At Metro Bank, we believe the best banking experience starts with people who genuinely care. We're not just delivering banking services - we're building trust through authentic connections. Here, our people come first; our colleagues are part of a team that values individuality, collaboration, and long-standing relationships. We are also all about balance so most of our jobs offer the opportunity for hybrid working built around your role and home life, wherever possible. What you will do: Collaborate with various first line of defence teams to ensure alignment of technology controls to relevant information security standards Support and challenge Information Security control design across IT and the wider business to be as efficient and effective as possible given the dynamic nature of risk and threat within the banking industry Ensure transparency in Information Security decisions made across all programmes and projects that you are supporting Support a varied and demanding programme of bank-wide change working with project teams to advise and guide on information security best practice. You will help ensure that final outputs comply with external best practice, regulation and internal governance, whilst balancing the specific delivery needs and challenges of the project Identify security testing requirements, collaborate with appropriate stakeholders to scope these tests and to ensure that the business risk associated with any issues identified is incorporated into project risk management and treated in accordance with the Bank's risk management policies and processes Information Security management reporting, specifically within the change and project environment When required, deputise for the Head of Information Security Change And we are a bank so risk is a part of everything we do. We love people who take responsibility, do the right thing for customers, colleagues and Metro Bank and have the ability to call out any concerns. What you will need: You must have a strong understanding of information security within the project management lifecycle, alongside a solid working knowledge of enterprise technology You must have a strong risk management background and experience in conducting security risk assessments on projects and developing security controls Specific experience in secure design, build and control methodologies aligned to relevant security standards, e.g. ISO27001, PCI DSS, NIST Demonstrable experience of Agile, DevSecOps, Cloud, containerization, microservices and similar technologies is desirable Excellent stakeholder management skills with the ability to distil complex conversations into information that can be consumed by a non-technical audience to make decisions You are able to critically assess regulatory risks applicable to systems and projects within the financial industry against the wider business and information security risks Understand the risks associated with your job and what that means for you, Metro Bank and all our stakeholders Our promise to you We will make sure that you are well-rewarded by providing you with a competitive salary, discretionary annual bonus, and a wide range of benefits, including generous holiday allowance, attractive pension scheme, healthcare, life assurance, and a number of colleague discounts! We will give you the training to ensure you succeed in your role and plenty of internal opportunities to progress your career (around 40% of our recruitment comes from internal promotions! Diverse teams really are the best teams. We know that candidates (especially women, research tells us) may be put off applying for a job unless they can tick every box. We also know that 'normal' office hours aren't always doable, and while we can't accommodate every flexible working request we are happy to be asked. So if you are excited about working with us and think you can do much of what we are looking for but aren't sure if you are 100% there yet why not give it a whirl? Please note that sometimes we may close a job earlier for applications if we are inundated with amazing candidates Good luck!
Dec 11, 2025
Full time
At Metro Bank, we believe the best banking experience starts with people who genuinely care. We're not just delivering banking services - we're building trust through authentic connections. Here, our people come first; our colleagues are part of a team that values individuality, collaboration, and long-standing relationships. We are also all about balance so most of our jobs offer the opportunity for hybrid working built around your role and home life, wherever possible. What you will do: Collaborate with various first line of defence teams to ensure alignment of technology controls to relevant information security standards Support and challenge Information Security control design across IT and the wider business to be as efficient and effective as possible given the dynamic nature of risk and threat within the banking industry Ensure transparency in Information Security decisions made across all programmes and projects that you are supporting Support a varied and demanding programme of bank-wide change working with project teams to advise and guide on information security best practice. You will help ensure that final outputs comply with external best practice, regulation and internal governance, whilst balancing the specific delivery needs and challenges of the project Identify security testing requirements, collaborate with appropriate stakeholders to scope these tests and to ensure that the business risk associated with any issues identified is incorporated into project risk management and treated in accordance with the Bank's risk management policies and processes Information Security management reporting, specifically within the change and project environment When required, deputise for the Head of Information Security Change And we are a bank so risk is a part of everything we do. We love people who take responsibility, do the right thing for customers, colleagues and Metro Bank and have the ability to call out any concerns. What you will need: You must have a strong understanding of information security within the project management lifecycle, alongside a solid working knowledge of enterprise technology You must have a strong risk management background and experience in conducting security risk assessments on projects and developing security controls Specific experience in secure design, build and control methodologies aligned to relevant security standards, e.g. ISO27001, PCI DSS, NIST Demonstrable experience of Agile, DevSecOps, Cloud, containerization, microservices and similar technologies is desirable Excellent stakeholder management skills with the ability to distil complex conversations into information that can be consumed by a non-technical audience to make decisions You are able to critically assess regulatory risks applicable to systems and projects within the financial industry against the wider business and information security risks Understand the risks associated with your job and what that means for you, Metro Bank and all our stakeholders Our promise to you We will make sure that you are well-rewarded by providing you with a competitive salary, discretionary annual bonus, and a wide range of benefits, including generous holiday allowance, attractive pension scheme, healthcare, life assurance, and a number of colleague discounts! We will give you the training to ensure you succeed in your role and plenty of internal opportunities to progress your career (around 40% of our recruitment comes from internal promotions! Diverse teams really are the best teams. We know that candidates (especially women, research tells us) may be put off applying for a job unless they can tick every box. We also know that 'normal' office hours aren't always doable, and while we can't accommodate every flexible working request we are happy to be asked. So if you are excited about working with us and think you can do much of what we are looking for but aren't sure if you are 100% there yet why not give it a whirl? Please note that sometimes we may close a job earlier for applications if we are inundated with amazing candidates Good luck!
Role: Head of Security (Cyber Security) Reporting to: CTO Location: Remote - UK Job Type: Full-time, Permanent Salary: Competitive, based on experience + benefits + bonus potential About Us Come and be a part of The Investigo Group (TIG), a dynamic coalition of cutting-edge tech firms specialising in Platform, Software, Data, AI and other bleeding edge technology solutions. Our innovative prowess spans the globe while proudly hailing from the United Kingdom. The group is multi functional with a large portfolio of B2B products and services. Our ecosystem is made up of: IIS, Providing secure internet access in both the public and private sectors. Its mission? To deliver world class secure internet capabilities enhancing productivity across diverse skillsets and organisations. Vestigo Consulting is our training and consultancy company, tailored around specialist sector specific knowledge, and provides regular courses and CPD for our community. The Consultancy side concentrates on expert support of our customers as well as specifically assigned individual deployments. Collaboraite is a bleeding edge company that provides our Data and AI capability. A collaborative partner for designing user centred secure data solutions to overcome operational hurdles, delivered through design thinking and agile coaching. Diversity, Equity, and Inclusion (DEI) are at the heart of The Investigo Group (TIG). We're dedicated to creating a workplace where people from all backgrounds are not only welcome but empowered to excel. We actively seek diverse talent, promote fairness, and foster an inclusive environment where every voice matters, driving innovation and progress in our dynamic tech community. The group provides bespoke, secure, user centric products fuelled by deep technical knowledge advanced data and analytical skills. We proudly stand as a global leader in this space, partnering with esteemed entities that require these advanced forward thinking capabilities. These partnerships have been forged from our understanding of customer challenges, as well as our expertise in developing world leading enterprise product sets. Join us at TIG, where innovation knows no bounds, and together, we'll shape the future of technology solutions for a safer, more efficient world. About You: You are an accomplished security leader with the credibility to influence at Board level and the technical depth to guide teams across cyber, physical, personnel, and operational resilience. You thrive in complex, high stakes environments where risk management, regulatory compliance, and innovation must coexist. You are equally comfortable defining long term strategy as you are rolling up your sleeves to solve immediate challenges. With a strong track record of building and leading multidisciplinary teams, you foster a culture of accountability, collaboration, and continuous improvement. You proven experience of shaping security functions in government, defence, critical national infrastructure, or highly regulated commercial sectors, and are fluent in the language of both security operations and business transformation. Above all, you see security as a business enabler; protecting today while preparing for tomorrow. About The Team: The Security & Resilience team spans cyber, physical, personnel, and operational resilience. The function is responsible for delivering the organisation wide Security Strategy, overseeing operations, architecture, compliance, and risk management, as well as leading resilience and incident response activities. As Head of Security, you will build and lead this cross disciplinary team, ensuring continuous development, resource alignment, and the delivery of targeted training and awareness programmes. The team works closely with engineering, DevSecOps, compliance, legal, and senior leadership to embed security by design and enable scalable, business aligned security practices. About The Role: We're looking for a seasoned and strategic Head of Security to take ownership of our organisation's entire security landscape, spanning cyber, physical, personnel, and operational resilience. This is a senior leadership role at the heart of the business, ensuring that security not only protects but also enables our growth. You will set and deliver a comprehensive security strategy that balances commercial ambitions with risk management, regulatory compliance, and resilience. Acting as a trusted advisor to the Board, you'll provide clear visibility of emerging threats, opportunities, and priorities while shaping security as a true business enabler. Leading a high performing, cross disciplinary team, you will drive innovation across security operations, architecture, risk, and assurance, embedding a security first culture that supports our long term success. Key Responsibilities: Strategic Leadership & Governance Report on key performance indicators (KPIs), threat landscape, and security posture to the Board of Directors. Lead the development and delivery of the organisation wide Security Strategy. Align security operations with commercial expansion goals and emerging geopolitical and sector trends. Champion a security first culture across all departments. Shape security as a business enabling capabilityli> Security Operations & Architecture Oversee the design, implementation, and operation of a modern Security Operations Centre (SOC), resilience programmes, red teaming, insider threat monitoring, and secure architecture consulting. Lead proactive threat intelligence, detection, and response efforts. Drive the implementation of security by design principles in collaboration with engineering and DevSecOps teams. Create and mature a Security Architecture function supporting SSDLC and security. Risk, Compliance & Assurance Own the enterprise risk register, redefining the organisation's approach to risk and resilience. Ensure full compliance with local, international, and sector specific standards (GDPR, etc.). Oversee supply chain and third party risk assessments, security onboarding, and vendor compliance. Lead ISMS development and manage external audits and certifications. Team Leadership & Development Build and lead a cross disciplinary security team (cyber, physical, personnel, and resilience). Ensure continuous development and resource alignment across the function. Deliver targeted training, simulations, and awareness campaigns to build a secure by default workforce. Establish performance tracking dashboards and feedback loops to measure effectiveness and drive continuous improvement. Engagement & Stakeholder Management Actively participate in the Senior Leadership Team, contributing to enterprise level transformation and strategy. Collaborate with legal, compliance, and engineering teams to ensure holistic and scalable security practices. Engage with external regulators government bodies, and strategic partners to share intelligence and influence standards. Resilience & Incident Management Lead organisation wide incident response, recovery, and post incident review processes. Design and scale resilience testing (e.g. tabletop exercises, scenario simulations) to improve organisational maturity and customer trust. Success in This Role Looks Like A clear, board approved Security Strategy is in place, actively aligning security priorities with business growth and regulatory requirements. The organisation has full visibility of key risks, with proactive reporting and measurable improvements to security posture and resilience. A high performing, cross disciplinary security team is established, continuously developed, and recognised as a trusted partner across the business. Security operations, including SOC, threat intelligence, incident response, and secure architecture are running effectively, with security by design embedded into products and services. Compliance with sector specific standards which is demonstrable through successful audits, certifications, vendor risk management. Incident response and resilience exercises are embedded into business as usual, strengthening customer trust and organisational readiness. A strong security culture is visible across the workforce, supported by awareness campaigns, training, and leadership engagement. Why Join Us? Play a critical role in shaping the future of security in a fast growing, mission driven organisation. Work closely with the Board and Senior Leadership Team to influence real change. Lead innovative security programmes at the intersection of commercial, operational, and national security domains. Access to unique sector opportunities, collaborative government networks, and meaningful impact on society. What We're Looking For: Proven experience in a senior InfoSec or Head of Security role, preferably in government, defence, law enforcement, or highly regulated sectors. Deep understanding of risk management, compliance, and resilience within complex organisations. Strong leadership and communication skills, with experience advising C level stakeholders and Boards. Technical fluency across cybersecurity, security architecture, threat intelligence, and secure development lifecycles. . click apply for full job details
Dec 10, 2025
Full time
Role: Head of Security (Cyber Security) Reporting to: CTO Location: Remote - UK Job Type: Full-time, Permanent Salary: Competitive, based on experience + benefits + bonus potential About Us Come and be a part of The Investigo Group (TIG), a dynamic coalition of cutting-edge tech firms specialising in Platform, Software, Data, AI and other bleeding edge technology solutions. Our innovative prowess spans the globe while proudly hailing from the United Kingdom. The group is multi functional with a large portfolio of B2B products and services. Our ecosystem is made up of: IIS, Providing secure internet access in both the public and private sectors. Its mission? To deliver world class secure internet capabilities enhancing productivity across diverse skillsets and organisations. Vestigo Consulting is our training and consultancy company, tailored around specialist sector specific knowledge, and provides regular courses and CPD for our community. The Consultancy side concentrates on expert support of our customers as well as specifically assigned individual deployments. Collaboraite is a bleeding edge company that provides our Data and AI capability. A collaborative partner for designing user centred secure data solutions to overcome operational hurdles, delivered through design thinking and agile coaching. Diversity, Equity, and Inclusion (DEI) are at the heart of The Investigo Group (TIG). We're dedicated to creating a workplace where people from all backgrounds are not only welcome but empowered to excel. We actively seek diverse talent, promote fairness, and foster an inclusive environment where every voice matters, driving innovation and progress in our dynamic tech community. The group provides bespoke, secure, user centric products fuelled by deep technical knowledge advanced data and analytical skills. We proudly stand as a global leader in this space, partnering with esteemed entities that require these advanced forward thinking capabilities. These partnerships have been forged from our understanding of customer challenges, as well as our expertise in developing world leading enterprise product sets. Join us at TIG, where innovation knows no bounds, and together, we'll shape the future of technology solutions for a safer, more efficient world. About You: You are an accomplished security leader with the credibility to influence at Board level and the technical depth to guide teams across cyber, physical, personnel, and operational resilience. You thrive in complex, high stakes environments where risk management, regulatory compliance, and innovation must coexist. You are equally comfortable defining long term strategy as you are rolling up your sleeves to solve immediate challenges. With a strong track record of building and leading multidisciplinary teams, you foster a culture of accountability, collaboration, and continuous improvement. You proven experience of shaping security functions in government, defence, critical national infrastructure, or highly regulated commercial sectors, and are fluent in the language of both security operations and business transformation. Above all, you see security as a business enabler; protecting today while preparing for tomorrow. About The Team: The Security & Resilience team spans cyber, physical, personnel, and operational resilience. The function is responsible for delivering the organisation wide Security Strategy, overseeing operations, architecture, compliance, and risk management, as well as leading resilience and incident response activities. As Head of Security, you will build and lead this cross disciplinary team, ensuring continuous development, resource alignment, and the delivery of targeted training and awareness programmes. The team works closely with engineering, DevSecOps, compliance, legal, and senior leadership to embed security by design and enable scalable, business aligned security practices. About The Role: We're looking for a seasoned and strategic Head of Security to take ownership of our organisation's entire security landscape, spanning cyber, physical, personnel, and operational resilience. This is a senior leadership role at the heart of the business, ensuring that security not only protects but also enables our growth. You will set and deliver a comprehensive security strategy that balances commercial ambitions with risk management, regulatory compliance, and resilience. Acting as a trusted advisor to the Board, you'll provide clear visibility of emerging threats, opportunities, and priorities while shaping security as a true business enabler. Leading a high performing, cross disciplinary team, you will drive innovation across security operations, architecture, risk, and assurance, embedding a security first culture that supports our long term success. Key Responsibilities: Strategic Leadership & Governance Report on key performance indicators (KPIs), threat landscape, and security posture to the Board of Directors. Lead the development and delivery of the organisation wide Security Strategy. Align security operations with commercial expansion goals and emerging geopolitical and sector trends. Champion a security first culture across all departments. Shape security as a business enabling capabilityli> Security Operations & Architecture Oversee the design, implementation, and operation of a modern Security Operations Centre (SOC), resilience programmes, red teaming, insider threat monitoring, and secure architecture consulting. Lead proactive threat intelligence, detection, and response efforts. Drive the implementation of security by design principles in collaboration with engineering and DevSecOps teams. Create and mature a Security Architecture function supporting SSDLC and security. Risk, Compliance & Assurance Own the enterprise risk register, redefining the organisation's approach to risk and resilience. Ensure full compliance with local, international, and sector specific standards (GDPR, etc.). Oversee supply chain and third party risk assessments, security onboarding, and vendor compliance. Lead ISMS development and manage external audits and certifications. Team Leadership & Development Build and lead a cross disciplinary security team (cyber, physical, personnel, and resilience). Ensure continuous development and resource alignment across the function. Deliver targeted training, simulations, and awareness campaigns to build a secure by default workforce. Establish performance tracking dashboards and feedback loops to measure effectiveness and drive continuous improvement. Engagement & Stakeholder Management Actively participate in the Senior Leadership Team, contributing to enterprise level transformation and strategy. Collaborate with legal, compliance, and engineering teams to ensure holistic and scalable security practices. Engage with external regulators government bodies, and strategic partners to share intelligence and influence standards. Resilience & Incident Management Lead organisation wide incident response, recovery, and post incident review processes. Design and scale resilience testing (e.g. tabletop exercises, scenario simulations) to improve organisational maturity and customer trust. Success in This Role Looks Like A clear, board approved Security Strategy is in place, actively aligning security priorities with business growth and regulatory requirements. The organisation has full visibility of key risks, with proactive reporting and measurable improvements to security posture and resilience. A high performing, cross disciplinary security team is established, continuously developed, and recognised as a trusted partner across the business. Security operations, including SOC, threat intelligence, incident response, and secure architecture are running effectively, with security by design embedded into products and services. Compliance with sector specific standards which is demonstrable through successful audits, certifications, vendor risk management. Incident response and resilience exercises are embedded into business as usual, strengthening customer trust and organisational readiness. A strong security culture is visible across the workforce, supported by awareness campaigns, training, and leadership engagement. Why Join Us? Play a critical role in shaping the future of security in a fast growing, mission driven organisation. Work closely with the Board and Senior Leadership Team to influence real change. Lead innovative security programmes at the intersection of commercial, operational, and national security domains. Access to unique sector opportunities, collaborative government networks, and meaningful impact on society. What We're Looking For: Proven experience in a senior InfoSec or Head of Security role, preferably in government, defence, law enforcement, or highly regulated sectors. Deep understanding of risk management, compliance, and resilience within complex organisations. Strong leadership and communication skills, with experience advising C level stakeholders and Boards. Technical fluency across cybersecurity, security architecture, threat intelligence, and secure development lifecycles. . click apply for full job details
Contract Infrastructure Architect / Senior Infrastructure Engineer Outside IR per day Defence & Security Hampshire Contract position at a defence consultancy operating at the forefront of national security initiatives for an infrastructure architect/senior engineer PLEASE NOTE - The nature of this project will require the work to be carried out onsite and successful candidates will be required to be security cleared (SC Level) prior to appointment. You'll lead the build of JEDI-X, guiding the technical team and supporting its use through the experimentation phase. You'll look after multi-classification virtualised collaboration and development environments, keeping them secure and improving them over time. You'll work with internal infrastructure teams to strengthen Secure by Design across business and projects, and support Office 365 plus project systems in public, private and hybrid clouds. You'll handle infrastructure changes, monitor alerts and tickets, patch platforms to policy, and respond to incidents quickly. You'll spot trends, plan fixes to improve stability, stay current on secure cloud and network tech, share knowledge with the team, and support customer and project needs, including helping with bids. Essential skills Windows Server 2016+ admin, VMware vSphere/vCenter/VCF, Azure and Microsoft 365. Linux across CentOS/RedHat/Ubuntu. PowerShell. EUD provisioning via Autopilot with patching and hardening. Solid SSO knowledge. Comfortable in protectively marked environments. Desirable skills Kubernetes (e.g., VMware TKGI), DevSecOps tooling like Elastic and Nessus, application packaging, HashiCorp tools such as Terraform and Vault, and experience working in Agile sprints. PLEASE NOTE - The nature of this project will require the work to be carried out onsite and successful candidates will be required to be security cleared (SC Level) prior to appointment. Please apply or get in touch to find out more.
Dec 10, 2025
Contractor
Contract Infrastructure Architect / Senior Infrastructure Engineer Outside IR per day Defence & Security Hampshire Contract position at a defence consultancy operating at the forefront of national security initiatives for an infrastructure architect/senior engineer PLEASE NOTE - The nature of this project will require the work to be carried out onsite and successful candidates will be required to be security cleared (SC Level) prior to appointment. You'll lead the build of JEDI-X, guiding the technical team and supporting its use through the experimentation phase. You'll look after multi-classification virtualised collaboration and development environments, keeping them secure and improving them over time. You'll work with internal infrastructure teams to strengthen Secure by Design across business and projects, and support Office 365 plus project systems in public, private and hybrid clouds. You'll handle infrastructure changes, monitor alerts and tickets, patch platforms to policy, and respond to incidents quickly. You'll spot trends, plan fixes to improve stability, stay current on secure cloud and network tech, share knowledge with the team, and support customer and project needs, including helping with bids. Essential skills Windows Server 2016+ admin, VMware vSphere/vCenter/VCF, Azure and Microsoft 365. Linux across CentOS/RedHat/Ubuntu. PowerShell. EUD provisioning via Autopilot with patching and hardening. Solid SSO knowledge. Comfortable in protectively marked environments. Desirable skills Kubernetes (e.g., VMware TKGI), DevSecOps tooling like Elastic and Nessus, application packaging, HashiCorp tools such as Terraform and Vault, and experience working in Agile sprints. PLEASE NOTE - The nature of this project will require the work to be carried out onsite and successful candidates will be required to be security cleared (SC Level) prior to appointment. Please apply or get in touch to find out more.
Vulnerability Management Operations Lead page is loaded Vulnerability Management Operations Leadlocations: London, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: RLSEG is seeking a Vulnerability Management Operations Lead to drive the execution, coordination, and continuous improvement of our global vulnerability management program. This is a hands-on technical leadership role that blends operational oversight with deep analytical and engineering engagement. You'll provide direction and coordination across specialized vulnerability management domains, including infrastructure and application level, ensuring alignment, consistency, and measurable risk reduction. As the key operational partner to the Head of Vulnerability Management, you'll serve as the connective tissue across the program, enabling technical teams, translating intelligence into action, defining performance metrics, and representing vulnerability management in critical business and incident contexts. Who you are You're a technical leader and analytical thinker who thrives at the intersection of engineering, data, and security operations. You combine a hands-on understanding of vulnerabilities and exploits with the ability to orchestrate complex operational programs. You are data-driven, curious, and relentless in pursuit of improvement, always looking for better ways to measure, prioritize, and reduce risk. You excel under pressure, lead with credibility, and elevate those around you through mentorship, clarity, and technical insight. Key Responsibilities Operational Leadership Provide matrix leadership and coordination across domain-aligned vulnerability management engineers. Oversee daily and strategic vulnerability management operations, ensuring consistent execution, quality, and prioritization across all domains. Coordinate activities across VM engineers to identify systemic weaknesses, unknown exposures, and emerging risks. Act as the key representative of the vulnerability management function during major incidents, providing expert analysis and coordinated response leadership. Threat and Intelligence Integration Assess and triage Cyber Threat Intelligence input, determining impact and required actions across the environment. Drive targeted response campaigns and validation efforts in collaboration with domain engineers. Translate external threat intelligence into actionable technical outcomes and measurable risk mitigation. Process and Governance Serve as a key contributor to the overarching VM process, framework, and standards, ensuring technical rigor and operational efficiency. Define, track, and evolve key performance and risk metrics (e.g., vulnerability MTTR, backlog trends, exploit exposure, patch SLAs, coverage rates). Collaborate with the VM Governance team to ensure alignment of reporting, dashboards, and audit readiness. Champion data-driven decision-making and measurable accountability across all VM activities. Technical Oversight Provide technical oversight to vulnerability management engineers, ensuring analytical depth, accuracy, and consistency in findings and remediation guidance. Partner with engineering, infrastructure, and DevSecOps teams to improve vulnerability lifecycle management, from identification and triage to remediation and validation. Contribute to root cause and trend analysis of recurring vulnerabilities to inform long-term preventative measures. Continuous Improvement Drive the ongoing enhancement of vulnerability management processes, leveraging lessons learned and industry developments. Identify and implement automation opportunities to streamline operations and improve response times. Foster a culture of continuous improvement within the team and across the wider security function. Required Skills and Experience Proven experience in vulnerability management, security operations, or a related information security domain. Strong understanding of vulnerability identification methodologies (e.g. infrastructure scanning, SAST, SCA, penetration testing) and remediation processes. Demonstrated ability to lead technical teams and manage operational workflows. Solid grasp of threat intelligence, risk assessment, and security best practices. Excellent analytical, problem-solving, and decision-making skills. Effective communication skills, capable of engaging both technical and non-technical stakeholders.Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership , Excellence and Change underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce.We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyone's race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.You will be part of a collaborative and creative culture where we encourage new ideas. We are committed to sustainability across our global business and we are proud to partner with our customers to help them meet their sustainability objectives. Our charity, the LSEG Foundation provides charitable grants to community groups that help people access economic opportunities and build a secure future with financial independence. Colleagues can get involved through fundraising and volunteering.LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.Please take a moment to read this carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what it's used for, and how it's obtained, .If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice.LSEG (London Stock Exchange Group) is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth. Our culture of connecting, creating opportunity and delivering excellence shapes how we think, how we do things and how we help our people fulfil their potential.
Dec 10, 2025
Full time
Vulnerability Management Operations Lead page is loaded Vulnerability Management Operations Leadlocations: London, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: RLSEG is seeking a Vulnerability Management Operations Lead to drive the execution, coordination, and continuous improvement of our global vulnerability management program. This is a hands-on technical leadership role that blends operational oversight with deep analytical and engineering engagement. You'll provide direction and coordination across specialized vulnerability management domains, including infrastructure and application level, ensuring alignment, consistency, and measurable risk reduction. As the key operational partner to the Head of Vulnerability Management, you'll serve as the connective tissue across the program, enabling technical teams, translating intelligence into action, defining performance metrics, and representing vulnerability management in critical business and incident contexts. Who you are You're a technical leader and analytical thinker who thrives at the intersection of engineering, data, and security operations. You combine a hands-on understanding of vulnerabilities and exploits with the ability to orchestrate complex operational programs. You are data-driven, curious, and relentless in pursuit of improvement, always looking for better ways to measure, prioritize, and reduce risk. You excel under pressure, lead with credibility, and elevate those around you through mentorship, clarity, and technical insight. Key Responsibilities Operational Leadership Provide matrix leadership and coordination across domain-aligned vulnerability management engineers. Oversee daily and strategic vulnerability management operations, ensuring consistent execution, quality, and prioritization across all domains. Coordinate activities across VM engineers to identify systemic weaknesses, unknown exposures, and emerging risks. Act as the key representative of the vulnerability management function during major incidents, providing expert analysis and coordinated response leadership. Threat and Intelligence Integration Assess and triage Cyber Threat Intelligence input, determining impact and required actions across the environment. Drive targeted response campaigns and validation efforts in collaboration with domain engineers. Translate external threat intelligence into actionable technical outcomes and measurable risk mitigation. Process and Governance Serve as a key contributor to the overarching VM process, framework, and standards, ensuring technical rigor and operational efficiency. Define, track, and evolve key performance and risk metrics (e.g., vulnerability MTTR, backlog trends, exploit exposure, patch SLAs, coverage rates). Collaborate with the VM Governance team to ensure alignment of reporting, dashboards, and audit readiness. Champion data-driven decision-making and measurable accountability across all VM activities. Technical Oversight Provide technical oversight to vulnerability management engineers, ensuring analytical depth, accuracy, and consistency in findings and remediation guidance. Partner with engineering, infrastructure, and DevSecOps teams to improve vulnerability lifecycle management, from identification and triage to remediation and validation. Contribute to root cause and trend analysis of recurring vulnerabilities to inform long-term preventative measures. Continuous Improvement Drive the ongoing enhancement of vulnerability management processes, leveraging lessons learned and industry developments. Identify and implement automation opportunities to streamline operations and improve response times. Foster a culture of continuous improvement within the team and across the wider security function. Required Skills and Experience Proven experience in vulnerability management, security operations, or a related information security domain. Strong understanding of vulnerability identification methodologies (e.g. infrastructure scanning, SAST, SCA, penetration testing) and remediation processes. Demonstrated ability to lead technical teams and manage operational workflows. Solid grasp of threat intelligence, risk assessment, and security best practices. Excellent analytical, problem-solving, and decision-making skills. Effective communication skills, capable of engaging both technical and non-technical stakeholders.Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership , Excellence and Change underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce.We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyone's race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.You will be part of a collaborative and creative culture where we encourage new ideas. We are committed to sustainability across our global business and we are proud to partner with our customers to help them meet their sustainability objectives. Our charity, the LSEG Foundation provides charitable grants to community groups that help people access economic opportunities and build a secure future with financial independence. Colleagues can get involved through fundraising and volunteering.LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.Please take a moment to read this carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what it's used for, and how it's obtained, .If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice.LSEG (London Stock Exchange Group) is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth. Our culture of connecting, creating opportunity and delivering excellence shapes how we think, how we do things and how we help our people fulfil their potential.
Senior Vulnerability Management Engineer page is loaded Senior Vulnerability Management Engineerlocations: London, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: RLSEG is seeking a Senior Vulnerability Management Engineer to join our internal offensive security team with focus on driving closure of penetration testing findings. This role bridges offensive security and engineering by translating penetration test results into clear, actionable remediation guidance and partnering with application and platform teams to implement secure fixes. The successful candidate has a strong penetration testing or application security background, hands on remediation experience, and the ability to coordinate multiple collaborators to reduce risk at scale. This is a highly technical, delivery focused role with responsibility for both individual findings and systemic improvements. Key Responsibilities Analyze and review penetration test reports to understand technical impact, exploitability, and business risk. Develop, document and maintain remediation guidance, patterns, and blue-prints for common vulnerability types (e.g. injections, access control, auth, session management, misconfigurations). Provide consultation to application and platform teams on secure design and remediation approaches, including code-level, configuration-level and business-level recommendations. Coordinate remediation activities across multiple teams, ensuring, clear ownership, agreed timelines, and risk-based prioritization. Validate fixes by retesting vulnerabilities (manually and/or via tools/scripts) and updating the status of findings through closure. Manage and track the remediation backlog, including SLAs, aging finings, and critical issues when needed. Produce and maintain documentation on remediation processes, workflows, and controls for audit and compliance purposes. Prepare and deliver regular status reports and metrics on remediation progress, trends, and risk reduction to management and partners. Perform root cause analysis for recurring or systemic issues and work with engineering, architecture, and governance teams to implement long-term corrective actions. Contribute to continuous improvement of the pentest-to-remediation lifecycle, including automation, standardization and integration with SDLC/DevSecOps pipelines. Compile technical documents, track and document remediation metadata + Engagement details (who, what, when, where) + Testing team members and roles + Tools and methodologies used + Schedule and timelines + Target systems and environments + Constraints, exclusions, and limitations + Testing activities and event logs Contribute to team improvement efforts and ensure all initiatives and feedback are well documented for future references. Contribute to the continuous improvement of testing methodologies, tooling, automation. Stay ahead of with emerging threats, vulnerabilities, and offensive security techniques. Participate in R&D initiatives as guided from leadership. Support knowledge sharing and mentoring within the team. Required Skills & Experience Proven hands-on experience in penetration testing of Web Applications, APIs, Thick Client and Common Infrastructures (Active Directory, Cloud and Cloud-native based environments). Proficiency with tools such as Burp Suite, common command-line tools, and ability to write custom scripts when needed. Experience in automating pentesting tasks. Solid understanding of application security, network protocols, and operating systems. Experience with cloud platforms (AWS, Azure, GCP) and containerized environments (Docker, Kubernetes). Solid understanding of common vulnerabilities and exposures (OWASP Top 10, SANS Top 25) and secure coding practices in at least on major language stack (e.g. Java/Springboot, .NET, JavaScript/Node, Python) Ability to write clear, technical reports and communicate findings and fixes to both technical and non-technical partners. Experience working in large, complex enterprise environments. Proficient communication skills in English, both written and verbal. Relevant certifications and engagement with the security community is a plus Threat Modelling experience is a plus. Proven track record of successfully managing and driving security engagements for various organizations with differing operational and technical profiles. Ability to identify, assess, and communicate technical and project risks to partners. Understanding project requirements and aligning work with agreed upon objectives and timelines.Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership , Excellence and Change underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce.We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyone's race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.You will be part of a collaborative and creative culture where we encourage new ideas. We are committed to sustainability across our global business and we are proud to partner with our customers to help them meet their sustainability objectives. Our charity, the LSEG Foundation provides charitable grants to community groups that help people access economic opportunities and build a secure future with financial independence. Colleagues can get involved through fundraising and volunteering.LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.Please take a moment to read this carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what it's used for, and how it's obtained, .If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice.locations: London, United Kingdomtime type: Full timeposted on: Posted 30+ Days AgoLSEG (London Stock Exchange Group) is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth. Our culture of connecting, creating opportunity and delivering excellence shapes how we think, how we do things and how we help our people fulfil their potential.
Dec 10, 2025
Full time
Senior Vulnerability Management Engineer page is loaded Senior Vulnerability Management Engineerlocations: London, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: RLSEG is seeking a Senior Vulnerability Management Engineer to join our internal offensive security team with focus on driving closure of penetration testing findings. This role bridges offensive security and engineering by translating penetration test results into clear, actionable remediation guidance and partnering with application and platform teams to implement secure fixes. The successful candidate has a strong penetration testing or application security background, hands on remediation experience, and the ability to coordinate multiple collaborators to reduce risk at scale. This is a highly technical, delivery focused role with responsibility for both individual findings and systemic improvements. Key Responsibilities Analyze and review penetration test reports to understand technical impact, exploitability, and business risk. Develop, document and maintain remediation guidance, patterns, and blue-prints for common vulnerability types (e.g. injections, access control, auth, session management, misconfigurations). Provide consultation to application and platform teams on secure design and remediation approaches, including code-level, configuration-level and business-level recommendations. Coordinate remediation activities across multiple teams, ensuring, clear ownership, agreed timelines, and risk-based prioritization. Validate fixes by retesting vulnerabilities (manually and/or via tools/scripts) and updating the status of findings through closure. Manage and track the remediation backlog, including SLAs, aging finings, and critical issues when needed. Produce and maintain documentation on remediation processes, workflows, and controls for audit and compliance purposes. Prepare and deliver regular status reports and metrics on remediation progress, trends, and risk reduction to management and partners. Perform root cause analysis for recurring or systemic issues and work with engineering, architecture, and governance teams to implement long-term corrective actions. Contribute to continuous improvement of the pentest-to-remediation lifecycle, including automation, standardization and integration with SDLC/DevSecOps pipelines. Compile technical documents, track and document remediation metadata + Engagement details (who, what, when, where) + Testing team members and roles + Tools and methodologies used + Schedule and timelines + Target systems and environments + Constraints, exclusions, and limitations + Testing activities and event logs Contribute to team improvement efforts and ensure all initiatives and feedback are well documented for future references. Contribute to the continuous improvement of testing methodologies, tooling, automation. Stay ahead of with emerging threats, vulnerabilities, and offensive security techniques. Participate in R&D initiatives as guided from leadership. Support knowledge sharing and mentoring within the team. Required Skills & Experience Proven hands-on experience in penetration testing of Web Applications, APIs, Thick Client and Common Infrastructures (Active Directory, Cloud and Cloud-native based environments). Proficiency with tools such as Burp Suite, common command-line tools, and ability to write custom scripts when needed. Experience in automating pentesting tasks. Solid understanding of application security, network protocols, and operating systems. Experience with cloud platforms (AWS, Azure, GCP) and containerized environments (Docker, Kubernetes). Solid understanding of common vulnerabilities and exposures (OWASP Top 10, SANS Top 25) and secure coding practices in at least on major language stack (e.g. Java/Springboot, .NET, JavaScript/Node, Python) Ability to write clear, technical reports and communicate findings and fixes to both technical and non-technical partners. Experience working in large, complex enterprise environments. Proficient communication skills in English, both written and verbal. Relevant certifications and engagement with the security community is a plus Threat Modelling experience is a plus. Proven track record of successfully managing and driving security engagements for various organizations with differing operational and technical profiles. Ability to identify, assess, and communicate technical and project risks to partners. Understanding project requirements and aligning work with agreed upon objectives and timelines.Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership , Excellence and Change underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce.We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyone's race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.You will be part of a collaborative and creative culture where we encourage new ideas. We are committed to sustainability across our global business and we are proud to partner with our customers to help them meet their sustainability objectives. Our charity, the LSEG Foundation provides charitable grants to community groups that help people access economic opportunities and build a secure future with financial independence. Colleagues can get involved through fundraising and volunteering.LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.Please take a moment to read this carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what it's used for, and how it's obtained, .If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice.locations: London, United Kingdomtime type: Full timeposted on: Posted 30+ Days AgoLSEG (London Stock Exchange Group) is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth. Our culture of connecting, creating opportunity and delivering excellence shapes how we think, how we do things and how we help our people fulfil their potential.
Sanderson are currently looking to hire a Lead DevSecOps Engineer for a long-term client of ours. The role will be leading and contributing to the technical delivery of the DevSecOps processes, pipelines and integrated security tooling. Your role will involve Responsible for the technical implementation, delivery and assurance of the DevSecOps tooling, associated processes and ways of working click apply for full job details
Dec 10, 2025
Full time
Sanderson are currently looking to hire a Lead DevSecOps Engineer for a long-term client of ours. The role will be leading and contributing to the technical delivery of the DevSecOps processes, pipelines and integrated security tooling. Your role will involve Responsible for the technical implementation, delivery and assurance of the DevSecOps tooling, associated processes and ways of working click apply for full job details
We are seeking a highly motivated and experienced AWS Architect with strong DevOps expertise to support digital transformation across the UK public sector. This role is ideal for a self-starter who thrives in dynamic environments, is hands on with cloud technologies, and can operate both strategically and tactically. You will be instrumental in designing and delivering secure, scalable, and automated cloud solutions. Key Responsibilities Architect and implement secure, scalable, and resilient AWS cloud solutions. Lead DevOps practices including CI/CD pipeline development, infrastructure automation, and monitoring. Act as a trusted advisor to stakeholders, translating business needs into technical solutions. Drive cloud adoption and DevOps transformation initiatives across public sector projects. Ensure compliance with UK public sector regulations and security standards. Collaborate with cross-functional teams to deliver end to end cloud native solutions. Mentor engineering teams and promote best practices in cloud and DevOps. Take initiative in identifying opportunities for innovation and improvement. Essential Skills & Experience Several years of hands on experience with AWS architecture and services. Strong DevOps background with experience in automation, CI/CD, and infrastructure as code. Proficiency with tools such as Terraform, CloudFormation, Jenkins, GitLab CI, or AWS CodePipeline. Experience with containerization and orchestration (e.g., Docker, Kubernetes, ECS/EKS). Solid understanding of cloud security, identity management, and compliance frameworks. Demonstrated experience working in or with UK public sector organizations. Active UK Security Clearance (or eligibility to obtain). Ability to work independently, take ownership, and drive initiatives forward. Strong communication and collaboration skills; a true team player. Desirable Qualifications AWS Certified Solutions Architect - Professional AWS Certified DevOps Engineer - Professional Experience with monitoring and observability tools (e.g., CloudWatch, Prometheus, Grafana) Familiarity with Agile and DevSecOps methodologies
Dec 10, 2025
Full time
We are seeking a highly motivated and experienced AWS Architect with strong DevOps expertise to support digital transformation across the UK public sector. This role is ideal for a self-starter who thrives in dynamic environments, is hands on with cloud technologies, and can operate both strategically and tactically. You will be instrumental in designing and delivering secure, scalable, and automated cloud solutions. Key Responsibilities Architect and implement secure, scalable, and resilient AWS cloud solutions. Lead DevOps practices including CI/CD pipeline development, infrastructure automation, and monitoring. Act as a trusted advisor to stakeholders, translating business needs into technical solutions. Drive cloud adoption and DevOps transformation initiatives across public sector projects. Ensure compliance with UK public sector regulations and security standards. Collaborate with cross-functional teams to deliver end to end cloud native solutions. Mentor engineering teams and promote best practices in cloud and DevOps. Take initiative in identifying opportunities for innovation and improvement. Essential Skills & Experience Several years of hands on experience with AWS architecture and services. Strong DevOps background with experience in automation, CI/CD, and infrastructure as code. Proficiency with tools such as Terraform, CloudFormation, Jenkins, GitLab CI, or AWS CodePipeline. Experience with containerization and orchestration (e.g., Docker, Kubernetes, ECS/EKS). Solid understanding of cloud security, identity management, and compliance frameworks. Demonstrated experience working in or with UK public sector organizations. Active UK Security Clearance (or eligibility to obtain). Ability to work independently, take ownership, and drive initiatives forward. Strong communication and collaboration skills; a true team player. Desirable Qualifications AWS Certified Solutions Architect - Professional AWS Certified DevOps Engineer - Professional Experience with monitoring and observability tools (e.g., CloudWatch, Prometheus, Grafana) Familiarity with Agile and DevSecOps methodologies
Introduction At IBM CIC, we provide technical and industry expertise to a wide range of public and private sector clients in the UK. A career in IBM CIC means you'll have the opportunity to work with leading professionals across multiple industries to improve the hybrid cloud and AI journey for the most innovative and valuable companies in the world. You will get the chance to deliver effective solutions, driving meaningful business change for our clients, using some of the latest technology platforms. Curiosity and a constant quest for knowledge serve as the foundation to success here. You'll be encouraged and supported to constantly reinvent yourself, focusing on skills in demand in an ever changing market. You'll be working with diverse teams, coming up with creative solutions which impact a wide network of clients, who may be at their site or one of our CIC or IBM locations. Our culture of evolution centres on long-term career growth and development opportunities in an environment that embraces your unique skills and experience. We offer Many training opportunities from classroom to e-learning, mentoring and coaching programs and the chance to gain industry recognized certifications Regular and frequent promotion opportunities to ensure you can drive and develop your career with us Feedback and checkpoints throughout the year Diversity & Inclusion as an essential and authentic component of our culture through our policies and process as well as our Employee Champion teams and support networks A culture where your ideas for growth and innovation are always welcome Internal recognition programs for peer-to-peer appreciation as well as from manager to employees Tools and policies to support your work-life balance from flexible working approaches, sabbatical programs, paid paternity leave, maternity leave and an innovative maternity returners scheme Your role and responsibilities We are looking for a highly skilled Data Platforms Data Engineer to design and implement advanced data engineering solutions across complex environments. You will develop applications using Big Data technologies, building APIs and data pipelines that enable robust data integration and analytics. Your expertise in DataStage, Redshift, S3, and QuickSight will be essential for developing scalable data warehouses and dashboards. You will also apply your knowledge of analytics libraries, open-source Natural Language Processing, and statistical computing to enhance data insights. Working in an Agile environment, you will ensure data quality, security, and performance optimisation across all systems. This is a hands-on technical role requiring deep coding expertise and innovation in data platform engineering. Responsibilities Design and develop data pipelines and APIs using Big Data technologies. Implement and optimise ETL processes for batch and real-time data flows. Develop data warehouse solutions using Redshift and DataStage. Build dashboards and analytical reports using QuickSight. Apply DevSecOps practices to automate and secure data workflows. Required technical and professional expertise Strong proficiency in Java, SQL, and data pipeline development. Expertise in AWS data tools such as Redshift, S3, and QuickSight. Experience with DataStage or similar ETL frameworks. Knowledge of analytics libraries and open-source NLP tools. Familiarity with GitHub/GitLab and Agile development practices. Experience with data migration/ ETL both batch and real time, data warehouse development, DevSecOps, Java, sql, relational databases Preferred technical and professional experience Experience with Python or Spark for data processing. Understanding of data security and compliance frameworks. Background in statistical computing or machine learning integration. Exposure to containerisation or CI/CD pipelines. Eligibility As an equal opportunities' employer, we welcome applications from individuals of all backgrounds. However, for you to be eligible for this role, you must have the valid right to work in the UK. Unfortunately, we do not offer visa sponsorship and have no future plans to do so. You must be a resident in the UK and have been living continuously in the UK for the last 5 years. Equal opportunity statement IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
Dec 10, 2025
Full time
Introduction At IBM CIC, we provide technical and industry expertise to a wide range of public and private sector clients in the UK. A career in IBM CIC means you'll have the opportunity to work with leading professionals across multiple industries to improve the hybrid cloud and AI journey for the most innovative and valuable companies in the world. You will get the chance to deliver effective solutions, driving meaningful business change for our clients, using some of the latest technology platforms. Curiosity and a constant quest for knowledge serve as the foundation to success here. You'll be encouraged and supported to constantly reinvent yourself, focusing on skills in demand in an ever changing market. You'll be working with diverse teams, coming up with creative solutions which impact a wide network of clients, who may be at their site or one of our CIC or IBM locations. Our culture of evolution centres on long-term career growth and development opportunities in an environment that embraces your unique skills and experience. We offer Many training opportunities from classroom to e-learning, mentoring and coaching programs and the chance to gain industry recognized certifications Regular and frequent promotion opportunities to ensure you can drive and develop your career with us Feedback and checkpoints throughout the year Diversity & Inclusion as an essential and authentic component of our culture through our policies and process as well as our Employee Champion teams and support networks A culture where your ideas for growth and innovation are always welcome Internal recognition programs for peer-to-peer appreciation as well as from manager to employees Tools and policies to support your work-life balance from flexible working approaches, sabbatical programs, paid paternity leave, maternity leave and an innovative maternity returners scheme Your role and responsibilities We are looking for a highly skilled Data Platforms Data Engineer to design and implement advanced data engineering solutions across complex environments. You will develop applications using Big Data technologies, building APIs and data pipelines that enable robust data integration and analytics. Your expertise in DataStage, Redshift, S3, and QuickSight will be essential for developing scalable data warehouses and dashboards. You will also apply your knowledge of analytics libraries, open-source Natural Language Processing, and statistical computing to enhance data insights. Working in an Agile environment, you will ensure data quality, security, and performance optimisation across all systems. This is a hands-on technical role requiring deep coding expertise and innovation in data platform engineering. Responsibilities Design and develop data pipelines and APIs using Big Data technologies. Implement and optimise ETL processes for batch and real-time data flows. Develop data warehouse solutions using Redshift and DataStage. Build dashboards and analytical reports using QuickSight. Apply DevSecOps practices to automate and secure data workflows. Required technical and professional expertise Strong proficiency in Java, SQL, and data pipeline development. Expertise in AWS data tools such as Redshift, S3, and QuickSight. Experience with DataStage or similar ETL frameworks. Knowledge of analytics libraries and open-source NLP tools. Familiarity with GitHub/GitLab and Agile development practices. Experience with data migration/ ETL both batch and real time, data warehouse development, DevSecOps, Java, sql, relational databases Preferred technical and professional experience Experience with Python or Spark for data processing. Understanding of data security and compliance frameworks. Background in statistical computing or machine learning integration. Exposure to containerisation or CI/CD pipelines. Eligibility As an equal opportunities' employer, we welcome applications from individuals of all backgrounds. However, for you to be eligible for this role, you must have the valid right to work in the UK. Unfortunately, we do not offer visa sponsorship and have no future plans to do so. You must be a resident in the UK and have been living continuously in the UK for the last 5 years. Equal opportunity statement IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
The Associate is responsible for the design, implementation, maintenance, and support of the Bank's platforms and software solutions. The Associate plays a critical role within the squad, taking a lead on designing, developing and optimising EBRD's infrastructure and software solutions within their own value stream. The Associate provides guidance to individual contributors, and works closely with other multi-functional teams and business product owners, to deliver high quality, product aligned services, that meets our users' needs. The role may involve leading small projects and the individual is expected to be proficient in software design and ability to implement CI/CD pipeline, Infrastructure as Code (IaC) or technologies within their specialism. Accountabilities & Responsibilities Simplify to amplify: Working within the squad and across other multi-disciplinary teams, the Associate openly questions complexity within and across teams and aims to simplify. The Associate works with business Product Owners to challenge current processes and requests which add no real value and is open to similar challenges from others. The Associate adopts and role models a "progress over perfection" approach across the team to emphasize the importance of continuous and incremental improvements. The Associate is comfortable taking swift decisions within their sphere of responsibility and instils trust in others to encourage them to take their own. The Associate understands the power of the team and the need to support decisions made, even when these may not be ones they would personally make. The Associate recognises that enabling the team to take swift decisions more efficiently, increases EBRD's agility and our ability to deliver value quicker. Listen well and speak up : The Associate helps to create a continuous learning and growth culture where each team member feels safe to share their different perspectives and people do not fear being judged. They encourage and facilitate dialogue and share feedback positively, constructively and respectfully. They role model these behaviours. Collaborate smartly : The Associate takes an active role in establishing and encouraging a collaborative culture across a squad, mentoring new team members and fostering productive working relationships with peers in other multi-disciplinary teams. The Associate builds close relationships with critical business Product Owners and SMEs and constantly seeks to improve the delivery of services to the Business. Engineering Excellence : The Associate brings in-depth knowledge and experience and uses this to enable others within the team to be successful, though remains humble and is proactive in keeping updated with the latest technologies, tools and best practices within their field. The role will mentor and guide less experienced engineers, fostering a culture of technical excellence, innovation and learning. The role will work with colleagues to understand business needs, design optimal engineering architectures and ensure engineering quality throughout the lifecycle. Agile Ways of Working : The Associate is an established agile practitioner and will help the squad to adopt Agile Ways of Working. The role will build and maintain high-performing teams focused on delivering continuous value to our business whilst enabling teams to learn how to adopt an adaptive and iterative approach using experimentation and metrics to help learning and continuous improvement. Managing cost and budget: The Associate will follow the appropriate tooling to track time and effort. The Associate will not be directly responsible for budget management however would be responsible for effectively managing the value from technology and delivery partners. Quality at our core : The Associate ensures that technical excellence and a quality assurance mindset are embedded with their own and the team's work. This involves a strong focus on automation and use of industry best practices such as Test Driven Development to embed the mindset of accountability across the development lifecycle. Secure First : The Associate actively promotes and ensures engineering activities are fully aligned with EBRD Cyber and IT Security policies and procedures, and works to embed a DevSecOps culture and working practices. Working closely with IT security, engineering peers and architecture, the role will ensure that key security controls, toolchain automation, and risk/threat analysis is carried out at every stage of the work done by the team. Drives User Experience : The Associate ensures that services which are being developed and supported are based on user needs, which are captured in user stories and acceptance criteria. This helps keep users at the centre of engineering efforts, and enables teams to align with established user journeys and user experience goals, in support of business requirements. Knowledge, Skills, Experience & Qualifications Education and Qualifications Networks - Network Security Technology experience in this area includes but is not limited to: Perimeter Security, including firewalls, intrusion detection/ prevention (IDS/IPS), anti-malware and threat prevention (Check Point, Palo Alto Networks and Cisco). Cloud network security (Check Point and Microsoft Azure). Web Application Firewalls (WAFs) - SaaS / on Prem / Azure. SSL VPNs. Secure Access Service Edge (SASE). Macro and micro network segmentation and tagging. Load balancing, including Global Server Load Balancing (GSLB). Network Access Control (NAC) covering 802.1x, profiling and MAB. Wi-Fi security (encryption / authentication / IPS). RADIUS and TACACS authentication. PKI infrastructure / certificate deployment and operation. What is it like to work at the EBRD? Our agile and innovative approach is what makes life at the EBRD a unique experience! You will be part of a pioneering and diverse international organisation, and use your talents to make a real difference to people's lives and help shape the future of the regions we invest in. The EBRD environment provides you with: Varied, stimulating and engaging work that gives you an opportunity to interact with a wide range of experts in the financial, political, public and private sectors across the regions we invest in; A working culture that embraces inclusion and celebrates diversity; An environment that places sustainability, equality and digital transformation at the heart of what we do. Diversity is one of the Bank's core values which are at the heart of everything it does. A diverse workforce with the right knowledge and skills enables connection with our clients, brings pioneering ideas, energy and innovation. The EBRD staff is characterised by its rich diversity of nationalities, cultures and opinions and we aim to sustain and build on this strength. As such, the EBRD seeks to ensure that everyone is treated with respect and given equal opportunities and works in an inclusive environment. The EBRD encourages all qualified candidates who are nationals of the EBRD member countries to apply regardless of their racial, ethnic, religious and cultural background, gender, sexual orientation or disabilities. As an inclusive employer, we promote flexible working and expecting our employee to attend the office 50% of their working time. Job Segment: Network Engineer, Embedded, Sustainability, Testing, Engineer, Engineering, Technology, Energy
Dec 10, 2025
Full time
The Associate is responsible for the design, implementation, maintenance, and support of the Bank's platforms and software solutions. The Associate plays a critical role within the squad, taking a lead on designing, developing and optimising EBRD's infrastructure and software solutions within their own value stream. The Associate provides guidance to individual contributors, and works closely with other multi-functional teams and business product owners, to deliver high quality, product aligned services, that meets our users' needs. The role may involve leading small projects and the individual is expected to be proficient in software design and ability to implement CI/CD pipeline, Infrastructure as Code (IaC) or technologies within their specialism. Accountabilities & Responsibilities Simplify to amplify: Working within the squad and across other multi-disciplinary teams, the Associate openly questions complexity within and across teams and aims to simplify. The Associate works with business Product Owners to challenge current processes and requests which add no real value and is open to similar challenges from others. The Associate adopts and role models a "progress over perfection" approach across the team to emphasize the importance of continuous and incremental improvements. The Associate is comfortable taking swift decisions within their sphere of responsibility and instils trust in others to encourage them to take their own. The Associate understands the power of the team and the need to support decisions made, even when these may not be ones they would personally make. The Associate recognises that enabling the team to take swift decisions more efficiently, increases EBRD's agility and our ability to deliver value quicker. Listen well and speak up : The Associate helps to create a continuous learning and growth culture where each team member feels safe to share their different perspectives and people do not fear being judged. They encourage and facilitate dialogue and share feedback positively, constructively and respectfully. They role model these behaviours. Collaborate smartly : The Associate takes an active role in establishing and encouraging a collaborative culture across a squad, mentoring new team members and fostering productive working relationships with peers in other multi-disciplinary teams. The Associate builds close relationships with critical business Product Owners and SMEs and constantly seeks to improve the delivery of services to the Business. Engineering Excellence : The Associate brings in-depth knowledge and experience and uses this to enable others within the team to be successful, though remains humble and is proactive in keeping updated with the latest technologies, tools and best practices within their field. The role will mentor and guide less experienced engineers, fostering a culture of technical excellence, innovation and learning. The role will work with colleagues to understand business needs, design optimal engineering architectures and ensure engineering quality throughout the lifecycle. Agile Ways of Working : The Associate is an established agile practitioner and will help the squad to adopt Agile Ways of Working. The role will build and maintain high-performing teams focused on delivering continuous value to our business whilst enabling teams to learn how to adopt an adaptive and iterative approach using experimentation and metrics to help learning and continuous improvement. Managing cost and budget: The Associate will follow the appropriate tooling to track time and effort. The Associate will not be directly responsible for budget management however would be responsible for effectively managing the value from technology and delivery partners. Quality at our core : The Associate ensures that technical excellence and a quality assurance mindset are embedded with their own and the team's work. This involves a strong focus on automation and use of industry best practices such as Test Driven Development to embed the mindset of accountability across the development lifecycle. Secure First : The Associate actively promotes and ensures engineering activities are fully aligned with EBRD Cyber and IT Security policies and procedures, and works to embed a DevSecOps culture and working practices. Working closely with IT security, engineering peers and architecture, the role will ensure that key security controls, toolchain automation, and risk/threat analysis is carried out at every stage of the work done by the team. Drives User Experience : The Associate ensures that services which are being developed and supported are based on user needs, which are captured in user stories and acceptance criteria. This helps keep users at the centre of engineering efforts, and enables teams to align with established user journeys and user experience goals, in support of business requirements. Knowledge, Skills, Experience & Qualifications Education and Qualifications Networks - Network Security Technology experience in this area includes but is not limited to: Perimeter Security, including firewalls, intrusion detection/ prevention (IDS/IPS), anti-malware and threat prevention (Check Point, Palo Alto Networks and Cisco). Cloud network security (Check Point and Microsoft Azure). Web Application Firewalls (WAFs) - SaaS / on Prem / Azure. SSL VPNs. Secure Access Service Edge (SASE). Macro and micro network segmentation and tagging. Load balancing, including Global Server Load Balancing (GSLB). Network Access Control (NAC) covering 802.1x, profiling and MAB. Wi-Fi security (encryption / authentication / IPS). RADIUS and TACACS authentication. PKI infrastructure / certificate deployment and operation. What is it like to work at the EBRD? Our agile and innovative approach is what makes life at the EBRD a unique experience! You will be part of a pioneering and diverse international organisation, and use your talents to make a real difference to people's lives and help shape the future of the regions we invest in. The EBRD environment provides you with: Varied, stimulating and engaging work that gives you an opportunity to interact with a wide range of experts in the financial, political, public and private sectors across the regions we invest in; A working culture that embraces inclusion and celebrates diversity; An environment that places sustainability, equality and digital transformation at the heart of what we do. Diversity is one of the Bank's core values which are at the heart of everything it does. A diverse workforce with the right knowledge and skills enables connection with our clients, brings pioneering ideas, energy and innovation. The EBRD staff is characterised by its rich diversity of nationalities, cultures and opinions and we aim to sustain and build on this strength. As such, the EBRD seeks to ensure that everyone is treated with respect and given equal opportunities and works in an inclusive environment. The EBRD encourages all qualified candidates who are nationals of the EBRD member countries to apply regardless of their racial, ethnic, religious and cultural background, gender, sexual orientation or disabilities. As an inclusive employer, we promote flexible working and expecting our employee to attend the office 50% of their working time. Job Segment: Network Engineer, Embedded, Sustainability, Testing, Engineer, Engineering, Technology, Energy
Locations : Boston London Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures-and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive. What You'll Do The Global Delivery Director - Secure Data is a critical leadership role that enables the secure foundation of BCG's digital operations globally. By driving scalable, automated, and user-focused security engineering-and by embedding security into modern engineering and operational practices-this role ensures BCG can innovate securely while maintaining trust, compliance, and operational excellence. The Global Delivery Director - Secure Data is responsible for leading the design, delivery, and continuous evolution of BCG's data security strategy and controls. This role ensures that BCG's most sensitive data is protected globally through secure-by-design engineering, automation at scale, and resilient security platforms. The Director will drive strategic planning, execution, and operations of scalable, automated, and resilient security solutions that safeguard BCG's global operations and users, while enabling innovation and agility across BCG Core, BCG X, and CT worldwide. This role is accountable for embedding security within DevSecOps practices, applying Site Reliability Engineering (SRE) principles across all security services, and aligning with privacy, compliance, and business leaders to maintain trust and regulatory compliance. Key Responsibilities: Strategic Leadership & Transformation: Define and execute a unified security engineering strategy that addresses data protection across all environments and data lifecycle stages. Lead the design and implementation of scalable, automated solutions that integrate seamlessly into enterprise platforms and user experiences. Establish a global security architecture and engineering roadmap focused on prevention, detection, and rapid response. Drive continuous improvement of security posture while aligning with business needs, regulatory requirements, and user experience expectations. Champion DevSecOps practices to embed security early into development and delivery workflows. Data Security Engineering: Build and operate scalable data protection solutions, including data loss prevention (DLP), secrets management, encryption, and classification. Collaborate with the IAM team to align authentication, authorization, and privileged access policies with data security controls. Deliver security capabilities that support modern work scenarios, remote access, zero-trust networking, and protection of sensitive data in AI/ML workloads. Leverage automation frameworks and IaC to improve scalability and reduce manual intervention. Operational Security, SRE & Assurance: Ensure security platforms are resilient, continuously monitored, and designed for 24x7 support and incident response readiness. Embed security telemetry and observability to enable proactive threat detection and automated response. Apply SRE principles to improve reliability, performance, and maintainability of security services. Define service level objectives (SLOs) and key performance indicators (KPIs) for all security services. Compliance, Governance & Risk Management: Ensure alignment with global compliance requirements such as ISO 27001, NIST, SOC 2, GDPR, and others. Partner with governance, legal, and ISRM teams to implement enforceable policies and standards across identity, endpoint, and data domains. Implement automated compliance controls and continuous assurance checks. Lead risk mitigation efforts with technical solutions that scale across diverse user and system profiles. Financial & Vendor Management: Manage security platform budgets and investments with a focus on cost optimization and long-term value. Evaluate and manage third-party vendors and partners, ensuring they meet technical, contractual, and security expectations. Lead procurement and renewal cycles in alignment with operational and architectural strategies. Leadership & Talent Development: Build and mentor a global team of security engineers, fostering a high-performance, collaborative, and forward-thinking culture. Drive internal knowledge sharing and upskilling programs across the team. Collaborate cross-functionally with platform, product, and enterprise architecture teams to embed security early and often. What You'll Bring Required Qualifications: 10+ years of experience in cybersecurity, security engineering, or platform security roles. 5+ years in a senior leadership position with accountability for enterprise-scale security platforms. Deep expertise in data protection technologies, with proven ability to design and scale global solutions. Experience with security engineering in hybrid and cloud-native environments (AWS, Azure, GCP). Proven track record in automating security controls, implementing zero-trust models, and supporting 24x7 security operations. Strong understanding of compliance frameworks and risk management strategies. Demonstrated ability to present complex security topics to executive leadership. Preferred Qualifications: Certifications such as CISSP, CCSP, CISM, AWS/Azure Security Specialty, or equivalent. Experience with tools like Symantec DLP, Zscaler CASB, MS Purview, Palo Alto Prisma, Hashi Vault and other modern security platforms. Familiarity with DevSecOps principles, Infrastructure as Code, and secure software development practices. Who You'll Work With Work Environment & Additional Information: Hybrid or on-site work model. Occasional travel may be required for business, vendor, or team engagement. Ability to operate in a fast-paced, complex environment, balancing long-term strategy with operational agility. Additional info For US locations only In the US, we have a compensation transparency approach. Total compensation for this role includes base salary, annual discretionary performance bonus, retirement contribution, and a market leading benefits package described below. The base salary range for this role in Boston is $181,000.00 - $221,000.00 This is an estimated range, however, specific base salaries within the range depend on various factors such as experience and skill set. It is not common for new BCG employees to be hired at the high-end of the salary range. BCG regularly reviews its ranges to ensure market competitiveness. In addition to your base salary, your total compensation will include a bonus of up to 30% and a generous retirement contribution that starts at 5% and moves to 10% after 2 years. All of our plans provide best in class coverage: Zero dollar ($0) health insurance premiums for BCG employees, spouses, and children Low $10 (USD) copays for trips to the doctor, urgent care visits and prescriptions for generic drugs Dental coverage, including up to $5,000 in orthodontia benefits Vision insurance with coverage for both glasses and contact lenses annually Reimbursement for gym memberships and other fitness activities Fully vested Profit Sharing Retirement Fund contributions made annually, whether you contribute or not, plus the option for employees to make personal contributions to a 401(k) plan Paid Parental Leave and other family benefits such as elective egg freezing, surrogacy, and adoption reimbursement Generous paid time off including 12 holidays per year, an annual office closure between Christmas and New Years, and 15 vacation days per year (earned at 1.25 days per month) Paid sick time on an as needed basis Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify.
Dec 09, 2025
Full time
Locations : Boston London Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures-and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive. What You'll Do The Global Delivery Director - Secure Data is a critical leadership role that enables the secure foundation of BCG's digital operations globally. By driving scalable, automated, and user-focused security engineering-and by embedding security into modern engineering and operational practices-this role ensures BCG can innovate securely while maintaining trust, compliance, and operational excellence. The Global Delivery Director - Secure Data is responsible for leading the design, delivery, and continuous evolution of BCG's data security strategy and controls. This role ensures that BCG's most sensitive data is protected globally through secure-by-design engineering, automation at scale, and resilient security platforms. The Director will drive strategic planning, execution, and operations of scalable, automated, and resilient security solutions that safeguard BCG's global operations and users, while enabling innovation and agility across BCG Core, BCG X, and CT worldwide. This role is accountable for embedding security within DevSecOps practices, applying Site Reliability Engineering (SRE) principles across all security services, and aligning with privacy, compliance, and business leaders to maintain trust and regulatory compliance. Key Responsibilities: Strategic Leadership & Transformation: Define and execute a unified security engineering strategy that addresses data protection across all environments and data lifecycle stages. Lead the design and implementation of scalable, automated solutions that integrate seamlessly into enterprise platforms and user experiences. Establish a global security architecture and engineering roadmap focused on prevention, detection, and rapid response. Drive continuous improvement of security posture while aligning with business needs, regulatory requirements, and user experience expectations. Champion DevSecOps practices to embed security early into development and delivery workflows. Data Security Engineering: Build and operate scalable data protection solutions, including data loss prevention (DLP), secrets management, encryption, and classification. Collaborate with the IAM team to align authentication, authorization, and privileged access policies with data security controls. Deliver security capabilities that support modern work scenarios, remote access, zero-trust networking, and protection of sensitive data in AI/ML workloads. Leverage automation frameworks and IaC to improve scalability and reduce manual intervention. Operational Security, SRE & Assurance: Ensure security platforms are resilient, continuously monitored, and designed for 24x7 support and incident response readiness. Embed security telemetry and observability to enable proactive threat detection and automated response. Apply SRE principles to improve reliability, performance, and maintainability of security services. Define service level objectives (SLOs) and key performance indicators (KPIs) for all security services. Compliance, Governance & Risk Management: Ensure alignment with global compliance requirements such as ISO 27001, NIST, SOC 2, GDPR, and others. Partner with governance, legal, and ISRM teams to implement enforceable policies and standards across identity, endpoint, and data domains. Implement automated compliance controls and continuous assurance checks. Lead risk mitigation efforts with technical solutions that scale across diverse user and system profiles. Financial & Vendor Management: Manage security platform budgets and investments with a focus on cost optimization and long-term value. Evaluate and manage third-party vendors and partners, ensuring they meet technical, contractual, and security expectations. Lead procurement and renewal cycles in alignment with operational and architectural strategies. Leadership & Talent Development: Build and mentor a global team of security engineers, fostering a high-performance, collaborative, and forward-thinking culture. Drive internal knowledge sharing and upskilling programs across the team. Collaborate cross-functionally with platform, product, and enterprise architecture teams to embed security early and often. What You'll Bring Required Qualifications: 10+ years of experience in cybersecurity, security engineering, or platform security roles. 5+ years in a senior leadership position with accountability for enterprise-scale security platforms. Deep expertise in data protection technologies, with proven ability to design and scale global solutions. Experience with security engineering in hybrid and cloud-native environments (AWS, Azure, GCP). Proven track record in automating security controls, implementing zero-trust models, and supporting 24x7 security operations. Strong understanding of compliance frameworks and risk management strategies. Demonstrated ability to present complex security topics to executive leadership. Preferred Qualifications: Certifications such as CISSP, CCSP, CISM, AWS/Azure Security Specialty, or equivalent. Experience with tools like Symantec DLP, Zscaler CASB, MS Purview, Palo Alto Prisma, Hashi Vault and other modern security platforms. Familiarity with DevSecOps principles, Infrastructure as Code, and secure software development practices. Who You'll Work With Work Environment & Additional Information: Hybrid or on-site work model. Occasional travel may be required for business, vendor, or team engagement. Ability to operate in a fast-paced, complex environment, balancing long-term strategy with operational agility. Additional info For US locations only In the US, we have a compensation transparency approach. Total compensation for this role includes base salary, annual discretionary performance bonus, retirement contribution, and a market leading benefits package described below. The base salary range for this role in Boston is $181,000.00 - $221,000.00 This is an estimated range, however, specific base salaries within the range depend on various factors such as experience and skill set. It is not common for new BCG employees to be hired at the high-end of the salary range. BCG regularly reviews its ranges to ensure market competitiveness. In addition to your base salary, your total compensation will include a bonus of up to 30% and a generous retirement contribution that starts at 5% and moves to 10% after 2 years. All of our plans provide best in class coverage: Zero dollar ($0) health insurance premiums for BCG employees, spouses, and children Low $10 (USD) copays for trips to the doctor, urgent care visits and prescriptions for generic drugs Dental coverage, including up to $5,000 in orthodontia benefits Vision insurance with coverage for both glasses and contact lenses annually Reimbursement for gym memberships and other fitness activities Fully vested Profit Sharing Retirement Fund contributions made annually, whether you contribute or not, plus the option for employees to make personal contributions to a 401(k) plan Paid Parental Leave and other family benefits such as elective egg freezing, surrogacy, and adoption reimbursement Generous paid time off including 12 holidays per year, an annual office closure between Christmas and New Years, and 15 vacation days per year (earned at 1.25 days per month) Paid sick time on an as needed basis Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify.
At Trustpilot, we're on an incredible journey. We're a profitable, high-growth FTSE-250 company with a big vision: to become the universal symbol of trust. We run the world's largest independent consumer review platform, and while we've come a long way, there's still so much exciting work to do. Come join us at the heart of trust! We are searching for a SecOps Engineer to enable us to continue to advance the security of our products, our data, our infrastructures, our people, to protect our brand and reputation. This is a great chance to learn and develop within a forward-thinking DevSecOps focused team. This is a wide-ranging role, an opportunity to propel important work streams which could range from supporting the build out of our threat hunting and operations capabilities, improving our playbooks and breach response, to Cloud anomaly detection and response. What you'll be doing: Enhance our Security Operations capabilities and abilities to threat hunt Work closely with other team members and the Security Operations Lead on roadmap planning and delivery Mature metrics and KPI's Run with incidents and investigations into alerts Keep up to date with current security trends, advisories, publications and security research across the industry Contribute to facilitate an awesome culture of trust by engaging across the business, evangelising Security across both tech and non-tech areas Participate in an on-call rotation (avg 10 out of 52 weeks) to handle urgent-only, out-of-hour's needs, for which you will be additionally compensated. Who you are: Keen interest in security and want to develop Experience in SIEM or SOAR Knowledge of the MITRE ATT,CK Framework or common attack and response methods Previous experience with incident response in a fast-paced environment Knowledge of Cloud environments AWS or GCP Python experience preferred Benefits: A range of flexible working options to dedicate time to what matters to you Competitive compensation package + bonus 25 days holiday per year, increasing to 28 days after 2 years of employment Two (paid) volunteering days a year to spend your time giving back to the causes that matter to you and your community Rich learning and development opportunities are supported through the Trustpilot Academy and Blinkist Pension and life insurance Health cash plan, online GP, 24/7, Employee Assistance Plan Full access to Headspace, a popular mindfulness app to promote positive mental health Paid parental leave Season ticket loan and a cycle-to-work scheme Central office location complete with table tennis, a gaming corner, coffee bars and all the snacks and refreshments you can ask for Regular opportunities to connect and get to know your fellow Trusties, including company-wide celebrations and events, ERG activities, and team socials. Access to over 4,000 deals and discounts on things like travel, electronics, fashion, fitness, cinema discounts, and more. Independent financial advice and free standard professional mortgage broker advice Talent acceleration programs: Fast-track your career with our tailored development programs designed to support growth at whatever stage of your career About us Trustpilot began in 2007 with a simple yet powerful idea that is more relevant today than ever - to be the universal symbol of trust, bringing consumers and businesses together through reviews. Trustpilot is open, independent, and impartial - we help consumers make the right choices and businesses to build trust, grow and improve. Today, we have more than 300 million reviews and 64 million monthly active users on average across the globe, with 140 billion annual Trustbox impressions, and the numbers keep growing. We have more than 1,000 employees and we're headquartered in Copenhagen, with operations in Amsterdam, Denver, Edinburgh, Hamburg, London, Melbourne, Milan and New York. We're driven by connection. It's at the heart of what we do. Our culture keeps things fresh it's built on the relationships we create. We talk, we laugh, we collaborate and we respect each other. We work across borders and cultures to be the universal symbol of trust in an ever-changing world. With vibrant office locations worldwide and over 50 nationalities, we're proud to be an equal opportunity workplace with diverse perspectives and ideas. Our purpose to help people and businesses help each other is a tall order, but we keep it real. We're a great bunch of humans, doing awesome stuff, without fuss or pretense. A successful Trustpilot future is driven by you we give you the autonomy to shape a career you can be proud of. If you're ready to grow, let's go. Join us at the heart of trust. Trustpilot is committed to creating an inclusive environment where people from all backgrounds can thrive and where different viewpoints and experiences are valued and respected. Trustpilot will consider all applications for employment without regard to race, ethnicity, national origin, religious beliefs, gender identity or expression, sexual orientation, neurodiversity, disability, age, parental or veteran status. Together, we are the heart of trust. Trustpilot is a global company and our data practices are designed to ensure that your personally identifiable information is appropriately protected. Please note that your personal information will be transferred, accessed, and stored globally as necessary for the uses and disclosures stated in our Privacy Policy. If you have a disability and would like to discuss any adjustments you might need either in submitting your application, or to the recruitment process more generally, please let us know by contacting our Talent Acquisition Team (). Quoting the role you wish to apply for. Any offer of employment for this position will be subject to our standard background checks.
Dec 09, 2025
Full time
At Trustpilot, we're on an incredible journey. We're a profitable, high-growth FTSE-250 company with a big vision: to become the universal symbol of trust. We run the world's largest independent consumer review platform, and while we've come a long way, there's still so much exciting work to do. Come join us at the heart of trust! We are searching for a SecOps Engineer to enable us to continue to advance the security of our products, our data, our infrastructures, our people, to protect our brand and reputation. This is a great chance to learn and develop within a forward-thinking DevSecOps focused team. This is a wide-ranging role, an opportunity to propel important work streams which could range from supporting the build out of our threat hunting and operations capabilities, improving our playbooks and breach response, to Cloud anomaly detection and response. What you'll be doing: Enhance our Security Operations capabilities and abilities to threat hunt Work closely with other team members and the Security Operations Lead on roadmap planning and delivery Mature metrics and KPI's Run with incidents and investigations into alerts Keep up to date with current security trends, advisories, publications and security research across the industry Contribute to facilitate an awesome culture of trust by engaging across the business, evangelising Security across both tech and non-tech areas Participate in an on-call rotation (avg 10 out of 52 weeks) to handle urgent-only, out-of-hour's needs, for which you will be additionally compensated. Who you are: Keen interest in security and want to develop Experience in SIEM or SOAR Knowledge of the MITRE ATT,CK Framework or common attack and response methods Previous experience with incident response in a fast-paced environment Knowledge of Cloud environments AWS or GCP Python experience preferred Benefits: A range of flexible working options to dedicate time to what matters to you Competitive compensation package + bonus 25 days holiday per year, increasing to 28 days after 2 years of employment Two (paid) volunteering days a year to spend your time giving back to the causes that matter to you and your community Rich learning and development opportunities are supported through the Trustpilot Academy and Blinkist Pension and life insurance Health cash plan, online GP, 24/7, Employee Assistance Plan Full access to Headspace, a popular mindfulness app to promote positive mental health Paid parental leave Season ticket loan and a cycle-to-work scheme Central office location complete with table tennis, a gaming corner, coffee bars and all the snacks and refreshments you can ask for Regular opportunities to connect and get to know your fellow Trusties, including company-wide celebrations and events, ERG activities, and team socials. Access to over 4,000 deals and discounts on things like travel, electronics, fashion, fitness, cinema discounts, and more. Independent financial advice and free standard professional mortgage broker advice Talent acceleration programs: Fast-track your career with our tailored development programs designed to support growth at whatever stage of your career About us Trustpilot began in 2007 with a simple yet powerful idea that is more relevant today than ever - to be the universal symbol of trust, bringing consumers and businesses together through reviews. Trustpilot is open, independent, and impartial - we help consumers make the right choices and businesses to build trust, grow and improve. Today, we have more than 300 million reviews and 64 million monthly active users on average across the globe, with 140 billion annual Trustbox impressions, and the numbers keep growing. We have more than 1,000 employees and we're headquartered in Copenhagen, with operations in Amsterdam, Denver, Edinburgh, Hamburg, London, Melbourne, Milan and New York. We're driven by connection. It's at the heart of what we do. Our culture keeps things fresh it's built on the relationships we create. We talk, we laugh, we collaborate and we respect each other. We work across borders and cultures to be the universal symbol of trust in an ever-changing world. With vibrant office locations worldwide and over 50 nationalities, we're proud to be an equal opportunity workplace with diverse perspectives and ideas. Our purpose to help people and businesses help each other is a tall order, but we keep it real. We're a great bunch of humans, doing awesome stuff, without fuss or pretense. A successful Trustpilot future is driven by you we give you the autonomy to shape a career you can be proud of. If you're ready to grow, let's go. Join us at the heart of trust. Trustpilot is committed to creating an inclusive environment where people from all backgrounds can thrive and where different viewpoints and experiences are valued and respected. Trustpilot will consider all applications for employment without regard to race, ethnicity, national origin, religious beliefs, gender identity or expression, sexual orientation, neurodiversity, disability, age, parental or veteran status. Together, we are the heart of trust. Trustpilot is a global company and our data practices are designed to ensure that your personally identifiable information is appropriately protected. Please note that your personal information will be transferred, accessed, and stored globally as necessary for the uses and disclosures stated in our Privacy Policy. If you have a disability and would like to discuss any adjustments you might need either in submitting your application, or to the recruitment process more generally, please let us know by contacting our Talent Acquisition Team (). Quoting the role you wish to apply for. Any offer of employment for this position will be subject to our standard background checks.
A leading security-focused technology company in Leeds is seeking an experienced DevSecOps professional. In this role, you will integrate security practices, assess vulnerabilities, and work closely with development teams. The ideal candidate has 3-5 years of relevant experience, strong mentorship abilities, and a comprehensive knowledge of security frameworks such as OWASP and Snyk, along with familiarity in various programming languages and cloud security practices. This position offers a competitive salary and excellent benefits.
Dec 09, 2025
Full time
A leading security-focused technology company in Leeds is seeking an experienced DevSecOps professional. In this role, you will integrate security practices, assess vulnerabilities, and work closely with development teams. The ideal candidate has 3-5 years of relevant experience, strong mentorship abilities, and a comprehensive knowledge of security frameworks such as OWASP and Snyk, along with familiarity in various programming languages and cloud security practices. This position offers a competitive salary and excellent benefits.
A leading IT Systems Integrator is seeking a Lead DevSecOps Engineer to drive the technical delivery of CI/CD pipelines and integrated security tooling. This role offers significant responsibilities in implementation and mentoring junior engineers, with an attractive benefits package including a salary of £78k plus bonuses and flexible benefits. Suitable candidates must be eligible for SC and DV clearance to work within the UK defence sector.
Dec 08, 2025
Full time
A leading IT Systems Integrator is seeking a Lead DevSecOps Engineer to drive the technical delivery of CI/CD pipelines and integrated security tooling. This role offers significant responsibilities in implementation and mentoring junior engineers, with an attractive benefits package including a salary of £78k plus bonuses and flexible benefits. Suitable candidates must be eligible for SC and DV clearance to work within the UK defence sector.
Get Staffed Online Recruitment Limited
Melton Mowbray, Leicestershire
Cyber Security Consultant £30,000 £45,000 per annum Melton Mowbray Role Summary Our client is a growing MSP based in Melton Mowbray, helping organisations of all sizes strengthen their security posture and achieve recognised certifications. They are looking for a skilled Cyber Security Consultant specialising in Penetration Testing to deliver high-quality security testing and assurance across a diverse client base. You ll lead and support security assessments including network, web application, mobile, cloud, wireless, and internal infrastructure testing, alongside Cyber Essentials and Cyber Essentials Plus (CE/CE+) assessments. This role suits someone who enjoys hands-on technical work, clear reporting, and helping clients improve their security posture in practical, measurable ways. This is primarily an office-based role that will require occasional travel to client sites. Key Responsibilities Penetration Testing and Security Assessments: Deliver CREST-aligned penetration tests across external and internal networks, web applications and APIs, mobile applications (iOS/Android), and Cloud environments (Azure, AWS, GCP). Wireless networks and remote working setups. Security configuration and segmentation reviews. Perform vulnerability assessments and risk-based testing using industry best practices. Validate findings, reproduce issues, and advise on realistic remediation. Support red team / adversarial simulation exercises where appropriate. Cyber Essentials and Cyber Essentials Plus: Conduct Cyber Essentials readiness reviews, gap assessments, and remediation guidance. Lead Cyber Essentials Plus technical audits, including sampling, evidence review, and on-site/remote verification. Help clients interpret requirements and maintain compliance across re-certification cycles. Ensure assessments are completed to scheme standards and timelines. Reporting and Client Engagement: Produce clear, high-quality technical reports with actionable remediation advice. Present findings to technical and non-technical stakeholders. Provide pragmatic risk prioritisation and security improvement roadmaps. Contribute to scoping calls, statements of work, and test planning. Continuous Improvement: Maintain current knowledge of security threats, tooling, and testing methodologies. Contribute to internal playbooks, checklists, and training materials. Support junior consultants through mentoring and peer review. Essential Skills and Experience: Proven experience delivering penetration tests in commercial or consultancy settings. Strong understanding of OWASP Top 10 / ASVS, common exploitation techniques and mitigations, network protocols, Active Directory, and Windows/Linux environments, and cloud security fundamentals. Hands-on ability with common tools such as Burp Suite, Nmap, Metasploit, Nessus/Qualys, Wireshark, BloodHound, etc. Confident communicator with excellent report-writing skills. Solid grasp of compliance-driven security testing (esp. Cyber Essentials/CE+). Full UK Driving Licence. Desirable Skills and Certifications: CREST CRT/CCRT/CCT or CHECK Team Member. OSCP / OSWE / OSEP / GPEN / eCPPT / similar. Experience with secure code review, SAST/DAST pipelines, or DevSecOps. Familiarity with ISO 27001 or wider GRC frameworks. What Our Client Offers: Competitive salary and annual performance bonus. Training budget and certification support. Clear progression path into Senior/Lead Consultant roles. Flexible working and wellbeing support. Exposure to varied, interesting client environments and modern tech stacks. Collaborative team culture focused on quality and continuous learning. Click apply and upload your CV.
Dec 08, 2025
Full time
Cyber Security Consultant £30,000 £45,000 per annum Melton Mowbray Role Summary Our client is a growing MSP based in Melton Mowbray, helping organisations of all sizes strengthen their security posture and achieve recognised certifications. They are looking for a skilled Cyber Security Consultant specialising in Penetration Testing to deliver high-quality security testing and assurance across a diverse client base. You ll lead and support security assessments including network, web application, mobile, cloud, wireless, and internal infrastructure testing, alongside Cyber Essentials and Cyber Essentials Plus (CE/CE+) assessments. This role suits someone who enjoys hands-on technical work, clear reporting, and helping clients improve their security posture in practical, measurable ways. This is primarily an office-based role that will require occasional travel to client sites. Key Responsibilities Penetration Testing and Security Assessments: Deliver CREST-aligned penetration tests across external and internal networks, web applications and APIs, mobile applications (iOS/Android), and Cloud environments (Azure, AWS, GCP). Wireless networks and remote working setups. Security configuration and segmentation reviews. Perform vulnerability assessments and risk-based testing using industry best practices. Validate findings, reproduce issues, and advise on realistic remediation. Support red team / adversarial simulation exercises where appropriate. Cyber Essentials and Cyber Essentials Plus: Conduct Cyber Essentials readiness reviews, gap assessments, and remediation guidance. Lead Cyber Essentials Plus technical audits, including sampling, evidence review, and on-site/remote verification. Help clients interpret requirements and maintain compliance across re-certification cycles. Ensure assessments are completed to scheme standards and timelines. Reporting and Client Engagement: Produce clear, high-quality technical reports with actionable remediation advice. Present findings to technical and non-technical stakeholders. Provide pragmatic risk prioritisation and security improvement roadmaps. Contribute to scoping calls, statements of work, and test planning. Continuous Improvement: Maintain current knowledge of security threats, tooling, and testing methodologies. Contribute to internal playbooks, checklists, and training materials. Support junior consultants through mentoring and peer review. Essential Skills and Experience: Proven experience delivering penetration tests in commercial or consultancy settings. Strong understanding of OWASP Top 10 / ASVS, common exploitation techniques and mitigations, network protocols, Active Directory, and Windows/Linux environments, and cloud security fundamentals. Hands-on ability with common tools such as Burp Suite, Nmap, Metasploit, Nessus/Qualys, Wireshark, BloodHound, etc. Confident communicator with excellent report-writing skills. Solid grasp of compliance-driven security testing (esp. Cyber Essentials/CE+). Full UK Driving Licence. Desirable Skills and Certifications: CREST CRT/CCRT/CCT or CHECK Team Member. OSCP / OSWE / OSEP / GPEN / eCPPT / similar. Experience with secure code review, SAST/DAST pipelines, or DevSecOps. Familiarity with ISO 27001 or wider GRC frameworks. What Our Client Offers: Competitive salary and annual performance bonus. Training budget and certification support. Clear progression path into Senior/Lead Consultant roles. Flexible working and wellbeing support. Exposure to varied, interesting client environments and modern tech stacks. Collaborative team culture focused on quality and continuous learning. Click apply and upload your CV.
Information Security Officer R58724 Department: IT Employment Type: Permanent - Full Time Location: Milton Keynes Compensation: £50,000 - £60,000 / year Description Here's what you need to know about Kinetic At Kinetic, we're redefining operational excellence in higher education, conferencing, and events. As the leading provider of software solutions for student accommodation, event management, catering, and residential services, we help institutions streamline operations, elevate customer experiences, and unlock their full potential. With over 25 years of experience and trusted by more than 350 institutions worldwide, our software empowers universities and venues to run smarter, faster, and more collaboratively. From bustling campuses to dynamic corporate environments, our technology adapts to the rhythm of each organisation - helping them thrive in a fast-changing world. But we're more than just software. We're a team of passionate problem-solvers, innovators, and collaborators who care deeply about our customers and each other. Our culture is built on empowerment, community, and continuous growth. We believe in giving people the tools, support, and freedom to do their best work - and have fun while doing it. Joining Kinetic means being part of a purpose-driven business where your ideas matter, your development is supported, and your impact is real. If you're ready to help shape the future of operational technology in education and events, we'd love to meet you. What will I be bringing to life in this role? We're seeking an experienced Information Security Officer to lead security strategy, operations, and compliance. This is a hands-on role combining strategic security architecture with operational security management and regulatory compliance oversight. The successful candidate will define security standards across our product portfolio, manage security environments, and serve as our central point for ISO27001, PCI/DSS, and GDPR compliance while supporting commercial teams with tender responses and client security assurance. Core Responsibilities Strategic (30%) Define technical security architecture and standards across multi-cloud SaaS platforms Embed security into product development lifecycle and roadmap planning Conduct threat modeling and risk assessments for new features and system changes Evaluate and recommend security technologies and tools Operational (40%) Manage security environments across Azure and AWS infrastructure Coordinate security incident response and vulnerability remediation Oversee security monitoring, alerting, and detection capabilities Manage vulnerability assessment and penetration testing programs Maintain identity and access management controls Compliance & Assurance (30%) Maintain ISO27001 certification and manage audit cycles Ensure PCI/DSS compliance for payment processing systems Manage GDPR compliance across all products and operations Complete HECVAT and security questionnaires for higher education tenders Support sales and customer success with security documentation and evidence Act as primary security contact for customers and prospects What will I need to hit the ground running? Essential Requirements Substantial information security experience in SaaS/cloud software environment (ISV or B2B software preferred) Proven track record managing ISO27001 certification and compliance Practical GDPR implementation experience in software products PCI/DSS compliance experience with payment processing systems Strong understanding of cloud security (Azure and/or AWS) Application security and secure development lifecycle knowledge Security incident management and cross-functional response coordination Excellent communication skills - able to translate technical security for commercial and executive audiences Experience supporting tender responses and client security assurance Preferred/Nice-to-Have Professional certifications: CISSP, CISM, CISA, or equivalent Higher education sector experience Multi-tenant SaaS architecture security experience DevSecOps and CI/CD security integration knowledge Security frameworks: NIST, CIS Controls, OWASP Multi-jurisdictional data protection knowledge Enterprise sales cycle support experience Key Attributes Strategic thinker who can balance security with business needs Pragmatic approach to security implementation Detail-oriented with strong organizational skills Collaborative and able to influence across teams Proactive in identifying risks and improvement opportunities Comfortable in fast-paced, dynamic environment What extras will make me thrive? At Kinetic, we believe work should come with rewards that make a real difference. Here's just a taste of what you can expect when you join us: 25 days holiday (plus bank holidays) - with extra days the longer you're with us Two paid wellbeing days each year, with a budget to enjoy some time out with someone important to you Enhanced pension contributions to support your future Two paid days a year to give back through volunteering, charity work, or sustainability projects with our Green Team Salary sacrifice schemes for electric vehicles and cycle-to-work 24/7 access to our Employee Assistance Programme for confidential advice and support A full annual health check to keep you at your best A flexible benefits platform - from life assurance and learning opportunities to retail discounts and cinema tickets A genuine people-first culture where your growth and wellbeing come first Performance-related bonus scheme to reward your contribution Regular socials - from team get-togethers to all-company celebrations, with each department owning a budget for their events The opportunity to attend group conferences, away days and learning forums both in the UK and abroad - network with other talent We've created a welcoming office environment, with well-stocked kitchens offering free breakfast, fresh fruit, hot and cold drinks, and a range of tuck shop goodies to keep you fuelled throughout the day. Kinetic is an equal opportunity employer, fostering diversity and committed to creating an inclusive environment for all employees.
Dec 08, 2025
Full time
Information Security Officer R58724 Department: IT Employment Type: Permanent - Full Time Location: Milton Keynes Compensation: £50,000 - £60,000 / year Description Here's what you need to know about Kinetic At Kinetic, we're redefining operational excellence in higher education, conferencing, and events. As the leading provider of software solutions for student accommodation, event management, catering, and residential services, we help institutions streamline operations, elevate customer experiences, and unlock their full potential. With over 25 years of experience and trusted by more than 350 institutions worldwide, our software empowers universities and venues to run smarter, faster, and more collaboratively. From bustling campuses to dynamic corporate environments, our technology adapts to the rhythm of each organisation - helping them thrive in a fast-changing world. But we're more than just software. We're a team of passionate problem-solvers, innovators, and collaborators who care deeply about our customers and each other. Our culture is built on empowerment, community, and continuous growth. We believe in giving people the tools, support, and freedom to do their best work - and have fun while doing it. Joining Kinetic means being part of a purpose-driven business where your ideas matter, your development is supported, and your impact is real. If you're ready to help shape the future of operational technology in education and events, we'd love to meet you. What will I be bringing to life in this role? We're seeking an experienced Information Security Officer to lead security strategy, operations, and compliance. This is a hands-on role combining strategic security architecture with operational security management and regulatory compliance oversight. The successful candidate will define security standards across our product portfolio, manage security environments, and serve as our central point for ISO27001, PCI/DSS, and GDPR compliance while supporting commercial teams with tender responses and client security assurance. Core Responsibilities Strategic (30%) Define technical security architecture and standards across multi-cloud SaaS platforms Embed security into product development lifecycle and roadmap planning Conduct threat modeling and risk assessments for new features and system changes Evaluate and recommend security technologies and tools Operational (40%) Manage security environments across Azure and AWS infrastructure Coordinate security incident response and vulnerability remediation Oversee security monitoring, alerting, and detection capabilities Manage vulnerability assessment and penetration testing programs Maintain identity and access management controls Compliance & Assurance (30%) Maintain ISO27001 certification and manage audit cycles Ensure PCI/DSS compliance for payment processing systems Manage GDPR compliance across all products and operations Complete HECVAT and security questionnaires for higher education tenders Support sales and customer success with security documentation and evidence Act as primary security contact for customers and prospects What will I need to hit the ground running? Essential Requirements Substantial information security experience in SaaS/cloud software environment (ISV or B2B software preferred) Proven track record managing ISO27001 certification and compliance Practical GDPR implementation experience in software products PCI/DSS compliance experience with payment processing systems Strong understanding of cloud security (Azure and/or AWS) Application security and secure development lifecycle knowledge Security incident management and cross-functional response coordination Excellent communication skills - able to translate technical security for commercial and executive audiences Experience supporting tender responses and client security assurance Preferred/Nice-to-Have Professional certifications: CISSP, CISM, CISA, or equivalent Higher education sector experience Multi-tenant SaaS architecture security experience DevSecOps and CI/CD security integration knowledge Security frameworks: NIST, CIS Controls, OWASP Multi-jurisdictional data protection knowledge Enterprise sales cycle support experience Key Attributes Strategic thinker who can balance security with business needs Pragmatic approach to security implementation Detail-oriented with strong organizational skills Collaborative and able to influence across teams Proactive in identifying risks and improvement opportunities Comfortable in fast-paced, dynamic environment What extras will make me thrive? At Kinetic, we believe work should come with rewards that make a real difference. Here's just a taste of what you can expect when you join us: 25 days holiday (plus bank holidays) - with extra days the longer you're with us Two paid wellbeing days each year, with a budget to enjoy some time out with someone important to you Enhanced pension contributions to support your future Two paid days a year to give back through volunteering, charity work, or sustainability projects with our Green Team Salary sacrifice schemes for electric vehicles and cycle-to-work 24/7 access to our Employee Assistance Programme for confidential advice and support A full annual health check to keep you at your best A flexible benefits platform - from life assurance and learning opportunities to retail discounts and cinema tickets A genuine people-first culture where your growth and wellbeing come first Performance-related bonus scheme to reward your contribution Regular socials - from team get-togethers to all-company celebrations, with each department owning a budget for their events The opportunity to attend group conferences, away days and learning forums both in the UK and abroad - network with other talent We've created a welcoming office environment, with well-stocked kitchens offering free breakfast, fresh fruit, hot and cold drinks, and a range of tuck shop goodies to keep you fuelled throughout the day. Kinetic is an equal opportunity employer, fostering diversity and committed to creating an inclusive environment for all employees.
DevSecOps Lead Engineer - Defence Sector This role is for a high-impact DevOps and Automation Evangelist responsible for the technical implementation and strategic direction of the DevSecOps platform, ensuring alignment with critical business and security objectives. Core Responsibilities Technical DevSecOps Ownership: Lead the design, technical implementation, delivery, and assurance of the DevSecOp click apply for full job details
Dec 08, 2025
Full time
DevSecOps Lead Engineer - Defence Sector This role is for a high-impact DevOps and Automation Evangelist responsible for the technical implementation and strategic direction of the DevSecOps platform, ensuring alignment with critical business and security objectives. Core Responsibilities Technical DevSecOps Ownership: Lead the design, technical implementation, delivery, and assurance of the DevSecOp click apply for full job details
A World-Changing Company Palantir builds the world's leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a UKG Compliance Engineer, you will help our engineers implement and audit Palantir security controls across our entire product line. You'll work closely with many different teams to shape these controls and cultivate a robust and nimble approach to risk management across the company. You will navigate and interpret complex government regulatory frameworks and approaches (e.g. Secure-by-Design, application of relevant MOD JSPs and NIST standards) in order to provide practical guidance on technical architecture, documentation and operational concerns, and sustainable processes that will allow us to continue to grow quickly and efficiently. Core Responsibilities Partner with engineers to interpret and map compliance requirements to control implementation and assist with product architecture. Directly facilitate operational and regulatory outcomes across our UK government client portfolio, including Secure by Design adherence, MOD JSP compliance and continuous monitoring. Develop and deliver evidence to meet regulatory compliance audits across the UK government client portfolio. Propose and implement ideas for operational improvements and facilitate automation for procedural compliance controls. Guide technical and operational decision-making towards future product offerings and efficient organisational processes. Evaluate and advise the business on new and evolving UK Government certification programmes, requirements, and technologies. Manage and participate in audits, as appropriate. What We Value Deep understanding of on-premises infrastructure and security concepts Experience working directly with the UK Ministry of Defence or other government departments Experience successfully supporting security and compliance efforts in complex on-premises data centres Experience performing technical assessments in direct support of compliance efforts Experience developing security and risk assessment plans and related documentation Ability to clearly convey compliance requirements to internal engineering teams and associated implementation to external customers using effective written and verbal communication skills Proficiency with security concepts (encryption, authentication, etc.) and tooling for continuous monitoring (Nessus SecurityCenter, Burp, Jira, Splunk, etc.) Knowledge of cloud security compliance (AWS, Azure, GCP) Understanding of DevSecOps practices and secure software development lifecycles What We Require 3+ years' experience with compliance audits and prior UK Government compliance and audit experience (MOD JSP application, Secure by Design, NIST 800-53, and UK Government ATOs, etc.) Current UK security clearance (SC or DV level) Relevant professional certifications (CIPM, CIPP/E, CRISC, CISSP, or similar) Familiarity with data protection compliance tools and GRC platforms Life at Palantir We want every Palantirian to achieve their best outcomes, that's why we celebrate individuals' strengths, skills, and interests, from your first interview to your longterm growth, rather than rely on traditional career ladders. Paying attention to the needs of our community enables us to optimize our opportunities to grow and helps ensure many pathways to success at Palantir. Promoting health and well-being across all areas of Palantirians' lives is just one of the ways we're investing in our community. Learn more at Life at Palantir and note that our offerings may vary by region. In keeping consistent with Palantir's values and culture, we believe employees are "better together" and in-person work affords the opportunity for more creative outcomes. Therefore, we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week), allowing our employees to strike the right trade-off for their personal productivity. Based on business need, there are a few roles that allow for "Remote" work on an exceptional basis. If you are applying for one of these roles, you must work from the city and or country in which you are employed. If the posting is specified as Onsite, you are required to work from an office. If you want to empower the world's most important institutions, you belong here. Palantir values excellence regardless of background. We are committed to making the application and hiring process accessible to everyone and will provide a reasonable accommodation for those living with a disability. If you need an accommodation for the application or hiring process, please reach out and let us know how we can help.
Dec 06, 2025
Full time
A World-Changing Company Palantir builds the world's leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a UKG Compliance Engineer, you will help our engineers implement and audit Palantir security controls across our entire product line. You'll work closely with many different teams to shape these controls and cultivate a robust and nimble approach to risk management across the company. You will navigate and interpret complex government regulatory frameworks and approaches (e.g. Secure-by-Design, application of relevant MOD JSPs and NIST standards) in order to provide practical guidance on technical architecture, documentation and operational concerns, and sustainable processes that will allow us to continue to grow quickly and efficiently. Core Responsibilities Partner with engineers to interpret and map compliance requirements to control implementation and assist with product architecture. Directly facilitate operational and regulatory outcomes across our UK government client portfolio, including Secure by Design adherence, MOD JSP compliance and continuous monitoring. Develop and deliver evidence to meet regulatory compliance audits across the UK government client portfolio. Propose and implement ideas for operational improvements and facilitate automation for procedural compliance controls. Guide technical and operational decision-making towards future product offerings and efficient organisational processes. Evaluate and advise the business on new and evolving UK Government certification programmes, requirements, and technologies. Manage and participate in audits, as appropriate. What We Value Deep understanding of on-premises infrastructure and security concepts Experience working directly with the UK Ministry of Defence or other government departments Experience successfully supporting security and compliance efforts in complex on-premises data centres Experience performing technical assessments in direct support of compliance efforts Experience developing security and risk assessment plans and related documentation Ability to clearly convey compliance requirements to internal engineering teams and associated implementation to external customers using effective written and verbal communication skills Proficiency with security concepts (encryption, authentication, etc.) and tooling for continuous monitoring (Nessus SecurityCenter, Burp, Jira, Splunk, etc.) Knowledge of cloud security compliance (AWS, Azure, GCP) Understanding of DevSecOps practices and secure software development lifecycles What We Require 3+ years' experience with compliance audits and prior UK Government compliance and audit experience (MOD JSP application, Secure by Design, NIST 800-53, and UK Government ATOs, etc.) Current UK security clearance (SC or DV level) Relevant professional certifications (CIPM, CIPP/E, CRISC, CISSP, or similar) Familiarity with data protection compliance tools and GRC platforms Life at Palantir We want every Palantirian to achieve their best outcomes, that's why we celebrate individuals' strengths, skills, and interests, from your first interview to your longterm growth, rather than rely on traditional career ladders. Paying attention to the needs of our community enables us to optimize our opportunities to grow and helps ensure many pathways to success at Palantir. Promoting health and well-being across all areas of Palantirians' lives is just one of the ways we're investing in our community. Learn more at Life at Palantir and note that our offerings may vary by region. In keeping consistent with Palantir's values and culture, we believe employees are "better together" and in-person work affords the opportunity for more creative outcomes. Therefore, we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week), allowing our employees to strike the right trade-off for their personal productivity. Based on business need, there are a few roles that allow for "Remote" work on an exceptional basis. If you are applying for one of these roles, you must work from the city and or country in which you are employed. If the posting is specified as Onsite, you are required to work from an office. If you want to empower the world's most important institutions, you belong here. Palantir values excellence regardless of background. We are committed to making the application and hiring process accessible to everyone and will provide a reasonable accommodation for those living with a disability. If you need an accommodation for the application or hiring process, please reach out and let us know how we can help.
CBSbutler Holdings Limited trading as CBSbutler
Basingstoke, Hampshire
DevSecOps Lead +Permanent opportunity +On site in Basingstoke +DV cleared role + 78,000 - 104,000 Skills: +DevOps +Team leadership +CI/CD pipelines +Azure / AWS As a Lead DevSecOps Engineer you will contribute to this by driving the technical delivery of the DevSecOps (CI/CD pipelines and integrated security tooling) and associated processes, ensuring these are delivered and utilised in the most effective way. The role promises exciting opportunities, use of cutting-edge technologies and a culture that encourages innovation, nurtures talent and drives delivery excellence. It provides the right candidate with an exciting career path and real opportunity to not only grow themselves but to influence the business as we work together to bring our Defence customers into the digital age. On the project, this role will report into (and support) the DevSecOps Tech Lead (MSL) and will lead the engineers, to drive scrum teams' adoption of the DevOps toolchain. This team is widely recognised as an exciting and inspiring team, driving positive change on one of DNS's most critical and technologically advanced programmes, this role provides excellent customer exposure and a real opportunity to catapult your career forwards. Owns significant parts of the Solution, Development of automation scripts, writes Build Automation scripts (Ansible) and IaC (Terraform), configures and builds CI/CD pipelines. Advises on use of DevOps Tooling, best practices and secure engineering processes. Works with DevOps delivery team to understand roadmap and processes. Works with the Customer to ensure that DevOps adoption is aligned to Engineering process. Preferably experienced at working in an agile, sprint-based lifecycle. Experienced with both Windows and Linux operating systems. Work closely with the DevSecOps Tech Lead (MSL), Managed Service Teams and Engineering Process Lead to drive the usage and implementation of DevOps tooling to facilitate secure build and test automation. Develop, and document re-usable automation scripts and IaC artefacts to assist various teams on the project in their deliveries. Act as an evangelist and advisor on the use of DevOps tools and Automation technologies. Your role will involve Responsible for the significant aspects of the technical implementation, delivery and assurance of the DevSecOps tooling, associated processed and ways of working. Leading Technical Implementation and design activities, making Design decisions and assessing options. Advising on use of DevSecOps technologies and processes, to senior customers. Works with DevSecOps Tech Lead (MSL)., Product Owners and Scrum Master to define/prioritise work and raise Risks/Dependencies. Works with DevSecOps Tech Lead (MSL) to ensure the DevSecOps implementation satisfies its requirements and ensuring it aligns to the Business Outcomes and security needs. Mentoring junior engineers and making implementation decisions. Contribution to Planning the work for the team. Reporting on progress and tracking this with Solution Owner. Defines Support Approach working with Service/Support Team. Engages with other teams on the usage of the tooling and dependency management. Your transferable skills and experience: Key Skills Significant experience in the Implementation / Configuration / Usage in a number of the following - CI/CD Pipelines, ideally Azure DevOps IaC code tooling , including Terraform, Ansible, Harbor SCA/IAST/DAST tooling, e.g. Black Duck, Coverity, Codesight, JFrog, Snyk Automated Test tooling , ideally Selenium / Robot Framework Test Management Tooling ideally Azure Test Plans Secure Secrets Management, ideally Azure DevOps and Hashicorp Vault Version control with Git General Software Development Background Strong problem-solving and analytical skills. Excellent communication and teamwork skills. DevSecOps tooling and practices Technical Leadership If you'd like to discuss this DevSecOps Lead in more detail, please send your updated CV to (url removed) and I will get in touch.
Dec 05, 2025
Full time
DevSecOps Lead +Permanent opportunity +On site in Basingstoke +DV cleared role + 78,000 - 104,000 Skills: +DevOps +Team leadership +CI/CD pipelines +Azure / AWS As a Lead DevSecOps Engineer you will contribute to this by driving the technical delivery of the DevSecOps (CI/CD pipelines and integrated security tooling) and associated processes, ensuring these are delivered and utilised in the most effective way. The role promises exciting opportunities, use of cutting-edge technologies and a culture that encourages innovation, nurtures talent and drives delivery excellence. It provides the right candidate with an exciting career path and real opportunity to not only grow themselves but to influence the business as we work together to bring our Defence customers into the digital age. On the project, this role will report into (and support) the DevSecOps Tech Lead (MSL) and will lead the engineers, to drive scrum teams' adoption of the DevOps toolchain. This team is widely recognised as an exciting and inspiring team, driving positive change on one of DNS's most critical and technologically advanced programmes, this role provides excellent customer exposure and a real opportunity to catapult your career forwards. Owns significant parts of the Solution, Development of automation scripts, writes Build Automation scripts (Ansible) and IaC (Terraform), configures and builds CI/CD pipelines. Advises on use of DevOps Tooling, best practices and secure engineering processes. Works with DevOps delivery team to understand roadmap and processes. Works with the Customer to ensure that DevOps adoption is aligned to Engineering process. Preferably experienced at working in an agile, sprint-based lifecycle. Experienced with both Windows and Linux operating systems. Work closely with the DevSecOps Tech Lead (MSL), Managed Service Teams and Engineering Process Lead to drive the usage and implementation of DevOps tooling to facilitate secure build and test automation. Develop, and document re-usable automation scripts and IaC artefacts to assist various teams on the project in their deliveries. Act as an evangelist and advisor on the use of DevOps tools and Automation technologies. Your role will involve Responsible for the significant aspects of the technical implementation, delivery and assurance of the DevSecOps tooling, associated processed and ways of working. Leading Technical Implementation and design activities, making Design decisions and assessing options. Advising on use of DevSecOps technologies and processes, to senior customers. Works with DevSecOps Tech Lead (MSL)., Product Owners and Scrum Master to define/prioritise work and raise Risks/Dependencies. Works with DevSecOps Tech Lead (MSL) to ensure the DevSecOps implementation satisfies its requirements and ensuring it aligns to the Business Outcomes and security needs. Mentoring junior engineers and making implementation decisions. Contribution to Planning the work for the team. Reporting on progress and tracking this with Solution Owner. Defines Support Approach working with Service/Support Team. Engages with other teams on the usage of the tooling and dependency management. Your transferable skills and experience: Key Skills Significant experience in the Implementation / Configuration / Usage in a number of the following - CI/CD Pipelines, ideally Azure DevOps IaC code tooling , including Terraform, Ansible, Harbor SCA/IAST/DAST tooling, e.g. Black Duck, Coverity, Codesight, JFrog, Snyk Automated Test tooling , ideally Selenium / Robot Framework Test Management Tooling ideally Azure Test Plans Secure Secrets Management, ideally Azure DevOps and Hashicorp Vault Version control with Git General Software Development Background Strong problem-solving and analytical skills. Excellent communication and teamwork skills. DevSecOps tooling and practices Technical Leadership If you'd like to discuss this DevSecOps Lead in more detail, please send your updated CV to (url removed) and I will get in touch.