Business Development Manager Defence & Government Markets Reports to: Managing Director Location: United Kingdom (Hybrid with UK and International Travel) Package including: Negotiable salary with commission, bonus, company car Are you a business development executive with experience in the defence sector? We would welcome ex MOD or service who have a strong sales background. Job Purpose The Business Development Manager is responsible for identifying, developing and securing new business opportunities across the UK Ministry of Defence (MOD), NATO, prime defence contractors and international defence organisations. The role is focused on developing long-term strategic customer relationships, winning profitable contracts and supporting sustainable business growth while ensuring full compliance with defence procurement regulations and security requirements. The successful candidate will possess a strong understanding of the UK defence market, defence acquisition processes and the ability to engage confidently with senior military, government and commercial stakeholders. Key Responsibilities Business Development Develop and execute a Defence Business Development Strategy aligned with company objectives. Identify new opportunities within UK MOD, NATO and international defence markets. Generate and qualify new business leads. Develop annual sales and growth plans. Build and maintain a robust opportunity pipeline Monitor market trends, defence spending and procurement programmes. Customer Relationship Management Develop strategic relationships with: UK Ministry of Defence Defence Equipment & Support (DE&S) Defence Infrastructure Organisation (DIO) Prime Contractors Tier 1 and Tier 2 Defence Suppliers NATO procurement agencies International defence organisations Maintain regular engagement with procurement teams, programme managers and technical specialists. Represent the company at customer meetings and defence exhibitions. Market Intelligence Monitor: Defence budgets Future procurement programmes Framework agreements Competitor activity Emerging technologies Government policy Identify opportunities arising from defence capability reviews. Strategic Growth Develop opportunities across sectors including: Soldier Systems C4ISR Tactical Communications Personal Protective Equipment Medical Systems Vehicle Systems Naval Equipment Aerospace Secure Textiles Load Carriage Equipment Weapon Accessories Sustainment & Logistics Commercial Responsibilities Achieve annual sales targets. Deliver profitable revenue growth. Prepare sales forecasts. Manage account development plans. Protect company margins. Support long-term strategic agreements. Cross Functional Collaboration Work closely with: Technical Design Production Quality Procurement Programme Management to ensure customer requirements are fully understood and delivered. Compliance Ensure all activities comply with: UK Export Control Regulations MOD procurement rules Security classifications ISO 9001 ISO 14001 Cyber Essentials / Cyber Essentials Plus DEFCONs JSP Publications Modern Slavery Act Bribery Act 2010 Key Performance Indicators (KPIs) Annual Sales Revenue Gross Margin New Customer Acquisition Pipeline Value Contract Awards Customer Retention Forecast Accuracy Number of Customer Visits New Market Penetration Strategic Account Growth Knowledge & Experience Essential Minimum 5 years' Business Development experience within the defence sector. Proven track record of winning defence contracts. Experience dealing with MOD and prime contractors. Understanding of defence procurement processes. Strong commercial negotiation skills. Experience managing strategic customer accounts. Excellent presentation and communication skills. Experience using CRM systems. Full UK driving licence. Willingness to travel throughout the UK Desirable Knowledge of NATO procurement. Experience within textile manufacturing, defence equipment, engineering or protective systems. Understanding of government framework agreements. Existing defence industry network. Experience with export markets. Security cleared (SC or DV) or eligible to obtain clearance. Skills & Competencies Commercial Business Acumen Strategic Thinking Negotiation Financial Awareness Opportunity Management Leadership Influencing Skills Relationship Building Stakeholder Management Decision Making Personal Self-motivated Highly organised Professional Resilient Results driven Customer focused Excellent communicator Ethical High integrity Qualifications Essential Degree in Business, Engineering, Manufacturing or related discipline, or equivalent industry experience. Desirable MBA Institute of Sales Professionals Membership Prince2 or equivalent project management qualification Security Requirements The successful candidate must: Be eligible for UK Security Clearance (SC) as a minimum. Be capable of obtaining Developed Vetting (DV) if required. Meet UK Export Control compliance requirements. Comply with company information security policies. Typical Customers UK Ministry of Defence (MOD) Defence Equipment & Support (DE&S) BAE Systems INVISIO Babcock International Leonardo UK Thales UK Rheinmetall UK QinetiQ General Dynamics UK Lockheed Martin UK Rolls-Royce Defence MBDA UK NATO Support and Procurement Agency (NSPA) Career Progression Senior Business Development Manager Head of Business Development Commercial Manager Sales Director Business Unit Director Commercial Director
Jul 31, 2026
Full time
Business Development Manager Defence & Government Markets Reports to: Managing Director Location: United Kingdom (Hybrid with UK and International Travel) Package including: Negotiable salary with commission, bonus, company car Are you a business development executive with experience in the defence sector? We would welcome ex MOD or service who have a strong sales background. Job Purpose The Business Development Manager is responsible for identifying, developing and securing new business opportunities across the UK Ministry of Defence (MOD), NATO, prime defence contractors and international defence organisations. The role is focused on developing long-term strategic customer relationships, winning profitable contracts and supporting sustainable business growth while ensuring full compliance with defence procurement regulations and security requirements. The successful candidate will possess a strong understanding of the UK defence market, defence acquisition processes and the ability to engage confidently with senior military, government and commercial stakeholders. Key Responsibilities Business Development Develop and execute a Defence Business Development Strategy aligned with company objectives. Identify new opportunities within UK MOD, NATO and international defence markets. Generate and qualify new business leads. Develop annual sales and growth plans. Build and maintain a robust opportunity pipeline Monitor market trends, defence spending and procurement programmes. Customer Relationship Management Develop strategic relationships with: UK Ministry of Defence Defence Equipment & Support (DE&S) Defence Infrastructure Organisation (DIO) Prime Contractors Tier 1 and Tier 2 Defence Suppliers NATO procurement agencies International defence organisations Maintain regular engagement with procurement teams, programme managers and technical specialists. Represent the company at customer meetings and defence exhibitions. Market Intelligence Monitor: Defence budgets Future procurement programmes Framework agreements Competitor activity Emerging technologies Government policy Identify opportunities arising from defence capability reviews. Strategic Growth Develop opportunities across sectors including: Soldier Systems C4ISR Tactical Communications Personal Protective Equipment Medical Systems Vehicle Systems Naval Equipment Aerospace Secure Textiles Load Carriage Equipment Weapon Accessories Sustainment & Logistics Commercial Responsibilities Achieve annual sales targets. Deliver profitable revenue growth. Prepare sales forecasts. Manage account development plans. Protect company margins. Support long-term strategic agreements. Cross Functional Collaboration Work closely with: Technical Design Production Quality Procurement Programme Management to ensure customer requirements are fully understood and delivered. Compliance Ensure all activities comply with: UK Export Control Regulations MOD procurement rules Security classifications ISO 9001 ISO 14001 Cyber Essentials / Cyber Essentials Plus DEFCONs JSP Publications Modern Slavery Act Bribery Act 2010 Key Performance Indicators (KPIs) Annual Sales Revenue Gross Margin New Customer Acquisition Pipeline Value Contract Awards Customer Retention Forecast Accuracy Number of Customer Visits New Market Penetration Strategic Account Growth Knowledge & Experience Essential Minimum 5 years' Business Development experience within the defence sector. Proven track record of winning defence contracts. Experience dealing with MOD and prime contractors. Understanding of defence procurement processes. Strong commercial negotiation skills. Experience managing strategic customer accounts. Excellent presentation and communication skills. Experience using CRM systems. Full UK driving licence. Willingness to travel throughout the UK Desirable Knowledge of NATO procurement. Experience within textile manufacturing, defence equipment, engineering or protective systems. Understanding of government framework agreements. Existing defence industry network. Experience with export markets. Security cleared (SC or DV) or eligible to obtain clearance. Skills & Competencies Commercial Business Acumen Strategic Thinking Negotiation Financial Awareness Opportunity Management Leadership Influencing Skills Relationship Building Stakeholder Management Decision Making Personal Self-motivated Highly organised Professional Resilient Results driven Customer focused Excellent communicator Ethical High integrity Qualifications Essential Degree in Business, Engineering, Manufacturing or related discipline, or equivalent industry experience. Desirable MBA Institute of Sales Professionals Membership Prince2 or equivalent project management qualification Security Requirements The successful candidate must: Be eligible for UK Security Clearance (SC) as a minimum. Be capable of obtaining Developed Vetting (DV) if required. Meet UK Export Control compliance requirements. Comply with company information security policies. Typical Customers UK Ministry of Defence (MOD) Defence Equipment & Support (DE&S) BAE Systems INVISIO Babcock International Leonardo UK Thales UK Rheinmetall UK QinetiQ General Dynamics UK Lockheed Martin UK Rolls-Royce Defence MBDA UK NATO Support and Procurement Agency (NSPA) Career Progression Senior Business Development Manager Head of Business Development Commercial Manager Sales Director Business Unit Director Commercial Director
Job Title: Cyber Security Engineer (DV Cleared) Location: West London (still confirming whether 4 or 5 days onsite) Rate: £700-750 a day Contract: Minimum 6 months IR35: Inside IR35 Clearance: Active DV clearance required The Opportunity We're supporting a search for DV Cleared Cyber Security Engineers to join a programme delivering secure technology services within a highly sensitive Defence envi click apply for full job details
May 29, 2026
Contractor
Job Title: Cyber Security Engineer (DV Cleared) Location: West London (still confirming whether 4 or 5 days onsite) Rate: £700-750 a day Contract: Minimum 6 months IR35: Inside IR35 Clearance: Active DV clearance required The Opportunity We're supporting a search for DV Cleared Cyber Security Engineers to join a programme delivering secure technology services within a highly sensitive Defence envi click apply for full job details
Integration Lead - Secure Digital Platform 6-Month contract - Inside IR35 - market rate Reading based - 5 days a week onsite Defence sector - need to be eligible for SC Clearance - current and active SC Cleared already is strongly preferred Role Description The Integration Lead is responsible for leading the technical design, development, and delivery of secure, scalable, and reusable foundational technology services within the Secure Digital Platform. The Integration Lead partners with Delivery Leads, product owners and architects, to lead and manage the technical implementation of platform capabilities and enterprise services to the roadmap planned for each platform. The Integration Lead acts as a hands-on technical leader and subject matter expert, ensuring engineering excellence, operational integrity, and alignment of delivery with enterprise architectural direction and business objectives. Key Responsibilities Provide delivery leadership across the Engineering, Agile team and Test teams to build and maintain reusable and secure platform services aligned with the organisation's technology strategy. Work with the Delivery leads to understand the roadmap of work Work closely with Product Owners / Architects to implement and test the capabilities within the platforms Drive high-quality software engineering practices across the team, including code reviews, test automation, CI/CD pipelines, performance monitoring, and observability. Ensure delivered solutions align with solution designs and security guardrails. Guide teams in the selection and use of modern tools, frameworks, and platforms that optimise development efficiency and operational effectiveness for delivery. Support the development and evolution of the Secure Digital Platform roadmap by identifying technical dependencies, enablers, and delivery risks. Partner with the wider Secure Digital Platform team to establish and enforce standards for infrastructure-as-code, API development, cloud-native services, and integration. Collaborate with cybersecurity, operations, and compliance teams to ensure secure design and adherence to internal and external policies. Act as a technical escalation point for complex engineering issues and support the Engineering, Agile and Test leads to develop and row technical capability within the teams. Contribute to the preparation of delivery-related artefacts such as technical documentation, support handovers, and implementation Runbook. Foster a culture of continuous improvement, experimentation, and feedback within engineering teams. Skills and Experience Essential 5+ years of experience in technical leadership roles within software engineering, infrastructure, or platform development teams Proven experience delivering secure, scalable technology services or platforms in complex enterprise environment Hands-on experience with cloud platforms (e.g., AWS, Azure, GCP), container orchestration, and infrastructure automation (e.g., Terraform, Ansible) Strong understanding of DevSecOps principles, CI/CD pipelines, test automation, and observability tooling Familiarity with platform and product-centric delivery models and agile frameworks (e.g., Scrum, SAFe) Excellent communication and stakeholder management skills across technical and non-technical audiences Strong problem-solving skills and ability to make pragmatic decisions under ambiguity or time constraints Commitment to fostering engineering culture, mentoring others, and growing internal technical capability High ethical standards when handling confidential information Desirable Experience with platform engineering, internal developer platforms (IDPs), or technical enablement teams Experience in a highly regulated industry (e.g., Aerospace & Defence, Finance, Critical Infrastructure) Exposure to secure coding practices, threat modelling, and secure-by-design approaches Experience leading hybrid delivery teams (e.g., internal and external/partner teams) Familiarity with ITSM and incident/problem/change/ management in an enterprise context Disclaimer: This vacancy is being advertised by either Advanced Resource Managers Limited, Advanced Resource Managers IT Limited or Advanced Resource Managers Engineering Limited ("ARM"). ARM is a specialist talent acquisition and management consultancy. We provide technical contingency recruitment and a portfolio of more complex resource solutions. Our specialist recruitment divisions cover the entire technical arena, including some of the most economically and strategically important industries in the UK and the world today. We will never send your CV without your permission. Where the role is marked as Outside IR35 in the advertisement this is subject to receipt of a final Status Determination Statement from the end Client and may be subject to change.
May 22, 2026
Contractor
Integration Lead - Secure Digital Platform 6-Month contract - Inside IR35 - market rate Reading based - 5 days a week onsite Defence sector - need to be eligible for SC Clearance - current and active SC Cleared already is strongly preferred Role Description The Integration Lead is responsible for leading the technical design, development, and delivery of secure, scalable, and reusable foundational technology services within the Secure Digital Platform. The Integration Lead partners with Delivery Leads, product owners and architects, to lead and manage the technical implementation of platform capabilities and enterprise services to the roadmap planned for each platform. The Integration Lead acts as a hands-on technical leader and subject matter expert, ensuring engineering excellence, operational integrity, and alignment of delivery with enterprise architectural direction and business objectives. Key Responsibilities Provide delivery leadership across the Engineering, Agile team and Test teams to build and maintain reusable and secure platform services aligned with the organisation's technology strategy. Work with the Delivery leads to understand the roadmap of work Work closely with Product Owners / Architects to implement and test the capabilities within the platforms Drive high-quality software engineering practices across the team, including code reviews, test automation, CI/CD pipelines, performance monitoring, and observability. Ensure delivered solutions align with solution designs and security guardrails. Guide teams in the selection and use of modern tools, frameworks, and platforms that optimise development efficiency and operational effectiveness for delivery. Support the development and evolution of the Secure Digital Platform roadmap by identifying technical dependencies, enablers, and delivery risks. Partner with the wider Secure Digital Platform team to establish and enforce standards for infrastructure-as-code, API development, cloud-native services, and integration. Collaborate with cybersecurity, operations, and compliance teams to ensure secure design and adherence to internal and external policies. Act as a technical escalation point for complex engineering issues and support the Engineering, Agile and Test leads to develop and row technical capability within the teams. Contribute to the preparation of delivery-related artefacts such as technical documentation, support handovers, and implementation Runbook. Foster a culture of continuous improvement, experimentation, and feedback within engineering teams. Skills and Experience Essential 5+ years of experience in technical leadership roles within software engineering, infrastructure, or platform development teams Proven experience delivering secure, scalable technology services or platforms in complex enterprise environment Hands-on experience with cloud platforms (e.g., AWS, Azure, GCP), container orchestration, and infrastructure automation (e.g., Terraform, Ansible) Strong understanding of DevSecOps principles, CI/CD pipelines, test automation, and observability tooling Familiarity with platform and product-centric delivery models and agile frameworks (e.g., Scrum, SAFe) Excellent communication and stakeholder management skills across technical and non-technical audiences Strong problem-solving skills and ability to make pragmatic decisions under ambiguity or time constraints Commitment to fostering engineering culture, mentoring others, and growing internal technical capability High ethical standards when handling confidential information Desirable Experience with platform engineering, internal developer platforms (IDPs), or technical enablement teams Experience in a highly regulated industry (e.g., Aerospace & Defence, Finance, Critical Infrastructure) Exposure to secure coding practices, threat modelling, and secure-by-design approaches Experience leading hybrid delivery teams (e.g., internal and external/partner teams) Familiarity with ITSM and incident/problem/change/ management in an enterprise context Disclaimer: This vacancy is being advertised by either Advanced Resource Managers Limited, Advanced Resource Managers IT Limited or Advanced Resource Managers Engineering Limited ("ARM"). ARM is a specialist talent acquisition and management consultancy. We provide technical contingency recruitment and a portfolio of more complex resource solutions. Our specialist recruitment divisions cover the entire technical arena, including some of the most economically and strategically important industries in the UK and the world today. We will never send your CV without your permission. Where the role is marked as Outside IR35 in the advertisement this is subject to receipt of a final Status Determination Statement from the end Client and may be subject to change.
Cyber Software Engineer - SC / DV / eDV Cleared New Permanent Opportunity for Cyber Software Engineers in London with Security Clearance to work on Mission-Critical, National Security projects Role: Cyber Software Engineer Location: London (hybrid) Clearance: SC, MOD DV or eDV (must be held or eligible) To apply : Email: We are looking for a Cyber Software Engineer to join a team delivering high-assurance cyber capabilities into UK defence and national security environments. This role is focused on operational technology (OT) cyber projects , working close to real systems and real users. You'll be part of a highly cleared engineering team developing secure, robust software where correctness, performance and assurance genuinely matter. What you'll be doing Developing high-assurance software in C++ for cyber and security-critical systems Working on operational technology cyber projects , not just enterprise IT Contributing to secure system design, implementation and verification Collaborating with cyber specialists, systems engineers and end users Supporting software through its full lifecycle in classified environments Essential skills & experience Strong C++ software engineering experience Background in secure / high-assurance systems (defence, cyber, safety-critical or similar) Solid understanding of secure coding practices and software design Comfortable working in on-site, classified environments Active SC, DV or eDV clearance Nice to have Experience with Golang and/or Rust Cyber security qualifications such as CEH, OSCP or similar Vulnerability research and/or reverse engineering experience Exposure to OT environments , embedded systems or low-level development Experience working with MOD or national security customers Why this role Work on genuinely operational cyber projects with real-world impact High-trust, highly technical engineering environment Long-term programmes with stability and purpose London-based role with a strong on-site engineering culture
May 22, 2026
Full time
Cyber Software Engineer - SC / DV / eDV Cleared New Permanent Opportunity for Cyber Software Engineers in London with Security Clearance to work on Mission-Critical, National Security projects Role: Cyber Software Engineer Location: London (hybrid) Clearance: SC, MOD DV or eDV (must be held or eligible) To apply : Email: We are looking for a Cyber Software Engineer to join a team delivering high-assurance cyber capabilities into UK defence and national security environments. This role is focused on operational technology (OT) cyber projects , working close to real systems and real users. You'll be part of a highly cleared engineering team developing secure, robust software where correctness, performance and assurance genuinely matter. What you'll be doing Developing high-assurance software in C++ for cyber and security-critical systems Working on operational technology cyber projects , not just enterprise IT Contributing to secure system design, implementation and verification Collaborating with cyber specialists, systems engineers and end users Supporting software through its full lifecycle in classified environments Essential skills & experience Strong C++ software engineering experience Background in secure / high-assurance systems (defence, cyber, safety-critical or similar) Solid understanding of secure coding practices and software design Comfortable working in on-site, classified environments Active SC, DV or eDV clearance Nice to have Experience with Golang and/or Rust Cyber security qualifications such as CEH, OSCP or similar Vulnerability research and/or reverse engineering experience Exposure to OT environments , embedded systems or low-level development Experience working with MOD or national security customers Why this role Work on genuinely operational cyber projects with real-world impact High-trust, highly technical engineering environment Long-term programmes with stability and purpose London-based role with a strong on-site engineering culture
SENIOR SOFTWARE ENGINEER - eDV CLEARED NEW PERMANENT JOB OPPORTUNITY AVAILABLE WITHIN A GLOBALLY LEADING NATIONAL SECURITY COMPANY FOR A SENIOR SOFTWARE ENGINEER WITH eDV CLEARANCE Permanent job opportunity for a Senior Software Engineer Globally leading defence / cyber security company Salary up to £100,000 plus clearance bonus London based organisation in an easily accessible location Permanent Software Engineer To apply please call / or email WHO WE ARE? We are recruiting Senior and Lead Software Engineers to work with a multi-national, industry leading National Security client in central London. Due to the nature of the work you must hold enhanced DV Security Clearance. WHAT WILL THE SENIOR SOFTWARE ENGINEER BE DOING? As a Senior Software Engineer, you will work with an experienced agile team to design and deliver packages of bespoke work, work development teams and liaise with customers. You will work through the entire software development life cycle from requirements capture to R&D, implementation to automation. WE NEED THE SENIOR SOFTWARE ENGINEER TO HAVE . Current enhanced DV clearance Experience with at least one or more of the following: Java, Python, C++, .NET, C#, JavaScript, React Experience mentoring juniors or leading a team Experience / Knowledge of automation IT WOULD BE NICE FOR THE SENIOR SOFTWARE ENGINEER TO HAVE . Cloud based experience Microservice architecture or server-less architecture Big Data / Messaging technologies such as Apache Nifi / MiNiFi / Kafka TO BE CONSIDERED . Please either apply by clicking online or emailing me directly to For further information please call me on . I can make myself available outside of normal working hours to suit from 7am until 10pm. If unavailable please leave a message and either myself or one of my colleagues will respond. By applying for this role you give express consent for us to process & submit (subject to required skills) your application to our client in conjunction with this vacancy only. Also feel free to connect with me on LinkedIn, just search Dominic Barbet. I look forward to hearing from you. SENIOR SOFTWARE ENGINEER - DV CLEARED KEY SKILLS: SENIOR SOFTWARE ENGINEER / SENIOR SOFTWARE DEVELOPER LEAD SOFTWARE ENGINEER / JAVA DEVELOPER / JAVA ENGINEER / LEAD SOFTWARE DEVELOPER / SENIOR SOFTWARE DEVELOPER / DV CLEARED / DV CLEARANCE / DEVELOPPED VETTING / DEVELOPED VETTED / DEEP VETTING / DEEP VETTED / SC CLEARED / SC CLEARANCE / SECURITY CLEARED / SECURITY CLEARANCE
May 22, 2026
Full time
SENIOR SOFTWARE ENGINEER - eDV CLEARED NEW PERMANENT JOB OPPORTUNITY AVAILABLE WITHIN A GLOBALLY LEADING NATIONAL SECURITY COMPANY FOR A SENIOR SOFTWARE ENGINEER WITH eDV CLEARANCE Permanent job opportunity for a Senior Software Engineer Globally leading defence / cyber security company Salary up to £100,000 plus clearance bonus London based organisation in an easily accessible location Permanent Software Engineer To apply please call / or email WHO WE ARE? We are recruiting Senior and Lead Software Engineers to work with a multi-national, industry leading National Security client in central London. Due to the nature of the work you must hold enhanced DV Security Clearance. WHAT WILL THE SENIOR SOFTWARE ENGINEER BE DOING? As a Senior Software Engineer, you will work with an experienced agile team to design and deliver packages of bespoke work, work development teams and liaise with customers. You will work through the entire software development life cycle from requirements capture to R&D, implementation to automation. WE NEED THE SENIOR SOFTWARE ENGINEER TO HAVE . Current enhanced DV clearance Experience with at least one or more of the following: Java, Python, C++, .NET, C#, JavaScript, React Experience mentoring juniors or leading a team Experience / Knowledge of automation IT WOULD BE NICE FOR THE SENIOR SOFTWARE ENGINEER TO HAVE . Cloud based experience Microservice architecture or server-less architecture Big Data / Messaging technologies such as Apache Nifi / MiNiFi / Kafka TO BE CONSIDERED . Please either apply by clicking online or emailing me directly to For further information please call me on . I can make myself available outside of normal working hours to suit from 7am until 10pm. If unavailable please leave a message and either myself or one of my colleagues will respond. By applying for this role you give express consent for us to process & submit (subject to required skills) your application to our client in conjunction with this vacancy only. Also feel free to connect with me on LinkedIn, just search Dominic Barbet. I look forward to hearing from you. SENIOR SOFTWARE ENGINEER - DV CLEARED KEY SKILLS: SENIOR SOFTWARE ENGINEER / SENIOR SOFTWARE DEVELOPER LEAD SOFTWARE ENGINEER / JAVA DEVELOPER / JAVA ENGINEER / LEAD SOFTWARE DEVELOPER / SENIOR SOFTWARE DEVELOPER / DV CLEARED / DV CLEARANCE / DEVELOPPED VETTING / DEVELOPED VETTED / DEEP VETTING / DEEP VETTED / SC CLEARED / SC CLEARANCE / SECURITY CLEARED / SECURITY CLEARANCE
Cyber Software Engineer - SC / DV / eDV Cleared New Permanent Opportunity for Cyber Software Engineers in Gloucester with Security Clearance to work on Mission-Critical, National Security projects Role: Cyber Software Engineer Location: Gloucester (hybrid) Clearance: SC, MOD DV or eDV To apply : Email: We are looking for a Cyber Software Engineer to join a team delivering high-assurance cyber capabilities into UK defence and national security environments. This role is focused on operational technology (OT) cyber projects , working close to real systems and real users. You'll be part of a highly cleared engineering team developing secure, robust software where correctness, performance and assurance genuinely matter. What you'll be doing Developing high-assurance software in C++ for cyber and security-critical systems Working on operational technology cyber projects , not just enterprise IT Contributing to secure system design, implementation and verification Collaborating with cyber specialists, systems engineers and end users Supporting software through its full lifecycle in classified environments Essential skills & experience Strong C++ software engineering experience Background in secure / high-assurance systems (defence, cyber, safety-critical or similar) Solid understanding of secure coding practices and software design Comfortable working in on-site, classified environments Active SC, DV or eDV clearance Nice to have Experience with Golang and/or Rust Cyber security qualifications such as CEH, OSCP or similar Vulnerability research and/or reverse engineering experience Exposure to OT environments , embedded systems or low-level development Experience working with MOD or national security customers Why this role Work on genuinely operational cyber projects with real-world impact High-trust, highly technical engineering environment Long-term programmes with stability and purpose Gloucester-based role with a strong on-site engineering culture
May 22, 2026
Full time
Cyber Software Engineer - SC / DV / eDV Cleared New Permanent Opportunity for Cyber Software Engineers in Gloucester with Security Clearance to work on Mission-Critical, National Security projects Role: Cyber Software Engineer Location: Gloucester (hybrid) Clearance: SC, MOD DV or eDV To apply : Email: We are looking for a Cyber Software Engineer to join a team delivering high-assurance cyber capabilities into UK defence and national security environments. This role is focused on operational technology (OT) cyber projects , working close to real systems and real users. You'll be part of a highly cleared engineering team developing secure, robust software where correctness, performance and assurance genuinely matter. What you'll be doing Developing high-assurance software in C++ for cyber and security-critical systems Working on operational technology cyber projects , not just enterprise IT Contributing to secure system design, implementation and verification Collaborating with cyber specialists, systems engineers and end users Supporting software through its full lifecycle in classified environments Essential skills & experience Strong C++ software engineering experience Background in secure / high-assurance systems (defence, cyber, safety-critical or similar) Solid understanding of secure coding practices and software design Comfortable working in on-site, classified environments Active SC, DV or eDV clearance Nice to have Experience with Golang and/or Rust Cyber security qualifications such as CEH, OSCP or similar Vulnerability research and/or reverse engineering experience Exposure to OT environments , embedded systems or low-level development Experience working with MOD or national security customers Why this role Work on genuinely operational cyber projects with real-world impact High-trust, highly technical engineering environment Long-term programmes with stability and purpose Gloucester-based role with a strong on-site engineering culture
CONTRACT SENIOR SOFTWARE ENGINEER - eDV CLEARED NEW CONTRACT JOB OPPORTUNITY AVAILABLE WITHIN A LEADING NATIONAL SECURITY COMPANY FOR A SENIOR SOFTWARE ENGINEER WITH eDV CLEARANCE Contract job opportunity for a Senior Software Engineer Globally leading defence / cyber security company £500 - £750 per day (inside and outside IR35 roles available) London based organisation in an easily accessible location Contract Senior Software Engineer To apply please call or email
May 22, 2026
Contractor
CONTRACT SENIOR SOFTWARE ENGINEER - eDV CLEARED NEW CONTRACT JOB OPPORTUNITY AVAILABLE WITHIN A LEADING NATIONAL SECURITY COMPANY FOR A SENIOR SOFTWARE ENGINEER WITH eDV CLEARANCE Contract job opportunity for a Senior Software Engineer Globally leading defence / cyber security company £500 - £750 per day (inside and outside IR35 roles available) London based organisation in an easily accessible location Contract Senior Software Engineer To apply please call or email
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
May 20, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Gloucester location - hybrid working when possible Must hold active Enhanced DV Clearance (West) Competitive Salary DOE - 6% bonus, 25 days holiday, clearance bonus Experience in Data Pipelines, ETL processing, Data Integration, Apache, SQL/NoSQL, Team Leadership Who Are We? Our client is a trusted and growing supplier to the National Security sector, delivering mission-critical solutions that help keep the nation safe, secure, and prosperous. You'll work with cutting-edge technologies, including AI/Data Science, Cyber, Cloud, DevOps/SRE, and Platform Engineering. They have long-term contracts secured across the latest customer framework and are set for significant growth. What will the Lead Data Engineer be Doing? You will develop mission-critical data solutions for National Security clients, working with cutting-edge technologies such as AI/DS, Cyber, Cloud, DevOps/SRE, and Platform Engineering. You'll collaborate directly with customers across National Security, Defence, and Intelligence to solve complex, high-stakes challenges. The role involves designing and implementing sophisticated data pipelines to connect operational systems with analytics and business intelligence platforms. Responsibilities include: Design, build, and maintain data pipelines, including ingestion, orchestration, and enrichment Develop data-streaming and ETL solutions (e.g. NiFi) Model databases and integrate data from diverse sources Ensure data quality, consistency, and security Monitor and optimise system performance Write clean, secure, reusable, test-driven code Apply systems integration expertise within agile teams Decompose user needs into epics and stories Promote reuse of data flows and best practices across teams Champion data engineering standards across government The Lead Data Engineer Should Have: Active eDV clearance (West) Willingness to work full-time on-site in Gloucester when required. Required experience in the following: Apache Kafka Apache NiFI SQL and NoSQL databases (e.g. MongoDB) ETL processing languages such as Groovy, Python or Java Understand and interpret technical and business stakeholder needs Manage expectations through clear, proactive communication Lead and support challenging conversations with teams and senior stakeholders To be Considered: Please either apply by clicking online or emailing me directly to . For further information please call me on / - I can make myself available outside of normal working hours to suit from 7am until 10pm. If unavailable, please leave a message and either myself or one of my colleagues will respond. By applying for this role, you give express consent for us to process & submit (subject to required skills) your application to our client in conjunction with this vacancy only. Also feel free to follow me on or connect with me on LinkedIn, just search Henry Clay-Davies (searchability). I look forward to hearing from you. KEY SKILLS: DATA ENGINEER / DATA ENGINEERING / DEFENCE / NATIONAL SECURITY / DATA STRATEGY / DATA PIPELINES / DATA GOVERNANCE / SQL / NOSQL / APACHE / NIFI / KAFKA / ETL / GLOUCESTER / DV / SECURITY CLEARED / DV CLEARANCE
May 19, 2026
Full time
Gloucester location - hybrid working when possible Must hold active Enhanced DV Clearance (West) Competitive Salary DOE - 6% bonus, 25 days holiday, clearance bonus Experience in Data Pipelines, ETL processing, Data Integration, Apache, SQL/NoSQL, Team Leadership Who Are We? Our client is a trusted and growing supplier to the National Security sector, delivering mission-critical solutions that help keep the nation safe, secure, and prosperous. You'll work with cutting-edge technologies, including AI/Data Science, Cyber, Cloud, DevOps/SRE, and Platform Engineering. They have long-term contracts secured across the latest customer framework and are set for significant growth. What will the Lead Data Engineer be Doing? You will develop mission-critical data solutions for National Security clients, working with cutting-edge technologies such as AI/DS, Cyber, Cloud, DevOps/SRE, and Platform Engineering. You'll collaborate directly with customers across National Security, Defence, and Intelligence to solve complex, high-stakes challenges. The role involves designing and implementing sophisticated data pipelines to connect operational systems with analytics and business intelligence platforms. Responsibilities include: Design, build, and maintain data pipelines, including ingestion, orchestration, and enrichment Develop data-streaming and ETL solutions (e.g. NiFi) Model databases and integrate data from diverse sources Ensure data quality, consistency, and security Monitor and optimise system performance Write clean, secure, reusable, test-driven code Apply systems integration expertise within agile teams Decompose user needs into epics and stories Promote reuse of data flows and best practices across teams Champion data engineering standards across government The Lead Data Engineer Should Have: Active eDV clearance (West) Willingness to work full-time on-site in Gloucester when required. Required experience in the following: Apache Kafka Apache NiFI SQL and NoSQL databases (e.g. MongoDB) ETL processing languages such as Groovy, Python or Java Understand and interpret technical and business stakeholder needs Manage expectations through clear, proactive communication Lead and support challenging conversations with teams and senior stakeholders To be Considered: Please either apply by clicking online or emailing me directly to . For further information please call me on / - I can make myself available outside of normal working hours to suit from 7am until 10pm. If unavailable, please leave a message and either myself or one of my colleagues will respond. By applying for this role, you give express consent for us to process & submit (subject to required skills) your application to our client in conjunction with this vacancy only. Also feel free to follow me on or connect with me on LinkedIn, just search Henry Clay-Davies (searchability). I look forward to hearing from you. KEY SKILLS: DATA ENGINEER / DATA ENGINEERING / DEFENCE / NATIONAL SECURITY / DATA STRATEGY / DATA PIPELINES / DATA GOVERNANCE / SQL / NOSQL / APACHE / NIFI / KAFKA / ETL / GLOUCESTER / DV / SECURITY CLEARED / DV CLEARANCE
Role: DV-Cleared Cyber Security Analyst / SOC Analyst Salary/Rate: £540-640 per day inside IR35 Location: on site Corsham 5x pw Contract Duration: contract until April 2027 We are currently looking for a Cyber Security Analyst / SOC Analyst for our government client. This Cyber Security Analyst / SOC Analyst role is based fully on site, 5 days per week in Corsham, over 13-hour shifts spanning days and nights, including weekends, 4 on 5 off, then 5 on 4 off. There is no further flexibility with the on-site requirement or office location. Security Clearance: Developed Vetting (DV Clearance) + sole UK national + Sensitive Post Check (which can take 3 months) The contract for this Cyber Security Analyst / SOC Analyst position is until April 2027, with potential to extend, operating inside IR35. This role is inside IR35 - Due to the service of the role, it will now be based on an Umbrella solution. Essential Skills / Experience required: Industry standard SOC Security qualifications (SANS, ISC2, etc.) Proven Tier 2/3 SOC Analyst experience (2 years+) Perform triage of security events ; determine scope, priority and impact, and make recommendations that enable expeditious remediation. Demonstratable experience working with SIEM technology and SIEM engineering (including tool configuration) i.e. ArcSight within an enterprise SOC. Experience in creation of use-cases, analytics and playbooks . An understanding of cloud Conduct real-time management of security incidents from detection to resolution. Technical Knowledge within anti-virus, networking, vulnerability management, encryption, Microsoft technologies, Linux. Knowledge of Information Security standards , legislation and practices, including GDPR & Data Protection Act 2018. Experience in dealing with a wide range of Information Security matters and operating in an ITIL based environment. Strong problem-solving ability, with flexibility to think creatively and adapt to and implement rapidly changing systems and services. Incident management experience and an ability to quickly tailor responses to deal with fast-moving situations. Highly desirable: Degree level qualification; preferably in technical, engineering or computing subject. Lead experience but would take a Tier 2 Analyst. Defence experience Role / Responsibilities: Responsible for supporting information security delivery work, including the development and implementation of Information Security Policies, Standards, processes and guidance. Responsibility for the security of Digital infrastructure by proactively analysing security threats/challenges/risks to the environment, including conducting penetration testing and compliance reviews monitoring of Information Security and information management to ensure compliance including reviewing and monitoring system and network logs for malicious activity or unacceptable use. If you are interested in the above role, please click Apply Now and send a CV for quick review. As a member of the Disability Confident Scheme, Circle and our Client guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Our client is proud to support the Armed Forces Covenant and as such, they guarantee to interview all veterans, spouses / partners of military personnel who meet all the essential criteria for the vacancy. In cases where they have a high volume of ex-military candidates / military spouses, partners, who meet all of the essential criteria, they will interview the best candidates from within that group. If you qualify, please notify us on igs at circlerecruitment dot com. We will be in touch to discuss your suitability and arrange your guaranteed interview. Should you require reasonable adjustments at any point during the recruitment process, if there is a better way for us to communicate, please do let us know. Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter and LinkedIn - Circle Recruitment.
May 19, 2026
Contractor
Role: DV-Cleared Cyber Security Analyst / SOC Analyst Salary/Rate: £540-640 per day inside IR35 Location: on site Corsham 5x pw Contract Duration: contract until April 2027 We are currently looking for a Cyber Security Analyst / SOC Analyst for our government client. This Cyber Security Analyst / SOC Analyst role is based fully on site, 5 days per week in Corsham, over 13-hour shifts spanning days and nights, including weekends, 4 on 5 off, then 5 on 4 off. There is no further flexibility with the on-site requirement or office location. Security Clearance: Developed Vetting (DV Clearance) + sole UK national + Sensitive Post Check (which can take 3 months) The contract for this Cyber Security Analyst / SOC Analyst position is until April 2027, with potential to extend, operating inside IR35. This role is inside IR35 - Due to the service of the role, it will now be based on an Umbrella solution. Essential Skills / Experience required: Industry standard SOC Security qualifications (SANS, ISC2, etc.) Proven Tier 2/3 SOC Analyst experience (2 years+) Perform triage of security events ; determine scope, priority and impact, and make recommendations that enable expeditious remediation. Demonstratable experience working with SIEM technology and SIEM engineering (including tool configuration) i.e. ArcSight within an enterprise SOC. Experience in creation of use-cases, analytics and playbooks . An understanding of cloud Conduct real-time management of security incidents from detection to resolution. Technical Knowledge within anti-virus, networking, vulnerability management, encryption, Microsoft technologies, Linux. Knowledge of Information Security standards , legislation and practices, including GDPR & Data Protection Act 2018. Experience in dealing with a wide range of Information Security matters and operating in an ITIL based environment. Strong problem-solving ability, with flexibility to think creatively and adapt to and implement rapidly changing systems and services. Incident management experience and an ability to quickly tailor responses to deal with fast-moving situations. Highly desirable: Degree level qualification; preferably in technical, engineering or computing subject. Lead experience but would take a Tier 2 Analyst. Defence experience Role / Responsibilities: Responsible for supporting information security delivery work, including the development and implementation of Information Security Policies, Standards, processes and guidance. Responsibility for the security of Digital infrastructure by proactively analysing security threats/challenges/risks to the environment, including conducting penetration testing and compliance reviews monitoring of Information Security and information management to ensure compliance including reviewing and monitoring system and network logs for malicious activity or unacceptable use. If you are interested in the above role, please click Apply Now and send a CV for quick review. As a member of the Disability Confident Scheme, Circle and our Client guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Our client is proud to support the Armed Forces Covenant and as such, they guarantee to interview all veterans, spouses / partners of military personnel who meet all the essential criteria for the vacancy. In cases where they have a high volume of ex-military candidates / military spouses, partners, who meet all of the essential criteria, they will interview the best candidates from within that group. If you qualify, please notify us on igs at circlerecruitment dot com. We will be in touch to discuss your suitability and arrange your guaranteed interview. Should you require reasonable adjustments at any point during the recruitment process, if there is a better way for us to communicate, please do let us know. Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter and LinkedIn - Circle Recruitment.
Job Title: DV Cleared Technical Author Location: Cheltenham Duration: 6 months with likely extension Rate: Up to 650 per day via an approved umbrella company Must be willing and able to go through highest security clearance process Our client, a leading organisation in the Defence sector, is hiring an experienced Technical Author. This is a unique opportunity to contribute to critical systems and operational processes within a secure environment. What you'll be doing: Producing, maintaining, and managing high-quality technical documentation for classified systems Translating complex technical concepts into clear, concise, and accurate written materials suitable for secure audiences Developing system documentation including architecture, design documents, user guides, operational manuals, and SOPs Supporting accreditation, assurance, and compliance documentation Collaborating closely with engineers, architects, cyber specialists, and stakeholders to validate content Ensuring all documentation aligns with security policies, governance frameworks, and information assurance standards Managing document control, versioning, and configuration throughout system lifecycles Preparing materials for both technical and non-technical audiences What you'll bring: Proven experience as a Technical Author or Documentation Specialist in highly secure or classified environments Strong ability to document complex technical systems clearly and accurately Experience producing documentation for IT, cyber, data, or engineering systems Excellent written communication skills with keen attention to detail Familiarity with formal documentation standards and structured authoring methods Ability to work collaboratively with technical teams and security professionals Strong understanding of information security and handling requirements Desirable skills: Background supporting UK defence, intelligence, or national security projects Experience documenting cyber security, data platforms, or software-based systems Familiarity with accreditation, risk management, or assurance documentation Experience with document management tools and markup languages such as Confluence, SharePoint, Markdown, or XML This role offers a chance to work on vital projects within a dynamic, secure environment. If you hold the necessary clearance and are passionate about producing impactful technical documentation, we encourage you to apply today!
May 18, 2026
Contractor
Job Title: DV Cleared Technical Author Location: Cheltenham Duration: 6 months with likely extension Rate: Up to 650 per day via an approved umbrella company Must be willing and able to go through highest security clearance process Our client, a leading organisation in the Defence sector, is hiring an experienced Technical Author. This is a unique opportunity to contribute to critical systems and operational processes within a secure environment. What you'll be doing: Producing, maintaining, and managing high-quality technical documentation for classified systems Translating complex technical concepts into clear, concise, and accurate written materials suitable for secure audiences Developing system documentation including architecture, design documents, user guides, operational manuals, and SOPs Supporting accreditation, assurance, and compliance documentation Collaborating closely with engineers, architects, cyber specialists, and stakeholders to validate content Ensuring all documentation aligns with security policies, governance frameworks, and information assurance standards Managing document control, versioning, and configuration throughout system lifecycles Preparing materials for both technical and non-technical audiences What you'll bring: Proven experience as a Technical Author or Documentation Specialist in highly secure or classified environments Strong ability to document complex technical systems clearly and accurately Experience producing documentation for IT, cyber, data, or engineering systems Excellent written communication skills with keen attention to detail Familiarity with formal documentation standards and structured authoring methods Ability to work collaboratively with technical teams and security professionals Strong understanding of information security and handling requirements Desirable skills: Background supporting UK defence, intelligence, or national security projects Experience documenting cyber security, data platforms, or software-based systems Familiarity with accreditation, risk management, or assurance documentation Experience with document management tools and markup languages such as Confluence, SharePoint, Markdown, or XML This role offers a chance to work on vital projects within a dynamic, secure environment. If you hold the necessary clearance and are passionate about producing impactful technical documentation, we encourage you to apply today!
PRINCIPAL CYBERSECURITY ENGINEER SC Cleared - UK Only - (Sponsorship is unavailable) you must hold SC Clearance.Provide expert advice on the defences against cyber threats, data breaches, and emerging risks. This includes offering guidance on the selection, design, justification, implementation, and operational management of cybersecurity strategies, technologies, and standards. Contribute to the development and refinement of controls and processes to ensure the safety, confidentiality, integrity, availability, and overall security of data stored on systems. You will be responsible for identifying gaps in existing cybersecurity policies and procedures and, in collaboration with security, network, information governance, and technical leads, developing new measures to address these gaps. KEY RESPONSIBILITIES: You will work closely with system and service owners, as well as internal and external stakeholders, to design, implement, and enforce appropriate protective and detective security controls, policies, and procedures. The role includes the administration and operational management of security tooling and SIEM platforms, with responsibility for monitoring, detecting, and responding to cyber threats, intrusions, and unauthorised or suspicious activity. This includes Microsoft Sentinel (data and source tuning, creation and maintenance of workbooks and connectors, and threat intelligence review), Microsoft Defender for Endpoint and Defender for Cloud, and Darktrace, including system and model tuning, email module management, and configuration of autonomous response actions. You will be responsible for incident response activities, including triaging security alerts, investigating incidents, coordinating escalation and remediation, and conducting root cause analysis. You must be able to communicate effectively about security incidents and cyber risks to both technical and non-technical stakeholders. The role works closely with the Security Operations Centre (SOC) partner, supporting the assessment and investigation of alerts and contributing to the development and refinement of incident response plans and playbooks. You will support vulnerability management activities, including vulnerability assessments, annual audits, and penetration testing. This includes preparing and presenting incident, threat, and compliance reporting to stakeholders at all levels, including compiling a monthly SIRO report. Continuous improvement is a core responsibility. You will conduct post-incident reviews, recommend control and process improvements, and contribute to the creation and maintenance of cybersecurity governance documentation. You will also research emerging cyber threats and mitigation strategies and provide reports or presentations to senior stakeholders as required. The role supports cybersecurity training and awareness initiatives, promoting a strong security culture and helping to upskill colleagues in cybersecurity best practices. You will also collaborate with solution architects and project teams to ensure security is embedded into system and application designs, supporting secure architecture and delivery from the outset. Compliance & Framework Alignment: Ensure security operations align with regulatory standards and frameworks such as NIST, ISO 27001, and NCSC CAF. Person SpecificationEssential: Demonstrated experience with Microsoft Sentinel, Microsoft Defender for Endpoint/Cloud SIEM tools, threat intelligence platforms, and vulnerability management. Technical experience securing Microsoft Azure and Amazon Web Services cloud environments as well as on-premise/virtual Microsoft technologies. Strong analytical, communication, and problem-solving skills, including the ability to produce clear technical and non-technical reports. Ability to analyse and interpret security events/logs and perform remediation work to address security issues. Desirable: Recognised cybersecurity certifications (e.g., CompTIA Security+, CEH, GIAC, CISSP). Experience with DarkTrace Qualifications Bachelor's degree in Cybersecurity or Computer Science Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
May 07, 2026
Full time
PRINCIPAL CYBERSECURITY ENGINEER SC Cleared - UK Only - (Sponsorship is unavailable) you must hold SC Clearance.Provide expert advice on the defences against cyber threats, data breaches, and emerging risks. This includes offering guidance on the selection, design, justification, implementation, and operational management of cybersecurity strategies, technologies, and standards. Contribute to the development and refinement of controls and processes to ensure the safety, confidentiality, integrity, availability, and overall security of data stored on systems. You will be responsible for identifying gaps in existing cybersecurity policies and procedures and, in collaboration with security, network, information governance, and technical leads, developing new measures to address these gaps. KEY RESPONSIBILITIES: You will work closely with system and service owners, as well as internal and external stakeholders, to design, implement, and enforce appropriate protective and detective security controls, policies, and procedures. The role includes the administration and operational management of security tooling and SIEM platforms, with responsibility for monitoring, detecting, and responding to cyber threats, intrusions, and unauthorised or suspicious activity. This includes Microsoft Sentinel (data and source tuning, creation and maintenance of workbooks and connectors, and threat intelligence review), Microsoft Defender for Endpoint and Defender for Cloud, and Darktrace, including system and model tuning, email module management, and configuration of autonomous response actions. You will be responsible for incident response activities, including triaging security alerts, investigating incidents, coordinating escalation and remediation, and conducting root cause analysis. You must be able to communicate effectively about security incidents and cyber risks to both technical and non-technical stakeholders. The role works closely with the Security Operations Centre (SOC) partner, supporting the assessment and investigation of alerts and contributing to the development and refinement of incident response plans and playbooks. You will support vulnerability management activities, including vulnerability assessments, annual audits, and penetration testing. This includes preparing and presenting incident, threat, and compliance reporting to stakeholders at all levels, including compiling a monthly SIRO report. Continuous improvement is a core responsibility. You will conduct post-incident reviews, recommend control and process improvements, and contribute to the creation and maintenance of cybersecurity governance documentation. You will also research emerging cyber threats and mitigation strategies and provide reports or presentations to senior stakeholders as required. The role supports cybersecurity training and awareness initiatives, promoting a strong security culture and helping to upskill colleagues in cybersecurity best practices. You will also collaborate with solution architects and project teams to ensure security is embedded into system and application designs, supporting secure architecture and delivery from the outset. Compliance & Framework Alignment: Ensure security operations align with regulatory standards and frameworks such as NIST, ISO 27001, and NCSC CAF. Person SpecificationEssential: Demonstrated experience with Microsoft Sentinel, Microsoft Defender for Endpoint/Cloud SIEM tools, threat intelligence platforms, and vulnerability management. Technical experience securing Microsoft Azure and Amazon Web Services cloud environments as well as on-premise/virtual Microsoft technologies. Strong analytical, communication, and problem-solving skills, including the ability to produce clear technical and non-technical reports. Ability to analyse and interpret security events/logs and perform remediation work to address security issues. Desirable: Recognised cybersecurity certifications (e.g., CompTIA Security+, CEH, GIAC, CISSP). Experience with DarkTrace Qualifications Bachelor's degree in Cybersecurity or Computer Science Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
Are you a Detection Engineer ready to take on the fight against modern adversaries? Join a well-established SOC working with high-profile Defence clients, where your expertise genuinely matters. In this hands-on technical role, you'll own the end-to-end design, development and maturity of detection logic across SIEM platforms-engineering effective responses to real-world attacker techniques. You'll operate with a high degree of autonomy, acting as a trusted SME across multiple secure environments within a complex MSSP setting. This is a standout opportunity to advance your career at the sharp end of cyber defence. Location: Hybrid working - 2 days per week in our Farnborough office. Security: You must hold or be eligible for SC Clearance. What you'll be doing: ? Design, build, test and continuously refine advanced SIEM detection logic, including rules, correlations and analytics. Research emerging threats, vulnerabilities and adversary TTPs, mapping them to MITRE ATT&CK to close detection and visibility gaps. Tune and validate detections to minimise false positives and deliver high-fidelity alerts for SOC analysts. Act as a technical authority, providing expert guidance to SOC Analysts, Architects and Engineers to strengthen overall detection capability. Define, implement and maintain technical detection standards across environments. Clearly communicate complex technical risks and detection logic to both technical teams and non-technical stakeholders. What you'll bring: Deep SIEM expertise, building advanced detection logic, automation and complex queries in Splunk (SPL) and Microsoft Sentinel (KQL). A proven track record delivering complex detection engineering projects within enterprise or MSSP environments. Strong analytical skills, with the ability to break down sophisticated attacks into actionable detection patterns. Confidence to own technical delivery end-to-end, driving work through to completion with minimal escalation. Expert knowledge of MITRE ATT&CK, with real-world application in detection engineering. A BSc in Computer Science, IT, or a related discipline. Solid scripting skills in Python, PowerShell, or similar, supporting automation and data manipulation. Experience developing detections in QRadar and/or conducting EDR-focused threat hunting (e.g. CrowdStrike, Microsoft Defender for Endpoint). Broad infrastructure awareness across Cloud (Azure/AWS), on-prem, and SaaS / PaaS / IaaS environments. If you are interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Full-time, Permanent. Location: Hybrid: 2 days per week in Farnborough. Security Clearance Level: SC Cleared or eligible. Internal Recruiter: Jane. Salary: To £65,000. Benefits: 25 days annual leave with the choice to buy additional days, health cash plan, life assurance and pension. Sopra Steria: Our Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.
May 03, 2026
Full time
Are you a Detection Engineer ready to take on the fight against modern adversaries? Join a well-established SOC working with high-profile Defence clients, where your expertise genuinely matters. In this hands-on technical role, you'll own the end-to-end design, development and maturity of detection logic across SIEM platforms-engineering effective responses to real-world attacker techniques. You'll operate with a high degree of autonomy, acting as a trusted SME across multiple secure environments within a complex MSSP setting. This is a standout opportunity to advance your career at the sharp end of cyber defence. Location: Hybrid working - 2 days per week in our Farnborough office. Security: You must hold or be eligible for SC Clearance. What you'll be doing: ? Design, build, test and continuously refine advanced SIEM detection logic, including rules, correlations and analytics. Research emerging threats, vulnerabilities and adversary TTPs, mapping them to MITRE ATT&CK to close detection and visibility gaps. Tune and validate detections to minimise false positives and deliver high-fidelity alerts for SOC analysts. Act as a technical authority, providing expert guidance to SOC Analysts, Architects and Engineers to strengthen overall detection capability. Define, implement and maintain technical detection standards across environments. Clearly communicate complex technical risks and detection logic to both technical teams and non-technical stakeholders. What you'll bring: Deep SIEM expertise, building advanced detection logic, automation and complex queries in Splunk (SPL) and Microsoft Sentinel (KQL). A proven track record delivering complex detection engineering projects within enterprise or MSSP environments. Strong analytical skills, with the ability to break down sophisticated attacks into actionable detection patterns. Confidence to own technical delivery end-to-end, driving work through to completion with minimal escalation. Expert knowledge of MITRE ATT&CK, with real-world application in detection engineering. A BSc in Computer Science, IT, or a related discipline. Solid scripting skills in Python, PowerShell, or similar, supporting automation and data manipulation. Experience developing detections in QRadar and/or conducting EDR-focused threat hunting (e.g. CrowdStrike, Microsoft Defender for Endpoint). Broad infrastructure awareness across Cloud (Azure/AWS), on-prem, and SaaS / PaaS / IaaS environments. If you are interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Full-time, Permanent. Location: Hybrid: 2 days per week in Farnborough. Security Clearance Level: SC Cleared or eligible. Internal Recruiter: Jane. Salary: To £65,000. Benefits: 25 days annual leave with the choice to buy additional days, health cash plan, life assurance and pension. Sopra Steria: Our Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.
We are looking for a Managing Security Engineer to lead the design, implementation and documentation of enterprise security monitoring platforms. This is a key technical leadership role, responsible for ensuring the right tooling, controls and processes are in place to help protect and monitor our clients' environments. This opportunity is ideally suited to someone with strong hands-on experience deploying and managing Splunk at enterprise scale. In return, the role offers the chance to broaden your capability and gain deeper experience in Elastic Security, with support to build your expertise further. You will work closely with cross-functional teams to assess risk, design effective security controls and define testing requirements. You will champion security by design, promote engineering excellence and act as a trusted advisor to clients, helping them understand their security challenges and implement practical, effective solutions to strengthen their security posture. This is an excellent opportunity to deepen your hands-on cybersecurity expertise while making a meaningful impact across both client and organisational security. This role is permanent and requires full-time, on-site working in Hemel Hempstead. The successful candidate may also participate in an out-of-hours call-out rota. What you will be doing: Lead the deployment, management and optimisation of Splunk Enterprise and Splunk ES platforms in large, complex environments. Support and develop capability in Elastic Stack / Elastic Security, with training and upskilling provided as needed. Design, implement and maintain data pipelines, including log ingestion, enrichment and schema standardisation. Develop and tune security detection content, translating threat intelligence and TTPs aligned to MITRE ATT&CK into actionable, high-value alerts. Manage the full detection content lifecycle: design, test, deploy, monitor, tune and retire, using version control and rollback processes. Automate workflows and platform configurations using CI/CD, SOAR, scripting and Infrastructure as Code tools such as Terraform and Ansible. Ensure platform performance, stability and resilience through capacity planning, high availability, disaster recovery and proactive monitoring. Provide technical leadership and guidance to internal teams and clients on security monitoring strategy and best practice. What you will bring: Proven experience deploying and managing Splunk at enterprise scale. Strong hands-on knowledge of SIEM engineering, including indexing, parsing, onboarding and performance tuning. Experience designing and optimising detection content, including MITRE ATT&CK-aligned use cases and alert tuning to reduce noise. Good understanding of data pipeline engineering, log enrichment, data quality and large-scale ingestion architectures. Strong knowledge of SPL; experience with KQL and EQL would be beneficial, but is not essential. Experience with automation and Infrastructure-as-Code within security monitoring or SIEM environments. Solid understanding of SIEM platform operations, including clustering, scaling, high availability, disaster recovery and performance optimisation. Strong problem-solving skills and a proactive approach to improving security operations. An interest in developing expertise in Elastic Security, with support and training available as part of the role. If you are interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Full Time, Permanent Location: Hemel Hempstead Security Clearance Level: DV Cleared Internal Recruiter: Jane Salary: from £DOE Benefits: £5400 Car Allowance, 25 days annual leave with the option to buy additional days, private health care, life assurance, pension, and generous flexible benefits fund Loved reading about this job and want to know more about us? Sopra Steria's Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.
May 03, 2026
Full time
We are looking for a Managing Security Engineer to lead the design, implementation and documentation of enterprise security monitoring platforms. This is a key technical leadership role, responsible for ensuring the right tooling, controls and processes are in place to help protect and monitor our clients' environments. This opportunity is ideally suited to someone with strong hands-on experience deploying and managing Splunk at enterprise scale. In return, the role offers the chance to broaden your capability and gain deeper experience in Elastic Security, with support to build your expertise further. You will work closely with cross-functional teams to assess risk, design effective security controls and define testing requirements. You will champion security by design, promote engineering excellence and act as a trusted advisor to clients, helping them understand their security challenges and implement practical, effective solutions to strengthen their security posture. This is an excellent opportunity to deepen your hands-on cybersecurity expertise while making a meaningful impact across both client and organisational security. This role is permanent and requires full-time, on-site working in Hemel Hempstead. The successful candidate may also participate in an out-of-hours call-out rota. What you will be doing: Lead the deployment, management and optimisation of Splunk Enterprise and Splunk ES platforms in large, complex environments. Support and develop capability in Elastic Stack / Elastic Security, with training and upskilling provided as needed. Design, implement and maintain data pipelines, including log ingestion, enrichment and schema standardisation. Develop and tune security detection content, translating threat intelligence and TTPs aligned to MITRE ATT&CK into actionable, high-value alerts. Manage the full detection content lifecycle: design, test, deploy, monitor, tune and retire, using version control and rollback processes. Automate workflows and platform configurations using CI/CD, SOAR, scripting and Infrastructure as Code tools such as Terraform and Ansible. Ensure platform performance, stability and resilience through capacity planning, high availability, disaster recovery and proactive monitoring. Provide technical leadership and guidance to internal teams and clients on security monitoring strategy and best practice. What you will bring: Proven experience deploying and managing Splunk at enterprise scale. Strong hands-on knowledge of SIEM engineering, including indexing, parsing, onboarding and performance tuning. Experience designing and optimising detection content, including MITRE ATT&CK-aligned use cases and alert tuning to reduce noise. Good understanding of data pipeline engineering, log enrichment, data quality and large-scale ingestion architectures. Strong knowledge of SPL; experience with KQL and EQL would be beneficial, but is not essential. Experience with automation and Infrastructure-as-Code within security monitoring or SIEM environments. Solid understanding of SIEM platform operations, including clustering, scaling, high availability, disaster recovery and performance optimisation. Strong problem-solving skills and a proactive approach to improving security operations. An interest in developing expertise in Elastic Security, with support and training available as part of the role. If you are interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Full Time, Permanent Location: Hemel Hempstead Security Clearance Level: DV Cleared Internal Recruiter: Jane Salary: from £DOE Benefits: £5400 Car Allowance, 25 days annual leave with the option to buy additional days, private health care, life assurance, pension, and generous flexible benefits fund Loved reading about this job and want to know more about us? Sopra Steria's Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Apr 30, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Apr 30, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Job Title: DV Cleared Technical Author Location: Cheltenham Duration: 6 months with likely extension Rate: Up to 650 per day via an approved umbrella company Must be willing and able to go through highest security clearance process Our client, a leading organisation in the Defence sector, is hiring an experienced Technical Author. This is a unique opportunity to contribute to critical systems and operational processes within a secure environment. What you'll be doing: Producing, maintaining, and managing high-quality technical documentation for classified systems Translating complex technical concepts into clear, concise, and accurate written materials suitable for secure audiences Developing system documentation including architecture, design documents, user guides, operational manuals, and SOPs Supporting accreditation, assurance, and compliance documentation Collaborating closely with engineers, architects, cyber specialists, and stakeholders to validate content Ensuring all documentation aligns with security policies, governance frameworks, and information assurance standards Managing document control, versioning, and configuration throughout system lifecycles Preparing materials for both technical and non-technical audiences What you'll bring: Proven experience as a Technical Author or Documentation Specialist in highly secure or classified environments Strong ability to document complex technical systems clearly and accurately Experience producing documentation for IT, cyber, data, or engineering systems Excellent written communication skills with keen attention to detail Familiarity with formal documentation standards and structured authoring methods Ability to work collaboratively with technical teams and security professionals Strong understanding of information security and handling requirements Desirable skills: Background supporting UK defence, intelligence, or national security projects Experience documenting cyber security, data platforms, or software-based systems Familiarity with accreditation, risk management, or assurance documentation Experience with document management tools and markup languages such as Confluence, SharePoint, Markdown, or XML This role offers a chance to work on vital projects within a dynamic, secure environment. If you hold the necessary clearance and are passionate about producing impactful technical documentation, we encourage you to apply today!
Apr 20, 2026
Contractor
Job Title: DV Cleared Technical Author Location: Cheltenham Duration: 6 months with likely extension Rate: Up to 650 per day via an approved umbrella company Must be willing and able to go through highest security clearance process Our client, a leading organisation in the Defence sector, is hiring an experienced Technical Author. This is a unique opportunity to contribute to critical systems and operational processes within a secure environment. What you'll be doing: Producing, maintaining, and managing high-quality technical documentation for classified systems Translating complex technical concepts into clear, concise, and accurate written materials suitable for secure audiences Developing system documentation including architecture, design documents, user guides, operational manuals, and SOPs Supporting accreditation, assurance, and compliance documentation Collaborating closely with engineers, architects, cyber specialists, and stakeholders to validate content Ensuring all documentation aligns with security policies, governance frameworks, and information assurance standards Managing document control, versioning, and configuration throughout system lifecycles Preparing materials for both technical and non-technical audiences What you'll bring: Proven experience as a Technical Author or Documentation Specialist in highly secure or classified environments Strong ability to document complex technical systems clearly and accurately Experience producing documentation for IT, cyber, data, or engineering systems Excellent written communication skills with keen attention to detail Familiarity with formal documentation standards and structured authoring methods Ability to work collaboratively with technical teams and security professionals Strong understanding of information security and handling requirements Desirable skills: Background supporting UK defence, intelligence, or national security projects Experience documenting cyber security, data platforms, or software-based systems Familiarity with accreditation, risk management, or assurance documentation Experience with document management tools and markup languages such as Confluence, SharePoint, Markdown, or XML This role offers a chance to work on vital projects within a dynamic, secure environment. If you hold the necessary clearance and are passionate about producing impactful technical documentation, we encourage you to apply today!