it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

81 jobs found

Email me jobs like this
Refine Search
Current Search
senior security operations lead soc threat response
Senior SOC Analyst: Threat Hunting & Incident Response
iomart Group Marlow, Buckinghamshire
iomart Group's Atech division is seeking an experienced Level 3 SOC Analyst to join our Security Operations Centre. This senior role leads investigations, conducts threat hunting and mentors junior analysts to raise technical capability. You'll detect, analyse and respond to security incidents across endpoints, cloud and identity, reconstruct attack activity from multiple telemetry sources, and provide clear reports and recommendations to customers. A hybrid remote working model is available.
27/07/2026
Full time
iomart Group's Atech division is seeking an experienced Level 3 SOC Analyst to join our Security Operations Centre. This senior role leads investigations, conducts threat hunting and mentors junior analysts to raise technical capability. You'll detect, analyse and respond to security incidents across endpoints, cloud and identity, reconstruct attack activity from multiple telemetry sources, and provide clear reports and recommendations to customers. A hybrid remote working model is available.
SOC Analyst L3
iomart Group Marlow, Buckinghamshire
What you'll be doing: At Atech, we believe cyber security is about more than reacting to threats - it's about staying ahead of them. As a leading provider of cloud, cyber security and managed services, we help organisations strengthen their security posture through innovation, expertise and a customer-first approach. We're looking for an experienced Level 3 SOC Analyst to join our growing Security Operations Centre (SOC). This is a senior technical role where you'll lead complex investigations, conduct advanced threat hunting activities and help shape the future of our SOC capability. You'll act as a technical authority during major security incidents while mentoring colleagues and driving continuous improvement across our security services. As a Level 3 SOC Analyst, you'll be: Leading complex cyber security incidents from initial investigation through to containment, eradication and recovery. Acting as the technical escalation point for high-priority and complex security events. Conducting advanced threat hunting activities across endpoint, cloud, identity and email environments. Correlating multiple telemetry sources to reconstruct attack chains, identify root causes and determine remediation actions. Providing clear and confident communication to customers and stakeholders during major security incidents. Developing and enhancing detection use cases, analytics and alert tuning within Microsoft Sentinel and Microsoft Defender XDR. Identifying opportunities to improve SOC processes, standards, tooling and operational maturity. Producing high-quality incident reports, lessons learned documentation and technical recommendations. Mentoring and coaching Level 1 and Level 2 SOC Analysts, helping to raise technical capability across the team. Supporting vulnerability assessment and security posture improvement activities when required. Collaborating with internal and customer technical teams to coordinate effective incident response and recovery. We want to hear from you if you: Have significant experience working within a Security Operations Centre environment. Possess advanced hands-on expertise with Microsoft Sentinel, Microsoft Defender XDR and Microsoft Entra ID Protection. Have a strong background in threat hunting, incident response and cyber security investigations. Can analyse and correlate data from multiple telemetry sources to uncover threats and reconstruct attack activity. Are confident leading major incidents and providing technical direction under pressure. Have experience improving detection logic, tuning security tools and enhancing SOC effectiveness. Can communicate complex technical information clearly to both technical and non-technical audiences. Enjoy mentoring others and sharing knowledge to develop team capability. Demonstrate a proactive, analytical and continuous improvement mindset. Must hold Microsoft SC-200 Desirable Certifications SC-300 or SC-400 Microsoft AZ-500 GIAC GCIA, GCFA or GCED CREST CRT or CCT Other advanced cloud or cyber security certifications What's in it for me? Competitive salary and benefits package. Flexible hybrid working model with remote working opportunities. Exposure to a broad range of cyber security technologies and customer environments. Opportunity to work on complex and high-impact security incidents. Ongoing learning, certification and professional development support. Clear career progression within a growing cyber security practice. A collaborative and supportive team environment where knowledge sharing is encouraged. The opportunity to influence SOC maturity, service innovation and security outcomes for our customers. Who you'll be doing it for: Atech part of the Iomart Group is a highly accredited Microsoft Partner who delivers transformed technology with managed services. Our team of certified Microsoft experts align with your team to deliver an excellent service tailored to your individual needs, 24/7/365. Our services support 25,000 users globally and proactively monitor 45,000+ devices in key areas: Azure infrastructure managed service Modern Workplace: Office 365, Microsoft 365, and Azure Virtual Desktop Managed Security and SOC with Microsoft Defender, Sentinel We're an equal opportunities employer and want our vacancies to be available to all, so if you need us to make any reasonable adjustments during the process then just let us know.
27/07/2026
Full time
What you'll be doing: At Atech, we believe cyber security is about more than reacting to threats - it's about staying ahead of them. As a leading provider of cloud, cyber security and managed services, we help organisations strengthen their security posture through innovation, expertise and a customer-first approach. We're looking for an experienced Level 3 SOC Analyst to join our growing Security Operations Centre (SOC). This is a senior technical role where you'll lead complex investigations, conduct advanced threat hunting activities and help shape the future of our SOC capability. You'll act as a technical authority during major security incidents while mentoring colleagues and driving continuous improvement across our security services. As a Level 3 SOC Analyst, you'll be: Leading complex cyber security incidents from initial investigation through to containment, eradication and recovery. Acting as the technical escalation point for high-priority and complex security events. Conducting advanced threat hunting activities across endpoint, cloud, identity and email environments. Correlating multiple telemetry sources to reconstruct attack chains, identify root causes and determine remediation actions. Providing clear and confident communication to customers and stakeholders during major security incidents. Developing and enhancing detection use cases, analytics and alert tuning within Microsoft Sentinel and Microsoft Defender XDR. Identifying opportunities to improve SOC processes, standards, tooling and operational maturity. Producing high-quality incident reports, lessons learned documentation and technical recommendations. Mentoring and coaching Level 1 and Level 2 SOC Analysts, helping to raise technical capability across the team. Supporting vulnerability assessment and security posture improvement activities when required. Collaborating with internal and customer technical teams to coordinate effective incident response and recovery. We want to hear from you if you: Have significant experience working within a Security Operations Centre environment. Possess advanced hands-on expertise with Microsoft Sentinel, Microsoft Defender XDR and Microsoft Entra ID Protection. Have a strong background in threat hunting, incident response and cyber security investigations. Can analyse and correlate data from multiple telemetry sources to uncover threats and reconstruct attack activity. Are confident leading major incidents and providing technical direction under pressure. Have experience improving detection logic, tuning security tools and enhancing SOC effectiveness. Can communicate complex technical information clearly to both technical and non-technical audiences. Enjoy mentoring others and sharing knowledge to develop team capability. Demonstrate a proactive, analytical and continuous improvement mindset. Must hold Microsoft SC-200 Desirable Certifications SC-300 or SC-400 Microsoft AZ-500 GIAC GCIA, GCFA or GCED CREST CRT or CCT Other advanced cloud or cyber security certifications What's in it for me? Competitive salary and benefits package. Flexible hybrid working model with remote working opportunities. Exposure to a broad range of cyber security technologies and customer environments. Opportunity to work on complex and high-impact security incidents. Ongoing learning, certification and professional development support. Clear career progression within a growing cyber security practice. A collaborative and supportive team environment where knowledge sharing is encouraged. The opportunity to influence SOC maturity, service innovation and security outcomes for our customers. Who you'll be doing it for: Atech part of the Iomart Group is a highly accredited Microsoft Partner who delivers transformed technology with managed services. Our team of certified Microsoft experts align with your team to deliver an excellent service tailored to your individual needs, 24/7/365. Our services support 25,000 users globally and proactively monitor 45,000+ devices in key areas: Azure infrastructure managed service Modern Workplace: Office 365, Microsoft 365, and Azure Virtual Desktop Managed Security and SOC with Microsoft Defender, Sentinel We're an equal opportunities employer and want our vacancies to be available to all, so if you need us to make any reasonable adjustments during the process then just let us know.
Security Operations Technical Lead
慨正橡扯 Manchester, Lancashire
Job Description To support the Head of Security Operations in delivering effective day-to-day security operations, ensuring AJ Bell maintains the appropriate capability to detect, investigate and respond to security events and incidents. The Security Operations Technical Lead is responsible for ensuring that security operations activities are executed efficiently, consistently and in line with defined SLAs and operational standards, through hands on technical leadership across SOC, Incident Response, Threat Intelligence, Insider Risk and Vulnerability Management. This role acts as a senior technical escalation point, supporting complex investigations and driving improvements in detection, response, automation and operational processes. The role holder is expected to lead through expertise, supporting analysts and ensuring Security Operations operates with discipline, quality and continuous improvement. The key responsibilities of the role are: Act as the primary technical escalation point for security events and incidents identified by the Security Operations team. Support the Head of Security Operations in ensuring AJ Bell has the appropriate capability to detect and respond to security events and incidents. Oversee the day to day execution of security operations, ensuring alerts and incidents are handled in line with defined processes and SLAs. Ensure security operations SLAs and OLAs are met, including alert triage, escalation and incident response timelines, highlighting and addressing risks where required. Ensure adherence to our KRI and KPI's and any variation in these are raised to the Head of Security Operations. Provide hands on support in the investigation and response to security incidents, including endpoint, identity, network, cloud and insider related threats. Ensure consistent execution and continuous improvement of incident response playbooks and operational runbooks, validating them through real incidents and simulations. Support the optimisation and tuning of security monitoring and detection capabilities, including SIEM and endpoint tooling, to improve signal quality and reduce false positives. Support the execution of the end to end vulnerability management process, including validation of findings and tracking remediation activities. Work closely with MSSP and security vendors to ensure effective delivery of security operations services. Challenge and validate vendor outputs, driving operational efficiency, quality improvements and better use of tooling capabilities. Actively design and implement automation and orchestration to reduce manual effort, repetitive or high volume tasks, improve response times and increase consistency across security operations processes. Work with the Security Engineering team to ensure tooling, logging and detection gaps are identified and addressed. Support the effective operation of 24x7 security monitoring, including coordination with third party providers. Contribute to the development and delivery of operational MI and reporting, ensuring accuracy and insight into security trends and performance. Maintain visibility of security incidents, trends and operational risks, escalating issues where required. Technical Skills: Strong hands on experience of Security Operations tools and capabilities, including SIEM and SOAR platforms (e.g. Sentinel, ServiceNow, Splunk SOAR, Cortex), Endpoint Detection & Response (EDR/XDR), Strong hands on experience of Threat Intelligence platforms (e.g. Recorded Future, Doppel, ZeroFox, Google Threat Intelligence), Vulnerability management solutions (e.g. Tenable, Rapid7), and Insider Risk and DLP tools (e.g. Purview, Netskope). Strong hands on experience with Network security solutions like Next Gen Firewalls, Network Anomaly, WAF & DDoS solutions. Experience of leading and responding to Cyber Incident Response aligned to NIST Knowledge of threat detection techniques and use case development Experience of applying threat intelligence in an operational context Strong experience with vulnerability management tools and processes Strong awareness of cloud services and supporting security controls and monitoring capabilities Working knowledge of Microsoft security stack (Defender, Sentinel, Purview), Active Directory and Azure AD, Windows and Linux environments. Experience with data loss prevention and insider risk tooling advantageous Hands on experience with automation and scripting (e.g. PowerShell, Python) highly desirable Competence Experience working within recognised Information Security frameworks and best practices such as ISO27001, NIST, MITRE ATT&CK Knowledge of relevant regulatory requirements (e.g. GDPR, FCA/PRA) Experience in an Information Security role gained in a financial services environment preferred Experience working in a Security Operations role for a minimum 7 years and operating within a Lead / Senior Analyst role for at least 3 years. Knowledge & Skills Strong analytical and investigative capability Ability to work under pressure and manage multiple concurrent incidents and priorities Strong ownership of tasks, attention to detail and follow through to conclusion Ability to provide technical leadership without formal line management responsibility Ability to challenge approach, tooling and processes to improve operational effectiveness Structured, self starting and able to work under own initiative Effective communication skills, both written and verbal Ability to plan, organise and deliver tasks with minimal supervision Collaborative approach to working with analysts, engineering teams and external partners Strong focus on quality, consistency and continuous improvement About AJ Bell At AJ Bell, we believe investing should feel good. Whether you're looking for an ISA, pension or dealing account, whether you want to invest with the help of a financial adviser or do it yourself, we have easy to use solutions to suit people from all walks of life. We're one of the UK's fastest growing investment platform businesses, trusted by everyone from professional financial advisers to first time investors. Today, over 723,000 customers trust us to manage more than £108.7 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures. We're proud to be recognised as one of the UK's Best 100 Companies to Work For for six consecutive years, and a Great Place to Work in 2025 and 2026, a reflection of our supportive and collaborative culture. What we offer Competitive starting salary 26days holiday, increasing with service + buy/sell scheme + bank holidays 7% Pension with matched contributions Discretionary bonus scheme Share schemes (including free shares and BAYE) Health Cash Plan and discounted private healthcare Free gym Enhanced family leave (subject to qualifying criteria) Travel and bike loan schemes Employee Assistance Programme Life at AJ Bell Regular social events including summer and Christmas parties Learning and development opportunities tailored to you Casual dress code Friendly, supportive team environment Our ways of working At AJ Bell, our people are the heart of our culture. We believe in building strong connections by working together. That's why we offer a hybrid working model, where you'll spend a minimum of 50% of working time per month in the office. For new team members, an initial period will be spent full time in the office to help you immerse yourself in our business and build valuable relationships with your colleagues. Inclusion & diversity We're committed to creating an inclusive environment where everyone feels respected, supported and able to be themselves at work. We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential. Agency information This vacancy is being managed exclusively by our in house Recruitment team. We are not partnering with recruitment agencies on this opportunity and will only accept applications submitted directly by candidates
27/07/2026
Full time
Job Description To support the Head of Security Operations in delivering effective day-to-day security operations, ensuring AJ Bell maintains the appropriate capability to detect, investigate and respond to security events and incidents. The Security Operations Technical Lead is responsible for ensuring that security operations activities are executed efficiently, consistently and in line with defined SLAs and operational standards, through hands on technical leadership across SOC, Incident Response, Threat Intelligence, Insider Risk and Vulnerability Management. This role acts as a senior technical escalation point, supporting complex investigations and driving improvements in detection, response, automation and operational processes. The role holder is expected to lead through expertise, supporting analysts and ensuring Security Operations operates with discipline, quality and continuous improvement. The key responsibilities of the role are: Act as the primary technical escalation point for security events and incidents identified by the Security Operations team. Support the Head of Security Operations in ensuring AJ Bell has the appropriate capability to detect and respond to security events and incidents. Oversee the day to day execution of security operations, ensuring alerts and incidents are handled in line with defined processes and SLAs. Ensure security operations SLAs and OLAs are met, including alert triage, escalation and incident response timelines, highlighting and addressing risks where required. Ensure adherence to our KRI and KPI's and any variation in these are raised to the Head of Security Operations. Provide hands on support in the investigation and response to security incidents, including endpoint, identity, network, cloud and insider related threats. Ensure consistent execution and continuous improvement of incident response playbooks and operational runbooks, validating them through real incidents and simulations. Support the optimisation and tuning of security monitoring and detection capabilities, including SIEM and endpoint tooling, to improve signal quality and reduce false positives. Support the execution of the end to end vulnerability management process, including validation of findings and tracking remediation activities. Work closely with MSSP and security vendors to ensure effective delivery of security operations services. Challenge and validate vendor outputs, driving operational efficiency, quality improvements and better use of tooling capabilities. Actively design and implement automation and orchestration to reduce manual effort, repetitive or high volume tasks, improve response times and increase consistency across security operations processes. Work with the Security Engineering team to ensure tooling, logging and detection gaps are identified and addressed. Support the effective operation of 24x7 security monitoring, including coordination with third party providers. Contribute to the development and delivery of operational MI and reporting, ensuring accuracy and insight into security trends and performance. Maintain visibility of security incidents, trends and operational risks, escalating issues where required. Technical Skills: Strong hands on experience of Security Operations tools and capabilities, including SIEM and SOAR platforms (e.g. Sentinel, ServiceNow, Splunk SOAR, Cortex), Endpoint Detection & Response (EDR/XDR), Strong hands on experience of Threat Intelligence platforms (e.g. Recorded Future, Doppel, ZeroFox, Google Threat Intelligence), Vulnerability management solutions (e.g. Tenable, Rapid7), and Insider Risk and DLP tools (e.g. Purview, Netskope). Strong hands on experience with Network security solutions like Next Gen Firewalls, Network Anomaly, WAF & DDoS solutions. Experience of leading and responding to Cyber Incident Response aligned to NIST Knowledge of threat detection techniques and use case development Experience of applying threat intelligence in an operational context Strong experience with vulnerability management tools and processes Strong awareness of cloud services and supporting security controls and monitoring capabilities Working knowledge of Microsoft security stack (Defender, Sentinel, Purview), Active Directory and Azure AD, Windows and Linux environments. Experience with data loss prevention and insider risk tooling advantageous Hands on experience with automation and scripting (e.g. PowerShell, Python) highly desirable Competence Experience working within recognised Information Security frameworks and best practices such as ISO27001, NIST, MITRE ATT&CK Knowledge of relevant regulatory requirements (e.g. GDPR, FCA/PRA) Experience in an Information Security role gained in a financial services environment preferred Experience working in a Security Operations role for a minimum 7 years and operating within a Lead / Senior Analyst role for at least 3 years. Knowledge & Skills Strong analytical and investigative capability Ability to work under pressure and manage multiple concurrent incidents and priorities Strong ownership of tasks, attention to detail and follow through to conclusion Ability to provide technical leadership without formal line management responsibility Ability to challenge approach, tooling and processes to improve operational effectiveness Structured, self starting and able to work under own initiative Effective communication skills, both written and verbal Ability to plan, organise and deliver tasks with minimal supervision Collaborative approach to working with analysts, engineering teams and external partners Strong focus on quality, consistency and continuous improvement About AJ Bell At AJ Bell, we believe investing should feel good. Whether you're looking for an ISA, pension or dealing account, whether you want to invest with the help of a financial adviser or do it yourself, we have easy to use solutions to suit people from all walks of life. We're one of the UK's fastest growing investment platform businesses, trusted by everyone from professional financial advisers to first time investors. Today, over 723,000 customers trust us to manage more than £108.7 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures. We're proud to be recognised as one of the UK's Best 100 Companies to Work For for six consecutive years, and a Great Place to Work in 2025 and 2026, a reflection of our supportive and collaborative culture. What we offer Competitive starting salary 26days holiday, increasing with service + buy/sell scheme + bank holidays 7% Pension with matched contributions Discretionary bonus scheme Share schemes (including free shares and BAYE) Health Cash Plan and discounted private healthcare Free gym Enhanced family leave (subject to qualifying criteria) Travel and bike loan schemes Employee Assistance Programme Life at AJ Bell Regular social events including summer and Christmas parties Learning and development opportunities tailored to you Casual dress code Friendly, supportive team environment Our ways of working At AJ Bell, our people are the heart of our culture. We believe in building strong connections by working together. That's why we offer a hybrid working model, where you'll spend a minimum of 50% of working time per month in the office. For new team members, an initial period will be spent full time in the office to help you immerse yourself in our business and build valuable relationships with your colleagues. Inclusion & diversity We're committed to creating an inclusive environment where everyone feels respected, supported and able to be themselves at work. We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential. Agency information This vacancy is being managed exclusively by our in house Recruitment team. We are not partnering with recruitment agencies on this opportunity and will only accept applications submitted directly by candidates
Cloud Operations Engineer
Mimecast Services Ltd
Cloud Operations Engineer Overview At Mimecast, we operate at scale-protecting billions of emails daily across a global hybrid-cloud infrastructure. If you're passionate about reliability, automation, and solving complex challenges in mission-critical environments, this is the opportunity for you. Why Join Us "This is a hands-on role in a team responsible for ensuring Mimecast's Hybrid Cloud infrastructure remains secure, resilient, and scalable. You'll work with cutting-edge technologies like Kubernetes, AWS, and Infrastructure-as-Code, all while collaborating with a supportive and talented team. If you're excited about making a real impact and growing your career in our Cloud Platform Team, I'd love to hear from you." - Hiring Manager, Cloud Platform AI-First Engineering at Mimecast Mimecast is an AI-First engineering organization. Our teams actively leverage AI-powered development tools across all facets of engineering, from code development to testing, documentation, and operations. We're looking for leaders who don't just use AI tools but champion their adoption and establish new ways of working. Our AI leadership extends beyond how we build to what we build. Our Mihra AI agent delivers 7x faster threat response for customers, and we're recognized as "Agents of Change" in Human Risk Management. Engineers here work at the intersection of cutting-edge AI tooling and AI-powered security products that protect organizations worldwide. What You'll Do: Ensure platform reliability : Configure and maintain infrastructure to ensure optimal performance, security, and availability. Manage containerization platforms : Operate and improve Kubernetes and AWS EKS to support Mimecast's microservices architecture. Automate infrastructure : Build reusable Infrastructure-as-Code (IaC) and automation to standardize infrastructure provisioning and deployment processes. Troubleshoot and resolve issues : Identify and resolve infrastructure issues across Linux and Kubernetes systems in a hybrid-cloud environment, minimizing downtime. Enhance security : Strengthen the security posture of infrastructure configurations, aligning with the latest cybersecurity standards. Improve processes : Collaborate with the team to continuously refine operational processes and documentation. Maintain observability tools : Manage and operate monitoring and observability tools like Graphite, Prometheus, Grafana, Elastic, Nagios, and LogScale. Support engineering teams : Provide exceptional support to internal Product and Engineering teams, meeting their requirements for the Mimecast Cloud Platform. Participate in on-call rotations : Support the team by participating in on-call rotations and performing out-of-hours maintenance as necessary. What You'll Bring: Technical expertise : Experience in roles such as Site Reliability Engineer (SRE), Platform Engineer, Cloud Operations, or Sys Admin. Kubernetes proficiency : Strong hands-on experience with Kubernetes (k8s) and containerization in production environments. Linux expertise : Proficiency in maintaining and troubleshooting Linux operating systems and distributed systems at scale. Infrastructure knowledge : Solid understanding of core infrastructure services such as DNS, Identity Management, load balancers, and web servers. Networking basics : Foundational knowledge of computer networking. IaC and scripting : Experience with Infrastructure-as-Code tools like Terraform/CloudFormation and configuration management tools like Puppet. Proficiency in at least one programming or scripting language. Proactive problem-solver : A proactive attitude with a willingness to take on new challenges, deliver results, and learn new technologies quickly. Collaboration skills : Outstanding communication and social skills, with the ability to connect with others and problem-solve effectively. Why This Role: Global impact : Join a cybersecurity company operating at genuine global scale, protecting organizations and their people. Engineering excellence : Be part of a Cloud Platform organization that values automation, reliability, and doing things properly. Competitive rewards : Enjoy competitive compensation as part of a broader total rewards package, including benefits and wellbeing programs. Career growth : Access opportunities to develop expertise in hybrid-cloud infrastructure, Kubernetes, and automation, with clear paths to senior engineering roles. Collaborative culture : Work alongside experienced engineers and leaders who invest in your development. Career Growth Opportunities Develop deep expertise in hybrid-cloud infrastructure, Kubernetes, and automation. Build strong Infrastructure-as-Code and automation skills in a production environment that demands them. Grow into senior engineering or team lead roles within Cloud Platform. Work alongside experienced engineers and leaders who are committed to your development. Manager's Working Style & Team's Purpose The Site Reliability Engineering team exists to ensure the reliability and resiliency of Mimecast's Hybrid Cloud infrastructure. The team's purpose is to deliver a platform that is secure, performant, and scalable, enabling Product and Engineering teams to innovate faster and deliver more value to customers. Day-to-day, you'll work in a collaborative environment, tackling complex challenges and contributing to the continuous improvement of Mimecast's infrastructure. The expectation is hands-on technical credibility combined with a proactive approach to problem-solving and teamwork. Join our Cloud Platform team to accelerate your career journey, working with cutting-edge technologies and contributing to projects that have real customer impact. You will be immersed in a dynamic environment that recognizes and celebrates your achievements. Mimecast offers formal and on the job learning opportunities, maintains a comprehensive benefits package that helps our employees and their family members to sustain a healthy lifestyle, and importantly - working in cross functional teams to build your knowledge! Our Hybrid Model: We provide you with the flexibility to live balanced, healthy lives through our hybrid working model that champions both collaborative teamwork and individual flexibility. Employees are expected to come to the office at least two days per week, because working together in person: Fosters a culture of collaboration, communication, performance and learning. Drives innovation and creativity within and between teams. Introduces employees to priorities outside of their immediate realm. Ensures important interpersonal relationships and connections with one another and our community! The base salary range for this position is £64,000 £96,000 plus benefits. This range represents the minimum and maximum new hire compensation for this role. The position may also be eligible for incentive plans and additional benefits, in accordance with company policy and local regulations. Our salary ranges are determined by role, level, and location with individual compensation also dependent on factors such as qualifications, experience, and skills. Final offers will reflect these considerations and may vary accordingly. Belonging at Mimecast Cybersecurity is a community effort. That's why we're committed to building an inclusive, diverse community that celebrates and welcomes everyone - unless they're a cybercriminal, of course. We're proud to be an Equal Opportunity and Affirmative Action Employer, and we'd encourage you to join us whatever your background. We particularly welcome applicants from traditionally underrepresented groups. We consider everyone equally: your race, age, religion, sexual orientation, gender identity, ability, marital status, nationality, or any other protected characteristic won't affect your application. Due to certain obligations to our customers, an offer of employment will be subject to your successful completion of applicable background checks, conducted in accordance with local law. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment.
27/07/2026
Full time
Cloud Operations Engineer Overview At Mimecast, we operate at scale-protecting billions of emails daily across a global hybrid-cloud infrastructure. If you're passionate about reliability, automation, and solving complex challenges in mission-critical environments, this is the opportunity for you. Why Join Us "This is a hands-on role in a team responsible for ensuring Mimecast's Hybrid Cloud infrastructure remains secure, resilient, and scalable. You'll work with cutting-edge technologies like Kubernetes, AWS, and Infrastructure-as-Code, all while collaborating with a supportive and talented team. If you're excited about making a real impact and growing your career in our Cloud Platform Team, I'd love to hear from you." - Hiring Manager, Cloud Platform AI-First Engineering at Mimecast Mimecast is an AI-First engineering organization. Our teams actively leverage AI-powered development tools across all facets of engineering, from code development to testing, documentation, and operations. We're looking for leaders who don't just use AI tools but champion their adoption and establish new ways of working. Our AI leadership extends beyond how we build to what we build. Our Mihra AI agent delivers 7x faster threat response for customers, and we're recognized as "Agents of Change" in Human Risk Management. Engineers here work at the intersection of cutting-edge AI tooling and AI-powered security products that protect organizations worldwide. What You'll Do: Ensure platform reliability : Configure and maintain infrastructure to ensure optimal performance, security, and availability. Manage containerization platforms : Operate and improve Kubernetes and AWS EKS to support Mimecast's microservices architecture. Automate infrastructure : Build reusable Infrastructure-as-Code (IaC) and automation to standardize infrastructure provisioning and deployment processes. Troubleshoot and resolve issues : Identify and resolve infrastructure issues across Linux and Kubernetes systems in a hybrid-cloud environment, minimizing downtime. Enhance security : Strengthen the security posture of infrastructure configurations, aligning with the latest cybersecurity standards. Improve processes : Collaborate with the team to continuously refine operational processes and documentation. Maintain observability tools : Manage and operate monitoring and observability tools like Graphite, Prometheus, Grafana, Elastic, Nagios, and LogScale. Support engineering teams : Provide exceptional support to internal Product and Engineering teams, meeting their requirements for the Mimecast Cloud Platform. Participate in on-call rotations : Support the team by participating in on-call rotations and performing out-of-hours maintenance as necessary. What You'll Bring: Technical expertise : Experience in roles such as Site Reliability Engineer (SRE), Platform Engineer, Cloud Operations, or Sys Admin. Kubernetes proficiency : Strong hands-on experience with Kubernetes (k8s) and containerization in production environments. Linux expertise : Proficiency in maintaining and troubleshooting Linux operating systems and distributed systems at scale. Infrastructure knowledge : Solid understanding of core infrastructure services such as DNS, Identity Management, load balancers, and web servers. Networking basics : Foundational knowledge of computer networking. IaC and scripting : Experience with Infrastructure-as-Code tools like Terraform/CloudFormation and configuration management tools like Puppet. Proficiency in at least one programming or scripting language. Proactive problem-solver : A proactive attitude with a willingness to take on new challenges, deliver results, and learn new technologies quickly. Collaboration skills : Outstanding communication and social skills, with the ability to connect with others and problem-solve effectively. Why This Role: Global impact : Join a cybersecurity company operating at genuine global scale, protecting organizations and their people. Engineering excellence : Be part of a Cloud Platform organization that values automation, reliability, and doing things properly. Competitive rewards : Enjoy competitive compensation as part of a broader total rewards package, including benefits and wellbeing programs. Career growth : Access opportunities to develop expertise in hybrid-cloud infrastructure, Kubernetes, and automation, with clear paths to senior engineering roles. Collaborative culture : Work alongside experienced engineers and leaders who invest in your development. Career Growth Opportunities Develop deep expertise in hybrid-cloud infrastructure, Kubernetes, and automation. Build strong Infrastructure-as-Code and automation skills in a production environment that demands them. Grow into senior engineering or team lead roles within Cloud Platform. Work alongside experienced engineers and leaders who are committed to your development. Manager's Working Style & Team's Purpose The Site Reliability Engineering team exists to ensure the reliability and resiliency of Mimecast's Hybrid Cloud infrastructure. The team's purpose is to deliver a platform that is secure, performant, and scalable, enabling Product and Engineering teams to innovate faster and deliver more value to customers. Day-to-day, you'll work in a collaborative environment, tackling complex challenges and contributing to the continuous improvement of Mimecast's infrastructure. The expectation is hands-on technical credibility combined with a proactive approach to problem-solving and teamwork. Join our Cloud Platform team to accelerate your career journey, working with cutting-edge technologies and contributing to projects that have real customer impact. You will be immersed in a dynamic environment that recognizes and celebrates your achievements. Mimecast offers formal and on the job learning opportunities, maintains a comprehensive benefits package that helps our employees and their family members to sustain a healthy lifestyle, and importantly - working in cross functional teams to build your knowledge! Our Hybrid Model: We provide you with the flexibility to live balanced, healthy lives through our hybrid working model that champions both collaborative teamwork and individual flexibility. Employees are expected to come to the office at least two days per week, because working together in person: Fosters a culture of collaboration, communication, performance and learning. Drives innovation and creativity within and between teams. Introduces employees to priorities outside of their immediate realm. Ensures important interpersonal relationships and connections with one another and our community! The base salary range for this position is £64,000 £96,000 plus benefits. This range represents the minimum and maximum new hire compensation for this role. The position may also be eligible for incentive plans and additional benefits, in accordance with company policy and local regulations. Our salary ranges are determined by role, level, and location with individual compensation also dependent on factors such as qualifications, experience, and skills. Final offers will reflect these considerations and may vary accordingly. Belonging at Mimecast Cybersecurity is a community effort. That's why we're committed to building an inclusive, diverse community that celebrates and welcomes everyone - unless they're a cybercriminal, of course. We're proud to be an Equal Opportunity and Affirmative Action Employer, and we'd encourage you to join us whatever your background. We particularly welcome applicants from traditionally underrepresented groups. We consider everyone equally: your race, age, religion, sexual orientation, gender identity, ability, marital status, nationality, or any other protected characteristic won't affect your application. Due to certain obligations to our customers, an offer of employment will be subject to your successful completion of applicable background checks, conducted in accordance with local law. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment.
BAE Systems
Senior SOC Analyst - Leeds
BAE Systems Leeds, Yorkshire
Location(s):UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123212 Location: Leeds Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
26/07/2026
Full time
Location(s):UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123212 Location: Leeds Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
BAE Systems
Senior SOC Analyst & Shift Lead - Hybrid (Leeds)
BAE Systems Leeds, Yorkshire
BAE Systems Digital Intelligence in Leeds seeks a Senior SOC Analyst and Shift Lead to join our 24/7 security operations team. You will monitor and investigate incidents across Azure and AWS hosted networks, working with a blended customer and BAE staff team from our Leeds office. The role requires a minimum of security clearance and will support threat intelligence and incident response activities. Initial terms include 6- and 12-month contracts with potential extensions.
26/07/2026
Full time
BAE Systems Digital Intelligence in Leeds seeks a Senior SOC Analyst and Shift Lead to join our 24/7 security operations team. You will monitor and investigate incidents across Azure and AWS hosted networks, working with a blended customer and BAE staff team from our Leeds office. The role requires a minimum of security clearance and will support threat intelligence and incident response activities. Initial terms include 6- and 12-month contracts with potential extensions.
Senior SOC Analyst - Leeds
慨正橡扯 Leeds, Yorkshire
Location(s):UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123212 Location: Leeds Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
26/07/2026
Full time
Location(s):UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123212 Location: Leeds Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
BAE Systems
Senior SOC Analyst - Manchester
BAE Systems Manchester, Lancashire
Location(s):UK, Europe & Africa : UK : Manchester BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123208 Location: Manchester Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
26/07/2026
Full time
Location(s):UK, Europe & Africa : UK : Manchester BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123208 Location: Manchester Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
Senior Security Architect - SecOps and Vulnerability Management
JPMorgan Chase & Co.
Join us to directly influence the future of technology at JPMorganChase. As a Senior Security Architect - SecOps and Vulnerability Management, you'll collaborate with top cybersecurity and engineering talent, solving complex challenges and enabling safe, secure innovation. Your passion for security and drive to make a real impact are valued here. Grow your skills in a dynamic environment designed for achievers. Help us build products that prioritize security from the start. Job Summary: As a Senior Security Architect - SecOps and Vulnerability Management in the Cybersecurity & Technology Controls team for International Consumer, you will proactively partner with technology and business colleagues to identify and address security issues. You will embed security culture, lead threat modeling, and drive architecture reviews to ensure our products are secure by design. Your role will be pivotal in managing emerging risks, influencing product strategy, and serving as the subject matter expert for the SecOps and Vulnerability Management strategy as well as embedding detection and response capabilities on a modern technology stack. You will collaborate globally, supporting audit, regulatory, and risk initiatives, with a focus on cloud computing and emerging technologies. Job Responsibilities: Design, scale, and manage the enterprise SIEM architecture to provide centralized visibility and high-fidelity threat detection across all corporate and cloud infrastructure. Develop and influence advanced SIEM correlation rules, custom data parsers, and detection logic to significantly minimize alert fatigue for the SOC team. Architect the end-to-end SBOM lifecycle to continuously track, analyze, and mitigate open-source and third-party software supply chain risks. Design a risk-based vulnerability management platform that automatically prioritizes infrastructure and application flaws utilizing real-world exploit intelligence and asset criticality. Build and optimize SOAR playbooks to automate incident response workflows, accelerate threat containment, and streamline vulnerability ticketing. Provide senior technical escalation support during critical security incidents and drive post-incident root-cause analysis to continuously improve defensive controls. Cultivate a security-first culture across product, technology, and business teams by providing developer-friendly tooling, training, and reusable secure patterns that accelerate rather than hinder delivery. Act with urgency to manage emerging security issues, monitor risk indicators, and recommend resolutions. Serve as the escalation point for IT Risk and Cyber domains related to Cybersecurity Operations and Vulnerability Management. Partner with engineering leads, product owners, and vendors to ensure effective technology risk management, translating regulatory and policy requirements into actionable, engineer-friendly controls. Support audit, regulatory, and risk activities by providing evidence of control effectiveness and translating compliance requirements into automated, repeatable processes. Identify and address unfamiliar technology components, share best practices, and influence peers to drive continuous improvement in SecOps and Vulnerability Management maturity across the organization. Uses enterprise-authorized AI capabilities within the work environment to accelerate cybersecurity risk analysis and control assessment, validating outputs and handling data according to sensitivity and security requirements. Drives reuse-first adoption of AI-assisted security validation within SDLC/toolchain routines, improving control testing, remediation quality, and traceability/auditability in line with resiliency expectations. Required Qualifications, Capabilities, and Skills: Hands-on experience advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps). Must be proficient in writing/reviewing advanced detection logic (KQL, SPL, or YARA rules). Deep execution knowledge of generating, managing, and analyzing Software Bills of Materials (SBOMs using frameworks like CycloneDX or SPDX) and integrating them with tools like Dependency-Track or Snyk to track open-source vulnerabilities. Advanced threat modeling experience (e.g., STRIDE-LM) for SIEM data flows, log ingestion pipelines, and vulnerability management platforms Experience architecting vulnerability programs using tools like Tenable, Qualys, or Wiz, specifically utilizing EPSS (Exploit Prediction Scoring System) alongside CVSS to determine patching prioritisation. Ability to design and influence automated response playbooks using SOAR platforms Practical experience creating reference architectures and patterns for engineering teams. Proven ability to design and deploy automated preventive and detective guardrails at scale. Ability to solve design and functionality problems independently. Strong written and verbal communication skills. Demonstrated success in influencing peers and stakeholders. Ability to evaluate and recommend emerging technologies for future state architecture. Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support cybersecurity architecture workflows with strong validation habits and awareness of data sensitivity. Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations. Preferred Qualifications, Capabilities, and Skills: Experience deploying AI-native capabilities within Google SecOps, leveraging Gemini-powered intelligence and ML-based anomaly detection to enhance UEBA and accelerate SOC triage at scale. Experience partnering with Red/Purple Teams to simulate attacks and actively validate that SIEM rules fire as intended. The ability to identify thematic vulnerability trends and common denominators to drive highest-impact, lowest-effort Vulnerability remediation. Experience operating in regulated organizations with a 3LoD model. Willingness to challenge existing processes respectfully. Experience translating policy and regulatory requirements into control design for engineers and architects. Proven ability to upskill and learn modern technologies. Experience in financial services consumer businesses or Fintech organizations.
26/07/2026
Full time
Join us to directly influence the future of technology at JPMorganChase. As a Senior Security Architect - SecOps and Vulnerability Management, you'll collaborate with top cybersecurity and engineering talent, solving complex challenges and enabling safe, secure innovation. Your passion for security and drive to make a real impact are valued here. Grow your skills in a dynamic environment designed for achievers. Help us build products that prioritize security from the start. Job Summary: As a Senior Security Architect - SecOps and Vulnerability Management in the Cybersecurity & Technology Controls team for International Consumer, you will proactively partner with technology and business colleagues to identify and address security issues. You will embed security culture, lead threat modeling, and drive architecture reviews to ensure our products are secure by design. Your role will be pivotal in managing emerging risks, influencing product strategy, and serving as the subject matter expert for the SecOps and Vulnerability Management strategy as well as embedding detection and response capabilities on a modern technology stack. You will collaborate globally, supporting audit, regulatory, and risk initiatives, with a focus on cloud computing and emerging technologies. Job Responsibilities: Design, scale, and manage the enterprise SIEM architecture to provide centralized visibility and high-fidelity threat detection across all corporate and cloud infrastructure. Develop and influence advanced SIEM correlation rules, custom data parsers, and detection logic to significantly minimize alert fatigue for the SOC team. Architect the end-to-end SBOM lifecycle to continuously track, analyze, and mitigate open-source and third-party software supply chain risks. Design a risk-based vulnerability management platform that automatically prioritizes infrastructure and application flaws utilizing real-world exploit intelligence and asset criticality. Build and optimize SOAR playbooks to automate incident response workflows, accelerate threat containment, and streamline vulnerability ticketing. Provide senior technical escalation support during critical security incidents and drive post-incident root-cause analysis to continuously improve defensive controls. Cultivate a security-first culture across product, technology, and business teams by providing developer-friendly tooling, training, and reusable secure patterns that accelerate rather than hinder delivery. Act with urgency to manage emerging security issues, monitor risk indicators, and recommend resolutions. Serve as the escalation point for IT Risk and Cyber domains related to Cybersecurity Operations and Vulnerability Management. Partner with engineering leads, product owners, and vendors to ensure effective technology risk management, translating regulatory and policy requirements into actionable, engineer-friendly controls. Support audit, regulatory, and risk activities by providing evidence of control effectiveness and translating compliance requirements into automated, repeatable processes. Identify and address unfamiliar technology components, share best practices, and influence peers to drive continuous improvement in SecOps and Vulnerability Management maturity across the organization. Uses enterprise-authorized AI capabilities within the work environment to accelerate cybersecurity risk analysis and control assessment, validating outputs and handling data according to sensitivity and security requirements. Drives reuse-first adoption of AI-assisted security validation within SDLC/toolchain routines, improving control testing, remediation quality, and traceability/auditability in line with resiliency expectations. Required Qualifications, Capabilities, and Skills: Hands-on experience advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps). Must be proficient in writing/reviewing advanced detection logic (KQL, SPL, or YARA rules). Deep execution knowledge of generating, managing, and analyzing Software Bills of Materials (SBOMs using frameworks like CycloneDX or SPDX) and integrating them with tools like Dependency-Track or Snyk to track open-source vulnerabilities. Advanced threat modeling experience (e.g., STRIDE-LM) for SIEM data flows, log ingestion pipelines, and vulnerability management platforms Experience architecting vulnerability programs using tools like Tenable, Qualys, or Wiz, specifically utilizing EPSS (Exploit Prediction Scoring System) alongside CVSS to determine patching prioritisation. Ability to design and influence automated response playbooks using SOAR platforms Practical experience creating reference architectures and patterns for engineering teams. Proven ability to design and deploy automated preventive and detective guardrails at scale. Ability to solve design and functionality problems independently. Strong written and verbal communication skills. Demonstrated success in influencing peers and stakeholders. Ability to evaluate and recommend emerging technologies for future state architecture. Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support cybersecurity architecture workflows with strong validation habits and awareness of data sensitivity. Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations. Preferred Qualifications, Capabilities, and Skills: Experience deploying AI-native capabilities within Google SecOps, leveraging Gemini-powered intelligence and ML-based anomaly detection to enhance UEBA and accelerate SOC triage at scale. Experience partnering with Red/Purple Teams to simulate attacks and actively validate that SIEM rules fire as intended. The ability to identify thematic vulnerability trends and common denominators to drive highest-impact, lowest-effort Vulnerability remediation. Experience operating in regulated organizations with a 3LoD model. Willingness to challenge existing processes respectfully. Experience translating policy and regulatory requirements into control design for engineers and architects. Proven ability to upskill and learn modern technologies. Experience in financial services consumer businesses or Fintech organizations.
Senior Identity Protection Specialist
FUJIFILM Holdings America Corporation
Position Overview Protect identities at global scale. We're hiring a hands on Senior Identity Protection Engineer/Specialist to lead detection, investigation, and response for identity based threats across Microsoft Entra ID/Azure AD, on prem Active Directory, and connected SaaS/IaaS. You'll serve as the enterprise SME/administrator for CrowdStrike Identity Protection, tune high fidelity detections, integrate dark web intelligence, and orchestrate automation that measurably reduces MTTD/MTTR and risk. What you'll do Lead identity threat monitoring and triage Operate and tune CrowdStrike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks like impossible travel, atypical sign ins, MFA fatigue, and session hijacking Validate true/false positives, prioritize by business impact, and escalate per playbooks/SLAs Drive rapid containment and remediation Execute containment actions (disable accounts, revoke sessions/tokens, isolate hosts) Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closure Own identity focused incident response Lead IR for credential compromise, privilege escalation, directory persistence, and lateral movement Ensure evidence handling, root cause analysis, post incident reviews, and lessons learned Engineer detections and hunt for threats Build and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CK Close visibility gaps, reduce false positives, and expand privileged activity monitoring Strengthen privileged access controls Detect anomalous privileged behavior via SIEM/UEBA and Netskope telemetry Recommend/enforce JIT, break glass patterns, and mover/leaver privilege hygiene with IAM Respond to dark web/credential exposure Integrate sources like CyberInt; assess exposure and targeted campaigns Orchestrate takedowns, forced resets, token revocation, and Conditional Access updates Administer platforms and sustain hygiene Maintain coverage/health for identity monitoring; manage upgrades and changes via CAB Keep operational runbooks, SOPs, and playbooks current Automate and orchestrate at scale Use PowerShell/Python and REST/Graph/CrowdStrike APIs (and SOAR where applicable) to automate enrichment and response, standardize workflows, and improve signal fidelity Shape identity policy and controls Advise on Conditional Access, MFA exceptions, SSO/SCIM patterns, and session controls under the shared responsibility model with IAM Report outcomes and support audits Produce executive ready dashboards and KPIs (identity incident volume, MTTD/MTTR, CA/MFA efficacy, exposure/takedown cycle time) Maintain audit ready evidence and support internal/external audits What you'll bring Bachelor's degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience 8+ years in IT/cybersecurity, including 3-5+ years focused on identity security/operations (Entra ID/Azure AD, on prem AD, MFA, Conditional Access, SSO/SCIM) Hands on enterprise experience administering/operating CrowdStrike Identity Protection Proficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms (e.g., Netskope) for identity telemetry, detection, and investigations Demonstrated experience in identity centric IR, threat hunting, and detection engineering (KQL/SQL/regex/Sigma) Scripting/automation with PowerShell and Python; experience with REST/Graph/CrowdStrike APIs and SOAR Clear communication and documentation skills; comfortable producing executive ready reports and audit evidence Operates effectively within change control/CAB and under pressure during high severity incidents Bonus points Certifications: Microsoft SC 200/SC 300; Okta Certified Administrator/Professional; CISSP, SSCP, Security+; GIAC (GMON, GCIH, GCDA) or equivalent Deep knowledge of identity attack paths and protocols (Kerberos/NTLM), token/session abuse, and persistence techniques (e.g., Golden/Silver Ticket, DCShadow) Experience with JIT/JEA, PAM concepts, and global on call rotations Location, work style, and travel Opportunities in the United States, United Kingdom, and Denmark Onsite or hybrid depending on location and business needs Occasional on call coverage may be required Why you'll love it here Own a mission critical identity defense stack and make measurable impact on MTTD/MTTR and privilege hygiene Solve complex problems from dark web exposure to directory persistence and lateral movement Collaborate with experienced global teams and leading vendors to continuously raise the bar Grow your career in a modern, data driven security operations environment Our programs are designed to focus on maintaining and enhancing all pillars of health with a robust benefitspackage including medical, dental, vision and prescription drug coverage with the option of a Health Savings Account with company contributions. In addition, we offer an industry leading 401(k) savings plan, insurance coverage, employee assistance programs and various wellness incentives. We support life work balance with paid vacation time, sick time, and company holidays. Explore a supportive environment that enriches both your personal and professional growth! EEO Information Fujifilm is committed to providing equal opportunities in hiring, promotion and advancement, compensation, benefits, and training regardless of nationality, age, gender, sexual orientation or gender identity, race, ethnicity, religion, political creed, ideology, national, or social origin, disability, veteran status, etc. ADA Information If you require reasonable accommodation in completing this application, interviewing, completing any pre employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our HR Department ().
26/07/2026
Full time
Position Overview Protect identities at global scale. We're hiring a hands on Senior Identity Protection Engineer/Specialist to lead detection, investigation, and response for identity based threats across Microsoft Entra ID/Azure AD, on prem Active Directory, and connected SaaS/IaaS. You'll serve as the enterprise SME/administrator for CrowdStrike Identity Protection, tune high fidelity detections, integrate dark web intelligence, and orchestrate automation that measurably reduces MTTD/MTTR and risk. What you'll do Lead identity threat monitoring and triage Operate and tune CrowdStrike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks like impossible travel, atypical sign ins, MFA fatigue, and session hijacking Validate true/false positives, prioritize by business impact, and escalate per playbooks/SLAs Drive rapid containment and remediation Execute containment actions (disable accounts, revoke sessions/tokens, isolate hosts) Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closure Own identity focused incident response Lead IR for credential compromise, privilege escalation, directory persistence, and lateral movement Ensure evidence handling, root cause analysis, post incident reviews, and lessons learned Engineer detections and hunt for threats Build and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CK Close visibility gaps, reduce false positives, and expand privileged activity monitoring Strengthen privileged access controls Detect anomalous privileged behavior via SIEM/UEBA and Netskope telemetry Recommend/enforce JIT, break glass patterns, and mover/leaver privilege hygiene with IAM Respond to dark web/credential exposure Integrate sources like CyberInt; assess exposure and targeted campaigns Orchestrate takedowns, forced resets, token revocation, and Conditional Access updates Administer platforms and sustain hygiene Maintain coverage/health for identity monitoring; manage upgrades and changes via CAB Keep operational runbooks, SOPs, and playbooks current Automate and orchestrate at scale Use PowerShell/Python and REST/Graph/CrowdStrike APIs (and SOAR where applicable) to automate enrichment and response, standardize workflows, and improve signal fidelity Shape identity policy and controls Advise on Conditional Access, MFA exceptions, SSO/SCIM patterns, and session controls under the shared responsibility model with IAM Report outcomes and support audits Produce executive ready dashboards and KPIs (identity incident volume, MTTD/MTTR, CA/MFA efficacy, exposure/takedown cycle time) Maintain audit ready evidence and support internal/external audits What you'll bring Bachelor's degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience 8+ years in IT/cybersecurity, including 3-5+ years focused on identity security/operations (Entra ID/Azure AD, on prem AD, MFA, Conditional Access, SSO/SCIM) Hands on enterprise experience administering/operating CrowdStrike Identity Protection Proficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms (e.g., Netskope) for identity telemetry, detection, and investigations Demonstrated experience in identity centric IR, threat hunting, and detection engineering (KQL/SQL/regex/Sigma) Scripting/automation with PowerShell and Python; experience with REST/Graph/CrowdStrike APIs and SOAR Clear communication and documentation skills; comfortable producing executive ready reports and audit evidence Operates effectively within change control/CAB and under pressure during high severity incidents Bonus points Certifications: Microsoft SC 200/SC 300; Okta Certified Administrator/Professional; CISSP, SSCP, Security+; GIAC (GMON, GCIH, GCDA) or equivalent Deep knowledge of identity attack paths and protocols (Kerberos/NTLM), token/session abuse, and persistence techniques (e.g., Golden/Silver Ticket, DCShadow) Experience with JIT/JEA, PAM concepts, and global on call rotations Location, work style, and travel Opportunities in the United States, United Kingdom, and Denmark Onsite or hybrid depending on location and business needs Occasional on call coverage may be required Why you'll love it here Own a mission critical identity defense stack and make measurable impact on MTTD/MTTR and privilege hygiene Solve complex problems from dark web exposure to directory persistence and lateral movement Collaborate with experienced global teams and leading vendors to continuously raise the bar Grow your career in a modern, data driven security operations environment Our programs are designed to focus on maintaining and enhancing all pillars of health with a robust benefitspackage including medical, dental, vision and prescription drug coverage with the option of a Health Savings Account with company contributions. In addition, we offer an industry leading 401(k) savings plan, insurance coverage, employee assistance programs and various wellness incentives. We support life work balance with paid vacation time, sick time, and company holidays. Explore a supportive environment that enriches both your personal and professional growth! EEO Information Fujifilm is committed to providing equal opportunities in hiring, promotion and advancement, compensation, benefits, and training regardless of nationality, age, gender, sexual orientation or gender identity, race, ethnicity, religion, political creed, ideology, national, or social origin, disability, veteran status, etc. ADA Information If you require reasonable accommodation in completing this application, interviewing, completing any pre employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our HR Department ().
IT Operations and Security Lead
Onyx-Conseil
IT Operations Platforms and Security Lead In summary the Client is looking to recruit an all round individual with expert knowledge and hands on experience of IT Infrastructure coupled with Security, Compliance & Risk Management You must have upwards of 10 years hands on expertise in IT Infrastructure combined with Security and Risk - ideally from within the banking or insurance sector. The IT Operational Platform and Security Lead is responsible for overseeing the organisation's IT operations, ensuring the stability, continuity, security, and efficiency of its technology platforms within a global commercial insurance environment. While Microsoft technologies (Microsoft 365, Azure, Exchange Online) form a core part of the infrastructure, the role also encompasses broader enterprise IT systems, multi layered networking, security, data management, and third party platforms that support global business operations and the associated applications estate. The role requires a proactive leader who can drive IT operational excellence, manage security risks, focus on continual service improvement, drive transformational delivery projects, and work effectively with internal stakeholders and third party vendors to deliver a high quality Global IT services. Working in line with the Architecture defined IT principle of a "buy before build" environment, the individual will need to ensure that outsourced and cloud based services are robust, cost effective, and aligned with business needs and the Strategic IT vision. They will also play a key role in enhancing cybersecurity, protecting data and systems, driving transformative operational change, enhancing IT processes and ensuring compliance with governance bodies and industry regulations. Due to the nature of the role, complexity of the estate, current transformation activities and team size, the role requires the functional capability and proficiency to technically augment the team capabilities (when required) and have a detailed knowledge of technical IT support roles/services as a requirement, across multiple technical areas. Security, Compliance & Risk Management Define and enforce cloud security policies, identity management, and access controls to protect systems, networks, and data. Oversee the adoption of zero trust security principles to enhance protection across cloud platforms. Manage identity and access management (IAM) in a cloud first environment, including Azure AD, MFA, Conditional Access, SSO, and Privileged Access Management (PAM). Lead threat monitoring, detection, and response using cloud native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. Oversee endpoint security, cloud network and API security for robust protection across all assets. Define, manage and maintain accurate DR and BCP plans for the infrastructure area with biannual tests. Technical Experience Microsoft Azure Infrastructure design and administration, including topology, Azure networking, services, and component knowledge. Microsoft AD (Entra), Server and SQL experience. O365 administration and design. Global Software Patching and estate management via Intune. Firewall (Azure, CheckPoint and Cloudflare), DNS, VPN, WIFI and Local Area Network design & administration experience. Software Defined Networking (Cisco, Meraki, Versa). Key Skills Microsoft 365 & Azure: Strong experience managing Microsoft 365 (Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign On (SSO), and Privileged Access Management (PAM). Threat Management & Incident Response: Ability to detect, respond to, and mitigate cyber threats using SIEM, endpoint security, and vulnerability management tools. Networking & Infrastructure Security: Understanding of firewalls, VPNs, SD WAN, DNS security, endpoint protection, and cloud security controls. IT Service Management & Automation: Experience implementing ITIL based service management, automating operational tasks, and optimising service delivery. Operational & Leadership Skills IT Operations & Service Continuity: Ability to ensure IT systems are highly available, resilient, and fit for purpose, with a strong focus on business continuity and disaster recovery. Supplier & Vendor Management: Experience managing third party IT vendors, MSPs, and SaaS providers, ensuring service levels, performance, and cost effectiveness. Project Leadership & Change Management: Ability to lead technology projects, system upgrades, and platform migrations, ensuring smooth execution and minimal business disruption. Process Improvement & Automation: Strong analytical mindset to identify inefficiencies, automate workflows, and enhance security controls. Skills & Mindset Problem Solving & Decision Making: Capable of making informed decisions and resolving complex IT issues in a fast paced environment. Stakeholder Engagement: Ability to communicate effectively with technical and non technical stakeholders, including senior leadership and business users. Resilience & Adaptability: Comfortable working in an evolving technology landscape, with a proactive and security first approach. The Client is a financial organisation based in the City of London. This is a hybrid position with 3 days in the office. Must have a Bachelor's degree in IT or similar. The salary for this role will be in the range £85K - £95K plus Benefits. Do send your CV to us in Word format along with your salary and notice period.
26/07/2026
Full time
IT Operations Platforms and Security Lead In summary the Client is looking to recruit an all round individual with expert knowledge and hands on experience of IT Infrastructure coupled with Security, Compliance & Risk Management You must have upwards of 10 years hands on expertise in IT Infrastructure combined with Security and Risk - ideally from within the banking or insurance sector. The IT Operational Platform and Security Lead is responsible for overseeing the organisation's IT operations, ensuring the stability, continuity, security, and efficiency of its technology platforms within a global commercial insurance environment. While Microsoft technologies (Microsoft 365, Azure, Exchange Online) form a core part of the infrastructure, the role also encompasses broader enterprise IT systems, multi layered networking, security, data management, and third party platforms that support global business operations and the associated applications estate. The role requires a proactive leader who can drive IT operational excellence, manage security risks, focus on continual service improvement, drive transformational delivery projects, and work effectively with internal stakeholders and third party vendors to deliver a high quality Global IT services. Working in line with the Architecture defined IT principle of a "buy before build" environment, the individual will need to ensure that outsourced and cloud based services are robust, cost effective, and aligned with business needs and the Strategic IT vision. They will also play a key role in enhancing cybersecurity, protecting data and systems, driving transformative operational change, enhancing IT processes and ensuring compliance with governance bodies and industry regulations. Due to the nature of the role, complexity of the estate, current transformation activities and team size, the role requires the functional capability and proficiency to technically augment the team capabilities (when required) and have a detailed knowledge of technical IT support roles/services as a requirement, across multiple technical areas. Security, Compliance & Risk Management Define and enforce cloud security policies, identity management, and access controls to protect systems, networks, and data. Oversee the adoption of zero trust security principles to enhance protection across cloud platforms. Manage identity and access management (IAM) in a cloud first environment, including Azure AD, MFA, Conditional Access, SSO, and Privileged Access Management (PAM). Lead threat monitoring, detection, and response using cloud native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. Oversee endpoint security, cloud network and API security for robust protection across all assets. Define, manage and maintain accurate DR and BCP plans for the infrastructure area with biannual tests. Technical Experience Microsoft Azure Infrastructure design and administration, including topology, Azure networking, services, and component knowledge. Microsoft AD (Entra), Server and SQL experience. O365 administration and design. Global Software Patching and estate management via Intune. Firewall (Azure, CheckPoint and Cloudflare), DNS, VPN, WIFI and Local Area Network design & administration experience. Software Defined Networking (Cisco, Meraki, Versa). Key Skills Microsoft 365 & Azure: Strong experience managing Microsoft 365 (Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign On (SSO), and Privileged Access Management (PAM). Threat Management & Incident Response: Ability to detect, respond to, and mitigate cyber threats using SIEM, endpoint security, and vulnerability management tools. Networking & Infrastructure Security: Understanding of firewalls, VPNs, SD WAN, DNS security, endpoint protection, and cloud security controls. IT Service Management & Automation: Experience implementing ITIL based service management, automating operational tasks, and optimising service delivery. Operational & Leadership Skills IT Operations & Service Continuity: Ability to ensure IT systems are highly available, resilient, and fit for purpose, with a strong focus on business continuity and disaster recovery. Supplier & Vendor Management: Experience managing third party IT vendors, MSPs, and SaaS providers, ensuring service levels, performance, and cost effectiveness. Project Leadership & Change Management: Ability to lead technology projects, system upgrades, and platform migrations, ensuring smooth execution and minimal business disruption. Process Improvement & Automation: Strong analytical mindset to identify inefficiencies, automate workflows, and enhance security controls. Skills & Mindset Problem Solving & Decision Making: Capable of making informed decisions and resolving complex IT issues in a fast paced environment. Stakeholder Engagement: Ability to communicate effectively with technical and non technical stakeholders, including senior leadership and business users. Resilience & Adaptability: Comfortable working in an evolving technology landscape, with a proactive and security first approach. The Client is a financial organisation based in the City of London. This is a hybrid position with 3 days in the office. Must have a Bachelor's degree in IT or similar. The salary for this role will be in the range £85K - £95K plus Benefits. Do send your CV to us in Word format along with your salary and notice period.
IT Operations Platforms and Security Lead
Onyx-Conseil
IT Operations Platforms and Security Lead This role requires excellent management of a small team in IT along with managing stakeholders and vendors. You must be hands on technically in IT Infrastructure. The IT Operational Platform and Security Lead is responsible for overseeing the organisation's IT operations, ensuring the stability, continuity, security, and efficiency of its technology platforms within a global commercial insurance environment. While Microsoft technologies (Microsoft 365, Azure, Exchange Online) form a core part of the infrastructure, the role also encompasses broader enterprise IT systems, multi layered networking, security, data management, and third party platforms that support global business operations and the associated applications estate. The role requires a proactive leader who can drive IT operational excellence, manage security risks, focus on continual service improvement, drive transformational delivery projects, and work effectively with internal stakeholders and third party vendors to deliver a high quality Global IT services. Working in line with the Architecture defined IT principle of a 'buy before build' environment, the individual will need to ensure that outsourced and cloud based services are robust, cost effective, and aligned with business needs and the Strategic IT vision. They will also play a key role in enhancing cybersecurity, protecting data and systems, driving transformative operational change, enhancing IT processes and ensuring compliance with governance bodies and industry regulations. Due to the nature of the role, complexity Security, Compliance & Risk Management Define and enforce cloud security policies, identity management, and access controls to protect systems, networks, and data. Oversee the adoption of zero trust security principles to enhance protection across cloud platforms. Manage identity and access management (IAM) in a cloud first environment, including Azure AD, MFA, Conditional Access, SSO, and Privileged Access Management (PAM). Lead threat monitoring, detection, and response using cloud native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. Oversee endpoint security, cloud network and API security for robust protection across all assets. Define, manage and maintain accurate DR and BCP plans for the infrastructure area with biannual tests. Technical Experience Microsoft Azure Infrastructure design and administration, including topology, Azure networking, services, and component knowledge. Microsoft AD (Entra), Server and SQL experience. O365 administration and design. Global Software Patching and estate management via Intune. Firewall (Azure, CheckPoint and Cloudflare), DNS, VPN, WIFI and Local Area Network design & administration experience. Software Defined Networking (Cisco, Meraki, Versa). Key Skills Microsoft 365 & Azure: Strong experience managing Microsoft 365 (Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign On (SSO), and Privileged Access Management (PAM). Threat Management & Incident Response: Ability to detect, respond to, and mitigate cyber threats using SIEM, endpoint security, and vulnerability management tools. Networking & Infrastructure Security: Understanding of firewalls, VPNs, SD WAN, DNS security, endpoint protection, and cloud security controls. IT Service Management & Automation: Experience implementing ITIL based service management, automating operational tasks, and optimising service delivery. IT Operations & Service Continuity: Ability to ensure IT systems are highly available, resilient, and fit for purpose, with a strong focus on business continuity and disaster recovery. Supplier & Vendor Management: Experience managing third party IT vendors, MSPs, and SaaS providers, ensuring service levels, performance, and cost effectiveness. Project Leadership & Change Management: Ability to lead technology projects, system upgrades, and platform migrations, ensuring smooth execution and minimal business disruption. Process Improvement & Automation: Strong analytical mindset to identify inefficiencies, automate workflows, and enhance security controls. Problem Solving & Decision Making: Capable of making informed decisions and resolving complex IT issues in a fast paced environment. Stakeholder Engagement: Ability to communicate effectively with technical and non technical stakeholders, including senior leadership and business users. Resilience & Adaptability: Comfortable working in an evolving technology landscape, with a proactive and security first approach. Summary of Skills Required: Global Enterprise level Infrastructure Management position for the last 5 years. Global team management (human resources, strategic delivery, operational service, audit lead for Infra, budget ). Key - 3rd party operational infrastructure vendor management - i.e management of managed service partners. Migration of Legacy VM based estates to SaaS and Cloud services platforms. Legacy tech to Azure knowledge/experience. Prior to the last 5 years, a technical infrastructure engineering level background, working on Windows Server, AD , SQL environments, Firewalls/SDWAN, and Networks (WAN &/or LAN). The Client is based in the City of London. This is a hybrid position with 3 days in the office. The salary for this role will be in the range £85K - £100K plus Benefits. Do send your CV to us in Word format along with your salary and notice period.
26/07/2026
Full time
IT Operations Platforms and Security Lead This role requires excellent management of a small team in IT along with managing stakeholders and vendors. You must be hands on technically in IT Infrastructure. The IT Operational Platform and Security Lead is responsible for overseeing the organisation's IT operations, ensuring the stability, continuity, security, and efficiency of its technology platforms within a global commercial insurance environment. While Microsoft technologies (Microsoft 365, Azure, Exchange Online) form a core part of the infrastructure, the role also encompasses broader enterprise IT systems, multi layered networking, security, data management, and third party platforms that support global business operations and the associated applications estate. The role requires a proactive leader who can drive IT operational excellence, manage security risks, focus on continual service improvement, drive transformational delivery projects, and work effectively with internal stakeholders and third party vendors to deliver a high quality Global IT services. Working in line with the Architecture defined IT principle of a 'buy before build' environment, the individual will need to ensure that outsourced and cloud based services are robust, cost effective, and aligned with business needs and the Strategic IT vision. They will also play a key role in enhancing cybersecurity, protecting data and systems, driving transformative operational change, enhancing IT processes and ensuring compliance with governance bodies and industry regulations. Due to the nature of the role, complexity Security, Compliance & Risk Management Define and enforce cloud security policies, identity management, and access controls to protect systems, networks, and data. Oversee the adoption of zero trust security principles to enhance protection across cloud platforms. Manage identity and access management (IAM) in a cloud first environment, including Azure AD, MFA, Conditional Access, SSO, and Privileged Access Management (PAM). Lead threat monitoring, detection, and response using cloud native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. Oversee endpoint security, cloud network and API security for robust protection across all assets. Define, manage and maintain accurate DR and BCP plans for the infrastructure area with biannual tests. Technical Experience Microsoft Azure Infrastructure design and administration, including topology, Azure networking, services, and component knowledge. Microsoft AD (Entra), Server and SQL experience. O365 administration and design. Global Software Patching and estate management via Intune. Firewall (Azure, CheckPoint and Cloudflare), DNS, VPN, WIFI and Local Area Network design & administration experience. Software Defined Networking (Cisco, Meraki, Versa). Key Skills Microsoft 365 & Azure: Strong experience managing Microsoft 365 (Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign On (SSO), and Privileged Access Management (PAM). Threat Management & Incident Response: Ability to detect, respond to, and mitigate cyber threats using SIEM, endpoint security, and vulnerability management tools. Networking & Infrastructure Security: Understanding of firewalls, VPNs, SD WAN, DNS security, endpoint protection, and cloud security controls. IT Service Management & Automation: Experience implementing ITIL based service management, automating operational tasks, and optimising service delivery. IT Operations & Service Continuity: Ability to ensure IT systems are highly available, resilient, and fit for purpose, with a strong focus on business continuity and disaster recovery. Supplier & Vendor Management: Experience managing third party IT vendors, MSPs, and SaaS providers, ensuring service levels, performance, and cost effectiveness. Project Leadership & Change Management: Ability to lead technology projects, system upgrades, and platform migrations, ensuring smooth execution and minimal business disruption. Process Improvement & Automation: Strong analytical mindset to identify inefficiencies, automate workflows, and enhance security controls. Problem Solving & Decision Making: Capable of making informed decisions and resolving complex IT issues in a fast paced environment. Stakeholder Engagement: Ability to communicate effectively with technical and non technical stakeholders, including senior leadership and business users. Resilience & Adaptability: Comfortable working in an evolving technology landscape, with a proactive and security first approach. Summary of Skills Required: Global Enterprise level Infrastructure Management position for the last 5 years. Global team management (human resources, strategic delivery, operational service, audit lead for Infra, budget ). Key - 3rd party operational infrastructure vendor management - i.e management of managed service partners. Migration of Legacy VM based estates to SaaS and Cloud services platforms. Legacy tech to Azure knowledge/experience. Prior to the last 5 years, a technical infrastructure engineering level background, working on Windows Server, AD , SQL environments, Firewalls/SDWAN, and Networks (WAN &/or LAN). The Client is based in the City of London. This is a hybrid position with 3 days in the office. The salary for this role will be in the range £85K - £100K plus Benefits. Do send your CV to us in Word format along with your salary and notice period.
Senior Identity Protection Specialist
FUJIFILM Holdings America Corporation Billingham, Yorkshire
Position Overview Protect identities at global scale. We're hiring a hands on Senior Identity Protection Engineer/Specialist to lead detection, investigation, and response for identity based threats across Microsoft Entra ID/Azure AD, on prem Active Directory, and connected SaaS/IaaS. You'll serve as the enterprise SME/administrator for CrowdStrike Identity Protection, tune high fidelity detections, integrate dark web intelligence, and orchestrate automation that measurably reduces MTTD/MTTR and risk. What you'll do Lead identity threat monitoring and triage Operate and tune CrowdStrike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks like impossible travel, atypical sign ins, MFA fatigue, and session hijacking Validate true/false positives, prioritize by business impact, and escalate per playbooks/SLAs Drive rapid containment and remediation Execute containment actions (disable accounts, revoke sessions/tokens, isolate hosts) Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closure Own identity focused incident response Lead IR for credential compromise, privilege escalation, directory persistence, and lateral movement Ensure evidence handling, root cause analysis, post incident reviews, and lessons learned Engineer detections and hunt for threats Build and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CK Close visibility gaps, reduce false positives, and expand privileged activity monitoring Strengthen privileged access controls Detect anomalous privileged behavior via SIEM/UEBA and Netskope telemetry Recommend/enforce JIT, break glass patterns, and mover/leaver privilege hygiene with IAM Respond to dark web/credential exposure Integrate sources like CyberInt; assess exposure and targeted campaigns Orchestrate takedowns, forced resets, token revocation, and Conditional Access updates Administer platforms and sustain hygiene Maintain coverage/health for identity monitoring; manage upgrades and changes via CAB Keep operational runbooks, SOPs, and playbooks current Automate and orchestrate at scale Use PowerShell/Python and REST/Graph/CrowdStrike APIs (and SOAR where applicable) to automate enrichment and response, standardize workflows, and improve signal fidelity Shape identity policy and controls Advise on Conditional Access, MFA exceptions, SSO/SCIM patterns, and session controls under the shared responsibility model with IAM Report outcomes and support audits Produce executive ready dashboards and KPIs (identity incident volume, MTTD/MTTR, CA/MFA efficacy, exposure/takedown cycle time) Maintain audit ready evidence and support internal/external audits What you'll bring Bachelor's degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience 8+ years in IT/cybersecurity, including 3-5+ years focused on identity security/operations (Entra ID/Azure AD, on prem AD, MFA, Conditional Access, SSO/SCIM) Hands on enterprise experience administering/operating CrowdStrike Identity Protection Proficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms (e.g., Netskope) for identity telemetry, detection, and investigations Demonstrated experience in identity centric IR, threat hunting, and detection engineering (KQL/SQL/regex/Sigma) Scripting/automation with PowerShell and Python; experience with REST/Graph/CrowdStrike APIs and SOAR Clear communication and documentation skills; comfortable producing executive ready reports and audit evidence Operates effectively within change control/CAB and under pressure during high severity incidents Bonus points Certifications: Microsoft SC 200/SC 300; Okta Certified Administrator/Professional; CISSP, SSCP, Security+; GIAC (GMON, GCIH, GCDA) or equivalent Deep knowledge of identity attack paths and protocols (Kerberos/NTLM), token/session abuse, and persistence techniques (e.g., Golden/Silver Ticket, DCShadow) Experience with JIT/JEA, PAM concepts, and global on call rotations Location, work style, and travel Opportunities in the United States, United Kingdom, and Denmark Onsite or hybrid depending on location and business needs Occasional on call coverage may be required Why you'll love it here Own a mission critical identity defense stack and make measurable impact on MTTD/MTTR and privilege hygiene Solve complex problems from dark web exposure to directory persistence and lateral movement Collaborate with experienced global teams and leading vendors to continuously raise the bar Grow your career in a modern, data driven security operations environment Our programs are designed to focus on maintaining and enhancing all pillars of health with a robust benefitspackage including medical, dental, vision and prescription drug coverage with the option of a Health Savings Account with company contributions. In addition, we offer an industry leading 401(k) savings plan, insurance coverage, employee assistance programs and various wellness incentives. We support life work balance with paid vacation time, sick time, and company holidays. Explore a supportive environment that enriches both your personal and professional growth! EEO Information Fujifilm is committed to providing equal opportunities in hiring, promotion and advancement, compensation, benefits, and training regardless of nationality, age, gender, sexual orientation or gender identity, race, ethnicity, religion, political creed, ideology, national, or social origin, disability, veteran status, etc. ADA Information If you require reasonable accommodation in completing this application, interviewing, completing any pre employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our HR Department ().
26/07/2026
Full time
Position Overview Protect identities at global scale. We're hiring a hands on Senior Identity Protection Engineer/Specialist to lead detection, investigation, and response for identity based threats across Microsoft Entra ID/Azure AD, on prem Active Directory, and connected SaaS/IaaS. You'll serve as the enterprise SME/administrator for CrowdStrike Identity Protection, tune high fidelity detections, integrate dark web intelligence, and orchestrate automation that measurably reduces MTTD/MTTR and risk. What you'll do Lead identity threat monitoring and triage Operate and tune CrowdStrike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks like impossible travel, atypical sign ins, MFA fatigue, and session hijacking Validate true/false positives, prioritize by business impact, and escalate per playbooks/SLAs Drive rapid containment and remediation Execute containment actions (disable accounts, revoke sessions/tokens, isolate hosts) Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closure Own identity focused incident response Lead IR for credential compromise, privilege escalation, directory persistence, and lateral movement Ensure evidence handling, root cause analysis, post incident reviews, and lessons learned Engineer detections and hunt for threats Build and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CK Close visibility gaps, reduce false positives, and expand privileged activity monitoring Strengthen privileged access controls Detect anomalous privileged behavior via SIEM/UEBA and Netskope telemetry Recommend/enforce JIT, break glass patterns, and mover/leaver privilege hygiene with IAM Respond to dark web/credential exposure Integrate sources like CyberInt; assess exposure and targeted campaigns Orchestrate takedowns, forced resets, token revocation, and Conditional Access updates Administer platforms and sustain hygiene Maintain coverage/health for identity monitoring; manage upgrades and changes via CAB Keep operational runbooks, SOPs, and playbooks current Automate and orchestrate at scale Use PowerShell/Python and REST/Graph/CrowdStrike APIs (and SOAR where applicable) to automate enrichment and response, standardize workflows, and improve signal fidelity Shape identity policy and controls Advise on Conditional Access, MFA exceptions, SSO/SCIM patterns, and session controls under the shared responsibility model with IAM Report outcomes and support audits Produce executive ready dashboards and KPIs (identity incident volume, MTTD/MTTR, CA/MFA efficacy, exposure/takedown cycle time) Maintain audit ready evidence and support internal/external audits What you'll bring Bachelor's degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience 8+ years in IT/cybersecurity, including 3-5+ years focused on identity security/operations (Entra ID/Azure AD, on prem AD, MFA, Conditional Access, SSO/SCIM) Hands on enterprise experience administering/operating CrowdStrike Identity Protection Proficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms (e.g., Netskope) for identity telemetry, detection, and investigations Demonstrated experience in identity centric IR, threat hunting, and detection engineering (KQL/SQL/regex/Sigma) Scripting/automation with PowerShell and Python; experience with REST/Graph/CrowdStrike APIs and SOAR Clear communication and documentation skills; comfortable producing executive ready reports and audit evidence Operates effectively within change control/CAB and under pressure during high severity incidents Bonus points Certifications: Microsoft SC 200/SC 300; Okta Certified Administrator/Professional; CISSP, SSCP, Security+; GIAC (GMON, GCIH, GCDA) or equivalent Deep knowledge of identity attack paths and protocols (Kerberos/NTLM), token/session abuse, and persistence techniques (e.g., Golden/Silver Ticket, DCShadow) Experience with JIT/JEA, PAM concepts, and global on call rotations Location, work style, and travel Opportunities in the United States, United Kingdom, and Denmark Onsite or hybrid depending on location and business needs Occasional on call coverage may be required Why you'll love it here Own a mission critical identity defense stack and make measurable impact on MTTD/MTTR and privilege hygiene Solve complex problems from dark web exposure to directory persistence and lateral movement Collaborate with experienced global teams and leading vendors to continuously raise the bar Grow your career in a modern, data driven security operations environment Our programs are designed to focus on maintaining and enhancing all pillars of health with a robust benefitspackage including medical, dental, vision and prescription drug coverage with the option of a Health Savings Account with company contributions. In addition, we offer an industry leading 401(k) savings plan, insurance coverage, employee assistance programs and various wellness incentives. We support life work balance with paid vacation time, sick time, and company holidays. Explore a supportive environment that enriches both your personal and professional growth! EEO Information Fujifilm is committed to providing equal opportunities in hiring, promotion and advancement, compensation, benefits, and training regardless of nationality, age, gender, sexual orientation or gender identity, race, ethnicity, religion, political creed, ideology, national, or social origin, disability, veteran status, etc. ADA Information If you require reasonable accommodation in completing this application, interviewing, completing any pre employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our HR Department ().
Senior Security Engineer
Semble
About the role You will report directly to the Head of Information Security and work alongside a Senior Technical Support Engineer to form the senior core of the IT Delivery and Security Services team. You will own a broad portfolio of security responsibilities, from application security and secure SDLC enablement to AI governance and security programmes, with significant autonomy to shape how that work gets done. The role is hybrid within the UK, with occasional travel to our London office for collaboration and workshops. What you will be doing Application Security and Secure SDLC Embed security into Agile development by partnering with engineering squads during planning, refinement, and delivery, and be the security voice in the room. Define, roll out, and continuously improve secure coding standards, secure design patterns, and developer-friendly guidance that scales across the engineering team. Run threat modelling for new features and major architectural changes, capturing abuse cases and security requirements early, and apply emerging frameworks to model and mitigate new threat surfaces, especially for AI-powered features. Own SAST, SCA, DAST, container, and IaC scanning pipelines, using Snyk as the primary platform. Integrate with CI/CD, manage policies, and focus on developer experience and false-positive reduction. Triage and manage vulnerabilities end-to-end: classification, SLAs, fix validation, and reporting. Build frictionless guardrails such as pre-commit hooks, secure templates, reference code, and paved paths that make doing the right thing easy. Deliver targeted training and just-in-time enablement based on findings and stack specifics. Security Architecture and Design Advise on architecture choices for key product feature developments, including authorisation, secrets and key management, data protection, and zero-trust-aligned designs. Guide secure API and microservice patterns, including input validation, rate limiting, secure session handling, and token-based security (OAuth 2.0/OIDC). Review designs for cloud-native services and edge components, ensuring sensible security trade-offs aligned to product goals. Advise on the security architecture of agent orchestration, tool integrations, memory handling, and MCP server deployments as agentic AI capabilities expand. AI Security and Governance Apply and evolve Semble's approach to AI specific threats: prompt injection, excessive agent autonomy, tool and plugin abuse, AI supply chain risks, and context manipulation, using OWASP LLM Top 10 and OWASP Top 10 for Agentic Applications. Work with the Head of Information Security to develop and maintain AI governance posture, aligned with ISO 42001 and evolving AI regulatory landscape in healthcare. Assess risks from third party AI integrations, AI assisted development tooling, and agentic workflows, and implement appropriate mitigations. Security Operations and Threat Management Monitor, investigate, and respond to security alerts, incidents, and anomalous behaviour across Semble's environment. Develop and mature threat intelligence capabilities, including vulnerability management, penetration testing coordination, and incident response processes. Maintain and improve security tooling, logging, and detection capabilities with an automation first mindset. Contribute to incident response runbooks for application layer and AI related incidents, and support blameless post incident reviews to embed learning back into the SDLC. Identify and address security gaps proactively, improving the overall security posture. Compliance, Certification and Audit Readiness Own or co own delivery of compliance programmes, including ISO 27001, Cyber Essentials+, NHS DSPT, and the journey toward SOC 2 readiness. Support and contribute to ISO 42001 implementation as AI governance matures. Define and track pragmatic security KPIs such as time to remediate, coverage, critical resolutions within SLA, threat model coverage, and audit readiness indicators. Maintain audit quality documentation, evidence, and records at all times. Customer and Stakeholder Engagement Support the sales process by responding to customer security questionnaires and due diligence requests with accuracy and confidence. Occasionally engage directly with customers on security topics, acting as a credible representative of Semble's security function. Work with internal stakeholders to ensure security requirements are understood and embedded across the business. What we are looking for Required Minimum of 5 years' experience in application security, product security, or a combination of software engineering and security with strong AppSec ownership. Hands on experience with Snyk across SCA, SAST, Container, and IaC, including CI/CD integration and policy management. Strong grounding in modern web and application security: OWASP Top 10, API Security Top 10, and emerging understanding of the OWASP Top 10 for Agentic Applications. Practical experience embedding security into Agile workflows and DevSecOps tooling. Solid understanding of authn/authz patterns, secrets management, encryption, and cloud native security controls. Experience with compliance frameworks, particularly ISO 27001; familiarity with Cyber Essentials+, NHS DSPT, or SOC 2 is a strong advantage. Practical understanding of AI security risks, including prompt injection, LLM vulnerabilities, and agentic system threats, and how to address them in a product context. Experience working in a SaaS environment or similarly regulated industry, appreciating the product, engineering, and commercial context that security decisions sit within. Ability to communicate clearly with engineers, leadership, and occasionally customers, translating complex security risk into clear, actionable language. Genuine, hands on AI experience: you must be able to discuss specific ways you are already using AI to improve security operations, detection, or engineering workflows. A track record of maintaining security programmes to a continuously high standard, with audit readiness as a default rather than a periodic event. A proactive, ownership mindset: you identify gaps, propose solutions, and deliver them without waiting to be told. Desirable CISSP certification (strongly preferred). Experience with threat modelling methodologies such as STRIDE or attack trees, and running effective threat model sessions with engineering teams. Familiarity with API gateways, container orchestration, and software supply chain security. Experience securing AI enabled features, ML pipelines, agentic workflows, or MCP based integrations. Experience building or maturing a security function within a scaling organisation. Exposure to healthcare data regulations and NHS security requirements. Proficiency in the French language (nice to have, not mandatory). Benefits £80-90k salary package, reflecting the specialist and technical nature of this role. Autonomy and ownership - you set the vision and run with it. 36 days off: 25 holidays + bank holidays + 3 extra days (birthday and feel good days). Private health insurance covering physical and mental health, as well as dental and optical. Hybrid & flexible work environment - work from anywhere in the UK, with some flexibility to work across Europe. Latest MacBook (or Windows) and equipment to set up a home office ergonomically. Equal Opportunity We welcome applications from people of all backgrounds and walks of life, including those from groups typically underrepresented in the technology industry. We also encourage applications from disabled and neurodiverse candidates. If there are adjustments we can make to support you throughout the recruitment process, please let us know.
25/07/2026
Full time
About the role You will report directly to the Head of Information Security and work alongside a Senior Technical Support Engineer to form the senior core of the IT Delivery and Security Services team. You will own a broad portfolio of security responsibilities, from application security and secure SDLC enablement to AI governance and security programmes, with significant autonomy to shape how that work gets done. The role is hybrid within the UK, with occasional travel to our London office for collaboration and workshops. What you will be doing Application Security and Secure SDLC Embed security into Agile development by partnering with engineering squads during planning, refinement, and delivery, and be the security voice in the room. Define, roll out, and continuously improve secure coding standards, secure design patterns, and developer-friendly guidance that scales across the engineering team. Run threat modelling for new features and major architectural changes, capturing abuse cases and security requirements early, and apply emerging frameworks to model and mitigate new threat surfaces, especially for AI-powered features. Own SAST, SCA, DAST, container, and IaC scanning pipelines, using Snyk as the primary platform. Integrate with CI/CD, manage policies, and focus on developer experience and false-positive reduction. Triage and manage vulnerabilities end-to-end: classification, SLAs, fix validation, and reporting. Build frictionless guardrails such as pre-commit hooks, secure templates, reference code, and paved paths that make doing the right thing easy. Deliver targeted training and just-in-time enablement based on findings and stack specifics. Security Architecture and Design Advise on architecture choices for key product feature developments, including authorisation, secrets and key management, data protection, and zero-trust-aligned designs. Guide secure API and microservice patterns, including input validation, rate limiting, secure session handling, and token-based security (OAuth 2.0/OIDC). Review designs for cloud-native services and edge components, ensuring sensible security trade-offs aligned to product goals. Advise on the security architecture of agent orchestration, tool integrations, memory handling, and MCP server deployments as agentic AI capabilities expand. AI Security and Governance Apply and evolve Semble's approach to AI specific threats: prompt injection, excessive agent autonomy, tool and plugin abuse, AI supply chain risks, and context manipulation, using OWASP LLM Top 10 and OWASP Top 10 for Agentic Applications. Work with the Head of Information Security to develop and maintain AI governance posture, aligned with ISO 42001 and evolving AI regulatory landscape in healthcare. Assess risks from third party AI integrations, AI assisted development tooling, and agentic workflows, and implement appropriate mitigations. Security Operations and Threat Management Monitor, investigate, and respond to security alerts, incidents, and anomalous behaviour across Semble's environment. Develop and mature threat intelligence capabilities, including vulnerability management, penetration testing coordination, and incident response processes. Maintain and improve security tooling, logging, and detection capabilities with an automation first mindset. Contribute to incident response runbooks for application layer and AI related incidents, and support blameless post incident reviews to embed learning back into the SDLC. Identify and address security gaps proactively, improving the overall security posture. Compliance, Certification and Audit Readiness Own or co own delivery of compliance programmes, including ISO 27001, Cyber Essentials+, NHS DSPT, and the journey toward SOC 2 readiness. Support and contribute to ISO 42001 implementation as AI governance matures. Define and track pragmatic security KPIs such as time to remediate, coverage, critical resolutions within SLA, threat model coverage, and audit readiness indicators. Maintain audit quality documentation, evidence, and records at all times. Customer and Stakeholder Engagement Support the sales process by responding to customer security questionnaires and due diligence requests with accuracy and confidence. Occasionally engage directly with customers on security topics, acting as a credible representative of Semble's security function. Work with internal stakeholders to ensure security requirements are understood and embedded across the business. What we are looking for Required Minimum of 5 years' experience in application security, product security, or a combination of software engineering and security with strong AppSec ownership. Hands on experience with Snyk across SCA, SAST, Container, and IaC, including CI/CD integration and policy management. Strong grounding in modern web and application security: OWASP Top 10, API Security Top 10, and emerging understanding of the OWASP Top 10 for Agentic Applications. Practical experience embedding security into Agile workflows and DevSecOps tooling. Solid understanding of authn/authz patterns, secrets management, encryption, and cloud native security controls. Experience with compliance frameworks, particularly ISO 27001; familiarity with Cyber Essentials+, NHS DSPT, or SOC 2 is a strong advantage. Practical understanding of AI security risks, including prompt injection, LLM vulnerabilities, and agentic system threats, and how to address them in a product context. Experience working in a SaaS environment or similarly regulated industry, appreciating the product, engineering, and commercial context that security decisions sit within. Ability to communicate clearly with engineers, leadership, and occasionally customers, translating complex security risk into clear, actionable language. Genuine, hands on AI experience: you must be able to discuss specific ways you are already using AI to improve security operations, detection, or engineering workflows. A track record of maintaining security programmes to a continuously high standard, with audit readiness as a default rather than a periodic event. A proactive, ownership mindset: you identify gaps, propose solutions, and deliver them without waiting to be told. Desirable CISSP certification (strongly preferred). Experience with threat modelling methodologies such as STRIDE or attack trees, and running effective threat model sessions with engineering teams. Familiarity with API gateways, container orchestration, and software supply chain security. Experience securing AI enabled features, ML pipelines, agentic workflows, or MCP based integrations. Experience building or maturing a security function within a scaling organisation. Exposure to healthcare data regulations and NHS security requirements. Proficiency in the French language (nice to have, not mandatory). Benefits £80-90k salary package, reflecting the specialist and technical nature of this role. Autonomy and ownership - you set the vision and run with it. 36 days off: 25 holidays + bank holidays + 3 extra days (birthday and feel good days). Private health insurance covering physical and mental health, as well as dental and optical. Hybrid & flexible work environment - work from anywhere in the UK, with some flexibility to work across Europe. Latest MacBook (or Windows) and equipment to set up a home office ergonomically. Equal Opportunity We welcome applications from people of all backgrounds and walks of life, including those from groups typically underrepresented in the technology industry. We also encourage applications from disabled and neurodiverse candidates. If there are adjustments we can make to support you throughout the recruitment process, please let us know.
SOC Analysts - Tier 1
Xypher Limited Doncaster, Yorkshire
The DigitalXRaid Security Operations Centre provides around the clock protective monitoring solutions to a client base that spans multiple industry verticals. Utilising industry-leading detection technology, our team of experienced SOC team members work to provide assurance detection and incident response capabilities to organisations of all sizes. DigitalXRaid are looking for a Level 1 SOC Analyst to join the Security Operations Centre and Incident Response team based United Kingdom. This role is shift based (4 on, 4 off) and operates a hybrid working operation. Key Responsibilities Analyse, Triage and Remediate Security Incidents through the ITSM platform Correctly Classify Security Incidents Identify and Escalate Validated Incidents to L2/L3 Analysts Within SLA Apply Basic Containment Actions (e.g. isolating endpoints) Where Authorised Participate in Various Stages of Incident Investigations Collaborate With Senior Analysts to Resolve Incidents Efficiently. Contribute to Enhancing SOC Such as Tuning Suggestions, Process Suggestions Assess URL and Domain Reputation Using Threat Intelligence Tools Key Skills 0-2 years of experience within a SOC environment Excellent communication skills and comfortable in a client facing role. A keen interest in cyber security and associated industries. Proven ability to effectively communicate when under pressure (high pressure situations may arise during ongoing incidents or attacks). Proven ability to adapt to difficult situations (high pressure situations may arise during ongoing incidents or attacks). Industry certifications are desirable to the role, such as Microsoft SC-200, AZ-500, SC-100, Security Blue Team L1 Experience in any of the following technologies would be advantageous - MS Sentinel, MS Defender, USM Anywhere, SentinelOne, Tenable IO
24/07/2026
Full time
The DigitalXRaid Security Operations Centre provides around the clock protective monitoring solutions to a client base that spans multiple industry verticals. Utilising industry-leading detection technology, our team of experienced SOC team members work to provide assurance detection and incident response capabilities to organisations of all sizes. DigitalXRaid are looking for a Level 1 SOC Analyst to join the Security Operations Centre and Incident Response team based United Kingdom. This role is shift based (4 on, 4 off) and operates a hybrid working operation. Key Responsibilities Analyse, Triage and Remediate Security Incidents through the ITSM platform Correctly Classify Security Incidents Identify and Escalate Validated Incidents to L2/L3 Analysts Within SLA Apply Basic Containment Actions (e.g. isolating endpoints) Where Authorised Participate in Various Stages of Incident Investigations Collaborate With Senior Analysts to Resolve Incidents Efficiently. Contribute to Enhancing SOC Such as Tuning Suggestions, Process Suggestions Assess URL and Domain Reputation Using Threat Intelligence Tools Key Skills 0-2 years of experience within a SOC environment Excellent communication skills and comfortable in a client facing role. A keen interest in cyber security and associated industries. Proven ability to effectively communicate when under pressure (high pressure situations may arise during ongoing incidents or attacks). Proven ability to adapt to difficult situations (high pressure situations may arise during ongoing incidents or attacks). Industry certifications are desirable to the role, such as Microsoft SC-200, AZ-500, SC-100, Security Blue Team L1 Experience in any of the following technologies would be advantageous - MS Sentinel, MS Defender, USM Anywhere, SentinelOne, Tenable IO
Senior Cyber Security Engineer
Baker Hughes Gruppe Nailsea, Somerset
Job Description Are you passionate about securing critical energy infrastructure and industrial control systems? Do you enjoy applying cyber security expertise to complex subsea production systems and real world engineering challenges? Join our team Baker Hughes is a global energy technology company operating in over 120 countries. We deliver innovative solutions that make energy safer, cleaner, and more efficient. Our engineering teams play a vital role in designing and delivering subsea production systems, control equipment, and digital solutions that enable reliable energy production worldwide. Cyber security is a critical enabler of safe and reliable operations. Our teams work to protect industrial control systems, communication networks, and subsea assets from evolving cyber threats while ensuring compliance with industry standards and regulatory requirements. Senior Cyber Security Engineer - Subsea Production Systems The Senior Cyber Security Engineer will be responsible for designing, implementing, and maintaining cyber security solutions across subsea control systems, SCADA environments, and associated digital infrastructure. You will work closely with system engineers, software teams, and product stakeholders to ensure that cyber security is embedded throughout the lifecycle of subsea production systems-from design through deployment and operation. The role requires a strong understanding of OT (Operational Technology) security, industrial communication protocols, and secure system architecture within safety critical environments. Responsibilities Designing and implementing secure architectures for subsea control systems, including topside and subsea communication networks Performing cyber security risk assessments, threat modeling, and vulnerability analysis for SPS and SCADA systems Defining and enforcing secure coding practices and design principles across PLC, HMI, and control software platforms Ensuring compliance with relevant standards such as IEC 62443, NIST, ISO 27001, and industry specific regulations Leading security reviews and audits across system designs, software releases, and project deliverables Supporting incident response and root cause analysis for cyber security events in operational environments Implementing and maintaining network segmentation, secure remote access, and monitoring controls for OT environments Collaborating with engineering teams to secure industrial protocols (e.g., OPC UA, Modbus TCP/IP, Ethernet/IP) Defining requirements for authentication, encryption, certificate management, and key infrastructure within subsea systems Providing technical guidance and mentorship to junior engineers and project teams on cyber security best practices Supporting customer engagements, including security documentation, compliance evidence, and technical responses Qualifications A Bachelor's or Master's degree in Cyber Security, Computer Engineering, Electrical Engineering, or a related field Significant experience in cyber security engineering within industrial/OT environments, preferably in oil & gas or energy Strong knowledge of industrial control systems (ICS), SCADA, and subsea production systems architectures Proven experience with cyber security standards and frameworks (IEC 62443 highly desirable) Familiarity with industrial communication protocols such as OPC UA, Modbus, TCP/IP, and secure communication design Experience with network security technologies, including firewalls, IDS/IPS, VPNs, and segmentation strategies Experience in risk assessment methodologies, penetration testing, or vulnerability management Have a permanent work permit in the UK Benefits Contemporary work life balance policies and wellbeing programs Comprehensive private medical care options Life insurance and disability coverage Tailored financial programs Additional elected or voluntary benefits Working Arrangement 4 days from office 1 day from home (remote) Equal Opportunity Employer Baker Hughes Company is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status, or other characteristics protected by law.
24/07/2026
Full time
Job Description Are you passionate about securing critical energy infrastructure and industrial control systems? Do you enjoy applying cyber security expertise to complex subsea production systems and real world engineering challenges? Join our team Baker Hughes is a global energy technology company operating in over 120 countries. We deliver innovative solutions that make energy safer, cleaner, and more efficient. Our engineering teams play a vital role in designing and delivering subsea production systems, control equipment, and digital solutions that enable reliable energy production worldwide. Cyber security is a critical enabler of safe and reliable operations. Our teams work to protect industrial control systems, communication networks, and subsea assets from evolving cyber threats while ensuring compliance with industry standards and regulatory requirements. Senior Cyber Security Engineer - Subsea Production Systems The Senior Cyber Security Engineer will be responsible for designing, implementing, and maintaining cyber security solutions across subsea control systems, SCADA environments, and associated digital infrastructure. You will work closely with system engineers, software teams, and product stakeholders to ensure that cyber security is embedded throughout the lifecycle of subsea production systems-from design through deployment and operation. The role requires a strong understanding of OT (Operational Technology) security, industrial communication protocols, and secure system architecture within safety critical environments. Responsibilities Designing and implementing secure architectures for subsea control systems, including topside and subsea communication networks Performing cyber security risk assessments, threat modeling, and vulnerability analysis for SPS and SCADA systems Defining and enforcing secure coding practices and design principles across PLC, HMI, and control software platforms Ensuring compliance with relevant standards such as IEC 62443, NIST, ISO 27001, and industry specific regulations Leading security reviews and audits across system designs, software releases, and project deliverables Supporting incident response and root cause analysis for cyber security events in operational environments Implementing and maintaining network segmentation, secure remote access, and monitoring controls for OT environments Collaborating with engineering teams to secure industrial protocols (e.g., OPC UA, Modbus TCP/IP, Ethernet/IP) Defining requirements for authentication, encryption, certificate management, and key infrastructure within subsea systems Providing technical guidance and mentorship to junior engineers and project teams on cyber security best practices Supporting customer engagements, including security documentation, compliance evidence, and technical responses Qualifications A Bachelor's or Master's degree in Cyber Security, Computer Engineering, Electrical Engineering, or a related field Significant experience in cyber security engineering within industrial/OT environments, preferably in oil & gas or energy Strong knowledge of industrial control systems (ICS), SCADA, and subsea production systems architectures Proven experience with cyber security standards and frameworks (IEC 62443 highly desirable) Familiarity with industrial communication protocols such as OPC UA, Modbus, TCP/IP, and secure communication design Experience with network security technologies, including firewalls, IDS/IPS, VPNs, and segmentation strategies Experience in risk assessment methodologies, penetration testing, or vulnerability management Have a permanent work permit in the UK Benefits Contemporary work life balance policies and wellbeing programs Comprehensive private medical care options Life insurance and disability coverage Tailored financial programs Additional elected or voluntary benefits Working Arrangement 4 days from office 1 day from home (remote) Equal Opportunity Employer Baker Hughes Company is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status, or other characteristics protected by law.
Senior SOC Engineer
Nomios Basingstoke, Hampshire
Nomios' mission is to build a 'secure and connected' future. Organisations across Europe depend on us to help secure and connect their digital infrastructures. In support of our continued UK growth, we are seeking a Senior SOC Engineer to join our Security Operations team. This role presents a great opportunity to shape the direction of a modern, technology focused SOC that values engineering excellence, deep technical capability and a culture of innovation. You will work with a broad and diverse customer base that relies on Nomios to deliver meaningful and effective security outcomes. Your role as Senior SOC Engineer As a Senior SOC Engineer at Nomios, you'll lead the design, deployment, and ongoing improvement of the technologies that underpin our SOC, including SIEM, XDR, SOAR, scripting, and automation. From building custom log parsers and response workflows to developing platform architecture, you'll drive meaningful enhancements to our detection and response capabilities. You'll play a central role in security orchestration and automation, helping reduce time to detect and respond by refining playbooks and building intelligent workflows. You'll also lead customer onboarding in collaboration with SOC Operations, ensuring secure, efficient deployments aligned with our model. Working directly with SIEM/XDR platforms and custom tooling, you'll have access to dedicated SOC infrastructure: lab environments for malware analysis, detection testing, threat intel development, and proof of concepts. You'll be part of a high-performing team that values hands-on expertise, technical leadership, and continuous growth. Our SOC culture is built by engineers who've progressed through roles in security operations, threat intelligence, and engineering. You'll benefit from cyber ranges, training labs, and the freedom to shape your development path. As part of a leading MSSP, you'll gain exposure to a wide range of industries, from government and defence to healthcare, telecoms, legal, and manufacturing, broadening your knowledge of real-world security practices. Whether you're a seasoned Senior Engineer or ready to step up, this role offers ownership, impact, and the chance to help shape the mission. Key Responsibilities Build Mentor and guide SOC engineers and analysts, supporting their technical development and helping them grow within a high-performance team. Design, develop and maintain automation across key SOC workflows, improving efficiency, response speed and consistency. Create and manage log parsing and data normalisation across a variety of internal and external sources, ensuring high quality telemetry across the estate. Architect and implement SIEM and XDR environments tailored to both internal use and customer-facing deployments. Deploy, manage and continually enhance core SOC technologies, including SIEM, XDR, SOAR, vulnerability management and custom automation scripts, all supported by our dedicated in-house infrastructure and lab environments. Investigate Act as a senior escalation point during complex engineering incidents across both internal systems and managed customer environments. Work with the wider engineering team to document, maintain and improve internal wikis and deployment guides, ensuring consistent and high quality engineering delivery across the team. Improve Reporting to the Lead SOC Engineer, collaborate with the Head of Security Operations, on the ongoing development and execution of the SOC's engineering maturity roadmap. Continuously assess and deliver automation and process improvements, both internally and across customer environments, to enhance detection, response and operational efficiency. Apply lessons learned from incidents, threat intelligence and emerging attack techniques to refine and improve engineering output, ensuring the SOC remains agile, proactive and threat-driven. We hire result-orientated, smart, and high-energy individuals who bring a can-do attitude and a willingness to go the extra mile and deliver exceptional outcomes. You should be organised and rigorous, with excellent analytical skills. Good communication with customers and internal stakeholders is vital, as is the ability to work as part of a dynamic team. Required technical skills include: Expert Knowledge of SOAR - including developing custom automation and integrations. Preferred vendors: Palo Alto Cortex XSOAR, Logic Apps, Siemplify, Jupyter Notebooks Good Knowledge of Cloud Environments & Architecture - including developing custom automation and integrations via API with proficiency in at least one scripting language (preferably Python or GO). Preferred vendors: Azure, AWS, GCP Expert Knowledge of SIEM Architecture and Design - Including familiarity in SIEM deployment and architecture of at least one cloud environment (GCP, AWS, Azure, IBM). Preferred vendors: Microsoft Sentinel, Google SecOps, XSIAM Expert Knowledge of EDR/XDR - including configuration and deployment/maintenance. Preferred vendors: CrowdStrike, Microsoft Defender, Palo Alto XDR, SentinelOne Intermediate Knowledge of VM - including deployment, automation of reporting. Preferred vendors: Rapid 7, Tennable Intermediate Knowledge of CTI - including ingestion methodologies, and common ingestion and parsing methods (STIX/TAXII). Preferred vendors: Mandiant Additional requirements include: 3-5 years' experience working within a Security Operations Centre (SOC) as a security engineer. Proven experience in SOC automation, log source parsing and configuration of security toolsets. Fluent in English with excellent written and oral communication skills. Eligible for SC or DV clearance is required. Ability to use initiative and work independently. Strong team player. Job Specifics Location: This is a hybrid role, requiring attendance at our Basingstoke office (free hot & cold drinks, breakfast items, snacks, lunches, and regular takeaway Fridays are provided to all staff in the office!). Hours: Full-time, Monday-Friday, 9:00am-5:30pm Why would you choose to come and work with us? We invest in our people. You will get to work in a dynamic, fast-paced environment where you are free to use your initiative in support of our strategic objectives. You will work alongside high calibre sales, technical, and operational experts as part of a supportive, tight-knit team, within which every individual has an important part to play and makes a real difference. Nomios offers a highly competitive salary and commission scheme along with industry-leading benefits. Ready to make an impact? Apply now! Nomios is an equal opportunity employer and is committed to creating and sustaining an environment in which everyone is provided with an equal opportunity to grow and develop, and no individual will be unjustly discriminated against. This includes, but is not limited to, discrimination because of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion and belief, sex and sexual orientation.
24/07/2026
Full time
Nomios' mission is to build a 'secure and connected' future. Organisations across Europe depend on us to help secure and connect their digital infrastructures. In support of our continued UK growth, we are seeking a Senior SOC Engineer to join our Security Operations team. This role presents a great opportunity to shape the direction of a modern, technology focused SOC that values engineering excellence, deep technical capability and a culture of innovation. You will work with a broad and diverse customer base that relies on Nomios to deliver meaningful and effective security outcomes. Your role as Senior SOC Engineer As a Senior SOC Engineer at Nomios, you'll lead the design, deployment, and ongoing improvement of the technologies that underpin our SOC, including SIEM, XDR, SOAR, scripting, and automation. From building custom log parsers and response workflows to developing platform architecture, you'll drive meaningful enhancements to our detection and response capabilities. You'll play a central role in security orchestration and automation, helping reduce time to detect and respond by refining playbooks and building intelligent workflows. You'll also lead customer onboarding in collaboration with SOC Operations, ensuring secure, efficient deployments aligned with our model. Working directly with SIEM/XDR platforms and custom tooling, you'll have access to dedicated SOC infrastructure: lab environments for malware analysis, detection testing, threat intel development, and proof of concepts. You'll be part of a high-performing team that values hands-on expertise, technical leadership, and continuous growth. Our SOC culture is built by engineers who've progressed through roles in security operations, threat intelligence, and engineering. You'll benefit from cyber ranges, training labs, and the freedom to shape your development path. As part of a leading MSSP, you'll gain exposure to a wide range of industries, from government and defence to healthcare, telecoms, legal, and manufacturing, broadening your knowledge of real-world security practices. Whether you're a seasoned Senior Engineer or ready to step up, this role offers ownership, impact, and the chance to help shape the mission. Key Responsibilities Build Mentor and guide SOC engineers and analysts, supporting their technical development and helping them grow within a high-performance team. Design, develop and maintain automation across key SOC workflows, improving efficiency, response speed and consistency. Create and manage log parsing and data normalisation across a variety of internal and external sources, ensuring high quality telemetry across the estate. Architect and implement SIEM and XDR environments tailored to both internal use and customer-facing deployments. Deploy, manage and continually enhance core SOC technologies, including SIEM, XDR, SOAR, vulnerability management and custom automation scripts, all supported by our dedicated in-house infrastructure and lab environments. Investigate Act as a senior escalation point during complex engineering incidents across both internal systems and managed customer environments. Work with the wider engineering team to document, maintain and improve internal wikis and deployment guides, ensuring consistent and high quality engineering delivery across the team. Improve Reporting to the Lead SOC Engineer, collaborate with the Head of Security Operations, on the ongoing development and execution of the SOC's engineering maturity roadmap. Continuously assess and deliver automation and process improvements, both internally and across customer environments, to enhance detection, response and operational efficiency. Apply lessons learned from incidents, threat intelligence and emerging attack techniques to refine and improve engineering output, ensuring the SOC remains agile, proactive and threat-driven. We hire result-orientated, smart, and high-energy individuals who bring a can-do attitude and a willingness to go the extra mile and deliver exceptional outcomes. You should be organised and rigorous, with excellent analytical skills. Good communication with customers and internal stakeholders is vital, as is the ability to work as part of a dynamic team. Required technical skills include: Expert Knowledge of SOAR - including developing custom automation and integrations. Preferred vendors: Palo Alto Cortex XSOAR, Logic Apps, Siemplify, Jupyter Notebooks Good Knowledge of Cloud Environments & Architecture - including developing custom automation and integrations via API with proficiency in at least one scripting language (preferably Python or GO). Preferred vendors: Azure, AWS, GCP Expert Knowledge of SIEM Architecture and Design - Including familiarity in SIEM deployment and architecture of at least one cloud environment (GCP, AWS, Azure, IBM). Preferred vendors: Microsoft Sentinel, Google SecOps, XSIAM Expert Knowledge of EDR/XDR - including configuration and deployment/maintenance. Preferred vendors: CrowdStrike, Microsoft Defender, Palo Alto XDR, SentinelOne Intermediate Knowledge of VM - including deployment, automation of reporting. Preferred vendors: Rapid 7, Tennable Intermediate Knowledge of CTI - including ingestion methodologies, and common ingestion and parsing methods (STIX/TAXII). Preferred vendors: Mandiant Additional requirements include: 3-5 years' experience working within a Security Operations Centre (SOC) as a security engineer. Proven experience in SOC automation, log source parsing and configuration of security toolsets. Fluent in English with excellent written and oral communication skills. Eligible for SC or DV clearance is required. Ability to use initiative and work independently. Strong team player. Job Specifics Location: This is a hybrid role, requiring attendance at our Basingstoke office (free hot & cold drinks, breakfast items, snacks, lunches, and regular takeaway Fridays are provided to all staff in the office!). Hours: Full-time, Monday-Friday, 9:00am-5:30pm Why would you choose to come and work with us? We invest in our people. You will get to work in a dynamic, fast-paced environment where you are free to use your initiative in support of our strategic objectives. You will work alongside high calibre sales, technical, and operational experts as part of a supportive, tight-knit team, within which every individual has an important part to play and makes a real difference. Nomios offers a highly competitive salary and commission scheme along with industry-leading benefits. Ready to make an impact? Apply now! Nomios is an equal opportunity employer and is committed to creating and sustaining an environment in which everyone is provided with an equal opportunity to grow and develop, and no individual will be unjustly discriminated against. This includes, but is not limited to, discrimination because of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion and belief, sex and sexual orientation.
Senior Cyber Security Engineer (CyberArk & PAM)
SYSGROUP PLC Edinburgh, Midlothian
Senior Cyber Security Engineer (CyberArk & PAM) Edinburgh, United Kingdom Posted on 16/07/2026 SysGroup ishiring a Senior Cyber Security Engineer specialising in privileged accessmanagement, with CyberArk as the core platform. This is the senior tooling andidentity specialist role in the Cyber Security team under our 2026 operatingmodel: you own the design, deployment and health of the security tooling estateacross our managed clients, with PAM as your deepest expertise. BeyondCyberArk, the role carries breadth across the modern security stack: hands-onexperience with Zscaler (ZIA/ZPA) and working capability across EDR, SIEM, vulnerability management and the wider cyber product set we operate forclients. You will reportto the Cyber Operations Lead and work closely with the SOC engineers, thePre-sales Security Consultant and the Platform & Infrastructure teams. CyberArk & privileged access management Own CyberArk design, deployment and operation across managed clients: vaulting, session management, secretsmanagement and privileged threat analytics. Design PAM onboarding programmes for new clients: discovery, scoping, policy design and rollout. Integrate PAM with the wideridentity stack: Entra ID, conditional access, MFA and just-in-time accesspatterns. Set privileged access standards and evidence them for client audits (ISO 27001, Cyber Essentials Plus). Security tooling & engineering Deploy, configure and maintain the security tooling estate: EDR, SIEM integrations, vulnerability scanning and email security. Support Zscaler (ZIA/ZPA)deployment and policy work alongside the zero trust leads. Own tooling health: versioncurrency, coverage gaps, tuning quality and integration reliability. Automate deployment and operational tasks with scripts and APIs; contribute to the shared automation library. Act as senior escalation foridentity and tooling incidents; support major incident response. Document designs, runbooks and standards to a level the wider team can operate from. Contribute tooling and PAMexpertise to service reviews and solution scoping when needed. Adopt AI-assisted workflows for diagnostics, configuration review and documentation. Experience 5+ years in security engineering with 2+ years of hands on CyberArk design and administration (PAM Self Hosted or Privilege Cloud). Experience deploying or operating Zscaler (ZIA/ZPA) and at least two of: EDR platforms, SIEM, vulnerability management, email security. Strong scripting capability (PowerShell or Python) applied to security tooling automation and integration. MSP/MSSP or multi client environment experience preferred; client audit exposure an advantage. Certifications Essential (or equivalent hands on experience): CyberArk Defender certification; CyberArk Sentry strongly preferred. Desirable: CyberArk Guardian, Zscaler professional level certification (ZIA/ZPA), Microsoft SC 300, SC 200, AZ 500, or EDR vendor certifications. Why Join Us? Joining Sysgroup means becoming part of adynamic and innovative team that is dedicated to excellence. We offer a supportive, and collaborative work environment, where your ideas and contributions are valued. Here are some of the benefits of working with us: Competitive Compensation We offer a competitive salary package, including performance-based incentives, to reward your hard work and achievements. Private Healthcare Life insurance Pension We believe in investing in our employees' professional development. You will have your own individual development learning paths with access to various training material and ongoing career advancement opportunities.
22/07/2026
Full time
Senior Cyber Security Engineer (CyberArk & PAM) Edinburgh, United Kingdom Posted on 16/07/2026 SysGroup ishiring a Senior Cyber Security Engineer specialising in privileged accessmanagement, with CyberArk as the core platform. This is the senior tooling andidentity specialist role in the Cyber Security team under our 2026 operatingmodel: you own the design, deployment and health of the security tooling estateacross our managed clients, with PAM as your deepest expertise. BeyondCyberArk, the role carries breadth across the modern security stack: hands-onexperience with Zscaler (ZIA/ZPA) and working capability across EDR, SIEM, vulnerability management and the wider cyber product set we operate forclients. You will reportto the Cyber Operations Lead and work closely with the SOC engineers, thePre-sales Security Consultant and the Platform & Infrastructure teams. CyberArk & privileged access management Own CyberArk design, deployment and operation across managed clients: vaulting, session management, secretsmanagement and privileged threat analytics. Design PAM onboarding programmes for new clients: discovery, scoping, policy design and rollout. Integrate PAM with the wideridentity stack: Entra ID, conditional access, MFA and just-in-time accesspatterns. Set privileged access standards and evidence them for client audits (ISO 27001, Cyber Essentials Plus). Security tooling & engineering Deploy, configure and maintain the security tooling estate: EDR, SIEM integrations, vulnerability scanning and email security. Support Zscaler (ZIA/ZPA)deployment and policy work alongside the zero trust leads. Own tooling health: versioncurrency, coverage gaps, tuning quality and integration reliability. Automate deployment and operational tasks with scripts and APIs; contribute to the shared automation library. Act as senior escalation foridentity and tooling incidents; support major incident response. Document designs, runbooks and standards to a level the wider team can operate from. Contribute tooling and PAMexpertise to service reviews and solution scoping when needed. Adopt AI-assisted workflows for diagnostics, configuration review and documentation. Experience 5+ years in security engineering with 2+ years of hands on CyberArk design and administration (PAM Self Hosted or Privilege Cloud). Experience deploying or operating Zscaler (ZIA/ZPA) and at least two of: EDR platforms, SIEM, vulnerability management, email security. Strong scripting capability (PowerShell or Python) applied to security tooling automation and integration. MSP/MSSP or multi client environment experience preferred; client audit exposure an advantage. Certifications Essential (or equivalent hands on experience): CyberArk Defender certification; CyberArk Sentry strongly preferred. Desirable: CyberArk Guardian, Zscaler professional level certification (ZIA/ZPA), Microsoft SC 300, SC 200, AZ 500, or EDR vendor certifications. Why Join Us? Joining Sysgroup means becoming part of adynamic and innovative team that is dedicated to excellence. We offer a supportive, and collaborative work environment, where your ideas and contributions are valued. Here are some of the benefits of working with us: Competitive Compensation We offer a competitive salary package, including performance-based incentives, to reward your hard work and achievements. Private Healthcare Life insurance Pension We believe in investing in our employees' professional development. You will have your own individual development learning paths with access to various training material and ongoing career advancement opportunities.
Senior DevSecOps Engineer
Certus Sales Recruitment
Senior DevSecOps Engineer London (Hybrid - 1 day per week in office) £70,000-£100,000 + Benefits Certus Recruitment is partnering with an ambitious fintech business building a next-generation regulated financial platform. As they move from proof of concept to full production deployment, they are seeking a Senior DevSecOps Engineer to take ownership of the operational, infrastructure, and security foundations that will support long term growth. This is a high impact role for someone who enjoys building secure, scalable, and compliant environments from the ground up. You'll become the technical authority across infrastructure, cloud operations, DevSecOps, platform security, and compliance readiness, ensuring the business can meet the rigorous standards expected within a regulated financial environment. Working closely with engineering leadership, you will be responsible for creating the systems, controls, processes, and evidence required to support a secure and auditable production platform. Key Responsibilities Own infrastructure, platform security, and operational readiness across the business Design and implement secure cloud environments and production grade infrastructure Lead security initiatives including vulnerability management, threat modelling, penetration testing, and incident response planning Build and evolve CI/CD pipelines, release management processes, and deployment automation Establish observability, monitoring, logging, alerting, and operational runbooks Manage secrets, key custody, access controls, and infrastructure governance Deliver backup, disaster recovery, and business continuity strategies Drive compliance readiness for SOC 2, ISO 27001, and regulatory audits Partner with software engineering teams to ensure applications are secure, observable, and production ready Lead infrastructure migration and cloud hardening initiatives Required Experience 6+ years of engineering experience with at least 3 years focused on infrastructure, DevSecOps, platform engineering, or security Proven experience operating within highly regulated environments such as fintech, banking, payments, financial services, healthcare, defence, or similar sectors Experience taking systems from early stage development through to secure production deployment Strong background in cloud infrastructure, automation, and operational security Experience supporting or leading SOC 2 Type II and/or ISO 27001 programmes Strong documentation and communication skills with the ability to create clear technical and compliance focused artefacts Comfortable acting as the subject matter expert across security, infrastructure, and operational best practices Technical Experience Terraform and Infrastructure as Code environments Kubernetes, Docker, and containerised application deployment Modern CI/CD platforms including GitHub Actions, Cloud Build, Buildkite, CircleCI, or similar Cloud platforms, ideally GCP Observability tooling including Prometheus, Grafana, OpenTelemetry, or equivalent PostgreSQL operations, backup, recovery, and data durability Identity management, API gateways, networking, and access controls Bash and Python scripting for automation and tooling Desirable Experience Exposure to blockchain infrastructure, digital assets, or cryptocurrency ecosystems Experience with HSM, KMS, key management, or cryptographic systems Familiarity with Kubernetes security, service meshes, and zero trust architectures Knowledge of event driven architectures and messaging platforms such as Kafka Understanding of UK financial services regulation and compliance frameworks Experience supporting cloud migrations and multi environment platform strategies This is an opportunity to join a business at a pivotal stage of growth and play a leading role in building the infrastructure and security foundations of a highly regulated financial platform. The successful candidate will enjoy significant ownership, technical autonomy, and the opportunity to shape best practices from the ground up.
22/07/2026
Full time
Senior DevSecOps Engineer London (Hybrid - 1 day per week in office) £70,000-£100,000 + Benefits Certus Recruitment is partnering with an ambitious fintech business building a next-generation regulated financial platform. As they move from proof of concept to full production deployment, they are seeking a Senior DevSecOps Engineer to take ownership of the operational, infrastructure, and security foundations that will support long term growth. This is a high impact role for someone who enjoys building secure, scalable, and compliant environments from the ground up. You'll become the technical authority across infrastructure, cloud operations, DevSecOps, platform security, and compliance readiness, ensuring the business can meet the rigorous standards expected within a regulated financial environment. Working closely with engineering leadership, you will be responsible for creating the systems, controls, processes, and evidence required to support a secure and auditable production platform. Key Responsibilities Own infrastructure, platform security, and operational readiness across the business Design and implement secure cloud environments and production grade infrastructure Lead security initiatives including vulnerability management, threat modelling, penetration testing, and incident response planning Build and evolve CI/CD pipelines, release management processes, and deployment automation Establish observability, monitoring, logging, alerting, and operational runbooks Manage secrets, key custody, access controls, and infrastructure governance Deliver backup, disaster recovery, and business continuity strategies Drive compliance readiness for SOC 2, ISO 27001, and regulatory audits Partner with software engineering teams to ensure applications are secure, observable, and production ready Lead infrastructure migration and cloud hardening initiatives Required Experience 6+ years of engineering experience with at least 3 years focused on infrastructure, DevSecOps, platform engineering, or security Proven experience operating within highly regulated environments such as fintech, banking, payments, financial services, healthcare, defence, or similar sectors Experience taking systems from early stage development through to secure production deployment Strong background in cloud infrastructure, automation, and operational security Experience supporting or leading SOC 2 Type II and/or ISO 27001 programmes Strong documentation and communication skills with the ability to create clear technical and compliance focused artefacts Comfortable acting as the subject matter expert across security, infrastructure, and operational best practices Technical Experience Terraform and Infrastructure as Code environments Kubernetes, Docker, and containerised application deployment Modern CI/CD platforms including GitHub Actions, Cloud Build, Buildkite, CircleCI, or similar Cloud platforms, ideally GCP Observability tooling including Prometheus, Grafana, OpenTelemetry, or equivalent PostgreSQL operations, backup, recovery, and data durability Identity management, API gateways, networking, and access controls Bash and Python scripting for automation and tooling Desirable Experience Exposure to blockchain infrastructure, digital assets, or cryptocurrency ecosystems Experience with HSM, KMS, key management, or cryptographic systems Familiarity with Kubernetes security, service meshes, and zero trust architectures Knowledge of event driven architectures and messaging platforms such as Kafka Understanding of UK financial services regulation and compliance frameworks Experience supporting cloud migrations and multi environment platform strategies This is an opportunity to join a business at a pivotal stage of growth and play a leading role in building the infrastructure and security foundations of a highly regulated financial platform. The successful candidate will enjoy significant ownership, technical autonomy, and the opportunity to shape best practices from the ground up.
Inspire People
Senior Security Engineer
Inspire People South Croydon, Surrey
HM Land Registry (HMLR) are looking for a Senior Infrastructure Engineer in the Security Cluster to help protect the critical infrastructure and digital services that support land and property ownership across England and Wales. Permanent role, salary £48,400 - £59,300 (based on interview assessment), 29% employer pension contribution plus full Civil Service benefits. Flexible, hybrid working from Plymouth. About the role This is a specialist role within HMLR's IT Operations Practice, working as part of an established Security function responsible for protecting systems, platforms and services across a varied technology estate. You will help design, implement and improve technical security controls across cloud, on-premise and legacy environments. The role will involve resolving complex technical issues, managing security risks, improving vulnerability tooling and providing security advice to operational and project teams. You will work across technologies including Windows, Linux, mainframe, AWS and Azure, while collaborating with infrastructure teams, security colleagues, suppliers and wider stakeholders. Responsibilities Design, implement and improve technical security systems and controls across HMLR's infrastructure. Investigate and resolve complex security issues arising from incidents, operational activity and service development. Identify and manage technical security risks, vulnerabilities and appropriate mitigations. Develop and maintain security monitoring, vulnerability and threat-detection tooling. Provide technical guidance, assurance and mentoring to operational teams, projects and colleagues. Essential skills Strong experience designing and implementing technical security systems and controls. Advanced knowledge of at least three security technologies, such as SIEM, Defender, Sentinel, EDR/XDR, Active Directory, Nessus, PAM, AWS IAM or Entra. Extensive knowledge of security controls across Windows, Linux, mainframe, AWS or Azure environments. Strong analytical and problem-solving skills, including threat analysis and security incident response. Ability to manage priorities, communicate technical risks clearly and demonstrate leadership through coaching or mentoring. Desirable criteria Experience working across both cloud and on-premise environments. Knowledge of identity and access management, privileged access, cryptography or network security. Experience using automation, scripting or coding to improve operational security. Experience supporting customer-facing digital services within a large or complex organisation. Previous experience working within government, a regulated environment or another organisation operating critical services. Benefits Alongside your salary of £48,400 plus any allowance up to £59,300 HM Land Registry contributes £14,021 towards you being a member of the Civil Service Defined Benefit Pension scheme along with the following: Annual leave of 28.5 days' paid holiday during each holiday year plus 8 days public holidays A clear progression pathway inc. personalised training and development plans including expensed accreditations with training days set aside Over 29% employer pension contribution Flexi-time scheme (You decide what working hours work best for you) Opportunity to work condensed hours Social and sports club Access to our employee assistance programme for counselling and support on a wide range of issues Interest-free loan for season tickets Cycle to work scheme (salary sacrifice). HMLR have a strong and positive culture, a commitment to inclusivity, an emphasis on continuous learning and development and flexible ways of working. Additional information Locations - Plymouth. Expectation is to be working from the Plymouth office 60% of your time across the month (typically 3 days/week), hours are flexible and condensed hours are an option. HMLR are unable to sponsor any individuals for Skilled Worker Sponsorship. For SC eligibility, you must have resided in the UK for the last 5 years continuously Why join HMLR? This is an opportunity to help protect critical national infrastructure and digital services relied upon across England and Wales. You will work at significant scale, strengthening the security and resilience of a complex technology estate that supports millions of property transactions and users. You will also have substantial scope to develop your career. The breadth of HMLR's environment will give you exposure to cloud, on-premise, legacy and modern security technologies, alongside opportunities to deepen your expertise, broaden into new areas and learn from experienced specialists across the wider security function. Apply now or contact Inspire People in complete confidence.
22/07/2026
Full time
HM Land Registry (HMLR) are looking for a Senior Infrastructure Engineer in the Security Cluster to help protect the critical infrastructure and digital services that support land and property ownership across England and Wales. Permanent role, salary £48,400 - £59,300 (based on interview assessment), 29% employer pension contribution plus full Civil Service benefits. Flexible, hybrid working from Plymouth. About the role This is a specialist role within HMLR's IT Operations Practice, working as part of an established Security function responsible for protecting systems, platforms and services across a varied technology estate. You will help design, implement and improve technical security controls across cloud, on-premise and legacy environments. The role will involve resolving complex technical issues, managing security risks, improving vulnerability tooling and providing security advice to operational and project teams. You will work across technologies including Windows, Linux, mainframe, AWS and Azure, while collaborating with infrastructure teams, security colleagues, suppliers and wider stakeholders. Responsibilities Design, implement and improve technical security systems and controls across HMLR's infrastructure. Investigate and resolve complex security issues arising from incidents, operational activity and service development. Identify and manage technical security risks, vulnerabilities and appropriate mitigations. Develop and maintain security monitoring, vulnerability and threat-detection tooling. Provide technical guidance, assurance and mentoring to operational teams, projects and colleagues. Essential skills Strong experience designing and implementing technical security systems and controls. Advanced knowledge of at least three security technologies, such as SIEM, Defender, Sentinel, EDR/XDR, Active Directory, Nessus, PAM, AWS IAM or Entra. Extensive knowledge of security controls across Windows, Linux, mainframe, AWS or Azure environments. Strong analytical and problem-solving skills, including threat analysis and security incident response. Ability to manage priorities, communicate technical risks clearly and demonstrate leadership through coaching or mentoring. Desirable criteria Experience working across both cloud and on-premise environments. Knowledge of identity and access management, privileged access, cryptography or network security. Experience using automation, scripting or coding to improve operational security. Experience supporting customer-facing digital services within a large or complex organisation. Previous experience working within government, a regulated environment or another organisation operating critical services. Benefits Alongside your salary of £48,400 plus any allowance up to £59,300 HM Land Registry contributes £14,021 towards you being a member of the Civil Service Defined Benefit Pension scheme along with the following: Annual leave of 28.5 days' paid holiday during each holiday year plus 8 days public holidays A clear progression pathway inc. personalised training and development plans including expensed accreditations with training days set aside Over 29% employer pension contribution Flexi-time scheme (You decide what working hours work best for you) Opportunity to work condensed hours Social and sports club Access to our employee assistance programme for counselling and support on a wide range of issues Interest-free loan for season tickets Cycle to work scheme (salary sacrifice). HMLR have a strong and positive culture, a commitment to inclusivity, an emphasis on continuous learning and development and flexible ways of working. Additional information Locations - Plymouth. Expectation is to be working from the Plymouth office 60% of your time across the month (typically 3 days/week), hours are flexible and condensed hours are an option. HMLR are unable to sponsor any individuals for Skilled Worker Sponsorship. For SC eligibility, you must have resided in the UK for the last 5 years continuously Why join HMLR? This is an opportunity to help protect critical national infrastructure and digital services relied upon across England and Wales. You will work at significant scale, strengthening the security and resilience of a complex technology estate that supports millions of property transactions and users. You will also have substantial scope to develop your career. The breadth of HMLR's environment will give you exposure to cloud, on-premise, legacy and modern security technologies, alongside opportunities to deepen your expertise, broaden into new areas and learn from experienced specialists across the wider security function. Apply now or contact Inspire People in complete confidence.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board