spend control processes via the use of the Legal Services panel and other supplier panels as appropriate. Sourcing & Tendering: Plan and execute end to end sourcing activities (RFI/RFP/RFQ/Spot Bid), evaluation, negotiation and contract award in line with governance requirements. Commercial Leadership: Negotiate commercials (rates, discounts, value adds, KPIs, gainshare), define statements of work (SoWs), and ensure clear deliverables and acceptance criteria. Hiscox Marketplace: embed the use of Hiscox Marketplace and policies as required to deploy best practice based processes. Contracting & Compliance: Use of A.I. and partner with Legal and Risk to implement appropriate contractual terms (IP, confidentiality, data protection, liability, conflicts of interest, anti bribery) and ensure policy compliance. Governance: Implement appropriate controls for legal services engagements (SoW approvals, rate cards, time & materials governance, change control, and invoice validation). Supplier Management: Own strategic supplier relationships, QBRs, performance scorecards, continuous improvement plans, and issue resolution/escalations. Reporting: Use of A.I. to undertake and input into the creation of procurement MI as required and reporting such as savings and volumes of requests. Carry out any other tasks or requirements as required by Hiscox from time to time. Required Skills Commercial acumen: Strong negotiation skills; able to structure deals, manage risk/reward, and agree measurable outcomes. Analytical capability: Rate benchmarking, total cost of ownership thinking, financial modelling, and data driven decision making. Stakeholder influence: Credible at senior levels; able to challenge constructively and build alignment across competing priorities. Supplier relationship management: Balances partnership and performance; manages escalations with pace and professionalism. Contract literacy: Strong understanding of key legal services contract terms (IP, confidentiality, data protection, conflicts, liability, audit rights). Project management: Plans and executes sourcing projects to deadlines; manages evaluation, governance and approvals. Communication: Clear, concise written and verbal communication; able to present recommendations and business cases. Integrity and judgement: Applies strong ethical standards; manages confidential information appropriately. Necessary: Strong leadership skills across matrix structures. Team player at executive level: collaborate with Business Units and functional partners in Finance, and Operations across the Hiscox Business Units. Solid operational management and general business skills to project manage business teams to support delivery of procurement activity as required. Excellent communication skills in order to get the 'voice of the internal customer' and to understand the company culture and how to best communicate procurement's value to it. Qualifications and Training Degree (or equivalent experience) in business, procurement, finance, law or a related discipline. Professional procurement qualification preferred (e.g., CIPS Level 5/6 or equivalent). Desirable Contract management qualification and/or relevant compliance training (e.g., anti bribery, modern slavery, data protection). Negotiation Training. Diversity and flexible working We are committed to diversity and creating a truly inclusive culture, which we believe drives success. Hybrid working is encouraged to support a healthy work life balance; it is set by the team rather than the business to enable you to manage your own personal work life balance. This best of both worlds; structure and sociability on one hand, and independence and flexibility on the other.
Defend Critical Infrastructure. Hunt Threats. Make a Real Impact. Cyber threats never stand stilland neither do we. We're looking for a Senior Security Operations Centre (SOC) Analyst to join our growing Cyber Security team and play a key role in protecting some of the UK's most critical organisations. This is your opportunity to work at the frontline of cyber defence, investigating real-world threa click apply for full job details
Aug 21, 2026
Full time
Defend Critical Infrastructure. Hunt Threats. Make a Real Impact. Cyber threats never stand stilland neither do we. We're looking for a Senior Security Operations Centre (SOC) Analyst to join our growing Cyber Security team and play a key role in protecting some of the UK's most critical organisations. This is your opportunity to work at the frontline of cyber defence, investigating real-world threa click apply for full job details
慨正橡扯 is seeking a DFIR Lead Cyber Operations Analyst at VP level in Knutsford. In this key role, you will deliver advanced digital forensics and incident response while leading complex investigations. You will collaborate with internal teams and law enforcement, and produce clear reports under pressure. Ideal candidates will have expertise in digital forensics, excellent communication skills, and experience in cloud investigation and automation.
Aug 21, 2026
Full time
慨正橡扯 is seeking a DFIR Lead Cyber Operations Analyst at VP level in Knutsford. In this key role, you will deliver advanced digital forensics and incident response while leading complex investigations. You will collaborate with internal teams and law enforcement, and produce clear reports under pressure. Ideal candidates will have expertise in digital forensics, excellent communication skills, and experience in cloud investigation and automation.
Cyber Security Contractors (Multiple Opportunities) SC Cleared 594/day Remote UK Location: UK Remote (occasional client-site visits required) Contract: Inside IR35 Rate: 594 per day (Umbrella) Duration: Until March 2027 Security Clearance: Active SC Clearance Required We are supporting a major, long-term Cyber Security Programme and are seeking experienced SC-cleared professionals across several specialist disciplines. These are excellent opportunities to join a high-profile programme delivering critical security services within a complex environment. Opportunities Available Security Architect (Cloud Security) Key responsibilities include: Cloud security architecture and design assurance Security assessments and risk reviews Development and implementation of security standards, patterns, and best practices Collaboration with technical and business stakeholders to ensure secure-by-design solutions Experience required: Strong cloud security architecture background Experience with enterprise cloud platforms (AWS, Azure, or GCP) Security design and assurance expertise Knowledge of security frameworks and standards Security Operations Analyst Key responsibilities include: Security operations monitoring and analysis Cyber threat intelligence assessment Threat modelling and risk identification Incident investigation and security event analysis Experience required: Security Operations Centre (SOC) or cyber defence experience Hands-on threat intelligence and analysis capability Threat modelling expertise Strong understanding of cyber security technologies and processes Threat Intelligence Analyst Key responsibilities include: Production of threat intelligence reports and assessments Analysis of Indicators of Compromise (IOCs) and Tactics, Techniques & Procedures (TTPs) Tracking emerging cyber threats and threat actors Supporting security architecture and operational security decision-making Experience required: Proven cyber threat intelligence background Experience analysing threat actor activity and attack methodologies Strong reporting and stakeholder engagement skills Knowledge of intelligence frameworks such as MITRE ATT&CK Information Assurance Consultant Key responsibilities include: Information Assurance (IA) and Governance, Risk & Compliance (GRC) activities Quality assurance and quality management support Business Continuity and Disaster Recovery (BCDR) planning and assessment Policy, controls, and compliance reviews Experience required: Strong IA/GRC experience Knowledge of security governance frameworks Experience in quality management and assurance activities BCDR planning and implementation expertise Essential Requirements Active SC Clearance (mandatory) Proven experience within the relevant cyber security discipline Ability to work effectively in complex stakeholder environments Strong communication and reporting skills
Aug 20, 2026
Contractor
Cyber Security Contractors (Multiple Opportunities) SC Cleared 594/day Remote UK Location: UK Remote (occasional client-site visits required) Contract: Inside IR35 Rate: 594 per day (Umbrella) Duration: Until March 2027 Security Clearance: Active SC Clearance Required We are supporting a major, long-term Cyber Security Programme and are seeking experienced SC-cleared professionals across several specialist disciplines. These are excellent opportunities to join a high-profile programme delivering critical security services within a complex environment. Opportunities Available Security Architect (Cloud Security) Key responsibilities include: Cloud security architecture and design assurance Security assessments and risk reviews Development and implementation of security standards, patterns, and best practices Collaboration with technical and business stakeholders to ensure secure-by-design solutions Experience required: Strong cloud security architecture background Experience with enterprise cloud platforms (AWS, Azure, or GCP) Security design and assurance expertise Knowledge of security frameworks and standards Security Operations Analyst Key responsibilities include: Security operations monitoring and analysis Cyber threat intelligence assessment Threat modelling and risk identification Incident investigation and security event analysis Experience required: Security Operations Centre (SOC) or cyber defence experience Hands-on threat intelligence and analysis capability Threat modelling expertise Strong understanding of cyber security technologies and processes Threat Intelligence Analyst Key responsibilities include: Production of threat intelligence reports and assessments Analysis of Indicators of Compromise (IOCs) and Tactics, Techniques & Procedures (TTPs) Tracking emerging cyber threats and threat actors Supporting security architecture and operational security decision-making Experience required: Proven cyber threat intelligence background Experience analysing threat actor activity and attack methodologies Strong reporting and stakeholder engagement skills Knowledge of intelligence frameworks such as MITRE ATT&CK Information Assurance Consultant Key responsibilities include: Information Assurance (IA) and Governance, Risk & Compliance (GRC) activities Quality assurance and quality management support Business Continuity and Disaster Recovery (BCDR) planning and assessment Policy, controls, and compliance reviews Experience required: Strong IA/GRC experience Knowledge of security governance frameworks Experience in quality management and assurance activities BCDR planning and implementation expertise Essential Requirements Active SC Clearance (mandatory) Proven experience within the relevant cyber security discipline Ability to work effectively in complex stakeholder environments Strong communication and reporting skills
Smart Communications group
City Of Westminster, London
Information Security Director We are seeking a highly skilled and experienced Director of Information Security to join our dynamic and growing team. As the Director of Information Security you will play a crucial role in ensuring safety, integrity and privacy, securing our company and data against cyber threats. We operate in a highly secure global SaaS organization that holds multiple certifications such as PCI DSS, ISO/IEC 27001, SOC, HIPAA, IRAP and works with a large, federated customer base. Responsibilities Develop and lead a team of Security Analysts and Engineers, providing management, mentorship and direction. Partner with Product, Engineering, Operations, HR, Legal and Finance functions to embed security into all business operations and change programmes. Collaborate with the CIO to provide a future vision of technology and systems with security in mind. Provide strategic planning, development and delivery of the information security strategy across the business. Lead and direct security operations team in monitoring, detecting, and responding to security incidents and breaches. Champion the adoption of security by design and privacy by design principles, fostering a culture of security. Required Skills and Experience A minimum of 10+ years hands on, proven industry experience in a similar role. Bachelor's or master's degree in computer science, Information Security, or a related field. Industry certifications such as CISSP, CISM, CEH, ECSA, LPT, OSCP, AWS certified security or equivalent are highly desirable. Strong budget planning and financial management capabilities related to security operations, combined with a proactive problem solving attitude and service oriented approach. Experience managing and growing high performing teams. Excellent communication and interpersonal skills enabling effective presentation of ideas, drive change, influence stakeholders and build relationships. In depth knowledge of security principles, technologies and best practices, threat detection and mitigation strategies. Proactive approach to staying updated with the latest security threats, vulnerabilities and mitigation techniques. Advantageous Skills and Experience Experience working on projects ensuring compliance with PCI DSS, ISO/IEC 27001, SOC, HIPAA, IRAP controls. Knowledge of security compliance standards relevant to the SaaS industry such as PCI, GDPR, ISO 27001, SOC 2, NIST. Benefits Competitive salary commensurate with experience. Extensive health insurance, income protection, life assurance. Subsidised gym membership, leisure travel insurance. Pension contribution and 25 days holiday allowance plus an additional day off for your birthday. Fully remote role with flexible working environment. Equal Opportunity We are an equal opportunity employer. All qualified applicants will receive consideration for employment regardless of colour, religion, sex, national origin, sexual orientation, age, disability, marital status or gender identity. Location UK - Remote
Aug 20, 2026
Full time
Information Security Director We are seeking a highly skilled and experienced Director of Information Security to join our dynamic and growing team. As the Director of Information Security you will play a crucial role in ensuring safety, integrity and privacy, securing our company and data against cyber threats. We operate in a highly secure global SaaS organization that holds multiple certifications such as PCI DSS, ISO/IEC 27001, SOC, HIPAA, IRAP and works with a large, federated customer base. Responsibilities Develop and lead a team of Security Analysts and Engineers, providing management, mentorship and direction. Partner with Product, Engineering, Operations, HR, Legal and Finance functions to embed security into all business operations and change programmes. Collaborate with the CIO to provide a future vision of technology and systems with security in mind. Provide strategic planning, development and delivery of the information security strategy across the business. Lead and direct security operations team in monitoring, detecting, and responding to security incidents and breaches. Champion the adoption of security by design and privacy by design principles, fostering a culture of security. Required Skills and Experience A minimum of 10+ years hands on, proven industry experience in a similar role. Bachelor's or master's degree in computer science, Information Security, or a related field. Industry certifications such as CISSP, CISM, CEH, ECSA, LPT, OSCP, AWS certified security or equivalent are highly desirable. Strong budget planning and financial management capabilities related to security operations, combined with a proactive problem solving attitude and service oriented approach. Experience managing and growing high performing teams. Excellent communication and interpersonal skills enabling effective presentation of ideas, drive change, influence stakeholders and build relationships. In depth knowledge of security principles, technologies and best practices, threat detection and mitigation strategies. Proactive approach to staying updated with the latest security threats, vulnerabilities and mitigation techniques. Advantageous Skills and Experience Experience working on projects ensuring compliance with PCI DSS, ISO/IEC 27001, SOC, HIPAA, IRAP controls. Knowledge of security compliance standards relevant to the SaaS industry such as PCI, GDPR, ISO 27001, SOC 2, NIST. Benefits Competitive salary commensurate with experience. Extensive health insurance, income protection, life assurance. Subsidised gym membership, leisure travel insurance. Pension contribution and 25 days holiday allowance plus an additional day off for your birthday. Fully remote role with flexible working environment. Equal Opportunity We are an equal opportunity employer. All qualified applicants will receive consideration for employment regardless of colour, religion, sex, national origin, sexual orientation, age, disability, marital status or gender identity. Location UK - Remote
Join Barclays as a DFIR Lead Cyber Operations Analyst, a VP-level role at the centre of the bank's cyber defence, delivering advanced digital forensics and incident response. You will analyse malware, malicious samples and network activity to support complex investigations, working closely with internal teams, external partners and law enforcement. This is a highly technical, hands on position suited to an experienced cyber or digital forensics professional, with passion for deep investigation, and the ability to produce clear, high quality reporting in a fast paced, high pressure environment. Please note that this role includes an on call support rotation. Occasional additional support may be required, including extended hours and weekend work. To be successful in this role, you will need the following: Digital forensics and incident response expertise, including host, network, cloud and live forensic analysis, supported by rigorous documentation practices. Excellent written and verbal communication skills, with the ability to clearly articulate complex technical findings to senior stakeholders and non technical business teams. Proven leadership under pressure, including coordinating investigations, managing cross functional stakeholders, and operating effectively within a regulated banking environment. Some other highly valued skills may include: Cloud investigation experience across platforms such as AWS, Azure, or Google Cloud. Scripting and automation capabilities, using languages such as Python, PowerShell, Bash, or JavaScript. Relevant industry certifications, such as GCFA, GNFA, GCFE, or GREM. You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking and digital and technology, as well as job specific technical skills. The successful candidate will be based in Knutsford (Radbroke Hall). Purpose of the role To monitor the performance of operational controls, implement and manage security controls and consider lessons learned in order to protect the bank from potential cyber attacks and respond to threats. Accountabilities Management of security monitoring systems, including intrusive prevention and detection systems, to alert, detect and block potential cyber security incidents, and provide a prompt response to restore normal operations with minimised system damage. Identification of emerging cyber security threats, attack techniques and technologies to detect/prevent incidents, and collaborate with networks and conferences to gain industry knowledge and expertise. Management and analysis of security information and event management systems to collect, correlate and analyse security logs, events and alerts/potential threats. Triage of data loss prevention alerts to identify and prevent sensitive data for being exfiltrated from the banks network. Management of cyber security incidents including remediation & driving to closure. Vice President Expectations To contribute or set strategy, drive requirements and make recommendations for change. Plan resources, budgets, and policies; manage and maintain policies/processes; deliver continuous improvements and escalate breaches of policies/procedures. If managing a team, they define jobs and responsibilities, planning for the department's future needs and operations, counselling employees on performance and contributing to employee pay decisions/changes. They may also lead a number of specialists to influence the operations of a department, in alignment with strategic as well as tactical priorities, while balancing short and long term goals and ensuring that budgets and schedules meet corporate requirements. If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L - Listen and be authentic, E - Energise and inspire, A - Align across the enterprise, D - Develop others. OR for an individual contributor, they will be a subject matter expert within own discipline and will guide technical direction. They will lead collaborative, multi year assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions. Advise key stakeholders, including functional leadership teams and senior management on functional and cross functional areas of impact and alignment. Manage and mitigate risks through assessment, in support of the control and governance agenda. Demonstrate leadership and accountability for managing risk and strengthening controls in relation to the work your team does. Demonstrate comprehensive understanding of the organisation functions to contribute to achieving the goals of the business. Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategies. Create solutions based on sophisticated analytical thought comparing and selecting complex alternatives. In depth analysis with interpretative thinking will be required to define problems and develop innovative solutions. Adopt and include the outcomes of extensive research in problem solving processes. Seek out, build and maintain trusting relationships and partnerships with internal and external stakeholders in order to accomplish key business objectives, using influencing and negotiating skills to achieve outcomes. All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship - our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset - to Empower, Challenge and Drive - the operating manual for how we behave.
Aug 19, 2026
Full time
Join Barclays as a DFIR Lead Cyber Operations Analyst, a VP-level role at the centre of the bank's cyber defence, delivering advanced digital forensics and incident response. You will analyse malware, malicious samples and network activity to support complex investigations, working closely with internal teams, external partners and law enforcement. This is a highly technical, hands on position suited to an experienced cyber or digital forensics professional, with passion for deep investigation, and the ability to produce clear, high quality reporting in a fast paced, high pressure environment. Please note that this role includes an on call support rotation. Occasional additional support may be required, including extended hours and weekend work. To be successful in this role, you will need the following: Digital forensics and incident response expertise, including host, network, cloud and live forensic analysis, supported by rigorous documentation practices. Excellent written and verbal communication skills, with the ability to clearly articulate complex technical findings to senior stakeholders and non technical business teams. Proven leadership under pressure, including coordinating investigations, managing cross functional stakeholders, and operating effectively within a regulated banking environment. Some other highly valued skills may include: Cloud investigation experience across platforms such as AWS, Azure, or Google Cloud. Scripting and automation capabilities, using languages such as Python, PowerShell, Bash, or JavaScript. Relevant industry certifications, such as GCFA, GNFA, GCFE, or GREM. You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking and digital and technology, as well as job specific technical skills. The successful candidate will be based in Knutsford (Radbroke Hall). Purpose of the role To monitor the performance of operational controls, implement and manage security controls and consider lessons learned in order to protect the bank from potential cyber attacks and respond to threats. Accountabilities Management of security monitoring systems, including intrusive prevention and detection systems, to alert, detect and block potential cyber security incidents, and provide a prompt response to restore normal operations with minimised system damage. Identification of emerging cyber security threats, attack techniques and technologies to detect/prevent incidents, and collaborate with networks and conferences to gain industry knowledge and expertise. Management and analysis of security information and event management systems to collect, correlate and analyse security logs, events and alerts/potential threats. Triage of data loss prevention alerts to identify and prevent sensitive data for being exfiltrated from the banks network. Management of cyber security incidents including remediation & driving to closure. Vice President Expectations To contribute or set strategy, drive requirements and make recommendations for change. Plan resources, budgets, and policies; manage and maintain policies/processes; deliver continuous improvements and escalate breaches of policies/procedures. If managing a team, they define jobs and responsibilities, planning for the department's future needs and operations, counselling employees on performance and contributing to employee pay decisions/changes. They may also lead a number of specialists to influence the operations of a department, in alignment with strategic as well as tactical priorities, while balancing short and long term goals and ensuring that budgets and schedules meet corporate requirements. If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L - Listen and be authentic, E - Energise and inspire, A - Align across the enterprise, D - Develop others. OR for an individual contributor, they will be a subject matter expert within own discipline and will guide technical direction. They will lead collaborative, multi year assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions. Advise key stakeholders, including functional leadership teams and senior management on functional and cross functional areas of impact and alignment. Manage and mitigate risks through assessment, in support of the control and governance agenda. Demonstrate leadership and accountability for managing risk and strengthening controls in relation to the work your team does. Demonstrate comprehensive understanding of the organisation functions to contribute to achieving the goals of the business. Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategies. Create solutions based on sophisticated analytical thought comparing and selecting complex alternatives. In depth analysis with interpretative thinking will be required to define problems and develop innovative solutions. Adopt and include the outcomes of extensive research in problem solving processes. Seek out, build and maintain trusting relationships and partnerships with internal and external stakeholders in order to accomplish key business objectives, using influencing and negotiating skills to achieve outcomes. All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship - our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset - to Empower, Challenge and Drive - the operating manual for how we behave.
慨正橡扯 is seeking a DFIR Lead Cyber Operations Analyst to lead in cyber defence efforts. This VP-level role involves analyzing malware and network activities, producing quality reports, and working closely with various stakeholders. The ideal candidate will excel in digital forensics, have strong communication skills, and provide leadership during high-pressure situations. Responsibilities include managing security threats and implementing effective controls to protect against cyber attacks.
Aug 19, 2026
Full time
慨正橡扯 is seeking a DFIR Lead Cyber Operations Analyst to lead in cyber defence efforts. This VP-level role involves analyzing malware and network activities, producing quality reports, and working closely with various stakeholders. The ideal candidate will excel in digital forensics, have strong communication skills, and provide leadership during high-pressure situations. Responsibilities include managing security threats and implementing effective controls to protect against cyber attacks.
As one of the Best Big Companies to Work For, we have a rich history of loving our customers and looking after our teams. We understand that success is achieved through our people, and we are searching for a skilled and experienced Cyber Resilience Analyst to join our team. The successful candidate will report to the Cyber Operations and Engineering Manager click apply for full job details
Aug 16, 2026
Full time
As one of the Best Big Companies to Work For, we have a rich history of loving our customers and looking after our teams. We understand that success is achieved through our people, and we are searching for a skilled and experienced Cyber Resilience Analyst to join our team. The successful candidate will report to the Cyber Operations and Engineering Manager click apply for full job details
Job Title: Security Automation & AI SOC Engineer Location: London (2 days per week onsite) Remuneration: Up to 750 per day Contract Details: Temporary, Initial 6 Months (strong likelihood of extension) Overview: Join our client's dynamic team as a Security Automation & AI SOC Engineer and help reshape the future of Security Operations! This isn't your typical SOAR engineering position. You'll be at the forefront of designing and embedding scalable operational processes and automation frameworks, while integrating AI in a meaningful way. If you have a passion for security automation and a knack for AI adoption, this is the role for you! Responsibilities: Security Automation Design, develop, and maintain security automation workflows using hyperautomation platforms like Torq, Tines, Swimlane, and Cortex XSOAR. Identify and automate manual, repetitive SOC activities to enhance efficiency. Develop automated triage, enrichment, and response workflows that make a difference. Improve integrations across security tools and collaboration systems. Establish best practises and governance for automation development. AI-Enabled Security Operations Assess and introduce AI capabilities safely into SOC operations. Design AI-assisted investigation and triage processes to support analysts. Create governance models for AI workflows and measure their effectiveness. Define the future operational model for analysts working with automation and AI. SOC Strategy & Transformation Develop a comprehensive Security Automation and AI roadmap. Determine the balance between human-led and automated activities. Build scalable frameworks while ensuring operational quality. Collaborate with SOC analysts and stakeholders to drive adoption and change. Continuous Improvement Measure automation outcomes and identify further optimisation opportunities. Support knowledge sharing and capability uplift within the Security Operations team. Stay updated on emerging industry practises around Security Automation and AI SOCs. Essential Experience: Strong background in Security Operations, Incident Response, Detection Engineering, or Security Engineering. Hands-on experience with automation solutions and platforms (Tines, Swimlane, Cortex XSOAR, etc.). Proven track record of improving SOC processes and workflows. Practical experience with AI capabilities within a SOC environment. Excellent analytical and problem-solving skills. Desirable Experience: Experience designing an AI adoption strategy for a SOC. Familiarity with Microsoft Sentinel, Splunk, Azure, AWS, or GCP security technologies. Knowledge of detection engineering and automation metrics. What Success Looks Like: Deliver meaningful reductions in manual analyst effort through automation. Establish a sustainable model where analysts, automation, and AI capabilities work in harmony. Improve SOC productivity while enhancing security outcomes. If you're an innovative thinker with a passion for transforming Security Operations through automation and AI, we'd love to hear from you! Join us in making a significant impact in the cybersecurity landscape. Apply today! Pontoon is an employment consultancy. We put expertise, energy, and enthusiasm into improving everyone's chance of being part of the workplace. We respect and appreciate people of all ethnicities, generations, religious beliefs, sexual orientations, gender identities , and more. We do this by showcasing their talents, skills, and unique experience in an inclusive environment that helps them thrive. We use generative AI tools to support our candidate screening process. This helps us ensure a fair, consistent, and efficient experience for all applicants. Rest assured, all final decisions are made by our hiring team, and your application will be reviewed with care and attention.
Aug 08, 2026
Contractor
Job Title: Security Automation & AI SOC Engineer Location: London (2 days per week onsite) Remuneration: Up to 750 per day Contract Details: Temporary, Initial 6 Months (strong likelihood of extension) Overview: Join our client's dynamic team as a Security Automation & AI SOC Engineer and help reshape the future of Security Operations! This isn't your typical SOAR engineering position. You'll be at the forefront of designing and embedding scalable operational processes and automation frameworks, while integrating AI in a meaningful way. If you have a passion for security automation and a knack for AI adoption, this is the role for you! Responsibilities: Security Automation Design, develop, and maintain security automation workflows using hyperautomation platforms like Torq, Tines, Swimlane, and Cortex XSOAR. Identify and automate manual, repetitive SOC activities to enhance efficiency. Develop automated triage, enrichment, and response workflows that make a difference. Improve integrations across security tools and collaboration systems. Establish best practises and governance for automation development. AI-Enabled Security Operations Assess and introduce AI capabilities safely into SOC operations. Design AI-assisted investigation and triage processes to support analysts. Create governance models for AI workflows and measure their effectiveness. Define the future operational model for analysts working with automation and AI. SOC Strategy & Transformation Develop a comprehensive Security Automation and AI roadmap. Determine the balance between human-led and automated activities. Build scalable frameworks while ensuring operational quality. Collaborate with SOC analysts and stakeholders to drive adoption and change. Continuous Improvement Measure automation outcomes and identify further optimisation opportunities. Support knowledge sharing and capability uplift within the Security Operations team. Stay updated on emerging industry practises around Security Automation and AI SOCs. Essential Experience: Strong background in Security Operations, Incident Response, Detection Engineering, or Security Engineering. Hands-on experience with automation solutions and platforms (Tines, Swimlane, Cortex XSOAR, etc.). Proven track record of improving SOC processes and workflows. Practical experience with AI capabilities within a SOC environment. Excellent analytical and problem-solving skills. Desirable Experience: Experience designing an AI adoption strategy for a SOC. Familiarity with Microsoft Sentinel, Splunk, Azure, AWS, or GCP security technologies. Knowledge of detection engineering and automation metrics. What Success Looks Like: Deliver meaningful reductions in manual analyst effort through automation. Establish a sustainable model where analysts, automation, and AI capabilities work in harmony. Improve SOC productivity while enhancing security outcomes. If you're an innovative thinker with a passion for transforming Security Operations through automation and AI, we'd love to hear from you! Join us in making a significant impact in the cybersecurity landscape. Apply today! Pontoon is an employment consultancy. We put expertise, energy, and enthusiasm into improving everyone's chance of being part of the workplace. We respect and appreciate people of all ethnicities, generations, religious beliefs, sexual orientations, gender identities , and more. We do this by showcasing their talents, skills, and unique experience in an inclusive environment that helps them thrive. We use generative AI tools to support our candidate screening process. This helps us ensure a fair, consistent, and efficient experience for all applicants. Rest assured, all final decisions are made by our hiring team, and your application will be reviewed with care and attention.
Senior SOC Engineer - Hybrid Join a leading cyber security services organisation as a Senior SOC Engineer , taking ownership of the technology, automation, and engineering capabilities that support a modern Security Operations Centre (SOC). The Role You'll design, deploy, and enhance core SOC platforms including SIEM, XDR, SOAR, automation, and security tooling , driving improvements in threat detection, response, and operational efficiency. Working closely with operational teams, you'll support customer onboarding, develop automated workflows, and help shape the future direction of SOC engineering. Key Responsibilities Design, deploy and optimise SIEM, XDR and SOAR platforms. Build security automation, integrations, and response workflows. Develop log parsing, data normalisation and telemetry solutions. Lead technical onboarding and implementation projects. Act as an escalation point for complex security engineering issues. Mentor SOC analysts and engineers. Improve detection, response and operational processes through automation. Maintain engineering documentation, standards and best practices. Skills & Experience 3-5+ years' experience within a SOC or cyber security engineering environment. Strong experience with SIEM, SOAR and EDR/XDR technologies. Scripting and automation expertise (Python, Go, APIs). Experience with cloud platforms such as Azure, AWS or GCP. Knowledge of vulnerability management and threat intelligence integrations. Strong communication, analytical and problem-solving skills. Eligibility for UK security clearance desirable. What's on Offer 2 Days in the Office Per Month Exposure to a wide range of security environments and technologies. Opportunity to influence SOC strategy and engineering direction. Dedicated training, development, and lab environments. Competitive salary and comprehensive benefits package. Ideal for an experienced SOC Engineer looking to step into a senior, technically focused role with significant ownership, automation responsibilities, and career progression opportunities.
Jul 31, 2026
Full time
Senior SOC Engineer - Hybrid Join a leading cyber security services organisation as a Senior SOC Engineer , taking ownership of the technology, automation, and engineering capabilities that support a modern Security Operations Centre (SOC). The Role You'll design, deploy, and enhance core SOC platforms including SIEM, XDR, SOAR, automation, and security tooling , driving improvements in threat detection, response, and operational efficiency. Working closely with operational teams, you'll support customer onboarding, develop automated workflows, and help shape the future direction of SOC engineering. Key Responsibilities Design, deploy and optimise SIEM, XDR and SOAR platforms. Build security automation, integrations, and response workflows. Develop log parsing, data normalisation and telemetry solutions. Lead technical onboarding and implementation projects. Act as an escalation point for complex security engineering issues. Mentor SOC analysts and engineers. Improve detection, response and operational processes through automation. Maintain engineering documentation, standards and best practices. Skills & Experience 3-5+ years' experience within a SOC or cyber security engineering environment. Strong experience with SIEM, SOAR and EDR/XDR technologies. Scripting and automation expertise (Python, Go, APIs). Experience with cloud platforms such as Azure, AWS or GCP. Knowledge of vulnerability management and threat intelligence integrations. Strong communication, analytical and problem-solving skills. Eligibility for UK security clearance desirable. What's on Offer 2 Days in the Office Per Month Exposure to a wide range of security environments and technologies. Opportunity to influence SOC strategy and engineering direction. Dedicated training, development, and lab environments. Competitive salary and comprehensive benefits package. Ideal for an experienced SOC Engineer looking to step into a senior, technically focused role with significant ownership, automation responsibilities, and career progression opportunities.
Information Vulnerability Analyst - Staffordshire Our client is looking for an Information Vulnerability Analyst to join their growing Information Security team. This is a key role focused on identifying, assessing, and mitigating security vulnerabilities across IT, OT, cloud, and SaaS environments. You will work closely with infrastructure, applications, and operations teams to ensure that risks are effectively managed and remediated. This position is ideal for someone who is proactive rather than reactive someone who enjoys identifying vulnerabilities before they become issues and takes ownership of driving them through to resolution. We are looking for a hands-on individual who thrives in a collaborative environment. You will work closely with service desk, networking, and infrastructure teams, influencing stakeholders and ensuring a joined-up approach to vulnerability management across the organisation. Key Responsibilities Manage the global vulnerability management process and associated platforms Perform regular vulnerability scans across IT, OT, and SaaS environments using industry-standard tools Coordinate and manage third-party security penetration testing across internal and external systems Analyse scan results, prioritise vulnerabilities, and drive remediation through to completion Maintain and enhance vulnerability management processes and reporting frameworks Contribute to the risk register and support ongoing security improvements Track remediation progress and report on risk posture to senior stakeholders Work closely with IT and engineering teams to ensure secure configurations and effective patch management Identify root causes of vulnerabilities and support long-term solutions Support compliance with frameworks such as NIST and Cyber Essentials Assist with threat modelling and risk assessments Maintain documentation, procedures, and security best practices Proactively identify opportunities to strengthen the organisation s overall security posture This is a fantastic opportunity to make a real impact in a business that values proactive security and continuous improvement. If this sounds like the right next step in your career, we d love to hear from you. This is an onsite position with opportunities for progression and development. For more info, please get in touch.
Jul 31, 2026
Full time
Information Vulnerability Analyst - Staffordshire Our client is looking for an Information Vulnerability Analyst to join their growing Information Security team. This is a key role focused on identifying, assessing, and mitigating security vulnerabilities across IT, OT, cloud, and SaaS environments. You will work closely with infrastructure, applications, and operations teams to ensure that risks are effectively managed and remediated. This position is ideal for someone who is proactive rather than reactive someone who enjoys identifying vulnerabilities before they become issues and takes ownership of driving them through to resolution. We are looking for a hands-on individual who thrives in a collaborative environment. You will work closely with service desk, networking, and infrastructure teams, influencing stakeholders and ensuring a joined-up approach to vulnerability management across the organisation. Key Responsibilities Manage the global vulnerability management process and associated platforms Perform regular vulnerability scans across IT, OT, and SaaS environments using industry-standard tools Coordinate and manage third-party security penetration testing across internal and external systems Analyse scan results, prioritise vulnerabilities, and drive remediation through to completion Maintain and enhance vulnerability management processes and reporting frameworks Contribute to the risk register and support ongoing security improvements Track remediation progress and report on risk posture to senior stakeholders Work closely with IT and engineering teams to ensure secure configurations and effective patch management Identify root causes of vulnerabilities and support long-term solutions Support compliance with frameworks such as NIST and Cyber Essentials Assist with threat modelling and risk assessments Maintain documentation, procedures, and security best practices Proactively identify opportunities to strengthen the organisation s overall security posture This is a fantastic opportunity to make a real impact in a business that values proactive security and continuous improvement. If this sounds like the right next step in your career, we d love to hear from you. This is an onsite position with opportunities for progression and development. For more info, please get in touch.
Duty Manager / SOC Analyst (DV Cleared) Location: Hounslow Park (On-site) Salary: 65,000 + 10,000 Bonus Employment Type: Permanent Security Clearance: Must hold current MOD DV Clearance Nationality Requirement: Sole UK Nationals only Overview We are seeking an experienced Duty Manager / SOC Analyst to join a high-profile operational environment, supporting critical services within a secure, live operations centre. This is a unique hybrid position that combines operational leadership with technical awareness . You'll take ownership of the live operational picture, coordinating incident response across cyber, network, infrastructure and physical security teams while ensuring informed, timely decision-making. This role is ideal for someone who thrives in a fast-paced control room environment and can confidently lead operational response without needing to be a deep technical specialist. Key Responsibilities Maintain a single operational view across cyber, network, service and physical security domains. Monitor live operational environments and assess alerts and incidents in real time. Perform initial triage and validation of alerts, reducing noise and ensuring accurate incident classification. Control incident prioritisation and escalation in line with operational procedures. Coordinate activities across SOC, NOC, Infrastructure and Security teams. Support and lead Major Incident Management activities where required. Maintain accurate operational logs, dashboards and reporting. Deliver effective shift handovers and maintain continuous situational awareness. About the Role This position is intentionally balanced between operational leadership and technical understanding: 60% Operational Leadership & Coordination 40% Technical Awareness & Incident Triage You'll be expected to understand operational and technical information, ask the right questions, coordinate the right teams and maintain control during high-pressure situations. Essential Skills & Experience Experience within a SOC, NOC, Major Incident Management or 24/7 Operations Centre . Good understanding of SOC and NOC workflows, including alert triage and escalation processes. Ability to interpret monitoring alerts, operational dashboards and logs at a high level. Strong understanding of incident severity, business impact and prioritisation. Proven experience coordinating multiple technical teams during live incidents. Excellent communication, decision-making and stakeholder management skills. Ability to remain calm and organised in time-critical operational environments. Ideal Background We would particularly welcome applications from candidates with experience as: Major Incident Manager with technical exposure. Senior SOC Analyst or NOC Analyst with leadership responsibilities. Service Operations Lead within a 24/7 operations or command centre. Operational Duty Manager supporting secure or critical environments. What's on Offer 65,000 basic salary. 10,000 annual bonus. Permanent position. Opportunity to work within a highly secure, mission-critical environment. Challenging and rewarding operational leadership role with significant responsibility. Eligibility Requirements Due to the nature of this position, applicants must : Hold current MOD Developed Vetting (DV) Clearance . Be a sole UK national . Be able to work full-time on-site in Hounslow Park .
Jul 31, 2026
Full time
Duty Manager / SOC Analyst (DV Cleared) Location: Hounslow Park (On-site) Salary: 65,000 + 10,000 Bonus Employment Type: Permanent Security Clearance: Must hold current MOD DV Clearance Nationality Requirement: Sole UK Nationals only Overview We are seeking an experienced Duty Manager / SOC Analyst to join a high-profile operational environment, supporting critical services within a secure, live operations centre. This is a unique hybrid position that combines operational leadership with technical awareness . You'll take ownership of the live operational picture, coordinating incident response across cyber, network, infrastructure and physical security teams while ensuring informed, timely decision-making. This role is ideal for someone who thrives in a fast-paced control room environment and can confidently lead operational response without needing to be a deep technical specialist. Key Responsibilities Maintain a single operational view across cyber, network, service and physical security domains. Monitor live operational environments and assess alerts and incidents in real time. Perform initial triage and validation of alerts, reducing noise and ensuring accurate incident classification. Control incident prioritisation and escalation in line with operational procedures. Coordinate activities across SOC, NOC, Infrastructure and Security teams. Support and lead Major Incident Management activities where required. Maintain accurate operational logs, dashboards and reporting. Deliver effective shift handovers and maintain continuous situational awareness. About the Role This position is intentionally balanced between operational leadership and technical understanding: 60% Operational Leadership & Coordination 40% Technical Awareness & Incident Triage You'll be expected to understand operational and technical information, ask the right questions, coordinate the right teams and maintain control during high-pressure situations. Essential Skills & Experience Experience within a SOC, NOC, Major Incident Management or 24/7 Operations Centre . Good understanding of SOC and NOC workflows, including alert triage and escalation processes. Ability to interpret monitoring alerts, operational dashboards and logs at a high level. Strong understanding of incident severity, business impact and prioritisation. Proven experience coordinating multiple technical teams during live incidents. Excellent communication, decision-making and stakeholder management skills. Ability to remain calm and organised in time-critical operational environments. Ideal Background We would particularly welcome applications from candidates with experience as: Major Incident Manager with technical exposure. Senior SOC Analyst or NOC Analyst with leadership responsibilities. Service Operations Lead within a 24/7 operations or command centre. Operational Duty Manager supporting secure or critical environments. What's on Offer 65,000 basic salary. 10,000 annual bonus. Permanent position. Opportunity to work within a highly secure, mission-critical environment. Challenging and rewarding operational leadership role with significant responsibility. Eligibility Requirements Due to the nature of this position, applicants must : Hold current MOD Developed Vetting (DV) Clearance . Be a sole UK national . Be able to work full-time on-site in Hounslow Park .