NCC Group plc in Manchester is seeking a Detection Engineer to enhance security detections using Splunk. Responsibilities include developing detections across cloud and infrastructure, analyzing logs, and documenting processes. Ideal candidates will have experience with Splunk and various security concepts, along with the ability to support SOC analysts. This role offers a flexible working arrangement and a generous holiday allowance.
20/07/2026
Full time
NCC Group plc in Manchester is seeking a Detection Engineer to enhance security detections using Splunk. Responsibilities include developing detections across cloud and infrastructure, analyzing logs, and documenting processes. Ideal candidates will have experience with Splunk and various security concepts, along with the ability to support SOC analysts. This role offers a flexible working arrangement and a generous holiday allowance.
NCC Group plc is seeking a Global Detection Engineer in Cheltenham who will lead a team focused on developing and maintaining cutting-edge detection logic for cyber threats. The successful candidate will work closely with international teams to ensure efficiency in detecting high-risk cyber attack techniques. Key responsibilities include leading the implementation team, managing detection engineers, and ensuring market-leading detection coverage. Candidates should have extensive experience in detection engineering and strong leadership skills.
20/07/2026
Full time
NCC Group plc is seeking a Global Detection Engineer in Cheltenham who will lead a team focused on developing and maintaining cutting-edge detection logic for cyber threats. The successful candidate will work closely with international teams to ensure efficiency in detecting high-risk cyber attack techniques. Key responsibilities include leading the implementation team, managing detection engineers, and ensuring market-leading detection coverage. Candidates should have extensive experience in detection engineering and strong leadership skills.
NCC Group plc in Manchester is seeking a Lead Enterprise Architect to lead the review and design of their enterprise architecture. This role is pivotal for supporting various internal projects and aligning business needs with IT long-term strategies. The ideal candidate will have extensive experience in Enterprise Architecture and strong knowledge of IT risks and cyber security. Key responsibilities include delivering architectural documents, gathering requirements, and collaborating with cross-functional teams. Benefits include flexible working options, enhanced holiday allowances, and various health and financial benefits.
18/07/2026
Full time
NCC Group plc in Manchester is seeking a Lead Enterprise Architect to lead the review and design of their enterprise architecture. This role is pivotal for supporting various internal projects and aligning business needs with IT long-term strategies. The ideal candidate will have extensive experience in Enterprise Architecture and strong knowledge of IT risks and cyber security. Key responsibilities include delivering architectural documents, gathering requirements, and collaborating with cross-functional teams. Benefits include flexible working options, enhanced holiday allowances, and various health and financial benefits.
Lead Enterprise Architect Department: IT Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Marthijn Van Den Brand Description Within the Design Authority you will be working on Architecture for both business systems as well as corporate services. Within the design authority you will focus on aligning business needs together with IT long-term strategy. The DA within NCC group is a facilitating and cooperative entity that will bridge knowledge and ensure Global Technical Service teams as well as the business engineering teams are aligned, and knowledge is shared where possible. As a member of the DA you will join projects in a very early stage to help and ensure our Systems development cross the NCC Group. We are seeking a highly skilled and experienced Lead Enterprise Architect to lead the review, design and implementation of our estate from a EA perspective. Key Responsibilities As a Lead Enterprise Architect you will play a key role in supporting internal GTS projects as well as Business projects with your expertise. You will work in various projects delivering oversight translation to and from business and technical teams and be able to work out the final solution together with experts across the group. Deliver architecture documents that meet requirements from various stakeholders and are in line with our strategy. Deliver your knowledge and skills to the business engineering teams Able to gather and document requirements (functional and technical) Align business requirements with strategic long-term plan. Present overall architecture if needed to various audiences Write long term roadmaps Chair technical sessions with engineering teams and translating those into written technical and functional documentation Investigate the 'as is' state currently in place across the group's systems and networks. Produce a picture of company assets and where any security concerns may arise. Define and document how the implementation of a new system or new interfaces between systems. Skills, Knowledge and Expertise Requirement's analysis Experience with at least the following: Networking Domains (and Domain Segregation) Hybrid Cloud Microsoft O365/ActiveDirectory/AzureAD/Sharepoint/PowerBI High Availability deployment strategy Enterprise Architecture Security principles Written functional documentation Technical documentation writing Familiar with TOGAF (or similar frameworks) Proactive project membership and attitude Strong in T's and C's Proven experience as a Architect or similar role. Prior knowledge of Security architecture in a number of different technologies. Strong working knowledge of IT risks, cyber security, and computer operating software The aptitude and ability to quickly absorb technical detail of new or unfamiliar technologies is essential. Proven experience with writing architecture documentation. Frameworks Togaf9 / Zachman / UAF / Agile / FEAF / MoD AF BPMN / UML / ArchiMate Networking / VPN / IPSEC Possible Certifications AWS Cert Sol. Architecture CISSP Dell EMC Cloud Professional Cloud Solutions Architect Open Group Cert. Arch. Benefits Flexible Working: Balance your work and personal life with our flexible working options. Enhanced Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
18/07/2026
Full time
Lead Enterprise Architect Department: IT Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Marthijn Van Den Brand Description Within the Design Authority you will be working on Architecture for both business systems as well as corporate services. Within the design authority you will focus on aligning business needs together with IT long-term strategy. The DA within NCC group is a facilitating and cooperative entity that will bridge knowledge and ensure Global Technical Service teams as well as the business engineering teams are aligned, and knowledge is shared where possible. As a member of the DA you will join projects in a very early stage to help and ensure our Systems development cross the NCC Group. We are seeking a highly skilled and experienced Lead Enterprise Architect to lead the review, design and implementation of our estate from a EA perspective. Key Responsibilities As a Lead Enterprise Architect you will play a key role in supporting internal GTS projects as well as Business projects with your expertise. You will work in various projects delivering oversight translation to and from business and technical teams and be able to work out the final solution together with experts across the group. Deliver architecture documents that meet requirements from various stakeholders and are in line with our strategy. Deliver your knowledge and skills to the business engineering teams Able to gather and document requirements (functional and technical) Align business requirements with strategic long-term plan. Present overall architecture if needed to various audiences Write long term roadmaps Chair technical sessions with engineering teams and translating those into written technical and functional documentation Investigate the 'as is' state currently in place across the group's systems and networks. Produce a picture of company assets and where any security concerns may arise. Define and document how the implementation of a new system or new interfaces between systems. Skills, Knowledge and Expertise Requirement's analysis Experience with at least the following: Networking Domains (and Domain Segregation) Hybrid Cloud Microsoft O365/ActiveDirectory/AzureAD/Sharepoint/PowerBI High Availability deployment strategy Enterprise Architecture Security principles Written functional documentation Technical documentation writing Familiar with TOGAF (or similar frameworks) Proactive project membership and attitude Strong in T's and C's Proven experience as a Architect or similar role. Prior knowledge of Security architecture in a number of different technologies. Strong working knowledge of IT risks, cyber security, and computer operating software The aptitude and ability to quickly absorb technical detail of new or unfamiliar technologies is essential. Proven experience with writing architecture documentation. Frameworks Togaf9 / Zachman / UAF / Agile / FEAF / MoD AF BPMN / UML / ArchiMate Networking / VPN / IPSEC Possible Certifications AWS Cert Sol. Architecture CISSP Dell EMC Cloud Professional Cloud Solutions Architect Open Group Cert. Arch. Benefits Flexible Working: Balance your work and personal life with our flexible working options. Enhanced Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
AD - Global Detection Engineering Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR London Description The purpose of this role is to lead a global team that builds, maintains and continuously improves detection logic across a variety of MXDR technologies, according to a clear strategy that is regularly updated to meet market and client demands. The global team will be made up of regionally located colleagues (UK, NL, AU & PH), that all contribute to a global set of detection logic, custom detections for clients and structural improvement projects around these themes. The head of global detection engineering will be responsible for ensuring a market leading detection coverage on the technologies we deploy as part of our MXDR services. They ensure that we detect high risk cyber attack techniques, that result in high fidelity detections at our clients, with low false positive ratios. A key part of the role is engaging and collaborating with other leaders in the GMS and NCC business, to ensure that we achieve the following key ambitions: Develop new detection logic to contribute to Detection Engineering content repository. Continuously improve existing detection logic. Write and maintain detection tests cases. Review findings of TI, CERT, and Red Team activities and evaluate from a detection engineering improvement perspective. Key Responsibilities Lead a global implementation team that builds, maintains and continuously improves detection logic across a variety of MXDR technologies Be part of the GMS DevSecOps leadership team and actively contribute to setting vision, direction and feature set of our technology platforms Ensure that our detection logic is a differentiator in the market, providing extensive and high quality coverage for advanced cyber attacks Manage senior detection engineers who each manage a number of detection engineers on a specific technology set (EDR, NDR, SIEM) Work pro-actively with wider NCC teams to ensure all relevant inputs are available (TI, DFIR, RTO etc) to build top-notch detection logic and to ensure other teams (like solution architecture and implementations) have the required information to deploy high quality MXDR systems with the best possible coverage Ensure that we can always provide transparency to clients about the detection coverage they receive Ensure that we develop new ways of applying data science to our vast data sets in order to further improve detection of cyber attacks, correlation of alerts and other efficiencies and improvements that provide improved coverage to clients and improved efficiency to our SOC Skills, Knowledge & Expertise Experience in detection engineering on a range of technologies (SIEM and EDR, ideally NDR as well) Experience in working in a global firm in a multi-cultural context Experience in working in a complex international environment, that's subjected to a significant amount of change Excellent oral and written communication skills Ability to work with clients and NCC colleagues to continuously improve the service we deliver Experience with and knowledge of application of data science within a cyber security context Inspiring leader, with ability to communicate effectively at all levels, creating an approachable and supportive environment for colleagues Desirable skills Have hands-on experience with a variety of technologies we use: Sentinel, Defender for End-point, Carbon Black, Splunk, etc Experience with purple teaming and other adjacent cyber security practices/topics that strengthen detection engineering Forensics and/or incident response experience Job Benefits What do we offer in return? We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Enhanced Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
17/07/2026
Full time
AD - Global Detection Engineering Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR London Description The purpose of this role is to lead a global team that builds, maintains and continuously improves detection logic across a variety of MXDR technologies, according to a clear strategy that is regularly updated to meet market and client demands. The global team will be made up of regionally located colleagues (UK, NL, AU & PH), that all contribute to a global set of detection logic, custom detections for clients and structural improvement projects around these themes. The head of global detection engineering will be responsible for ensuring a market leading detection coverage on the technologies we deploy as part of our MXDR services. They ensure that we detect high risk cyber attack techniques, that result in high fidelity detections at our clients, with low false positive ratios. A key part of the role is engaging and collaborating with other leaders in the GMS and NCC business, to ensure that we achieve the following key ambitions: Develop new detection logic to contribute to Detection Engineering content repository. Continuously improve existing detection logic. Write and maintain detection tests cases. Review findings of TI, CERT, and Red Team activities and evaluate from a detection engineering improvement perspective. Key Responsibilities Lead a global implementation team that builds, maintains and continuously improves detection logic across a variety of MXDR technologies Be part of the GMS DevSecOps leadership team and actively contribute to setting vision, direction and feature set of our technology platforms Ensure that our detection logic is a differentiator in the market, providing extensive and high quality coverage for advanced cyber attacks Manage senior detection engineers who each manage a number of detection engineers on a specific technology set (EDR, NDR, SIEM) Work pro-actively with wider NCC teams to ensure all relevant inputs are available (TI, DFIR, RTO etc) to build top-notch detection logic and to ensure other teams (like solution architecture and implementations) have the required information to deploy high quality MXDR systems with the best possible coverage Ensure that we can always provide transparency to clients about the detection coverage they receive Ensure that we develop new ways of applying data science to our vast data sets in order to further improve detection of cyber attacks, correlation of alerts and other efficiencies and improvements that provide improved coverage to clients and improved efficiency to our SOC Skills, Knowledge & Expertise Experience in detection engineering on a range of technologies (SIEM and EDR, ideally NDR as well) Experience in working in a global firm in a multi-cultural context Experience in working in a complex international environment, that's subjected to a significant amount of change Excellent oral and written communication skills Ability to work with clients and NCC colleagues to continuously improve the service we deliver Experience with and knowledge of application of data science within a cyber security context Inspiring leader, with ability to communicate effectively at all levels, creating an approachable and supportive environment for colleagues Desirable skills Have hands-on experience with a variety of technologies we use: Sentinel, Defender for End-point, Carbon Black, Splunk, etc Experience with purple teaming and other adjacent cyber security practices/topics that strengthen detection engineering Forensics and/or incident response experience Job Benefits What do we offer in return? We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Enhanced Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
NCC Group plc in Greater London is looking for a head of Global Detection Engineering to lead a diverse team dedicated to developing market-leading detection logic. This role includes collaboration with international colleagues to enhance detection capabilities across various technologies. Ideal candidates will have experience in detection engineering, excellent communication skills, and the ability to drive improvements in service delivery. The position offers a comprehensive benefits package along with flexibility to balance work and personal life.
17/07/2026
Full time
NCC Group plc in Greater London is looking for a head of Global Detection Engineering to lead a diverse team dedicated to developing market-leading detection logic. This role includes collaboration with international colleagues to enhance detection capabilities across various technologies. Ideal candidates will have experience in detection engineering, excellent communication skills, and the ability to drive improvements in service delivery. The position offers a comprehensive benefits package along with flexibility to balance work and personal life.
Detection Engineer Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Description NCC Group is looking for a Detection Engineer to join the Detection Engineering team. The role will focus on developing, maintaining, and improving Splunk-based security detections across cloud, infrastructure, and custom log sources. The successful candidate will help turn security risks, threat models, assurance requirements, and log sources into practical detections that can be deployed, tuned, and documented. Key Responsibilities Develop and maintain detections using Splunk SPL. Analyse logs from cloud, infrastructure, application, gateway, Linux, SSH, CDN, vulnerability management, and audit sources. Create detections for areas such as: cloud security monitoring and cloud control-plane activity, infrastructure, platform, and access-related security events, bespoke assurance use cases based on customer-specific log sources, suspicious or anomalous activity identified through threat models, security testing. Review existing detection coverage and identify gaps. Assess new log sources and define detection use cases. Map detections to MITRE ATT&CK, risk scenarios, and assurance requirements where relevant. Tune detections to reduce false positives and improve analyst usability. Document detection purpose, logic, alerting criteria, data source, MITRE mapping, false positives, and investigation guidance. Support SOC analysts with alert context and investigation advice. Skills, Knowledge & Expertise Candidates do not need to meet every requirement, but should have experience in some of the following: Splunk SPL or similar query language. Security detection engineering, SIEM engineering, threat hunting, or security monitoring. Cloud audit logs, especially AWS; GCP or OCI experience is also useful. MITRE ATT&CK and common attacker behaviours. Kubernetes or container security monitoring. Cloud security concepts such as IAM, KMS, security groups, route tables, ACLs, object storage, and service accounts. Use of allowlists, thresholds, baselines, aggregation, and anomaly-style detection logic. Regex and basic scripting, e.g. Python, Bash, or PowerShell. Documentation using Jira, JSM, Confluence, or similar tools. Desirable Experience: Experience with Splunk Enterprise Security and Splunk Security Essentials. Experience writing or tuning scheduled alerts. Experience reviewing threat models, security testing outputs, or assurance requirements. Experience using a detection as code deployment pipeline. Job Benefits Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
17/07/2026
Full time
Detection Engineer Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Description NCC Group is looking for a Detection Engineer to join the Detection Engineering team. The role will focus on developing, maintaining, and improving Splunk-based security detections across cloud, infrastructure, and custom log sources. The successful candidate will help turn security risks, threat models, assurance requirements, and log sources into practical detections that can be deployed, tuned, and documented. Key Responsibilities Develop and maintain detections using Splunk SPL. Analyse logs from cloud, infrastructure, application, gateway, Linux, SSH, CDN, vulnerability management, and audit sources. Create detections for areas such as: cloud security monitoring and cloud control-plane activity, infrastructure, platform, and access-related security events, bespoke assurance use cases based on customer-specific log sources, suspicious or anomalous activity identified through threat models, security testing. Review existing detection coverage and identify gaps. Assess new log sources and define detection use cases. Map detections to MITRE ATT&CK, risk scenarios, and assurance requirements where relevant. Tune detections to reduce false positives and improve analyst usability. Document detection purpose, logic, alerting criteria, data source, MITRE mapping, false positives, and investigation guidance. Support SOC analysts with alert context and investigation advice. Skills, Knowledge & Expertise Candidates do not need to meet every requirement, but should have experience in some of the following: Splunk SPL or similar query language. Security detection engineering, SIEM engineering, threat hunting, or security monitoring. Cloud audit logs, especially AWS; GCP or OCI experience is also useful. MITRE ATT&CK and common attacker behaviours. Kubernetes or container security monitoring. Cloud security concepts such as IAM, KMS, security groups, route tables, ACLs, object storage, and service accounts. Use of allowlists, thresholds, baselines, aggregation, and anomaly-style detection logic. Regex and basic scripting, e.g. Python, Bash, or PowerShell. Documentation using Jira, JSM, Confluence, or similar tools. Desirable Experience: Experience with Splunk Enterprise Security and Splunk Security Essentials. Experience writing or tuning scheduled alerts. Experience reviewing threat models, security testing outputs, or assurance requirements. Experience using a detection as code deployment pipeline. Job Benefits Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
AD - Global Detection Engineering Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Cheltenham Jessop House Description The purpose of this role is to lead a global team that builds, maintains and continuously improves detection logic across a variety of MXDR technologies, according to a clear strategy that is regularly updated to meet market and client demands. The global team will be made up of regionally located colleagues (UK, NL, AU & PH), that all contribute to a global set of detection logic, custom detections for clients and structural improvement projects around these themes. The head of global detection engineering will be responsible for ensuring a market leading detection coverage on the technologies we deploy as part of our MXDR services. They ensure that we detect high risk cyber attack techniques, that result in high fidelity detections at our clients, with low false positive ratios. A key part of the role is engaging and collaborating with other leaders in the GMS and NCC business, to ensure that we achieve the following key ambitions: Develop new detection logic to contribute to Detection Engineering content repository. Continuously improve existing detection logic. Write and maintain detection tests cases. Review findings of TI, CERT, and Red Team activities and evaluate from a detection engineering improvement perspective. Key Responsibilities Lead a global implementation team that builds, maintains and continuously improves detection logic across a variety of MXDR technologies. Be part of the GMS DevSecOps leadership team and actively contribute to setting vision, direction and feature set of our technology platforms. Ensure that our detection logic is a differentiator in the market, providing extensive and high quality coverage for advanced cyber attacks. Manage senior detection engineers who each manage a number of detection engineers on a specific technology set (EDR, NDR, SIEM). Work pro-actively with wider NCC teams to ensure all relevant inputs are available (TI, DFIR, RTO etc) to build top-notch detection logic and to ensure other teams (like solution architecture and implementations) have the required information to deploy high quality MXDR systems with the best possible coverage. Ensure that we can always provide transparency to clients about the detection coverage they receive. Ensure that we develop new ways of applying data science to our vast data sets in order to further improve detection of cyber attacks, correlation of alerts and other efficiencies and improvements that provide improved coverage to clients and improved efficiency to our SOC. Skills, Knowledge & Expertise Experience in detection engineering on a range of technologies (SIEM and EDR, ideally NDR as well) Experience in working in a global firm in a multi-cultural context Experience in working in a complex international environment, that's subjected to a significant amount of change Excellent oral and written communication skills Ability to work with clients and NCC colleagues to continuously improve the service we deliver Experience with and knowledge of application of data science within a cyber security context Inspiring leader, with ability to communicate effectively at all levels, creating an approachable and supportive environment for colleagues Desirable skills Hands on experience with a variety of technologies we use: Sentinel, Defender for End-point, Carbon Black, Splunk, etc. Experience with purple teaming and other adjacent cyber security practices/topics that strengthen detection engineering. Forensics and/or incident response experience. Job Benefits Flexible Working: Balance your work and personal life with our flexible working options. Enhanced Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
17/07/2026
Full time
AD - Global Detection Engineering Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Cheltenham Jessop House Description The purpose of this role is to lead a global team that builds, maintains and continuously improves detection logic across a variety of MXDR technologies, according to a clear strategy that is regularly updated to meet market and client demands. The global team will be made up of regionally located colleagues (UK, NL, AU & PH), that all contribute to a global set of detection logic, custom detections for clients and structural improvement projects around these themes. The head of global detection engineering will be responsible for ensuring a market leading detection coverage on the technologies we deploy as part of our MXDR services. They ensure that we detect high risk cyber attack techniques, that result in high fidelity detections at our clients, with low false positive ratios. A key part of the role is engaging and collaborating with other leaders in the GMS and NCC business, to ensure that we achieve the following key ambitions: Develop new detection logic to contribute to Detection Engineering content repository. Continuously improve existing detection logic. Write and maintain detection tests cases. Review findings of TI, CERT, and Red Team activities and evaluate from a detection engineering improvement perspective. Key Responsibilities Lead a global implementation team that builds, maintains and continuously improves detection logic across a variety of MXDR technologies. Be part of the GMS DevSecOps leadership team and actively contribute to setting vision, direction and feature set of our technology platforms. Ensure that our detection logic is a differentiator in the market, providing extensive and high quality coverage for advanced cyber attacks. Manage senior detection engineers who each manage a number of detection engineers on a specific technology set (EDR, NDR, SIEM). Work pro-actively with wider NCC teams to ensure all relevant inputs are available (TI, DFIR, RTO etc) to build top-notch detection logic and to ensure other teams (like solution architecture and implementations) have the required information to deploy high quality MXDR systems with the best possible coverage. Ensure that we can always provide transparency to clients about the detection coverage they receive. Ensure that we develop new ways of applying data science to our vast data sets in order to further improve detection of cyber attacks, correlation of alerts and other efficiencies and improvements that provide improved coverage to clients and improved efficiency to our SOC. Skills, Knowledge & Expertise Experience in detection engineering on a range of technologies (SIEM and EDR, ideally NDR as well) Experience in working in a global firm in a multi-cultural context Experience in working in a complex international environment, that's subjected to a significant amount of change Excellent oral and written communication skills Ability to work with clients and NCC colleagues to continuously improve the service we deliver Experience with and knowledge of application of data science within a cyber security context Inspiring leader, with ability to communicate effectively at all levels, creating an approachable and supportive environment for colleagues Desirable skills Hands on experience with a variety of technologies we use: Sentinel, Defender for End-point, Carbon Black, Splunk, etc. Experience with purple teaming and other adjacent cyber security practices/topics that strengthen detection engineering. Forensics and/or incident response experience. Job Benefits Flexible Working: Balance your work and personal life with our flexible working options. Enhanced Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
NCC Group plc in Cheltenham is seeking an experienced Embedded Vulnerability Researcher to join their growing National Security Business Unit. The role involves conducting research on complex security challenges, using advanced reverse engineering skills, and developing innovative solutions. Benefits include flexible working options, 25 days of holiday plus additional leave options, and generous financial and investment benefits to ensure a healthy work-life balance.
14/07/2026
Full time
NCC Group plc in Cheltenham is seeking an experienced Embedded Vulnerability Researcher to join their growing National Security Business Unit. The role involves conducting research on complex security challenges, using advanced reverse engineering skills, and developing innovative solutions. Benefits include flexible working options, 25 days of holiday plus additional leave options, and generous financial and investment benefits to ensure a healthy work-life balance.
Embedded Researcher Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Cheltenham Jessop House Description Thanks for checking out our job opening; we are excited that YOU are interested in learning more about NCC Group. The opportunity Our National Security Business Unit is growing, and we're seeking Embedded Vulnerability Researchers to join our team. Whether you're an experienced researcher or ready to build on your skills, we offer a variety of exciting opportunities. You'll work alongside a team of experts on projects ranging from short-term tactical challenges to long-term research engagements. The role is based out of our Cheltenham office with the possibility of a hybrid working approach. With dedicated lab facilities, regular team and research events, and a focus on training and development, this is an excellent opportunity to take the next step in your career. Key Accountabilities As an Embedded Vulnerability Researcher, you'll work on long-term, deep-dive research projects for our esteemed clients, solving complex security challenges and delivering innovative solutions. Conducting research on mobile phone operating systems and embedded systems. Using reverse engineering skills to solve technical challenges. Developing proof-of-concept solutions. Creating high-quality technical reports. Sharing knowledge and mentoring team members. Skills Essential Skills: High-level National Security clearance. Proven experience in mobile research activities. Reverse Engineering (x86/ARM/PowerPC/MIPS). Proficiency with Debugging tools (GDB/x64dbg/r2/windbg/frida) and Disassemblers (IDA/Ghidra). Experience with mobile research and fuzzing. C Programming and scripting (Python/Perl). Networking protocol knowledge. Applied cryptography and mathematics. Source code review and applied security research. Technology: Mobile devices (Android and iOS). Embedded systems. Linux and Windows. What do we offer in return? We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
14/07/2026
Full time
Embedded Researcher Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Cheltenham Jessop House Description Thanks for checking out our job opening; we are excited that YOU are interested in learning more about NCC Group. The opportunity Our National Security Business Unit is growing, and we're seeking Embedded Vulnerability Researchers to join our team. Whether you're an experienced researcher or ready to build on your skills, we offer a variety of exciting opportunities. You'll work alongside a team of experts on projects ranging from short-term tactical challenges to long-term research engagements. The role is based out of our Cheltenham office with the possibility of a hybrid working approach. With dedicated lab facilities, regular team and research events, and a focus on training and development, this is an excellent opportunity to take the next step in your career. Key Accountabilities As an Embedded Vulnerability Researcher, you'll work on long-term, deep-dive research projects for our esteemed clients, solving complex security challenges and delivering innovative solutions. Conducting research on mobile phone operating systems and embedded systems. Using reverse engineering skills to solve technical challenges. Developing proof-of-concept solutions. Creating high-quality technical reports. Sharing knowledge and mentoring team members. Skills Essential Skills: High-level National Security clearance. Proven experience in mobile research activities. Reverse Engineering (x86/ARM/PowerPC/MIPS). Proficiency with Debugging tools (GDB/x64dbg/r2/windbg/frida) and Disassemblers (IDA/Ghidra). Experience with mobile research and fuzzing. C Programming and scripting (Python/Perl). Networking protocol knowledge. Applied cryptography and mathematics. Source code review and applied security research. Technology: Mobile devices (Android and iOS). Embedded systems. Linux and Windows. What do we offer in return? We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
NCC Group plc in Manchester is seeking a Senior Security Engineer to join the IT security team. You will implement and maintain security tools and configurations to safeguard Group information systems, while supporting cyber risk management and business requirements. The role involves collaborating with IT Operations, Architecture and SOC/DF teams, delivering security solutions, and participating in incident investigations.
14/07/2026
Full time
NCC Group plc in Manchester is seeking a Senior Security Engineer to join the IT security team. You will implement and maintain security tools and configurations to safeguard Group information systems, while supporting cyber risk management and business requirements. The role involves collaborating with IT Operations, Architecture and SOC/DF teams, delivering security solutions, and participating in incident investigations.
Senior Security Engineer Department: IT Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Danny Cooke Description The Cyber and Information Security Team play a critical role in supporting our internal business functions alongside our external customer commitments. NCC Group's internal security team work to develop, introduce and maintain administrative, technical and physical security controls to continually improve the Group's security. The Senior Security Engineer is primarily responsible for implementing, monitoring and maintaining security tools, technologies and configurations to ensure the confidentiality, integrity and availability of Group information systems and assets. This role presents an excellent opportunity to support this area and will help the Security Engineering Team in managing cyber risks and meeting its business requirements. Key Responsibilities Assisting the Group in constantly striving to improve its cyber security posture, seeking out and exploiting opportunities for improvement. Assisting with and providing technical subject matter expertise into the design of security solutions, working in conjunction with IT Operations and Architecture colleagues. Implementing, supporting and maintaining security solutions (e.g. Defender for Endpoint, privileged access management systems, access policies, application management, etc.) Sharing security engineering expertise across the Group globally, championing implementation of best practice. Taking part in the investigation of security alerts and incidents, in conjunction with the Security Operations Centre and Digital Forensics colleagues. Driving the investigation, development and adoption of cyber and information security technology, process, policy and best practice. Working on BAU and Project tasks assigned to the Security Engineering Team. Working closely with the Security Program Team and Technical IT Teams where required. There is a requirement for on call work as a part of this role. Skills, Knowledge & Expertise You will have the following experience - Prior experience in an IT security role, or a comparable function, is essential. Ability to quickly understand the technical detail of new or unfamiliar technologies is essential. Knowledge and experience of hybrid cloud environments with a particular emphasis on EntraID/M365 Excellent communication skills and the ability to explain security concepts to management and other stakeholders both technical and non technical, who may not have a security background. Excellent analytical and problem solving skills. Ability to take direction but also take ownership on both Project and BAU work. Ability to work proactively in identifying security issues then working to define and deliver appropriate mitigations. Any Security related certifications may be advantageous - Security+, Microsoft SC900, AZ900 Willing to travel to NCC office locations globally and stay away from home on occasion. Knowledge and experience of these technologies is a key requirement: Microsoft EntraID/Azure Microsoft Defender 365 (including Microsoft Defender XDR) Microsoft Sentinel Microsoft Active Directory Microsoft Intune VMWare Experience in as many of these technologies/areas as possible is highly desirable: Security Frameworks (NIST, CIS etc.) PAM Tools and Technologies AWS Security Incident Response Endpoint Security (including mobile devices, Windows and Linux) Job Benefits We have a high-performance culture which is balanced evenly with world-class well being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle to work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
14/07/2026
Full time
Senior Security Engineer Department: IT Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Danny Cooke Description The Cyber and Information Security Team play a critical role in supporting our internal business functions alongside our external customer commitments. NCC Group's internal security team work to develop, introduce and maintain administrative, technical and physical security controls to continually improve the Group's security. The Senior Security Engineer is primarily responsible for implementing, monitoring and maintaining security tools, technologies and configurations to ensure the confidentiality, integrity and availability of Group information systems and assets. This role presents an excellent opportunity to support this area and will help the Security Engineering Team in managing cyber risks and meeting its business requirements. Key Responsibilities Assisting the Group in constantly striving to improve its cyber security posture, seeking out and exploiting opportunities for improvement. Assisting with and providing technical subject matter expertise into the design of security solutions, working in conjunction with IT Operations and Architecture colleagues. Implementing, supporting and maintaining security solutions (e.g. Defender for Endpoint, privileged access management systems, access policies, application management, etc.) Sharing security engineering expertise across the Group globally, championing implementation of best practice. Taking part in the investigation of security alerts and incidents, in conjunction with the Security Operations Centre and Digital Forensics colleagues. Driving the investigation, development and adoption of cyber and information security technology, process, policy and best practice. Working on BAU and Project tasks assigned to the Security Engineering Team. Working closely with the Security Program Team and Technical IT Teams where required. There is a requirement for on call work as a part of this role. Skills, Knowledge & Expertise You will have the following experience - Prior experience in an IT security role, or a comparable function, is essential. Ability to quickly understand the technical detail of new or unfamiliar technologies is essential. Knowledge and experience of hybrid cloud environments with a particular emphasis on EntraID/M365 Excellent communication skills and the ability to explain security concepts to management and other stakeholders both technical and non technical, who may not have a security background. Excellent analytical and problem solving skills. Ability to take direction but also take ownership on both Project and BAU work. Ability to work proactively in identifying security issues then working to define and deliver appropriate mitigations. Any Security related certifications may be advantageous - Security+, Microsoft SC900, AZ900 Willing to travel to NCC office locations globally and stay away from home on occasion. Knowledge and experience of these technologies is a key requirement: Microsoft EntraID/Azure Microsoft Defender 365 (including Microsoft Defender XDR) Microsoft Sentinel Microsoft Active Directory Microsoft Intune VMWare Experience in as many of these technologies/areas as possible is highly desirable: Security Frameworks (NIST, CIS etc.) PAM Tools and Technologies AWS Security Incident Response Endpoint Security (including mobile devices, Windows and Linux) Job Benefits We have a high-performance culture which is balanced evenly with world-class well being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle to work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
Principal Solution Architect Application Deadline: 31 July 2026 Department: Sales Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Andy Jarvis Description The Principal Solution Architect is a senior technical role within NCC Group's Sales Engineering & Field Strategy team, responsible for shaping and delivering complex, high-value cyber security solutions across both professional and managed services. This role serves as a technical authority and strategic partner to clients, translating business challenges into secure, scalable, and commercially viable solutions. In addition to leading solution design and client engagements, the Principal Solution Architect plays a key role in mentoring and developing the wider team of Solution Architects. They provide technical guidance, coaching, and quality assurance to ensure consistency, innovation, and excellence in solution delivery. Acting as a role model and escalation point, they foster a culture of continuous improvement, collaboration, and technical curiosity across the team. This role requires a blend of deep technical expertise, commercial awareness, and strong interpersonal skills to influence stakeholders, support sales activities, and drive the evolution of NCC Group's service offerings in response to emerging threats and market demands. Key Responsibilities Lead the creation of technical solution designs and bid responses for large-scale client opportunities, integrating services across NCC Group's offerings. Provide expert technical solution consultancy, including scope definition, approach, dependencies, assumptions, and cost modelling aligned with governance processes. Act as a senior technical advisor in client engagements, translating business needs into actionable cybersecurity solutions. Collaborate with Sales, Delivery, and Product Management teams to ensure alignment of proposed solutions with client requirements and internal capabilities. Own the quality assurance of client-facing documentation, ensuring clarity, accuracy, and technical integrity. Mentor and support Solution Architects, acting as a technical escalation point. Identify market trends and gaps to inform service development and maintain competitive advantage. Contribute to account planning and opportunity development, supporting strategic growth initiatives. Deliver internal training and briefings on NCC Group services, research, and intellectual property. Represent NCC Group at client meetings, conferences, and industry events, occasionally requiring national travel. Skills, Knowledge & Expertise Proven experience in designing and delivering complex cyber security solutions in a pre-sales or consulting capacity. Strong understanding of network architecture, IT infrastructure, cloud platforms (Azure, AWS), and emerging technologies. Deep knowledge of cybersecurity threats, threat actors, and mitigation strategies. Familiarity with penetration testing methodologies and outcomes. Demonstrable experience with at least two of the following frameworks: NIST, ISO 27001, PCI DSS, CIS Controls. Strong commercial acumen with the ability to balance client needs and profitability. Excellent communication skills, including the ability to present technical content to non-technical audiences and senior stakeholders. Proficiency in Microsoft Office and technical documentation tools. Relevant certifications such as CISM, CISSP, CCSP, or equivalent demonstrable expertise. Desired Requirements Experience in integrating cybersecurity solutions into enterprise environments. Understanding of compliance and regulatory requirements across different sectors. Exposure to managed security services and operational security models. Experience working with international clients and multi-region solution deployments. Knowledge of in-region cyber security regulations, compliance and privacy frameworks. Job Benefits We have a high-performance culture which is balanced evenly with world-class well being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
14/07/2026
Full time
Principal Solution Architect Application Deadline: 31 July 2026 Department: Sales Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Andy Jarvis Description The Principal Solution Architect is a senior technical role within NCC Group's Sales Engineering & Field Strategy team, responsible for shaping and delivering complex, high-value cyber security solutions across both professional and managed services. This role serves as a technical authority and strategic partner to clients, translating business challenges into secure, scalable, and commercially viable solutions. In addition to leading solution design and client engagements, the Principal Solution Architect plays a key role in mentoring and developing the wider team of Solution Architects. They provide technical guidance, coaching, and quality assurance to ensure consistency, innovation, and excellence in solution delivery. Acting as a role model and escalation point, they foster a culture of continuous improvement, collaboration, and technical curiosity across the team. This role requires a blend of deep technical expertise, commercial awareness, and strong interpersonal skills to influence stakeholders, support sales activities, and drive the evolution of NCC Group's service offerings in response to emerging threats and market demands. Key Responsibilities Lead the creation of technical solution designs and bid responses for large-scale client opportunities, integrating services across NCC Group's offerings. Provide expert technical solution consultancy, including scope definition, approach, dependencies, assumptions, and cost modelling aligned with governance processes. Act as a senior technical advisor in client engagements, translating business needs into actionable cybersecurity solutions. Collaborate with Sales, Delivery, and Product Management teams to ensure alignment of proposed solutions with client requirements and internal capabilities. Own the quality assurance of client-facing documentation, ensuring clarity, accuracy, and technical integrity. Mentor and support Solution Architects, acting as a technical escalation point. Identify market trends and gaps to inform service development and maintain competitive advantage. Contribute to account planning and opportunity development, supporting strategic growth initiatives. Deliver internal training and briefings on NCC Group services, research, and intellectual property. Represent NCC Group at client meetings, conferences, and industry events, occasionally requiring national travel. Skills, Knowledge & Expertise Proven experience in designing and delivering complex cyber security solutions in a pre-sales or consulting capacity. Strong understanding of network architecture, IT infrastructure, cloud platforms (Azure, AWS), and emerging technologies. Deep knowledge of cybersecurity threats, threat actors, and mitigation strategies. Familiarity with penetration testing methodologies and outcomes. Demonstrable experience with at least two of the following frameworks: NIST, ISO 27001, PCI DSS, CIS Controls. Strong commercial acumen with the ability to balance client needs and profitability. Excellent communication skills, including the ability to present technical content to non-technical audiences and senior stakeholders. Proficiency in Microsoft Office and technical documentation tools. Relevant certifications such as CISM, CISSP, CCSP, or equivalent demonstrable expertise. Desired Requirements Experience in integrating cybersecurity solutions into enterprise environments. Understanding of compliance and regulatory requirements across different sectors. Exposure to managed security services and operational security models. Experience working with international clients and multi-region solution deployments. Knowledge of in-region cyber security regulations, compliance and privacy frameworks. Job Benefits We have a high-performance culture which is balanced evenly with world-class well being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
NCC Group plc, a leading cyber security and assurance company, seeks a Principal Solution Architect to shape and deliver high-value cyber security solutions for clients. You will lead solution design, engage in pre-sales activities, mentor junior architects, and collaborate across Sales, Delivery and Product teams. National travel may be required. This senior role combines deep technical expertise with commercial awareness to influence outcomes and drive NCC Group's service evolution in response
14/07/2026
Full time
NCC Group plc, a leading cyber security and assurance company, seeks a Principal Solution Architect to shape and deliver high-value cyber security solutions for clients. You will lead solution design, engage in pre-sales activities, mentor junior architects, and collaborate across Sales, Delivery and Product teams. National travel may be required. This senior role combines deep technical expertise with commercial awareness to influence outcomes and drive NCC Group's service evolution in response
Senior Python Developer Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Description An exciting opportunity to be one of the core team members of the Software Engineering team within NCC Group's GMS division. You will be a development SME playing a key role in designing, delivering, and supporting high quality software solutions. This is a great opportunity to work on mission critical Cyber Security-related products and services, for one of the world's leading practices. The role requires strong hands on expertise in Python along with a broad and deep understanding of modern coding practices, multiple programming languages, and software delivery standards spanning across a number of new and existing project streams; working alongside a wider global team to efficiently develop cloud solutions following CICD best practices. We are looking for a highly skilled and experienced Senior Python Developer to join our dynamic team. The ideal candidate will be responsible for designing, developing, and maintaining scalable and efficient software systems using Python, cloud and serverless technologies. This role requires a deep understanding of Python and related technologies, as well as strong leadership and mentoring abilities. You will be a senior member of the development team with the ability to contribute as well as guide other members of the team towards the development of high quality software with the help of the Product Engineering / Architecture Lead. Work closely with other Developers, UX, QA, DevOps and Cloud Architecture Development of high quality code following development practices set by the Product Engineering / Architecture Lead Mentoring of more junior members of the team Perform regular code reviews Implement a test first approach and contribute to upholding code quality metrics Key Responsibilities Design and Development: Create and implement Python-based applications and systems, ensuring functionality and performance. Leadership & Mentorship: Guide and mentor junior developers, providing technical expertise and ensuring adherence to best practices. Collaboration: Work collaboratively with cross-functional teams to define project requirements and specifications, ensuring software meets business objectives. Code Quality Assurance: Conduct code reviews to ensure quality, suggest improvements, and maintain best practices. Troubleshooting and Debugging:Identify and resolve code bugs, ensuring smooth operation of software. Staying Informed: Keep up to date with the latest trends and standards in Python development. Performance Optimisation:Optimize and test software to ensure functionality and smooth operation. Documentation: Prepare and maintain technical documentation to ensure transparency and accessibility for the team. Skills, Knowledge & Expertise Behaviours: Focusing on Clients and Customers. Working as One NCC. Always Learning. Being Inclusive and Respectful. Delivery Brilliantly. Qualifications: Bachelor's or Master's degree in Computer Science, Engineering, or a related field. Proven experience as a Python Developer. Familiarity with creating code in serverless environments Familiarity with Azure Architecture and REST APIs. Understanding of databases and SQL. Secure Software Development. Attention to detail and strong problem solving abilities. Excellent communication and leadership skills. Desired Skills: Full stack python development Expert Experience with cloud architectures and infrastructure. Agile Development Experience working with CI/CD practices Test first approach Microservice infrastructure Knowledge of software development best practices and standards. Strong analytical and problem solving abilities. Job Benefits Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Schem e: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
13/07/2026
Full time
Senior Python Developer Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Description An exciting opportunity to be one of the core team members of the Software Engineering team within NCC Group's GMS division. You will be a development SME playing a key role in designing, delivering, and supporting high quality software solutions. This is a great opportunity to work on mission critical Cyber Security-related products and services, for one of the world's leading practices. The role requires strong hands on expertise in Python along with a broad and deep understanding of modern coding practices, multiple programming languages, and software delivery standards spanning across a number of new and existing project streams; working alongside a wider global team to efficiently develop cloud solutions following CICD best practices. We are looking for a highly skilled and experienced Senior Python Developer to join our dynamic team. The ideal candidate will be responsible for designing, developing, and maintaining scalable and efficient software systems using Python, cloud and serverless technologies. This role requires a deep understanding of Python and related technologies, as well as strong leadership and mentoring abilities. You will be a senior member of the development team with the ability to contribute as well as guide other members of the team towards the development of high quality software with the help of the Product Engineering / Architecture Lead. Work closely with other Developers, UX, QA, DevOps and Cloud Architecture Development of high quality code following development practices set by the Product Engineering / Architecture Lead Mentoring of more junior members of the team Perform regular code reviews Implement a test first approach and contribute to upholding code quality metrics Key Responsibilities Design and Development: Create and implement Python-based applications and systems, ensuring functionality and performance. Leadership & Mentorship: Guide and mentor junior developers, providing technical expertise and ensuring adherence to best practices. Collaboration: Work collaboratively with cross-functional teams to define project requirements and specifications, ensuring software meets business objectives. Code Quality Assurance: Conduct code reviews to ensure quality, suggest improvements, and maintain best practices. Troubleshooting and Debugging:Identify and resolve code bugs, ensuring smooth operation of software. Staying Informed: Keep up to date with the latest trends and standards in Python development. Performance Optimisation:Optimize and test software to ensure functionality and smooth operation. Documentation: Prepare and maintain technical documentation to ensure transparency and accessibility for the team. Skills, Knowledge & Expertise Behaviours: Focusing on Clients and Customers. Working as One NCC. Always Learning. Being Inclusive and Respectful. Delivery Brilliantly. Qualifications: Bachelor's or Master's degree in Computer Science, Engineering, or a related field. Proven experience as a Python Developer. Familiarity with creating code in serverless environments Familiarity with Azure Architecture and REST APIs. Understanding of databases and SQL. Secure Software Development. Attention to detail and strong problem solving abilities. Excellent communication and leadership skills. Desired Skills: Full stack python development Expert Experience with cloud architectures and infrastructure. Agile Development Experience working with CI/CD practices Test first approach Microservice infrastructure Knowledge of software development best practices and standards. Strong analytical and problem solving abilities. Job Benefits Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Schem e: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
Associate Director, Platform Security Architecture Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Ronnie Miller Description This leadership role is responsible for shaping and driving the Platform and Security Architecture strategy across all platforms that have commercial or revenue impact, including those that are client-facing or used in the delivery of billable services. The Associate Director will lead the adoption of architectural standards across professional and managed services platforms, driving improvements in platform resilience, security, scalability, innovation, customer confidence, presales success, and operational efficiency. Acting as a recognised subject matter expert in cyber platform engineering, cloud security, and advanced detection technologies, the role will provide strategic technology leadership, influence platform evolution, and guide key business decisions across engineering, operations, product, and commercial functions. A key part of the role is collaborating with senior stakeholders to: Define and govern architectural standards across professional and managed services platforms. Drive platform innovation and the adoption of emerging technologies, including AI and machine learning. Improve platform resilience, scalability, and security. Shape long term technology strategy aligned to business objectives. Increase operational efficiency and customer value through platform transformation. Support strategic client engagements and presales opportunities with senior level technical assurance. Key Responsibilities Define and govern architectural standards for professional and managed service platforms, ensuring a unified, scalable, and secure technology foundation. Maintain strong partnerships with internal technology and security teams to ensure architecture decisions align with enterprise standards and governance requirements. Lead high complexity customer workshops spanning consulting, implementation, technical assurance, and managed services. Support strategic sales opportunities by providing authoritative architectural guidance and technical assurance. Shape platform strategy across managed services environments, cyber tooling ecosystems, and operational platforms. Partner with senior leadership to define and deliver long term technology strategy and innovation roadmaps. Evaluate and integrate emerging technologies, including AI/ML enhanced detection, workflow automation, and next generation platform engineering capabilities. Design secure multi tenant architectures, cloud native solutions, integration frameworks, and advanced telemetry platforms. Develop reference architectures, engineering frameworks, and design patterns used across engineering and cyber defence teams. Provide technical leadership and guidance on platform design, infrastructure as code, security controls, and platform hardening best practices. Drive the maturity of AI powered workflows, including detection generation, anomaly analysis, automated response, and operational optimisation initiatives. Provide senior level architectural advisory support across engineering, operations, product, commercial, and executive functions. Skills, Knowledge & Expertise Significant experience defining and leading global engineering and platform strategies within professional services and managed services environments. Strong experience with enterprise technologies and platforms such as Microsoft, Splunk, ServiceNow, Cyber security tooling, and large scale operational or automation platforms. Experience designing and governing secure, scalable cloud and platform architectures. Strong planning, organisational, and prioritisation skills. Excellent stakeholder management and relationship building capabilities. Strong communication skills with the ability to explain complex technical concepts to both technical and non technical audiences. Strong analytical, problem solving, and decision making skills. Ability to work independently while collaborating effectively across multiple teams. High attention to detail and commitment to quality. Adaptability and resilience in a fast paced, evolving environment. Experience with AI, machine learning, and automation technologies within cyber security and platform engineering environments. Experience supporting customer facing architecture engagements and strategic presales activities. Expertise in cyber platform engineering, cloud security, and advanced detection technologies. Job Benefits We have a high performance culture which is balanced evenly with world class wellbeing initiatives and benefits: Flexible Working - Balance your work and personal life with our flexible working options. Enhanced Holiday Allowance - Enjoy 25 days of holiday plus bank holidays, with the option to buy up to 5 additional days. Medicash & Critical Illness Scheme Financial & Investment Benefits - Pension, Life Assurance and Share Save Scheme. Community & Volunteering Programmes - Opportunities to make a difference through volunteering. Green Car Scheme - Drive greener while saving money. Cycle Scheme - Support for cycling to work and staying active. Special Time Off - Additional leave for key life moments, including marriage/civil partnership, becoming a grandparent, and welcoming a new pet. Family Planning Support - Generous maternity and paternity leave, plus support for fertility treatment.
10/07/2026
Full time
Associate Director, Platform Security Architecture Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Ronnie Miller Description This leadership role is responsible for shaping and driving the Platform and Security Architecture strategy across all platforms that have commercial or revenue impact, including those that are client-facing or used in the delivery of billable services. The Associate Director will lead the adoption of architectural standards across professional and managed services platforms, driving improvements in platform resilience, security, scalability, innovation, customer confidence, presales success, and operational efficiency. Acting as a recognised subject matter expert in cyber platform engineering, cloud security, and advanced detection technologies, the role will provide strategic technology leadership, influence platform evolution, and guide key business decisions across engineering, operations, product, and commercial functions. A key part of the role is collaborating with senior stakeholders to: Define and govern architectural standards across professional and managed services platforms. Drive platform innovation and the adoption of emerging technologies, including AI and machine learning. Improve platform resilience, scalability, and security. Shape long term technology strategy aligned to business objectives. Increase operational efficiency and customer value through platform transformation. Support strategic client engagements and presales opportunities with senior level technical assurance. Key Responsibilities Define and govern architectural standards for professional and managed service platforms, ensuring a unified, scalable, and secure technology foundation. Maintain strong partnerships with internal technology and security teams to ensure architecture decisions align with enterprise standards and governance requirements. Lead high complexity customer workshops spanning consulting, implementation, technical assurance, and managed services. Support strategic sales opportunities by providing authoritative architectural guidance and technical assurance. Shape platform strategy across managed services environments, cyber tooling ecosystems, and operational platforms. Partner with senior leadership to define and deliver long term technology strategy and innovation roadmaps. Evaluate and integrate emerging technologies, including AI/ML enhanced detection, workflow automation, and next generation platform engineering capabilities. Design secure multi tenant architectures, cloud native solutions, integration frameworks, and advanced telemetry platforms. Develop reference architectures, engineering frameworks, and design patterns used across engineering and cyber defence teams. Provide technical leadership and guidance on platform design, infrastructure as code, security controls, and platform hardening best practices. Drive the maturity of AI powered workflows, including detection generation, anomaly analysis, automated response, and operational optimisation initiatives. Provide senior level architectural advisory support across engineering, operations, product, commercial, and executive functions. Skills, Knowledge & Expertise Significant experience defining and leading global engineering and platform strategies within professional services and managed services environments. Strong experience with enterprise technologies and platforms such as Microsoft, Splunk, ServiceNow, Cyber security tooling, and large scale operational or automation platforms. Experience designing and governing secure, scalable cloud and platform architectures. Strong planning, organisational, and prioritisation skills. Excellent stakeholder management and relationship building capabilities. Strong communication skills with the ability to explain complex technical concepts to both technical and non technical audiences. Strong analytical, problem solving, and decision making skills. Ability to work independently while collaborating effectively across multiple teams. High attention to detail and commitment to quality. Adaptability and resilience in a fast paced, evolving environment. Experience with AI, machine learning, and automation technologies within cyber security and platform engineering environments. Experience supporting customer facing architecture engagements and strategic presales activities. Expertise in cyber platform engineering, cloud security, and advanced detection technologies. Job Benefits We have a high performance culture which is balanced evenly with world class wellbeing initiatives and benefits: Flexible Working - Balance your work and personal life with our flexible working options. Enhanced Holiday Allowance - Enjoy 25 days of holiday plus bank holidays, with the option to buy up to 5 additional days. Medicash & Critical Illness Scheme Financial & Investment Benefits - Pension, Life Assurance and Share Save Scheme. Community & Volunteering Programmes - Opportunities to make a difference through volunteering. Green Car Scheme - Drive greener while saving money. Cycle Scheme - Support for cycling to work and staying active. Special Time Off - Additional leave for key life moments, including marriage/civil partnership, becoming a grandparent, and welcoming a new pet. Family Planning Support - Generous maternity and paternity leave, plus support for fertility treatment.
NCC Group plc is searching for a Rail Cyber Security Lead to enhance their cyber security capabilities in the rail sector. This position requires technical leadership to ensure compliance with international standards and successful project delivery. The candidate should possess a profound understanding of operational technology, rail systems, and penetration testing methodologies. Strong communication skills and the ability to lead client interactions are essential for this client-facing role.
09/07/2026
Full time
NCC Group plc is searching for a Rail Cyber Security Lead to enhance their cyber security capabilities in the rail sector. This position requires technical leadership to ensure compliance with international standards and successful project delivery. The candidate should possess a profound understanding of operational technology, rail systems, and penetration testing methodologies. Strong communication skills and the ability to lead client interactions are essential for this client-facing role.
Team Lead, SOC Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Description Today, it is an unavoidable fact that your business-critical infrastructure and systems are at risk of attack. The key to good security is a clear understanding of what is most critical to the business. Where you do not have enough internal resources, time or skills to monitor and manage your IT environment 24/7, NCC Group can help, freeing up your skilled employees to focus on value add activity. NCC Group provide a range of managed and hosted services delivered from our UK based Security Operations Centre SOC which operates 24/7, 365 days a year. Our team of over 30 accredited security experts are available 24/7, dealing daily with over 200 million log events and providing support for over 5,000 network devices. NCC Group's Cloud XDR Team provide a world class Extended Detection and Response (XDR) services, detecting, responding and mitigating cyber attacks on our customers networks in our Security Operations Centres using the Microsoft Sentinel ecosystem. The Cloud XDR Team are looking for a Team Lead with a passion for security to join the team to help the customers get the most out of our services and to protect their networks. This is an opportunity to join a technically advanced and talented team and help NCC Group build and deliver world class services to our customers. This role is ideal for a seasoned SOC Analyst with experience in cyber security looking to broaden their scope of cyber skills with a strong focus on detection and response to cyber incidents. Key Responsibilities Monitor global systems looking for potential threats, vulnerabilities and indicators of compromise. Perform in-depth analysis of security alerts utilizing Microsoft XDR suite (Sentinel/Defender etc) Act as incident handlers during high priority incidents Provide Incident remediation and prevention documentation and recommendations to customers based on defined procedures and analyst experience. Document and conform to processes related to security monitoring procedures. Provide customer service that always exceeds our customers' expectations. Initiate escalation procedure to counteract potential threats, vulnerabilities and threat actors. Compilation and review of service focused reporting. Act as an escalation point for more junior members of the team, providing assistance and mentoring where necessary. Providing assistance to XDR SOC Analysts on general Triage and Threat Hunting engagements. Contributing to the continuous improvement of SOC procedures and documentation. Actively liaise with clients in order to understand specific risk areas and act as a touch point for issues raised Perform other duties as assigned. Skills, Knowledge & Expertise Experience / Skills Experience working in relevant SOC analyst roles Practical knowledge and experience of security and networking toolsets such including Microsoft's XDR suite (Sentinel/Defender) Pre-existing, in-depth knowledge of common network protocols and endpoint detection/forensics Pre-existing, in-depth knowledge of Windows and Linux based operating systems. Experience in the extensive analysis of common security incidents. Ability to stay calm in highly sensitive and high-pressure incidents. Certifications The following certifications are desirable, but not a requirement. Successful candidates that do not possess these certifications may be tasked with working towards them at the beginning of their employment: Azure based certifications (SC-200, AZ-500, MS-500) GIAC GCIA/GCIH CREST CPSA / CRIA / CMRE / CNIA / CHIA CompTIA Security+ CompTIA Network+ Other relevant certifications. Job Benefits Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
08/07/2026
Full time
Team Lead, SOC Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Description Today, it is an unavoidable fact that your business-critical infrastructure and systems are at risk of attack. The key to good security is a clear understanding of what is most critical to the business. Where you do not have enough internal resources, time or skills to monitor and manage your IT environment 24/7, NCC Group can help, freeing up your skilled employees to focus on value add activity. NCC Group provide a range of managed and hosted services delivered from our UK based Security Operations Centre SOC which operates 24/7, 365 days a year. Our team of over 30 accredited security experts are available 24/7, dealing daily with over 200 million log events and providing support for over 5,000 network devices. NCC Group's Cloud XDR Team provide a world class Extended Detection and Response (XDR) services, detecting, responding and mitigating cyber attacks on our customers networks in our Security Operations Centres using the Microsoft Sentinel ecosystem. The Cloud XDR Team are looking for a Team Lead with a passion for security to join the team to help the customers get the most out of our services and to protect their networks. This is an opportunity to join a technically advanced and talented team and help NCC Group build and deliver world class services to our customers. This role is ideal for a seasoned SOC Analyst with experience in cyber security looking to broaden their scope of cyber skills with a strong focus on detection and response to cyber incidents. Key Responsibilities Monitor global systems looking for potential threats, vulnerabilities and indicators of compromise. Perform in-depth analysis of security alerts utilizing Microsoft XDR suite (Sentinel/Defender etc) Act as incident handlers during high priority incidents Provide Incident remediation and prevention documentation and recommendations to customers based on defined procedures and analyst experience. Document and conform to processes related to security monitoring procedures. Provide customer service that always exceeds our customers' expectations. Initiate escalation procedure to counteract potential threats, vulnerabilities and threat actors. Compilation and review of service focused reporting. Act as an escalation point for more junior members of the team, providing assistance and mentoring where necessary. Providing assistance to XDR SOC Analysts on general Triage and Threat Hunting engagements. Contributing to the continuous improvement of SOC procedures and documentation. Actively liaise with clients in order to understand specific risk areas and act as a touch point for issues raised Perform other duties as assigned. Skills, Knowledge & Expertise Experience / Skills Experience working in relevant SOC analyst roles Practical knowledge and experience of security and networking toolsets such including Microsoft's XDR suite (Sentinel/Defender) Pre-existing, in-depth knowledge of common network protocols and endpoint detection/forensics Pre-existing, in-depth knowledge of Windows and Linux based operating systems. Experience in the extensive analysis of common security incidents. Ability to stay calm in highly sensitive and high-pressure incidents. Certifications The following certifications are desirable, but not a requirement. Successful candidates that do not possess these certifications may be tasked with working towards them at the beginning of their employment: Azure based certifications (SC-200, AZ-500, MS-500) GIAC GCIA/GCIH CREST CPSA / CRIA / CMRE / CNIA / CHIA CompTIA Security+ CompTIA Network+ Other relevant certifications. Job Benefits Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
NCC Group plc in Manchester is seeking a Team Lead for their Security Operations Centre, ideal for seasoned SOC Analysts wanting to broaden their cyber skills. The candidate will manage incidents, monitor threats, and mentor junior team members while contributing to clients' cyber security. In this role, you will join a team of accredited security experts focused on providing top-tier services, collaborating with clients, and enhancing your skills in a supportive environment.
08/07/2026
Full time
NCC Group plc in Manchester is seeking a Team Lead for their Security Operations Centre, ideal for seasoned SOC Analysts wanting to broaden their cyber skills. The candidate will manage incidents, monitor threats, and mentor junior team members while contributing to clients' cyber security. In this role, you will join a team of accredited security experts focused on providing top-tier services, collaborating with clients, and enhancing your skills in a supportive environment.
Rail Cyber Security Lead Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR London Reporting To: Gary Cannon Description We are seeking a highly skilled Cyber Security Rail Lead to join our Global Transport practice. This role is pivotal in strengthening and expanding our cyber security capability within the global rail ecosystem, while also supporting cross-domain engagements in maritime, automotive, and aviation as needed. The ideal candidate will bring deep knowledge of operational technology (OT), rail systems, relevant international cyber security standards (including IEC 62443, TS 50701, IEC 63452), penetration testing methodologies, and the broader transport ecosystem. In addition to technical leadership, the individual will play a key role in supporting business development, building client trust, and elevating NCC Group's profile within the rail sector. This is a client facing role requiring strong collaboration, communication and leadership skills. Key Responsibilities 1. Technical Leadership (Rail Cyber Security) Serve as the subject matter expert (SME) for rail cyber security across global engagements. Lead, design, and deliver complex cyber security assessments across both operational technology (OT) and information technology (IT) environments. Apply deep knowledge of rail specific standards and frameworks, including: IEC 62443 (Industrial Cyber Security) TS 50701 (Railway Cyber Security) IEC 63452 (Railway Rolling Stock Cyber Security) Conduct or oversee penetration testing activities, vulnerability assessments, architecture reviews, risk assessment and threat modelling for rail clients. Provide expert interpretation of cyber security requirements for railway operators, manufacturers, and integrators. Ensure security recommendations are aligned with safety, operational continuity, and regulatory requirements across the rail ecosystem. 2. Rail Domain Expertise Provide expert understanding of the rail ecosystem, including: Signalling systems Rolling stock Control centres Wayside and trackside equipment Rail operational processes and safety requirements Translate complex rail operations knowledge into training and mentorship for internal teams. Act as the internal thought leader on emerging rail threats, vulnerabilities, and industry trends. 3. Business Development & Practice Growth Support the creation and growth of new rail opportunities globally. Build NCC Group's market presence in the rail sector through: Thought leadership (whitepapers, webinars, industry events) Client engagements and pre sales support Partnerships with key rail OEMs, operators, and regulators Collaborate with engagement managers and leadership to define rail focused service offerings. Contribute to bids, proposals, and technical scoping activities for prospective customers. 4. Cross Domain Support (Multi Modal Transport) Potentially support projects across maritime, automotive, and aviation domains as required, with team backing. Maintain awareness of common OT and safety critical technologies across transport sectors. Promote knowledge sharing across the wider Transport Cyber Security practice. 5. Teamwork, Collaboration & Mentorship Provide mentoring, guidance, and technical leadership to consultants at various levels. Work closely with colleagues across global teams to deliver integrated and high quality engagements. Promote a collaborative, supportive, and inclusive team culture. 6. Client Engagement & Delivery Excellence Act as a trusted advisor to clients, providing clear, actionable cyber security recommendations. Communicate complex concepts in a clear, professional, and client friendly manner. Ensure high quality deliverables and maintain strong client satisfaction throughout engagements. Skills, Knowledge and Expertise Technical Experience Proven experience in rail cyber security, ideally within operators, OEMs, integrators, or a cyber consultancy. Strong experience working with and applying: IEC 62443 (critical infrastructure cyber security) TS 50701 (railway cyber security framework) IEC 63452 (rolling stock cyber security) Strong understanding of OT systems and technologies, including SCADA, industrial control systems (ICS), and safety critical environments. Practical experience in penetration testing or security assessment methodologies (not necessarily a full time tester, but capable). Experience with secure architecture review, threat modelling, and risk assessment in industrial or transport environments. Domain Knowledge In depth understanding of the rail operational ecosystem, including signalling, rolling stock, safety systems, and regulatory standards. Direct experience working within or for rail operators, system suppliers, or rail integrated cyber projects. Soft Skills & Professional Attributes Excellent communication skills in both technical and non technical contexts. Strong client facing experience and relationship management skills. Ability to lead engagements and influence stakeholders at all levels. Willingness to work collaboratively across geographies and disciplines. Ability to teach and mentor others on rail systems and cyber security. Desirable (Not Mandatory) Recognised cyber certifications (e.g., CISSP, GICSP, ISA/IEC 62443 CyberSecurity Expert). Experience contributing to industry standards or regulatory consultations. Background in safety engineering or systems engineering in transport. Benefits Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave differs for SOC shift workers, please speak to your TA partner for more information). Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle to work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
08/07/2026
Full time
Rail Cyber Security Lead Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR London Reporting To: Gary Cannon Description We are seeking a highly skilled Cyber Security Rail Lead to join our Global Transport practice. This role is pivotal in strengthening and expanding our cyber security capability within the global rail ecosystem, while also supporting cross-domain engagements in maritime, automotive, and aviation as needed. The ideal candidate will bring deep knowledge of operational technology (OT), rail systems, relevant international cyber security standards (including IEC 62443, TS 50701, IEC 63452), penetration testing methodologies, and the broader transport ecosystem. In addition to technical leadership, the individual will play a key role in supporting business development, building client trust, and elevating NCC Group's profile within the rail sector. This is a client facing role requiring strong collaboration, communication and leadership skills. Key Responsibilities 1. Technical Leadership (Rail Cyber Security) Serve as the subject matter expert (SME) for rail cyber security across global engagements. Lead, design, and deliver complex cyber security assessments across both operational technology (OT) and information technology (IT) environments. Apply deep knowledge of rail specific standards and frameworks, including: IEC 62443 (Industrial Cyber Security) TS 50701 (Railway Cyber Security) IEC 63452 (Railway Rolling Stock Cyber Security) Conduct or oversee penetration testing activities, vulnerability assessments, architecture reviews, risk assessment and threat modelling for rail clients. Provide expert interpretation of cyber security requirements for railway operators, manufacturers, and integrators. Ensure security recommendations are aligned with safety, operational continuity, and regulatory requirements across the rail ecosystem. 2. Rail Domain Expertise Provide expert understanding of the rail ecosystem, including: Signalling systems Rolling stock Control centres Wayside and trackside equipment Rail operational processes and safety requirements Translate complex rail operations knowledge into training and mentorship for internal teams. Act as the internal thought leader on emerging rail threats, vulnerabilities, and industry trends. 3. Business Development & Practice Growth Support the creation and growth of new rail opportunities globally. Build NCC Group's market presence in the rail sector through: Thought leadership (whitepapers, webinars, industry events) Client engagements and pre sales support Partnerships with key rail OEMs, operators, and regulators Collaborate with engagement managers and leadership to define rail focused service offerings. Contribute to bids, proposals, and technical scoping activities for prospective customers. 4. Cross Domain Support (Multi Modal Transport) Potentially support projects across maritime, automotive, and aviation domains as required, with team backing. Maintain awareness of common OT and safety critical technologies across transport sectors. Promote knowledge sharing across the wider Transport Cyber Security practice. 5. Teamwork, Collaboration & Mentorship Provide mentoring, guidance, and technical leadership to consultants at various levels. Work closely with colleagues across global teams to deliver integrated and high quality engagements. Promote a collaborative, supportive, and inclusive team culture. 6. Client Engagement & Delivery Excellence Act as a trusted advisor to clients, providing clear, actionable cyber security recommendations. Communicate complex concepts in a clear, professional, and client friendly manner. Ensure high quality deliverables and maintain strong client satisfaction throughout engagements. Skills, Knowledge and Expertise Technical Experience Proven experience in rail cyber security, ideally within operators, OEMs, integrators, or a cyber consultancy. Strong experience working with and applying: IEC 62443 (critical infrastructure cyber security) TS 50701 (railway cyber security framework) IEC 63452 (rolling stock cyber security) Strong understanding of OT systems and technologies, including SCADA, industrial control systems (ICS), and safety critical environments. Practical experience in penetration testing or security assessment methodologies (not necessarily a full time tester, but capable). Experience with secure architecture review, threat modelling, and risk assessment in industrial or transport environments. Domain Knowledge In depth understanding of the rail operational ecosystem, including signalling, rolling stock, safety systems, and regulatory standards. Direct experience working within or for rail operators, system suppliers, or rail integrated cyber projects. Soft Skills & Professional Attributes Excellent communication skills in both technical and non technical contexts. Strong client facing experience and relationship management skills. Ability to lead engagements and influence stakeholders at all levels. Willingness to work collaboratively across geographies and disciplines. Ability to teach and mentor others on rail systems and cyber security. Desirable (Not Mandatory) Recognised cyber certifications (e.g., CISSP, GICSP, ISA/IEC 62443 CyberSecurity Expert). Experience contributing to industry standards or regulatory consultations. Background in safety engineering or systems engineering in transport. Benefits Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave differs for SOC shift workers, please speak to your TA partner for more information). Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle to work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.