Apto Solutions
Pembroke Road, Clifton, Bristol BS8 3BA, UK
Who this is for
An early-career engineering role inside Operate, our managed service. Security or observability background — either is welcome.
You have been working for eighteen months to three years in a hands-on technical role — a platform team, a SOC or security engineering team, an MSP or MSSP, an infrastructure or DevOps team, a vendor’s support or professional services desk — and you are looking for your first move. You have had your hands on something that runs in production and matters to somebody. You want to go deeper, faster, in a smaller business where the work you do is seen. This is not a graduate scheme and it is not a helpdesk. It is a real engineering seat with real customers, real supervision and a clear path up.
The Role
This is a hands-on engineering role inside Operate, our managed service. You will help run customer telemetry platforms day to day, improve them, and contribute to the platform that lets us run them well. You will do this as part of a small engineering pool, with a senior engineer checking your work before it reaches a customer and a line manager who is accountable for your development.
Operate has two shapes and you will work in both.
Operate Core is always-on. It is continuous ownership of a customer’s platform — health, ingestion, data quality, alerting, upgrades, capacity. There is no handover and no final deliverable. The platform is ours to keep healthy for as long as the customer is ours. Success is measured in the absence of surprises and in the platform being demonstrably better in six months than it is today.
Operate Attach is sprint-based improvement. A customer has a defined problem — noisy alerts, a data source that will not normalise, ingest costs running away, a detection gap, a migration — and we take a scoped block of work and fix it. Attach has a start, a shape and an end. It sits on top of Core, for the same customers, with the same engineers.
Alongside that you will take a share of professional services delivery: shorter, project-shaped engagements that are usually how a customer first meets us.
What You’ll do
Everything below is done with supervision at first and with increasing independence as you show you can carry it. We will be explicit with you about where that line is and how it moves.
Day-to-day health of customer platforms.
Ingestion pipelines, data quality, alerting, licensing and capacity, upgrades and patching. You will start by owning a slice of a named customer estate, and you will be expected to notice problems before the customer does.
Incident and problem work.
Triage, diagnosis and resolution — and then the harder part, which is the root cause and the permanent fix so it does not come back.
Content and configuration.
Detections, dashboards, parsers, normalisation, alert rules, pipeline routing — built properly, peer reviewed, version controlled, documented.
Attach sprints and PS work.
Taking a defined piece of a scoped improvement, delivering it, and being able to show what changed.
Automation.
If you do something manually three times, we expect you to want to automate the fourth. Most of our platform tooling started as an engineer being annoyed by something.
Documentation and runbooks.
Your own, to a standard, every time. Undocumented work is unfinished work.
What this role is NOT
Being clear about this matters as much as the role definition itself.
It is not a SOC analyst seat.
You are not sitting in a queue triaging alerts against someone else’s runbook. You help build and run the platform that the analysts depend on.
It is not a service desk or first-line support role.
You will talk to customers about technical matters, but the work is engineering, not ticket handling.
It is not a data science role.
We work with very large volumes of machine data, but the work is systems and operations engineering, not modelling or statistics. Python and dashboards are not the same thing as running a platform.
It is not a graduate scheme.
We paused our graduate hire to open this role instead, because we want someone who has already spent time in a production environment and knows what it feels like when something breaks at an awkward hour.
It is not a project role with a finish line.
Core has no end date. If what you enjoy is shipping a thing and walking away, you will find the continuous half of this job frustrating.
Who we are looking for
We are indifferent to whether your background is security or observability. Either one is a good starting point, and the interesting work at Apto sits where the two meet — the same telemetry usually has to serve both a security question and an operational one. What we need is depth in one and genuine curiosity about the other
Experience we’re looking for
Roughly eighteen months to three years in a hands-on technical role. We care much more about what you have actually done than about the number of months attached to it, and we know that at this stage most of what you have done was somebody else’s decision. That is fine. We are looking for the shape of it.
You have had your hands on a telemetry, SIEM, observability or monitoring platform that was running in production — not only in a course or a home lab. You have onboarded a data source, tuned an alert, applied an upgrade, or been the person who had to work out why the data stopped arriving.
You have carried something over time rather than only delivering a task and moving on — a set of alerts you looked after, a customer estate you knew well, an on-call rotation, a service that was yours to keep healthy.
You are comfortable in Linux, in at least one query language, and you have written scripts that did something useful. Python is what we mostly use; anything credible is a fine starting point.
You have automated or fixed something real and you can show it. A script, a repo, a before-and-after number, a description concrete enough for us to ask sensible questions about.
You can write. A clear runbook, a readable incident note, a straight message to a customer. This is a customer-facing role.
You have worked in at least one of our vendor families — Splunk, Cribl, Sentinel, Grafana, Datadog, Elastic, Prometheus, OpenTelemetry — or a close analogue. The specific product is negotiable. Real exposure is not.
If you meet most of this and not all of it, apply anyway and tell us which parts you do not have. We would rather read an honest gap than a padded CV.
The platform work – why this is interesting
Most managed service jobs are the same job with a different logo on the ticketing system. This one is not, because we are building our own platform underneath the service and you will work on it. We have replaced a vendor-licensed telemetry backend with an open-source stack we run ourselves. A base platform (secret ;-)) On top of that sits multi-vendor collection — the pattern that lets us onboard a Splunk, a Cribl or a Sentinel customer without rebuilding it from scratch each time. Beyond that, the vendors are all shipping AI and agentic layers — MCP servers, agentic investigation, cross-vendor gateways — and we already have that work live with a customer. You will get early, hands-on exposure to it while most of the industry is still writing slide decks about it.
07/09/2026
Full time
Who this is for
An early-career engineering role inside Operate, our managed service. Security or observability background — either is welcome.
You have been working for eighteen months to three years in a hands-on technical role — a platform team, a SOC or security engineering team, an MSP or MSSP, an infrastructure or DevOps team, a vendor’s support or professional services desk — and you are looking for your first move. You have had your hands on something that runs in production and matters to somebody. You want to go deeper, faster, in a smaller business where the work you do is seen. This is not a graduate scheme and it is not a helpdesk. It is a real engineering seat with real customers, real supervision and a clear path up.
The Role
This is a hands-on engineering role inside Operate, our managed service. You will help run customer telemetry platforms day to day, improve them, and contribute to the platform that lets us run them well. You will do this as part of a small engineering pool, with a senior engineer checking your work before it reaches a customer and a line manager who is accountable for your development.
Operate has two shapes and you will work in both.
Operate Core is always-on. It is continuous ownership of a customer’s platform — health, ingestion, data quality, alerting, upgrades, capacity. There is no handover and no final deliverable. The platform is ours to keep healthy for as long as the customer is ours. Success is measured in the absence of surprises and in the platform being demonstrably better in six months than it is today.
Operate Attach is sprint-based improvement. A customer has a defined problem — noisy alerts, a data source that will not normalise, ingest costs running away, a detection gap, a migration — and we take a scoped block of work and fix it. Attach has a start, a shape and an end. It sits on top of Core, for the same customers, with the same engineers.
Alongside that you will take a share of professional services delivery: shorter, project-shaped engagements that are usually how a customer first meets us.
What You’ll do
Everything below is done with supervision at first and with increasing independence as you show you can carry it. We will be explicit with you about where that line is and how it moves.
Day-to-day health of customer platforms.
Ingestion pipelines, data quality, alerting, licensing and capacity, upgrades and patching. You will start by owning a slice of a named customer estate, and you will be expected to notice problems before the customer does.
Incident and problem work.
Triage, diagnosis and resolution — and then the harder part, which is the root cause and the permanent fix so it does not come back.
Content and configuration.
Detections, dashboards, parsers, normalisation, alert rules, pipeline routing — built properly, peer reviewed, version controlled, documented.
Attach sprints and PS work.
Taking a defined piece of a scoped improvement, delivering it, and being able to show what changed.
Automation.
If you do something manually three times, we expect you to want to automate the fourth. Most of our platform tooling started as an engineer being annoyed by something.
Documentation and runbooks.
Your own, to a standard, every time. Undocumented work is unfinished work.
What this role is NOT
Being clear about this matters as much as the role definition itself.
It is not a SOC analyst seat.
You are not sitting in a queue triaging alerts against someone else’s runbook. You help build and run the platform that the analysts depend on.
It is not a service desk or first-line support role.
You will talk to customers about technical matters, but the work is engineering, not ticket handling.
It is not a data science role.
We work with very large volumes of machine data, but the work is systems and operations engineering, not modelling or statistics. Python and dashboards are not the same thing as running a platform.
It is not a graduate scheme.
We paused our graduate hire to open this role instead, because we want someone who has already spent time in a production environment and knows what it feels like when something breaks at an awkward hour.
It is not a project role with a finish line.
Core has no end date. If what you enjoy is shipping a thing and walking away, you will find the continuous half of this job frustrating.
Who we are looking for
We are indifferent to whether your background is security or observability. Either one is a good starting point, and the interesting work at Apto sits where the two meet — the same telemetry usually has to serve both a security question and an operational one. What we need is depth in one and genuine curiosity about the other
Experience we’re looking for
Roughly eighteen months to three years in a hands-on technical role. We care much more about what you have actually done than about the number of months attached to it, and we know that at this stage most of what you have done was somebody else’s decision. That is fine. We are looking for the shape of it.
You have had your hands on a telemetry, SIEM, observability or monitoring platform that was running in production — not only in a course or a home lab. You have onboarded a data source, tuned an alert, applied an upgrade, or been the person who had to work out why the data stopped arriving.
You have carried something over time rather than only delivering a task and moving on — a set of alerts you looked after, a customer estate you knew well, an on-call rotation, a service that was yours to keep healthy.
You are comfortable in Linux, in at least one query language, and you have written scripts that did something useful. Python is what we mostly use; anything credible is a fine starting point.
You have automated or fixed something real and you can show it. A script, a repo, a before-and-after number, a description concrete enough for us to ask sensible questions about.
You can write. A clear runbook, a readable incident note, a straight message to a customer. This is a customer-facing role.
You have worked in at least one of our vendor families — Splunk, Cribl, Sentinel, Grafana, Datadog, Elastic, Prometheus, OpenTelemetry — or a close analogue. The specific product is negotiable. Real exposure is not.
If you meet most of this and not all of it, apply anyway and tell us which parts you do not have. We would rather read an honest gap than a padded CV.
The platform work – why this is interesting
Most managed service jobs are the same job with a different logo on the ticketing system. This one is not, because we are building our own platform underneath the service and you will work on it. We have replaced a vendor-licensed telemetry backend with an open-source stack we run ourselves. A base platform (secret ;-)) On top of that sits multi-vendor collection — the pattern that lets us onboard a Splunk, a Cribl or a Sentinel customer without rebuilding it from scratch each time. Beyond that, the vendors are all shipping AI and agentic layers — MCP servers, agentic investigation, cross-vendor gateways — and we already have that work live with a customer. You will get early, hands-on exposure to it while most of the industry is still writing slide decks about it.
Principal Identity & Access Lead Milton Keynes (2 days on site) 75 - 85k + 15% bonus We are working with an established organisation who are embarking on a significant digital transformation programme and are seeking a Principal Identity & Access Lead to shape and deliver their enterprise Identity and Access Management (IAM) strategy. The role will play a pivotal role in protecting critical systems, data, and business services by leading the evolution of the organisation's IAM capability. Working closely with the CISO and senior stakeholders, you will design, implement, and continuously enhance IAM and Privileged Access Management (PAM) solutions that strengthen resilience, support regulatory compliance, and enable secure business transformation. Key responsibilities include: Own and drive the enterprise IAM vision, roadmap and strategy, ensuring identity security capabilities support organisational goals and regulatory expectations Lead the selection, deployment, integration and ongoing optimisation of IAM and PAM solutions Champion identity governance and access management best practices across the organisation, influencing stakeholders at all levels Lead the design and operation of robust IAM and PAM controls that protect critical systems, data and business services Drive a culture of least privilege, accountability and access governance through effective control frameworks and stakeholder engagement Deliver insightful reporting and executive-level briefings on IAM risk, compliance, maturity and control effectiveness Lead a team of IAM Analysts Experience with IAM and PAM tools such as SailPoint, CyberArk, Delinea or similar is essential. This role can be based in central London or Milton Keynes, 2 days per week onsite. If London, occasional travel to Milton Keynes will be required, 2 days per month. If you're passionate about building secure, scalable identity services and enjoy working across technology, architecture and business teams, please apply now.
22/09/2026
Full time
Principal Identity & Access Lead Milton Keynes (2 days on site) 75 - 85k + 15% bonus We are working with an established organisation who are embarking on a significant digital transformation programme and are seeking a Principal Identity & Access Lead to shape and deliver their enterprise Identity and Access Management (IAM) strategy. The role will play a pivotal role in protecting critical systems, data, and business services by leading the evolution of the organisation's IAM capability. Working closely with the CISO and senior stakeholders, you will design, implement, and continuously enhance IAM and Privileged Access Management (PAM) solutions that strengthen resilience, support regulatory compliance, and enable secure business transformation. Key responsibilities include: Own and drive the enterprise IAM vision, roadmap and strategy, ensuring identity security capabilities support organisational goals and regulatory expectations Lead the selection, deployment, integration and ongoing optimisation of IAM and PAM solutions Champion identity governance and access management best practices across the organisation, influencing stakeholders at all levels Lead the design and operation of robust IAM and PAM controls that protect critical systems, data and business services Drive a culture of least privilege, accountability and access governance through effective control frameworks and stakeholder engagement Deliver insightful reporting and executive-level briefings on IAM risk, compliance, maturity and control effectiveness Lead a team of IAM Analysts Experience with IAM and PAM tools such as SailPoint, CyberArk, Delinea or similar is essential. This role can be based in central London or Milton Keynes, 2 days per week onsite. If London, occasional travel to Milton Keynes will be required, 2 days per month. If you're passionate about building secure, scalable identity services and enjoy working across technology, architecture and business teams, please apply now.
About the role Do you want play a hands-on role within a rapidly growing, innovative company - keeping our environment secure, stable, and continuously improving? We're looking for an IT Security Analyst to join our growing tech function. This is very much a doer role where you'll be in the detail - monitoring alerts, investigating incidents, tuning detections - but also stepping back to help us get better over time. That might be improving how we use Sentinel, tightening up controls in Defender, or getting more value out of Purview. You'll work closely with our internal teams and our SOC, and you'll have genuine ownership over parts of the security operation. It's not just about reacting to issues - it's about helping us spot them earlier, reduce noise, and build something more proactive. There's also room to expand your experience - alongside core SecOps work, you'll get involved in how we protect data (Purview, DLP, labelling), and how we support compliance and assurance across the business. This is the perfect role for someone who wants to: Get properly hands-on in a working security operations environment Build deeper expertise in Microsoft security tooling (Defender, Sentinel, Purview) Start broadening into data protection and governance , not just core SecOps Have a say in how things are done , not just follow a runbook We're not trying to build something overly complicated - we just want it to be solid, sensible, and continuously improving . You'll be part of that. You'll be getting up to a range of tasks and responsibilities, including; Security Operations & Incident Response Monitoring and triaging alerts across Microsoft Defender and Sentinel Investigating incidents properly - getting to root cause, not just fixing the symptom Working with our SOC to improve detections and cut down false positives Documenting what happened and feeding that back into better processes and playbooks Vulnerability & Threat Management Supporting vulnerability scanning and making sure issues are actually getting fixed Helping prioritise what matters vs what's just noise Using threat intel and trends to strengthen how we detect and respond Supporting patch validation and general configuration hygiene across endpoints and cloud Data Protection & Information Security Working with Microsoft Purview, particularly around DLP and data visibility Supporting sensitivity labelling (and improving how it's used in practice) Helping us identify where sensitive data lives and how it's being used Contributing to making data protection part of the day-to-day-not just a policy document Risk, Compliance & General Security Hygiene Supporting ISO 27001 and Cyber Essentials Plus activities Helping with audits, evidence, and keeping documentation current Getting involved in control reviews and basic assurance work Supporting supplier/security checks where needed Working With Others Partnering with Infrastructure, Service Desk, GRC, and the wider Tech team Being someone people can come to with security questions (and getting them sensible answers) Supporting user awareness - phishing simulations, guidance, that kind of thing Chipping in with ideas on how we improve, not just maintain About you At Cooper Parry, we're in it together . All we ask of our people is that they play all in . You'll continuously strive to keep learning - whether you're a trainee or a Partner - and you'll be brave , stepping out of your comfort zone to tackle new challenges. Above all, be nice . A simple notion, but an irreplaceable part of what makes CP, CP. We're not expecting a finished product here - but we do want someone who's comfortable in a security operations role and keen to take ownership of their space. You'll already have; Experience working with tools like Defender and Sentinel Understanding of how to investigate alerts properly rather than just clearing queues Knowledge of Microsoft 365 & Azure from a security point of view A grasp of how incident response should actually work in practice. From a technical angle, it would be ideal if you've had some exposure to things like KQL, PowerShell, or similar - nothing too niche, just enough to show you can dig into data and automate where it makes sense. It would also be great if you've touched Purview, DLP, or anything around data protection. More broadly, we're looking for someone who's naturally curious. Someone who doesn't just accept alerts at face value, but wants to understand what actually happened and why. You should be comfortable working across teams, explaining things in plain English when needed, and managing your own workload without constant direction. You don't need to tick every box - but you do need to be someone who takes ownership, thinks things through properly, and wants to get better over time. About us We've been dubbed 'the rebels of accountancy'. We're straight-talking. Never afraid to share our opinions. We put people and relationships before products and services, and deliver a streamlined, client-focused service - free from unnecessary red tape. Check out our recent achievements: Best Companies' No.1 Accountancy Firm & No.30 Best Large Company to Work For in the UK Became B Corp Certified in 2023 and we're still the UK's largest accountancy B Corp, measuring and improving our impact beyond business for a brighter tomorrow Achieved 5 awards at the Inspiring Workplace Awards in 2025: winner in the Large Business category and best in class for inspiring People & Culture, Wellbeing, Inclusion and Employee Experience What's in it for you? Our people are the beating heart of our culture. We know that if you love working here, and you're given the trust and autonomy to work in a way that best suits you, you'll produce amazing results. That's why we offer things like: A flexible approach to work - balancing working from home, in office or with clients A generous holiday entitlement An enhanced parental leave policy An enhanced pension scheme No dress code - just "wear something!" A multi-award-winning wellbeing offering to support your physical, mental, spiritual, and financial health Volunteering opportunities to work closer with local communities and charities Cooper Parry social/sports clubs Feeling supported and welcomed is such a big part of bringing your whole self to work. As an equal opportunities employer, we'll work with you to ensure you have everything you need to develop your skills and achieve your best. Get in touch if you have any questions about our commitment to Diversity & Inclusion or about accessibility/accommodations during your application process. For the attention of agencies - unsolicited CVs will not be honoured. We will only accept CV submissions for roles briefed to you by our Talent Acquisition team.
22/09/2026
Full time
About the role Do you want play a hands-on role within a rapidly growing, innovative company - keeping our environment secure, stable, and continuously improving? We're looking for an IT Security Analyst to join our growing tech function. This is very much a doer role where you'll be in the detail - monitoring alerts, investigating incidents, tuning detections - but also stepping back to help us get better over time. That might be improving how we use Sentinel, tightening up controls in Defender, or getting more value out of Purview. You'll work closely with our internal teams and our SOC, and you'll have genuine ownership over parts of the security operation. It's not just about reacting to issues - it's about helping us spot them earlier, reduce noise, and build something more proactive. There's also room to expand your experience - alongside core SecOps work, you'll get involved in how we protect data (Purview, DLP, labelling), and how we support compliance and assurance across the business. This is the perfect role for someone who wants to: Get properly hands-on in a working security operations environment Build deeper expertise in Microsoft security tooling (Defender, Sentinel, Purview) Start broadening into data protection and governance , not just core SecOps Have a say in how things are done , not just follow a runbook We're not trying to build something overly complicated - we just want it to be solid, sensible, and continuously improving . You'll be part of that. You'll be getting up to a range of tasks and responsibilities, including; Security Operations & Incident Response Monitoring and triaging alerts across Microsoft Defender and Sentinel Investigating incidents properly - getting to root cause, not just fixing the symptom Working with our SOC to improve detections and cut down false positives Documenting what happened and feeding that back into better processes and playbooks Vulnerability & Threat Management Supporting vulnerability scanning and making sure issues are actually getting fixed Helping prioritise what matters vs what's just noise Using threat intel and trends to strengthen how we detect and respond Supporting patch validation and general configuration hygiene across endpoints and cloud Data Protection & Information Security Working with Microsoft Purview, particularly around DLP and data visibility Supporting sensitivity labelling (and improving how it's used in practice) Helping us identify where sensitive data lives and how it's being used Contributing to making data protection part of the day-to-day-not just a policy document Risk, Compliance & General Security Hygiene Supporting ISO 27001 and Cyber Essentials Plus activities Helping with audits, evidence, and keeping documentation current Getting involved in control reviews and basic assurance work Supporting supplier/security checks where needed Working With Others Partnering with Infrastructure, Service Desk, GRC, and the wider Tech team Being someone people can come to with security questions (and getting them sensible answers) Supporting user awareness - phishing simulations, guidance, that kind of thing Chipping in with ideas on how we improve, not just maintain About you At Cooper Parry, we're in it together . All we ask of our people is that they play all in . You'll continuously strive to keep learning - whether you're a trainee or a Partner - and you'll be brave , stepping out of your comfort zone to tackle new challenges. Above all, be nice . A simple notion, but an irreplaceable part of what makes CP, CP. We're not expecting a finished product here - but we do want someone who's comfortable in a security operations role and keen to take ownership of their space. You'll already have; Experience working with tools like Defender and Sentinel Understanding of how to investigate alerts properly rather than just clearing queues Knowledge of Microsoft 365 & Azure from a security point of view A grasp of how incident response should actually work in practice. From a technical angle, it would be ideal if you've had some exposure to things like KQL, PowerShell, or similar - nothing too niche, just enough to show you can dig into data and automate where it makes sense. It would also be great if you've touched Purview, DLP, or anything around data protection. More broadly, we're looking for someone who's naturally curious. Someone who doesn't just accept alerts at face value, but wants to understand what actually happened and why. You should be comfortable working across teams, explaining things in plain English when needed, and managing your own workload without constant direction. You don't need to tick every box - but you do need to be someone who takes ownership, thinks things through properly, and wants to get better over time. About us We've been dubbed 'the rebels of accountancy'. We're straight-talking. Never afraid to share our opinions. We put people and relationships before products and services, and deliver a streamlined, client-focused service - free from unnecessary red tape. Check out our recent achievements: Best Companies' No.1 Accountancy Firm & No.30 Best Large Company to Work For in the UK Became B Corp Certified in 2023 and we're still the UK's largest accountancy B Corp, measuring and improving our impact beyond business for a brighter tomorrow Achieved 5 awards at the Inspiring Workplace Awards in 2025: winner in the Large Business category and best in class for inspiring People & Culture, Wellbeing, Inclusion and Employee Experience What's in it for you? Our people are the beating heart of our culture. We know that if you love working here, and you're given the trust and autonomy to work in a way that best suits you, you'll produce amazing results. That's why we offer things like: A flexible approach to work - balancing working from home, in office or with clients A generous holiday entitlement An enhanced parental leave policy An enhanced pension scheme No dress code - just "wear something!" A multi-award-winning wellbeing offering to support your physical, mental, spiritual, and financial health Volunteering opportunities to work closer with local communities and charities Cooper Parry social/sports clubs Feeling supported and welcomed is such a big part of bringing your whole self to work. As an equal opportunities employer, we'll work with you to ensure you have everything you need to develop your skills and achieve your best. Get in touch if you have any questions about our commitment to Diversity & Inclusion or about accessibility/accommodations during your application process. For the attention of agencies - unsolicited CVs will not be honoured. We will only accept CV submissions for roles briefed to you by our Talent Acquisition team.
About the job Job summary Discover a career in your hands at HMRC. Whether you're seeking purpose, growth, or a workplace that gives you a true sense of belonging, hear from some of our employees as they share their story about what it's really like to work at HMRC. Visit our YouTube channel to watch the full series and come and discover your potential. The Fraud Prevention Centre (FPC) is a strategic capability within HMRC Security, designed to safeguard customers and the organisation against identity-related fraud and emerging threats. Its mission is built on three interconnected pillars: Protection, Detection, and Response, all underpinned by advanced threat intelligence and customer support. The Centre operates across multiple functional areas, including Proactive Protection, Customer Support & Response, and Strategy & Advisory, to deliver a holistic approach to fraud prevention. Our team is rapidly growing as we invest in new technologies and capabilities, and we are in search of enthusiastic individuals who can help us in achieving our mission. Job description As a Cyber Fraud Senior Analyst, you will play a key role in identifying, investigating, and mitigating identity related and cyber enabled fraud impacting HMRC services. Working within the FPC, the role blends cyber security, data analytics, and operational fraud response, combining advanced analytical techniques and threat based thinking, to protect customers and HMRC from emerging threats. A Cyber Fraud Senior Analyst is responsible for detecting, analysing, and responding to cyber enabled and identity related fraud affecting HMRC's digital services. This role is critical in enabling HMRC to stay ahead of adversaries. You act as both a technical specialist and an operational decision maker-identifying suspicious activity, supporting investigations, guiding interventions, and improving HMRC's fraud detection capabilities. Person specification Data Analysis & Tool Development Innovate with new tools and techniques to enhance data analysis capabilities. Detect suspicious identity-related activity using methods like data mining, data matching, clustering, and outlier detection. You will also use your experience of scripting, to proactively search and discover anomalies. Investigation Investigate anomalies and suspicious activity, applying intelligence-led approaches to disrupt fraudulent behaviour. Case Management Lead and advise on complex and sensitive fraud investigations. Be the escalation point for high-impact or difficult data analysis cases. Innovation Support innovation and continuous improvement in fraud prevention techniques, leveraging automation, anomaly detection, and advanced analytics to stay ahead of evolving threats, and ensure a prompt and effective response. Team Development Provide day-to-day guidance and mentorship to junior analysts, supporting their development, guiding fraud detection techniques, and ensuring high standards of analytical rigour and teamwork across the function. Strategic Reporting & Leadership Support and deputise for the G7 Cyber Customer Operations Lead by producing clear, insightful reports and presentations for senior stakeholders, translating technical findings into business-relevant insights. Cross-functional Collaboration Act as the key liaison across multiple Fraud Prevention Centre and HMRC teams, contributing to planning by interpreting the broader fraud threat landscape. Adaptability Embrace ambiguity in this evolving role, contributing flexibly as the team grows and responsibilities expand. Essential Criteria Proven experience in fraud detection, cyber security, or threat intelligence within a large organisation. Knowledge of fraud detection techniques, including behavioural analysis and anomaly detection and investigation and OSINT (Intelligence) methods. Data analysis skills and experience with large data sets, with proficiency software development and scripting complex queries in analysis environments. Solid technical understanding of web and API services (e.g. cookies, IP addresses, authentication processes) and threats to those services from cybercrime actors and tools. A degree in Data Analysis, Data Science, Information Security, Cyber Security, or at least previous experience in a relevant cyber role. Experience using Security Information and Event Management (SIEM) platforms, preferably in a security operations setting. A sound understanding of Identity, Verification and Authentication principles. Desirable Criteria Strong communicator across both technical and business domains, with the ability to influence and mentor team members and stakeholders. Skilled in reporting, presenting, and visualising complex data in creative, digestible formats. Technical understanding of web services (e.g. cookies, IP addresses, authentication processes) and experience using SIEM platforms such as Splunk. Scripting skills (e.g., Excel functions) and awareness of fraud risks in digital services. Further Location Information Please ensure that you only apply for a location that you are willing and able to work from, as we will only make one offer of employment. Any additional notes included in a 'Further Location Preferences (optional)' field within the application form, will not be considered. Please be aware that you cannot change your location preference after submitting your application. Office Closures If your location preference is for one of the following sites, it's important to note that these are not long-term sites for HMRC and we will require you to move to a new building in the future, subject to our location strategy and the applicable employee policies at that time. For more information on where you might be working, review this information on our locations (opens in a new window) These sites are: Benton Park View, Newcastle - moving to Pilgrims Quarter, Newcastle Telford Plaza, Telford - moving to Parkside Court, Telford Trinity Bridge House, Salford - moving to an alternative office in Manchester/ Salford You will be given more information about what this means at the job offer stage. Leeds Location Moves Adjustment Payment will be available for this role, provided the successful applicant is a current HMRC colleague in Bradford and meets the eligibility requirements outlined in the HMRC's Moves Adjustment Payment guidance. Additional Security Information The successful candidate may be required to apply for Developed Vetting (DV) clearance level once in post but must already hold or be willing to obtain Security Check (SC) clearance level before starting the role. Technical skills We'll assess you against these technical skills during the selection process: Technical Question based on Digital Forensics Technical Question based on Incident Response Benefits Alongside your salary of £45,544, HM Revenue and Customs contributes £13,194 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window). HMRC operates both Flexible and Hybrid Working policies, allowing you to balance your work and personal commitments. We welcome applications from those who need to work a more flexible arrangement and will agree to requests where possible, considering our operational and customer service needs. We offer a generous leave allowance, starting at 25 days and increasing by a day for every year of qualifying service up to a maximum of 30 days. Pension - We make contributions to our colleagues' Alpha pension equal to at least 28.97% of their salary. Family friendly policies. Personal support. Coaching and development. To find out more about HMRC benefits and find out what it's really like to work for HMRC hear from our insiders or visit Thinking of joining the Civil Service Things you need to know Artificial intelligence Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use. Selection process details This vacancy is using Success Profiles (opens in a new window), and will assess your Strengths, Experience and Technical skills. How to Apply As part of the application process, you will be asked to provide the following: A name-blind CV including your job history and previous experiences. Your CV should cover up to a maximum of your last 3 roles and your qualifications. The word limit for each role is 100 words. You should outline any key responsibilities and significant achievements. A 750-word Personal Statement. Your Personal Statement should be used to describe how your skills and experience would be suitable for the advertised role . click apply for full job details
22/09/2026
Full time
About the job Job summary Discover a career in your hands at HMRC. Whether you're seeking purpose, growth, or a workplace that gives you a true sense of belonging, hear from some of our employees as they share their story about what it's really like to work at HMRC. Visit our YouTube channel to watch the full series and come and discover your potential. The Fraud Prevention Centre (FPC) is a strategic capability within HMRC Security, designed to safeguard customers and the organisation against identity-related fraud and emerging threats. Its mission is built on three interconnected pillars: Protection, Detection, and Response, all underpinned by advanced threat intelligence and customer support. The Centre operates across multiple functional areas, including Proactive Protection, Customer Support & Response, and Strategy & Advisory, to deliver a holistic approach to fraud prevention. Our team is rapidly growing as we invest in new technologies and capabilities, and we are in search of enthusiastic individuals who can help us in achieving our mission. Job description As a Cyber Fraud Senior Analyst, you will play a key role in identifying, investigating, and mitigating identity related and cyber enabled fraud impacting HMRC services. Working within the FPC, the role blends cyber security, data analytics, and operational fraud response, combining advanced analytical techniques and threat based thinking, to protect customers and HMRC from emerging threats. A Cyber Fraud Senior Analyst is responsible for detecting, analysing, and responding to cyber enabled and identity related fraud affecting HMRC's digital services. This role is critical in enabling HMRC to stay ahead of adversaries. You act as both a technical specialist and an operational decision maker-identifying suspicious activity, supporting investigations, guiding interventions, and improving HMRC's fraud detection capabilities. Person specification Data Analysis & Tool Development Innovate with new tools and techniques to enhance data analysis capabilities. Detect suspicious identity-related activity using methods like data mining, data matching, clustering, and outlier detection. You will also use your experience of scripting, to proactively search and discover anomalies. Investigation Investigate anomalies and suspicious activity, applying intelligence-led approaches to disrupt fraudulent behaviour. Case Management Lead and advise on complex and sensitive fraud investigations. Be the escalation point for high-impact or difficult data analysis cases. Innovation Support innovation and continuous improvement in fraud prevention techniques, leveraging automation, anomaly detection, and advanced analytics to stay ahead of evolving threats, and ensure a prompt and effective response. Team Development Provide day-to-day guidance and mentorship to junior analysts, supporting their development, guiding fraud detection techniques, and ensuring high standards of analytical rigour and teamwork across the function. Strategic Reporting & Leadership Support and deputise for the G7 Cyber Customer Operations Lead by producing clear, insightful reports and presentations for senior stakeholders, translating technical findings into business-relevant insights. Cross-functional Collaboration Act as the key liaison across multiple Fraud Prevention Centre and HMRC teams, contributing to planning by interpreting the broader fraud threat landscape. Adaptability Embrace ambiguity in this evolving role, contributing flexibly as the team grows and responsibilities expand. Essential Criteria Proven experience in fraud detection, cyber security, or threat intelligence within a large organisation. Knowledge of fraud detection techniques, including behavioural analysis and anomaly detection and investigation and OSINT (Intelligence) methods. Data analysis skills and experience with large data sets, with proficiency software development and scripting complex queries in analysis environments. Solid technical understanding of web and API services (e.g. cookies, IP addresses, authentication processes) and threats to those services from cybercrime actors and tools. A degree in Data Analysis, Data Science, Information Security, Cyber Security, or at least previous experience in a relevant cyber role. Experience using Security Information and Event Management (SIEM) platforms, preferably in a security operations setting. A sound understanding of Identity, Verification and Authentication principles. Desirable Criteria Strong communicator across both technical and business domains, with the ability to influence and mentor team members and stakeholders. Skilled in reporting, presenting, and visualising complex data in creative, digestible formats. Technical understanding of web services (e.g. cookies, IP addresses, authentication processes) and experience using SIEM platforms such as Splunk. Scripting skills (e.g., Excel functions) and awareness of fraud risks in digital services. Further Location Information Please ensure that you only apply for a location that you are willing and able to work from, as we will only make one offer of employment. Any additional notes included in a 'Further Location Preferences (optional)' field within the application form, will not be considered. Please be aware that you cannot change your location preference after submitting your application. Office Closures If your location preference is for one of the following sites, it's important to note that these are not long-term sites for HMRC and we will require you to move to a new building in the future, subject to our location strategy and the applicable employee policies at that time. For more information on where you might be working, review this information on our locations (opens in a new window) These sites are: Benton Park View, Newcastle - moving to Pilgrims Quarter, Newcastle Telford Plaza, Telford - moving to Parkside Court, Telford Trinity Bridge House, Salford - moving to an alternative office in Manchester/ Salford You will be given more information about what this means at the job offer stage. Leeds Location Moves Adjustment Payment will be available for this role, provided the successful applicant is a current HMRC colleague in Bradford and meets the eligibility requirements outlined in the HMRC's Moves Adjustment Payment guidance. Additional Security Information The successful candidate may be required to apply for Developed Vetting (DV) clearance level once in post but must already hold or be willing to obtain Security Check (SC) clearance level before starting the role. Technical skills We'll assess you against these technical skills during the selection process: Technical Question based on Digital Forensics Technical Question based on Incident Response Benefits Alongside your salary of £45,544, HM Revenue and Customs contributes £13,194 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window). HMRC operates both Flexible and Hybrid Working policies, allowing you to balance your work and personal commitments. We welcome applications from those who need to work a more flexible arrangement and will agree to requests where possible, considering our operational and customer service needs. We offer a generous leave allowance, starting at 25 days and increasing by a day for every year of qualifying service up to a maximum of 30 days. Pension - We make contributions to our colleagues' Alpha pension equal to at least 28.97% of their salary. Family friendly policies. Personal support. Coaching and development. To find out more about HMRC benefits and find out what it's really like to work for HMRC hear from our insiders or visit Thinking of joining the Civil Service Things you need to know Artificial intelligence Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use. Selection process details This vacancy is using Success Profiles (opens in a new window), and will assess your Strengths, Experience and Technical skills. How to Apply As part of the application process, you will be asked to provide the following: A name-blind CV including your job history and previous experiences. Your CV should cover up to a maximum of your last 3 roles and your qualifications. The word limit for each role is 100 words. You should outline any key responsibilities and significant achievements. A 750-word Personal Statement. Your Personal Statement should be used to describe how your skills and experience would be suitable for the advertised role . click apply for full job details
Job title: Cyber AI Engineer - OpenAI / LLM / RAG Location: Remote Rate: 400 - 425 per day Contract: 6 months rolling Candidates must be willing and eligible to go through SC security clearance for this role. Want to work at the intersection of Generative AI and Cyber Security? We're looking for a Cyber AI Engineer to help turn cutting-edge AI capabilities into practical solutions for Security Operations Centres (SOCs). This is a hands-on role focused on prototyping, experimentation and proof-of-concept development - taking ideas from discovery through to working AI solutions that could genuinely augment cyber analysts and operations. You'll work closely with an AI Solution Architect and Business Analyst, translating cyber use cases into secure, measurable and technically viable AI solutions. Responsibilities: Designing and developing OpenAI-powered solutions for cyber security operations Building and integrating LLM, Generative AI and RAG solutions Developing AI assistants, copilots and agentic AI workflows Experimenting with multi-agent orchestration and knowledge retrieval Developing AI solutions using Python and modern AI frameworks Working with vector databases and retrieval technologies Integrating AI capabilities with SIEM, SOAR and wider cyber platforms Designing prompts and optimising LLM performance Building proofs-of-concept and technical prototypes Developing evaluation frameworks to test model performance, accuracy and reliability Applying Responsible AI and AI safety controls Ensuring solutions are built with security, scalability and operational requirements in mind Working with technical and non-technical stakeholders to turn ideas into workable solutions Required Expereince: We're interested in engineers who have genuine hands-on experience with Generative AI and LLM technologies, ideally alongside an understanding of cyber security operations. You'll ideally bring experience across: OpenAI platform / API development LLMs and Generative AI RAG implementation Prompt engineering and optimisation AI assistants / copilots Agentic AI or multi-agent systems Python development Vector databases and knowledge retrieval AI evaluation and model testing API integration and secure software engineering Cyber Security / SOC environments SIEM / SOAR technologies Rapid prototyping and PoC development You don't need to have done everything above. Strong practical GenAI engineering experience combined with an interest in applying AI to cyber security is what matters. The opportunity This isn't a role where you'll simply be talking about what AI could do. You'll be building it, testing it and proving whether it works against real cyber security use cases. If you're an AI Engineer, GenAI Engineer, LLM Engineer or Python Engineer who wants to move deeper into Cyber AI, this is an opportunity to work on some genuinely interesting problems across AI, automation and security operations.
22/09/2026
Contractor
Job title: Cyber AI Engineer - OpenAI / LLM / RAG Location: Remote Rate: 400 - 425 per day Contract: 6 months rolling Candidates must be willing and eligible to go through SC security clearance for this role. Want to work at the intersection of Generative AI and Cyber Security? We're looking for a Cyber AI Engineer to help turn cutting-edge AI capabilities into practical solutions for Security Operations Centres (SOCs). This is a hands-on role focused on prototyping, experimentation and proof-of-concept development - taking ideas from discovery through to working AI solutions that could genuinely augment cyber analysts and operations. You'll work closely with an AI Solution Architect and Business Analyst, translating cyber use cases into secure, measurable and technically viable AI solutions. Responsibilities: Designing and developing OpenAI-powered solutions for cyber security operations Building and integrating LLM, Generative AI and RAG solutions Developing AI assistants, copilots and agentic AI workflows Experimenting with multi-agent orchestration and knowledge retrieval Developing AI solutions using Python and modern AI frameworks Working with vector databases and retrieval technologies Integrating AI capabilities with SIEM, SOAR and wider cyber platforms Designing prompts and optimising LLM performance Building proofs-of-concept and technical prototypes Developing evaluation frameworks to test model performance, accuracy and reliability Applying Responsible AI and AI safety controls Ensuring solutions are built with security, scalability and operational requirements in mind Working with technical and non-technical stakeholders to turn ideas into workable solutions Required Expereince: We're interested in engineers who have genuine hands-on experience with Generative AI and LLM technologies, ideally alongside an understanding of cyber security operations. You'll ideally bring experience across: OpenAI platform / API development LLMs and Generative AI RAG implementation Prompt engineering and optimisation AI assistants / copilots Agentic AI or multi-agent systems Python development Vector databases and knowledge retrieval AI evaluation and model testing API integration and secure software engineering Cyber Security / SOC environments SIEM / SOAR technologies Rapid prototyping and PoC development You don't need to have done everything above. Strong practical GenAI engineering experience combined with an interest in applying AI to cyber security is what matters. The opportunity This isn't a role where you'll simply be talking about what AI could do. You'll be building it, testing it and proving whether it works against real cyber security use cases. If you're an AI Engineer, GenAI Engineer, LLM Engineer or Python Engineer who wants to move deeper into Cyber AI, this is an opportunity to work on some genuinely interesting problems across AI, automation and security operations.
AI Engineer - 3 months - Circa 450 per day inside ir35 - Remote Please note: Due to the nature of the project, successful applicants will be required to be SC cleared prior to appointment Lead the practical design, prototyping and evaluation of OpenAI-powered solutions to augment Cyber Security Operations Centre (SOC) activities. The role will work alongside the AI Solution Architect and Business Analyst to translate discovery findings into working proof-of-concepts, validate technical feasibility, and assess how Large Language Models (LLMs), Retrieval-Augmented Generation (RAG), assistants and agentic AI approaches can safely support SOC analysts and cyber operations. The role will focus on the application of OpenAI technologies to real-world cyber use cases, ensuring solutions are secure, responsible, measurable and aligned to operational requirements. Key Skills OpenAI platform and API development Large Language Models (LLMs) and Generative AI Prompt engineering and prompt optimisation Retrieval-Augmented Generation (RAG) implementation Agentic AI and multi-agent orchestration AI assistant and copilot development Python development and AI frameworks Vector databases and knowledge retrieval SOC processes and cyber security operations understanding Evaluation frameworks and model performance testing Responsible AI and AI safety controls Integration with SIEM, SOAR and cyber platforms Secure software engineering and API integration Experimentation, prototyping and proof-of-concept development Technical communication and stakeholder engagement Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy which can be found on our website. Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and ability to perform the duties of the job. Should the role require the successful candidate to undergo and be eligible for UK Security Vetting. Clearance sponsorship will be provided where required. Due to the nature of the work, candidates should meet the relevant residency requirements. If applicable, Reserved Post nationality restrictions will be confirmed by the client. Damia is committed to inclusive recruitment and welcomes applicants from all backgrounds. Damia Group is acting as an Employment Business in relation to this vacancy and in accordance to Conduct Regulations 2003.
21/09/2026
Contractor
AI Engineer - 3 months - Circa 450 per day inside ir35 - Remote Please note: Due to the nature of the project, successful applicants will be required to be SC cleared prior to appointment Lead the practical design, prototyping and evaluation of OpenAI-powered solutions to augment Cyber Security Operations Centre (SOC) activities. The role will work alongside the AI Solution Architect and Business Analyst to translate discovery findings into working proof-of-concepts, validate technical feasibility, and assess how Large Language Models (LLMs), Retrieval-Augmented Generation (RAG), assistants and agentic AI approaches can safely support SOC analysts and cyber operations. The role will focus on the application of OpenAI technologies to real-world cyber use cases, ensuring solutions are secure, responsible, measurable and aligned to operational requirements. Key Skills OpenAI platform and API development Large Language Models (LLMs) and Generative AI Prompt engineering and prompt optimisation Retrieval-Augmented Generation (RAG) implementation Agentic AI and multi-agent orchestration AI assistant and copilot development Python development and AI frameworks Vector databases and knowledge retrieval SOC processes and cyber security operations understanding Evaluation frameworks and model performance testing Responsible AI and AI safety controls Integration with SIEM, SOAR and cyber platforms Secure software engineering and API integration Experimentation, prototyping and proof-of-concept development Technical communication and stakeholder engagement Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy which can be found on our website. Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and ability to perform the duties of the job. Should the role require the successful candidate to undergo and be eligible for UK Security Vetting. Clearance sponsorship will be provided where required. Due to the nature of the work, candidates should meet the relevant residency requirements. If applicable, Reserved Post nationality restrictions will be confirmed by the client. Damia is committed to inclusive recruitment and welcomes applicants from all backgrounds. Damia Group is acting as an Employment Business in relation to this vacancy and in accordance to Conduct Regulations 2003.
If you enjoy getting hands-on with cyber security, investigating threats and improving the protection of complex IT environments, this could be an opportunity worth exploring. Cyber Security Analyst Southampton Hybrid - 3 days on-site Up to 65,000 We're working with a UK rail freight and logistics business looking for a Cyber Security Analyst to support its IT Systems Manager in protecting systems, networks and data across the organisation. This is an operational, technically focused role combining cyber security, network security and elements of systems administration. You'll work alongside infrastructure, applications and service delivery teams, helping maintain security controls, investigate incidents and support compliance across the business. The Role You'll take responsibility for day-to-day security operations, helping ensure that security controls are working effectively and that potential risks are identified and addressed. Your responsibilities will include: Monitoring security systems, investigating alerts and coordinating incident resolution. Configuring, maintaining and supporting security technologies across on-premises, cloud and SaaS environments. Supporting firewalls, VPNs, endpoint protection, email security, identity and access controls, vulnerability management and security monitoring platforms. Coordinating vulnerability assessments and working with system owners to track remediation through to completion or formal acceptance. Reviewing systems, applications and cloud services for secure configuration and alignment with approved standards. Supporting penetration tests, audits, assurance reviews and accreditation activities. Contributing technical evidence and documentation for security policies, risk assessments and compliance requirements. Providing practical security guidance to technical teams and project stakeholders. Identifying opportunities to improve security services through upgrades, automation and better operational processes. You'll also help maintain alignment with the NIST Cybersecurity Framework and applicable Network and Information Systems (NIS) Regulations. What You'll Bring You'll have significant hands-on experience supporting complex IT, network or cyber security environments, with a strong understanding of how security controls operate across infrastructure, networks, endpoints, cloud services and applications. You'll also bring: Practical knowledge of TCP/IP, firewalls, VPNs, DNS, DHCP, certificates and SSL/TLS. Experience with vulnerability scanning, secure configuration assessments and remediation tracking. An understanding of common attack techniques, security monitoring and incident response. Knowledge of the OWASP Top 10 and recognised cyber security principles. An understanding of the NIST Cybersecurity Framework and NIS Regulations. Experience working towards Cyber Essentials. The ability to maintain security policies, procedures, technical documentation and audit evidence. A methodical approach to investigating issues, prioritising risks and communicating findings clearly. You'll be comfortable working with technical teams and stakeholders, managing competing priorities and taking ownership of security-related actions. A willingness to support occasional out-of-hours requirements is also needed. Desirable Experience Experience with any of the following would be useful: Microsoft Azure, Microsoft 365, Entra ID, Defender or Sentinel. SIEM, endpoint detection and response, secure web gateways, email security or privileged access technologies. Security audits, NIS compliance, assurance reviews or accreditation programmes. ITIL or working within an IT service management framework. Relevant certifications such as CompTIA Security+, CISSP, SSCP, CCNA Security or Microsoft and Palo Alto Networks security certifications. Working in a regulated, safety-critical, transport, logistics or multi-site environment. What's on Offer Salary up to 65,000. Hybrid working, with 3 days a week on-site in Southampton. 25 days' holiday plus bank holidays. Company pension and life assurance. Employee discounts and Cycle to Work scheme. Ongoing training and career development. Employee Assistance Programme and wellbeing support. Occasional travel to other sites may also be required. Apply now or contact Ruby Calver at Spectrum IT Recruitment to find out more. Spectrum IT Recruitment (South) Limited is acting as an Employment Agency in relation to this vacancy.
21/09/2026
Full time
If you enjoy getting hands-on with cyber security, investigating threats and improving the protection of complex IT environments, this could be an opportunity worth exploring. Cyber Security Analyst Southampton Hybrid - 3 days on-site Up to 65,000 We're working with a UK rail freight and logistics business looking for a Cyber Security Analyst to support its IT Systems Manager in protecting systems, networks and data across the organisation. This is an operational, technically focused role combining cyber security, network security and elements of systems administration. You'll work alongside infrastructure, applications and service delivery teams, helping maintain security controls, investigate incidents and support compliance across the business. The Role You'll take responsibility for day-to-day security operations, helping ensure that security controls are working effectively and that potential risks are identified and addressed. Your responsibilities will include: Monitoring security systems, investigating alerts and coordinating incident resolution. Configuring, maintaining and supporting security technologies across on-premises, cloud and SaaS environments. Supporting firewalls, VPNs, endpoint protection, email security, identity and access controls, vulnerability management and security monitoring platforms. Coordinating vulnerability assessments and working with system owners to track remediation through to completion or formal acceptance. Reviewing systems, applications and cloud services for secure configuration and alignment with approved standards. Supporting penetration tests, audits, assurance reviews and accreditation activities. Contributing technical evidence and documentation for security policies, risk assessments and compliance requirements. Providing practical security guidance to technical teams and project stakeholders. Identifying opportunities to improve security services through upgrades, automation and better operational processes. You'll also help maintain alignment with the NIST Cybersecurity Framework and applicable Network and Information Systems (NIS) Regulations. What You'll Bring You'll have significant hands-on experience supporting complex IT, network or cyber security environments, with a strong understanding of how security controls operate across infrastructure, networks, endpoints, cloud services and applications. You'll also bring: Practical knowledge of TCP/IP, firewalls, VPNs, DNS, DHCP, certificates and SSL/TLS. Experience with vulnerability scanning, secure configuration assessments and remediation tracking. An understanding of common attack techniques, security monitoring and incident response. Knowledge of the OWASP Top 10 and recognised cyber security principles. An understanding of the NIST Cybersecurity Framework and NIS Regulations. Experience working towards Cyber Essentials. The ability to maintain security policies, procedures, technical documentation and audit evidence. A methodical approach to investigating issues, prioritising risks and communicating findings clearly. You'll be comfortable working with technical teams and stakeholders, managing competing priorities and taking ownership of security-related actions. A willingness to support occasional out-of-hours requirements is also needed. Desirable Experience Experience with any of the following would be useful: Microsoft Azure, Microsoft 365, Entra ID, Defender or Sentinel. SIEM, endpoint detection and response, secure web gateways, email security or privileged access technologies. Security audits, NIS compliance, assurance reviews or accreditation programmes. ITIL or working within an IT service management framework. Relevant certifications such as CompTIA Security+, CISSP, SSCP, CCNA Security or Microsoft and Palo Alto Networks security certifications. Working in a regulated, safety-critical, transport, logistics or multi-site environment. What's on Offer Salary up to 65,000. Hybrid working, with 3 days a week on-site in Southampton. 25 days' holiday plus bank holidays. Company pension and life assurance. Employee discounts and Cycle to Work scheme. Ongoing training and career development. Employee Assistance Programme and wellbeing support. Occasional travel to other sites may also be required. Apply now or contact Ruby Calver at Spectrum IT Recruitment to find out more. Spectrum IT Recruitment (South) Limited is acting as an Employment Agency in relation to this vacancy.
Solus Accident Repair Centres
Birchanger, Hertfordshire
Overview We are searching for a Product Analyst tosupport the development, evolution and optimisation of Solus' Evolve platform by translating user needs, process insights and business opportunities into clear, actionable product requirements. You will work closelywith Product Managers, Engineers, UX, SMEs and stakeholderstoshape the product backlog, guide discovery and refinement, validate requirements through data and user insight, and ensure that Evolve delivers measurable value across operations. This role will be perfect for someone that has a blend of skills includingbusiness analysis, product thinking, user research and process optimisation. Responsibilities Product Discovery & Insights Conduct discovery activities to understand user pain points, workflows and improvement opportunities. Analyse product usage data, customer feedback and operational metrics to identify trends and insights. Work with Product Owners to turn insights into prioritised problem statements and feature ideas. Requirements Definition Write clear, testable and value-focused user stories, acceptance criteria, business rules and user journeys. Create process maps, data flows, interaction diagrams and system behaviour definitions tailored for Evolve. Shape epics/features alongside Product Owners to support roadmap planning. Product Development Support Support refinement sessions with engineering teams, ensuring requirements are well understood and sized. Answer detailed questions, clarify edge cases and ensure alignment during build cycles. Support test planning, support UAT, review QA outputs and validate delivered features meet acceptance. Participate in release readiness checks and post-release evaluation. Workflow & Process Analysis Map current-state and future-state processes across operational functions that use Evolve. Identify improvements in workflow efficiency, user experience and data quality. Ensure proposed changes align with Solus operational needs and Evolve's long-term direction. Governance & Compliance Ensure requirements adhere to internal standards, data governance, cyber security and regulatory considerations. Support documentation and traceability for audit, compliance or integration governance. Continuous Improvement Identify opportunities to reduce complexity, remove manual workarounds and enhance product usability. Collaborate with operational teams to validate improvement ideas and measure outcomes. Stakeholder Engagement Facilitate workshops, playback sessions and design discussions for requirement gathering and solution shaping. Support communication between Product, Engineering and business users throughout the product lifecycle. Qualifications You should have the following skills and experience: Strong understanding of digital product development, product lifecycle and iterative delivery. A solid grasp of IT systems, integrations, APIs, data models and application behaviour. The ability to translate business needs into product requirements, user stories and acceptance criteria. Proficiency with analysis, mapping and documentation tools (e.g., Azure DevOps/Jira, Visio, process modelling). A good understanding of Agile delivery, testing cycles and release processes. Strong analytical and communication skills. You may also haveProduct or Business Analysis certifications (BCS, IIBA, Product Owner, Scrum) and training in analytics, data models, SQL or systems analysis. Solus, who are owned by Aviva, are one of the UK leaders in vehicle repairs, returning cars to the road in just 11 days on average and a 4.6/5 star customer rating. With an award-winning apprenticeship programme and winners of other recognised industry awards Solus are proud to be shaping the future of vehicle repair. Why Join Solus? We have so much to offer when it comes to being a Solus colleague: Competitive salary based on location, skills, experience, and qualifications. Bonus opportunity tied to your performance and the overall success of Solus. Company pension scheme with employer contributions. 33 days' holiday (including bank holidays), with the option to buy or sell up to 5 days. Save money with up to 40% discount on Aviva products and other retailer discounts. Share in Aviva's success through the Aviva Save As You Earn scheme. Supportive policies including parental and carer's leave. Wellbeing focus with tools like Group Income Protection and 24/7 GP access. At Solus, we value inclusivity and welcome all applicants. If you're excited but don't tick every box, we encourage you to apply-your unique skills might be just what we need. We guarantee an interview for disabled applicants meeting the minimum criteria-just email us after applying to let us know. Ready to join us? Apply online today, and our team will be in touch within 14 days.
19/09/2026
Full time
Overview We are searching for a Product Analyst tosupport the development, evolution and optimisation of Solus' Evolve platform by translating user needs, process insights and business opportunities into clear, actionable product requirements. You will work closelywith Product Managers, Engineers, UX, SMEs and stakeholderstoshape the product backlog, guide discovery and refinement, validate requirements through data and user insight, and ensure that Evolve delivers measurable value across operations. This role will be perfect for someone that has a blend of skills includingbusiness analysis, product thinking, user research and process optimisation. Responsibilities Product Discovery & Insights Conduct discovery activities to understand user pain points, workflows and improvement opportunities. Analyse product usage data, customer feedback and operational metrics to identify trends and insights. Work with Product Owners to turn insights into prioritised problem statements and feature ideas. Requirements Definition Write clear, testable and value-focused user stories, acceptance criteria, business rules and user journeys. Create process maps, data flows, interaction diagrams and system behaviour definitions tailored for Evolve. Shape epics/features alongside Product Owners to support roadmap planning. Product Development Support Support refinement sessions with engineering teams, ensuring requirements are well understood and sized. Answer detailed questions, clarify edge cases and ensure alignment during build cycles. Support test planning, support UAT, review QA outputs and validate delivered features meet acceptance. Participate in release readiness checks and post-release evaluation. Workflow & Process Analysis Map current-state and future-state processes across operational functions that use Evolve. Identify improvements in workflow efficiency, user experience and data quality. Ensure proposed changes align with Solus operational needs and Evolve's long-term direction. Governance & Compliance Ensure requirements adhere to internal standards, data governance, cyber security and regulatory considerations. Support documentation and traceability for audit, compliance or integration governance. Continuous Improvement Identify opportunities to reduce complexity, remove manual workarounds and enhance product usability. Collaborate with operational teams to validate improvement ideas and measure outcomes. Stakeholder Engagement Facilitate workshops, playback sessions and design discussions for requirement gathering and solution shaping. Support communication between Product, Engineering and business users throughout the product lifecycle. Qualifications You should have the following skills and experience: Strong understanding of digital product development, product lifecycle and iterative delivery. A solid grasp of IT systems, integrations, APIs, data models and application behaviour. The ability to translate business needs into product requirements, user stories and acceptance criteria. Proficiency with analysis, mapping and documentation tools (e.g., Azure DevOps/Jira, Visio, process modelling). A good understanding of Agile delivery, testing cycles and release processes. Strong analytical and communication skills. You may also haveProduct or Business Analysis certifications (BCS, IIBA, Product Owner, Scrum) and training in analytics, data models, SQL or systems analysis. Solus, who are owned by Aviva, are one of the UK leaders in vehicle repairs, returning cars to the road in just 11 days on average and a 4.6/5 star customer rating. With an award-winning apprenticeship programme and winners of other recognised industry awards Solus are proud to be shaping the future of vehicle repair. Why Join Solus? We have so much to offer when it comes to being a Solus colleague: Competitive salary based on location, skills, experience, and qualifications. Bonus opportunity tied to your performance and the overall success of Solus. Company pension scheme with employer contributions. 33 days' holiday (including bank holidays), with the option to buy or sell up to 5 days. Save money with up to 40% discount on Aviva products and other retailer discounts. Share in Aviva's success through the Aviva Save As You Earn scheme. Supportive policies including parental and carer's leave. Wellbeing focus with tools like Group Income Protection and 24/7 GP access. At Solus, we value inclusivity and welcome all applicants. If you're excited but don't tick every box, we encourage you to apply-your unique skills might be just what we need. We guarantee an interview for disabled applicants meeting the minimum criteria-just email us after applying to let us know. Ready to join us? Apply online today, and our team will be in touch within 14 days.
About The Role FDM is a global business and technology consultancy seeking a Technical Business Analyst to work for our client within the Financial Services sector. This is initially a 6-12 month contract with the potential to extend and will be a hybrid role that will be based in London, Edinburgh or Bristol. Our client is seeking a Technical Business Analyst who bridges business, technology, cyber security, fraud operations, data and risk teams. The role translates strategic outcomes and operational needs into clear product, data, control and engineering requirements for the Fraud & Security Value Stream. The role supports the design, implementation and continuous improvement of AI-enabled capabilities that strengthen fraud detection, cyber defence, security observability, operational resilience and AI governance. It maintains alignment between business priorities, delivery outcomes, control obligations and technical implementation throughout the lifecycle of each initiative. Responsibilities Analyse and document business, operational, regulatory and technical requirements. Facilitate workshops. Translate outcomes into ADO epics, features, user stories and acceptance criteria. Maintain end-to-end traceability and support prioritisation Identify and shape opportunities across threat detection, alert triage, investigation, case management, orchestration, fraud analytics, resilience and AI governance monitoring. Define workflows, business rules, exception handling, decision boundaries and human oversight. Define data requirements, authoritative sources, ownership, lineage, quality, access and retention needs. Produce mappings, dictionaries and data-flow views. Work with data and engineering teams to confirm readiness. Embed secure-by-design and responsible AI requirements. Document control, privacy, compliance, auditability, observability and governance-gate evidence. Support risk assessments and production-readiness reviews. Partner with architects, product leads, engineers and platform teams. Support backlog refinement, dependency management, sprint planning, testing, release and operational readiness. Maintain assumptions, risks, issues and decisions. Define baselines, outcomes and KPIs for fraud, cyber and operational use cases. Support benefits tracking, dashboards, post-implementation review and continuous improvement. About You At least five years of business analysis or technical business analysis experience. Experience delivering technology-enabled transformation. Experience translating complex business and control needs into technical requirements. Experience working in Agile or iterative delivery environments. Strong stakeholder management across business and technology teams. Experience supporting testing, operational readiness and adoption. Technical and Professional Skills Requirements elicitation and traceability. Process modelling and workshop facilitation. Data analysis, data mapping and integration concepts. API, cloud, analytics and security-monitoring concepts. Agile backlog management and testing methods. Risk, control and audit documentation. Clear written and executive communication Desirable Experience Experience in cyber security, fraud, risk, operational resilience or financial services. Experience delivering AI, machine learning, analytics or intelligent automation capabilities. Experience with cloud and data platforms, preferably Microsoft Azure. Knowledge of security operations, fraud operations, SIEM/XDR, case management or orchestration. Knowledge of responsible AI and AI governance practices. About Us FDM is an award-winning global leader in tech and business talent solutions, backed by more than 35 years of industry experience. We have centres across Europe, North America, and Asia-Pacific, and a global workforce of over 2500 employees. FDM has shown exponential growth throughout the years, firmly establishing itself as an award-winning employer, currently listed on the FTSE4Good Index and as a 2026 Financial Times UK 'Best Employer'. Diversity and Inclusion FDM Group is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, national origin, age, disability, veteran status or any other status protected by federal, provincial or local laws. Why join us Career coaching, mentoring and access to upskilling throughout your entire FDM career Assignments with global companies and opportunities to work abroad Opportunity to re-skill and up-skill into new areas, develop non-linear career paths and build a skillset within your field Annual leave and work-place pension
18/09/2026
Full time
About The Role FDM is a global business and technology consultancy seeking a Technical Business Analyst to work for our client within the Financial Services sector. This is initially a 6-12 month contract with the potential to extend and will be a hybrid role that will be based in London, Edinburgh or Bristol. Our client is seeking a Technical Business Analyst who bridges business, technology, cyber security, fraud operations, data and risk teams. The role translates strategic outcomes and operational needs into clear product, data, control and engineering requirements for the Fraud & Security Value Stream. The role supports the design, implementation and continuous improvement of AI-enabled capabilities that strengthen fraud detection, cyber defence, security observability, operational resilience and AI governance. It maintains alignment between business priorities, delivery outcomes, control obligations and technical implementation throughout the lifecycle of each initiative. Responsibilities Analyse and document business, operational, regulatory and technical requirements. Facilitate workshops. Translate outcomes into ADO epics, features, user stories and acceptance criteria. Maintain end-to-end traceability and support prioritisation Identify and shape opportunities across threat detection, alert triage, investigation, case management, orchestration, fraud analytics, resilience and AI governance monitoring. Define workflows, business rules, exception handling, decision boundaries and human oversight. Define data requirements, authoritative sources, ownership, lineage, quality, access and retention needs. Produce mappings, dictionaries and data-flow views. Work with data and engineering teams to confirm readiness. Embed secure-by-design and responsible AI requirements. Document control, privacy, compliance, auditability, observability and governance-gate evidence. Support risk assessments and production-readiness reviews. Partner with architects, product leads, engineers and platform teams. Support backlog refinement, dependency management, sprint planning, testing, release and operational readiness. Maintain assumptions, risks, issues and decisions. Define baselines, outcomes and KPIs for fraud, cyber and operational use cases. Support benefits tracking, dashboards, post-implementation review and continuous improvement. About You At least five years of business analysis or technical business analysis experience. Experience delivering technology-enabled transformation. Experience translating complex business and control needs into technical requirements. Experience working in Agile or iterative delivery environments. Strong stakeholder management across business and technology teams. Experience supporting testing, operational readiness and adoption. Technical and Professional Skills Requirements elicitation and traceability. Process modelling and workshop facilitation. Data analysis, data mapping and integration concepts. API, cloud, analytics and security-monitoring concepts. Agile backlog management and testing methods. Risk, control and audit documentation. Clear written and executive communication Desirable Experience Experience in cyber security, fraud, risk, operational resilience or financial services. Experience delivering AI, machine learning, analytics or intelligent automation capabilities. Experience with cloud and data platforms, preferably Microsoft Azure. Knowledge of security operations, fraud operations, SIEM/XDR, case management or orchestration. Knowledge of responsible AI and AI governance practices. About Us FDM is an award-winning global leader in tech and business talent solutions, backed by more than 35 years of industry experience. We have centres across Europe, North America, and Asia-Pacific, and a global workforce of over 2500 employees. FDM has shown exponential growth throughout the years, firmly establishing itself as an award-winning employer, currently listed on the FTSE4Good Index and as a 2026 Financial Times UK 'Best Employer'. Diversity and Inclusion FDM Group is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, national origin, age, disability, veteran status or any other status protected by federal, provincial or local laws. Why join us Career coaching, mentoring and access to upskilling throughout your entire FDM career Assignments with global companies and opportunities to work abroad Opportunity to re-skill and up-skill into new areas, develop non-linear career paths and build a skillset within your field Annual leave and work-place pension
About the Company Our client is a long established financial services organisation with several offices throughout the UK. Due to continued investment in technology and information security, they are looking to recruit a Junior Cyber Security Analyst to support the protection of their systems, networks, and sensitive financial data. This is an excellent opportunity for an aspiring cyber security professional to gain hands-on experience within a highly regulated industry, working alongside experienced IT and security specialists. Role Overview The Junior Cyber Security Analyst will assist with monitoring, identifying, and responding to potential security threats while helping to ensure the business maintains a strong cyber security posture. The successful candidate will gain exposure to a wide range of cyber security tools, processes, and technologies while developing their knowledge within the financial sector. Key Responsibilities Monitor security alerts and events using cyber security monitoring tools. Assist in identifying, investigating, and escalating potential security incidents. Support vulnerability assessments and security testing activities. Help maintain cyber security policies, procedures, and documentation. Assist with user access reviews and identity management processes. Support the implementation of security controls across systems and networks. Monitor endpoint protection and anti-malware solutions. Contribute to cyber security awareness initiatives across the organisation. Assist with security audits and compliance activities. Maintain accurate records of incidents, investigations, and security activities. Support disaster recovery and business continuity processes where required. Keep up to date with emerging cyber threats and industry best practices. Required Skills & Qualities Passion for cyber security and technology. Strong analytical and problem-solving skills. Excellent attention to detail. Ability to investigate issues methodically and accurately. Good communication and interpersonal skills. Ability to handle sensitive information confidentially. Strong organisational and time-management skills. Willingness to learn and develop technical knowledge.
17/09/2026
Full time
About the Company Our client is a long established financial services organisation with several offices throughout the UK. Due to continued investment in technology and information security, they are looking to recruit a Junior Cyber Security Analyst to support the protection of their systems, networks, and sensitive financial data. This is an excellent opportunity for an aspiring cyber security professional to gain hands-on experience within a highly regulated industry, working alongside experienced IT and security specialists. Role Overview The Junior Cyber Security Analyst will assist with monitoring, identifying, and responding to potential security threats while helping to ensure the business maintains a strong cyber security posture. The successful candidate will gain exposure to a wide range of cyber security tools, processes, and technologies while developing their knowledge within the financial sector. Key Responsibilities Monitor security alerts and events using cyber security monitoring tools. Assist in identifying, investigating, and escalating potential security incidents. Support vulnerability assessments and security testing activities. Help maintain cyber security policies, procedures, and documentation. Assist with user access reviews and identity management processes. Support the implementation of security controls across systems and networks. Monitor endpoint protection and anti-malware solutions. Contribute to cyber security awareness initiatives across the organisation. Assist with security audits and compliance activities. Maintain accurate records of incidents, investigations, and security activities. Support disaster recovery and business continuity processes where required. Keep up to date with emerging cyber threats and industry best practices. Required Skills & Qualities Passion for cyber security and technology. Strong analytical and problem-solving skills. Excellent attention to detail. Ability to investigate issues methodically and accurately. Good communication and interpersonal skills. Ability to handle sensitive information confidentially. Strong organisational and time-management skills. Willingness to learn and develop technical knowledge.
Spectrum IT Recruitment
Bletchley, Buckinghamshire
SOC Engineer Hybrid - Milton Keynes - 3 Days per Week 40,000 - 45,000 + On Call Must be Eligible for Security Clearance We are looking for a hands-on SOC Engineer to join a highly skilled Cyber Security Operations Centre within a leading internationally advanced technology solutions provider. Working across customers in sectors including Finance, Manufacturing, Utilities and Retail, you'll play a key role in maintaining and improving the technology, telemetry and automation that enables the SOC to detect, investigate and respond to cyber threats across critical infrastructure. This is a technically focused role where you'll combine security operations with engineering, helping to strengthen monitoring capabilities, improve visibility and automate SOC processes. Key Responsibilities Operate, tune and support security monitoring and alerting platforms. Maintain and optimise log ingestion pipelines across multiple data sources. Develop and refine detection rules, alerts and playbooks with SOC Analysts. Support security investigations, incident response and containment. Automate repetitive SOC tasks using PowerShell, Python or Bash. Onboard new services and infrastructure into SOC monitoring. Troubleshoot internal and customer cyber engineering incidents. Maintain technical documentation and operational procedures. Work with engineering teams to improve security visibility and telemetry. Experience Required You'll have experience in a similar operational or security environment, with: Hands-on experience supporting security operations, detection, response or log collection tools. Scripting or automation experience using PowerShell, Python or Bash. Strong networking knowledge, including TCP/IP, DNS, firewalls and proxies. Working knowledge of Windows and Linux systems, particularly logging and monitoring. Experience within a SOC, NOC or 24/7 operational environment. Experience with alert tuning, detection logic or security playbooks. Understanding of monitoring hybrid on-premises and cloud infrastructure. Awareness of security frameworks and structured detection methodologies. If you have the skills and ambition required and want to join and company that can offer career progression opportunities then please send your CV to (url removed) Spectrum IT Recruitment (South) Limited is acting as an Employment Agency in relation to this vacancy.
17/09/2026
Full time
SOC Engineer Hybrid - Milton Keynes - 3 Days per Week 40,000 - 45,000 + On Call Must be Eligible for Security Clearance We are looking for a hands-on SOC Engineer to join a highly skilled Cyber Security Operations Centre within a leading internationally advanced technology solutions provider. Working across customers in sectors including Finance, Manufacturing, Utilities and Retail, you'll play a key role in maintaining and improving the technology, telemetry and automation that enables the SOC to detect, investigate and respond to cyber threats across critical infrastructure. This is a technically focused role where you'll combine security operations with engineering, helping to strengthen monitoring capabilities, improve visibility and automate SOC processes. Key Responsibilities Operate, tune and support security monitoring and alerting platforms. Maintain and optimise log ingestion pipelines across multiple data sources. Develop and refine detection rules, alerts and playbooks with SOC Analysts. Support security investigations, incident response and containment. Automate repetitive SOC tasks using PowerShell, Python or Bash. Onboard new services and infrastructure into SOC monitoring. Troubleshoot internal and customer cyber engineering incidents. Maintain technical documentation and operational procedures. Work with engineering teams to improve security visibility and telemetry. Experience Required You'll have experience in a similar operational or security environment, with: Hands-on experience supporting security operations, detection, response or log collection tools. Scripting or automation experience using PowerShell, Python or Bash. Strong networking knowledge, including TCP/IP, DNS, firewalls and proxies. Working knowledge of Windows and Linux systems, particularly logging and monitoring. Experience within a SOC, NOC or 24/7 operational environment. Experience with alert tuning, detection logic or security playbooks. Understanding of monitoring hybrid on-premises and cloud infrastructure. Awareness of security frameworks and structured detection methodologies. If you have the skills and ambition required and want to join and company that can offer career progression opportunities then please send your CV to (url removed) Spectrum IT Recruitment (South) Limited is acting as an Employment Agency in relation to this vacancy.
About the Company Our client is a long established financial services organisation with several offices throughout the UK. Due to continued investment in technology and information security, they are looking to recruit a Junior Cyber Security Analyst to support the protection of their systems, networks, and sensitive financial data. This is an excellent opportunity for an aspiring cyber security professional to gain hands-on experience within a highly regulated industry, working alongside experienced IT and security specialists. Role Overview The Junior Cyber Security Analyst will assist with monitoring, identifying, and responding to potential security threats while helping to ensure the business maintains a strong cyber security posture. The successful candidate will gain exposure to a wide range of cyber security tools, processes, and technologies while developing their knowledge within the financial sector. Key Responsibilities Monitor security alerts and events using cyber security monitoring tools. Assist in identifying, investigating, and escalating potential security incidents. Support vulnerability assessments and security testing activities. Help maintain cyber security policies, procedures, and documentation. Assist with user access reviews and identity management processes. Support the implementation of security controls across systems and networks. Monitor endpoint protection and anti-malware solutions. Contribute to cyber security awareness initiatives across the organisation. Assist with security audits and compliance activities. Maintain accurate records of incidents, investigations, and security activities. Support disaster recovery and business continuity processes where required. Keep up to date with emerging cyber threats and industry best practices. Required Skills & Qualities Passion for cyber security and technology. Strong analytical and problem-solving skills. Excellent attention to detail. Ability to investigate issues methodically and accurately. Good communication and interpersonal skills. Ability to handle sensitive information confidentially. Strong organisational and time-management skills. Willingness to learn and develop technical knowledge.
17/09/2026
Full time
About the Company Our client is a long established financial services organisation with several offices throughout the UK. Due to continued investment in technology and information security, they are looking to recruit a Junior Cyber Security Analyst to support the protection of their systems, networks, and sensitive financial data. This is an excellent opportunity for an aspiring cyber security professional to gain hands-on experience within a highly regulated industry, working alongside experienced IT and security specialists. Role Overview The Junior Cyber Security Analyst will assist with monitoring, identifying, and responding to potential security threats while helping to ensure the business maintains a strong cyber security posture. The successful candidate will gain exposure to a wide range of cyber security tools, processes, and technologies while developing their knowledge within the financial sector. Key Responsibilities Monitor security alerts and events using cyber security monitoring tools. Assist in identifying, investigating, and escalating potential security incidents. Support vulnerability assessments and security testing activities. Help maintain cyber security policies, procedures, and documentation. Assist with user access reviews and identity management processes. Support the implementation of security controls across systems and networks. Monitor endpoint protection and anti-malware solutions. Contribute to cyber security awareness initiatives across the organisation. Assist with security audits and compliance activities. Maintain accurate records of incidents, investigations, and security activities. Support disaster recovery and business continuity processes where required. Keep up to date with emerging cyber threats and industry best practices. Required Skills & Qualities Passion for cyber security and technology. Strong analytical and problem-solving skills. Excellent attention to detail. Ability to investigate issues methodically and accurately. Good communication and interpersonal skills. Ability to handle sensitive information confidentially. Strong organisational and time-management skills. Willingness to learn and develop technical knowledge.
Our client is a well-established commerce business that relies heavily on secure digital systems to support its operations. They are seeking a motivated Junior Cyber Security Analyst to join their growing IT team. Role overview This entry-level position is ideal for an individual looking to begin a career in cyber security. The successful candidate will support the protection of company systems, networks and data while learning from experienced IT and security professionals. Key duties Monitor security alerts and escalate incidents when necessary. Assist with vulnerability assessments and security audits. Support the implementation of cyber security policies and procedures. Help investigate potential security threats and suspicious activities. Conduct routine system checks and security monitoring. Assist with user access administration and account security. Support cyber awareness initiatives for colleagues. Maintain accurate records and documentation. Candidate requirements Strong interest in cyber security and IT. Excellent analytical and problem-solving skills. Good attention to detail. Ability to follow procedures and work accurately. Strong communication and teamwork skills.
10/09/2026
Full time
Our client is a well-established commerce business that relies heavily on secure digital systems to support its operations. They are seeking a motivated Junior Cyber Security Analyst to join their growing IT team. Role overview This entry-level position is ideal for an individual looking to begin a career in cyber security. The successful candidate will support the protection of company systems, networks and data while learning from experienced IT and security professionals. Key duties Monitor security alerts and escalate incidents when necessary. Assist with vulnerability assessments and security audits. Support the implementation of cyber security policies and procedures. Help investigate potential security threats and suspicious activities. Conduct routine system checks and security monitoring. Assist with user access administration and account security. Support cyber awareness initiatives for colleagues. Maintain accurate records and documentation. Candidate requirements Strong interest in cyber security and IT. Excellent analytical and problem-solving skills. Good attention to detail. Ability to follow procedures and work accurately. Strong communication and teamwork skills.
Our client is a well-established commerce business that relies heavily on secure digital systems to support its operations. They are seeking a motivated Junior Cyber Security Analyst to join their growing IT team. Role overview The successful candidate will play a vital role in supporting office administration, maintaining digital records and ensuring clients receive a professional service. This role is ideal for an organised and detail-oriented individual looking to start a career within business administration and professional services. Key duties Manage electronic filing systems and maintain accurate records. Process client information and update databases. Support onboarding and administration processes. Prepare digital documents, reports and correspondence. Schedule appointments and manage calendars. Handle incoming emails and telephone enquiries. Assist with data entry and document management tasks. Ensure compliance with company procedures and confidentiality requirements. Candidate requirements Strong organisational and administrative skills. Excellent attention to detail. Good communication skills, both written and verbal. Confidence using Microsoft Office applications. Ability to prioritise workloads and meet deadlines. Professional and customer-focused approach.
10/09/2026
Full time
Our client is a well-established commerce business that relies heavily on secure digital systems to support its operations. They are seeking a motivated Junior Cyber Security Analyst to join their growing IT team. Role overview The successful candidate will play a vital role in supporting office administration, maintaining digital records and ensuring clients receive a professional service. This role is ideal for an organised and detail-oriented individual looking to start a career within business administration and professional services. Key duties Manage electronic filing systems and maintain accurate records. Process client information and update databases. Support onboarding and administration processes. Prepare digital documents, reports and correspondence. Schedule appointments and manage calendars. Handle incoming emails and telephone enquiries. Assist with data entry and document management tasks. Ensure compliance with company procedures and confidentiality requirements. Candidate requirements Strong organisational and administrative skills. Excellent attention to detail. Good communication skills, both written and verbal. Confidence using Microsoft Office applications. Ability to prioritise workloads and meet deadlines. Professional and customer-focused approach.
At Lumentum, we develop the technologies that power the world's most advanced communications, industrial and cloud infrastructure. Security is fundamental to everything we do, and we're looking for an experienced Senior Information Security Analyst to help protect our people, data and global operations. This is an opportunity to join a collaborative cyber security team where you'll lead complex investigations, strengthen security controls and influence how we defend against an evolving threat landscape. You'll work across cloud, identity, endpoint, network and data security while partnering with technical and business teams to continuously improve our security capability. If you enjoy solving challenging security problems, mentoring others and driving meaningful improvements, we'd love to hear from you. What you'll be doing As a senior member of our Information Security team, you'll: Lead the investigation and response to complex cyber security incidents across cloud, endpoint, identity, network, email and application environments. Drive improvements to our Security Operations capability through enhanced detections, playbooks, automation and operational processes. Own and enhance key security controls, including Data Loss Prevention (DLP) and Multi-Factor Authentication (MFA), ensuring they remain effective, measurable and aligned with business needs. Assess vulnerabilities, prioritise remediation activities and work with technology teams to reduce cyber risk across the organisation. Provide security assurance for new projects and technology changes, helping embed security by design. Produce meaningful security metrics and reporting for technical and business stakeholders. Coach and mentor colleagues, sharing knowledge and raising security capability across the organisation. Translate complex technical issues into clear, practical recommendations that support informed business decisions. What you'll bring You'll have experience in several of the following areas: Security Operations, Security Incident Response or Security Engineering. Security Information and Event Management (SIEM) and Endpoint Detection & Response (EDR) technologies. Identity and Access Management, including MFA, Conditional Access and Privileged Access. Data Loss Prevention (DLP) technologies and policy management. Vulnerability Management and security hardening. Security architecture reviews and technical assurance. Threat detection, investigation and root cause analysis. Security automation, scripting or workflow improvement. You'll also be comfortable working with recognised security frameworks such as NIST CSF, ISO 27001, CIS Controls or the NCSC Cyber Assessment Framework. About you We're looking for someone who: Has significant experience within cyber security, information security or security operations. Enjoys leading investigations and solving complex technical challenges. Can influence stakeholders at all levels with clear, confident communication. Thinks strategically while remaining hands-on. Takes ownership and is driven by continuous improvement. Builds strong relationships and enjoys developing others. Professional certifications such as CISSP, CISM or CISA are desirable but not essential if you can demonstrate equivalent experience. Why join Lumentum? At Lumentum, you'll work alongside talented people solving real-world technology challenges in a global organisation that values innovation, collaboration and continuous learning. In return, you'll benefit from: The opportunity to influence enterprise-wide cyber security. Exposure to modern cloud and security technologies. A collaborative and supportive team environment. Ongoing professional development and learning opportunities. The chance to make a genuine impact protecting critical business services. Ready to make an impact? If you're passionate about cyber security, thrive in a fast-paced environment and want to help shape the future of security at a global technology leader, we'd love to hear from you.
10/09/2026
Full time
At Lumentum, we develop the technologies that power the world's most advanced communications, industrial and cloud infrastructure. Security is fundamental to everything we do, and we're looking for an experienced Senior Information Security Analyst to help protect our people, data and global operations. This is an opportunity to join a collaborative cyber security team where you'll lead complex investigations, strengthen security controls and influence how we defend against an evolving threat landscape. You'll work across cloud, identity, endpoint, network and data security while partnering with technical and business teams to continuously improve our security capability. If you enjoy solving challenging security problems, mentoring others and driving meaningful improvements, we'd love to hear from you. What you'll be doing As a senior member of our Information Security team, you'll: Lead the investigation and response to complex cyber security incidents across cloud, endpoint, identity, network, email and application environments. Drive improvements to our Security Operations capability through enhanced detections, playbooks, automation and operational processes. Own and enhance key security controls, including Data Loss Prevention (DLP) and Multi-Factor Authentication (MFA), ensuring they remain effective, measurable and aligned with business needs. Assess vulnerabilities, prioritise remediation activities and work with technology teams to reduce cyber risk across the organisation. Provide security assurance for new projects and technology changes, helping embed security by design. Produce meaningful security metrics and reporting for technical and business stakeholders. Coach and mentor colleagues, sharing knowledge and raising security capability across the organisation. Translate complex technical issues into clear, practical recommendations that support informed business decisions. What you'll bring You'll have experience in several of the following areas: Security Operations, Security Incident Response or Security Engineering. Security Information and Event Management (SIEM) and Endpoint Detection & Response (EDR) technologies. Identity and Access Management, including MFA, Conditional Access and Privileged Access. Data Loss Prevention (DLP) technologies and policy management. Vulnerability Management and security hardening. Security architecture reviews and technical assurance. Threat detection, investigation and root cause analysis. Security automation, scripting or workflow improvement. You'll also be comfortable working with recognised security frameworks such as NIST CSF, ISO 27001, CIS Controls or the NCSC Cyber Assessment Framework. About you We're looking for someone who: Has significant experience within cyber security, information security or security operations. Enjoys leading investigations and solving complex technical challenges. Can influence stakeholders at all levels with clear, confident communication. Thinks strategically while remaining hands-on. Takes ownership and is driven by continuous improvement. Builds strong relationships and enjoys developing others. Professional certifications such as CISSP, CISM or CISA are desirable but not essential if you can demonstrate equivalent experience. Why join Lumentum? At Lumentum, you'll work alongside talented people solving real-world technology challenges in a global organisation that values innovation, collaboration and continuous learning. In return, you'll benefit from: The opportunity to influence enterprise-wide cyber security. Exposure to modern cloud and security technologies. A collaborative and supportive team environment. Ongoing professional development and learning opportunities. The chance to make a genuine impact protecting critical business services. Ready to make an impact? If you're passionate about cyber security, thrive in a fast-paced environment and want to help shape the future of security at a global technology leader, we'd love to hear from you.
An NHS Trust is seeking a Business Analyst for a 6 month initial contract. The Business Analyst will support the Innovation Hub in discovering, assessing, designing and delivering technologies for pilot within the Trust. The role will provide structured analysis across the application development lifecycle: defining needs, evaluating opportunities, managing requirements, completing cyber security and Information Governance due diligence, and aligning solutions with operational benefits and the NHS Trust Digital Strategy. Responsibilities Establish a clear understanding of business problems, user needs, opportunities and desired outcomes. Elicit, analyse, document, validate and manage requirements. Assess technologies for strategic fit, feasibility, value, risk, operational impact and readiness. Complete proportionate information governance, data protection, cyber security, clinical, technical, commercial and organisational due diligence. Define current and future processes and identify improvement opportunities for service improvement and process redesign. Build effective relationships across the organisation, including with senior management. Key Deliverables Discovery brief, problem statement and agreed scope. Stakeholder map and engagement plan. Prioritised requirements catalogue or specification, traceable to business objectives. Current and future process maps with supporting analysis. Options appraisal, feasibility assessment or recommendation. Due diligence and assurance tracker covering evidence, risks, actions and approvals. Data-flow documentation and information requirements. Business impact assessment, benefits and measurable success criteria. User stories, use cases, acceptance criteria and support for testing, where applicable. Decision, risk, issue, action and dependency logs, with progress and executive updates. Handover materials and lessons learned for each initiative. If you have experience as Business Analyst across application projects, please do get in touch
09/09/2026
Contractor
An NHS Trust is seeking a Business Analyst for a 6 month initial contract. The Business Analyst will support the Innovation Hub in discovering, assessing, designing and delivering technologies for pilot within the Trust. The role will provide structured analysis across the application development lifecycle: defining needs, evaluating opportunities, managing requirements, completing cyber security and Information Governance due diligence, and aligning solutions with operational benefits and the NHS Trust Digital Strategy. Responsibilities Establish a clear understanding of business problems, user needs, opportunities and desired outcomes. Elicit, analyse, document, validate and manage requirements. Assess technologies for strategic fit, feasibility, value, risk, operational impact and readiness. Complete proportionate information governance, data protection, cyber security, clinical, technical, commercial and organisational due diligence. Define current and future processes and identify improvement opportunities for service improvement and process redesign. Build effective relationships across the organisation, including with senior management. Key Deliverables Discovery brief, problem statement and agreed scope. Stakeholder map and engagement plan. Prioritised requirements catalogue or specification, traceable to business objectives. Current and future process maps with supporting analysis. Options appraisal, feasibility assessment or recommendation. Due diligence and assurance tracker covering evidence, risks, actions and approvals. Data-flow documentation and information requirements. Business impact assessment, benefits and measurable success criteria. User stories, use cases, acceptance criteria and support for testing, where applicable. Decision, risk, issue, action and dependency logs, with progress and executive updates. Handover materials and lessons learned for each initiative. If you have experience as Business Analyst across application projects, please do get in touch
Job Title: Digital & IT Analyst (Infrastructure Site Leader) Location: Stevenage (4 days/week) & Loughborough (1 day/week - travel expenses/mileage covered) Working Hours: Full-Time, On-Site (37 hours/week) Role Overview We are seeking a hands-on Digital & IT Analyst to deliver Tier 1/2 technical support and manage site IT infrastructure across two operational locations. Supporting an site of 80 engineering and production staff, this role combines desk-side support, hardware and vendor management, data analysis, continuous improvement, and local IT project delivery. Key Responsibilities Provide Tier 1 and 2 desk-side technical support for hardware, software, laptops, and mobile devices. Manage and support local site infrastructure across standard and air-gapped networks, including Active Directory, local servers, backup solutions, LAN/WAN, and disaster recovery. Manage external IT vendors and oversee hardware/software procurement. Lead local infrastructure projects using continuous improvement techniques and project management standards (Agile preferred). Act as site control owner for IT security and compliance standards, including Cyber Essentials, CMMC, and SOX key controls. Monitor site key performance indicators (KPIs), track support tickets, and maintain systems documentation. Requirements & Qualifications Experience: 5+ years in broad IT support, infrastructure management, vendor coordination, and desktop support. Technical Proficiency: Strong working knowledge of Windows OS, Active Directory, mobile device management, hardware repair, and ITSM ticketing tools (e.g., ServiceNow). Project & Analytical Skills: Hands-on experience in data analysis, continuous improvement methodologies, and project management. Security Clearance: Active UK SC Clearance is ideal, or eligibility for SC Clearance (minimum 5 years continuous UK residency; open nationality excluding restricted nations). Travel Flexibility: Ability to work on-site 4 days per week in Stevenage and 1 day per week in Loughborough. Package & Benefits 37-hour working week 25 days Annual Leave Performance-related annual bonus scheme (up to 15%) Highly competitive employer-matched pension plan BUPA Private Health Insurance Inter-site travel expenses / mileage reimbursement covered If interested please reply with your CV to dona. com or call me at (phone number removed). Randstad Technologies Ltd is a leading specialist recruitment business for the IT & Engineering industries. Please note that due to a high level of applications, we can only respond to applicants whose skills & qualifications are suitable for this position. No terminology in this advert is intended to discriminate against any of the protected characteristics that fall under the Equality Act 2010. For the purposes of the Conduct Regulations 2003, when advertising permanent vacancies we are acting as an Employment Agency, and when advertising temporary/contract vacancies we are acting as an Employment Business.
05/09/2026
Full time
Job Title: Digital & IT Analyst (Infrastructure Site Leader) Location: Stevenage (4 days/week) & Loughborough (1 day/week - travel expenses/mileage covered) Working Hours: Full-Time, On-Site (37 hours/week) Role Overview We are seeking a hands-on Digital & IT Analyst to deliver Tier 1/2 technical support and manage site IT infrastructure across two operational locations. Supporting an site of 80 engineering and production staff, this role combines desk-side support, hardware and vendor management, data analysis, continuous improvement, and local IT project delivery. Key Responsibilities Provide Tier 1 and 2 desk-side technical support for hardware, software, laptops, and mobile devices. Manage and support local site infrastructure across standard and air-gapped networks, including Active Directory, local servers, backup solutions, LAN/WAN, and disaster recovery. Manage external IT vendors and oversee hardware/software procurement. Lead local infrastructure projects using continuous improvement techniques and project management standards (Agile preferred). Act as site control owner for IT security and compliance standards, including Cyber Essentials, CMMC, and SOX key controls. Monitor site key performance indicators (KPIs), track support tickets, and maintain systems documentation. Requirements & Qualifications Experience: 5+ years in broad IT support, infrastructure management, vendor coordination, and desktop support. Technical Proficiency: Strong working knowledge of Windows OS, Active Directory, mobile device management, hardware repair, and ITSM ticketing tools (e.g., ServiceNow). Project & Analytical Skills: Hands-on experience in data analysis, continuous improvement methodologies, and project management. Security Clearance: Active UK SC Clearance is ideal, or eligibility for SC Clearance (minimum 5 years continuous UK residency; open nationality excluding restricted nations). Travel Flexibility: Ability to work on-site 4 days per week in Stevenage and 1 day per week in Loughborough. Package & Benefits 37-hour working week 25 days Annual Leave Performance-related annual bonus scheme (up to 15%) Highly competitive employer-matched pension plan BUPA Private Health Insurance Inter-site travel expenses / mileage reimbursement covered If interested please reply with your CV to dona. com or call me at (phone number removed). Randstad Technologies Ltd is a leading specialist recruitment business for the IT & Engineering industries. Please note that due to a high level of applications, we can only respond to applicants whose skills & qualifications are suitable for this position. No terminology in this advert is intended to discriminate against any of the protected characteristics that fall under the Equality Act 2010. For the purposes of the Conduct Regulations 2003, when advertising permanent vacancies we are acting as an Employment Agency, and when advertising temporary/contract vacancies we are acting as an Employment Business.
Vulnerability Management Analyst Preston or Inverness (Hybrid) 40k - 50k per annum + benefits Must be a sole UK national and eligible for Security Clearance Are you a cyber security professional with a passion for vulnerability management? Do you thrive on coordinating remediation, engaging suppliers, and turning technical risk into clear, actionable reporting? If so, this could be your next big move. We're recruiting on behalf of a global technology and business transformation leader, currently looking to bring five Vulnerability Management Analysts into a high-performing Security Operations team. This is a fantastic opportunity to join a growing cyber security function at a genuinely exciting time, working alongside a global network of security experts, from Architects and Engineers to Analysts and Compliance Managers. Rather than operating the tooling directly, you'll take ownership of the process end-to-end: reviewing findings, coordinating remediation with suppliers, tracking progress, and driving timely resolution of security issues across the environment. Key Responsibilities Coordinate and track vulnerabilities from identification through to remediation and closure, ensuring progress meets agreed SLAs and escalating high-risk or overdue issues Engage with suppliers and technical stakeholders to obtain, validate and maintain accurate vulnerability data, ensuring consistent reporting standards and clear ownership Produce vulnerability reports, dashboards and metrics that give visibility of ageing vulnerabilities, recurring issues, SLA breaches and emerging trends Support governance and compliance by maintaining audit-ready evidence and documentation, and ensuring adherence to vulnerability management processes, policies and risk exception procedures What You'll Bring Experience in cyber security, information security, service management or governance, with a solid grasp of vulnerability management principles (CVSS, KEV, risk ratings and remediation tracking) Strong analytical and reporting skills, with the ability to produce meaningful security metrics Proven experience engaging multiple stakeholders and suppliers to drive remediation and performance improvements Familiarity with vulnerability management tooling, reporting processes and audit/assurance requirements, ideally gained within a SIAM or multi-supplier, regulated, public sector or defence environment Desirable: Recognised Vulnerability Management qualifications and/or hands-on experience with tools such as Qualys, Brinqa or Tenable If you've held any of these roles or used these technologies/skills, this role could be a great fit: Vulnerability Management Analyst, Vulnerability Analyst, Cyber Security Analyst, Security Analyst, Information Security Analyst, Threat and Vulnerability Analyst, VM Analyst, Patch Management Analyst, Security Governance Analyst, Risk and Compliance Analyst, Remediation Coordinator, CVSS, KEV, Qualys, Brinqa, Tenable, SIAM, Security Operations, SecOps. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate 1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
04/09/2026
Full time
Vulnerability Management Analyst Preston or Inverness (Hybrid) 40k - 50k per annum + benefits Must be a sole UK national and eligible for Security Clearance Are you a cyber security professional with a passion for vulnerability management? Do you thrive on coordinating remediation, engaging suppliers, and turning technical risk into clear, actionable reporting? If so, this could be your next big move. We're recruiting on behalf of a global technology and business transformation leader, currently looking to bring five Vulnerability Management Analysts into a high-performing Security Operations team. This is a fantastic opportunity to join a growing cyber security function at a genuinely exciting time, working alongside a global network of security experts, from Architects and Engineers to Analysts and Compliance Managers. Rather than operating the tooling directly, you'll take ownership of the process end-to-end: reviewing findings, coordinating remediation with suppliers, tracking progress, and driving timely resolution of security issues across the environment. Key Responsibilities Coordinate and track vulnerabilities from identification through to remediation and closure, ensuring progress meets agreed SLAs and escalating high-risk or overdue issues Engage with suppliers and technical stakeholders to obtain, validate and maintain accurate vulnerability data, ensuring consistent reporting standards and clear ownership Produce vulnerability reports, dashboards and metrics that give visibility of ageing vulnerabilities, recurring issues, SLA breaches and emerging trends Support governance and compliance by maintaining audit-ready evidence and documentation, and ensuring adherence to vulnerability management processes, policies and risk exception procedures What You'll Bring Experience in cyber security, information security, service management or governance, with a solid grasp of vulnerability management principles (CVSS, KEV, risk ratings and remediation tracking) Strong analytical and reporting skills, with the ability to produce meaningful security metrics Proven experience engaging multiple stakeholders and suppliers to drive remediation and performance improvements Familiarity with vulnerability management tooling, reporting processes and audit/assurance requirements, ideally gained within a SIAM or multi-supplier, regulated, public sector or defence environment Desirable: Recognised Vulnerability Management qualifications and/or hands-on experience with tools such as Qualys, Brinqa or Tenable If you've held any of these roles or used these technologies/skills, this role could be a great fit: Vulnerability Management Analyst, Vulnerability Analyst, Cyber Security Analyst, Security Analyst, Information Security Analyst, Threat and Vulnerability Analyst, VM Analyst, Patch Management Analyst, Security Governance Analyst, Risk and Compliance Analyst, Remediation Coordinator, CVSS, KEV, Qualys, Brinqa, Tenable, SIAM, Security Operations, SecOps. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate 1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
Our client, a leading organisation operating within a global multinational group and recognised as part of a Fortune 500 business, is seeking a highly motivated and enthusiastic IT Service Desk Analyst to join their progressive, values-driven IT Infrastructure team based at their Billingham site. Our client is committed to delivering sustainable solutions that support both industry and communities. Their employees are focused on safe and reliable operations, environmental responsibility, and continuous improvement. Joining the organisation means becoming part of a collaborative team where diverse skills, experiences, and perspectives are valued. Employees are encouraged to develop their careers, take on new challenges, and contribute to meaningful work in a supportive and inclusive environment. In this role, you will provide first-line, and where appropriate second-line, technical support across the business. You will be responsible for logging, tracking, and resolving IT incidents and service requests received via telephone, email, and self-service portals. You will also play an active role in on-call support and out-of-hours cover to help ensure safe, reliable, and effective business operations. A competitive salary and benefits package is on offer, including a performance-related bonus scheme, enhanced pension contributions, life assurance, employee assistance programme, and healthcare benefits. Our client is committed to creating an inclusive workplace where everyone is treated with respect and fairness. They actively promote diversity and equal opportunities, recognising the value that different perspectives bring to their organisation. Key Responsibilities Provide technical support to users across all aspects of hardware, software, networking, and peripheral equipment issues. Develop a strong understanding of business systems and applications, applying troubleshooting and analytical skills to resolve technical problems. Create and maintain technical documentation, user guides, and troubleshooting resources. Manage incidents and service requests through established IT service management processes, ensuring accurate logging, tracking, escalation, resolution, and closure. Deliver first-line service desk support and end-user assistance across Microsoft technologies and business applications. Maintain, configure, and administer computer networks and associated IT infrastructure, including hardware, operating systems, applications, backup solutions, and disaster recovery processes. Complete project-related tasks assigned by the IT Team Leader efficiently and within agreed timescales. Monitor, diagnose, and resolve hardware, software, network, and system issues, escalating where necessary and replacing defective components when required. Support operational technology and manufacturing-related systems where applicable. Maintain cybersecurity and data protection standards, ensuring compliance with company policies and best practices. Manage user accounts, profiles, data backups, and equipment for both active and departing employees. Liaise with subject matter experts, third-party suppliers, and vendors to resolve technical issues and improve service delivery. Support IT asset management activities, including procurement, inventory control, software licensing, and hardware lifecycle management. Ensure compliance with internal controls, policies, procedures, and regulatory requirements, including IT General Controls (ITGCs), Managed Access, Managed Operations, Change Management, SOX compliance, data backup and recovery, data classification, and IT Asset Management (ITAM).
04/09/2026
Contractor
Our client, a leading organisation operating within a global multinational group and recognised as part of a Fortune 500 business, is seeking a highly motivated and enthusiastic IT Service Desk Analyst to join their progressive, values-driven IT Infrastructure team based at their Billingham site. Our client is committed to delivering sustainable solutions that support both industry and communities. Their employees are focused on safe and reliable operations, environmental responsibility, and continuous improvement. Joining the organisation means becoming part of a collaborative team where diverse skills, experiences, and perspectives are valued. Employees are encouraged to develop their careers, take on new challenges, and contribute to meaningful work in a supportive and inclusive environment. In this role, you will provide first-line, and where appropriate second-line, technical support across the business. You will be responsible for logging, tracking, and resolving IT incidents and service requests received via telephone, email, and self-service portals. You will also play an active role in on-call support and out-of-hours cover to help ensure safe, reliable, and effective business operations. A competitive salary and benefits package is on offer, including a performance-related bonus scheme, enhanced pension contributions, life assurance, employee assistance programme, and healthcare benefits. Our client is committed to creating an inclusive workplace where everyone is treated with respect and fairness. They actively promote diversity and equal opportunities, recognising the value that different perspectives bring to their organisation. Key Responsibilities Provide technical support to users across all aspects of hardware, software, networking, and peripheral equipment issues. Develop a strong understanding of business systems and applications, applying troubleshooting and analytical skills to resolve technical problems. Create and maintain technical documentation, user guides, and troubleshooting resources. Manage incidents and service requests through established IT service management processes, ensuring accurate logging, tracking, escalation, resolution, and closure. Deliver first-line service desk support and end-user assistance across Microsoft technologies and business applications. Maintain, configure, and administer computer networks and associated IT infrastructure, including hardware, operating systems, applications, backup solutions, and disaster recovery processes. Complete project-related tasks assigned by the IT Team Leader efficiently and within agreed timescales. Monitor, diagnose, and resolve hardware, software, network, and system issues, escalating where necessary and replacing defective components when required. Support operational technology and manufacturing-related systems where applicable. Maintain cybersecurity and data protection standards, ensuring compliance with company policies and best practices. Manage user accounts, profiles, data backups, and equipment for both active and departing employees. Liaise with subject matter experts, third-party suppliers, and vendors to resolve technical issues and improve service delivery. Support IT asset management activities, including procurement, inventory control, software licensing, and hardware lifecycle management. Ensure compliance with internal controls, policies, procedures, and regulatory requirements, including IT General Controls (ITGCs), Managed Access, Managed Operations, Change Management, SOX compliance, data backup and recovery, data classification, and IT Asset Management (ITAM).
An exciting opportunity has arisen to join our growing ICT Department as a member of the InfoSec team, working in a dynamic and fast-paced environment with new challenges every day, based in our Manchester Head Office. Having rationalised our infrastructure and established a modern, cloud-first security stack, it is an exciting time to join the business as we mature our detection, response, and automation capabilities across a global estate. You will work collaboratively with the business and the wider IT team - Infrastructure, Network, Development, DevOps, and Service Desk - to provide security and governance for existing and new services. The purpose of this role is to deliver the day-to-day security operations of the InfoSec Team and to act as a first point of escalation and support for our Junior and Graduate analysts. Reporting to the Associate Director - Cyber Security, you will work closely with other team members, IT colleagues, and the wider business to ensure a consistent approach to information and cyber security across all areas of IT. You will analyse security events, investigate alerts, identify issues, and recommend and implement solutions, while keeping up to date with current threats, technologies, and techniques. You will be responsible for daily security operations, ensuring risks are identified and resolved in a timely manner. In practice, this means managing tickets and requests through Halo ITSM and working daily with Palo Alto Cortex XSIAM and XSOAR, Cortex XDR, Microsoft Purview, Mimecast, Abnormal, Nessus, and Microsoft 365. You will participate in security investigations and incident response, responding to events involving malware, data loss, phishing, or network intrusion, and supporting our data protection and vulnerability management activity. You will work both independently and collaboratively, sharing knowledge openly and supporting your colleagues across all regions. You will follow security best practice, apply the principles of layered security, and serve as a trusted resource to the wider business on all matters of information and cyber security. This is a customer-facing role, so you will be a strong communicator, able to explain complex concepts clearly to both technical and non-technical audiences, with your input helping to shape and improve our day-to-day monitoring, detection, and response. You will be self-motivated, bringing the knowledge and experience gained in previous roles, genuinely passionate about data and cyber security, and committed to continued learning and professional development. Key Objectives and Responsibilities Daily Operations & Incident Handling Manage day-to-day security tickets, requests, and alerts through Halo ITSM, meeting SLAs and making full use of existing automation. Monitor, triage, and investigate alerts within Palo Alto Cortex XSIAM, responding and escalating as required. Respond to security incidents involving malware, data loss, phishing, or network intrusion, following established playbooks and incident response processes. Manage email security operations across Mimecast and Abnormal, including releases, journal pulls, and reported-phishing investigations. Monitor threat feeds and threat intelligence, applying relevant findings to the environment. Maintain and tune detections, correlation rules, and Cortex XSOAR playbooks to reduce noise and improve response times. Identify opportunities for automation and continual improvement across monitoring and response workflows. Contribute to the development and upkeep of SOC processes, runbooks, and documentation. Run and interpret vulnerability scans using Nessus, tracking remediation through to closure with the relevant teams. Support endpoint security and patch compliance across the Windows and macOS estates, working with Intune, Jamf, Alectrona, and Cortex XDR. Data Protection & Compliance Support and monitor the company's Data Loss Prevention controls within Microsoft Purview, and data classification through Azure Information Protection labelling. Help maintain the evidence and controls that support the company's accreditations, including ISO/IEC 27001, 27017, and 27018, Cyber Essentials Plus, and SOC 2. Learn and apply the principles of risk and information governance within the context of cyber security. Experience and Technical Requirements Two or more years' experience in a cyber security, SOC, or information security analyst role. Experience working within an ISO/IEC 27001 (or equivalent) accredited environment. Familiarity with ITIL service management processes, particularly Incident, Request, Change, and Problem management. Understanding of GDPR, data protection, and information governance. Hands-on experience with a SIEM platform (Cortex XSIAM, Microsoft Sentinel, Splunk, or equivalent). Experience with, or a strong aptitude to learn, SOAR and automation tooling (Cortex XSOAR). Experience with Endpoint Detection and Response (Cortex XDR or an equivalent EDR/XDR platform). Experience with email security platforms (O365, Mimecast, Abnormal, or equivalent). Understanding of Data Loss Prevention and data classification (Microsoft Purview and Azure labelling, or equivalent). Experience with vulnerability scanning and management (Nessus or equivalent). Working knowledge of endpoint management across Windows and macOS (Intune, Jamf). Strong knowledge of cloud environments, including Microsoft Azure, AWS, and Microsoft 365. Understanding of layered security, threat hunting, and incident response. Qualifications A degree in a computer-related subject, or equivalent experience in cyber security. Holding, or actively working towards, relevant industry certifications (e.g. SANS GCIH, EC-Council CEH, ISC2 SSCP, CompTIA CySA+, Blue Team Level 1, Microsoft SC-200, or equivalent), with a genuine commitment to continued professional development. Benefits 25 Days Holiday + Bank Holidays Day off for your birthday Health Shield Cash Plan Cycle to Work Scheme Train Season Ticket Scheme Profit Share Scheme Contributory company pension scheme Access to the Employee Assistance Programme (EAP) 51903MS INDMANS The Portfolio Group are acting on behalf of our client in recruiting for this position.
03/09/2026
Full time
An exciting opportunity has arisen to join our growing ICT Department as a member of the InfoSec team, working in a dynamic and fast-paced environment with new challenges every day, based in our Manchester Head Office. Having rationalised our infrastructure and established a modern, cloud-first security stack, it is an exciting time to join the business as we mature our detection, response, and automation capabilities across a global estate. You will work collaboratively with the business and the wider IT team - Infrastructure, Network, Development, DevOps, and Service Desk - to provide security and governance for existing and new services. The purpose of this role is to deliver the day-to-day security operations of the InfoSec Team and to act as a first point of escalation and support for our Junior and Graduate analysts. Reporting to the Associate Director - Cyber Security, you will work closely with other team members, IT colleagues, and the wider business to ensure a consistent approach to information and cyber security across all areas of IT. You will analyse security events, investigate alerts, identify issues, and recommend and implement solutions, while keeping up to date with current threats, technologies, and techniques. You will be responsible for daily security operations, ensuring risks are identified and resolved in a timely manner. In practice, this means managing tickets and requests through Halo ITSM and working daily with Palo Alto Cortex XSIAM and XSOAR, Cortex XDR, Microsoft Purview, Mimecast, Abnormal, Nessus, and Microsoft 365. You will participate in security investigations and incident response, responding to events involving malware, data loss, phishing, or network intrusion, and supporting our data protection and vulnerability management activity. You will work both independently and collaboratively, sharing knowledge openly and supporting your colleagues across all regions. You will follow security best practice, apply the principles of layered security, and serve as a trusted resource to the wider business on all matters of information and cyber security. This is a customer-facing role, so you will be a strong communicator, able to explain complex concepts clearly to both technical and non-technical audiences, with your input helping to shape and improve our day-to-day monitoring, detection, and response. You will be self-motivated, bringing the knowledge and experience gained in previous roles, genuinely passionate about data and cyber security, and committed to continued learning and professional development. Key Objectives and Responsibilities Daily Operations & Incident Handling Manage day-to-day security tickets, requests, and alerts through Halo ITSM, meeting SLAs and making full use of existing automation. Monitor, triage, and investigate alerts within Palo Alto Cortex XSIAM, responding and escalating as required. Respond to security incidents involving malware, data loss, phishing, or network intrusion, following established playbooks and incident response processes. Manage email security operations across Mimecast and Abnormal, including releases, journal pulls, and reported-phishing investigations. Monitor threat feeds and threat intelligence, applying relevant findings to the environment. Maintain and tune detections, correlation rules, and Cortex XSOAR playbooks to reduce noise and improve response times. Identify opportunities for automation and continual improvement across monitoring and response workflows. Contribute to the development and upkeep of SOC processes, runbooks, and documentation. Run and interpret vulnerability scans using Nessus, tracking remediation through to closure with the relevant teams. Support endpoint security and patch compliance across the Windows and macOS estates, working with Intune, Jamf, Alectrona, and Cortex XDR. Data Protection & Compliance Support and monitor the company's Data Loss Prevention controls within Microsoft Purview, and data classification through Azure Information Protection labelling. Help maintain the evidence and controls that support the company's accreditations, including ISO/IEC 27001, 27017, and 27018, Cyber Essentials Plus, and SOC 2. Learn and apply the principles of risk and information governance within the context of cyber security. Experience and Technical Requirements Two or more years' experience in a cyber security, SOC, or information security analyst role. Experience working within an ISO/IEC 27001 (or equivalent) accredited environment. Familiarity with ITIL service management processes, particularly Incident, Request, Change, and Problem management. Understanding of GDPR, data protection, and information governance. Hands-on experience with a SIEM platform (Cortex XSIAM, Microsoft Sentinel, Splunk, or equivalent). Experience with, or a strong aptitude to learn, SOAR and automation tooling (Cortex XSOAR). Experience with Endpoint Detection and Response (Cortex XDR or an equivalent EDR/XDR platform). Experience with email security platforms (O365, Mimecast, Abnormal, or equivalent). Understanding of Data Loss Prevention and data classification (Microsoft Purview and Azure labelling, or equivalent). Experience with vulnerability scanning and management (Nessus or equivalent). Working knowledge of endpoint management across Windows and macOS (Intune, Jamf). Strong knowledge of cloud environments, including Microsoft Azure, AWS, and Microsoft 365. Understanding of layered security, threat hunting, and incident response. Qualifications A degree in a computer-related subject, or equivalent experience in cyber security. Holding, or actively working towards, relevant industry certifications (e.g. SANS GCIH, EC-Council CEH, ISC2 SSCP, CompTIA CySA+, Blue Team Level 1, Microsoft SC-200, or equivalent), with a genuine commitment to continued professional development. Benefits 25 Days Holiday + Bank Holidays Day off for your birthday Health Shield Cash Plan Cycle to Work Scheme Train Season Ticket Scheme Profit Share Scheme Contributory company pension scheme Access to the Employee Assistance Programme (EAP) 51903MS INDMANS The Portfolio Group are acting on behalf of our client in recruiting for this position.