it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

35 jobs found

Email me jobs like this
Refine Search
Current Search
cyber security vulnerability analyst
Triumph Consultants Ltd
Principal Offensive Security Operator-Cyber Security Analyst (Red Teaming)
Triumph Consultants Ltd
Our client isseeking an experienced Cyber Security Analyst/Red Team Specialist to conduct safe, controlled and intelligence-led cyber-attack simulations across complex technology estates. Working as a real-world adversary might, the successful candidate will identify weaknesses, test defensive capabilities and provide expert cyber security insight to support strategic security decision-making. The role requires strong hands-on offensive security experience, with the ability to tactically assess and execute sophisticated attack scenarios across traditional enterprise environments and modern digital services. You will be comfortable conducting complex, multi-stage operations, including chained attacks, evasion techniques, persistence, post-exploitation and lateral movement, while maintaining a strong focus on operational security and avoiding unnecessary disruption to live services. Key Responsibilities Design and execute threat intelligence-led, full-spectrum cyber-attack simulations, including long-term campaign planning, persistence and post-exploitation activity. Adopt a Red Team/adversary simulation approach to identify high-impact vulnerabilities across critical technology estates and business areas. Validate the effectiveness of the organisation's wider cyber security controls, defensive capabilities and security architecture. Conduct scenario-driven engagements based on realistic threat actor capabilities, behaviours and tradecraft. Perform exploitation across infrastructure, web applications, cloud platforms and enterprise technology environments. Identify and analyse attack paths towards high-value systems, data and business services. Apply appropriate evasion and operational security techniques to ensure engagements are controlled and do not unnecessarily disrupt business operations. Communicate technical findings clearly, translating complex vulnerabilities and attack paths into business risk, impact and remediation requirements for senior stakeholders. Develop, enhance and automate offensive security tools, techniques and methodologies. Build and maintain attack infrastructure, including C2 frameworks and supporting infrastructure-as-code. Mentor junior Red Team colleagues, supporting the development of their technical capability and understanding of offensive security. Share knowledge with wider cyber security and non-security teams to help strengthen the organisation's overall security culture. Contribute to vulnerability management, threat mitigation and risk-based security decision-making. Essential Experience & Skills The successful candidate will demonstrate: Proven experience planning and executing complex, multi-phase offensive security operations. Strong experience delivering scenario-driven adversary simulations and Red Team engagements. Excellent threat intelligence analysis and assessment capability. Extensive hands-on exploitation experience across a broad range of technologies, including: Microsoft Entra ID Active Directory Microsoft 365 macOS Kubernetes CI/CD environments AWS Azure Infrastructure and web applications Strong understanding of post-exploitation, persistence and lateral movement, including tactical analysis of attack paths to high-value targets. Experience conducting engagements in accordance with operational security best practice and within a range of threat actor capabilities and tradecraft. Deep technical understanding of security technologies within end-user and server operating systems, together with supporting infrastructure and enterprise architecture. Experience working across complex Legacy and modern enterprise environments at scale. Experience developing, deploying and using tools to support Red Team activities. Practical experience with attack infrastructure, C2 frameworks and Infrastructure as Code (IaC) technologies. Excellent written and verbal communication skills, with the ability to explain complex technical vulnerabilities, risks and attack scenarios to both technical and non-technical audiences, including senior stakeholders. Experience contributing to or participating in GCASE, GBEST, CBEST or TIBER engagements. Desirable Experience Experience in threat research and/or vulnerability research, including publishing research or presenting findings to the wider cyber security community. Previous experience in a related security discipline, such as: Protective Monitoring Incident Response Security Engineering Security Architecture Experience working within large, complex public sector, government or highly regulated environments. Experience mentoring or developing junior offensive security professionals. Professional Qualifications Relevant Red Team and offensive security certifications are desirable, including: CCSAS CRTL Other recognised offensive security/Red Team certifications would also be considered. What We're Looking For This is a technically demanding role for an experienced offensive security professional who can combine deep technical exploitation capability with strategic security thinking. The successful candidate will be able to operate confidently across complex enterprise, cloud and modern digital environments, understand how sophisticated attacks can be chained together, and communicate the resulting risks in a way that enables senior decision-makers to take effective action. If you have substantial experience in Red Teaming , adversary simulation, threat intelligence, exploitation, post-exploitation and attack-path analysis, we would be keen to hear from you.
20/08/2026
Contractor
Our client isseeking an experienced Cyber Security Analyst/Red Team Specialist to conduct safe, controlled and intelligence-led cyber-attack simulations across complex technology estates. Working as a real-world adversary might, the successful candidate will identify weaknesses, test defensive capabilities and provide expert cyber security insight to support strategic security decision-making. The role requires strong hands-on offensive security experience, with the ability to tactically assess and execute sophisticated attack scenarios across traditional enterprise environments and modern digital services. You will be comfortable conducting complex, multi-stage operations, including chained attacks, evasion techniques, persistence, post-exploitation and lateral movement, while maintaining a strong focus on operational security and avoiding unnecessary disruption to live services. Key Responsibilities Design and execute threat intelligence-led, full-spectrum cyber-attack simulations, including long-term campaign planning, persistence and post-exploitation activity. Adopt a Red Team/adversary simulation approach to identify high-impact vulnerabilities across critical technology estates and business areas. Validate the effectiveness of the organisation's wider cyber security controls, defensive capabilities and security architecture. Conduct scenario-driven engagements based on realistic threat actor capabilities, behaviours and tradecraft. Perform exploitation across infrastructure, web applications, cloud platforms and enterprise technology environments. Identify and analyse attack paths towards high-value systems, data and business services. Apply appropriate evasion and operational security techniques to ensure engagements are controlled and do not unnecessarily disrupt business operations. Communicate technical findings clearly, translating complex vulnerabilities and attack paths into business risk, impact and remediation requirements for senior stakeholders. Develop, enhance and automate offensive security tools, techniques and methodologies. Build and maintain attack infrastructure, including C2 frameworks and supporting infrastructure-as-code. Mentor junior Red Team colleagues, supporting the development of their technical capability and understanding of offensive security. Share knowledge with wider cyber security and non-security teams to help strengthen the organisation's overall security culture. Contribute to vulnerability management, threat mitigation and risk-based security decision-making. Essential Experience & Skills The successful candidate will demonstrate: Proven experience planning and executing complex, multi-phase offensive security operations. Strong experience delivering scenario-driven adversary simulations and Red Team engagements. Excellent threat intelligence analysis and assessment capability. Extensive hands-on exploitation experience across a broad range of technologies, including: Microsoft Entra ID Active Directory Microsoft 365 macOS Kubernetes CI/CD environments AWS Azure Infrastructure and web applications Strong understanding of post-exploitation, persistence and lateral movement, including tactical analysis of attack paths to high-value targets. Experience conducting engagements in accordance with operational security best practice and within a range of threat actor capabilities and tradecraft. Deep technical understanding of security technologies within end-user and server operating systems, together with supporting infrastructure and enterprise architecture. Experience working across complex Legacy and modern enterprise environments at scale. Experience developing, deploying and using tools to support Red Team activities. Practical experience with attack infrastructure, C2 frameworks and Infrastructure as Code (IaC) technologies. Excellent written and verbal communication skills, with the ability to explain complex technical vulnerabilities, risks and attack scenarios to both technical and non-technical audiences, including senior stakeholders. Experience contributing to or participating in GCASE, GBEST, CBEST or TIBER engagements. Desirable Experience Experience in threat research and/or vulnerability research, including publishing research or presenting findings to the wider cyber security community. Previous experience in a related security discipline, such as: Protective Monitoring Incident Response Security Engineering Security Architecture Experience working within large, complex public sector, government or highly regulated environments. Experience mentoring or developing junior offensive security professionals. Professional Qualifications Relevant Red Team and offensive security certifications are desirable, including: CCSAS CRTL Other recognised offensive security/Red Team certifications would also be considered. What We're Looking For This is a technically demanding role for an experienced offensive security professional who can combine deep technical exploitation capability with strategic security thinking. The successful candidate will be able to operate confidently across complex enterprise, cloud and modern digital environments, understand how sophisticated attacks can be chained together, and communicate the resulting risks in a way that enables senior decision-makers to take effective action. If you have substantial experience in Red Teaming , adversary simulation, threat intelligence, exploitation, post-exploitation and attack-path analysis, we would be keen to hear from you.
Nexere Consulting Limited
Senior Network Engineer - Palo Alto Firewalls - Network Infrastructure - Cyber Security - SIEM tools
Nexere Consulting Limited
Senior Network and Security Engineer - L2/L3 Network Infrastructure - Cyber Security - SIEM tools My client who are leaders in their field are looking for a Senior Cyber Security and Network Analyst to provide effective and timely operational support, development and management of the IT network and security infrastructure to meet business requirements and objectives. Responsibilities: Support the delivery and maintenance of the organisation's cyber security and network infrastructure, ensuring systems remain secure, resilient, and aligned to business needs Manage day-to-day security operations, including monitoring SIEM platforms, Firewalls, endpoint protection, and threat detection tools Investigate security incidents and vulnerabilities, recommending and implementing corrective actions where required Maintain and support network technologies including LAN/WAN, Wi-Fi, Internet connectivity, and Layer 2/3 infrastructure Contribute to cyber security and infrastructure projects, including the implementation of new security controls and technologies Perform patching, upgrades, and ongoing maintenance across security and network environments to minimise risk and downtime Develop and maintain security policies, operational procedures, technical documentation, and compliance standards Support disaster recovery and business continuity planning, testing, and readiness activities Key Experience & Skills: Palo Alto Firewalls and all associated NG services Endpoint detection and remediation Proven track record in Cyber security and understanding of cyber security analysis, tools and software Experience of implementing, supporting and developing L2/3 network infrastructure Qualys Vulnerability Management Aruba Wifi L2/3 switching - Cisco Nexus Network Load balancing Penetration Testing (3rd Party) Incident management Data Security
20/08/2026
Full time
Senior Network and Security Engineer - L2/L3 Network Infrastructure - Cyber Security - SIEM tools My client who are leaders in their field are looking for a Senior Cyber Security and Network Analyst to provide effective and timely operational support, development and management of the IT network and security infrastructure to meet business requirements and objectives. Responsibilities: Support the delivery and maintenance of the organisation's cyber security and network infrastructure, ensuring systems remain secure, resilient, and aligned to business needs Manage day-to-day security operations, including monitoring SIEM platforms, Firewalls, endpoint protection, and threat detection tools Investigate security incidents and vulnerabilities, recommending and implementing corrective actions where required Maintain and support network technologies including LAN/WAN, Wi-Fi, Internet connectivity, and Layer 2/3 infrastructure Contribute to cyber security and infrastructure projects, including the implementation of new security controls and technologies Perform patching, upgrades, and ongoing maintenance across security and network environments to minimise risk and downtime Develop and maintain security policies, operational procedures, technical documentation, and compliance standards Support disaster recovery and business continuity planning, testing, and readiness activities Key Experience & Skills: Palo Alto Firewalls and all associated NG services Endpoint detection and remediation Proven track record in Cyber security and understanding of cyber security analysis, tools and software Experience of implementing, supporting and developing L2/3 network infrastructure Qualys Vulnerability Management Aruba Wifi L2/3 switching - Cisco Nexus Network Load balancing Penetration Testing (3rd Party) Incident management Data Security
Yolk Recruitment
Cyber Security Analyst
Yolk Recruitment
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
20/08/2026
Full time
Security Analyst Cardiff, London, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Castle Employment
IT Security Analyst
Castle Employment Cranswick, North Humberside
IT Security Analyst Location: East Yorkshire area Salary: Competitive, depending on experience Working pattern: Full-time, on-site with collaborative team environment Protect systems. Strengthen resilience. Shape cyber security strategy. An established organisation is investing in its cyber capability and is looking for an IT Security Analyst to play a key role in protecting its systems, data and operations. This is an opportunity to join a collaborative IT environment where security is a business priority, not an afterthought. You will work closely with infrastructure and technical teams to strengthen cyber resilience, respond to threats and continuously improve security practices across the organisation. If you enjoy hands-on security work, problem solving and influencing best practice, this role offers real scope to make an impact. What you will be doing Monitor, develop and optimise SIEM and threat detection systems Investigate security incidents, coordinating response, containment and escalation Conduct vulnerability scanning and support remediation across the IT estate Work closely with infrastructure and technical teams to implement secure configurations Support and maintain security policies, procedures and controls Ensure alignment with recognised frameworks including ISO 27001 and NIST Deliver user awareness initiatives such as phishing simulations and training Stay up to date with emerging threats and recommend improvements to strengthen security posture Support disaster recovery, backup and data protection strategies aligned to business needs What we are looking for Proven experience in a cyber security or infrastructure security role Strong understanding of security principles, threat detection and risk-based thinking Experience with SIEM platforms, vulnerability management tools and detection response technologies such as EDR, XDR or MDR Knowledge of cyber security frameworks such as ISO 27001 or NIST Understanding of data protection legislation including GDPR Ability to investigate incidents, analyse findings and communicate clearly with stakeholders Strong analytical and problem-solving skills Ability to manage priorities and work effectively in a fast-paced environment Full UK driving licence Desirable experience Exposure to cloud platforms such as Azure Security certifications such as CompTIA Security+, CISSP or Microsoft accreditations Experience with ERP systems Scripting or automation knowledge Why apply? Opportunity to influence and improve cyber security across a growing organisation Collaborative environment working alongside infrastructure and technical specialists Exposure to modern security tools, frameworks and evolving technologies A role where your recommendations and expertise will directly shape security strategy Apply now If you are looking for a role where you can take ownership of security improvements and work in a business that values cyber resilience, we would like to hear from you.
18/08/2026
Full time
IT Security Analyst Location: East Yorkshire area Salary: Competitive, depending on experience Working pattern: Full-time, on-site with collaborative team environment Protect systems. Strengthen resilience. Shape cyber security strategy. An established organisation is investing in its cyber capability and is looking for an IT Security Analyst to play a key role in protecting its systems, data and operations. This is an opportunity to join a collaborative IT environment where security is a business priority, not an afterthought. You will work closely with infrastructure and technical teams to strengthen cyber resilience, respond to threats and continuously improve security practices across the organisation. If you enjoy hands-on security work, problem solving and influencing best practice, this role offers real scope to make an impact. What you will be doing Monitor, develop and optimise SIEM and threat detection systems Investigate security incidents, coordinating response, containment and escalation Conduct vulnerability scanning and support remediation across the IT estate Work closely with infrastructure and technical teams to implement secure configurations Support and maintain security policies, procedures and controls Ensure alignment with recognised frameworks including ISO 27001 and NIST Deliver user awareness initiatives such as phishing simulations and training Stay up to date with emerging threats and recommend improvements to strengthen security posture Support disaster recovery, backup and data protection strategies aligned to business needs What we are looking for Proven experience in a cyber security or infrastructure security role Strong understanding of security principles, threat detection and risk-based thinking Experience with SIEM platforms, vulnerability management tools and detection response technologies such as EDR, XDR or MDR Knowledge of cyber security frameworks such as ISO 27001 or NIST Understanding of data protection legislation including GDPR Ability to investigate incidents, analyse findings and communicate clearly with stakeholders Strong analytical and problem-solving skills Ability to manage priorities and work effectively in a fast-paced environment Full UK driving licence Desirable experience Exposure to cloud platforms such as Azure Security certifications such as CompTIA Security+, CISSP or Microsoft accreditations Experience with ERP systems Scripting or automation knowledge Why apply? Opportunity to influence and improve cyber security across a growing organisation Collaborative environment working alongside infrastructure and technical specialists Exposure to modern security tools, frameworks and evolving technologies A role where your recommendations and expertise will directly shape security strategy Apply now If you are looking for a role where you can take ownership of security improvements and work in a business that values cyber resilience, we would like to hear from you.
Akkodis
Data Analyst - Cyber Security
Akkodis
Data Analyst - Cyber Security 45,000 - 50,000 + bonus and extensive benefits Full Time / Permanent West Midlands / Hybrid - 1 day a month in the office The Role and Company: I am looking for a driven Data Analyst / Cyber Security Analyst with a strong data analytics skill set to join a large nationally recognised brand head quartered in the West Midlands. As a Data Analyst within the Cyber Security team, you will play a key role collecting, analysing, and interpreting Cyber Security related data to identify vulnerabilities, threats and detect suspicious activity. You will support the wider team to deliver a comprehensive programme of security testing, including vulnerability scanning and security configuration reviews, ensuring weaknesses are identified early and accurately. Responsibilities: Analyse the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the business, and existing security controls. Collaborate with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner. Generate detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders. Experience required: Previous experience in a similar Data Analyst ideally within a Cyber Security team or environment or with a keen interested or degree in Cyber Security. Excellent analytical and investigative skills Previous experience with Power BI is preferred. Effective communication, critical thinking and problem-solving skills Must either hold SC clearance already or be eligible to obtain this if successful Please apply via the link or contact (url removed) for more information Modis International Ltd acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers in the UK. Modis Europe Ltd provide a variety of international solutions that connect clients to the best talent in the world. For all positions based in Switzerland, Modis Europe Ltd works with its licensed Swiss partner Accurity GmbH to ensure that candidate applications are handled in accordance with Swiss law. Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers. By applying for this role your details will be submitted to Modis International Ltd and/ or Modis Europe Ltd. Our Candidate Privacy Information Statement which explains how we will use your information is available on the Modis website.
17/08/2026
Full time
Data Analyst - Cyber Security 45,000 - 50,000 + bonus and extensive benefits Full Time / Permanent West Midlands / Hybrid - 1 day a month in the office The Role and Company: I am looking for a driven Data Analyst / Cyber Security Analyst with a strong data analytics skill set to join a large nationally recognised brand head quartered in the West Midlands. As a Data Analyst within the Cyber Security team, you will play a key role collecting, analysing, and interpreting Cyber Security related data to identify vulnerabilities, threats and detect suspicious activity. You will support the wider team to deliver a comprehensive programme of security testing, including vulnerability scanning and security configuration reviews, ensuring weaknesses are identified early and accurately. Responsibilities: Analyse the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the business, and existing security controls. Collaborate with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner. Generate detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders. Experience required: Previous experience in a similar Data Analyst ideally within a Cyber Security team or environment or with a keen interested or degree in Cyber Security. Excellent analytical and investigative skills Previous experience with Power BI is preferred. Effective communication, critical thinking and problem-solving skills Must either hold SC clearance already or be eligible to obtain this if successful Please apply via the link or contact (url removed) for more information Modis International Ltd acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers in the UK. Modis Europe Ltd provide a variety of international solutions that connect clients to the best talent in the world. For all positions based in Switzerland, Modis Europe Ltd works with its licensed Swiss partner Accurity GmbH to ensure that candidate applications are handled in accordance with Swiss law. Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers. By applying for this role your details will be submitted to Modis International Ltd and/ or Modis Europe Ltd. Our Candidate Privacy Information Statement which explains how we will use your information is available on the Modis website.
Akkodis
Vulnerability Analyst
Akkodis
Vulnerability Analyst 45,000 - 50,000 + bonus and extensive benefits Full Time / Permanent West Midlands / Hybrid - 1 day a week in the office ideally The Role and Company: I am looking for a driven Vulnerability Analyst to join a large nationally recognised brand head quartered in the West Midlands. As a Vulnerability Analyst you will play a key role in proactively testing, assessing and challenging the resilience of technology and operational environments. The Vulnerability Analyst helps to deliver a comprehensive programme of security testing, including vulnerability scanning and security configuration reviews, ensuring weaknesses are identified early and accurately. We are ideally looking for someone Midlands based who can be on site in Warwickshire 1 day a week on average. Responsibilities: Conducting regular vulnerability assessments using automated scanning tools, manual testing techniques, and security best practices to identify vulnerabilities in systems, networks, and applications Managing the lifecycle of vulnerabilities from discovery to remediation, including vulnerability triage, prioritisation, tracking, and reporting Analysing the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the organisation, and existing security controls Collaborating with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner Working closely with IT teams to ensure that security patches and updates are applied promptly to mitigate known vulnerabilities and reduce the organisation's exposure to security risks Generating detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders Providing guidance and training to employees on best practices for identifying and reporting security vulnerabilities, promoting a culture of security awareness within the organisation Experience required: Previous experience in a similar Vulnerability Management role preferably with experience in Operational Technology (OT) Skilled in cyber security, physical security, and risk management principles Excellent analytical and investigative skills Strong knowledge of the hardware and software systems in use across both IT and OT domains and the architectural arrangements in place to support management and operation of systems Ability to adapt to evolving threat landscapes Effective communication, critical thinking and problem-solving skills Must either hold SC clearance already or be eligible to obtain this if successful Please apply via the link or contact (url removed) for more information Modis International Ltd acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers in the UK. Modis Europe Ltd provide a variety of international solutions that connect clients to the best talent in the world. For all positions based in Switzerland, Modis Europe Ltd works with its licensed Swiss partner Accurity GmbH to ensure that candidate applications are handled in accordance with Swiss law. Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers. By applying for this role your details will be submitted to Modis International Ltd and/ or Modis Europe Ltd. Our Candidate Privacy Information Statement which explains how we will use your information is available on the Modis website.
14/08/2026
Full time
Vulnerability Analyst 45,000 - 50,000 + bonus and extensive benefits Full Time / Permanent West Midlands / Hybrid - 1 day a week in the office ideally The Role and Company: I am looking for a driven Vulnerability Analyst to join a large nationally recognised brand head quartered in the West Midlands. As a Vulnerability Analyst you will play a key role in proactively testing, assessing and challenging the resilience of technology and operational environments. The Vulnerability Analyst helps to deliver a comprehensive programme of security testing, including vulnerability scanning and security configuration reviews, ensuring weaknesses are identified early and accurately. We are ideally looking for someone Midlands based who can be on site in Warwickshire 1 day a week on average. Responsibilities: Conducting regular vulnerability assessments using automated scanning tools, manual testing techniques, and security best practices to identify vulnerabilities in systems, networks, and applications Managing the lifecycle of vulnerabilities from discovery to remediation, including vulnerability triage, prioritisation, tracking, and reporting Analysing the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the organisation, and existing security controls Collaborating with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner Working closely with IT teams to ensure that security patches and updates are applied promptly to mitigate known vulnerabilities and reduce the organisation's exposure to security risks Generating detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders Providing guidance and training to employees on best practices for identifying and reporting security vulnerabilities, promoting a culture of security awareness within the organisation Experience required: Previous experience in a similar Vulnerability Management role preferably with experience in Operational Technology (OT) Skilled in cyber security, physical security, and risk management principles Excellent analytical and investigative skills Strong knowledge of the hardware and software systems in use across both IT and OT domains and the architectural arrangements in place to support management and operation of systems Ability to adapt to evolving threat landscapes Effective communication, critical thinking and problem-solving skills Must either hold SC clearance already or be eligible to obtain this if successful Please apply via the link or contact (url removed) for more information Modis International Ltd acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers in the UK. Modis Europe Ltd provide a variety of international solutions that connect clients to the best talent in the world. For all positions based in Switzerland, Modis Europe Ltd works with its licensed Swiss partner Accurity GmbH to ensure that candidate applications are handled in accordance with Swiss law. Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers. By applying for this role your details will be submitted to Modis International Ltd and/ or Modis Europe Ltd. Our Candidate Privacy Information Statement which explains how we will use your information is available on the Modis website.
Rebel Recruitment Limited
Cyber Security Lead
Rebel Recruitment Limited
Role: Cyber Security Lead Location: Nottinghamshire Working Arrangement: 3 days a week in office Salary: Up to 70k Are you an experienced SOC professional who's ready to take the next step into leadership without leaving the technical work behind? We're looking for a Cyber Security Operations Manager to lead our in-house Security Operations capability while remaining deeply involved in the day-to-day technical aspects of detection, response and continuous improvement. This role is ideal for someone moving from a Senior SOC Analyst, Senior Security Engineer or SOC Team Lead position who wants to develop their leadership skills while staying hands-on. You'll spend around 80% of your time working on technical security operations and 20% leading and developing the team, making this an excellent opportunity for someone looking for their first management role. What you'll be doing Leading and mentoring a small SOC team while remaining an active technical contributor. Investigating and responding to security incidents across enterprise, cloud and operational technology environments. Improving detection capabilities, automation and SOC processes to stay ahead of emerging threats. Working closely with vulnerability management, incident response and governance teams to strengthen the organisation's security posture. Taking part in the on-call rota and providing technical leadership during security incidents. What we're looking for You'll likely have experience in a senior SOC or security operations role and be ready to take the next step into people leadership. You'll bring: Strong experience with security monitoring, threat detection and incident response. Hands-on knowledge of SIEM, SOAR and security tooling. A passion for improving detection capabilities and automating security operations. The confidence to mentor others and influence technical decisions. Excellent communication skills and the ability to collaborate across technical teams. Professional certifications such as CISSP, CISM, GCIH, GCIA, GSEC or cloud security certifications are welcome but not essential. Why join us? This is an opportunity to shape the future of an evolving Security Operations function within a large, complex technology environment. You'll have the autonomy to improve processes, introduce new ideas and develop your leadership career while remaining close to the technology you enjoy. If you're looking for a role that combines technical depth with your first step into management, we'd love to hear from you. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
13/08/2026
Full time
Role: Cyber Security Lead Location: Nottinghamshire Working Arrangement: 3 days a week in office Salary: Up to 70k Are you an experienced SOC professional who's ready to take the next step into leadership without leaving the technical work behind? We're looking for a Cyber Security Operations Manager to lead our in-house Security Operations capability while remaining deeply involved in the day-to-day technical aspects of detection, response and continuous improvement. This role is ideal for someone moving from a Senior SOC Analyst, Senior Security Engineer or SOC Team Lead position who wants to develop their leadership skills while staying hands-on. You'll spend around 80% of your time working on technical security operations and 20% leading and developing the team, making this an excellent opportunity for someone looking for their first management role. What you'll be doing Leading and mentoring a small SOC team while remaining an active technical contributor. Investigating and responding to security incidents across enterprise, cloud and operational technology environments. Improving detection capabilities, automation and SOC processes to stay ahead of emerging threats. Working closely with vulnerability management, incident response and governance teams to strengthen the organisation's security posture. Taking part in the on-call rota and providing technical leadership during security incidents. What we're looking for You'll likely have experience in a senior SOC or security operations role and be ready to take the next step into people leadership. You'll bring: Strong experience with security monitoring, threat detection and incident response. Hands-on knowledge of SIEM, SOAR and security tooling. A passion for improving detection capabilities and automating security operations. The confidence to mentor others and influence technical decisions. Excellent communication skills and the ability to collaborate across technical teams. Professional certifications such as CISSP, CISM, GCIH, GCIA, GSEC or cloud security certifications are welcome but not essential. Why join us? This is an opportunity to shape the future of an evolving Security Operations function within a large, complex technology environment. You'll have the autonomy to improve processes, introduce new ideas and develop your leadership career while remaining close to the technology you enjoy. If you're looking for a role that combines technical depth with your first step into management, we'd love to hear from you. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Castle Employment
Cyber Security Engineer
Castle Employment Cranswick, North Humberside
IT Security Analyst Location: East Yorkshire area Salary: Competitive, depending on experience Working pattern: Full-time, on-site with collaborative team environment Protect systems. Strengthen resilience. Shape cyber security strategy. An established organisation is investing in its cyber capability and is looking for an IT Security Analyst to play a key role in protecting its systems, data and operations. This is an opportunity to join a collaborative IT environment where security is a business priority, not an afterthought. You will work closely with infrastructure and technical teams to strengthen cyber resilience, respond to threats and continuously improve security practices across the organisation. If you enjoy hands-on security work, problem solving and influencing best practice, this role offers real scope to make an impact. What you will be doing Monitor, develop and optimise SIEM and threat detection systems Investigate security incidents, coordinating response, containment and escalation Conduct vulnerability scanning and support remediation across the IT estate Work closely with infrastructure and technical teams to implement secure configurations Support and maintain security policies, procedures and controls Ensure alignment with recognised frameworks including ISO 27001 and NIST Deliver user awareness initiatives such as phishing simulations and training Stay up to date with emerging threats and recommend improvements to strengthen security posture Support disaster recovery, backup and data protection strategies aligned to business needs What we are looking for Proven experience in a cyber security or infrastructure security role Strong understanding of security principles, threat detection and risk-based thinking Experience with SIEM platforms, vulnerability management tools and detection response technologies such as EDR, XDR or MDR Knowledge of cyber security frameworks such as ISO 27001 or NIST Understanding of data protection legislation including GDPR Ability to investigate incidents, analyse findings and communicate clearly with stakeholders Strong analytical and problem-solving skills Ability to manage priorities and work effectively in a fast-paced environment Full UK driving licence Desirable experience Exposure to cloud platforms such as Azure Security certifications such as CompTIA Security+, CISSP or Microsoft accreditations Experience with ERP systems Scripting or automation knowledge Why apply? Opportunity to influence and improve cyber security across a growing organisation Collaborative environment working alongside infrastructure and technical specialists Exposure to modern security tools, frameworks and evolving technologies A role where your recommendations and expertise will directly shape security strategy Apply now If you are looking for a role where you can take ownership of security improvements and work in a business that values cyber resilience, we would like to hear from you.
11/08/2026
Full time
IT Security Analyst Location: East Yorkshire area Salary: Competitive, depending on experience Working pattern: Full-time, on-site with collaborative team environment Protect systems. Strengthen resilience. Shape cyber security strategy. An established organisation is investing in its cyber capability and is looking for an IT Security Analyst to play a key role in protecting its systems, data and operations. This is an opportunity to join a collaborative IT environment where security is a business priority, not an afterthought. You will work closely with infrastructure and technical teams to strengthen cyber resilience, respond to threats and continuously improve security practices across the organisation. If you enjoy hands-on security work, problem solving and influencing best practice, this role offers real scope to make an impact. What you will be doing Monitor, develop and optimise SIEM and threat detection systems Investigate security incidents, coordinating response, containment and escalation Conduct vulnerability scanning and support remediation across the IT estate Work closely with infrastructure and technical teams to implement secure configurations Support and maintain security policies, procedures and controls Ensure alignment with recognised frameworks including ISO 27001 and NIST Deliver user awareness initiatives such as phishing simulations and training Stay up to date with emerging threats and recommend improvements to strengthen security posture Support disaster recovery, backup and data protection strategies aligned to business needs What we are looking for Proven experience in a cyber security or infrastructure security role Strong understanding of security principles, threat detection and risk-based thinking Experience with SIEM platforms, vulnerability management tools and detection response technologies such as EDR, XDR or MDR Knowledge of cyber security frameworks such as ISO 27001 or NIST Understanding of data protection legislation including GDPR Ability to investigate incidents, analyse findings and communicate clearly with stakeholders Strong analytical and problem-solving skills Ability to manage priorities and work effectively in a fast-paced environment Full UK driving licence Desirable experience Exposure to cloud platforms such as Azure Security certifications such as CompTIA Security+, CISSP or Microsoft accreditations Experience with ERP systems Scripting or automation knowledge Why apply? Opportunity to influence and improve cyber security across a growing organisation Collaborative environment working alongside infrastructure and technical specialists Exposure to modern security tools, frameworks and evolving technologies A role where your recommendations and expertise will directly shape security strategy Apply now If you are looking for a role where you can take ownership of security improvements and work in a business that values cyber resilience, we would like to hear from you.
Principal IT
IT Security Analyst
Principal IT
IT Security Analyst - 40,000/ 45,000 per annum - Brandesburton (Hybrid) Principal IT are proud to be supporting a leading provider of modular buildings for various sectors, such as education, healthcare, defence, and justice. This is an excellent opportunity for someone with a passion for cybersecurity who is looking to play a key role in strengthening and developing an organisation's overall security posture and cyber resilience strategy. Working closely with the Infrastructure & Security Manager, you will be responsible for monitoring, detecting, investigating, and responding to security threats across the organisation's infrastructure and systems. You will also support vulnerability management, compliance initiatives, and wider security improvement projects across the business. This role would suit someone with 2-4 years' experience in a cybersecurity, SOC, or infrastructure security-focused position who enjoys working across a broad technology estate and keeping up to date with emerging threats and security technologies. Key Responsibilities: Monitor and develop SIEM and threat detection platforms Investigate and respond to security incidents and alerts Support vulnerability scanning, remediation, and reporting activities Assist with development of security policies, procedures, and controls Work alongside Infrastructure and Technical Services teams to improve security across the estate Support compliance activities aligned to ISO27001, GDPR, and NIST frameworks Conduct security awareness initiatives including phishing simulations and end-user training Maintain and improve endpoint protection, IDS/IPS, EDR, XDR, and MDR solutions Assist with backup, disaster recovery, and digital asset protection strategies Stay up to date with emerging cyber threats and recommend improvements where appropriate Key Skills & Experience: 2-4 years' experience within a cybersecurity or infrastructure security role Experience working with SIEM tools and vulnerability management platforms Strong understanding of EDR, XDR, MDR, IDS/IPS technologies Good knowledge of Microsoft security technologies and infrastructure environments Understanding of ISO27001, NIST, GDPR, and security best practices Experience investigating security incidents and producing clear documentation Full UK driving licence Desirable: CompTIA Security+ CISSP Associate Microsoft certifications Experience with Azure environments Scripting or automation knowledge Experience working with ERP systems This is a fantastic opportunity to join a business investing heavily in cybersecurity, where you will have the chance to influence security best practices, work with modern technologies, and continue developing your technical skillset within a collaborative environment. The Package: If successful our client is offering a salary of between 40,000/ 45,000 per annum, favorable holiday allowance, company contributed pension scheme and opportunities for professional development including training and advancement. This a hybrid working role 3 days on site and 2 days working from home. How to Apply: If you are interested in hearing more about this IT security analyst vacancy or interested in applying for the role please email me at or contact Principal IT Directly on LinkedIn. INDGH
10/08/2026
Full time
IT Security Analyst - 40,000/ 45,000 per annum - Brandesburton (Hybrid) Principal IT are proud to be supporting a leading provider of modular buildings for various sectors, such as education, healthcare, defence, and justice. This is an excellent opportunity for someone with a passion for cybersecurity who is looking to play a key role in strengthening and developing an organisation's overall security posture and cyber resilience strategy. Working closely with the Infrastructure & Security Manager, you will be responsible for monitoring, detecting, investigating, and responding to security threats across the organisation's infrastructure and systems. You will also support vulnerability management, compliance initiatives, and wider security improvement projects across the business. This role would suit someone with 2-4 years' experience in a cybersecurity, SOC, or infrastructure security-focused position who enjoys working across a broad technology estate and keeping up to date with emerging threats and security technologies. Key Responsibilities: Monitor and develop SIEM and threat detection platforms Investigate and respond to security incidents and alerts Support vulnerability scanning, remediation, and reporting activities Assist with development of security policies, procedures, and controls Work alongside Infrastructure and Technical Services teams to improve security across the estate Support compliance activities aligned to ISO27001, GDPR, and NIST frameworks Conduct security awareness initiatives including phishing simulations and end-user training Maintain and improve endpoint protection, IDS/IPS, EDR, XDR, and MDR solutions Assist with backup, disaster recovery, and digital asset protection strategies Stay up to date with emerging cyber threats and recommend improvements where appropriate Key Skills & Experience: 2-4 years' experience within a cybersecurity or infrastructure security role Experience working with SIEM tools and vulnerability management platforms Strong understanding of EDR, XDR, MDR, IDS/IPS technologies Good knowledge of Microsoft security technologies and infrastructure environments Understanding of ISO27001, NIST, GDPR, and security best practices Experience investigating security incidents and producing clear documentation Full UK driving licence Desirable: CompTIA Security+ CISSP Associate Microsoft certifications Experience with Azure environments Scripting or automation knowledge Experience working with ERP systems This is a fantastic opportunity to join a business investing heavily in cybersecurity, where you will have the chance to influence security best practices, work with modern technologies, and continue developing your technical skillset within a collaborative environment. The Package: If successful our client is offering a salary of between 40,000/ 45,000 per annum, favorable holiday allowance, company contributed pension scheme and opportunities for professional development including training and advancement. This a hybrid working role 3 days on site and 2 days working from home. How to Apply: If you are interested in hearing more about this IT security analyst vacancy or interested in applying for the role please email me at or contact Principal IT Directly on LinkedIn. INDGH
SSA Digital Recruitment
Cyber Security Lead
SSA Digital Recruitment Bedford, Bedfordshire
Cyber Security Lead / Information Security Lead Bedford, Bedfordshire Hybrid 3 Days Office / 2 Days Remote £60,000 £70,000 + Excellent Benefits Permanent Infrastructure Security Network Security Cyber Security ISO 27001 Azure Microsoft 365 Are you an experienced Cyber Security Lead, Information Security Lead or Senior Security Engineer looking for an opportunity to step into a broader security leadership role? We are looking for a technically strong Cyber Security Lead / Information Security Lead to join a growing technology business in Bedford. This is an excellent opportunity for an Infrastructure Security, Network Security or Cyber Security professional who wants greater ownership and influence while remaining close to the technical side of security. This is not a purely GRC or compliance-focused position. The successful Cyber Security Lead will bring a strong technical foundation across infrastructure, networks and security engineering, combined with experience or exposure to Information Security, ISO 27001, security governance, risk and compliance. Working closely with Infrastructure, IT Operations, Engineering and senior stakeholders, you'll help strengthen the organisation's security posture across networks, servers, cloud platforms, Microsoft 365, Azure and business systems. What You'll Be Doing As the Cyber Security Lead, you'll take a leading role in information security and cyber security activities across the organisation. You'll help develop and continually improve the Information Security Management System (ISMS), maintain ISO 27001, support internal and external security audits and ensure security controls remain practical, effective and appropriate. You'll work closely with technical teams on infrastructure security, network security, vulnerability management, patch management and security remediation, coordinating penetration testing and ensuring identified vulnerabilities and security issues are addressed effectively. You'll also manage information security risk assessments, support incident response, supplier and third-party security assurance, Business Continuity and Disaster Recovery, while helping embed a strong security culture across the organisation. The Technical Background We're Looking For We're particularly interested in candidates who have developed their careers through Infrastructure, Network or Cyber Security and are now ready to take on greater Information Security leadership responsibility. You'll ideally bring experience across: Network & Infrastructure Security: firewalls, networking, Windows Server, Active Directory, endpoints and infrastructure hardening. Cloud & Identity Security: Microsoft 365, Azure Security, Identity & Access Management (IAM) and access controls. Security Operations: vulnerability management, patch management, penetration testing, remediation and incident response. Information Security: ISO 27001, ISMS, security audits, Cyber Essentials, security policies, governance, risk and compliance. You don't necessarily need to already hold the title of Cyber Security Lead. We would also be interested in hearing from experienced Senior Cyber Security Analysts, Senior Information Security Analysts, Security Engineers, Infrastructure Security Engineers, Network Security Engineers and Technical Security Leads who are ready to take the next step. Strong communication and stakeholder management skills are important. You'll be comfortable working with technical teams while also being able to explain security risks, controls and priorities clearly to senior and non-technical stakeholders. Why Consider This Cyber Security Lead Role? This is an opportunity to move beyond a purely engineering-focused position and take broader ownership of Information Security and Cyber Security, without leaving your technical background behind. You'll have the opportunity to influence security strategy, improve technical security controls, develop the ISMS, support ISO 27001 and work across Infrastructure Security, Network Security, Cloud Security, Security Governance and Cyber Security. Salary: £60,000 £70,000 Location: Bedford, Bedfordshire Working Pattern: Hybrid 3 days office / 2 days remote Employment: Permanent Focus: Cyber Security, Information Security, Infrastructure Security & Network Security Frameworks: ISO 27001 / ISMS / Cyber Essentials Ready for Your Next Move? If you're an experienced Cyber Security Lead, Information Security Lead, Senior Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead or Senior Cyber Security Analyst, we'd like to hear from you. This could be an excellent next step for a technically strong security professional who wants to take greater ownership of Cyber Security and Information Security, influence security strategy and work across infrastructure, networks, cloud, risk, governance and compliance. Apply today for a confidential discussion. Key Skills: Cyber Security Lead, Information Security Lead, Cyber Security, Information Security, Infrastructure Security, Network Security, Security Engineering, Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead, ISO 27001, ISMS, GRC, Security Governance, Security Compliance, Vulnerability Management, Patch Management, Penetration Testing, Azure Security, Microsoft 365 Security, Active Directory, IAM, Firewalls, Incident Response, Cyber Essentials, Security Audits, Risk Management, Supplier Assurance, Business Continuity, Disaster Recovery.
07/08/2026
Full time
Cyber Security Lead / Information Security Lead Bedford, Bedfordshire Hybrid 3 Days Office / 2 Days Remote £60,000 £70,000 + Excellent Benefits Permanent Infrastructure Security Network Security Cyber Security ISO 27001 Azure Microsoft 365 Are you an experienced Cyber Security Lead, Information Security Lead or Senior Security Engineer looking for an opportunity to step into a broader security leadership role? We are looking for a technically strong Cyber Security Lead / Information Security Lead to join a growing technology business in Bedford. This is an excellent opportunity for an Infrastructure Security, Network Security or Cyber Security professional who wants greater ownership and influence while remaining close to the technical side of security. This is not a purely GRC or compliance-focused position. The successful Cyber Security Lead will bring a strong technical foundation across infrastructure, networks and security engineering, combined with experience or exposure to Information Security, ISO 27001, security governance, risk and compliance. Working closely with Infrastructure, IT Operations, Engineering and senior stakeholders, you'll help strengthen the organisation's security posture across networks, servers, cloud platforms, Microsoft 365, Azure and business systems. What You'll Be Doing As the Cyber Security Lead, you'll take a leading role in information security and cyber security activities across the organisation. You'll help develop and continually improve the Information Security Management System (ISMS), maintain ISO 27001, support internal and external security audits and ensure security controls remain practical, effective and appropriate. You'll work closely with technical teams on infrastructure security, network security, vulnerability management, patch management and security remediation, coordinating penetration testing and ensuring identified vulnerabilities and security issues are addressed effectively. You'll also manage information security risk assessments, support incident response, supplier and third-party security assurance, Business Continuity and Disaster Recovery, while helping embed a strong security culture across the organisation. The Technical Background We're Looking For We're particularly interested in candidates who have developed their careers through Infrastructure, Network or Cyber Security and are now ready to take on greater Information Security leadership responsibility. You'll ideally bring experience across: Network & Infrastructure Security: firewalls, networking, Windows Server, Active Directory, endpoints and infrastructure hardening. Cloud & Identity Security: Microsoft 365, Azure Security, Identity & Access Management (IAM) and access controls. Security Operations: vulnerability management, patch management, penetration testing, remediation and incident response. Information Security: ISO 27001, ISMS, security audits, Cyber Essentials, security policies, governance, risk and compliance. You don't necessarily need to already hold the title of Cyber Security Lead. We would also be interested in hearing from experienced Senior Cyber Security Analysts, Senior Information Security Analysts, Security Engineers, Infrastructure Security Engineers, Network Security Engineers and Technical Security Leads who are ready to take the next step. Strong communication and stakeholder management skills are important. You'll be comfortable working with technical teams while also being able to explain security risks, controls and priorities clearly to senior and non-technical stakeholders. Why Consider This Cyber Security Lead Role? This is an opportunity to move beyond a purely engineering-focused position and take broader ownership of Information Security and Cyber Security, without leaving your technical background behind. You'll have the opportunity to influence security strategy, improve technical security controls, develop the ISMS, support ISO 27001 and work across Infrastructure Security, Network Security, Cloud Security, Security Governance and Cyber Security. Salary: £60,000 £70,000 Location: Bedford, Bedfordshire Working Pattern: Hybrid 3 days office / 2 days remote Employment: Permanent Focus: Cyber Security, Information Security, Infrastructure Security & Network Security Frameworks: ISO 27001 / ISMS / Cyber Essentials Ready for Your Next Move? If you're an experienced Cyber Security Lead, Information Security Lead, Senior Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead or Senior Cyber Security Analyst, we'd like to hear from you. This could be an excellent next step for a technically strong security professional who wants to take greater ownership of Cyber Security and Information Security, influence security strategy and work across infrastructure, networks, cloud, risk, governance and compliance. Apply today for a confidential discussion. Key Skills: Cyber Security Lead, Information Security Lead, Cyber Security, Information Security, Infrastructure Security, Network Security, Security Engineering, Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead, ISO 27001, ISMS, GRC, Security Governance, Security Compliance, Vulnerability Management, Patch Management, Penetration Testing, Azure Security, Microsoft 365 Security, Active Directory, IAM, Firewalls, Incident Response, Cyber Essentials, Security Audits, Risk Management, Supplier Assurance, Business Continuity, Disaster Recovery.
Randstad Technologies Recruitment
SOC Manager
Randstad Technologies Recruitment City, London
Job Title: SOC Manager Location: Remote (with occasional business travel) Duration: 6 Months The Role We are seeking an experienced SOC Manager for a 6-month contract. This is a strategic leadership position-not a hands-on technical analyst role. You will take full ownership of the Cyber Security Operations Centre (CSOC), driving strategy, managing incident response, and directing internal teams and external vendors. Key Responsibilities Define and lead the CSOC strategy, operations, and governance. Take command of major incident response, managing remediation and stakeholder communication. Oversee threat intelligence, vulnerability management, and security monitoring capabilities. Manage relationships with external agencies, Managed Security Service Providers (MSSPs), and technology partners. What We Need From You Proven experience as a SOC Manager (previous leadership experience is essential; this is not an entry-level management role). Deep expertise in incident management processes and live crisis response. Strong background in managing third-party vendors (MSSPs). Strategic mindset to plan security investments, tooling, and resourcing. Desirable: CISSP/CISM, Cloud Security (AWS/Azure), ITIL. How to Apply: Please submit your most up-to-date CV to (url removed) to be considered for this critical leadership role. Randstad Technologies is acting as an Employment Business in relation to this vacancy.
07/08/2026
Contractor
Job Title: SOC Manager Location: Remote (with occasional business travel) Duration: 6 Months The Role We are seeking an experienced SOC Manager for a 6-month contract. This is a strategic leadership position-not a hands-on technical analyst role. You will take full ownership of the Cyber Security Operations Centre (CSOC), driving strategy, managing incident response, and directing internal teams and external vendors. Key Responsibilities Define and lead the CSOC strategy, operations, and governance. Take command of major incident response, managing remediation and stakeholder communication. Oversee threat intelligence, vulnerability management, and security monitoring capabilities. Manage relationships with external agencies, Managed Security Service Providers (MSSPs), and technology partners. What We Need From You Proven experience as a SOC Manager (previous leadership experience is essential; this is not an entry-level management role). Deep expertise in incident management processes and live crisis response. Strong background in managing third-party vendors (MSSPs). Strategic mindset to plan security investments, tooling, and resourcing. Desirable: CISSP/CISM, Cloud Security (AWS/Azure), ITIL. How to Apply: Please submit your most up-to-date CV to (url removed) to be considered for this critical leadership role. Randstad Technologies is acting as an Employment Business in relation to this vacancy.
AI Security Researcher
Roke Manor Research Limited Romsey, Hampshire
AI Security Researcher Great ideas come from different minds. That's why we bring together engineers, scientists, analysts, and creatives from every background - and give them the trust, tools, and freedom to make a difference. What connects us is the mission: solving meaningful problems and building capability that protects what matters most. And as the challenges evolve, so do we - working on the technologies that will shape tomorrow, not just today. Responsibilities Conduct in-depth research into emerging AI security threats, vulnerabilities and attack techniques. Design and develop novel solutions, tools and prototypes that help protect systems and inform customer decisions. Perform vulnerability analysis, reverse engineering and security assessments across a range of platforms. Collaborate with multidisciplinary teams to transition research into real-world capabilities. Contribute to technical reports, white papers and customer deliverables that explain complex findings clearly. Present to both technical and non-technical audiences, communicating clearly the relevance and impact of the work. Stay ahead of the latest developments in AI security and share practical insights with the wider team. Qualifications You bring strong technical curiosity, sound judgement and experience in one or more of the following areas: Exploit development. Malware analysis. Secure software development. Vulnerability research skills. Machine Learning model development and understanding of the ML eco-system. Familiarity with vulnerability research tools and frameworks. Understanding of operating systems, networks and system architecture. Reverse engineering. Nice to Have Experience researching AI, machine learning or large language model security risks. Experience turning research ideas into working prototypes, tools or customer-facing demonstrations. Ability to explain technical findings to both specialist and non-specialist audiences. Benefits Learning as part of the way we work every day, through mentoring, coaching and new opportunities. ROKE Academy support for technical mastery, leadership development and long-term career growth. 30 days' holiday plus bank holidays, with the opportunity to buy or sell additional days. Private medical insurance, plus health, wellness and family support. Chemring ShareSave scheme, EV salary sacrifice scheme and access to discounts and cashback. About ROKE Built on over a 70-year heritage, ROKE offers specialist knowledge in sensors, communications, cyber, AI and machine learning. We change the way organisations think and act through dynamic insights from multiple layers of data. We take care of the innovative, technical work that keeps everyone safe. We have secured long-term work across the full spectrum on the latest client framework, creating a strong platform for continued growth and development in this domain. Location & Clearance This role can be based from Woking or Romsey, with an opportunity to visit our client sites in the London area. Due to the nature of this role, you must be eligible and willing to achieve DV clearance.
05/08/2026
Full time
AI Security Researcher Great ideas come from different minds. That's why we bring together engineers, scientists, analysts, and creatives from every background - and give them the trust, tools, and freedom to make a difference. What connects us is the mission: solving meaningful problems and building capability that protects what matters most. And as the challenges evolve, so do we - working on the technologies that will shape tomorrow, not just today. Responsibilities Conduct in-depth research into emerging AI security threats, vulnerabilities and attack techniques. Design and develop novel solutions, tools and prototypes that help protect systems and inform customer decisions. Perform vulnerability analysis, reverse engineering and security assessments across a range of platforms. Collaborate with multidisciplinary teams to transition research into real-world capabilities. Contribute to technical reports, white papers and customer deliverables that explain complex findings clearly. Present to both technical and non-technical audiences, communicating clearly the relevance and impact of the work. Stay ahead of the latest developments in AI security and share practical insights with the wider team. Qualifications You bring strong technical curiosity, sound judgement and experience in one or more of the following areas: Exploit development. Malware analysis. Secure software development. Vulnerability research skills. Machine Learning model development and understanding of the ML eco-system. Familiarity with vulnerability research tools and frameworks. Understanding of operating systems, networks and system architecture. Reverse engineering. Nice to Have Experience researching AI, machine learning or large language model security risks. Experience turning research ideas into working prototypes, tools or customer-facing demonstrations. Ability to explain technical findings to both specialist and non-specialist audiences. Benefits Learning as part of the way we work every day, through mentoring, coaching and new opportunities. ROKE Academy support for technical mastery, leadership development and long-term career growth. 30 days' holiday plus bank holidays, with the opportunity to buy or sell additional days. Private medical insurance, plus health, wellness and family support. Chemring ShareSave scheme, EV salary sacrifice scheme and access to discounts and cashback. About ROKE Built on over a 70-year heritage, ROKE offers specialist knowledge in sensors, communications, cyber, AI and machine learning. We change the way organisations think and act through dynamic insights from multiple layers of data. We take care of the innovative, technical work that keeps everyone safe. We have secured long-term work across the full spectrum on the latest client framework, creating a strong platform for continued growth and development in this domain. Location & Clearance This role can be based from Woking or Romsey, with an opportunity to visit our client sites in the London area. Due to the nature of this role, you must be eligible and willing to achieve DV clearance.
Cybersecurity Analyst
Academy Education Network Ltd Manchester, Lancashire
Overview Cybersecurity Analysts protect organisations from cyber threats. Depending on the speciality, roles may involve monitoring live security events in a Security Operations Centre (SOC), researching threat intelligence, conducting penetration tests to uncover vulnerabilities, or managing Governance, Risk & Compliance (GRC) workstreams. All work aligns with recognised frameworks such as NIST CSF, ISO 27001, and CIS Controls. Responsibilities Monitor security events and respond to active threats in real time. Run vulnerability assessments, penetration tests, and incident response exercises. Specialise in SOC analysis, threat intelligence, penetration testing, GRC, or cloud security. Work for banks, telcos, defence contractors, government agencies, NHS and FTSE 100 corporates. Career Progression Typical career stages for a Cybersecurity Analyst: Years 0-2: SOC Analyst (Tier 1) - monitor events and respond to common incidents; progression via CompTIA Security+ and SANS GCIH or CEH. Years 2-5: Cybersecurity Analyst / Penetration Tester - specialise in penetration testing (CREST CRT, OSCP), threat intelligence or GRC (ISO 27001 Lead Auditor). Years 5-8: Senior Analyst / Security Engineer - lead complex incident response, run major risk assessments, or design enterprise security architecture; often required to hold CISSP. Years 8+: Lead / Head of Security / CISO - strategic leadership of an organisation's security function; requires technical depth and business/board level communication. Qualifications & Skills Required technical knowledge and professional traits include: Calm decision making under incident pressure. Clear written reporting for non technical executives. Ethical decision making and professional integrity. Continuous learning across rapidly evolving threats. Methodical, evidence based investigation. Teamwork across IT, business and law enforcement. Relevant certifications such as CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP, ISO 27001 Lead Auditor. Typical Salary Ranges (UK) Junior SOC analysts at major banks and managed service providers start at £35,000-£45,000. Penetration testers and threat intelligence analysts at top consultancies earn £45,000-£65,000 within 3 years. Senior engineers and CISO track leaders in FTSE 100 companies can reach £100,000+. Education and Entry Routes Common pathways include: MSc Cybersecurity - 1 year postgraduate specialist degree (many are NCSC certified). Cybersecurity Apprenticeship - 2-4 years, fully employer funded (Levels 4 & 6). CompTIA Security+ plus a Tier 1 SOC role - common entry for career changers. University undergraduate degree in Cybersecurity or Computer Science - 3 years; with student loans and progression into junior roles. FAQ - Becoming a Cybersecurity Analyst in the UK How long does it take to become a cyber analyst? Typically straight after a 3 year undergraduate degree, or via CompTIA Security+ and a Tier 1 SOC role. Do I need a cybersecurity degree to work in the UK? Not strictly, but a specialist degree and relevant certifications are the most reliable route. Is the role on the Skilled Worker visa shortage list? No; however, salaries often meet the threshold and most private sector employers sponsor international analysts. What's the difference between a SOC analyst and a penetration tester? SOC analysts monitor events; penetration testers actively find vulnerabilities. Which UK certifications matter most? CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP. Can I move into cybersecurity from another career? Yes - career changers can transition via Security+ and a Tier 1 SOC role within 6-12 months.
04/08/2026
Full time
Overview Cybersecurity Analysts protect organisations from cyber threats. Depending on the speciality, roles may involve monitoring live security events in a Security Operations Centre (SOC), researching threat intelligence, conducting penetration tests to uncover vulnerabilities, or managing Governance, Risk & Compliance (GRC) workstreams. All work aligns with recognised frameworks such as NIST CSF, ISO 27001, and CIS Controls. Responsibilities Monitor security events and respond to active threats in real time. Run vulnerability assessments, penetration tests, and incident response exercises. Specialise in SOC analysis, threat intelligence, penetration testing, GRC, or cloud security. Work for banks, telcos, defence contractors, government agencies, NHS and FTSE 100 corporates. Career Progression Typical career stages for a Cybersecurity Analyst: Years 0-2: SOC Analyst (Tier 1) - monitor events and respond to common incidents; progression via CompTIA Security+ and SANS GCIH or CEH. Years 2-5: Cybersecurity Analyst / Penetration Tester - specialise in penetration testing (CREST CRT, OSCP), threat intelligence or GRC (ISO 27001 Lead Auditor). Years 5-8: Senior Analyst / Security Engineer - lead complex incident response, run major risk assessments, or design enterprise security architecture; often required to hold CISSP. Years 8+: Lead / Head of Security / CISO - strategic leadership of an organisation's security function; requires technical depth and business/board level communication. Qualifications & Skills Required technical knowledge and professional traits include: Calm decision making under incident pressure. Clear written reporting for non technical executives. Ethical decision making and professional integrity. Continuous learning across rapidly evolving threats. Methodical, evidence based investigation. Teamwork across IT, business and law enforcement. Relevant certifications such as CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP, ISO 27001 Lead Auditor. Typical Salary Ranges (UK) Junior SOC analysts at major banks and managed service providers start at £35,000-£45,000. Penetration testers and threat intelligence analysts at top consultancies earn £45,000-£65,000 within 3 years. Senior engineers and CISO track leaders in FTSE 100 companies can reach £100,000+. Education and Entry Routes Common pathways include: MSc Cybersecurity - 1 year postgraduate specialist degree (many are NCSC certified). Cybersecurity Apprenticeship - 2-4 years, fully employer funded (Levels 4 & 6). CompTIA Security+ plus a Tier 1 SOC role - common entry for career changers. University undergraduate degree in Cybersecurity or Computer Science - 3 years; with student loans and progression into junior roles. FAQ - Becoming a Cybersecurity Analyst in the UK How long does it take to become a cyber analyst? Typically straight after a 3 year undergraduate degree, or via CompTIA Security+ and a Tier 1 SOC role. Do I need a cybersecurity degree to work in the UK? Not strictly, but a specialist degree and relevant certifications are the most reliable route. Is the role on the Skilled Worker visa shortage list? No; however, salaries often meet the threshold and most private sector employers sponsor international analysts. What's the difference between a SOC analyst and a penetration tester? SOC analysts monitor events; penetration testers actively find vulnerabilities. Which UK certifications matter most? CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP. Can I move into cybersecurity from another career? Yes - career changers can transition via Security+ and a Tier 1 SOC role within 6-12 months.
Morson Edge
Secuity Operations Lead
Morson Edge
Our client Scottish Power are looking for a Security Operations Lead for an initial 12 month contract role, which will in all likelihood extend further. This is based at the client offices in Glasgow, working hybrid, 3 days in the office. SP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations and deliver a cyber resilient business, the Security Operations Lead will be essential in achieving our goals. The Security Operations Lead will be a subject matter expert on security incident detection and response. They will drive continuous improvement across the outsourced SOC and in-house SOC teams of analysts and engineers. Youll have experience of configuring SIEM tools, onboarding sources, writing processes and alerts, understanding business environments and managing incidents affecting applications and infrastructure across a varied technology stack spanning operational technology and information technology environments. You ll also be able to undertake post incident reviews to identify root causes and put follow-up mitigations in place. The postholder will work within a security operations team containing various cyber security functions such as threat intelligence, identity & access management, response & recovery and vulnerability management. What Youll be doing Support the Security Operations Manager in the running of BAU activities Implement and maintain 3rd line security incident / event management, escalation and technical response process and investigate suspected and actual incidents / events. Acting as a key escalation point in the team to the relevant team/individual Design, implement, manage, monitor, and upgrade security measures for the protections of the information systems and networks Identify and feedback any potential improvements from a cyber perspective to OT systems and infrastructure Ensuring incident identification, assessment, quantification, reporting, communication, mitigation and monitoring Ensuring compliance to policy, process, and procedure adherence and process improvisation to achieve operational objectives Revise and develop processes to strengthen the current Security Operations Framework Review policies and highlight the challenges in managing SLAs Ensuring daily management, administration & maintenance of security technology to achieve operational effectiveness Ensure the orchestration and integration of security services and platforms to maximise its usage and coverage The role will be integrated into an active and ambitious global cyber security function, contributing to SPEN s cyber security purpose of delivering cyber resilient OT and IT, to enable a safe and reliable electricity supply to customers What Youll bring Skills and experience in understanding at a technical level security operations. Awareness of key legislation and regulation impacting IT/OT General Control requirements in an energy utility. Experience in working within a SOC. Record of academic achievement, including some form of recognised qualification from further education, such as a degree or diploma. Good oral and written communication skills. Must be a proven team player to work, promote and consolidate efficient team working relationships.
04/08/2026
Contractor
Our client Scottish Power are looking for a Security Operations Lead for an initial 12 month contract role, which will in all likelihood extend further. This is based at the client offices in Glasgow, working hybrid, 3 days in the office. SP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations and deliver a cyber resilient business, the Security Operations Lead will be essential in achieving our goals. The Security Operations Lead will be a subject matter expert on security incident detection and response. They will drive continuous improvement across the outsourced SOC and in-house SOC teams of analysts and engineers. Youll have experience of configuring SIEM tools, onboarding sources, writing processes and alerts, understanding business environments and managing incidents affecting applications and infrastructure across a varied technology stack spanning operational technology and information technology environments. You ll also be able to undertake post incident reviews to identify root causes and put follow-up mitigations in place. The postholder will work within a security operations team containing various cyber security functions such as threat intelligence, identity & access management, response & recovery and vulnerability management. What Youll be doing Support the Security Operations Manager in the running of BAU activities Implement and maintain 3rd line security incident / event management, escalation and technical response process and investigate suspected and actual incidents / events. Acting as a key escalation point in the team to the relevant team/individual Design, implement, manage, monitor, and upgrade security measures for the protections of the information systems and networks Identify and feedback any potential improvements from a cyber perspective to OT systems and infrastructure Ensuring incident identification, assessment, quantification, reporting, communication, mitigation and monitoring Ensuring compliance to policy, process, and procedure adherence and process improvisation to achieve operational objectives Revise and develop processes to strengthen the current Security Operations Framework Review policies and highlight the challenges in managing SLAs Ensuring daily management, administration & maintenance of security technology to achieve operational effectiveness Ensure the orchestration and integration of security services and platforms to maximise its usage and coverage The role will be integrated into an active and ambitious global cyber security function, contributing to SPEN s cyber security purpose of delivering cyber resilient OT and IT, to enable a safe and reliable electricity supply to customers What Youll bring Skills and experience in understanding at a technical level security operations. Awareness of key legislation and regulation impacting IT/OT General Control requirements in an energy utility. Experience in working within a SOC. Record of academic achievement, including some form of recognised qualification from further education, such as a degree or diploma. Good oral and written communication skills. Must be a proven team player to work, promote and consolidate efficient team working relationships.
Cyber Security Analyst
Novia Financial Plc Bath, Somerset
The Cyber Security Analyst is responsible for helping us to secure our systems and protect our key stakeholders, IT infrastructure, information assets and business operations. Reporting to the Head of Information Security, the successful candidate will work with key business stakeholders, SOC, IT and 3rd party vendors, to ensure that we operate a robust Cyber Security infrastructure and ISO27001 ISMS that, is highly effective in protecting the business, in line with our commitment to clients and our regulatory obligations. Key Responsibilities: Working with the Head of Information Security to develop policy and strategy in line with the group's vision. Help implement security controls to protect systems, networks, applications, and customer data. Monitor security events and respond to cyber incidents, ensuring threats are detected, contained, and remediated. Oversee and monitor vulnerabilities and security patching, coordinating remediation with IT and business teams. Oversee and monitor cloud and on-premises environments, including Microsoft 365, Entra ID, servers, endpoints, and network infrastructure. Support regulatory and compliance requirements such as FCA, GDPR, ISO 27001, and other industry standards. Conduct security assessments and testing, including configuration reviews, penetration test remediation, and risk assessments. Provide security advice to projects and technology teams, ensuring secure-by-design principles are applied. Develop and improve security monitoring, automation, and detection capabilities to enhance cyber resilience. Specialist Skills, Qualifications and Experience: Essential: 3+ years' experience in a cyber security role. Experience with Microsoft 365, Entra ID, Purview, endpoint security, SIEM, and vulnerability management. Experience in incident response and security monitoring. Knowledge of ISO 27001, GDPR, and financial services regulatory requirements. Advanced security certifications such as CISSP, CISM, CCSP, GIAC, or equivalent. Experience conducting security assessments, technical reviews, and supporting audit activities. Desirable: Experience with cloud security, security automation, and security architecture. Knowledge of FCA, PRA, DORA, and cyber resilience requirements. Experience mentoring junior engineers or leading technical security projects. Experience working with SIEM, EDR, vulnerability management, and identity and access management solutions. Knowledge of Microsoft Purview, DLP policy creation and reporting Knowledge of KQL and JSON for queries and automation Core Competencies Analytical & Problem-Solving Skills: Ability to assess complex security issues and develop practical, risk-based solutions. Communication & Stakeholder Management: Ability to explain security risks and recommendations to both technical and non-technical audiences. Business Focus: The motivation and ability to always apply good financial practice and company procedures. Operational Excellence: Continually delivering and improving excellence for all clients and customers. Client and Customer Focus: Add value to client/customer, adhere to Treating Customers Fairly principles, and operate as a true business partner. Communication: Communicate clearly and concisely, tailoring content and style, with ability to make a positive impression on others. Expert Knowledge: Consistent application of professional or specialist knowledge and skills; takes opportunities to contribute to policy and best practice. Working with others: Working successfully with others and building a network of good relationships to achieve shared goals. Performance Focus: Demonstrate energy and enthusiasm, takes ownership, delivers results and improves personal performance.
03/08/2026
Full time
The Cyber Security Analyst is responsible for helping us to secure our systems and protect our key stakeholders, IT infrastructure, information assets and business operations. Reporting to the Head of Information Security, the successful candidate will work with key business stakeholders, SOC, IT and 3rd party vendors, to ensure that we operate a robust Cyber Security infrastructure and ISO27001 ISMS that, is highly effective in protecting the business, in line with our commitment to clients and our regulatory obligations. Key Responsibilities: Working with the Head of Information Security to develop policy and strategy in line with the group's vision. Help implement security controls to protect systems, networks, applications, and customer data. Monitor security events and respond to cyber incidents, ensuring threats are detected, contained, and remediated. Oversee and monitor vulnerabilities and security patching, coordinating remediation with IT and business teams. Oversee and monitor cloud and on-premises environments, including Microsoft 365, Entra ID, servers, endpoints, and network infrastructure. Support regulatory and compliance requirements such as FCA, GDPR, ISO 27001, and other industry standards. Conduct security assessments and testing, including configuration reviews, penetration test remediation, and risk assessments. Provide security advice to projects and technology teams, ensuring secure-by-design principles are applied. Develop and improve security monitoring, automation, and detection capabilities to enhance cyber resilience. Specialist Skills, Qualifications and Experience: Essential: 3+ years' experience in a cyber security role. Experience with Microsoft 365, Entra ID, Purview, endpoint security, SIEM, and vulnerability management. Experience in incident response and security monitoring. Knowledge of ISO 27001, GDPR, and financial services regulatory requirements. Advanced security certifications such as CISSP, CISM, CCSP, GIAC, or equivalent. Experience conducting security assessments, technical reviews, and supporting audit activities. Desirable: Experience with cloud security, security automation, and security architecture. Knowledge of FCA, PRA, DORA, and cyber resilience requirements. Experience mentoring junior engineers or leading technical security projects. Experience working with SIEM, EDR, vulnerability management, and identity and access management solutions. Knowledge of Microsoft Purview, DLP policy creation and reporting Knowledge of KQL and JSON for queries and automation Core Competencies Analytical & Problem-Solving Skills: Ability to assess complex security issues and develop practical, risk-based solutions. Communication & Stakeholder Management: Ability to explain security risks and recommendations to both technical and non-technical audiences. Business Focus: The motivation and ability to always apply good financial practice and company procedures. Operational Excellence: Continually delivering and improving excellence for all clients and customers. Client and Customer Focus: Add value to client/customer, adhere to Treating Customers Fairly principles, and operate as a true business partner. Communication: Communicate clearly and concisely, tailoring content and style, with ability to make a positive impression on others. Expert Knowledge: Consistent application of professional or specialist knowledge and skills; takes opportunities to contribute to policy and best practice. Working with others: Working successfully with others and building a network of good relationships to achieve shared goals. Performance Focus: Demonstrate energy and enthusiasm, takes ownership, delivers results and improves personal performance.
Security Engineer
Cheshire West and Chester Ellesmere Port, Cheshire
Grade 12 £54,992 - £62,778(as of April 2025 pay band figures) The Cheshire West and Chester Council Digital, Data and Technology (DDAT) department has recently undergone a huge transformation and is looking for a Security Engineer tolead the protection of the Councils' hosting, networks, and data infrastructure.The post holder will support the implementation and maintenance of the systems used toprotect computer systems and networks and track incidents. Closing date for applications: Midnight on 12th August 2026 Cheshire West and Chester Council brings a fresh and energetic approach to providing top quality services for its many customers and communities. The Cheshire West and Chester Council Digital, Data and Technology (DDAT) department has recently undergone a huge transformation and is looking for aSecurity Engineer to lead the protection of the Councils' hosting, networks, and data infrastructure. The post holder will support the implementation and maintenance of the systems used to protect computer systems and networks and track incidents. This is an exciting opportunity to join a newly created and progressive team with big ambitions for the future. This role is a Grade 12, £54,992 - £62,778(as of April 2025 pay band figures). Closing date for applications is midnight on 12th August 2026. Role responsibilities include: Lead day to day operational security across the DDaT service, including incident response, cross team coordination, security assessments, vulnerability scanning and code audits Identify and resolve security vulnerabilities by developing technical solutions, researching emerging threats, building threat models and driving automation of security improvements Oversee phishing testing and awareness activity, working with the security analyst team and reporting outcomes to senior management Support the development and continuous review of cyber security policies, ensuring they remain effective in a changing threat landscape Act as the main point of contact for operational security matters, providing guidance and support across the council and monitoring security tools to manage risks effectively Participate in the out of hours rota, responding to alerts and incidents raised by the SOC We are seeking a skilled and motivated cyber security professional with a strong technical background, supported by a degree in Computer Science, Cybersecurity or equivalent experience, and relevant industry certifications such as CISSP, CISM, CompTIA Security+ or CISA. You will bring proven experience in securing network and infrastructure environments, including firewalls, encryption, VPNs and endpoint protection, alongside hands on experience of vulnerability identification and remediation, for example through penetration testing and threat analysis. A solid understanding of security tools, monitoring, reporting and auditing, as well as familiarity with ISO27001 and modern practices such as patch management and DevOps or SecOps, is essential. You will have practical experience of protecting a range of systems and data platforms, including Windows and legacy environments, and be confident in monitoring network activity to detect and prevent intrusion. The ability to write secure code, for example in Python or similar languages, to support automation and continuous improvement is important, along with up to date knowledge of emerging threats and attack methods. You will be a strong communicator and collaborator, able to explain technical concepts clearly to a range of audiences and build effective working relationships across the organisation and with external partners. You will be self motivated, resilient and able to manage competing priorities in a fast paced environment, using sound judgement to balance business needs and technical constraints while delivering practical, innovative solutions. Experience within local government or in roles such as a security analyst or penetration tester would be advantageous. By joining Cheshire West and Chester Council, you will be part of a GOLD Investors in People (IiP) organisation which is focused on building a stronger future where we all play our part in thriving, caring and sustainable communities.
03/08/2026
Full time
Grade 12 £54,992 - £62,778(as of April 2025 pay band figures) The Cheshire West and Chester Council Digital, Data and Technology (DDAT) department has recently undergone a huge transformation and is looking for a Security Engineer tolead the protection of the Councils' hosting, networks, and data infrastructure.The post holder will support the implementation and maintenance of the systems used toprotect computer systems and networks and track incidents. Closing date for applications: Midnight on 12th August 2026 Cheshire West and Chester Council brings a fresh and energetic approach to providing top quality services for its many customers and communities. The Cheshire West and Chester Council Digital, Data and Technology (DDAT) department has recently undergone a huge transformation and is looking for aSecurity Engineer to lead the protection of the Councils' hosting, networks, and data infrastructure. The post holder will support the implementation and maintenance of the systems used to protect computer systems and networks and track incidents. This is an exciting opportunity to join a newly created and progressive team with big ambitions for the future. This role is a Grade 12, £54,992 - £62,778(as of April 2025 pay band figures). Closing date for applications is midnight on 12th August 2026. Role responsibilities include: Lead day to day operational security across the DDaT service, including incident response, cross team coordination, security assessments, vulnerability scanning and code audits Identify and resolve security vulnerabilities by developing technical solutions, researching emerging threats, building threat models and driving automation of security improvements Oversee phishing testing and awareness activity, working with the security analyst team and reporting outcomes to senior management Support the development and continuous review of cyber security policies, ensuring they remain effective in a changing threat landscape Act as the main point of contact for operational security matters, providing guidance and support across the council and monitoring security tools to manage risks effectively Participate in the out of hours rota, responding to alerts and incidents raised by the SOC We are seeking a skilled and motivated cyber security professional with a strong technical background, supported by a degree in Computer Science, Cybersecurity or equivalent experience, and relevant industry certifications such as CISSP, CISM, CompTIA Security+ or CISA. You will bring proven experience in securing network and infrastructure environments, including firewalls, encryption, VPNs and endpoint protection, alongside hands on experience of vulnerability identification and remediation, for example through penetration testing and threat analysis. A solid understanding of security tools, monitoring, reporting and auditing, as well as familiarity with ISO27001 and modern practices such as patch management and DevOps or SecOps, is essential. You will have practical experience of protecting a range of systems and data platforms, including Windows and legacy environments, and be confident in monitoring network activity to detect and prevent intrusion. The ability to write secure code, for example in Python or similar languages, to support automation and continuous improvement is important, along with up to date knowledge of emerging threats and attack methods. You will be a strong communicator and collaborator, able to explain technical concepts clearly to a range of audiences and build effective working relationships across the organisation and with external partners. You will be self motivated, resilient and able to manage competing priorities in a fast paced environment, using sound judgement to balance business needs and technical constraints while delivering practical, innovative solutions. Experience within local government or in roles such as a security analyst or penetration tester would be advantageous. By joining Cheshire West and Chester Council, you will be part of a GOLD Investors in People (IiP) organisation which is focused on building a stronger future where we all play our part in thriving, caring and sustainable communities.
Level 1 SOC Analyst
Webhosting
TelefonicaTech United Kingdom, Belfast Not specified Full-time Not specified Operations Job Description Due to expansion, we're now recruiting for a Cyber Security Analyst - L1. The Security Operation Centre (SOC) Information Security Analyst is the first level of monitoring in the SOC. The position monitors and responds to security events from managed customer security systems as part of a team on a rotating 24 x 7 x 365 basis. Your background should include exposure to security technologies including SIEM/EDR, firewalls, logging, monitoring and vulnerability management. You should understand network security practices. Excellent customer service while solving problems should be a top priority for you. Telefonica Tech is a fast-paced, entrepreneurial environment so to be successful you'll need to be a pro-active individual, take direction well, communicate succinctly and collaborate effectively. Key Responsibilities Ability to clearly explain technical concepts to non-technical stakeholders. Recommend enhancements to SOC security process, procedures and policies. Communicate effectively with customers, teammates, and management. Provide further detail on incidents should they arise, this can include, basic level sandboxing, IP reputation or further detailing of IOC's. Can provide base level remediation (blocking user accounts, isolating servers) to then triage for Level 2 for further investigation. Analyse and report on anomalous behaviour. Determines and directs Advanced remediation and recovery efforts (with assistance from tooling and/or Level 2) Investigate alerts using SIEM, data visualisation, pattern analysis and automation. Solid cyber security skills including SIEM Have the drive to dive deep into issues Ability to identify security threats, trends and anomalies Logical thinker and creative problem solver Telefónica Tech(part of the Telefónica Group) is a leading NextGen Tech solutions provider with a highly diversified team of over 6,000 exceptionally skilled employees and nationalities. We serve more than 5.5m customers every day in over 175 countries, with a global ecosystem of market-leading partners. Global strategic hubs: Spain, Brazil, the UK, Germany. The Telefónica Tech UK&I hub has an end- to-end portfolio of market leading services and develops integrated technology solutions to accelerate digital transformation through: Cloud, Data & AI, Enterprise Applications, Workplace Services and Cyber Security & Networking. Values:Open, Trusted and Bold HPE:Platinum Partner - FY23 UK&I Solution Provider of the Year Palo Alto & Crowdstrike:part of our NextDefense Cyber Security Portfolio Fortinet:Elite VIP Program - one of only 2 in the UK AWS:Advanced Solution & Managed Service Provider Program
03/08/2026
Full time
TelefonicaTech United Kingdom, Belfast Not specified Full-time Not specified Operations Job Description Due to expansion, we're now recruiting for a Cyber Security Analyst - L1. The Security Operation Centre (SOC) Information Security Analyst is the first level of monitoring in the SOC. The position monitors and responds to security events from managed customer security systems as part of a team on a rotating 24 x 7 x 365 basis. Your background should include exposure to security technologies including SIEM/EDR, firewalls, logging, monitoring and vulnerability management. You should understand network security practices. Excellent customer service while solving problems should be a top priority for you. Telefonica Tech is a fast-paced, entrepreneurial environment so to be successful you'll need to be a pro-active individual, take direction well, communicate succinctly and collaborate effectively. Key Responsibilities Ability to clearly explain technical concepts to non-technical stakeholders. Recommend enhancements to SOC security process, procedures and policies. Communicate effectively with customers, teammates, and management. Provide further detail on incidents should they arise, this can include, basic level sandboxing, IP reputation or further detailing of IOC's. Can provide base level remediation (blocking user accounts, isolating servers) to then triage for Level 2 for further investigation. Analyse and report on anomalous behaviour. Determines and directs Advanced remediation and recovery efforts (with assistance from tooling and/or Level 2) Investigate alerts using SIEM, data visualisation, pattern analysis and automation. Solid cyber security skills including SIEM Have the drive to dive deep into issues Ability to identify security threats, trends and anomalies Logical thinker and creative problem solver Telefónica Tech(part of the Telefónica Group) is a leading NextGen Tech solutions provider with a highly diversified team of over 6,000 exceptionally skilled employees and nationalities. We serve more than 5.5m customers every day in over 175 countries, with a global ecosystem of market-leading partners. Global strategic hubs: Spain, Brazil, the UK, Germany. The Telefónica Tech UK&I hub has an end- to-end portfolio of market leading services and develops integrated technology solutions to accelerate digital transformation through: Cloud, Data & AI, Enterprise Applications, Workplace Services and Cyber Security & Networking. Values:Open, Trusted and Bold HPE:Platinum Partner - FY23 UK&I Solution Provider of the Year Palo Alto & Crowdstrike:part of our NextDefense Cyber Security Portfolio Fortinet:Elite VIP Program - one of only 2 in the UK AWS:Advanced Solution & Managed Service Provider Program
Focus Group
Senior SOC Analyst
Focus Group Manchester, Lancashire
Senior SOC Analyst UK - 3 days a week in our Manchester office (Suite B, Maple Court, M60 Office Park, Wynne Ave, Swinton, Clifton, Manchester, M27 8FF) £50-£55k (Dependent on experience) + benefits Focus Group is looking for a Senior SOC Analyst to play a key role within our Managed Security Services team. This is a dual focused position combining hands on technical expertise with day to day operational leadership, ensuring high quality delivery of managed detection and response services across a diverse customer base. You'll lead SOC operations, act as the escalation point for complex security incidents, and mentor junior analysts-driving both service excellence and team development. What you'll do Lead day to day SOC operations, ensuring effective triage, escalation, and communication workflows Act as the primary escalation point for complex security investigations and incidents Conduct advanced threat investigations across endpoints, networks, and cloud environments Perform proactive threat hunting and detection tuning to improve coverage and reduce noise Manage and mentor Tier 1-2 analysts, supporting development and technical growth Ensure ticket quality, SLA adherence, and high service standards across SOC operations Support onboarding of new customers into monitoring and detection platforms Collaborate with Cyber Security leadership to improve detection strategy and SOC maturity Analyse logs and security data to identify malicious or suspicious activity Develop and maintain playbooks, runbooks, and knowledge base content Produce clear, actionable incident reports for internal and customer stakeholders Engage directly with customers during escalations, incident reviews, and briefings Identify opportunities for automation, process improvement, and enhanced detection capabilities Stay up to date with emerging threats, attack techniques, and MITRE ATT&CK developments What you'll bring 4-6 years' experience in a SOC or MSSP environment at Tier 2-3 or Lead level Strong hands on experience with SIEM platforms (e.g. Microsoft Sentinel, Splunk, Elastic, LogPoint) Experience with EDR tools such as Microsoft Defender, SentinelOne, or Bitdefender Deep understanding of MITRE ATT&CK and modern threat detection methodologies Strong incident response, investigation, and log analysis capability across multiple data sources Ability to lead during high pressure incidents with calm, confident decision making Strong communication skills, including producing clear incident reports and updates Proven ability to mentor, coach, and support junior analysts Organised approach with the ability to manage multiple concurrent incidents Proactive mindset focused on continuous improvement and service optimisation Nice to have Certifications such as SC 200, GCIH, GCIA, Security+, or BTL1 Experience in an MSSP or multi customer environment Microsoft security stack experience (Defender XDR, Sentinel, M365 security) Knowledge of cloud security, email security, and vulnerability management Experience with KQL or other query languages Scripting skills (PowerShell, Python) Familiarity with SOAR and threat intelligence platforms Understanding of compliance frameworks (ISO 27001, NIST, Cyber Essentials) Future opportunities SOC Manager / Head of Security Operations Cyber Security Technical Lead Detection Engineering Lead Threat Intelligence LeadIncident Response Manager Security Consultant / Advisory
03/08/2026
Full time
Senior SOC Analyst UK - 3 days a week in our Manchester office (Suite B, Maple Court, M60 Office Park, Wynne Ave, Swinton, Clifton, Manchester, M27 8FF) £50-£55k (Dependent on experience) + benefits Focus Group is looking for a Senior SOC Analyst to play a key role within our Managed Security Services team. This is a dual focused position combining hands on technical expertise with day to day operational leadership, ensuring high quality delivery of managed detection and response services across a diverse customer base. You'll lead SOC operations, act as the escalation point for complex security incidents, and mentor junior analysts-driving both service excellence and team development. What you'll do Lead day to day SOC operations, ensuring effective triage, escalation, and communication workflows Act as the primary escalation point for complex security investigations and incidents Conduct advanced threat investigations across endpoints, networks, and cloud environments Perform proactive threat hunting and detection tuning to improve coverage and reduce noise Manage and mentor Tier 1-2 analysts, supporting development and technical growth Ensure ticket quality, SLA adherence, and high service standards across SOC operations Support onboarding of new customers into monitoring and detection platforms Collaborate with Cyber Security leadership to improve detection strategy and SOC maturity Analyse logs and security data to identify malicious or suspicious activity Develop and maintain playbooks, runbooks, and knowledge base content Produce clear, actionable incident reports for internal and customer stakeholders Engage directly with customers during escalations, incident reviews, and briefings Identify opportunities for automation, process improvement, and enhanced detection capabilities Stay up to date with emerging threats, attack techniques, and MITRE ATT&CK developments What you'll bring 4-6 years' experience in a SOC or MSSP environment at Tier 2-3 or Lead level Strong hands on experience with SIEM platforms (e.g. Microsoft Sentinel, Splunk, Elastic, LogPoint) Experience with EDR tools such as Microsoft Defender, SentinelOne, or Bitdefender Deep understanding of MITRE ATT&CK and modern threat detection methodologies Strong incident response, investigation, and log analysis capability across multiple data sources Ability to lead during high pressure incidents with calm, confident decision making Strong communication skills, including producing clear incident reports and updates Proven ability to mentor, coach, and support junior analysts Organised approach with the ability to manage multiple concurrent incidents Proactive mindset focused on continuous improvement and service optimisation Nice to have Certifications such as SC 200, GCIH, GCIA, Security+, or BTL1 Experience in an MSSP or multi customer environment Microsoft security stack experience (Defender XDR, Sentinel, M365 security) Knowledge of cloud security, email security, and vulnerability management Experience with KQL or other query languages Scripting skills (PowerShell, Python) Familiarity with SOAR and threat intelligence platforms Understanding of compliance frameworks (ISO 27001, NIST, Cyber Essentials) Future opportunities SOC Manager / Head of Security Operations Cyber Security Technical Lead Detection Engineering Lead Threat Intelligence LeadIncident Response Manager Security Consultant / Advisory
Security Operations Centre Analyst
Sussex Police
This role is within a unit where Surrey Police and Sussex Police work in collaboration, whilst remaining two separate legal entities/employers with different terms and conditions. Both Surrey Police staff and Sussex Police staff are employed in this unit on their own force terms and conditions. Successful candidates may be appointed on the terms and conditions of employment of either Surrey Police or Sussex Police, depending on organisational requirements. A discussion will be held with the successful candidate to confirm the details of location, salary, allowances and hours. Division / Department - Digital Data & Technology Grade - Surrey Police Grade H / Sussex Police Grade 11 Status - Full Time Contract Type - Permanent Salary Grade Range - Surrey Police £39,149 - £45,058 / Sussex Police £41,487 - £45,765 Working Hours - 37.0 Hours per Week Shift Allowance - No Politically Restricted - No Location - See Advert The starting salary for this role will usually be at the bottom of the salary range and will be pro-rata if the working hours are less than full time. The Role & Key Responsibilities We are seeking a talented and motivated Security Operations Centre (SOC) Analyst to join our dynamic team. The SOC Analyst will play a crucial role in safeguarding Surrey Police and Sussex Police information systems and data against cyber threats. You will be expected to: Monitor security alerts and incidents to identify potential threats and vulnerabilities. Investigate and analyse security incidents, assessing the impact and implementing appropriate response measures. Utilise security tools and technologies to detect and mitigate security breaches. Collaborate with cross-functional teams to develop and implement security policies and procedures. Perform vulnerability assessments on internal networks, systems, and devices. Participate in incident response activities, including documentation and reporting. Produce security metrics to be presented to key stakeholders. Stay updated on the latest security trends, threats, and technologies. Skills & Experience The preferred candidate will possess experience in protective monitoring or demonstrate a clear passion and eagerness to advance in the field of cyber security. Essential qualifications and skills Qualifications and/or Certifications in cyber security, e.g. BA in a related field, CompTIA Sec+, Microsoft Certified (SC-900). Experience with vulnerability assessment and management of findings, including tools such as Nessus, Qualys, or OpenVAS. In-depth knowledge of cyber-security principles, tools, and technologies. Proven and well-evidenced analytical, investigative and problem-solving skills. Hands on experience with SIEM (Security Information and Event Management) tools. Proven ability to write and present clear, concise, accurate and logical reports. Excellent communication and teamwork abilities. If you possess these skills and are eager to contribute to our team, we encourage you to apply. SFIA 9 Skills Mapping Security Operations (SCAD): Level 4 Incident Management (USUP): Level 3 Vulnerability Assessment (VUAS): Level 4 Why Work With Us? Policing is an exciting 24/7 business and we all have commitments outside work. We're invested in supporting people to balance their life with work and we encourage flexible working. We are open to conversations about job shares and part time working. We encourage agile working, giving you the opportunity to manage your own diary and work wherever you give the best service to the public. This may include flexi time and home working. We take pride in looking after our people and offer a variety of benefits; career progression contributory pension scheme (LGPS) generous annual leave allowance discounts for everyday spend on site gyms and a range of sports clubs generous and supportive parental leave financial and mental wellbeing guidance and support discounted contributory healthcare scheme We welcome any queries that you may have regarding this vacancy. If you wish to discuss anything further then please contact Matthew Williams, IT Security Officer, at Surrey Police and Sussex Police work together in collaboration for this role, however they remain two different employers with differing pay scales, allowances, and terms and conditions including hours of employment. Location preferences will be discussed with the successful candidate. Diversity Statement We are only as good as our people. It's important that our officers and staff can be themselves in the workplace and we know that as an organisation we'll grow from the variety of thinking, approach, and the skills that diversity brings; all of which help us to deliver a better policing service. We strive to ensure how we deliver our services, provide information and how we recruit is open and accessible to all. We have multiple staff support groups who help to improve our understanding of minority issues and ensure they are reflected in our work. We are proud members of Disability Confident, hold Race Equality Matters Trailblazer status, are a signatory of the Race at Work Charter and are aligned with the Armed Forces Covenant and the HeForShe movement. We are committed to being an anti racist police service. We promise to challenge injustice, ensure fairness and to uphold anti racist principles in both our organisation and our communities. For more information, you can read our full anti racism statement here . We value the differences that people bring from all backgrounds and communities. Regardless of age, sex, ethnicity, sexual orientation, gender identity or gender expression, disability, social status, or religious belief, we would love to hear from you.
03/08/2026
Full time
This role is within a unit where Surrey Police and Sussex Police work in collaboration, whilst remaining two separate legal entities/employers with different terms and conditions. Both Surrey Police staff and Sussex Police staff are employed in this unit on their own force terms and conditions. Successful candidates may be appointed on the terms and conditions of employment of either Surrey Police or Sussex Police, depending on organisational requirements. A discussion will be held with the successful candidate to confirm the details of location, salary, allowances and hours. Division / Department - Digital Data & Technology Grade - Surrey Police Grade H / Sussex Police Grade 11 Status - Full Time Contract Type - Permanent Salary Grade Range - Surrey Police £39,149 - £45,058 / Sussex Police £41,487 - £45,765 Working Hours - 37.0 Hours per Week Shift Allowance - No Politically Restricted - No Location - See Advert The starting salary for this role will usually be at the bottom of the salary range and will be pro-rata if the working hours are less than full time. The Role & Key Responsibilities We are seeking a talented and motivated Security Operations Centre (SOC) Analyst to join our dynamic team. The SOC Analyst will play a crucial role in safeguarding Surrey Police and Sussex Police information systems and data against cyber threats. You will be expected to: Monitor security alerts and incidents to identify potential threats and vulnerabilities. Investigate and analyse security incidents, assessing the impact and implementing appropriate response measures. Utilise security tools and technologies to detect and mitigate security breaches. Collaborate with cross-functional teams to develop and implement security policies and procedures. Perform vulnerability assessments on internal networks, systems, and devices. Participate in incident response activities, including documentation and reporting. Produce security metrics to be presented to key stakeholders. Stay updated on the latest security trends, threats, and technologies. Skills & Experience The preferred candidate will possess experience in protective monitoring or demonstrate a clear passion and eagerness to advance in the field of cyber security. Essential qualifications and skills Qualifications and/or Certifications in cyber security, e.g. BA in a related field, CompTIA Sec+, Microsoft Certified (SC-900). Experience with vulnerability assessment and management of findings, including tools such as Nessus, Qualys, or OpenVAS. In-depth knowledge of cyber-security principles, tools, and technologies. Proven and well-evidenced analytical, investigative and problem-solving skills. Hands on experience with SIEM (Security Information and Event Management) tools. Proven ability to write and present clear, concise, accurate and logical reports. Excellent communication and teamwork abilities. If you possess these skills and are eager to contribute to our team, we encourage you to apply. SFIA 9 Skills Mapping Security Operations (SCAD): Level 4 Incident Management (USUP): Level 3 Vulnerability Assessment (VUAS): Level 4 Why Work With Us? Policing is an exciting 24/7 business and we all have commitments outside work. We're invested in supporting people to balance their life with work and we encourage flexible working. We are open to conversations about job shares and part time working. We encourage agile working, giving you the opportunity to manage your own diary and work wherever you give the best service to the public. This may include flexi time and home working. We take pride in looking after our people and offer a variety of benefits; career progression contributory pension scheme (LGPS) generous annual leave allowance discounts for everyday spend on site gyms and a range of sports clubs generous and supportive parental leave financial and mental wellbeing guidance and support discounted contributory healthcare scheme We welcome any queries that you may have regarding this vacancy. If you wish to discuss anything further then please contact Matthew Williams, IT Security Officer, at Surrey Police and Sussex Police work together in collaboration for this role, however they remain two different employers with differing pay scales, allowances, and terms and conditions including hours of employment. Location preferences will be discussed with the successful candidate. Diversity Statement We are only as good as our people. It's important that our officers and staff can be themselves in the workplace and we know that as an organisation we'll grow from the variety of thinking, approach, and the skills that diversity brings; all of which help us to deliver a better policing service. We strive to ensure how we deliver our services, provide information and how we recruit is open and accessible to all. We have multiple staff support groups who help to improve our understanding of minority issues and ensure they are reflected in our work. We are proud members of Disability Confident, hold Race Equality Matters Trailblazer status, are a signatory of the Race at Work Charter and are aligned with the Armed Forces Covenant and the HeForShe movement. We are committed to being an anti racist police service. We promise to challenge injustice, ensure fairness and to uphold anti racist principles in both our organisation and our communities. For more information, you can read our full anti racism statement here . We value the differences that people bring from all backgrounds and communities. Regardless of age, sex, ethnicity, sexual orientation, gender identity or gender expression, disability, social status, or religious belief, we would love to hear from you.
Senior IT Cyber Governance, Risk & Compliance Analyst
The Fidelis Partnership
Senior IT Cyber Governance, Risk & Compliance Analyst London Contractor On Site About us The Fidelis Partnership is a leading privately-owned, Bermuda-based Managing General Underwriter, which, through its subsidiaries, is a global underwriter of property, bespoke and specialty insurance and reinsurance products. The Fidelis Partnership is one of the largest Managing General Underwriters globally and its operations also include outwards reinsurance, claims handling, exposure management and portfolio analytics. The Fidelis Partnership also sponsors and incubates specialist MGAs through its Pine Walk platform. The Fidelis Partnership is separately owned and managed from the ownership and management of Fidelis Insurance Group. Across product lines and geographies, we focus on three diversified pillars: reinsurance, specialty and bespoke solutions. We are truly diversified. Our long-standing partnerships with capital providers and quota share partners make us nimble. Our breadth of expertise and capabilities deliver outstanding market returns. The role The Senior IT Cyber Governance, Risk & Compliance Analyst will support the development, implementation and oversight of the organisation's IT governance, cyber risk and compliance activities. This role involves supporting IT and cyber risk assessments, compliance with relevant regulatory and control frameworks, audit activity, and the identification and tracking of vulnerabilities, control gaps and remediation actions across IT systems and processes. The Senior IT Cyber Governance, Risk & Compliance Analyst will work closely with internal stakeholders to help ensure that IT and cyber activities are aligned with regulatory expectations, internal policies and good practice. Key accountabilities Compliance and Risk Management: Support compliance with applicable regulatory, IT, cyber and control frameworks, which may include DORA, ISO 27001, NIST CSF, SOX and Cyber Essentials. Support the evaluation and management of IT, cyber, compliance and security risks across systems, processes and operations. Monitor emerging technology, cyber and operational resilience risks to support proactive risk management and timely escalation. Assist in preparing for and supporting regulatory inspections and internal, external and third-party audits. Support the tracking of cyber risk remediation actions, including actions arising from risk assessments, assurance reviews, incidents, audits, control reviews and control improvement initiatives. Support the maintenance of the cyber risk register, including the capture of risks, issues and remediation actions, and the preparation of updates for governance forums. Support third-party and supplier security assurance activities, including security due diligence, assessment of supplier responses and tracking of supplier remediation actions. Coordinate and evidence user access reviews and privileged access reviews with system owners and the business, supporting the move to tool-based access certification. Perform first-line compliance monitoring and control checks against information security policies and standards, including the tracking of policy exceptions. Policy & Procedure Development: Support the development, implementation and updating of IT risk, cyber security and compliance policies, standards and procedures to ensure alignment with legal, regulatory, control and sound practice requirements. Maintain an up-to-date understanding of applicable regulatory requirements and help implement changes to comply with new or evolving regulations. Assist in developing and delivering internal training and awareness on IT governance, cyber risk and compliance topics. Reporting & Communication: Support the preparation of cyber risk, control and remediation reporting for management and governance forums. Support the development and tracking of key performance indicators (KPIs) related to IT risk and compliance. Support internal breach notification and escalation processes where required, in coordination with Legal, Data Protection and relevant stakeholders, including supporting regulatory reporting where appropriate. Skills & experience Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or a related field, or equivalent experience. Relevant certifications such as CRISC, CISA, CISM, ISO 27001 or CISSP, or a willingness to undertake similar, are desirable. Minimum of 5 years' experience in IT governance, risk management, cyber or information security, or a related role, with a strong knowledge of related control and compliance requirements. Working knowledge of key technology areas, including infrastructure, applications, networking, cloud services, vulnerability management, incident management and access controls. Experience supporting audit, regulatory or compliance activities, including evidence coordination, issue tracking and remediation follow-up. Experience with SOX compliance and ITGCs is desirable. Experience in insurance or wider financial services, or another regulated environment, is desirable. Excellent communication skills, with the ability to convey technical information to non-technical stakeholders. Other The Fidelis Partnership Ethos At The Fidelis Partnership, we aim to be different while making a difference. We set the standard for quality in our industry. Guided by our expertise, our clients can take unique and material risks with confidence. Our approach is tailored and designed to deliver excellence for our clients. We are trailblazers, creating unique solutions in the (re)insurance space. We are experts. Our brokers and clients value the depth of our knowledge and experience. We leverage state-of-the-art underwriting technology to be a market leader. We believe sound ethics make for good business. We deliver value for our customers, investors and communities while actively avoid trading with industries that cause harm to people, the environment and animals. We pride ourselves in creating a workplace that prizes execution, meritocracy, Diversity & Inclusion. Our people herald from countless backgrounds and are united by ambition and the unabashed desire to deliver excellence every day. We provide a competitive environment that helps people cultivate themselves professionally and personally and balance a rigorous workplace with a mindset that prioritises environmental and charitable activities in our communities worldwide. Our ethos dictates our decisions and actions. It unites us as a team of experts and colleagues and provides us with a compass for ensuring we deliver our best to every stakeholder we serve. Diversity, Equity & Inclusion Diversity & Inclusion in the workplace Insofar as possible, we aim to ensure the composition of our workforce reflects the make-up of the local community We have specific programmes in all our offices to support diversity within the hiring process, e.g. internship and scholarship award programmes This is a particular focus in Bermuda, where we engage actively with local organisations to source diverse talent and provide coaching/mentoring for underrepresented groups We aim to maintain a focus on equal opportunities across all stages of hiring process We measure and minimise the pay gap where possible. Bring Your Whole Self to Work Our vision is for a workplace culture where differences are valued and where diversity of background, experience and thought are welcomed. We want to create an environment where all employees, regardless of who they are, are given equal opportunities for career progression and enjoy fair reward from their and The Fidelis Partnership's successes. This will be driven by a workforce that embraces Diversity & Inclusion at every level, in every department across The Fidelis Partnership. To ensure that all candidates have a fair opportunity to show their abilities during the recruitment process, adjustments may be required. If your physical or mental health or disability may necessitate an adjustment, please contact to discuss. All information relating to your health or disability will be treated in accordance with our data protection policy. The Leader in Bespoke & Specialty insurance
03/08/2026
Full time
Senior IT Cyber Governance, Risk & Compliance Analyst London Contractor On Site About us The Fidelis Partnership is a leading privately-owned, Bermuda-based Managing General Underwriter, which, through its subsidiaries, is a global underwriter of property, bespoke and specialty insurance and reinsurance products. The Fidelis Partnership is one of the largest Managing General Underwriters globally and its operations also include outwards reinsurance, claims handling, exposure management and portfolio analytics. The Fidelis Partnership also sponsors and incubates specialist MGAs through its Pine Walk platform. The Fidelis Partnership is separately owned and managed from the ownership and management of Fidelis Insurance Group. Across product lines and geographies, we focus on three diversified pillars: reinsurance, specialty and bespoke solutions. We are truly diversified. Our long-standing partnerships with capital providers and quota share partners make us nimble. Our breadth of expertise and capabilities deliver outstanding market returns. The role The Senior IT Cyber Governance, Risk & Compliance Analyst will support the development, implementation and oversight of the organisation's IT governance, cyber risk and compliance activities. This role involves supporting IT and cyber risk assessments, compliance with relevant regulatory and control frameworks, audit activity, and the identification and tracking of vulnerabilities, control gaps and remediation actions across IT systems and processes. The Senior IT Cyber Governance, Risk & Compliance Analyst will work closely with internal stakeholders to help ensure that IT and cyber activities are aligned with regulatory expectations, internal policies and good practice. Key accountabilities Compliance and Risk Management: Support compliance with applicable regulatory, IT, cyber and control frameworks, which may include DORA, ISO 27001, NIST CSF, SOX and Cyber Essentials. Support the evaluation and management of IT, cyber, compliance and security risks across systems, processes and operations. Monitor emerging technology, cyber and operational resilience risks to support proactive risk management and timely escalation. Assist in preparing for and supporting regulatory inspections and internal, external and third-party audits. Support the tracking of cyber risk remediation actions, including actions arising from risk assessments, assurance reviews, incidents, audits, control reviews and control improvement initiatives. Support the maintenance of the cyber risk register, including the capture of risks, issues and remediation actions, and the preparation of updates for governance forums. Support third-party and supplier security assurance activities, including security due diligence, assessment of supplier responses and tracking of supplier remediation actions. Coordinate and evidence user access reviews and privileged access reviews with system owners and the business, supporting the move to tool-based access certification. Perform first-line compliance monitoring and control checks against information security policies and standards, including the tracking of policy exceptions. Policy & Procedure Development: Support the development, implementation and updating of IT risk, cyber security and compliance policies, standards and procedures to ensure alignment with legal, regulatory, control and sound practice requirements. Maintain an up-to-date understanding of applicable regulatory requirements and help implement changes to comply with new or evolving regulations. Assist in developing and delivering internal training and awareness on IT governance, cyber risk and compliance topics. Reporting & Communication: Support the preparation of cyber risk, control and remediation reporting for management and governance forums. Support the development and tracking of key performance indicators (KPIs) related to IT risk and compliance. Support internal breach notification and escalation processes where required, in coordination with Legal, Data Protection and relevant stakeholders, including supporting regulatory reporting where appropriate. Skills & experience Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or a related field, or equivalent experience. Relevant certifications such as CRISC, CISA, CISM, ISO 27001 or CISSP, or a willingness to undertake similar, are desirable. Minimum of 5 years' experience in IT governance, risk management, cyber or information security, or a related role, with a strong knowledge of related control and compliance requirements. Working knowledge of key technology areas, including infrastructure, applications, networking, cloud services, vulnerability management, incident management and access controls. Experience supporting audit, regulatory or compliance activities, including evidence coordination, issue tracking and remediation follow-up. Experience with SOX compliance and ITGCs is desirable. Experience in insurance or wider financial services, or another regulated environment, is desirable. Excellent communication skills, with the ability to convey technical information to non-technical stakeholders. Other The Fidelis Partnership Ethos At The Fidelis Partnership, we aim to be different while making a difference. We set the standard for quality in our industry. Guided by our expertise, our clients can take unique and material risks with confidence. Our approach is tailored and designed to deliver excellence for our clients. We are trailblazers, creating unique solutions in the (re)insurance space. We are experts. Our brokers and clients value the depth of our knowledge and experience. We leverage state-of-the-art underwriting technology to be a market leader. We believe sound ethics make for good business. We deliver value for our customers, investors and communities while actively avoid trading with industries that cause harm to people, the environment and animals. We pride ourselves in creating a workplace that prizes execution, meritocracy, Diversity & Inclusion. Our people herald from countless backgrounds and are united by ambition and the unabashed desire to deliver excellence every day. We provide a competitive environment that helps people cultivate themselves professionally and personally and balance a rigorous workplace with a mindset that prioritises environmental and charitable activities in our communities worldwide. Our ethos dictates our decisions and actions. It unites us as a team of experts and colleagues and provides us with a compass for ensuring we deliver our best to every stakeholder we serve. Diversity, Equity & Inclusion Diversity & Inclusion in the workplace Insofar as possible, we aim to ensure the composition of our workforce reflects the make-up of the local community We have specific programmes in all our offices to support diversity within the hiring process, e.g. internship and scholarship award programmes This is a particular focus in Bermuda, where we engage actively with local organisations to source diverse talent and provide coaching/mentoring for underrepresented groups We aim to maintain a focus on equal opportunities across all stages of hiring process We measure and minimise the pay gap where possible. Bring Your Whole Self to Work Our vision is for a workplace culture where differences are valued and where diversity of background, experience and thought are welcomed. We want to create an environment where all employees, regardless of who they are, are given equal opportunities for career progression and enjoy fair reward from their and The Fidelis Partnership's successes. This will be driven by a workforce that embraces Diversity & Inclusion at every level, in every department across The Fidelis Partnership. To ensure that all candidates have a fair opportunity to show their abilities during the recruitment process, adjustments may be required. If your physical or mental health or disability may necessitate an adjustment, please contact to discuss. All information relating to your health or disability will be treated in accordance with our data protection policy. The Leader in Bespoke & Specialty insurance

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board