Senior SecOps Engineer - Microsoft Security UK Predominantly Remote Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure Sentinel Microsoft Defender / Defender XDR Strong KQL / Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps / Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
23/08/2026
Full time
Senior SecOps Engineer - Microsoft Security UK Predominantly Remote Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure Sentinel Microsoft Defender / Defender XDR Strong KQL / Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps / Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Our client isseeking an experienced Cyber Security Analyst/Red Team Specialist to conduct safe, controlled and intelligence-led cyber-attack simulations across complex technology estates. Working as a real-world adversary might, the successful candidate will identify weaknesses, test defensive capabilities and provide expert cyber security insight to support strategic security decision-making. The role requires strong hands-on offensive security experience, with the ability to tactically assess and execute sophisticated attack scenarios across traditional enterprise environments and modern digital services. You will be comfortable conducting complex, multi-stage operations, including chained attacks, evasion techniques, persistence, post-exploitation and lateral movement, while maintaining a strong focus on operational security and avoiding unnecessary disruption to live services. Key Responsibilities Design and execute threat intelligence-led, full-spectrum cyber-attack simulations, including long-term campaign planning, persistence and post-exploitation activity. Adopt a Red Team/adversary simulation approach to identify high-impact vulnerabilities across critical technology estates and business areas. Validate the effectiveness of the organisation's wider cyber security controls, defensive capabilities and security architecture. Conduct scenario-driven engagements based on realistic threat actor capabilities, behaviours and tradecraft. Perform exploitation across infrastructure, web applications, cloud platforms and enterprise technology environments. Identify and analyse attack paths towards high-value systems, data and business services. Apply appropriate evasion and operational security techniques to ensure engagements are controlled and do not unnecessarily disrupt business operations. Communicate technical findings clearly, translating complex vulnerabilities and attack paths into business risk, impact and remediation requirements for senior stakeholders. Develop, enhance and automate offensive security tools, techniques and methodologies. Build and maintain attack infrastructure, including C2 frameworks and supporting infrastructure-as-code. Mentor junior Red Team colleagues, supporting the development of their technical capability and understanding of offensive security. Share knowledge with wider cyber security and non-security teams to help strengthen the organisation's overall security culture. Contribute to vulnerability management, threat mitigation and risk-based security decision-making. Essential Experience & Skills The successful candidate will demonstrate: Proven experience planning and executing complex, multi-phase offensive security operations. Strong experience delivering scenario-driven adversary simulations and Red Team engagements. Excellent threat intelligence analysis and assessment capability. Extensive hands-on exploitation experience across a broad range of technologies, including: Microsoft Entra ID Active Directory Microsoft 365 macOS Kubernetes CI/CD environments AWS Azure Infrastructure and web applications Strong understanding of post-exploitation, persistence and lateral movement, including tactical analysis of attack paths to high-value targets. Experience conducting engagements in accordance with operational security best practice and within a range of threat actor capabilities and tradecraft. Deep technical understanding of security technologies within end-user and server operating systems, together with supporting infrastructure and enterprise architecture. Experience working across complex Legacy and modern enterprise environments at scale. Experience developing, deploying and using tools to support Red Team activities. Practical experience with attack infrastructure, C2 frameworks and Infrastructure as Code (IaC) technologies. Excellent written and verbal communication skills, with the ability to explain complex technical vulnerabilities, risks and attack scenarios to both technical and non-technical audiences, including senior stakeholders. Experience contributing to or participating in GCASE, GBEST, CBEST or TIBER engagements. Desirable Experience Experience in threat research and/or vulnerability research, including publishing research or presenting findings to the wider cyber security community. Previous experience in a related security discipline, such as: Protective Monitoring Incident Response Security Engineering Security Architecture Experience working within large, complex public sector, government or highly regulated environments. Experience mentoring or developing junior offensive security professionals. Professional Qualifications Relevant Red Team and offensive security certifications are desirable, including: CCSAS CRTL Other recognised offensive security/Red Team certifications would also be considered. What We're Looking For This is a technically demanding role for an experienced offensive security professional who can combine deep technical exploitation capability with strategic security thinking. The successful candidate will be able to operate confidently across complex enterprise, cloud and modern digital environments, understand how sophisticated attacks can be chained together, and communicate the resulting risks in a way that enables senior decision-makers to take effective action. If you have substantial experience in Red Teaming , adversary simulation, threat intelligence, exploitation, post-exploitation and attack-path analysis, we would be keen to hear from you.
20/08/2026
Contractor
Our client isseeking an experienced Cyber Security Analyst/Red Team Specialist to conduct safe, controlled and intelligence-led cyber-attack simulations across complex technology estates. Working as a real-world adversary might, the successful candidate will identify weaknesses, test defensive capabilities and provide expert cyber security insight to support strategic security decision-making. The role requires strong hands-on offensive security experience, with the ability to tactically assess and execute sophisticated attack scenarios across traditional enterprise environments and modern digital services. You will be comfortable conducting complex, multi-stage operations, including chained attacks, evasion techniques, persistence, post-exploitation and lateral movement, while maintaining a strong focus on operational security and avoiding unnecessary disruption to live services. Key Responsibilities Design and execute threat intelligence-led, full-spectrum cyber-attack simulations, including long-term campaign planning, persistence and post-exploitation activity. Adopt a Red Team/adversary simulation approach to identify high-impact vulnerabilities across critical technology estates and business areas. Validate the effectiveness of the organisation's wider cyber security controls, defensive capabilities and security architecture. Conduct scenario-driven engagements based on realistic threat actor capabilities, behaviours and tradecraft. Perform exploitation across infrastructure, web applications, cloud platforms and enterprise technology environments. Identify and analyse attack paths towards high-value systems, data and business services. Apply appropriate evasion and operational security techniques to ensure engagements are controlled and do not unnecessarily disrupt business operations. Communicate technical findings clearly, translating complex vulnerabilities and attack paths into business risk, impact and remediation requirements for senior stakeholders. Develop, enhance and automate offensive security tools, techniques and methodologies. Build and maintain attack infrastructure, including C2 frameworks and supporting infrastructure-as-code. Mentor junior Red Team colleagues, supporting the development of their technical capability and understanding of offensive security. Share knowledge with wider cyber security and non-security teams to help strengthen the organisation's overall security culture. Contribute to vulnerability management, threat mitigation and risk-based security decision-making. Essential Experience & Skills The successful candidate will demonstrate: Proven experience planning and executing complex, multi-phase offensive security operations. Strong experience delivering scenario-driven adversary simulations and Red Team engagements. Excellent threat intelligence analysis and assessment capability. Extensive hands-on exploitation experience across a broad range of technologies, including: Microsoft Entra ID Active Directory Microsoft 365 macOS Kubernetes CI/CD environments AWS Azure Infrastructure and web applications Strong understanding of post-exploitation, persistence and lateral movement, including tactical analysis of attack paths to high-value targets. Experience conducting engagements in accordance with operational security best practice and within a range of threat actor capabilities and tradecraft. Deep technical understanding of security technologies within end-user and server operating systems, together with supporting infrastructure and enterprise architecture. Experience working across complex Legacy and modern enterprise environments at scale. Experience developing, deploying and using tools to support Red Team activities. Practical experience with attack infrastructure, C2 frameworks and Infrastructure as Code (IaC) technologies. Excellent written and verbal communication skills, with the ability to explain complex technical vulnerabilities, risks and attack scenarios to both technical and non-technical audiences, including senior stakeholders. Experience contributing to or participating in GCASE, GBEST, CBEST or TIBER engagements. Desirable Experience Experience in threat research and/or vulnerability research, including publishing research or presenting findings to the wider cyber security community. Previous experience in a related security discipline, such as: Protective Monitoring Incident Response Security Engineering Security Architecture Experience working within large, complex public sector, government or highly regulated environments. Experience mentoring or developing junior offensive security professionals. Professional Qualifications Relevant Red Team and offensive security certifications are desirable, including: CCSAS CRTL Other recognised offensive security/Red Team certifications would also be considered. What We're Looking For This is a technically demanding role for an experienced offensive security professional who can combine deep technical exploitation capability with strategic security thinking. The successful candidate will be able to operate confidently across complex enterprise, cloud and modern digital environments, understand how sophisticated attacks can be chained together, and communicate the resulting risks in a way that enables senior decision-makers to take effective action. If you have substantial experience in Red Teaming , adversary simulation, threat intelligence, exploitation, post-exploitation and attack-path analysis, we would be keen to hear from you.
Cyber Assurance & Risk Analyst Location: IWM London Salary : £42,500 to £45,000 per annum Vacancy Type: Permanent, Full Time (36hours per week) Closing Date: 8th of September 2026 At Imperial War Museums, we're driven by a shared purpose: helping people understand conflict and its impact on people's lives, from the First World War through to the present day. Our collections contain millions of items, stories and digital assets that preserve some of the most important moments in modern history. You'll join a collaborative team who work together to protect and make these collections accessible for future generations. It's a unique opportunity to combine cyber security expertise with meaningful work that supports one of the world's leading museums of conflict. Why This Role Matters Cyber security plays a vital role in protecting IWM's systems, services and information assets from an evolving threat landscape. As Cyber Assurance & Risk Analyst, you'll help strengthen the organisation's cyber resilience by ensuring compliance with government and industry security standards, embedding secure-by-design principles into projects and managing cyber risks across our supplier landscape. By delivering key assurance activities, you'll help improve organisational cyber capability and ensure IWM continues to safeguard the services relied upon by colleagues, visitors, researchers and stakeholders. What You'll Be Doing Coordinate and manage IWM's Cyber Essentials certification, including evidence gathering, submission management and remediation tracking. Lead GovAssure submissions through control mapping, evidence collation and stakeholder engagement. Manage compliance against Civil Aviation Authority (CAA) cyber security requirements and other relevant standards. Maintain assurance documentation and support continuous compliance against recognised cyber security frameworks. Embed secure-by-design principles into technology and digital projects from initiation through to delivery. Review proposed solutions and provide assurance that appropriate security controls are implemented before go-live. Own and operate IWM's third-party cyber risk management platform, supporting supplier onboarding, assessments and ongoing monitoring. Identify, assess, manage and escalate cyber risks across the supply chain, tracking remediation activities where required. Produce assurance, compliance and cyber risk reports for governance boards and senior stakeholders. Support cyber governance activities, risk management processes and the maintenance of accurate cyber risk records. Contribute to the development of cyber security policies, standards, controls and continuous improvement initiatives. Provide guidance on cyber compliance matters and work collaboratively with colleagues, suppliers and external partners to support assurance objectives. Support financial administration activities, including purchase orders, invoice processing and departmental administration where required. What We're Looking For We'd love to hear from you if you have: Experience of cyber security governance, assurance, compliance or risk management activities. Knowledge of recognised cyber security frameworks and standards such as Cyber Essentials, NCSC guidance, ISO 27001 or equivalent. Experience managing compliance evidence, audit activities or regulatory submissions. Experience of supplier or third-party cyber risk assessment and management processes. Strong analytical skills with the ability to identify risks and communicate findings clearly to a range of stakeholders. Experience producing reports, dashboards or management information for governance forums and senior audiences. Benefits The benefits listed below are discretionary and IWM reserves the right, with due notice, to vary or withdraw them at any time. Annual Leave: You'll have 25 days of annual leave, with public holidays on top. After 3 years, this increases to 27 days and after 5 years, you ll get 30 days Company Group Pension Plan: Includes competitive employer contributions to your pension starting at 7% to a maximum of 12%. Enhanced Maternity and Paternity Benefits: Celebrate life s milestones with confidence, knowing that our policies support growing families. IWM4me: Tailor your benefits to your unique needs through IWM4me. Access health, protection, and lifestyle benefits at corporate rates, ensuring your holistic well-being. Free Sanitary Products: We prioritise your comfort by providing free sanitary products across all our sites. Retail Discounts: 25% off IWM Cafes, 20% discount in on-site shops, Benefits hub offering retail discounts to several high street shops and MyActive discounts for health and wellbeing based retail discounts Free Entry to IWM Air Shows: Witness the thrill of vintage aircraft at our air shows. To Apply If you feel you are a suitable candidate and would like to work for Imperial War Museum, please click apply to be redirected to our website to complete your application.
20/08/2026
Full time
Cyber Assurance & Risk Analyst Location: IWM London Salary : £42,500 to £45,000 per annum Vacancy Type: Permanent, Full Time (36hours per week) Closing Date: 8th of September 2026 At Imperial War Museums, we're driven by a shared purpose: helping people understand conflict and its impact on people's lives, from the First World War through to the present day. Our collections contain millions of items, stories and digital assets that preserve some of the most important moments in modern history. You'll join a collaborative team who work together to protect and make these collections accessible for future generations. It's a unique opportunity to combine cyber security expertise with meaningful work that supports one of the world's leading museums of conflict. Why This Role Matters Cyber security plays a vital role in protecting IWM's systems, services and information assets from an evolving threat landscape. As Cyber Assurance & Risk Analyst, you'll help strengthen the organisation's cyber resilience by ensuring compliance with government and industry security standards, embedding secure-by-design principles into projects and managing cyber risks across our supplier landscape. By delivering key assurance activities, you'll help improve organisational cyber capability and ensure IWM continues to safeguard the services relied upon by colleagues, visitors, researchers and stakeholders. What You'll Be Doing Coordinate and manage IWM's Cyber Essentials certification, including evidence gathering, submission management and remediation tracking. Lead GovAssure submissions through control mapping, evidence collation and stakeholder engagement. Manage compliance against Civil Aviation Authority (CAA) cyber security requirements and other relevant standards. Maintain assurance documentation and support continuous compliance against recognised cyber security frameworks. Embed secure-by-design principles into technology and digital projects from initiation through to delivery. Review proposed solutions and provide assurance that appropriate security controls are implemented before go-live. Own and operate IWM's third-party cyber risk management platform, supporting supplier onboarding, assessments and ongoing monitoring. Identify, assess, manage and escalate cyber risks across the supply chain, tracking remediation activities where required. Produce assurance, compliance and cyber risk reports for governance boards and senior stakeholders. Support cyber governance activities, risk management processes and the maintenance of accurate cyber risk records. Contribute to the development of cyber security policies, standards, controls and continuous improvement initiatives. Provide guidance on cyber compliance matters and work collaboratively with colleagues, suppliers and external partners to support assurance objectives. Support financial administration activities, including purchase orders, invoice processing and departmental administration where required. What We're Looking For We'd love to hear from you if you have: Experience of cyber security governance, assurance, compliance or risk management activities. Knowledge of recognised cyber security frameworks and standards such as Cyber Essentials, NCSC guidance, ISO 27001 or equivalent. Experience managing compliance evidence, audit activities or regulatory submissions. Experience of supplier or third-party cyber risk assessment and management processes. Strong analytical skills with the ability to identify risks and communicate findings clearly to a range of stakeholders. Experience producing reports, dashboards or management information for governance forums and senior audiences. Benefits The benefits listed below are discretionary and IWM reserves the right, with due notice, to vary or withdraw them at any time. Annual Leave: You'll have 25 days of annual leave, with public holidays on top. After 3 years, this increases to 27 days and after 5 years, you ll get 30 days Company Group Pension Plan: Includes competitive employer contributions to your pension starting at 7% to a maximum of 12%. Enhanced Maternity and Paternity Benefits: Celebrate life s milestones with confidence, knowing that our policies support growing families. IWM4me: Tailor your benefits to your unique needs through IWM4me. Access health, protection, and lifestyle benefits at corporate rates, ensuring your holistic well-being. Free Sanitary Products: We prioritise your comfort by providing free sanitary products across all our sites. Retail Discounts: 25% off IWM Cafes, 20% discount in on-site shops, Benefits hub offering retail discounts to several high street shops and MyActive discounts for health and wellbeing based retail discounts Free Entry to IWM Air Shows: Witness the thrill of vintage aircraft at our air shows. To Apply If you feel you are a suitable candidate and would like to work for Imperial War Museum, please click apply to be redirected to our website to complete your application.
Senior Network and Security Engineer - L2/L3 Network Infrastructure - Cyber Security - SIEM tools My client who are leaders in their field are looking for a Senior Cyber Security and Network Analyst to provide effective and timely operational support, development and management of the IT network and security infrastructure to meet business requirements and objectives. Responsibilities: Support the delivery and maintenance of the organisation's cyber security and network infrastructure, ensuring systems remain secure, resilient, and aligned to business needs Manage day-to-day security operations, including monitoring SIEM platforms, Firewalls, endpoint protection, and threat detection tools Investigate security incidents and vulnerabilities, recommending and implementing corrective actions where required Maintain and support network technologies including LAN/WAN, Wi-Fi, Internet connectivity, and Layer 2/3 infrastructure Contribute to cyber security and infrastructure projects, including the implementation of new security controls and technologies Perform patching, upgrades, and ongoing maintenance across security and network environments to minimise risk and downtime Develop and maintain security policies, operational procedures, technical documentation, and compliance standards Support disaster recovery and business continuity planning, testing, and readiness activities Key Experience & Skills: Palo Alto Firewalls and all associated NG services Endpoint detection and remediation Proven track record in Cyber security and understanding of cyber security analysis, tools and software Experience of implementing, supporting and developing L2/3 network infrastructure Qualys Vulnerability Management Aruba Wifi L2/3 switching - Cisco Nexus Network Load balancing Penetration Testing (3rd Party) Incident management Data Security
20/08/2026
Full time
Senior Network and Security Engineer - L2/L3 Network Infrastructure - Cyber Security - SIEM tools My client who are leaders in their field are looking for a Senior Cyber Security and Network Analyst to provide effective and timely operational support, development and management of the IT network and security infrastructure to meet business requirements and objectives. Responsibilities: Support the delivery and maintenance of the organisation's cyber security and network infrastructure, ensuring systems remain secure, resilient, and aligned to business needs Manage day-to-day security operations, including monitoring SIEM platforms, Firewalls, endpoint protection, and threat detection tools Investigate security incidents and vulnerabilities, recommending and implementing corrective actions where required Maintain and support network technologies including LAN/WAN, Wi-Fi, Internet connectivity, and Layer 2/3 infrastructure Contribute to cyber security and infrastructure projects, including the implementation of new security controls and technologies Perform patching, upgrades, and ongoing maintenance across security and network environments to minimise risk and downtime Develop and maintain security policies, operational procedures, technical documentation, and compliance standards Support disaster recovery and business continuity planning, testing, and readiness activities Key Experience & Skills: Palo Alto Firewalls and all associated NG services Endpoint detection and remediation Proven track record in Cyber security and understanding of cyber security analysis, tools and software Experience of implementing, supporting and developing L2/3 network infrastructure Qualys Vulnerability Management Aruba Wifi L2/3 switching - Cisco Nexus Network Load balancing Penetration Testing (3rd Party) Incident management Data Security
Senior Cyber Security Risk & Assurance Consultant - Product Risk (PBRA) (CONTRACTOR) - London Duration: 1 year contract Hybrid Working - 8 days onsite per month - the rest is remote working About the Team The Product-Based Risk Assessment (PBRA) service conducts recurring security assessments of applications, services, and technologies to identify emerging threats, evaluate control effectiveness, and drive remediation that strengthens The clients cyber resilience. The team supports business and technology stakeholders by assessing cyber security risks and ensuring alignment with The Banks security standards and risk appetite. Key Accountabilities Product-Based Risk Assessments Lead end-to-end Product-Based Risk Assessments (PBRA) for critical applications, platforms, and technology services. Analyse application architectures, business processes, information flows, and supporting infrastructure. Identify and assess cyber threats, vulnerabilities, control weaknesses, and potential business impacts. Evaluate the design and effectiveness of security controls using clients security frameworks and standards. Assess residual risks and propose actionable remediation plans. Security Risk Analysis Perform security risk assessments using recognised methodologies and industry frameworks. Evaluate risks related to infrastructure, software, cloud services, networks, third-party integrations, and information assets. Contribute to threat modelling and attack surface analysis activities. Support technology-focused assessments such as cloud, AI, and emerging technology evaluations. Stakeholder Engagement Act as the primary security assessment contact for business and IT stakeholders. Facilitate workshops, interviews, and assessment review sessions. Challenge assumptions and provide expert security guidance to delivery and operations teams. Build trusted relationships across CISO, CTO, Architecture, Risk Management, and Engineering teams. Reporting & Governance Produce high-quality assessment reports, risk summaries, and executive-level communications. Present findings and recommendations to senior management and governance bodies. Track remediation plans and risk treatment activities through closure. Support internal and external audit activities as required. Continuous Improvement Contribute to the evolution of the PBRA service, methodologies, tools, and operating model. Help drive the transition toward data-enabled and automated security assessment capabilities. Identify opportunities to improve efficiency, consistency, and risk coverage across assessments. Support knowledge sharing and mentoring of junior analysts. Required Skills & Experience Technical Skills Strong understanding of cybersecurity principles, controls, and risk management practices. Knowledge of application security, cloud security, infrastructure security, and network security. Experience conducting security assessments, threat modelling, or risk analyses. Familiarity with industry frameworks and standards such as: NIST Cyber Security Framework ISO 27001 CIS Controls Secure Controls Framework (SCF) DORA ANSSI EBIOS RM OWASP Professional Experience Minimum 7 years of experience in Information Security, Cyber Risk, Security Assurance, or Security Architecture. Experience leading complex security assessments across large technology environments. Experience working with senior business and technology stakeholders. Strong report-writing and presentation skills. Personal Competencies Strong analytical and critical-thinking capabilities. Excellent communication and stakeholder management skills. Ability to challenge constructively and influence decision-making. Self-driven with strong ownership and accountability. Pragmatic, risk-based mindset. Comfortable operating in a complex, regulated environment. Please do send across to me the most up to date CV to (url removed) Rates depend on experience and client requirements
19/08/2026
Contractor
Senior Cyber Security Risk & Assurance Consultant - Product Risk (PBRA) (CONTRACTOR) - London Duration: 1 year contract Hybrid Working - 8 days onsite per month - the rest is remote working About the Team The Product-Based Risk Assessment (PBRA) service conducts recurring security assessments of applications, services, and technologies to identify emerging threats, evaluate control effectiveness, and drive remediation that strengthens The clients cyber resilience. The team supports business and technology stakeholders by assessing cyber security risks and ensuring alignment with The Banks security standards and risk appetite. Key Accountabilities Product-Based Risk Assessments Lead end-to-end Product-Based Risk Assessments (PBRA) for critical applications, platforms, and technology services. Analyse application architectures, business processes, information flows, and supporting infrastructure. Identify and assess cyber threats, vulnerabilities, control weaknesses, and potential business impacts. Evaluate the design and effectiveness of security controls using clients security frameworks and standards. Assess residual risks and propose actionable remediation plans. Security Risk Analysis Perform security risk assessments using recognised methodologies and industry frameworks. Evaluate risks related to infrastructure, software, cloud services, networks, third-party integrations, and information assets. Contribute to threat modelling and attack surface analysis activities. Support technology-focused assessments such as cloud, AI, and emerging technology evaluations. Stakeholder Engagement Act as the primary security assessment contact for business and IT stakeholders. Facilitate workshops, interviews, and assessment review sessions. Challenge assumptions and provide expert security guidance to delivery and operations teams. Build trusted relationships across CISO, CTO, Architecture, Risk Management, and Engineering teams. Reporting & Governance Produce high-quality assessment reports, risk summaries, and executive-level communications. Present findings and recommendations to senior management and governance bodies. Track remediation plans and risk treatment activities through closure. Support internal and external audit activities as required. Continuous Improvement Contribute to the evolution of the PBRA service, methodologies, tools, and operating model. Help drive the transition toward data-enabled and automated security assessment capabilities. Identify opportunities to improve efficiency, consistency, and risk coverage across assessments. Support knowledge sharing and mentoring of junior analysts. Required Skills & Experience Technical Skills Strong understanding of cybersecurity principles, controls, and risk management practices. Knowledge of application security, cloud security, infrastructure security, and network security. Experience conducting security assessments, threat modelling, or risk analyses. Familiarity with industry frameworks and standards such as: NIST Cyber Security Framework ISO 27001 CIS Controls Secure Controls Framework (SCF) DORA ANSSI EBIOS RM OWASP Professional Experience Minimum 7 years of experience in Information Security, Cyber Risk, Security Assurance, or Security Architecture. Experience leading complex security assessments across large technology environments. Experience working with senior business and technology stakeholders. Strong report-writing and presentation skills. Personal Competencies Strong analytical and critical-thinking capabilities. Excellent communication and stakeholder management skills. Ability to challenge constructively and influence decision-making. Self-driven with strong ownership and accountability. Pragmatic, risk-based mindset. Comfortable operating in a complex, regulated environment. Please do send across to me the most up to date CV to (url removed) Rates depend on experience and client requirements
Prject Manager Cyber - Inside IR35 SZC is developing its security posture to improve maturity against NIST CSF and reduce residual risk. This includes preparation for ISO27001 certification of our Information Security Management System (ISMS) by the end of 2026 together with the associated arrangements, assurance and risk management. To support the many related activities and alignment with our alliances we require a Project Manager familiar with Cyber. This role will coordinate meetings, minutes and actions together with preparation activities for sessions refining controls, platforms, compliance, policy and risk alongside our Digital and CWA colleagues. Key Responsibilities Own the Cyber Development plan for Scope 27, ensuring key milestones, dependencies, and the critical path are mapped out and understood. Identify and manage issues and risks that could affect the successful delivery of activities Assign tasks to team and update Azure Dev Ops (ADO) Board capturing these activities Schedule meetings with Digital PM, SMEs, alliances and partners relating to the delivery activities, present status updates, inc from ADO as above Draft supply chain related administration for services using provided templates and examples. Coordinate with local teams visits and stakeholders for assurance, whiteboard and comms sessions. Review and collaborate on copy relating to documents, communications campaigns including awareness and global emails. Required Skills/Experience Experienced project manager/business analyst. Strong planning, delivery management, issue resolution, and senior engagement skills Comfortable working with stakeholders across business technical and leadership; experience with previous cyber projects is highly desirable. Familiarity with Microsoft Office including Visio and ADO or Kanban Boards highly desirable Ability to work flexibly and under pressure with ability to travel to London, Ipswich and Leiston Rullion celebrates and supports diversity and is committed to ensuring equal opportunities for both employees and applicants.
13/08/2026
Contractor
Prject Manager Cyber - Inside IR35 SZC is developing its security posture to improve maturity against NIST CSF and reduce residual risk. This includes preparation for ISO27001 certification of our Information Security Management System (ISMS) by the end of 2026 together with the associated arrangements, assurance and risk management. To support the many related activities and alignment with our alliances we require a Project Manager familiar with Cyber. This role will coordinate meetings, minutes and actions together with preparation activities for sessions refining controls, platforms, compliance, policy and risk alongside our Digital and CWA colleagues. Key Responsibilities Own the Cyber Development plan for Scope 27, ensuring key milestones, dependencies, and the critical path are mapped out and understood. Identify and manage issues and risks that could affect the successful delivery of activities Assign tasks to team and update Azure Dev Ops (ADO) Board capturing these activities Schedule meetings with Digital PM, SMEs, alliances and partners relating to the delivery activities, present status updates, inc from ADO as above Draft supply chain related administration for services using provided templates and examples. Coordinate with local teams visits and stakeholders for assurance, whiteboard and comms sessions. Review and collaborate on copy relating to documents, communications campaigns including awareness and global emails. Required Skills/Experience Experienced project manager/business analyst. Strong planning, delivery management, issue resolution, and senior engagement skills Comfortable working with stakeholders across business technical and leadership; experience with previous cyber projects is highly desirable. Familiarity with Microsoft Office including Visio and ADO or Kanban Boards highly desirable Ability to work flexibly and under pressure with ability to travel to London, Ipswich and Leiston Rullion celebrates and supports diversity and is committed to ensuring equal opportunities for both employees and applicants.
Role: Cyber Security Lead Location: Nottinghamshire Working Arrangement: 3 days a week in office Salary: Up to 70k Are you an experienced SOC professional who's ready to take the next step into leadership without leaving the technical work behind? We're looking for a Cyber Security Operations Manager to lead our in-house Security Operations capability while remaining deeply involved in the day-to-day technical aspects of detection, response and continuous improvement. This role is ideal for someone moving from a Senior SOC Analyst, Senior Security Engineer or SOC Team Lead position who wants to develop their leadership skills while staying hands-on. You'll spend around 80% of your time working on technical security operations and 20% leading and developing the team, making this an excellent opportunity for someone looking for their first management role. What you'll be doing Leading and mentoring a small SOC team while remaining an active technical contributor. Investigating and responding to security incidents across enterprise, cloud and operational technology environments. Improving detection capabilities, automation and SOC processes to stay ahead of emerging threats. Working closely with vulnerability management, incident response and governance teams to strengthen the organisation's security posture. Taking part in the on-call rota and providing technical leadership during security incidents. What we're looking for You'll likely have experience in a senior SOC or security operations role and be ready to take the next step into people leadership. You'll bring: Strong experience with security monitoring, threat detection and incident response. Hands-on knowledge of SIEM, SOAR and security tooling. A passion for improving detection capabilities and automating security operations. The confidence to mentor others and influence technical decisions. Excellent communication skills and the ability to collaborate across technical teams. Professional certifications such as CISSP, CISM, GCIH, GCIA, GSEC or cloud security certifications are welcome but not essential. Why join us? This is an opportunity to shape the future of an evolving Security Operations function within a large, complex technology environment. You'll have the autonomy to improve processes, introduce new ideas and develop your leadership career while remaining close to the technology you enjoy. If you're looking for a role that combines technical depth with your first step into management, we'd love to hear from you. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
13/08/2026
Full time
Role: Cyber Security Lead Location: Nottinghamshire Working Arrangement: 3 days a week in office Salary: Up to 70k Are you an experienced SOC professional who's ready to take the next step into leadership without leaving the technical work behind? We're looking for a Cyber Security Operations Manager to lead our in-house Security Operations capability while remaining deeply involved in the day-to-day technical aspects of detection, response and continuous improvement. This role is ideal for someone moving from a Senior SOC Analyst, Senior Security Engineer or SOC Team Lead position who wants to develop their leadership skills while staying hands-on. You'll spend around 80% of your time working on technical security operations and 20% leading and developing the team, making this an excellent opportunity for someone looking for their first management role. What you'll be doing Leading and mentoring a small SOC team while remaining an active technical contributor. Investigating and responding to security incidents across enterprise, cloud and operational technology environments. Improving detection capabilities, automation and SOC processes to stay ahead of emerging threats. Working closely with vulnerability management, incident response and governance teams to strengthen the organisation's security posture. Taking part in the on-call rota and providing technical leadership during security incidents. What we're looking for You'll likely have experience in a senior SOC or security operations role and be ready to take the next step into people leadership. You'll bring: Strong experience with security monitoring, threat detection and incident response. Hands-on knowledge of SIEM, SOAR and security tooling. A passion for improving detection capabilities and automating security operations. The confidence to mentor others and influence technical decisions. Excellent communication skills and the ability to collaborate across technical teams. Professional certifications such as CISSP, CISM, GCIH, GCIA, GSEC or cloud security certifications are welcome but not essential. Why join us? This is an opportunity to shape the future of an evolving Security Operations function within a large, complex technology environment. You'll have the autonomy to improve processes, introduce new ideas and develop your leadership career while remaining close to the technology you enjoy. If you're looking for a role that combines technical depth with your first step into management, we'd love to hear from you. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Pontoon is an employment consultancy. We put expertise, energy, and enthusiasm into improving everyone's chance of being part of the workplace. We respect and appreciate people of all ethnicities, generations, religious beliefs, sexual orientations, gender identities, and more. We do this by showcasing their talents, skills, and unique experience in an inclusive environment that helps them thrive. Job Title: PMO Analyst Location: Warwick / Hybrid Contract Type: 6 months with scope to extend Role Overview We are seeking an experienced PMO Analyst to provide PMO, financial governance and commercial management support across a Cyber Security portfolio. The role will take ownership of a key part of the project management and financial activities currently supported by Engineers and Project Managers. This will include managing financial information, maintaining global trackers, supporting forecasting and spend profiling, and ensuring activities progress effectively through the Procure-to-Pay (P2P) process. The successful candidate will work closely with Project Managers, Engineers, Delivery Leads, Finance, Procurement, Contract Managers and key suppliers. The wider team is split across the UK and US, so some flexibility around working hours may occasionally be required. Key Responsibilities PMO & Programme Governance Provide PMO and analytical support across the Cyber Security portfolio. Maintain portfolio reporting, financial trackers and management information. Work with Project Managers and Delivery Leads to ensure project information is accurate and up to date. Support the preparation of Business Cases, investment sanctions, Closure Reports, stage-gate documentation and other governance artefacts. Track actions, risks, issues and key deliverables across projects. Provide clear and accurate reporting to stakeholders at different levels of seniority. Financial Management & Reporting Extract financial information from core systems and maintain the global portfolio tracker. Work with Delivery Leads and partners to understand project spend profiles and future forecasts. Support budget management, forecasting, actuals, commitments and variance analysis. Manage and report OPEX and CAPEX expenditure. Work closely with Finance Business Partners and Contract Managers to ensure financial information is accurate. Identify financial issues, risks and discrepancies and proactively drive resolution. Provide financial insight to support portfolio and investment decisions. Commercial, Procurement & Supplier Management Manage and coordinate Change Orders (CORs), Purchase Orders and receipting activities. Support the end-to-end P2P process, ensuring purchasing and invoicing activities progress within agreed timescales. Work closely with Procurement, Finance and Contract Managers on commercial and contractual matters. Manage supplier invoicing queries and ensure suppliers meet agreed requirements and deadlines. Be confident challenging suppliers where contractual or process requirements are not being met. Support the management of strategic technology suppliers, including complex or non-standard invoicing arrangements. Act as a key interface between Security, Finance, Procurement, Commercial and Supplier Management teams. Key Skills & Experience Essential Strong experience as a PMO Analyst, Project Analyst, Programme Analyst or Financial PMO. Strong financial management and analytical skills. Experience with OPEX/CAPEX, forecasting, budget control and financial reporting. Good understanding of Purchase Orders, invoicing, receipting and P2P processes. Strong Excel skills, with experience managing complex financial trackers. Experience with Coupa and Ariba. Excellent written and verbal communication skills. Strong command of written English, with the ability to produce high-quality documentation for senior stakeholders. Experience producing formal documentation such as Business Cases and Closure Reports. Strong stakeholder management skills and confidence to challenge suppliers and internal stakeholders. Highly organised, detail-oriented and proactive. Comfortable working with UK and US-based teams and flexible when occasional changes to working hours are required. Desirable Cyber Security experience. Experience within a large-scale technology, IT infrastructure or transformation environment. ServiceNow SPM experience. Experience managing strategic technology suppliers or complex contracts. Experience supporting investment governance and project lifecycle activities. Apply now! Please be advised: if you haven't heard from us within 48 hours, then unfortunately your application has not been successful on this occasion. We may, however, keep your details on file for any suitable future vacancies and contact you accordingly. We use generative AI tools to support our candidate screening process. This helps us ensure a fair, consistent, and efficient experience for all applicants. Rest assured, all final decisions are made by our hiring team, and your application will be reviewed with care and attention.
11/08/2026
Contractor
Pontoon is an employment consultancy. We put expertise, energy, and enthusiasm into improving everyone's chance of being part of the workplace. We respect and appreciate people of all ethnicities, generations, religious beliefs, sexual orientations, gender identities, and more. We do this by showcasing their talents, skills, and unique experience in an inclusive environment that helps them thrive. Job Title: PMO Analyst Location: Warwick / Hybrid Contract Type: 6 months with scope to extend Role Overview We are seeking an experienced PMO Analyst to provide PMO, financial governance and commercial management support across a Cyber Security portfolio. The role will take ownership of a key part of the project management and financial activities currently supported by Engineers and Project Managers. This will include managing financial information, maintaining global trackers, supporting forecasting and spend profiling, and ensuring activities progress effectively through the Procure-to-Pay (P2P) process. The successful candidate will work closely with Project Managers, Engineers, Delivery Leads, Finance, Procurement, Contract Managers and key suppliers. The wider team is split across the UK and US, so some flexibility around working hours may occasionally be required. Key Responsibilities PMO & Programme Governance Provide PMO and analytical support across the Cyber Security portfolio. Maintain portfolio reporting, financial trackers and management information. Work with Project Managers and Delivery Leads to ensure project information is accurate and up to date. Support the preparation of Business Cases, investment sanctions, Closure Reports, stage-gate documentation and other governance artefacts. Track actions, risks, issues and key deliverables across projects. Provide clear and accurate reporting to stakeholders at different levels of seniority. Financial Management & Reporting Extract financial information from core systems and maintain the global portfolio tracker. Work with Delivery Leads and partners to understand project spend profiles and future forecasts. Support budget management, forecasting, actuals, commitments and variance analysis. Manage and report OPEX and CAPEX expenditure. Work closely with Finance Business Partners and Contract Managers to ensure financial information is accurate. Identify financial issues, risks and discrepancies and proactively drive resolution. Provide financial insight to support portfolio and investment decisions. Commercial, Procurement & Supplier Management Manage and coordinate Change Orders (CORs), Purchase Orders and receipting activities. Support the end-to-end P2P process, ensuring purchasing and invoicing activities progress within agreed timescales. Work closely with Procurement, Finance and Contract Managers on commercial and contractual matters. Manage supplier invoicing queries and ensure suppliers meet agreed requirements and deadlines. Be confident challenging suppliers where contractual or process requirements are not being met. Support the management of strategic technology suppliers, including complex or non-standard invoicing arrangements. Act as a key interface between Security, Finance, Procurement, Commercial and Supplier Management teams. Key Skills & Experience Essential Strong experience as a PMO Analyst, Project Analyst, Programme Analyst or Financial PMO. Strong financial management and analytical skills. Experience with OPEX/CAPEX, forecasting, budget control and financial reporting. Good understanding of Purchase Orders, invoicing, receipting and P2P processes. Strong Excel skills, with experience managing complex financial trackers. Experience with Coupa and Ariba. Excellent written and verbal communication skills. Strong command of written English, with the ability to produce high-quality documentation for senior stakeholders. Experience producing formal documentation such as Business Cases and Closure Reports. Strong stakeholder management skills and confidence to challenge suppliers and internal stakeholders. Highly organised, detail-oriented and proactive. Comfortable working with UK and US-based teams and flexible when occasional changes to working hours are required. Desirable Cyber Security experience. Experience within a large-scale technology, IT infrastructure or transformation environment. ServiceNow SPM experience. Experience managing strategic technology suppliers or complex contracts. Experience supporting investment governance and project lifecycle activities. Apply now! Please be advised: if you haven't heard from us within 48 hours, then unfortunately your application has not been successful on this occasion. We may, however, keep your details on file for any suitable future vacancies and contact you accordingly. We use generative AI tools to support our candidate screening process. This helps us ensure a fair, consistent, and efficient experience for all applicants. Rest assured, all final decisions are made by our hiring team, and your application will be reviewed with care and attention.
IT & Systems Manager Salary: 50,000 + Bonus + Benefits Location: Driffield, East Yorkshire Hours: Monday to Friday, 37.5 hours per week, Hybrid Are you an experienced IT & Systems professional looking for an opportunity to own and shape technology within a growing international business? We're recruiting for an IT & Systems Manager to join a fast-growing company based in Driffield. Reporting directly to the CEO, you'll take ownership of the company's technology landscape, leading business systems, ERP optimisation, digital transformation and continuous improvement initiatives that will support ambitious growth plans over the coming years. This is a unique opportunity for someone who enjoys combining technology with commercial thinking, working closely with senior leadership to improve business processes, drive automation and ensure technology becomes a key enabler of business success. The Role As IT & Systems Manager, you'll become the internal owner of the company's technology estate, working across business systems, applications and third-party suppliers while driving improvements across the organisation. Your responsibilities will include: Owning and developing core business systems including Odoo ERP, Shopify, Microsoft 365, Qlik, Netstock, Pimberly and eDesk Leading ERP optimisation, systems integrations and automation projects Identifying opportunities to improve business processes through technology Supporting users through training, documentation and best practice Managing relationships with external IT providers and software vendors Coordinating Microsoft 365 administration and user management Supporting cyber security, disaster recovery and business continuity initiatives Managing software licensing and hardware procurement Driving digital transformation and continuous improvement projects Improving reporting, data quality and business intelligence Evaluating AI tools and automation opportunities that deliver genuine business value Helping shape the company's long-term technology roadmap What We're Looking For We're looking for someone who enjoys understanding how businesses operate and using technology to improve efficiency, productivity and performance. You'll likely have experience in one of the following roles: IT Manager Business Systems Manager Applications Manager Systems Manager ERP Manager Business Systems Analyst (Senior) Essential Previous experience managing business systems or IT within a commercial environment Strong experience supporting ERP or integrated business systems Experience delivering technology improvement or implementation projects Microsoft 365 administration experience Experience managing third-party technology suppliers Excellent stakeholder management and communication skills Strong analytical and problem-solving ability Commercial mindset with a passion for continuous improvement Desirable Odoo ERP Shopify Qlik Netstock Pimberly API integrations AI and automation technologies Cyber security and IT governance Distribution, wholesale, manufacturing or e-commerce experience Why Join? This is a genuine opportunity to influence the future direction of technology within a rapidly expanding international business. You'll join at an exciting stage of the company's growth, taking ownership of systems that are central to future success while working directly with the CEO and senior leadership team. Over the coming years you'll play a key role in: Expanding ERP capability Driving automation across the business Enhancing reporting and business intelligence Improving business processes Supporting future acquisitions and integrations Developing AI capabilities where they add commercial value There is genuine scope for this role to develop into a broader technology leadership position as the business continues to grow. Salary & Benefits 50,000 salary Annual performance bonus Hybrid working Private medical cover 25 days annual leave plus Bank Holidays Company pension Ongoing professional development Opportunity to shape technology strategy within a growing international business If you're looking for a role where you can combine technical expertise with commercial impact and play a key part in a company's growth journey, we'd love to hear from you.
10/08/2026
Full time
IT & Systems Manager Salary: 50,000 + Bonus + Benefits Location: Driffield, East Yorkshire Hours: Monday to Friday, 37.5 hours per week, Hybrid Are you an experienced IT & Systems professional looking for an opportunity to own and shape technology within a growing international business? We're recruiting for an IT & Systems Manager to join a fast-growing company based in Driffield. Reporting directly to the CEO, you'll take ownership of the company's technology landscape, leading business systems, ERP optimisation, digital transformation and continuous improvement initiatives that will support ambitious growth plans over the coming years. This is a unique opportunity for someone who enjoys combining technology with commercial thinking, working closely with senior leadership to improve business processes, drive automation and ensure technology becomes a key enabler of business success. The Role As IT & Systems Manager, you'll become the internal owner of the company's technology estate, working across business systems, applications and third-party suppliers while driving improvements across the organisation. Your responsibilities will include: Owning and developing core business systems including Odoo ERP, Shopify, Microsoft 365, Qlik, Netstock, Pimberly and eDesk Leading ERP optimisation, systems integrations and automation projects Identifying opportunities to improve business processes through technology Supporting users through training, documentation and best practice Managing relationships with external IT providers and software vendors Coordinating Microsoft 365 administration and user management Supporting cyber security, disaster recovery and business continuity initiatives Managing software licensing and hardware procurement Driving digital transformation and continuous improvement projects Improving reporting, data quality and business intelligence Evaluating AI tools and automation opportunities that deliver genuine business value Helping shape the company's long-term technology roadmap What We're Looking For We're looking for someone who enjoys understanding how businesses operate and using technology to improve efficiency, productivity and performance. You'll likely have experience in one of the following roles: IT Manager Business Systems Manager Applications Manager Systems Manager ERP Manager Business Systems Analyst (Senior) Essential Previous experience managing business systems or IT within a commercial environment Strong experience supporting ERP or integrated business systems Experience delivering technology improvement or implementation projects Microsoft 365 administration experience Experience managing third-party technology suppliers Excellent stakeholder management and communication skills Strong analytical and problem-solving ability Commercial mindset with a passion for continuous improvement Desirable Odoo ERP Shopify Qlik Netstock Pimberly API integrations AI and automation technologies Cyber security and IT governance Distribution, wholesale, manufacturing or e-commerce experience Why Join? This is a genuine opportunity to influence the future direction of technology within a rapidly expanding international business. You'll join at an exciting stage of the company's growth, taking ownership of systems that are central to future success while working directly with the CEO and senior leadership team. Over the coming years you'll play a key role in: Expanding ERP capability Driving automation across the business Enhancing reporting and business intelligence Improving business processes Supporting future acquisitions and integrations Developing AI capabilities where they add commercial value There is genuine scope for this role to develop into a broader technology leadership position as the business continues to grow. Salary & Benefits 50,000 salary Annual performance bonus Hybrid working Private medical cover 25 days annual leave plus Bank Holidays Company pension Ongoing professional development Opportunity to shape technology strategy within a growing international business If you're looking for a role where you can combine technical expertise with commercial impact and play a key part in a company's growth journey, we'd love to hear from you.
Business Analyst AI & Digital Transformation Location: Gloucester Hybrid, 2 days per week on-site Salary: £50,000 Type: Permanent Benefits: Hybrid working + wider benefits package Our client, a leading public sector organisation, is hiring an experienced Business Analyst to support the delivery of AI, automation and digital transformation initiatives. This is an opportunity to work on projects that will have a genuine impact on how public services are delivered, identifying where AI and automation can improve processes, reduce manual activity and enable better decision-making. You ll work across the full project lifecycle, from discovery and requirements gathering through to testing and implementation, helping turn business challenges into practical, secure and responsible technology solutions. What you ll do Lead business and process analysis across AI and digital transformation projects Run workshops and discovery sessions with operational teams, technical specialists and senior stakeholders Map current and future-state processes and identify opportunities for improvement Gather and translate business needs into clear functional and non-functional requirements Develop user stories, acceptance criteria, use cases and process models Assess potential AI and automation use cases for feasibility, value and operational impact Work alongside data specialists, developers and architects to shape AI-enabled solutions Support proof-of-concept and pilot projects through to wider implementation Define success measures and benefits to demonstrate the value of new solutions Support testing, UAT and operational readiness ahead of go-live You ll work closely with digital, data, architecture, information governance, cyber security and operational teams, acting as the bridge between business requirements and technical delivery. What we re looking for Strong Business Analysis experience within complex digital or transformation programmes Previous experience within local government, central government, the NHS or another public sector environment Strong requirements gathering, process mapping and service improvement experience Experience working across the full project lifecycle, from discovery through to implementation Exposure to AI, automation, data, digital platforms or other emerging technologies Excellent stakeholder management skills, including working with senior and non-technical stakeholders Experience developing business cases, options appraisals and benefits measures Understanding of data protection, information governance and cyber security Experience working within Agile, Waterfall or hybrid delivery environments Experience with Generative AI, Microsoft Copilot, machine learning, Power Platform, Power Automate or Azure AI would be particularly beneficial. The ideal candidate will be analytical, pragmatic and comfortable challenging existing ways of working. You ll be able to translate complex technical concepts into clear business language and understand both the opportunities and limitations of AI. Why join? £50,000 salary Hybrid working with only 2 days per week in Gloucester Work on high-profile AI and digital transformation initiatives Help shape how emerging technology is adopted across public services Work across projects from initial discovery through to real-world implementation This is an excellent opportunity for a Business Analyst who wants to move further into AI and digital transformation, while working on projects with tangible organisational and service impact.
07/08/2026
Full time
Business Analyst AI & Digital Transformation Location: Gloucester Hybrid, 2 days per week on-site Salary: £50,000 Type: Permanent Benefits: Hybrid working + wider benefits package Our client, a leading public sector organisation, is hiring an experienced Business Analyst to support the delivery of AI, automation and digital transformation initiatives. This is an opportunity to work on projects that will have a genuine impact on how public services are delivered, identifying where AI and automation can improve processes, reduce manual activity and enable better decision-making. You ll work across the full project lifecycle, from discovery and requirements gathering through to testing and implementation, helping turn business challenges into practical, secure and responsible technology solutions. What you ll do Lead business and process analysis across AI and digital transformation projects Run workshops and discovery sessions with operational teams, technical specialists and senior stakeholders Map current and future-state processes and identify opportunities for improvement Gather and translate business needs into clear functional and non-functional requirements Develop user stories, acceptance criteria, use cases and process models Assess potential AI and automation use cases for feasibility, value and operational impact Work alongside data specialists, developers and architects to shape AI-enabled solutions Support proof-of-concept and pilot projects through to wider implementation Define success measures and benefits to demonstrate the value of new solutions Support testing, UAT and operational readiness ahead of go-live You ll work closely with digital, data, architecture, information governance, cyber security and operational teams, acting as the bridge between business requirements and technical delivery. What we re looking for Strong Business Analysis experience within complex digital or transformation programmes Previous experience within local government, central government, the NHS or another public sector environment Strong requirements gathering, process mapping and service improvement experience Experience working across the full project lifecycle, from discovery through to implementation Exposure to AI, automation, data, digital platforms or other emerging technologies Excellent stakeholder management skills, including working with senior and non-technical stakeholders Experience developing business cases, options appraisals and benefits measures Understanding of data protection, information governance and cyber security Experience working within Agile, Waterfall or hybrid delivery environments Experience with Generative AI, Microsoft Copilot, machine learning, Power Platform, Power Automate or Azure AI would be particularly beneficial. The ideal candidate will be analytical, pragmatic and comfortable challenging existing ways of working. You ll be able to translate complex technical concepts into clear business language and understand both the opportunities and limitations of AI. Why join? £50,000 salary Hybrid working with only 2 days per week in Gloucester Work on high-profile AI and digital transformation initiatives Help shape how emerging technology is adopted across public services Work across projects from initial discovery through to real-world implementation This is an excellent opportunity for a Business Analyst who wants to move further into AI and digital transformation, while working on projects with tangible organisational and service impact.
Cyber Security Lead / Information Security Lead Bedford, Bedfordshire Hybrid 3 Days Office / 2 Days Remote £60,000 £70,000 + Excellent Benefits Permanent Infrastructure Security Network Security Cyber Security ISO 27001 Azure Microsoft 365 Are you an experienced Cyber Security Lead, Information Security Lead or Senior Security Engineer looking for an opportunity to step into a broader security leadership role? We are looking for a technically strong Cyber Security Lead / Information Security Lead to join a growing technology business in Bedford. This is an excellent opportunity for an Infrastructure Security, Network Security or Cyber Security professional who wants greater ownership and influence while remaining close to the technical side of security. This is not a purely GRC or compliance-focused position. The successful Cyber Security Lead will bring a strong technical foundation across infrastructure, networks and security engineering, combined with experience or exposure to Information Security, ISO 27001, security governance, risk and compliance. Working closely with Infrastructure, IT Operations, Engineering and senior stakeholders, you'll help strengthen the organisation's security posture across networks, servers, cloud platforms, Microsoft 365, Azure and business systems. What You'll Be Doing As the Cyber Security Lead, you'll take a leading role in information security and cyber security activities across the organisation. You'll help develop and continually improve the Information Security Management System (ISMS), maintain ISO 27001, support internal and external security audits and ensure security controls remain practical, effective and appropriate. You'll work closely with technical teams on infrastructure security, network security, vulnerability management, patch management and security remediation, coordinating penetration testing and ensuring identified vulnerabilities and security issues are addressed effectively. You'll also manage information security risk assessments, support incident response, supplier and third-party security assurance, Business Continuity and Disaster Recovery, while helping embed a strong security culture across the organisation. The Technical Background We're Looking For We're particularly interested in candidates who have developed their careers through Infrastructure, Network or Cyber Security and are now ready to take on greater Information Security leadership responsibility. You'll ideally bring experience across: Network & Infrastructure Security: firewalls, networking, Windows Server, Active Directory, endpoints and infrastructure hardening. Cloud & Identity Security: Microsoft 365, Azure Security, Identity & Access Management (IAM) and access controls. Security Operations: vulnerability management, patch management, penetration testing, remediation and incident response. Information Security: ISO 27001, ISMS, security audits, Cyber Essentials, security policies, governance, risk and compliance. You don't necessarily need to already hold the title of Cyber Security Lead. We would also be interested in hearing from experienced Senior Cyber Security Analysts, Senior Information Security Analysts, Security Engineers, Infrastructure Security Engineers, Network Security Engineers and Technical Security Leads who are ready to take the next step. Strong communication and stakeholder management skills are important. You'll be comfortable working with technical teams while also being able to explain security risks, controls and priorities clearly to senior and non-technical stakeholders. Why Consider This Cyber Security Lead Role? This is an opportunity to move beyond a purely engineering-focused position and take broader ownership of Information Security and Cyber Security, without leaving your technical background behind. You'll have the opportunity to influence security strategy, improve technical security controls, develop the ISMS, support ISO 27001 and work across Infrastructure Security, Network Security, Cloud Security, Security Governance and Cyber Security. Salary: £60,000 £70,000 Location: Bedford, Bedfordshire Working Pattern: Hybrid 3 days office / 2 days remote Employment: Permanent Focus: Cyber Security, Information Security, Infrastructure Security & Network Security Frameworks: ISO 27001 / ISMS / Cyber Essentials Ready for Your Next Move? If you're an experienced Cyber Security Lead, Information Security Lead, Senior Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead or Senior Cyber Security Analyst, we'd like to hear from you. This could be an excellent next step for a technically strong security professional who wants to take greater ownership of Cyber Security and Information Security, influence security strategy and work across infrastructure, networks, cloud, risk, governance and compliance. Apply today for a confidential discussion. Key Skills: Cyber Security Lead, Information Security Lead, Cyber Security, Information Security, Infrastructure Security, Network Security, Security Engineering, Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead, ISO 27001, ISMS, GRC, Security Governance, Security Compliance, Vulnerability Management, Patch Management, Penetration Testing, Azure Security, Microsoft 365 Security, Active Directory, IAM, Firewalls, Incident Response, Cyber Essentials, Security Audits, Risk Management, Supplier Assurance, Business Continuity, Disaster Recovery.
07/08/2026
Full time
Cyber Security Lead / Information Security Lead Bedford, Bedfordshire Hybrid 3 Days Office / 2 Days Remote £60,000 £70,000 + Excellent Benefits Permanent Infrastructure Security Network Security Cyber Security ISO 27001 Azure Microsoft 365 Are you an experienced Cyber Security Lead, Information Security Lead or Senior Security Engineer looking for an opportunity to step into a broader security leadership role? We are looking for a technically strong Cyber Security Lead / Information Security Lead to join a growing technology business in Bedford. This is an excellent opportunity for an Infrastructure Security, Network Security or Cyber Security professional who wants greater ownership and influence while remaining close to the technical side of security. This is not a purely GRC or compliance-focused position. The successful Cyber Security Lead will bring a strong technical foundation across infrastructure, networks and security engineering, combined with experience or exposure to Information Security, ISO 27001, security governance, risk and compliance. Working closely with Infrastructure, IT Operations, Engineering and senior stakeholders, you'll help strengthen the organisation's security posture across networks, servers, cloud platforms, Microsoft 365, Azure and business systems. What You'll Be Doing As the Cyber Security Lead, you'll take a leading role in information security and cyber security activities across the organisation. You'll help develop and continually improve the Information Security Management System (ISMS), maintain ISO 27001, support internal and external security audits and ensure security controls remain practical, effective and appropriate. You'll work closely with technical teams on infrastructure security, network security, vulnerability management, patch management and security remediation, coordinating penetration testing and ensuring identified vulnerabilities and security issues are addressed effectively. You'll also manage information security risk assessments, support incident response, supplier and third-party security assurance, Business Continuity and Disaster Recovery, while helping embed a strong security culture across the organisation. The Technical Background We're Looking For We're particularly interested in candidates who have developed their careers through Infrastructure, Network or Cyber Security and are now ready to take on greater Information Security leadership responsibility. You'll ideally bring experience across: Network & Infrastructure Security: firewalls, networking, Windows Server, Active Directory, endpoints and infrastructure hardening. Cloud & Identity Security: Microsoft 365, Azure Security, Identity & Access Management (IAM) and access controls. Security Operations: vulnerability management, patch management, penetration testing, remediation and incident response. Information Security: ISO 27001, ISMS, security audits, Cyber Essentials, security policies, governance, risk and compliance. You don't necessarily need to already hold the title of Cyber Security Lead. We would also be interested in hearing from experienced Senior Cyber Security Analysts, Senior Information Security Analysts, Security Engineers, Infrastructure Security Engineers, Network Security Engineers and Technical Security Leads who are ready to take the next step. Strong communication and stakeholder management skills are important. You'll be comfortable working with technical teams while also being able to explain security risks, controls and priorities clearly to senior and non-technical stakeholders. Why Consider This Cyber Security Lead Role? This is an opportunity to move beyond a purely engineering-focused position and take broader ownership of Information Security and Cyber Security, without leaving your technical background behind. You'll have the opportunity to influence security strategy, improve technical security controls, develop the ISMS, support ISO 27001 and work across Infrastructure Security, Network Security, Cloud Security, Security Governance and Cyber Security. Salary: £60,000 £70,000 Location: Bedford, Bedfordshire Working Pattern: Hybrid 3 days office / 2 days remote Employment: Permanent Focus: Cyber Security, Information Security, Infrastructure Security & Network Security Frameworks: ISO 27001 / ISMS / Cyber Essentials Ready for Your Next Move? If you're an experienced Cyber Security Lead, Information Security Lead, Senior Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead or Senior Cyber Security Analyst, we'd like to hear from you. This could be an excellent next step for a technically strong security professional who wants to take greater ownership of Cyber Security and Information Security, influence security strategy and work across infrastructure, networks, cloud, risk, governance and compliance. Apply today for a confidential discussion. Key Skills: Cyber Security Lead, Information Security Lead, Cyber Security, Information Security, Infrastructure Security, Network Security, Security Engineering, Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead, ISO 27001, ISMS, GRC, Security Governance, Security Compliance, Vulnerability Management, Patch Management, Penetration Testing, Azure Security, Microsoft 365 Security, Active Directory, IAM, Firewalls, Incident Response, Cyber Essentials, Security Audits, Risk Management, Supplier Assurance, Business Continuity, Disaster Recovery.
Governance Risk and Compliance (GRC) Analyst Leeds, West Yorkshire, United Kingdom - Full Time Location : Hybrid - Remote / Leeds UK Position Title : Governance, Risk and Compliance (GRC) Analyst Job Type : Full-Time Assured Data Protection is a global leader in data backup and disaster recovery managed services, specialising in safeguarding against data loss and downtime in the event of a disaster, cyber, or ransomware attack. Our fully managed services include immutable backup, disaster recovery, and cyber resiliency to protect data on-premises and in the cloud, with 24/7/365 expert support. We offer a flexible, consumption-based model to grow with your business, making data protection cost-effective and scalable. Our purpose built software provides industry leading monitoring and reporting capabilities to provide actionable insights into your data protection strategy. Our global datacentres ensure data sovereignty, meeting your organisation's compliance requirements. A dedicated team is always available to recover your data and minimise disruption in the event of a disaster. As the Governance, Risk and Compliance Analyst, you will work under the direction of the Global Head of Compliance to ensure international compliance needs are met. The GRC analyst is a key member of the Governance, Risk and Compliance team, responsible for supporting the development, implementation and maintenance of the company's GRC framework. The role involves a blend of operational and analytical tasks, working closely with various departments to ensure adherence to internal policies and external regulations. The role is critical for developing, implementing and maintaining the business' GRC Framework, contributing to a culture of compliance, integrity and ethical conduct. Key Responsibilities: Governance Assist in maintaining our Information Security Management System (ISMS), Quality Management System (QMS) and SOC2 in our Compliance monitoring tooling. Support with policy development and creation. Compliance & Regulatory Adherence Complete customer, partner and vendor due diligence activities. Assist with internal and external audits. Identify and remedy gaps in policy and process to support compliance needs. Assist in the development of Compliance training programs to support a culture of compliance within the organisation. Risk Management Assist with our Risk Management process which includes maintenance of our Risk Register. Ensure identified risks are documented and logged on our InfoSec Risk Register. Key Experience and Qualifications: Preferred Qualifications Industry recognised certifications such as CRISC, ISO 27001 Lead Implementer would be highly beneficial. Experience Prior work experience or equivalent in the Technology sector. Prior work experience in international compliance frameworks and standards; such as UK & EU GDPR, HIPAA, PCI-DSS, NIST, SOC2, ISO 27001, ISO 9001. Project Management experience. Prior experience with compliance tooling. Experience working with Information Security and Legal Teams. Skills & Competencies Understanding of core Risk Management principles. Ability to embrace flexibility and adapt seamlessly to change. Ability to use initiative to solve complex problems. Ability to communicate with stakeholders at every seniority level of the business. What We Offer: Hybrid working options for flexibility Regular team building and off site company events. A dynamic, inclusive, and collaborative work environment At Assured Data Protection we value diversity and inclusivity. We offer perks such as flex holidays and flexible working practices to allow our employees to show up as their whole selves. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know. You must have the legal right to work in the UK at the time of application, as we are unable to offer visa sponsorship for this role.
06/08/2026
Full time
Governance Risk and Compliance (GRC) Analyst Leeds, West Yorkshire, United Kingdom - Full Time Location : Hybrid - Remote / Leeds UK Position Title : Governance, Risk and Compliance (GRC) Analyst Job Type : Full-Time Assured Data Protection is a global leader in data backup and disaster recovery managed services, specialising in safeguarding against data loss and downtime in the event of a disaster, cyber, or ransomware attack. Our fully managed services include immutable backup, disaster recovery, and cyber resiliency to protect data on-premises and in the cloud, with 24/7/365 expert support. We offer a flexible, consumption-based model to grow with your business, making data protection cost-effective and scalable. Our purpose built software provides industry leading monitoring and reporting capabilities to provide actionable insights into your data protection strategy. Our global datacentres ensure data sovereignty, meeting your organisation's compliance requirements. A dedicated team is always available to recover your data and minimise disruption in the event of a disaster. As the Governance, Risk and Compliance Analyst, you will work under the direction of the Global Head of Compliance to ensure international compliance needs are met. The GRC analyst is a key member of the Governance, Risk and Compliance team, responsible for supporting the development, implementation and maintenance of the company's GRC framework. The role involves a blend of operational and analytical tasks, working closely with various departments to ensure adherence to internal policies and external regulations. The role is critical for developing, implementing and maintaining the business' GRC Framework, contributing to a culture of compliance, integrity and ethical conduct. Key Responsibilities: Governance Assist in maintaining our Information Security Management System (ISMS), Quality Management System (QMS) and SOC2 in our Compliance monitoring tooling. Support with policy development and creation. Compliance & Regulatory Adherence Complete customer, partner and vendor due diligence activities. Assist with internal and external audits. Identify and remedy gaps in policy and process to support compliance needs. Assist in the development of Compliance training programs to support a culture of compliance within the organisation. Risk Management Assist with our Risk Management process which includes maintenance of our Risk Register. Ensure identified risks are documented and logged on our InfoSec Risk Register. Key Experience and Qualifications: Preferred Qualifications Industry recognised certifications such as CRISC, ISO 27001 Lead Implementer would be highly beneficial. Experience Prior work experience or equivalent in the Technology sector. Prior work experience in international compliance frameworks and standards; such as UK & EU GDPR, HIPAA, PCI-DSS, NIST, SOC2, ISO 27001, ISO 9001. Project Management experience. Prior experience with compliance tooling. Experience working with Information Security and Legal Teams. Skills & Competencies Understanding of core Risk Management principles. Ability to embrace flexibility and adapt seamlessly to change. Ability to use initiative to solve complex problems. Ability to communicate with stakeholders at every seniority level of the business. What We Offer: Hybrid working options for flexibility Regular team building and off site company events. A dynamic, inclusive, and collaborative work environment At Assured Data Protection we value diversity and inclusivity. We offer perks such as flex holidays and flexible working practices to allow our employees to show up as their whole selves. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know. You must have the legal right to work in the UK at the time of application, as we are unable to offer visa sponsorship for this role.
Title: Senior Security Operations Analyst Location: Hybrid - Manchester or Leeds 3 days per week, 2 days remote Salary: From £54,000 Who we are: interactive investor is an award-winning investment platform that puts its customers in control of their financial future. We've been helping investors for nearly 30 years. We've seen market highs and lows and been resilient throughout. We're now the UK's number one flat-fee investment platform, with assets under administration approaching £75 billion and over 500,000 customers. For a simple, flat monthly fee we provide a secure home for your pensions, ISAs and investments. We offer a wide choice of over 20,000 UK and international investment options, including shares, funds, trusts and ETFs. We also bring impartial, expert content from our award-winning financial journalists, highly engaged community of investors, and daily newsletters and insights. Purpose of the Role We are recruiting for a Senior Security Operations Analyst to join the Information Security Team to support our continued growth. You will help maintain and protect our key business assets from threats and risks by monitoring, detecting, analysing, and responding to security incidents. Key Responsibilities Oversee the day to day running of our SIEM solution (Chronicle) working closely with Infrastructure, Networks, DevOps and our outsourced Security Operations Centre (SOC) team. Define and facilitate the creation of new rules or fine-tuning existing rules within SIEM. Investigate SIEM alerts and other security incidents through to completion. Work within the Information Security Team to provide a dynamic monitoring and incident response capability. Monitor and analyse security events identifying trends, attacks, and potential threats. Identify and raise problems. Communicate & raise these via the appropriate channels and track through to remediation. Monitoring and gathering Threat intelligence and coordinating subsequent Threat Hunting. Assess security threats from multiple sources and plan mitigation/remediation. Gather relevant data, analyse and respond to cyber security incidents. Research and stay current on the latest trends, best practices, and technology developments for all things cyber. Assist in the design, management, and documentation of security policies, solutions, standards, and processes. Designing effective test methods for logical security controls. Day to day management of Endpoint Detection and Response (EDR). REQUIREMENTS A good understanding of technical and network security requirements. Ability to proactively identify control weakness and vulnerabilities. Knowledge and use of SIEM tooling i.e., Splunk, Chronicle, Sentinel etc and event log data. Experience in understanding Firewalls and IDS/IPS and Windows Security Event Logs. Strong verbal and written communication skills with the ability to articulate complex ideas in easy to comprehend business terms. Comfortable taking ownership for own work, identifying the need for action whilst working effectively within a team. Ability to quickly understand existing infrastructure, network security principles, data flow and security architectures. Knowledge of the fundamentals of cloud infrastructure as well as traditional technologies. Degree in IT / Cyber preferred or industry recognised qualification. BENEFITS Group Personal Pension Plan - 8% employer contribution and 4% employee contribution Life Assurance and Group Income Protection Private Medical Insurance - Provided by Bupa 25 Days Annual Leave, plus bank holidays Staff Discounts on our investment products Personal & Well-being Fund - Supporting your physical and mental wellness Retail Discounts - Savings at a wide range of high street and online retailers Voluntary Flexible Benefits - Tailor your benefits to suit your lifestyle
06/08/2026
Full time
Title: Senior Security Operations Analyst Location: Hybrid - Manchester or Leeds 3 days per week, 2 days remote Salary: From £54,000 Who we are: interactive investor is an award-winning investment platform that puts its customers in control of their financial future. We've been helping investors for nearly 30 years. We've seen market highs and lows and been resilient throughout. We're now the UK's number one flat-fee investment platform, with assets under administration approaching £75 billion and over 500,000 customers. For a simple, flat monthly fee we provide a secure home for your pensions, ISAs and investments. We offer a wide choice of over 20,000 UK and international investment options, including shares, funds, trusts and ETFs. We also bring impartial, expert content from our award-winning financial journalists, highly engaged community of investors, and daily newsletters and insights. Purpose of the Role We are recruiting for a Senior Security Operations Analyst to join the Information Security Team to support our continued growth. You will help maintain and protect our key business assets from threats and risks by monitoring, detecting, analysing, and responding to security incidents. Key Responsibilities Oversee the day to day running of our SIEM solution (Chronicle) working closely with Infrastructure, Networks, DevOps and our outsourced Security Operations Centre (SOC) team. Define and facilitate the creation of new rules or fine-tuning existing rules within SIEM. Investigate SIEM alerts and other security incidents through to completion. Work within the Information Security Team to provide a dynamic monitoring and incident response capability. Monitor and analyse security events identifying trends, attacks, and potential threats. Identify and raise problems. Communicate & raise these via the appropriate channels and track through to remediation. Monitoring and gathering Threat intelligence and coordinating subsequent Threat Hunting. Assess security threats from multiple sources and plan mitigation/remediation. Gather relevant data, analyse and respond to cyber security incidents. Research and stay current on the latest trends, best practices, and technology developments for all things cyber. Assist in the design, management, and documentation of security policies, solutions, standards, and processes. Designing effective test methods for logical security controls. Day to day management of Endpoint Detection and Response (EDR). REQUIREMENTS A good understanding of technical and network security requirements. Ability to proactively identify control weakness and vulnerabilities. Knowledge and use of SIEM tooling i.e., Splunk, Chronicle, Sentinel etc and event log data. Experience in understanding Firewalls and IDS/IPS and Windows Security Event Logs. Strong verbal and written communication skills with the ability to articulate complex ideas in easy to comprehend business terms. Comfortable taking ownership for own work, identifying the need for action whilst working effectively within a team. Ability to quickly understand existing infrastructure, network security principles, data flow and security architectures. Knowledge of the fundamentals of cloud infrastructure as well as traditional technologies. Degree in IT / Cyber preferred or industry recognised qualification. BENEFITS Group Personal Pension Plan - 8% employer contribution and 4% employee contribution Life Assurance and Group Income Protection Private Medical Insurance - Provided by Bupa 25 Days Annual Leave, plus bank holidays Staff Discounts on our investment products Personal & Well-being Fund - Supporting your physical and mental wellness Retail Discounts - Savings at a wide range of high street and online retailers Voluntary Flexible Benefits - Tailor your benefits to suit your lifestyle
Technical Specialist - Detection, Engineering and Automation申请locations: Kingswood Fields Officetime type: Full timeposted on: 今天发布time left to apply: 结束日期:2026年7月31日 (申请时间还剩 30+ 天)job requisition id: J67604# About the Opportunity Job Type: PermanentApplication Deadline: 31 July 2026 Job Description Title Technical Specialist -Detection, Engineering and Automation Department FIL - Global Cybersecurity Operations Location Kingswood, Surrey Reports To Senior Manager - Detection, Engineering and Automation Level 4 We share a commitment to making things better for clients and each other. We continually explore new technology and different ways of working to put our clients first. So bring your boldest ideas to our Cyber Defense Operations team and feel like you're making progress. About your team Technology function across FIL is responsible for all global aspects of Technology, Digital, Cybersecurity, and Innovation. Fidelity is a value-driven, customer-obsessed organization and in Technology we are fortunate to play a direct role in helping our clients with one of the most important aspects of their lives - their financial well-being. Within the Technology function is our Global Cyber & Information Security (GCIS) that operates enterprise security services and controls. These are designed to mitigate Cyber and Information Security risks ensuring that Fidelity's business operates securely. The Technical Cybersecurity teams monitor both the internal and external threat environment, responding to security alerts and events in close to real time, as well as providing security assurance and access management services across the enterprise technology and business environment. Our global innovative Cyber Defence Operations team sits within GCIS and provides proactive, cutting-edge solutions to protect clients' digital assets and infrastructure against evolving cyber threats. The Detection Engineering & Automation team within our Global Cybersecurity Operations focuses on the development of automated detection capabilities to reduce manual effort of the Global Cybersecurity Operations team freeing up time to focus on real cyber threats. They ensure that security controls are performing effectively and efficiently and that they are feeding into automation technologies allowing the organisation to make intelligent correlated decisions. About your role The Detection Engineering & Automation Specialist plays a critical hands on role in strengthening the Global Cybersecurity Operations capability by building, maintaining and enhancing the security tooling that underpins our detection and response functions. The ideal candidate will work deeply across technologies including SIEM, SOAR, EDR, email security and cloud security platforms, contributing engineering expertise to ensure these controls operate effectively and deliver high quality telemetry. You will be responsible for developing and improving detections, building CI/CD pipelines, onboarding new log sources, implementing automation and supporting technical investigations during security incidents. The ideal candidate has experience using a wide range of security technologies to enhance detection coverage, streamline analyst workflows and support the ongoing maintenance and optimisation of critical security controls. This role is essential in supporting engineering maturity and ensuring our cyber defence capabilities remain modern, integrated and responsive to evolving threats. About you Key Responsibilities The Detection, Automation and Engineering Specialist will be responsible to: Build, maintain and enhance security detections using Sentinel as Code, ensuring accurate and high quality analytics. Develop and maintain CI/CD pipelines to automate deployment of detections, automation playbooks and configuration updates. Engineer and optimise SOAR automation and integrations to reduce manual analyst workload and streamline response processes. Onboard high value security logs into the SIEM from the backlog, ensuring quality, normalisation and integration into detection logic. Support SOC and CIRT during incidents by providing engineering expertise, rapid telemetry onboarding, and timely detection and automation enhancements. Maintain and improve security controls across SIEM, SOAR, EDR, email security and network detection tooling. Assess and implement tool updates, new features and product enhancements, ensuring their secure and effective adoption across the environment. Manage tooling related incidents with vendors and internal teams, ensuring business impact is known, communicated and minimised. Work with global engineering teams to deliver high priority backlog items and operational improvements. Collaborate with front line analysts to identify quick win improvements for detections, automation and tooling integrations. Produce clear documentation, reporting and quality checks to support engineering delivery and continuous improvement. Experience and Skills Required At least 4 years of experience working in a Detection Engineering function, or a combination of Detection Engineering and hands on engineering responsibilities within a SOC environment. Experience focusing on automation, engineering maturity and continuous improvement within security operations. Experience managing and maintaining security tools within a global environment, preferably within Financial Services. Hands on experience developing detections in Microsoft Sentinel, including strong KQL and detection as code practices. Proven ability to build and maintain CI/CD pipelines (Azure DevOps, GitHub Actions) for detection, automation and configuration deployments. Experience onboarding and operationalising new log sources into a SIEM, ensuring data quality, enrichment and alignment with detection logic. Practical experience engineering SIEM, SOAR or EDR platforms and improving their operational effectiveness. Experience supporting security incidents from an engineering perspective by enabling telemetry, building detections and enhancing automation under time pressure. Strong experience with cloud platforms, particularly AWS and Azure, including their native security telemetry and integrations. Experience with email security solutions (such as Proofpoint, Microsoft Defender for Office 365, or equivalent), with a solid understanding of how email telemetry can be used in detection engineering. Strong scripting skills (PowerShell, Python, Bash or JavaScript) for automation, integration and tooling improvements. Familiarity with YAML/JSON, IaC principles and modern automation frameworks. Knowledge of Azure and/or AWS cloud environments and their native security telemetry. Strong communication skills with the ability to take technical feedback from SOC/CIRT and translate it into meaningful engineering improvements. Analytical mindset with a passion for cybersecurity, process improvement and challenging inefficient workflows. Preferred Certifications: Microsoft SC 200, AZ 500, AWS Security Specialty, CySA+, SSCP, OSCP. Feel rewarded For starters, we'll offer you a comprehensive benefits package. We'll value your wellbeing and support your development. And we'll be as flexible as we can about where and when you work - finding a balance that works for all of us. It's all part of our commitment to making you feel motivated by the work you do and happy to be part of our team. For more about our work, our approach to dynamic working and how you could build your future here, visit For more about our work, our approach to dynamic working and how you could build your future here, visit As an international financial services organisation, we are in-scope of international regulations in the way that we carry out our work. This position is involved in work that is regulated by the FCA and/or the PRA and their Individual Conduct Rules (COCON) apply to it, along with any other regulation. We provide training on COCON and how it affects our employees. More information about COCON can be found in the Employment Handbook.
06/08/2026
Full time
Technical Specialist - Detection, Engineering and Automation申请locations: Kingswood Fields Officetime type: Full timeposted on: 今天发布time left to apply: 结束日期:2026年7月31日 (申请时间还剩 30+ 天)job requisition id: J67604# About the Opportunity Job Type: PermanentApplication Deadline: 31 July 2026 Job Description Title Technical Specialist -Detection, Engineering and Automation Department FIL - Global Cybersecurity Operations Location Kingswood, Surrey Reports To Senior Manager - Detection, Engineering and Automation Level 4 We share a commitment to making things better for clients and each other. We continually explore new technology and different ways of working to put our clients first. So bring your boldest ideas to our Cyber Defense Operations team and feel like you're making progress. About your team Technology function across FIL is responsible for all global aspects of Technology, Digital, Cybersecurity, and Innovation. Fidelity is a value-driven, customer-obsessed organization and in Technology we are fortunate to play a direct role in helping our clients with one of the most important aspects of their lives - their financial well-being. Within the Technology function is our Global Cyber & Information Security (GCIS) that operates enterprise security services and controls. These are designed to mitigate Cyber and Information Security risks ensuring that Fidelity's business operates securely. The Technical Cybersecurity teams monitor both the internal and external threat environment, responding to security alerts and events in close to real time, as well as providing security assurance and access management services across the enterprise technology and business environment. Our global innovative Cyber Defence Operations team sits within GCIS and provides proactive, cutting-edge solutions to protect clients' digital assets and infrastructure against evolving cyber threats. The Detection Engineering & Automation team within our Global Cybersecurity Operations focuses on the development of automated detection capabilities to reduce manual effort of the Global Cybersecurity Operations team freeing up time to focus on real cyber threats. They ensure that security controls are performing effectively and efficiently and that they are feeding into automation technologies allowing the organisation to make intelligent correlated decisions. About your role The Detection Engineering & Automation Specialist plays a critical hands on role in strengthening the Global Cybersecurity Operations capability by building, maintaining and enhancing the security tooling that underpins our detection and response functions. The ideal candidate will work deeply across technologies including SIEM, SOAR, EDR, email security and cloud security platforms, contributing engineering expertise to ensure these controls operate effectively and deliver high quality telemetry. You will be responsible for developing and improving detections, building CI/CD pipelines, onboarding new log sources, implementing automation and supporting technical investigations during security incidents. The ideal candidate has experience using a wide range of security technologies to enhance detection coverage, streamline analyst workflows and support the ongoing maintenance and optimisation of critical security controls. This role is essential in supporting engineering maturity and ensuring our cyber defence capabilities remain modern, integrated and responsive to evolving threats. About you Key Responsibilities The Detection, Automation and Engineering Specialist will be responsible to: Build, maintain and enhance security detections using Sentinel as Code, ensuring accurate and high quality analytics. Develop and maintain CI/CD pipelines to automate deployment of detections, automation playbooks and configuration updates. Engineer and optimise SOAR automation and integrations to reduce manual analyst workload and streamline response processes. Onboard high value security logs into the SIEM from the backlog, ensuring quality, normalisation and integration into detection logic. Support SOC and CIRT during incidents by providing engineering expertise, rapid telemetry onboarding, and timely detection and automation enhancements. Maintain and improve security controls across SIEM, SOAR, EDR, email security and network detection tooling. Assess and implement tool updates, new features and product enhancements, ensuring their secure and effective adoption across the environment. Manage tooling related incidents with vendors and internal teams, ensuring business impact is known, communicated and minimised. Work with global engineering teams to deliver high priority backlog items and operational improvements. Collaborate with front line analysts to identify quick win improvements for detections, automation and tooling integrations. Produce clear documentation, reporting and quality checks to support engineering delivery and continuous improvement. Experience and Skills Required At least 4 years of experience working in a Detection Engineering function, or a combination of Detection Engineering and hands on engineering responsibilities within a SOC environment. Experience focusing on automation, engineering maturity and continuous improvement within security operations. Experience managing and maintaining security tools within a global environment, preferably within Financial Services. Hands on experience developing detections in Microsoft Sentinel, including strong KQL and detection as code practices. Proven ability to build and maintain CI/CD pipelines (Azure DevOps, GitHub Actions) for detection, automation and configuration deployments. Experience onboarding and operationalising new log sources into a SIEM, ensuring data quality, enrichment and alignment with detection logic. Practical experience engineering SIEM, SOAR or EDR platforms and improving their operational effectiveness. Experience supporting security incidents from an engineering perspective by enabling telemetry, building detections and enhancing automation under time pressure. Strong experience with cloud platforms, particularly AWS and Azure, including their native security telemetry and integrations. Experience with email security solutions (such as Proofpoint, Microsoft Defender for Office 365, or equivalent), with a solid understanding of how email telemetry can be used in detection engineering. Strong scripting skills (PowerShell, Python, Bash or JavaScript) for automation, integration and tooling improvements. Familiarity with YAML/JSON, IaC principles and modern automation frameworks. Knowledge of Azure and/or AWS cloud environments and their native security telemetry. Strong communication skills with the ability to take technical feedback from SOC/CIRT and translate it into meaningful engineering improvements. Analytical mindset with a passion for cybersecurity, process improvement and challenging inefficient workflows. Preferred Certifications: Microsoft SC 200, AZ 500, AWS Security Specialty, CySA+, SSCP, OSCP. Feel rewarded For starters, we'll offer you a comprehensive benefits package. We'll value your wellbeing and support your development. And we'll be as flexible as we can about where and when you work - finding a balance that works for all of us. It's all part of our commitment to making you feel motivated by the work you do and happy to be part of our team. For more about our work, our approach to dynamic working and how you could build your future here, visit For more about our work, our approach to dynamic working and how you could build your future here, visit As an international financial services organisation, we are in-scope of international regulations in the way that we carry out our work. This position is involved in work that is regulated by the FCA and/or the PRA and their Individual Conduct Rules (COCON) apply to it, along with any other regulation. We provide training on COCON and how it affects our employees. More information about COCON can be found in the Employment Handbook.
ECI is the leading global provider of managed services, cybersecurity, and business transformation for mid-market financial services organizations across the globe. From its unmatched range of services, ECI provides stability, security and improved business performance, freeing clients from technology concerns and enabling them to focus on running their businesses. More than 1,000 customers worldwide with over $3 trillion of assets under management put their trust in ECI. At ECI, we believe success is driven by passion and purpose. Our passion for technology is only surpassed by our commitment to empowering ouremployees around the world. The Opportunity: ECI is seeking an enthusiastic, personable, and qualified Service Desk Analyst with proficiency in a range of technologies and highly adept problem-solving skills to join our amazing team of Technologists. In this role, you will provide end-user desktop support to multiple users at multiple locations running Windows, Exchange, and Office 365 environments.The successful Service Desk Analyst will "see the world through the eyes of the customer" delivering world class desktop support and end-user server administration for all client issues while responding to Level 1 and 2 service tickets in a fast-paced, dynamic environment. In addition, you will work shoulder to shoulder with an awesome team! Interfacing with high profile financial industry clients daily, you will provide unparalleled IT Support and Fully Managed Helpdesk Services. We're not just about fixing issues; we're about creating solutions!No two days are ever the same within this role, and the successful candidate will be expected to identify trends and patterns, which will inform continual service improvement activities and contribute to the transformation of the service desk, through creative thinking and optimization of service desk processes. This is an onsite role for qualified candidates commutable to the London area. What you will do: Provide Level 1 and 2 end-user desktop support to multiple users at multiple locations running Windows, Exchange, and Office 365 environments. "See the world through the eyes of the customer" delivering world classdesktop support for all client issues while responding to Level 1 and 2 service tickets. There is also the potential for Tier 3 support work in conjunction with a Senior Technician. Triage daily support incidents, desktop and light server troubleshooting, hardware and software installation, upgrades, and transformative projects. Action daily midlevel to advanced infrastructure support incidents Resolve incidents and requests related to, but not limited to the following: Mail Application/Office 365 issues, Client/Server Connectivity issues, Time Sensitive and VIP Workstation incidents, File Restores, Remote Access incidents (Citrix and Terminal Services), Password Resets to name a few. Execute basic system maintenance including software and operating system patching and software version upgrades. Provide support of Active Directory such as add/remove users, password resets and Group Policy application. Interface with common technology support tools such as Remote Monitoring and Management (RMM), Mobile Device Management (MDM) Project work for the installation & Support of Windows PCs & Servers, Azure & Microsoft 365, VMware & Cloud Migration Services. Creation and administration of user accounts on all group technology supported systems. Work closely with other IT teams to ensure swift ticket resolution and ensure Service level agreements ("SLAs") are being met. Contact third-party vendors for warranty service repair. Who you are: Minimum 2 years of end user support Microsoft Operating Systems such as Windows 10,11 Microsoft Office along with Exceptional experience MS Office Suite including Office 365 installation and administration, configuration, and troubleshooting. Provide midlevel - advanced support and guidance to end-users on all aspects of Office 365 applications and services, including but not limited to Outlook, SharePoint, Teams, OneDrive, and Office Suite. Hands-on experience with Azure, Intune, OneDrive, Exchange online and SharePoint. With some expertise in Azure services. Basic PowerShell experience, e.g., copy/paste (not writing script) Android/iOS configuration, troubleshooting and potential integration with MDM solutions. Familiar with cyber-security concepts, e.g., Multi-Factor Authentication (MFA), Anti-virus/Anti-malware, Software Firewall, Web Filtering. Basic Networking: TCP/IP, LAN/WAN, DHCP, DNS, DFS, Routing, Switching and Firewalls. Along with understanding of networking concepts and security principles in Azure environments. Experience with hardware troubleshooting (desktop/laptop, printer, mobile device) Excellent communication and customer service skills with a strong ability to articulate technical information to non-technical people. Familiarity with file system support including permissions, sharing, backups and restores. Experience working a service desk ticketing system (ServiceNow, ConnectWise, Jira etc.) Experience troubleshooting file and print services. Bonus points if you have: Familiarity of ITIL, and ITIL best practices within an IT operations environment Certifications in AZ900, M365 fundamentals, ITIL V4 Experience with Managed Service Providers (MSP) Experience with Market Data vendors like Bloomberg, Reuters, Factset ECI's culture is all about connection - connection with our clients, our technology and most importantly with each other. In addition to working with an amazing team around the world, ECI also offers a competitive compensation package and so much more! If you believe you'd be a great fit and are ready for your best job ever, Love Your Job, Share Your Technology Passion, Create Your Future Here!
05/08/2026
Full time
ECI is the leading global provider of managed services, cybersecurity, and business transformation for mid-market financial services organizations across the globe. From its unmatched range of services, ECI provides stability, security and improved business performance, freeing clients from technology concerns and enabling them to focus on running their businesses. More than 1,000 customers worldwide with over $3 trillion of assets under management put their trust in ECI. At ECI, we believe success is driven by passion and purpose. Our passion for technology is only surpassed by our commitment to empowering ouremployees around the world. The Opportunity: ECI is seeking an enthusiastic, personable, and qualified Service Desk Analyst with proficiency in a range of technologies and highly adept problem-solving skills to join our amazing team of Technologists. In this role, you will provide end-user desktop support to multiple users at multiple locations running Windows, Exchange, and Office 365 environments.The successful Service Desk Analyst will "see the world through the eyes of the customer" delivering world class desktop support and end-user server administration for all client issues while responding to Level 1 and 2 service tickets in a fast-paced, dynamic environment. In addition, you will work shoulder to shoulder with an awesome team! Interfacing with high profile financial industry clients daily, you will provide unparalleled IT Support and Fully Managed Helpdesk Services. We're not just about fixing issues; we're about creating solutions!No two days are ever the same within this role, and the successful candidate will be expected to identify trends and patterns, which will inform continual service improvement activities and contribute to the transformation of the service desk, through creative thinking and optimization of service desk processes. This is an onsite role for qualified candidates commutable to the London area. What you will do: Provide Level 1 and 2 end-user desktop support to multiple users at multiple locations running Windows, Exchange, and Office 365 environments. "See the world through the eyes of the customer" delivering world classdesktop support for all client issues while responding to Level 1 and 2 service tickets. There is also the potential for Tier 3 support work in conjunction with a Senior Technician. Triage daily support incidents, desktop and light server troubleshooting, hardware and software installation, upgrades, and transformative projects. Action daily midlevel to advanced infrastructure support incidents Resolve incidents and requests related to, but not limited to the following: Mail Application/Office 365 issues, Client/Server Connectivity issues, Time Sensitive and VIP Workstation incidents, File Restores, Remote Access incidents (Citrix and Terminal Services), Password Resets to name a few. Execute basic system maintenance including software and operating system patching and software version upgrades. Provide support of Active Directory such as add/remove users, password resets and Group Policy application. Interface with common technology support tools such as Remote Monitoring and Management (RMM), Mobile Device Management (MDM) Project work for the installation & Support of Windows PCs & Servers, Azure & Microsoft 365, VMware & Cloud Migration Services. Creation and administration of user accounts on all group technology supported systems. Work closely with other IT teams to ensure swift ticket resolution and ensure Service level agreements ("SLAs") are being met. Contact third-party vendors for warranty service repair. Who you are: Minimum 2 years of end user support Microsoft Operating Systems such as Windows 10,11 Microsoft Office along with Exceptional experience MS Office Suite including Office 365 installation and administration, configuration, and troubleshooting. Provide midlevel - advanced support and guidance to end-users on all aspects of Office 365 applications and services, including but not limited to Outlook, SharePoint, Teams, OneDrive, and Office Suite. Hands-on experience with Azure, Intune, OneDrive, Exchange online and SharePoint. With some expertise in Azure services. Basic PowerShell experience, e.g., copy/paste (not writing script) Android/iOS configuration, troubleshooting and potential integration with MDM solutions. Familiar with cyber-security concepts, e.g., Multi-Factor Authentication (MFA), Anti-virus/Anti-malware, Software Firewall, Web Filtering. Basic Networking: TCP/IP, LAN/WAN, DHCP, DNS, DFS, Routing, Switching and Firewalls. Along with understanding of networking concepts and security principles in Azure environments. Experience with hardware troubleshooting (desktop/laptop, printer, mobile device) Excellent communication and customer service skills with a strong ability to articulate technical information to non-technical people. Familiarity with file system support including permissions, sharing, backups and restores. Experience working a service desk ticketing system (ServiceNow, ConnectWise, Jira etc.) Experience troubleshooting file and print services. Bonus points if you have: Familiarity of ITIL, and ITIL best practices within an IT operations environment Certifications in AZ900, M365 fundamentals, ITIL V4 Experience with Managed Service Providers (MSP) Experience with Market Data vendors like Bloomberg, Reuters, Factset ECI's culture is all about connection - connection with our clients, our technology and most importantly with each other. In addition to working with an amazing team around the world, ECI also offers a competitive compensation package and so much more! If you believe you'd be a great fit and are ready for your best job ever, Love Your Job, Share Your Technology Passion, Create Your Future Here!
Data Protection AnalystApplylocations: Englandtime type: Full timeposted on: Posted Todayjob requisition id: R14541 About Us: Proofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend data and protect people. How We Work: At Proofpoint you'll be part of a global team that breaks barriers to redefine cybersecurity guided by our BRAVE core values: Bold in how we dream and innovate Responsive to feedback, challenges and opportunities Accountable for results and best in class outcomes Visionary in future focused problem-solving Exceptional in execution and impact The Role This is a Data Protection Analyst role with a clear technical development pathway into Information Protection engineering. It combines day-to-day data protection operations with hands-on exposure to troubleshooting, policy and rule validation, platform health, configuration support and technical delivery.You will work alongside experienced engineers and service teams, taking ownership of first-line technical work and building towards greater responsibility for standard configuration and production changes as your capability grows.This role suits a curious, hands-on problem solver who enjoys learning technology, breaking issues down step by step and growing into engineering ownership. Your day to day Monitor and triage alerts across DLP, Insider Risk, endpoint, cloud and email security services. Investigate policy triggers, gather evidence, record clear findings and escalate risk when needed. Complete platform health checks covering endpoint connectivity, agents, telemetry and integrations. Verify new and updated rules, including monthly hot items, alert accuracy, exceptions and false positives. Handle Level 1 client requests, resolving standard issues or escalating with useful technical evidence. Troubleshoot methodically using logs, dashboards and testing to isolate likely root causes. Support policy and rule configuration, testing, tuning, validation and handover activities. Assist with approved platform changes and progressively own standard changes as capability grows. Research product behaviour, known issues and configuration options, then recommend next steps. Keep workbooks, runbooks, change records, knowledge articles and customer documentation accurate. Work with senior engineers, consultants and service managers to improve repeatable service delivery. Qualifications A genuine interest in data protection, cyber security and developing into a technical engineering role. A logical troubleshooting mindset and the patience to work through a problem step by step. Basic knowledge of networking, compute, endpoints, identity and how SaaS services connect. Confidence reading logs, technical documentation and system information to form a clear view. Curiosity, grit and ownership, with the drive to keep learning when the answer is not obvious. Clear written and verbal communication, including the ability to explain findings simply. Strong attention to detail and an organised approach to evidence, records and follow-up actions. A collaborative, customer-focused approach and the judgement to ask for support when needed.Desirable Experience Experience in data protection, security operations, a service desk, technical support or a similar client-facing role. Exposure to Proofpoint Data Security, DLP, Insider Threat Management, Email Protection or comparable platforms. Experience reviewing alerts, policy matches, endpoint health, agent status or telemetry. Familiarity with TCP/IP, DNS, HTTP/S, proxies, firewalls and email flow at a practical level. Working knowledge of Windows or macOS endpoints, cloud services, SaaS administration or identity and access. Experience testing or tuning policies and rules, validating outcomes or supporting controlled changes. Comfort using log search, dashboards, reporting tools, vendor knowledge bases or technical documentation. Relevant training or certification in cyber security, networking, cloud, systems or a related discipline. Awareness of scripting, APIs or automation concepts, with an interest in developing these skills. Additional information This role is designed to build a strong foundation in Information Protection operations and engineering. With coaching, product learning and demonstrated capability, the role can expand from investigation and validation into greater ownership of configuration, testing, standard changes and technical delivery.Success will be shaped by how you learn, troubleshoot, communicate and take ownership - not by already being a fully formed engineer on day one.You do not need to meet every point. We value technical aptitude, learning ability and the right mindset alongside experience. Why Proofpoint? At Proofpoint, we believe that an exceptional career experience includes a comprehensive compensation and benefits package. Here are just a few reasons you'll love working with us: Competitive compensation Comprehensive benefits Career success on your terms Flexible work environment Annual wellness and community outreach days Always on recognition for your contributions Global collaboration and networking opportunities Our Culture: Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone.We encourage applications from individuals of all backgrounds, experiences, and perspectives. If you need accommodation during the application or interview process, please reach out to . How to Apply Interested? Submit your application along with any supporting information- we can't wait to hear from you!
05/08/2026
Full time
Data Protection AnalystApplylocations: Englandtime type: Full timeposted on: Posted Todayjob requisition id: R14541 About Us: Proofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend data and protect people. How We Work: At Proofpoint you'll be part of a global team that breaks barriers to redefine cybersecurity guided by our BRAVE core values: Bold in how we dream and innovate Responsive to feedback, challenges and opportunities Accountable for results and best in class outcomes Visionary in future focused problem-solving Exceptional in execution and impact The Role This is a Data Protection Analyst role with a clear technical development pathway into Information Protection engineering. It combines day-to-day data protection operations with hands-on exposure to troubleshooting, policy and rule validation, platform health, configuration support and technical delivery.You will work alongside experienced engineers and service teams, taking ownership of first-line technical work and building towards greater responsibility for standard configuration and production changes as your capability grows.This role suits a curious, hands-on problem solver who enjoys learning technology, breaking issues down step by step and growing into engineering ownership. Your day to day Monitor and triage alerts across DLP, Insider Risk, endpoint, cloud and email security services. Investigate policy triggers, gather evidence, record clear findings and escalate risk when needed. Complete platform health checks covering endpoint connectivity, agents, telemetry and integrations. Verify new and updated rules, including monthly hot items, alert accuracy, exceptions and false positives. Handle Level 1 client requests, resolving standard issues or escalating with useful technical evidence. Troubleshoot methodically using logs, dashboards and testing to isolate likely root causes. Support policy and rule configuration, testing, tuning, validation and handover activities. Assist with approved platform changes and progressively own standard changes as capability grows. Research product behaviour, known issues and configuration options, then recommend next steps. Keep workbooks, runbooks, change records, knowledge articles and customer documentation accurate. Work with senior engineers, consultants and service managers to improve repeatable service delivery. Qualifications A genuine interest in data protection, cyber security and developing into a technical engineering role. A logical troubleshooting mindset and the patience to work through a problem step by step. Basic knowledge of networking, compute, endpoints, identity and how SaaS services connect. Confidence reading logs, technical documentation and system information to form a clear view. Curiosity, grit and ownership, with the drive to keep learning when the answer is not obvious. Clear written and verbal communication, including the ability to explain findings simply. Strong attention to detail and an organised approach to evidence, records and follow-up actions. A collaborative, customer-focused approach and the judgement to ask for support when needed.Desirable Experience Experience in data protection, security operations, a service desk, technical support or a similar client-facing role. Exposure to Proofpoint Data Security, DLP, Insider Threat Management, Email Protection or comparable platforms. Experience reviewing alerts, policy matches, endpoint health, agent status or telemetry. Familiarity with TCP/IP, DNS, HTTP/S, proxies, firewalls and email flow at a practical level. Working knowledge of Windows or macOS endpoints, cloud services, SaaS administration or identity and access. Experience testing or tuning policies and rules, validating outcomes or supporting controlled changes. Comfort using log search, dashboards, reporting tools, vendor knowledge bases or technical documentation. Relevant training or certification in cyber security, networking, cloud, systems or a related discipline. Awareness of scripting, APIs or automation concepts, with an interest in developing these skills. Additional information This role is designed to build a strong foundation in Information Protection operations and engineering. With coaching, product learning and demonstrated capability, the role can expand from investigation and validation into greater ownership of configuration, testing, standard changes and technical delivery.Success will be shaped by how you learn, troubleshoot, communicate and take ownership - not by already being a fully formed engineer on day one.You do not need to meet every point. We value technical aptitude, learning ability and the right mindset alongside experience. Why Proofpoint? At Proofpoint, we believe that an exceptional career experience includes a comprehensive compensation and benefits package. Here are just a few reasons you'll love working with us: Competitive compensation Comprehensive benefits Career success on your terms Flexible work environment Annual wellness and community outreach days Always on recognition for your contributions Global collaboration and networking opportunities Our Culture: Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone.We encourage applications from individuals of all backgrounds, experiences, and perspectives. If you need accommodation during the application or interview process, please reach out to . How to Apply Interested? Submit your application along with any supporting information- we can't wait to hear from you!
Academy Education Network Ltd
Manchester, Lancashire
Overview Cybersecurity Analysts protect organisations from cyber threats. Depending on the speciality, roles may involve monitoring live security events in a Security Operations Centre (SOC), researching threat intelligence, conducting penetration tests to uncover vulnerabilities, or managing Governance, Risk & Compliance (GRC) workstreams. All work aligns with recognised frameworks such as NIST CSF, ISO 27001, and CIS Controls. Responsibilities Monitor security events and respond to active threats in real time. Run vulnerability assessments, penetration tests, and incident response exercises. Specialise in SOC analysis, threat intelligence, penetration testing, GRC, or cloud security. Work for banks, telcos, defence contractors, government agencies, NHS and FTSE 100 corporates. Career Progression Typical career stages for a Cybersecurity Analyst: Years 0-2: SOC Analyst (Tier 1) - monitor events and respond to common incidents; progression via CompTIA Security+ and SANS GCIH or CEH. Years 2-5: Cybersecurity Analyst / Penetration Tester - specialise in penetration testing (CREST CRT, OSCP), threat intelligence or GRC (ISO 27001 Lead Auditor). Years 5-8: Senior Analyst / Security Engineer - lead complex incident response, run major risk assessments, or design enterprise security architecture; often required to hold CISSP. Years 8+: Lead / Head of Security / CISO - strategic leadership of an organisation's security function; requires technical depth and business/board level communication. Qualifications & Skills Required technical knowledge and professional traits include: Calm decision making under incident pressure. Clear written reporting for non technical executives. Ethical decision making and professional integrity. Continuous learning across rapidly evolving threats. Methodical, evidence based investigation. Teamwork across IT, business and law enforcement. Relevant certifications such as CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP, ISO 27001 Lead Auditor. Typical Salary Ranges (UK) Junior SOC analysts at major banks and managed service providers start at £35,000-£45,000. Penetration testers and threat intelligence analysts at top consultancies earn £45,000-£65,000 within 3 years. Senior engineers and CISO track leaders in FTSE 100 companies can reach £100,000+. Education and Entry Routes Common pathways include: MSc Cybersecurity - 1 year postgraduate specialist degree (many are NCSC certified). Cybersecurity Apprenticeship - 2-4 years, fully employer funded (Levels 4 & 6). CompTIA Security+ plus a Tier 1 SOC role - common entry for career changers. University undergraduate degree in Cybersecurity or Computer Science - 3 years; with student loans and progression into junior roles. FAQ - Becoming a Cybersecurity Analyst in the UK How long does it take to become a cyber analyst? Typically straight after a 3 year undergraduate degree, or via CompTIA Security+ and a Tier 1 SOC role. Do I need a cybersecurity degree to work in the UK? Not strictly, but a specialist degree and relevant certifications are the most reliable route. Is the role on the Skilled Worker visa shortage list? No; however, salaries often meet the threshold and most private sector employers sponsor international analysts. What's the difference between a SOC analyst and a penetration tester? SOC analysts monitor events; penetration testers actively find vulnerabilities. Which UK certifications matter most? CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP. Can I move into cybersecurity from another career? Yes - career changers can transition via Security+ and a Tier 1 SOC role within 6-12 months.
04/08/2026
Full time
Overview Cybersecurity Analysts protect organisations from cyber threats. Depending on the speciality, roles may involve monitoring live security events in a Security Operations Centre (SOC), researching threat intelligence, conducting penetration tests to uncover vulnerabilities, or managing Governance, Risk & Compliance (GRC) workstreams. All work aligns with recognised frameworks such as NIST CSF, ISO 27001, and CIS Controls. Responsibilities Monitor security events and respond to active threats in real time. Run vulnerability assessments, penetration tests, and incident response exercises. Specialise in SOC analysis, threat intelligence, penetration testing, GRC, or cloud security. Work for banks, telcos, defence contractors, government agencies, NHS and FTSE 100 corporates. Career Progression Typical career stages for a Cybersecurity Analyst: Years 0-2: SOC Analyst (Tier 1) - monitor events and respond to common incidents; progression via CompTIA Security+ and SANS GCIH or CEH. Years 2-5: Cybersecurity Analyst / Penetration Tester - specialise in penetration testing (CREST CRT, OSCP), threat intelligence or GRC (ISO 27001 Lead Auditor). Years 5-8: Senior Analyst / Security Engineer - lead complex incident response, run major risk assessments, or design enterprise security architecture; often required to hold CISSP. Years 8+: Lead / Head of Security / CISO - strategic leadership of an organisation's security function; requires technical depth and business/board level communication. Qualifications & Skills Required technical knowledge and professional traits include: Calm decision making under incident pressure. Clear written reporting for non technical executives. Ethical decision making and professional integrity. Continuous learning across rapidly evolving threats. Methodical, evidence based investigation. Teamwork across IT, business and law enforcement. Relevant certifications such as CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP, ISO 27001 Lead Auditor. Typical Salary Ranges (UK) Junior SOC analysts at major banks and managed service providers start at £35,000-£45,000. Penetration testers and threat intelligence analysts at top consultancies earn £45,000-£65,000 within 3 years. Senior engineers and CISO track leaders in FTSE 100 companies can reach £100,000+. Education and Entry Routes Common pathways include: MSc Cybersecurity - 1 year postgraduate specialist degree (many are NCSC certified). Cybersecurity Apprenticeship - 2-4 years, fully employer funded (Levels 4 & 6). CompTIA Security+ plus a Tier 1 SOC role - common entry for career changers. University undergraduate degree in Cybersecurity or Computer Science - 3 years; with student loans and progression into junior roles. FAQ - Becoming a Cybersecurity Analyst in the UK How long does it take to become a cyber analyst? Typically straight after a 3 year undergraduate degree, or via CompTIA Security+ and a Tier 1 SOC role. Do I need a cybersecurity degree to work in the UK? Not strictly, but a specialist degree and relevant certifications are the most reliable route. Is the role on the Skilled Worker visa shortage list? No; however, salaries often meet the threshold and most private sector employers sponsor international analysts. What's the difference between a SOC analyst and a penetration tester? SOC analysts monitor events; penetration testers actively find vulnerabilities. Which UK certifications matter most? CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP. Can I move into cybersecurity from another career? Yes - career changers can transition via Security+ and a Tier 1 SOC role within 6-12 months.
Responsibilities Monitor and review alerts from SIEM tools across a 24/7/365 shift pattern to detect, triage, and respond to security incidents. Act as the first line of response for security incidents by identifying, validating, and classifying potential threats. Collaborate to suggest improvements to use-cases, documentation, processes, and playbooks. Conduct handover/takeover procedures to ensure continuity of operations across 24/7 shift. Assist senior analysts with complex investigations, continuity briefs, and updates on service status issues. Identify and suggest improvements to processes and procedures to streamline SOC workflow. Engage with available knowledge and training tools to maintain and improve technical skills. Stay informed of current cyber threats relevant to DXC and DXC customers. Knowledge and Skills Required Understanding of fundamental networking concepts including IP addressing, protocols, and traffic flows. Understanding of basic Windows and Linux Operating Systems including terminal basics, file systems, and authentication mechanisms. Fundamental competency in log analysis to identify malicious activity. Able to navigate ElasticStack visualisation solutions (Analytics, Search, Observability, Security) to hunt for and identify threats. Familiar with open-source intelligence (OSINT) techniques to aid in identifying potential threats and gathering information. Able to communicate clearly and efficiently with team members and stakeholders under direction from senior analysts. Able to communicate simple technical issues to non-technical individuals in a clear and understandable way. Able to manage personal workload effectively to ensure timely completion of assigned tasks. Willing to collaborate/knowledge share with team members and accept guidance from more experienced analysts. Show initiative in learning new technologies and techniques, leveraging internal resources and training to grow professionally. Desirable IT or security related certifications (e.g. CompTIA Security+) Experience using Elastic Stack or other SIEM tools Experience working a non-standard shift pattern Currently held SC/DV UKSV clearance Other Requirements Eligibility to hold UKGov DV clearance is VITAL to this role Full Driving Licence Fluent in written and spoken English This role is part of a 4-on 4 off shift rota working across days and nights This role cannot be performed remotely At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We're committed to fostering an inclusive environment where everyone can thrive.
03/08/2026
Full time
Responsibilities Monitor and review alerts from SIEM tools across a 24/7/365 shift pattern to detect, triage, and respond to security incidents. Act as the first line of response for security incidents by identifying, validating, and classifying potential threats. Collaborate to suggest improvements to use-cases, documentation, processes, and playbooks. Conduct handover/takeover procedures to ensure continuity of operations across 24/7 shift. Assist senior analysts with complex investigations, continuity briefs, and updates on service status issues. Identify and suggest improvements to processes and procedures to streamline SOC workflow. Engage with available knowledge and training tools to maintain and improve technical skills. Stay informed of current cyber threats relevant to DXC and DXC customers. Knowledge and Skills Required Understanding of fundamental networking concepts including IP addressing, protocols, and traffic flows. Understanding of basic Windows and Linux Operating Systems including terminal basics, file systems, and authentication mechanisms. Fundamental competency in log analysis to identify malicious activity. Able to navigate ElasticStack visualisation solutions (Analytics, Search, Observability, Security) to hunt for and identify threats. Familiar with open-source intelligence (OSINT) techniques to aid in identifying potential threats and gathering information. Able to communicate clearly and efficiently with team members and stakeholders under direction from senior analysts. Able to communicate simple technical issues to non-technical individuals in a clear and understandable way. Able to manage personal workload effectively to ensure timely completion of assigned tasks. Willing to collaborate/knowledge share with team members and accept guidance from more experienced analysts. Show initiative in learning new technologies and techniques, leveraging internal resources and training to grow professionally. Desirable IT or security related certifications (e.g. CompTIA Security+) Experience using Elastic Stack or other SIEM tools Experience working a non-standard shift pattern Currently held SC/DV UKSV clearance Other Requirements Eligibility to hold UKGov DV clearance is VITAL to this role Full Driving Licence Fluent in written and spoken English This role is part of a 4-on 4 off shift rota working across days and nights This role cannot be performed remotely At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We're committed to fostering an inclusive environment where everyone can thrive.
Cheshire West and Chester
Ellesmere Port, Cheshire
Grade 12 £54,992 - £62,778(as of April 2025 pay band figures) The Cheshire West and Chester Council Digital, Data and Technology (DDAT) department has recently undergone a huge transformation and is looking for a Security Engineer tolead the protection of the Councils' hosting, networks, and data infrastructure.The post holder will support the implementation and maintenance of the systems used toprotect computer systems and networks and track incidents. Closing date for applications: Midnight on 12th August 2026 Cheshire West and Chester Council brings a fresh and energetic approach to providing top quality services for its many customers and communities. The Cheshire West and Chester Council Digital, Data and Technology (DDAT) department has recently undergone a huge transformation and is looking for aSecurity Engineer to lead the protection of the Councils' hosting, networks, and data infrastructure. The post holder will support the implementation and maintenance of the systems used to protect computer systems and networks and track incidents. This is an exciting opportunity to join a newly created and progressive team with big ambitions for the future. This role is a Grade 12, £54,992 - £62,778(as of April 2025 pay band figures). Closing date for applications is midnight on 12th August 2026. Role responsibilities include: Lead day to day operational security across the DDaT service, including incident response, cross team coordination, security assessments, vulnerability scanning and code audits Identify and resolve security vulnerabilities by developing technical solutions, researching emerging threats, building threat models and driving automation of security improvements Oversee phishing testing and awareness activity, working with the security analyst team and reporting outcomes to senior management Support the development and continuous review of cyber security policies, ensuring they remain effective in a changing threat landscape Act as the main point of contact for operational security matters, providing guidance and support across the council and monitoring security tools to manage risks effectively Participate in the out of hours rota, responding to alerts and incidents raised by the SOC We are seeking a skilled and motivated cyber security professional with a strong technical background, supported by a degree in Computer Science, Cybersecurity or equivalent experience, and relevant industry certifications such as CISSP, CISM, CompTIA Security+ or CISA. You will bring proven experience in securing network and infrastructure environments, including firewalls, encryption, VPNs and endpoint protection, alongside hands on experience of vulnerability identification and remediation, for example through penetration testing and threat analysis. A solid understanding of security tools, monitoring, reporting and auditing, as well as familiarity with ISO27001 and modern practices such as patch management and DevOps or SecOps, is essential. You will have practical experience of protecting a range of systems and data platforms, including Windows and legacy environments, and be confident in monitoring network activity to detect and prevent intrusion. The ability to write secure code, for example in Python or similar languages, to support automation and continuous improvement is important, along with up to date knowledge of emerging threats and attack methods. You will be a strong communicator and collaborator, able to explain technical concepts clearly to a range of audiences and build effective working relationships across the organisation and with external partners. You will be self motivated, resilient and able to manage competing priorities in a fast paced environment, using sound judgement to balance business needs and technical constraints while delivering practical, innovative solutions. Experience within local government or in roles such as a security analyst or penetration tester would be advantageous. By joining Cheshire West and Chester Council, you will be part of a GOLD Investors in People (IiP) organisation which is focused on building a stronger future where we all play our part in thriving, caring and sustainable communities.
03/08/2026
Full time
Grade 12 £54,992 - £62,778(as of April 2025 pay band figures) The Cheshire West and Chester Council Digital, Data and Technology (DDAT) department has recently undergone a huge transformation and is looking for a Security Engineer tolead the protection of the Councils' hosting, networks, and data infrastructure.The post holder will support the implementation and maintenance of the systems used toprotect computer systems and networks and track incidents. Closing date for applications: Midnight on 12th August 2026 Cheshire West and Chester Council brings a fresh and energetic approach to providing top quality services for its many customers and communities. The Cheshire West and Chester Council Digital, Data and Technology (DDAT) department has recently undergone a huge transformation and is looking for aSecurity Engineer to lead the protection of the Councils' hosting, networks, and data infrastructure. The post holder will support the implementation and maintenance of the systems used to protect computer systems and networks and track incidents. This is an exciting opportunity to join a newly created and progressive team with big ambitions for the future. This role is a Grade 12, £54,992 - £62,778(as of April 2025 pay band figures). Closing date for applications is midnight on 12th August 2026. Role responsibilities include: Lead day to day operational security across the DDaT service, including incident response, cross team coordination, security assessments, vulnerability scanning and code audits Identify and resolve security vulnerabilities by developing technical solutions, researching emerging threats, building threat models and driving automation of security improvements Oversee phishing testing and awareness activity, working with the security analyst team and reporting outcomes to senior management Support the development and continuous review of cyber security policies, ensuring they remain effective in a changing threat landscape Act as the main point of contact for operational security matters, providing guidance and support across the council and monitoring security tools to manage risks effectively Participate in the out of hours rota, responding to alerts and incidents raised by the SOC We are seeking a skilled and motivated cyber security professional with a strong technical background, supported by a degree in Computer Science, Cybersecurity or equivalent experience, and relevant industry certifications such as CISSP, CISM, CompTIA Security+ or CISA. You will bring proven experience in securing network and infrastructure environments, including firewalls, encryption, VPNs and endpoint protection, alongside hands on experience of vulnerability identification and remediation, for example through penetration testing and threat analysis. A solid understanding of security tools, monitoring, reporting and auditing, as well as familiarity with ISO27001 and modern practices such as patch management and DevOps or SecOps, is essential. You will have practical experience of protecting a range of systems and data platforms, including Windows and legacy environments, and be confident in monitoring network activity to detect and prevent intrusion. The ability to write secure code, for example in Python or similar languages, to support automation and continuous improvement is important, along with up to date knowledge of emerging threats and attack methods. You will be a strong communicator and collaborator, able to explain technical concepts clearly to a range of audiences and build effective working relationships across the organisation and with external partners. You will be self motivated, resilient and able to manage competing priorities in a fast paced environment, using sound judgement to balance business needs and technical constraints while delivering practical, innovative solutions. Experience within local government or in roles such as a security analyst or penetration tester would be advantageous. By joining Cheshire West and Chester Council, you will be part of a GOLD Investors in People (IiP) organisation which is focused on building a stronger future where we all play our part in thriving, caring and sustainable communities.
Senior SOC Analyst UK - 3 days a week in our Manchester office (Suite B, Maple Court, M60 Office Park, Wynne Ave, Swinton, Clifton, Manchester, M27 8FF) £50-£55k (Dependent on experience) + benefits Focus Group is looking for a Senior SOC Analyst to play a key role within our Managed Security Services team. This is a dual focused position combining hands on technical expertise with day to day operational leadership, ensuring high quality delivery of managed detection and response services across a diverse customer base. You'll lead SOC operations, act as the escalation point for complex security incidents, and mentor junior analysts-driving both service excellence and team development. What you'll do Lead day to day SOC operations, ensuring effective triage, escalation, and communication workflows Act as the primary escalation point for complex security investigations and incidents Conduct advanced threat investigations across endpoints, networks, and cloud environments Perform proactive threat hunting and detection tuning to improve coverage and reduce noise Manage and mentor Tier 1-2 analysts, supporting development and technical growth Ensure ticket quality, SLA adherence, and high service standards across SOC operations Support onboarding of new customers into monitoring and detection platforms Collaborate with Cyber Security leadership to improve detection strategy and SOC maturity Analyse logs and security data to identify malicious or suspicious activity Develop and maintain playbooks, runbooks, and knowledge base content Produce clear, actionable incident reports for internal and customer stakeholders Engage directly with customers during escalations, incident reviews, and briefings Identify opportunities for automation, process improvement, and enhanced detection capabilities Stay up to date with emerging threats, attack techniques, and MITRE ATT&CK developments What you'll bring 4-6 years' experience in a SOC or MSSP environment at Tier 2-3 or Lead level Strong hands on experience with SIEM platforms (e.g. Microsoft Sentinel, Splunk, Elastic, LogPoint) Experience with EDR tools such as Microsoft Defender, SentinelOne, or Bitdefender Deep understanding of MITRE ATT&CK and modern threat detection methodologies Strong incident response, investigation, and log analysis capability across multiple data sources Ability to lead during high pressure incidents with calm, confident decision making Strong communication skills, including producing clear incident reports and updates Proven ability to mentor, coach, and support junior analysts Organised approach with the ability to manage multiple concurrent incidents Proactive mindset focused on continuous improvement and service optimisation Nice to have Certifications such as SC 200, GCIH, GCIA, Security+, or BTL1 Experience in an MSSP or multi customer environment Microsoft security stack experience (Defender XDR, Sentinel, M365 security) Knowledge of cloud security, email security, and vulnerability management Experience with KQL or other query languages Scripting skills (PowerShell, Python) Familiarity with SOAR and threat intelligence platforms Understanding of compliance frameworks (ISO 27001, NIST, Cyber Essentials) Future opportunities SOC Manager / Head of Security Operations Cyber Security Technical Lead Detection Engineering Lead Threat Intelligence LeadIncident Response Manager Security Consultant / Advisory
03/08/2026
Full time
Senior SOC Analyst UK - 3 days a week in our Manchester office (Suite B, Maple Court, M60 Office Park, Wynne Ave, Swinton, Clifton, Manchester, M27 8FF) £50-£55k (Dependent on experience) + benefits Focus Group is looking for a Senior SOC Analyst to play a key role within our Managed Security Services team. This is a dual focused position combining hands on technical expertise with day to day operational leadership, ensuring high quality delivery of managed detection and response services across a diverse customer base. You'll lead SOC operations, act as the escalation point for complex security incidents, and mentor junior analysts-driving both service excellence and team development. What you'll do Lead day to day SOC operations, ensuring effective triage, escalation, and communication workflows Act as the primary escalation point for complex security investigations and incidents Conduct advanced threat investigations across endpoints, networks, and cloud environments Perform proactive threat hunting and detection tuning to improve coverage and reduce noise Manage and mentor Tier 1-2 analysts, supporting development and technical growth Ensure ticket quality, SLA adherence, and high service standards across SOC operations Support onboarding of new customers into monitoring and detection platforms Collaborate with Cyber Security leadership to improve detection strategy and SOC maturity Analyse logs and security data to identify malicious or suspicious activity Develop and maintain playbooks, runbooks, and knowledge base content Produce clear, actionable incident reports for internal and customer stakeholders Engage directly with customers during escalations, incident reviews, and briefings Identify opportunities for automation, process improvement, and enhanced detection capabilities Stay up to date with emerging threats, attack techniques, and MITRE ATT&CK developments What you'll bring 4-6 years' experience in a SOC or MSSP environment at Tier 2-3 or Lead level Strong hands on experience with SIEM platforms (e.g. Microsoft Sentinel, Splunk, Elastic, LogPoint) Experience with EDR tools such as Microsoft Defender, SentinelOne, or Bitdefender Deep understanding of MITRE ATT&CK and modern threat detection methodologies Strong incident response, investigation, and log analysis capability across multiple data sources Ability to lead during high pressure incidents with calm, confident decision making Strong communication skills, including producing clear incident reports and updates Proven ability to mentor, coach, and support junior analysts Organised approach with the ability to manage multiple concurrent incidents Proactive mindset focused on continuous improvement and service optimisation Nice to have Certifications such as SC 200, GCIH, GCIA, Security+, or BTL1 Experience in an MSSP or multi customer environment Microsoft security stack experience (Defender XDR, Sentinel, M365 security) Knowledge of cloud security, email security, and vulnerability management Experience with KQL or other query languages Scripting skills (PowerShell, Python) Familiarity with SOAR and threat intelligence platforms Understanding of compliance frameworks (ISO 27001, NIST, Cyber Essentials) Future opportunities SOC Manager / Head of Security Operations Cyber Security Technical Lead Detection Engineering Lead Threat Intelligence LeadIncident Response Manager Security Consultant / Advisory