Acorn Insurance and Financial Services Limited
Liverpool
Due to a period of exciting growth Acorn are looking for a highly skilled and experienced Senior Information Security Analyst to join our Information Security Team. Within this role you get the opportunity to join a collaborative team and have a chance to blend GRC responsibilities with technical security experience, all whilst working for a market leading insurance company, supporting and maintaining robust security controls and regulatory compliance.
Job Title: Senior Information Security Analyst (12 month FTC)
Location: Liverpool City Centre, Hybrid working available
Working Hours: Monday to Friday, 37.5 hours per week , 9:00 AM – 5:30 PM
Salary: £50,000 - £60,000 pa (DOE).
What you will be doing:
Work with all parties across the business to identify and assess risk and ensure mitigations are tracked to completion.
Lead the development and maintenance of information security policies, standards and procedures in line with regulatory frameworks and industry standards.
Lead third party risk management processes.
Collaborate across all areas of the business to align security policies and processes with business objectives and regulatory obligations.
Work with Security Operations and IT teams to provide oversight of vulnerability assessments and remediation activities.
Lead on security architecture reviews for new systems and services.
Evaluate technical security controls and recommending improvements.
Support the implementation of security tools and technologies.
Provide oversight of the security incident management process.
Provide security metrics for interested parties at all levels.
Lead the security awareness programme to promote a culture of security within all levels of the Group.
Provide support for internal and external security audits.
Lead security governance meetings representing the Information Security team and standing in for the Head of Information Security when required.
Provide subject matter expertise liaising across all business functions.
What we look for:
Minimum 5 years' experience in information security roles.
Strong leadership and mentorship abilities with a strategic mindset.
Experience with risk assessment methodologies.
Excellent analytical and problem-solving skills with attention to detail.
Strong communication skills with the ability to explain complex security concepts to non-technical stakeholders.
Ability to manage risk and compliance projects and drive security initiatives.
Knowledge of information security frameworks such as ISO 27001 or NIST.
Knowledge of vulnerability management processes.
About Acorn Insurance With over 40 years of experience, Acorn Insurance is a specialist provider dedicated to helping individuals secure motor insurance across the UK. We proudly serve more than 50,000 customers, ensuring they find policies that meet their needs and provide the peace of mind that comes with high-quality cover.
At Acorn Insurance, we offer comprehensive training and continuous in-house coaching. You'll receive in-depth, FCA-regulated industry knowledge and all the tools necessary to grow your career with us.
We celebrate diversity and are committed to fostering a culture where everyone feels respected and valued. As a Disability Confident Level 1 and Level 2 employer, we ensure our workplace is accessible and inclusive, encouraging our people to bring their best selves to work every day.
The Acorn Group has been recognised as a Great Place to Work for 2024/5. A record number of employees participated in our survey, overwhelmingly highlighting our welcoming and supportive atmosphere as an excellent place to build a career. We are committed to continuous improvement and have ambitious plans for 2025.
Why Acorn Insurance? Acorn Insurance want to give you more than a job, we want to give you a purpose and a career. So, what can we offer you as an employer? Some of the "your tomorrow" benefits you will receive include: Wellbeing:
Enhanced Annual Leave entitlement starting at 31 days and potentially increasing to 35 days per year depending on grade & length of service (including bank holidays)
Enhanced paternity pay and 16 weeks full maternity pay.
Colleague Assistance programme offers a suite of wellbeing services such as:
6 Free Counselling sessions per year
Unlimited access to a telephone councillor 24/7
Access to a free 4-week programme of cognitive behavioural therapy (CBT) with a trained therapist mentor.
Network of internal qualified mental health first aiders are available to provide support to colleagues.
Financial:
A core level of life assurance with the option to increase cover via salary sacrifice and add your spouse/partner
Ability to access your earnings before payday via Dayforce Wallet.
Company pension scheme
Refer a friend scheme with a £250 bonus for every colleague recommended on passing their probation period.
Access to a flexible benefits platform including an annual flex pot allowance to spend on over 15 benefits of your choice.
Ability to give back. You can opt into donating money to charity to climate positive organisations directly from your salary.
Reward, Recognition and Culture :
Long Service Award paid on 5,10- and 15-years’ service
A reward and recognition hub to celebrate and reward colleagues and peers.
Consistent and engaging company events including company awards, competitions and charity fundraisers.
Budgets for department leaders to use for social and engagement events. Please visit out website to view more of our excellent work benefits!
All roles are subject to DBS and Financial checks, any offer made will be conditional until checks are completed to a satisfactory standard. Unfortunately, due to the length of training and complexity of the role, we can only accept applications from candidates who have at least one year remaining on their (Graduate/ Post study work) visa. Unfortunately, we are unable to provide visa sponsorships. At Acorn, we are committed to creating an inclusive and supportive work environment. We recognise that candidates may have specific needs and are happy to consider reasonable adjustments to the recruitment process and working environment to accommodate individual requirements. Whether it’s modifying equipment, adjusting working hours, or providing additional support, we aim to ensure all employees can perform at their best. If you require any reasonable adjustments, please let us know during the application or interview process, and we will work with you to ensure your needs are met.
25/04/2025
Full time
Due to a period of exciting growth Acorn are looking for a highly skilled and experienced Senior Information Security Analyst to join our Information Security Team. Within this role you get the opportunity to join a collaborative team and have a chance to blend GRC responsibilities with technical security experience, all whilst working for a market leading insurance company, supporting and maintaining robust security controls and regulatory compliance.
Job Title: Senior Information Security Analyst (12 month FTC)
Location: Liverpool City Centre, Hybrid working available
Working Hours: Monday to Friday, 37.5 hours per week , 9:00 AM – 5:30 PM
Salary: £50,000 - £60,000 pa (DOE).
What you will be doing:
Work with all parties across the business to identify and assess risk and ensure mitigations are tracked to completion.
Lead the development and maintenance of information security policies, standards and procedures in line with regulatory frameworks and industry standards.
Lead third party risk management processes.
Collaborate across all areas of the business to align security policies and processes with business objectives and regulatory obligations.
Work with Security Operations and IT teams to provide oversight of vulnerability assessments and remediation activities.
Lead on security architecture reviews for new systems and services.
Evaluate technical security controls and recommending improvements.
Support the implementation of security tools and technologies.
Provide oversight of the security incident management process.
Provide security metrics for interested parties at all levels.
Lead the security awareness programme to promote a culture of security within all levels of the Group.
Provide support for internal and external security audits.
Lead security governance meetings representing the Information Security team and standing in for the Head of Information Security when required.
Provide subject matter expertise liaising across all business functions.
What we look for:
Minimum 5 years' experience in information security roles.
Strong leadership and mentorship abilities with a strategic mindset.
Experience with risk assessment methodologies.
Excellent analytical and problem-solving skills with attention to detail.
Strong communication skills with the ability to explain complex security concepts to non-technical stakeholders.
Ability to manage risk and compliance projects and drive security initiatives.
Knowledge of information security frameworks such as ISO 27001 or NIST.
Knowledge of vulnerability management processes.
About Acorn Insurance With over 40 years of experience, Acorn Insurance is a specialist provider dedicated to helping individuals secure motor insurance across the UK. We proudly serve more than 50,000 customers, ensuring they find policies that meet their needs and provide the peace of mind that comes with high-quality cover.
At Acorn Insurance, we offer comprehensive training and continuous in-house coaching. You'll receive in-depth, FCA-regulated industry knowledge and all the tools necessary to grow your career with us.
We celebrate diversity and are committed to fostering a culture where everyone feels respected and valued. As a Disability Confident Level 1 and Level 2 employer, we ensure our workplace is accessible and inclusive, encouraging our people to bring their best selves to work every day.
The Acorn Group has been recognised as a Great Place to Work for 2024/5. A record number of employees participated in our survey, overwhelmingly highlighting our welcoming and supportive atmosphere as an excellent place to build a career. We are committed to continuous improvement and have ambitious plans for 2025.
Why Acorn Insurance? Acorn Insurance want to give you more than a job, we want to give you a purpose and a career. So, what can we offer you as an employer? Some of the "your tomorrow" benefits you will receive include: Wellbeing:
Enhanced Annual Leave entitlement starting at 31 days and potentially increasing to 35 days per year depending on grade & length of service (including bank holidays)
Enhanced paternity pay and 16 weeks full maternity pay.
Colleague Assistance programme offers a suite of wellbeing services such as:
6 Free Counselling sessions per year
Unlimited access to a telephone councillor 24/7
Access to a free 4-week programme of cognitive behavioural therapy (CBT) with a trained therapist mentor.
Network of internal qualified mental health first aiders are available to provide support to colleagues.
Financial:
A core level of life assurance with the option to increase cover via salary sacrifice and add your spouse/partner
Ability to access your earnings before payday via Dayforce Wallet.
Company pension scheme
Refer a friend scheme with a £250 bonus for every colleague recommended on passing their probation period.
Access to a flexible benefits platform including an annual flex pot allowance to spend on over 15 benefits of your choice.
Ability to give back. You can opt into donating money to charity to climate positive organisations directly from your salary.
Reward, Recognition and Culture :
Long Service Award paid on 5,10- and 15-years’ service
A reward and recognition hub to celebrate and reward colleagues and peers.
Consistent and engaging company events including company awards, competitions and charity fundraisers.
Budgets for department leaders to use for social and engagement events. Please visit out website to view more of our excellent work benefits!
All roles are subject to DBS and Financial checks, any offer made will be conditional until checks are completed to a satisfactory standard. Unfortunately, due to the length of training and complexity of the role, we can only accept applications from candidates who have at least one year remaining on their (Graduate/ Post study work) visa. Unfortunately, we are unable to provide visa sponsorships. At Acorn, we are committed to creating an inclusive and supportive work environment. We recognise that candidates may have specific needs and are happy to consider reasonable adjustments to the recruitment process and working environment to accommodate individual requirements. Whether it’s modifying equipment, adjusting working hours, or providing additional support, we aim to ensure all employees can perform at their best. If you require any reasonable adjustments, please let us know during the application or interview process, and we will work with you to ensure your needs are met.
Purpose of the Job: Design, build, and maintain robust data systems and pipelines that support data storage, processing, and analysis on the Cloud. Work with large datasets, ensuring data quality, scalability, and performance, while collaborating. closely with data scientists, analysts, and other engineering teams to understand their data needs and provide them with high-quality, accessible data. They are responsible for ensuring that the underlying data infrastructure supports the organizations broader data and business goals, enabling more effective data-driven decision-making. Key Accountabilities: Design and implement scalable, efficient, and secure data architectures, ensuring optimal data flow across systems in order to achieve high service levels of support, maintenance and development You will own development and change projects to ensure requirements are met in the most cost-effective manner while minimising associated risk to expected standards. Responsibly for cloud data platform development, data modelling, shaping and technical planning You will be a mentor among the owning decision making and evaluation of requirement suitability, facilitate reliable estimates, technical project management, stakeholder management with a project Ensure that resource requirements are understood and planned/estimated effectively against demand, including identification of additional temporary resource capability within projects Maintain appropriate process procedures, compliance and service level monitoring, performance reporting and vendor management. Implementing best practices around data security, privacy, and compliance for the teams compliance with cyber security and data protection and supporting along with BI lead Strong stakeholder management will be required for maintaining relationships with our business users to clarify and influence requirements. Including liaising with internal business departments and functions to manage the service level expected from the data team. Collaborating with external organisations and third-party software/service suppliers for ongoing support, maintenance and development of systems. You will be able to demonstrate you are quality focused to ensure that they solutions are built to an appropriate standard whilst being balanced with a drive to deliver against tight deadlines. Support in developing and implementing best practices and process across the team along with BI lead. Influence the evolution of business and system requirements and contribute to the design of technical solutions to feed a delivery pipeline that increasingly employs Agile methods such as SCRUM and Kanban You will be required to develop unit tested code and then support test cycles including post implementation validation. You will be required to contribute to the transition into service and ongoing support of the applications in the area which provides the opportunity to reduce technical debt and rationalise our technical footprint Mentor data engineers, supporting their professional growth and development Outcome, Results and Key Performance Indicators: Delivery of projects to expected timely, cost and quality standards Excellent levels of application availability and resilience as required by business operations. Necessary governance and control requirements defined - design, code and test standards and guidelines. Ensure data systems comply with necessary governance and control requirements. Internally-developed data solutions are fit for purpose and fit correctly within the data architecture. Built and tested to user requirements, performing to defined performance and capacity requirements. Company data is secure, accurate, maintained and available according to requirements. Technical risks and issues correctly mitigated and managed on Projects and Production support. High quality software delivered in to production - zero critical and high defects before production release. Dimensions of Job: This role is part of a well-established data team, the role offers a great opportunity for the right candidate to hone their modern data management skills in a friendly and supportive environment. This role requires attendance to a Leeds based office as often as needed with a minimum 2 days a week. Able to work effectively as part of a remote team. A great opportunity for a motivated data engineer seeking a new opportunity with a friendly, newly formed data team and able to contribute to the team's growth with their technical expertise Key Relationships: Internal: Wider technical teams (including apps, test, dev ops and more), Project managers, business SME's, data teams and communities , Data scientists, BI Lead, Head of Data External: software & service suppliers, consultants. Knowledge and Skills: Knowledge - Broad data management technical knowledge so as to be able to work across full data cycle. - Proven Experience working with AWS data technologies (S3, Redshift, Glue, Lambda, Lake formation, Cloud Formation), GitHub, CI/CD - Coding experience in Apache Spark, Iceberg or Python (Pandas) - Experience in change and release management. - Experience in Database Warehouse design and data modelling - Experience managing Data Migration projects. - Cloud data platform development and deployment. - Experience of performance tuning in a variery of database settings. - Experience of Infrastructure as code practises. - Proven ability to organise and produce work within deadlines. Skills - Good project and people management skills. - Excellent data development skills. - Excellent data manipulation and analysis skills using a variety of tools including SQL, Phyton, AWS services and the MSBI stack. - Ability to prioritise and be flexible to change those priorities at short notice. - Commercial acumen. - Able to demonstrate a practical approach to problem solving. - Able to provide appropriate and understandable data to a wide ranging audience. - Well-developed and professional communication skills. - Strong analytical skills - ability to create models and analyse data in order to solve complex problems or reinforce commercial decisions. - Able to understand business processes and how this is achieved/influenced by technology. - Must be able to work as part of a collaborative team to solve problems and assist other colleagues. - Ability to learn new technologies, programs and procedures. Technical Essentials: - Expertise across data warehouse and ETL/ ELT development in AWS preferred with experience in the following: - Strong experience in some of the AWS services like Redshift, Lambda,S3,Step Functions, Batch, Cloud formation, Lake Formation, Code Build, CI/CD, GitHub, IAM, SQS, SNS, Aurora DB - Good experience with DBT, Apache Iceberg, Docker, Microsoft BI stack (nice to have) - Experience in data warehouse design (Kimball and lake house, medallion and data vault) is a definite preference as is knowledge of other data tools and programming languages such as Python & Spark and Strong SQL experience. - Experience is building Data lake and building CI/CD data pipelines - A candidate is expected to understand and can demonstrate experience across the delivery lifecycle and understand both Agile and Waterfall methods and when to apply these. Experience: This position requires several years of practical experience in a similar environment. We require a good balance of technical and personal/softer skills so successful candidates can be fully effective immediately. - Proven experience in developing, delivering and maintaining tactical and enterprise data management solutions. - Proven experience in delivering data solutions using cloud platform tools. - Proven experience in assessing the impact of proposed changes on production solutions. - Proven experience in managing and developing a team of technical experts to deliver business outcomes and meet performance criteria. - Exposure to Energy markets, Energy Supply industry sector - Developing and implementing operational processes and procedures.
24/10/2025
Full time
Purpose of the Job: Design, build, and maintain robust data systems and pipelines that support data storage, processing, and analysis on the Cloud. Work with large datasets, ensuring data quality, scalability, and performance, while collaborating. closely with data scientists, analysts, and other engineering teams to understand their data needs and provide them with high-quality, accessible data. They are responsible for ensuring that the underlying data infrastructure supports the organizations broader data and business goals, enabling more effective data-driven decision-making. Key Accountabilities: Design and implement scalable, efficient, and secure data architectures, ensuring optimal data flow across systems in order to achieve high service levels of support, maintenance and development You will own development and change projects to ensure requirements are met in the most cost-effective manner while minimising associated risk to expected standards. Responsibly for cloud data platform development, data modelling, shaping and technical planning You will be a mentor among the owning decision making and evaluation of requirement suitability, facilitate reliable estimates, technical project management, stakeholder management with a project Ensure that resource requirements are understood and planned/estimated effectively against demand, including identification of additional temporary resource capability within projects Maintain appropriate process procedures, compliance and service level monitoring, performance reporting and vendor management. Implementing best practices around data security, privacy, and compliance for the teams compliance with cyber security and data protection and supporting along with BI lead Strong stakeholder management will be required for maintaining relationships with our business users to clarify and influence requirements. Including liaising with internal business departments and functions to manage the service level expected from the data team. Collaborating with external organisations and third-party software/service suppliers for ongoing support, maintenance and development of systems. You will be able to demonstrate you are quality focused to ensure that they solutions are built to an appropriate standard whilst being balanced with a drive to deliver against tight deadlines. Support in developing and implementing best practices and process across the team along with BI lead. Influence the evolution of business and system requirements and contribute to the design of technical solutions to feed a delivery pipeline that increasingly employs Agile methods such as SCRUM and Kanban You will be required to develop unit tested code and then support test cycles including post implementation validation. You will be required to contribute to the transition into service and ongoing support of the applications in the area which provides the opportunity to reduce technical debt and rationalise our technical footprint Mentor data engineers, supporting their professional growth and development Outcome, Results and Key Performance Indicators: Delivery of projects to expected timely, cost and quality standards Excellent levels of application availability and resilience as required by business operations. Necessary governance and control requirements defined - design, code and test standards and guidelines. Ensure data systems comply with necessary governance and control requirements. Internally-developed data solutions are fit for purpose and fit correctly within the data architecture. Built and tested to user requirements, performing to defined performance and capacity requirements. Company data is secure, accurate, maintained and available according to requirements. Technical risks and issues correctly mitigated and managed on Projects and Production support. High quality software delivered in to production - zero critical and high defects before production release. Dimensions of Job: This role is part of a well-established data team, the role offers a great opportunity for the right candidate to hone their modern data management skills in a friendly and supportive environment. This role requires attendance to a Leeds based office as often as needed with a minimum 2 days a week. Able to work effectively as part of a remote team. A great opportunity for a motivated data engineer seeking a new opportunity with a friendly, newly formed data team and able to contribute to the team's growth with their technical expertise Key Relationships: Internal: Wider technical teams (including apps, test, dev ops and more), Project managers, business SME's, data teams and communities , Data scientists, BI Lead, Head of Data External: software & service suppliers, consultants. Knowledge and Skills: Knowledge - Broad data management technical knowledge so as to be able to work across full data cycle. - Proven Experience working with AWS data technologies (S3, Redshift, Glue, Lambda, Lake formation, Cloud Formation), GitHub, CI/CD - Coding experience in Apache Spark, Iceberg or Python (Pandas) - Experience in change and release management. - Experience in Database Warehouse design and data modelling - Experience managing Data Migration projects. - Cloud data platform development and deployment. - Experience of performance tuning in a variery of database settings. - Experience of Infrastructure as code practises. - Proven ability to organise and produce work within deadlines. Skills - Good project and people management skills. - Excellent data development skills. - Excellent data manipulation and analysis skills using a variety of tools including SQL, Phyton, AWS services and the MSBI stack. - Ability to prioritise and be flexible to change those priorities at short notice. - Commercial acumen. - Able to demonstrate a practical approach to problem solving. - Able to provide appropriate and understandable data to a wide ranging audience. - Well-developed and professional communication skills. - Strong analytical skills - ability to create models and analyse data in order to solve complex problems or reinforce commercial decisions. - Able to understand business processes and how this is achieved/influenced by technology. - Must be able to work as part of a collaborative team to solve problems and assist other colleagues. - Ability to learn new technologies, programs and procedures. Technical Essentials: - Expertise across data warehouse and ETL/ ELT development in AWS preferred with experience in the following: - Strong experience in some of the AWS services like Redshift, Lambda,S3,Step Functions, Batch, Cloud formation, Lake Formation, Code Build, CI/CD, GitHub, IAM, SQS, SNS, Aurora DB - Good experience with DBT, Apache Iceberg, Docker, Microsoft BI stack (nice to have) - Experience in data warehouse design (Kimball and lake house, medallion and data vault) is a definite preference as is knowledge of other data tools and programming languages such as Python & Spark and Strong SQL experience. - Experience is building Data lake and building CI/CD data pipelines - A candidate is expected to understand and can demonstrate experience across the delivery lifecycle and understand both Agile and Waterfall methods and when to apply these. Experience: This position requires several years of practical experience in a similar environment. We require a good balance of technical and personal/softer skills so successful candidates can be fully effective immediately. - Proven experience in developing, delivering and maintaining tactical and enterprise data management solutions. - Proven experience in delivering data solutions using cloud platform tools. - Proven experience in assessing the impact of proposed changes on production solutions. - Proven experience in managing and developing a team of technical experts to deliver business outcomes and meet performance criteria. - Exposure to Energy markets, Energy Supply industry sector - Developing and implementing operational processes and procedures.
IT Project Manager Feltham (Hybrid Working) £45,000 - £50,000 Base + Benefits The IT Project Manager is responsible for planning, executing, and delivering technology projects that align with business goals and strategic priorities. This role ensures projects are completed on time, within budget, and meet defined objectives. The IT Project Manager works closely with cross functional teams-including software developers, network engineers, cybersecurity specialists, and business stakeholders-to ensure seamless project delivery. Key Responsibilities Project Planning & Execution Define project scope, goals, and deliverables that support business objectives. Develop detailed project plans, schedules, and budgets, including resource allocation and risk management. Manage all phases of the project lifecycle-initiation, planning, execution, monitoring, and closure. Track progress, manage dependencies, and ensure timely delivery of milestones. Collaborate with IT teams to ensure infrastructure, applications, and security requirements are properly integrated. Oversee software development, system implementations, cloud migrations, or IT infrastructure upgrades. Coordinate vendor relationships and third-party integrations when applicable. Serve as the key liaison between technical teams, business leaders, and end-users. Communicate project status, risks, and issues through detailed reports and executive updates. Facilitate meetings, sprint reviews, and retrospectives in Agile environments. Identify and mitigate project risks and issues proactively. Ensure deliverables meet quality assurance standards and align with IT governance frameworks. Maintain compliance with internal IT policies, data protection laws, and cybersecurity standards. Leadership & Team Management Lead and motivate project teams across technical disciplines. Support Agile and DevOps principles to foster collaboration and continuous improvement. Mentor junior project coordinators or business analysts when needed. Qualifications Education: Bachelor's degree in Computer Science, Information Technology, or a related discipline.• Experience: 3+ years of experience managing IT projects, including software development, system integration, or infrastructure projects. • Certifications: PMP, PRINCE2, Agile (CSM, PMI-ACP), or ITIL certifications preferred. Skills & Competencies Required Strong understanding of IT systems, cloud technologies, and software development life cycles (SDLC). Proficiency in project management tools such as Jira, Confluence, MS Project, or Asana. Experience with Agile, Scrum, or hybrid delivery methodologies. Excellent communication, stakeholder management, and problem-solving skills. Ability to balance technical depth with business understanding
23/10/2025
Full time
IT Project Manager Feltham (Hybrid Working) £45,000 - £50,000 Base + Benefits The IT Project Manager is responsible for planning, executing, and delivering technology projects that align with business goals and strategic priorities. This role ensures projects are completed on time, within budget, and meet defined objectives. The IT Project Manager works closely with cross functional teams-including software developers, network engineers, cybersecurity specialists, and business stakeholders-to ensure seamless project delivery. Key Responsibilities Project Planning & Execution Define project scope, goals, and deliverables that support business objectives. Develop detailed project plans, schedules, and budgets, including resource allocation and risk management. Manage all phases of the project lifecycle-initiation, planning, execution, monitoring, and closure. Track progress, manage dependencies, and ensure timely delivery of milestones. Collaborate with IT teams to ensure infrastructure, applications, and security requirements are properly integrated. Oversee software development, system implementations, cloud migrations, or IT infrastructure upgrades. Coordinate vendor relationships and third-party integrations when applicable. Serve as the key liaison between technical teams, business leaders, and end-users. Communicate project status, risks, and issues through detailed reports and executive updates. Facilitate meetings, sprint reviews, and retrospectives in Agile environments. Identify and mitigate project risks and issues proactively. Ensure deliverables meet quality assurance standards and align with IT governance frameworks. Maintain compliance with internal IT policies, data protection laws, and cybersecurity standards. Leadership & Team Management Lead and motivate project teams across technical disciplines. Support Agile and DevOps principles to foster collaboration and continuous improvement. Mentor junior project coordinators or business analysts when needed. Qualifications Education: Bachelor's degree in Computer Science, Information Technology, or a related discipline.• Experience: 3+ years of experience managing IT projects, including software development, system integration, or infrastructure projects. • Certifications: PMP, PRINCE2, Agile (CSM, PMI-ACP), or ITIL certifications preferred. Skills & Competencies Required Strong understanding of IT systems, cloud technologies, and software development life cycles (SDLC). Proficiency in project management tools such as Jira, Confluence, MS Project, or Asana. Experience with Agile, Scrum, or hybrid delivery methodologies. Excellent communication, stakeholder management, and problem-solving skills. Ability to balance technical depth with business understanding
Role Overview We are working with a Charity who are seeking a proactive and detail-oriented Cyber Security Analyst to support the ongoing protection of their digital assets, systems, and data. This home-based role will be instrumental in monitoring threats, identifying risk, assessing vulnerabilities, and improving their security posture across the organisation. You'll work closely with the IT Security Manager, wider IT team, and third-party partners to ensure security best practices are maintained across their cloud and on-premise environments. Key Responsibilities Conduct threat and vulnerability assessments and recommend remediation steps Support the investigation of security incidents and policy violations Assist with risk assessments and security audits Implement and maintain security standards, and guidelines Work with third-party vendors and partners on pen testing and remediation activities Support awareness campaigns to improve cybersecurity hygiene among staff Assist in the development and implementation of disaster recovery and business continuity plans. Produce reports and metrics for senior IT and governance stakeholders Stay updated with the latest threats, trends, and compliance requirements (e.g., GDPR, PCI DSS, Cyber Essentials) Person Specification Essential: Demonstrable experience in a related role Excellent problem-solving, analytical, and communication skills An appetite for keeping up to date with the latest developments in technology, business practices, and the wider threat environment Ability to work independently and remotely with minimal supervision Understanding of current threats, attack vectors, and security frameworks Familiarity with Microsoft 365 security tools (Defender, Purview, Entra, etc.) Working knowledge of network protocols, email security, and IT architectures Right to work in the UK Desirable: Industry certifications (e.g., CompTIA Security+, SSCP) Experience in the charity or non-profit sector Familiarity with Microsoft Azure cloud platforms and identity management Experience with compliance frameworks (PCI DSS, Cyber Essentials) Experience with auditing and compliance Experience of BCP/DR
23/10/2025
Full time
Role Overview We are working with a Charity who are seeking a proactive and detail-oriented Cyber Security Analyst to support the ongoing protection of their digital assets, systems, and data. This home-based role will be instrumental in monitoring threats, identifying risk, assessing vulnerabilities, and improving their security posture across the organisation. You'll work closely with the IT Security Manager, wider IT team, and third-party partners to ensure security best practices are maintained across their cloud and on-premise environments. Key Responsibilities Conduct threat and vulnerability assessments and recommend remediation steps Support the investigation of security incidents and policy violations Assist with risk assessments and security audits Implement and maintain security standards, and guidelines Work with third-party vendors and partners on pen testing and remediation activities Support awareness campaigns to improve cybersecurity hygiene among staff Assist in the development and implementation of disaster recovery and business continuity plans. Produce reports and metrics for senior IT and governance stakeholders Stay updated with the latest threats, trends, and compliance requirements (e.g., GDPR, PCI DSS, Cyber Essentials) Person Specification Essential: Demonstrable experience in a related role Excellent problem-solving, analytical, and communication skills An appetite for keeping up to date with the latest developments in technology, business practices, and the wider threat environment Ability to work independently and remotely with minimal supervision Understanding of current threats, attack vectors, and security frameworks Familiarity with Microsoft 365 security tools (Defender, Purview, Entra, etc.) Working knowledge of network protocols, email security, and IT architectures Right to work in the UK Desirable: Industry certifications (e.g., CompTIA Security+, SSCP) Experience in the charity or non-profit sector Familiarity with Microsoft Azure cloud platforms and identity management Experience with compliance frameworks (PCI DSS, Cyber Essentials) Experience with auditing and compliance Experience of BCP/DR
Cyber Security Lead Oxfordshire - Hybrid - 2 days per week (Flexible) 50k - 60k plus Benefits Our Client are an award-winning leading IT company offering complete outsourced IT solutions to organisations across the UK and Europe. Based in Oxfordshire they provide a comprehensive range of support services, software and hardware solutions to major blue-chip clients and their technicians are highly skilled in planning, implementing and trouble shooting. They strive to become one of the top places to work in the UK - in fact, they believe that they already are! Most of the team have been here for years, have built a terrific career, and as corny as it may sound, they really do call themselves the Planet Family. They welcome new people to the team all the time, from all backgrounds and all levels of experience. They are able to attract talent to our business by investing in staff training and staff rewards, which has become a bedrock of our success. This initiative has resulted in staff becoming even better at what they do, great staff retention and greater company buy-in from the team. As part of this strategy, the more staff learn via official courses, the better the service and the more we reward them. Primary Purpose The Security Lead is both the client-facing strategist and the internal accountable owner of security within the MSP. They lead Quarterly Security Reviews (QSRs), own the client risk register and exception process, and ensure services are delivered in line with frameworks such as Cyber Essentials, ISO27001, and NIST. Internally, the Security Lead is accountable for the MSP's own security posture ensuring tools, processes, and teams meet the same standards we deliver to clients. They monitor measurable posture metrics (e.g., Microsoft Secure Score, Vulnerability etc.), ensure continuous improvement, and keep the MSP's security practice relevant through ongoing training, certifications, and emerging threat awareness. While day-to-day execution is delegated to Security Analysts and service teams, the Security Lead owns security end-to-end: identifying risks, embedding controls, and ensuring compliance is demonstrable. Key Responsibilities Client-Facing Lead Quarterly Security Reviews (QSRs), presenting patch/vulnerability posture, incidents, compliance status, and risk register updates. Translate technical security risks into clear business impact and outcomes. Own the client exception process, ensuring risks are documented, communicated, and signed off. Support Account Managers and Strategic Partnership Managers in roadmap and IT strategy sessions. Act as the strategic security escalation point for clients when risks require senior involvement. Internal MSP Security Own the MSP's internal security frameworks and certifications (e.g., CE+, ISO, SOC 2). Oversee patching, vulnerability, and risk management of MSP-owned infrastructure and tools. Ensure MSP's technology stack (RMM, XDR, PSA, backup, etc.) is securely deployed and monitored. Drive staff security awareness, training, and compliance with secure processes. Delegate operational tasks to Security Analysts while retaining accountability for end-to-end outcomes. Governance & Standards Maintain the client and internal risk registers. Define and evolve gold-standard security "whitepapers" for projects and BAU. Sign off security requirements for project scope/designs that impact compliance or frameworks. Collaborate with Service Delivery Manager and Project Delivery Manager to ensure security is embedded in BAU, change control, and project execution. Monitor and report on client posture metrics (e.g., Microsoft Secure Score, M365 compliance dashboards). Drive continuous posture improvement across client environments. Team Leadership & Growth Mentor and develop Security Analysts. Ensure team certifications remain up to date (minimum 2 per year per Analyst). Lead internal knowledge-sharing sessions to keep the team and wider MSP relevant against new threats and frameworks. Champion automation (RPA/AI) in evidence gathering, reporting, and triage. Identify scale points for growing the Security Practice (e.g., Security Architect, more Analysts). Behaviors Required Strategic Thinking - able to translate technical risks into business outcomes and align security initiatives with client goals and budgets. Strong Governance Mindset - experienced in managing frameworks (Cyber Essentials, ISO27001, NIST) and embedding them into MSP operations and client environments. Risk Communication - skilled at presenting complex security issues clearly to non-technical stakeholders, both internally and at client leadership level. Technical Depth - hands-on understanding of vulnerability management, patch governance, endpoint security (EDR/XDR), and cloud (M365/Azure security). Analytical Skills - capable of interpreting scan results, posture metrics (e.g., Microsoft Secure Score), and incident trends into actionable insights. Delegation & Leadership - experienced in mentoring Analysts and delegating effectively while retaining accountability for outcomes. Collaboration - able to work cross-functionally with Service Delivery, Projects, Account Managers, and vendors to embed security consistently. Continuous Learning - committed to staying current with evolving threats, frameworks, and technologies, and ensuring the team is trained and certified. Client-Facing Confidence - comfortable leading Quarterly Security Reviews (QSRs), participating in roadmap sessions, and engaging with C-level stakeholders. Change Agent - able to influence internal teams and clients to adopt best practice, even when it means shifting established ways of working. Person Specification: Minimum 5+ years in IT security or MSP environment. Strong knowledge of Cyber Essentials, ISO27001, or NIST frameworks. Experience with patch/vulnerability management governance. Ability to communicate technical risks in business language. Proven ability to run client-facing reviews or presentations. Desirable CISSP, CISM, or equivalent certifications. Experience delivering or auditing compliance frameworks. Familiarity with RMM/XDR/EDR, SIEM, and vulnerability scanning platforms. Experience leading small teams (mentoring, guiding). Exposure to incident response and tabletop exercises. What Success Looks Like: Success means the Security Lead is recognised by clients as a trusted advisor who simplifies security into business language. All client and internal risks are captured, visible, and acted upon with no blind spots. QSRs consistently deliver actionable improvements that feed into roadmaps and IT strategy, while client security posture measurably improves quarter-on-quarter (demonstrated in metrics such as Microsoft Secure Score, CE+ readiness, and vulnerability closure rates). Internally, the MSP leads by example: our own systems, tools, and processes are secure, audit-ready, and improving over time. The Security Lead ensures their team is certified, trained, and ahead of industry changes, delegating operational execution while embedding governance across service, INDIT Planet Recruitment acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers. Planet Recruitment is an Equal Opportunities Employer. By applying for this role your details will be submitted to Planet Recruitment. Our Candidate Privacy Information Statement explains how we will use your information. Only candidates with the relevant skills and experience will be contacted after application, if you do not hear back from us within 7 days you have unfortunately been unsuccessful in your application. Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and abilities to perform the duties of the position.
23/10/2025
Full time
Cyber Security Lead Oxfordshire - Hybrid - 2 days per week (Flexible) 50k - 60k plus Benefits Our Client are an award-winning leading IT company offering complete outsourced IT solutions to organisations across the UK and Europe. Based in Oxfordshire they provide a comprehensive range of support services, software and hardware solutions to major blue-chip clients and their technicians are highly skilled in planning, implementing and trouble shooting. They strive to become one of the top places to work in the UK - in fact, they believe that they already are! Most of the team have been here for years, have built a terrific career, and as corny as it may sound, they really do call themselves the Planet Family. They welcome new people to the team all the time, from all backgrounds and all levels of experience. They are able to attract talent to our business by investing in staff training and staff rewards, which has become a bedrock of our success. This initiative has resulted in staff becoming even better at what they do, great staff retention and greater company buy-in from the team. As part of this strategy, the more staff learn via official courses, the better the service and the more we reward them. Primary Purpose The Security Lead is both the client-facing strategist and the internal accountable owner of security within the MSP. They lead Quarterly Security Reviews (QSRs), own the client risk register and exception process, and ensure services are delivered in line with frameworks such as Cyber Essentials, ISO27001, and NIST. Internally, the Security Lead is accountable for the MSP's own security posture ensuring tools, processes, and teams meet the same standards we deliver to clients. They monitor measurable posture metrics (e.g., Microsoft Secure Score, Vulnerability etc.), ensure continuous improvement, and keep the MSP's security practice relevant through ongoing training, certifications, and emerging threat awareness. While day-to-day execution is delegated to Security Analysts and service teams, the Security Lead owns security end-to-end: identifying risks, embedding controls, and ensuring compliance is demonstrable. Key Responsibilities Client-Facing Lead Quarterly Security Reviews (QSRs), presenting patch/vulnerability posture, incidents, compliance status, and risk register updates. Translate technical security risks into clear business impact and outcomes. Own the client exception process, ensuring risks are documented, communicated, and signed off. Support Account Managers and Strategic Partnership Managers in roadmap and IT strategy sessions. Act as the strategic security escalation point for clients when risks require senior involvement. Internal MSP Security Own the MSP's internal security frameworks and certifications (e.g., CE+, ISO, SOC 2). Oversee patching, vulnerability, and risk management of MSP-owned infrastructure and tools. Ensure MSP's technology stack (RMM, XDR, PSA, backup, etc.) is securely deployed and monitored. Drive staff security awareness, training, and compliance with secure processes. Delegate operational tasks to Security Analysts while retaining accountability for end-to-end outcomes. Governance & Standards Maintain the client and internal risk registers. Define and evolve gold-standard security "whitepapers" for projects and BAU. Sign off security requirements for project scope/designs that impact compliance or frameworks. Collaborate with Service Delivery Manager and Project Delivery Manager to ensure security is embedded in BAU, change control, and project execution. Monitor and report on client posture metrics (e.g., Microsoft Secure Score, M365 compliance dashboards). Drive continuous posture improvement across client environments. Team Leadership & Growth Mentor and develop Security Analysts. Ensure team certifications remain up to date (minimum 2 per year per Analyst). Lead internal knowledge-sharing sessions to keep the team and wider MSP relevant against new threats and frameworks. Champion automation (RPA/AI) in evidence gathering, reporting, and triage. Identify scale points for growing the Security Practice (e.g., Security Architect, more Analysts). Behaviors Required Strategic Thinking - able to translate technical risks into business outcomes and align security initiatives with client goals and budgets. Strong Governance Mindset - experienced in managing frameworks (Cyber Essentials, ISO27001, NIST) and embedding them into MSP operations and client environments. Risk Communication - skilled at presenting complex security issues clearly to non-technical stakeholders, both internally and at client leadership level. Technical Depth - hands-on understanding of vulnerability management, patch governance, endpoint security (EDR/XDR), and cloud (M365/Azure security). Analytical Skills - capable of interpreting scan results, posture metrics (e.g., Microsoft Secure Score), and incident trends into actionable insights. Delegation & Leadership - experienced in mentoring Analysts and delegating effectively while retaining accountability for outcomes. Collaboration - able to work cross-functionally with Service Delivery, Projects, Account Managers, and vendors to embed security consistently. Continuous Learning - committed to staying current with evolving threats, frameworks, and technologies, and ensuring the team is trained and certified. Client-Facing Confidence - comfortable leading Quarterly Security Reviews (QSRs), participating in roadmap sessions, and engaging with C-level stakeholders. Change Agent - able to influence internal teams and clients to adopt best practice, even when it means shifting established ways of working. Person Specification: Minimum 5+ years in IT security or MSP environment. Strong knowledge of Cyber Essentials, ISO27001, or NIST frameworks. Experience with patch/vulnerability management governance. Ability to communicate technical risks in business language. Proven ability to run client-facing reviews or presentations. Desirable CISSP, CISM, or equivalent certifications. Experience delivering or auditing compliance frameworks. Familiarity with RMM/XDR/EDR, SIEM, and vulnerability scanning platforms. Experience leading small teams (mentoring, guiding). Exposure to incident response and tabletop exercises. What Success Looks Like: Success means the Security Lead is recognised by clients as a trusted advisor who simplifies security into business language. All client and internal risks are captured, visible, and acted upon with no blind spots. QSRs consistently deliver actionable improvements that feed into roadmaps and IT strategy, while client security posture measurably improves quarter-on-quarter (demonstrated in metrics such as Microsoft Secure Score, CE+ readiness, and vulnerability closure rates). Internally, the MSP leads by example: our own systems, tools, and processes are secure, audit-ready, and improving over time. The Security Lead ensures their team is certified, trained, and ahead of industry changes, delegating operational execution while embedding governance across service, INDIT Planet Recruitment acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers. Planet Recruitment is an Equal Opportunities Employer. By applying for this role your details will be submitted to Planet Recruitment. Our Candidate Privacy Information Statement explains how we will use your information. Only candidates with the relevant skills and experience will be contacted after application, if you do not hear back from us within 7 days you have unfortunately been unsuccessful in your application. Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and abilities to perform the duties of the position.
Role Overview We are working with a Charity who are seeking a proactive and detail-oriented Cyber Security Analyst to support the ongoing protection of their digital assets, systems, and data.This home-based role will be instrumental in monitoring threats, identifying risk, assessing vulnerabilities, and improving their security posture across the organisation.You'll work closely with the IT Security Manager, wider IT team, and third-party partners to ensure security best practices are maintained across their cloud and on-premise environments. Key Responsibilities Conduct threat and vulnerability assessments and recommend remediation steps Support the investigation of security incidents and policy violations Assist with risk assessments and security audits Implement and maintain security standards, and guidelines Work with third-party vendors and partners on pen testing and remediation activities Support awareness campaigns to improve cybersecurity hygiene among staff Assist in the development and implementation of disaster recovery and business continuity plans. Produce reports and metrics for senior IT and governance stakeholders Stay updated with the latest threats, trends, and compliance requirements (e.g., GDPR, PCI DSS, Cyber Essentials) Person Specification Essential: Demonstrable experience in a related role Excellent problem-solving, analytical, and communication skills An appetite for keeping up to date with the latest developments in technology, business practices, and the wider threat environment Ability to work independently and remotely with minimal supervision Understanding of current threats, attack vectors, and security frameworks Familiarity with Microsoft 365 security tools (Defender, Purview, Entra, etc.) Working knowledge of network protocols, email security, and IT architectures Right to work in the UK Desirable: Industry certifications (e.g., CompTIA Security+, SSCP) Experience in the charity or non-profit sector Familiarity with Microsoft Azure cloud platforms and identity management Experience with compliance frameworks (PCI DSS, Cyber Essentials) Experience with auditing and compliance Experience of BCP/DR
23/10/2025
Full time
Role Overview We are working with a Charity who are seeking a proactive and detail-oriented Cyber Security Analyst to support the ongoing protection of their digital assets, systems, and data.This home-based role will be instrumental in monitoring threats, identifying risk, assessing vulnerabilities, and improving their security posture across the organisation.You'll work closely with the IT Security Manager, wider IT team, and third-party partners to ensure security best practices are maintained across their cloud and on-premise environments. Key Responsibilities Conduct threat and vulnerability assessments and recommend remediation steps Support the investigation of security incidents and policy violations Assist with risk assessments and security audits Implement and maintain security standards, and guidelines Work with third-party vendors and partners on pen testing and remediation activities Support awareness campaigns to improve cybersecurity hygiene among staff Assist in the development and implementation of disaster recovery and business continuity plans. Produce reports and metrics for senior IT and governance stakeholders Stay updated with the latest threats, trends, and compliance requirements (e.g., GDPR, PCI DSS, Cyber Essentials) Person Specification Essential: Demonstrable experience in a related role Excellent problem-solving, analytical, and communication skills An appetite for keeping up to date with the latest developments in technology, business practices, and the wider threat environment Ability to work independently and remotely with minimal supervision Understanding of current threats, attack vectors, and security frameworks Familiarity with Microsoft 365 security tools (Defender, Purview, Entra, etc.) Working knowledge of network protocols, email security, and IT architectures Right to work in the UK Desirable: Industry certifications (e.g., CompTIA Security+, SSCP) Experience in the charity or non-profit sector Familiarity with Microsoft Azure cloud platforms and identity management Experience with compliance frameworks (PCI DSS, Cyber Essentials) Experience with auditing and compliance Experience of BCP/DR
Security Lead Oxfordshire / Hybrid / Permanent / up to £65,000 About the Role We're seeking a Security Lead to take ownership of both client-facing and internal security strategy within our Managed Services environment. This is a strategic and hands-on leadership position - you'll oversee security governance, ensure compliance with leading frameworks (Cyber Essentials, ISO27001, NIST), and maintain a strong internal security posture across our systems and services. You'll lead Quarterly Security Reviews (QSRs), manage client risk registers, and act as a trusted advisor translating complex risks into clear business outcomes. Internally, you'll own our security frameworks, guide improvement across tools and teams, and ensure compliance through measurable posture metrics and ongoing development. Key Responsibilities Lead client Quarterly Security Reviews (QSRs) covering vulnerabilities, incidents, compliance, and risk registers. Translate technical risks into meaningful business impacts and recommendations. Manage internal and client risk registers and exception processes. Oversee security compliance across frameworks such as Cyber Essentials+, ISO27001, and NIST . Ensure secure deployment and monitoring of core MSP systems (RMM, XDR, PSA, backup, etc.). Collaborate with service and project teams to embed security into delivery and change control. Mentor and develop Security Analysts, maintaining up-to-date certifications and knowledge sharing. Drive continuous improvement through automation, posture metrics, and emerging threat awareness. About You You'll bring a strong balance of strategic thinking, governance, and technical depth , with experience embedding security frameworks in managed environments. You're confident presenting to senior stakeholders and enjoy leading teams and shaping best practice. Essential Skills & Experience 5+ years in IT security or MSP environments . Strong understanding of Cyber Essentials, ISO27001, or NIST frameworks. Experience managing patching, vulnerability, and risk governance . Skilled communicator with the ability to explain risks to non-technical audiences. Proven experience leading client-facing security reviews . Desirable CISSP, CISM , or equivalent certifications. Experience auditing or delivering compliance frameworks. Familiarity with RMM/XDR/EDR , SIEM, and vulnerability scanning platforms. Background in mentoring or managing small teams. Exposure to incident response and tabletop exercises. Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
22/10/2025
Full time
Security Lead Oxfordshire / Hybrid / Permanent / up to £65,000 About the Role We're seeking a Security Lead to take ownership of both client-facing and internal security strategy within our Managed Services environment. This is a strategic and hands-on leadership position - you'll oversee security governance, ensure compliance with leading frameworks (Cyber Essentials, ISO27001, NIST), and maintain a strong internal security posture across our systems and services. You'll lead Quarterly Security Reviews (QSRs), manage client risk registers, and act as a trusted advisor translating complex risks into clear business outcomes. Internally, you'll own our security frameworks, guide improvement across tools and teams, and ensure compliance through measurable posture metrics and ongoing development. Key Responsibilities Lead client Quarterly Security Reviews (QSRs) covering vulnerabilities, incidents, compliance, and risk registers. Translate technical risks into meaningful business impacts and recommendations. Manage internal and client risk registers and exception processes. Oversee security compliance across frameworks such as Cyber Essentials+, ISO27001, and NIST . Ensure secure deployment and monitoring of core MSP systems (RMM, XDR, PSA, backup, etc.). Collaborate with service and project teams to embed security into delivery and change control. Mentor and develop Security Analysts, maintaining up-to-date certifications and knowledge sharing. Drive continuous improvement through automation, posture metrics, and emerging threat awareness. About You You'll bring a strong balance of strategic thinking, governance, and technical depth , with experience embedding security frameworks in managed environments. You're confident presenting to senior stakeholders and enjoy leading teams and shaping best practice. Essential Skills & Experience 5+ years in IT security or MSP environments . Strong understanding of Cyber Essentials, ISO27001, or NIST frameworks. Experience managing patching, vulnerability, and risk governance . Skilled communicator with the ability to explain risks to non-technical audiences. Proven experience leading client-facing security reviews . Desirable CISSP, CISM , or equivalent certifications. Experience auditing or delivering compliance frameworks. Familiarity with RMM/XDR/EDR , SIEM, and vulnerability scanning platforms. Background in mentoring or managing small teams. Exposure to incident response and tabletop exercises. Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
Security Lead Oxfordshire/Hybrid/Permanent/up to £65,000 About the Role We're seeking a Security Lead to take ownership of both client-facing and internal security strategy within our Managed Services environment. This is a strategic and hands-on leadership position - you'll oversee security governance, ensure compliance with leading frameworks (Cyber Essentials, ISO27001, NIST), and maintain a strong internal security posture across our systems and services. You'll lead Quarterly Security Reviews (QSRs), manage client risk registers, and act as a trusted advisor translating complex risks into clear business outcomes. Internally, you'll own our security frameworks, guide improvement across tools and teams, and ensure compliance through measurable posture metrics and ongoing development. Key Responsibilities Lead client Quarterly Security Reviews (QSRs) covering vulnerabilities, incidents, compliance, and risk registers. Translate technical risks into meaningful business impacts and recommendations. Manage internal and client risk registers and exception processes. Oversee security compliance across frameworks such as Cyber Essentials+, ISO27001, and NIST . Ensure secure deployment and monitoring of core MSP systems (RMM, XDR, PSA, backup, etc.). Collaborate with service and project teams to embed security into delivery and change control. Mentor and develop Security Analysts, maintaining up-to-date certifications and knowledge sharing. Drive continuous improvement through automation, posture metrics, and emerging threat awareness. About You You'll bring a strong balance of strategic thinking, governance, and technical depth , with experience embedding security frameworks in managed environments. You're confident presenting to senior stakeholders and enjoy leading teams and shaping best practice. Essential Skills & Experience 5+ years in IT security or MSP environments . Strong understanding of Cyber Essentials, ISO27001, or NIST frameworks. Experience managing patching, vulnerability, and risk governance . Skilled communicator with the ability to explain risks to non-technical audiences. Proven experience leading client-facing security reviews . Desirable CISSP, CISM , or equivalent certifications. Experience auditing or delivering compliance frameworks. Familiarity with RMM/XDR/EDR , SIEM, and vulnerability scanning platforms. Background in mentoring or managing small teams. Exposure to incident response and tabletop exercises. Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
22/10/2025
Full time
Security Lead Oxfordshire/Hybrid/Permanent/up to £65,000 About the Role We're seeking a Security Lead to take ownership of both client-facing and internal security strategy within our Managed Services environment. This is a strategic and hands-on leadership position - you'll oversee security governance, ensure compliance with leading frameworks (Cyber Essentials, ISO27001, NIST), and maintain a strong internal security posture across our systems and services. You'll lead Quarterly Security Reviews (QSRs), manage client risk registers, and act as a trusted advisor translating complex risks into clear business outcomes. Internally, you'll own our security frameworks, guide improvement across tools and teams, and ensure compliance through measurable posture metrics and ongoing development. Key Responsibilities Lead client Quarterly Security Reviews (QSRs) covering vulnerabilities, incidents, compliance, and risk registers. Translate technical risks into meaningful business impacts and recommendations. Manage internal and client risk registers and exception processes. Oversee security compliance across frameworks such as Cyber Essentials+, ISO27001, and NIST . Ensure secure deployment and monitoring of core MSP systems (RMM, XDR, PSA, backup, etc.). Collaborate with service and project teams to embed security into delivery and change control. Mentor and develop Security Analysts, maintaining up-to-date certifications and knowledge sharing. Drive continuous improvement through automation, posture metrics, and emerging threat awareness. About You You'll bring a strong balance of strategic thinking, governance, and technical depth , with experience embedding security frameworks in managed environments. You're confident presenting to senior stakeholders and enjoy leading teams and shaping best practice. Essential Skills & Experience 5+ years in IT security or MSP environments . Strong understanding of Cyber Essentials, ISO27001, or NIST frameworks. Experience managing patching, vulnerability, and risk governance . Skilled communicator with the ability to explain risks to non-technical audiences. Proven experience leading client-facing security reviews . Desirable CISSP, CISM , or equivalent certifications. Experience auditing or delivering compliance frameworks. Familiarity with RMM/XDR/EDR , SIEM, and vulnerability scanning platforms. Background in mentoring or managing small teams. Exposure to incident response and tabletop exercises. Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
Information Security Analyst Up to 50,000 + benefits Hereford Hybrid Permanent Full-time We are looking for an experienced Information Security Analyst to join our client who will play a key role in driving compliance, governance, and continual improvement across key security frameworks including ISO 27001, PCI DSS, and Cyber Essentials Plus. Key Responsibilities: Lead on the operation and continual improvement of the Information Security Management System (ISMS) Coordinate internal and external audit readiness for ISO 27001, PCI DSS, and Cyber Essentials Plus Draft and update information security policies, procedures, and technical standards Work with procurement and commercial teams to support supplier assurance and risk assessment Contribute to tender responses and bid processes, ensuring security and compliance requirements are met Promote good security practices and raise awareness across departments Act as an escalation point and day-to-day contact for other team members Stay up to date with changes in legislation and standards relating to information and cyber security Key Skills & Experience: Essential: Background in IT, Cyber Security, Information Systems, or a related discipline Strong working knowledge of ISO 27001, PCI DSS, and Cyber Essentials Plus Proven ability to support and prepare for audits, including evidence collation and audit readiness Excellent attention to detail and ability to produce high-quality documentation Strong stakeholder communication skills, both written and verbal Ability to build effective working relationships and influence at all levels Comfortable working independently and proactively across teams Desirable: Experience in supplier risk management and/or tender processes ISO 27001 Lead Auditor/Implementer, PCIP, CISM, CompTIA Security+, or CISMP certification What you get in return: Up to 50,000 per annum + benefits Hybrid working (3 to 4 days in office) Opportunity to lead and mentor within a growing security team Professional development and training support This company is an equal opportunity employer and values diversity. We do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Interested? Please submit your CV to Meg Kewley at DCS Recruitment via the link provided. DCS Recruitment and all associated companies are committed to creating a working environment where diversity is celebrated and everyone is treated fairly, regardless of gender, gender identity, disability, ethnic origin, religion or belief, sexual orientation, marital or transgender status, age, or nationality
21/10/2025
Full time
Information Security Analyst Up to 50,000 + benefits Hereford Hybrid Permanent Full-time We are looking for an experienced Information Security Analyst to join our client who will play a key role in driving compliance, governance, and continual improvement across key security frameworks including ISO 27001, PCI DSS, and Cyber Essentials Plus. Key Responsibilities: Lead on the operation and continual improvement of the Information Security Management System (ISMS) Coordinate internal and external audit readiness for ISO 27001, PCI DSS, and Cyber Essentials Plus Draft and update information security policies, procedures, and technical standards Work with procurement and commercial teams to support supplier assurance and risk assessment Contribute to tender responses and bid processes, ensuring security and compliance requirements are met Promote good security practices and raise awareness across departments Act as an escalation point and day-to-day contact for other team members Stay up to date with changes in legislation and standards relating to information and cyber security Key Skills & Experience: Essential: Background in IT, Cyber Security, Information Systems, or a related discipline Strong working knowledge of ISO 27001, PCI DSS, and Cyber Essentials Plus Proven ability to support and prepare for audits, including evidence collation and audit readiness Excellent attention to detail and ability to produce high-quality documentation Strong stakeholder communication skills, both written and verbal Ability to build effective working relationships and influence at all levels Comfortable working independently and proactively across teams Desirable: Experience in supplier risk management and/or tender processes ISO 27001 Lead Auditor/Implementer, PCIP, CISM, CompTIA Security+, or CISMP certification What you get in return: Up to 50,000 per annum + benefits Hybrid working (3 to 4 days in office) Opportunity to lead and mentor within a growing security team Professional development and training support This company is an equal opportunity employer and values diversity. We do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Interested? Please submit your CV to Meg Kewley at DCS Recruitment via the link provided. DCS Recruitment and all associated companies are committed to creating a working environment where diversity is celebrated and everyone is treated fairly, regardless of gender, gender identity, disability, ethnic origin, religion or belief, sexual orientation, marital or transgender status, age, or nationality
We are looking for an Information Governance/Security Analyst to support one of our NHS customers in the North West. Key Responsibilities: Essential Functions Establishment - Review Trust-wide populated BCPs to identify systems, suppliers, their function, criticality, and interdependencies. - Formalise the Trust Essential Functions Register, populating the NHSE DSPT Essential Function Template with supporting policies and procedures. Supplier & Subcontractor Assurance - Complete supplier discovery and data processor mapping for critical business functions. Complete divisional discovery work to identify gaps in suppliers and data processors. - Populate identified gaps into the central Data Agreement Register. - Review contracts for: - Cybersecurity clauses - Right to audit - Data protection clauses - Incident breach notification requirements - Details of sub-processors - Review contracts for technical and security risks. - Document supplier certifications and ensure records are in date.
21/10/2025
Full time
We are looking for an Information Governance/Security Analyst to support one of our NHS customers in the North West. Key Responsibilities: Essential Functions Establishment - Review Trust-wide populated BCPs to identify systems, suppliers, their function, criticality, and interdependencies. - Formalise the Trust Essential Functions Register, populating the NHSE DSPT Essential Function Template with supporting policies and procedures. Supplier & Subcontractor Assurance - Complete supplier discovery and data processor mapping for critical business functions. Complete divisional discovery work to identify gaps in suppliers and data processors. - Populate identified gaps into the central Data Agreement Register. - Review contracts for: - Cybersecurity clauses - Right to audit - Data protection clauses - Incident breach notification requirements - Details of sub-processors - Review contracts for technical and security risks. - Document supplier certifications and ensure records are in date.
This newly created role represents a fantastic opportunity for an experienced systems-based Financial Crime Analyst to make a real impact in strengthening the first line of defence against fraud and financial crime within a FTSE 500 financial services provider. The role will play a pivotal part in enhancing detection, prevention, and reporting capabilities across multiple Financial Crime (FC) systems. Working in a data-rich environment, the successful candidate will combine technical expertise with analytical insight to help identify emerging threats, optimise system performance, and ensure controls remain robust, efficient, and compliant. Key Responsibilities Lead and support the development and optimisation of fraud detection and prevention strategies across all Financial Crime systems. Interrogate and analyse large and complex data sets using advanced SQL and data management tools to uncover patterns, trends, and anomalies. Develop, track, and report on key fraud metrics, presenting findings and recommendations to senior stakeholders. Design and implement data models and machine learning scoring models to drive predictive insights and enhance fraud detection accuracy. Optimise and fine-tune Financial Crime system rule sets in line with risk appetite, balancing risk mitigation with operational efficiency. Collaborate with cross-functional teams in Technology, Risk, and Compliance to deliver data-driven improvements and strategic initiatives. Maintain robust governance and controls over the use of fraud detection systems, ensuring full compliance with regulatory and internal standards. Stay current with evolving financial crime trends, industry best practices, and emerging technologies to continuously strengthen defences. Engage with external partners, technology vendors, and industry peers to explore new detection techniques and system capabilities. Skills Strong background in Financial Crime or Fraud Analytics within a banking or financial services environment. Advanced SQL skills with proven ability to manage and analyse large-scale, complex datasets. Experience with database platforms such as SQL Server, Oracle, SAS, or Access. Familiarity with data visualisation tools (e.g. Power BI, Tableau) for insight generation and reporting. Knowledge of AI and Machine Learning models for risk scoring and predictive analytics. Expertise with Financial Crime platforms such as ACI PRM (Proactive Risk Manager), SIRA, SONAR, ThreatMetrix, Mitek, and CIFAS. In-depth understanding of payments fraud, AML, CTF, KYC, and internal fraud practices. Excellent analytical and problem-solving skills, with high accuracy in data investigation and interpretation. Strong communication skills, capable of translating technical findings into actionable business insights. Qualifications Degree in Computer Science, Data Analytics, Mathematics MIS/CIS, AI, or Machine Learning, or equivalent experience. Recognised SQL / Database qualification (Microsoft, Oracle, or equivalent). Relevant certification in Financial Crime, Fraud, or Cybercrime is desirable. Exceptional candidates without formal qualifications but with equivalent experience will also be considered. In return Competitive salary between £60,000 and £70,000, dependent on experience. Hybrid working - two days per week in the West Midlands office. Ongoing professional development and access to advanced Financial Crime training. The opportunity to shape a newly established role within a growing and innovative team. A collaborative and supportive environment focused on continuous improvement and data-led decision making. How to Apply If you're an experienced financial crime systems analyst looking for a new challenge and the opportunity to influence how a leading financial institution protects its customers, please send your CV and a short cover letter outlining your experience and motivation for the role. Applicants must have full UK working rights - sponsorship is not available for this position.
21/10/2025
Full time
This newly created role represents a fantastic opportunity for an experienced systems-based Financial Crime Analyst to make a real impact in strengthening the first line of defence against fraud and financial crime within a FTSE 500 financial services provider. The role will play a pivotal part in enhancing detection, prevention, and reporting capabilities across multiple Financial Crime (FC) systems. Working in a data-rich environment, the successful candidate will combine technical expertise with analytical insight to help identify emerging threats, optimise system performance, and ensure controls remain robust, efficient, and compliant. Key Responsibilities Lead and support the development and optimisation of fraud detection and prevention strategies across all Financial Crime systems. Interrogate and analyse large and complex data sets using advanced SQL and data management tools to uncover patterns, trends, and anomalies. Develop, track, and report on key fraud metrics, presenting findings and recommendations to senior stakeholders. Design and implement data models and machine learning scoring models to drive predictive insights and enhance fraud detection accuracy. Optimise and fine-tune Financial Crime system rule sets in line with risk appetite, balancing risk mitigation with operational efficiency. Collaborate with cross-functional teams in Technology, Risk, and Compliance to deliver data-driven improvements and strategic initiatives. Maintain robust governance and controls over the use of fraud detection systems, ensuring full compliance with regulatory and internal standards. Stay current with evolving financial crime trends, industry best practices, and emerging technologies to continuously strengthen defences. Engage with external partners, technology vendors, and industry peers to explore new detection techniques and system capabilities. Skills Strong background in Financial Crime or Fraud Analytics within a banking or financial services environment. Advanced SQL skills with proven ability to manage and analyse large-scale, complex datasets. Experience with database platforms such as SQL Server, Oracle, SAS, or Access. Familiarity with data visualisation tools (e.g. Power BI, Tableau) for insight generation and reporting. Knowledge of AI and Machine Learning models for risk scoring and predictive analytics. Expertise with Financial Crime platforms such as ACI PRM (Proactive Risk Manager), SIRA, SONAR, ThreatMetrix, Mitek, and CIFAS. In-depth understanding of payments fraud, AML, CTF, KYC, and internal fraud practices. Excellent analytical and problem-solving skills, with high accuracy in data investigation and interpretation. Strong communication skills, capable of translating technical findings into actionable business insights. Qualifications Degree in Computer Science, Data Analytics, Mathematics MIS/CIS, AI, or Machine Learning, or equivalent experience. Recognised SQL / Database qualification (Microsoft, Oracle, or equivalent). Relevant certification in Financial Crime, Fraud, or Cybercrime is desirable. Exceptional candidates without formal qualifications but with equivalent experience will also be considered. In return Competitive salary between £60,000 and £70,000, dependent on experience. Hybrid working - two days per week in the West Midlands office. Ongoing professional development and access to advanced Financial Crime training. The opportunity to shape a newly established role within a growing and innovative team. A collaborative and supportive environment focused on continuous improvement and data-led decision making. How to Apply If you're an experienced financial crime systems analyst looking for a new challenge and the opportunity to influence how a leading financial institution protects its customers, please send your CV and a short cover letter outlining your experience and motivation for the role. Applicants must have full UK working rights - sponsorship is not available for this position.
Location - London, Bristol or Manchester (1 day a month onsite) Duration - 6 months Rate - £550 - £600pd (inside ir35) As a Data Engineer in the Cyber and Domains Protection Team you will: Work within an Agile team to support the development of dashboards and build automated reports to meet the needs of technical and non-technical users Work with the data analyst and user researcher to update relevant data models to allow business intelligence data to meet the organisation's specific needs Develop business intelligence reports that can be automated, reused and shared with users directly Implement data flows to connect operational systems, data for analytics and business intelligence (BI) systems Build accessible data for analysis Deliver data solutions in accordance with agreed organisational standards that ensure services are resilient, scalable and future-proof Investigate problems in systems, processes and services This role aligns to the Data Analyst role in the Government Digital and Data Profession Capability Framework. At this role level, your skills include: Applying statistical and analytical tools and techniques Communicating between the technical and non-technical Data ethics and privacy Data management Data preparation and linkage Data visualisation Developing code for analysis You will also have the following specialist skills, at Working level: Advanced SQL proficiency : expertise in writing complex, highly-performant SQL queries, including common table expressions (CTEs), window functions, and complex joins. Experience with query optimization and performance tuning on relational databases like PostgreSQL, MySQL, or similar Cloud data ecosystem (AWS) : hands-on experience with core AWS data services. Key services include: S3 for data lake storage AWS Glue for ETL and data cataloging Amazon Redshift or Athena for data warehousing and analytics Lambda for event-driven data processing. ETL/ELT pipeline development : experience in designing, building, and maintaining robust, automated data pipelines. You should be comfortable with both the theory and practical application of extracting, transforming, and loading data between systems Programming for data : Strong scripting skills, including Python Infrastructure as code (IaC) : Experience deploying and managing cloud infrastructure using tools like Terraform or AWS CDK / CloudFormation Data modelling and warehousing: Dimensional Data Modeling : Deep understanding of data warehousing concepts and best practices. Experience of, and ability to, transform raw transactional data into well-structured analytics-ready datasets using schemas like the star schema (Kimball methodology) Data Quality & Governance : build trust in data by implementing data validation checks, testing frameworks, and clear documentation within your pipelines Experience in the following areas is not essential but would be beneficial: Data Orchestration Tools: Familiarity with modern workflow management tools like Apache Airflow, Prefect, or Dagster Modern Data Transformation: Experience with dbt (Data Build Tool) for managing the transformation layer of the data warehouse BI Tool Familiarity : An understanding of how BI tools like AWS QuickSight consume data, and the ability to structure datasets optimally for visualization and reporting e Please submit a copy of your latest CV for more information on this vacancy.
20/10/2025
Full time
Location - London, Bristol or Manchester (1 day a month onsite) Duration - 6 months Rate - £550 - £600pd (inside ir35) As a Data Engineer in the Cyber and Domains Protection Team you will: Work within an Agile team to support the development of dashboards and build automated reports to meet the needs of technical and non-technical users Work with the data analyst and user researcher to update relevant data models to allow business intelligence data to meet the organisation's specific needs Develop business intelligence reports that can be automated, reused and shared with users directly Implement data flows to connect operational systems, data for analytics and business intelligence (BI) systems Build accessible data for analysis Deliver data solutions in accordance with agreed organisational standards that ensure services are resilient, scalable and future-proof Investigate problems in systems, processes and services This role aligns to the Data Analyst role in the Government Digital and Data Profession Capability Framework. At this role level, your skills include: Applying statistical and analytical tools and techniques Communicating between the technical and non-technical Data ethics and privacy Data management Data preparation and linkage Data visualisation Developing code for analysis You will also have the following specialist skills, at Working level: Advanced SQL proficiency : expertise in writing complex, highly-performant SQL queries, including common table expressions (CTEs), window functions, and complex joins. Experience with query optimization and performance tuning on relational databases like PostgreSQL, MySQL, or similar Cloud data ecosystem (AWS) : hands-on experience with core AWS data services. Key services include: S3 for data lake storage AWS Glue for ETL and data cataloging Amazon Redshift or Athena for data warehousing and analytics Lambda for event-driven data processing. ETL/ELT pipeline development : experience in designing, building, and maintaining robust, automated data pipelines. You should be comfortable with both the theory and practical application of extracting, transforming, and loading data between systems Programming for data : Strong scripting skills, including Python Infrastructure as code (IaC) : Experience deploying and managing cloud infrastructure using tools like Terraform or AWS CDK / CloudFormation Data modelling and warehousing: Dimensional Data Modeling : Deep understanding of data warehousing concepts and best practices. Experience of, and ability to, transform raw transactional data into well-structured analytics-ready datasets using schemas like the star schema (Kimball methodology) Data Quality & Governance : build trust in data by implementing data validation checks, testing frameworks, and clear documentation within your pipelines Experience in the following areas is not essential but would be beneficial: Data Orchestration Tools: Familiarity with modern workflow management tools like Apache Airflow, Prefect, or Dagster Modern Data Transformation: Experience with dbt (Data Build Tool) for managing the transformation layer of the data warehouse BI Tool Familiarity : An understanding of how BI tools like AWS QuickSight consume data, and the ability to structure datasets optimally for visualization and reporting e Please submit a copy of your latest CV for more information on this vacancy.
Cyber Security Analyst Milton Keynes - hybrid Up to £60,000, 10% annual bonus and excellent benefits. Our client is an impressive, innovative, multiple award-winning, leading IT Managed Service Provider; they believe great people build great companies and invest heavily in staff development, cultivating a culture of innovation, quality, and excellence. We are looking for a skilled and proactive Cyber Security Analyst to join their specialist security team. This role offers the opportunity to work across a diverse range of clients and environments, applying your technical expertise to enhance security operations, tooling, and compliance. You will play a key role in managing incidents, optimising security tools, and mentoring junior analysts, while contributing to the continuous improvement of their security posture. This is a hands-on, operationally focused role that blends technical security responsibilities with governance, risk, and compliance (GRC) elements. As Cyber Security Analyst, you will: Lead cyber incident investigations with SOC and client teams Triage and analyse alerts across email, cloud, and hybrid systems Perform threat hunting and develop detection use cases Manage vulnerability assessments and remediation efforts Maintain and optimise DLP tools and incident response Support forensic readiness and insider risk initiatives Develop and enforce security policies and awareness programs Lead incident response and produce investigation reports Utilise and enhance Microsoft Security Stack (Sentinel, Defender, Purview) Drive Zero Trust implementation Conduct security audits and generate KPI/compliance reports Mentor junior analysts and support their growth What are we looking for? Industry certifications such as Security+, ISC2 CC, Cisco, or equivalent. Progress toward or completion of Microsoft certifications: AZ-900, SC-200, SC-401, SC-500, and ideally SC-100. Strong written and verbal communication skills. Solid understanding of enterprise security operations and tooling. Experience in a technical cyber security role. Hands-on experience with the Microsoft Security Stack and other leading security tools. Familiarity with network and application firewalls. Working knowledge of security frameworks such as ISO27001, NIST, SOC2, and Cyber Essentials Plus. Experience with Privileged Access Management tools (e.g., CyberArk, Entra, SailPoint). Ability to quickly learn and adapt to new security tools and technologies. Please be aware this advert will remain open until the vacancy has been filled. Interviews will take place throughout this period, therefore we encourage you to apply early to avoid disappointment. Tate is acting as an Employment Business in relation to this vacancy. Tate is committed to promoting equal opportunities. To ensure that every candidate has the best experience with us, we encourage you to let us know if there are any adjustments we can make during the application or interview process. Your comfort and accessibility are our priority, and we are here to support you every step of the way. Additionally, we value and respect your individuality, and we invite you to share your preferred pronouns in your application.
20/10/2025
Full time
Cyber Security Analyst Milton Keynes - hybrid Up to £60,000, 10% annual bonus and excellent benefits. Our client is an impressive, innovative, multiple award-winning, leading IT Managed Service Provider; they believe great people build great companies and invest heavily in staff development, cultivating a culture of innovation, quality, and excellence. We are looking for a skilled and proactive Cyber Security Analyst to join their specialist security team. This role offers the opportunity to work across a diverse range of clients and environments, applying your technical expertise to enhance security operations, tooling, and compliance. You will play a key role in managing incidents, optimising security tools, and mentoring junior analysts, while contributing to the continuous improvement of their security posture. This is a hands-on, operationally focused role that blends technical security responsibilities with governance, risk, and compliance (GRC) elements. As Cyber Security Analyst, you will: Lead cyber incident investigations with SOC and client teams Triage and analyse alerts across email, cloud, and hybrid systems Perform threat hunting and develop detection use cases Manage vulnerability assessments and remediation efforts Maintain and optimise DLP tools and incident response Support forensic readiness and insider risk initiatives Develop and enforce security policies and awareness programs Lead incident response and produce investigation reports Utilise and enhance Microsoft Security Stack (Sentinel, Defender, Purview) Drive Zero Trust implementation Conduct security audits and generate KPI/compliance reports Mentor junior analysts and support their growth What are we looking for? Industry certifications such as Security+, ISC2 CC, Cisco, or equivalent. Progress toward or completion of Microsoft certifications: AZ-900, SC-200, SC-401, SC-500, and ideally SC-100. Strong written and verbal communication skills. Solid understanding of enterprise security operations and tooling. Experience in a technical cyber security role. Hands-on experience with the Microsoft Security Stack and other leading security tools. Familiarity with network and application firewalls. Working knowledge of security frameworks such as ISO27001, NIST, SOC2, and Cyber Essentials Plus. Experience with Privileged Access Management tools (e.g., CyberArk, Entra, SailPoint). Ability to quickly learn and adapt to new security tools and technologies. Please be aware this advert will remain open until the vacancy has been filled. Interviews will take place throughout this period, therefore we encourage you to apply early to avoid disappointment. Tate is acting as an Employment Business in relation to this vacancy. Tate is committed to promoting equal opportunities. To ensure that every candidate has the best experience with us, we encourage you to let us know if there are any adjustments we can make during the application or interview process. Your comfort and accessibility are our priority, and we are here to support you every step of the way. Additionally, we value and respect your individuality, and we invite you to share your preferred pronouns in your application.
Location - London, Bristol or Manchester (1 day a month onsite) Duration - 6 months Rate - 550 - 600pd (inside ir35) As a Data Engineer in the Cyber and Domains Protection Team you will: Work within an Agile team to support the development of dashboards and build automated reports to meet the needs of technical and non-technical users Work with the data analyst and user researcher to update relevant data models to allow business intelligence data to meet the organisation's specific needs Develop business intelligence reports that can be automated, reused and shared with users directly Implement data flows to connect operational systems, data for analytics and business intelligence (BI) systems Build accessible data for analysis Deliver data solutions in accordance with agreed organisational standards that ensure services are resilient, scalable and future-proof Investigate problems in systems, processes and services This role aligns to the Data Analyst role in the Government Digital and Data Profession Capability Framework. At this role level, your skills include: Applying statistical and analytical tools and techniques Communicating between the technical and non-technical Data ethics and privacy Data management Data preparation and linkage Data visualisation Developing code for analysis You will also have the following specialist skills, at Working level: Advanced SQL proficiency : expertise in writing complex, highly-performant SQL queries, including common table expressions (CTEs), window functions, and complex joins. Experience with query optimization and performance tuning on relational databases like PostgreSQL, MySQL, or similar Cloud data ecosystem (AWS) : hands-on experience with core AWS data services. Key services include: S3 for data lake storage AWS Glue for ETL and data cataloging Amazon Redshift or Athena for data warehousing and analytics Lambda for event-driven data processing. ETL/ELT pipeline development : experience in designing, building, and maintaining robust, automated data pipelines. You should be comfortable with both the theory and practical application of extracting, transforming, and loading data between systems Programming for data : Strong scripting skills, including Python Infrastructure as code (IaC) : Experience deploying and managing cloud infrastructure using tools like Terraform or AWS CDK / CloudFormation Data modelling and warehousing: Dimensional Data Modeling : Deep understanding of data warehousing concepts and best practices. Experience of, and ability to, transform raw transactional data into well-structured analytics-ready datasets using schemas like the star schema (Kimball methodology) Data Quality & Governance : build trust in data by implementing data validation checks, testing frameworks, and clear documentation within your pipelines Experience in the following areas is not essential but would be beneficial: Data Orchestration Tools: Familiarity with modern workflow management tools like Apache Airflow, Prefect, or Dagster Modern Data Transformation: Experience with dbt (Data Build Tool) for managing the transformation layer of the data warehouse BI Tool Familiarity : An understanding of how BI tools like AWS QuickSight consume data, and the ability to structure datasets optimally for visualization and reporting e Please submit a copy of your latest CV for more information on this vacancy.
20/10/2025
Contractor
Location - London, Bristol or Manchester (1 day a month onsite) Duration - 6 months Rate - 550 - 600pd (inside ir35) As a Data Engineer in the Cyber and Domains Protection Team you will: Work within an Agile team to support the development of dashboards and build automated reports to meet the needs of technical and non-technical users Work with the data analyst and user researcher to update relevant data models to allow business intelligence data to meet the organisation's specific needs Develop business intelligence reports that can be automated, reused and shared with users directly Implement data flows to connect operational systems, data for analytics and business intelligence (BI) systems Build accessible data for analysis Deliver data solutions in accordance with agreed organisational standards that ensure services are resilient, scalable and future-proof Investigate problems in systems, processes and services This role aligns to the Data Analyst role in the Government Digital and Data Profession Capability Framework. At this role level, your skills include: Applying statistical and analytical tools and techniques Communicating between the technical and non-technical Data ethics and privacy Data management Data preparation and linkage Data visualisation Developing code for analysis You will also have the following specialist skills, at Working level: Advanced SQL proficiency : expertise in writing complex, highly-performant SQL queries, including common table expressions (CTEs), window functions, and complex joins. Experience with query optimization and performance tuning on relational databases like PostgreSQL, MySQL, or similar Cloud data ecosystem (AWS) : hands-on experience with core AWS data services. Key services include: S3 for data lake storage AWS Glue for ETL and data cataloging Amazon Redshift or Athena for data warehousing and analytics Lambda for event-driven data processing. ETL/ELT pipeline development : experience in designing, building, and maintaining robust, automated data pipelines. You should be comfortable with both the theory and practical application of extracting, transforming, and loading data between systems Programming for data : Strong scripting skills, including Python Infrastructure as code (IaC) : Experience deploying and managing cloud infrastructure using tools like Terraform or AWS CDK / CloudFormation Data modelling and warehousing: Dimensional Data Modeling : Deep understanding of data warehousing concepts and best practices. Experience of, and ability to, transform raw transactional data into well-structured analytics-ready datasets using schemas like the star schema (Kimball methodology) Data Quality & Governance : build trust in data by implementing data validation checks, testing frameworks, and clear documentation within your pipelines Experience in the following areas is not essential but would be beneficial: Data Orchestration Tools: Familiarity with modern workflow management tools like Apache Airflow, Prefect, or Dagster Modern Data Transformation: Experience with dbt (Data Build Tool) for managing the transformation layer of the data warehouse BI Tool Familiarity : An understanding of how BI tools like AWS QuickSight consume data, and the ability to structure datasets optimally for visualization and reporting e Please submit a copy of your latest CV for more information on this vacancy.
Cyber Security Analyst Milton Keynes - hybrid Up to 60,000, 10% annual bonus and excellent benefits. Our client is an impressive, innovative, multiple award-winning, leading IT Managed Service Provider; they believe great people build great companies and invest heavily in staff development, cultivating a culture of innovation, quality, and excellence. We are looking for a skilled and proactive Cyber Security Analyst to join their specialist security team. This role offers the opportunity to work across a diverse range of clients and environments, applying your technical expertise to enhance security operations, tooling, and compliance. You will play a key role in managing incidents, optimising security tools, and mentoring junior analysts, while contributing to the continuous improvement of their security posture. This is a hands-on, operationally focused role that blends technical security responsibilities with governance, risk, and compliance (GRC) elements. As Cyber Security Analyst, you will: Lead cyber incident investigations with SOC and client teams Triage and analyse alerts across email, cloud, and hybrid systems Perform threat hunting and develop detection use cases Manage vulnerability assessments and remediation efforts Maintain and optimise DLP tools and incident response Support forensic readiness and insider risk initiatives Develop and enforce security policies and awareness programs Lead incident response and produce investigation reports Utilise and enhance Microsoft Security Stack (Sentinel, Defender, Purview) Drive Zero Trust implementation Conduct security audits and generate KPI/compliance reports Mentor junior analysts and support their growth What are we looking for? Industry certifications such as Security+, ISC2 CC, Cisco, or equivalent. Progress toward or completion of Microsoft certifications: AZ-900, SC-200, SC-401, SC-500, and ideally SC-100. Strong written and verbal communication skills. Solid understanding of enterprise security operations and tooling. Experience in a technical cyber security role. Hands-on experience with the Microsoft Security Stack and other leading security tools. Familiarity with network and application firewalls. Working knowledge of security frameworks such as ISO27001, NIST, SOC2, and Cyber Essentials Plus. Experience with Privileged Access Management tools (e.g., CyberArk, Entra, SailPoint). Ability to quickly learn and adapt to new security tools and technologies. Please be aware this advert will remain open until the vacancy has been filled. Interviews will take place throughout this period, therefore we encourage you to apply early to avoid disappointment. Tate is acting as an Employment Business in relation to this vacancy. Tate is committed to promoting equal opportunities. To ensure that every candidate has the best experience with us, we encourage you to let us know if there are any adjustments we can make during the application or interview process. Your comfort and accessibility are our priority, and we are here to support you every step of the way. Additionally, we value and respect your individuality, and we invite you to share your preferred pronouns in your application.
20/10/2025
Full time
Cyber Security Analyst Milton Keynes - hybrid Up to 60,000, 10% annual bonus and excellent benefits. Our client is an impressive, innovative, multiple award-winning, leading IT Managed Service Provider; they believe great people build great companies and invest heavily in staff development, cultivating a culture of innovation, quality, and excellence. We are looking for a skilled and proactive Cyber Security Analyst to join their specialist security team. This role offers the opportunity to work across a diverse range of clients and environments, applying your technical expertise to enhance security operations, tooling, and compliance. You will play a key role in managing incidents, optimising security tools, and mentoring junior analysts, while contributing to the continuous improvement of their security posture. This is a hands-on, operationally focused role that blends technical security responsibilities with governance, risk, and compliance (GRC) elements. As Cyber Security Analyst, you will: Lead cyber incident investigations with SOC and client teams Triage and analyse alerts across email, cloud, and hybrid systems Perform threat hunting and develop detection use cases Manage vulnerability assessments and remediation efforts Maintain and optimise DLP tools and incident response Support forensic readiness and insider risk initiatives Develop and enforce security policies and awareness programs Lead incident response and produce investigation reports Utilise and enhance Microsoft Security Stack (Sentinel, Defender, Purview) Drive Zero Trust implementation Conduct security audits and generate KPI/compliance reports Mentor junior analysts and support their growth What are we looking for? Industry certifications such as Security+, ISC2 CC, Cisco, or equivalent. Progress toward or completion of Microsoft certifications: AZ-900, SC-200, SC-401, SC-500, and ideally SC-100. Strong written and verbal communication skills. Solid understanding of enterprise security operations and tooling. Experience in a technical cyber security role. Hands-on experience with the Microsoft Security Stack and other leading security tools. Familiarity with network and application firewalls. Working knowledge of security frameworks such as ISO27001, NIST, SOC2, and Cyber Essentials Plus. Experience with Privileged Access Management tools (e.g., CyberArk, Entra, SailPoint). Ability to quickly learn and adapt to new security tools and technologies. Please be aware this advert will remain open until the vacancy has been filled. Interviews will take place throughout this period, therefore we encourage you to apply early to avoid disappointment. Tate is acting as an Employment Business in relation to this vacancy. Tate is committed to promoting equal opportunities. To ensure that every candidate has the best experience with us, we encourage you to let us know if there are any adjustments we can make during the application or interview process. Your comfort and accessibility are our priority, and we are here to support you every step of the way. Additionally, we value and respect your individuality, and we invite you to share your preferred pronouns in your application.
Contract Role - Security Analyst (Network & Endpoint) - England/Remote - 4+ Months Initial We are looking for a highly capable and technically skilled Security Analyst (Network & Endpoint) to join our cybersecurity team. This role focuses on network and endpoint security operations, threat intelligence, and incident response within a Security Operations Centre (SOC) environment. The successful candidate will have hands-on experience with leading security platforms and demonstrate the ability to operate at a team lead level. Role Overview: Job Title: Security Analyst (Network & Endpoint) Location: England/Remote Contract Type: Contract Duration: Contract till 31st Mar 26 Sector: Healthcare . Key Responsibilities: Network Detection & Response: Administer and optimise Darktrace for network threat detection, model tuning, and behavioural analysis. Investigate anomalies and escalate incidents based on network telemetry. Endpoint Protection: Deploy and manage CrowdStrike Falcon agents across enterprise endpoints. Maintain and update detection rules, ensuring alignment with threat intelligence. Security Operations Centre (SOC): Act as a Level 2 SOC Analyst and Incident Handler. Triage, investigate, and respond to security alerts and incidents. Collaborate with other SOC team members to ensure timely resolution and documentation. Threat Intelligence & Insider Threat Monitoring: Monitor threat feeds and manage Indicators of Compromise (IOCs). Conduct insider threat analysis and support investigations. Cloud & Identity Security: Use Microsoft Sentinel for incident investigation, alert correlation, and dashboard monitoring. Manage identity governance and conditional access policies via Microsoft Entra ID. Monitor Entra ID logs and integrate with Sentinel for rule-based alerting. Additional Technologies: Experience with Zscaler for secure web gateway and DLP. Exposure to Google SecOps is advantageous. Team Leadership: Operate at a team lead level, supporting junior analysts and coordinating operational tasks. Provide technical guidance and contribute to process improvement initiatives. Preferred Certifications: Essential: CompTIA Security+ Microsoft Certified: Security Operations Analyst Associate (SC-200) CrowdStrike Certified Falcon Administrator (CCFA) Darktrace Analyst Certification (if available) Desirable: GIAC Certified Intrusion Analyst (GCIA) EC-Council Certified Threat Intelligence Analyst (CTIA) Microsoft Certified: Identity and Access Administrator Associate (SC-300) CISSP or equivalent foundational certification Please feel free to contact myself - Daisy Nguyen at Gibbs Consulting for a confidential chat to know more details about the role. Please also note: Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted.
17/10/2025
Contractor
Contract Role - Security Analyst (Network & Endpoint) - England/Remote - 4+ Months Initial We are looking for a highly capable and technically skilled Security Analyst (Network & Endpoint) to join our cybersecurity team. This role focuses on network and endpoint security operations, threat intelligence, and incident response within a Security Operations Centre (SOC) environment. The successful candidate will have hands-on experience with leading security platforms and demonstrate the ability to operate at a team lead level. Role Overview: Job Title: Security Analyst (Network & Endpoint) Location: England/Remote Contract Type: Contract Duration: Contract till 31st Mar 26 Sector: Healthcare . Key Responsibilities: Network Detection & Response: Administer and optimise Darktrace for network threat detection, model tuning, and behavioural analysis. Investigate anomalies and escalate incidents based on network telemetry. Endpoint Protection: Deploy and manage CrowdStrike Falcon agents across enterprise endpoints. Maintain and update detection rules, ensuring alignment with threat intelligence. Security Operations Centre (SOC): Act as a Level 2 SOC Analyst and Incident Handler. Triage, investigate, and respond to security alerts and incidents. Collaborate with other SOC team members to ensure timely resolution and documentation. Threat Intelligence & Insider Threat Monitoring: Monitor threat feeds and manage Indicators of Compromise (IOCs). Conduct insider threat analysis and support investigations. Cloud & Identity Security: Use Microsoft Sentinel for incident investigation, alert correlation, and dashboard monitoring. Manage identity governance and conditional access policies via Microsoft Entra ID. Monitor Entra ID logs and integrate with Sentinel for rule-based alerting. Additional Technologies: Experience with Zscaler for secure web gateway and DLP. Exposure to Google SecOps is advantageous. Team Leadership: Operate at a team lead level, supporting junior analysts and coordinating operational tasks. Provide technical guidance and contribute to process improvement initiatives. Preferred Certifications: Essential: CompTIA Security+ Microsoft Certified: Security Operations Analyst Associate (SC-200) CrowdStrike Certified Falcon Administrator (CCFA) Darktrace Analyst Certification (if available) Desirable: GIAC Certified Intrusion Analyst (GCIA) EC-Council Certified Threat Intelligence Analyst (CTIA) Microsoft Certified: Identity and Access Administrator Associate (SC-300) CISSP or equivalent foundational certification Please feel free to contact myself - Daisy Nguyen at Gibbs Consulting for a confidential chat to know more details about the role. Please also note: Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted.
Senior Cyber Security Risk Analyst Milton Keynes- 4 days per week on site £70- £85,000 + bonus + benefits My client, a leading global manufacturer based in Berkshire are actively looking for Senior Cyber Security Risk Analyst to join their dynamic team. This role is an exciting opportunity to be a part of really helping to define and shape what governance and risk assurance looks like for the organisation. This will include areas such as building out and developing their education and awareness programme as well as taking ownership over third party assurance. If you are looking for a role where you can be a part of building out something exciting, with a fantastic long term career path, then this is the role for you! Within this role you will: Lead and evolve the cybersecurity risk management framework, ensuring effective identification, assessment, and remediation of risks. Conduct detailed risk and control assessments across business units, projects, vendors, and IT systems, aligning with standards like ISO 27001, NIST CSF, and CIS Controls. Manage and enhance Third-Party Risk Management, including cybersecurity assessments of external partners and suppliers. Collaborate with stakeholders to develop and track cyber risk treatment plans, implement corrective actions, and report on key risk indicators and control effectiveness. Drive continuous improvement of cybersecurity policies and practices, while fostering strong relationships to embed a risk-aware culture across the organisation. Experience you will have: Expertise in cybersecurity risk frameworks and compliance, including CIS Controls, ISO 27001, NIST CSF, GDPR, SOX, and PCI. Strong technical and analytical skills, with the ability to assess risks, identify gaps, and propose mitigation strategies across IT systems and third parties. Excellent communication and stakeholder management, including experience presenting risk insights to senior leadership and working across technical and business teams. Proven experience in cybersecurity disciplines, ideally 5-7 years in roles covering risk management, architecture, engineering, or vulnerability management. Relevant certifications and tools knowledge, such as CRISC, CISSP, CGEIT, and experience with platforms like UpGuard, AuditBoard, SAP GRC, and ServiceNow. For more details, please reach out to Mary Pearson on - . Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
17/10/2025
Full time
Senior Cyber Security Risk Analyst Milton Keynes- 4 days per week on site £70- £85,000 + bonus + benefits My client, a leading global manufacturer based in Berkshire are actively looking for Senior Cyber Security Risk Analyst to join their dynamic team. This role is an exciting opportunity to be a part of really helping to define and shape what governance and risk assurance looks like for the organisation. This will include areas such as building out and developing their education and awareness programme as well as taking ownership over third party assurance. If you are looking for a role where you can be a part of building out something exciting, with a fantastic long term career path, then this is the role for you! Within this role you will: Lead and evolve the cybersecurity risk management framework, ensuring effective identification, assessment, and remediation of risks. Conduct detailed risk and control assessments across business units, projects, vendors, and IT systems, aligning with standards like ISO 27001, NIST CSF, and CIS Controls. Manage and enhance Third-Party Risk Management, including cybersecurity assessments of external partners and suppliers. Collaborate with stakeholders to develop and track cyber risk treatment plans, implement corrective actions, and report on key risk indicators and control effectiveness. Drive continuous improvement of cybersecurity policies and practices, while fostering strong relationships to embed a risk-aware culture across the organisation. Experience you will have: Expertise in cybersecurity risk frameworks and compliance, including CIS Controls, ISO 27001, NIST CSF, GDPR, SOX, and PCI. Strong technical and analytical skills, with the ability to assess risks, identify gaps, and propose mitigation strategies across IT systems and third parties. Excellent communication and stakeholder management, including experience presenting risk insights to senior leadership and working across technical and business teams. Proven experience in cybersecurity disciplines, ideally 5-7 years in roles covering risk management, architecture, engineering, or vulnerability management. Relevant certifications and tools knowledge, such as CRISC, CISSP, CGEIT, and experience with platforms like UpGuard, AuditBoard, SAP GRC, and ServiceNow. For more details, please reach out to Mary Pearson on - . Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
Are you passionate about cybersecurity and ready to take ownership of key threat detection platforms? Do you enjoy working across teams to improve security awareness and compliance? Want to make a real impact in a growing organisation? If you're confident in network defence, incident response, and stakeholder collaboration - this could be your next move. About the Role We're looking for a proactive and skilled Information Security Analyst to strengthen our cybersecurity posture. You'll manage key platforms like CyGlass and KnowBe4, coordinate with external partners including Pentest People, and support internal compliance efforts. This is a hands-on role with variety - from incident response and penetration testing coordination to user training and policy development. Key Responsibilities Security Operations & Monitoring • Manage and monitor the CyGlass network defence platform • Coordinate penetration testing and remediation with Pentest People • Investigate and respond to security alerts and incidents Cybersecurity Awareness & Training • Administer the KnowBe4 training platform • Create campaigns, track engagement, and promote user awareness Compliance & Governance • Support the DPO with GDPR and data protection compliance • Assist in developing and enforcing security policies and procedures Infrastructure Security • Collaborate with IT Infrastructure team to secure systems and networks • Conduct regular risk assessments and security reviews Vendor & Stakeholder Management • Act as primary contact for CyGlass and Pentest People • Provide regular updates to internal stakeholders on security posture Candidate Requirements Essential Skills & Experience • Experience in information security or infrastructure engineering • Strong understanding of network security and incident response • Familiarity with CyGlass, Pentest People, or similar platforms • Experience with KnowBe4 or other cybersecurity training tools • Knowledge of data protection regulations (e.g., GDPR, ISO27001) • Excellent communication and stakeholder management skills Preferred • Relevant certifications (e.g., CISSP, CISM, CompTIA Security+) Why Apply? • Own and manage key cybersecurity platforms • Collaborate with internal and external stakeholders • Support compliance and drive user awareness • Be part of a forward-thinking IT Infrastructure team
17/10/2025
Full time
Are you passionate about cybersecurity and ready to take ownership of key threat detection platforms? Do you enjoy working across teams to improve security awareness and compliance? Want to make a real impact in a growing organisation? If you're confident in network defence, incident response, and stakeholder collaboration - this could be your next move. About the Role We're looking for a proactive and skilled Information Security Analyst to strengthen our cybersecurity posture. You'll manage key platforms like CyGlass and KnowBe4, coordinate with external partners including Pentest People, and support internal compliance efforts. This is a hands-on role with variety - from incident response and penetration testing coordination to user training and policy development. Key Responsibilities Security Operations & Monitoring • Manage and monitor the CyGlass network defence platform • Coordinate penetration testing and remediation with Pentest People • Investigate and respond to security alerts and incidents Cybersecurity Awareness & Training • Administer the KnowBe4 training platform • Create campaigns, track engagement, and promote user awareness Compliance & Governance • Support the DPO with GDPR and data protection compliance • Assist in developing and enforcing security policies and procedures Infrastructure Security • Collaborate with IT Infrastructure team to secure systems and networks • Conduct regular risk assessments and security reviews Vendor & Stakeholder Management • Act as primary contact for CyGlass and Pentest People • Provide regular updates to internal stakeholders on security posture Candidate Requirements Essential Skills & Experience • Experience in information security or infrastructure engineering • Strong understanding of network security and incident response • Familiarity with CyGlass, Pentest People, or similar platforms • Experience with KnowBe4 or other cybersecurity training tools • Knowledge of data protection regulations (e.g., GDPR, ISO27001) • Excellent communication and stakeholder management skills Preferred • Relevant certifications (e.g., CISSP, CISM, CompTIA Security+) Why Apply? • Own and manage key cybersecurity platforms • Collaborate with internal and external stakeholders • Support compliance and drive user awareness • Be part of a forward-thinking IT Infrastructure team
IT Risk & Control Analyst Leading Financial InstitutionHybrid - 3 Days p/w in London£70k - £82k + Benefits + Bonus Join a leading financial institution as an AVP IT Risk & Control Analyst, where you'll play a key role in managing and enhancing technology risk frameworks, cybersecurity controls, and risk reporting. As a vital member of the IT Risk and Control team, you will lead key control testing, develop and manage risk indicators, and support monthly governance activities. Working closely with Technology and business teams, your insights will drive continuous improvement in risk management and help maintain compliance with regulatory standards. What You'll Do: Perform and report on control testing to evaluate cybersecurity and IT controls. Enhance risk frameworks and key risk indicators to support executive leadership in decision-making. Lead monthly governance activities and contribute to firm-wide risk initiatives. Collaborate with stakeholders to identify process gaps and recommend practical solutions. Communicate findings effectively to a range of audiences, including senior management. About You: Experience in IT security, risk management, or control assurance, preferably within financial services. Skilled in IT controls governance, testing, and executive-level reporting. Professional certifications such as CRISC or CISA are highly desirable. Strong analytical, communication, and stakeholder management skills. This permanent position based in Central London (3 days per week onsite, 2 days per week WFH) pays a base salary of £70k - £82k plus a performance based bonus and benefits including a 10% employer pension contribution, life insurance, income protection, critical illness cover, generous holiday allowances with options to buy/sell, private medical insurance, premier health screening and a flexible benefits portal for optional extras via salary sacrifice. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate £1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
17/10/2025
Full time
IT Risk & Control Analyst Leading Financial InstitutionHybrid - 3 Days p/w in London£70k - £82k + Benefits + Bonus Join a leading financial institution as an AVP IT Risk & Control Analyst, where you'll play a key role in managing and enhancing technology risk frameworks, cybersecurity controls, and risk reporting. As a vital member of the IT Risk and Control team, you will lead key control testing, develop and manage risk indicators, and support monthly governance activities. Working closely with Technology and business teams, your insights will drive continuous improvement in risk management and help maintain compliance with regulatory standards. What You'll Do: Perform and report on control testing to evaluate cybersecurity and IT controls. Enhance risk frameworks and key risk indicators to support executive leadership in decision-making. Lead monthly governance activities and contribute to firm-wide risk initiatives. Collaborate with stakeholders to identify process gaps and recommend practical solutions. Communicate findings effectively to a range of audiences, including senior management. About You: Experience in IT security, risk management, or control assurance, preferably within financial services. Skilled in IT controls governance, testing, and executive-level reporting. Professional certifications such as CRISC or CISA are highly desirable. Strong analytical, communication, and stakeholder management skills. This permanent position based in Central London (3 days per week onsite, 2 days per week WFH) pays a base salary of £70k - £82k plus a performance based bonus and benefits including a 10% employer pension contribution, life insurance, income protection, critical illness cover, generous holiday allowances with options to buy/sell, private medical insurance, premier health screening and a flexible benefits portal for optional extras via salary sacrifice. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate £1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
Senior Data Engineer (Python AWS SQL DBT) Cheshire to £90k Are you a data technologist looking for an opportunity to progress your career in a hands-on, impactful role with lots of ownership? You could be joining a Cybersecurity technology company and enjoying a huge range of perks and benefits from continual learning and self-development opportunities (including "buy any book" policy) through to health and well-being, enhanced paternity packages, generous holiday allowance, inclusive social events and much more. As a Senior Data Engineer you'll lead a significant data re-architecture project, with the autonomy to make the critical data architecture decisions, laying the foundations that will empower the entire business, from product and analytics through to customer intelligence and commercial growth. You'll collaborate with the business and Data Analysts to expand on and re-engineer the data pipelines, building new scalable services within a modern cloud based (AWS) environment. There's a culture of software engineering excellence, with a collaborative team environment that values knowledge sharing and continual improvement. Location: You'll join colleagues in amazing offices in Cheshire five days a week with a wide range of facilities and an array of perks including: Free lunch daily catered for by the onsite chef A range of afternoon treats and barista style coffee Onsite gym with trainer led classes including karate, yoga and sound bath, shower facilities and of course, all the latest kit to work with About you: You have experience in a similar, senior Data Engineer position You have experience of re-architecting / engineering data pipelines and services You have an indepth knowledge of SQL and Python You have strong hands-on experience of building scalable data pipelines in cloud based environments using tools such as DBT, AWS Glue, AWS Lake Formation, Apache Spark and Amazon Redshift You have a good knowledge of data modelling, ELT design patterns, data governance and security best practices You're collaborative and pragmatic with great communication skills What's in it for you: As a Senior Data Engineer you will earn a highly competitive package including: Salary to £90k 8% pension contribution Life Assurance and Income Protection Enhanced maternity / paternity packages Private Medical care for you and your family including same day GP appointments and prescriptions Flexible working hours 25 days holiday Charitable donations matching scheme and much more Apply now to find out more about this Senior Data Engineer (Python AWS SQL DBT) opportunity. At Client Server we believe in a diverse workplace that allows people to play to their strengths and continually learn. We're an equal opportunities employer whose people come from all walks of life and will never discriminate based on race, colour, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. The clients we work with share our values.
17/10/2025
Full time
Senior Data Engineer (Python AWS SQL DBT) Cheshire to £90k Are you a data technologist looking for an opportunity to progress your career in a hands-on, impactful role with lots of ownership? You could be joining a Cybersecurity technology company and enjoying a huge range of perks and benefits from continual learning and self-development opportunities (including "buy any book" policy) through to health and well-being, enhanced paternity packages, generous holiday allowance, inclusive social events and much more. As a Senior Data Engineer you'll lead a significant data re-architecture project, with the autonomy to make the critical data architecture decisions, laying the foundations that will empower the entire business, from product and analytics through to customer intelligence and commercial growth. You'll collaborate with the business and Data Analysts to expand on and re-engineer the data pipelines, building new scalable services within a modern cloud based (AWS) environment. There's a culture of software engineering excellence, with a collaborative team environment that values knowledge sharing and continual improvement. Location: You'll join colleagues in amazing offices in Cheshire five days a week with a wide range of facilities and an array of perks including: Free lunch daily catered for by the onsite chef A range of afternoon treats and barista style coffee Onsite gym with trainer led classes including karate, yoga and sound bath, shower facilities and of course, all the latest kit to work with About you: You have experience in a similar, senior Data Engineer position You have experience of re-architecting / engineering data pipelines and services You have an indepth knowledge of SQL and Python You have strong hands-on experience of building scalable data pipelines in cloud based environments using tools such as DBT, AWS Glue, AWS Lake Formation, Apache Spark and Amazon Redshift You have a good knowledge of data modelling, ELT design patterns, data governance and security best practices You're collaborative and pragmatic with great communication skills What's in it for you: As a Senior Data Engineer you will earn a highly competitive package including: Salary to £90k 8% pension contribution Life Assurance and Income Protection Enhanced maternity / paternity packages Private Medical care for you and your family including same day GP appointments and prescriptions Flexible working hours 25 days holiday Charitable donations matching scheme and much more Apply now to find out more about this Senior Data Engineer (Python AWS SQL DBT) opportunity. At Client Server we believe in a diverse workplace that allows people to play to their strengths and continually learn. We're an equal opportunities employer whose people come from all walks of life and will never discriminate based on race, colour, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. The clients we work with share our values.
Jobs - Frequently Asked Questions
Use the location filter to find IT jobs in cities like London, Manchester, Birmingham, and across the UK.
Entry-level roles include IT support technician, junior developer, QA tester, and helpdesk analyst.
New jobs are posted daily. Set up alerts to be notified as soon as new roles match your preferences.
Key skills include problem-solving, coding, cloud computing, networking, and familiarity with tools like AWS or SQL.
Yes, many employers offer training or junior roles. Focus on building a strong CV with relevant coursework or personal projects.