it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

23 jobs found

Email me jobs like this
Refine Search
Current Search
security engineering consultant siem
Senior Cyber Security Engineer (CyberArk & PAM)
SYSGROUP PLC Edinburgh, Midlothian
Senior Cyber Security Engineer (CyberArk & PAM) Edinburgh, United Kingdom Posted on 16/07/2026 SysGroup ishiring a Senior Cyber Security Engineer specialising in privileged accessmanagement, with CyberArk as the core platform. This is the senior tooling andidentity specialist role in the Cyber Security team under our 2026 operatingmodel: you own the design, deployment and health of the security tooling estateacross our managed clients, with PAM as your deepest expertise. BeyondCyberArk, the role carries breadth across the modern security stack: hands-onexperience with Zscaler (ZIA/ZPA) and working capability across EDR, SIEM, vulnerability management and the wider cyber product set we operate forclients. You will reportto the Cyber Operations Lead and work closely with the SOC engineers, thePre-sales Security Consultant and the Platform & Infrastructure teams. CyberArk & privileged access management Own CyberArk design, deployment and operation across managed clients: vaulting, session management, secretsmanagement and privileged threat analytics. Design PAM onboarding programmes for new clients: discovery, scoping, policy design and rollout. Integrate PAM with the wideridentity stack: Entra ID, conditional access, MFA and just-in-time accesspatterns. Set privileged access standards and evidence them for client audits (ISO 27001, Cyber Essentials Plus). Security tooling & engineering Deploy, configure and maintain the security tooling estate: EDR, SIEM integrations, vulnerability scanning and email security. Support Zscaler (ZIA/ZPA)deployment and policy work alongside the zero trust leads. Own tooling health: versioncurrency, coverage gaps, tuning quality and integration reliability. Automate deployment and operational tasks with scripts and APIs; contribute to the shared automation library. Act as senior escalation foridentity and tooling incidents; support major incident response. Document designs, runbooks and standards to a level the wider team can operate from. Contribute tooling and PAMexpertise to service reviews and solution scoping when needed. Adopt AI-assisted workflows for diagnostics, configuration review and documentation. Experience 5+ years in security engineering with 2+ years of hands on CyberArk design and administration (PAM Self Hosted or Privilege Cloud). Experience deploying or operating Zscaler (ZIA/ZPA) and at least two of: EDR platforms, SIEM, vulnerability management, email security. Strong scripting capability (PowerShell or Python) applied to security tooling automation and integration. MSP/MSSP or multi client environment experience preferred; client audit exposure an advantage. Certifications Essential (or equivalent hands on experience): CyberArk Defender certification; CyberArk Sentry strongly preferred. Desirable: CyberArk Guardian, Zscaler professional level certification (ZIA/ZPA), Microsoft SC 300, SC 200, AZ 500, or EDR vendor certifications. Why Join Us? Joining Sysgroup means becoming part of adynamic and innovative team that is dedicated to excellence. We offer a supportive, and collaborative work environment, where your ideas and contributions are valued. Here are some of the benefits of working with us: Competitive Compensation We offer a competitive salary package, including performance-based incentives, to reward your hard work and achievements. Private Healthcare Life insurance Pension We believe in investing in our employees' professional development. You will have your own individual development learning paths with access to various training material and ongoing career advancement opportunities.
22/07/2026
Full time
Senior Cyber Security Engineer (CyberArk & PAM) Edinburgh, United Kingdom Posted on 16/07/2026 SysGroup ishiring a Senior Cyber Security Engineer specialising in privileged accessmanagement, with CyberArk as the core platform. This is the senior tooling andidentity specialist role in the Cyber Security team under our 2026 operatingmodel: you own the design, deployment and health of the security tooling estateacross our managed clients, with PAM as your deepest expertise. BeyondCyberArk, the role carries breadth across the modern security stack: hands-onexperience with Zscaler (ZIA/ZPA) and working capability across EDR, SIEM, vulnerability management and the wider cyber product set we operate forclients. You will reportto the Cyber Operations Lead and work closely with the SOC engineers, thePre-sales Security Consultant and the Platform & Infrastructure teams. CyberArk & privileged access management Own CyberArk design, deployment and operation across managed clients: vaulting, session management, secretsmanagement and privileged threat analytics. Design PAM onboarding programmes for new clients: discovery, scoping, policy design and rollout. Integrate PAM with the wideridentity stack: Entra ID, conditional access, MFA and just-in-time accesspatterns. Set privileged access standards and evidence them for client audits (ISO 27001, Cyber Essentials Plus). Security tooling & engineering Deploy, configure and maintain the security tooling estate: EDR, SIEM integrations, vulnerability scanning and email security. Support Zscaler (ZIA/ZPA)deployment and policy work alongside the zero trust leads. Own tooling health: versioncurrency, coverage gaps, tuning quality and integration reliability. Automate deployment and operational tasks with scripts and APIs; contribute to the shared automation library. Act as senior escalation foridentity and tooling incidents; support major incident response. Document designs, runbooks and standards to a level the wider team can operate from. Contribute tooling and PAMexpertise to service reviews and solution scoping when needed. Adopt AI-assisted workflows for diagnostics, configuration review and documentation. Experience 5+ years in security engineering with 2+ years of hands on CyberArk design and administration (PAM Self Hosted or Privilege Cloud). Experience deploying or operating Zscaler (ZIA/ZPA) and at least two of: EDR platforms, SIEM, vulnerability management, email security. Strong scripting capability (PowerShell or Python) applied to security tooling automation and integration. MSP/MSSP or multi client environment experience preferred; client audit exposure an advantage. Certifications Essential (or equivalent hands on experience): CyberArk Defender certification; CyberArk Sentry strongly preferred. Desirable: CyberArk Guardian, Zscaler professional level certification (ZIA/ZPA), Microsoft SC 300, SC 200, AZ 500, or EDR vendor certifications. Why Join Us? Joining Sysgroup means becoming part of adynamic and innovative team that is dedicated to excellence. We offer a supportive, and collaborative work environment, where your ideas and contributions are valued. Here are some of the benefits of working with us: Competitive Compensation We offer a competitive salary package, including performance-based incentives, to reward your hard work and achievements. Private Healthcare Life insurance Pension We believe in investing in our employees' professional development. You will have your own individual development learning paths with access to various training material and ongoing career advancement opportunities.
Health Hero
Senior Cloud Security Engineer
Health Hero
Senior Cloud Security Engineer (London, Bracknell or Bristol) We are HealthHero, Europe's largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe - giving you the chance to shape security at the heart of a fast-growing, AI-driven business. We are recruiting an exciting Senior Cloud Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent - based in either our London or Bristol office two days per week. About the role This role will form a fundamental part of a growing Platform Security function, where the team covers application security, cloud security, security operations, culture and risk management. As a tech-centric organisation the Information Security team will play a critical part in embedding a security-first mindset into application development and continuous application monitoring. This role will co-own the cloud security posture and tooling across HealthHero's AWS and Azure estates and have the opportunity to tackle cloud security with an international scope. The role will be supported by a multidisciplinary force of Infrastructure, Data Governance and Engineering team leads with a security focus as part of their remit. The role has a focus on infrastructure and cloud networking when it comes to security posture. As an experienced Cloud Security Engineer, your working day will include but not be limited to: DevSecOps & SDLC Champion integration of security testing into CI/CD pipelines across all development teams and usage of automated security gates: SAST, DAST, dependency scanning, secrets detection Enable self-serve security tooling for development teams Ability to set up development environment Cloud Security Own cloud security posture management using Wiz (or similar CSPM) Define and enforce cloud security baselines, guardrails, and policies in AWS Implement and maintain IaC security scanning for Terraform Manage IAM policies, network segmentation, and secrets management Configure and tune SIEM (or similar) for cloud-focused detection Establish logging, monitoring, and alerting requirements based on threat modelling Investigate and respond to cloud security events Risk & Compliance Identify, articulate, and escalate security risks to senior leadership with mitigation plans Track and remediate vulnerabilities across infrastructure Manage customer initiatives related to due diligence when required to Support and develop annual programme of Penetration Testing and associated remediations Stakeholder Engagement Partner with internal and stakeholder management to support any requirements from the security function - particularly governance and accreditation requirements across different countries Provide expertise on emerging threats and vulnerabilities Support response to customer/client due diligence requests with timely and accurate information regarding vulnerability exposure Key Skills and Experience Essential Proven experience in application security, DevSecOps, or cloud security Strong understanding of cloud networking Experience securing cloud environments (AWS, Azure) Ability to read and write IAC (Terraform) code, comfortable with IAC lifecycles Familiarity with container security and Kubernetes Understanding of secure coding, penetration testing techniques, SIEM, and vulnerability management Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security and risk analysis Understanding of managing Secure Development Lifecycle and Vulnerability Management. Understanding and practical experience of ISO27001:2022 controls and audit processes Desirable AWS Security Specialty or similar certification Experience in regulated environments (healthcare, financial services) Familiarity with NHS DSPT Technical knowledge of GDPR and data protection requirements Hands-on with CI/CD security tooling and pipeline integration Interest in learning other countries health and security regulations (France / UK / IR / DE) About us We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. HealthHero is Europe's largest digital health provider , delivering 4 million consultations per year. But we're just getting started. We've built a seamless digital clinic that brings body and mind together - from GP appointments and mental health support to long-term condition management. By sitting behind the world's leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it. We are a high-growth, capital-backed business with a sophisticated scale strategy. Our team is a unique blend of those with strong digital experience, management consultants, creatives and industry-leading clinical experts. We aren't just digitising appointments; we're building the next generation of healthcare. We're creating an AI-powered, always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts. Join us, and help build a next generation health system the world is waiting for. What we offer A full induction training programme, which will be undertaken via Microsoft Teams. An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic. 25 days leave. Bank Holidays and your birthday off as leave. Regular 1-2-1s with your line Manager. 24/7 on-call staff support. Auto-enrolment pension scheme. Health Scheme and access to our Employee Assistance Programme. Life Insurance Scheme. Hybrid: London, Bracknell or Bristol (There is a requirement to work in the office for a minimum of two days per week) Additional information Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer.
20/07/2026
Contractor
Senior Cloud Security Engineer (London, Bracknell or Bristol) We are HealthHero, Europe's largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe - giving you the chance to shape security at the heart of a fast-growing, AI-driven business. We are recruiting an exciting Senior Cloud Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent - based in either our London or Bristol office two days per week. About the role This role will form a fundamental part of a growing Platform Security function, where the team covers application security, cloud security, security operations, culture and risk management. As a tech-centric organisation the Information Security team will play a critical part in embedding a security-first mindset into application development and continuous application monitoring. This role will co-own the cloud security posture and tooling across HealthHero's AWS and Azure estates and have the opportunity to tackle cloud security with an international scope. The role will be supported by a multidisciplinary force of Infrastructure, Data Governance and Engineering team leads with a security focus as part of their remit. The role has a focus on infrastructure and cloud networking when it comes to security posture. As an experienced Cloud Security Engineer, your working day will include but not be limited to: DevSecOps & SDLC Champion integration of security testing into CI/CD pipelines across all development teams and usage of automated security gates: SAST, DAST, dependency scanning, secrets detection Enable self-serve security tooling for development teams Ability to set up development environment Cloud Security Own cloud security posture management using Wiz (or similar CSPM) Define and enforce cloud security baselines, guardrails, and policies in AWS Implement and maintain IaC security scanning for Terraform Manage IAM policies, network segmentation, and secrets management Configure and tune SIEM (or similar) for cloud-focused detection Establish logging, monitoring, and alerting requirements based on threat modelling Investigate and respond to cloud security events Risk & Compliance Identify, articulate, and escalate security risks to senior leadership with mitigation plans Track and remediate vulnerabilities across infrastructure Manage customer initiatives related to due diligence when required to Support and develop annual programme of Penetration Testing and associated remediations Stakeholder Engagement Partner with internal and stakeholder management to support any requirements from the security function - particularly governance and accreditation requirements across different countries Provide expertise on emerging threats and vulnerabilities Support response to customer/client due diligence requests with timely and accurate information regarding vulnerability exposure Key Skills and Experience Essential Proven experience in application security, DevSecOps, or cloud security Strong understanding of cloud networking Experience securing cloud environments (AWS, Azure) Ability to read and write IAC (Terraform) code, comfortable with IAC lifecycles Familiarity with container security and Kubernetes Understanding of secure coding, penetration testing techniques, SIEM, and vulnerability management Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security and risk analysis Understanding of managing Secure Development Lifecycle and Vulnerability Management. Understanding and practical experience of ISO27001:2022 controls and audit processes Desirable AWS Security Specialty or similar certification Experience in regulated environments (healthcare, financial services) Familiarity with NHS DSPT Technical knowledge of GDPR and data protection requirements Hands-on with CI/CD security tooling and pipeline integration Interest in learning other countries health and security regulations (France / UK / IR / DE) About us We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. HealthHero is Europe's largest digital health provider , delivering 4 million consultations per year. But we're just getting started. We've built a seamless digital clinic that brings body and mind together - from GP appointments and mental health support to long-term condition management. By sitting behind the world's leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it. We are a high-growth, capital-backed business with a sophisticated scale strategy. Our team is a unique blend of those with strong digital experience, management consultants, creatives and industry-leading clinical experts. We aren't just digitising appointments; we're building the next generation of healthcare. We're creating an AI-powered, always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts. Join us, and help build a next generation health system the world is waiting for. What we offer A full induction training programme, which will be undertaken via Microsoft Teams. An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic. 25 days leave. Bank Holidays and your birthday off as leave. Regular 1-2-1s with your line Manager. 24/7 on-call staff support. Auto-enrolment pension scheme. Health Scheme and access to our Employee Assistance Programme. Life Insurance Scheme. Hybrid: London, Bracknell or Bristol (There is a requirement to work in the office for a minimum of two days per week) Additional information Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer.
Information Security Senior Consultant
Westpac Group
Role Title: Information Security Senior Consultant - Detection and Response (Europe & Americas) About Westpac:Westpac is one of the world's oldest banks and a leading financial services organisation with a strong presence across Australia, New Zealand and key international markets. We support individuals, businesses and institutions through a broad range of banking and financial solutions. Our culture is values led and performance driven. At Westpac, success is measured by both what we deliver and how we deliver it. We focus on always delivering safely, doing the right thing, executing with excellence and delivering for customers. These outcomes are underpinned by our behaviours of Care, Listen and Act, which guide how we work together and how we build trust with our customers and communities. About the Team: This role is a core part of Westpac's global 24/7 cybersecurity monitoring and incident response capability - the bank's first line of cyber defence. How will I help? You will be responsible for analysing and responding to potential cyber threats and attacks against our systems, staff and customers. You will also have the opportunity to design, validate, implement and continually improve detection content, translating threat intelligence and attacker behaviours into actionable detections aligned to Westpac's environment and cyber risk priorities. Key Responsibilities Investigate and prioritise security alerts and events, supporting in-depth analysis of logs and threat information from a variety of systems and security tools, including endpoint and network devices. Ensure threats and alerts are prioritised based on risk, investigated and mitigated effectively and efficiently, based on available context and data. Apply critical thinking and analytical mindset to guide and influence decisions where documented process is unclear or incomplete, including exceptions escalated by junior team members. Maintain and continually uplift SOC capability by recommending, leading and implementing operational and process improvements and contributing to the team knowledge base. Collaborate with local and global detection and response teams to optimise detections, integrate logic with SOAR playbooks and improve consistency, coverage and control effectiveness. Support proactive threat hunting to identify control gaps, emerging threats and opportunities to improve detection coverage. What's in it for me? You'll be joining a highly supportive and collaborative team with international coverage during a period of growth across Westpac's international regions. You will work closely with experienced cyber security professionals and senior stakeholders across our global offices, supporting incident response for real world cyber incidents and operational environments. We're obsessed with becoming our customers' banking partner for life and we're looking for people who are passionate about helping us achieve that goal. In return, we're committed to making Westpac the best place to work in the country. Here are just a few of the ways we're already doing that: Flexible work arrangements to help you achieve a greater work/life balance, and a variety of leave options including Culture, Lifestyle and Wellbeing leave. Tailored learning and development opportunities to help your grow your career within the bank. What do I need? 5+ years of relevant experience in a Cyber Security detection and response role Hands on detection engineering experience and/or related qualifications highly regarded Highly developed written and verbal communication, critical thinking, and analytical skills. Proficiency with SOC tools such as SIEM and SOAR, ideally in a corporate technology environment. A strong understanding of common cyber threats and attacks against financial services organisations. Proven ability to translate incident learnings into practical improvements in detection, response and operational resilience. Strong technical background, including knowledge of network technologies and protocols. Ability to understand business context, identify issues, and analyse and correlate information. Good understanding of concepts such as Cyber Kill Chain and MITRE ATT&CK framework. A self-leader, capable of working independently on complex tasks with minimal supervision. Start Here. Just click on theAPPLYbutton. Job Info Job Identification 70173 Job Category Information & Cyber Security
19/07/2026
Full time
Role Title: Information Security Senior Consultant - Detection and Response (Europe & Americas) About Westpac:Westpac is one of the world's oldest banks and a leading financial services organisation with a strong presence across Australia, New Zealand and key international markets. We support individuals, businesses and institutions through a broad range of banking and financial solutions. Our culture is values led and performance driven. At Westpac, success is measured by both what we deliver and how we deliver it. We focus on always delivering safely, doing the right thing, executing with excellence and delivering for customers. These outcomes are underpinned by our behaviours of Care, Listen and Act, which guide how we work together and how we build trust with our customers and communities. About the Team: This role is a core part of Westpac's global 24/7 cybersecurity monitoring and incident response capability - the bank's first line of cyber defence. How will I help? You will be responsible for analysing and responding to potential cyber threats and attacks against our systems, staff and customers. You will also have the opportunity to design, validate, implement and continually improve detection content, translating threat intelligence and attacker behaviours into actionable detections aligned to Westpac's environment and cyber risk priorities. Key Responsibilities Investigate and prioritise security alerts and events, supporting in-depth analysis of logs and threat information from a variety of systems and security tools, including endpoint and network devices. Ensure threats and alerts are prioritised based on risk, investigated and mitigated effectively and efficiently, based on available context and data. Apply critical thinking and analytical mindset to guide and influence decisions where documented process is unclear or incomplete, including exceptions escalated by junior team members. Maintain and continually uplift SOC capability by recommending, leading and implementing operational and process improvements and contributing to the team knowledge base. Collaborate with local and global detection and response teams to optimise detections, integrate logic with SOAR playbooks and improve consistency, coverage and control effectiveness. Support proactive threat hunting to identify control gaps, emerging threats and opportunities to improve detection coverage. What's in it for me? You'll be joining a highly supportive and collaborative team with international coverage during a period of growth across Westpac's international regions. You will work closely with experienced cyber security professionals and senior stakeholders across our global offices, supporting incident response for real world cyber incidents and operational environments. We're obsessed with becoming our customers' banking partner for life and we're looking for people who are passionate about helping us achieve that goal. In return, we're committed to making Westpac the best place to work in the country. Here are just a few of the ways we're already doing that: Flexible work arrangements to help you achieve a greater work/life balance, and a variety of leave options including Culture, Lifestyle and Wellbeing leave. Tailored learning and development opportunities to help your grow your career within the bank. What do I need? 5+ years of relevant experience in a Cyber Security detection and response role Hands on detection engineering experience and/or related qualifications highly regarded Highly developed written and verbal communication, critical thinking, and analytical skills. Proficiency with SOC tools such as SIEM and SOAR, ideally in a corporate technology environment. A strong understanding of common cyber threats and attacks against financial services organisations. Proven ability to translate incident learnings into practical improvements in detection, response and operational resilience. Strong technical background, including knowledge of network technologies and protocols. Ability to understand business context, identify issues, and analyse and correlate information. Good understanding of concepts such as Cyber Kill Chain and MITRE ATT&CK framework. A self-leader, capable of working independently on complex tasks with minimal supervision. Start Here. Just click on theAPPLYbutton. Job Info Job Identification 70173 Job Category Information & Cyber Security
Customer Engineering - EMEA
TENEX.AI
ENEX.AI is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in cybersecurity, automation and AI-driven solutions. Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the AI-Native MDR landscape. We're a fast growing startup backed by industry experts and top tier investors led by Crosspoint Capital Partners and also backed by Shield Capital, DTCP (formerly Deutsche Telekom Capital Partners), Deepwork Capital, and the Florida Opportunity Fund. Seed round led by Andreessen Horowitz (a16z). As an early employee, you'll play a meaningful role in defining and building our culture. Get in on the ground floor. We're a small but well-funded team that just raised a substantial round - joining now comes with limited risk and unlimited upside We are seeking a dynamic Customer Engineer (CE) to join our team, reporting to the VP of Customer Engineering. This hybrid role combines the technical expertise of a Pre-Sales Engineer with hands on contributions to Customer Success and Security Operations. As a CE, you will act as a trusted advisor, showcasing TENEX.AI's AI driven security solutions during the pre sales and evaluation processes, ensuring seamless handover to customer onboarding, and supporting rapid onboarding of operational initiatives to enhance security outcomes. This field based role requires up to 50% travel to client sites, with remote work flexibility. The ideal candidate is passionate about cybersecurity, thrives in a fast paced environment, and excels at translating complex technical concepts into compelling business value. Cultivated culture is one of the most important things at TENEX.AI-explore our culture deck at culture.tenex.ai to witness how we embody it, prioritizing the irreplaceable collaboration and community of in person work. Key Responsibilities Sales Engineering Excellence: Partner with the sales team to deliver technical expertise during pre sales. Conduct product demonstrations, proof of concepts (POCs), and security assessments tailored to client needs. Understand and address security concerns, compliance requirements (e.g., GDPR, HIPAA, SOC 2), and risk mitigation strategies to drive deal closures. Meet and exceed individual and team sales targets, consistently achieving and surpassing assigned quotas. Customer Success & Operational Support: Collaborate with Customer Success managers to streamline onboarding of new clients. Review client security architectures and recommend best practices for AI driven security deployments. Support incident response planning and contribute to developing operational tools, processes, and documentation to scale security operations. Thought Leadership: Represent TENEX at industry events, webinars, and conferences as a cybersecurity expert. Create high impact content (e.g., whitepapers, case studies, blog posts) to educate the market on AI driven security trends. Provide actionable customer feedback to influence product roadmap enhancements. Cross Functional Collaboration: Work with all TENEX teams to align on both customer and internal business needs. Share field insights to refine GTM strategies and operational workflows. Work closely with the marketing and technical teams to ensure cohesive messaging. Cloud Security Expertise: Develop and maintain deep knowledge of Google Cloud & Microsoft Azure solutions, aligning with TENEX's strategic partnerships to deliver integrated MDR offerings. Qualifications Experience: 5+ years in cybersecurity, with 5+ years in a customer facing role (e.g., Sales Engineer, Solutions Architect, Consultant). Technical Skills: Strong understanding of cybersecurity principles Familiarity with security operations platforms (e.g., SIEM, SOAR, Threat Intelligence, UEBA). Knowledge of cloud security (e.g., Google Cloud, AWS, Azure) is a plus. Google SecOps or Microsoft Sentinel a strong plus. Soft Skills: Exceptional communication and presentation skills, with the ability to simplify complex security topics for non technical audiences. Strong problem solving skills, customer empathy, and experience engaging executive stakeholders (e.g., CISOs, CTOs). Other: Willingness to travel (up to 50%); valid driver's license required. Must pass a background check and maintain up to date security clearances if applicable. Why Join Us? Opportunity to work with cutting edge AI driven cybersecurity technologies and Google SecOps solutions. Collaborate with a talented and innovative team focused on continuously improving security operations. Competitive salary and benefits package. A culture of growth and development, with opportunities to expand your knowledge in AI, cybersecurity, and emerging technologies.
17/07/2026
Full time
ENEX.AI is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in cybersecurity, automation and AI-driven solutions. Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the AI-Native MDR landscape. We're a fast growing startup backed by industry experts and top tier investors led by Crosspoint Capital Partners and also backed by Shield Capital, DTCP (formerly Deutsche Telekom Capital Partners), Deepwork Capital, and the Florida Opportunity Fund. Seed round led by Andreessen Horowitz (a16z). As an early employee, you'll play a meaningful role in defining and building our culture. Get in on the ground floor. We're a small but well-funded team that just raised a substantial round - joining now comes with limited risk and unlimited upside We are seeking a dynamic Customer Engineer (CE) to join our team, reporting to the VP of Customer Engineering. This hybrid role combines the technical expertise of a Pre-Sales Engineer with hands on contributions to Customer Success and Security Operations. As a CE, you will act as a trusted advisor, showcasing TENEX.AI's AI driven security solutions during the pre sales and evaluation processes, ensuring seamless handover to customer onboarding, and supporting rapid onboarding of operational initiatives to enhance security outcomes. This field based role requires up to 50% travel to client sites, with remote work flexibility. The ideal candidate is passionate about cybersecurity, thrives in a fast paced environment, and excels at translating complex technical concepts into compelling business value. Cultivated culture is one of the most important things at TENEX.AI-explore our culture deck at culture.tenex.ai to witness how we embody it, prioritizing the irreplaceable collaboration and community of in person work. Key Responsibilities Sales Engineering Excellence: Partner with the sales team to deliver technical expertise during pre sales. Conduct product demonstrations, proof of concepts (POCs), and security assessments tailored to client needs. Understand and address security concerns, compliance requirements (e.g., GDPR, HIPAA, SOC 2), and risk mitigation strategies to drive deal closures. Meet and exceed individual and team sales targets, consistently achieving and surpassing assigned quotas. Customer Success & Operational Support: Collaborate with Customer Success managers to streamline onboarding of new clients. Review client security architectures and recommend best practices for AI driven security deployments. Support incident response planning and contribute to developing operational tools, processes, and documentation to scale security operations. Thought Leadership: Represent TENEX at industry events, webinars, and conferences as a cybersecurity expert. Create high impact content (e.g., whitepapers, case studies, blog posts) to educate the market on AI driven security trends. Provide actionable customer feedback to influence product roadmap enhancements. Cross Functional Collaboration: Work with all TENEX teams to align on both customer and internal business needs. Share field insights to refine GTM strategies and operational workflows. Work closely with the marketing and technical teams to ensure cohesive messaging. Cloud Security Expertise: Develop and maintain deep knowledge of Google Cloud & Microsoft Azure solutions, aligning with TENEX's strategic partnerships to deliver integrated MDR offerings. Qualifications Experience: 5+ years in cybersecurity, with 5+ years in a customer facing role (e.g., Sales Engineer, Solutions Architect, Consultant). Technical Skills: Strong understanding of cybersecurity principles Familiarity with security operations platforms (e.g., SIEM, SOAR, Threat Intelligence, UEBA). Knowledge of cloud security (e.g., Google Cloud, AWS, Azure) is a plus. Google SecOps or Microsoft Sentinel a strong plus. Soft Skills: Exceptional communication and presentation skills, with the ability to simplify complex security topics for non technical audiences. Strong problem solving skills, customer empathy, and experience engaging executive stakeholders (e.g., CISOs, CTOs). Other: Willingness to travel (up to 50%); valid driver's license required. Must pass a background check and maintain up to date security clearances if applicable. Why Join Us? Opportunity to work with cutting edge AI driven cybersecurity technologies and Google SecOps solutions. Collaborate with a talented and innovative team focused on continuously improving security operations. Competitive salary and benefits package. A culture of growth and development, with opportunities to expand your knowledge in AI, cybersecurity, and emerging technologies.
Internal Cyber Defence Consultant
Vastbouw
As part of this evolution, we are looking for an Internal Cyber Defence Consultant to strengthen our defensive posture, lead the maturity of our Blue Team capability, and ensure Ricoh remains resilient against an ever evolving threat landscape. This is a high impact individual contributor role with virtual leadership responsibilities and working closely with security, technology and business teams across Europe. What you will be doing The Internal Cyber Defence Consultant will be responsible for shaping and maturing Ricoh's defensive security operations. This includes overseeing detection engineering, incident response, threat hunting, and vulnerability management. You will guide the virtual Blue Team, set the direction for defensive strategy, and ensure security controls, processes, and technologies deliver protection across Ricoh's systems, networks and data. Operating in a complex and fast paced environment, you will be accountable for the design and continual improvement of detection and response capabilities, while ensuring alignment with industry standards, regulatory requirements and Ricoh's risk appetite. This role blends technical expertise, leadership, analysis and communication, requiring someone who can influence without direct authority and act decisively when incidents occur. Key Responsibilities Include: Blue Team Leadership & Operations Leading and coordinating the virtual Blue Team, including SOC analysts, incident responders, threat hunters and defensive engineers Setting strategic direction, improving processes, and supporting skill development across the defensive capability Acting as a senior escalation point during investigations and major incidents Designing, implementing and tuning detection rules across SIEM, SOAR, EDR and NDR platforms Managing log ingestion, telemetry pipelines and data quality to ensure visibility across all environments Identifying gaps in logging, coverage or monitoring and driving improvements Managing incident response processes, including playbooks, tabletop exercises and post incident reviews Leading investigations, coordinating cross functional teams and ensuring effective containment, eradication and recovery Embedding lessons learned into future detection, tooling and process enhancements Threat Hunting & Proactive Defence Conducting hypothesis driven threat hunts informed by threat intelligence Identifying stealthy or emerging threats not caught by automated detection Collaborating with Red Team operators to validate detection gaps and enhance Blue Team response Vulnerability & Exposure Management Overseeing vulnerability management processes and coordinating risk based remediation Working with infrastructure and application teams to prioritise and address high risk weaknesses Reporting remediation progress and exposure trends to senior leadership Governance, Reporting & Culture Ensuring compliance with ISO 27001, GDPR, NIS2 and internal security policies Providing clear reporting on threat trends, risk indicators, detection maturity and incident metrics Championing a security first culture through guidance, awareness and training initiatives You will ideally have Technical Expertise Strong hands on experience across SIEM, SOAR, EDR and NDR technologies - covering the Microsoft suite. Zero Trust experience, ideally with zScaler. Proficiency in detection engineering, alert tuning, log analysis and data correlation Solid understanding of MITRE ATT&CK, cyber kill chain and threat actor TTPs Experience conducting or leading incident response and digital forensics investigations Skilled in threat hunting techniques, anomaly detection and behavioural analytics Strong knowledge of vulnerability management processes and tooling Understanding of enterprise networks, cloud environments, endpoints and identity systems Leadership & Interpersonal Skills Experience guiding virtual or multidisciplinary security teams Strong communicator, comfortable engaging senior stakeholders across technical and non technical functions Able to influence decision making, challenge assumptions and advocate for necessary security improvements Skilled at maintaining calm, clarity and leadership during high pressure security incidents Capable of building trust, fostering collaboration and promoting continuous improvement Business & Strategic Acumen Understanding of Ricoh's business context, regulatory environment and operational dependencies Ability to translate technical risk into meaningful business impact Awareness of sector specific risks and organisational priorities Experience working in or with regulated enterprise environments Qualifications & Experience Bachelor's degree in Cybersecurity, Computer Science, IT or related field Relevant certifications such as GCIH, GCIA, GMON or CISSP Extensive proven experience in defensive cyber security roles Proven experience in a leadership or senior operational position Hands on experience leading major incident investigations in enterprise environments Exposure to red/purple team exercises, detection tuning and threat driven defence In return for your commitment, you can expect At Ricoh, work should feel meaningful, supportive and fulfilling. The Ricoh Promise shapes your experience through four pillars that bring our culture to life. Love to Connect You become part of a global community built on openness, inclusion and genuine collaboration. Across teams, countries and roles, you'll find people who listen, involve and encourage you - helping you feel valued and able to be yourself every day. Love to Grow Your development truly matters to us. With access to learning pathways, mentoring and career opportunities across functions and countries, you'll be supported to stretch your skills, explore new directions and stay future ready in a changing world. Love to Give Back Purpose is part of how we work. You'll have opportunities to make a difference through volunteering, sustainability initiatives and community programmes that reflect our shared values and commitment to positive impact. Love to Succeed Success at Ricoh is something we pursue together. You'll benefit from fair rewards, flexible working, wellbeing resources and real recognition - including programmes such as the Imagine. Change. Awards, where colleagues celebrate each other's achievements. We are an equal opportunities employer We believe that diverse perspectives make us stronger, and we welcome applications from people of all backgrounds, identities, and experiences. Our hiring decisions are based on skills, experience and potential, and we are committed to creating a fair and inclusive recruitment process. If you require any reasonable adjustments at any stage of the recruitment journey, please let us know and we will support you to bring your best self forward.
16/07/2026
Full time
As part of this evolution, we are looking for an Internal Cyber Defence Consultant to strengthen our defensive posture, lead the maturity of our Blue Team capability, and ensure Ricoh remains resilient against an ever evolving threat landscape. This is a high impact individual contributor role with virtual leadership responsibilities and working closely with security, technology and business teams across Europe. What you will be doing The Internal Cyber Defence Consultant will be responsible for shaping and maturing Ricoh's defensive security operations. This includes overseeing detection engineering, incident response, threat hunting, and vulnerability management. You will guide the virtual Blue Team, set the direction for defensive strategy, and ensure security controls, processes, and technologies deliver protection across Ricoh's systems, networks and data. Operating in a complex and fast paced environment, you will be accountable for the design and continual improvement of detection and response capabilities, while ensuring alignment with industry standards, regulatory requirements and Ricoh's risk appetite. This role blends technical expertise, leadership, analysis and communication, requiring someone who can influence without direct authority and act decisively when incidents occur. Key Responsibilities Include: Blue Team Leadership & Operations Leading and coordinating the virtual Blue Team, including SOC analysts, incident responders, threat hunters and defensive engineers Setting strategic direction, improving processes, and supporting skill development across the defensive capability Acting as a senior escalation point during investigations and major incidents Designing, implementing and tuning detection rules across SIEM, SOAR, EDR and NDR platforms Managing log ingestion, telemetry pipelines and data quality to ensure visibility across all environments Identifying gaps in logging, coverage or monitoring and driving improvements Managing incident response processes, including playbooks, tabletop exercises and post incident reviews Leading investigations, coordinating cross functional teams and ensuring effective containment, eradication and recovery Embedding lessons learned into future detection, tooling and process enhancements Threat Hunting & Proactive Defence Conducting hypothesis driven threat hunts informed by threat intelligence Identifying stealthy or emerging threats not caught by automated detection Collaborating with Red Team operators to validate detection gaps and enhance Blue Team response Vulnerability & Exposure Management Overseeing vulnerability management processes and coordinating risk based remediation Working with infrastructure and application teams to prioritise and address high risk weaknesses Reporting remediation progress and exposure trends to senior leadership Governance, Reporting & Culture Ensuring compliance with ISO 27001, GDPR, NIS2 and internal security policies Providing clear reporting on threat trends, risk indicators, detection maturity and incident metrics Championing a security first culture through guidance, awareness and training initiatives You will ideally have Technical Expertise Strong hands on experience across SIEM, SOAR, EDR and NDR technologies - covering the Microsoft suite. Zero Trust experience, ideally with zScaler. Proficiency in detection engineering, alert tuning, log analysis and data correlation Solid understanding of MITRE ATT&CK, cyber kill chain and threat actor TTPs Experience conducting or leading incident response and digital forensics investigations Skilled in threat hunting techniques, anomaly detection and behavioural analytics Strong knowledge of vulnerability management processes and tooling Understanding of enterprise networks, cloud environments, endpoints and identity systems Leadership & Interpersonal Skills Experience guiding virtual or multidisciplinary security teams Strong communicator, comfortable engaging senior stakeholders across technical and non technical functions Able to influence decision making, challenge assumptions and advocate for necessary security improvements Skilled at maintaining calm, clarity and leadership during high pressure security incidents Capable of building trust, fostering collaboration and promoting continuous improvement Business & Strategic Acumen Understanding of Ricoh's business context, regulatory environment and operational dependencies Ability to translate technical risk into meaningful business impact Awareness of sector specific risks and organisational priorities Experience working in or with regulated enterprise environments Qualifications & Experience Bachelor's degree in Cybersecurity, Computer Science, IT or related field Relevant certifications such as GCIH, GCIA, GMON or CISSP Extensive proven experience in defensive cyber security roles Proven experience in a leadership or senior operational position Hands on experience leading major incident investigations in enterprise environments Exposure to red/purple team exercises, detection tuning and threat driven defence In return for your commitment, you can expect At Ricoh, work should feel meaningful, supportive and fulfilling. The Ricoh Promise shapes your experience through four pillars that bring our culture to life. Love to Connect You become part of a global community built on openness, inclusion and genuine collaboration. Across teams, countries and roles, you'll find people who listen, involve and encourage you - helping you feel valued and able to be yourself every day. Love to Grow Your development truly matters to us. With access to learning pathways, mentoring and career opportunities across functions and countries, you'll be supported to stretch your skills, explore new directions and stay future ready in a changing world. Love to Give Back Purpose is part of how we work. You'll have opportunities to make a difference through volunteering, sustainability initiatives and community programmes that reflect our shared values and commitment to positive impact. Love to Succeed Success at Ricoh is something we pursue together. You'll benefit from fair rewards, flexible working, wellbeing resources and real recognition - including programmes such as the Imagine. Change. Awards, where colleagues celebrate each other's achievements. We are an equal opportunities employer We believe that diverse perspectives make us stronger, and we welcome applications from people of all backgrounds, identities, and experiences. Our hiring decisions are based on skills, experience and potential, and we are committed to creating a fair and inclusive recruitment process. If you require any reasonable adjustments at any stage of the recruitment journey, please let us know and we will support you to bring your best self forward.
Cloud Security Consultant
Solutions & Innovations Company
Cloud Security Consultant A Global Financial Services firm requires a Contract Cloud Security Consultant to join their Cyber Transformation Programme consulting across Al, DevSecOps & Microsoft Security Suite. Travel: Hydbrid Location: London IT Security Cloud Consultant working in Al engineering and project teams, ensuring all deliverables align with security standards (e.g. NIST CSF 2.0) and protect information assets (Confidentiality, Integrity, Availability). Lead threat modelling, risk assessments, and secure coding initiatives (especially in Python and Azure environments) across the chatbot lifecycle and broader IT systems, mitigating vulnerabilities and ensuring compliance with data protection laws (e.g., GDPR). Establish, implement, and maintain security policies, standards, and operational controls; support audits, incident response, vulnerability remediation, and ensure effective use of security tooling (eg., Sentinel, Defender for Cloud, SIEM). Work closely with Operational Risk, DevOps, and Information Security teams to embed best practices into Agile delivery pipelines, balance stakeholder priorities, and drive the security agenda within a matrixed environment. Serve as the security point of contact for projects, leveraging deep knowledge in DevSecOps, Azure IAM, PKI, secure SDLC, and adversarial Al threats, while promoting a culture of continuous improvement and security awareness.
15/07/2026
Full time
Cloud Security Consultant A Global Financial Services firm requires a Contract Cloud Security Consultant to join their Cyber Transformation Programme consulting across Al, DevSecOps & Microsoft Security Suite. Travel: Hydbrid Location: London IT Security Cloud Consultant working in Al engineering and project teams, ensuring all deliverables align with security standards (e.g. NIST CSF 2.0) and protect information assets (Confidentiality, Integrity, Availability). Lead threat modelling, risk assessments, and secure coding initiatives (especially in Python and Azure environments) across the chatbot lifecycle and broader IT systems, mitigating vulnerabilities and ensuring compliance with data protection laws (e.g., GDPR). Establish, implement, and maintain security policies, standards, and operational controls; support audits, incident response, vulnerability remediation, and ensure effective use of security tooling (eg., Sentinel, Defender for Cloud, SIEM). Work closely with Operational Risk, DevOps, and Information Security teams to embed best practices into Agile delivery pipelines, balance stakeholder priorities, and drive the security agenda within a matrixed environment. Serve as the security point of contact for projects, leveraging deep knowledge in DevSecOps, Azure IAM, PKI, secure SDLC, and adversarial Al threats, while promoting a culture of continuous improvement and security awareness.
Senior Cloud Security Engineer (SecOps / GCP)
Beyond Manchester, Lancashire
About the role We help regulated and enterprise customers protect their Google Cloud Estates. As a Premier Google Cloud Partner, we deliver Google Unified Security (GUS) engagements across the full stack - from greenfield SIEM/SOAR deployments and SOC modernisation programmes to detection engineering, posture management, threat hunting, and incident response uplift. Secure GCP estates with the adoption of CI/CD pipelines, secure landing zones and cloud posture reviews. Expertise when integrating third party tools such as Wiz. We're looking for a Senior Security Engineer with deep, hands on experience across the GCP and Google Security portfolio. You'll lead the technical work on customer engagements, build reusable content for the practice, and help customers deliver security solutions at scale. This is a hands on senior role. Most of your week is client delivery. The rest goes into our practice - accelerators, parsers, rule packs, playbooks, and points of view that make the next engagement faster than the last. What you'll do Google SecOps (SIEM / SOAR) Lead end to end SecOps deployments - tenant setup, multi tenant architecture, data ingestion, retention design, RBAC, and feed onboarding. Build and maintain parsers, UDM mappings, and data models for Google Cloud, AWS, Azure, endpoint, identity, and network sources. Write, test, and tune YARA L detection rules, including single event, multi event, and composite detections. Design SOAR playbooks and python integrations. Develop custom agents that can be deployed in customer environments using GCP infrastructure. GCP Configure CI/CD pipelines with integrated security tools. Configure GCP security solutions including Security Command Center Enterprise, IAP, VPC Service Controls, and Model Armor. Work with platform teams to support the deployment of secure cloud foundation blueprints. Support clients with secure AI workloads including the use of model armor and agent identities. Google Threat Intelligence Operationalise Google Threat Intelligence inside SecOps - IoC matching, Applied Threat Intelligence, and curated detections. Build threat informed defence programmes tied to customer specific threat profiles (sector, geography, adversary groups). Run threat hunting campaigns using GTI, Mandiant frontline intelligence, and UDM search. Validate detection coverage against MITRE ATT&CK using Mandiant Security Validation where in scope. Practice growth Mentor engineers and consultants; lead internal SecOps and GUS enablement. Represent the practice in pre sales, customer workshops, and Google partner forums. What we're looking for Essential Strong SIEM/SOC delivery experience (any major platform; Google SecOps / Chronicle preferred). Hands on with Google SecOps: UDM, YARA L, parsers, SOAR playbooks, data ingestion patterns. Solid grounding in Google Cloud security primitives: IAM, Organization Policies, VPC Service Controls, Cloud Logging, Cloud KMS. Comfortable with Terraform, CI/CD pipelines and at least one scripting language (Python, Go) for automation, parser development, and integration work. Experience supporting regulated workloads (financial services, public sector, healthcare) and translating compliance requirements into operational controls. Able to explain risk, trade offs, and findings to both SOC analysts and executive stakeholders. Nice to have Google Professional Cloud Security Engineer or Google SecOps certification. Prior SIEM migration experience (Splunk SecOps, Sentinel SecOps, etc.). Experience with adjacent tooling: Wiz, CrowdStrike, Splunk, Sentinel, Snyk. Consulting or systems integrator background. Contributions to open detection content (Sigma, MITRE, public rule repos). Benefits We believe in supporting our team members both professionally and personally. Here's how we invest in you: Compensation and Financial Wellbeing Competitive base salary Matching pension scheme (up to 5%) from day one Discretionary company bonus scheme 4 x annual salary Death in Service coverage from day one Employee referral scheme Tech Scheme Health and Wellness Private medical insurance from day one Optical and dental cashback scheme app: access to remote GP's, second opinions, mental health support, and physiotherapy EAP service Cycle to work scheme Work Life balance and Growth 28 days annual leave (plus bank holidays) An extra paid day off for your birthday Ten paid learning days per year Flexible working hours Work from anywhere (up to 3 weeks per year) Industry recognised training and certifications Bonusly employee recognition and reward platform Clear opportunities for career progression Length of service awards Regular company events Diversity and Inclusion At Beyond we champion diversity and inclusion. We believe that a career in IT should be open to everyone, regardless of race, ethnicity, gender, age, sexual orientation, disability or neurotype. We value the unique talents and perspectives that each individual brings to our team, and we strive to create a fair and accessible hiring process for all.
15/07/2026
Full time
About the role We help regulated and enterprise customers protect their Google Cloud Estates. As a Premier Google Cloud Partner, we deliver Google Unified Security (GUS) engagements across the full stack - from greenfield SIEM/SOAR deployments and SOC modernisation programmes to detection engineering, posture management, threat hunting, and incident response uplift. Secure GCP estates with the adoption of CI/CD pipelines, secure landing zones and cloud posture reviews. Expertise when integrating third party tools such as Wiz. We're looking for a Senior Security Engineer with deep, hands on experience across the GCP and Google Security portfolio. You'll lead the technical work on customer engagements, build reusable content for the practice, and help customers deliver security solutions at scale. This is a hands on senior role. Most of your week is client delivery. The rest goes into our practice - accelerators, parsers, rule packs, playbooks, and points of view that make the next engagement faster than the last. What you'll do Google SecOps (SIEM / SOAR) Lead end to end SecOps deployments - tenant setup, multi tenant architecture, data ingestion, retention design, RBAC, and feed onboarding. Build and maintain parsers, UDM mappings, and data models for Google Cloud, AWS, Azure, endpoint, identity, and network sources. Write, test, and tune YARA L detection rules, including single event, multi event, and composite detections. Design SOAR playbooks and python integrations. Develop custom agents that can be deployed in customer environments using GCP infrastructure. GCP Configure CI/CD pipelines with integrated security tools. Configure GCP security solutions including Security Command Center Enterprise, IAP, VPC Service Controls, and Model Armor. Work with platform teams to support the deployment of secure cloud foundation blueprints. Support clients with secure AI workloads including the use of model armor and agent identities. Google Threat Intelligence Operationalise Google Threat Intelligence inside SecOps - IoC matching, Applied Threat Intelligence, and curated detections. Build threat informed defence programmes tied to customer specific threat profiles (sector, geography, adversary groups). Run threat hunting campaigns using GTI, Mandiant frontline intelligence, and UDM search. Validate detection coverage against MITRE ATT&CK using Mandiant Security Validation where in scope. Practice growth Mentor engineers and consultants; lead internal SecOps and GUS enablement. Represent the practice in pre sales, customer workshops, and Google partner forums. What we're looking for Essential Strong SIEM/SOC delivery experience (any major platform; Google SecOps / Chronicle preferred). Hands on with Google SecOps: UDM, YARA L, parsers, SOAR playbooks, data ingestion patterns. Solid grounding in Google Cloud security primitives: IAM, Organization Policies, VPC Service Controls, Cloud Logging, Cloud KMS. Comfortable with Terraform, CI/CD pipelines and at least one scripting language (Python, Go) for automation, parser development, and integration work. Experience supporting regulated workloads (financial services, public sector, healthcare) and translating compliance requirements into operational controls. Able to explain risk, trade offs, and findings to both SOC analysts and executive stakeholders. Nice to have Google Professional Cloud Security Engineer or Google SecOps certification. Prior SIEM migration experience (Splunk SecOps, Sentinel SecOps, etc.). Experience with adjacent tooling: Wiz, CrowdStrike, Splunk, Sentinel, Snyk. Consulting or systems integrator background. Contributions to open detection content (Sigma, MITRE, public rule repos). Benefits We believe in supporting our team members both professionally and personally. Here's how we invest in you: Compensation and Financial Wellbeing Competitive base salary Matching pension scheme (up to 5%) from day one Discretionary company bonus scheme 4 x annual salary Death in Service coverage from day one Employee referral scheme Tech Scheme Health and Wellness Private medical insurance from day one Optical and dental cashback scheme app: access to remote GP's, second opinions, mental health support, and physiotherapy EAP service Cycle to work scheme Work Life balance and Growth 28 days annual leave (plus bank holidays) An extra paid day off for your birthday Ten paid learning days per year Flexible working hours Work from anywhere (up to 3 weeks per year) Industry recognised training and certifications Bonusly employee recognition and reward platform Clear opportunities for career progression Length of service awards Regular company events Diversity and Inclusion At Beyond we champion diversity and inclusion. We believe that a career in IT should be open to everyone, regardless of race, ethnicity, gender, age, sexual orientation, disability or neurotype. We value the unique talents and perspectives that each individual brings to our team, and we strive to create a fair and accessible hiring process for all.
SOC Operations Technical Lead
Nettitude Group Birmingham, Staffordshire
Role objective The purpose of this role is to lead a team of SOC analysts, who are collectively operating on a 24/7/365 basis. Technical and client-oriented SOC Operations Technical Lead role plays a pivotal senior role within our Managed Security Services Provider (MSSP) environment. This role reports to Head of SOC Operations. This hands on position serves as the senior technical authority for SOC operations, driving excellence in threat detection, incident response, and security operations across a diverse multi-client portfolio. You will combine deep technical proficiency with strong consulting skills to mentor analysts, manage shift rotations, optimise SOC processes and tools, lead complex incident escalations, and act as a trusted advisor. Although you will manage a team of SOC analysts, this is not a purely managerial role; you will remain deeply involved in technical work while elevating team capabilities and delivering strategic value to our clients. In this role you will be accountable for the effective functioning of your team, ensuring high performance standards while continuously developing their skills as part of a high trust, high performing security service. You will leverage your combined experience in leadership and security operations to enable the smooth delivery of our award winning defensive monitoring service, supporting proactive detection and response for clients across the globe. You will be expected to contribute, hands on, technically where and when needed, including deep dive investigations, incident response escalations, threat hunting, tuning detections, delivering technical training, and driving process and capability improvements. Strong technical knowledge is essential to mentor junior analysts, develop their capabilities, and ensure the team remains at the forefront of security operations. You must proactively initiate actions and work independently to quickly mitigate threats, set an example, maintain operational continuity, make informed decisions, and ensure team efficiency under pressure. The roles and responsibilities are reviewed annually to ensure alignment with current organisational needs, emerging threats, and industry best practice. Collaboration with other teams As SOC Operations Technical Lead, you will be working closely with Threat Intelligence, Engineering and Incident Response teams as this is essential to strengthen the SOC's ability to detect, investigate, and respond to emerging threats. This collaboration ensures timely sharing of actionable intelligence, refinement of detection rules, improvement of security tools, and alignment of operational processes, ultimately enhancing overall organisational security posture. This role drives continuous improvement within the SOC by identifying gaps in processes, detection capabilities, and team performance, and implementing solutions to enhance operational efficiency. The SOC Operations Technical Lead evaluates incidents and alerts to refine triage and response workflows, ensuring lessons learned are translated into updated playbooks and best practices. By monitoring emerging threats, tuning detections, and adopting new tools and techniques, the role strengthens the SOC's proactive defence posture. Team Leadership & Operations Oversight Lead day to day activities of the SOC analysts across all shifts (24/7 operations through and on call rotation). Manage team scheduling, shift handovers, and always ensure proper coverage. Act as the first point of escalation for security events and staff queries during shifts. Aim to ensure high quality incident triage, investigation, and response by team members, following predefined and agreed SOC processes. Coordinate with other shifts to maintain operational continuity and consistent processes. Lead and Facilitate the Development of the wider monitoring team through technical training courses, workshops and exercises. Applicable department objectives and projects are completed within specification, deadline and budgetary constraints. Ensure completion of all HALO case management on time and with accurate and timely results. Technical Leadership & Operations Excellence Provide technical leadership and guidance to SOC analysts on alert triage, investigation, threat hunting, and incident response. Function as the primary technical escalation point for complex, high severity, or novel security alerts across multiple client environments. Drive continuous improvement of SOC processes, playbooks, detection rules, and automation to enhance efficiency, reduce false positives, and accelerate response times. Evaluate, recommend, and support the implementation and optimization of SOC technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms) across heterogeneous client stacks. Develop and maintain advanced detection content, custom queries, correlation rules, and use cases tailored to client environments and emerging threats. Consulting & Client Engagement Serve as a trusted technical consultant to clients, participating in security reviews, root cause analyses, and recommendations for security posture improvements. Translate complex technical findings and recommendations into clear, actionable insights for both technical and executive client stakeholders. Mentor and coach SOC analysts, fostering technical growth, best practices, and a high performance culture. Conduct technical training sessions, knowledge sharing workshops, and skills assessments. Support performance management, including goal setting and feedback for direct or matrix team members. Strategic & Operational Contributions Identify opportunities to enhance MSSP service offerings through new capabilities, automation, or methodology improvements. Monitor industry trends, threat intelligence, and tool advancements to keep SOC operations at the cutting edge. Ensure compliance with SLAs, internal standards, and relevant regulatory requirements. Required Qualifications & Experience 7+ years of experience in Security Operations, with at least 3-4 years in a senior/lead technical role within a SOC (preferably in an MSSP or multi-client environment). Strong hands on expertise with industry leading tools: SIEM platforms (Microsoft Sentinel, CrowdStrike) EDR/XDR solutions (CrowdStrike, Microsoft Defender, Carbon Black) SOAR, threat intelligence platforms, and network security tools. Proven experience in advanced threat hunting. Solid automation skills to improve SOC efficiency. Experience designing and tuning detection rules, use cases, and correlation logic in multi tenant environments. Demonstrated consulting skills and ability to communicate effectively with clients, present findings, and provide strategic security advice. Preferred Qualifications Relevant certifications: CISSP, GIAC (GCIH, GCIA, GREM), SC 200, SC 300 or equivalent. Experience with cloud security operations environments. Background in professional services, consulting, or MSSP delivery. Familiarity with ITIL, NIST, ISO27001 or other security frameworks in a service provider context. Exceptional technical depth combined with the ability to explain complex concepts simply. Strong problem solving, analytical thinking, and decision making under pressure. Excellent written and verbal communication skills, including client facing presentation abilities. Leadership presence with a collaborative, mentoring approach. Ability to manage multiple priorities and thrive in a fast paced, 24/7 MSSP environment.
15/07/2026
Full time
Role objective The purpose of this role is to lead a team of SOC analysts, who are collectively operating on a 24/7/365 basis. Technical and client-oriented SOC Operations Technical Lead role plays a pivotal senior role within our Managed Security Services Provider (MSSP) environment. This role reports to Head of SOC Operations. This hands on position serves as the senior technical authority for SOC operations, driving excellence in threat detection, incident response, and security operations across a diverse multi-client portfolio. You will combine deep technical proficiency with strong consulting skills to mentor analysts, manage shift rotations, optimise SOC processes and tools, lead complex incident escalations, and act as a trusted advisor. Although you will manage a team of SOC analysts, this is not a purely managerial role; you will remain deeply involved in technical work while elevating team capabilities and delivering strategic value to our clients. In this role you will be accountable for the effective functioning of your team, ensuring high performance standards while continuously developing their skills as part of a high trust, high performing security service. You will leverage your combined experience in leadership and security operations to enable the smooth delivery of our award winning defensive monitoring service, supporting proactive detection and response for clients across the globe. You will be expected to contribute, hands on, technically where and when needed, including deep dive investigations, incident response escalations, threat hunting, tuning detections, delivering technical training, and driving process and capability improvements. Strong technical knowledge is essential to mentor junior analysts, develop their capabilities, and ensure the team remains at the forefront of security operations. You must proactively initiate actions and work independently to quickly mitigate threats, set an example, maintain operational continuity, make informed decisions, and ensure team efficiency under pressure. The roles and responsibilities are reviewed annually to ensure alignment with current organisational needs, emerging threats, and industry best practice. Collaboration with other teams As SOC Operations Technical Lead, you will be working closely with Threat Intelligence, Engineering and Incident Response teams as this is essential to strengthen the SOC's ability to detect, investigate, and respond to emerging threats. This collaboration ensures timely sharing of actionable intelligence, refinement of detection rules, improvement of security tools, and alignment of operational processes, ultimately enhancing overall organisational security posture. This role drives continuous improvement within the SOC by identifying gaps in processes, detection capabilities, and team performance, and implementing solutions to enhance operational efficiency. The SOC Operations Technical Lead evaluates incidents and alerts to refine triage and response workflows, ensuring lessons learned are translated into updated playbooks and best practices. By monitoring emerging threats, tuning detections, and adopting new tools and techniques, the role strengthens the SOC's proactive defence posture. Team Leadership & Operations Oversight Lead day to day activities of the SOC analysts across all shifts (24/7 operations through and on call rotation). Manage team scheduling, shift handovers, and always ensure proper coverage. Act as the first point of escalation for security events and staff queries during shifts. Aim to ensure high quality incident triage, investigation, and response by team members, following predefined and agreed SOC processes. Coordinate with other shifts to maintain operational continuity and consistent processes. Lead and Facilitate the Development of the wider monitoring team through technical training courses, workshops and exercises. Applicable department objectives and projects are completed within specification, deadline and budgetary constraints. Ensure completion of all HALO case management on time and with accurate and timely results. Technical Leadership & Operations Excellence Provide technical leadership and guidance to SOC analysts on alert triage, investigation, threat hunting, and incident response. Function as the primary technical escalation point for complex, high severity, or novel security alerts across multiple client environments. Drive continuous improvement of SOC processes, playbooks, detection rules, and automation to enhance efficiency, reduce false positives, and accelerate response times. Evaluate, recommend, and support the implementation and optimization of SOC technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms) across heterogeneous client stacks. Develop and maintain advanced detection content, custom queries, correlation rules, and use cases tailored to client environments and emerging threats. Consulting & Client Engagement Serve as a trusted technical consultant to clients, participating in security reviews, root cause analyses, and recommendations for security posture improvements. Translate complex technical findings and recommendations into clear, actionable insights for both technical and executive client stakeholders. Mentor and coach SOC analysts, fostering technical growth, best practices, and a high performance culture. Conduct technical training sessions, knowledge sharing workshops, and skills assessments. Support performance management, including goal setting and feedback for direct or matrix team members. Strategic & Operational Contributions Identify opportunities to enhance MSSP service offerings through new capabilities, automation, or methodology improvements. Monitor industry trends, threat intelligence, and tool advancements to keep SOC operations at the cutting edge. Ensure compliance with SLAs, internal standards, and relevant regulatory requirements. Required Qualifications & Experience 7+ years of experience in Security Operations, with at least 3-4 years in a senior/lead technical role within a SOC (preferably in an MSSP or multi-client environment). Strong hands on expertise with industry leading tools: SIEM platforms (Microsoft Sentinel, CrowdStrike) EDR/XDR solutions (CrowdStrike, Microsoft Defender, Carbon Black) SOAR, threat intelligence platforms, and network security tools. Proven experience in advanced threat hunting. Solid automation skills to improve SOC efficiency. Experience designing and tuning detection rules, use cases, and correlation logic in multi tenant environments. Demonstrated consulting skills and ability to communicate effectively with clients, present findings, and provide strategic security advice. Preferred Qualifications Relevant certifications: CISSP, GIAC (GCIH, GCIA, GREM), SC 200, SC 300 or equivalent. Experience with cloud security operations environments. Background in professional services, consulting, or MSSP delivery. Familiarity with ITIL, NIST, ISO27001 or other security frameworks in a service provider context. Exceptional technical depth combined with the ability to explain complex concepts simply. Strong problem solving, analytical thinking, and decision making under pressure. Excellent written and verbal communication skills, including client facing presentation abilities. Leadership presence with a collaborative, mentoring approach. Ability to manage multiple priorities and thrive in a fast paced, 24/7 MSSP environment.
Reed Technology
Senior Cyber Consultant
Reed Technology
Senior Cyber Consultant 65,000 + 15k Bonus Hybrid UK A growing cyber security consultancy is seeking a Senior Cyber Consultant to help organisations enhance their Security Operations and threat detection capabilities. This is a client-facing role focused on designing and delivering SIEM, XDR and SOAR solutions, developing detection content, automating security processes, and improving SOC effectiveness. You will lead detection engineering initiatives, create use cases aligned to MITRE ATT&CK, develop response playbooks, and implement Detection-as-Code best practices. Key Requirements Experience with SIEM platforms (Microsoft Sentinel preferred) Strong KQL and detection engineering skills SOAR automation and playbook development experience Python and/or PowerShell scripting XDR/EDR experience Knowledge of MITRE ATT&CK and threat detection methodologies Azure security and cloud telemetry exposure Previous consultancy or customer-facing experience What's on Offer 65,000 base salary Annual Bonus Predominantly remote working No on-call requirement Exposure to enterprise-scale cyber security projects Strong development and progression opportunities Ideal for: Detection Engineers, SIEM Engineers, Senior SOC Analysts, Security Automation Engineers, SOC Consultants, and Cyber Security Engineers seeking a consultancy-focused role.
15/07/2026
Full time
Senior Cyber Consultant 65,000 + 15k Bonus Hybrid UK A growing cyber security consultancy is seeking a Senior Cyber Consultant to help organisations enhance their Security Operations and threat detection capabilities. This is a client-facing role focused on designing and delivering SIEM, XDR and SOAR solutions, developing detection content, automating security processes, and improving SOC effectiveness. You will lead detection engineering initiatives, create use cases aligned to MITRE ATT&CK, develop response playbooks, and implement Detection-as-Code best practices. Key Requirements Experience with SIEM platforms (Microsoft Sentinel preferred) Strong KQL and detection engineering skills SOAR automation and playbook development experience Python and/or PowerShell scripting XDR/EDR experience Knowledge of MITRE ATT&CK and threat detection methodologies Azure security and cloud telemetry exposure Previous consultancy or customer-facing experience What's on Offer 65,000 base salary Annual Bonus Predominantly remote working No on-call requirement Exposure to enterprise-scale cyber security projects Strong development and progression opportunities Ideal for: Detection Engineers, SIEM Engineers, Senior SOC Analysts, Security Automation Engineers, SOC Consultants, and Cyber Security Engineers seeking a consultancy-focused role.
Senior Cloud Security Engineer (SecOps / GCP)
Qodea Manchester, Lancashire
About the role We help regulated and enterprise customers protect their Google Cloud Estates. As a Premier Google Cloud Partner, we deliver Google Unified Security (GUS) engagements across the full stack - from greenfield SIEM/SOAR deployments and SOC modernisation programmes to detection engineering, posture management, threat hunting, and incident response uplift. Secure GCP estates with the adoption of CI/CD pipelines, secure landing zones and cloud posture reviews. Expertise when integrating third party tools such as Wiz. We're looking for a Senior Security Engineer with deep, hands on experience across the GCP and Google Security portfolio. You'll lead the technical work on customer engagements, build reusable content for the practice, and help customers deliver security solutions at scale. This is a hands on senior role. Most of your week is client delivery. The rest goes into our practice - accelerators, parsers, rule packs, playbooks, and points of view that make the next engagement faster than the last. What you'll do Google SecOps (SIEM / SOAR) Lead end to end SecOps deployments - tenant setup, multi tenant architecture, data ingestion, retention design, RBAC, and feed onboarding. Build and maintain parsers, UDM mappings, and data models for Google Cloud, AWS, Azure, endpoint, identity, and network sources. Write, test, and tune YARA L detection rules, including single event, multi event, and composite detections. Design SOAR playbooks and python integrations. Develop custom agents that can be deployed in customer environments using GCP infrastructure. GCP Configure CI/CD pipelines with integrated security tools. Configure GCP security solutions including Security Command Center Enterprise, IAP, VPC Service Controls, and Model Armor. Work with platform teams to support the deployment of secure cloud foundation blueprints. Support clients with secure AI workloads including the use of model armor and agent identities. Google Threat Intelligence Operationalise Google Threat Intelligence inside SecOps - IoC matching, Applied Threat Intelligence, and curated detections. Build threat informed defence programmes tied to customer specific threat profiles (sector, geography, adversary groups). Run threat hunting campaigns using GTI, Mandiant frontline intelligence, and UDM search. Validate detection coverage against MITRE ATT&CK using Mandiant Security Validation where in scope. Practice growth Mentor engineers and consultants; lead internal SecOps and GUS enablement. Represent the practice in pre sales, customer workshops, and Google partner forums. What we're looking for Essential Strong SIEM/SOC delivery experience (any major platform; Google SecOps / Chronicle preferred). Hands on with Google SecOps: UDM, YARA L, parsers, SOAR playbooks, data ingestion patterns. Solid grounding in Google Cloud security primitives: IAM, Organization Policies, VPC Service Controls, Cloud Logging, Cloud KMS. Comfortable with Terraform, CI/CD pipelines and at least one scripting language (Python, Go) for automation, parser development, and integration work. Experience supporting regulated workloads (financial services, public sector, healthcare) and translating compliance requirements into operational controls. Able to explain risk, trade offs, and findings to both SOC analysts and executive stakeholders. Nice to have Google Professional Cloud Security Engineer or Google SecOps certification. Prior SIEM migration experience (Splunk SecOps, Sentinel SecOps, etc.). Experience with adjacent tooling: Wiz, CrowdStrike, Splunk, Sentinel, Snyk. Consulting or systems integrator background. Contributions to open detection content (Sigma, MITRE, public rule repos). Benefits We believe in supporting our team members both professionally and personally. Here's how we invest in you: Compensation and Financial Wellbeing Competitive base salary Matching pension scheme (up to 5%) from day one Discretionary company bonus scheme 4 x annual salary Death in Service coverage from day one Employee referral scheme Tech Scheme Health and Wellness Private medical insurance from day one Optical and dental cashback scheme app: access to remote GP's, second opinions, mental health support, and physiotherapy EAP service Cycle to work scheme Work Life balance and Growth 28 days annual leave (plus bank holidays) An extra paid day off for your birthday Ten paid learning days per year Flexible working hours Work from anywhere (up to 3 weeks per year) Industry recognised training and certifications Bonusly employee recognition and reward platform Clear opportunities for career progression Length of service awards Regular company events Diversity and Inclusion At Beyond we champion diversity and inclusion. We believe that a career in IT should be open to everyone, regardless of race, ethnicity, gender, age, sexual orientation, disability or neurotype. We value the unique talents and perspectives that each individual brings to our team, and we strive to create a fair and accessible hiring process for all.
13/07/2026
Full time
About the role We help regulated and enterprise customers protect their Google Cloud Estates. As a Premier Google Cloud Partner, we deliver Google Unified Security (GUS) engagements across the full stack - from greenfield SIEM/SOAR deployments and SOC modernisation programmes to detection engineering, posture management, threat hunting, and incident response uplift. Secure GCP estates with the adoption of CI/CD pipelines, secure landing zones and cloud posture reviews. Expertise when integrating third party tools such as Wiz. We're looking for a Senior Security Engineer with deep, hands on experience across the GCP and Google Security portfolio. You'll lead the technical work on customer engagements, build reusable content for the practice, and help customers deliver security solutions at scale. This is a hands on senior role. Most of your week is client delivery. The rest goes into our practice - accelerators, parsers, rule packs, playbooks, and points of view that make the next engagement faster than the last. What you'll do Google SecOps (SIEM / SOAR) Lead end to end SecOps deployments - tenant setup, multi tenant architecture, data ingestion, retention design, RBAC, and feed onboarding. Build and maintain parsers, UDM mappings, and data models for Google Cloud, AWS, Azure, endpoint, identity, and network sources. Write, test, and tune YARA L detection rules, including single event, multi event, and composite detections. Design SOAR playbooks and python integrations. Develop custom agents that can be deployed in customer environments using GCP infrastructure. GCP Configure CI/CD pipelines with integrated security tools. Configure GCP security solutions including Security Command Center Enterprise, IAP, VPC Service Controls, and Model Armor. Work with platform teams to support the deployment of secure cloud foundation blueprints. Support clients with secure AI workloads including the use of model armor and agent identities. Google Threat Intelligence Operationalise Google Threat Intelligence inside SecOps - IoC matching, Applied Threat Intelligence, and curated detections. Build threat informed defence programmes tied to customer specific threat profiles (sector, geography, adversary groups). Run threat hunting campaigns using GTI, Mandiant frontline intelligence, and UDM search. Validate detection coverage against MITRE ATT&CK using Mandiant Security Validation where in scope. Practice growth Mentor engineers and consultants; lead internal SecOps and GUS enablement. Represent the practice in pre sales, customer workshops, and Google partner forums. What we're looking for Essential Strong SIEM/SOC delivery experience (any major platform; Google SecOps / Chronicle preferred). Hands on with Google SecOps: UDM, YARA L, parsers, SOAR playbooks, data ingestion patterns. Solid grounding in Google Cloud security primitives: IAM, Organization Policies, VPC Service Controls, Cloud Logging, Cloud KMS. Comfortable with Terraform, CI/CD pipelines and at least one scripting language (Python, Go) for automation, parser development, and integration work. Experience supporting regulated workloads (financial services, public sector, healthcare) and translating compliance requirements into operational controls. Able to explain risk, trade offs, and findings to both SOC analysts and executive stakeholders. Nice to have Google Professional Cloud Security Engineer or Google SecOps certification. Prior SIEM migration experience (Splunk SecOps, Sentinel SecOps, etc.). Experience with adjacent tooling: Wiz, CrowdStrike, Splunk, Sentinel, Snyk. Consulting or systems integrator background. Contributions to open detection content (Sigma, MITRE, public rule repos). Benefits We believe in supporting our team members both professionally and personally. Here's how we invest in you: Compensation and Financial Wellbeing Competitive base salary Matching pension scheme (up to 5%) from day one Discretionary company bonus scheme 4 x annual salary Death in Service coverage from day one Employee referral scheme Tech Scheme Health and Wellness Private medical insurance from day one Optical and dental cashback scheme app: access to remote GP's, second opinions, mental health support, and physiotherapy EAP service Cycle to work scheme Work Life balance and Growth 28 days annual leave (plus bank holidays) An extra paid day off for your birthday Ten paid learning days per year Flexible working hours Work from anywhere (up to 3 weeks per year) Industry recognised training and certifications Bonusly employee recognition and reward platform Clear opportunities for career progression Length of service awards Regular company events Diversity and Inclusion At Beyond we champion diversity and inclusion. We believe that a career in IT should be open to everyone, regardless of race, ethnicity, gender, age, sexual orientation, disability or neurotype. We value the unique talents and perspectives that each individual brings to our team, and we strive to create a fair and accessible hiring process for all.
Senior Security Engineer (GCP)
Bynd Limited Manchester, Lancashire
About the role We help regulated and enterprise customers protect their Google Cloud Estates. As a Premier Google Cloud Partner, we deliver Google Unified Security (GUS) engagements across the full stack - from greenfield SIEM/SOAR deployments and SOC modernisation programmes to detection engineering, posture management, threat hunting, and incident response uplift. Secure GCP estates with the adoption of CI/CD pipelines, secure landing zones and cloud posture reviews. Expertise when integrating third party tools such as Wiz. We're looking for a Senior Security Engineer with deep, hands on experience across the GCP and Google Security portfolio. You'll lead the technical work on customer engagements, build reusable content for the practice, and help customers deliver security solutions at scale. This is a hands on senior role. Most of your week is client delivery. The rest goes into our practice - accelerators, parsers, rule packs, playbooks, and points of view that make the next engagement faster than the last. What you'll do Google SecOps (SIEM / SOAR) Lead end to end SecOps deployments - tenant setup, multi tenant architecture, data ingestion, retention design, RBAC, and feed onboarding. Build and maintain parsers, UDM mappings, and data models for Google Cloud, AWS, Azure, endpoint, identity, and network sources. Write, test, and tune YARA L detection rules, including single event, multi event, and composite detections. Design SOAR playbooks and python integrations. Develop custom agents that can be deployed in customer environments using GCP infrastructure. GCP Configure CI/CD pipelines with integrated security tools. Configure GCP security solutions including Security Command Center Enterprise, IAP, VPC Service Controls, and Model Armor. Work with platform teams to support the deployment of secure cloud foundation blueprints. Support clients with secure AI workloads including the use of model armor and agent identities. Google Threat Intelligence Operationalise Google Threat Intelligence inside SecOps - IoC matching, Applied Threat Intelligence, and curated detections. Build threat informed defence programmes tied to customer specific threat profiles (sector, geography, adversary groups). Run threat hunting campaigns using GTI, Mandiant frontline intelligence, and UDM search. Validate detection coverage against MITRE ATT&CK using Mandiant Security Validation where in scope. Practice growth Mentor engineers and consultants; lead internal SecOps and GUS enablement. Represent the practice in pre sales, customer workshops, and Google partner forums. What we're looking for Essential Strong SIEM/SOC delivery experience (any major platform; Google SecOps / Chronicle preferred). Hands on with Google SecOps: UDM, YARA L, parsers, SOAR playbooks, data ingestion patterns. Solid grounding in Google Cloud security primitives: IAM, Organization Policies, VPC Service Controls, Cloud Logging, Cloud KMS. Comfortable with Terraform, CI/CD pipelines and at least one scripting language (Python, Go) for automation, parser development, and integration work. Experience supporting regulated workloads (financial services, public sector, healthcare) and translating compliance requirements into operational controls. Able to explain risk, trade offs, and findings to both SOC analysts and executive stakeholders. Nice to have Google Professional Cloud Security Engineer or Google SecOps certification. Prior SIEM migration experience (Splunk SecOps, Sentinel SecOps, etc.). Experience with adjacent tooling: Wiz, CrowdStrike, Splunk, Sentinel, Snyk. Consulting or systems integrator background. Contributions to open detection content (Sigma, MITRE, public rule repos). Benefits We believe in supporting our team members both professionally and personally. Here's how we invest in you: Compensation and Financial Wellbeing Competitive base salary Matching pension scheme (up to 5%) from day one Discretionary company bonus scheme 4 x annual salary Death in Service coverage from day one Employee referral scheme Tech Scheme Health and Wellness Private medical insurance from day one Optical and dental cashback scheme app: access to remote GP's, second opinions, mental health support, and physiotherapy EAP service Cycle to work scheme Work Life balance and Growth 28 days annual leave (plus bank holidays) An extra paid day off for your birthday Ten paid learning days per year Flexible working hours Work from anywhere (up to 3 weeks per year) Industry recognised training and certifications Bonusly employee recognition and reward platform Clear opportunities for career progression Length of service awards Regular company events Diversity and Inclusion At Beyond we champion diversity and inclusion. We believe that a career in IT should be open to everyone, regardless of race, ethnicity, gender, age, sexual orientation, disability or neurotype. We value the unique talents and perspectives that each individual brings to our team, and we strive to create a fair and accessible hiring process for all.
12/07/2026
Full time
About the role We help regulated and enterprise customers protect their Google Cloud Estates. As a Premier Google Cloud Partner, we deliver Google Unified Security (GUS) engagements across the full stack - from greenfield SIEM/SOAR deployments and SOC modernisation programmes to detection engineering, posture management, threat hunting, and incident response uplift. Secure GCP estates with the adoption of CI/CD pipelines, secure landing zones and cloud posture reviews. Expertise when integrating third party tools such as Wiz. We're looking for a Senior Security Engineer with deep, hands on experience across the GCP and Google Security portfolio. You'll lead the technical work on customer engagements, build reusable content for the practice, and help customers deliver security solutions at scale. This is a hands on senior role. Most of your week is client delivery. The rest goes into our practice - accelerators, parsers, rule packs, playbooks, and points of view that make the next engagement faster than the last. What you'll do Google SecOps (SIEM / SOAR) Lead end to end SecOps deployments - tenant setup, multi tenant architecture, data ingestion, retention design, RBAC, and feed onboarding. Build and maintain parsers, UDM mappings, and data models for Google Cloud, AWS, Azure, endpoint, identity, and network sources. Write, test, and tune YARA L detection rules, including single event, multi event, and composite detections. Design SOAR playbooks and python integrations. Develop custom agents that can be deployed in customer environments using GCP infrastructure. GCP Configure CI/CD pipelines with integrated security tools. Configure GCP security solutions including Security Command Center Enterprise, IAP, VPC Service Controls, and Model Armor. Work with platform teams to support the deployment of secure cloud foundation blueprints. Support clients with secure AI workloads including the use of model armor and agent identities. Google Threat Intelligence Operationalise Google Threat Intelligence inside SecOps - IoC matching, Applied Threat Intelligence, and curated detections. Build threat informed defence programmes tied to customer specific threat profiles (sector, geography, adversary groups). Run threat hunting campaigns using GTI, Mandiant frontline intelligence, and UDM search. Validate detection coverage against MITRE ATT&CK using Mandiant Security Validation where in scope. Practice growth Mentor engineers and consultants; lead internal SecOps and GUS enablement. Represent the practice in pre sales, customer workshops, and Google partner forums. What we're looking for Essential Strong SIEM/SOC delivery experience (any major platform; Google SecOps / Chronicle preferred). Hands on with Google SecOps: UDM, YARA L, parsers, SOAR playbooks, data ingestion patterns. Solid grounding in Google Cloud security primitives: IAM, Organization Policies, VPC Service Controls, Cloud Logging, Cloud KMS. Comfortable with Terraform, CI/CD pipelines and at least one scripting language (Python, Go) for automation, parser development, and integration work. Experience supporting regulated workloads (financial services, public sector, healthcare) and translating compliance requirements into operational controls. Able to explain risk, trade offs, and findings to both SOC analysts and executive stakeholders. Nice to have Google Professional Cloud Security Engineer or Google SecOps certification. Prior SIEM migration experience (Splunk SecOps, Sentinel SecOps, etc.). Experience with adjacent tooling: Wiz, CrowdStrike, Splunk, Sentinel, Snyk. Consulting or systems integrator background. Contributions to open detection content (Sigma, MITRE, public rule repos). Benefits We believe in supporting our team members both professionally and personally. Here's how we invest in you: Compensation and Financial Wellbeing Competitive base salary Matching pension scheme (up to 5%) from day one Discretionary company bonus scheme 4 x annual salary Death in Service coverage from day one Employee referral scheme Tech Scheme Health and Wellness Private medical insurance from day one Optical and dental cashback scheme app: access to remote GP's, second opinions, mental health support, and physiotherapy EAP service Cycle to work scheme Work Life balance and Growth 28 days annual leave (plus bank holidays) An extra paid day off for your birthday Ten paid learning days per year Flexible working hours Work from anywhere (up to 3 weeks per year) Industry recognised training and certifications Bonusly employee recognition and reward platform Clear opportunities for career progression Length of service awards Regular company events Diversity and Inclusion At Beyond we champion diversity and inclusion. We believe that a career in IT should be open to everyone, regardless of race, ethnicity, gender, age, sexual orientation, disability or neurotype. We value the unique talents and perspectives that each individual brings to our team, and we strive to create a fair and accessible hiring process for all.
Hastings Direct
Principal Security Engineer
Hastings Direct Leicester, Leicestershire
Principal Security Engineer page is loaded Principal Security Engineerlocations: Bexhill: Leicestertime type: Full timeposted on: Posted Todayjob requisition id: We're a digital insurance provider with ambitious plans to become The Best and Biggest in the UK market. Over the past few years, we've made significant investments in our data and tech capabilities, particularly within our CIO function. Our CIO team is at the forefront of driving innovation and ensuring our technology infrastructure supports our ambitious goals. We've nurtured our 4Cs culture, fostering collaboration, creativity, and continuous improvement.We're proud of the journey we're on as a company and know that our continued success will rely on the contribution of our talented colleagues. The CIO team plays a crucial role in this journey, working on cutting-edge projects that enhance our digital presence and improve customer engagement.We provide insurance to nearly four million customers, but we know there's even bigger opportunity out there. The fact you're now reading this job advert means we've tempted you to find out more about - we really hope you like what you see, and you'll join us to share in the success of the exciting chapter that lies ahead.We understand some people may not apply for jobs unless they feel they tick every box. If you are excited about joining us and think you have some of what we are looking for, even if you're not 100% sure, we would love to hear from you. Our CIO team is always looking for passionate individuals who are eager to make a difference and contribute to our success. Job Details Promote a culture where we re-use more which allows us to optimise workflow efficiency and reduce duplication. Guide and coach teams on good security engineering practices and process improvements, helping to build capability and maturity across the organisation. Supports the team in delivering outcomes efficiently, by reducing manual execution. Ensure fast, reliable feedback loops are in place to enable fail-fast delivery and continuous improvement. Define and implement best practices and controls, ensuring adherence and enabling early detection of issues. Drive engagement and collaboration across Scrum Teams and the CIO community, leading the definition and adoption of best practices to enable faster, secure and more reliable delivery. Skills we would love you to have Extensive practical experience in IT Security working in an agile environment. Transformational leadership skills being able to influence decision making and implement new processes and procedures in support of the company's vision. Excellent mentoring skills to support direct reports in their ongoing development Proven experience in designing, implementing, and securing cloud environments, with a strong emphasis on Microsoft Azure services. In-depth knowledge of cloud security best practices, network security, identity and access management, encryption, and secure coding principles. Excellent problem-solving skills and the ability to analyse complex security issues and develop effective solutions. Strong communication and collaboration skills, with the ability to work effectively in cross-functional teams. Track record of successfully designing, building, and deploying scalable, secure, and highly available security infrastructures using Azure. Strong proficiency in leveraging data and advanced analytics to drive decision-making and continuously enhance security solutions. Tools & Technologies: Proficient knowledge of at least on agile methodology (eg Scrum, Kanban, SAFe)Familiar with backlog and test case management in a system of record such as Jira or Octane Expert knowledge using Cloud Technologies Strong understanding of regulatory compliance requirements (e.g. GDPR, ISO 27001, NIST) and experience implementing security controls to meet those requirements. Hands-on experience with Azure Kubernetes Service (AKS) and microservices architecture. Familiarity with DevSecOps methodologies and tools, enabling the seamless integration of security into the development process. Proficiency in Microsoft Defender security assessment tools, vulnerability scanning tools, and SIEM platforms. In-depth understanding of the Microsoft ecosystem, including hands-on experience with Firewalls, IDS/IPS, Load Balancers, Applications Gateways, Proxies, M365, EDR, KQL. Expertise in utilizing Azure DevOps to drive efficient and collaborative development processes, including the development of security solutions and updates in code. Unfortunately, we are unable to progress with candidates that require sponsorship at this time What we offer Join us and you'll find a different way of doing things. We call it the 4Cs. We focus on getting it right for our colleagues, customers, company, and community. As one of our colleagues, you'll be helping to drive our growth, so in return, we'll give you all the support, training and development you need. Not to mention plenty of recognition and rewards, and the scope to voice your ideas and put them into practice. Reward Salary - Attractive salary based on experience + car allowance (pay reviews also completed each year) Flexible Working - We champion a flexible and hybrid working approach so please speak to your recruiter to discuss in more detail, including days in the office and at home. Competitive Bonus Scheme - All colleagues are eligible for our annual 4Cs performance bonus, which is usually paid in March. The scheme is based on Hastings' performance against our business goals and your own personal performance. Physical Wellbeing - as a Band 4 colleague, Hastings pay for you to receive private medical Insurance (also known as PMI) This gives you flexibility and convenience to see a specialist or consultant and allows you to decide when and where you will be seen. Financial Wellbeing - As well as providing you with 4x your salary with our life assurance cover and income protection at no extra cost, pension contribution match up to 10%, we are proud to provide you with an AWARD WINNING package which includes - discounts and cashback at everyday retailers and on our own products, fee free independent mortgage advice, and free access to financial wellbeing support. Mental Wellbeing programme - At Hastings Direct we understand that mental health cannot not be scheduled, that's why we have a range of support to help you keep yourself well. We have the thrive mental health app, our colleague assistance programme available 24/7, our own, in-house mental health first aiders, support groups and a dedicated team to make sure we are covering your needs There's more! - 27 days annual leave + bank holidays, with the option to buy or sell one of your contracted weeks, access to our health care cash back plans, dental plans, discounted health assessments, Cycle to work and tech schemes, discounted and free onsite facilities, social events throughout the year and much more Our 4Cs principles are simple: we believe by creating the right culture for our colleagues and giving them the right tools to do their job, we'll deliver good outcomes for every customer, helping us to grow the company profitably and sustainably and allowing us to invest in the communities we serve.We deliver good outcomes for our customers every time by providing great products at the right price with our simple and straightforward service. We treat customers like we want to be treated - fairly, respectfully and with their best interests at heart.Hastings Group is an equal opportunities employer which means we treat people fairly. We welcome applications from all suitably skilled persons regardless of their gender, age, race, disability, ethnic background, religion/belief, sexual orientation, gender reassignment or marital/family status. Please also
11/07/2026
Full time
Principal Security Engineer page is loaded Principal Security Engineerlocations: Bexhill: Leicestertime type: Full timeposted on: Posted Todayjob requisition id: We're a digital insurance provider with ambitious plans to become The Best and Biggest in the UK market. Over the past few years, we've made significant investments in our data and tech capabilities, particularly within our CIO function. Our CIO team is at the forefront of driving innovation and ensuring our technology infrastructure supports our ambitious goals. We've nurtured our 4Cs culture, fostering collaboration, creativity, and continuous improvement.We're proud of the journey we're on as a company and know that our continued success will rely on the contribution of our talented colleagues. The CIO team plays a crucial role in this journey, working on cutting-edge projects that enhance our digital presence and improve customer engagement.We provide insurance to nearly four million customers, but we know there's even bigger opportunity out there. The fact you're now reading this job advert means we've tempted you to find out more about - we really hope you like what you see, and you'll join us to share in the success of the exciting chapter that lies ahead.We understand some people may not apply for jobs unless they feel they tick every box. If you are excited about joining us and think you have some of what we are looking for, even if you're not 100% sure, we would love to hear from you. Our CIO team is always looking for passionate individuals who are eager to make a difference and contribute to our success. Job Details Promote a culture where we re-use more which allows us to optimise workflow efficiency and reduce duplication. Guide and coach teams on good security engineering practices and process improvements, helping to build capability and maturity across the organisation. Supports the team in delivering outcomes efficiently, by reducing manual execution. Ensure fast, reliable feedback loops are in place to enable fail-fast delivery and continuous improvement. Define and implement best practices and controls, ensuring adherence and enabling early detection of issues. Drive engagement and collaboration across Scrum Teams and the CIO community, leading the definition and adoption of best practices to enable faster, secure and more reliable delivery. Skills we would love you to have Extensive practical experience in IT Security working in an agile environment. Transformational leadership skills being able to influence decision making and implement new processes and procedures in support of the company's vision. Excellent mentoring skills to support direct reports in their ongoing development Proven experience in designing, implementing, and securing cloud environments, with a strong emphasis on Microsoft Azure services. In-depth knowledge of cloud security best practices, network security, identity and access management, encryption, and secure coding principles. Excellent problem-solving skills and the ability to analyse complex security issues and develop effective solutions. Strong communication and collaboration skills, with the ability to work effectively in cross-functional teams. Track record of successfully designing, building, and deploying scalable, secure, and highly available security infrastructures using Azure. Strong proficiency in leveraging data and advanced analytics to drive decision-making and continuously enhance security solutions. Tools & Technologies: Proficient knowledge of at least on agile methodology (eg Scrum, Kanban, SAFe)Familiar with backlog and test case management in a system of record such as Jira or Octane Expert knowledge using Cloud Technologies Strong understanding of regulatory compliance requirements (e.g. GDPR, ISO 27001, NIST) and experience implementing security controls to meet those requirements. Hands-on experience with Azure Kubernetes Service (AKS) and microservices architecture. Familiarity with DevSecOps methodologies and tools, enabling the seamless integration of security into the development process. Proficiency in Microsoft Defender security assessment tools, vulnerability scanning tools, and SIEM platforms. In-depth understanding of the Microsoft ecosystem, including hands-on experience with Firewalls, IDS/IPS, Load Balancers, Applications Gateways, Proxies, M365, EDR, KQL. Expertise in utilizing Azure DevOps to drive efficient and collaborative development processes, including the development of security solutions and updates in code. Unfortunately, we are unable to progress with candidates that require sponsorship at this time What we offer Join us and you'll find a different way of doing things. We call it the 4Cs. We focus on getting it right for our colleagues, customers, company, and community. As one of our colleagues, you'll be helping to drive our growth, so in return, we'll give you all the support, training and development you need. Not to mention plenty of recognition and rewards, and the scope to voice your ideas and put them into practice. Reward Salary - Attractive salary based on experience + car allowance (pay reviews also completed each year) Flexible Working - We champion a flexible and hybrid working approach so please speak to your recruiter to discuss in more detail, including days in the office and at home. Competitive Bonus Scheme - All colleagues are eligible for our annual 4Cs performance bonus, which is usually paid in March. The scheme is based on Hastings' performance against our business goals and your own personal performance. Physical Wellbeing - as a Band 4 colleague, Hastings pay for you to receive private medical Insurance (also known as PMI) This gives you flexibility and convenience to see a specialist or consultant and allows you to decide when and where you will be seen. Financial Wellbeing - As well as providing you with 4x your salary with our life assurance cover and income protection at no extra cost, pension contribution match up to 10%, we are proud to provide you with an AWARD WINNING package which includes - discounts and cashback at everyday retailers and on our own products, fee free independent mortgage advice, and free access to financial wellbeing support. Mental Wellbeing programme - At Hastings Direct we understand that mental health cannot not be scheduled, that's why we have a range of support to help you keep yourself well. We have the thrive mental health app, our colleague assistance programme available 24/7, our own, in-house mental health first aiders, support groups and a dedicated team to make sure we are covering your needs There's more! - 27 days annual leave + bank holidays, with the option to buy or sell one of your contracted weeks, access to our health care cash back plans, dental plans, discounted health assessments, Cycle to work and tech schemes, discounted and free onsite facilities, social events throughout the year and much more Our 4Cs principles are simple: we believe by creating the right culture for our colleagues and giving them the right tools to do their job, we'll deliver good outcomes for every customer, helping us to grow the company profitably and sustainably and allowing us to invest in the communities we serve.We deliver good outcomes for our customers every time by providing great products at the right price with our simple and straightforward service. We treat customers like we want to be treated - fairly, respectfully and with their best interests at heart.Hastings Group is an equal opportunities employer which means we treat people fairly. We welcome applications from all suitably skilled persons regardless of their gender, age, race, disability, ethnic background, religion/belief, sexual orientation, gender reassignment or marital/family status. Please also
VodafoneThree - Senior Cyber Engineer Farnborough, United Kingdom VBSE Managed Security Service ...
Vodafone Group Plc Farnborough, Hampshire
VodafoneThree - Senior Cyber EngineerFarnborough, United KingdomApply NowFind out how well you match with this jobRequisition ID286229Date posted07/07/2026 Location: Farnborough or Newbury (onsite) Salary: Excellent basic salary plus bonus and Vodafone benefits Working Hours: Full time 37.5 hours per week - Mon to Fri Who We Are We're here to build a network the UK can count on - one that connects people, places and potential. Because no matter where you live, what your background is, or how you get online - we think everyone deserves the same chance to stay connected, and with VodafoneThree, that future's being built - today. We're creating more than the UK's best network. We're helping close the digital divide, empower communities and drive meaningful progress. We believe that everyone should feel they belong. Whoever you are and whatever your story, there's space for you here. We're building a workplace where different perspectives are welcomed, voices are heard, and everyone feels safe to show up as themselves. You'll join a team that genuinely cares - about each other, about our customers, and about the future we're building. From day one, you'll be welcomed, valued and encouraged to bring your whole self to work. Why VodafoneThree Join us and you'll be at the heart of change. That means building responsibly, investing sustainably and creating opportunities that last. We're not just expanding connectivity; we're reimagining what a connected nation looks like. With £11bn invested in 5G and digital infrastructure, your work will directly power businesses, services, and communities across the country. You'll work on real challenges, with real impact, across every corner of the country. Wherever you join us, whatever your role, you'll be helping to build a future that works better for everyone. We move at pace, because what we're building matters - and we're learning as we go. We're proud of the progress we've made, but we're just getting started.Join Vodafone Business Security Enhanced and strengthen the cyber security of the UK's Critical National Infrastructure and public sector organisations. What you'll do To provide in-depth Cyber Security Architecture and Design for Vodafone and its customers. Provide support to a Cyber Security Engineering and SOC teams that provide Managed Security Services, including Protective Monitoring (SIEM), Managed Detection & Response services for both Vodafone and its customers. Implement and maintain SOC infrastructure - Analyst systems, SIEM, SOAR, Log/Event Collection systems and networks Support solutions consultant and pre-sales teams with customer bids Investigate threats and vulnerabilities affecting Vodafone Network/IT infrastructure Provide in-depth Network/IT support to SOC Analysts and other Cyber Defence, Security and Incident Response teams. Support customer deployments, on-boarding and user acceptance testing Who you are Experience of working as an IT/Network/Cyber Engineer, ideally in an telecoms/ISP environment (5yrs) In-depth knowledge of a wide range of Network and Security technologies, including Routers (Cisco, Juniper, Fortinet), Switches, Firewalls (ASA, SRX, Palo Alto), IDS/IPS (Cisco/Sourcefire) Strong background in IT systems administration, including Windows, Linux, VMWare In-depth understanding of Big Data, Database and Storage Technologies, e.g. SQL, Hadoop, Solr, Elastic Search Scripting - Python, Powershell Must be able to maintain DV security clearance Worried that you don't meet all the desired criteria exactly? We know that everyone is unique, with multiple aspects to their identity and different experiences behind them. We are passionate about Inclusion for All and creating a workplace where everyone can thrive, whatever their personal or professional background. If you're excited about this role but your experience doesn't align exactly with every part of the job description, we encourage you to apply as you may be the right candidate for this role or another role, and our recruitment team can help you see how your skills fit in. What we offer We care about our people's success by offering great pay, bonuses, up to 28 days off plus bank holidays, and paid time for charity work. You can personalise our benefits for you and your family, like discounts, vouchers, a pension plan and loads more. We help with your career through our amazing learning tools and top-notch parental leave policies. Need to Know We are regulated by the Financial Conduct Authority and all offers of employment for this role are subject to background checks, including criminal (DBS) and financial checks to meet the regulators standards. If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, a sign language interpreter, or assistive technology, please refer to the Accessibility section of our Careers website () for guidance. We use AI in different parts of our business to boost innovation, improve efficiency, and create new opportunities. We know many candidates use AI to fine-tune their CVs or prepare for interviews, but what we really care about is your unique experiences and achievements. During the interview, we want you to rely on your own knowledge and skills to show us who you really are-your personality, creativity, and abilities. Above all, we're looking for authenticity and can't wait to get to know the real you.
10/07/2026
Full time
VodafoneThree - Senior Cyber EngineerFarnborough, United KingdomApply NowFind out how well you match with this jobRequisition ID286229Date posted07/07/2026 Location: Farnborough or Newbury (onsite) Salary: Excellent basic salary plus bonus and Vodafone benefits Working Hours: Full time 37.5 hours per week - Mon to Fri Who We Are We're here to build a network the UK can count on - one that connects people, places and potential. Because no matter where you live, what your background is, or how you get online - we think everyone deserves the same chance to stay connected, and with VodafoneThree, that future's being built - today. We're creating more than the UK's best network. We're helping close the digital divide, empower communities and drive meaningful progress. We believe that everyone should feel they belong. Whoever you are and whatever your story, there's space for you here. We're building a workplace where different perspectives are welcomed, voices are heard, and everyone feels safe to show up as themselves. You'll join a team that genuinely cares - about each other, about our customers, and about the future we're building. From day one, you'll be welcomed, valued and encouraged to bring your whole self to work. Why VodafoneThree Join us and you'll be at the heart of change. That means building responsibly, investing sustainably and creating opportunities that last. We're not just expanding connectivity; we're reimagining what a connected nation looks like. With £11bn invested in 5G and digital infrastructure, your work will directly power businesses, services, and communities across the country. You'll work on real challenges, with real impact, across every corner of the country. Wherever you join us, whatever your role, you'll be helping to build a future that works better for everyone. We move at pace, because what we're building matters - and we're learning as we go. We're proud of the progress we've made, but we're just getting started.Join Vodafone Business Security Enhanced and strengthen the cyber security of the UK's Critical National Infrastructure and public sector organisations. What you'll do To provide in-depth Cyber Security Architecture and Design for Vodafone and its customers. Provide support to a Cyber Security Engineering and SOC teams that provide Managed Security Services, including Protective Monitoring (SIEM), Managed Detection & Response services for both Vodafone and its customers. Implement and maintain SOC infrastructure - Analyst systems, SIEM, SOAR, Log/Event Collection systems and networks Support solutions consultant and pre-sales teams with customer bids Investigate threats and vulnerabilities affecting Vodafone Network/IT infrastructure Provide in-depth Network/IT support to SOC Analysts and other Cyber Defence, Security and Incident Response teams. Support customer deployments, on-boarding and user acceptance testing Who you are Experience of working as an IT/Network/Cyber Engineer, ideally in an telecoms/ISP environment (5yrs) In-depth knowledge of a wide range of Network and Security technologies, including Routers (Cisco, Juniper, Fortinet), Switches, Firewalls (ASA, SRX, Palo Alto), IDS/IPS (Cisco/Sourcefire) Strong background in IT systems administration, including Windows, Linux, VMWare In-depth understanding of Big Data, Database and Storage Technologies, e.g. SQL, Hadoop, Solr, Elastic Search Scripting - Python, Powershell Must be able to maintain DV security clearance Worried that you don't meet all the desired criteria exactly? We know that everyone is unique, with multiple aspects to their identity and different experiences behind them. We are passionate about Inclusion for All and creating a workplace where everyone can thrive, whatever their personal or professional background. If you're excited about this role but your experience doesn't align exactly with every part of the job description, we encourage you to apply as you may be the right candidate for this role or another role, and our recruitment team can help you see how your skills fit in. What we offer We care about our people's success by offering great pay, bonuses, up to 28 days off plus bank holidays, and paid time for charity work. You can personalise our benefits for you and your family, like discounts, vouchers, a pension plan and loads more. We help with your career through our amazing learning tools and top-notch parental leave policies. Need to Know We are regulated by the Financial Conduct Authority and all offers of employment for this role are subject to background checks, including criminal (DBS) and financial checks to meet the regulators standards. If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, a sign language interpreter, or assistive technology, please refer to the Accessibility section of our Careers website () for guidance. We use AI in different parts of our business to boost innovation, improve efficiency, and create new opportunities. We know many candidates use AI to fine-tune their CVs or prepare for interviews, but what we really care about is your unique experiences and achievements. During the interview, we want you to rely on your own knowledge and skills to show us who you really are-your personality, creativity, and abilities. Above all, we're looking for authenticity and can't wait to get to know the real you.
VodafoneThree - Senior Cyber Engineer
Vodafone Group Plc Farnborough, Hampshire
Location: Farnborough or Newbury (onsite) Salary: Excellent basic salary plus bonus and Vodafone benefits Working Hours: Full time 37.5 hours per week - Mon to Fri We're here to build a network the UK can count on - one that connects people, places and potential. Because no matter where you live, what your background is, or how you get online - we think everyone deserves the same chance to stay connected, and with VodafoneThree, that future's being built - today. We're creating more than the UK's best network. We're helping close the digital divide, empower communities and drive meaningful progress. We believe that everyone should feel they belong. Whoever you are and whatever your story, there's space for you here. We're building a workplace where different perspectives are welcomed, voices are heard, and everyone feels safe to show up as themselves. You'll join a team that genuinely cares - about each other, about our customers, and about the future we're building. From day one, you'll be welcomed, valued and encouraged to bring your whole self to work. What you'll do Join Vodafone Business Security Enhanced and strengthen the cyber security of the UK's Critical National Infrastructure and public sector organisations. Provide in-depth Cyber Security Architecture and Design for Vodafone and its customers. Provide support to a Cyber Security Engineering and SOC teams that provide Managed Security Services, including Protective Monitoring (SIEM), Managed Detection & Response services for both Vodafone and its customers. Implement and maintain SOC infrastructure - Analyst systems, SIEM, SOAR, Log/Event Collection systems and networks. Support solutions consultant and pre sales teams with customer bids. Investigate threats and vulnerabilities affecting Vodafone Network/IT infrastructure. Provide in-depth Network/IT support to SOC Analysts and other Cyber Defence, Security and Incident Response teams. Support customer deployments, on boarding and user acceptance testing. Who you are Experience of working as an IT/Network/Cyber Engineer, ideally in a telecoms/ISP environment (5yrs). In-depth knowledge of a wide range of Network and Security technologies, including Routers (Cisco, Juniper, Fortinet), Switches, Firewalls (ASA, SRX, Palo Alto), IDS/IPS (Cisco/Sourcefire). Strong background in IT systems administration, including Windows, Linux, VMWare. In-depth understanding of Big Data, Database and Storage Technologies, e.g. SQL, Hadoop, Solr, Elastic Search. Scripting - Python, Powershell. Must be able to maintain DV security clearance. Worried that you don't meet all the desired criteria exactly? We know that everyone is unique, with multiple aspects to their identity and different experiences behind them. We are passionate about Inclusion for All and creating a workplace where everyone can thrive, whatever their personal or professional background. If you're excited about this role but your experience doesn't align exactly with every part of the job description, we encourage you to apply as you may be the right candidate for this role or another role, and our recruitment team can help you see how your skills fit in. What we offer We care about our people's success by offering great pay, bonuses, up to 28 days off plus bank holidays, and paid time for charity work. You can personalise our benefits for you and your family, like discounts, vouchers, a pension plan and loads more. We help with your career through our amazing learning tools and top notch parental leave policies. Need to Know We are regulated by the Financial Conduct Authority and all offers of employment for this role are subject to background checks, including criminal (DBS) and financial checks to meet the regulator's standards. We use AI in different parts of our business to boost innovation, improve efficiency, and create new opportunities. We know many candidates use AI to fine tune their CVs or prepare for interviews, but what we really care about is your unique experiences and achievements. During the interview, we want you to rely on your own knowledge and skills to show us who you really are-your personality, creativity, and abilities. Above all, we're looking for authenticity and can't wait to get to know the real you. If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, a sign language interpreter, or assistive technology, please refer to the Accessibility section of our Careers website () for guidance.
10/07/2026
Full time
Location: Farnborough or Newbury (onsite) Salary: Excellent basic salary plus bonus and Vodafone benefits Working Hours: Full time 37.5 hours per week - Mon to Fri We're here to build a network the UK can count on - one that connects people, places and potential. Because no matter where you live, what your background is, or how you get online - we think everyone deserves the same chance to stay connected, and with VodafoneThree, that future's being built - today. We're creating more than the UK's best network. We're helping close the digital divide, empower communities and drive meaningful progress. We believe that everyone should feel they belong. Whoever you are and whatever your story, there's space for you here. We're building a workplace where different perspectives are welcomed, voices are heard, and everyone feels safe to show up as themselves. You'll join a team that genuinely cares - about each other, about our customers, and about the future we're building. From day one, you'll be welcomed, valued and encouraged to bring your whole self to work. What you'll do Join Vodafone Business Security Enhanced and strengthen the cyber security of the UK's Critical National Infrastructure and public sector organisations. Provide in-depth Cyber Security Architecture and Design for Vodafone and its customers. Provide support to a Cyber Security Engineering and SOC teams that provide Managed Security Services, including Protective Monitoring (SIEM), Managed Detection & Response services for both Vodafone and its customers. Implement and maintain SOC infrastructure - Analyst systems, SIEM, SOAR, Log/Event Collection systems and networks. Support solutions consultant and pre sales teams with customer bids. Investigate threats and vulnerabilities affecting Vodafone Network/IT infrastructure. Provide in-depth Network/IT support to SOC Analysts and other Cyber Defence, Security and Incident Response teams. Support customer deployments, on boarding and user acceptance testing. Who you are Experience of working as an IT/Network/Cyber Engineer, ideally in a telecoms/ISP environment (5yrs). In-depth knowledge of a wide range of Network and Security technologies, including Routers (Cisco, Juniper, Fortinet), Switches, Firewalls (ASA, SRX, Palo Alto), IDS/IPS (Cisco/Sourcefire). Strong background in IT systems administration, including Windows, Linux, VMWare. In-depth understanding of Big Data, Database and Storage Technologies, e.g. SQL, Hadoop, Solr, Elastic Search. Scripting - Python, Powershell. Must be able to maintain DV security clearance. Worried that you don't meet all the desired criteria exactly? We know that everyone is unique, with multiple aspects to their identity and different experiences behind them. We are passionate about Inclusion for All and creating a workplace where everyone can thrive, whatever their personal or professional background. If you're excited about this role but your experience doesn't align exactly with every part of the job description, we encourage you to apply as you may be the right candidate for this role or another role, and our recruitment team can help you see how your skills fit in. What we offer We care about our people's success by offering great pay, bonuses, up to 28 days off plus bank holidays, and paid time for charity work. You can personalise our benefits for you and your family, like discounts, vouchers, a pension plan and loads more. We help with your career through our amazing learning tools and top notch parental leave policies. Need to Know We are regulated by the Financial Conduct Authority and all offers of employment for this role are subject to background checks, including criminal (DBS) and financial checks to meet the regulator's standards. We use AI in different parts of our business to boost innovation, improve efficiency, and create new opportunities. We know many candidates use AI to fine tune their CVs or prepare for interviews, but what we really care about is your unique experiences and achievements. During the interview, we want you to rely on your own knowledge and skills to show us who you really are-your personality, creativity, and abilities. Above all, we're looking for authenticity and can't wait to get to know the real you. If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, a sign language interpreter, or assistive technology, please refer to the Accessibility section of our Careers website () for guidance.
SOC Operations Technical Lead
Nettitude Group
Company: LRQA Job ID: 43649 Location: LRQA Nettitude: Birmingham: 1, Birmingham: 1 Trinity Park: Bi Position Category: Information Technology Position Type: Employee Regular Role objective The purpose of this role is to lead a team of SOC analysts, who are collectively operating on a 24/7/365 basis. Technical and client-oriented SOC Operations Technical Lead role plays a pivotal senior role within our Managed Security Services Provider (MSSP) environment. This role reports to Head of SOC Operations. This hands on position serves as the senior technical authority for SOC operations, driving excellence in threat detection, incident response, and security operations across a diverse multi client portfolio. You will combine deep technical proficiency with strong consulting skills to mentor analysts, manage shift rotations, optimise SOC processes and tools, lead complex incident escalations, and act as a trusted advisor. Although you will manage a team of SOC analysts, this is not a purely managerial role; you will remain deeply involved in technical work while elevating team capabilities and delivering strategic value to our clients. In this role you will be accountable for the effective functioning of your team, ensuring high performance standards while continuously developing their skills as part of a high trust, high performing security service. You will leverage your combined experience in leadership and security operations to enable the smooth delivery of our award winning defensive monitoring service, supporting proactive detection and response for clients across the globe. You will be expected to contribute, hands on, technically where and when needed, including deep dive investigations, incident response escalations, threat hunting, tuning detections, delivering technical training, and driving process and capability improvements. Strong technical knowledge is essential to mentor junior analysts, develop their capabilities, and ensure the team remains at the forefront of security operations. You must proactively initiate actions and work independently to quickly mitigate threats, set an example, maintain operational continuity, make informed decisions, and ensure team efficiency under pressure. The roles and responsibilities are reviewed annually to ensure alignment with current organisational needs, emerging threats, and industry best practice. Collaboration with other teams Work closely with Threat Intelligence, Engineering and Incident Response teams to strengthen the SOC's ability to detect, investigate, and respond to emerging threats. Drive continuous improvement within the SOC by identifying gaps in processes, detection capabilities, and team performance, and implementing solutions to enhance operational efficiency. Evaluate incidents and alerts to refine triage and response workflows, ensuring lessons learned are translated into updated playbooks and best practices. Monitor emerging threats, tune detections, and adopt new tools and techniques to strengthen the SOC's proactive defence posture. Team Leadership & Operations Oversight Lead day to day activities of the SOC analysts across all shifts (24/7 operations through on call rotation). Manage team scheduling, shift handovers, and always ensure proper coverage. Act as the first point of escalation for security events and staff queries during shifts. Aim to ensure high quality incident triage, investigation, and response by team members, following predefined agreed SOC processes. Coordinate with other shifts to maintain operational continuity and consistent processes. Lead and facilitate the development of the wider monitoring team through technical training courses, workshops and exercises. Ensure departmental objectives and projects are completed within specifications, deadlines and budgetary constraints. Ensure completion of all HALO case management on time and with accurate and timely results. Technical Leadership & Operations Excellence Provide technical leadership and guidance to SOC analysts on alert triage, investigation, threat hunting, and incident response. Function as the primary technical escalation point for complex, high severity or novel security alerts across multiple client environments. Drive continuous improvement of SOC processes, playbooks, detection rules, and automation to enhance efficiency, reduce false positives, and accelerate response times. Evaluate, recommend, and support the implementation and optimisation of SOC technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms) across heterogeneous client stacks. Develop and maintain advanced detection content, custom queries, correlation rules, and use cases tailored to client environments and emerging threats. Consulting & Client Engagement Serve as a trusted technical consultant to clients, participating in security reviews, root cause analyses, and recommendations for security posture improvements. Translate complex technical findings and recommendations into clear, actionable insights for both technical and executive client stakeholders. Mentor and coach SOC analysts, fostering technical growth, best practices, and a high performance culture. Conduct technical training sessions, knowledge sharing workshops, and skills assessments. Support performance management, including goal setting and feedback for direct or matrix team members. Strategic & Operational Contributions Identify opportunities to enhance MSSP service offerings through new capabilities, automation, or methodology improvements. Monitor industry trends, threat intelligence, and tool advancements to keep SOC operations at the cutting edge. Ensure compliance with SLAs, internal standards, and relevant regulatory requirements. Required Qualifications & Experience 7+ years of experience in Security Operations, with at least 3-4 years in a senior/lead technical role within a SOC (preferably in an MSSP or multi client environment). Strong hands on expertise with industry leading tools: SIEM platforms (Microsoft Sentinel, CrowdStrike) EDR/XDR solutions (CrowdStrike, Microsoft Defender, Carbon Black)SOAR, threat intelligence platforms, and network security tools. Proven experience in advanced threat hunting. Solid automation skills to improve SOC efficiency. Experience designing and tuning detection rules, use cases, and correlation logic in multi-tenant environments. Demonstrated consulting skills and ability to communicate effectively with clients, present findings, and provide strategic security advice. Preferred Qualifications Relevant certifications: CISSP, GIAC (GCIH, GCIA, GREM), SC 200, SC 300 or equivalent. Experience with cloud security operations environments. Background in professional services, consulting, or MSSP delivery. Familiarity with ITIL, NIST, ISO27001 or other security frameworks in a service provider context. Exceptional technical depth combined with the ability to explain complex concepts simply. Strong problem solving, analytical thinking, and decision-making under pressure. Excellent written and verbal communication skills, including client facing presentation abilities. Leadership presence with a collaborative, mentoring approach. Ability to manage multiple priorities and thrive in a fast paced, 24/7 MSSP environment.
09/07/2026
Full time
Company: LRQA Job ID: 43649 Location: LRQA Nettitude: Birmingham: 1, Birmingham: 1 Trinity Park: Bi Position Category: Information Technology Position Type: Employee Regular Role objective The purpose of this role is to lead a team of SOC analysts, who are collectively operating on a 24/7/365 basis. Technical and client-oriented SOC Operations Technical Lead role plays a pivotal senior role within our Managed Security Services Provider (MSSP) environment. This role reports to Head of SOC Operations. This hands on position serves as the senior technical authority for SOC operations, driving excellence in threat detection, incident response, and security operations across a diverse multi client portfolio. You will combine deep technical proficiency with strong consulting skills to mentor analysts, manage shift rotations, optimise SOC processes and tools, lead complex incident escalations, and act as a trusted advisor. Although you will manage a team of SOC analysts, this is not a purely managerial role; you will remain deeply involved in technical work while elevating team capabilities and delivering strategic value to our clients. In this role you will be accountable for the effective functioning of your team, ensuring high performance standards while continuously developing their skills as part of a high trust, high performing security service. You will leverage your combined experience in leadership and security operations to enable the smooth delivery of our award winning defensive monitoring service, supporting proactive detection and response for clients across the globe. You will be expected to contribute, hands on, technically where and when needed, including deep dive investigations, incident response escalations, threat hunting, tuning detections, delivering technical training, and driving process and capability improvements. Strong technical knowledge is essential to mentor junior analysts, develop their capabilities, and ensure the team remains at the forefront of security operations. You must proactively initiate actions and work independently to quickly mitigate threats, set an example, maintain operational continuity, make informed decisions, and ensure team efficiency under pressure. The roles and responsibilities are reviewed annually to ensure alignment with current organisational needs, emerging threats, and industry best practice. Collaboration with other teams Work closely with Threat Intelligence, Engineering and Incident Response teams to strengthen the SOC's ability to detect, investigate, and respond to emerging threats. Drive continuous improvement within the SOC by identifying gaps in processes, detection capabilities, and team performance, and implementing solutions to enhance operational efficiency. Evaluate incidents and alerts to refine triage and response workflows, ensuring lessons learned are translated into updated playbooks and best practices. Monitor emerging threats, tune detections, and adopt new tools and techniques to strengthen the SOC's proactive defence posture. Team Leadership & Operations Oversight Lead day to day activities of the SOC analysts across all shifts (24/7 operations through on call rotation). Manage team scheduling, shift handovers, and always ensure proper coverage. Act as the first point of escalation for security events and staff queries during shifts. Aim to ensure high quality incident triage, investigation, and response by team members, following predefined agreed SOC processes. Coordinate with other shifts to maintain operational continuity and consistent processes. Lead and facilitate the development of the wider monitoring team through technical training courses, workshops and exercises. Ensure departmental objectives and projects are completed within specifications, deadlines and budgetary constraints. Ensure completion of all HALO case management on time and with accurate and timely results. Technical Leadership & Operations Excellence Provide technical leadership and guidance to SOC analysts on alert triage, investigation, threat hunting, and incident response. Function as the primary technical escalation point for complex, high severity or novel security alerts across multiple client environments. Drive continuous improvement of SOC processes, playbooks, detection rules, and automation to enhance efficiency, reduce false positives, and accelerate response times. Evaluate, recommend, and support the implementation and optimisation of SOC technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms) across heterogeneous client stacks. Develop and maintain advanced detection content, custom queries, correlation rules, and use cases tailored to client environments and emerging threats. Consulting & Client Engagement Serve as a trusted technical consultant to clients, participating in security reviews, root cause analyses, and recommendations for security posture improvements. Translate complex technical findings and recommendations into clear, actionable insights for both technical and executive client stakeholders. Mentor and coach SOC analysts, fostering technical growth, best practices, and a high performance culture. Conduct technical training sessions, knowledge sharing workshops, and skills assessments. Support performance management, including goal setting and feedback for direct or matrix team members. Strategic & Operational Contributions Identify opportunities to enhance MSSP service offerings through new capabilities, automation, or methodology improvements. Monitor industry trends, threat intelligence, and tool advancements to keep SOC operations at the cutting edge. Ensure compliance with SLAs, internal standards, and relevant regulatory requirements. Required Qualifications & Experience 7+ years of experience in Security Operations, with at least 3-4 years in a senior/lead technical role within a SOC (preferably in an MSSP or multi client environment). Strong hands on expertise with industry leading tools: SIEM platforms (Microsoft Sentinel, CrowdStrike) EDR/XDR solutions (CrowdStrike, Microsoft Defender, Carbon Black)SOAR, threat intelligence platforms, and network security tools. Proven experience in advanced threat hunting. Solid automation skills to improve SOC efficiency. Experience designing and tuning detection rules, use cases, and correlation logic in multi-tenant environments. Demonstrated consulting skills and ability to communicate effectively with clients, present findings, and provide strategic security advice. Preferred Qualifications Relevant certifications: CISSP, GIAC (GCIH, GCIA, GREM), SC 200, SC 300 or equivalent. Experience with cloud security operations environments. Background in professional services, consulting, or MSSP delivery. Familiarity with ITIL, NIST, ISO27001 or other security frameworks in a service provider context. Exceptional technical depth combined with the ability to explain complex concepts simply. Strong problem solving, analytical thinking, and decision-making under pressure. Excellent written and verbal communication skills, including client facing presentation abilities. Leadership presence with a collaborative, mentoring approach. Ability to manage multiple priorities and thrive in a fast paced, 24/7 MSSP environment.
Application Security Engineer (London or Bristol)
HealthHero Services Ltd
Application Security Engineer (London or Bristol) We are HealthHero, Europe's largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe - giving you the chance to shape security at the heart of a fast-growing, AI driven business. We are recruiting an exciting Application Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent - based in either our London or Bristol office two days per week. About the role You will own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly. This role works closely with UK and France engineering teams. As an experienced Application Security Engineer, your working day will include but not be limited to: DevSecOps & Pipeline Security Implement and maintain security testing in GitLab CI pipelines Configure and tune SAST, DAST, dependency scanning, and secrets detection Build automated security gates that balance rigour with delivery velocity Enable self serve security tooling for development teams Contribute code and patches to security tooling and configurations Secure Development Define and enforce secure coding standards Conduct security focused code reviews and threat modelling for new features Provide remediation guidance for application vulnerabilities Train and support developers on secure coding practices Vulnerability Management Triage, patch and track application vulnerabilities through to remediation Manage dependency vulnerabilities and upgrade cycles Report on application security posture to senior leadership Risk & Compliance Embed GDPR and healthcare regulatory requirements into development processes Support DCB0129 clinical safety compliance for software changes Support customer security due diligence and audits Support ISO27001:2022 ISMS controls and audit process Key Skills and Experience Essential 3+ years in application security, DevSecOps, and secure software development Hands on experience with CI/CD security integration (GitLab CI or similar) Familiarity with SAST/DAST tooling and dependency scanning Understanding of common vulnerabilities (OWASP Top 10) and remediation Previous experience working as a back end or full stack developer Knowledge of GDPR and data protection legislation Strong communicator; able to translate security requirements for developers Desirable Development background with security focus Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel) Experience with CSPM tooling (Wiz, Prisma Cloud, or similar) Penetration testing or bug bounty experience Experience in regulated environments (healthcare, financial services) Familiarity with threat modelling frameworks (STRIDE, PASTA) About us We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. HealthHero is Europe's largest digital health provider, delivering 4 million consultations per year. But we're just getting started. We've built a seamless digital clinic that brings body and mind together - from GP appointments and mental health support to long term condition management. By sitting behind the world's leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it. We are a high growth, capital backed business with a sophisticated scale strategy. Our team is a unique blend of digital native pioneers, management consultants, creatives and industry leading clinical experts. We aren't just digitising appointments; we're building the next generation of healthcare. We're creating an AI powered, always on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts. Join us, and help build a next generation health system the world is waiting for. We're proud to be recognised as a Great Place to Work, which reflects our commitment to creating a supportive and engaging culture. We have also been featured as the fastest growing digital healthcare company of scale in the first Sunday Times 100 Tech list. This recognition shows our impact in the digital health sector and our dedication to innovation and excellence. Committed to achieving excellence in the delivery of person centred care, we invest in people, resources and technology to continuously improve the quality of its services and organisational culture. Why us? Our values guide us, every day we strive to Simplify, Own, Aspire and Respect (SOAR). and we're rewarded when we do. What we offer A full induction training programme, which will be undertaken via Microsoft Teams. An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic. 25 days leave. Bank Holidays and your birthday off as leave. Regular 1 2 1s with your line Manager. 24/7 on call staff support. Auto enrolment pension scheme. Health Scheme and access to our Employee Assistance Programme. Life Insurance Scheme. Apply If you are interested in making a difference and believe this role is a good fit for you, we would love to hear from you. If you have any questions, please contact our Recruitment Team at Hybrid: London or Bristol (There is a requirement to work in the office for a minimum of two days per week) Closing date for applications: Friday 29 May (5pm) Additional information We reserve the right to close this job in the event we receive a sufficient number of applications. Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer. Equality, Inclusivity and Diversity In line with our commitment to Equality, Inclusivity and Diversity, we welcome and encourage applications from all suitably qualified candidates from all backgrounds. We are committed to supporting and promoting equality and diversity and aim to establish an inclusive working environment. As such, we welcome diverse applications from candidates irrespective of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race (including colour, nationality, ethnic and national origin), religion or belief, sex, or sexual orientation. We are a certified Disability Confident Employer and is committed to affording equal opportunities for candidates with disabilities or special needs. Should you require any reasonable adjustments to be made at any part of your application process, please let us know by contacting us at Safeguarding Please see for information relating to our commitment to safeguarding.
08/07/2026
Full time
Application Security Engineer (London or Bristol) We are HealthHero, Europe's largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe - giving you the chance to shape security at the heart of a fast-growing, AI driven business. We are recruiting an exciting Application Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent - based in either our London or Bristol office two days per week. About the role You will own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly. This role works closely with UK and France engineering teams. As an experienced Application Security Engineer, your working day will include but not be limited to: DevSecOps & Pipeline Security Implement and maintain security testing in GitLab CI pipelines Configure and tune SAST, DAST, dependency scanning, and secrets detection Build automated security gates that balance rigour with delivery velocity Enable self serve security tooling for development teams Contribute code and patches to security tooling and configurations Secure Development Define and enforce secure coding standards Conduct security focused code reviews and threat modelling for new features Provide remediation guidance for application vulnerabilities Train and support developers on secure coding practices Vulnerability Management Triage, patch and track application vulnerabilities through to remediation Manage dependency vulnerabilities and upgrade cycles Report on application security posture to senior leadership Risk & Compliance Embed GDPR and healthcare regulatory requirements into development processes Support DCB0129 clinical safety compliance for software changes Support customer security due diligence and audits Support ISO27001:2022 ISMS controls and audit process Key Skills and Experience Essential 3+ years in application security, DevSecOps, and secure software development Hands on experience with CI/CD security integration (GitLab CI or similar) Familiarity with SAST/DAST tooling and dependency scanning Understanding of common vulnerabilities (OWASP Top 10) and remediation Previous experience working as a back end or full stack developer Knowledge of GDPR and data protection legislation Strong communicator; able to translate security requirements for developers Desirable Development background with security focus Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel) Experience with CSPM tooling (Wiz, Prisma Cloud, or similar) Penetration testing or bug bounty experience Experience in regulated environments (healthcare, financial services) Familiarity with threat modelling frameworks (STRIDE, PASTA) About us We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. HealthHero is Europe's largest digital health provider, delivering 4 million consultations per year. But we're just getting started. We've built a seamless digital clinic that brings body and mind together - from GP appointments and mental health support to long term condition management. By sitting behind the world's leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it. We are a high growth, capital backed business with a sophisticated scale strategy. Our team is a unique blend of digital native pioneers, management consultants, creatives and industry leading clinical experts. We aren't just digitising appointments; we're building the next generation of healthcare. We're creating an AI powered, always on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts. Join us, and help build a next generation health system the world is waiting for. We're proud to be recognised as a Great Place to Work, which reflects our commitment to creating a supportive and engaging culture. We have also been featured as the fastest growing digital healthcare company of scale in the first Sunday Times 100 Tech list. This recognition shows our impact in the digital health sector and our dedication to innovation and excellence. Committed to achieving excellence in the delivery of person centred care, we invest in people, resources and technology to continuously improve the quality of its services and organisational culture. Why us? Our values guide us, every day we strive to Simplify, Own, Aspire and Respect (SOAR). and we're rewarded when we do. What we offer A full induction training programme, which will be undertaken via Microsoft Teams. An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic. 25 days leave. Bank Holidays and your birthday off as leave. Regular 1 2 1s with your line Manager. 24/7 on call staff support. Auto enrolment pension scheme. Health Scheme and access to our Employee Assistance Programme. Life Insurance Scheme. Apply If you are interested in making a difference and believe this role is a good fit for you, we would love to hear from you. If you have any questions, please contact our Recruitment Team at Hybrid: London or Bristol (There is a requirement to work in the office for a minimum of two days per week) Closing date for applications: Friday 29 May (5pm) Additional information We reserve the right to close this job in the event we receive a sufficient number of applications. Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer. Equality, Inclusivity and Diversity In line with our commitment to Equality, Inclusivity and Diversity, we welcome and encourage applications from all suitably qualified candidates from all backgrounds. We are committed to supporting and promoting equality and diversity and aim to establish an inclusive working environment. As such, we welcome diverse applications from candidates irrespective of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race (including colour, nationality, ethnic and national origin), religion or belief, sex, or sexual orientation. We are a certified Disability Confident Employer and is committed to affording equal opportunities for candidates with disabilities or special needs. Should you require any reasonable adjustments to be made at any part of your application process, please let us know by contacting us at Safeguarding Please see for information relating to our commitment to safeguarding.
Senior Cloud Security Engineer (SecOps / GCP)
Beyond
About the role We help regulated and enterprise customers protect their Google Cloud Estates. As a Premier Google Cloud Partner, we deliver Google Unified Security (GUS) engagements across the full stack - from greenfield SIEM/SOAR deployments and SOC modernisation programmes to detection engineering, posture management, threat hunting, and incident response uplift. Secure GCP estates with the adoption of CI/CD pipelines, secure landing zones and cloud posture reviews. Expertise when integrating third party tools such as Wiz. We're looking for a Senior Security Engineer with deep, hands on experience across the GCP and Google Security portfolio. You'll lead the technical work on customer engagements, build reusable content for the practice, and help customers deliver security solutions at scale. This is a hands on senior role. Most of your week is client delivery. The rest goes into our practice - accelerators, parsers, rule packs, playbooks, and points of view that make the next engagement faster than the last. What you'll do Google SecOps (SIEM / SOAR) Lead end to end SecOps deployments - tenant setup, multi tenant architecture, data ingestion, retention design, RBAC, and feed onboarding. Build and maintain parsers, UDM mappings, and data models for Google Cloud, AWS, Azure, endpoint, identity, and network sources. Write, test, and tune YARA L detection rules, including single event, multi event, and composite detections. Design SOAR playbooks and python integrations. Develop custom agents that can be deployed in customer environments using GCP infrastructure. GCP Configure CI/CD pipelines with integrated security tools. Configure GCP security solutions including Security Command Center Enterprise, IAP, VPC Service Controls, and Model Armor. Work with platform teams to support the deployment of secure cloud foundation blueprints. Support clients with secure AI workloads including the use of model armor and agent identities. Google Threat Intelligence Operationalise Google Threat Intelligence inside SecOps - IoC matching, Applied Threat Intelligence, and curated detections. Build threat informed defence programmes tied to customer specific threat profiles (sector, geography, adversary groups). Run threat hunting campaigns using GTI, Mandiant frontline intelligence, and UDM search. Validate detection coverage against MITRE ATT&CK using Mandiant Security Validation where in scope. Practice growth Mentor engineers and consultants; lead internal SecOps and GUS enablement. Represent the practice in pre sales, customer workshops, and Google partner forums. What we're looking for Essential Strong SIEM/SOC delivery experience (any major platform; Google SecOps / Chronicle preferred). Hands on with Google SecOps: UDM, YARA L, parsers, SOAR playbooks, data ingestion patterns. Solid grounding in Google Cloud security primitives: IAM, Organization Policies, VPC Service Controls, Cloud Logging, Cloud KMS. Comfortable with Terraform, CI/CD pipelines and at least one scripting language (Python, Go) for automation, parser development, and integration work. Experience supporting regulated workloads (financial services, public sector, healthcare) and translating compliance requirements into operational controls. Able to explain risk, trade offs, and findings to both SOC analysts and executive stakeholders. Nice to have Google Professional Cloud Security Engineer or Google SecOps certification. Prior SIEM migration experience (Splunk SecOps, Sentinel SecOps, etc.). Experience with adjacent tooling: Wiz, CrowdStrike, Splunk, Sentinel, Snyk. Consulting or systems integrator background. Contributions to open detection content (Sigma, MITRE, public rule repos). Benefits We believe in supporting our team members both professionally and personally. Here's how we invest in you: Compensation and Financial Wellbeing Competitive base salary Matching pension scheme (up to 5%) from day one Discretionary company bonus scheme 4 x annual salary Death in Service coverage from day one Employee referral scheme Tech Scheme Health and Wellness Private medical insurance from day one Optical and dental cashback scheme app: access to remote GP's, second opinions, mental health support, and physiotherapy EAP service Cycle to work scheme Work Life balance and Growth 28 days annual leave (plus bank holidays) An extra paid day off for your birthday Ten paid learning days per year Flexible working hours Work from anywhere (up to 3 weeks per year) Industry recognised training and certifications Bonusly employee recognition and reward platform Clear opportunities for career progression Length of service awards Regular company events Diversity and Inclusion At Beyond we champion diversity and inclusion. We believe that a career in IT should be open to everyone, regardless of race, ethnicity, gender, age, sexual orientation, disability or neurotype. We value the unique talents and perspectives that each individual brings to our team, and we strive to create a fair and accessible hiring process for all.
07/07/2026
Full time
About the role We help regulated and enterprise customers protect their Google Cloud Estates. As a Premier Google Cloud Partner, we deliver Google Unified Security (GUS) engagements across the full stack - from greenfield SIEM/SOAR deployments and SOC modernisation programmes to detection engineering, posture management, threat hunting, and incident response uplift. Secure GCP estates with the adoption of CI/CD pipelines, secure landing zones and cloud posture reviews. Expertise when integrating third party tools such as Wiz. We're looking for a Senior Security Engineer with deep, hands on experience across the GCP and Google Security portfolio. You'll lead the technical work on customer engagements, build reusable content for the practice, and help customers deliver security solutions at scale. This is a hands on senior role. Most of your week is client delivery. The rest goes into our practice - accelerators, parsers, rule packs, playbooks, and points of view that make the next engagement faster than the last. What you'll do Google SecOps (SIEM / SOAR) Lead end to end SecOps deployments - tenant setup, multi tenant architecture, data ingestion, retention design, RBAC, and feed onboarding. Build and maintain parsers, UDM mappings, and data models for Google Cloud, AWS, Azure, endpoint, identity, and network sources. Write, test, and tune YARA L detection rules, including single event, multi event, and composite detections. Design SOAR playbooks and python integrations. Develop custom agents that can be deployed in customer environments using GCP infrastructure. GCP Configure CI/CD pipelines with integrated security tools. Configure GCP security solutions including Security Command Center Enterprise, IAP, VPC Service Controls, and Model Armor. Work with platform teams to support the deployment of secure cloud foundation blueprints. Support clients with secure AI workloads including the use of model armor and agent identities. Google Threat Intelligence Operationalise Google Threat Intelligence inside SecOps - IoC matching, Applied Threat Intelligence, and curated detections. Build threat informed defence programmes tied to customer specific threat profiles (sector, geography, adversary groups). Run threat hunting campaigns using GTI, Mandiant frontline intelligence, and UDM search. Validate detection coverage against MITRE ATT&CK using Mandiant Security Validation where in scope. Practice growth Mentor engineers and consultants; lead internal SecOps and GUS enablement. Represent the practice in pre sales, customer workshops, and Google partner forums. What we're looking for Essential Strong SIEM/SOC delivery experience (any major platform; Google SecOps / Chronicle preferred). Hands on with Google SecOps: UDM, YARA L, parsers, SOAR playbooks, data ingestion patterns. Solid grounding in Google Cloud security primitives: IAM, Organization Policies, VPC Service Controls, Cloud Logging, Cloud KMS. Comfortable with Terraform, CI/CD pipelines and at least one scripting language (Python, Go) for automation, parser development, and integration work. Experience supporting regulated workloads (financial services, public sector, healthcare) and translating compliance requirements into operational controls. Able to explain risk, trade offs, and findings to both SOC analysts and executive stakeholders. Nice to have Google Professional Cloud Security Engineer or Google SecOps certification. Prior SIEM migration experience (Splunk SecOps, Sentinel SecOps, etc.). Experience with adjacent tooling: Wiz, CrowdStrike, Splunk, Sentinel, Snyk. Consulting or systems integrator background. Contributions to open detection content (Sigma, MITRE, public rule repos). Benefits We believe in supporting our team members both professionally and personally. Here's how we invest in you: Compensation and Financial Wellbeing Competitive base salary Matching pension scheme (up to 5%) from day one Discretionary company bonus scheme 4 x annual salary Death in Service coverage from day one Employee referral scheme Tech Scheme Health and Wellness Private medical insurance from day one Optical and dental cashback scheme app: access to remote GP's, second opinions, mental health support, and physiotherapy EAP service Cycle to work scheme Work Life balance and Growth 28 days annual leave (plus bank holidays) An extra paid day off for your birthday Ten paid learning days per year Flexible working hours Work from anywhere (up to 3 weeks per year) Industry recognised training and certifications Bonusly employee recognition and reward platform Clear opportunities for career progression Length of service awards Regular company events Diversity and Inclusion At Beyond we champion diversity and inclusion. We believe that a career in IT should be open to everyone, regardless of race, ethnicity, gender, age, sexual orientation, disability or neurotype. We value the unique talents and perspectives that each individual brings to our team, and we strive to create a fair and accessible hiring process for all.
Focus Group
Senior SOC Analyst
Focus Group Manchester, Lancashire
Senior SOC Analyst UK - 3 days a week in our Manchester office (Suite B, Maple Court, M60 Office Park, Wynne Ave, Swinton, Clifton, Manchester, M27 8FF) £50-£55k (Dependent on experience) + benefits Focus Group is looking for a Senior SOC Analyst to play a key role within our Managed Security Services team. This is a dual focused position combining hands on technical expertise with day to day operational leadership, ensuring high quality delivery of managed detection and response services across a diverse customer base. You'll lead SOC operations, act as the escalation point for complex security incidents, and mentor junior analysts-driving both service excellence and team development. What you'll do Lead day to day SOC operations, ensuring effective triage, escalation, and communication workflows Act as the primary escalation point for complex security investigations and incidents Conduct advanced threat investigations across endpoints, networks, and cloud environments Perform proactive threat hunting and detection tuning to improve coverage and reduce noise Manage and mentor Tier 1-2 analysts, supporting development and technical growth Ensure ticket quality, SLA adherence, and high service standards across SOC operations Support onboarding of new customers into monitoring and detection platforms Collaborate with Cyber Security leadership to improve detection strategy and SOC maturity Analyse logs and security data to identify malicious or suspicious activity Develop and maintain playbooks, runbooks, and knowledge base content Produce clear, actionable incident reports for internal and customer stakeholders Engage directly with customers during escalations, incident reviews, and briefings Identify opportunities for automation, process improvement, and enhanced detection capabilities Stay up to date with emerging threats, attack techniques, and MITRE ATT&CK developments What you'll bring 4-6 years' experience in a SOC or MSSP environment at Tier 2-3 or Lead level Strong hands on experience with SIEM platforms (e.g. Microsoft Sentinel, Splunk, Elastic, LogPoint) Experience with EDR tools such as Microsoft Defender, SentinelOne, or Bitdefender Deep understanding of MITRE ATT&CK and modern threat detection methodologies Strong incident response, investigation, and log analysis capability across multiple data sources Ability to lead during high pressure incidents with calm, confident decision making Strong communication skills, including producing clear incident reports and updates Proven ability to mentor, coach, and support junior analysts Organised approach with the ability to manage multiple concurrent incidents Proactive mindset focused on continuous improvement and service optimisation Nice to have Certifications such as SC 200, GCIH, GCIA, Security+, or BTL1 Experience in an MSSP or multi customer environment Microsoft security stack experience (Defender XDR, Sentinel, M365 security) Knowledge of cloud security, email security, and vulnerability management Experience with KQL or other query languages Scripting skills (PowerShell, Python) Familiarity with SOAR and threat intelligence platforms Understanding of compliance frameworks (ISO 27001, NIST, Cyber Essentials) Future opportunities SOC Manager / Head of Security Operations Cyber Security Technical Lead Detection Engineering Lead Threat Intelligence LeadIncident Response Manager Security Consultant / Advisory
06/07/2026
Full time
Senior SOC Analyst UK - 3 days a week in our Manchester office (Suite B, Maple Court, M60 Office Park, Wynne Ave, Swinton, Clifton, Manchester, M27 8FF) £50-£55k (Dependent on experience) + benefits Focus Group is looking for a Senior SOC Analyst to play a key role within our Managed Security Services team. This is a dual focused position combining hands on technical expertise with day to day operational leadership, ensuring high quality delivery of managed detection and response services across a diverse customer base. You'll lead SOC operations, act as the escalation point for complex security incidents, and mentor junior analysts-driving both service excellence and team development. What you'll do Lead day to day SOC operations, ensuring effective triage, escalation, and communication workflows Act as the primary escalation point for complex security investigations and incidents Conduct advanced threat investigations across endpoints, networks, and cloud environments Perform proactive threat hunting and detection tuning to improve coverage and reduce noise Manage and mentor Tier 1-2 analysts, supporting development and technical growth Ensure ticket quality, SLA adherence, and high service standards across SOC operations Support onboarding of new customers into monitoring and detection platforms Collaborate with Cyber Security leadership to improve detection strategy and SOC maturity Analyse logs and security data to identify malicious or suspicious activity Develop and maintain playbooks, runbooks, and knowledge base content Produce clear, actionable incident reports for internal and customer stakeholders Engage directly with customers during escalations, incident reviews, and briefings Identify opportunities for automation, process improvement, and enhanced detection capabilities Stay up to date with emerging threats, attack techniques, and MITRE ATT&CK developments What you'll bring 4-6 years' experience in a SOC or MSSP environment at Tier 2-3 or Lead level Strong hands on experience with SIEM platforms (e.g. Microsoft Sentinel, Splunk, Elastic, LogPoint) Experience with EDR tools such as Microsoft Defender, SentinelOne, or Bitdefender Deep understanding of MITRE ATT&CK and modern threat detection methodologies Strong incident response, investigation, and log analysis capability across multiple data sources Ability to lead during high pressure incidents with calm, confident decision making Strong communication skills, including producing clear incident reports and updates Proven ability to mentor, coach, and support junior analysts Organised approach with the ability to manage multiple concurrent incidents Proactive mindset focused on continuous improvement and service optimisation Nice to have Certifications such as SC 200, GCIH, GCIA, Security+, or BTL1 Experience in an MSSP or multi customer environment Microsoft security stack experience (Defender XDR, Sentinel, M365 security) Knowledge of cloud security, email security, and vulnerability management Experience with KQL or other query languages Scripting skills (PowerShell, Python) Familiarity with SOAR and threat intelligence platforms Understanding of compliance frameworks (ISO 27001, NIST, Cyber Essentials) Future opportunities SOC Manager / Head of Security Operations Cyber Security Technical Lead Detection Engineering Lead Threat Intelligence LeadIncident Response Manager Security Consultant / Advisory
IBM
Consulting Senior SOC Analyst - Public Sector Professional Hursley, GB
IBM Hursley, Hampshire
At IBM Consulting UK FutureNow, you'll build a career at the forefront of hybrid cloud and AI, working with leading clients across the public and private sectors. You'll collaborate with top industry professionals, gain hands on experience with cutting edge technologies, and deliver solutions that create real business impact. From day one, you'll work on meaningful, high profile programmes that stretch your skills and accelerate your growth. We invest heavily in you-supporting continuous learning, in demand skills development, and long term career progression. You'll thrive in a flexible, inclusive environment that values curiosity, encourages reinvention, and recognises what makes you unique. We offer: Tools and policies to support your work-life balance from flexible working approaches, sabbatical programs, paid paternity leave, maternity leave and an innovative maternity returners scheme More traditional benefits, such as 25 days holiday (in addition to public holidays), private medical, dental & optical cover, online shopping discounts, an Employee Assistance Program, life assurance and a group pension plan through salary sacrifice. In this role, you'll work in one of our IBM Consulting Client Innovation Centers (Delivery Centers), where we deliver deep technical and industry expertise to a wide range of public and private sector clients around the world. Our delivery centers offer our clients locally based skills and technical expertise to drive innovation and adoption of new technology. Your role and responsibilities As a Technical Consultant specialising in Threat Detection, Response & Intelligence, you will support and lead the monitoring, detection, and initial response to cyber security threats within a 24 7 SOC consulting environment. You will play a key role in maintaining operational excellence on shift, supporting incident investigation, and ensuring consistent delivery of high-quality security operations across client environments. Working across SIEM platforms, security tooling, and incident response workflows, you will help ensure threats are identified, triaged, and escalated effectively, while contributing to the continuous improvement of SOC processes and capabilities. This is a hands on operational role with responsibility for incident leadership, team support, and quality assurance, alongside exposure to client environments and senior stakeholders. Key Responsibilities Monitor, triage, and investigate security alerts and incidents across a range of SIEM and security platforms Lead or support incident response activities, including: Containment coordination Escalation to relevant teams Act as a senior presence on shift, supporting Tier 1/2 analysts and ensuring smooth SOC operations Drive incident quality and consistency, ensuring playbooks and procedures are followed Support major incident initiation and coordination, including communication across technical and non-technical stakeholders Analyse security events and identify: Patterns Threat behaviours Opportunities for improvement Contribute to playbook development and refinement, improving SOC efficiency and response capability Work with detection and engineering teams to: Reduce false positives Support operational effectiveness Produce clear and structured incident reports and handovers Participate in shift handovers, retrospectives, and continuous improvement activities Support client interactions where required, providing updates and operational insights Required education None Preferred education Bachelor's Degree Required Professional and/or Technical Expertise Proven experience working in a SOC environment (L2 / L3 level) within a 24 7 operational setting Strong experience with SIEM platforms, such as: Microsoft Sentinel QRadar Splunk Elastic or similar Practical experience in: Incident triage and investigation Security event analysis Alert validation and escalation Understanding of: Incident response processes and workflows Exposure to security tooling, such as: EDR/XDR platforms Network security technologies Identity and access systems Ability to interpret logs and identify suspicious behaviour across: Networks Cloud environments Strong communication skills, with the ability to clearly articulate incidents and risks Experience working in client-facing or service-based environments This role is subject to pre employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personal Security Controls referred to as National Security Vetting (NVS) may apply; this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). Preferred Professional/Technical Expertise Experience acting as a shift lead or senior escalation point within a SOC Exposure to threat hunting or detection improvement activities Experience working with: MITRE ATT&CK Familiarity with SOAR platforms and automated response workflows Relevant certifications such as: SC-200 GCIH / GIAC Experience working in regulated or public sector environments Understanding of SOC performance metrics and continuous improvement approaches IBM is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, neurodivergence, age, or other characteristics protected by the applicable law. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
05/07/2026
Full time
At IBM Consulting UK FutureNow, you'll build a career at the forefront of hybrid cloud and AI, working with leading clients across the public and private sectors. You'll collaborate with top industry professionals, gain hands on experience with cutting edge technologies, and deliver solutions that create real business impact. From day one, you'll work on meaningful, high profile programmes that stretch your skills and accelerate your growth. We invest heavily in you-supporting continuous learning, in demand skills development, and long term career progression. You'll thrive in a flexible, inclusive environment that values curiosity, encourages reinvention, and recognises what makes you unique. We offer: Tools and policies to support your work-life balance from flexible working approaches, sabbatical programs, paid paternity leave, maternity leave and an innovative maternity returners scheme More traditional benefits, such as 25 days holiday (in addition to public holidays), private medical, dental & optical cover, online shopping discounts, an Employee Assistance Program, life assurance and a group pension plan through salary sacrifice. In this role, you'll work in one of our IBM Consulting Client Innovation Centers (Delivery Centers), where we deliver deep technical and industry expertise to a wide range of public and private sector clients around the world. Our delivery centers offer our clients locally based skills and technical expertise to drive innovation and adoption of new technology. Your role and responsibilities As a Technical Consultant specialising in Threat Detection, Response & Intelligence, you will support and lead the monitoring, detection, and initial response to cyber security threats within a 24 7 SOC consulting environment. You will play a key role in maintaining operational excellence on shift, supporting incident investigation, and ensuring consistent delivery of high-quality security operations across client environments. Working across SIEM platforms, security tooling, and incident response workflows, you will help ensure threats are identified, triaged, and escalated effectively, while contributing to the continuous improvement of SOC processes and capabilities. This is a hands on operational role with responsibility for incident leadership, team support, and quality assurance, alongside exposure to client environments and senior stakeholders. Key Responsibilities Monitor, triage, and investigate security alerts and incidents across a range of SIEM and security platforms Lead or support incident response activities, including: Containment coordination Escalation to relevant teams Act as a senior presence on shift, supporting Tier 1/2 analysts and ensuring smooth SOC operations Drive incident quality and consistency, ensuring playbooks and procedures are followed Support major incident initiation and coordination, including communication across technical and non-technical stakeholders Analyse security events and identify: Patterns Threat behaviours Opportunities for improvement Contribute to playbook development and refinement, improving SOC efficiency and response capability Work with detection and engineering teams to: Reduce false positives Support operational effectiveness Produce clear and structured incident reports and handovers Participate in shift handovers, retrospectives, and continuous improvement activities Support client interactions where required, providing updates and operational insights Required education None Preferred education Bachelor's Degree Required Professional and/or Technical Expertise Proven experience working in a SOC environment (L2 / L3 level) within a 24 7 operational setting Strong experience with SIEM platforms, such as: Microsoft Sentinel QRadar Splunk Elastic or similar Practical experience in: Incident triage and investigation Security event analysis Alert validation and escalation Understanding of: Incident response processes and workflows Exposure to security tooling, such as: EDR/XDR platforms Network security technologies Identity and access systems Ability to interpret logs and identify suspicious behaviour across: Networks Cloud environments Strong communication skills, with the ability to clearly articulate incidents and risks Experience working in client-facing or service-based environments This role is subject to pre employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personal Security Controls referred to as National Security Vetting (NVS) may apply; this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). Preferred Professional/Technical Expertise Experience acting as a shift lead or senior escalation point within a SOC Exposure to threat hunting or detection improvement activities Experience working with: MITRE ATT&CK Familiarity with SOAR platforms and automated response workflows Relevant certifications such as: SC-200 GCIH / GIAC Experience working in regulated or public sector environments Understanding of SOC performance metrics and continuous improvement approaches IBM is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, neurodivergence, age, or other characteristics protected by the applicable law. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
Senior Cyber Security Consultant
nxzen Global Solihull, West Midlands
Senior Cyber Security Consultant We are seeking a highly experienced Senior OT Security Consultant to lead and deliver complex security engagements across UK Energy & Utilities clients. This senior role will be responsible for shaping security strategy, leading technical delivery, influencing senior stakeholders, and mentoring consultants across IT/OT security domains. The ideal candidate brings deep OT/ICS expertise, an understanding of energy and utility sector regulations, strong consulting capability, and the ability to operate confidently at both technical and executive levels. The role ABOUT THE ROLE OT Security Advisory Leadership Lead OT and ICs security strategy development, maturity assessments, and architectural reviews. Advise senior client stakeholders on governance, risk, resilience, and regulatory obligations. Define OT security improvement roadmaps and investment cases. Technical OT / ICs Delivery Leadership Lead design and validation of secure OT architectures including segmentation, firewalls, DMZs, and remote access. Oversee OT vulnerability assessments, configuration reviews, and secure integration of ICs solutions. Provide senior guidance during OT cyber incidents including containment, forensics, and recovery. Regulatory & Compliance Expertise Interpret and apply NIS/NISR, Ofgem/Ofwat expectations, NCSC CAF and IEC62443 requirements. Support audit readiness, evidence collation, and remediation planning. Client Engagement & Delivery Excellence Own client relationships and act as senior point of escalation. Produce and review high-quality deliverables including designs, assessments, and reports. Lead proposals, pre sales activities and contribute to business development. Mentor and coach junior consultants. Responsibilities Essential Experience Extensive experience with OT, ICs, SCADA, DCS and industrial networking. Proven track record delivering and leading OT security engagements in Energy & Utilities. Expert understanding of ICs protocols (Modbus, DNP3, IEC 104, OPC/UA etc.). Significant experience designing and reviewing OT architectures using the Purdue Model. Strong familiarity with major OT/ICs vendors (Siemens, ABB, GE, Schneider Electric). Experience applying frameworks such as IEC62443, NIST CSF, NIST , NCSC CAF. Senior level stakeholder management experience. Certifications - Highly Desirable OT/ICs Security/Safety Certifications ISA/IEC 62443 Cybersecurity Expert GIAC: GRID, GICSP, GCIP TÜV Certified Cyber Security or Functional Safety (preferred) General Security Certifications CISSP, CISM, ISO 27001 Lead Implementer/Lead Auditor Engineering Certifications CCNA/CCNP or equivalent networking certification (optional) Personal Attributes Strategic thinker with ability to influence senior stakeholders. Strong analytical and problem solving capability. Excellent communication and documentation skills. Ability to work flexibly across industrial client environments. The candidate Nice to have Technical Leadership Skills Experience with OT IDS technologies (e.g. Claroty, Nozomi, Dragos). Knowledge of secure ICs engineering lifecycle and OT asset management. Experience leading OT penetration testing or red team style engagements. Understanding of IoT/IIoT integrations and cloud connected OT systems. Consulting & Leadership Skills Ability to translate complex OT risks into business aligned recommendations. Strong workshop facilitation and presentation capability. Ability to lead multidisciplinary teams and manage complex client programmes.
04/07/2026
Full time
Senior Cyber Security Consultant We are seeking a highly experienced Senior OT Security Consultant to lead and deliver complex security engagements across UK Energy & Utilities clients. This senior role will be responsible for shaping security strategy, leading technical delivery, influencing senior stakeholders, and mentoring consultants across IT/OT security domains. The ideal candidate brings deep OT/ICS expertise, an understanding of energy and utility sector regulations, strong consulting capability, and the ability to operate confidently at both technical and executive levels. The role ABOUT THE ROLE OT Security Advisory Leadership Lead OT and ICs security strategy development, maturity assessments, and architectural reviews. Advise senior client stakeholders on governance, risk, resilience, and regulatory obligations. Define OT security improvement roadmaps and investment cases. Technical OT / ICs Delivery Leadership Lead design and validation of secure OT architectures including segmentation, firewalls, DMZs, and remote access. Oversee OT vulnerability assessments, configuration reviews, and secure integration of ICs solutions. Provide senior guidance during OT cyber incidents including containment, forensics, and recovery. Regulatory & Compliance Expertise Interpret and apply NIS/NISR, Ofgem/Ofwat expectations, NCSC CAF and IEC62443 requirements. Support audit readiness, evidence collation, and remediation planning. Client Engagement & Delivery Excellence Own client relationships and act as senior point of escalation. Produce and review high-quality deliverables including designs, assessments, and reports. Lead proposals, pre sales activities and contribute to business development. Mentor and coach junior consultants. Responsibilities Essential Experience Extensive experience with OT, ICs, SCADA, DCS and industrial networking. Proven track record delivering and leading OT security engagements in Energy & Utilities. Expert understanding of ICs protocols (Modbus, DNP3, IEC 104, OPC/UA etc.). Significant experience designing and reviewing OT architectures using the Purdue Model. Strong familiarity with major OT/ICs vendors (Siemens, ABB, GE, Schneider Electric). Experience applying frameworks such as IEC62443, NIST CSF, NIST , NCSC CAF. Senior level stakeholder management experience. Certifications - Highly Desirable OT/ICs Security/Safety Certifications ISA/IEC 62443 Cybersecurity Expert GIAC: GRID, GICSP, GCIP TÜV Certified Cyber Security or Functional Safety (preferred) General Security Certifications CISSP, CISM, ISO 27001 Lead Implementer/Lead Auditor Engineering Certifications CCNA/CCNP or equivalent networking certification (optional) Personal Attributes Strategic thinker with ability to influence senior stakeholders. Strong analytical and problem solving capability. Excellent communication and documentation skills. Ability to work flexibly across industrial client environments. The candidate Nice to have Technical Leadership Skills Experience with OT IDS technologies (e.g. Claroty, Nozomi, Dragos). Knowledge of secure ICs engineering lifecycle and OT asset management. Experience leading OT penetration testing or red team style engagements. Understanding of IoT/IIoT integrations and cloud connected OT systems. Consulting & Leadership Skills Ability to translate complex OT risks into business aligned recommendations. Strong workshop facilitation and presentation capability. Ability to lead multidisciplinary teams and manage complex client programmes.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board