• Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
  • Sign in
  • Sign up
  • Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

69 jobs found

Email me jobs like this
Refine Search
Current Search
cyber threat and vulnerability management lead
Government Digital & Data
Head of Cyber Security Risk Management (Digital Identity) - Government Digital Service - G6
Government Digital & Data
Location Bristol, London, Manchester About the job Job summary This role will require the post holder to have SC clearance to start and may be required to undergo Developed Vetting (DV) once in post, therefore successful candidates will be expected to either hold this or be willing to undertake the DV clearance process once in post. More information on DV clearance is linked here The Government Digital Service (GDS) is the digital centre of government. We are responsible for setting, leading and delivering the vision for a modern digital government. Our priorities are to drive a modern digital government, by: joining up public sector services harnessing the power of AI for the public good strengthening and extending our digital and data public infrastructure elevating leadership and investing in talent funding for outcomes andprocuringfor growth and innovation committing to transparency and driving accountability We are home to the Incubator for Artificial Intelligence (I.AI), the world-leading GOV.UK and at the forefront of coordinating the UK's geospatial strategy and activity. We lead the Government Digital and Data function and champion the work of digital teams across government. We're part of the Department for Science, Innovation and Technology (DSIT) and employ more than 1,000 people all over the UK, with hubs in Manchester, London and Bristol. The Government Digital Service is where talent translates into impact. From your first day, you'll be working with some of the world's most highly-skilled digital professionals, all contributing their knowledge to make change on a national scale. Join us for rewarding work that makes a difference across the UK. You'll solve some of the nation's highest-priority digital challenges, helping millions of people access services they need Job description As Head of Cyber Security Risk Management for One Login and Digital Identity you will play a central role in protecting the UK's current and future digital identity ecosystem. At scale, One Login will be the front door for millions of users to access digital public services. Security, reliability and resilience are absolutely critical to delivering our mission. This is a high profile role, suited to an experienced security leader with a track record of setting direction and running security risk, governance and assurance for a complex area. As Head of Cyber Security Risk Management you will have oversight for the Digital Identity Cyber Information Assurance team, taking responsibility for the governance, risk management, compliance and 3rd party assurance. In addition, you will be responsible for: governance, risk and assurance leadership: building civil servant capability to run a mature, responsive cyber assurance team, working in collaboration with One Logins dedicated Security Operations, Security Design & Architecture, Pods (developer teams) and wider GDS and DSIT cyber teams. Work in partnership with GDS (Privacy, Information Assurance, Security Architecture, Cyber), GSG, CDIO Cyber, NCSC and other government departments governance, risk and assurance: lead design, implementation and operating of information security governance frameworks aligned to DSIT and regulatory context. Ensure the team provides independent information assurance across the One Login Programme but work closely with the GDS Infosec team for second line assurance. Build and lead the third party and supply chain assurance strategy. Maintain and innovate the current risk management board ensuring present risk positions are clearly communicated to the senior leadership team (SLT). multi tier assurance: work closely with the GDS Infosec Team to support 2nd line assurance. Build and manage an integrated governance process which has a unified risk perspective enabling both first and second line assurance to work on a common understanding of the risk posture. Drive proactive engagement across both teams to stop any siloed forming and make sure the risk development lifecycle is balanced. policy & standards: develop and maintain security policies, standards frameworks, and governance processes aligned to government and industry best practice for complex cloud-native environments assurance & remediation: drive security assurance activities across One Login programmes, suppliers, and operational services, including audits, assessments, and ensuring timely remediation within required SLOs stakeholder collaboration: build strong relationships with key stakeholders-including GDS (Privacy, Information Assurance, Security Architecture), GSG, CDIO Cyber, and NCSC-to embed security into delivery, architecture, procurement, and operational decision making compliance & frameworks: ensure all operations meet stringent UK Government security requirements by supporting regulatory and contractual compliance activities, including alignment to standards such as NIST, CAF, and GovAssure governance & reporting: establish and maintain operational metrics to produce clear, meaningful reporting and dashboards that measure the programme's threat posture and support executive decision making security culture leadership : working in close collaboration with the Head of Product Security and Head of Security Operations for One Login and the GDS CISO, take responsibility for embedding a robust security culture across the programme. Person specification We're interested in people who have experience and knowledge of most of the following: a strong track record of experience leading security governance, assurance, risk, or compliance functions, ideally for a Critical National Infrastructure (CNI) or comparable risk/profile/impact level product in-depth knowledge of government security standards, frameworks, and assurance approaches, with demonstrable success applying frameworks such as CAF, NIST 800-53, GovAssure, and Secure by Design Principles experience developing and implementing security policies and control frameworks in complex cloud-native environments and serverless architectures ability to communicate complex security concepts clearly and establish effective working relationships with key security stakeholders, including technical and non-technical specialists across organisational boundaries strong analytical, reporting, and risk management capabilities, including building governance dashboards and executive-level assurance reporting understanding of supplier assurance, vulnerability management, and experience integrating governance with security operational integration. hold recognised cyber security certifications such as CISSP, CISM, or CRISC
Aug 24, 2026
Full time
Location Bristol, London, Manchester About the job Job summary This role will require the post holder to have SC clearance to start and may be required to undergo Developed Vetting (DV) once in post, therefore successful candidates will be expected to either hold this or be willing to undertake the DV clearance process once in post. More information on DV clearance is linked here The Government Digital Service (GDS) is the digital centre of government. We are responsible for setting, leading and delivering the vision for a modern digital government. Our priorities are to drive a modern digital government, by: joining up public sector services harnessing the power of AI for the public good strengthening and extending our digital and data public infrastructure elevating leadership and investing in talent funding for outcomes andprocuringfor growth and innovation committing to transparency and driving accountability We are home to the Incubator for Artificial Intelligence (I.AI), the world-leading GOV.UK and at the forefront of coordinating the UK's geospatial strategy and activity. We lead the Government Digital and Data function and champion the work of digital teams across government. We're part of the Department for Science, Innovation and Technology (DSIT) and employ more than 1,000 people all over the UK, with hubs in Manchester, London and Bristol. The Government Digital Service is where talent translates into impact. From your first day, you'll be working with some of the world's most highly-skilled digital professionals, all contributing their knowledge to make change on a national scale. Join us for rewarding work that makes a difference across the UK. You'll solve some of the nation's highest-priority digital challenges, helping millions of people access services they need Job description As Head of Cyber Security Risk Management for One Login and Digital Identity you will play a central role in protecting the UK's current and future digital identity ecosystem. At scale, One Login will be the front door for millions of users to access digital public services. Security, reliability and resilience are absolutely critical to delivering our mission. This is a high profile role, suited to an experienced security leader with a track record of setting direction and running security risk, governance and assurance for a complex area. As Head of Cyber Security Risk Management you will have oversight for the Digital Identity Cyber Information Assurance team, taking responsibility for the governance, risk management, compliance and 3rd party assurance. In addition, you will be responsible for: governance, risk and assurance leadership: building civil servant capability to run a mature, responsive cyber assurance team, working in collaboration with One Logins dedicated Security Operations, Security Design & Architecture, Pods (developer teams) and wider GDS and DSIT cyber teams. Work in partnership with GDS (Privacy, Information Assurance, Security Architecture, Cyber), GSG, CDIO Cyber, NCSC and other government departments governance, risk and assurance: lead design, implementation and operating of information security governance frameworks aligned to DSIT and regulatory context. Ensure the team provides independent information assurance across the One Login Programme but work closely with the GDS Infosec team for second line assurance. Build and lead the third party and supply chain assurance strategy. Maintain and innovate the current risk management board ensuring present risk positions are clearly communicated to the senior leadership team (SLT). multi tier assurance: work closely with the GDS Infosec Team to support 2nd line assurance. Build and manage an integrated governance process which has a unified risk perspective enabling both first and second line assurance to work on a common understanding of the risk posture. Drive proactive engagement across both teams to stop any siloed forming and make sure the risk development lifecycle is balanced. policy & standards: develop and maintain security policies, standards frameworks, and governance processes aligned to government and industry best practice for complex cloud-native environments assurance & remediation: drive security assurance activities across One Login programmes, suppliers, and operational services, including audits, assessments, and ensuring timely remediation within required SLOs stakeholder collaboration: build strong relationships with key stakeholders-including GDS (Privacy, Information Assurance, Security Architecture), GSG, CDIO Cyber, and NCSC-to embed security into delivery, architecture, procurement, and operational decision making compliance & frameworks: ensure all operations meet stringent UK Government security requirements by supporting regulatory and contractual compliance activities, including alignment to standards such as NIST, CAF, and GovAssure governance & reporting: establish and maintain operational metrics to produce clear, meaningful reporting and dashboards that measure the programme's threat posture and support executive decision making security culture leadership : working in close collaboration with the Head of Product Security and Head of Security Operations for One Login and the GDS CISO, take responsibility for embedding a robust security culture across the programme. Person specification We're interested in people who have experience and knowledge of most of the following: a strong track record of experience leading security governance, assurance, risk, or compliance functions, ideally for a Critical National Infrastructure (CNI) or comparable risk/profile/impact level product in-depth knowledge of government security standards, frameworks, and assurance approaches, with demonstrable success applying frameworks such as CAF, NIST 800-53, GovAssure, and Secure by Design Principles experience developing and implementing security policies and control frameworks in complex cloud-native environments and serverless architectures ability to communicate complex security concepts clearly and establish effective working relationships with key security stakeholders, including technical and non-technical specialists across organisational boundaries strong analytical, reporting, and risk management capabilities, including building governance dashboards and executive-level assurance reporting understanding of supplier assurance, vulnerability management, and experience integrating governance with security operational integration. hold recognised cyber security certifications such as CISSP, CISM, or CRISC
Yolk Recruitment
Cyber Security Analyst
Yolk Recruitment
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Aug 23, 2026
Full time
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Rebel Recruitment Limited
Cyber Assurance Consultant
Rebel Recruitment Limited Nottingham, Nottinghamshire
Role: Cyber and Information Assurance Consultant Mid, Senior & Principal Levels Location: Nottingham / Remote-first Working Arrangement: Remote-first, with travel to Nottingham and customer sites as required Salary: £65,000 £120,000 Are you a cyber security or information assurance professional who enjoys working with customers, getting into complex problems and turning security risks into practical solutions? We re looking for Cyber and Information Assurance Consultants across Mid, Senior and Principal levels to join a growing team working on complex, high-assurance environments across defence, government and critical infrastructure. This is a consultancy-focused role, so you won t be sitting in a purely internal security position. You ll work directly with customers, technical teams and senior stakeholders to assess risk, understand threats and vulnerabilities, and provide clear recommendations on how security can be improved. You ll work across areas including cyber risk assessments, information assurance, security governance and secure-by-design. Depending on your level and experience, you could be reviewing solution designs, developing security cases, supporting accreditation and assurance activity, maintaining risk registers or helping shape security requirements across major programmes. You ll also work closely with architects, engineers, project teams, suppliers and customer security teams. A big part of the role will be taking technical evidence and security requirements and explaining what they actually mean from a risk and business perspective. You ll ideally have professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline, alongside experience contributing to security assessment or assurance work. You ll need to be comfortable producing clear security documentation and communicating with both technical and non-technical audiences. Knowledge of areas such as cyber risk management, security controls, threat and vulnerability assessment, security governance and risk acceptance is important. Experience with frameworks such as ISO 27001, ISO 27005, the NCSC Cyber Assessment Framework, NIST or MOD security standards would be beneficial. Experience within defence, government, critical infrastructure or another high-assurance environment would be particularly relevant. Experience with cloud security assurance, security architecture reviews, accreditation or secure information exchange would also be useful. The level you join at will depend on your experience, with opportunities available from Mid-level through to Principal. There is a clear progression route into senior consultancy, security architecture, cyber risk leadership and information assurance leadership, with support towards professional qualifications such as CISSP, CISM, CRISC and ISO 27001. The role is remote-first, although you ll need to be comfortable travelling to the Nottingham office and customer sites when required. Regular UK travel may form part of the role, with occasional international travel possible. If you re looking for a role where you can work on genuinely complex security challenges, have direct customer exposure and continue developing your career across cyber security and assurance, please apply now or get in touch to find out more. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Aug 23, 2026
Full time
Role: Cyber and Information Assurance Consultant Mid, Senior & Principal Levels Location: Nottingham / Remote-first Working Arrangement: Remote-first, with travel to Nottingham and customer sites as required Salary: £65,000 £120,000 Are you a cyber security or information assurance professional who enjoys working with customers, getting into complex problems and turning security risks into practical solutions? We re looking for Cyber and Information Assurance Consultants across Mid, Senior and Principal levels to join a growing team working on complex, high-assurance environments across defence, government and critical infrastructure. This is a consultancy-focused role, so you won t be sitting in a purely internal security position. You ll work directly with customers, technical teams and senior stakeholders to assess risk, understand threats and vulnerabilities, and provide clear recommendations on how security can be improved. You ll work across areas including cyber risk assessments, information assurance, security governance and secure-by-design. Depending on your level and experience, you could be reviewing solution designs, developing security cases, supporting accreditation and assurance activity, maintaining risk registers or helping shape security requirements across major programmes. You ll also work closely with architects, engineers, project teams, suppliers and customer security teams. A big part of the role will be taking technical evidence and security requirements and explaining what they actually mean from a risk and business perspective. You ll ideally have professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline, alongside experience contributing to security assessment or assurance work. You ll need to be comfortable producing clear security documentation and communicating with both technical and non-technical audiences. Knowledge of areas such as cyber risk management, security controls, threat and vulnerability assessment, security governance and risk acceptance is important. Experience with frameworks such as ISO 27001, ISO 27005, the NCSC Cyber Assessment Framework, NIST or MOD security standards would be beneficial. Experience within defence, government, critical infrastructure or another high-assurance environment would be particularly relevant. Experience with cloud security assurance, security architecture reviews, accreditation or secure information exchange would also be useful. The level you join at will depend on your experience, with opportunities available from Mid-level through to Principal. There is a clear progression route into senior consultancy, security architecture, cyber risk leadership and information assurance leadership, with support towards professional qualifications such as CISSP, CISM, CRISC and ISO 27001. The role is remote-first, although you ll need to be comfortable travelling to the Nottingham office and customer sites when required. Regular UK travel may form part of the role, with occasional international travel possible. If you re looking for a role where you can work on genuinely complex security challenges, have direct customer exposure and continue developing your career across cyber security and assurance, please apply now or get in touch to find out more. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Lead Software Security Engineer
United States Digital Space LLC
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Aug 23, 2026
Full time
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Comtecs Ltd
Cyber Security Engineer - MS Sentinel, Defender, SSO, PKI, SC-100/200, CISSP
Comtecs Ltd
IT Cyber Security Specialist / Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team, supporting and continually improving cybersecurity across a global IT environment. Reporting to the Infrastructure Engineering Manager, you'll take ownership of cybersecurity controls and security architecture while working closely with Infrastructure Operations and other technology teams to identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across a complex infrastructure environment, identifying and mitigating security risks, supporting major cyber incidents and contributing to strategic security and infrastructure projects. You'll also help develop security awareness, business continuity capabilities and ongoing improvements to the firm's security controls. Key Responsibilities: Continuously review and improve the firm's cybersecurity posture from an infrastructure perspective and external security rating. Identify, assess and remediate vulnerabilities across hardware, software and infrastructure (Windows Server and Azure Cloud). Monitor emerging threats and lead or support Incident Response investigations and mitigation. Evaluate, test and recommend security enhancements, controls and threat prevention technologies. Identify security risks and exposures and develop measures to prevent future incidents. Lead CE+ accreditation and support security, risk and data protection requirements from a technical (Not GRC) perspective. Participate in and lead infrastructure lifecycle, security and technology projects. Provide 3rd Line / Major Incident support as a cybersecurity subject matter expert. Work with third-party suppliers and advise internal technical teams on security measures to resolve security and infrastructure issues. We're looking for experienced Cyber Security engineer with strong technical infrastructure knowledge and proven experience across incident response, threat monitoring and vulnerability management. You will possess: Extensive experience in a similar role blending Cyber Security with core Wintel Infrastructure and Azure cloud engineering. Strong knowledge of modern security architecture, threat prevention techniques and incident response. Strong Windows Server 2016/2019/2022 knowledge including Active Directory, DNS, DHCP, Intune, Group Policy, PKI, Entra and Azure SSO. Demonstrable experience across Cyber Security, Incident Response, Threat Monitoring and Vulnerability Management using tools such as MS Sentinel, MS Defender etc for threat hunting, vulnerability monitoring and security posture improvement. CISSP, CEH, CCNA Security, SC-100, SC200 or equivalent security certification. Experience designing, integrating and managing complex infrastructure and cloud solutions from a cyber security standpoint and advising technical infrastructure teams on security focussed designs and operations Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. Experience working with third-party providers across on-premise and cloud services. Strong planning skills and knowledge of ITIL processes and best practice. This is an excellent opportunity to join a highly regarded global organisation where you'll play a key role in strengthening cybersecurity across a complex international IT environment, combining hands-on security engineering, incident response and strategic infrastructure projects.
Aug 22, 2026
Full time
IT Cyber Security Specialist / Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team, supporting and continually improving cybersecurity across a global IT environment. Reporting to the Infrastructure Engineering Manager, you'll take ownership of cybersecurity controls and security architecture while working closely with Infrastructure Operations and other technology teams to identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across a complex infrastructure environment, identifying and mitigating security risks, supporting major cyber incidents and contributing to strategic security and infrastructure projects. You'll also help develop security awareness, business continuity capabilities and ongoing improvements to the firm's security controls. Key Responsibilities: Continuously review and improve the firm's cybersecurity posture from an infrastructure perspective and external security rating. Identify, assess and remediate vulnerabilities across hardware, software and infrastructure (Windows Server and Azure Cloud). Monitor emerging threats and lead or support Incident Response investigations and mitigation. Evaluate, test and recommend security enhancements, controls and threat prevention technologies. Identify security risks and exposures and develop measures to prevent future incidents. Lead CE+ accreditation and support security, risk and data protection requirements from a technical (Not GRC) perspective. Participate in and lead infrastructure lifecycle, security and technology projects. Provide 3rd Line / Major Incident support as a cybersecurity subject matter expert. Work with third-party suppliers and advise internal technical teams on security measures to resolve security and infrastructure issues. We're looking for experienced Cyber Security engineer with strong technical infrastructure knowledge and proven experience across incident response, threat monitoring and vulnerability management. You will possess: Extensive experience in a similar role blending Cyber Security with core Wintel Infrastructure and Azure cloud engineering. Strong knowledge of modern security architecture, threat prevention techniques and incident response. Strong Windows Server 2016/2019/2022 knowledge including Active Directory, DNS, DHCP, Intune, Group Policy, PKI, Entra and Azure SSO. Demonstrable experience across Cyber Security, Incident Response, Threat Monitoring and Vulnerability Management using tools such as MS Sentinel, MS Defender etc for threat hunting, vulnerability monitoring and security posture improvement. CISSP, CEH, CCNA Security, SC-100, SC200 or equivalent security certification. Experience designing, integrating and managing complex infrastructure and cloud solutions from a cyber security standpoint and advising technical infrastructure teams on security focussed designs and operations Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. Experience working with third-party providers across on-premise and cloud services. Strong planning skills and knowledge of ITIL processes and best practice. This is an excellent opportunity to join a highly regarded global organisation where you'll play a key role in strengthening cybersecurity across a complex international IT environment, combining hands-on security engineering, incident response and strategic infrastructure projects.
Cyber Security Lead
慨正橡扯
Primary Details Time Type: Full time Worker Type: Employee Cyber Security Lead Location: London Type: Permanent, full time Hybrid role, happy to talk flexible working The Opportunity QBE Europe is recruiting a Cyber Security Lead to join our European Cyber Security team in our London office. The role has accountability across operational delivery and advisory capabilities within QBE's cyber services and value streams, with the opportunity to drive continuous improvement and transformational change in the way Cyber and information security risk is considered and mitigated across the core business, our programs and projects. The role works to make QBE safe, secure and resilient; working to continuously out pace and outsmart cyber threat faced by our business. This intellectually challenging and highly influential role is part of an enterprise wide Cyber Security capability, accountable for safeguarding QBE from increasingly sophisticated Cyber and information security threats. This is a highly collaborative role, requiring a sustained level of curiosity and a continuous ability to grow deep technical knowledge that translates into insight to solve root cause problems and supports strategic business outcomes. Having the right to work in the UK is a requirement for this role. QBE may consider sponsorship at its discretion. About QBE At QBE, we get to the heart of what matters for our customers. And we do it all with a human touch. We're an international insurer with more than 13,000 people working across 26 countries - which means we're big enough for your ambitions, yet small enough for you to make a real impact. It's an exciting time. We're building momentum towards our vision to become the most consistent and innovative risk partner. What if you could have a positive impact - at work and in the world? As part of the QBE team, you'll get to spend every day working with people who are passionate, talented and kind. Your new role Deliver an effective cyber and information security capability across QBE, partnering to deliver appropriate levels of engagement and risk mitigation. Develop the cyber and information security experience across QBE, building awareness and engendering healthy curiosity. Build strong collaborative relationships, providing advice and working together to identify and solve root cause problems; demonstrating great tenacity in reducing potential threats and risks. Take personal accountability for seeking out and identifying security weaknesses; seeing mitigation through to a secure conclusion. Drive Cyber engagement across QBE to ensure issues are identified, self reported and notified to key stakeholders. Act with integrity and transparency in threat and risk identification and problem solving. Role model the creation, innovation and negotiation of solutions and risk mitigation strategies; driving fast paced and agile behaviours. Drive the development, execution and assurance of an effective Cyber practice; including the adoption of relevant policy, standards, processes and templates. Manage and quality assure cyber service and outsourced security arrangements; ensuring delivery to SLAs, quality controls and alignment with QBE requirements. Drive collaboration and partnership across the QBE business value streams. Track compliance and security benefits to demonstrate impact and mitigation success. About You Demonstrates exceptional resilience and tenacity in managing and mitigating 24x7 cyber threats whilst successfully managing work life balance. Solution oriented. Problem solving mindset with the ability to see solutions through to delivery. Demonstrable ability to support the development of QBE cyber services and talent, building technical excellence and decision making confidence. Insightful and expert ability to consider where and how people or technology could be exploited; getting into the mindset of an adversary. Exceptional ability to get deeply technical and apply that skill to the business environment. Expertise in one or more of the following areas: Identity and Access Management, Data Security, Threat and Vulnerability Management, Third Party Risk, Cyber Security Infrastructure and Cyber Security Operations. Strong decision making ability when faced with complex and business critical threats. Excellent communication, negotiation and conflict management skills, with an ability to anticipate and pre empt potential obstacles; strong listening skills. Good ability to write and articulate, summarise and present complex problems and messages in a succinct and comprehensible manner. Exceptionally curious and enquiring mindset with a fast paced and agile personal drive to meet business needs. Benefits 30 days holiday a year with the option to buy up to 2 additional days. Flexible working - balancing work and life is important so our flexible working opportunities are open to all, including part time, job share and compressed hours. Pension - you are automatically enrolled into the QBE pension plan, which entitles you to receive employer contributions of 10% of your basic salary. Equal Employment Opportunity: QBE is an equal opportunity employer and is required to comply with equal employment opportunity legislation in each jurisdiction it operates. Application Close Date: 12/06/:59 PM
Aug 21, 2026
Full time
Primary Details Time Type: Full time Worker Type: Employee Cyber Security Lead Location: London Type: Permanent, full time Hybrid role, happy to talk flexible working The Opportunity QBE Europe is recruiting a Cyber Security Lead to join our European Cyber Security team in our London office. The role has accountability across operational delivery and advisory capabilities within QBE's cyber services and value streams, with the opportunity to drive continuous improvement and transformational change in the way Cyber and information security risk is considered and mitigated across the core business, our programs and projects. The role works to make QBE safe, secure and resilient; working to continuously out pace and outsmart cyber threat faced by our business. This intellectually challenging and highly influential role is part of an enterprise wide Cyber Security capability, accountable for safeguarding QBE from increasingly sophisticated Cyber and information security threats. This is a highly collaborative role, requiring a sustained level of curiosity and a continuous ability to grow deep technical knowledge that translates into insight to solve root cause problems and supports strategic business outcomes. Having the right to work in the UK is a requirement for this role. QBE may consider sponsorship at its discretion. About QBE At QBE, we get to the heart of what matters for our customers. And we do it all with a human touch. We're an international insurer with more than 13,000 people working across 26 countries - which means we're big enough for your ambitions, yet small enough for you to make a real impact. It's an exciting time. We're building momentum towards our vision to become the most consistent and innovative risk partner. What if you could have a positive impact - at work and in the world? As part of the QBE team, you'll get to spend every day working with people who are passionate, talented and kind. Your new role Deliver an effective cyber and information security capability across QBE, partnering to deliver appropriate levels of engagement and risk mitigation. Develop the cyber and information security experience across QBE, building awareness and engendering healthy curiosity. Build strong collaborative relationships, providing advice and working together to identify and solve root cause problems; demonstrating great tenacity in reducing potential threats and risks. Take personal accountability for seeking out and identifying security weaknesses; seeing mitigation through to a secure conclusion. Drive Cyber engagement across QBE to ensure issues are identified, self reported and notified to key stakeholders. Act with integrity and transparency in threat and risk identification and problem solving. Role model the creation, innovation and negotiation of solutions and risk mitigation strategies; driving fast paced and agile behaviours. Drive the development, execution and assurance of an effective Cyber practice; including the adoption of relevant policy, standards, processes and templates. Manage and quality assure cyber service and outsourced security arrangements; ensuring delivery to SLAs, quality controls and alignment with QBE requirements. Drive collaboration and partnership across the QBE business value streams. Track compliance and security benefits to demonstrate impact and mitigation success. About You Demonstrates exceptional resilience and tenacity in managing and mitigating 24x7 cyber threats whilst successfully managing work life balance. Solution oriented. Problem solving mindset with the ability to see solutions through to delivery. Demonstrable ability to support the development of QBE cyber services and talent, building technical excellence and decision making confidence. Insightful and expert ability to consider where and how people or technology could be exploited; getting into the mindset of an adversary. Exceptional ability to get deeply technical and apply that skill to the business environment. Expertise in one or more of the following areas: Identity and Access Management, Data Security, Threat and Vulnerability Management, Third Party Risk, Cyber Security Infrastructure and Cyber Security Operations. Strong decision making ability when faced with complex and business critical threats. Excellent communication, negotiation and conflict management skills, with an ability to anticipate and pre empt potential obstacles; strong listening skills. Good ability to write and articulate, summarise and present complex problems and messages in a succinct and comprehensible manner. Exceptionally curious and enquiring mindset with a fast paced and agile personal drive to meet business needs. Benefits 30 days holiday a year with the option to buy up to 2 additional days. Flexible working - balancing work and life is important so our flexible working opportunities are open to all, including part time, job share and compressed hours. Pension - you are automatically enrolled into the QBE pension plan, which entitles you to receive employer contributions of 10% of your basic salary. Equal Employment Opportunity: QBE is an equal opportunity employer and is required to comply with equal employment opportunity legislation in each jurisdiction it operates. Application Close Date: 12/06/:59 PM
Standard 8
Information Security Manager - Cyber
Standard 8 Guildford, Surrey
Standard 8 is supporting a space agency looking to appoint an IT Security Manager to lead its internal security capability. You'll manage a small team, shape security strategy and remain hands-on where it matters, helping protect a complex technology estate spanning infrastructure, cloud platforms and business-critical systems. You'll take ownership of security across the organisation, working closely with technical teams and senior stakeholders to improve security posture, manage risk and drive continuous improvement. Key responsibilities include: Leading and developing a small cyber security team Delivering the organisation's security roadmap and controls framework Acting as the senior escalation point for security-related issues Overseeing security operations, incident response and vulnerability management Supporting secure Azure and AWS environments Managing and optimising security tooling including SIEM, EDR and related platforms Reviewing projects, infrastructure changes and technical designs from a security perspective Driving secure-by-design principles across technology initiatives Managing third-party security providers and key supplier relationships Leading risk assessments, audit activities and compliance initiatives Maintaining incident response and business continuity capabilities Delivering security awareness and guidance across the wider business Skill required Security operations and cyber defence Azure and AWS security Enterprise infrastructure and networking Identity and access management Threat detection and incident response Vulnerability management Security governance, risk and compliance Secure development and DevSecOps practices Experience with Splunk Enterprise Security would be advantageous. Certifications such as CISSP, CISM, CCSP, CRISC, CEH, AZ-500 or AWS Security Speciality are beneficial, but practical experience and technical credibility are what matter most.
Aug 21, 2026
Full time
Standard 8 is supporting a space agency looking to appoint an IT Security Manager to lead its internal security capability. You'll manage a small team, shape security strategy and remain hands-on where it matters, helping protect a complex technology estate spanning infrastructure, cloud platforms and business-critical systems. You'll take ownership of security across the organisation, working closely with technical teams and senior stakeholders to improve security posture, manage risk and drive continuous improvement. Key responsibilities include: Leading and developing a small cyber security team Delivering the organisation's security roadmap and controls framework Acting as the senior escalation point for security-related issues Overseeing security operations, incident response and vulnerability management Supporting secure Azure and AWS environments Managing and optimising security tooling including SIEM, EDR and related platforms Reviewing projects, infrastructure changes and technical designs from a security perspective Driving secure-by-design principles across technology initiatives Managing third-party security providers and key supplier relationships Leading risk assessments, audit activities and compliance initiatives Maintaining incident response and business continuity capabilities Delivering security awareness and guidance across the wider business Skill required Security operations and cyber defence Azure and AWS security Enterprise infrastructure and networking Identity and access management Threat detection and incident response Vulnerability management Security governance, risk and compliance Secure development and DevSecOps practices Experience with Splunk Enterprise Security would be advantageous. Certifications such as CISSP, CISM, CCSP, CRISC, CEH, AZ-500 or AWS Security Speciality are beneficial, but practical experience and technical credibility are what matter most.
Hays Specialist Recruitment Limited
CyberSecurity OpenSource Data Platform Solution Architect
Hays Specialist Recruitment Limited Sheffield, Yorkshire
We are working with a client who is a global leader in consulting, technology services, and digital transformation, committed to delivering positive change through technology and human collaboration. They have a Cybersecurity Sciences & Analytics (CSA) team that is currently a $50m and 150 headcount function, bringing together expertise across cybersecurity, data science, AI, software and cloud engineering, governance, and programme management. This Technical Solution Architect role is a hands-on architecture and solution design specialist within the CSA Strategy and Governance team. They shape and assure end-to-end technical designs that enable CSA's cyber analytics and engineering outcomes. They define and maintain key architecture artefacts (HLDs/LLDs, reference architectures, patterns, and ADRs). They also drive technology evaluation and standardisation across an open-source, petabyte-scale data platform. They own solution designs for custom cybersecurity applications, from requirements through to production support. Partnering with engineering, platform, and central architecture/governance teams, they run design and governance forums and influence without authority. They'll bring genuine cybersecurity expertise-threat modelling, security controls, identity and access, encryption, logging, and secure SDLC-so CSA's platforms and products can be trusted in production and stand up to regulatory scrutiny. They balance target architecture with delivery realities, collaborate across geographies, and contribute hands-on when needed, including coding. The ideal candidate will possess a strong technical background, an eagerness to learn, a keen interest in Cybersecurity, the ability to work collaboratively in a fast-paced environment, and an aptitude for picking up new tools and techniques on the job, building on existing skillsets as a foundation.In this role you will be defining and maintaining architecture artefacts, including HLDs/LLDs, reference architectures, patterns, ADRs (Architecture Decision Records), and reusable templates. Contributing to the design and evolution of a petabyte-scale data platform built on open-source technologies. Evaluate technologies and drive standardisation: assess OSS components and vendors, run PoCs, document trade-offs, and promote reusable patterns to reduce fragmentation. Own the end-to-end solution design for custom-built applications that support our client's cybersecurity ambitions. Provide architecture and design input to software engineering and platform teams to support implementation and delivery. Partner with central architecture and governance teams to ensure solutions align with the client's controls, policies, standards, and guardrails. Help ensure solutions remain compliant, operationally supportable, and within agreed cost boundaries.In order to apply for this role, you must have demonstrable experience designing, deploying, and operating big data platforms at scale. You will have hands-on experience with OSS data ecosystems (e.g., Spark, Trino, Airflow, Apache Superset, and similar technologies). You will have knowledge of cloud platforms and traditional on-premise hosting; hands-on experience with Azure, AWS and/or GCP is beneficial. You will also have proven security architecture expertise, including: Threat modelling and secure-by-design practices. IAM (RBAC/ABAC), privileged access concepts, and service-to-service authentication. Encryption in transit/at rest, key management, secrets management. Secure logging/telemetry, auditability, and evidence-driven control assurance. Secure SDLC, vulnerability management, and dependency/supply-chain risk controls. Proven experience delivering end-to-end solution designs, from requirements through to production operations and support.Please be clear that only candidates that meet the above criteria with the right to work and that are resident in the UK will be considered. No sponsorship is available. This role will involve hybrid working here in the UK at a site based in Sheffield in South Yorkshire - expected on site 3 days per week and 2 from home. More flexibility may be offered once in situ in the contract. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
Aug 21, 2026
Contractor
We are working with a client who is a global leader in consulting, technology services, and digital transformation, committed to delivering positive change through technology and human collaboration. They have a Cybersecurity Sciences & Analytics (CSA) team that is currently a $50m and 150 headcount function, bringing together expertise across cybersecurity, data science, AI, software and cloud engineering, governance, and programme management. This Technical Solution Architect role is a hands-on architecture and solution design specialist within the CSA Strategy and Governance team. They shape and assure end-to-end technical designs that enable CSA's cyber analytics and engineering outcomes. They define and maintain key architecture artefacts (HLDs/LLDs, reference architectures, patterns, and ADRs). They also drive technology evaluation and standardisation across an open-source, petabyte-scale data platform. They own solution designs for custom cybersecurity applications, from requirements through to production support. Partnering with engineering, platform, and central architecture/governance teams, they run design and governance forums and influence without authority. They'll bring genuine cybersecurity expertise-threat modelling, security controls, identity and access, encryption, logging, and secure SDLC-so CSA's platforms and products can be trusted in production and stand up to regulatory scrutiny. They balance target architecture with delivery realities, collaborate across geographies, and contribute hands-on when needed, including coding. The ideal candidate will possess a strong technical background, an eagerness to learn, a keen interest in Cybersecurity, the ability to work collaboratively in a fast-paced environment, and an aptitude for picking up new tools and techniques on the job, building on existing skillsets as a foundation.In this role you will be defining and maintaining architecture artefacts, including HLDs/LLDs, reference architectures, patterns, ADRs (Architecture Decision Records), and reusable templates. Contributing to the design and evolution of a petabyte-scale data platform built on open-source technologies. Evaluate technologies and drive standardisation: assess OSS components and vendors, run PoCs, document trade-offs, and promote reusable patterns to reduce fragmentation. Own the end-to-end solution design for custom-built applications that support our client's cybersecurity ambitions. Provide architecture and design input to software engineering and platform teams to support implementation and delivery. Partner with central architecture and governance teams to ensure solutions align with the client's controls, policies, standards, and guardrails. Help ensure solutions remain compliant, operationally supportable, and within agreed cost boundaries.In order to apply for this role, you must have demonstrable experience designing, deploying, and operating big data platforms at scale. You will have hands-on experience with OSS data ecosystems (e.g., Spark, Trino, Airflow, Apache Superset, and similar technologies). You will have knowledge of cloud platforms and traditional on-premise hosting; hands-on experience with Azure, AWS and/or GCP is beneficial. You will also have proven security architecture expertise, including: Threat modelling and secure-by-design practices. IAM (RBAC/ABAC), privileged access concepts, and service-to-service authentication. Encryption in transit/at rest, key management, secrets management. Secure logging/telemetry, auditability, and evidence-driven control assurance. Secure SDLC, vulnerability management, and dependency/supply-chain risk controls. Proven experience delivering end-to-end solution designs, from requirements through to production operations and support.Please be clear that only candidates that meet the above criteria with the right to work and that are resident in the UK will be considered. No sponsorship is available. This role will involve hybrid working here in the UK at a site based in Sheffield in South Yorkshire - expected on site 3 days per week and 2 from home. More flexibility may be offered once in situ in the contract. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
Morgan Hunt Recruitment
Cyber Security Engineer
Morgan Hunt Recruitment
Cyber Security Engineer Housing Association 12-Month FTC Up to £65,000 Hybrid - Farringdon Morgan Hunt is delighted to be partnering with a leading Housing Association to recruit an experienced Cyber Security Engineer on an initial 12-month Fixed-Term Contract .This is an excellent opportunity for a hands-on security professional to join an established cyber security function and play a key role in strengthening the organisation's security capabilities across applications, infrastructure, networks, data and cloud platforms. The Role Working closely with the Cyber Security Manager and Senior Cyber Security Engineer , you will help design, implement and maintain the organisation's cyber security capabilities.You will have a broad remit across Microsoft security technologies, identity and access management, vulnerability management, incident response, SIEM/SOAR, threat hunting and cloud security , while also providing security advice to technology projects and supporting security-by-design principles. Key Responsibilities Design, implement and maintain cyber security solutions and capabilities. Administer and monitor Microsoft 365 security technologies , including Intune, Entra ID, Defender, Purview, Exchange Online, SharePoint and Teams. Support identity and access management, vulnerability management and security monitoring . Investigate and respond to security incidents, including SIEM/SOAR investigations and advanced threat hunting. Support security reviews, audits and annual penetration testing. Identify vulnerabilities, risks and opportunities to improve the organisation's security posture. Provide security advice to IT projects, ensuring security is embedded into solution design and technology decisions. Support and maintain alignment with Cyber Essentials Plus . Contribute to information security policies, procedures and standards. Work with internal teams and external partners to deliver security improvements. Keep up to date with emerging cyber security threats, vulnerabilities and industry best practice. About You We're looking for a Cyber Security Engineer with practical experience working within an information or cyber security environment.You should have: Strong knowledge of Microsoft Security technologies . Experience with Microsoft 365, Entra ID, Intune and Defender . Knowledge of SIEM/SOAR, vulnerability management and incident response . Understanding of cloud security and network security principles . Experience supporting security assessments, audits and penetration testing. Knowledge of security frameworks including NIST and Cyber Essentials . Understanding of ITIL processes, particularly Incident, Change and Problem Management. Strong communication and stakeholder management skills. The ability to work independently, manage competing priorities and solve complex security problems. Qualifications Essential: CompTIA Security+ or equivalent security experience. Desirable: Microsoft SC-200, SC-300 or SC-400 CEH CISSP CCNA Package & Working Arrangements Salary: Up to £65,000 per annum Contract: 12-month FTC Location: Farringdon, London Working pattern: Hybrid - 2 days per week in the office Benefits: 28 days holiday, Life Assurance, Pension (9%), and other benefits Sector: Housing / Not-for-Profit Morgan Hunt is a multi-award-winning recruitment business for interim, contract and temporary recruitment and acts as an Employment Agency in relation to permanent vacancies. Morgan Hunt is an equal opportunities employer. Job suitability is assessed on merit in accordance with the individual's skills, qualifications and abilities to perform the relevant duties required in a particular role.
Aug 21, 2026
Full time
Cyber Security Engineer Housing Association 12-Month FTC Up to £65,000 Hybrid - Farringdon Morgan Hunt is delighted to be partnering with a leading Housing Association to recruit an experienced Cyber Security Engineer on an initial 12-month Fixed-Term Contract .This is an excellent opportunity for a hands-on security professional to join an established cyber security function and play a key role in strengthening the organisation's security capabilities across applications, infrastructure, networks, data and cloud platforms. The Role Working closely with the Cyber Security Manager and Senior Cyber Security Engineer , you will help design, implement and maintain the organisation's cyber security capabilities.You will have a broad remit across Microsoft security technologies, identity and access management, vulnerability management, incident response, SIEM/SOAR, threat hunting and cloud security , while also providing security advice to technology projects and supporting security-by-design principles. Key Responsibilities Design, implement and maintain cyber security solutions and capabilities. Administer and monitor Microsoft 365 security technologies , including Intune, Entra ID, Defender, Purview, Exchange Online, SharePoint and Teams. Support identity and access management, vulnerability management and security monitoring . Investigate and respond to security incidents, including SIEM/SOAR investigations and advanced threat hunting. Support security reviews, audits and annual penetration testing. Identify vulnerabilities, risks and opportunities to improve the organisation's security posture. Provide security advice to IT projects, ensuring security is embedded into solution design and technology decisions. Support and maintain alignment with Cyber Essentials Plus . Contribute to information security policies, procedures and standards. Work with internal teams and external partners to deliver security improvements. Keep up to date with emerging cyber security threats, vulnerabilities and industry best practice. About You We're looking for a Cyber Security Engineer with practical experience working within an information or cyber security environment.You should have: Strong knowledge of Microsoft Security technologies . Experience with Microsoft 365, Entra ID, Intune and Defender . Knowledge of SIEM/SOAR, vulnerability management and incident response . Understanding of cloud security and network security principles . Experience supporting security assessments, audits and penetration testing. Knowledge of security frameworks including NIST and Cyber Essentials . Understanding of ITIL processes, particularly Incident, Change and Problem Management. Strong communication and stakeholder management skills. The ability to work independently, manage competing priorities and solve complex security problems. Qualifications Essential: CompTIA Security+ or equivalent security experience. Desirable: Microsoft SC-200, SC-300 or SC-400 CEH CISSP CCNA Package & Working Arrangements Salary: Up to £65,000 per annum Contract: 12-month FTC Location: Farringdon, London Working pattern: Hybrid - 2 days per week in the office Benefits: 28 days holiday, Life Assurance, Pension (9%), and other benefits Sector: Housing / Not-for-Profit Morgan Hunt is a multi-award-winning recruitment business for interim, contract and temporary recruitment and acts as an Employment Agency in relation to permanent vacancies. Morgan Hunt is an equal opportunities employer. Job suitability is assessed on merit in accordance with the individual's skills, qualifications and abilities to perform the relevant duties required in a particular role.
Adele Carr Recruitment Limited
Information Security Manager
Adele Carr Recruitment Limited Liverpool, Merseyside
Information Security Manager - Liverpool - £55,000-£65,000 The Information Security Manager is responsible for the operational delivery, maintenance, and continuous improvement of the organisation's information security framework.The role ensures that information assets, systems, and services are appropriately protected against internal and external threats, while maintaining compliance with regulatory, legal, and internal policy requirements.Reporting to the Head of Information Security & Continuity, the role plays a key part in embedding a strong security culture, managing security risk, and ensuring effective response to cyber incidents. The Information Security Manager works closely with Technology, Risk, Compliance, and business teams to ensure that security controls are proportionate, effective, and aligned to business objectives. Core Responsibilities Support the development, implementation, and ongoing maintenance of the Information Security Management System (ISMS) aligned to ISO 27001Implement and enforce information security policies, standards, and procedures across the organisationConduct security risk assessments, ensuring risks are identified, assessed, and managed through appropriate controlsMaintain and track remediation of vulnerabilities and audit findingsMonitor the threat landscape and coordinate responses to emerging risks and vulnerabilitiesLead the investigation and response to information security incidents, ensuring lessons learned and improvements are implementedSupport internal and external audits, including ISO 27001 certification and surveillance activitiesManage third-party and supplier security risk assessments and assurance processesWork with IT and project teams to ensure security is embedded into system design, development, and change management processesDeliver and continuously improve the organisation's security awareness and training programmeEnsure compliance with regulatory requirements, including FCA expectations and data protection legislation (GDPR)Provide regular reporting on security risk, incidents, control effectiveness, and compliance status Essential Experience Demonstrable experience in an Information Security or Cyber Security role within a corporate environmentStrong working knowledge of information security frameworks and standards (e.g. ISO 27001, NIST Cyber Security Framework)Experience in conducting risk assessments and implementing effective security controlsHands-on experience in incident response, investigation, and resolutionExperience supporting internal and external audits and compliance activitiesExperience managing third-party security risk or supplier assurance processesAbility to translate technical risks into clear business impact for stakeholdersStrong communication, stakeholder engagement, and organisational skillsUnderstanding of fundamentals of IT Infrastructure Desirable Experience Experience working within financial services or regulated environmentsExperience with cloud security (e.g. Azure, AWS)Familiarity with SIEM, vulnerability management, and endpoint security toolsUnderstanding of data protection and GDPR requirementsEssential QualificationsDegree or equivalent professional experience in a relevant fieldIndustry certifications such as CISSP, CISM, or equivalent (desirable)ISO 27001 Lead Implementer or Auditor (desirable)
Aug 21, 2026
Full time
Information Security Manager - Liverpool - £55,000-£65,000 The Information Security Manager is responsible for the operational delivery, maintenance, and continuous improvement of the organisation's information security framework.The role ensures that information assets, systems, and services are appropriately protected against internal and external threats, while maintaining compliance with regulatory, legal, and internal policy requirements.Reporting to the Head of Information Security & Continuity, the role plays a key part in embedding a strong security culture, managing security risk, and ensuring effective response to cyber incidents. The Information Security Manager works closely with Technology, Risk, Compliance, and business teams to ensure that security controls are proportionate, effective, and aligned to business objectives. Core Responsibilities Support the development, implementation, and ongoing maintenance of the Information Security Management System (ISMS) aligned to ISO 27001Implement and enforce information security policies, standards, and procedures across the organisationConduct security risk assessments, ensuring risks are identified, assessed, and managed through appropriate controlsMaintain and track remediation of vulnerabilities and audit findingsMonitor the threat landscape and coordinate responses to emerging risks and vulnerabilitiesLead the investigation and response to information security incidents, ensuring lessons learned and improvements are implementedSupport internal and external audits, including ISO 27001 certification and surveillance activitiesManage third-party and supplier security risk assessments and assurance processesWork with IT and project teams to ensure security is embedded into system design, development, and change management processesDeliver and continuously improve the organisation's security awareness and training programmeEnsure compliance with regulatory requirements, including FCA expectations and data protection legislation (GDPR)Provide regular reporting on security risk, incidents, control effectiveness, and compliance status Essential Experience Demonstrable experience in an Information Security or Cyber Security role within a corporate environmentStrong working knowledge of information security frameworks and standards (e.g. ISO 27001, NIST Cyber Security Framework)Experience in conducting risk assessments and implementing effective security controlsHands-on experience in incident response, investigation, and resolutionExperience supporting internal and external audits and compliance activitiesExperience managing third-party security risk or supplier assurance processesAbility to translate technical risks into clear business impact for stakeholdersStrong communication, stakeholder engagement, and organisational skillsUnderstanding of fundamentals of IT Infrastructure Desirable Experience Experience working within financial services or regulated environmentsExperience with cloud security (e.g. Azure, AWS)Familiarity with SIEM, vulnerability management, and endpoint security toolsUnderstanding of data protection and GDPR requirementsEssential QualificationsDegree or equivalent professional experience in a relevant fieldIndustry certifications such as CISSP, CISM, or equivalent (desirable)ISO 27001 Lead Implementer or Auditor (desirable)
Senior Security Engineer
Data Science Festival
Staff Software Security Engineer Salary: Up to £135,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Staff Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Staff Software Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Software Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Staff Software Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £135,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Aug 20, 2026
Full time
Staff Software Security Engineer Salary: Up to £135,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Staff Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Staff Software Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Software Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Staff Software Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £135,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
Sanderson
Cyber Security Operations Specialist
Sanderson Bristol, Somerset
Cyber Security Operations Specialist Rate - £500 - £550 Inside IR35 Duration - 6 months Location - Bristol - twice a week on site A major organisation is seeking a Cyber Security Operations Specialist to join its Security Operations team. This is a hands on role focused on incident response, threat detection, vulnerability management and continuous improvement across enterprise technology environments. You'll be expected to hit the ground running, managing security alerts, investigations, tickets and operational queues while helping improve the effectiveness of the security tooling estate. The Role Monitor, investigate and respond to cyber security incidents. Manage and triage security alerts, tickets and operational queues. Lead or support incident response activities through to resolution. Support vulnerability management and remediation activities. Apply threat intelligence to strengthen detection and response capabilities. Develop and optimise SIEM detections, alerting rules and response workflows. Improve the performance and effectiveness of security platforms rather than simply operating them. Produce clear incident reports and recommendations. Work closely with teams across the business to explain risks, security controls and operational blockers. Build strong relationships with both technical and non technical stakeholders to drive security improvements. Technology Environment Experience with the following is highly desirable: Microsoft Defender Microsoft Sentinel Microsoft Purview Proofpoint SIEM, EDR and related security technologies About You You'll have a strong background in Security Operations and Incident Response, with hands on experience working with Microsoft security technologies and enterprise security tooling. You'll be comfortable managing multiple priorities, working through investigations and security queues, and responding effectively to incidents as they arise. We're looking for someone who can quickly become a key contributor to the team, bringing experience in vulnerability management, threat intelligence and detection engineering. You'll enjoy improving platforms, processes and controls, identifying opportunities to strengthen security capability and driving measurable improvements across the environment. Strong communication skills are essential. You'll be confident engaging with stakeholders at all levels, translating technical issues into business language and helping teams understand security requirements without creating unnecessary friction. This is an excellent opportunity for a security professional who combines strong technical capability with a collaborative approach and a genuine passion for improving cyber security operations. Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
Aug 20, 2026
Contractor
Cyber Security Operations Specialist Rate - £500 - £550 Inside IR35 Duration - 6 months Location - Bristol - twice a week on site A major organisation is seeking a Cyber Security Operations Specialist to join its Security Operations team. This is a hands on role focused on incident response, threat detection, vulnerability management and continuous improvement across enterprise technology environments. You'll be expected to hit the ground running, managing security alerts, investigations, tickets and operational queues while helping improve the effectiveness of the security tooling estate. The Role Monitor, investigate and respond to cyber security incidents. Manage and triage security alerts, tickets and operational queues. Lead or support incident response activities through to resolution. Support vulnerability management and remediation activities. Apply threat intelligence to strengthen detection and response capabilities. Develop and optimise SIEM detections, alerting rules and response workflows. Improve the performance and effectiveness of security platforms rather than simply operating them. Produce clear incident reports and recommendations. Work closely with teams across the business to explain risks, security controls and operational blockers. Build strong relationships with both technical and non technical stakeholders to drive security improvements. Technology Environment Experience with the following is highly desirable: Microsoft Defender Microsoft Sentinel Microsoft Purview Proofpoint SIEM, EDR and related security technologies About You You'll have a strong background in Security Operations and Incident Response, with hands on experience working with Microsoft security technologies and enterprise security tooling. You'll be comfortable managing multiple priorities, working through investigations and security queues, and responding effectively to incidents as they arise. We're looking for someone who can quickly become a key contributor to the team, bringing experience in vulnerability management, threat intelligence and detection engineering. You'll enjoy improving platforms, processes and controls, identifying opportunities to strengthen security capability and driving measurable improvements across the environment. Strong communication skills are essential. You'll be confident engaging with stakeholders at all levels, translating technical issues into business language and helping teams understand security requirements without creating unnecessary friction. This is an excellent opportunity for a security professional who combines strong technical capability with a collaborative approach and a genuine passion for improving cyber security operations. Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
Marshall Wolfe
PCI-DSS IT Security Manager
Marshall Wolfe Luton, Bedfordshire
IT Security Manager- Cyber Security Manager - PCI-DSS Location: Luton, 2 days per week on-site. Our client, a national organisation with offices near Luton, are seeking an experienced IT Security Manager to lead and enhance their security landscape while owning their Tier 1 PCI-DSS compliance programme. This is a fantastic opportunity for a hands-on security specialist who enjoys operating at both strategic and technical levels, working closely with senior stakeholders to drive security best practice across the organisation. Reporting to the Head of Technical Delivery, you will be the go-to expert for all aspects of cyber security, governance, risk, and compliance. This is a standalone role offering significant ownership and influence, making it ideal for someone who enjoys autonomy and genuinely shaping an organisation's security strategy. Key Responsibilities Cyber Security: Develop and continuously improve the organisation's cyber security strategy, controls, and policies. Monitor emerging threats and ensure effective protection across endpoint, network, cloud, and identity environments. Lead security incident response activities, investigations, and remediation efforts. Drive vulnerability management and penetration testing programmes through to successful resolution. Act as the internal cyber security subject matter expert. PCI-DSS Compliance & Audit: Take ownership of end-to-end PCI-DSS compliance activities. Lead annual audit and attestation processes, working closely with external assessors. Manage compliance documentation, evidence gathering, and control frameworks. Coordinate with technical and business teams to embed compliance requirements into day-to-day operations. Provide compliance reporting and updates to senior stakeholders. Governance, Risk & Compliance: Support wider compliance initiatives including ISO 27001, Cyber Essentials, and GDPR. Maintain security policies, standards, and procedures. Conduct risk assessments and manage the security risk register. Deliver security awareness initiatives across the business. Manage relationships with third-party suppliers, security vendors, and auditors. Essential Skills & Experience Proven experience within IT or Cyber Security with ownership of PCI-DSS compliance in a Tier 1 environment. Strong understanding of security frameworks, controls, and governance practices. Experience managing security incidents, vulnerability remediation, and audit activities. Ability to engage confidently with senior stakeholders and external auditors. Comfortable working independently and taking ownership of a broad security remit. Desirable CISSP, CISM, CISA, PCI ISA, or similar industry certifications. Experience within retail, hospitality, payments, or other highly regulated environments. Knowledge of Azure, AWS, and modern SOC/SIEM technologies. If you're an experienced IT Security Manager, Cyber Security Manager, Information Security Manager, or PCI Compliance Specialist looking for your next challenge, we'd love to hear from you.
Aug 20, 2026
Full time
IT Security Manager- Cyber Security Manager - PCI-DSS Location: Luton, 2 days per week on-site. Our client, a national organisation with offices near Luton, are seeking an experienced IT Security Manager to lead and enhance their security landscape while owning their Tier 1 PCI-DSS compliance programme. This is a fantastic opportunity for a hands-on security specialist who enjoys operating at both strategic and technical levels, working closely with senior stakeholders to drive security best practice across the organisation. Reporting to the Head of Technical Delivery, you will be the go-to expert for all aspects of cyber security, governance, risk, and compliance. This is a standalone role offering significant ownership and influence, making it ideal for someone who enjoys autonomy and genuinely shaping an organisation's security strategy. Key Responsibilities Cyber Security: Develop and continuously improve the organisation's cyber security strategy, controls, and policies. Monitor emerging threats and ensure effective protection across endpoint, network, cloud, and identity environments. Lead security incident response activities, investigations, and remediation efforts. Drive vulnerability management and penetration testing programmes through to successful resolution. Act as the internal cyber security subject matter expert. PCI-DSS Compliance & Audit: Take ownership of end-to-end PCI-DSS compliance activities. Lead annual audit and attestation processes, working closely with external assessors. Manage compliance documentation, evidence gathering, and control frameworks. Coordinate with technical and business teams to embed compliance requirements into day-to-day operations. Provide compliance reporting and updates to senior stakeholders. Governance, Risk & Compliance: Support wider compliance initiatives including ISO 27001, Cyber Essentials, and GDPR. Maintain security policies, standards, and procedures. Conduct risk assessments and manage the security risk register. Deliver security awareness initiatives across the business. Manage relationships with third-party suppliers, security vendors, and auditors. Essential Skills & Experience Proven experience within IT or Cyber Security with ownership of PCI-DSS compliance in a Tier 1 environment. Strong understanding of security frameworks, controls, and governance practices. Experience managing security incidents, vulnerability remediation, and audit activities. Ability to engage confidently with senior stakeholders and external auditors. Comfortable working independently and taking ownership of a broad security remit. Desirable CISSP, CISM, CISA, PCI ISA, or similar industry certifications. Experience within retail, hospitality, payments, or other highly regulated environments. Knowledge of Azure, AWS, and modern SOC/SIEM technologies. If you're an experienced IT Security Manager, Cyber Security Manager, Information Security Manager, or PCI Compliance Specialist looking for your next challenge, we'd love to hear from you.
Everywhen, part of the Ardonagh Group
Threat Intelligence Lead
Everywhen, part of the Ardonagh Group
An exciting remote-based opportunity has arisen for a Threat Intelligence Lead to join our Technology team, reporting to the Chief Information Security Officer. You will design and lead the company's cyber threat intelligence (CTI), security testing and proactive threat-hunting programmes, helping to protect our customers, assets and brands across our global operations.Working closely with our internal and external security operations teams, you will anticipate, assess and mitigate threats. The intelligence you provide will support strategic decisions, incident response and continuous improvements to our cyber resilience. This pivotal Cyber Security role requires strong technical expertise, intelligence capability and commercial awareness within a regulated financial environment. What you will do as our Threat Intelligence Lead: This is an overview and not an exhaustive list of responsibilities. Collaborating with your Line Manager, you will develop your own objectives but focus on all of the following and more: Lead the development of our CTI function, establishing clear governance, processes, intelligence priorities and measurable outcomes. Represent the organisation in key external intelligence-sharing forums, including FS-ISAC, the NCSC's CiSP and relevant industry partnerships. Use the MITRE ATT&CK framework to identify and analyse attacker tactics, techniques and procedures and strengthen our detection capabilities. Develop the Proactive Threat Hunting Initiative, using intelligence and security tools to identify emerging threats, attack paths and vulnerabilities and security gaps. Oversee the collection and analysis of tactical, operational and strategic threat intelligence, with a particular focus on threats affecting insurance and financial services sectors. Proactively search for malicious activity, anomalies and emerging threats across enterprise networks, endpoints and cloud environments. Provide clear, actionable intelligence and threat landscaping briefings to senior leaders, Board committees and key stakeholders across the business. What are we looking for in our Threat Intelligence Lead? We're looking for an experienced Cyber Threat Intelligence professional who can combine their strong technical expertise with the ability to develop our CTI capability and turn complex intelligence into clear, actionable business insights. MITRE ATT&CK training/certification is essential . Experience developing Priority Intelligence Requirements (PIRs). Strong experience working closely with SOC, Incident Response, Vulnerability Management, Security Engineering and Risk. Experience managing the end-to-end intelligence lifecycle. Significant Cyber Threat Intelligence (CTI) or closely related cyber security experience. Strong experience analysing strategic, operational, and tactical threat intelligence. Practical experience with MITRE ATT&CK, threat actor profiling, IOC analysis, threat hunting and intelligence-led detection engineering. Evidence of leading/developing a CTI capability. Relevant professional certification such as GCTI, CRTIA, CPTIA, GIAC, or CISSP is desirable. In return you will be welcomed and supported by our Ardonagh family joining an organisation that cares about you as a person and your wellbeing. Some of the other benefits are: Holiday entitlement of 26 days plus bank holidays, increasing with length of service 35 hour working week Opportunity to progress your career across the entire Ardonagh family Award-winning learning & development offering and support to obtain professional qualifications to enhance your knowledge and career prospects Pension scheme for when you feel it's time to retire 24-hour Employee Assistance support for you and your family's physical and mental wellbeing Corporate perks such as discounted gym memberships, cinema tickets, shopping, Eyecare vouchers, cycle to work and much more One day paid volunteering to give back to our communities Ardonagh Community Trust (ACT) - raising funds for charity with donation matching in your local community The Spotlight Awards, where we celebrate the best of the Ardonagh Group and all the bright talent across our business. We offer genuine potential for both personal and professional development, come and be part of our story and help us shape our future. So, what are you waiting for? Apply today and one of our team will be in touch. INDX3 Everywhen is an equal opportunities employer, with a growing and thriving diversity, equity and inclusion strategy; we are committed to a working environment that is free from discrimination, is inclusive, and empowers our people to bring their whole self to work and reach their full potential. If your application is successful, we will conduct relevant employment checks prior to you commencing employment with us. These will include verifying your recent employment, address, credit history and a standard criminal record check. As an Everywhen colleague, you will be expected to uphold our values, act professionally and respectfully towards others, and contribute to a workplace where everyone is treated with dignity and respect. We expect all colleagues to help maintain an environment free from bullying, harassment, victimisation and other inappropriate behaviours, supporting our commitment to an inclusive and high-performing culture. Please note: We may close a vacancy prior to the publish end date if the required quality or number of applications has been received. Note to recruiters and employment agencies: We will not pay for unsolicited CVs from recruiters and employment agencies unless we have a signed agreement and have requested assistance, in writing, for a specific opening.
Aug 20, 2026
Full time
An exciting remote-based opportunity has arisen for a Threat Intelligence Lead to join our Technology team, reporting to the Chief Information Security Officer. You will design and lead the company's cyber threat intelligence (CTI), security testing and proactive threat-hunting programmes, helping to protect our customers, assets and brands across our global operations.Working closely with our internal and external security operations teams, you will anticipate, assess and mitigate threats. The intelligence you provide will support strategic decisions, incident response and continuous improvements to our cyber resilience. This pivotal Cyber Security role requires strong technical expertise, intelligence capability and commercial awareness within a regulated financial environment. What you will do as our Threat Intelligence Lead: This is an overview and not an exhaustive list of responsibilities. Collaborating with your Line Manager, you will develop your own objectives but focus on all of the following and more: Lead the development of our CTI function, establishing clear governance, processes, intelligence priorities and measurable outcomes. Represent the organisation in key external intelligence-sharing forums, including FS-ISAC, the NCSC's CiSP and relevant industry partnerships. Use the MITRE ATT&CK framework to identify and analyse attacker tactics, techniques and procedures and strengthen our detection capabilities. Develop the Proactive Threat Hunting Initiative, using intelligence and security tools to identify emerging threats, attack paths and vulnerabilities and security gaps. Oversee the collection and analysis of tactical, operational and strategic threat intelligence, with a particular focus on threats affecting insurance and financial services sectors. Proactively search for malicious activity, anomalies and emerging threats across enterprise networks, endpoints and cloud environments. Provide clear, actionable intelligence and threat landscaping briefings to senior leaders, Board committees and key stakeholders across the business. What are we looking for in our Threat Intelligence Lead? We're looking for an experienced Cyber Threat Intelligence professional who can combine their strong technical expertise with the ability to develop our CTI capability and turn complex intelligence into clear, actionable business insights. MITRE ATT&CK training/certification is essential . Experience developing Priority Intelligence Requirements (PIRs). Strong experience working closely with SOC, Incident Response, Vulnerability Management, Security Engineering and Risk. Experience managing the end-to-end intelligence lifecycle. Significant Cyber Threat Intelligence (CTI) or closely related cyber security experience. Strong experience analysing strategic, operational, and tactical threat intelligence. Practical experience with MITRE ATT&CK, threat actor profiling, IOC analysis, threat hunting and intelligence-led detection engineering. Evidence of leading/developing a CTI capability. Relevant professional certification such as GCTI, CRTIA, CPTIA, GIAC, or CISSP is desirable. In return you will be welcomed and supported by our Ardonagh family joining an organisation that cares about you as a person and your wellbeing. Some of the other benefits are: Holiday entitlement of 26 days plus bank holidays, increasing with length of service 35 hour working week Opportunity to progress your career across the entire Ardonagh family Award-winning learning & development offering and support to obtain professional qualifications to enhance your knowledge and career prospects Pension scheme for when you feel it's time to retire 24-hour Employee Assistance support for you and your family's physical and mental wellbeing Corporate perks such as discounted gym memberships, cinema tickets, shopping, Eyecare vouchers, cycle to work and much more One day paid volunteering to give back to our communities Ardonagh Community Trust (ACT) - raising funds for charity with donation matching in your local community The Spotlight Awards, where we celebrate the best of the Ardonagh Group and all the bright talent across our business. We offer genuine potential for both personal and professional development, come and be part of our story and help us shape our future. So, what are you waiting for? Apply today and one of our team will be in touch. INDX3 Everywhen is an equal opportunities employer, with a growing and thriving diversity, equity and inclusion strategy; we are committed to a working environment that is free from discrimination, is inclusive, and empowers our people to bring their whole self to work and reach their full potential. If your application is successful, we will conduct relevant employment checks prior to you commencing employment with us. These will include verifying your recent employment, address, credit history and a standard criminal record check. As an Everywhen colleague, you will be expected to uphold our values, act professionally and respectfully towards others, and contribute to a workplace where everyone is treated with dignity and respect. We expect all colleagues to help maintain an environment free from bullying, harassment, victimisation and other inappropriate behaviours, supporting our commitment to an inclusive and high-performing culture. Please note: We may close a vacancy prior to the publish end date if the required quality or number of applications has been received. Note to recruiters and employment agencies: We will not pay for unsolicited CVs from recruiters and employment agencies unless we have a signed agreement and have requested assistance, in writing, for a specific opening.
Cambridge University Press & Assessment
Security Assurance Lead
Cambridge University Press & Assessment Cambridge, Cambridgeshire
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role. We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working. This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment. Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement. Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure. Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery. Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported. Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST. Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders. Support incident preparedness, including investigations and exercises that test our ability to respond effectively. Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation. This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition. About You We are looking for someone with extensive knowledge of 5+ year experience in security testing and assurance and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks and (e.g. ISO 27001, NIST) and risk management practices. You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing. You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management. You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously. If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria: Development and maintained a supply chain risk register within a similar sized organisation Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure Experience of reporting risks to senior leadership For a detailed job description, please refer to the link at the bottom of the advert on our careers site. We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition. Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for. Rewards and benefits We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including: 28 days annual leave plus bank holidays Private medical and Permanent Health Insurance Discretionary annual bonus Group personal pension scheme Life assurance up to 4 x annual salary Green travel schemes Ready to pursue your potential? Apply now. We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2 nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after. The application and interview process consists of: 3 role related questions with brief answers A 15-minute screening call with the Hiring Manager. First stage virtual interview via MS Teams. Final stage interview: in-person at our offices in Cambridge. If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs. Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry. We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter. Why join us Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe - for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration. Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
Aug 18, 2026
Full time
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role. We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working. This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment. Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement. Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure. Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery. Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported. Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST. Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders. Support incident preparedness, including investigations and exercises that test our ability to respond effectively. Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation. This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition. About You We are looking for someone with extensive knowledge of 5+ year experience in security testing and assurance and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks and (e.g. ISO 27001, NIST) and risk management practices. You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing. You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management. You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously. If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria: Development and maintained a supply chain risk register within a similar sized organisation Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure Experience of reporting risks to senior leadership For a detailed job description, please refer to the link at the bottom of the advert on our careers site. We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition. Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for. Rewards and benefits We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including: 28 days annual leave plus bank holidays Private medical and Permanent Health Insurance Discretionary annual bonus Group personal pension scheme Life assurance up to 4 x annual salary Green travel schemes Ready to pursue your potential? Apply now. We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2 nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after. The application and interview process consists of: 3 role related questions with brief answers A 15-minute screening call with the Hiring Manager. First stage virtual interview via MS Teams. Final stage interview: in-person at our offices in Cambridge. If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs. Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry. We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter. Why join us Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe - for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration. Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
UK Biobank
Director of Information Security
UK Biobank Cheadle, Staffordshire
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
Aug 17, 2026
Full time
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
IS Platform and Security Supervisor
Harbour Energy
Since its creation in 2014, Harbour has grown to become one of the world's largest and most geographically diverse independent oil and gas companies. Today, Harbour is producing between 475,000 and 485,000 barrels of oil equivalent per day with significant production in Norway, the UK, Germany, Argentina and North Africa. Harbour benefits from competitive operating costs and resilient margins, and a broad set of growth options including near-infrastructure opportunities in Norway, unconventional scalable opportunities in Argentina and conventional offshore projects in Mexico and Indonesia. With low GHG emissions intensity and a leading CO2 storage position in Europe, Harbour remains committed to producing oil and gas safely and responsibly to help meet the world's energy needs. Harbour is headquartered in London with approximately 5,000 staff and contractors across its operations and offices. Ours is an inclusive workplace where individuals can bring their whole selves to their job and feel recognised for the value they add. We are committed to creating a genuinely inclusive and supportive working environment to ensure everyone has a positive experience at work. At Harbour Energy, we aim to recruit, retain and promote our people based on their unique skills, regardless of race, gender or background. We need excellent people to help shape and develop the future of our company. Could this be you? Purpose of Role The IS Platform and Security Supervisor ensures all environments are secure, compliant, resilient, and aligned with global IS/OT standards, while meeting business and operational requirements. The role oversees the IS platforms, the operational security, Operational Technology, and communications landscape within the Mexico BU. Acts as a point of coordination for BU IS/OT platforms and security working in line with corporate teams. Drive continuous improvement, cost optimisation, and service reliability across IT/OT platforms and communications. Critical Responsibilities (MAE/MATTE/HSES ) Ensure that all activities are carried out in a safe manner complying with all regulatory requirements, legislation and Harbour Energy HSES Procedures. Ethics and Compliance Responsibilities Ensure that all activities and behaviours are carried out in accordance with Harbour Energy's Ethics and Compliance Policies and Procedures and to complete any compulsory compliance training as required. Areas of Accountability, Responsibility and Competence Oversee and manage local infrastructure and cloud services, ensuring full compliance with global IS governance and security standards with focus on availability and performance. Lead local cyber security activities in close collaboration with Global IS Security teams ensuring hands on support and situational awareness during cyber security incidents. Maintain situational awareness and hands on response during incidents. Drive vulnerability management, patching, monitoring, and risk reduction across all supported platforms. Oversee OT systems supporting drilling, offshore, and real time operations ensuring secure integration between IT and OT environments and apply and enforce Global OT cyber security standards. Management of local IT and telecommunications networks including offshore operations. Manage and provide IT systems and facility services to the Mexico BU office including, but not limited to, access control and CCTV. Management of local suppliers to ensure high-quality and compliant service delivery. Support and manage local telecommunications management (internet lines, mobile phone contracts etc). Implementation and execution of local backup and DR concepts. Provide guidance and oversight to ensure technical solutions and procedures remain fit for purpose, secure, and up to date. Participate in audits and verifications of partners and contractors. Provide technical support to tenders and contracts as required. Participate in relevant projects related to IT/OT infrastructure and applications. Manage smaller projects and initiatives. Ensure IS infrastructure and security services are stable, resilient, and consistently meet or exceed agreed service levels. Vendors, partners, and internal teams are aligned, with clear accountability and proactive issue resolution. Processes, tools, and solutions are regularly reviewed and enhanced to drive efficiency, security, and business value. May be required for on call support. Technical Skills IS Security (security operations, security architecture, asset security, communications and network security monitoring.). Private and Public Cloud management, security, and monitoring (AWS, Azure, Google Cloud Platform etc.). Identity & Access Management (Active Directory, LDAP, SSO, MFA). Threat & vulnerability management (risk assessment, penetration testing, malware analysis etc.). Security standards such as ISO 27001, NIST, CIS Controls, SOC 2. Knowledge of OT Environments/Real-time data sources/drilling and rig operations. Commercial awareness, including budget tracking and cost control. Non-Technical Skills Communication skills for reporting of security incidents and providing guidance. Strong stakeholder management skills across business and technical audiences. Professional Experience Experience in prioritising workload, managing demand and delivering against agreed plans. Education Bachelor's degree in relevant field. Language Harbour Principles and Values Strong alignment with Harbour Energy's core values, behaviours, and commitment to operational excellence and integrity. Inclusive recruitment is a vital part of our diversity, equity and inclusion strategy. Whatever your background, if you feel you need an adjustment during our selection process to suit your needs, please let us know, and we will be happy to help.
Aug 15, 2026
Full time
Since its creation in 2014, Harbour has grown to become one of the world's largest and most geographically diverse independent oil and gas companies. Today, Harbour is producing between 475,000 and 485,000 barrels of oil equivalent per day with significant production in Norway, the UK, Germany, Argentina and North Africa. Harbour benefits from competitive operating costs and resilient margins, and a broad set of growth options including near-infrastructure opportunities in Norway, unconventional scalable opportunities in Argentina and conventional offshore projects in Mexico and Indonesia. With low GHG emissions intensity and a leading CO2 storage position in Europe, Harbour remains committed to producing oil and gas safely and responsibly to help meet the world's energy needs. Harbour is headquartered in London with approximately 5,000 staff and contractors across its operations and offices. Ours is an inclusive workplace where individuals can bring their whole selves to their job and feel recognised for the value they add. We are committed to creating a genuinely inclusive and supportive working environment to ensure everyone has a positive experience at work. At Harbour Energy, we aim to recruit, retain and promote our people based on their unique skills, regardless of race, gender or background. We need excellent people to help shape and develop the future of our company. Could this be you? Purpose of Role The IS Platform and Security Supervisor ensures all environments are secure, compliant, resilient, and aligned with global IS/OT standards, while meeting business and operational requirements. The role oversees the IS platforms, the operational security, Operational Technology, and communications landscape within the Mexico BU. Acts as a point of coordination for BU IS/OT platforms and security working in line with corporate teams. Drive continuous improvement, cost optimisation, and service reliability across IT/OT platforms and communications. Critical Responsibilities (MAE/MATTE/HSES ) Ensure that all activities are carried out in a safe manner complying with all regulatory requirements, legislation and Harbour Energy HSES Procedures. Ethics and Compliance Responsibilities Ensure that all activities and behaviours are carried out in accordance with Harbour Energy's Ethics and Compliance Policies and Procedures and to complete any compulsory compliance training as required. Areas of Accountability, Responsibility and Competence Oversee and manage local infrastructure and cloud services, ensuring full compliance with global IS governance and security standards with focus on availability and performance. Lead local cyber security activities in close collaboration with Global IS Security teams ensuring hands on support and situational awareness during cyber security incidents. Maintain situational awareness and hands on response during incidents. Drive vulnerability management, patching, monitoring, and risk reduction across all supported platforms. Oversee OT systems supporting drilling, offshore, and real time operations ensuring secure integration between IT and OT environments and apply and enforce Global OT cyber security standards. Management of local IT and telecommunications networks including offshore operations. Manage and provide IT systems and facility services to the Mexico BU office including, but not limited to, access control and CCTV. Management of local suppliers to ensure high-quality and compliant service delivery. Support and manage local telecommunications management (internet lines, mobile phone contracts etc). Implementation and execution of local backup and DR concepts. Provide guidance and oversight to ensure technical solutions and procedures remain fit for purpose, secure, and up to date. Participate in audits and verifications of partners and contractors. Provide technical support to tenders and contracts as required. Participate in relevant projects related to IT/OT infrastructure and applications. Manage smaller projects and initiatives. Ensure IS infrastructure and security services are stable, resilient, and consistently meet or exceed agreed service levels. Vendors, partners, and internal teams are aligned, with clear accountability and proactive issue resolution. Processes, tools, and solutions are regularly reviewed and enhanced to drive efficiency, security, and business value. May be required for on call support. Technical Skills IS Security (security operations, security architecture, asset security, communications and network security monitoring.). Private and Public Cloud management, security, and monitoring (AWS, Azure, Google Cloud Platform etc.). Identity & Access Management (Active Directory, LDAP, SSO, MFA). Threat & vulnerability management (risk assessment, penetration testing, malware analysis etc.). Security standards such as ISO 27001, NIST, CIS Controls, SOC 2. Knowledge of OT Environments/Real-time data sources/drilling and rig operations. Commercial awareness, including budget tracking and cost control. Non-Technical Skills Communication skills for reporting of security incidents and providing guidance. Strong stakeholder management skills across business and technical audiences. Professional Experience Experience in prioritising workload, managing demand and delivering against agreed plans. Education Bachelor's degree in relevant field. Language Harbour Principles and Values Strong alignment with Harbour Energy's core values, behaviours, and commitment to operational excellence and integrity. Inclusive recruitment is a vital part of our diversity, equity and inclusion strategy. Whatever your background, if you feel you need an adjustment during our selection process to suit your needs, please let us know, and we will be happy to help.
NEST Corporation
Technology and Data Risk Manager
NEST Corporation
Role Overview The Technology & Data Risk Manager is a new second line of defence role within the Risk Directorate, responsible for providing independent oversight, assurance and expert challenge across technology, data, cyber security, and related operational risks. Reporting to the Head of Technical Risk and Data Protection Officer, the role supports the effective management of technology and data risks by ensuring first line teams identify, assess and mitigate risks in line with Nest's risk appetite while enabling the organisation to deliver its strategic objectives securely and efficiently.Working across the organisation, the role promotes strong risk management practices, providing expert challenge on technology, data protection, information security, and third-party risk matters. It plays a key role in strengthening governance, embedding a strong data protection and security culture, and supporting compliance with regulatory requirements and recognised standards, includingUK GDPR, the Data Protection Act 2018 and ISO 27001.The Technology & Data Risk Manager also helps the organisation anticipate and respond to emerging risks and opportunities, including developments in artificial intelligence, evolving cyber threats, and third-party dependencies. Through effective stakeholder engagement, assurance activity and risk reporting, the role contributes to maintaining a resilient, compliant, and well-controlled technology and data environment across Nest. The minimum criteria for this role are: Essential Sound knowledge of information security and data risk domains (access control, vulnerability management, logging and monitoring, incident response, secure development etc). Experience in technology, data, security, or technical risk management including control frameworks such as ISO 27001 and NIST, ideally within a regulated or complex organisation. Strong understanding of second line assurance and oversight, including how to challenge constructively while remaining independent. Experience of assessing third-party technical risk. Desirable Experience with product security and secure SDLC assurance. Knowledge of AI risk, data ethics or emerging technology governance. Working knowledge of UK GDPR and the Data Protection Act 2018. Knowledge of threat intelligence, vulnerability disclosure, and security testing approaches. Relevant professional certifications (e.g. CISM, CISSP, ISO 27001 LI/LA, CRISC, ITIL). Don't worry if you think you don't have all the key skills, it might be worth taking the few minutes to apply as we're good at spotting potential. At Nest, you'll have access to a range of learning opportunities to learn, grow and build the skills you need to be successful in your role and career. Flexible and agile working Everyone's personal situation is different.To make the most out of hybrid working, we've introduced different ways of working, which include (subject to role requirements): hybrid of office (Canary Wharf, London) and home working (there will be an expectation to attend the office, once - twice a week, or more, as required) vary working hours Directorate/Department Overview The Technical Risk team sits within the Risk Directorate, along with Risk, Risk Assurance, Risk Operations and Regulatory Risk, and Controls Oversight. The directorate supports the business in delivering its strategic priorities by overseeing that risk and controls are identified, prioritised and managed through an enterprise risk management framework. Nest operates a 'three lines of defence' model, with Risk sitting in the second line providing advice, guidance and challenge to the first line.The Technical Risk team provides support to Nest specifically in relation to risks covering data, privacy, technology, cyber and financial crime. Support includes conducting investigations, regulatory reporting as well as training and awareness across Nest Corporation. Organisational Overview Nest is an award-winning workplace pension scheme, the largest in the country. Set up by the government to give every worker in the UK somewhere to save, our first-class responsible investment practice and governance are the backbone of what we do, supported by all the functions you'd expect to find in a thriving business. We're committed to creating a workplace where you can be your authentic self and offer an inclusive and flexible working environment. Diversity, Equity and Inclusion Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of their age, disability, gender identity, marital status, national origin, pregnancy or caring responsibilities, race, religion/belief, sex, sexual orientation or socio economic background.We also recognise the importance of diversity of thought and other forms of neurocognitive variation.Nest is a Disability Confident Leader, which is the highest level of the Disability Confident Scheme. If you have a disability, please declare that you're applying through the scheme. We aim to offer an interview to those applicants who apply through the Disability Confident Scheme and best meet the minimum criteria. However, there may be some circumstances where this is not possible due to the volume of applications.Please note that this advert may close early if we receive a sufficient number of satisfactory applications. If you have any difficulty in sending your application or need the application pack in an alternative format, or you require any reasonable adjustments please contact: .
Aug 15, 2026
Full time
Role Overview The Technology & Data Risk Manager is a new second line of defence role within the Risk Directorate, responsible for providing independent oversight, assurance and expert challenge across technology, data, cyber security, and related operational risks. Reporting to the Head of Technical Risk and Data Protection Officer, the role supports the effective management of technology and data risks by ensuring first line teams identify, assess and mitigate risks in line with Nest's risk appetite while enabling the organisation to deliver its strategic objectives securely and efficiently.Working across the organisation, the role promotes strong risk management practices, providing expert challenge on technology, data protection, information security, and third-party risk matters. It plays a key role in strengthening governance, embedding a strong data protection and security culture, and supporting compliance with regulatory requirements and recognised standards, includingUK GDPR, the Data Protection Act 2018 and ISO 27001.The Technology & Data Risk Manager also helps the organisation anticipate and respond to emerging risks and opportunities, including developments in artificial intelligence, evolving cyber threats, and third-party dependencies. Through effective stakeholder engagement, assurance activity and risk reporting, the role contributes to maintaining a resilient, compliant, and well-controlled technology and data environment across Nest. The minimum criteria for this role are: Essential Sound knowledge of information security and data risk domains (access control, vulnerability management, logging and monitoring, incident response, secure development etc). Experience in technology, data, security, or technical risk management including control frameworks such as ISO 27001 and NIST, ideally within a regulated or complex organisation. Strong understanding of second line assurance and oversight, including how to challenge constructively while remaining independent. Experience of assessing third-party technical risk. Desirable Experience with product security and secure SDLC assurance. Knowledge of AI risk, data ethics or emerging technology governance. Working knowledge of UK GDPR and the Data Protection Act 2018. Knowledge of threat intelligence, vulnerability disclosure, and security testing approaches. Relevant professional certifications (e.g. CISM, CISSP, ISO 27001 LI/LA, CRISC, ITIL). Don't worry if you think you don't have all the key skills, it might be worth taking the few minutes to apply as we're good at spotting potential. At Nest, you'll have access to a range of learning opportunities to learn, grow and build the skills you need to be successful in your role and career. Flexible and agile working Everyone's personal situation is different.To make the most out of hybrid working, we've introduced different ways of working, which include (subject to role requirements): hybrid of office (Canary Wharf, London) and home working (there will be an expectation to attend the office, once - twice a week, or more, as required) vary working hours Directorate/Department Overview The Technical Risk team sits within the Risk Directorate, along with Risk, Risk Assurance, Risk Operations and Regulatory Risk, and Controls Oversight. The directorate supports the business in delivering its strategic priorities by overseeing that risk and controls are identified, prioritised and managed through an enterprise risk management framework. Nest operates a 'three lines of defence' model, with Risk sitting in the second line providing advice, guidance and challenge to the first line.The Technical Risk team provides support to Nest specifically in relation to risks covering data, privacy, technology, cyber and financial crime. Support includes conducting investigations, regulatory reporting as well as training and awareness across Nest Corporation. Organisational Overview Nest is an award-winning workplace pension scheme, the largest in the country. Set up by the government to give every worker in the UK somewhere to save, our first-class responsible investment practice and governance are the backbone of what we do, supported by all the functions you'd expect to find in a thriving business. We're committed to creating a workplace where you can be your authentic self and offer an inclusive and flexible working environment. Diversity, Equity and Inclusion Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of their age, disability, gender identity, marital status, national origin, pregnancy or caring responsibilities, race, religion/belief, sex, sexual orientation or socio economic background.We also recognise the importance of diversity of thought and other forms of neurocognitive variation.Nest is a Disability Confident Leader, which is the highest level of the Disability Confident Scheme. If you have a disability, please declare that you're applying through the scheme. We aim to offer an interview to those applicants who apply through the Disability Confident Scheme and best meet the minimum criteria. However, there may be some circumstances where this is not possible due to the volume of applications.Please note that this advert may close early if we receive a sufficient number of satisfactory applications. If you have any difficulty in sending your application or need the application pack in an alternative format, or you require any reasonable adjustments please contact: .
Saab UK
Cyber Security Manager
Saab UK Fareham, Hampshire
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Aug 14, 2026
Full time
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Saab UK
Cyber Security Manager
Saab UK Fareham, Hampshire
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Aug 11, 2026
Full time
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.

Modal Window

  • Home
  • Contact
  • About Us
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • Facebook
  • Twitter
  • Google Plus
  • LinkedIn
Parent and Partner sites: IT Job Board | Jobs Near Me | RightTalent.co.uk | Quantity Surveyor jobs | Building Surveyor jobs | Construction Recruitment | Talent Recruiter | Construction Job Board | Property jobs | myJobsnearme.com | Jobs near me
© 2008-2026 Jobsite Jobs | Designed by Web Design Agency