People Security Adviser Inside IR35 - 450 p/d Remote - once a month travel into London Active SC Mandatory We are looking for an experienced People Security Adviser to support the development and maturation of a newly established security function within a large, complex organisation. This role will play a key part in designing and embedding modern people security capabilities, integrating personnel security across physical security, cyber security, identity and access management, HR, fraud prevention and wider business operations. The successful candidate will help develop security policy, manage insider risk, deliver investigations and assurance activities, and drive continuous improvement across people security. Key Responsibilities Support the design, implementation and delivery of People and Physical Security capability improvement programmes. Develop, maintain and enhance people security policies, standards, procedures, controls and guidance. Provide subject matter expertise and advisory support on personnel security risks and security governance. Help embed people security across business functions including Physical Security, Cyber Security, Security Operations, Identity & Access Management, HR and Fraud teams. Support the development and delivery of an organisation-wide Insider Risk Programme. Plan, coordinate and deliver personnel security risk assessments. Conduct people security investigations, post-incident reviews and implement lessons learned. Develop and maintain people security incident response policies, plans and procedures. Support physical security activities where required, including site risk assessments and assurance reviews. Deliver people security engagement across suppliers and third-party organisations. Capture business requirements and support the commissioning and oversight of people security services. Develop, monitor and continuously improve People Security KPIs and reporting. Support and facilitate security governance meetings, working groups and stakeholder forums. Engage with relevant government security authorities, industry bodies and external partners to ensure alignment with best practice and national guidance. Essential Skills & Experience Active SC Clearance . Demonstrable experience delivering security improvements and change programmes. Strong stakeholder management with the ability to influence and negotiate security requirements. Excellent written communication skills, including policy and procedural documentation. Comfortable working independently and within multidisciplinary teams. Strong experience within People (Personnel) Security . Good understanding of UK Government personnel security and vetting frameworks. Extensive knowledge of personnel and physical security management principles. Experience developing, reviewing and maintaining security policies and processes. Experience conducting physical security surveys and risk assessments. Experience leading personnel and physical security investigations. Knowledge of government security standards and National Technical Authority guidance.
24/08/2026
Contractor
People Security Adviser Inside IR35 - 450 p/d Remote - once a month travel into London Active SC Mandatory We are looking for an experienced People Security Adviser to support the development and maturation of a newly established security function within a large, complex organisation. This role will play a key part in designing and embedding modern people security capabilities, integrating personnel security across physical security, cyber security, identity and access management, HR, fraud prevention and wider business operations. The successful candidate will help develop security policy, manage insider risk, deliver investigations and assurance activities, and drive continuous improvement across people security. Key Responsibilities Support the design, implementation and delivery of People and Physical Security capability improvement programmes. Develop, maintain and enhance people security policies, standards, procedures, controls and guidance. Provide subject matter expertise and advisory support on personnel security risks and security governance. Help embed people security across business functions including Physical Security, Cyber Security, Security Operations, Identity & Access Management, HR and Fraud teams. Support the development and delivery of an organisation-wide Insider Risk Programme. Plan, coordinate and deliver personnel security risk assessments. Conduct people security investigations, post-incident reviews and implement lessons learned. Develop and maintain people security incident response policies, plans and procedures. Support physical security activities where required, including site risk assessments and assurance reviews. Deliver people security engagement across suppliers and third-party organisations. Capture business requirements and support the commissioning and oversight of people security services. Develop, monitor and continuously improve People Security KPIs and reporting. Support and facilitate security governance meetings, working groups and stakeholder forums. Engage with relevant government security authorities, industry bodies and external partners to ensure alignment with best practice and national guidance. Essential Skills & Experience Active SC Clearance . Demonstrable experience delivering security improvements and change programmes. Strong stakeholder management with the ability to influence and negotiate security requirements. Excellent written communication skills, including policy and procedural documentation. Comfortable working independently and within multidisciplinary teams. Strong experience within People (Personnel) Security . Good understanding of UK Government personnel security and vetting frameworks. Extensive knowledge of personnel and physical security management principles. Experience developing, reviewing and maintaining security policies and processes. Experience conducting physical security surveys and risk assessments. Experience leading personnel and physical security investigations. Knowledge of government security standards and National Technical Authority guidance.
Great Ormond Street Hospital for Children NHS Foundation Trust
Great Ormond Street Hospital for Children NHS Foundation Trust Chief Digital & Information Officer Salary: Competitive Location: London Great Ormond Street Hospital (GOSH) is one of the world's leading children's hospitals, renowned for delivering specialist care to children and young people with rare, complex and life-limiting conditions. Caring for more than 300,000 patients each year and partnering with the UCL Great Ormond Street Institute of Child Health, GOSH combines exceptional clinical care, pioneering research and world-leading innovation to transform outcomes for children across the UK and internationally. From genomics and advanced therapies to digital innovation through our globally recognised DRIVE Unit, GOSH is helping shape the future of paediatric healthcare and setting new standards for what is possible. We are now seeking an outstanding Chief Digital & Information Officer (CDIO) to join our leadership team at a pivotal moment in the Trust's evolution. Reporting to the Chief Operating Officer, the CDIO will lead our Digital, Data, ICT and AI functions, ensuring technology, data and innovation are embedded as core enablers of clinical excellence, research, operational performance and service transformation. This is a unique opportunity to help realise our ambition to be at the forefront of digital healthcare and become a leading adopter of emerging technologies, including Agentic AI, whilst translating innovation into meaningful and measurable improvements for patients, families and staff. We are looking for a proven senior leader with significant experience of leading large-scale digital, data and technology transformation within complex organisations. You will bring a strong track record in developing high-performing teams, delivering change through influence and partnership, and creating cultures where people are empowered, supported and inspired to achieve their full potential. Deep expertise in digital strategy, information governance, cyber security and data-driven improvement will be essential, alongside a sophisticated understanding of AI governance, ethical deployment, assurance and risk management. Above all, you will be a values-led leader whose approach reflects GOSH's recently refreshed Values - recognising that collaboration, respect and curiosity are fundamental to sustained success. World class care requires world class leadership: this is an exceptional opportunity to join GOSH and lead our Digital, data and AI teams at one of the most exciting, stretching, periods in our evolution. If you have the vision, credibility and leadership capability to build on an already outstanding digital and innovation platform, challenge established thinking and help shape the future of child health on a national and global stage, we would be delighted to hear from you. For more information on the role and details of how to apply, please download the candidate information pack which can be found by clicking apply on website. For a confidential discussion please contact our recruitment partners at GatenbySanderson: Laura Cubillo-Aparicio (Researcher) T: (0) Serena Dobson (Senior Consultant) T: Melanie Shearer (Partner) T: Closing date for applications: 09:00 Friday 11th September Preliminary Interviews: w/c 21st September Final Panel Interviews: w/c 12th October
24/08/2026
Full time
Great Ormond Street Hospital for Children NHS Foundation Trust Chief Digital & Information Officer Salary: Competitive Location: London Great Ormond Street Hospital (GOSH) is one of the world's leading children's hospitals, renowned for delivering specialist care to children and young people with rare, complex and life-limiting conditions. Caring for more than 300,000 patients each year and partnering with the UCL Great Ormond Street Institute of Child Health, GOSH combines exceptional clinical care, pioneering research and world-leading innovation to transform outcomes for children across the UK and internationally. From genomics and advanced therapies to digital innovation through our globally recognised DRIVE Unit, GOSH is helping shape the future of paediatric healthcare and setting new standards for what is possible. We are now seeking an outstanding Chief Digital & Information Officer (CDIO) to join our leadership team at a pivotal moment in the Trust's evolution. Reporting to the Chief Operating Officer, the CDIO will lead our Digital, Data, ICT and AI functions, ensuring technology, data and innovation are embedded as core enablers of clinical excellence, research, operational performance and service transformation. This is a unique opportunity to help realise our ambition to be at the forefront of digital healthcare and become a leading adopter of emerging technologies, including Agentic AI, whilst translating innovation into meaningful and measurable improvements for patients, families and staff. We are looking for a proven senior leader with significant experience of leading large-scale digital, data and technology transformation within complex organisations. You will bring a strong track record in developing high-performing teams, delivering change through influence and partnership, and creating cultures where people are empowered, supported and inspired to achieve their full potential. Deep expertise in digital strategy, information governance, cyber security and data-driven improvement will be essential, alongside a sophisticated understanding of AI governance, ethical deployment, assurance and risk management. Above all, you will be a values-led leader whose approach reflects GOSH's recently refreshed Values - recognising that collaboration, respect and curiosity are fundamental to sustained success. World class care requires world class leadership: this is an exceptional opportunity to join GOSH and lead our Digital, data and AI teams at one of the most exciting, stretching, periods in our evolution. If you have the vision, credibility and leadership capability to build on an already outstanding digital and innovation platform, challenge established thinking and help shape the future of child health on a national and global stage, we would be delighted to hear from you. For more information on the role and details of how to apply, please download the candidate information pack which can be found by clicking apply on website. For a confidential discussion please contact our recruitment partners at GatenbySanderson: Laura Cubillo-Aparicio (Researcher) T: (0) Serena Dobson (Senior Consultant) T: Melanie Shearer (Partner) T: Closing date for applications: 09:00 Friday 11th September Preliminary Interviews: w/c 21st September Final Panel Interviews: w/c 12th October
Information Security & Assurance Officer Salary: up to 50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite) REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworks About You We're interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levels Desirable Experience Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent What's on Offer? 15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunities This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
21/08/2026
Full time
Information Security & Assurance Officer Salary: up to 50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite) REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworks About You We're interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levels Desirable Experience Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent What's on Offer? 15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunities This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
Information Security & Assurance Officer Salary: up to £50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite) REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworks About You We're interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levels Desirable Experience Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent What's on Offer? 15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunities This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
21/08/2026
Full time
Information Security & Assurance Officer Salary: up to £50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite) REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworks About You We're interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levels Desirable Experience Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent What's on Offer? 15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunities This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
Senior Security Architect (contractor)- Data Protection & Azure Cloud Security Rate: Flexible Duration: 1 year Hybrid working - 8 days onsite per month (Inside of IR35) We are looking for an experienced Senior Security Architect to join a major enterprise cybersecurity function, taking a leading role in the design and governance of security architecture across Data Protection and Cloud Security . This is a senior architecture position within a large, complex and highly regulated environment. You will work across business, technology, engineering, risk and security teams to ensure new applications, platforms and cloud solutions are designed securely from the outset. A major focus of the role will be enterprise data protection and Azure cloud security , including the architecture and governance of controls covering data classification, discovery, labelling, lifecycle management and protection of sensitive information. Key Responsibilities Lead the design and delivery of end-to-end security architecture across enterprise applications, platforms and cloud environments. Develop high-level security designs and translate business, technology and risk requirements into practical security architecture. Define and maintain security architecture principles, standards, patterns and reusable design guidance . Provide architecture governance and design assurance, challenging proposed solutions and ensuring security requirements are addressed throughout the delivery lifecycle. Act as a Subject Matter Expert for Data Protection and Cloud Security , providing technical guidance to architecture, engineering and business teams. Design and govern enterprise data protection and data security controls , including: Data discovery and inventory Data classification and sensitivity labelling Data Loss Prevention (DLP) Data governance Data retention and disposal Data lifecycle controls Protection of structured and unstructured information Encryption and access controls Support the secure design and adoption of Microsoft Azure , alongside AWS, SaaS and hybrid-cloud environments. Ensure appropriate security controls across applications, infrastructure, identities, networks and data. Translate cyber risks and regulatory requirements into appropriate security controls and non-functional requirements (NFRs) . Conduct and support security architecture reviews, threat/risk assessments and design validation. Work closely with Enterprise Architecture, Engineering, Cloud, DevSecOps, Risk, Compliance and CISO teams. Identify gaps within the existing security landscape and recommend improvements. Support secure technology adoption and major transformation initiatives. Essential Experience We are looking for candidates with strong experience across both Security Architecture and Data/Cloud Security . You should have: Significant experience as a Security Architect, Cyber Security Architect, Security Solution Architect or Enterprise Security Architect . Proven experience delivering end-to-end security architecture within large and complex organisations. Strong knowledge of security architecture governance, including standards, patterns, design reviews and architecture assurance . Strong Data Protection / Data Security Architecture experience. Experience with data classification, discovery, inventory, labelling, governance, retention/disposal and lifecycle controls. Understanding of security controls for both structured and unstructured data . Strong Microsoft Azure Security architecture experience. Good knowledge of AWS, SaaS and hybrid/multi-cloud security. Experience securing enterprise applications, infrastructure and cloud platforms. Understanding of IAM, Zero Trust, encryption, key management and access-control principles. Ability to translate risk assessments and regulatory requirements into technical security architecture. Experience working within regulatory frameworks such as GDPR, DORA, PCI-DSS, SOX and/or SWIFT CSP . Excellent communication skills with the ability to engage with senior stakeholders, architects, engineers, risk and compliance teams. Highly Desirable Experience with Microsoft Purview , particularly Information Protection, data classification, sensitivity labelling, DLP and information governance. Experience defining data-protection architecture across Azure and Microsoft 365 environments. Financial Services, Banking, Payments, Market Infrastructure or other highly regulated/critical infrastructure experience. Experience with security architecture frameworks such as SABSA, TOGAF or similar . Knowledge of DevSecOps and secure SDLC practices. Experience working within Agile delivery environments and across multiple release trains. Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, Azure Security/Architecture, CISM or equivalent . Rates depend on experience and client requirements
20/08/2026
Contractor
Senior Security Architect (contractor)- Data Protection & Azure Cloud Security Rate: Flexible Duration: 1 year Hybrid working - 8 days onsite per month (Inside of IR35) We are looking for an experienced Senior Security Architect to join a major enterprise cybersecurity function, taking a leading role in the design and governance of security architecture across Data Protection and Cloud Security . This is a senior architecture position within a large, complex and highly regulated environment. You will work across business, technology, engineering, risk and security teams to ensure new applications, platforms and cloud solutions are designed securely from the outset. A major focus of the role will be enterprise data protection and Azure cloud security , including the architecture and governance of controls covering data classification, discovery, labelling, lifecycle management and protection of sensitive information. Key Responsibilities Lead the design and delivery of end-to-end security architecture across enterprise applications, platforms and cloud environments. Develop high-level security designs and translate business, technology and risk requirements into practical security architecture. Define and maintain security architecture principles, standards, patterns and reusable design guidance . Provide architecture governance and design assurance, challenging proposed solutions and ensuring security requirements are addressed throughout the delivery lifecycle. Act as a Subject Matter Expert for Data Protection and Cloud Security , providing technical guidance to architecture, engineering and business teams. Design and govern enterprise data protection and data security controls , including: Data discovery and inventory Data classification and sensitivity labelling Data Loss Prevention (DLP) Data governance Data retention and disposal Data lifecycle controls Protection of structured and unstructured information Encryption and access controls Support the secure design and adoption of Microsoft Azure , alongside AWS, SaaS and hybrid-cloud environments. Ensure appropriate security controls across applications, infrastructure, identities, networks and data. Translate cyber risks and regulatory requirements into appropriate security controls and non-functional requirements (NFRs) . Conduct and support security architecture reviews, threat/risk assessments and design validation. Work closely with Enterprise Architecture, Engineering, Cloud, DevSecOps, Risk, Compliance and CISO teams. Identify gaps within the existing security landscape and recommend improvements. Support secure technology adoption and major transformation initiatives. Essential Experience We are looking for candidates with strong experience across both Security Architecture and Data/Cloud Security . You should have: Significant experience as a Security Architect, Cyber Security Architect, Security Solution Architect or Enterprise Security Architect . Proven experience delivering end-to-end security architecture within large and complex organisations. Strong knowledge of security architecture governance, including standards, patterns, design reviews and architecture assurance . Strong Data Protection / Data Security Architecture experience. Experience with data classification, discovery, inventory, labelling, governance, retention/disposal and lifecycle controls. Understanding of security controls for both structured and unstructured data . Strong Microsoft Azure Security architecture experience. Good knowledge of AWS, SaaS and hybrid/multi-cloud security. Experience securing enterprise applications, infrastructure and cloud platforms. Understanding of IAM, Zero Trust, encryption, key management and access-control principles. Ability to translate risk assessments and regulatory requirements into technical security architecture. Experience working within regulatory frameworks such as GDPR, DORA, PCI-DSS, SOX and/or SWIFT CSP . Excellent communication skills with the ability to engage with senior stakeholders, architects, engineers, risk and compliance teams. Highly Desirable Experience with Microsoft Purview , particularly Information Protection, data classification, sensitivity labelling, DLP and information governance. Experience defining data-protection architecture across Azure and Microsoft 365 environments. Financial Services, Banking, Payments, Market Infrastructure or other highly regulated/critical infrastructure experience. Experience with security architecture frameworks such as SABSA, TOGAF or similar . Knowledge of DevSecOps and secure SDLC practices. Experience working within Agile delivery environments and across multiple release trains. Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, Azure Security/Architecture, CISM or equivalent . Rates depend on experience and client requirements
Senior IT Operations Manager Deep Sea Electronics is a global leader in the design and manufacture of generator controllers, automatic transfer switch controllers, battery chargers, and vehicle and off-highway control systems. With over 200 employees across four continents, we supply our products to customers in more than 150 countries, both directly from our UK head office and through a well-established international distributor network. This is a hands-on senior leadership role responsible for shaping and delivering the organisation's IT strategy, while maintaining overall accountability for the day-to-day management and operational performance of the IT function. The role holder will assume end-to-end responsibility for the company's IT function, providing strategic and operational leadership across all technology services, infrastructure, networks, systems, applications, cybersecurity, and end-user support. They will ensure that technology capabilities are secure, resilient, scalable, and aligned with the organisation's business objectives. The successful candidate will lead both the IT team, establish and embed robust IT governance and change management processes, and take ownership of the organisation's cybersecurity programme, including leading the journey towards ISO 27001 accreditation. They will be accountable for service delivery, infrastructure performance, information security, technology risk management, and the development and execution of the long-term IT roadmap. Operating within a manufacturing environment, the role requires close collaboration with the organisation's parent company to ensure effective alignment, integration, and standardisation of IT services and strategic initiatives where appropriate. As a key member of the leadership team, the postholder will act as a trusted advisor and stakeholder to directors and senior business leaders, translating business requirements into technology solutions and ensuring IT investments deliver measurable business value. The Senior IT Operations Manager is a senior operational leadership position requiring an individual who can successfully balance strategic thinking with hands-on technical oversight. The right candidate will be equally comfortable resolving complex infrastructure challenges, leading and developing technical teams, and presenting technology strategy, risks, and opportunities to senior leadership. The Senior IT Operations Manager will be responsible for: IT Leadership and Direction Define and deliver the IT strategy aligned with overall business objectives and group direction across all technology services Act as the senior IT advisor to the leadership team, contributing to business planning and decision-making Develop a scalable and secure IT architecture to support future growth and international operations Drive continuous improvement across the organisation IT Infrastructure & Operations Responsible for the day-to-day performance, availability, and reliability of all IT infrastructure including networks, servers, end-user computing, cloud, VoIP, and connectivity services Ensure IT support services are delivered to agreed SLAs across all sites Oversee system maintenance, patching, upgrades, and capacity planning Supporting a complex engineering environment Own disaster recovery and business continuity planning, documentation, and regular testing Parent Company Integration & Change Management Act as the primary senior business stakeholder for IT integration and alignment activities with our parent company. Taking part in international IT team meetings and activities Design, implement, and embed a structured IT change management process from the ground up, ensuring it is adopted and followed consistently across the business Align the change management framework with parent company requirements where applicable, whilst protecting local operational continuity Cyber Security & ISO 27001 Lead the organisation's ISO 27001 accreditation programme from scoping through to certification Maintain and improve the day-to-day cyber security posture of the business Ensure alignment with international and parent company cybersecurity standards. Ensure disaster recovery, data protection, and business continuity plans are fit for purpose and regularly tested Manage compliance with relevant legal and regulatory requirements relating to IT systems and data Team Leadership & Development Lead, manage, and develop the IT team covering both support and network/infrastructure functions Set clear objectives, performance standards, and personal development plans for all team members Support the development of apprentices and longer-serving employees, building capability and reducing key-person dependency. Foster a proactive, service-oriented culture within the IT function Budget & Vendor Management Own and manage the IT budget, ensuring accurate forecasting and cost control Manage supplier and third-party relationships, holding vendors accountable for service quality and value Oversee procurement of IT systems, hardware, software, and services Why you should be our new Senior IT Operations Manager: 25 days holiday + Bank Holidays Company-wide performance-based annual bonus scheme Bupa Healthcare package + Life Assurance Enhanced Maternity/Paternity pay 5% Pension contributions Flexible holiday scheme
20/08/2026
Full time
Senior IT Operations Manager Deep Sea Electronics is a global leader in the design and manufacture of generator controllers, automatic transfer switch controllers, battery chargers, and vehicle and off-highway control systems. With over 200 employees across four continents, we supply our products to customers in more than 150 countries, both directly from our UK head office and through a well-established international distributor network. This is a hands-on senior leadership role responsible for shaping and delivering the organisation's IT strategy, while maintaining overall accountability for the day-to-day management and operational performance of the IT function. The role holder will assume end-to-end responsibility for the company's IT function, providing strategic and operational leadership across all technology services, infrastructure, networks, systems, applications, cybersecurity, and end-user support. They will ensure that technology capabilities are secure, resilient, scalable, and aligned with the organisation's business objectives. The successful candidate will lead both the IT team, establish and embed robust IT governance and change management processes, and take ownership of the organisation's cybersecurity programme, including leading the journey towards ISO 27001 accreditation. They will be accountable for service delivery, infrastructure performance, information security, technology risk management, and the development and execution of the long-term IT roadmap. Operating within a manufacturing environment, the role requires close collaboration with the organisation's parent company to ensure effective alignment, integration, and standardisation of IT services and strategic initiatives where appropriate. As a key member of the leadership team, the postholder will act as a trusted advisor and stakeholder to directors and senior business leaders, translating business requirements into technology solutions and ensuring IT investments deliver measurable business value. The Senior IT Operations Manager is a senior operational leadership position requiring an individual who can successfully balance strategic thinking with hands-on technical oversight. The right candidate will be equally comfortable resolving complex infrastructure challenges, leading and developing technical teams, and presenting technology strategy, risks, and opportunities to senior leadership. The Senior IT Operations Manager will be responsible for: IT Leadership and Direction Define and deliver the IT strategy aligned with overall business objectives and group direction across all technology services Act as the senior IT advisor to the leadership team, contributing to business planning and decision-making Develop a scalable and secure IT architecture to support future growth and international operations Drive continuous improvement across the organisation IT Infrastructure & Operations Responsible for the day-to-day performance, availability, and reliability of all IT infrastructure including networks, servers, end-user computing, cloud, VoIP, and connectivity services Ensure IT support services are delivered to agreed SLAs across all sites Oversee system maintenance, patching, upgrades, and capacity planning Supporting a complex engineering environment Own disaster recovery and business continuity planning, documentation, and regular testing Parent Company Integration & Change Management Act as the primary senior business stakeholder for IT integration and alignment activities with our parent company. Taking part in international IT team meetings and activities Design, implement, and embed a structured IT change management process from the ground up, ensuring it is adopted and followed consistently across the business Align the change management framework with parent company requirements where applicable, whilst protecting local operational continuity Cyber Security & ISO 27001 Lead the organisation's ISO 27001 accreditation programme from scoping through to certification Maintain and improve the day-to-day cyber security posture of the business Ensure alignment with international and parent company cybersecurity standards. Ensure disaster recovery, data protection, and business continuity plans are fit for purpose and regularly tested Manage compliance with relevant legal and regulatory requirements relating to IT systems and data Team Leadership & Development Lead, manage, and develop the IT team covering both support and network/infrastructure functions Set clear objectives, performance standards, and personal development plans for all team members Support the development of apprentices and longer-serving employees, building capability and reducing key-person dependency. Foster a proactive, service-oriented culture within the IT function Budget & Vendor Management Own and manage the IT budget, ensuring accurate forecasting and cost control Manage supplier and third-party relationships, holding vendors accountable for service quality and value Oversee procurement of IT systems, hardware, software, and services Why you should be our new Senior IT Operations Manager: 25 days holiday + Bank Holidays Company-wide performance-based annual bonus scheme Bupa Healthcare package + Life Assurance Enhanced Maternity/Paternity pay 5% Pension contributions Flexible holiday scheme
Cyber Assurance & Risk Analyst Location: IWM London Salary : £42,500 to £45,000 per annum Vacancy Type: Permanent, Full Time (36hours per week) Closing Date: 8th of September 2026 At Imperial War Museums, we're driven by a shared purpose: helping people understand conflict and its impact on people's lives, from the First World War through to the present day. Our collections contain millions of items, stories and digital assets that preserve some of the most important moments in modern history. You'll join a collaborative team who work together to protect and make these collections accessible for future generations. It's a unique opportunity to combine cyber security expertise with meaningful work that supports one of the world's leading museums of conflict. Why This Role Matters Cyber security plays a vital role in protecting IWM's systems, services and information assets from an evolving threat landscape. As Cyber Assurance & Risk Analyst, you'll help strengthen the organisation's cyber resilience by ensuring compliance with government and industry security standards, embedding secure-by-design principles into projects and managing cyber risks across our supplier landscape. By delivering key assurance activities, you'll help improve organisational cyber capability and ensure IWM continues to safeguard the services relied upon by colleagues, visitors, researchers and stakeholders. What You'll Be Doing Coordinate and manage IWM's Cyber Essentials certification, including evidence gathering, submission management and remediation tracking. Lead GovAssure submissions through control mapping, evidence collation and stakeholder engagement. Manage compliance against Civil Aviation Authority (CAA) cyber security requirements and other relevant standards. Maintain assurance documentation and support continuous compliance against recognised cyber security frameworks. Embed secure-by-design principles into technology and digital projects from initiation through to delivery. Review proposed solutions and provide assurance that appropriate security controls are implemented before go-live. Own and operate IWM's third-party cyber risk management platform, supporting supplier onboarding, assessments and ongoing monitoring. Identify, assess, manage and escalate cyber risks across the supply chain, tracking remediation activities where required. Produce assurance, compliance and cyber risk reports for governance boards and senior stakeholders. Support cyber governance activities, risk management processes and the maintenance of accurate cyber risk records. Contribute to the development of cyber security policies, standards, controls and continuous improvement initiatives. Provide guidance on cyber compliance matters and work collaboratively with colleagues, suppliers and external partners to support assurance objectives. Support financial administration activities, including purchase orders, invoice processing and departmental administration where required. What We're Looking For We'd love to hear from you if you have: Experience of cyber security governance, assurance, compliance or risk management activities. Knowledge of recognised cyber security frameworks and standards such as Cyber Essentials, NCSC guidance, ISO 27001 or equivalent. Experience managing compliance evidence, audit activities or regulatory submissions. Experience of supplier or third-party cyber risk assessment and management processes. Strong analytical skills with the ability to identify risks and communicate findings clearly to a range of stakeholders. Experience producing reports, dashboards or management information for governance forums and senior audiences. Benefits The benefits listed below are discretionary and IWM reserves the right, with due notice, to vary or withdraw them at any time. Annual Leave: You'll have 25 days of annual leave, with public holidays on top. After 3 years, this increases to 27 days and after 5 years, you ll get 30 days Company Group Pension Plan: Includes competitive employer contributions to your pension starting at 7% to a maximum of 12%. Enhanced Maternity and Paternity Benefits: Celebrate life s milestones with confidence, knowing that our policies support growing families. IWM4me: Tailor your benefits to your unique needs through IWM4me. Access health, protection, and lifestyle benefits at corporate rates, ensuring your holistic well-being. Free Sanitary Products: We prioritise your comfort by providing free sanitary products across all our sites. Retail Discounts: 25% off IWM Cafes, 20% discount in on-site shops, Benefits hub offering retail discounts to several high street shops and MyActive discounts for health and wellbeing based retail discounts Free Entry to IWM Air Shows: Witness the thrill of vintage aircraft at our air shows. To Apply If you feel you are a suitable candidate and would like to work for Imperial War Museum, please click apply to be redirected to our website to complete your application.
20/08/2026
Full time
Cyber Assurance & Risk Analyst Location: IWM London Salary : £42,500 to £45,000 per annum Vacancy Type: Permanent, Full Time (36hours per week) Closing Date: 8th of September 2026 At Imperial War Museums, we're driven by a shared purpose: helping people understand conflict and its impact on people's lives, from the First World War through to the present day. Our collections contain millions of items, stories and digital assets that preserve some of the most important moments in modern history. You'll join a collaborative team who work together to protect and make these collections accessible for future generations. It's a unique opportunity to combine cyber security expertise with meaningful work that supports one of the world's leading museums of conflict. Why This Role Matters Cyber security plays a vital role in protecting IWM's systems, services and information assets from an evolving threat landscape. As Cyber Assurance & Risk Analyst, you'll help strengthen the organisation's cyber resilience by ensuring compliance with government and industry security standards, embedding secure-by-design principles into projects and managing cyber risks across our supplier landscape. By delivering key assurance activities, you'll help improve organisational cyber capability and ensure IWM continues to safeguard the services relied upon by colleagues, visitors, researchers and stakeholders. What You'll Be Doing Coordinate and manage IWM's Cyber Essentials certification, including evidence gathering, submission management and remediation tracking. Lead GovAssure submissions through control mapping, evidence collation and stakeholder engagement. Manage compliance against Civil Aviation Authority (CAA) cyber security requirements and other relevant standards. Maintain assurance documentation and support continuous compliance against recognised cyber security frameworks. Embed secure-by-design principles into technology and digital projects from initiation through to delivery. Review proposed solutions and provide assurance that appropriate security controls are implemented before go-live. Own and operate IWM's third-party cyber risk management platform, supporting supplier onboarding, assessments and ongoing monitoring. Identify, assess, manage and escalate cyber risks across the supply chain, tracking remediation activities where required. Produce assurance, compliance and cyber risk reports for governance boards and senior stakeholders. Support cyber governance activities, risk management processes and the maintenance of accurate cyber risk records. Contribute to the development of cyber security policies, standards, controls and continuous improvement initiatives. Provide guidance on cyber compliance matters and work collaboratively with colleagues, suppliers and external partners to support assurance objectives. Support financial administration activities, including purchase orders, invoice processing and departmental administration where required. What We're Looking For We'd love to hear from you if you have: Experience of cyber security governance, assurance, compliance or risk management activities. Knowledge of recognised cyber security frameworks and standards such as Cyber Essentials, NCSC guidance, ISO 27001 or equivalent. Experience managing compliance evidence, audit activities or regulatory submissions. Experience of supplier or third-party cyber risk assessment and management processes. Strong analytical skills with the ability to identify risks and communicate findings clearly to a range of stakeholders. Experience producing reports, dashboards or management information for governance forums and senior audiences. Benefits The benefits listed below are discretionary and IWM reserves the right, with due notice, to vary or withdraw them at any time. Annual Leave: You'll have 25 days of annual leave, with public holidays on top. After 3 years, this increases to 27 days and after 5 years, you ll get 30 days Company Group Pension Plan: Includes competitive employer contributions to your pension starting at 7% to a maximum of 12%. Enhanced Maternity and Paternity Benefits: Celebrate life s milestones with confidence, knowing that our policies support growing families. IWM4me: Tailor your benefits to your unique needs through IWM4me. Access health, protection, and lifestyle benefits at corporate rates, ensuring your holistic well-being. Free Sanitary Products: We prioritise your comfort by providing free sanitary products across all our sites. Retail Discounts: 25% off IWM Cafes, 20% discount in on-site shops, Benefits hub offering retail discounts to several high street shops and MyActive discounts for health and wellbeing based retail discounts Free Entry to IWM Air Shows: Witness the thrill of vintage aircraft at our air shows. To Apply If you feel you are a suitable candidate and would like to work for Imperial War Museum, please click apply to be redirected to our website to complete your application.
Role: Cyber and Information Assurance Consultant Mid, Senior & Principal Levels Location: Nottingham / Remote-first Working Arrangement: Remote-first, with travel to Nottingham and customer sites as required Salary: £65,000 £120,000 Are you a cyber security or information assurance professional who enjoys working with customers, getting into complex problems and turning security risks into practical solutions? We re looking for Cyber and Information Assurance Consultants across Mid, Senior and Principal levels to join a growing team working on complex, high-assurance environments across defence, government and critical infrastructure. This is a consultancy-focused role, so you won t be sitting in a purely internal security position. You ll work directly with customers, technical teams and senior stakeholders to assess risk, understand threats and vulnerabilities, and provide clear recommendations on how security can be improved. You ll work across areas including cyber risk assessments, information assurance, security governance and secure-by-design. Depending on your level and experience, you could be reviewing solution designs, developing security cases, supporting accreditation and assurance activity, maintaining risk registers or helping shape security requirements across major programmes. You ll also work closely with architects, engineers, project teams, suppliers and customer security teams. A big part of the role will be taking technical evidence and security requirements and explaining what they actually mean from a risk and business perspective. You ll ideally have professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline, alongside experience contributing to security assessment or assurance work. You ll need to be comfortable producing clear security documentation and communicating with both technical and non-technical audiences. Knowledge of areas such as cyber risk management, security controls, threat and vulnerability assessment, security governance and risk acceptance is important. Experience with frameworks such as ISO 27001, ISO 27005, the NCSC Cyber Assessment Framework, NIST or MOD security standards would be beneficial. Experience within defence, government, critical infrastructure or another high-assurance environment would be particularly relevant. Experience with cloud security assurance, security architecture reviews, accreditation or secure information exchange would also be useful. The level you join at will depend on your experience, with opportunities available from Mid-level through to Principal. There is a clear progression route into senior consultancy, security architecture, cyber risk leadership and information assurance leadership, with support towards professional qualifications such as CISSP, CISM, CRISC and ISO 27001. The role is remote-first, although you ll need to be comfortable travelling to the Nottingham office and customer sites when required. Regular UK travel may form part of the role, with occasional international travel possible. If you re looking for a role where you can work on genuinely complex security challenges, have direct customer exposure and continue developing your career across cyber security and assurance, please apply now or get in touch to find out more. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
20/08/2026
Full time
Role: Cyber and Information Assurance Consultant Mid, Senior & Principal Levels Location: Nottingham / Remote-first Working Arrangement: Remote-first, with travel to Nottingham and customer sites as required Salary: £65,000 £120,000 Are you a cyber security or information assurance professional who enjoys working with customers, getting into complex problems and turning security risks into practical solutions? We re looking for Cyber and Information Assurance Consultants across Mid, Senior and Principal levels to join a growing team working on complex, high-assurance environments across defence, government and critical infrastructure. This is a consultancy-focused role, so you won t be sitting in a purely internal security position. You ll work directly with customers, technical teams and senior stakeholders to assess risk, understand threats and vulnerabilities, and provide clear recommendations on how security can be improved. You ll work across areas including cyber risk assessments, information assurance, security governance and secure-by-design. Depending on your level and experience, you could be reviewing solution designs, developing security cases, supporting accreditation and assurance activity, maintaining risk registers or helping shape security requirements across major programmes. You ll also work closely with architects, engineers, project teams, suppliers and customer security teams. A big part of the role will be taking technical evidence and security requirements and explaining what they actually mean from a risk and business perspective. You ll ideally have professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline, alongside experience contributing to security assessment or assurance work. You ll need to be comfortable producing clear security documentation and communicating with both technical and non-technical audiences. Knowledge of areas such as cyber risk management, security controls, threat and vulnerability assessment, security governance and risk acceptance is important. Experience with frameworks such as ISO 27001, ISO 27005, the NCSC Cyber Assessment Framework, NIST or MOD security standards would be beneficial. Experience within defence, government, critical infrastructure or another high-assurance environment would be particularly relevant. Experience with cloud security assurance, security architecture reviews, accreditation or secure information exchange would also be useful. The level you join at will depend on your experience, with opportunities available from Mid-level through to Principal. There is a clear progression route into senior consultancy, security architecture, cyber risk leadership and information assurance leadership, with support towards professional qualifications such as CISSP, CISM, CRISC and ISO 27001. The role is remote-first, although you ll need to be comfortable travelling to the Nottingham office and customer sites when required. Regular UK travel may form part of the role, with occasional international travel possible. If you re looking for a role where you can work on genuinely complex security challenges, have direct customer exposure and continue developing your career across cyber security and assurance, please apply now or get in touch to find out more. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Senior Cyber Security Risk & Assurance Consultant - Product Risk (PBRA) (CONTRACTOR) - London Duration: 1 year contract Hybrid Working - 8 days onsite per month - the rest is remote working About the Team The Product-Based Risk Assessment (PBRA) service conducts recurring security assessments of applications, services, and technologies to identify emerging threats, evaluate control effectiveness, and drive remediation that strengthens The clients cyber resilience. The team supports business and technology stakeholders by assessing cyber security risks and ensuring alignment with The Banks security standards and risk appetite. Key Accountabilities Product-Based Risk Assessments Lead end-to-end Product-Based Risk Assessments (PBRA) for critical applications, platforms, and technology services. Analyse application architectures, business processes, information flows, and supporting infrastructure. Identify and assess cyber threats, vulnerabilities, control weaknesses, and potential business impacts. Evaluate the design and effectiveness of security controls using clients security frameworks and standards. Assess residual risks and propose actionable remediation plans. Security Risk Analysis Perform security risk assessments using recognised methodologies and industry frameworks. Evaluate risks related to infrastructure, software, cloud services, networks, third-party integrations, and information assets. Contribute to threat modelling and attack surface analysis activities. Support technology-focused assessments such as cloud, AI, and emerging technology evaluations. Stakeholder Engagement Act as the primary security assessment contact for business and IT stakeholders. Facilitate workshops, interviews, and assessment review sessions. Challenge assumptions and provide expert security guidance to delivery and operations teams. Build trusted relationships across CISO, CTO, Architecture, Risk Management, and Engineering teams. Reporting & Governance Produce high-quality assessment reports, risk summaries, and executive-level communications. Present findings and recommendations to senior management and governance bodies. Track remediation plans and risk treatment activities through closure. Support internal and external audit activities as required. Continuous Improvement Contribute to the evolution of the PBRA service, methodologies, tools, and operating model. Help drive the transition toward data-enabled and automated security assessment capabilities. Identify opportunities to improve efficiency, consistency, and risk coverage across assessments. Support knowledge sharing and mentoring of junior analysts. Required Skills & Experience Technical Skills Strong understanding of cybersecurity principles, controls, and risk management practices. Knowledge of application security, cloud security, infrastructure security, and network security. Experience conducting security assessments, threat modelling, or risk analyses. Familiarity with industry frameworks and standards such as: NIST Cyber Security Framework ISO 27001 CIS Controls Secure Controls Framework (SCF) DORA ANSSI EBIOS RM OWASP Professional Experience Minimum 7 years of experience in Information Security, Cyber Risk, Security Assurance, or Security Architecture. Experience leading complex security assessments across large technology environments. Experience working with senior business and technology stakeholders. Strong report-writing and presentation skills. Personal Competencies Strong analytical and critical-thinking capabilities. Excellent communication and stakeholder management skills. Ability to challenge constructively and influence decision-making. Self-driven with strong ownership and accountability. Pragmatic, risk-based mindset. Comfortable operating in a complex, regulated environment. Please do send across to me the most up to date CV to (url removed) Rates depend on experience and client requirements
19/08/2026
Contractor
Senior Cyber Security Risk & Assurance Consultant - Product Risk (PBRA) (CONTRACTOR) - London Duration: 1 year contract Hybrid Working - 8 days onsite per month - the rest is remote working About the Team The Product-Based Risk Assessment (PBRA) service conducts recurring security assessments of applications, services, and technologies to identify emerging threats, evaluate control effectiveness, and drive remediation that strengthens The clients cyber resilience. The team supports business and technology stakeholders by assessing cyber security risks and ensuring alignment with The Banks security standards and risk appetite. Key Accountabilities Product-Based Risk Assessments Lead end-to-end Product-Based Risk Assessments (PBRA) for critical applications, platforms, and technology services. Analyse application architectures, business processes, information flows, and supporting infrastructure. Identify and assess cyber threats, vulnerabilities, control weaknesses, and potential business impacts. Evaluate the design and effectiveness of security controls using clients security frameworks and standards. Assess residual risks and propose actionable remediation plans. Security Risk Analysis Perform security risk assessments using recognised methodologies and industry frameworks. Evaluate risks related to infrastructure, software, cloud services, networks, third-party integrations, and information assets. Contribute to threat modelling and attack surface analysis activities. Support technology-focused assessments such as cloud, AI, and emerging technology evaluations. Stakeholder Engagement Act as the primary security assessment contact for business and IT stakeholders. Facilitate workshops, interviews, and assessment review sessions. Challenge assumptions and provide expert security guidance to delivery and operations teams. Build trusted relationships across CISO, CTO, Architecture, Risk Management, and Engineering teams. Reporting & Governance Produce high-quality assessment reports, risk summaries, and executive-level communications. Present findings and recommendations to senior management and governance bodies. Track remediation plans and risk treatment activities through closure. Support internal and external audit activities as required. Continuous Improvement Contribute to the evolution of the PBRA service, methodologies, tools, and operating model. Help drive the transition toward data-enabled and automated security assessment capabilities. Identify opportunities to improve efficiency, consistency, and risk coverage across assessments. Support knowledge sharing and mentoring of junior analysts. Required Skills & Experience Technical Skills Strong understanding of cybersecurity principles, controls, and risk management practices. Knowledge of application security, cloud security, infrastructure security, and network security. Experience conducting security assessments, threat modelling, or risk analyses. Familiarity with industry frameworks and standards such as: NIST Cyber Security Framework ISO 27001 CIS Controls Secure Controls Framework (SCF) DORA ANSSI EBIOS RM OWASP Professional Experience Minimum 7 years of experience in Information Security, Cyber Risk, Security Assurance, or Security Architecture. Experience leading complex security assessments across large technology environments. Experience working with senior business and technology stakeholders. Strong report-writing and presentation skills. Personal Competencies Strong analytical and critical-thinking capabilities. Excellent communication and stakeholder management skills. Ability to challenge constructively and influence decision-making. Self-driven with strong ownership and accountability. Pragmatic, risk-based mindset. Comfortable operating in a complex, regulated environment. Please do send across to me the most up to date CV to (url removed) Rates depend on experience and client requirements
Technical Architect required by my medium sized, extremely busy client. You must have valid SC Clearance . The Technical Architect shall provide technical and architecture expertise across a complex MOD R&D environment supporting defence capability development, systems integration, digital transformation, secure technology adoption and operational capability delivery. The role supports the design, assurance and implementation of secure, resilient and interoperable technical solutions across defence systems, platforms and services. Responsibilities include translating business, operational and enterprise architecture requirements into deliverable technical architectures that support military effectiveness, cyber resilience and future capability growth. The role contributes towards delivery of technology-enabled operational advantage through the development of scalable, secure and supportable technical solutions aligned with MOD strategic objectives, Defence transformation priorities and Integrated Force concepts. Key Responsibilities Technical Architecture Leadership Develop and maintain technical architecture artefacts, standards and design patterns. Produce high-level and low-level technical designs for defence systems and services. Ensure alignment between business requirements, operational needs and technical implementation. Solution Design and Integration Design secure and resilient technical architectures across complex defence environments. Define infrastructure, application, integration and platform architectures. Support interoperability between MOD, allied and industry systems. Develop technical standards, reference architectures and reusable design patterns. Support integration of legacy and modern digital technologies. Infrastructure and Platform Architecture Design and assess Hybrid cloud environments Private cloud infrastructures Edge computing solutions Data platforms Data Fabric Data Centred Security Secure networks Command and control environments Operational technology environments Ensure scalability, performance, resilience and maintainability requirements are achieved. Cyber Security and Technical Assurance Ensure compliance with: MOD Defence Standard 05-138 NCSC Cyber Assessment Framework (CAF) ISO 27001 Secure by Design principles Zero Trust Architecture approaches Support technical risk assessments and accreditation activities. Contribute to cyber resilience, system hardening and security assurance activities. Technical Governance Participate in technical design authorities and architecture review boards. Support technical assurance across programme deliverables. Support engineering governance and configuration management activities. Review supplier and partner technical designs for compliance and interoperability.
17/08/2026
Contractor
Technical Architect required by my medium sized, extremely busy client. You must have valid SC Clearance . The Technical Architect shall provide technical and architecture expertise across a complex MOD R&D environment supporting defence capability development, systems integration, digital transformation, secure technology adoption and operational capability delivery. The role supports the design, assurance and implementation of secure, resilient and interoperable technical solutions across defence systems, platforms and services. Responsibilities include translating business, operational and enterprise architecture requirements into deliverable technical architectures that support military effectiveness, cyber resilience and future capability growth. The role contributes towards delivery of technology-enabled operational advantage through the development of scalable, secure and supportable technical solutions aligned with MOD strategic objectives, Defence transformation priorities and Integrated Force concepts. Key Responsibilities Technical Architecture Leadership Develop and maintain technical architecture artefacts, standards and design patterns. Produce high-level and low-level technical designs for defence systems and services. Ensure alignment between business requirements, operational needs and technical implementation. Solution Design and Integration Design secure and resilient technical architectures across complex defence environments. Define infrastructure, application, integration and platform architectures. Support interoperability between MOD, allied and industry systems. Develop technical standards, reference architectures and reusable design patterns. Support integration of legacy and modern digital technologies. Infrastructure and Platform Architecture Design and assess Hybrid cloud environments Private cloud infrastructures Edge computing solutions Data platforms Data Fabric Data Centred Security Secure networks Command and control environments Operational technology environments Ensure scalability, performance, resilience and maintainability requirements are achieved. Cyber Security and Technical Assurance Ensure compliance with: MOD Defence Standard 05-138 NCSC Cyber Assessment Framework (CAF) ISO 27001 Secure by Design principles Zero Trust Architecture approaches Support technical risk assessments and accreditation activities. Contribute to cyber resilience, system hardening and security assurance activities. Technical Governance Participate in technical design authorities and architecture review boards. Support technical assurance across programme deliverables. Support engineering governance and configuration management activities. Review supplier and partner technical designs for compliance and interoperability.
Role Overview The Technology & Data Risk Manager is a new second line of defence role within the Risk Directorate, responsible for providing independent oversight, assurance and expert challenge across technology, data, cyber security, and related operational risks. Reporting to the Head of Technical Risk and Data Protection Officer, the role supports the effective management of technology and data risks by ensuring first line teams identify, assess and mitigate risks in line with Nest's risk appetite while enabling the organisation to deliver its strategic objectives securely and efficiently.Working across the organisation, the role promotes strong risk management practices, providing expert challenge on technology, data protection, information security, and third-party risk matters. It plays a key role in strengthening governance, embedding a strong data protection and security culture, and supporting compliance with regulatory requirements and recognised standards, includingUK GDPR, the Data Protection Act 2018 and ISO 27001.The Technology & Data Risk Manager also helps the organisation anticipate and respond to emerging risks and opportunities, including developments in artificial intelligence, evolving cyber threats, and third-party dependencies. Through effective stakeholder engagement, assurance activity and risk reporting, the role contributes to maintaining a resilient, compliant, and well-controlled technology and data environment across Nest. The minimum criteria for this role are: Essential Sound knowledge of information security and data risk domains (access control, vulnerability management, logging and monitoring, incident response, secure development etc). Experience in technology, data, security, or technical risk management including control frameworks such as ISO 27001 and NIST, ideally within a regulated or complex organisation. Strong understanding of second line assurance and oversight, including how to challenge constructively while remaining independent. Experience of assessing third-party technical risk. Desirable Experience with product security and secure SDLC assurance. Knowledge of AI risk, data ethics or emerging technology governance. Working knowledge of UK GDPR and the Data Protection Act 2018. Knowledge of threat intelligence, vulnerability disclosure, and security testing approaches. Relevant professional certifications (e.g. CISM, CISSP, ISO 27001 LI/LA, CRISC, ITIL). Don't worry if you think you don't have all the key skills, it might be worth taking the few minutes to apply as we're good at spotting potential. At Nest, you'll have access to a range of learning opportunities to learn, grow and build the skills you need to be successful in your role and career. Flexible and agile working Everyone's personal situation is different.To make the most out of hybrid working, we've introduced different ways of working, which include (subject to role requirements): hybrid of office (Canary Wharf, London) and home working (there will be an expectation to attend the office, once - twice a week, or more, as required) vary working hours Directorate/Department Overview The Technical Risk team sits within the Risk Directorate, along with Risk, Risk Assurance, Risk Operations and Regulatory Risk, and Controls Oversight. The directorate supports the business in delivering its strategic priorities by overseeing that risk and controls are identified, prioritised and managed through an enterprise risk management framework. Nest operates a 'three lines of defence' model, with Risk sitting in the second line providing advice, guidance and challenge to the first line.The Technical Risk team provides support to Nest specifically in relation to risks covering data, privacy, technology, cyber and financial crime. Support includes conducting investigations, regulatory reporting as well as training and awareness across Nest Corporation. Organisational Overview Nest is an award-winning workplace pension scheme, the largest in the country. Set up by the government to give every worker in the UK somewhere to save, our first-class responsible investment practice and governance are the backbone of what we do, supported by all the functions you'd expect to find in a thriving business. We're committed to creating a workplace where you can be your authentic self and offer an inclusive and flexible working environment. Diversity, Equity and Inclusion Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of their age, disability, gender identity, marital status, national origin, pregnancy or caring responsibilities, race, religion/belief, sex, sexual orientation or socio economic background.We also recognise the importance of diversity of thought and other forms of neurocognitive variation.Nest is a Disability Confident Leader, which is the highest level of the Disability Confident Scheme. If you have a disability, please declare that you're applying through the scheme. We aim to offer an interview to those applicants who apply through the Disability Confident Scheme and best meet the minimum criteria. However, there may be some circumstances where this is not possible due to the volume of applications.Please note that this advert may close early if we receive a sufficient number of satisfactory applications. If you have any difficulty in sending your application or need the application pack in an alternative format, or you require any reasonable adjustments please contact: .
15/08/2026
Full time
Role Overview The Technology & Data Risk Manager is a new second line of defence role within the Risk Directorate, responsible for providing independent oversight, assurance and expert challenge across technology, data, cyber security, and related operational risks. Reporting to the Head of Technical Risk and Data Protection Officer, the role supports the effective management of technology and data risks by ensuring first line teams identify, assess and mitigate risks in line with Nest's risk appetite while enabling the organisation to deliver its strategic objectives securely and efficiently.Working across the organisation, the role promotes strong risk management practices, providing expert challenge on technology, data protection, information security, and third-party risk matters. It plays a key role in strengthening governance, embedding a strong data protection and security culture, and supporting compliance with regulatory requirements and recognised standards, includingUK GDPR, the Data Protection Act 2018 and ISO 27001.The Technology & Data Risk Manager also helps the organisation anticipate and respond to emerging risks and opportunities, including developments in artificial intelligence, evolving cyber threats, and third-party dependencies. Through effective stakeholder engagement, assurance activity and risk reporting, the role contributes to maintaining a resilient, compliant, and well-controlled technology and data environment across Nest. The minimum criteria for this role are: Essential Sound knowledge of information security and data risk domains (access control, vulnerability management, logging and monitoring, incident response, secure development etc). Experience in technology, data, security, or technical risk management including control frameworks such as ISO 27001 and NIST, ideally within a regulated or complex organisation. Strong understanding of second line assurance and oversight, including how to challenge constructively while remaining independent. Experience of assessing third-party technical risk. Desirable Experience with product security and secure SDLC assurance. Knowledge of AI risk, data ethics or emerging technology governance. Working knowledge of UK GDPR and the Data Protection Act 2018. Knowledge of threat intelligence, vulnerability disclosure, and security testing approaches. Relevant professional certifications (e.g. CISM, CISSP, ISO 27001 LI/LA, CRISC, ITIL). Don't worry if you think you don't have all the key skills, it might be worth taking the few minutes to apply as we're good at spotting potential. At Nest, you'll have access to a range of learning opportunities to learn, grow and build the skills you need to be successful in your role and career. Flexible and agile working Everyone's personal situation is different.To make the most out of hybrid working, we've introduced different ways of working, which include (subject to role requirements): hybrid of office (Canary Wharf, London) and home working (there will be an expectation to attend the office, once - twice a week, or more, as required) vary working hours Directorate/Department Overview The Technical Risk team sits within the Risk Directorate, along with Risk, Risk Assurance, Risk Operations and Regulatory Risk, and Controls Oversight. The directorate supports the business in delivering its strategic priorities by overseeing that risk and controls are identified, prioritised and managed through an enterprise risk management framework. Nest operates a 'three lines of defence' model, with Risk sitting in the second line providing advice, guidance and challenge to the first line.The Technical Risk team provides support to Nest specifically in relation to risks covering data, privacy, technology, cyber and financial crime. Support includes conducting investigations, regulatory reporting as well as training and awareness across Nest Corporation. Organisational Overview Nest is an award-winning workplace pension scheme, the largest in the country. Set up by the government to give every worker in the UK somewhere to save, our first-class responsible investment practice and governance are the backbone of what we do, supported by all the functions you'd expect to find in a thriving business. We're committed to creating a workplace where you can be your authentic self and offer an inclusive and flexible working environment. Diversity, Equity and Inclusion Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of their age, disability, gender identity, marital status, national origin, pregnancy or caring responsibilities, race, religion/belief, sex, sexual orientation or socio economic background.We also recognise the importance of diversity of thought and other forms of neurocognitive variation.Nest is a Disability Confident Leader, which is the highest level of the Disability Confident Scheme. If you have a disability, please declare that you're applying through the scheme. We aim to offer an interview to those applicants who apply through the Disability Confident Scheme and best meet the minimum criteria. However, there may be some circumstances where this is not possible due to the volume of applications.Please note that this advert may close early if we receive a sufficient number of satisfactory applications. If you have any difficulty in sending your application or need the application pack in an alternative format, or you require any reasonable adjustments please contact: .
Cambridge University Press & Assessment
Cambridge, UK
Security Assurance Lead
Salary: £54,800 - £73,250
Location: Cambridge/ Hybrid with 2 days a week minimum in the office
Contract: Permanent
Hours: 35 hours per week
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role.
We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge.
About the role
As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working.
This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment.
Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement.
Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure.
Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery.
Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported.
Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST.
Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders.
Support incident preparedness, including investigations and exercises that test our ability to respond effectively.
Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation.
This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition.
About You
We are looking for someone with extensive knowledge and 5+ years of experience in security testing and assurance, and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks (e.g. ISO 27001, NIST) and risk management practices.
You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing.
You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management.
You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously.
If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria:
Development and maintained a supply chain risk register within a similar sized organisation
Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc
Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure
Experience of reporting risks to senior leadership
For a detailed job description, please refer to the link at the bottom of the advert on our careers site.
We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition.
Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for.
Rewards and benefits
We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including:
28 days annual leave plus bank holidays
Private medical and Permanent Health Insurance
Discretionary annual bonus
Group personal pension scheme
Life assurance up to 4 x annual salary
Green travel schemes
Ready to pursue your potential? Apply now.
We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after.
The application and interview process consists of:
3 role related questions with brief answers
A 15-minute screening call with the Hiring Manager.
First stage virtual interview via MS Teams.
Final stage interview: in-person at our offices in Cambridge.
If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs.
Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry.
We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter.
Why join us
Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe – for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration.
Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background.
We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
13/08/2026
Full time
Security Assurance Lead
Salary: £54,800 - £73,250
Location: Cambridge/ Hybrid with 2 days a week minimum in the office
Contract: Permanent
Hours: 35 hours per week
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role.
We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge.
About the role
As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working.
This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment.
Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement.
Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure.
Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery.
Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported.
Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST.
Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders.
Support incident preparedness, including investigations and exercises that test our ability to respond effectively.
Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation.
This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition.
About You
We are looking for someone with extensive knowledge and 5+ years of experience in security testing and assurance, and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks (e.g. ISO 27001, NIST) and risk management practices.
You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing.
You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management.
You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously.
If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria:
Development and maintained a supply chain risk register within a similar sized organisation
Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc
Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure
Experience of reporting risks to senior leadership
For a detailed job description, please refer to the link at the bottom of the advert on our careers site.
We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition.
Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for.
Rewards and benefits
We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including:
28 days annual leave plus bank holidays
Private medical and Permanent Health Insurance
Discretionary annual bonus
Group personal pension scheme
Life assurance up to 4 x annual salary
Green travel schemes
Ready to pursue your potential? Apply now.
We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after.
The application and interview process consists of:
3 role related questions with brief answers
A 15-minute screening call with the Hiring Manager.
First stage virtual interview via MS Teams.
Final stage interview: in-person at our offices in Cambridge.
If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs.
Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry.
We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter.
Why join us
Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe – for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration.
Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background.
We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
Our client is seeking an experienced and immediately available Interim Chief Information Security Officer (CISO) to provide strategic and operational cyber security leadership during a critical phase of security and risk maturity. This is an excellent opportunity for a seasoned security leader who has operated within complex, highly regulated, research-led, public sector or mission-driven environments. Experience across sectors such as Higher Education, Charity, Research & Development, Scientific Research, Government, Not-for-Profit, Public Sector or Similar Organisations would be highly advantageous. The successful candidate will be responsible for leading and enhancing the organisation's cyber security capability across operational security, governance, risk management, cyber assurance, security strategy and stakeholder engagement. The organisation currently operates within a managed SOC environment, and the incoming CISO will be expected to maximise the effectiveness of existing security operations while driving strategic improvements across the wider security function. Key Responsibilities Provide executive leadership for the information and cyber security function. Develop and execute a pragmatic cyber security strategy aligned to business and organisational objectives. Lead cyber governance, risk management and security assurance activities. Oversee operational security capabilities, including management of a third-party SOC and associated security providers. Establish and maintain effective security policies, standards and control frameworks. Deliver security reporting and risk updates to Executive Leadership Teams, Boards, Audit Committees and key stakeholders. Lead security incident preparedness, response oversight and resilience planning. Drive cyber maturity improvements across people, process and technology. Manage security risk assessments and remediation programmes. Ensure compliance with relevant regulatory, legal and governance requirements. Provide expert guidance on emerging threats, vulnerabilities and cyber risk exposure. Collaborate with technology, data protection, risk and business leaders to embed security across the organisation. Required Experience Previous experience operating as a CISO, Interim CISO, Head of Cyber Security, Director of Information Security or equivalent senior leadership role. Demonstrable experience leading enterprise-wide cyber security programmes. Strong background covering: Operational Security Security Governance Cyber Risk Management Cyber Assurance Security Strategy Third-Party Security Management Incident Response & Cyber Resilience Experience overseeing or working alongside managed SOC services. Strong stakeholder management skills with the ability to engage both technical and non-technical audiences. Proven ability to influence executive leadership and board-level stakeholders. Experience operating within complex, federated, research-led or highly regulated environments. If this sounds of interest please share you profile for more information, If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
10/08/2026
Contractor
Our client is seeking an experienced and immediately available Interim Chief Information Security Officer (CISO) to provide strategic and operational cyber security leadership during a critical phase of security and risk maturity. This is an excellent opportunity for a seasoned security leader who has operated within complex, highly regulated, research-led, public sector or mission-driven environments. Experience across sectors such as Higher Education, Charity, Research & Development, Scientific Research, Government, Not-for-Profit, Public Sector or Similar Organisations would be highly advantageous. The successful candidate will be responsible for leading and enhancing the organisation's cyber security capability across operational security, governance, risk management, cyber assurance, security strategy and stakeholder engagement. The organisation currently operates within a managed SOC environment, and the incoming CISO will be expected to maximise the effectiveness of existing security operations while driving strategic improvements across the wider security function. Key Responsibilities Provide executive leadership for the information and cyber security function. Develop and execute a pragmatic cyber security strategy aligned to business and organisational objectives. Lead cyber governance, risk management and security assurance activities. Oversee operational security capabilities, including management of a third-party SOC and associated security providers. Establish and maintain effective security policies, standards and control frameworks. Deliver security reporting and risk updates to Executive Leadership Teams, Boards, Audit Committees and key stakeholders. Lead security incident preparedness, response oversight and resilience planning. Drive cyber maturity improvements across people, process and technology. Manage security risk assessments and remediation programmes. Ensure compliance with relevant regulatory, legal and governance requirements. Provide expert guidance on emerging threats, vulnerabilities and cyber risk exposure. Collaborate with technology, data protection, risk and business leaders to embed security across the organisation. Required Experience Previous experience operating as a CISO, Interim CISO, Head of Cyber Security, Director of Information Security or equivalent senior leadership role. Demonstrable experience leading enterprise-wide cyber security programmes. Strong background covering: Operational Security Security Governance Cyber Risk Management Cyber Assurance Security Strategy Third-Party Security Management Incident Response & Cyber Resilience Experience overseeing or working alongside managed SOC services. Strong stakeholder management skills with the ability to engage both technical and non-technical audiences. Proven ability to influence executive leadership and board-level stakeholders. Experience operating within complex, federated, research-led or highly regulated environments. If this sounds of interest please share you profile for more information, If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Role Title: Assurance Lead Location: Manchester Hybrid 80% remote 20% onsite Duration: 31/10/2031 Rate - 500 - 560 CONTRACTOR MUST BE SC CLEARED (active) AND BE A SOLE UK NATIONAL The candidate hasn't been outside the UK for more than 28 consecutives days during the last 5 years Role Description: Maintain oversight of cyber security risks across suppliers Ensure risks are: Identified, Assessed, Recorded, Tracked & Escalated appropriately Govern risk acceptance and exception management processes Support risk-based prioritisation across security disciplines Coordinate supplier compliance activities within the SIAM framework Validate supplier adherence to agreed security requirements Monitor security performance against contractual obligations Drive accountability for control weaknesses, non-compliance, and improvement actions Maintain visibility of compliance obligations and control requirements Support compliance against frameworks and standards such as: ISO 27001, NIST CSF, NCSC guidance & Secure by Design principles Coordinate remediation of identified compliance gaps Produce consolidated security governance reporting Provide visibility of: Security risks, Compliance status, Control effectiveness, Supplier performance & Assurance findings Present governance information to client stakeholders and governance forums Support strategic planning and risk-informed decision making Drive security governance maturity improvements across the supplier landscape Identify opportunities to improve: Risk management, Compliance processes & Assurance effectiveness Security governance practices Support continuous improvement programmes across the cyber security operating model Facilitate cross-supplier resolution of governance issues If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
10/08/2026
Contractor
Role Title: Assurance Lead Location: Manchester Hybrid 80% remote 20% onsite Duration: 31/10/2031 Rate - 500 - 560 CONTRACTOR MUST BE SC CLEARED (active) AND BE A SOLE UK NATIONAL The candidate hasn't been outside the UK for more than 28 consecutives days during the last 5 years Role Description: Maintain oversight of cyber security risks across suppliers Ensure risks are: Identified, Assessed, Recorded, Tracked & Escalated appropriately Govern risk acceptance and exception management processes Support risk-based prioritisation across security disciplines Coordinate supplier compliance activities within the SIAM framework Validate supplier adherence to agreed security requirements Monitor security performance against contractual obligations Drive accountability for control weaknesses, non-compliance, and improvement actions Maintain visibility of compliance obligations and control requirements Support compliance against frameworks and standards such as: ISO 27001, NIST CSF, NCSC guidance & Secure by Design principles Coordinate remediation of identified compliance gaps Produce consolidated security governance reporting Provide visibility of: Security risks, Compliance status, Control effectiveness, Supplier performance & Assurance findings Present governance information to client stakeholders and governance forums Support strategic planning and risk-informed decision making Drive security governance maturity improvements across the supplier landscape Identify opportunities to improve: Risk management, Compliance processes & Assurance effectiveness Security governance practices Support continuous improvement programmes across the cyber security operating model Facilitate cross-supplier resolution of governance issues If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Role: DV Cleared Project Manager Location: Cheltenham - 3 days/week on-site Salary: £70,000 - £86,000 + benefits DV Cleared Project Manager needed to join our client, an established defence engineering firm based in Cheltenham. The Project Manager will join the UK Cyber & Intelligence business. The teams combines modern software-engineering practices with deep Defence and national-security expertise. You'll play a key role in delivering complex, sensitive and high-impact technology projects that support customers through ambitious digital transformation. You must currently hold the highest level of UK Government security clearance. What the role of the Project Manager entails: Some of the main duties of the Project Manager will include: Leading projects to deliver agreed outcomes within time, cost and quality constraints. Providing day-to-day leadership to the project team, ensuring effective decision-making and strong management controls. Designing the project structure, setting appropriate delivery methodologies and managing transitions between phases. Developing and maintaining business cases, budgets and project plans, ensuring performance and progress are clearly reported. Building and developing high-performing teams, identifying resource requirements and supporting recruitment where required. Managing stakeholder relationships, ensuring clear communication and senior-level engagement. Identifying, monitoring and reporting risks and issues, driving mitigation and escalation where appropriate. Supporting governance and assurance processes, including gateway reviews and change-control mechanisms. What experience you need to be the successful Project Manager: Current DV Security Clearance Proven experience in project or delivery management roles with strong evidence of collaborative working. Experience with UK Government or MOD environments, including PRINCE2, Agile, APM or MSP frameworks. Recent experience delivering IT, software or cyber projects within Government or similar complex organisations. Experience delivering to time, budget and quality within T&M and fixed-price contracts. Ability to manage competing priorities across specialist teams. This really is a fantastic opportunity for a Project Manager to progress their career. If you are interested please apply as soon as possible as this position will be filled quickly so don't miss out! Services advertised by Gold Group are those of an Agency and/or an Employment Business.We will contact you within the next 14 days if you are selected for interview. For a copy of our privacy policy please visit our website.
10/08/2026
Full time
Role: DV Cleared Project Manager Location: Cheltenham - 3 days/week on-site Salary: £70,000 - £86,000 + benefits DV Cleared Project Manager needed to join our client, an established defence engineering firm based in Cheltenham. The Project Manager will join the UK Cyber & Intelligence business. The teams combines modern software-engineering practices with deep Defence and national-security expertise. You'll play a key role in delivering complex, sensitive and high-impact technology projects that support customers through ambitious digital transformation. You must currently hold the highest level of UK Government security clearance. What the role of the Project Manager entails: Some of the main duties of the Project Manager will include: Leading projects to deliver agreed outcomes within time, cost and quality constraints. Providing day-to-day leadership to the project team, ensuring effective decision-making and strong management controls. Designing the project structure, setting appropriate delivery methodologies and managing transitions between phases. Developing and maintaining business cases, budgets and project plans, ensuring performance and progress are clearly reported. Building and developing high-performing teams, identifying resource requirements and supporting recruitment where required. Managing stakeholder relationships, ensuring clear communication and senior-level engagement. Identifying, monitoring and reporting risks and issues, driving mitigation and escalation where appropriate. Supporting governance and assurance processes, including gateway reviews and change-control mechanisms. What experience you need to be the successful Project Manager: Current DV Security Clearance Proven experience in project or delivery management roles with strong evidence of collaborative working. Experience with UK Government or MOD environments, including PRINCE2, Agile, APM or MSP frameworks. Recent experience delivering IT, software or cyber projects within Government or similar complex organisations. Experience delivering to time, budget and quality within T&M and fixed-price contracts. Ability to manage competing priorities across specialist teams. This really is a fantastic opportunity for a Project Manager to progress their career. If you are interested please apply as soon as possible as this position will be filled quickly so don't miss out! Services advertised by Gold Group are those of an Agency and/or an Employment Business.We will contact you within the next 14 days if you are selected for interview. For a copy of our privacy policy please visit our website.
Cyber Security Lead / Information Security Lead Bedford, Bedfordshire Hybrid 3 Days Office / 2 Days Remote £60,000 £70,000 + Excellent Benefits Permanent Infrastructure Security Network Security Cyber Security ISO 27001 Azure Microsoft 365 Are you an experienced Cyber Security Lead, Information Security Lead or Senior Security Engineer looking for an opportunity to step into a broader security leadership role? We are looking for a technically strong Cyber Security Lead / Information Security Lead to join a growing technology business in Bedford. This is an excellent opportunity for an Infrastructure Security, Network Security or Cyber Security professional who wants greater ownership and influence while remaining close to the technical side of security. This is not a purely GRC or compliance-focused position. The successful Cyber Security Lead will bring a strong technical foundation across infrastructure, networks and security engineering, combined with experience or exposure to Information Security, ISO 27001, security governance, risk and compliance. Working closely with Infrastructure, IT Operations, Engineering and senior stakeholders, you'll help strengthen the organisation's security posture across networks, servers, cloud platforms, Microsoft 365, Azure and business systems. What You'll Be Doing As the Cyber Security Lead, you'll take a leading role in information security and cyber security activities across the organisation. You'll help develop and continually improve the Information Security Management System (ISMS), maintain ISO 27001, support internal and external security audits and ensure security controls remain practical, effective and appropriate. You'll work closely with technical teams on infrastructure security, network security, vulnerability management, patch management and security remediation, coordinating penetration testing and ensuring identified vulnerabilities and security issues are addressed effectively. You'll also manage information security risk assessments, support incident response, supplier and third-party security assurance, Business Continuity and Disaster Recovery, while helping embed a strong security culture across the organisation. The Technical Background We're Looking For We're particularly interested in candidates who have developed their careers through Infrastructure, Network or Cyber Security and are now ready to take on greater Information Security leadership responsibility. You'll ideally bring experience across: Network & Infrastructure Security: firewalls, networking, Windows Server, Active Directory, endpoints and infrastructure hardening. Cloud & Identity Security: Microsoft 365, Azure Security, Identity & Access Management (IAM) and access controls. Security Operations: vulnerability management, patch management, penetration testing, remediation and incident response. Information Security: ISO 27001, ISMS, security audits, Cyber Essentials, security policies, governance, risk and compliance. You don't necessarily need to already hold the title of Cyber Security Lead. We would also be interested in hearing from experienced Senior Cyber Security Analysts, Senior Information Security Analysts, Security Engineers, Infrastructure Security Engineers, Network Security Engineers and Technical Security Leads who are ready to take the next step. Strong communication and stakeholder management skills are important. You'll be comfortable working with technical teams while also being able to explain security risks, controls and priorities clearly to senior and non-technical stakeholders. Why Consider This Cyber Security Lead Role? This is an opportunity to move beyond a purely engineering-focused position and take broader ownership of Information Security and Cyber Security, without leaving your technical background behind. You'll have the opportunity to influence security strategy, improve technical security controls, develop the ISMS, support ISO 27001 and work across Infrastructure Security, Network Security, Cloud Security, Security Governance and Cyber Security. Salary: £60,000 £70,000 Location: Bedford, Bedfordshire Working Pattern: Hybrid 3 days office / 2 days remote Employment: Permanent Focus: Cyber Security, Information Security, Infrastructure Security & Network Security Frameworks: ISO 27001 / ISMS / Cyber Essentials Ready for Your Next Move? If you're an experienced Cyber Security Lead, Information Security Lead, Senior Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead or Senior Cyber Security Analyst, we'd like to hear from you. This could be an excellent next step for a technically strong security professional who wants to take greater ownership of Cyber Security and Information Security, influence security strategy and work across infrastructure, networks, cloud, risk, governance and compliance. Apply today for a confidential discussion. Key Skills: Cyber Security Lead, Information Security Lead, Cyber Security, Information Security, Infrastructure Security, Network Security, Security Engineering, Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead, ISO 27001, ISMS, GRC, Security Governance, Security Compliance, Vulnerability Management, Patch Management, Penetration Testing, Azure Security, Microsoft 365 Security, Active Directory, IAM, Firewalls, Incident Response, Cyber Essentials, Security Audits, Risk Management, Supplier Assurance, Business Continuity, Disaster Recovery.
07/08/2026
Full time
Cyber Security Lead / Information Security Lead Bedford, Bedfordshire Hybrid 3 Days Office / 2 Days Remote £60,000 £70,000 + Excellent Benefits Permanent Infrastructure Security Network Security Cyber Security ISO 27001 Azure Microsoft 365 Are you an experienced Cyber Security Lead, Information Security Lead or Senior Security Engineer looking for an opportunity to step into a broader security leadership role? We are looking for a technically strong Cyber Security Lead / Information Security Lead to join a growing technology business in Bedford. This is an excellent opportunity for an Infrastructure Security, Network Security or Cyber Security professional who wants greater ownership and influence while remaining close to the technical side of security. This is not a purely GRC or compliance-focused position. The successful Cyber Security Lead will bring a strong technical foundation across infrastructure, networks and security engineering, combined with experience or exposure to Information Security, ISO 27001, security governance, risk and compliance. Working closely with Infrastructure, IT Operations, Engineering and senior stakeholders, you'll help strengthen the organisation's security posture across networks, servers, cloud platforms, Microsoft 365, Azure and business systems. What You'll Be Doing As the Cyber Security Lead, you'll take a leading role in information security and cyber security activities across the organisation. You'll help develop and continually improve the Information Security Management System (ISMS), maintain ISO 27001, support internal and external security audits and ensure security controls remain practical, effective and appropriate. You'll work closely with technical teams on infrastructure security, network security, vulnerability management, patch management and security remediation, coordinating penetration testing and ensuring identified vulnerabilities and security issues are addressed effectively. You'll also manage information security risk assessments, support incident response, supplier and third-party security assurance, Business Continuity and Disaster Recovery, while helping embed a strong security culture across the organisation. The Technical Background We're Looking For We're particularly interested in candidates who have developed their careers through Infrastructure, Network or Cyber Security and are now ready to take on greater Information Security leadership responsibility. You'll ideally bring experience across: Network & Infrastructure Security: firewalls, networking, Windows Server, Active Directory, endpoints and infrastructure hardening. Cloud & Identity Security: Microsoft 365, Azure Security, Identity & Access Management (IAM) and access controls. Security Operations: vulnerability management, patch management, penetration testing, remediation and incident response. Information Security: ISO 27001, ISMS, security audits, Cyber Essentials, security policies, governance, risk and compliance. You don't necessarily need to already hold the title of Cyber Security Lead. We would also be interested in hearing from experienced Senior Cyber Security Analysts, Senior Information Security Analysts, Security Engineers, Infrastructure Security Engineers, Network Security Engineers and Technical Security Leads who are ready to take the next step. Strong communication and stakeholder management skills are important. You'll be comfortable working with technical teams while also being able to explain security risks, controls and priorities clearly to senior and non-technical stakeholders. Why Consider This Cyber Security Lead Role? This is an opportunity to move beyond a purely engineering-focused position and take broader ownership of Information Security and Cyber Security, without leaving your technical background behind. You'll have the opportunity to influence security strategy, improve technical security controls, develop the ISMS, support ISO 27001 and work across Infrastructure Security, Network Security, Cloud Security, Security Governance and Cyber Security. Salary: £60,000 £70,000 Location: Bedford, Bedfordshire Working Pattern: Hybrid 3 days office / 2 days remote Employment: Permanent Focus: Cyber Security, Information Security, Infrastructure Security & Network Security Frameworks: ISO 27001 / ISMS / Cyber Essentials Ready for Your Next Move? If you're an experienced Cyber Security Lead, Information Security Lead, Senior Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead or Senior Cyber Security Analyst, we'd like to hear from you. This could be an excellent next step for a technically strong security professional who wants to take greater ownership of Cyber Security and Information Security, influence security strategy and work across infrastructure, networks, cloud, risk, governance and compliance. Apply today for a confidential discussion. Key Skills: Cyber Security Lead, Information Security Lead, Cyber Security, Information Security, Infrastructure Security, Network Security, Security Engineering, Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead, ISO 27001, ISMS, GRC, Security Governance, Security Compliance, Vulnerability Management, Patch Management, Penetration Testing, Azure Security, Microsoft 365 Security, Active Directory, IAM, Firewalls, Incident Response, Cyber Essentials, Security Audits, Risk Management, Supplier Assurance, Business Continuity, Disaster Recovery.
Infrastructure Architect Location: Remote (98% remote with very occasional travel to London or Manchester) Rate: 600 per day Duration: Contract until 30th June 2027 YOU MUST HOLD SC CLEARENCE WITH THE HOME OFFICE & HAVE NPPV3 CLEARANCE We are looking for an experienced Infrastructure Architect to join a major organisational transformation programme focused on bringing multiple organisations, business units, and user communities together under a unified Target Operating Model (TOM). Working as part of a multi-disciplinary transformation team, you will be responsible for defining, designing, and assuring the future-state infrastructure architecture that underpins consolidated services, platforms, and operating models. This role requires a strong blend of strategic architecture expertise, transformation experience, and stakeholder engagement skills to ensure infrastructure solutions are secure, resilient, scalable, and aligned to long-term business objectives. Infrastructure Architecture Strategy Develop and maintain the infrastructure architecture strategy supporting the Target Operating Model. Define the future-state infrastructure landscape across cloud, hosting, networking, end-user computing, identity, storage, and platform services. Ensure infrastructure architecture aligns with enterprise architecture principles, business objectives, and programme outcomes. Provide strategic architectural guidance throughout the transformation lifecycle. Transformation & Migration Support Work closely with programme teams to support the integration of multiple organisations into the target environment. Assess current-state infrastructure landscapes and identify opportunities for consolidation, optimisation, and standardisation. Support infrastructure transformation planning and migration activities. Ensure business continuity and operational stability throughout transition and implementation phases. Solution Design & Assurance Produce high-level and detailed infrastructure designs. Develop infrastructure standards, architectural patterns, and reference architectures. Review and assure solution designs delivered by internal teams, suppliers, and technical partners. Ensure designs meet security, availability, resilience, performance, and operational support requirements. Provide architecture governance and technical assurance across the programme. Platform & Service Alignment Define architectural requirements for hosting, connectivity, workplace technology, and platform services. Ensure infrastructure services support future operational and service management requirements. Align infrastructure architecture with service integration and operational readiness objectives. Support the successful adoption of shared platforms and infrastructure services. Cloud & Infrastructure Modernisation Define cloud adoption strategies and migration approaches where appropriate. Identify opportunities to modernise legacy infrastructure and improve operational efficiency. Promote infrastructure automation, Infrastructure as Code (IaC), and cloud-native design principles. Support the development of scalable and future-ready infrastructure capabilities. Security, Resilience & Compliance Ensure infrastructure solutions comply with security standards, policies, and regulatory requirements. Work closely with cyber security teams to embed secure-by-design principles. Support risk assessments, architecture reviews, and technical governance activities. Ensure solutions meet resilience, disaster recovery, backup, business continuity, and high-availability requirements. Stakeholder Engagement Collaborate with business stakeholders, technical teams, service providers, and programme leadership. Translate complex technical concepts into clear and understandable business language. Facilitate design workshops, architecture reviews, and stakeholder discussions. Support informed decision-making through robust architectural recommendations and assessments. Supplier & Partner Management Work closely with cloud providers, infrastructure suppliers, and technology partners. Ensure third-party solutions align with strategic architecture principles and target-state designs. Support technical governance across complex multi-vendor environments. Manage architecture dependencies associated with supplier-delivered services. Essential Skills & Experience Proven experience working as an Infrastructure Architect within complex enterprise environments. Experience supporting large-scale business or organisational transformation programmes. Strong knowledge of cloud technologies, including Azure, AWS, and/or Google Cloud Platform. Experience developing migration strategies, transformation roadmaps, and target-state architectures. Experience with infrastructure consolidation, platform rationalisation, and service modernisation initiatives. Strong understanding of high availability, disaster recovery, resilience, backup, and business continuity principles. Ability to assess technical solutions against business requirements and strategic objectives. Strong architecture governance, documentation, and design assurance experience. Excellent stakeholder engagement and communication skills. Experience working across multiple technical disciplines, including infrastructure, networking, cloud, identity, and workplace technologies. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
07/08/2026
Contractor
Infrastructure Architect Location: Remote (98% remote with very occasional travel to London or Manchester) Rate: 600 per day Duration: Contract until 30th June 2027 YOU MUST HOLD SC CLEARENCE WITH THE HOME OFFICE & HAVE NPPV3 CLEARANCE We are looking for an experienced Infrastructure Architect to join a major organisational transformation programme focused on bringing multiple organisations, business units, and user communities together under a unified Target Operating Model (TOM). Working as part of a multi-disciplinary transformation team, you will be responsible for defining, designing, and assuring the future-state infrastructure architecture that underpins consolidated services, platforms, and operating models. This role requires a strong blend of strategic architecture expertise, transformation experience, and stakeholder engagement skills to ensure infrastructure solutions are secure, resilient, scalable, and aligned to long-term business objectives. Infrastructure Architecture Strategy Develop and maintain the infrastructure architecture strategy supporting the Target Operating Model. Define the future-state infrastructure landscape across cloud, hosting, networking, end-user computing, identity, storage, and platform services. Ensure infrastructure architecture aligns with enterprise architecture principles, business objectives, and programme outcomes. Provide strategic architectural guidance throughout the transformation lifecycle. Transformation & Migration Support Work closely with programme teams to support the integration of multiple organisations into the target environment. Assess current-state infrastructure landscapes and identify opportunities for consolidation, optimisation, and standardisation. Support infrastructure transformation planning and migration activities. Ensure business continuity and operational stability throughout transition and implementation phases. Solution Design & Assurance Produce high-level and detailed infrastructure designs. Develop infrastructure standards, architectural patterns, and reference architectures. Review and assure solution designs delivered by internal teams, suppliers, and technical partners. Ensure designs meet security, availability, resilience, performance, and operational support requirements. Provide architecture governance and technical assurance across the programme. Platform & Service Alignment Define architectural requirements for hosting, connectivity, workplace technology, and platform services. Ensure infrastructure services support future operational and service management requirements. Align infrastructure architecture with service integration and operational readiness objectives. Support the successful adoption of shared platforms and infrastructure services. Cloud & Infrastructure Modernisation Define cloud adoption strategies and migration approaches where appropriate. Identify opportunities to modernise legacy infrastructure and improve operational efficiency. Promote infrastructure automation, Infrastructure as Code (IaC), and cloud-native design principles. Support the development of scalable and future-ready infrastructure capabilities. Security, Resilience & Compliance Ensure infrastructure solutions comply with security standards, policies, and regulatory requirements. Work closely with cyber security teams to embed secure-by-design principles. Support risk assessments, architecture reviews, and technical governance activities. Ensure solutions meet resilience, disaster recovery, backup, business continuity, and high-availability requirements. Stakeholder Engagement Collaborate with business stakeholders, technical teams, service providers, and programme leadership. Translate complex technical concepts into clear and understandable business language. Facilitate design workshops, architecture reviews, and stakeholder discussions. Support informed decision-making through robust architectural recommendations and assessments. Supplier & Partner Management Work closely with cloud providers, infrastructure suppliers, and technology partners. Ensure third-party solutions align with strategic architecture principles and target-state designs. Support technical governance across complex multi-vendor environments. Manage architecture dependencies associated with supplier-delivered services. Essential Skills & Experience Proven experience working as an Infrastructure Architect within complex enterprise environments. Experience supporting large-scale business or organisational transformation programmes. Strong knowledge of cloud technologies, including Azure, AWS, and/or Google Cloud Platform. Experience developing migration strategies, transformation roadmaps, and target-state architectures. Experience with infrastructure consolidation, platform rationalisation, and service modernisation initiatives. Strong understanding of high availability, disaster recovery, resilience, backup, and business continuity principles. Ability to assess technical solutions against business requirements and strategic objectives. Strong architecture governance, documentation, and design assurance experience. Excellent stakeholder engagement and communication skills. Experience working across multiple technical disciplines, including infrastructure, networking, cloud, identity, and workplace technologies. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments. As part of the Expleo UK Cybersecurity Practice, you will lead the delivery of product security, cyber assurance and secure-by-design activity for a major UK defence maritime programme, supporting an autonomous surface vessel capability being matured towards a whole-ship system design review. This is a senior, client-facing role requiring strong cybersecurity leadership, defence assurance experience, maritime or shipbuilding awareness, and the ability to embed security into complex engineering, platform, IT and OT environments. The platform is designed to operate crewless, which shifts the security centre of gravity from information confidentiality towards the safety and availability of operational technology, and makes the remote command-and-control link and position, navigation, and timing resilience the assets that matter most. You will act as the cyber authority within the client's integrated design team, owning the Security Management Plan and the coherence of the wider security artefact set, and directing the work of a security architect and a cybersecurity consultant. The role sits at the intersection of naval architecture, systems engineering, product security, information assurance and MOD/maritime cyber compliance. The role requires a strong blend of cybersecurity leadership, secure engineering, technical assurance, stakeholder management, governance, supplier oversight and defence regulatory experience. You will need to operate with autonomy, technical credibility and the ability to provide clear decision support to senior leaders. Own and maintain the Security Management Plan covering OT, IT and physical security, including the assurance and acceptance strategy, management of the supply chain and the route to demonstrating secure by design in accordance with UK MOD requirements. Act as the senior security authority within the client's integrated design team, providing direction, challenge and assurance across engineering and delivery activity. Develop the threat assessment and a proposed security risk appetite for agreement, in lieu of customer-supplied statements. Lead the preliminary security risk assessment and manage design risk exposure, proportionate to the design's maturity, through a live design risk register owned by and reported to the client delivery team. Produce the preliminary specification of security requirements and appropriate standards for OT, IT and physical security, including security classification and criticality assessment. Maintain traceability from threat to risk to control to requirement, so that every security requirement is justified and evidenced. Define supplier and supply chain security requirements and ensure they are embedded in specifications, delivery expectations and technical acceptance criteria. Review and assess supplier security deliverables, including security claims, compliance evidence, technical designs, assurance artefacts and software bills of materials. Direct and quality-assure the work of the security architect and cybersecurity consultant, ensuring the artefact set is coherent, traceable and defensible. Provide security input to formal engineering design reviews, including system design reviews and equivalent programme governance gates, prepare and present material, and close out resulting actions. Manage meetings with security stakeholders and represent the security position to senior client stakeholders and independent technical governance. Apply relevant MOD, NCSC, defence and maritime security frameworks to support assurance, accreditation and compliance activities, and reconcile the security position with the platform safety case. Generate a detailed scope of work for subsequent programme phases, and an outline scope for later phases. Produce clear technical assurance outputs, security design material, decision papers, risk statements, briefing notes and governance updates. Work independently as a senior subject matter expert, determining the day-to-day technical approach, stakeholder engagement and assurance rhythm required to achieve agreed outcomes. Relevant education or industry-recognised certifications in cybersecurity, information assurance, secure engineering, security architecture, risk management or a related discipline. Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CISA, CCP, ISO 27001 Lead Implementer/Lead Auditor, Security+, CySA+, SABSA, TOGAF, IEC 62443, NCSC CAF-related experience or equivalent professional experience. Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
06/08/2026
Full time
Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments. As part of the Expleo UK Cybersecurity Practice, you will lead the delivery of product security, cyber assurance and secure-by-design activity for a major UK defence maritime programme, supporting an autonomous surface vessel capability being matured towards a whole-ship system design review. This is a senior, client-facing role requiring strong cybersecurity leadership, defence assurance experience, maritime or shipbuilding awareness, and the ability to embed security into complex engineering, platform, IT and OT environments. The platform is designed to operate crewless, which shifts the security centre of gravity from information confidentiality towards the safety and availability of operational technology, and makes the remote command-and-control link and position, navigation, and timing resilience the assets that matter most. You will act as the cyber authority within the client's integrated design team, owning the Security Management Plan and the coherence of the wider security artefact set, and directing the work of a security architect and a cybersecurity consultant. The role sits at the intersection of naval architecture, systems engineering, product security, information assurance and MOD/maritime cyber compliance. The role requires a strong blend of cybersecurity leadership, secure engineering, technical assurance, stakeholder management, governance, supplier oversight and defence regulatory experience. You will need to operate with autonomy, technical credibility and the ability to provide clear decision support to senior leaders. Own and maintain the Security Management Plan covering OT, IT and physical security, including the assurance and acceptance strategy, management of the supply chain and the route to demonstrating secure by design in accordance with UK MOD requirements. Act as the senior security authority within the client's integrated design team, providing direction, challenge and assurance across engineering and delivery activity. Develop the threat assessment and a proposed security risk appetite for agreement, in lieu of customer-supplied statements. Lead the preliminary security risk assessment and manage design risk exposure, proportionate to the design's maturity, through a live design risk register owned by and reported to the client delivery team. Produce the preliminary specification of security requirements and appropriate standards for OT, IT and physical security, including security classification and criticality assessment. Maintain traceability from threat to risk to control to requirement, so that every security requirement is justified and evidenced. Define supplier and supply chain security requirements and ensure they are embedded in specifications, delivery expectations and technical acceptance criteria. Review and assess supplier security deliverables, including security claims, compliance evidence, technical designs, assurance artefacts and software bills of materials. Direct and quality-assure the work of the security architect and cybersecurity consultant, ensuring the artefact set is coherent, traceable and defensible. Provide security input to formal engineering design reviews, including system design reviews and equivalent programme governance gates, prepare and present material, and close out resulting actions. Manage meetings with security stakeholders and represent the security position to senior client stakeholders and independent technical governance. Apply relevant MOD, NCSC, defence and maritime security frameworks to support assurance, accreditation and compliance activities, and reconcile the security position with the platform safety case. Generate a detailed scope of work for subsequent programme phases, and an outline scope for later phases. Produce clear technical assurance outputs, security design material, decision papers, risk statements, briefing notes and governance updates. Work independently as a senior subject matter expert, determining the day-to-day technical approach, stakeholder engagement and assurance rhythm required to achieve agreed outcomes. Relevant education or industry-recognised certifications in cybersecurity, information assurance, secure engineering, security architecture, risk management or a related discipline. Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CISA, CCP, ISO 27001 Lead Implementer/Lead Auditor, Security+, CySA+, SABSA, TOGAF, IEC 62443, NCSC CAF-related experience or equivalent professional experience. Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
Assurance Engineer The Role: We are looking for a Senior or Principal Assurance Engineer to join the technology team at Synoptix. The technology team specialises in applying AI to solve challenges within complex systems, with expertise spanning object detection, neural network resilience, AI assurance, and the development of synthetic data. Through bespoke research and development programmes the team delivers high-grade AI systems and services for high-stakes environments. This role is about helping our customers design, justify and operate AI. You will produce defensible technical outputs, challenge weak assumptions and connect assurance evidence to real decisions about system design, deployment and operation. You will lead technically demanding client work, either working hands-on yourself or directing a project team. This is not primarily a governance, risk and compliance role. Nor are we looking for someone who treats compliance with standards as the end goal. Established standards and techniques will often guide the work. However, you must understand their purpose, limitations, and relevance to the system under consideration, particularly when working in situations where standards, processes, or accepted approaches have not yet been defined. Direct experience of AI assurance is desirable but not essential. We are looking for a broad range of assurance backgrounds, not just people who already work in AI assurance. You should have some exposure to AI or machine-learning systems or be able to demonstrate that you can learn unfamiliar technologies quickly and engage credibly with specialists. Key Experience: We are primarily interested in demonstrated experience, technical judgement and the quality of your thinking. You should have strong experience in at least one area relevant to the assurance or design of high-stakes systems. This might include: Safety engineering and safety cases Assurance cases and argument-based assurance High-integrity or safety-critical software AI verification, validation, testing or evaluation System safety and hazard analysis Software or system architecture Human factors and human-machine teaming Cybersecurity and resilience Quantitative risk, reliability or formal methods Operational monitoring and change assurance Clinical safety or healthcare technology assurance Another professional field involving difficult technical decisions with significant consequences We welcome candidates from a wide range of sectors including but not limited to defence, space, healthcare, nuclear or critical national infrastructure, but it is not essential. We also welcome transferable experience from aviation, automotive, rail, industrial automation and other high-integrity sectors. Day-to-Day tasking can include: Leading the technical delivery of assurance work for clients Developing assurance strategies and plans Structuring claims, arguments and supporting evidence Developing AI test and evaluation strategies Defining system requirements and design recommendations Developing operational monitoring and change-assurance approaches Reviewing and challenging evidence produced by clients or suppliers Producing reports that support senior technical and operational decisions Working with clients as a technical stakeholder Sharing and defending a proposed technical approach Leading technical discussions and contributing to workshops Challenging client or supplier assumptions constructively Building relationships while maintaining an independent technical position Supporting and developing the wider team, including both mentoring and supporting more junior engineers Develop partnerships with universities, research organisations, and industry collaborators to advance R&D opportunities and drive innovation Benefits: Annual Company Bonus Based on company performance 25 Days holiday not including bank holidays with the option to buy/sell up to 5 days Flexible hybrid working arrangements Continuous professional development including incentives Access to online Udemy training facility to support grade specific learning pathways Electric car scheme Bike to work scheme Private health care About Us: Synoptix was formed in 2011 to provide engineering solutions across various technical industries. We have evolved from a company established and focussed on Systems Thinking principles into an Engineering company providing solutions and services across three key capabilities: Systems, Cyber & InfoSec and Technology. What makes us stand out is how we engage in the crossover areas between these disciplines, combining our strengths to provide a truly bespoke, market leading approach. Our engineering competence is bolstered by expertise in commercial, legal, financial and resource, thereby ensuring that we uphold excellence in our product and service offerings. Please note that due to the nature of our projects we can only accept Sole UK National candidates who will need to be eligible to obtain UK Security Clearance. By applying to this position, you are confirming that you consent to the retention of your personal data. Your data is held securely on our own premises and under the terms of the Data Protection Act (2018). It will be treated as confidential, and will not be transferred to any third party, or to any other jurisdiction without your consent. We will not hold any data for any longer than is necessary for us to fulfil our obligations and will remove any data at your written request.
06/08/2026
Full time
Assurance Engineer The Role: We are looking for a Senior or Principal Assurance Engineer to join the technology team at Synoptix. The technology team specialises in applying AI to solve challenges within complex systems, with expertise spanning object detection, neural network resilience, AI assurance, and the development of synthetic data. Through bespoke research and development programmes the team delivers high-grade AI systems and services for high-stakes environments. This role is about helping our customers design, justify and operate AI. You will produce defensible technical outputs, challenge weak assumptions and connect assurance evidence to real decisions about system design, deployment and operation. You will lead technically demanding client work, either working hands-on yourself or directing a project team. This is not primarily a governance, risk and compliance role. Nor are we looking for someone who treats compliance with standards as the end goal. Established standards and techniques will often guide the work. However, you must understand their purpose, limitations, and relevance to the system under consideration, particularly when working in situations where standards, processes, or accepted approaches have not yet been defined. Direct experience of AI assurance is desirable but not essential. We are looking for a broad range of assurance backgrounds, not just people who already work in AI assurance. You should have some exposure to AI or machine-learning systems or be able to demonstrate that you can learn unfamiliar technologies quickly and engage credibly with specialists. Key Experience: We are primarily interested in demonstrated experience, technical judgement and the quality of your thinking. You should have strong experience in at least one area relevant to the assurance or design of high-stakes systems. This might include: Safety engineering and safety cases Assurance cases and argument-based assurance High-integrity or safety-critical software AI verification, validation, testing or evaluation System safety and hazard analysis Software or system architecture Human factors and human-machine teaming Cybersecurity and resilience Quantitative risk, reliability or formal methods Operational monitoring and change assurance Clinical safety or healthcare technology assurance Another professional field involving difficult technical decisions with significant consequences We welcome candidates from a wide range of sectors including but not limited to defence, space, healthcare, nuclear or critical national infrastructure, but it is not essential. We also welcome transferable experience from aviation, automotive, rail, industrial automation and other high-integrity sectors. Day-to-Day tasking can include: Leading the technical delivery of assurance work for clients Developing assurance strategies and plans Structuring claims, arguments and supporting evidence Developing AI test and evaluation strategies Defining system requirements and design recommendations Developing operational monitoring and change-assurance approaches Reviewing and challenging evidence produced by clients or suppliers Producing reports that support senior technical and operational decisions Working with clients as a technical stakeholder Sharing and defending a proposed technical approach Leading technical discussions and contributing to workshops Challenging client or supplier assumptions constructively Building relationships while maintaining an independent technical position Supporting and developing the wider team, including both mentoring and supporting more junior engineers Develop partnerships with universities, research organisations, and industry collaborators to advance R&D opportunities and drive innovation Benefits: Annual Company Bonus Based on company performance 25 Days holiday not including bank holidays with the option to buy/sell up to 5 days Flexible hybrid working arrangements Continuous professional development including incentives Access to online Udemy training facility to support grade specific learning pathways Electric car scheme Bike to work scheme Private health care About Us: Synoptix was formed in 2011 to provide engineering solutions across various technical industries. We have evolved from a company established and focussed on Systems Thinking principles into an Engineering company providing solutions and services across three key capabilities: Systems, Cyber & InfoSec and Technology. What makes us stand out is how we engage in the crossover areas between these disciplines, combining our strengths to provide a truly bespoke, market leading approach. Our engineering competence is bolstered by expertise in commercial, legal, financial and resource, thereby ensuring that we uphold excellence in our product and service offerings. Please note that due to the nature of our projects we can only accept Sole UK National candidates who will need to be eligible to obtain UK Security Clearance. By applying to this position, you are confirming that you consent to the retention of your personal data. Your data is held securely on our own premises and under the terms of the Data Protection Act (2018). It will be treated as confidential, and will not be transferred to any third party, or to any other jurisdiction without your consent. We will not hold any data for any longer than is necessary for us to fulfil our obligations and will remove any data at your written request.
Job Description: Salary Range: £44,171 - £61,950 Leonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity. Your impact Are you ready to take the next step in your testing career and lead the delivery of secure, high-quality test solutions? At Leonardo, our Senior Test Engineers combine deep technical knowledge with leadership, driving the design, execution, and assurance of tests that ensure our customers' systems are robust and mission-ready. Your work at Leonardo UK will see you take the lead in solving customer problems in an agile, innovative and team-centric manner. The role may involve a blended hybrid working model, with a mixture of working from home and working on site at one of our Leonardo offices to ensure close collaboration with the wider team and with our customers. Leonardo UK is seeking a Senior Test Engineer to join the Cyber & Security Solutions Division team. This role will see you working on the Emergency Services Mobile Communications Programme (ESMCP). You'll be working with a cross-functional team at Leonardo and with a wider multi-supplier delivery community to assure the successful delivery of the MC_linX Dispatcher capability for the Emergency Services Network (ESN). As a Senior Test Engineer, you will play a key role in assuring a mission-critical national capability that will support the transition of UK emergency services from the Airwave network to ESN. Working within an agile delivery environment, you will lead and execute testing activities across system, integration, interoperability, acceptance and non-functional test phases, ensuring that the solution meets demanding operational, security, performance and resilience requirements. You will be responsible for planning and coordinating test activities, developing and executing test cases, managing defects, and working collaboratively with customer representatives, partner organisations and development teams across the programme. The role requires a hands-on testing professional who is comfortable operating in complex stakeholder environments and who can confidently represent the test function during customer engagements, technical reviews and formal test events. This is an exciting opportunity to contribute to a secure cloud-hosted platform that will provide emergency service control rooms with a consolidated operational view of ESN users, helping to deliver resilient, standards-compliant communications capabilities that support public safety across the United Kingdom. What you will do as a Senior Test Engineer Lead the planning and execution of test work packages, including scope, effort estimates, and schedules. Represent the test function within a complex multi-supplier delivery environment, building effective relationships with customers, partners and engineering teams to achieve programme outcomes. Plan, coordinate and execute multi-party test activities involving the Home Office, customer representatives, partner organisations and third-party suppliers, ensuring successful end-to-end service integration. Support interoperability and interface testing across complex distributed systems, validating the exchange of data and services between multiple platforms and suppliers. Contribute to non-functional testing activities including security, performance, reliability, stability and usability testing to assure operational readiness of the service. Work closely with development and operational teams to support cloud-based software deliveries, test environments and service transition activities. Participate in customer-facing test events, workshops and formal assurance activities, providing clear communication of test progress, risks, defects and outcomes. Support service management and operational acceptance activities, ensuring testing evidence demonstrates that capacity, availability and service requirements can be achieved. Contribute to the development and adoption of automated testing approaches to improve quality, repeatability and delivery efficiency. Design, develop, and review test cases, scripts, and supporting documentation. Execute system, integration, and acceptance testing, ensuring alignment with customer requirements. Take ownership of defect management, collaborating with developers and stakeholders to ensure timely resolution. Mentor and guide Test Engineers and Technicians, supporting skills development and knowledge sharing. Conduct reviews of test deliverables to ensure accuracy, quality, and compliance with governance standards. Drive improvements in test practices, tools, and automation frameworks. Contribute to risk assessments, test strategies, and stakeholder reporting. What you'll bring Proven experience delivering functional, integration, system, acceptance and non-functional testing activities within complex software or systems integration programmes. Strong technical testing capability combined with the ability to lead test planning, execution and defect management activities across multiple workstreams. Experience working in customer-facing and multi-supplier environments, with the confidence to represent the test function during technical discussions, test events and stakeholder reviews. Excellent communication and collaboration skills, with the ability to build effective working relationships across engineering teams, customers and partner organisations. The ability to balance hands on technical testing with leadership responsibilities, mentoring others and contributing to wider test strategy and governance activities. The ideal candidate will be a confident and collaborative test professional who enjoys working directly with customers and partners to solve complex integration challenges. You will be comfortable operating in a fast-paced agile environment, balancing hands on testing with leadership responsibilities, and passionate about delivering high-quality, mission-critical services. Core areas (must have): Experience creating, executing and maintaining structured test plans, test cases and test evidence. Proven experience delivering system, integration, regression and user acceptance testing within complex software or systems integration programmes. Experience working within multi-supplier delivery environments, coordinating testing across organisational boundaries. Proficiency with defect management and test management tools (e.g. Jira, Xray, TestRail or Zephyr). Familiarity with test automation concepts and tooling, with experience contributing to automated testing approaches. Knowledge of non-functional testing disciplines, including security, performance, reliability, stability and usability testing. Understanding of secure software delivery practices and cyber security considerations within testing activities. Strong stakeholder engagement and communication skills, with the confidence to work directly with customers, suppliers and engineering teams Desirable: Familiarity with cloud-native software delivery and containerised environments (AWS, Kubernetes) Experience testing IT Service Management (ITSM) solutions and workflows, including ServiceNow Experience of interoperability and interface testing across integrated systems. ISTQB Advanced Level certification or equivalent experience Familiarity with cloud based software delivery and containerisation (e.g. AWS, Kubernetes) Awareness of ITIL practices or value streams relevant to service management Experience working with government departments or in secure project environments Experience contributing to multi party testing sessions Knowledge of non functional testing areas such as reliability, usability, security or stability Experience with performance, load, or penetration testing tools (e.g. JMeter, LoadRunner, OWASP ZAP) Knowledge of CI/CD and DevOps pipelines with integrated testing Familiarity with Agile/SAFe delivery and test automation in agile contexts Experience mentoring junior engineers and contributing to technical governance Security Clearance This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). For more information and guidance please visit: Location This role is predominantly based at the customer site in Hursley, with hybrid working on option. Your nominated Leonardo office will be at Southampton. Why join us At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we're here to help you thrive. Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year. . click apply for full job details
06/08/2026
Full time
Job Description: Salary Range: £44,171 - £61,950 Leonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity. Your impact Are you ready to take the next step in your testing career and lead the delivery of secure, high-quality test solutions? At Leonardo, our Senior Test Engineers combine deep technical knowledge with leadership, driving the design, execution, and assurance of tests that ensure our customers' systems are robust and mission-ready. Your work at Leonardo UK will see you take the lead in solving customer problems in an agile, innovative and team-centric manner. The role may involve a blended hybrid working model, with a mixture of working from home and working on site at one of our Leonardo offices to ensure close collaboration with the wider team and with our customers. Leonardo UK is seeking a Senior Test Engineer to join the Cyber & Security Solutions Division team. This role will see you working on the Emergency Services Mobile Communications Programme (ESMCP). You'll be working with a cross-functional team at Leonardo and with a wider multi-supplier delivery community to assure the successful delivery of the MC_linX Dispatcher capability for the Emergency Services Network (ESN). As a Senior Test Engineer, you will play a key role in assuring a mission-critical national capability that will support the transition of UK emergency services from the Airwave network to ESN. Working within an agile delivery environment, you will lead and execute testing activities across system, integration, interoperability, acceptance and non-functional test phases, ensuring that the solution meets demanding operational, security, performance and resilience requirements. You will be responsible for planning and coordinating test activities, developing and executing test cases, managing defects, and working collaboratively with customer representatives, partner organisations and development teams across the programme. The role requires a hands-on testing professional who is comfortable operating in complex stakeholder environments and who can confidently represent the test function during customer engagements, technical reviews and formal test events. This is an exciting opportunity to contribute to a secure cloud-hosted platform that will provide emergency service control rooms with a consolidated operational view of ESN users, helping to deliver resilient, standards-compliant communications capabilities that support public safety across the United Kingdom. What you will do as a Senior Test Engineer Lead the planning and execution of test work packages, including scope, effort estimates, and schedules. Represent the test function within a complex multi-supplier delivery environment, building effective relationships with customers, partners and engineering teams to achieve programme outcomes. Plan, coordinate and execute multi-party test activities involving the Home Office, customer representatives, partner organisations and third-party suppliers, ensuring successful end-to-end service integration. Support interoperability and interface testing across complex distributed systems, validating the exchange of data and services between multiple platforms and suppliers. Contribute to non-functional testing activities including security, performance, reliability, stability and usability testing to assure operational readiness of the service. Work closely with development and operational teams to support cloud-based software deliveries, test environments and service transition activities. Participate in customer-facing test events, workshops and formal assurance activities, providing clear communication of test progress, risks, defects and outcomes. Support service management and operational acceptance activities, ensuring testing evidence demonstrates that capacity, availability and service requirements can be achieved. Contribute to the development and adoption of automated testing approaches to improve quality, repeatability and delivery efficiency. Design, develop, and review test cases, scripts, and supporting documentation. Execute system, integration, and acceptance testing, ensuring alignment with customer requirements. Take ownership of defect management, collaborating with developers and stakeholders to ensure timely resolution. Mentor and guide Test Engineers and Technicians, supporting skills development and knowledge sharing. Conduct reviews of test deliverables to ensure accuracy, quality, and compliance with governance standards. Drive improvements in test practices, tools, and automation frameworks. Contribute to risk assessments, test strategies, and stakeholder reporting. What you'll bring Proven experience delivering functional, integration, system, acceptance and non-functional testing activities within complex software or systems integration programmes. Strong technical testing capability combined with the ability to lead test planning, execution and defect management activities across multiple workstreams. Experience working in customer-facing and multi-supplier environments, with the confidence to represent the test function during technical discussions, test events and stakeholder reviews. Excellent communication and collaboration skills, with the ability to build effective working relationships across engineering teams, customers and partner organisations. The ability to balance hands on technical testing with leadership responsibilities, mentoring others and contributing to wider test strategy and governance activities. The ideal candidate will be a confident and collaborative test professional who enjoys working directly with customers and partners to solve complex integration challenges. You will be comfortable operating in a fast-paced agile environment, balancing hands on testing with leadership responsibilities, and passionate about delivering high-quality, mission-critical services. Core areas (must have): Experience creating, executing and maintaining structured test plans, test cases and test evidence. Proven experience delivering system, integration, regression and user acceptance testing within complex software or systems integration programmes. Experience working within multi-supplier delivery environments, coordinating testing across organisational boundaries. Proficiency with defect management and test management tools (e.g. Jira, Xray, TestRail or Zephyr). Familiarity with test automation concepts and tooling, with experience contributing to automated testing approaches. Knowledge of non-functional testing disciplines, including security, performance, reliability, stability and usability testing. Understanding of secure software delivery practices and cyber security considerations within testing activities. Strong stakeholder engagement and communication skills, with the confidence to work directly with customers, suppliers and engineering teams Desirable: Familiarity with cloud-native software delivery and containerised environments (AWS, Kubernetes) Experience testing IT Service Management (ITSM) solutions and workflows, including ServiceNow Experience of interoperability and interface testing across integrated systems. ISTQB Advanced Level certification or equivalent experience Familiarity with cloud based software delivery and containerisation (e.g. AWS, Kubernetes) Awareness of ITIL practices or value streams relevant to service management Experience working with government departments or in secure project environments Experience contributing to multi party testing sessions Knowledge of non functional testing areas such as reliability, usability, security or stability Experience with performance, load, or penetration testing tools (e.g. JMeter, LoadRunner, OWASP ZAP) Knowledge of CI/CD and DevOps pipelines with integrated testing Familiarity with Agile/SAFe delivery and test automation in agile contexts Experience mentoring junior engineers and contributing to technical governance Security Clearance This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). For more information and guidance please visit: Location This role is predominantly based at the customer site in Hursley, with hybrid working on option. Your nominated Leonardo office will be at Southampton. Why join us At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we're here to help you thrive. Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year. . click apply for full job details