it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

39 jobs found

Email me jobs like this
Refine Search
Current Search
siem security engineer siem sc soc
Picture More Ltd
Cyber Security Engineer
Picture More Ltd Leeds, Yorkshire
Are you a hands-on Cyber Security Engineer looking to work with the latest security technologies and help shape a modern security function? We're working with a leading professional services firm that is looking to add an experienced Cyber Security Engineer to its growing team. Location: Leeds Working pattern: Hybrid - 3 days a week in the office Role type: Permanent Salary: Up to £60,000 plus benefits package This is a technical, hands-on role where you'll play a key part in protecting critical systems and data, while driving improvements across security operations, threat detection and incident response. You'll work with technologies including Microsoft Sentinel, Security Copilot and Azure, collaborating with internal IT teams and an outsourced SOC to strengthen security capabilities. You'll also have the opportunity to support AI-driven security initiatives and stay ahead of emerging threats, including AI and automated attack methods. We're looking for someone with: Experience in Cyber Security Operations, Incident Response or Threat Detection Strong hands-on experience with Microsoft Sentinel (SIEM) Experience with Microsoft Security Copilot or similar AI-assisted security tools Azure cloud security experience Experience working with an outsourced SOC/MDR provider Knowledge of modern cyber threats including ransomware, identity-based attacks and cloud security risks Relevant certifications such as SC-200, AZ-500, Security+, CySA+ or similar This is a great opportunity to join a collaborative team where you'll have the chance to make a real impact, work with leading security technologies, and contribute to the continued development of a modern cyber security capability.
24/08/2026
Full time
Are you a hands-on Cyber Security Engineer looking to work with the latest security technologies and help shape a modern security function? We're working with a leading professional services firm that is looking to add an experienced Cyber Security Engineer to its growing team. Location: Leeds Working pattern: Hybrid - 3 days a week in the office Role type: Permanent Salary: Up to £60,000 plus benefits package This is a technical, hands-on role where you'll play a key part in protecting critical systems and data, while driving improvements across security operations, threat detection and incident response. You'll work with technologies including Microsoft Sentinel, Security Copilot and Azure, collaborating with internal IT teams and an outsourced SOC to strengthen security capabilities. You'll also have the opportunity to support AI-driven security initiatives and stay ahead of emerging threats, including AI and automated attack methods. We're looking for someone with: Experience in Cyber Security Operations, Incident Response or Threat Detection Strong hands-on experience with Microsoft Sentinel (SIEM) Experience with Microsoft Security Copilot or similar AI-assisted security tools Azure cloud security experience Experience working with an outsourced SOC/MDR provider Knowledge of modern cyber threats including ransomware, identity-based attacks and cloud security risks Relevant certifications such as SC-200, AZ-500, Security+, CySA+ or similar This is a great opportunity to join a collaborative team where you'll have the chance to make a real impact, work with leading security technologies, and contribute to the continued development of a modern cyber security capability.
RecruitmentRevolution.com
IT Infrastructure & Cyber Security Engineer - 3rd Line, Cloud & AI
RecruitmentRevolution.com Mile End, Essex
Ready to Own More Than the Ticket Queue? You've built solid 3rd Line infrastructure experience. You know how to get to the bottom of complex technical problems, understand the importance of security and you're ready for more ownership. This could be that step. Join Bulk , one of Europe's leading active nutrition brands, and take ownership across the infrastructure and cyber security environment supporting our fast-moving digital business. You'll work across cloud, networks, endpoints and security, strengthen our email security, help lead our upcoming Cyber Essentials project and tackle the security challenges that come with our rapidly evolving use of AI. We're ahead of the curve when it comes to building with AI, so you'll get extensive exposure to new tools, integrations and systems - with the freedom to get involved in other technical projects as the business evolves. If you're a strong 3rd Line Engineer with cyber security credentials who's ready to broaden your remit and take genuine ownership, we'd love to hear from you. The Role at a Glance IT Infrastructure & Cyber Security Engineer Colchester, Essex Hybrid - 3 Days Office / 2 Days Home Occasional out-of-hours working and travel to London will be required. Competitive Salary + Excellent Benefits Full Time Permanent Focus: Infrastructure Cyber Security Cloud AI Enablement Your Background / Skills: 3rd Line Engineering, IT Infrastructure, Cyber Security, Azure, Google Workspace, Networking, CrowdStrike, Cisco, VMware vSphere, Windows Server, Jamf, Intune, Incident Response, Cyber Essentials, AI Tooling Who We Are Bulk is on an incredible journey, with a mission to evolve from a manufacturing-led retailer into a destination brand for active nutrition. We're shaking up the sports nutrition industry through innovative products, disruptive marketing and bold digital thinking that encourages people to see our brand differently. We want passionate risk-takers. People who challenge our thinking, live and breathe digital and aren't afraid to find a better way of doing things. And as our technology continues to evolve - particularly through AI - we need the infrastructure and security behind it to evolve just as quickly. The Opportunity As our IT Infrastructure & Cyber Security Engineer, you'll take ownership of Bulk's infrastructure and cyber security environment, supported by our IT Service Desk Team Lead and wider team. This is a broad, hands-on technical role with some clear priorities. You'll help upgrade our email security, manage the security aspects of AI integration and take a leading role in our Cyber Essentials project next year. You'll also oversee infrastructure, security tooling, incident response, budgeting and contracting, while becoming a Tier 3 escalation point for complex issues that need deeper technical expertise. And we're not expecting you to walk through the door knowing every technology on our list. We're looking for someone with strong infrastructure foundations and genuine cyber security capability who can demonstrate experience across roughly 80% of our technical environment, with the curiosity and ability to pick up the rest. What You'll Be Doing Infrastructure • Manage and maintain Bulk s on-premise and cloud infrastructure, including Azure, Google Workspace, networks, firewalls and VPNs. • Ensure systems are secure, reliable, resilient and up to date. • Lead infrastructure projects from planning through to deployment, including budgets and contracts. • Provide Tier 3 support for complex issues and maintain clear technical documentation and handovers. • Support wider technical projects as business requirements evolve. Cyber Security • Develop and improve Bulk s security environment, with particular focus on email security. • Monitor, investigate and respond to security threats, incidents and data breaches. • Manage and optimise security technologies including SIEM, SOAR, EDR/MDR/XDR, CASB, ZTNA and SASE. • Lead Cyber Essentials activity and support wider compliance, including ISO 27001. • Assess vendor security and work with stakeholders to implement secure technology solutions. AI Tooling & Security • Support the secure adoption and scaling of AI tools across Bulk. • Manage AI platforms including Claude Code, GitHub Copilot, Codex-style tools, MCP servers, integrations and connectors. • Own user access, permissions and governance, applying least-privilege principles. • Support teams onboarding new AI technologies, balancing innovation and productivity with security and compliance. • Develop appropriate controls as agentic AI, MCP and connector-based technologies evolve. About You You're probably already operating at strong 3rd Line Engineer level and looking for the opportunity to take broader ownership across infrastructure and cyber security. You enjoy getting hands-on with technology, but you're also interested in the bigger picture - resilience, security, risk, projects and how technology can enable the business to move faster. You don't need to tick every technology box. Breadth, strong foundations and the ability to learn matter here. You'll likely bring: • Around 2-3 years' experience in a similar role, operating at 3rd Line Engineer level or equivalent. • At least one cyber security certification. • Hands-on experience across approximately 80% of the technologies and environments outlined within this advert. • Strong infrastructure experience spanning cloud and on-premise environments. • Good working knowledge of Azure, Google Workspace, networking, endpoint management and security. • Experience across technologies such as CrowdStrike, Cisco, VMware vSphere, Windows Server, Mac/Windows, Jamf, Intune, Automox and VPNs. • Strong security monitoring, incident response and threat-analysis knowledge, including IOC investigation and remediation. • Experience or knowledge of security frameworks and compliance, ideally including Cyber Essentials and ISO 27001. • The confidence and technical capability to handle complex Tier 3 escalations. • Strong problem-solving skills and a proactive approach to improving infrastructure and security. • Excellent communication skills and the confidence to work with colleagues, suppliers and senior leadership. • Willingness to undertake occasional out-of-hours work and travel to London. Even Better If You Bring • Hands-on experience administering AI coding or agent tools, including Claude Code, GitHub Copilot or Codex. • Experience configuring MCP servers, connectors, permissions and access controls. • Familiarity with emerging agentic AI infrastructure and its associated security considerations. • Experience working with Netskope. • Hands-on Netskope CASB/SSE experience covering areas such as SSL/TLS inspection, DLP, Zero Trust architecture, CASB policy design and SCIM-based provisioning. • ITIL or project management certification such as PRINCE2. • Additional cyber security certifications such as CISSP, CISM or CompTIA. Why Join Bulk ? This is a great opportunity if you're ready to move beyond traditional 3rd Line support and build broader experience across infrastructure, cyber security and AI. You'll have genuine ownership, support from the wider IT team and exposure to a broad technology landscape within a business that's actively embracing new ways of working. Because Bulk is already pushing ahead with AI, you'll also be solving security and infrastructure challenges that many businesses haven't encountered yet. You'll also enjoy: • Monthly Bulk Bank Benefits Allowance, including subsidised gym membership. • 60% discount on Bulk products. • Birthday day off. • PerkBox subscription. • Flexi Start. • Optional additional annual leave. • Teammate pension scheme. • Life Assurance. • Medicash. • Volunteering day. • Cycle to Work Scheme. • Enhanced maternity and paternity leave. • Workplace nursery scheme. • Fully stocked Bulk Pantry. • Happy Hour drinks fridge on Thursdays and Fridays. • Summer working hours. • Hybrid working - 3 days in the Colchester office / 2 days from home. Your Experience / Background / Previous Roles May Include 3rd Line Engineer, Senior 3rd Line Engineer, Infrastructure Engineer, IT Infrastructure Engineer, Infrastructure & Security Engineer, IT Security Engineer, Systems & Security Engineer, Senior IT Engineer, Cloud Infrastructure Engineer, Cyber Security Engineer or Infrastructure Support Engineer. Apply Now If you've built strong 3rd Line foundations and you're ready for a role where you can take genuine ownership across infrastructure, cyber security and emerging AI technology, we'd love to hear from you. Bring your technical breadth, security mindset and curiosity about what's coming next - and help build the resilient, secure technology foundation behind Bulk's continued growth. Bulk is an equal opportunities employer and is committed to building a diverse and inclusive team. We welcome applications regardless of age, disability, race, gender, religion, sexual orientation, education, neurodiversity or any other protected characteristic. Application notice We take your privacy seriously . click apply for full job details
24/08/2026
Full time
Ready to Own More Than the Ticket Queue? You've built solid 3rd Line infrastructure experience. You know how to get to the bottom of complex technical problems, understand the importance of security and you're ready for more ownership. This could be that step. Join Bulk , one of Europe's leading active nutrition brands, and take ownership across the infrastructure and cyber security environment supporting our fast-moving digital business. You'll work across cloud, networks, endpoints and security, strengthen our email security, help lead our upcoming Cyber Essentials project and tackle the security challenges that come with our rapidly evolving use of AI. We're ahead of the curve when it comes to building with AI, so you'll get extensive exposure to new tools, integrations and systems - with the freedom to get involved in other technical projects as the business evolves. If you're a strong 3rd Line Engineer with cyber security credentials who's ready to broaden your remit and take genuine ownership, we'd love to hear from you. The Role at a Glance IT Infrastructure & Cyber Security Engineer Colchester, Essex Hybrid - 3 Days Office / 2 Days Home Occasional out-of-hours working and travel to London will be required. Competitive Salary + Excellent Benefits Full Time Permanent Focus: Infrastructure Cyber Security Cloud AI Enablement Your Background / Skills: 3rd Line Engineering, IT Infrastructure, Cyber Security, Azure, Google Workspace, Networking, CrowdStrike, Cisco, VMware vSphere, Windows Server, Jamf, Intune, Incident Response, Cyber Essentials, AI Tooling Who We Are Bulk is on an incredible journey, with a mission to evolve from a manufacturing-led retailer into a destination brand for active nutrition. We're shaking up the sports nutrition industry through innovative products, disruptive marketing and bold digital thinking that encourages people to see our brand differently. We want passionate risk-takers. People who challenge our thinking, live and breathe digital and aren't afraid to find a better way of doing things. And as our technology continues to evolve - particularly through AI - we need the infrastructure and security behind it to evolve just as quickly. The Opportunity As our IT Infrastructure & Cyber Security Engineer, you'll take ownership of Bulk's infrastructure and cyber security environment, supported by our IT Service Desk Team Lead and wider team. This is a broad, hands-on technical role with some clear priorities. You'll help upgrade our email security, manage the security aspects of AI integration and take a leading role in our Cyber Essentials project next year. You'll also oversee infrastructure, security tooling, incident response, budgeting and contracting, while becoming a Tier 3 escalation point for complex issues that need deeper technical expertise. And we're not expecting you to walk through the door knowing every technology on our list. We're looking for someone with strong infrastructure foundations and genuine cyber security capability who can demonstrate experience across roughly 80% of our technical environment, with the curiosity and ability to pick up the rest. What You'll Be Doing Infrastructure • Manage and maintain Bulk s on-premise and cloud infrastructure, including Azure, Google Workspace, networks, firewalls and VPNs. • Ensure systems are secure, reliable, resilient and up to date. • Lead infrastructure projects from planning through to deployment, including budgets and contracts. • Provide Tier 3 support for complex issues and maintain clear technical documentation and handovers. • Support wider technical projects as business requirements evolve. Cyber Security • Develop and improve Bulk s security environment, with particular focus on email security. • Monitor, investigate and respond to security threats, incidents and data breaches. • Manage and optimise security technologies including SIEM, SOAR, EDR/MDR/XDR, CASB, ZTNA and SASE. • Lead Cyber Essentials activity and support wider compliance, including ISO 27001. • Assess vendor security and work with stakeholders to implement secure technology solutions. AI Tooling & Security • Support the secure adoption and scaling of AI tools across Bulk. • Manage AI platforms including Claude Code, GitHub Copilot, Codex-style tools, MCP servers, integrations and connectors. • Own user access, permissions and governance, applying least-privilege principles. • Support teams onboarding new AI technologies, balancing innovation and productivity with security and compliance. • Develop appropriate controls as agentic AI, MCP and connector-based technologies evolve. About You You're probably already operating at strong 3rd Line Engineer level and looking for the opportunity to take broader ownership across infrastructure and cyber security. You enjoy getting hands-on with technology, but you're also interested in the bigger picture - resilience, security, risk, projects and how technology can enable the business to move faster. You don't need to tick every technology box. Breadth, strong foundations and the ability to learn matter here. You'll likely bring: • Around 2-3 years' experience in a similar role, operating at 3rd Line Engineer level or equivalent. • At least one cyber security certification. • Hands-on experience across approximately 80% of the technologies and environments outlined within this advert. • Strong infrastructure experience spanning cloud and on-premise environments. • Good working knowledge of Azure, Google Workspace, networking, endpoint management and security. • Experience across technologies such as CrowdStrike, Cisco, VMware vSphere, Windows Server, Mac/Windows, Jamf, Intune, Automox and VPNs. • Strong security monitoring, incident response and threat-analysis knowledge, including IOC investigation and remediation. • Experience or knowledge of security frameworks and compliance, ideally including Cyber Essentials and ISO 27001. • The confidence and technical capability to handle complex Tier 3 escalations. • Strong problem-solving skills and a proactive approach to improving infrastructure and security. • Excellent communication skills and the confidence to work with colleagues, suppliers and senior leadership. • Willingness to undertake occasional out-of-hours work and travel to London. Even Better If You Bring • Hands-on experience administering AI coding or agent tools, including Claude Code, GitHub Copilot or Codex. • Experience configuring MCP servers, connectors, permissions and access controls. • Familiarity with emerging agentic AI infrastructure and its associated security considerations. • Experience working with Netskope. • Hands-on Netskope CASB/SSE experience covering areas such as SSL/TLS inspection, DLP, Zero Trust architecture, CASB policy design and SCIM-based provisioning. • ITIL or project management certification such as PRINCE2. • Additional cyber security certifications such as CISSP, CISM or CompTIA. Why Join Bulk ? This is a great opportunity if you're ready to move beyond traditional 3rd Line support and build broader experience across infrastructure, cyber security and AI. You'll have genuine ownership, support from the wider IT team and exposure to a broad technology landscape within a business that's actively embracing new ways of working. Because Bulk is already pushing ahead with AI, you'll also be solving security and infrastructure challenges that many businesses haven't encountered yet. You'll also enjoy: • Monthly Bulk Bank Benefits Allowance, including subsidised gym membership. • 60% discount on Bulk products. • Birthday day off. • PerkBox subscription. • Flexi Start. • Optional additional annual leave. • Teammate pension scheme. • Life Assurance. • Medicash. • Volunteering day. • Cycle to Work Scheme. • Enhanced maternity and paternity leave. • Workplace nursery scheme. • Fully stocked Bulk Pantry. • Happy Hour drinks fridge on Thursdays and Fridays. • Summer working hours. • Hybrid working - 3 days in the Colchester office / 2 days from home. Your Experience / Background / Previous Roles May Include 3rd Line Engineer, Senior 3rd Line Engineer, Infrastructure Engineer, IT Infrastructure Engineer, Infrastructure & Security Engineer, IT Security Engineer, Systems & Security Engineer, Senior IT Engineer, Cloud Infrastructure Engineer, Cyber Security Engineer or Infrastructure Support Engineer. Apply Now If you've built strong 3rd Line foundations and you're ready for a role where you can take genuine ownership across infrastructure, cyber security and emerging AI technology, we'd love to hear from you. Bring your technical breadth, security mindset and curiosity about what's coming next - and help build the resilient, secure technology foundation behind Bulk's continued growth. Bulk is an equal opportunities employer and is committed to building a diverse and inclusive team. We welcome applications regardless of age, disability, race, gender, religion, sexual orientation, education, neurodiversity or any other protected characteristic. Application notice We take your privacy seriously . click apply for full job details
Experis IT
Senior SOC Engineer
Experis IT
Senior SecOps Engineer - Microsoft Security UK | Predominantly Remote | Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender/Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and Scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel/Azure Sentinel Microsoft Defender/Defender XDR Strong KQL/Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, Scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps/Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
24/08/2026
Full time
Senior SecOps Engineer - Microsoft Security UK | Predominantly Remote | Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender/Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and Scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel/Azure Sentinel Microsoft Defender/Defender XDR Strong KQL/Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, Scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps/Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Experis
Senior SOC Engineer
Experis
Senior SecOps Engineer - Microsoft Security UK Predominantly Remote Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure Sentinel Microsoft Defender / Defender XDR Strong KQL / Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps / Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
23/08/2026
Full time
Senior SecOps Engineer - Microsoft Security UK Predominantly Remote Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure Sentinel Microsoft Defender / Defender XDR Strong KQL / Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps / Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Tank Recruitment
Cyber Security Operations Specialist
Tank Recruitment Bath, Somerset
Cyber Security Operations Specialist We are looking for an experienced Cyber Security Operations Specialist to join a growing security team responsible for protecting a complex IT, cloud and operational technology environment. You will play a key role in detecting, investigating and responding to cyber threats, while helping to improve the organisation's overall security monitoring and incident response capabilities. The role combines hands-on security operations, tooling optimisation and continuous improvement across a varied technology estate. Key responsibilities: Monitor, triage and investigate security alerts and incidents across IT, cloud and OT environments. Lead or support incident response, including containment, eradication, recovery and escalation. Develop and optimise SIEM detection rules, EDR policies and security monitoring capabilities. Reduce false positives and improve detection coverage using threat intelligence and incident learnings. Investigate threats using frameworks such as MITRE ATT&CK. Work closely with internal IT, engineering and security teams, alongside external security providers. Maintain and improve security playbooks, procedures, documentation and response processes. Support security reporting, compliance and audit activity. Provide technical guidance and support to junior members of the security team. Key skills and experience: Strong background in Security Operations, SOC or Incident Response. Hands-on experience with SIEM and EDR platforms , ideally including Microsoft security technologies. Experience investigating security incidents across cloud and on-premise environments . Knowledge of Windows environments, with working knowledge of Linux/Unix. Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework . Experience improving detection logic, alert quality and security controls. Strong stakeholder communication and incident management skills. Knowledge of frameworks such as ISO 27001, NIS and GDPR would be beneficial. Desirable certifications include: SC-200, SC-300, SC-400, MS-500, Security+ or similar cyber security qualifications. The role will involve participation in an out-of-hours incident response rota , with occasional travel where required.
20/08/2026
Contractor
Cyber Security Operations Specialist We are looking for an experienced Cyber Security Operations Specialist to join a growing security team responsible for protecting a complex IT, cloud and operational technology environment. You will play a key role in detecting, investigating and responding to cyber threats, while helping to improve the organisation's overall security monitoring and incident response capabilities. The role combines hands-on security operations, tooling optimisation and continuous improvement across a varied technology estate. Key responsibilities: Monitor, triage and investigate security alerts and incidents across IT, cloud and OT environments. Lead or support incident response, including containment, eradication, recovery and escalation. Develop and optimise SIEM detection rules, EDR policies and security monitoring capabilities. Reduce false positives and improve detection coverage using threat intelligence and incident learnings. Investigate threats using frameworks such as MITRE ATT&CK. Work closely with internal IT, engineering and security teams, alongside external security providers. Maintain and improve security playbooks, procedures, documentation and response processes. Support security reporting, compliance and audit activity. Provide technical guidance and support to junior members of the security team. Key skills and experience: Strong background in Security Operations, SOC or Incident Response. Hands-on experience with SIEM and EDR platforms , ideally including Microsoft security technologies. Experience investigating security incidents across cloud and on-premise environments . Knowledge of Windows environments, with working knowledge of Linux/Unix. Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework . Experience improving detection logic, alert quality and security controls. Strong stakeholder communication and incident management skills. Knowledge of frameworks such as ISO 27001, NIS and GDPR would be beneficial. Desirable certifications include: SC-200, SC-300, SC-400, MS-500, Security+ or similar cyber security qualifications. The role will involve participation in an out-of-hours incident response rota , with occasional travel where required.
Nexere Consulting Limited
Senior Network Engineer - Palo Alto Firewalls - Network Infrastructure - Cyber Security - SIEM tools
Nexere Consulting Limited
Senior Network and Security Engineer - L2/L3 Network Infrastructure - Cyber Security - SIEM tools My client who are leaders in their field are looking for a Senior Cyber Security and Network Analyst to provide effective and timely operational support, development and management of the IT network and security infrastructure to meet business requirements and objectives. Responsibilities: Support the delivery and maintenance of the organisation's cyber security and network infrastructure, ensuring systems remain secure, resilient, and aligned to business needs Manage day-to-day security operations, including monitoring SIEM platforms, Firewalls, endpoint protection, and threat detection tools Investigate security incidents and vulnerabilities, recommending and implementing corrective actions where required Maintain and support network technologies including LAN/WAN, Wi-Fi, Internet connectivity, and Layer 2/3 infrastructure Contribute to cyber security and infrastructure projects, including the implementation of new security controls and technologies Perform patching, upgrades, and ongoing maintenance across security and network environments to minimise risk and downtime Develop and maintain security policies, operational procedures, technical documentation, and compliance standards Support disaster recovery and business continuity planning, testing, and readiness activities Key Experience & Skills: Palo Alto Firewalls and all associated NG services Endpoint detection and remediation Proven track record in Cyber security and understanding of cyber security analysis, tools and software Experience of implementing, supporting and developing L2/3 network infrastructure Qualys Vulnerability Management Aruba Wifi L2/3 switching - Cisco Nexus Network Load balancing Penetration Testing (3rd Party) Incident management Data Security
20/08/2026
Full time
Senior Network and Security Engineer - L2/L3 Network Infrastructure - Cyber Security - SIEM tools My client who are leaders in their field are looking for a Senior Cyber Security and Network Analyst to provide effective and timely operational support, development and management of the IT network and security infrastructure to meet business requirements and objectives. Responsibilities: Support the delivery and maintenance of the organisation's cyber security and network infrastructure, ensuring systems remain secure, resilient, and aligned to business needs Manage day-to-day security operations, including monitoring SIEM platforms, Firewalls, endpoint protection, and threat detection tools Investigate security incidents and vulnerabilities, recommending and implementing corrective actions where required Maintain and support network technologies including LAN/WAN, Wi-Fi, Internet connectivity, and Layer 2/3 infrastructure Contribute to cyber security and infrastructure projects, including the implementation of new security controls and technologies Perform patching, upgrades, and ongoing maintenance across security and network environments to minimise risk and downtime Develop and maintain security policies, operational procedures, technical documentation, and compliance standards Support disaster recovery and business continuity planning, testing, and readiness activities Key Experience & Skills: Palo Alto Firewalls and all associated NG services Endpoint detection and remediation Proven track record in Cyber security and understanding of cyber security analysis, tools and software Experience of implementing, supporting and developing L2/3 network infrastructure Qualys Vulnerability Management Aruba Wifi L2/3 switching - Cisco Nexus Network Load balancing Penetration Testing (3rd Party) Incident management Data Security
Technical Specialist - Detection, Engineering and Automation
Fidelity International
Technical Specialist - Detection, Engineering and Automation申请locations: Kingswood Fields Officetime type: Full timeposted on: 今天发布time left to apply: 结束日期:2026年7月31日 (申请时间还剩 30+ 天)job requisition id: J67604# About the Opportunity Job Type: PermanentApplication Deadline: 31 July 2026 Job Description Title Technical Specialist -Detection, Engineering and Automation Department FIL - Global Cybersecurity Operations Location Kingswood, Surrey Reports To Senior Manager - Detection, Engineering and Automation Level 4 We share a commitment to making things better for clients and each other. We continually explore new technology and different ways of working to put our clients first. So bring your boldest ideas to our Cyber Defense Operations team and feel like you're making progress. About your team Technology function across FIL is responsible for all global aspects of Technology, Digital, Cybersecurity, and Innovation. Fidelity is a value-driven, customer-obsessed organization and in Technology we are fortunate to play a direct role in helping our clients with one of the most important aspects of their lives - their financial well-being. Within the Technology function is our Global Cyber & Information Security (GCIS) that operates enterprise security services and controls. These are designed to mitigate Cyber and Information Security risks ensuring that Fidelity's business operates securely. The Technical Cybersecurity teams monitor both the internal and external threat environment, responding to security alerts and events in close to real time, as well as providing security assurance and access management services across the enterprise technology and business environment. Our global innovative Cyber Defence Operations team sits within GCIS and provides proactive, cutting-edge solutions to protect clients' digital assets and infrastructure against evolving cyber threats. The Detection Engineering & Automation team within our Global Cybersecurity Operations focuses on the development of automated detection capabilities to reduce manual effort of the Global Cybersecurity Operations team freeing up time to focus on real cyber threats. They ensure that security controls are performing effectively and efficiently and that they are feeding into automation technologies allowing the organisation to make intelligent correlated decisions. About your role The Detection Engineering & Automation Specialist plays a critical hands on role in strengthening the Global Cybersecurity Operations capability by building, maintaining and enhancing the security tooling that underpins our detection and response functions. The ideal candidate will work deeply across technologies including SIEM, SOAR, EDR, email security and cloud security platforms, contributing engineering expertise to ensure these controls operate effectively and deliver high quality telemetry. You will be responsible for developing and improving detections, building CI/CD pipelines, onboarding new log sources, implementing automation and supporting technical investigations during security incidents. The ideal candidate has experience using a wide range of security technologies to enhance detection coverage, streamline analyst workflows and support the ongoing maintenance and optimisation of critical security controls. This role is essential in supporting engineering maturity and ensuring our cyber defence capabilities remain modern, integrated and responsive to evolving threats. About you Key Responsibilities The Detection, Automation and Engineering Specialist will be responsible to: Build, maintain and enhance security detections using Sentinel as Code, ensuring accurate and high quality analytics. Develop and maintain CI/CD pipelines to automate deployment of detections, automation playbooks and configuration updates. Engineer and optimise SOAR automation and integrations to reduce manual analyst workload and streamline response processes. Onboard high value security logs into the SIEM from the backlog, ensuring quality, normalisation and integration into detection logic. Support SOC and CIRT during incidents by providing engineering expertise, rapid telemetry onboarding, and timely detection and automation enhancements. Maintain and improve security controls across SIEM, SOAR, EDR, email security and network detection tooling. Assess and implement tool updates, new features and product enhancements, ensuring their secure and effective adoption across the environment. Manage tooling related incidents with vendors and internal teams, ensuring business impact is known, communicated and minimised. Work with global engineering teams to deliver high priority backlog items and operational improvements. Collaborate with front line analysts to identify quick win improvements for detections, automation and tooling integrations. Produce clear documentation, reporting and quality checks to support engineering delivery and continuous improvement. Experience and Skills Required At least 4 years of experience working in a Detection Engineering function, or a combination of Detection Engineering and hands on engineering responsibilities within a SOC environment. Experience focusing on automation, engineering maturity and continuous improvement within security operations. Experience managing and maintaining security tools within a global environment, preferably within Financial Services. Hands on experience developing detections in Microsoft Sentinel, including strong KQL and detection as code practices. Proven ability to build and maintain CI/CD pipelines (Azure DevOps, GitHub Actions) for detection, automation and configuration deployments. Experience onboarding and operationalising new log sources into a SIEM, ensuring data quality, enrichment and alignment with detection logic. Practical experience engineering SIEM, SOAR or EDR platforms and improving their operational effectiveness. Experience supporting security incidents from an engineering perspective by enabling telemetry, building detections and enhancing automation under time pressure. Strong experience with cloud platforms, particularly AWS and Azure, including their native security telemetry and integrations. Experience with email security solutions (such as Proofpoint, Microsoft Defender for Office 365, or equivalent), with a solid understanding of how email telemetry can be used in detection engineering. Strong scripting skills (PowerShell, Python, Bash or JavaScript) for automation, integration and tooling improvements. Familiarity with YAML/JSON, IaC principles and modern automation frameworks. Knowledge of Azure and/or AWS cloud environments and their native security telemetry. Strong communication skills with the ability to take technical feedback from SOC/CIRT and translate it into meaningful engineering improvements. Analytical mindset with a passion for cybersecurity, process improvement and challenging inefficient workflows. Preferred Certifications: Microsoft SC 200, AZ 500, AWS Security Specialty, CySA+, SSCP, OSCP. Feel rewarded For starters, we'll offer you a comprehensive benefits package. We'll value your wellbeing and support your development. And we'll be as flexible as we can about where and when you work - finding a balance that works for all of us. It's all part of our commitment to making you feel motivated by the work you do and happy to be part of our team. For more about our work, our approach to dynamic working and how you could build your future here, visit For more about our work, our approach to dynamic working and how you could build your future here, visit As an international financial services organisation, we are in-scope of international regulations in the way that we carry out our work. This position is involved in work that is regulated by the FCA and/or the PRA and their Individual Conduct Rules (COCON) apply to it, along with any other regulation. We provide training on COCON and how it affects our employees. More information about COCON can be found in the Employment Handbook.
06/08/2026
Full time
Technical Specialist - Detection, Engineering and Automation申请locations: Kingswood Fields Officetime type: Full timeposted on: 今天发布time left to apply: 结束日期:2026年7月31日 (申请时间还剩 30+ 天)job requisition id: J67604# About the Opportunity Job Type: PermanentApplication Deadline: 31 July 2026 Job Description Title Technical Specialist -Detection, Engineering and Automation Department FIL - Global Cybersecurity Operations Location Kingswood, Surrey Reports To Senior Manager - Detection, Engineering and Automation Level 4 We share a commitment to making things better for clients and each other. We continually explore new technology and different ways of working to put our clients first. So bring your boldest ideas to our Cyber Defense Operations team and feel like you're making progress. About your team Technology function across FIL is responsible for all global aspects of Technology, Digital, Cybersecurity, and Innovation. Fidelity is a value-driven, customer-obsessed organization and in Technology we are fortunate to play a direct role in helping our clients with one of the most important aspects of their lives - their financial well-being. Within the Technology function is our Global Cyber & Information Security (GCIS) that operates enterprise security services and controls. These are designed to mitigate Cyber and Information Security risks ensuring that Fidelity's business operates securely. The Technical Cybersecurity teams monitor both the internal and external threat environment, responding to security alerts and events in close to real time, as well as providing security assurance and access management services across the enterprise technology and business environment. Our global innovative Cyber Defence Operations team sits within GCIS and provides proactive, cutting-edge solutions to protect clients' digital assets and infrastructure against evolving cyber threats. The Detection Engineering & Automation team within our Global Cybersecurity Operations focuses on the development of automated detection capabilities to reduce manual effort of the Global Cybersecurity Operations team freeing up time to focus on real cyber threats. They ensure that security controls are performing effectively and efficiently and that they are feeding into automation technologies allowing the organisation to make intelligent correlated decisions. About your role The Detection Engineering & Automation Specialist plays a critical hands on role in strengthening the Global Cybersecurity Operations capability by building, maintaining and enhancing the security tooling that underpins our detection and response functions. The ideal candidate will work deeply across technologies including SIEM, SOAR, EDR, email security and cloud security platforms, contributing engineering expertise to ensure these controls operate effectively and deliver high quality telemetry. You will be responsible for developing and improving detections, building CI/CD pipelines, onboarding new log sources, implementing automation and supporting technical investigations during security incidents. The ideal candidate has experience using a wide range of security technologies to enhance detection coverage, streamline analyst workflows and support the ongoing maintenance and optimisation of critical security controls. This role is essential in supporting engineering maturity and ensuring our cyber defence capabilities remain modern, integrated and responsive to evolving threats. About you Key Responsibilities The Detection, Automation and Engineering Specialist will be responsible to: Build, maintain and enhance security detections using Sentinel as Code, ensuring accurate and high quality analytics. Develop and maintain CI/CD pipelines to automate deployment of detections, automation playbooks and configuration updates. Engineer and optimise SOAR automation and integrations to reduce manual analyst workload and streamline response processes. Onboard high value security logs into the SIEM from the backlog, ensuring quality, normalisation and integration into detection logic. Support SOC and CIRT during incidents by providing engineering expertise, rapid telemetry onboarding, and timely detection and automation enhancements. Maintain and improve security controls across SIEM, SOAR, EDR, email security and network detection tooling. Assess and implement tool updates, new features and product enhancements, ensuring their secure and effective adoption across the environment. Manage tooling related incidents with vendors and internal teams, ensuring business impact is known, communicated and minimised. Work with global engineering teams to deliver high priority backlog items and operational improvements. Collaborate with front line analysts to identify quick win improvements for detections, automation and tooling integrations. Produce clear documentation, reporting and quality checks to support engineering delivery and continuous improvement. Experience and Skills Required At least 4 years of experience working in a Detection Engineering function, or a combination of Detection Engineering and hands on engineering responsibilities within a SOC environment. Experience focusing on automation, engineering maturity and continuous improvement within security operations. Experience managing and maintaining security tools within a global environment, preferably within Financial Services. Hands on experience developing detections in Microsoft Sentinel, including strong KQL and detection as code practices. Proven ability to build and maintain CI/CD pipelines (Azure DevOps, GitHub Actions) for detection, automation and configuration deployments. Experience onboarding and operationalising new log sources into a SIEM, ensuring data quality, enrichment and alignment with detection logic. Practical experience engineering SIEM, SOAR or EDR platforms and improving their operational effectiveness. Experience supporting security incidents from an engineering perspective by enabling telemetry, building detections and enhancing automation under time pressure. Strong experience with cloud platforms, particularly AWS and Azure, including their native security telemetry and integrations. Experience with email security solutions (such as Proofpoint, Microsoft Defender for Office 365, or equivalent), with a solid understanding of how email telemetry can be used in detection engineering. Strong scripting skills (PowerShell, Python, Bash or JavaScript) for automation, integration and tooling improvements. Familiarity with YAML/JSON, IaC principles and modern automation frameworks. Knowledge of Azure and/or AWS cloud environments and their native security telemetry. Strong communication skills with the ability to take technical feedback from SOC/CIRT and translate it into meaningful engineering improvements. Analytical mindset with a passion for cybersecurity, process improvement and challenging inefficient workflows. Preferred Certifications: Microsoft SC 200, AZ 500, AWS Security Specialty, CySA+, SSCP, OSCP. Feel rewarded For starters, we'll offer you a comprehensive benefits package. We'll value your wellbeing and support your development. And we'll be as flexible as we can about where and when you work - finding a balance that works for all of us. It's all part of our commitment to making you feel motivated by the work you do and happy to be part of our team. For more about our work, our approach to dynamic working and how you could build your future here, visit For more about our work, our approach to dynamic working and how you could build your future here, visit As an international financial services organisation, we are in-scope of international regulations in the way that we carry out our work. This position is involved in work that is regulated by the FCA and/or the PRA and their Individual Conduct Rules (COCON) apply to it, along with any other regulation. We provide training on COCON and how it affects our employees. More information about COCON can be found in the Employment Handbook.
Senior Security Operations Engineer New London
Risk Ledger
Risk Ledger is developing a network of connected organisations, all working together to defend against cybersecurity attacks in the supply chain. Organisations rely on us to establish trust, through sharing their security maturity and visualising the risks posed by their supply chain ecosystem. And we're already trusted by customers like ASOS, British Airways, BAE Systems and the NHS. We are putting together an amazing and talented team from a diverse set of backgrounds and skillsets to drive us towards our vision. Risk Ledger is built on the respect we have for one another and our users, united by our shared values and mission. Every one of us is still learning: it's how we grow as individuals. We're curious. We're ambitious. And we're humble and honest. At Risk Ledger, we aim high to find the best solutions we can and always put our users first. The team: You'll join the Director of Information Security supporting and collaborating with all parts of the business to deliver a secure environment enabling impactful outcomes for Risk Ledger and our customers. This role: As our Senior SecOps Engineer you'll be playing a critical part in maintaining and evolving the security of our product, business tools, people, and organisation. This is an opportunity to have a huge long-standing impact through improving our technical security strategy, which will lead to even greater success for our business and our customers. In the short to medium term, your focus will be on improving operational security capability - enhancing detection and response, incident management, vulnerability management and cloud security operations. As these capabilities mature, you'll increasingly focus on security engineering and architecture; designing scalable security services, improving our security platform and embedding secure-by-design principles across the organisation. From day one, you'll shape opportunities to empower our team by maintaining and improving the security of our tools and working practices for peak performance, all while safeguarding the confidentiality of our customers' data. Success hinges on collaboration, as you forge strong, trusted relationships across teams. In this role you will: Manage, build and mature our Security Operations capability (short to medium term) Own and continuously improve security monitoring, detection and incident response capabilities across our cloud, endpoint and SaaS environment. Build, tune, and maintain high-quality detections, reducing alert fatigue while increasing confidence that meaningful threats are identified quickly. Continuously improve vulnerability management through effective scanning, risk-based prioritisation, remediation and tracking. Improve our cloud security posture across AWS and GCP through strong identity management, telemetry, network security, encryption and continuous posture assessment. Develop and automate operational processes, playbooks and workflows that improve consistency and allow the team to scale efficiently. Support audit and compliance activities by ensuring operational controls are implemented, measurable and operating effectively. Evolve our Security Engineering capability (medium to long term) Design and engineer scalable security capabilities that improve visibility, detection, resilience and operational efficiency across the organisation. Architect and evolve our security telemetry and detection platform, transforming raw data into actionable security intelligence. Design security services, standards and reusable capabilities that can be adopted consistently across engineering teams. Lead technical security initiatives that improve the maturity of our security architecture and reduce long-term organisational risk. Partner closely with engineering teams to embed secure-by-design principles into systems and platforms. Evaluate emerging security technologies and identify opportunities to improve our overall security architecture through thoughtful adoption and automation. Help shape the long-term technical security roadmap alongside Engineering and Technology leadership. Across both areas Help secure and govern the organisation's use of AI technologies, reviewing new tooling, assessing risk and contributing to practical security guardrails. Mentor colleagues, provide technical leadership and act as a trusted escalation point during security incidents. Manage a varied portfolio of operational work, strategic improvements and technical projects, balancing immediate priorities with long-term objectives. Contribute wherever needed in a growing scale-up environment, helping improve the resilience and security of our products and services. You'll have: 5+ years' experience in Security Operations, Security Engineering or Incident Response, ideally within a customer-focused SaaS organisation. Strong hands-on experience securing cloud environments (AWS and/or GCP). Deep experience with security monitoring, SIEM platforms, EDR, detection engineering, alert triage and incident response. Experience building or improving operational security capabilities rather than simply operating existing tooling. Experience with security tooling including SIEM, EDR, DLP, MDM and cloud security platforms. Strong understanding of attacker techniques (MITRE ATT&CK) and how to translate them into effective detections. Experience with vulnerability management and security telemetry. Understanding of modern AI tooling, AI security risks and governance considerations. Good understanding of networking, distributed systems and cloud architectures. An interest in security architecture and building long-term security capabilities. You might have: Experience designing security architecture for cloud-native platforms. Experience building or operating detection engineering programmes. Threat hunting or purple team experience. Experience with CNAPP, CSPM or exposure management platforms. Experience with eBPF or modern observability tooling. Experience implementing security automation using SOAR or similar orchestration platforms. Knowledge of policy-as-code and security governance. Familiarity with supply chain security and software integrity. Experience evaluating AI/LLM security, agentic systems or model governance. You will be: An excellent communicator, able to produce clear incident reports, technical documentation and stakeholder updates. A pragmatic problem solver who balances operational needs with long-term improvements. Comfortable working through ambiguity and making sound technical decisions. Curious, with a desire to continually learn and improve both operational and engineering practices. Someone who enjoys building systems and capabilities that scale, rather than simply maintaining them. Collaborative and approachable, working as part of a team rather than in isolation. Able to balance short-term operational priorities with medium and long-term engineering and architectural outcomes. The perks: Generous EMI equity package 28 days annual leave + bank holidays Additional 30 days of unpaid leave per year to use as you wish Ad-hoc companywide time off over the festive period Private healthcare with AXA Insurance - including enhanced mental wellbeing coverage Hybrid working policy, typically 2-3 days in the office Enhanced family (parental) leave - gender-neutral policy, 12 weeks paid leave 5 days Caretaker's leave Enhanced occupational sick pay All the learning resources and books you want to aid in your personal development Regular socials to unwind and have some fun Salary range
06/08/2026
Full time
Risk Ledger is developing a network of connected organisations, all working together to defend against cybersecurity attacks in the supply chain. Organisations rely on us to establish trust, through sharing their security maturity and visualising the risks posed by their supply chain ecosystem. And we're already trusted by customers like ASOS, British Airways, BAE Systems and the NHS. We are putting together an amazing and talented team from a diverse set of backgrounds and skillsets to drive us towards our vision. Risk Ledger is built on the respect we have for one another and our users, united by our shared values and mission. Every one of us is still learning: it's how we grow as individuals. We're curious. We're ambitious. And we're humble and honest. At Risk Ledger, we aim high to find the best solutions we can and always put our users first. The team: You'll join the Director of Information Security supporting and collaborating with all parts of the business to deliver a secure environment enabling impactful outcomes for Risk Ledger and our customers. This role: As our Senior SecOps Engineer you'll be playing a critical part in maintaining and evolving the security of our product, business tools, people, and organisation. This is an opportunity to have a huge long-standing impact through improving our technical security strategy, which will lead to even greater success for our business and our customers. In the short to medium term, your focus will be on improving operational security capability - enhancing detection and response, incident management, vulnerability management and cloud security operations. As these capabilities mature, you'll increasingly focus on security engineering and architecture; designing scalable security services, improving our security platform and embedding secure-by-design principles across the organisation. From day one, you'll shape opportunities to empower our team by maintaining and improving the security of our tools and working practices for peak performance, all while safeguarding the confidentiality of our customers' data. Success hinges on collaboration, as you forge strong, trusted relationships across teams. In this role you will: Manage, build and mature our Security Operations capability (short to medium term) Own and continuously improve security monitoring, detection and incident response capabilities across our cloud, endpoint and SaaS environment. Build, tune, and maintain high-quality detections, reducing alert fatigue while increasing confidence that meaningful threats are identified quickly. Continuously improve vulnerability management through effective scanning, risk-based prioritisation, remediation and tracking. Improve our cloud security posture across AWS and GCP through strong identity management, telemetry, network security, encryption and continuous posture assessment. Develop and automate operational processes, playbooks and workflows that improve consistency and allow the team to scale efficiently. Support audit and compliance activities by ensuring operational controls are implemented, measurable and operating effectively. Evolve our Security Engineering capability (medium to long term) Design and engineer scalable security capabilities that improve visibility, detection, resilience and operational efficiency across the organisation. Architect and evolve our security telemetry and detection platform, transforming raw data into actionable security intelligence. Design security services, standards and reusable capabilities that can be adopted consistently across engineering teams. Lead technical security initiatives that improve the maturity of our security architecture and reduce long-term organisational risk. Partner closely with engineering teams to embed secure-by-design principles into systems and platforms. Evaluate emerging security technologies and identify opportunities to improve our overall security architecture through thoughtful adoption and automation. Help shape the long-term technical security roadmap alongside Engineering and Technology leadership. Across both areas Help secure and govern the organisation's use of AI technologies, reviewing new tooling, assessing risk and contributing to practical security guardrails. Mentor colleagues, provide technical leadership and act as a trusted escalation point during security incidents. Manage a varied portfolio of operational work, strategic improvements and technical projects, balancing immediate priorities with long-term objectives. Contribute wherever needed in a growing scale-up environment, helping improve the resilience and security of our products and services. You'll have: 5+ years' experience in Security Operations, Security Engineering or Incident Response, ideally within a customer-focused SaaS organisation. Strong hands-on experience securing cloud environments (AWS and/or GCP). Deep experience with security monitoring, SIEM platforms, EDR, detection engineering, alert triage and incident response. Experience building or improving operational security capabilities rather than simply operating existing tooling. Experience with security tooling including SIEM, EDR, DLP, MDM and cloud security platforms. Strong understanding of attacker techniques (MITRE ATT&CK) and how to translate them into effective detections. Experience with vulnerability management and security telemetry. Understanding of modern AI tooling, AI security risks and governance considerations. Good understanding of networking, distributed systems and cloud architectures. An interest in security architecture and building long-term security capabilities. You might have: Experience designing security architecture for cloud-native platforms. Experience building or operating detection engineering programmes. Threat hunting or purple team experience. Experience with CNAPP, CSPM or exposure management platforms. Experience with eBPF or modern observability tooling. Experience implementing security automation using SOAR or similar orchestration platforms. Knowledge of policy-as-code and security governance. Familiarity with supply chain security and software integrity. Experience evaluating AI/LLM security, agentic systems or model governance. You will be: An excellent communicator, able to produce clear incident reports, technical documentation and stakeholder updates. A pragmatic problem solver who balances operational needs with long-term improvements. Comfortable working through ambiguity and making sound technical decisions. Curious, with a desire to continually learn and improve both operational and engineering practices. Someone who enjoys building systems and capabilities that scale, rather than simply maintaining them. Collaborative and approachable, working as part of a team rather than in isolation. Able to balance short-term operational priorities with medium and long-term engineering and architectural outcomes. The perks: Generous EMI equity package 28 days annual leave + bank holidays Additional 30 days of unpaid leave per year to use as you wish Ad-hoc companywide time off over the festive period Private healthcare with AXA Insurance - including enhanced mental wellbeing coverage Hybrid working policy, typically 2-3 days in the office Enhanced family (parental) leave - gender-neutral policy, 12 weeks paid leave 5 days Caretaker's leave Enhanced occupational sick pay All the learning resources and books you want to aid in your personal development Regular socials to unwind and have some fun Salary range
Tank Recruitment
IT / Network Security Engineer
Tank Recruitment
IT & Network Security Engineer Job Title: IT Security Engineer Location: Oxfordshire - Hybrid (2 days per week on-site) Industry: Enterprise SaaS / Technology Solutions About the Role We are partnering with a rapidly scaling, globally active software and data platform enterprise looking to appoint a dedicated IT Security Engineer to join their growing security operations team. In this role, you will be instrumental in defending core infrastructure, enterprise networks, and critical data against modern cyber threats. Working closely with the Head of IT Security, you will oversee threat detection, manage security appliances, enforce compliance frameworks, and ensure that robust defensive postures are embedded across the technology stack. Key Responsibilities Security Operations: Oversee network telemetry for suspicious activities, execute rapid threat detection and response, tune perimeter defenses (firewalls and virtual private networks), and direct proactive patch management cycles. Compliance & Audits: Drive internal control testing and maintain alignment with structured information security standards such as ISO 27001, supporting both internal evaluations and external auditor walkthroughs. Incident Handling: Manage the end-to-end lifecycle of security alerts or breaches, lead formal root-cause analysis, and embed corrective actions into future preventive safeguards. Third-Party Risk: Evaluate external vendors and technology partners to ensure compliance with internal security policies and benchmark security standards. Cross-Functional Collaboration: Partner directly with IT infrastructure, application support, software engineering, and legal teams to bake security-by-design principles into technical architectures. Key Requirements Experience: A minimum of 3 to 5 years of dedicated professional experience within an IT or information security function. Technical Proficiency: Deep working knowledge of core network protocols (TCP/IP, DNS, routing, switching) and architecture design. Hands-on proficiency with network analysis utilities, packet sniffers, port scanners, and SIEM monitoring suites. Working familiarity with cryptographic methods, identity controls, endpoint hardening, and multi-cloud security management (AWS, Azure, or GCP). Framework Knowledge: Solid comprehension of ISO 27001 principles, threat modelling frameworks, vulnerability scanning, risk treatment life-cycles, and secondary compliance standards (e.g., SOC 2 or PCI DSS). Qualifications: Relevant technical diploma or equivalent practical background, reinforced by desirable professional credentials (such as CISSP, CEH, CCNA Security, or ISO 27001 Lead Auditor certifications). Personal Attributes: Strong analytical problem-solving skills, clear communication capabilities, and the adaptability to thrive in a fast-moving, collaborative environment. What is on Offer Competitive base salary package. Sustainable hybrid working model (2 days on-site in Oxfordshire). Continuous professional development and training opportunities within an expanding tech organisation. If you are a proactive security professional looking to make a meaningful impact, please submit your CV to begin a confidential discussion.
05/08/2026
Full time
IT & Network Security Engineer Job Title: IT Security Engineer Location: Oxfordshire - Hybrid (2 days per week on-site) Industry: Enterprise SaaS / Technology Solutions About the Role We are partnering with a rapidly scaling, globally active software and data platform enterprise looking to appoint a dedicated IT Security Engineer to join their growing security operations team. In this role, you will be instrumental in defending core infrastructure, enterprise networks, and critical data against modern cyber threats. Working closely with the Head of IT Security, you will oversee threat detection, manage security appliances, enforce compliance frameworks, and ensure that robust defensive postures are embedded across the technology stack. Key Responsibilities Security Operations: Oversee network telemetry for suspicious activities, execute rapid threat detection and response, tune perimeter defenses (firewalls and virtual private networks), and direct proactive patch management cycles. Compliance & Audits: Drive internal control testing and maintain alignment with structured information security standards such as ISO 27001, supporting both internal evaluations and external auditor walkthroughs. Incident Handling: Manage the end-to-end lifecycle of security alerts or breaches, lead formal root-cause analysis, and embed corrective actions into future preventive safeguards. Third-Party Risk: Evaluate external vendors and technology partners to ensure compliance with internal security policies and benchmark security standards. Cross-Functional Collaboration: Partner directly with IT infrastructure, application support, software engineering, and legal teams to bake security-by-design principles into technical architectures. Key Requirements Experience: A minimum of 3 to 5 years of dedicated professional experience within an IT or information security function. Technical Proficiency: Deep working knowledge of core network protocols (TCP/IP, DNS, routing, switching) and architecture design. Hands-on proficiency with network analysis utilities, packet sniffers, port scanners, and SIEM monitoring suites. Working familiarity with cryptographic methods, identity controls, endpoint hardening, and multi-cloud security management (AWS, Azure, or GCP). Framework Knowledge: Solid comprehension of ISO 27001 principles, threat modelling frameworks, vulnerability scanning, risk treatment life-cycles, and secondary compliance standards (e.g., SOC 2 or PCI DSS). Qualifications: Relevant technical diploma or equivalent practical background, reinforced by desirable professional credentials (such as CISSP, CEH, CCNA Security, or ISO 27001 Lead Auditor certifications). Personal Attributes: Strong analytical problem-solving skills, clear communication capabilities, and the adaptability to thrive in a fast-moving, collaborative environment. What is on Offer Competitive base salary package. Sustainable hybrid working model (2 days on-site in Oxfordshire). Continuous professional development and training opportunities within an expanding tech organisation. If you are a proactive security professional looking to make a meaningful impact, please submit your CV to begin a confidential discussion.
Tank Recruitment
Information Security & Compliance Lead (GRC)
Tank Recruitment
Information Security & Compliance Lead (GRC) Job Title: Information Security & Compliance Lead Location: Oxfordshire - Hybrid 2 days per week on site Industry: Enterprise SaaS / Technology Solutions About the Role We are partnering with a fast-growing, globally active software and data solutions enterprise looking to appoint an experienced Lead level Information Security & Compliance specialist (GRC). In this position, you will drive the operational security initiatives necessary to achieve and maintain formal security frameworks and attestation standards (including SOC 2 Type I/II lifecycles). You will translate complex trust criteria into practical, sustainable controls, bridge operational gaps, coordinate external audits, and elevate day-to-day security engineering across cloud platforms, products, and supply chains. Collaborating closely with engineering, product, legal, and operational teams, you will ensure security measures are robust, scalable, and integrated seamlessly without causing business friction. Key Responsibilities Assurance & Audit Management: Own the compliance roadmap from initial readiness assessments through to operating effectiveness and annual recurring audits; coordinate third-party auditors and evidence gathering. Control Engineering: Design, implement, and refine technical controls covering identity and access management, cloud security architecture, encryption, logging, monitoring, and endpoint protection. Risk & Governance: Maintain risk registers, execute supplier security due diligence, manage exception workflows, and deliver targeted security awareness programmes across internal teams. Vulnerability & Incident Operations: Strengthen patching schedules, penetration test remediation, secure change management, backup validation, and incident response procedures. Cross-Functional Collaboration: Partner with engineering and product groups to embed security-by-design principles into software delivery pipelines and operational workflows. Key Requirements Experience: Proven professional background delivering or materially supporting SOC 2 compliance readiness programmes or equivalent independent security audits within a cloud-first or SaaS environment. Technical Expertise: Hands-on experience engineering and testing security controls across major cloud infrastructure, IAM systems, endpoint tools, and SIEM monitoring platforms. Framework Knowledge: Strong working familiarity with trust service criteria, information security risk models (such as ISO 27001, NIST, or CIS benchmarks), and third-party risk principles. Competencies: Strong project ownership, excellent cross-functional communication skills, analytical rigor, and the ability to translate technical risk for diverse stakeholders. Qualifications: Relevant degree in Computer Science, Cyber Security, or equivalent practical experience, backed by recognized security or auditing certifications (such as CISSP, CISA, CCSP, or similar credentials).
05/08/2026
Full time
Information Security & Compliance Lead (GRC) Job Title: Information Security & Compliance Lead Location: Oxfordshire - Hybrid 2 days per week on site Industry: Enterprise SaaS / Technology Solutions About the Role We are partnering with a fast-growing, globally active software and data solutions enterprise looking to appoint an experienced Lead level Information Security & Compliance specialist (GRC). In this position, you will drive the operational security initiatives necessary to achieve and maintain formal security frameworks and attestation standards (including SOC 2 Type I/II lifecycles). You will translate complex trust criteria into practical, sustainable controls, bridge operational gaps, coordinate external audits, and elevate day-to-day security engineering across cloud platforms, products, and supply chains. Collaborating closely with engineering, product, legal, and operational teams, you will ensure security measures are robust, scalable, and integrated seamlessly without causing business friction. Key Responsibilities Assurance & Audit Management: Own the compliance roadmap from initial readiness assessments through to operating effectiveness and annual recurring audits; coordinate third-party auditors and evidence gathering. Control Engineering: Design, implement, and refine technical controls covering identity and access management, cloud security architecture, encryption, logging, monitoring, and endpoint protection. Risk & Governance: Maintain risk registers, execute supplier security due diligence, manage exception workflows, and deliver targeted security awareness programmes across internal teams. Vulnerability & Incident Operations: Strengthen patching schedules, penetration test remediation, secure change management, backup validation, and incident response procedures. Cross-Functional Collaboration: Partner with engineering and product groups to embed security-by-design principles into software delivery pipelines and operational workflows. Key Requirements Experience: Proven professional background delivering or materially supporting SOC 2 compliance readiness programmes or equivalent independent security audits within a cloud-first or SaaS environment. Technical Expertise: Hands-on experience engineering and testing security controls across major cloud infrastructure, IAM systems, endpoint tools, and SIEM monitoring platforms. Framework Knowledge: Strong working familiarity with trust service criteria, information security risk models (such as ISO 27001, NIST, or CIS benchmarks), and third-party risk principles. Competencies: Strong project ownership, excellent cross-functional communication skills, analytical rigor, and the ability to translate technical risk for diverse stakeholders. Qualifications: Relevant degree in Computer Science, Cyber Security, or equivalent practical experience, backed by recognized security or auditing certifications (such as CISSP, CISA, CCSP, or similar credentials).
Senior Platform Engineer (Cross Domain Gateway)
Leonardo S.p.A. Yeovil, Somerset
Senior Platform Engineer (Cross Domain Gateway)Applylocations: GB - Yeovil - Lysander Rdtime type: Full timeposted on: Posted Todayjob requisition id: R Job Description: Salary Range: £44,171 - £61,950Leonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity. Your Impact Are you ready to take on complex technical challenges supporting secure cross-domain services that protect national security? At Leonardo, our Senior Platform Engineers operate, maintain and improve secure gateway platforms that enable controlled information flow between security domains and keep our customers' missions running. Your work at Leonardo UK will see you take the lead in solving customer problems in an agile, innovative and team-centric manner. The role may involve a blended hybrid working model, with a mixture of working from home and working on site at one of our Leonardo offices to ensure close collaboration with the wider team and with our customers.Leonardo UK is seeking a Senior Platform Engineer to join the Cyber & Security Solutions Division team. This role is focused on operating, maintaining, assuring and improving secure cross-domain gateway services that underpin critical defence, government and public sector operations. What you will do as a Senior Platform Engineer Operate, maintain and support secure cross-domain gateway services across highly controlled environments. Monitor service health, investigate issues and support incident, problem and change activity in line with agreed service processes. Maintain secure configurations, transfer policies, rule sets and supporting documentation. Support patching, upgrades, vulnerability remediation and service continuity activities. Troubleshoot gateway, platform, network and data transfer issues across security boundaries. Produce and maintain operational documentation, including build records, support guides, runbooks and configuration baselines. Work with security, service management, engineering and customer stakeholders to ensure cross-domain services remain compliant, available and fit for purpose. Identify and deliver continuous service improvements to improve reliability, security and operational efficiency. What you'll bring Strong technical ability with experience operating and supporting secure platforms or gateway services in controlled environments. A disciplined service mindset, with the ability to balance hands-on technical support, assurance, documentation and continuous improvement. Confidence working across technical, security, service management and customer stakeholders to resolve issues and maintain service integrity. Core areas (must have): Cross-domain solutions: operation, support and controlled configuration of data transfer between security domains (e.g. high-to-low, restricted-to-enterprise) Windows and Linux operating systems Virtualisation platforms (VMware, Hyper-V) Secure data handling and policy enforcement (sanitisation, validation, filtering) Implementation of controlled and auditable data transfer mechanisms Networking concepts (TCP/IP, DNS, DHCP, firewalls) Automation and scripting (PowerShell, Bash, Python, Ansible, Terraform) Knowledge of cyber security controls and accreditation requirements Experience across the systems engineering lifecycle Design and assurance of secure data flows across trust boundaries Delivery within highly controlled / secure environments (e.g. cross-domain, air-gapped, defence) Incident, problem and change management Monitoring, patching, vulnerability remediation and service continuity Desirable: Experience with specific cross-domain or secure transfer products, such as Opswat or similar Data diode or one-way transfer architectures Integration with security tooling, such as SOC, SIEM or monitoring platforms Performance and throughput optimisation for secure data transfer systems Experience supporting service management processes, including incident, problem, change and configuration management Experience with cloud platforms, such as AWS or Azure, and Infrastructure as Code Hands-on use of DevSecOps tools, CI/CD pipelines or automation tooling Containerisation platforms, such as Kubernetes or Docker Security Clearance This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) will apply. This role requires Developed Vetting (DV) clearance prior to starting. For more information and guidance please visit: Location This role is based at our Yeovil site. Why join us At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Time to Recharge: Generous leave with the opportunity to accrue up to 12 additional flexi-days each year. Secure your Future: Award-winning pension scheme with up to 15% employer contribution. Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks. Never Stop Learning: Free access to 4,000+ online courses via Coursera and LinkedIn Learning. Tailored Perks: Spend up to £500 annually on flexible benefits such as private healthcare, lifestyle discounts, and gym memberships. Flexible Working: Flexible hours with hybrid working options.For a full list of our company benefits please visit our website. Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team-they are key contributors to shaping innovation, advancing technology, and enhancing global safety.At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know.Be part of something bigger - apply now!
05/08/2026
Full time
Senior Platform Engineer (Cross Domain Gateway)Applylocations: GB - Yeovil - Lysander Rdtime type: Full timeposted on: Posted Todayjob requisition id: R Job Description: Salary Range: £44,171 - £61,950Leonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity. Your Impact Are you ready to take on complex technical challenges supporting secure cross-domain services that protect national security? At Leonardo, our Senior Platform Engineers operate, maintain and improve secure gateway platforms that enable controlled information flow between security domains and keep our customers' missions running. Your work at Leonardo UK will see you take the lead in solving customer problems in an agile, innovative and team-centric manner. The role may involve a blended hybrid working model, with a mixture of working from home and working on site at one of our Leonardo offices to ensure close collaboration with the wider team and with our customers.Leonardo UK is seeking a Senior Platform Engineer to join the Cyber & Security Solutions Division team. This role is focused on operating, maintaining, assuring and improving secure cross-domain gateway services that underpin critical defence, government and public sector operations. What you will do as a Senior Platform Engineer Operate, maintain and support secure cross-domain gateway services across highly controlled environments. Monitor service health, investigate issues and support incident, problem and change activity in line with agreed service processes. Maintain secure configurations, transfer policies, rule sets and supporting documentation. Support patching, upgrades, vulnerability remediation and service continuity activities. Troubleshoot gateway, platform, network and data transfer issues across security boundaries. Produce and maintain operational documentation, including build records, support guides, runbooks and configuration baselines. Work with security, service management, engineering and customer stakeholders to ensure cross-domain services remain compliant, available and fit for purpose. Identify and deliver continuous service improvements to improve reliability, security and operational efficiency. What you'll bring Strong technical ability with experience operating and supporting secure platforms or gateway services in controlled environments. A disciplined service mindset, with the ability to balance hands-on technical support, assurance, documentation and continuous improvement. Confidence working across technical, security, service management and customer stakeholders to resolve issues and maintain service integrity. Core areas (must have): Cross-domain solutions: operation, support and controlled configuration of data transfer between security domains (e.g. high-to-low, restricted-to-enterprise) Windows and Linux operating systems Virtualisation platforms (VMware, Hyper-V) Secure data handling and policy enforcement (sanitisation, validation, filtering) Implementation of controlled and auditable data transfer mechanisms Networking concepts (TCP/IP, DNS, DHCP, firewalls) Automation and scripting (PowerShell, Bash, Python, Ansible, Terraform) Knowledge of cyber security controls and accreditation requirements Experience across the systems engineering lifecycle Design and assurance of secure data flows across trust boundaries Delivery within highly controlled / secure environments (e.g. cross-domain, air-gapped, defence) Incident, problem and change management Monitoring, patching, vulnerability remediation and service continuity Desirable: Experience with specific cross-domain or secure transfer products, such as Opswat or similar Data diode or one-way transfer architectures Integration with security tooling, such as SOC, SIEM or monitoring platforms Performance and throughput optimisation for secure data transfer systems Experience supporting service management processes, including incident, problem, change and configuration management Experience with cloud platforms, such as AWS or Azure, and Infrastructure as Code Hands-on use of DevSecOps tools, CI/CD pipelines or automation tooling Containerisation platforms, such as Kubernetes or Docker Security Clearance This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) will apply. This role requires Developed Vetting (DV) clearance prior to starting. For more information and guidance please visit: Location This role is based at our Yeovil site. Why join us At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Time to Recharge: Generous leave with the opportunity to accrue up to 12 additional flexi-days each year. Secure your Future: Award-winning pension scheme with up to 15% employer contribution. Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks. Never Stop Learning: Free access to 4,000+ online courses via Coursera and LinkedIn Learning. Tailored Perks: Spend up to £500 annually on flexible benefits such as private healthcare, lifestyle discounts, and gym memberships. Flexible Working: Flexible hours with hybrid working options.For a full list of our company benefits please visit our website. Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team-they are key contributors to shaping innovation, advancing technology, and enhancing global safety.At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know.Be part of something bigger - apply now!
Operations Advisor, Cyber Defense Operations
Cyderes
We Help the World Be Everyday Ready Today's threatscape is relentless. So are we. At Cyderes, we build practical Identity & Access Management (IAM), Exposure Management, and risk programs, helping organizations stop active threats fast with Managed Detection & Response (MDR)that integrates with existing tools. Powering it all is Meridian, our entity fabric that connects identities, assets, and access into one trusted reality. Augmented by AI and driven by seasoned operators, our tireless global team arms organizations with the people, platforms, and perspectives they need to conquer whatever tomorrow throws their way. Great Place to Work Certified United States Canada United Kingdom India Role Summary The Operations Advisor is the primary technical owner of detection outcomes for assigned clients. You improve detection quality, identify gaps in coverage, and advance client security maturity through expert-level advisory and hands-on detection engineering. You lead the technical account relationship, and you deliver measurable outcomes that clients can see and trust. This role reports to Manager, Cyber Defense Operations Responsibilities Own and maintain detection coverage aligned to the Cyderes Rule Set Lead tuning and optimization of detection rules across SIEM platforms Identify, prioritize, and remediate detection gaps Be a trusted advisor on detection strategy and operational effectiveness Identify detection improvements based on real-world incident insights Partner with SOC and DFIR teams during escalations Oversee the technical account relationship for assigned clients Lead technical cadence calls focused on detection performance, gaps, and outcomes Translate technical findings into risk-based, business-relevant insights Guide clients on prioritization of improvements based on detection impact Be a trusted advisor on detection strategy and operational effectiveness Requirements 3-5 years of experience in detection engineering, security operations, or a related discipline Hands-on proficiency with one or more enterprise SIEM platforms (Splunk, Microsoft Sentinel, Chronicle, or equivalent) Demonstrated experience writing and tuning detection rules in production environments Experience in a managed security services or MSSP environment serving multiple clients Proficiency in multiple SIEM query languages (SPL, KQL, YARA-L, or similar) Familiarity with SOAR platforms and automation-assisted detection workflows Experience with threat hunting methodologies and retrohunt program execution Relevant certifications: GCIA, GCIH, GCDA, or SIEM vendor certifications WHY CYDERES? Benefits that go beyond the basics, we support our people so they can do their best work. Medical Insurance - Employee covered Life Insurance -Protection for what matters most Retirement Match Program - We invest in your future Hybrid Work Model -2-3 days in office Maternity & Paternity Leave-Time for the moments that matter Paid Time Off -PTO+ sick & casual leave Bereavement & Volunteer Time - Giveback to your community Professional Development -Reimbursement program LinkedIn L&D Platform -Thousands of coursesat your fingertips Mobile Phone Reimbursement -Stay connected, on us Cyderes is an Equal Opportunity Employer (EOE). Qualified applicants are considered for employment without regard to race, religion, color, sex, age, disability, sexual orientation, genetic information, national origin, or veteran status. Note: This job posting is intended for direct applicants only. We request that outside recruiters do not contact us regarding this position.
04/08/2026
Full time
We Help the World Be Everyday Ready Today's threatscape is relentless. So are we. At Cyderes, we build practical Identity & Access Management (IAM), Exposure Management, and risk programs, helping organizations stop active threats fast with Managed Detection & Response (MDR)that integrates with existing tools. Powering it all is Meridian, our entity fabric that connects identities, assets, and access into one trusted reality. Augmented by AI and driven by seasoned operators, our tireless global team arms organizations with the people, platforms, and perspectives they need to conquer whatever tomorrow throws their way. Great Place to Work Certified United States Canada United Kingdom India Role Summary The Operations Advisor is the primary technical owner of detection outcomes for assigned clients. You improve detection quality, identify gaps in coverage, and advance client security maturity through expert-level advisory and hands-on detection engineering. You lead the technical account relationship, and you deliver measurable outcomes that clients can see and trust. This role reports to Manager, Cyber Defense Operations Responsibilities Own and maintain detection coverage aligned to the Cyderes Rule Set Lead tuning and optimization of detection rules across SIEM platforms Identify, prioritize, and remediate detection gaps Be a trusted advisor on detection strategy and operational effectiveness Identify detection improvements based on real-world incident insights Partner with SOC and DFIR teams during escalations Oversee the technical account relationship for assigned clients Lead technical cadence calls focused on detection performance, gaps, and outcomes Translate technical findings into risk-based, business-relevant insights Guide clients on prioritization of improvements based on detection impact Be a trusted advisor on detection strategy and operational effectiveness Requirements 3-5 years of experience in detection engineering, security operations, or a related discipline Hands-on proficiency with one or more enterprise SIEM platforms (Splunk, Microsoft Sentinel, Chronicle, or equivalent) Demonstrated experience writing and tuning detection rules in production environments Experience in a managed security services or MSSP environment serving multiple clients Proficiency in multiple SIEM query languages (SPL, KQL, YARA-L, or similar) Familiarity with SOAR platforms and automation-assisted detection workflows Experience with threat hunting methodologies and retrohunt program execution Relevant certifications: GCIA, GCIH, GCDA, or SIEM vendor certifications WHY CYDERES? Benefits that go beyond the basics, we support our people so they can do their best work. Medical Insurance - Employee covered Life Insurance -Protection for what matters most Retirement Match Program - We invest in your future Hybrid Work Model -2-3 days in office Maternity & Paternity Leave-Time for the moments that matter Paid Time Off -PTO+ sick & casual leave Bereavement & Volunteer Time - Giveback to your community Professional Development -Reimbursement program LinkedIn L&D Platform -Thousands of coursesat your fingertips Mobile Phone Reimbursement -Stay connected, on us Cyderes is an Equal Opportunity Employer (EOE). Qualified applicants are considered for employment without regard to race, religion, color, sex, age, disability, sexual orientation, genetic information, national origin, or veteran status. Note: This job posting is intended for direct applicants only. We request that outside recruiters do not contact us regarding this position.
Morson Edge
Secuity Operations Lead
Morson Edge
Our client Scottish Power are looking for a Security Operations Lead for an initial 12 month contract role, which will in all likelihood extend further. This is based at the client offices in Glasgow, working hybrid, 3 days in the office. SP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations and deliver a cyber resilient business, the Security Operations Lead will be essential in achieving our goals. The Security Operations Lead will be a subject matter expert on security incident detection and response. They will drive continuous improvement across the outsourced SOC and in-house SOC teams of analysts and engineers. Youll have experience of configuring SIEM tools, onboarding sources, writing processes and alerts, understanding business environments and managing incidents affecting applications and infrastructure across a varied technology stack spanning operational technology and information technology environments. You ll also be able to undertake post incident reviews to identify root causes and put follow-up mitigations in place. The postholder will work within a security operations team containing various cyber security functions such as threat intelligence, identity & access management, response & recovery and vulnerability management. What Youll be doing Support the Security Operations Manager in the running of BAU activities Implement and maintain 3rd line security incident / event management, escalation and technical response process and investigate suspected and actual incidents / events. Acting as a key escalation point in the team to the relevant team/individual Design, implement, manage, monitor, and upgrade security measures for the protections of the information systems and networks Identify and feedback any potential improvements from a cyber perspective to OT systems and infrastructure Ensuring incident identification, assessment, quantification, reporting, communication, mitigation and monitoring Ensuring compliance to policy, process, and procedure adherence and process improvisation to achieve operational objectives Revise and develop processes to strengthen the current Security Operations Framework Review policies and highlight the challenges in managing SLAs Ensuring daily management, administration & maintenance of security technology to achieve operational effectiveness Ensure the orchestration and integration of security services and platforms to maximise its usage and coverage The role will be integrated into an active and ambitious global cyber security function, contributing to SPEN s cyber security purpose of delivering cyber resilient OT and IT, to enable a safe and reliable electricity supply to customers What Youll bring Skills and experience in understanding at a technical level security operations. Awareness of key legislation and regulation impacting IT/OT General Control requirements in an energy utility. Experience in working within a SOC. Record of academic achievement, including some form of recognised qualification from further education, such as a degree or diploma. Good oral and written communication skills. Must be a proven team player to work, promote and consolidate efficient team working relationships.
04/08/2026
Contractor
Our client Scottish Power are looking for a Security Operations Lead for an initial 12 month contract role, which will in all likelihood extend further. This is based at the client offices in Glasgow, working hybrid, 3 days in the office. SP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations and deliver a cyber resilient business, the Security Operations Lead will be essential in achieving our goals. The Security Operations Lead will be a subject matter expert on security incident detection and response. They will drive continuous improvement across the outsourced SOC and in-house SOC teams of analysts and engineers. Youll have experience of configuring SIEM tools, onboarding sources, writing processes and alerts, understanding business environments and managing incidents affecting applications and infrastructure across a varied technology stack spanning operational technology and information technology environments. You ll also be able to undertake post incident reviews to identify root causes and put follow-up mitigations in place. The postholder will work within a security operations team containing various cyber security functions such as threat intelligence, identity & access management, response & recovery and vulnerability management. What Youll be doing Support the Security Operations Manager in the running of BAU activities Implement and maintain 3rd line security incident / event management, escalation and technical response process and investigate suspected and actual incidents / events. Acting as a key escalation point in the team to the relevant team/individual Design, implement, manage, monitor, and upgrade security measures for the protections of the information systems and networks Identify and feedback any potential improvements from a cyber perspective to OT systems and infrastructure Ensuring incident identification, assessment, quantification, reporting, communication, mitigation and monitoring Ensuring compliance to policy, process, and procedure adherence and process improvisation to achieve operational objectives Revise and develop processes to strengthen the current Security Operations Framework Review policies and highlight the challenges in managing SLAs Ensuring daily management, administration & maintenance of security technology to achieve operational effectiveness Ensure the orchestration and integration of security services and platforms to maximise its usage and coverage The role will be integrated into an active and ambitious global cyber security function, contributing to SPEN s cyber security purpose of delivering cyber resilient OT and IT, to enable a safe and reliable electricity supply to customers What Youll bring Skills and experience in understanding at a technical level security operations. Awareness of key legislation and regulation impacting IT/OT General Control requirements in an energy utility. Experience in working within a SOC. Record of academic achievement, including some form of recognised qualification from further education, such as a degree or diploma. Good oral and written communication skills. Must be a proven team player to work, promote and consolidate efficient team working relationships.
ALOIS TECHNOLOGIES LIMITED
Interim Cyber Security Officer
ALOIS TECHNOLOGIES LIMITED
Job Description Job Title Interim Cyber Security Officer (Senior Cyber Security Engineer) Contract Details Contract Length: 6 Months Start Date: March 2026 Location: London (Hybrid/On-site as required) IR35 Status: Inside IR35 Daily Rate: Up to 500 per day (Umbrella) Overview We are seeking an experienced Senior Cyber Security Engineer to join a Cyber Security team on an interim contract. This role will provide senior technical expertise to support and optimise an outsourced Security Operations Centre (SOC), ensuring the organisation maximises its investment in security technologies while strengthening its cyber defence capabilities. The successful candidate will have extensive hands-on experience with CrowdStrike Falcon and Splunk Enterprise Security , with the ability to enhance security monitoring, improve incident response processes, support threat hunting activities, and mentor internal team members. Key Responsibilities Lead the deployment, configuration, administration, and ongoing optimisation of the CrowdStrike Falcon platform, ensuring endpoint security policies are effectively implemented and maintained. Work closely with the outsourced Security Operations Centre to develop and enhance Splunk dashboards, alerts, data models, and monitoring capabilities, enabling the identification and investigation of sophisticated cyber threats. Act as the senior technical escalation point for complex and high-priority cyber security incidents, utilising Endpoint Detection and Response (EDR) and Security Information and Event Management (SIEM) technologies to support rapid investigation, containment, and remediation. Design, develop, and improve Security Orchestration, Automation and Response (SOAR) workflows to reduce manual effort, improve operational efficiency, and accelerate incident response. Conduct proactive threat hunting activities using advanced search techniques and security telemetry to identify malicious activity that may have evaded automated detection. Support vulnerability assessment activities and contribute to security testing initiatives, including exposure to penetration testing and web application security assessments. Develop and maintain cyber security policies, standards, and technical documentation to support governance and operational best practice. Provide technical guidance, mentoring, and knowledge transfer to existing cyber security team members, strengthening internal capability across CrowdStrike, Splunk, and security operations. Collaborate with internal stakeholders and external partners to continuously improve cyber security monitoring, detection, and response capabilities. Maintain awareness of emerging cyber threats, vulnerabilities, and industry best practices to ensure security controls remain effective and up to date. Essential Requirements Applicants must have a minimum of five years' experience working in a dedicated Cyber Security Engineering or SOC Tier 3 environment. Extensive hands-on experience administering and supporting CrowdStrike Falcon , including Falcon Prevent, Falcon Insight, and Falcon Discover, is essential. Strong experience working with Splunk Enterprise Security , including writing complex Search Processing Language (SPL) queries, developing dashboards, alerts, reports, and managing security data. Experience supporting Security Operations Centres, incident response, endpoint detection and response, security monitoring, and threat hunting activities. Excellent understanding of network protocols, cyber attack methodologies, security monitoring techniques, and the MITRE ATT&CK Framework . Good knowledge of cloud security principles across Microsoft Azure and/or AWS environments. Strong analytical, troubleshooting, communication, and stakeholder management skills with the ability to work independently and manage multiple priorities. Desirable Experience performing vulnerability assessments using recognised vulnerability management tools. Exposure to penetration testing and web application security testing. Experience creating and maintaining cyber security policies, standards, and governance documentation. Professional cyber security certifications such as CompTIA Security+, Network+, CySA+, GSEC, CISSP, GCIH, GCIA, or CCSP. CrowdStrike certifications including CCFA, CCFR, or CCSE. Splunk Certified Cybersecurity Defense Engineer certification.
03/08/2026
Contractor
Job Description Job Title Interim Cyber Security Officer (Senior Cyber Security Engineer) Contract Details Contract Length: 6 Months Start Date: March 2026 Location: London (Hybrid/On-site as required) IR35 Status: Inside IR35 Daily Rate: Up to 500 per day (Umbrella) Overview We are seeking an experienced Senior Cyber Security Engineer to join a Cyber Security team on an interim contract. This role will provide senior technical expertise to support and optimise an outsourced Security Operations Centre (SOC), ensuring the organisation maximises its investment in security technologies while strengthening its cyber defence capabilities. The successful candidate will have extensive hands-on experience with CrowdStrike Falcon and Splunk Enterprise Security , with the ability to enhance security monitoring, improve incident response processes, support threat hunting activities, and mentor internal team members. Key Responsibilities Lead the deployment, configuration, administration, and ongoing optimisation of the CrowdStrike Falcon platform, ensuring endpoint security policies are effectively implemented and maintained. Work closely with the outsourced Security Operations Centre to develop and enhance Splunk dashboards, alerts, data models, and monitoring capabilities, enabling the identification and investigation of sophisticated cyber threats. Act as the senior technical escalation point for complex and high-priority cyber security incidents, utilising Endpoint Detection and Response (EDR) and Security Information and Event Management (SIEM) technologies to support rapid investigation, containment, and remediation. Design, develop, and improve Security Orchestration, Automation and Response (SOAR) workflows to reduce manual effort, improve operational efficiency, and accelerate incident response. Conduct proactive threat hunting activities using advanced search techniques and security telemetry to identify malicious activity that may have evaded automated detection. Support vulnerability assessment activities and contribute to security testing initiatives, including exposure to penetration testing and web application security assessments. Develop and maintain cyber security policies, standards, and technical documentation to support governance and operational best practice. Provide technical guidance, mentoring, and knowledge transfer to existing cyber security team members, strengthening internal capability across CrowdStrike, Splunk, and security operations. Collaborate with internal stakeholders and external partners to continuously improve cyber security monitoring, detection, and response capabilities. Maintain awareness of emerging cyber threats, vulnerabilities, and industry best practices to ensure security controls remain effective and up to date. Essential Requirements Applicants must have a minimum of five years' experience working in a dedicated Cyber Security Engineering or SOC Tier 3 environment. Extensive hands-on experience administering and supporting CrowdStrike Falcon , including Falcon Prevent, Falcon Insight, and Falcon Discover, is essential. Strong experience working with Splunk Enterprise Security , including writing complex Search Processing Language (SPL) queries, developing dashboards, alerts, reports, and managing security data. Experience supporting Security Operations Centres, incident response, endpoint detection and response, security monitoring, and threat hunting activities. Excellent understanding of network protocols, cyber attack methodologies, security monitoring techniques, and the MITRE ATT&CK Framework . Good knowledge of cloud security principles across Microsoft Azure and/or AWS environments. Strong analytical, troubleshooting, communication, and stakeholder management skills with the ability to work independently and manage multiple priorities. Desirable Experience performing vulnerability assessments using recognised vulnerability management tools. Exposure to penetration testing and web application security testing. Experience creating and maintaining cyber security policies, standards, and governance documentation. Professional cyber security certifications such as CompTIA Security+, Network+, CySA+, GSEC, CISSP, GCIH, GCIA, or CCSP. CrowdStrike certifications including CCFA, CCFR, or CCSE. Splunk Certified Cybersecurity Defense Engineer certification.
VHDL FPGA Firmware Engineer
Leonardo Worldwide Corporation Southampton, Hampshire
VHDL FPGA Firmware EngineerApplylocations: GB - Southampton: GB - Bristol - Coldharbour Lanetime type: Full timeposted on: Posted Todayjob requisition id: R Job Description: Salary Ranges Engineer: £38k - £53kSenior: £45k - £61kLeonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity.Where this vacancy is being recruited across more than one grade, the successful candidate will be appointed to a specific assessed grade, and the applicable salary range will be that associated with the grade of appointment.Leonardo offers an additional allowances for some roles - for more information please contact Your Impact: This FPGA Firmware Engineer vacancy presents an exciting opportunity for an ambitious individual to develop their skills and knowledge within a thriving electronics organisation.In this broad VHDL firmware engineering role, you will work across a range of projects throughout various stages of the product lifecycle from initial concept development through to early life production. You will work with some of the latest high-speed FPGA's and System-on-Chips (SoC's) to help shape our future products.The role shall be based in either Southampton or Bristol with a primary focus on the design and development of embedded VHDL firmware for complex aircraft sensor and communication systems.You will be part of the Leonardo Airborne Communications product development group within the Integrated Sensing & Protection line of business, interacting with partner organisations, sub-contractors and potential customers. What you will do: Firmware requirements capture and management. FPGA design and analysis. Production of documentation for other engineers and evidence for design reviews. Development of FPGA test and FPGA integration plans. Perform system integration work with PCB designers and embedded software engineers. Support all firmware designs through the company firmware process - training will be given. Modification of existing firmware designs and test benches. What you'll bring: Experience using FPGA technologies especially from either Xilinx, Microsemi (Actel) or Lattice and their tools. Advanced verification techniques using either VHDL or System Verilog / UVM. Specifying complex timing and area constraints for efficient FPGA place and route. Ability to analyse system level requirements and derive detailed Firmware requirements. A methodical approach to the full firmware design lifecycle, working to a structured firmware process such as RTCA DO-254 or similar. Experience of working on safety related firmware to IEC 61508 would be advantageous. De-bugging firmware designs and supporting verification and integration at hardware and system level alongside Software and Hardware Engineers. Making technical decisions and mitigating technical risk for Firmware design activities. Ability to communicate effectively across different disciplines both verbally and in written form. Familiarity with Siemens EDA FPGA development tools including HDL Designer and ModelSim / Questa is an advantage. It would be nice if you had: Awareness of Safety, Security and other legislative constraints Engineering experience with radio-based communication systems. Experience of mentoring more junior members of the team. Security Clearance: This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). For more information and guidance please visit: Why join us At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we're here to help you thrive. Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year. Secure your Future: Benefit from our award-winning pension scheme with up to 15% employer contribution. Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks championing inclusion and diversity (Enable, Pride, Equalise, Armed Forces, Carers, Wellbeing and Ethnicity). Rewarding Performance : All employees at management level and below are eligible for our bonus scheme. Never Stop Learning : Free access to 4,000+ online courses via Coursera and LinkedIn Learning. Refer a friend: Receive a financial reward through our referral programme. Tailored Perks : Spend up to £500 annually on flexible benefits including private healthcare, dental, family cover, tech & lifestyle discounts, gym memberships and more. Flexible working: Flexible hours with hybrid working options. For part time opportunities, please talk to us about what might be possible for this role.For a full list of our company benefits please visit our website.Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team-they are key contributors to shaping innovation, advancing technology, and enhancing global safety.At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know.Be part of something bigger - apply now! Primary Location: GB - Southampton Additional Locations: GB - Bristol - Coldharbour Lane Contract Type: Permanent Hybrid Working: Hybrid
03/08/2026
Full time
VHDL FPGA Firmware EngineerApplylocations: GB - Southampton: GB - Bristol - Coldharbour Lanetime type: Full timeposted on: Posted Todayjob requisition id: R Job Description: Salary Ranges Engineer: £38k - £53kSenior: £45k - £61kLeonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity.Where this vacancy is being recruited across more than one grade, the successful candidate will be appointed to a specific assessed grade, and the applicable salary range will be that associated with the grade of appointment.Leonardo offers an additional allowances for some roles - for more information please contact Your Impact: This FPGA Firmware Engineer vacancy presents an exciting opportunity for an ambitious individual to develop their skills and knowledge within a thriving electronics organisation.In this broad VHDL firmware engineering role, you will work across a range of projects throughout various stages of the product lifecycle from initial concept development through to early life production. You will work with some of the latest high-speed FPGA's and System-on-Chips (SoC's) to help shape our future products.The role shall be based in either Southampton or Bristol with a primary focus on the design and development of embedded VHDL firmware for complex aircraft sensor and communication systems.You will be part of the Leonardo Airborne Communications product development group within the Integrated Sensing & Protection line of business, interacting with partner organisations, sub-contractors and potential customers. What you will do: Firmware requirements capture and management. FPGA design and analysis. Production of documentation for other engineers and evidence for design reviews. Development of FPGA test and FPGA integration plans. Perform system integration work with PCB designers and embedded software engineers. Support all firmware designs through the company firmware process - training will be given. Modification of existing firmware designs and test benches. What you'll bring: Experience using FPGA technologies especially from either Xilinx, Microsemi (Actel) or Lattice and their tools. Advanced verification techniques using either VHDL or System Verilog / UVM. Specifying complex timing and area constraints for efficient FPGA place and route. Ability to analyse system level requirements and derive detailed Firmware requirements. A methodical approach to the full firmware design lifecycle, working to a structured firmware process such as RTCA DO-254 or similar. Experience of working on safety related firmware to IEC 61508 would be advantageous. De-bugging firmware designs and supporting verification and integration at hardware and system level alongside Software and Hardware Engineers. Making technical decisions and mitigating technical risk for Firmware design activities. Ability to communicate effectively across different disciplines both verbally and in written form. Familiarity with Siemens EDA FPGA development tools including HDL Designer and ModelSim / Questa is an advantage. It would be nice if you had: Awareness of Safety, Security and other legislative constraints Engineering experience with radio-based communication systems. Experience of mentoring more junior members of the team. Security Clearance: This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). For more information and guidance please visit: Why join us At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we're here to help you thrive. Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year. Secure your Future: Benefit from our award-winning pension scheme with up to 15% employer contribution. Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks championing inclusion and diversity (Enable, Pride, Equalise, Armed Forces, Carers, Wellbeing and Ethnicity). Rewarding Performance : All employees at management level and below are eligible for our bonus scheme. Never Stop Learning : Free access to 4,000+ online courses via Coursera and LinkedIn Learning. Refer a friend: Receive a financial reward through our referral programme. Tailored Perks : Spend up to £500 annually on flexible benefits including private healthcare, dental, family cover, tech & lifestyle discounts, gym memberships and more. Flexible working: Flexible hours with hybrid working options. For part time opportunities, please talk to us about what might be possible for this role.For a full list of our company benefits please visit our website.Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team-they are key contributors to shaping innovation, advancing technology, and enhancing global safety.At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know.Be part of something bigger - apply now! Primary Location: GB - Southampton Additional Locations: GB - Bristol - Coldharbour Lane Contract Type: Permanent Hybrid Working: Hybrid
Focus Group
Senior SOC Analyst
Focus Group Manchester, Lancashire
Senior SOC Analyst UK - 3 days a week in our Manchester office (Suite B, Maple Court, M60 Office Park, Wynne Ave, Swinton, Clifton, Manchester, M27 8FF) £50-£55k (Dependent on experience) + benefits Focus Group is looking for a Senior SOC Analyst to play a key role within our Managed Security Services team. This is a dual focused position combining hands on technical expertise with day to day operational leadership, ensuring high quality delivery of managed detection and response services across a diverse customer base. You'll lead SOC operations, act as the escalation point for complex security incidents, and mentor junior analysts-driving both service excellence and team development. What you'll do Lead day to day SOC operations, ensuring effective triage, escalation, and communication workflows Act as the primary escalation point for complex security investigations and incidents Conduct advanced threat investigations across endpoints, networks, and cloud environments Perform proactive threat hunting and detection tuning to improve coverage and reduce noise Manage and mentor Tier 1-2 analysts, supporting development and technical growth Ensure ticket quality, SLA adherence, and high service standards across SOC operations Support onboarding of new customers into monitoring and detection platforms Collaborate with Cyber Security leadership to improve detection strategy and SOC maturity Analyse logs and security data to identify malicious or suspicious activity Develop and maintain playbooks, runbooks, and knowledge base content Produce clear, actionable incident reports for internal and customer stakeholders Engage directly with customers during escalations, incident reviews, and briefings Identify opportunities for automation, process improvement, and enhanced detection capabilities Stay up to date with emerging threats, attack techniques, and MITRE ATT&CK developments What you'll bring 4-6 years' experience in a SOC or MSSP environment at Tier 2-3 or Lead level Strong hands on experience with SIEM platforms (e.g. Microsoft Sentinel, Splunk, Elastic, LogPoint) Experience with EDR tools such as Microsoft Defender, SentinelOne, or Bitdefender Deep understanding of MITRE ATT&CK and modern threat detection methodologies Strong incident response, investigation, and log analysis capability across multiple data sources Ability to lead during high pressure incidents with calm, confident decision making Strong communication skills, including producing clear incident reports and updates Proven ability to mentor, coach, and support junior analysts Organised approach with the ability to manage multiple concurrent incidents Proactive mindset focused on continuous improvement and service optimisation Nice to have Certifications such as SC 200, GCIH, GCIA, Security+, or BTL1 Experience in an MSSP or multi customer environment Microsoft security stack experience (Defender XDR, Sentinel, M365 security) Knowledge of cloud security, email security, and vulnerability management Experience with KQL or other query languages Scripting skills (PowerShell, Python) Familiarity with SOAR and threat intelligence platforms Understanding of compliance frameworks (ISO 27001, NIST, Cyber Essentials) Future opportunities SOC Manager / Head of Security Operations Cyber Security Technical Lead Detection Engineering Lead Threat Intelligence LeadIncident Response Manager Security Consultant / Advisory
03/08/2026
Full time
Senior SOC Analyst UK - 3 days a week in our Manchester office (Suite B, Maple Court, M60 Office Park, Wynne Ave, Swinton, Clifton, Manchester, M27 8FF) £50-£55k (Dependent on experience) + benefits Focus Group is looking for a Senior SOC Analyst to play a key role within our Managed Security Services team. This is a dual focused position combining hands on technical expertise with day to day operational leadership, ensuring high quality delivery of managed detection and response services across a diverse customer base. You'll lead SOC operations, act as the escalation point for complex security incidents, and mentor junior analysts-driving both service excellence and team development. What you'll do Lead day to day SOC operations, ensuring effective triage, escalation, and communication workflows Act as the primary escalation point for complex security investigations and incidents Conduct advanced threat investigations across endpoints, networks, and cloud environments Perform proactive threat hunting and detection tuning to improve coverage and reduce noise Manage and mentor Tier 1-2 analysts, supporting development and technical growth Ensure ticket quality, SLA adherence, and high service standards across SOC operations Support onboarding of new customers into monitoring and detection platforms Collaborate with Cyber Security leadership to improve detection strategy and SOC maturity Analyse logs and security data to identify malicious or suspicious activity Develop and maintain playbooks, runbooks, and knowledge base content Produce clear, actionable incident reports for internal and customer stakeholders Engage directly with customers during escalations, incident reviews, and briefings Identify opportunities for automation, process improvement, and enhanced detection capabilities Stay up to date with emerging threats, attack techniques, and MITRE ATT&CK developments What you'll bring 4-6 years' experience in a SOC or MSSP environment at Tier 2-3 or Lead level Strong hands on experience with SIEM platforms (e.g. Microsoft Sentinel, Splunk, Elastic, LogPoint) Experience with EDR tools such as Microsoft Defender, SentinelOne, or Bitdefender Deep understanding of MITRE ATT&CK and modern threat detection methodologies Strong incident response, investigation, and log analysis capability across multiple data sources Ability to lead during high pressure incidents with calm, confident decision making Strong communication skills, including producing clear incident reports and updates Proven ability to mentor, coach, and support junior analysts Organised approach with the ability to manage multiple concurrent incidents Proactive mindset focused on continuous improvement and service optimisation Nice to have Certifications such as SC 200, GCIH, GCIA, Security+, or BTL1 Experience in an MSSP or multi customer environment Microsoft security stack experience (Defender XDR, Sentinel, M365 security) Knowledge of cloud security, email security, and vulnerability management Experience with KQL or other query languages Scripting skills (PowerShell, Python) Familiarity with SOAR and threat intelligence platforms Understanding of compliance frameworks (ISO 27001, NIST, Cyber Essentials) Future opportunities SOC Manager / Head of Security Operations Cyber Security Technical Lead Detection Engineering Lead Threat Intelligence LeadIncident Response Manager Security Consultant / Advisory
Expleo
Configuration Manager
Expleo Bristol, Gloucestershire
Overview Expleo is a global engineering, technology and consulting service provider that partners with leading organisations to guide them through their business transformation, helping them achieve operational excellence and future-proof their businesses. Expleo boasts an extensive global footprint, powered by 19,000 highly skilled experts delivering value in 50 countries and generating more than €1.4 billion in revenue. An exciting opportunity has arisen for an experienced Configuration Manager to support the growth and development of the Configuration and Data Management Team. Responsibilities Configuration Management Leadership Define, implement, and continuously improve Configuration Management (CM) policies, processes, procedures, and standards. Ensure compliance with relevant industry standards, contractual requirements, and regulatory obligations. Act as the Configuration Management Subject Matter Expert (SME) across the organisation. Develop and maintain Configuration Management Plans (CMPs) for programmes and projects. Configuration Identification Establish and maintain product structures, configuration item hierarchies, and naming conventions. Define and manage configuration baselines throughout the system lifecycle. Ensure all hardware, software, firmware, documentation, and associated assets are uniquely identified and controlled. Change Control Manage engineering change processes and governance frameworks. Facilitate Change Control Boards (CCBs) and Engineering Review Boards. Assess the impact of proposed changes on safety, cost, schedule, performance, and compliance. Ensure changes are reviewed, approved, implemented, and documented in line with organisational procedures. Configuration Status Accounting Maintain accurate records of configuration item status, changes, releases, and approvals. Produce configuration reports and metrics for programme and senior management reviews. Ensure full traceability between requirements, design artefacts, verification evidence, and released configurations. Verification and Audit Plan and conduct configuration audits including: Functional Configuration Audits (FCA) Physical Configuration Audits (PCA) Baseline reviews Support external audits by customers, regulators, certification authorities, and quality assurance functions. Ensure configuration evidence supports safety cases and design assurance activities. Safety and Compliance Support the development and maintenance of safety cases where configuration control forms part of the assurance argument. Ensure safety related products and documentation remain controlled and traceable. Work closely with Safety Engineers and Quality Managers to maintain compliance throughout the product lifecycle. Toolset Management Administer and optimise Configuration Management and Product Lifecycle Management (PLM) tools. Maintain data integrity within CM repositories and supporting systems. Support deployment of digital engineering and lifecycle management capabilities. Stakeholder Engagement Build strong relationships with engineering teams, programme managers, customers, suppliers, and regulatory bodies. Provide training, coaching, and guidance on configuration management principles and best practice. Support supplier configuration management activities and audits where required. Qualifications Essential Degree in Engineering, Systems Engineering, Quality Management, or a related discipline; or equivalent professional experience. Desirable Configuration Management certification. Engineering Council registration (EngTech, IEng, or CEng). Project Management qualification (APM, Prince2, PMI). Quality or Safety Management certification. Essential skills Strong understanding of engineering lifecycle processes including systems engineering, design, development, verification, validation, deployment, and support. Excellent stakeholder management and communication skills. Strong analytical and problem solving capability. Desired skills Knowledge of: ISO 10007 - Quality Management - Configuration Management EIA-649 Configuration Management Standard ISO 9001 IEC 61508 ARP4754A DO-178C DO-254 EN 50126 / 50128 / 50129 Defence Standards and Government Regulatory Frameworks Experience An extensive experience as a Configuration Manager (CM) Experience with tools such as: Teamcenter Windchill Siemens Polarion IBM Engineering Lifecycle Management (DOORS or DOOGS Next Gen) Jama Connect Azure DevOps SAP ServiceNow Experience operating formal change control processes and governance forums. Experience conducting configuration audits and supporting regulatory inspections. Proven experience managing configuration baselines across complex systems, products, or platforms. Experience using CM, PLM, ALM, or document management systems. Significant experience in Configuration Management within safety critical engineering environments. Experience in one or more of the following sectors: Defence Aerospace Rail Nuclear Maritime Automotive Medical Devices Energy What do I need before I apply Ability to obtain and maintain the appropriate level of security clearance. Compliance with organisational security, information management, and export control requirements. Benefits Collaborative working environment - we stand shoulder to shoulder with our clients and ourpeers through good times and challenges We empower all passionate technology loving professionals by allowing them to expand their skills and take part in inspiring projects ExpleoAcademy - enables you to acquire and develop the right skills by delivering a suite of accredited training courses Competitive company benefits Always working as one team, our people are not afraid to think big and challenge the status quo As a Disability Confident Committed Employer we have committed to: Ensure our recruitment process is inclusive and accessible Communicating and promoting vacancies Offering an interview to disabled people who meet the minimum criteria for the job Anticipating and providing reasonable adjustments as required Supporting any existing employee who acquires a disability or long term health condition, enabling them to stay in work at least one activity that will make a difference for disabled people "We are an equal opportunities employer and welcome applications from all suitably qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age". We treat everyone fairly and equitably across the organisation, including providing any additional support and adjustments needed for everyone to thrive
03/08/2026
Full time
Overview Expleo is a global engineering, technology and consulting service provider that partners with leading organisations to guide them through their business transformation, helping them achieve operational excellence and future-proof their businesses. Expleo boasts an extensive global footprint, powered by 19,000 highly skilled experts delivering value in 50 countries and generating more than €1.4 billion in revenue. An exciting opportunity has arisen for an experienced Configuration Manager to support the growth and development of the Configuration and Data Management Team. Responsibilities Configuration Management Leadership Define, implement, and continuously improve Configuration Management (CM) policies, processes, procedures, and standards. Ensure compliance with relevant industry standards, contractual requirements, and regulatory obligations. Act as the Configuration Management Subject Matter Expert (SME) across the organisation. Develop and maintain Configuration Management Plans (CMPs) for programmes and projects. Configuration Identification Establish and maintain product structures, configuration item hierarchies, and naming conventions. Define and manage configuration baselines throughout the system lifecycle. Ensure all hardware, software, firmware, documentation, and associated assets are uniquely identified and controlled. Change Control Manage engineering change processes and governance frameworks. Facilitate Change Control Boards (CCBs) and Engineering Review Boards. Assess the impact of proposed changes on safety, cost, schedule, performance, and compliance. Ensure changes are reviewed, approved, implemented, and documented in line with organisational procedures. Configuration Status Accounting Maintain accurate records of configuration item status, changes, releases, and approvals. Produce configuration reports and metrics for programme and senior management reviews. Ensure full traceability between requirements, design artefacts, verification evidence, and released configurations. Verification and Audit Plan and conduct configuration audits including: Functional Configuration Audits (FCA) Physical Configuration Audits (PCA) Baseline reviews Support external audits by customers, regulators, certification authorities, and quality assurance functions. Ensure configuration evidence supports safety cases and design assurance activities. Safety and Compliance Support the development and maintenance of safety cases where configuration control forms part of the assurance argument. Ensure safety related products and documentation remain controlled and traceable. Work closely with Safety Engineers and Quality Managers to maintain compliance throughout the product lifecycle. Toolset Management Administer and optimise Configuration Management and Product Lifecycle Management (PLM) tools. Maintain data integrity within CM repositories and supporting systems. Support deployment of digital engineering and lifecycle management capabilities. Stakeholder Engagement Build strong relationships with engineering teams, programme managers, customers, suppliers, and regulatory bodies. Provide training, coaching, and guidance on configuration management principles and best practice. Support supplier configuration management activities and audits where required. Qualifications Essential Degree in Engineering, Systems Engineering, Quality Management, or a related discipline; or equivalent professional experience. Desirable Configuration Management certification. Engineering Council registration (EngTech, IEng, or CEng). Project Management qualification (APM, Prince2, PMI). Quality or Safety Management certification. Essential skills Strong understanding of engineering lifecycle processes including systems engineering, design, development, verification, validation, deployment, and support. Excellent stakeholder management and communication skills. Strong analytical and problem solving capability. Desired skills Knowledge of: ISO 10007 - Quality Management - Configuration Management EIA-649 Configuration Management Standard ISO 9001 IEC 61508 ARP4754A DO-178C DO-254 EN 50126 / 50128 / 50129 Defence Standards and Government Regulatory Frameworks Experience An extensive experience as a Configuration Manager (CM) Experience with tools such as: Teamcenter Windchill Siemens Polarion IBM Engineering Lifecycle Management (DOORS or DOOGS Next Gen) Jama Connect Azure DevOps SAP ServiceNow Experience operating formal change control processes and governance forums. Experience conducting configuration audits and supporting regulatory inspections. Proven experience managing configuration baselines across complex systems, products, or platforms. Experience using CM, PLM, ALM, or document management systems. Significant experience in Configuration Management within safety critical engineering environments. Experience in one or more of the following sectors: Defence Aerospace Rail Nuclear Maritime Automotive Medical Devices Energy What do I need before I apply Ability to obtain and maintain the appropriate level of security clearance. Compliance with organisational security, information management, and export control requirements. Benefits Collaborative working environment - we stand shoulder to shoulder with our clients and ourpeers through good times and challenges We empower all passionate technology loving professionals by allowing them to expand their skills and take part in inspiring projects ExpleoAcademy - enables you to acquire and develop the right skills by delivering a suite of accredited training courses Competitive company benefits Always working as one team, our people are not afraid to think big and challenge the status quo As a Disability Confident Committed Employer we have committed to: Ensure our recruitment process is inclusive and accessible Communicating and promoting vacancies Offering an interview to disabled people who meet the minimum criteria for the job Anticipating and providing reasonable adjustments as required Supporting any existing employee who acquires a disability or long term health condition, enabling them to stay in work at least one activity that will make a difference for disabled people "We are an equal opportunities employer and welcome applications from all suitably qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age". We treat everyone fairly and equitably across the organisation, including providing any additional support and adjustments needed for everyone to thrive
Cyber Security Analyst
WeAreTechWomen
Job Description Role: Cyber Security Analyst Location: London/Manchester/Bristol Salary: Competitive salary and package dependent on experience Career Level: Specialist Please Note: Any offer of employment is subject to satisfactory BPSS and SC security clearance which typically requires 5 years continuous UK address history usually including no periods of 30 consecutive days or more spent outside of the UK and declaration of being a British passport holder with no dual nationalism at the point of application. Note: The above information relates to a specific client requirement Our Cyber Practice is a fast-growing community of industry leading experts. The practice covers Assurance, Compliance, Security Operations (SecOps), Offensive Security and Security Research. It is critical that the relevance and quality of the services that we provide is maintained and augmented and that the team members have every opportunity to grow and learn with the organisation. As part of our Blue Team, you'll use the latest intelligence and tooling to analyse information systems to ensure effective incident detection and response. Job Description If you are looking to make your mark on a rapidly growing SecOps team with some very exciting clients, look no further. We are searching for a passionate and enthusiastic Cyber Security Analyst to join our Blue Team. The ideal candidate will be a self-starter with an inquisitive nature and a keen interest when it comes to technical cybersecurity topics such as threat hunting, attacker tactics and techniques, monitoring and alerting, threat intelligence, and incident readiness and response. Key responsibilities of the role are summarised below: Security monitoring and incident response Detection engineering - Develop, maintain, and enhance security detection content primarily for the Splunk SIEM, to enable the detection of threats across diverse platforms (e.g. cloud, endpoints, and networks) Use frameworks like MITRE ATT&CK to map detection rules and maximise threat coverage Use analytical platforms to query high volume datasets to identify trends and spot unusual behaviours, indicative of malicious activity Proactive threat hunting using available client data Collection and/or interpretation of different sources of threat intelligence Incident response Automation of SecOps processes using scripting Qualification Desirable Attributes Core cybersecurity concepts such as network security, cryptography, cloud security, forensics Understanding of network protocols and how they can be abused by attackers Knowledge of the most prevalent APTs and their TTPs Ability to understand client-specific challenges and tailor solutions accordingly Commitment to staying abreast of emerging threats, technologies, and methodologies in cybersecurity Creative and resourceful in finding solutions to complex cyber challenges Knowledge of common analysis techniques associated with Windows and/or Linux Experience with Scripting and Programming - e.g. Python/Bash/c/C++/Java Note: This role requires an approximately 1-week per month on-call availability for high priority incidents. Please note there is additional compensation for this and the frequency is client-dependent. What's in it for you At Accenture in addition to a competitive basic salary, you will also have an extensive benefits package which includes up to 25 days of vacation per year, private medical insurance and three days leave per year for charitable work of your choice! Flexibility and mobility are required to deliver this role to deliver the first-class services we are known for. Closing Date for Applications: 31/08/2026 Accenture reserves the right to close the role prior to this date should a suitable applicant be found. Locations London Manchester Additional Information Equal Employment Opportunity Statement All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law. Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process. Accenture is committed to providing veteran employment opportunities to our service men and women. Please read Accenture's Recruiting and Hiring Statement for more information on how we process your data during the Recruiting and Hiring process. About Accenture We work with one shared purpose: to deliver on the promise of technology and human ingenuity. Every day, more than 775,000 of us help our stakeholders continuously reinvent. Together, we drive positive change and deliver value to our clients, partners, shareholders, communities, and each other. We believe that delivering value requires innovation, and innovation thrives in an inclusive and diverse environment. We actively foster a workplace free from bias, where everyone feels a sense of belonging and is respected and empowered to do their best work. At Accenture, we see well-being holistically, supporting our people's physical, mental, and financial health. We also provide opportunities to keep skills relevant through certifications, learning, and diverse work experiences. We're proud to be consistently recognized as one of the World's Best Workplaces . Join Accenture to work at the heart of change. Visit us at .
03/08/2026
Full time
Job Description Role: Cyber Security Analyst Location: London/Manchester/Bristol Salary: Competitive salary and package dependent on experience Career Level: Specialist Please Note: Any offer of employment is subject to satisfactory BPSS and SC security clearance which typically requires 5 years continuous UK address history usually including no periods of 30 consecutive days or more spent outside of the UK and declaration of being a British passport holder with no dual nationalism at the point of application. Note: The above information relates to a specific client requirement Our Cyber Practice is a fast-growing community of industry leading experts. The practice covers Assurance, Compliance, Security Operations (SecOps), Offensive Security and Security Research. It is critical that the relevance and quality of the services that we provide is maintained and augmented and that the team members have every opportunity to grow and learn with the organisation. As part of our Blue Team, you'll use the latest intelligence and tooling to analyse information systems to ensure effective incident detection and response. Job Description If you are looking to make your mark on a rapidly growing SecOps team with some very exciting clients, look no further. We are searching for a passionate and enthusiastic Cyber Security Analyst to join our Blue Team. The ideal candidate will be a self-starter with an inquisitive nature and a keen interest when it comes to technical cybersecurity topics such as threat hunting, attacker tactics and techniques, monitoring and alerting, threat intelligence, and incident readiness and response. Key responsibilities of the role are summarised below: Security monitoring and incident response Detection engineering - Develop, maintain, and enhance security detection content primarily for the Splunk SIEM, to enable the detection of threats across diverse platforms (e.g. cloud, endpoints, and networks) Use frameworks like MITRE ATT&CK to map detection rules and maximise threat coverage Use analytical platforms to query high volume datasets to identify trends and spot unusual behaviours, indicative of malicious activity Proactive threat hunting using available client data Collection and/or interpretation of different sources of threat intelligence Incident response Automation of SecOps processes using scripting Qualification Desirable Attributes Core cybersecurity concepts such as network security, cryptography, cloud security, forensics Understanding of network protocols and how they can be abused by attackers Knowledge of the most prevalent APTs and their TTPs Ability to understand client-specific challenges and tailor solutions accordingly Commitment to staying abreast of emerging threats, technologies, and methodologies in cybersecurity Creative and resourceful in finding solutions to complex cyber challenges Knowledge of common analysis techniques associated with Windows and/or Linux Experience with Scripting and Programming - e.g. Python/Bash/c/C++/Java Note: This role requires an approximately 1-week per month on-call availability for high priority incidents. Please note there is additional compensation for this and the frequency is client-dependent. What's in it for you At Accenture in addition to a competitive basic salary, you will also have an extensive benefits package which includes up to 25 days of vacation per year, private medical insurance and three days leave per year for charitable work of your choice! Flexibility and mobility are required to deliver this role to deliver the first-class services we are known for. Closing Date for Applications: 31/08/2026 Accenture reserves the right to close the role prior to this date should a suitable applicant be found. Locations London Manchester Additional Information Equal Employment Opportunity Statement All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law. Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process. Accenture is committed to providing veteran employment opportunities to our service men and women. Please read Accenture's Recruiting and Hiring Statement for more information on how we process your data during the Recruiting and Hiring process. About Accenture We work with one shared purpose: to deliver on the promise of technology and human ingenuity. Every day, more than 775,000 of us help our stakeholders continuously reinvent. Together, we drive positive change and deliver value to our clients, partners, shareholders, communities, and each other. We believe that delivering value requires innovation, and innovation thrives in an inclusive and diverse environment. We actively foster a workplace free from bias, where everyone feels a sense of belonging and is respected and empowered to do their best work. At Accenture, we see well-being holistically, supporting our people's physical, mental, and financial health. We also provide opportunities to keep skills relevant through certifications, learning, and diverse work experiences. We're proud to be consistently recognized as one of the World's Best Workplaces . Join Accenture to work at the heart of change. Visit us at .
Information Security Engineer
Rider Levett Bucknall
Information Security Engineer Department: IT Operations Employment Type: Permanent - Full Time Location: Birmingham Description Title: Information Security Engineer Discipline: IT Location: Birmingham (With Hybrid Working) Role Overview The Information Security Engineer will work closely with the Head of Security and Infrastructure, as well as the wider IT and Governance teams, to ensure the ongoing protection of RLB's IT environments. This is a critical role responsible for protecting infrastructure, cloud, software, and data against unauthorised use, modification, exfiltration, or damage. This role identifies threats, manages projects and engineers solutions. An ideal candidate for this role is dedicated to learning new things, security minded, strong initiative, and able to manage projects autonomously across diverse topics. Role Responsibilities Security Operations & Monitoring Management of day to day security operations and act as the primary contact for the third party SOC. Analyse and interpret logs, alerts, and threat data to identify potential security incidents. Ensure security alerts and incidents are managed and remediated. Ensure security tooling is correctly configured, operational, and fully utilised. Threat Detection, Incident Response & Vulnerability Management. Support or lead security incident investigations, including root cause analysis and remediation. Conduct vulnerability assessments and maturity scans, ensuring risks are clearly communicated and mitigated. Oversee third party penetration tests, manage remediation plans, and maintain strong vendor relationships. Security Engineering & Technology Work with Microsoft security technologies such as Microsoft Purview, Defender, M365, Entra ID, and Azure security tools, email security solutions and endpoint protection solutions. Oversee configuration changes, ensure tools are effectively integrated, and monitor identity and access management to detect potential misuse of credentials or privileges. Apply technical expertise to support improvements to security configuration, identity management, and endpoint security. Support internal teams when changes to systems may impact SOC monitoring or defensive controls. Governance, Audit & Compliance Help ensure alignment with standards such as Cyber Essentials Plus, NIST , ISO 27001, and UK GDPR. Carry out security audits and respond to DSAR requests. Assist with internal/external audits and maintain documentation to demonstrate compliance with RLB's security requirements. Assist with the completion of supply chain risk assessments. Provide support for the secure onboarding of software, ensuring adherence to data security protocols, software development best practices, and all relevant requirements. Security Culture & Continuous Improvement Develop and support awareness initiatives, phishing simulations, and internal training. Stay ahead of new threats and emerging technologies, recommending ongoing improvements. Promote best practice security behaviours. Qualifications Certifications such as CEH, CISSP, Security+ Relevant Microsoft certifications (SC 900, SC 200, AZ 140) Ability to obtain Security Clearance (essential) Experience Extensive experience configuring and managing M365, Microsoft Purview, Defender, and the broader Microsoft cloud security ecosystems. Experience working with information classification systems and Data Loss Prevention techniques. Experience working with or managing third party SOC, SIEM, and security vendors. Background in overseeing penetration tests and coordination of remediation activities. Solid understanding of incident response, vulnerability management, and general cyber defence principles. Demonstrable experience in NIST & ISO 27001 compliant environments. Behaviours Excellent interpersonal skills with the ability to influence peers and seniors on matters concerning protective security. Excellent organisational skills with the ability to prioritise workload and deliver to tight time scales. Possesses a professional and confident manner and maintains confidentiality at all times. A highly motivated and driven individual who adopts a flexible and adaptable approach. Desirable Exposure to secure software development and implementation practises. RLB Employee Benefits Hybrid Working - Working patterns to support your work life balance. As well as competitive maternity and paternity packages. Well Rewarded - A competitive salary and generous holiday entitlement. As well as the opportunity to purchase up to five extra days. Focus On Wellbeing - We offer a number of health and wellness options, including gym membership and cycle to work schemes. Healthcare Packages - Private healthcare insurance and medical support, including dental insurance and eyecare vouchers. Personal Development - A continuous learning and development programme, including established APC and in house mentoring schemes. Additional Benefits - We offer a wide range of benefits including a season ticket loan and professional membership subscriptions. Exceptional Exposure - You'll have the opportunity to work on diverse projects across different sectors and regions. Social Responsibility - We hold team and social events as well as charity fundraising and volunteering activities. Our Diversity, Equity & Inclusion Commitment We believe in building a diverse and inclusive environment where each person can be themselves, feel valued for their contribution and be challenged and supported to reach their full potential. We have a responsibility to support the communities in which we live and work, and that our workforce should reflect these communities and our clients. Our talent strategy should enable us to overcome bias in the construction industry by recruiting, retaining, developing, and promoting a diverse and inclusive workforce. Find out more here: If you require any reasonable adjustments to support you during any stage of the application or interview process, please contact our recruitment team at:
02/08/2026
Full time
Information Security Engineer Department: IT Operations Employment Type: Permanent - Full Time Location: Birmingham Description Title: Information Security Engineer Discipline: IT Location: Birmingham (With Hybrid Working) Role Overview The Information Security Engineer will work closely with the Head of Security and Infrastructure, as well as the wider IT and Governance teams, to ensure the ongoing protection of RLB's IT environments. This is a critical role responsible for protecting infrastructure, cloud, software, and data against unauthorised use, modification, exfiltration, or damage. This role identifies threats, manages projects and engineers solutions. An ideal candidate for this role is dedicated to learning new things, security minded, strong initiative, and able to manage projects autonomously across diverse topics. Role Responsibilities Security Operations & Monitoring Management of day to day security operations and act as the primary contact for the third party SOC. Analyse and interpret logs, alerts, and threat data to identify potential security incidents. Ensure security alerts and incidents are managed and remediated. Ensure security tooling is correctly configured, operational, and fully utilised. Threat Detection, Incident Response & Vulnerability Management. Support or lead security incident investigations, including root cause analysis and remediation. Conduct vulnerability assessments and maturity scans, ensuring risks are clearly communicated and mitigated. Oversee third party penetration tests, manage remediation plans, and maintain strong vendor relationships. Security Engineering & Technology Work with Microsoft security technologies such as Microsoft Purview, Defender, M365, Entra ID, and Azure security tools, email security solutions and endpoint protection solutions. Oversee configuration changes, ensure tools are effectively integrated, and monitor identity and access management to detect potential misuse of credentials or privileges. Apply technical expertise to support improvements to security configuration, identity management, and endpoint security. Support internal teams when changes to systems may impact SOC monitoring or defensive controls. Governance, Audit & Compliance Help ensure alignment with standards such as Cyber Essentials Plus, NIST , ISO 27001, and UK GDPR. Carry out security audits and respond to DSAR requests. Assist with internal/external audits and maintain documentation to demonstrate compliance with RLB's security requirements. Assist with the completion of supply chain risk assessments. Provide support for the secure onboarding of software, ensuring adherence to data security protocols, software development best practices, and all relevant requirements. Security Culture & Continuous Improvement Develop and support awareness initiatives, phishing simulations, and internal training. Stay ahead of new threats and emerging technologies, recommending ongoing improvements. Promote best practice security behaviours. Qualifications Certifications such as CEH, CISSP, Security+ Relevant Microsoft certifications (SC 900, SC 200, AZ 140) Ability to obtain Security Clearance (essential) Experience Extensive experience configuring and managing M365, Microsoft Purview, Defender, and the broader Microsoft cloud security ecosystems. Experience working with information classification systems and Data Loss Prevention techniques. Experience working with or managing third party SOC, SIEM, and security vendors. Background in overseeing penetration tests and coordination of remediation activities. Solid understanding of incident response, vulnerability management, and general cyber defence principles. Demonstrable experience in NIST & ISO 27001 compliant environments. Behaviours Excellent interpersonal skills with the ability to influence peers and seniors on matters concerning protective security. Excellent organisational skills with the ability to prioritise workload and deliver to tight time scales. Possesses a professional and confident manner and maintains confidentiality at all times. A highly motivated and driven individual who adopts a flexible and adaptable approach. Desirable Exposure to secure software development and implementation practises. RLB Employee Benefits Hybrid Working - Working patterns to support your work life balance. As well as competitive maternity and paternity packages. Well Rewarded - A competitive salary and generous holiday entitlement. As well as the opportunity to purchase up to five extra days. Focus On Wellbeing - We offer a number of health and wellness options, including gym membership and cycle to work schemes. Healthcare Packages - Private healthcare insurance and medical support, including dental insurance and eyecare vouchers. Personal Development - A continuous learning and development programme, including established APC and in house mentoring schemes. Additional Benefits - We offer a wide range of benefits including a season ticket loan and professional membership subscriptions. Exceptional Exposure - You'll have the opportunity to work on diverse projects across different sectors and regions. Social Responsibility - We hold team and social events as well as charity fundraising and volunteering activities. Our Diversity, Equity & Inclusion Commitment We believe in building a diverse and inclusive environment where each person can be themselves, feel valued for their contribution and be challenged and supported to reach their full potential. We have a responsibility to support the communities in which we live and work, and that our workforce should reflect these communities and our clients. Our talent strategy should enable us to overcome bias in the construction industry by recruiting, retaining, developing, and promoting a diverse and inclusive workforce. Find out more here: If you require any reasonable adjustments to support you during any stage of the application or interview process, please contact our recruitment team at:
Detection Operations Advisor - SIEM & MDR Expert
Cyderes
Cyderes in the United Kingdom seeks an Operations Advisor who owns detection outcomes for assigned clients. You will improve detection quality, identify coverage gaps, and advance client security maturity through expert advisory and hands-on detection engineering. You report to Manager, Cyber Defense Operations. You will lead the technical account relationship, deliver measurable outcomes, tune rules across SIEMs, and coordinate with SOC and DFIR teams during escalations, translating findings
01/08/2026
Full time
Cyderes in the United Kingdom seeks an Operations Advisor who owns detection outcomes for assigned clients. You will improve detection quality, identify coverage gaps, and advance client security maturity through expert advisory and hands-on detection engineering. You report to Manager, Cyber Defense Operations. You will lead the technical account relationship, deliver measurable outcomes, tune rules across SIEMs, and coordinate with SOC and DFIR teams during escalations, translating findings

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board