Senior IT Security Engineer SOC Engineer Southend on Sea, Essex 70,000 + benefits Full-Time Permanent Hybrid Are you an experienced SOC Engineer looking to play a key role in a small infrastructure team? We're working with a well-established, technology-led organisation who are investing in their cyber capability and looking for an IT Security / SOC Engineer to play a key role in protecting their systems, infrastructure, and data. This is a hands-on position where you'll contribute to threat detection, incident response, and continuous security improvement across the business. What You'll Be Doing Monitoring and analysing security events (SIEM, endpoints, networks) Investigating incidents, performing root cause analysis and remediation Identifying vulnerabilities and driving proactive security improvements Acting as the go-to escalation point for security issues Supporting compliance with security standards and best practice Working closely with IT and wider teams to embed security across systems What We're Looking For Experience in a cybersecurity / IT security role Strong knowledge of security tools (SIEM (Sentinel), EDR/XDR, firewalls, IDS) Experience working in a SOC/NOC or similar environment Good understanding of security frameworks (ISO 27001, NIST, GDPR etc.) Ability to investigate threats and respond to incidents effectively Bonus points for: Security certifications (Security+, CEH, CISM, CISA) Scripting/automation experience (e.g. PowerShell) What's On Offer Flexitime + early Friday finish 24 days holiday + bank holidays Pension (6-7%), life assurance & sick pay Free parking, onsite caf & gym access If you're looking for a role where you can influence strategy and make a real impact, this is well worth a conversation. Security Clearance is required for this role - applicants need to be eligible for UK Security clearance. Hit apply to upload your CV or contact (url removed) Spectrum IT Recruitment (South) Limited is acting as an Employment Agency in relation to this vacancy.
21/07/2026
Full time
Senior IT Security Engineer SOC Engineer Southend on Sea, Essex 70,000 + benefits Full-Time Permanent Hybrid Are you an experienced SOC Engineer looking to play a key role in a small infrastructure team? We're working with a well-established, technology-led organisation who are investing in their cyber capability and looking for an IT Security / SOC Engineer to play a key role in protecting their systems, infrastructure, and data. This is a hands-on position where you'll contribute to threat detection, incident response, and continuous security improvement across the business. What You'll Be Doing Monitoring and analysing security events (SIEM, endpoints, networks) Investigating incidents, performing root cause analysis and remediation Identifying vulnerabilities and driving proactive security improvements Acting as the go-to escalation point for security issues Supporting compliance with security standards and best practice Working closely with IT and wider teams to embed security across systems What We're Looking For Experience in a cybersecurity / IT security role Strong knowledge of security tools (SIEM (Sentinel), EDR/XDR, firewalls, IDS) Experience working in a SOC/NOC or similar environment Good understanding of security frameworks (ISO 27001, NIST, GDPR etc.) Ability to investigate threats and respond to incidents effectively Bonus points for: Security certifications (Security+, CEH, CISM, CISA) Scripting/automation experience (e.g. PowerShell) What's On Offer Flexitime + early Friday finish 24 days holiday + bank holidays Pension (6-7%), life assurance & sick pay Free parking, onsite caf & gym access If you're looking for a role where you can influence strategy and make a real impact, this is well worth a conversation. Security Clearance is required for this role - applicants need to be eligible for UK Security clearance. Hit apply to upload your CV or contact (url removed) Spectrum IT Recruitment (South) Limited is acting as an Employment Agency in relation to this vacancy.
Job Title: OT Cyber Security Analyst - SC Location: Culham, Oxfordshire 2 days/week on site) Contract Duration; 18/12/26 Daily Rate: £50/hr (Umbrella - Maximum) IR35 Status : Inside IR35 Security Clearance: SC or lapsed within the last 12 months The OT Cyber Security Analyst is responsible for the implementation, operation, and continuous improvement of OT security controls and monitoring capabilities across environments. The role delivers hands-on security engineering and operational support, ensuring OT systems are protected in line with defined strategy, standards, and risk priorities. This includes implementing an OT Security Strategy, contributing to the development of policies and standards, and apply appropriate security controls across OT environments. You will provide technical and governance compliance of OT security, ensuring alignment with industry frameworks (IEC 62443, NIST CSF, CAF, ISO 27001) and with enterprise cyber security objectives. The role will combine hands-on implementation and the creation of governance artefacts. You will also engage with engineering teams and managed service providers (MSPs) to ensure that OT security controls are effectively implemented and sustained. Experience with SIEM/SOC integration is valuable and considered desirable. Essential: Oil/gas/rail/chemical process industry Familiarity with SIEM/SOC integration for OT environments Demonstrable experience in maturing OT security within ICS or critical infrastructure environments. Proven ability implement OT security strategies, policies, and standards. Strong knowledge of OT security frameworks and standards (IEC 62443, NIST CSF, CAF, ISO 27001). Experience conducting OT security risk assessments, gap analysis, and remediation planning. Knowledge of OT networks, segmentation, and common industrial protocols. Experience working with operations and engineering teams in OT environments. Ability to provide technical recommendations for MSPs or third-party security service providers. Strong communication and documentation skills, particularly in policy/standards creation. Desirable: Experience with OT asset discovery, monitoring, and security tool deployment. Exposure to regulatory compliance in critical infrastructure (eg, NIS Directive, UK CAF). Knowledge of project and service delivery life cycles and ITSM controls. Disability Confident As a member of the disability confident scheme, CLIENT guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Armed Forces Covenant CLIENT is proud to support the Armed Forces Covenant and as such, we guarantee to interview all veterans or spouses/partners of military personnel who meet all the essential criteria for the vacancy. In cases where we have a high volume of ex-military candidates/military spouses or partners, who meet all of the essential criteria, we will interview the best candidates from within that group. If you qualify for the above, please notify us. We will be in touch to discuss your suitability and arrange your Guaranteed Interview. Should you require reasonable adjustments at any point during the recruitment process or if there is a more accessible way for us to communicate, please do let me know. To apply for this role please submit your latest CV or contact Aspect Resources
20/07/2026
Contractor
Job Title: OT Cyber Security Analyst - SC Location: Culham, Oxfordshire 2 days/week on site) Contract Duration; 18/12/26 Daily Rate: £50/hr (Umbrella - Maximum) IR35 Status : Inside IR35 Security Clearance: SC or lapsed within the last 12 months The OT Cyber Security Analyst is responsible for the implementation, operation, and continuous improvement of OT security controls and monitoring capabilities across environments. The role delivers hands-on security engineering and operational support, ensuring OT systems are protected in line with defined strategy, standards, and risk priorities. This includes implementing an OT Security Strategy, contributing to the development of policies and standards, and apply appropriate security controls across OT environments. You will provide technical and governance compliance of OT security, ensuring alignment with industry frameworks (IEC 62443, NIST CSF, CAF, ISO 27001) and with enterprise cyber security objectives. The role will combine hands-on implementation and the creation of governance artefacts. You will also engage with engineering teams and managed service providers (MSPs) to ensure that OT security controls are effectively implemented and sustained. Experience with SIEM/SOC integration is valuable and considered desirable. Essential: Oil/gas/rail/chemical process industry Familiarity with SIEM/SOC integration for OT environments Demonstrable experience in maturing OT security within ICS or critical infrastructure environments. Proven ability implement OT security strategies, policies, and standards. Strong knowledge of OT security frameworks and standards (IEC 62443, NIST CSF, CAF, ISO 27001). Experience conducting OT security risk assessments, gap analysis, and remediation planning. Knowledge of OT networks, segmentation, and common industrial protocols. Experience working with operations and engineering teams in OT environments. Ability to provide technical recommendations for MSPs or third-party security service providers. Strong communication and documentation skills, particularly in policy/standards creation. Desirable: Experience with OT asset discovery, monitoring, and security tool deployment. Exposure to regulatory compliance in critical infrastructure (eg, NIS Directive, UK CAF). Knowledge of project and service delivery life cycles and ITSM controls. Disability Confident As a member of the disability confident scheme, CLIENT guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Armed Forces Covenant CLIENT is proud to support the Armed Forces Covenant and as such, we guarantee to interview all veterans or spouses/partners of military personnel who meet all the essential criteria for the vacancy. In cases where we have a high volume of ex-military candidates/military spouses or partners, who meet all of the essential criteria, we will interview the best candidates from within that group. If you qualify for the above, please notify us. We will be in touch to discuss your suitability and arrange your Guaranteed Interview. Should you require reasonable adjustments at any point during the recruitment process or if there is a more accessible way for us to communicate, please do let me know. To apply for this role please submit your latest CV or contact Aspect Resources
Senior Cloud Security Engineer (London, Bracknell or Bristol) We are HealthHero, Europe's largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe - giving you the chance to shape security at the heart of a fast-growing, AI-driven business. We are recruiting an exciting Senior Cloud Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent - based in either our London or Bristol office two days per week. About the role This role will form a fundamental part of a growing Platform Security function, where the team covers application security, cloud security, security operations, culture and risk management. As a tech-centric organisation the Information Security team will play a critical part in embedding a security-first mindset into application development and continuous application monitoring. This role will co-own the cloud security posture and tooling across HealthHero's AWS and Azure estates and have the opportunity to tackle cloud security with an international scope. The role will be supported by a multidisciplinary force of Infrastructure, Data Governance and Engineering team leads with a security focus as part of their remit. The role has a focus on infrastructure and cloud networking when it comes to security posture. As an experienced Cloud Security Engineer, your working day will include but not be limited to: DevSecOps & SDLC Champion integration of security testing into CI/CD pipelines across all development teams and usage of automated security gates: SAST, DAST, dependency scanning, secrets detection Enable self-serve security tooling for development teams Ability to set up development environment Cloud Security Own cloud security posture management using Wiz (or similar CSPM) Define and enforce cloud security baselines, guardrails, and policies in AWS Implement and maintain IaC security scanning for Terraform Manage IAM policies, network segmentation, and secrets management Configure and tune SIEM (or similar) for cloud-focused detection Establish logging, monitoring, and alerting requirements based on threat modelling Investigate and respond to cloud security events Risk & Compliance Identify, articulate, and escalate security risks to senior leadership with mitigation plans Track and remediate vulnerabilities across infrastructure Manage customer initiatives related to due diligence when required to Support and develop annual programme of Penetration Testing and associated remediations Stakeholder Engagement Partner with internal and stakeholder management to support any requirements from the security function - particularly governance and accreditation requirements across different countries Provide expertise on emerging threats and vulnerabilities Support response to customer/client due diligence requests with timely and accurate information regarding vulnerability exposure Key Skills and Experience Essential Proven experience in application security, DevSecOps, or cloud security Strong understanding of cloud networking Experience securing cloud environments (AWS, Azure) Ability to read and write IAC (Terraform) code, comfortable with IAC lifecycles Familiarity with container security and Kubernetes Understanding of secure coding, penetration testing techniques, SIEM, and vulnerability management Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security and risk analysis Understanding of managing Secure Development Lifecycle and Vulnerability Management. Understanding and practical experience of ISO27001:2022 controls and audit processes Desirable AWS Security Specialty or similar certification Experience in regulated environments (healthcare, financial services) Familiarity with NHS DSPT Technical knowledge of GDPR and data protection requirements Hands-on with CI/CD security tooling and pipeline integration Interest in learning other countries health and security regulations (France / UK / IR / DE) About us We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. HealthHero is Europe's largest digital health provider , delivering 4 million consultations per year. But we're just getting started. We've built a seamless digital clinic that brings body and mind together - from GP appointments and mental health support to long-term condition management. By sitting behind the world's leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it. We are a high-growth, capital-backed business with a sophisticated scale strategy. Our team is a unique blend of those with strong digital experience, management consultants, creatives and industry-leading clinical experts. We aren't just digitising appointments; we're building the next generation of healthcare. We're creating an AI-powered, always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts. Join us, and help build a next generation health system the world is waiting for. What we offer A full induction training programme, which will be undertaken via Microsoft Teams. An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic. 25 days leave. Bank Holidays and your birthday off as leave. Regular 1-2-1s with your line Manager. 24/7 on-call staff support. Auto-enrolment pension scheme. Health Scheme and access to our Employee Assistance Programme. Life Insurance Scheme. Hybrid: London, Bracknell or Bristol (There is a requirement to work in the office for a minimum of two days per week) Additional information Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer.
20/07/2026
Contractor
Senior Cloud Security Engineer (London, Bracknell or Bristol) We are HealthHero, Europe's largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe - giving you the chance to shape security at the heart of a fast-growing, AI-driven business. We are recruiting an exciting Senior Cloud Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent - based in either our London or Bristol office two days per week. About the role This role will form a fundamental part of a growing Platform Security function, where the team covers application security, cloud security, security operations, culture and risk management. As a tech-centric organisation the Information Security team will play a critical part in embedding a security-first mindset into application development and continuous application monitoring. This role will co-own the cloud security posture and tooling across HealthHero's AWS and Azure estates and have the opportunity to tackle cloud security with an international scope. The role will be supported by a multidisciplinary force of Infrastructure, Data Governance and Engineering team leads with a security focus as part of their remit. The role has a focus on infrastructure and cloud networking when it comes to security posture. As an experienced Cloud Security Engineer, your working day will include but not be limited to: DevSecOps & SDLC Champion integration of security testing into CI/CD pipelines across all development teams and usage of automated security gates: SAST, DAST, dependency scanning, secrets detection Enable self-serve security tooling for development teams Ability to set up development environment Cloud Security Own cloud security posture management using Wiz (or similar CSPM) Define and enforce cloud security baselines, guardrails, and policies in AWS Implement and maintain IaC security scanning for Terraform Manage IAM policies, network segmentation, and secrets management Configure and tune SIEM (or similar) for cloud-focused detection Establish logging, monitoring, and alerting requirements based on threat modelling Investigate and respond to cloud security events Risk & Compliance Identify, articulate, and escalate security risks to senior leadership with mitigation plans Track and remediate vulnerabilities across infrastructure Manage customer initiatives related to due diligence when required to Support and develop annual programme of Penetration Testing and associated remediations Stakeholder Engagement Partner with internal and stakeholder management to support any requirements from the security function - particularly governance and accreditation requirements across different countries Provide expertise on emerging threats and vulnerabilities Support response to customer/client due diligence requests with timely and accurate information regarding vulnerability exposure Key Skills and Experience Essential Proven experience in application security, DevSecOps, or cloud security Strong understanding of cloud networking Experience securing cloud environments (AWS, Azure) Ability to read and write IAC (Terraform) code, comfortable with IAC lifecycles Familiarity with container security and Kubernetes Understanding of secure coding, penetration testing techniques, SIEM, and vulnerability management Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security and risk analysis Understanding of managing Secure Development Lifecycle and Vulnerability Management. Understanding and practical experience of ISO27001:2022 controls and audit processes Desirable AWS Security Specialty or similar certification Experience in regulated environments (healthcare, financial services) Familiarity with NHS DSPT Technical knowledge of GDPR and data protection requirements Hands-on with CI/CD security tooling and pipeline integration Interest in learning other countries health and security regulations (France / UK / IR / DE) About us We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. HealthHero is Europe's largest digital health provider , delivering 4 million consultations per year. But we're just getting started. We've built a seamless digital clinic that brings body and mind together - from GP appointments and mental health support to long-term condition management. By sitting behind the world's leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it. We are a high-growth, capital-backed business with a sophisticated scale strategy. Our team is a unique blend of those with strong digital experience, management consultants, creatives and industry-leading clinical experts. We aren't just digitising appointments; we're building the next generation of healthcare. We're creating an AI-powered, always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts. Join us, and help build a next generation health system the world is waiting for. What we offer A full induction training programme, which will be undertaken via Microsoft Teams. An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic. 25 days leave. Bank Holidays and your birthday off as leave. Regular 1-2-1s with your line Manager. 24/7 on-call staff support. Auto-enrolment pension scheme. Health Scheme and access to our Employee Assistance Programme. Life Insurance Scheme. Hybrid: London, Bracknell or Bristol (There is a requirement to work in the office for a minimum of two days per week) Additional information Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer.
Controls & Automation Engineer Shift: Days Basic Salary: Up to £57,000 + Overtime + Generous Call Out Allowance Location: Weston Super Mare Are you a budding Siemens S7 specialist looking for a role where you can genuinely make an impact? Have you built your experience fault finding live automated production equipment and want to be one of the go-to engineers within a fast-paced manufacturing environment? Yolk Recruitment are currently working with a well-established and heavily invested manufacturer who are looking to strengthen their existing automation and controls capability following continued growth and increasing demand across production. This is a fantastic opportunity for an experienced Controls & Automation Engineer to join a highly automated site where you'll play a key role in minimising downtime, improving machinery performance and supporting production-critical systems. The business can offer flexibility around working hours and shift patterns depending on the individual, alongside very strong earning potential through overtime and call-out payments. This is what you'll be doing As PLC / Automation Engineer, your duties will include: Fault finding and diagnosing issues across Siemens S7 PLC controlled production machinery and automated systems. Supporting production with reactive breakdowns, minimising downtime and restoring equipment safely and efficiently. Carrying out PLC modifications, programme adjustments and continuous improvement work to improve reliability, safety and performance. Working with systems including Siemens TIA Portal, HMI, SCADA, WinCC, Profinet and industrial networking. Supporting servo drive systems, inverters, motors and associated automation hardware. Assisting with commissioning, installation and upgrade projects across production equipment. Working closely with maintenance and production teams to provide technical automation support across site. Supporting electrical fault finding activities within panels, drives, safety circuits and control systems. Assisting with root cause analysis and implementing long-term engineering solutions. Participating in an on-call rota and providing technical support outside normal working hours when required (generous on call payment structure). Supporting and mentoring other engineers and apprentices around PLC systems and automation best practice. Ensuring all work is completed in line with health & safety and engineering standards. Are you what we're looking for? Qualifications and experience: Proven experience working as a PLC / Controls / Automation Engineer within manufacturing or industrial environments. Strong Siemens S7 fault finding experience with the ability to make programme modifications and adjustments. Experience with TIA Portal, HMI and SCADA systems. Strong understanding of industrial automation, drives, motors and control systems. Ability to fault find electrically from schematics and within control panels. Experience working on automated production or process equipment. Comfortable working within fast-paced manufacturing environments where downtime is critical. Engineering qualification such as City & Guilds, ONC, HNC, NVQ or equivalent. Strong communication skills with a practical and hands-on engineering approach. And this is what you'll get in return Basic Salary circa £50,000 - £57,000 (depending on experience)Overtime opportunitiesCall out payments and additional earning potentialFlexible shift options availablePension schemeLong-term stability within an established manufacturerInvestment into automation and engineering improvementsFurther benefits such as company sickness, healthcare and more!Training and future progression opportunities Want to Hear More? Are you what we're looking for? Please get in touch today with engineering specialist recruiter, Liam Reid who can discuss further details on this opportunity. Please apply with a CV. We also have a paid referral scheme so if you know somebody who would be great for the role, please get in touch. Please note, whilst we do our best to contact all candidates, due to the high number of applications we receive we cannot guarantee this for every role. If you have not heard anything from us within 7 days of applying, then unfortunately you have been unsuccessful. Please keep an eye on our website for more opportunities.
20/07/2026
Full time
Controls & Automation Engineer Shift: Days Basic Salary: Up to £57,000 + Overtime + Generous Call Out Allowance Location: Weston Super Mare Are you a budding Siemens S7 specialist looking for a role where you can genuinely make an impact? Have you built your experience fault finding live automated production equipment and want to be one of the go-to engineers within a fast-paced manufacturing environment? Yolk Recruitment are currently working with a well-established and heavily invested manufacturer who are looking to strengthen their existing automation and controls capability following continued growth and increasing demand across production. This is a fantastic opportunity for an experienced Controls & Automation Engineer to join a highly automated site where you'll play a key role in minimising downtime, improving machinery performance and supporting production-critical systems. The business can offer flexibility around working hours and shift patterns depending on the individual, alongside very strong earning potential through overtime and call-out payments. This is what you'll be doing As PLC / Automation Engineer, your duties will include: Fault finding and diagnosing issues across Siemens S7 PLC controlled production machinery and automated systems. Supporting production with reactive breakdowns, minimising downtime and restoring equipment safely and efficiently. Carrying out PLC modifications, programme adjustments and continuous improvement work to improve reliability, safety and performance. Working with systems including Siemens TIA Portal, HMI, SCADA, WinCC, Profinet and industrial networking. Supporting servo drive systems, inverters, motors and associated automation hardware. Assisting with commissioning, installation and upgrade projects across production equipment. Working closely with maintenance and production teams to provide technical automation support across site. Supporting electrical fault finding activities within panels, drives, safety circuits and control systems. Assisting with root cause analysis and implementing long-term engineering solutions. Participating in an on-call rota and providing technical support outside normal working hours when required (generous on call payment structure). Supporting and mentoring other engineers and apprentices around PLC systems and automation best practice. Ensuring all work is completed in line with health & safety and engineering standards. Are you what we're looking for? Qualifications and experience: Proven experience working as a PLC / Controls / Automation Engineer within manufacturing or industrial environments. Strong Siemens S7 fault finding experience with the ability to make programme modifications and adjustments. Experience with TIA Portal, HMI and SCADA systems. Strong understanding of industrial automation, drives, motors and control systems. Ability to fault find electrically from schematics and within control panels. Experience working on automated production or process equipment. Comfortable working within fast-paced manufacturing environments where downtime is critical. Engineering qualification such as City & Guilds, ONC, HNC, NVQ or equivalent. Strong communication skills with a practical and hands-on engineering approach. And this is what you'll get in return Basic Salary circa £50,000 - £57,000 (depending on experience)Overtime opportunitiesCall out payments and additional earning potentialFlexible shift options availablePension schemeLong-term stability within an established manufacturerInvestment into automation and engineering improvementsFurther benefits such as company sickness, healthcare and more!Training and future progression opportunities Want to Hear More? Are you what we're looking for? Please get in touch today with engineering specialist recruiter, Liam Reid who can discuss further details on this opportunity. Please apply with a CV. We also have a paid referral scheme so if you know somebody who would be great for the role, please get in touch. Please note, whilst we do our best to contact all candidates, due to the high number of applications we receive we cannot guarantee this for every role. If you have not heard anything from us within 7 days of applying, then unfortunately you have been unsuccessful. Please keep an eye on our website for more opportunities.
Overview ABOUT THE ROLE Salary: £62,900.00 - £100,000.00 Contract type: Permanent Working pattern: The Partnership has adopted a hybrid working approach, balancing time between the London head office and home based on personal needs and business requirements. The John Lewis Partnership (JLP) continually invests in its security capabilities, recognizing the trust our customers place in our brand and the information they provide to us. This role designs security solutions, patterns, and blueprints across data, platforms, cloud, and network capabilities to support our strategic aims within an evolving threat landscape. Key Responsibilities Design End-to-End Security Solutions: Create effective, repeatable, and sustainable security solutions and patterns across cloud platforms (AWS, GCP) and traditional hosting environments to strengthen business security. Embed Best Practice & Reduce Risk: Ensure security architecture best practices are applied during solution design activities by delivery teams and third parties to reduce delivery cost, operational risk, and technical debt. Democratize Secure Delivery: Enable architects and engineers through clear design principles, patterns, blueprints, and guardrails to scale secure delivery. Provide Commercial & Contractual Counsel: Advise on the commercial and contractual implications of existing or new obligations; review contractual terms of technologies and services within your domain. Drive Cross-Functional Collaboration: Partner with the CISO function, architecture, and engineering teams to ensure security capabilities deliver value; actively promote solution evangelism. Monitor & Advise on Industry Trends: Stay up-to-date with shifts in technology, retail, and socio-economic trends to influence internal technology and business decisions. Essential skills/experience Modern Security Architecture Expertise: Experience turning roadmap intent into clear, outcome-focused solutions with strong stakeholder engagement. Agile & Technical Architecture Delivery: Adaptable, engineering-focused mindset with experience across multiple service and domain teams using Agile delivery models. Core Security Frameworks & Methodologies: Experience with threat modeling; DevSecOps/SecOps; Zero Trust; and NIST Cybersecurity Framework. Hybrid-Cloud & Infrastructure Knowledge: Knowledge of securing data/workloads across Google Cloud/Workspace, AWS, Zscaler, and commodity SaaS. Critical Influence & Leadership: Ability to empower and influence others to align with business strategy and deliver outcomes. Emerging Tech & Threat Awareness: Understanding attacker tools/techniques and securing AI/LLM deployments. Desirable skills/experience Advanced Architecture Frameworks: Experience designing SOC architectures (SIEM, SOAR, vulnerability management) and secure SDLC. Regulated Environments & Evaluation: Experience in regulated environments (e.g., PCI-DSS) and leading tool evaluation and selection. Professional Certifications: TOGAF, SABSA, CISSP, CCSP, ISSAP, CEH, or platform-specific certs (GCP, Zscaler, CSA). Retail Business Domain Knowledge: Understanding of retail capabilities and processes; benchmarking to drive competitive advantage. Role Details Closing Date: July 20, 2026 Pay: £62,900.00 - £115,000.00 Annual Contract Type: Permanent Hours of Work: N/A Job Level: Partnership Level 6 Where You'll Be Working: London Central Office, 1 Drummond Gate, London, SW1V 2QQ About the Partnership We're the largest employee-owned business in the UK and home of John Lewis and Waitrose. We're not just employees; we're Partners, driven by our purpose to build a happier world. This is an exciting time to join us.
20/07/2026
Full time
Overview ABOUT THE ROLE Salary: £62,900.00 - £100,000.00 Contract type: Permanent Working pattern: The Partnership has adopted a hybrid working approach, balancing time between the London head office and home based on personal needs and business requirements. The John Lewis Partnership (JLP) continually invests in its security capabilities, recognizing the trust our customers place in our brand and the information they provide to us. This role designs security solutions, patterns, and blueprints across data, platforms, cloud, and network capabilities to support our strategic aims within an evolving threat landscape. Key Responsibilities Design End-to-End Security Solutions: Create effective, repeatable, and sustainable security solutions and patterns across cloud platforms (AWS, GCP) and traditional hosting environments to strengthen business security. Embed Best Practice & Reduce Risk: Ensure security architecture best practices are applied during solution design activities by delivery teams and third parties to reduce delivery cost, operational risk, and technical debt. Democratize Secure Delivery: Enable architects and engineers through clear design principles, patterns, blueprints, and guardrails to scale secure delivery. Provide Commercial & Contractual Counsel: Advise on the commercial and contractual implications of existing or new obligations; review contractual terms of technologies and services within your domain. Drive Cross-Functional Collaboration: Partner with the CISO function, architecture, and engineering teams to ensure security capabilities deliver value; actively promote solution evangelism. Monitor & Advise on Industry Trends: Stay up-to-date with shifts in technology, retail, and socio-economic trends to influence internal technology and business decisions. Essential skills/experience Modern Security Architecture Expertise: Experience turning roadmap intent into clear, outcome-focused solutions with strong stakeholder engagement. Agile & Technical Architecture Delivery: Adaptable, engineering-focused mindset with experience across multiple service and domain teams using Agile delivery models. Core Security Frameworks & Methodologies: Experience with threat modeling; DevSecOps/SecOps; Zero Trust; and NIST Cybersecurity Framework. Hybrid-Cloud & Infrastructure Knowledge: Knowledge of securing data/workloads across Google Cloud/Workspace, AWS, Zscaler, and commodity SaaS. Critical Influence & Leadership: Ability to empower and influence others to align with business strategy and deliver outcomes. Emerging Tech & Threat Awareness: Understanding attacker tools/techniques and securing AI/LLM deployments. Desirable skills/experience Advanced Architecture Frameworks: Experience designing SOC architectures (SIEM, SOAR, vulnerability management) and secure SDLC. Regulated Environments & Evaluation: Experience in regulated environments (e.g., PCI-DSS) and leading tool evaluation and selection. Professional Certifications: TOGAF, SABSA, CISSP, CCSP, ISSAP, CEH, or platform-specific certs (GCP, Zscaler, CSA). Retail Business Domain Knowledge: Understanding of retail capabilities and processes; benchmarking to drive competitive advantage. Role Details Closing Date: July 20, 2026 Pay: £62,900.00 - £115,000.00 Annual Contract Type: Permanent Hours of Work: N/A Job Level: Partnership Level 6 Where You'll Be Working: London Central Office, 1 Drummond Gate, London, SW1V 2QQ About the Partnership We're the largest employee-owned business in the UK and home of John Lewis and Waitrose. We're not just employees; we're Partners, driven by our purpose to build a happier world. This is an exciting time to join us.
Technical Solutions Architect - Ent Networking ONNEC Group are a leading independent technology partner and global integrator, with over 30 years' experience, and an 800+ team of global experts, specialising in providing end-to-end connectivity solutions that propel organisations everywhere. From structured cabling to managed services, our end-to-end services provide infrastructure that can be completely relied on. Design. Build. Deploy. Optimise. We offer a complete solution for business connectivity. We are a rapidly growing organisation and finding and retaining the highest calibre of people is fundamental to us for the success of our business. ONNEC has successfully achieved the Investors in Diversity Foundational Award for our commitment to equality, diversity and inclusion in the workplace. We are looking for a customer-facing Technical Solutions Architect - Enterprise Networking to act as a senior technical authority for ONNEC's enterprise networking solutions and service propositions. This role will bridge the gap between customer business challenges, sales opportunities and technical delivery, helping to shape creative, commercially viable and operationally achievable solutions for new and existing customers. What you'll be doing as our Technical Solutions Architect - Enterprise Networking: Acting as a trusted technical partner to customers by understanding their business challenges, goals, environments and operational requirements before shaping solutions. Proactively identifying, shaping and supporting new business opportunities and growth within existing accounts, working closely with Sales and Account Management teams. Developing creative, robust and commercially viable networking solution packages that meet customer needs and align with ONNEC's delivery capability. Providing high-quality pre-sales technical support, including discovery, technical qualification, customer workshops, solution presentations, demonstrations, proof of concepts and support for tenders, RFIs and RFPs. Translating customer requirements into scalable networking solutions, including high-level designs, solution overviews, technical assumptions, risk considerations, bill of materials input and handover material for delivery teams. Collaborating with vendors, manufacturers and strategic partners to stay ahead of emerging technologies, product roadmaps, lifecycle notices, licensing models and best practice design principles. What we're looking for in our Technical Solutions Architect - Enterprise Networking: A strong technical background in enterprise networking, technical architecture, pre-sales, solutions consulting or a technical design authority role. Experience supporting customer discovery sessions, understanding business drivers and converting requirements into practical, commercially aware technical solutions. Knowledge of modern networking technologies, including cyber security, cloud networking, enterprise switching, routing, wireless technologies, automation, telemetry and network assurance. Awareness of security and Zero Trust networking solutions such as SASE, DDoS protection, GRC, Zscaler and SIEM platforms, as well as hybrid and cloud networking solutions including AWS Direct Connect and Azure ExpressRoute. Understanding of controller-led campus and LAN architecture, NAC integration, virtualisation and HCI environments, including technologies such as Cisco Catalyst Center / DNA Center, Aruba Central, Juniper Mist, Cisco ISE, Aruba ClearPass and VMware / ESXi. Excellent communication, stakeholder management and presentation skills, with the ability to explain complex technical solutions clearly to both technical and non-technical audiences. Relevant professional or vendor accreditations are desirable, such as Cisco CCNA, CCDP, CCNP or CCIE, CISSP, CompTIA Security+, AWS Certified AI Practitioner, Azure AI Engineer Associate, or equivalent evidence of continued professional development. If you feel you have the required skills and experience, click apply now to be considered as our Technical Solutions Architect - Enterprise Networking. We'd love to hear from you!
20/07/2026
Full time
Technical Solutions Architect - Ent Networking ONNEC Group are a leading independent technology partner and global integrator, with over 30 years' experience, and an 800+ team of global experts, specialising in providing end-to-end connectivity solutions that propel organisations everywhere. From structured cabling to managed services, our end-to-end services provide infrastructure that can be completely relied on. Design. Build. Deploy. Optimise. We offer a complete solution for business connectivity. We are a rapidly growing organisation and finding and retaining the highest calibre of people is fundamental to us for the success of our business. ONNEC has successfully achieved the Investors in Diversity Foundational Award for our commitment to equality, diversity and inclusion in the workplace. We are looking for a customer-facing Technical Solutions Architect - Enterprise Networking to act as a senior technical authority for ONNEC's enterprise networking solutions and service propositions. This role will bridge the gap between customer business challenges, sales opportunities and technical delivery, helping to shape creative, commercially viable and operationally achievable solutions for new and existing customers. What you'll be doing as our Technical Solutions Architect - Enterprise Networking: Acting as a trusted technical partner to customers by understanding their business challenges, goals, environments and operational requirements before shaping solutions. Proactively identifying, shaping and supporting new business opportunities and growth within existing accounts, working closely with Sales and Account Management teams. Developing creative, robust and commercially viable networking solution packages that meet customer needs and align with ONNEC's delivery capability. Providing high-quality pre-sales technical support, including discovery, technical qualification, customer workshops, solution presentations, demonstrations, proof of concepts and support for tenders, RFIs and RFPs. Translating customer requirements into scalable networking solutions, including high-level designs, solution overviews, technical assumptions, risk considerations, bill of materials input and handover material for delivery teams. Collaborating with vendors, manufacturers and strategic partners to stay ahead of emerging technologies, product roadmaps, lifecycle notices, licensing models and best practice design principles. What we're looking for in our Technical Solutions Architect - Enterprise Networking: A strong technical background in enterprise networking, technical architecture, pre-sales, solutions consulting or a technical design authority role. Experience supporting customer discovery sessions, understanding business drivers and converting requirements into practical, commercially aware technical solutions. Knowledge of modern networking technologies, including cyber security, cloud networking, enterprise switching, routing, wireless technologies, automation, telemetry and network assurance. Awareness of security and Zero Trust networking solutions such as SASE, DDoS protection, GRC, Zscaler and SIEM platforms, as well as hybrid and cloud networking solutions including AWS Direct Connect and Azure ExpressRoute. Understanding of controller-led campus and LAN architecture, NAC integration, virtualisation and HCI environments, including technologies such as Cisco Catalyst Center / DNA Center, Aruba Central, Juniper Mist, Cisco ISE, Aruba ClearPass and VMware / ESXi. Excellent communication, stakeholder management and presentation skills, with the ability to explain complex technical solutions clearly to both technical and non-technical audiences. Relevant professional or vendor accreditations are desirable, such as Cisco CCNA, CCDP, CCNP or CCIE, CISSP, CompTIA Security+, AWS Certified AI Practitioner, Azure AI Engineer Associate, or equivalent evidence of continued professional development. If you feel you have the required skills and experience, click apply now to be considered as our Technical Solutions Architect - Enterprise Networking. We'd love to hear from you!
The Cyber Detection and Response Analyst supports day-to-day detection, investigation, and response activities as part of a Cyber Detection and Response Team (DART). This is a hands on technical role focused on identifying, analysing, and responding to cyber threats across the client's environment, working closely with Security Engineering and broader security stakeholders. This role will be a part of a 24/7 team and cover one of two shifts: Sunday-Thursday 9:00 am-5:00 pm GMT or Tuesday-Saturday 9:00 am-5:00 pm GMT Responsibilities Monitor, triage, and investigate security alerts and events across endpoint, network, cloud, and identity systems. Support incident response activities including analysis, containment, remediation, and documentation. Execute established incident response playbooks and contribute to their continuous improvement. Perform threat hunting activities to identify potential compromises and gaps in detection coverage. Leverage threat intelligence to inform investigations and detection tuning. Collaborate with Security Engineering to tune detection logic and improve security controls. Produce clear, concise incident reports and support root cause analysis and remediation efforts. Support on call rotations and escalation processes as part of a 24/7 detection and response capability. Qualifications 3-5 years of experience in cybersecurity, with a focus on incident response, SOC operations, or cyber defense. Hands on experience with SIEM, EDR/XDR, and log analysis tools (e.g., Splunk, Sentinel, CrowdStrike). Practical understanding of incident response methodologies and frameworks such as MITRE ATT&CK and NIST. Familiarity with threat hunting, malware analysis, or forensic investigation techniques. Exposure to cloud environments (AWS, Azure, or GCP) and modern enterprise architectures is preferred. Strong analytical and problem solving skills, with the ability to communicate technical findings clearly. Relevant certifications (e.g., Security+, GCIH, GCIA, or equivalent) are a plus.
20/07/2026
Full time
The Cyber Detection and Response Analyst supports day-to-day detection, investigation, and response activities as part of a Cyber Detection and Response Team (DART). This is a hands on technical role focused on identifying, analysing, and responding to cyber threats across the client's environment, working closely with Security Engineering and broader security stakeholders. This role will be a part of a 24/7 team and cover one of two shifts: Sunday-Thursday 9:00 am-5:00 pm GMT or Tuesday-Saturday 9:00 am-5:00 pm GMT Responsibilities Monitor, triage, and investigate security alerts and events across endpoint, network, cloud, and identity systems. Support incident response activities including analysis, containment, remediation, and documentation. Execute established incident response playbooks and contribute to their continuous improvement. Perform threat hunting activities to identify potential compromises and gaps in detection coverage. Leverage threat intelligence to inform investigations and detection tuning. Collaborate with Security Engineering to tune detection logic and improve security controls. Produce clear, concise incident reports and support root cause analysis and remediation efforts. Support on call rotations and escalation processes as part of a 24/7 detection and response capability. Qualifications 3-5 years of experience in cybersecurity, with a focus on incident response, SOC operations, or cyber defense. Hands on experience with SIEM, EDR/XDR, and log analysis tools (e.g., Splunk, Sentinel, CrowdStrike). Practical understanding of incident response methodologies and frameworks such as MITRE ATT&CK and NIST. Familiarity with threat hunting, malware analysis, or forensic investigation techniques. Exposure to cloud environments (AWS, Azure, or GCP) and modern enterprise architectures is preferred. Strong analytical and problem solving skills, with the ability to communicate technical findings clearly. Relevant certifications (e.g., Security+, GCIH, GCIA, or equivalent) are a plus.
Business Unit:Cubic Transportation SystemsCompany Details:When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people's lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Led by our talented teams around the world, Cubic is committed to solving global issues through innovation and service to our customers and partners.We have a top-tier portfolio of businesses, including Cubic Transportation Systems (CTS) and Cubic Defense (CD). Explore more on Details:Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly. A significant feature is providing Fare and Payment card services to government and municipal customers across the globe.Job Summary:As Member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. Evaluate posture of security controls and operating environment to ensure compliance with organization security policies and controls. Plans and prepares the scope of IT compliance evaluation programs across the organization and isolates potential risks or liabilities and develops mitigation plans. Partners with external auditors to coordinate and facilitate PCI-DSS, ISO 27001, etc. compliance/audit efforts. This position typically works under limited supervision and direction. Candidates for this position will regularly exercise discretionary and substantial decision-making authority.RESPONSIBILITIESEssential Job Duties and ResponsibilitiesPerform as the recognized Subject Matter Expert on Security Risk Assessment methodology, policy, strategy and processes.Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.Responsible for coordination with the Internal/External Auditors and Information Technology teams to successfully complete periodic audits. Works independently to schedule and conduct control walk through meetings and address follow up procedures to ensure all stakeholders understand duties and responsibilitiesLead the design and control reviews and assessments to support continuous compliance with security policies and standardsManage security review processes for all solutions to ensure they their design and implementation meets compliance requirements - including PCI-DSS, ISO 27001, SOC 1 & SOC 2 and other regional requirements Document and actively communicate any areas where the solutions and processes are not fully compliant.Identify and report significant information security risks associated with applications, development, networking, data centers, Cloud and physical IT infrastructure, vendors and other third parties.Identify stakeholders in remediation of compliance gaps and actively escalate issues to them in a constructive manner that helps them understand the actions required. Work to gain acceptance of responsibility and track progress towards remediation. Actively manage escalation as needed if solutions are not resolved in a timely manner.Work with system operators and security subject matter experts to communicate system compliance gaps and develop acceptable remediation plans.Capture compliance gaps and remediation plans in the OneTrust GRC system. Plans, reviews, and performs (as needed) controls monitoring around complex customer facing systems using the One Trust.Liaisengage with Cubic customers and Security Teams to build positive relationships and outcomesSupports efforts to educate Security Management and Security Team Members in compliant IT processes and controls. Prepare and maintain process and control documentationAid in the development of solutions to problems identified during audits and translates these solutions into practical recommendations. Partner with Operations and Engineering Teams to ensure timely and acceptable remediation of issues.Follow up on recommendations and appraises corrective actions taken to improve deficient conditions. To the greatest extent possible, ensure all Corporate Standards, SDLC, Change Management, and risk governance protocols are followed.Review vendor contracts and SOC reports to evaluate the impact on the company's controls. Coordinates with third party vendors where appropriate.General Duties and Responsibilities:Reliably demonstrate accountability for work assignments and proactive communications about issues and status. A strong history of proactively identifying effective solutions for challenges.Able to reliably demonstrate ethical behavior and accurate communications even when complex factors are involved.Able to operate in a professional manner, even in tense or continuous with Cubic's Quality Management SystemComply with Cubic's quality, health, safety, and security policies.Support the company's strategic objectives and collaborate across with Cubic Human Resources ProceduresSKILLS/EXPERIENCE/KNOWLEDGEEssential:Strong written and oral communication skills in English, with capability to use Microsoft Office solutions. Ability to effectively and openly collaborate with team members clients, IT management, staff, and business units in a cross functional and matrixed IT organizationComfortable working with staff at all levels and in other geographical locations within the organizationFamiliarity with PCI DSS 4, ISO , and or SOC I/II requirements and audits.Expert level experience collaborating with stakeholders and solution providers in a cross functional and matrixed IT organization. Able to adapt style efforts to persuade in delivering messages that relate to the wider business. Is frequently called on to advise others on complex matters and may be accountable through team for delivery of business targets.Exhibits advanced wide- ranging experience, using in- depth professional knowledge, acumen, concepts and company objectives to develop, resolve complex models and procedures. Provides solutions to issues in creative and effective ways. Understands the interrelationships of different disciplines. Directs the application of existing principles and guides development of new policies and ideas.Understands and works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors. Determines methods and procedures on new assignments. Exercises judgment in selecting methods, evaluating, adapting complex techniques and evaluation criteria for obtaining results.Desirable:Deep understanding of security risks and threats as they relate to the company's operating environments.QUALIFICATIONSEssential:Experience in services or IT systems in a mission critical setting.University degree in Computer Science, Engineering, or other technical fields, or Business Administration with relevant IT work experience.Experience working in IT security and/or Payment Card processing systems. Strong understanding of technical concepts, as well as demonstrated ability to understand complex internally developed systems.The candidate must reside within commuting distance from CTS offices in, and be able to periodically travel within the region.DesirableRelevant security or IT compliance certification in one or more areas, such as CISA, CRISC, CCSK, CCISSP, GIAC, PCI-ISA/QSA or equivalent.Knowledge of or willingness to learn information security best practices as it pertains to Open Payments, Mobility as a Service, data classifications, Microsoft Azure, AWS (or similar) cloud security and infrastructure, Web infrastructure security (Applications and APIs), Network security tools (IDS/IPS, firewalls, etc.), Encryption technology and implementation, Database security, Operating system security and hardening, vulnerability assessment tools and writing risk mitigation plans according to the assessment, and SIEM and FIM solutions.Worker Type:EmployeeWe are committed to creating an inclusive workplace and welcome applications from people of all backgrounds. We do not discriminate based on any protected characteristic under applicable law.
20/07/2026
Full time
Business Unit:Cubic Transportation SystemsCompany Details:When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people's lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Led by our talented teams around the world, Cubic is committed to solving global issues through innovation and service to our customers and partners.We have a top-tier portfolio of businesses, including Cubic Transportation Systems (CTS) and Cubic Defense (CD). Explore more on Details:Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly. A significant feature is providing Fare and Payment card services to government and municipal customers across the globe.Job Summary:As Member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. Evaluate posture of security controls and operating environment to ensure compliance with organization security policies and controls. Plans and prepares the scope of IT compliance evaluation programs across the organization and isolates potential risks or liabilities and develops mitigation plans. Partners with external auditors to coordinate and facilitate PCI-DSS, ISO 27001, etc. compliance/audit efforts. This position typically works under limited supervision and direction. Candidates for this position will regularly exercise discretionary and substantial decision-making authority.RESPONSIBILITIESEssential Job Duties and ResponsibilitiesPerform as the recognized Subject Matter Expert on Security Risk Assessment methodology, policy, strategy and processes.Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.Responsible for coordination with the Internal/External Auditors and Information Technology teams to successfully complete periodic audits. Works independently to schedule and conduct control walk through meetings and address follow up procedures to ensure all stakeholders understand duties and responsibilitiesLead the design and control reviews and assessments to support continuous compliance with security policies and standardsManage security review processes for all solutions to ensure they their design and implementation meets compliance requirements - including PCI-DSS, ISO 27001, SOC 1 & SOC 2 and other regional requirements Document and actively communicate any areas where the solutions and processes are not fully compliant.Identify and report significant information security risks associated with applications, development, networking, data centers, Cloud and physical IT infrastructure, vendors and other third parties.Identify stakeholders in remediation of compliance gaps and actively escalate issues to them in a constructive manner that helps them understand the actions required. Work to gain acceptance of responsibility and track progress towards remediation. Actively manage escalation as needed if solutions are not resolved in a timely manner.Work with system operators and security subject matter experts to communicate system compliance gaps and develop acceptable remediation plans.Capture compliance gaps and remediation plans in the OneTrust GRC system. Plans, reviews, and performs (as needed) controls monitoring around complex customer facing systems using the One Trust.Liaisengage with Cubic customers and Security Teams to build positive relationships and outcomesSupports efforts to educate Security Management and Security Team Members in compliant IT processes and controls. Prepare and maintain process and control documentationAid in the development of solutions to problems identified during audits and translates these solutions into practical recommendations. Partner with Operations and Engineering Teams to ensure timely and acceptable remediation of issues.Follow up on recommendations and appraises corrective actions taken to improve deficient conditions. To the greatest extent possible, ensure all Corporate Standards, SDLC, Change Management, and risk governance protocols are followed.Review vendor contracts and SOC reports to evaluate the impact on the company's controls. Coordinates with third party vendors where appropriate.General Duties and Responsibilities:Reliably demonstrate accountability for work assignments and proactive communications about issues and status. A strong history of proactively identifying effective solutions for challenges.Able to reliably demonstrate ethical behavior and accurate communications even when complex factors are involved.Able to operate in a professional manner, even in tense or continuous with Cubic's Quality Management SystemComply with Cubic's quality, health, safety, and security policies.Support the company's strategic objectives and collaborate across with Cubic Human Resources ProceduresSKILLS/EXPERIENCE/KNOWLEDGEEssential:Strong written and oral communication skills in English, with capability to use Microsoft Office solutions. Ability to effectively and openly collaborate with team members clients, IT management, staff, and business units in a cross functional and matrixed IT organizationComfortable working with staff at all levels and in other geographical locations within the organizationFamiliarity with PCI DSS 4, ISO , and or SOC I/II requirements and audits.Expert level experience collaborating with stakeholders and solution providers in a cross functional and matrixed IT organization. Able to adapt style efforts to persuade in delivering messages that relate to the wider business. Is frequently called on to advise others on complex matters and may be accountable through team for delivery of business targets.Exhibits advanced wide- ranging experience, using in- depth professional knowledge, acumen, concepts and company objectives to develop, resolve complex models and procedures. Provides solutions to issues in creative and effective ways. Understands the interrelationships of different disciplines. Directs the application of existing principles and guides development of new policies and ideas.Understands and works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors. Determines methods and procedures on new assignments. Exercises judgment in selecting methods, evaluating, adapting complex techniques and evaluation criteria for obtaining results.Desirable:Deep understanding of security risks and threats as they relate to the company's operating environments.QUALIFICATIONSEssential:Experience in services or IT systems in a mission critical setting.University degree in Computer Science, Engineering, or other technical fields, or Business Administration with relevant IT work experience.Experience working in IT security and/or Payment Card processing systems. Strong understanding of technical concepts, as well as demonstrated ability to understand complex internally developed systems.The candidate must reside within commuting distance from CTS offices in, and be able to periodically travel within the region.DesirableRelevant security or IT compliance certification in one or more areas, such as CISA, CRISC, CCSK, CCISSP, GIAC, PCI-ISA/QSA or equivalent.Knowledge of or willingness to learn information security best practices as it pertains to Open Payments, Mobility as a Service, data classifications, Microsoft Azure, AWS (or similar) cloud security and infrastructure, Web infrastructure security (Applications and APIs), Network security tools (IDS/IPS, firewalls, etc.), Encryption technology and implementation, Database security, Operating system security and hardening, vulnerability assessment tools and writing risk mitigation plans according to the assessment, and SIEM and FIM solutions.Worker Type:EmployeeWe are committed to creating an inclusive workplace and welcome applications from people of all backgrounds. We do not discriminate based on any protected characteristic under applicable law.
Amentum is a global leader in engineering, project and programme management, and solutions integration. Built on strong programme and engineering delivery experience, supported by deep specialist capabilities, Amentum is a recognised partner across major UK Government and commercial programmes. People are at the centre of what we do. We offer a competitive package designed to attract and retain talent. In addition to standard benefits, UK employees receive free single medical cover, digital GP services, enhanced family friendly policies, employee assistance programmes, and reimbursement for professional development. Our community initiatives include matched funding schemes, paid volunteering, and charitable contributions. About the Opportunity Amentum are offering an exciting opportunity to join our growing team of IT professionals to work on a range of projects for our diverse client portfolio that covers Critical National Infrastructure, National Security, Defence and Nuclear market sectors. Our team is growing and are we looking for proactive and collaborative professionals of all levels to work within us in providing a range of services to our clients. With our deep technical, commercial, and strategic expertise we develop solutions that address our client's critical challenges supporting digitalisation and security. We are looking for an individual to join our team supporting ICT system design activities for a UK defence project. You will play an integral role in safeguarding the integrity and confidentiality of our client's data and systems, responsible for designing, implementing, and maintaining security architectures that protect against a wide range of cyber threats. Key Responsibilities Designing Security Architecture. This is the core responsibility, involving the creation and oversight of robust security architectures for the ICT capabilities we are designing for our client. This includes planning, designing, building, and maintaining the overall security framework in line with SbD. Strategic Alignment. Ensuring that security architectures align with the client's overall business strategy and technology goals. Translate business needs into security requirements. Threat and Vulnerability Management. Identifying, assessing, and communicating current and emerging security threats and vulnerabilities. This involves performing or supervising risk analyses and security assessments (including ITHC). Security Solution Design and Evaluation. Researching, evaluating, and recommending security technologies, tools (e.g., firewalls, VPNs, IDS/IPS, EDR, SIEM, SOAR), and solutions to mitigate identified threats and address security needs. Policy and Procedure Development: Defining, implementing, and maintaining corporate security policies, standards, and procedures to ensure compliance with industry regulations, legal requirements (e.g., GDPR, HIPAA), and best practices. Incident Response and Management: Playing a key role in developing incident response plans and coordinating efforts to detect, analyse, and respond to security incidents and breaches. Stakeholder Communication and Collaboration: Effectively communicating complex security concepts, risks, and recommendations to diverse technical and non-technical stakeholders, including senior management. Here's What You'll Need Degree qualified in Cyber Security, Computer Science, Engineering, or related discipline (or equivalent experience). Excellent communication and stakeholder engagement skills, with the ability to influence at senior levels. Strong analytical skills with the ability to break down complex security challenges. Ability to produce high-quality technical documentation for both technical and non-technical audiences. Experience 5 years' experience as a Security Architect within UK Defence. Deep understanding of computer systems, networking, and cybersecurity principles. They should possess strong analytical and problem-solving skills, as well as the ability to think critically and creatively to identify and address potential security vulnerabilities. Knowledge of cybersecurity standards and best practices. Ability to design and implement security architectures. Ability to stay up-to-date with the latest cybersecurity threats and trends. Hands on experience with security technologies such as firewalls, intrusion detection systems, encryption etc. Standards & Frameworks Experience of MOD security standards and principles (e.g., JSP440, JSP453, Secure by Design), and industry frameworks (e.g., NIST Cyber Security Framework, ISO 27001). Professional certifications such as CISSP, CISM, or NCSC Certified Cyber Professional (CCP) desirable . Our Culture Our values stand on a foundation of safety, integrity, inclusion, and diversity. We put people at the heart of our business, and we genuinely believe that we all succeed by supporting one another through our culture of caring. We value positive mental health and a sense of belonging for all employees. We aim to embed inclusion and diversity in everything we do. We know that if we are inclusive, we are more connected, and if we are diverse, we're more creative. We accept people for who they are, regardless of age, disability, gender identity, gender expression, marital status, mental health, race, faith or belief, sexual orientation, socioeconomic background, and whether you're pregnant or on family leave. This is reflected in our wide range of Global Employee Networks centred on inclusion and diversity. We partner with VERCIDA to help us attract and retain diverse talent. For greater online accessibility, please visit Promoting Equality & Diversity in Jobs and Career - VERCIDA to view and access our roles. As a Disability Confident employer, we will interview all disabled applicants who meet the minimum criteria for a vacancy. We welcome applications from candidates who are seeking flexible working and from those who may not meet all the listed requirements for a role. Your application experience is important to us and we're keen to adapt to make every interaction even better. We welcome feedback on our recruitment process and if you need more from us before deciding to join us then please let us know.
20/07/2026
Full time
Amentum is a global leader in engineering, project and programme management, and solutions integration. Built on strong programme and engineering delivery experience, supported by deep specialist capabilities, Amentum is a recognised partner across major UK Government and commercial programmes. People are at the centre of what we do. We offer a competitive package designed to attract and retain talent. In addition to standard benefits, UK employees receive free single medical cover, digital GP services, enhanced family friendly policies, employee assistance programmes, and reimbursement for professional development. Our community initiatives include matched funding schemes, paid volunteering, and charitable contributions. About the Opportunity Amentum are offering an exciting opportunity to join our growing team of IT professionals to work on a range of projects for our diverse client portfolio that covers Critical National Infrastructure, National Security, Defence and Nuclear market sectors. Our team is growing and are we looking for proactive and collaborative professionals of all levels to work within us in providing a range of services to our clients. With our deep technical, commercial, and strategic expertise we develop solutions that address our client's critical challenges supporting digitalisation and security. We are looking for an individual to join our team supporting ICT system design activities for a UK defence project. You will play an integral role in safeguarding the integrity and confidentiality of our client's data and systems, responsible for designing, implementing, and maintaining security architectures that protect against a wide range of cyber threats. Key Responsibilities Designing Security Architecture. This is the core responsibility, involving the creation and oversight of robust security architectures for the ICT capabilities we are designing for our client. This includes planning, designing, building, and maintaining the overall security framework in line with SbD. Strategic Alignment. Ensuring that security architectures align with the client's overall business strategy and technology goals. Translate business needs into security requirements. Threat and Vulnerability Management. Identifying, assessing, and communicating current and emerging security threats and vulnerabilities. This involves performing or supervising risk analyses and security assessments (including ITHC). Security Solution Design and Evaluation. Researching, evaluating, and recommending security technologies, tools (e.g., firewalls, VPNs, IDS/IPS, EDR, SIEM, SOAR), and solutions to mitigate identified threats and address security needs. Policy and Procedure Development: Defining, implementing, and maintaining corporate security policies, standards, and procedures to ensure compliance with industry regulations, legal requirements (e.g., GDPR, HIPAA), and best practices. Incident Response and Management: Playing a key role in developing incident response plans and coordinating efforts to detect, analyse, and respond to security incidents and breaches. Stakeholder Communication and Collaboration: Effectively communicating complex security concepts, risks, and recommendations to diverse technical and non-technical stakeholders, including senior management. Here's What You'll Need Degree qualified in Cyber Security, Computer Science, Engineering, or related discipline (or equivalent experience). Excellent communication and stakeholder engagement skills, with the ability to influence at senior levels. Strong analytical skills with the ability to break down complex security challenges. Ability to produce high-quality technical documentation for both technical and non-technical audiences. Experience 5 years' experience as a Security Architect within UK Defence. Deep understanding of computer systems, networking, and cybersecurity principles. They should possess strong analytical and problem-solving skills, as well as the ability to think critically and creatively to identify and address potential security vulnerabilities. Knowledge of cybersecurity standards and best practices. Ability to design and implement security architectures. Ability to stay up-to-date with the latest cybersecurity threats and trends. Hands on experience with security technologies such as firewalls, intrusion detection systems, encryption etc. Standards & Frameworks Experience of MOD security standards and principles (e.g., JSP440, JSP453, Secure by Design), and industry frameworks (e.g., NIST Cyber Security Framework, ISO 27001). Professional certifications such as CISSP, CISM, or NCSC Certified Cyber Professional (CCP) desirable . Our Culture Our values stand on a foundation of safety, integrity, inclusion, and diversity. We put people at the heart of our business, and we genuinely believe that we all succeed by supporting one another through our culture of caring. We value positive mental health and a sense of belonging for all employees. We aim to embed inclusion and diversity in everything we do. We know that if we are inclusive, we are more connected, and if we are diverse, we're more creative. We accept people for who they are, regardless of age, disability, gender identity, gender expression, marital status, mental health, race, faith or belief, sexual orientation, socioeconomic background, and whether you're pregnant or on family leave. This is reflected in our wide range of Global Employee Networks centred on inclusion and diversity. We partner with VERCIDA to help us attract and retain diverse talent. For greater online accessibility, please visit Promoting Equality & Diversity in Jobs and Career - VERCIDA to view and access our roles. As a Disability Confident employer, we will interview all disabled applicants who meet the minimum criteria for a vacancy. We welcome applications from candidates who are seeking flexible working and from those who may not meet all the listed requirements for a role. Your application experience is important to us and we're keen to adapt to make every interaction even better. We welcome feedback on our recruitment process and if you need more from us before deciding to join us then please let us know.
Vertiv is the largest electrical switchgear manufacturer in the UK & Ireland, pioneering unique in-house integrated power solutions tailored to each individual client project. We believe that our people are our best asset and have invested in a highly qualified and experienced team of Engineers to work in our manufacturing facilities across three continents. With over 30 years of experience in delivering high-quality integrated power solutions, we are experts in providing technical services, project management services, and unrivalled customer support for every client project. Job (Assignment) Title: Power Software & Controls - Lead Systems Engineer Function/Department: Power BU Reports To: Power Software & Controls - Technical Manager Location: Derry / Londonderry POSITION SUMMARY The Power Software & Controls - Lead Systems Engineer plays a key leadership role in the software development department, overseeing the design, implementation, and maintenance of systems that integrate PLCs, SCADA platforms, networking, and cybersecurity solutions. The individual will work closely with multidisciplinary teams to ensure that systems are efficient, secure, and meet the operational requirements of the organization or clients. This position demands expertise in control systems, industrial automation, networking protocols, and cybersecurity practices, combined with strong leadership and project management skills to guide teams in achieving technical excellence. Reporting to the department's Technical Manager, this position provides an excellent opportunity to lead and take control of PLC & SCADA projects within the department for global projects. The main remit of the role will encompass the following duties. RESPONSIBILITIES Lead the design and development of PLC/SCADA-based automation systems and associated software solutions. Oversee system architecture planning, including integration of PLCs, SCADA platforms, and networking components. Ensure systems comply with industry standards, client specifications, and cybersecurity best practices. Develop and validate control algorithms, HMI configurations, and network infrastructure designs. Provide technical leadership and mentorship to engineering teams within the software development department. Collaborate with software developers, network engineers, and cybersecurity specialists to ensure seamless integration across systems. Act as the primary point of contact for technical inquiries, troubleshooting, and decision-making. Conduct technical reviews to maintain high-quality standards in system design and implementation. Design and implement secure industrial networks, including configuring switches, routers, and firewalls. Perform risk assessments and develop cybersecurity strategies for automation systems. Monitor, analyze, and respond to potential threats or vulnerabilities in control systems. Stay updated on emerging trends in OT (Operational Technology) and IT security to ensure proactive solutions. Oversee multiple projects simultaneously, ensuring they are delivered on time, within budget, and meet technical specifications. Communicate project progress to stakeholders and manage risk effectively. Coordinate with vendors and clients to ensure technical requirements are well-understood and executed. Establish and implement system monitoring and maintenance plans for PLC, SCADA, and networked systems. Develop documentation for system operation, troubleshooting, and updates. Support commissioning, testing, and troubleshooting activities during project handover phases. Provide ongoing technical support to ensure optimal system performance. Aid engineers both in the office environment for development and throughout project delivery. Be Subject Matter Expert (SME) in their field QUALIFICATIONS Bachelor's degree in Electrical Engineering, Computer Science, or a related field. 8+ years of experience in systems engineering, focusing on PLC/SCADA, networking, and cybersecurity. Strong expertise in industrial automation platforms such as Siemens, Rockwell, or Schneider. Deep understanding of networking protocols (TCP/IP, Ethernet/IP, Modbus, etc.) and cybersecurity frameworks
20/07/2026
Full time
Vertiv is the largest electrical switchgear manufacturer in the UK & Ireland, pioneering unique in-house integrated power solutions tailored to each individual client project. We believe that our people are our best asset and have invested in a highly qualified and experienced team of Engineers to work in our manufacturing facilities across three continents. With over 30 years of experience in delivering high-quality integrated power solutions, we are experts in providing technical services, project management services, and unrivalled customer support for every client project. Job (Assignment) Title: Power Software & Controls - Lead Systems Engineer Function/Department: Power BU Reports To: Power Software & Controls - Technical Manager Location: Derry / Londonderry POSITION SUMMARY The Power Software & Controls - Lead Systems Engineer plays a key leadership role in the software development department, overseeing the design, implementation, and maintenance of systems that integrate PLCs, SCADA platforms, networking, and cybersecurity solutions. The individual will work closely with multidisciplinary teams to ensure that systems are efficient, secure, and meet the operational requirements of the organization or clients. This position demands expertise in control systems, industrial automation, networking protocols, and cybersecurity practices, combined with strong leadership and project management skills to guide teams in achieving technical excellence. Reporting to the department's Technical Manager, this position provides an excellent opportunity to lead and take control of PLC & SCADA projects within the department for global projects. The main remit of the role will encompass the following duties. RESPONSIBILITIES Lead the design and development of PLC/SCADA-based automation systems and associated software solutions. Oversee system architecture planning, including integration of PLCs, SCADA platforms, and networking components. Ensure systems comply with industry standards, client specifications, and cybersecurity best practices. Develop and validate control algorithms, HMI configurations, and network infrastructure designs. Provide technical leadership and mentorship to engineering teams within the software development department. Collaborate with software developers, network engineers, and cybersecurity specialists to ensure seamless integration across systems. Act as the primary point of contact for technical inquiries, troubleshooting, and decision-making. Conduct technical reviews to maintain high-quality standards in system design and implementation. Design and implement secure industrial networks, including configuring switches, routers, and firewalls. Perform risk assessments and develop cybersecurity strategies for automation systems. Monitor, analyze, and respond to potential threats or vulnerabilities in control systems. Stay updated on emerging trends in OT (Operational Technology) and IT security to ensure proactive solutions. Oversee multiple projects simultaneously, ensuring they are delivered on time, within budget, and meet technical specifications. Communicate project progress to stakeholders and manage risk effectively. Coordinate with vendors and clients to ensure technical requirements are well-understood and executed. Establish and implement system monitoring and maintenance plans for PLC, SCADA, and networked systems. Develop documentation for system operation, troubleshooting, and updates. Support commissioning, testing, and troubleshooting activities during project handover phases. Provide ongoing technical support to ensure optimal system performance. Aid engineers both in the office environment for development and throughout project delivery. Be Subject Matter Expert (SME) in their field QUALIFICATIONS Bachelor's degree in Electrical Engineering, Computer Science, or a related field. 8+ years of experience in systems engineering, focusing on PLC/SCADA, networking, and cybersecurity. Strong expertise in industrial automation platforms such as Siemens, Rockwell, or Schneider. Deep understanding of networking protocols (TCP/IP, Ethernet/IP, Modbus, etc.) and cybersecurity frameworks
Cyber Security Consultant Department: Cyber Employment Type: Permanent - Full Time Location: City, London Compensation: £42,000 - £50,000 / year Description As part of our continued growth and increasing client demand for robust cyber and information security services, Moore Kingston Smith is seeking a skilled and motivated Cyber Security Consultant to join our client-facing advisory team. You will join Moore ClearComm, the cyber security advisory arm of Moore Kingston Smith, an NCSC recognised cyber security team operating within our wider business, technology and compliance risk practice. This is a hands on consulting role that will see you working with a wide variety of organisations, ranging from scale ups to established businesses across multiple sectors. Whether clients are just beginning their security journey or enhancing mature programs, you will provide tailored, actionable advice to support their operational resilience and regulatory compliance. With access to a diverse portfolio of clients, this is an excellent opportunity to deepen your InfoSec expertise and play a meaningful role in helping businesses improve their defences in a fast evolving threat landscape. We are looking for a proactive well rounded consultant with strong technical fundamentals, an ability to think critically, and a genuine interest in helping clients succeed. Key Responsibilities Lead and support the delivery of cyber and information security assessments, audits, and control reviews across diverse industries. Identify and assess security control weaknesses, articulate associated risks, and provide pragmatic recommendations tailored to client environments. Produce high quality, concise documentation including audit reports, risk assessments, and advisory outputs. Collaborate with technical and business stakeholders to design or enhance security control environments aligned to frameworks such as ISO 27001, NIST CSF, CIS Controls, and Cyber Essentials. Maintain up to date knowledge of cyber threats, mitigation strategies, regulatory requirements, and industry best practices. Contribute to the continuous improvement of internal methodologies and security services. Build and maintain strong client relationships with a service focused mindset. Identify client challenges and future needs that may lead to service expansion opportunities. Contribute to business development and client growth by supporting proposal creation, project scoping, thought leadership (e.g., blogs, webinars), and collaborating on presentations, tenders, and workshops with senior team members. A proactive, client oriented mindset with a passion for continuous learning and improving security outcomes. Skills, Knowledge and Expertise Essential Experience within cyber security consulting, security auditing, or risk advisory roles. Experience in delivering client facing cyber risk advisory services. Experience delivering assessments aligned with industry standards such as ISO 27001, NIST, CIS, NCSC 10 Steps, and GDPR. Strong written and verbal communication skills, able to clearly articulate technical jargon to non technical audiences and write impactful deliverables. Experience planning and delivering engagements independently and as part of a team, within tight timescales, to budget and a high level of quality. Competent in working with a range of clients, from SMEs to large enterprise environments. Experience preparing, supporting, or auditing certification audits (e.g., ISO 27001, SOC 2, Cyber Essentials) Desirable Industry recognised certifications such as ISO 27001 Lead Auditor/Implementer, CISSP, CISA, CISM, or similar. Exposure to penetration testing, or hands on vulnerability assessment (even if not a primary role). Experience with public cloud platforms (e.g., AWS, Azure, GCP, MS365) and understanding of cloud security principles. Experience in Operational Technology (OT) and understanding of SANS standards. Familiarity with modern security technology and tools, SIEM, and security automation. Hands on experience in security or IT engineering, including implementing technical controls, hardening systems, securing networks, or supporting secure architecture design. Benefits
20/07/2026
Full time
Cyber Security Consultant Department: Cyber Employment Type: Permanent - Full Time Location: City, London Compensation: £42,000 - £50,000 / year Description As part of our continued growth and increasing client demand for robust cyber and information security services, Moore Kingston Smith is seeking a skilled and motivated Cyber Security Consultant to join our client-facing advisory team. You will join Moore ClearComm, the cyber security advisory arm of Moore Kingston Smith, an NCSC recognised cyber security team operating within our wider business, technology and compliance risk practice. This is a hands on consulting role that will see you working with a wide variety of organisations, ranging from scale ups to established businesses across multiple sectors. Whether clients are just beginning their security journey or enhancing mature programs, you will provide tailored, actionable advice to support their operational resilience and regulatory compliance. With access to a diverse portfolio of clients, this is an excellent opportunity to deepen your InfoSec expertise and play a meaningful role in helping businesses improve their defences in a fast evolving threat landscape. We are looking for a proactive well rounded consultant with strong technical fundamentals, an ability to think critically, and a genuine interest in helping clients succeed. Key Responsibilities Lead and support the delivery of cyber and information security assessments, audits, and control reviews across diverse industries. Identify and assess security control weaknesses, articulate associated risks, and provide pragmatic recommendations tailored to client environments. Produce high quality, concise documentation including audit reports, risk assessments, and advisory outputs. Collaborate with technical and business stakeholders to design or enhance security control environments aligned to frameworks such as ISO 27001, NIST CSF, CIS Controls, and Cyber Essentials. Maintain up to date knowledge of cyber threats, mitigation strategies, regulatory requirements, and industry best practices. Contribute to the continuous improvement of internal methodologies and security services. Build and maintain strong client relationships with a service focused mindset. Identify client challenges and future needs that may lead to service expansion opportunities. Contribute to business development and client growth by supporting proposal creation, project scoping, thought leadership (e.g., blogs, webinars), and collaborating on presentations, tenders, and workshops with senior team members. A proactive, client oriented mindset with a passion for continuous learning and improving security outcomes. Skills, Knowledge and Expertise Essential Experience within cyber security consulting, security auditing, or risk advisory roles. Experience in delivering client facing cyber risk advisory services. Experience delivering assessments aligned with industry standards such as ISO 27001, NIST, CIS, NCSC 10 Steps, and GDPR. Strong written and verbal communication skills, able to clearly articulate technical jargon to non technical audiences and write impactful deliverables. Experience planning and delivering engagements independently and as part of a team, within tight timescales, to budget and a high level of quality. Competent in working with a range of clients, from SMEs to large enterprise environments. Experience preparing, supporting, or auditing certification audits (e.g., ISO 27001, SOC 2, Cyber Essentials) Desirable Industry recognised certifications such as ISO 27001 Lead Auditor/Implementer, CISSP, CISA, CISM, or similar. Exposure to penetration testing, or hands on vulnerability assessment (even if not a primary role). Experience with public cloud platforms (e.g., AWS, Azure, GCP, MS365) and understanding of cloud security principles. Experience in Operational Technology (OT) and understanding of SANS standards. Familiarity with modern security technology and tools, SIEM, and security automation. Hands on experience in security or IT engineering, including implementing technical controls, hardening systems, securing networks, or supporting secure architecture design. Benefits
Manchester, Glasgow, London or Newbury/Hybrid A bit about us At Gamma, we're a dynamic, forward-thinking team revolutionizing the way businesses connect and communicate. We provide voice, data, and mobile solutions to businesses across the UK, Germany, Spain, and the Benelux region. We're expanding rapidly to bring digital automation and Gamma-powered services to Enterprise, Public Sector and Small to medium businesses, both direct and through a growing network of channel partners. We move fast with a start up mindset, but we have the stability of a leading European business. Our team thrives on collaboration, innovation, and the belief that diverse perspectives make us stronger. Join us, and you'll have the opportunity to make an impact, grow your career, and be part of a company that celebrates inclusivity and fresh ideas. Who are we looking for? We are seeking a skilled and client focused Security Engineer with strong expertise in Vulnerability Management and Network Security engineering. This role operates within a managed service provider environment, delivering security services to enterprise clients, with a primary focus on risk based vulnerability management alongside network security, firewall optimisation and access control. The successful candidate will be responsible for identifying, assessing, prioritising and driving remediation of vulnerabilities across complex enterprise environments. In addition, they will contribute to strengthening overall cyber resilience by aligning vulnerability management with Managed Detection and Response (MDR) operations, supporting Secure Access Service Edge (SASE) frameworks and advancing Zero Trust security models across network, identity and access control layers. This is a hands on engineering role requiring deep technical expertise across vulnerability management and network security, combined with strong stakeholder engagement. The role ensures security risks are proactively reduced, controls are optimised and remediation is delivered in line with contractual SLAs and cyber security best practices. What will you be doing day to day? Key Responsibilities Vulnerability Management Services Deliver end to end vulnerability management services to clients, including discovery, assessment, prioritisation, reporting and remediation tracking Operate and maintain vulnerability scanning tools (e.g. Qualys, Nessus, Rapid7) across multiple client environments Perform regular vulnerability scans, validation and re testing to ensure remediation effectiveness Analyse vulnerability data, eliminate false positives and provide actionable remediation guidance tailored to client environments Prioritise vulnerabilities using risk based methodologies (CVSS, exploitability, business impact, threat intelligence) Track remediation activities and ensure closure within agreed SLAs and service metrics Produce client facing reports, dashboards and service reviews, highlighting risk posture, trends and key improvement areas Act as a trusted advisor to clients, providing best practice recommendations on vulnerability and risk reduction strategies Security Engineering & Detection Support deployment and optimisation of Microsoft Sentinel and SIEM/XDR platforms Contribute to detection engineering (use case development, rule tuning, alert optimisation) Onboard and integrate telemetry across network, endpoint, cloud and identity sources Support threat detection across SIEM, NDR and identity platforms Collaborate with SOC teams to improve detection coverage and reduce false positives Align vulnerability insights with MDR workflows and threat detection use cases Network Security & Remediation Identify, analyse and manage network and system vulnerabilities across enterprise environments Collaborate with infrastructure, cloud and application teams to drive remediation activities to completion Troubleshoot and resolve network/security issues linked to vulnerabilities and access controls Support secure network architecture and ensure adherence to security and compliance standards Support SASE architectures (e.g. Prisma, Cisco Secure) and secure connectivity models Contribute to Zero Trust implementation, including least privilege and identity controls Strengthen security posture across hybrid environments (network, cloud, SaaS, identity) Support pre sales activities, including solution design and vulnerability management offerings Provide SME input into RFPs, bids and technical workshops Assist with onboarding clients and transitioning services into BAU Build strong client relationships and act as a trusted technical advisor Support service adoption and continuous improvement initiatives Governance, Reporting & Documentation Maintain accurate records of vulnerabilities, remediation plans and audit evidence Support client audits, compliance requirements and security assessments Contribute to service improvement initiatives, automation and process optimisation Ensure adherence to ITIL based service management practices where applicable Breach Attack Simulation (BAS) Design, implement and maintain BAS scenarios to continuously validate the effectiveness of security controls across the enterprise Configure and operate BAS platforms to simulate real world threat actor techniques (MITRE ATT&CK aligned) and identify control gaps Analyse BAS results to prioritise vulnerabilities, misconfigurations and detection gaps, feeding findings into the vulnerability management lifecycle What you'll need: Strong experience in delivering vulnerability management services, ideally within a managed service or consultancy environment Deep understanding of vulnerability lifecycle management (discovery / assessment / remediation / validation / reporting) Hands on experience with Tufin (SecureTrack / SecureChange) or similar tools such as Palo Alto Panorama or Cisco Defense Orchestrator Proficiency with vulnerability scanning tools (Qualys, Nessus, Rapid7) Solid knowledge of network security principles (firewalls, VPNs, segmentation, protocols) Experience working with client stakeholders and managing competing priorities Ability to translate technical vulnerabilities into business risk and remediation actions Strong analytical, troubleshooting and communication skills Nice to haves Certifications such as CCNA / Security+ / CEH / CISSP (or working towards) Experience in multi client or managed security service provider (MSSP) environments Familiarity with multi vendor firewalls (Cisco, Palo Alto, Check Point) Knowledge of compliance frameworks (ISO 27001, NIST, CIS, PCI DSS) Exposure to risk based vulnerability management and threat intelligence integration Understanding of ITIL service delivery and SLA driven environments Experience with SASE, Zero Trust, MDR/XDR platforms Experience with RSA Authentication Manager or similar IAM solutions What do we offer you? At Gamma, we believe in work life balance, which is why we offer 25 days of annual leave, plus an extra day off for your birthday. Giving back is important to us, so we also provide a volunteer day to support a charity that matters to you. Family matters, too. With enhanced maternity and paternity pay and childcare vouchers, we're here to support you as a parent and help you thrive in your career. We care about your future, so our pension plan helps you save for the years ahead with contributions of 4.59% from Gamma, alongside your own contributions. Your well being is our priority. We offer group income protection and life assurance (four times your salary) to ensure peace of mind for you and your loved ones. We want you to share in our success. That's why we offer tax efficient share save and share incentive plans, giving you the opportunity to benefit from Gamma's growth. We're committed to health, both physical and mental, and provide private medical insurance through Vitality, which extends to your immediate family. And, because we care about the environment, we offer an Electric Vehicle scheme through Octopus and a Cycle to Work scheme, making it easier to get around sustainably. A few things to note Unfortunately, we can't offer visa sponsorship or relocation support for this role. This role is hybrid but with 3 days a week onsite at either our Manchester, Glasgow, London or Newbury sites. If you feel you could be a good fit for Gamma but do not think that you meet all the requirements, we still encourage you to apply as you could be the person that we are looking for! Gamma is an equal opportunity employer. We care about inclusion and believe in having diverse teams where everyone can be their true authentic selves. We value each person and their range of backgrounds and actively encourage people from underrepresented backgrounds to apply. We don't discriminate based on any protected characteristics e.g., race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, marital status, disability or age. We are a family friendly employer with a culture based on trust, autonomy and flexibility to help you create a work life balance and enjoy working here at Gamma. . click apply for full job details
20/07/2026
Full time
Manchester, Glasgow, London or Newbury/Hybrid A bit about us At Gamma, we're a dynamic, forward-thinking team revolutionizing the way businesses connect and communicate. We provide voice, data, and mobile solutions to businesses across the UK, Germany, Spain, and the Benelux region. We're expanding rapidly to bring digital automation and Gamma-powered services to Enterprise, Public Sector and Small to medium businesses, both direct and through a growing network of channel partners. We move fast with a start up mindset, but we have the stability of a leading European business. Our team thrives on collaboration, innovation, and the belief that diverse perspectives make us stronger. Join us, and you'll have the opportunity to make an impact, grow your career, and be part of a company that celebrates inclusivity and fresh ideas. Who are we looking for? We are seeking a skilled and client focused Security Engineer with strong expertise in Vulnerability Management and Network Security engineering. This role operates within a managed service provider environment, delivering security services to enterprise clients, with a primary focus on risk based vulnerability management alongside network security, firewall optimisation and access control. The successful candidate will be responsible for identifying, assessing, prioritising and driving remediation of vulnerabilities across complex enterprise environments. In addition, they will contribute to strengthening overall cyber resilience by aligning vulnerability management with Managed Detection and Response (MDR) operations, supporting Secure Access Service Edge (SASE) frameworks and advancing Zero Trust security models across network, identity and access control layers. This is a hands on engineering role requiring deep technical expertise across vulnerability management and network security, combined with strong stakeholder engagement. The role ensures security risks are proactively reduced, controls are optimised and remediation is delivered in line with contractual SLAs and cyber security best practices. What will you be doing day to day? Key Responsibilities Vulnerability Management Services Deliver end to end vulnerability management services to clients, including discovery, assessment, prioritisation, reporting and remediation tracking Operate and maintain vulnerability scanning tools (e.g. Qualys, Nessus, Rapid7) across multiple client environments Perform regular vulnerability scans, validation and re testing to ensure remediation effectiveness Analyse vulnerability data, eliminate false positives and provide actionable remediation guidance tailored to client environments Prioritise vulnerabilities using risk based methodologies (CVSS, exploitability, business impact, threat intelligence) Track remediation activities and ensure closure within agreed SLAs and service metrics Produce client facing reports, dashboards and service reviews, highlighting risk posture, trends and key improvement areas Act as a trusted advisor to clients, providing best practice recommendations on vulnerability and risk reduction strategies Security Engineering & Detection Support deployment and optimisation of Microsoft Sentinel and SIEM/XDR platforms Contribute to detection engineering (use case development, rule tuning, alert optimisation) Onboard and integrate telemetry across network, endpoint, cloud and identity sources Support threat detection across SIEM, NDR and identity platforms Collaborate with SOC teams to improve detection coverage and reduce false positives Align vulnerability insights with MDR workflows and threat detection use cases Network Security & Remediation Identify, analyse and manage network and system vulnerabilities across enterprise environments Collaborate with infrastructure, cloud and application teams to drive remediation activities to completion Troubleshoot and resolve network/security issues linked to vulnerabilities and access controls Support secure network architecture and ensure adherence to security and compliance standards Support SASE architectures (e.g. Prisma, Cisco Secure) and secure connectivity models Contribute to Zero Trust implementation, including least privilege and identity controls Strengthen security posture across hybrid environments (network, cloud, SaaS, identity) Support pre sales activities, including solution design and vulnerability management offerings Provide SME input into RFPs, bids and technical workshops Assist with onboarding clients and transitioning services into BAU Build strong client relationships and act as a trusted technical advisor Support service adoption and continuous improvement initiatives Governance, Reporting & Documentation Maintain accurate records of vulnerabilities, remediation plans and audit evidence Support client audits, compliance requirements and security assessments Contribute to service improvement initiatives, automation and process optimisation Ensure adherence to ITIL based service management practices where applicable Breach Attack Simulation (BAS) Design, implement and maintain BAS scenarios to continuously validate the effectiveness of security controls across the enterprise Configure and operate BAS platforms to simulate real world threat actor techniques (MITRE ATT&CK aligned) and identify control gaps Analyse BAS results to prioritise vulnerabilities, misconfigurations and detection gaps, feeding findings into the vulnerability management lifecycle What you'll need: Strong experience in delivering vulnerability management services, ideally within a managed service or consultancy environment Deep understanding of vulnerability lifecycle management (discovery / assessment / remediation / validation / reporting) Hands on experience with Tufin (SecureTrack / SecureChange) or similar tools such as Palo Alto Panorama or Cisco Defense Orchestrator Proficiency with vulnerability scanning tools (Qualys, Nessus, Rapid7) Solid knowledge of network security principles (firewalls, VPNs, segmentation, protocols) Experience working with client stakeholders and managing competing priorities Ability to translate technical vulnerabilities into business risk and remediation actions Strong analytical, troubleshooting and communication skills Nice to haves Certifications such as CCNA / Security+ / CEH / CISSP (or working towards) Experience in multi client or managed security service provider (MSSP) environments Familiarity with multi vendor firewalls (Cisco, Palo Alto, Check Point) Knowledge of compliance frameworks (ISO 27001, NIST, CIS, PCI DSS) Exposure to risk based vulnerability management and threat intelligence integration Understanding of ITIL service delivery and SLA driven environments Experience with SASE, Zero Trust, MDR/XDR platforms Experience with RSA Authentication Manager or similar IAM solutions What do we offer you? At Gamma, we believe in work life balance, which is why we offer 25 days of annual leave, plus an extra day off for your birthday. Giving back is important to us, so we also provide a volunteer day to support a charity that matters to you. Family matters, too. With enhanced maternity and paternity pay and childcare vouchers, we're here to support you as a parent and help you thrive in your career. We care about your future, so our pension plan helps you save for the years ahead with contributions of 4.59% from Gamma, alongside your own contributions. Your well being is our priority. We offer group income protection and life assurance (four times your salary) to ensure peace of mind for you and your loved ones. We want you to share in our success. That's why we offer tax efficient share save and share incentive plans, giving you the opportunity to benefit from Gamma's growth. We're committed to health, both physical and mental, and provide private medical insurance through Vitality, which extends to your immediate family. And, because we care about the environment, we offer an Electric Vehicle scheme through Octopus and a Cycle to Work scheme, making it easier to get around sustainably. A few things to note Unfortunately, we can't offer visa sponsorship or relocation support for this role. This role is hybrid but with 3 days a week onsite at either our Manchester, Glasgow, London or Newbury sites. If you feel you could be a good fit for Gamma but do not think that you meet all the requirements, we still encourage you to apply as you could be the person that we are looking for! Gamma is an equal opportunity employer. We care about inclusion and believe in having diverse teams where everyone can be their true authentic selves. We value each person and their range of backgrounds and actively encourage people from underrepresented backgrounds to apply. We don't discriminate based on any protected characteristics e.g., race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, marital status, disability or age. We are a family friendly employer with a culture based on trust, autonomy and flexibility to help you create a work life balance and enjoy working here at Gamma. . click apply for full job details
Protect identities at global scale. We're hiring a hands-on Senior Identity Protection Engineer/Specialist to lead detection, investigation, and response for identity-based threats across Microsoft Entra ID/Azure AD, on prem Active Directory, and connected SaaS/IaaS. You'll serve as the enterprise SME/administrator for CrowdStrike Identity Protection, tune high-fidelity detections, integrate dark web intelligence, and orchestrate automation that measurably reduces MTTD/MTTR and risk.What you'll doLead identity threat monitoring and triageOperate and tune CrowdStrike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks like impossible travel, atypical sign ins, MFA fatigue, and session hijackingValidate true/false positives, prioritize by business impact, and escalate per playbooks/SLAsDrive rapid containment and remediationExecute containment actions (disable accounts, revoke sessions/tokens, isolate hosts)Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closureOwn identity-focused incident responseLead IR for credential compromise, privilege escalation, directory persistence, and lateral movementEnsure evidence handling, root cause analysis, post incident reviews, and lessons learnedEngineer detections and hunt for threatsBuild and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CKClose visibility gaps, reduce false positives, and expand privileged activity monitoringStrengthen privileged access controlsDetect anomalous privileged behavior via SIEM/UEBA and Netskope telemetryRecommend/enforce JIT, break glass patterns, and mover/leaver privilege hygiene with IAMRespond to dark web/credential exposureIntegrate sources like CyberInt; assess exposure and targeted campaignsOrchestrate takedowns, forced resets, token revocation, and Conditional Access updatesAdminister platforms and sustain hygieneMaintain coverage/health for identity monitoring; manage upgrades and changes via CABKeep operational runbooks, SOPs, and playbooks currentAutomate and orchestrate at scaleUse PowerShell/Python and REST/Graph/CrowdStrike APIs (and SOAR where applicable) to automate enrichment and response, standardize workflows, and improve signal fidelityShape identity policy and controlsAdvise on Conditional Access, MFA exceptions, SSO/SCIM patterns, and session controls under the shared responsibility model with IAMReport outcomes and support auditsProduce executive-ready dashboards and KPIs (identity incident volume, MTTD/MTTR, CA/MFA efficacy, exposure/takedown cycle time)Maintain audit-ready evidence and support internal/external auditsWhat you'll bringBachelor's degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience8+ years in IT/cybersecurity, including 3+ years focused on identity security/operations (Entra ID/Azure AD, on prem AD, MFA, Conditional Access, SSO/SCIM)Hands-on enterprise experience administering/operating CrowdStrike Identity ProtectionProficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms (e.g., Netskope) for identity telemetry, detection, and investigationsDemonstrated experience in identity centric IR, threat hunting, and detection engineering (KQL/SQL/regex/Sigma)Scripting/automation with PowerShell and Python; experience with REST/Graph/CrowdStrike APIs and SOARClear communication and documentation skills; comfortable producing executive ready reports and audit evidenceOperates effectively within change control/CAB and under pressure during high severity incidentsBonus pointsCertifications: Microsoft SC 200/SC 300; Okta Certified Administrator/Professional; CISSP, SSCP, Security+; GIAC (GMON, GCIH, GCDA) or equivalentDeep knowledge of identity attack paths and protocols (Kerberos/NTLM), token/session abuse, and persistence techniques (e.g., Golden/Silver Ticket, DCShadow)Experience with JIT/JEA, PAM concepts, and global on call rotationsLocation, work style, and travelOpportunities in the United States, United Kingdom, and DenmarkOnsite or hybrid depending on location and business needsOccasional on call coverage may be requiredWhy you'll love it hereOwn a mission critical identity defense stack and make measurable impact on MTTD/MTTR and privilege hygieneSolve complex problems from dark web exposure to directory persistence and lateral movementCollaborate with experienced global teams and leading vendors to continuously raise the barGrow your career in a modern, data driven security operations environmentThis is a global position that will support all our FUJIFILM Biotechnologies sites. This position can be based at any of our locations around the globe. Benefits and compensation will be governed by the location that you are based from and considered your home site.As part of any recruitment process, FUJIFILM Diosynth Biotechnologies collects and processes personal data relating to job applicants. The organization is committed to being transparent about how it collects and uses that data and to meeting its data protection obligations and may share this as part of the global recruitment process with hiring managers in Europe and the United States.Please, no phone calls or emails to any employee of FUJIFILM about this requisition. All resumes submitted by search firms/employment agencies to any employee at FUJIFILM via-email, the internet or in any form and/or method will be deemed the sole property of FUJIFILM, unless such search firms/employment agencies were engaged by FUJIFILM for this requisition and a valid agreement with FUJIFILM is in place. In the event a candidate who was submitted outside of the FUJIFILM agency engagement process is hired, no fee or payment of any kind will be paid.
19/07/2026
Full time
Protect identities at global scale. We're hiring a hands-on Senior Identity Protection Engineer/Specialist to lead detection, investigation, and response for identity-based threats across Microsoft Entra ID/Azure AD, on prem Active Directory, and connected SaaS/IaaS. You'll serve as the enterprise SME/administrator for CrowdStrike Identity Protection, tune high-fidelity detections, integrate dark web intelligence, and orchestrate automation that measurably reduces MTTD/MTTR and risk.What you'll doLead identity threat monitoring and triageOperate and tune CrowdStrike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks like impossible travel, atypical sign ins, MFA fatigue, and session hijackingValidate true/false positives, prioritize by business impact, and escalate per playbooks/SLAsDrive rapid containment and remediationExecute containment actions (disable accounts, revoke sessions/tokens, isolate hosts)Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closureOwn identity-focused incident responseLead IR for credential compromise, privilege escalation, directory persistence, and lateral movementEnsure evidence handling, root cause analysis, post incident reviews, and lessons learnedEngineer detections and hunt for threatsBuild and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CKClose visibility gaps, reduce false positives, and expand privileged activity monitoringStrengthen privileged access controlsDetect anomalous privileged behavior via SIEM/UEBA and Netskope telemetryRecommend/enforce JIT, break glass patterns, and mover/leaver privilege hygiene with IAMRespond to dark web/credential exposureIntegrate sources like CyberInt; assess exposure and targeted campaignsOrchestrate takedowns, forced resets, token revocation, and Conditional Access updatesAdminister platforms and sustain hygieneMaintain coverage/health for identity monitoring; manage upgrades and changes via CABKeep operational runbooks, SOPs, and playbooks currentAutomate and orchestrate at scaleUse PowerShell/Python and REST/Graph/CrowdStrike APIs (and SOAR where applicable) to automate enrichment and response, standardize workflows, and improve signal fidelityShape identity policy and controlsAdvise on Conditional Access, MFA exceptions, SSO/SCIM patterns, and session controls under the shared responsibility model with IAMReport outcomes and support auditsProduce executive-ready dashboards and KPIs (identity incident volume, MTTD/MTTR, CA/MFA efficacy, exposure/takedown cycle time)Maintain audit-ready evidence and support internal/external auditsWhat you'll bringBachelor's degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience8+ years in IT/cybersecurity, including 3+ years focused on identity security/operations (Entra ID/Azure AD, on prem AD, MFA, Conditional Access, SSO/SCIM)Hands-on enterprise experience administering/operating CrowdStrike Identity ProtectionProficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms (e.g., Netskope) for identity telemetry, detection, and investigationsDemonstrated experience in identity centric IR, threat hunting, and detection engineering (KQL/SQL/regex/Sigma)Scripting/automation with PowerShell and Python; experience with REST/Graph/CrowdStrike APIs and SOARClear communication and documentation skills; comfortable producing executive ready reports and audit evidenceOperates effectively within change control/CAB and under pressure during high severity incidentsBonus pointsCertifications: Microsoft SC 200/SC 300; Okta Certified Administrator/Professional; CISSP, SSCP, Security+; GIAC (GMON, GCIH, GCDA) or equivalentDeep knowledge of identity attack paths and protocols (Kerberos/NTLM), token/session abuse, and persistence techniques (e.g., Golden/Silver Ticket, DCShadow)Experience with JIT/JEA, PAM concepts, and global on call rotationsLocation, work style, and travelOpportunities in the United States, United Kingdom, and DenmarkOnsite or hybrid depending on location and business needsOccasional on call coverage may be requiredWhy you'll love it hereOwn a mission critical identity defense stack and make measurable impact on MTTD/MTTR and privilege hygieneSolve complex problems from dark web exposure to directory persistence and lateral movementCollaborate with experienced global teams and leading vendors to continuously raise the barGrow your career in a modern, data driven security operations environmentThis is a global position that will support all our FUJIFILM Biotechnologies sites. This position can be based at any of our locations around the globe. Benefits and compensation will be governed by the location that you are based from and considered your home site.As part of any recruitment process, FUJIFILM Diosynth Biotechnologies collects and processes personal data relating to job applicants. The organization is committed to being transparent about how it collects and uses that data and to meeting its data protection obligations and may share this as part of the global recruitment process with hiring managers in Europe and the United States.Please, no phone calls or emails to any employee of FUJIFILM about this requisition. All resumes submitted by search firms/employment agencies to any employee at FUJIFILM via-email, the internet or in any form and/or method will be deemed the sole property of FUJIFILM, unless such search firms/employment agencies were engaged by FUJIFILM for this requisition and a valid agreement with FUJIFILM is in place. In the event a candidate who was submitted outside of the FUJIFILM agency engagement process is hired, no fee or payment of any kind will be paid.
Security Engineer - Microsoft, SIEM, Sentinel, AlienVault - Hybrid - Manchester - £55,000 - £60,000 + bonus You will work with some of the best Cyber Consultants in the country within a fast paced and demanding Security Engineering team. This is an exceptional chance to join one of the fastest growing and most exciting Security Consultancy's in the UK and become a leader within the organisation, collaborating with multiple areas of the business and making you an essential cog in the Microsoft Managed Security Service offering. Key Skills & Responsibilities: Working in a SOC environment - ideally MSSP Reviewing incidents, notifying malicious activities, and working with my client's customers to investigate and solve incidents Experience with SIEM tools e.g. Sentinel Assess risks and threats for new and existing customers Monitor security alerts from security platforms Act on 2nd Line security alerts, incidents, requests, and events to ensure that threats, vulnerabilities, and breaches are managed for successful resolution Resolve customer issues, provide additional information and answer questions related to incidents and monitoring Document and manage cases to utilise information for customer reports, to provide insightful and intelligent recommendations Facilitate recovery, following the resolution of incidents Work to SLA's and KPI's Document and close resolved security incidents according to agreed procedures
19/07/2026
Full time
Security Engineer - Microsoft, SIEM, Sentinel, AlienVault - Hybrid - Manchester - £55,000 - £60,000 + bonus You will work with some of the best Cyber Consultants in the country within a fast paced and demanding Security Engineering team. This is an exceptional chance to join one of the fastest growing and most exciting Security Consultancy's in the UK and become a leader within the organisation, collaborating with multiple areas of the business and making you an essential cog in the Microsoft Managed Security Service offering. Key Skills & Responsibilities: Working in a SOC environment - ideally MSSP Reviewing incidents, notifying malicious activities, and working with my client's customers to investigate and solve incidents Experience with SIEM tools e.g. Sentinel Assess risks and threats for new and existing customers Monitor security alerts from security platforms Act on 2nd Line security alerts, incidents, requests, and events to ensure that threats, vulnerabilities, and breaches are managed for successful resolution Resolve customer issues, provide additional information and answer questions related to incidents and monitoring Document and manage cases to utilise information for customer reports, to provide insightful and intelligent recommendations Facilitate recovery, following the resolution of incidents Work to SLA's and KPI's Document and close resolved security incidents according to agreed procedures
InfraView Ltd is looking for a Security Engineer to join their dynamic team in Manchester, offering a hybrid work model. In this role, you will be involved in addressing security incidents and working with clients to enhance their security posture. The successful candidate will have experience in a SOC environment, particularly with SIEM tools like Sentinel. A salary range of £55,000 to £60,000 plus bonuses is available for the right candidate.
19/07/2026
Full time
InfraView Ltd is looking for a Security Engineer to join their dynamic team in Manchester, offering a hybrid work model. In this role, you will be involved in addressing security incidents and working with clients to enhance their security posture. The successful candidate will have experience in a SOC environment, particularly with SIEM tools like Sentinel. A salary range of £55,000 to £60,000 plus bonuses is available for the right candidate.
As a Product Manager in Cybersecurity & Technology Controls, you will lead the end-to-end product lifecycle for a blockchain detection and prevention capability serving our SOC. You will translate SOC needs into a prioritized roadmap and backlog, partner closely with engineering and threat SMEs, and ensure detections are accurate, explainable, and operationally effective. Success means improving time-to-detect and time-to-respond while managing false positives and meeting reliability and resiliency expectations. Job Responsibilities Define product vision, strategy, and roadmap for SOC-focused blockchain detection and prevention Lead discovery with SOC analysts and incident responders: workflows, pain points, alert usability, escalation paths, and runbooks Own and refine the backlog: detection use cases, requirements, acceptance criteria, and prioritization tradeoffs Partner with engineering/threat teams to deliver end-to-end capability: signal ingestion, enrichment, alerting, triage experience, and response automation where appropriate Establish and track success metrics (e.g., precision/false positive rate, coverage, latency, time-to-detect/time-to-respond, alert volume, reliability/SLA) and drive continuous improvement Drive launch readiness: documentation, training, operational handoffs, and feedback loops with the SOC Required Qualifications, Capabilities, and Skills Product management experience delivering security detections, SOC tooling, or data/analytics products Strong understanding of SOC operations (alert lifecycle, triage, escalations, incident response) Background in blockchain fundamentals and common threat patterns/abuse cases Ability to use data to prioritize, measure detection efficacy, and manage false positives Preferred Experience with SIEM/SOAR and detection engineering programs Experience operating in a highly matrixed, complex organization Equal Opportunity Statement We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
19/07/2026
Full time
As a Product Manager in Cybersecurity & Technology Controls, you will lead the end-to-end product lifecycle for a blockchain detection and prevention capability serving our SOC. You will translate SOC needs into a prioritized roadmap and backlog, partner closely with engineering and threat SMEs, and ensure detections are accurate, explainable, and operationally effective. Success means improving time-to-detect and time-to-respond while managing false positives and meeting reliability and resiliency expectations. Job Responsibilities Define product vision, strategy, and roadmap for SOC-focused blockchain detection and prevention Lead discovery with SOC analysts and incident responders: workflows, pain points, alert usability, escalation paths, and runbooks Own and refine the backlog: detection use cases, requirements, acceptance criteria, and prioritization tradeoffs Partner with engineering/threat teams to deliver end-to-end capability: signal ingestion, enrichment, alerting, triage experience, and response automation where appropriate Establish and track success metrics (e.g., precision/false positive rate, coverage, latency, time-to-detect/time-to-respond, alert volume, reliability/SLA) and drive continuous improvement Drive launch readiness: documentation, training, operational handoffs, and feedback loops with the SOC Required Qualifications, Capabilities, and Skills Product management experience delivering security detections, SOC tooling, or data/analytics products Strong understanding of SOC operations (alert lifecycle, triage, escalations, incident response) Background in blockchain fundamentals and common threat patterns/abuse cases Ability to use data to prioritize, measure detection efficacy, and manage false positives Preferred Experience with SIEM/SOAR and detection engineering programs Experience operating in a highly matrixed, complex organization Equal Opportunity Statement We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
Job Summary Music is Universal. It's the passionate and dedicated team at Universal Music who help make us the world's leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does. Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation. We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email . Observability Engineer We are UMG, the Universal Music Group. We are the world's leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world. We are seeking a talented and proactive Observability Engineer to join our dynamic global team. You will be passionate about data driven decisions, automation, and committed to continuous improvement. In this pivotal role, you will be instrumental in building, maintaining and enhancing the comprehensive observability solutions that ensure the reliability, performance and scalability of our critical IT systems and applications across the globe. You'll work at the intersection of technology and the vibrant world of music, providing deep insights that drive operational excellence and enable rapid response to any challenge. Job Functions Design & Implementation: Working with the team to ensure our observability stack provides world class services through design, implementation and continuous improvement of our environment, encompassing monitoring, logging, tracing and alerting systems across diverse cloud native, on premise and hybrid environments. Innovate with Tooling: Evaluate, select and implement leading observability tools and platforms (Dynatrace, AWS Cloudwatch, Prometheus, Grafana, ELK Stack, Splunk, OpenTelemetry) and automate our observability pipelines and alerting mechanisms working with development teams. Champion Best Practices: Help define, enforce and advocate for observability standards and best practices across all engineering and operations teams, ensuring consistent instrumentation and visibility throughout our global organization. Develop Robust Monitoring: Create and maintain powerful monitoring solutions, intuitive dashboards and automated alerts to provide real time insights into system health, performance and availability. Drive Incident Resolution: Work with the Operations teams to utilize telemetry data for swift diagnosis and resolution and conduct post incident reviews to enhance our systems. Collaborate & Empower: Partner across other teams in the wider UMG global Technology team to drive positive change, influencing and driving best practice within the Observability space for their ultimate benefit. Work closely with development, SRE and infrastructure teams to embed observability throughout the entire technology lifecycle, empowering teams with the insights they need. Optimize Performance: Analyze telemetry data to identify and resolve performance bottlenecks, optimise resource allocation and fine tune configurations for peak efficiency. Support Compliance & Security: Contribute to our compliance and security efforts through effective log management and integration with SIEM systems. Other Essential Components: Work independently to deliver results while acting as part of a global team to design and implement robust solutions across a hybrid, complex ecosystem of systems; undertake system analysis based on observability notifications to troubleshoot complex issues to improve value from UMG's technology investments, working with a mindset of continual improvement; take an active part in documenting and defining processes and best practice. Make UMG the place to be: Actively taking part in making the Observability team a positive and respectful place to be. UMG is a place where everyone can bring themselves fully to work and thrive; as a key part of the Technology department you are an important part of building our culture. Job Requirements Experience: 3+ years of hands on experience in an Observability, Site Reliability Engineering or DevOps role, with a dedicated focus on observability. Technical Expertise: Strong understanding and practical experience with monitoring, logging and tracing systems; proficiency with industry standard observability tools (Dynatrace, AWS Cloudwatch, Prometheus, Grafana, ELK Stack, Splunk, Logic Monitor); strong technical knowledge with major cloud platforms (AWS, Azure or GCP); solid programming and scripting skills (Python, Go, Shell, JavaScript) for automation; understanding of distributed systems, microservices architectures and cloud native environments; experience with Docker/Kubernetes and DevOps principles; familiarity with CI/CD pipelines and automation tools (Ansible, Terraform). Problem Solving: Exceptional analytical and problem solving abilities, with a proactive approach to tackling complex technical challenges. Communication: Excellent communication, collaboration and interpersonal skills, with the ability to clearly articulate technical concepts to diverse audiences. Domain Knowledge: Prior experience supporting critical business applications within a large scale global enterprise environment. Security Awareness: Awareness of security best practices and the ability to integrate security monitoring into observability processes. Education: Bachelor's degree in Computer Science, Engineering or a related technical field, or equivalent practical experience. Self motivated with high degree of initiative and excellent follow up skills, along with strong analytical and problem solving skills. Travel may be required but is not part of the regular work schedule. Desired Qualifications Advanced Concepts: Experience with Chaos Engineering, Canary/Blue Green deployment strategies, capacity planning, data analysis and networking. Software Engineering: Experience in designing and automating observability workloads with a foundation in software engineering, database administration and system administration. Scripting and programming for observability as well as troubleshooting across Python, Go, Java and associated languages. Certifications: Relevant industry certifications (AWS Certified DevOps Engineer, Kubernetes certifications). Job Category Universal Music Group
19/07/2026
Full time
Job Summary Music is Universal. It's the passionate and dedicated team at Universal Music who help make us the world's leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does. Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation. We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email . Observability Engineer We are UMG, the Universal Music Group. We are the world's leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world. We are seeking a talented and proactive Observability Engineer to join our dynamic global team. You will be passionate about data driven decisions, automation, and committed to continuous improvement. In this pivotal role, you will be instrumental in building, maintaining and enhancing the comprehensive observability solutions that ensure the reliability, performance and scalability of our critical IT systems and applications across the globe. You'll work at the intersection of technology and the vibrant world of music, providing deep insights that drive operational excellence and enable rapid response to any challenge. Job Functions Design & Implementation: Working with the team to ensure our observability stack provides world class services through design, implementation and continuous improvement of our environment, encompassing monitoring, logging, tracing and alerting systems across diverse cloud native, on premise and hybrid environments. Innovate with Tooling: Evaluate, select and implement leading observability tools and platforms (Dynatrace, AWS Cloudwatch, Prometheus, Grafana, ELK Stack, Splunk, OpenTelemetry) and automate our observability pipelines and alerting mechanisms working with development teams. Champion Best Practices: Help define, enforce and advocate for observability standards and best practices across all engineering and operations teams, ensuring consistent instrumentation and visibility throughout our global organization. Develop Robust Monitoring: Create and maintain powerful monitoring solutions, intuitive dashboards and automated alerts to provide real time insights into system health, performance and availability. Drive Incident Resolution: Work with the Operations teams to utilize telemetry data for swift diagnosis and resolution and conduct post incident reviews to enhance our systems. Collaborate & Empower: Partner across other teams in the wider UMG global Technology team to drive positive change, influencing and driving best practice within the Observability space for their ultimate benefit. Work closely with development, SRE and infrastructure teams to embed observability throughout the entire technology lifecycle, empowering teams with the insights they need. Optimize Performance: Analyze telemetry data to identify and resolve performance bottlenecks, optimise resource allocation and fine tune configurations for peak efficiency. Support Compliance & Security: Contribute to our compliance and security efforts through effective log management and integration with SIEM systems. Other Essential Components: Work independently to deliver results while acting as part of a global team to design and implement robust solutions across a hybrid, complex ecosystem of systems; undertake system analysis based on observability notifications to troubleshoot complex issues to improve value from UMG's technology investments, working with a mindset of continual improvement; take an active part in documenting and defining processes and best practice. Make UMG the place to be: Actively taking part in making the Observability team a positive and respectful place to be. UMG is a place where everyone can bring themselves fully to work and thrive; as a key part of the Technology department you are an important part of building our culture. Job Requirements Experience: 3+ years of hands on experience in an Observability, Site Reliability Engineering or DevOps role, with a dedicated focus on observability. Technical Expertise: Strong understanding and practical experience with monitoring, logging and tracing systems; proficiency with industry standard observability tools (Dynatrace, AWS Cloudwatch, Prometheus, Grafana, ELK Stack, Splunk, Logic Monitor); strong technical knowledge with major cloud platforms (AWS, Azure or GCP); solid programming and scripting skills (Python, Go, Shell, JavaScript) for automation; understanding of distributed systems, microservices architectures and cloud native environments; experience with Docker/Kubernetes and DevOps principles; familiarity with CI/CD pipelines and automation tools (Ansible, Terraform). Problem Solving: Exceptional analytical and problem solving abilities, with a proactive approach to tackling complex technical challenges. Communication: Excellent communication, collaboration and interpersonal skills, with the ability to clearly articulate technical concepts to diverse audiences. Domain Knowledge: Prior experience supporting critical business applications within a large scale global enterprise environment. Security Awareness: Awareness of security best practices and the ability to integrate security monitoring into observability processes. Education: Bachelor's degree in Computer Science, Engineering or a related technical field, or equivalent practical experience. Self motivated with high degree of initiative and excellent follow up skills, along with strong analytical and problem solving skills. Travel may be required but is not part of the regular work schedule. Desired Qualifications Advanced Concepts: Experience with Chaos Engineering, Canary/Blue Green deployment strategies, capacity planning, data analysis and networking. Software Engineering: Experience in designing and automating observability workloads with a foundation in software engineering, database administration and system administration. Scripting and programming for observability as well as troubleshooting across Python, Go, Java and associated languages. Certifications: Relevant industry certifications (AWS Certified DevOps Engineer, Kubernetes certifications). Job Category Universal Music Group
About Vantage Data Centers Vantage Data Centers powers, cools, protects and connects the technology of the world's well-known hyperscalers, cloud providers and large enterprises. Developing and operating across North America, EMEA and Asia Pacific, Vantage has evolved data center design in innovative ways to deliver dramatic gains in reliability, efficiency and sustainability in flexible environments that can scale as quickly as the market demands. Position Overview The Vantage Cybersecurity Department is very hands on. In most cases, we specify, purchase, configure, and maintain all networking and server hardware with a keen focus on cybersecurity measures. We also work closely with partner Value Added Resellers (VARs) to learn about the latest technological changes and cybersecurity trends so that we can make informed purchase decisions. We are always looking for ways to strike the best balance between technology, performance, cost, and cybersecurity. Vantage Cybersecurity Department also participates in designing each of our new data center building's cybersecurity infrastructure. If you like getting your hands dirty and helping to design, build, and maintain cybersecurity infrastructure in a modern data center, then come work at Vantage. We're expanding with many new builds, enhancing our focus on safeguarding data and infrastructure in the face of evolving cyber threats. The IC/OT Cybersecurity Engineer will support the security of a global OT environment by implementing, and validating cybersecurity controls across IC/OT systems. The role includes performing risk and vulnerability assessments, contributing to secure architecture and strategy, and delivering hands on implementation of OT security solutions such as segmentation, monitoring, and privileged remote access. The engineer will also support controlled security testing and purple team activities to validate controls, identify attack paths, and improve detection and response. Additional responsibilities include analysis of security events, root cause investigation, and continuous improvement of monitoring and response capabilities, while working closely with other teams to ensure a safe, non disruptive security posture. Responsibilities Partner closely with the OT Cybersecurity Manager, other OT Cybersecurity Engineers, and wider cybersecurity functions including GRC and Threat Intelligence. Represent OT Cybersecurity, supporting on call activities and participating in meetings with site operations, vendors, and internal stakeholders to drive consistent implementation of OT cybersecurity practices. Perform OT Cybersecurity Risk assessments against best practices and industry frameworks (e.g., ISA/IEC 62443, NIST SP , NIST CSF) including participating in audits. Act as a key contributor in OT security testing by conducting controlled, non disruptive vulnerability assessments, security validation, and simulation based (purple team) activities to identify vulnerabilities, validate security controls, and assess potential attack paths in coordination with engineering and operations teams. Conduct technical data collection and analysis, including packet capture (PCAP), firewall rule reviews, system configuration reviews, Active Directory enumeration where relevant, and industrial network traffic analysis to identify vulnerabilities, attack paths, anomalous activity, and misconfigurations. Support integration of OT security monitoring into SOC workflows, including alert tuning, use case development, detection improvement, and SOAR playbook development. Support validation of alerts, reduce false positives, identify detection gaps, and improve response effectiveness against relevant OT attack techniques. Support Implementation and Ongoing management of Privileged Remote Access (PRA) solution to control and monitor third party access to critical OT environments. Perform OT asset discovery, inventory management, and risk classification using OT monitoring platforms (e.g., passive monitoring tools), and support the deployment and configuration of IC/OT IDS solutions. Work closely with data center teams to ensure cybersecurity controls do not impact uptime, safety, or operational resilience. Researching, developing, operationalizing, evaluating, and improving OT defensive tactics, techniques, and procedures (TTPs) for detecting and responding to cyber threats. Maintain and create documentation as needed. Perform other ad hoc duties to support the company's security goals. Job Requirements Hands on experience in IT / OT environments, deploying, configuring, and supporting IT / OT cybersecurity solutions across industrial systems and critical infrastructure. Proven experience performing cybersecurity risk assessments across IT / OT environments, including identification of threats, vulnerabilities, and operational impacts. Understanding of security testing methodologies, including white box, grey box, and controlled (non-disruptive) assessment approaches in IT / OT environments. Strong knowledge of cyber threats, attack vectors, exploits, and adversary tactics, techniques, and procedures (TTPs), with the ability to apply this knowledge to real world scenarios. Experience in purple team or security validation activities, including simulating attack scenarios in a controlled manner to validate security controls, detection capabilities, and response effectiveness. Ability to analyse network traffic and host based data (e.g., logs, packet captures, system configurations) to identify anomalies, security events, and potential attack paths. Strong understanding of networking fundamentals, including routing, switching, VLANs, segmentation, and secure network design for IT / OT environments. Experience supporting or participating in incident response activities and tabletop exercises, helping validate readiness and improve coordination across teams. Knowledge and Experience in one or more of the following areas Building Management Systems (BMS) Electrical Power Monitoring Systems (EPMS) SCADA platforms PLC platforms (e.g., Siemens, Schneider, Rockwell) Industrial Protocols (Modbus, DNP3, BACnet, OPC, S7, CIP) Passive OT monitoring solutions (e.g., Tenable, Nozomi, Claroty) Firewalls (IDS/IPS, DPI, application control, web filtering) Network infrastructure (routing, switching, wireless, segmentation) SIEM, SOAR, and XDR platforms Log analysis, alert investigation, and incident response workflows Familiarity with security testing and analysis tools such as Kali Linux, Nmap, Wireshark, Metasploit (controlled use), and other network and protocol analysis tools Bachelor's degree in Cybersecurity, Computer Science, Engineering, or related focused technical training or 4 additional years of engineering experience that may have been acquired in the military, public or private sectors. Following certifications are preferred: CCNA, GICSP, GRID, other Network and Security certifications. Following certifications are nice to have: OSCP / OSCP+, GPEN. Understanding of general cybersecurity frameworks (ISO IEC 27001/27002, ISO 15408, NIST Cybersecurity Framework (CSF), NIST SP). Excellent written and verbal communication skills with transparent and timely communication. Expected travel is less than 20% but may be higher during construction projects. May grow and evolve over time. Be available outside standard working hours when required. Data Center experience is strongly preferred, but not required. We offer a comprehensive suite of health and welfare, retirement, and paid leave benefits exceeding local expectations. Throughout the year, the advantage of being part of the Vantage team is evident with an array of benefits, recognition, training and development, and the knowledge that your contribution adds value to the company and our community. Vantage Data Centers is an Equal Opportunity Employer. Vantage Data Centers does not accept unsolicited resumes from search firm agencies. Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired; such resumes will be deemed the sole property of Vantage Data Centers.
19/07/2026
Full time
About Vantage Data Centers Vantage Data Centers powers, cools, protects and connects the technology of the world's well-known hyperscalers, cloud providers and large enterprises. Developing and operating across North America, EMEA and Asia Pacific, Vantage has evolved data center design in innovative ways to deliver dramatic gains in reliability, efficiency and sustainability in flexible environments that can scale as quickly as the market demands. Position Overview The Vantage Cybersecurity Department is very hands on. In most cases, we specify, purchase, configure, and maintain all networking and server hardware with a keen focus on cybersecurity measures. We also work closely with partner Value Added Resellers (VARs) to learn about the latest technological changes and cybersecurity trends so that we can make informed purchase decisions. We are always looking for ways to strike the best balance between technology, performance, cost, and cybersecurity. Vantage Cybersecurity Department also participates in designing each of our new data center building's cybersecurity infrastructure. If you like getting your hands dirty and helping to design, build, and maintain cybersecurity infrastructure in a modern data center, then come work at Vantage. We're expanding with many new builds, enhancing our focus on safeguarding data and infrastructure in the face of evolving cyber threats. The IC/OT Cybersecurity Engineer will support the security of a global OT environment by implementing, and validating cybersecurity controls across IC/OT systems. The role includes performing risk and vulnerability assessments, contributing to secure architecture and strategy, and delivering hands on implementation of OT security solutions such as segmentation, monitoring, and privileged remote access. The engineer will also support controlled security testing and purple team activities to validate controls, identify attack paths, and improve detection and response. Additional responsibilities include analysis of security events, root cause investigation, and continuous improvement of monitoring and response capabilities, while working closely with other teams to ensure a safe, non disruptive security posture. Responsibilities Partner closely with the OT Cybersecurity Manager, other OT Cybersecurity Engineers, and wider cybersecurity functions including GRC and Threat Intelligence. Represent OT Cybersecurity, supporting on call activities and participating in meetings with site operations, vendors, and internal stakeholders to drive consistent implementation of OT cybersecurity practices. Perform OT Cybersecurity Risk assessments against best practices and industry frameworks (e.g., ISA/IEC 62443, NIST SP , NIST CSF) including participating in audits. Act as a key contributor in OT security testing by conducting controlled, non disruptive vulnerability assessments, security validation, and simulation based (purple team) activities to identify vulnerabilities, validate security controls, and assess potential attack paths in coordination with engineering and operations teams. Conduct technical data collection and analysis, including packet capture (PCAP), firewall rule reviews, system configuration reviews, Active Directory enumeration where relevant, and industrial network traffic analysis to identify vulnerabilities, attack paths, anomalous activity, and misconfigurations. Support integration of OT security monitoring into SOC workflows, including alert tuning, use case development, detection improvement, and SOAR playbook development. Support validation of alerts, reduce false positives, identify detection gaps, and improve response effectiveness against relevant OT attack techniques. Support Implementation and Ongoing management of Privileged Remote Access (PRA) solution to control and monitor third party access to critical OT environments. Perform OT asset discovery, inventory management, and risk classification using OT monitoring platforms (e.g., passive monitoring tools), and support the deployment and configuration of IC/OT IDS solutions. Work closely with data center teams to ensure cybersecurity controls do not impact uptime, safety, or operational resilience. Researching, developing, operationalizing, evaluating, and improving OT defensive tactics, techniques, and procedures (TTPs) for detecting and responding to cyber threats. Maintain and create documentation as needed. Perform other ad hoc duties to support the company's security goals. Job Requirements Hands on experience in IT / OT environments, deploying, configuring, and supporting IT / OT cybersecurity solutions across industrial systems and critical infrastructure. Proven experience performing cybersecurity risk assessments across IT / OT environments, including identification of threats, vulnerabilities, and operational impacts. Understanding of security testing methodologies, including white box, grey box, and controlled (non-disruptive) assessment approaches in IT / OT environments. Strong knowledge of cyber threats, attack vectors, exploits, and adversary tactics, techniques, and procedures (TTPs), with the ability to apply this knowledge to real world scenarios. Experience in purple team or security validation activities, including simulating attack scenarios in a controlled manner to validate security controls, detection capabilities, and response effectiveness. Ability to analyse network traffic and host based data (e.g., logs, packet captures, system configurations) to identify anomalies, security events, and potential attack paths. Strong understanding of networking fundamentals, including routing, switching, VLANs, segmentation, and secure network design for IT / OT environments. Experience supporting or participating in incident response activities and tabletop exercises, helping validate readiness and improve coordination across teams. Knowledge and Experience in one or more of the following areas Building Management Systems (BMS) Electrical Power Monitoring Systems (EPMS) SCADA platforms PLC platforms (e.g., Siemens, Schneider, Rockwell) Industrial Protocols (Modbus, DNP3, BACnet, OPC, S7, CIP) Passive OT monitoring solutions (e.g., Tenable, Nozomi, Claroty) Firewalls (IDS/IPS, DPI, application control, web filtering) Network infrastructure (routing, switching, wireless, segmentation) SIEM, SOAR, and XDR platforms Log analysis, alert investigation, and incident response workflows Familiarity with security testing and analysis tools such as Kali Linux, Nmap, Wireshark, Metasploit (controlled use), and other network and protocol analysis tools Bachelor's degree in Cybersecurity, Computer Science, Engineering, or related focused technical training or 4 additional years of engineering experience that may have been acquired in the military, public or private sectors. Following certifications are preferred: CCNA, GICSP, GRID, other Network and Security certifications. Following certifications are nice to have: OSCP / OSCP+, GPEN. Understanding of general cybersecurity frameworks (ISO IEC 27001/27002, ISO 15408, NIST Cybersecurity Framework (CSF), NIST SP). Excellent written and verbal communication skills with transparent and timely communication. Expected travel is less than 20% but may be higher during construction projects. May grow and evolve over time. Be available outside standard working hours when required. Data Center experience is strongly preferred, but not required. We offer a comprehensive suite of health and welfare, retirement, and paid leave benefits exceeding local expectations. Throughout the year, the advantage of being part of the Vantage team is evident with an array of benefits, recognition, training and development, and the knowledge that your contribution adds value to the company and our community. Vantage Data Centers is an Equal Opportunity Employer. Vantage Data Centers does not accept unsolicited resumes from search firm agencies. Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired; such resumes will be deemed the sole property of Vantage Data Centers.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior SAP Automation Engineer based in the United Kingdom. Join an innovative and fast-growing technology environment focused on transforming SAP security operations through automation, observability, and intelligent remediation. This role offers the opportunity to lead the development of next-generation security solutions that address critical compliance and operational challenges faced by enterprise SAP environments. Working at the intersection of SAP engineering, cybersecurity, and product innovation, you will help shape scalable solutions used by global organizations. The position combines hands on development, strategic influence, and direct collaboration with customers and cross functional teams. This is an ideal opportunity for an experienced SAP professional looking to make a significant impact in a remote first, high growth setting. Accountabilities Lead the design and evolution of SAP security and compliance capabilities, contributing to product strategy and roadmap definition. Develop and implement automated security checks, observability features, and remediation workflows across SAP environments. Translate complex operational and audit challenges into scalable product functionalities and intelligent automation solutions. Define security data models, dashboards, reporting frameworks, and integration architectures involving SAP systems, BTP, SIEM tools, and compliance platforms. Build proof of concepts and innovative features such as automated certificate management, vulnerability prioritization, and SAP Note remediation processes. Collaborate closely with engineering, product, and design teams to enhance platform functionality and deliver customer centric solutions. Engage directly with customers to validate product capabilities and ensure alignment with real world security, compliance, and operational requirements. Requirements Extensive experience in SAP Basis, SAP operations, or SAP security within enterprise, consulting, or managed services environments. Strong hands on programming and automation expertise using technologies such as JavaScript, Python, PowerShell, Ansible, or similar tools. Deep understanding of SAP technical security across ECC, S/4HANA, and SAP Business Technology Platform (BTP). Familiarity with compliance and security frameworks including ISO 27001, SOC 2, NIST, SAP Security Baseline, or equivalent standards. Experience working with SAP monitoring and observability solutions such as SAP Solution Manager, SAP Cloud ALM, or related technologies. Ability to design, build, and implement security solutions with a strong focus on automation and operational excellence. Excellent communication and stakeholder management skills, with the ability to explain technical concepts to both engineering and executive audiences. Experience with ABAP or other SAP development technologies is considered an advantage. Benefits Competitive salary package. Comprehensive holiday and benefits offering. Fully remote working arrangement within the United Kingdom. Dedicated wellbeing day to support work life balance. Learning and development programs with strong opportunities for professional growth. Opportunity to play a key role in a rapidly growing software business with significant career progression potential. Collaborative and people focused culture emphasizing curiosity, innovation, and continuous improvement. Occasional travel opportunities for customer engagements, team gatherings, and company events.
19/07/2026
Full time
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior SAP Automation Engineer based in the United Kingdom. Join an innovative and fast-growing technology environment focused on transforming SAP security operations through automation, observability, and intelligent remediation. This role offers the opportunity to lead the development of next-generation security solutions that address critical compliance and operational challenges faced by enterprise SAP environments. Working at the intersection of SAP engineering, cybersecurity, and product innovation, you will help shape scalable solutions used by global organizations. The position combines hands on development, strategic influence, and direct collaboration with customers and cross functional teams. This is an ideal opportunity for an experienced SAP professional looking to make a significant impact in a remote first, high growth setting. Accountabilities Lead the design and evolution of SAP security and compliance capabilities, contributing to product strategy and roadmap definition. Develop and implement automated security checks, observability features, and remediation workflows across SAP environments. Translate complex operational and audit challenges into scalable product functionalities and intelligent automation solutions. Define security data models, dashboards, reporting frameworks, and integration architectures involving SAP systems, BTP, SIEM tools, and compliance platforms. Build proof of concepts and innovative features such as automated certificate management, vulnerability prioritization, and SAP Note remediation processes. Collaborate closely with engineering, product, and design teams to enhance platform functionality and deliver customer centric solutions. Engage directly with customers to validate product capabilities and ensure alignment with real world security, compliance, and operational requirements. Requirements Extensive experience in SAP Basis, SAP operations, or SAP security within enterprise, consulting, or managed services environments. Strong hands on programming and automation expertise using technologies such as JavaScript, Python, PowerShell, Ansible, or similar tools. Deep understanding of SAP technical security across ECC, S/4HANA, and SAP Business Technology Platform (BTP). Familiarity with compliance and security frameworks including ISO 27001, SOC 2, NIST, SAP Security Baseline, or equivalent standards. Experience working with SAP monitoring and observability solutions such as SAP Solution Manager, SAP Cloud ALM, or related technologies. Ability to design, build, and implement security solutions with a strong focus on automation and operational excellence. Excellent communication and stakeholder management skills, with the ability to explain technical concepts to both engineering and executive audiences. Experience with ABAP or other SAP development technologies is considered an advantage. Benefits Competitive salary package. Comprehensive holiday and benefits offering. Fully remote working arrangement within the United Kingdom. Dedicated wellbeing day to support work life balance. Learning and development programs with strong opportunities for professional growth. Opportunity to play a key role in a rapidly growing software business with significant career progression potential. Collaborative and people focused culture emphasizing curiosity, innovation, and continuous improvement. Occasional travel opportunities for customer engagements, team gatherings, and company events.
Role Title: Information Security Senior Consultant - Detection and Response (Europe & Americas) About Westpac:Westpac is one of the world's oldest banks and a leading financial services organisation with a strong presence across Australia, New Zealand and key international markets. We support individuals, businesses and institutions through a broad range of banking and financial solutions. Our culture is values led and performance driven. At Westpac, success is measured by both what we deliver and how we deliver it. We focus on always delivering safely, doing the right thing, executing with excellence and delivering for customers. These outcomes are underpinned by our behaviours of Care, Listen and Act, which guide how we work together and how we build trust with our customers and communities. About the Team: This role is a core part of Westpac's global 24/7 cybersecurity monitoring and incident response capability - the bank's first line of cyber defence. How will I help? You will be responsible for analysing and responding to potential cyber threats and attacks against our systems, staff and customers. You will also have the opportunity to design, validate, implement and continually improve detection content, translating threat intelligence and attacker behaviours into actionable detections aligned to Westpac's environment and cyber risk priorities. Key Responsibilities Investigate and prioritise security alerts and events, supporting in-depth analysis of logs and threat information from a variety of systems and security tools, including endpoint and network devices. Ensure threats and alerts are prioritised based on risk, investigated and mitigated effectively and efficiently, based on available context and data. Apply critical thinking and analytical mindset to guide and influence decisions where documented process is unclear or incomplete, including exceptions escalated by junior team members. Maintain and continually uplift SOC capability by recommending, leading and implementing operational and process improvements and contributing to the team knowledge base. Collaborate with local and global detection and response teams to optimise detections, integrate logic with SOAR playbooks and improve consistency, coverage and control effectiveness. Support proactive threat hunting to identify control gaps, emerging threats and opportunities to improve detection coverage. What's in it for me? You'll be joining a highly supportive and collaborative team with international coverage during a period of growth across Westpac's international regions. You will work closely with experienced cyber security professionals and senior stakeholders across our global offices, supporting incident response for real world cyber incidents and operational environments. We're obsessed with becoming our customers' banking partner for life and we're looking for people who are passionate about helping us achieve that goal. In return, we're committed to making Westpac the best place to work in the country. Here are just a few of the ways we're already doing that: Flexible work arrangements to help you achieve a greater work/life balance, and a variety of leave options including Culture, Lifestyle and Wellbeing leave. Tailored learning and development opportunities to help your grow your career within the bank. What do I need? 5+ years of relevant experience in a Cyber Security detection and response role Hands on detection engineering experience and/or related qualifications highly regarded Highly developed written and verbal communication, critical thinking, and analytical skills. Proficiency with SOC tools such as SIEM and SOAR, ideally in a corporate technology environment. A strong understanding of common cyber threats and attacks against financial services organisations. Proven ability to translate incident learnings into practical improvements in detection, response and operational resilience. Strong technical background, including knowledge of network technologies and protocols. Ability to understand business context, identify issues, and analyse and correlate information. Good understanding of concepts such as Cyber Kill Chain and MITRE ATT&CK framework. A self-leader, capable of working independently on complex tasks with minimal supervision. Start Here. Just click on theAPPLYbutton. Job Info Job Identification 70173 Job Category Information & Cyber Security
19/07/2026
Full time
Role Title: Information Security Senior Consultant - Detection and Response (Europe & Americas) About Westpac:Westpac is one of the world's oldest banks and a leading financial services organisation with a strong presence across Australia, New Zealand and key international markets. We support individuals, businesses and institutions through a broad range of banking and financial solutions. Our culture is values led and performance driven. At Westpac, success is measured by both what we deliver and how we deliver it. We focus on always delivering safely, doing the right thing, executing with excellence and delivering for customers. These outcomes are underpinned by our behaviours of Care, Listen and Act, which guide how we work together and how we build trust with our customers and communities. About the Team: This role is a core part of Westpac's global 24/7 cybersecurity monitoring and incident response capability - the bank's first line of cyber defence. How will I help? You will be responsible for analysing and responding to potential cyber threats and attacks against our systems, staff and customers. You will also have the opportunity to design, validate, implement and continually improve detection content, translating threat intelligence and attacker behaviours into actionable detections aligned to Westpac's environment and cyber risk priorities. Key Responsibilities Investigate and prioritise security alerts and events, supporting in-depth analysis of logs and threat information from a variety of systems and security tools, including endpoint and network devices. Ensure threats and alerts are prioritised based on risk, investigated and mitigated effectively and efficiently, based on available context and data. Apply critical thinking and analytical mindset to guide and influence decisions where documented process is unclear or incomplete, including exceptions escalated by junior team members. Maintain and continually uplift SOC capability by recommending, leading and implementing operational and process improvements and contributing to the team knowledge base. Collaborate with local and global detection and response teams to optimise detections, integrate logic with SOAR playbooks and improve consistency, coverage and control effectiveness. Support proactive threat hunting to identify control gaps, emerging threats and opportunities to improve detection coverage. What's in it for me? You'll be joining a highly supportive and collaborative team with international coverage during a period of growth across Westpac's international regions. You will work closely with experienced cyber security professionals and senior stakeholders across our global offices, supporting incident response for real world cyber incidents and operational environments. We're obsessed with becoming our customers' banking partner for life and we're looking for people who are passionate about helping us achieve that goal. In return, we're committed to making Westpac the best place to work in the country. Here are just a few of the ways we're already doing that: Flexible work arrangements to help you achieve a greater work/life balance, and a variety of leave options including Culture, Lifestyle and Wellbeing leave. Tailored learning and development opportunities to help your grow your career within the bank. What do I need? 5+ years of relevant experience in a Cyber Security detection and response role Hands on detection engineering experience and/or related qualifications highly regarded Highly developed written and verbal communication, critical thinking, and analytical skills. Proficiency with SOC tools such as SIEM and SOAR, ideally in a corporate technology environment. A strong understanding of common cyber threats and attacks against financial services organisations. Proven ability to translate incident learnings into practical improvements in detection, response and operational resilience. Strong technical background, including knowledge of network technologies and protocols. Ability to understand business context, identify issues, and analyse and correlate information. Good understanding of concepts such as Cyber Kill Chain and MITRE ATT&CK framework. A self-leader, capable of working independently on complex tasks with minimal supervision. Start Here. Just click on theAPPLYbutton. Job Info Job Identification 70173 Job Category Information & Cyber Security