Alastair LLP, located in Greater London, seeks a skilled individual for a cyber security position tackling complex security incidents. The ideal candidate will possess significant experience in cyber incident response and cloud security expertise across AWS and Azure. The role includes responsibilities such as mentoring junior analysts, developing automation workflows, and participating in threat detection. Benefits include competitive compensation, annual leave, and comprehensive healthcare.
28/07/2026
Full time
Alastair LLP, located in Greater London, seeks a skilled individual for a cyber security position tackling complex security incidents. The ideal candidate will possess significant experience in cyber incident response and cloud security expertise across AWS and Azure. The role includes responsibilities such as mentoring junior analysts, developing automation workflows, and participating in threat detection. Benefits include competitive compensation, annual leave, and comprehensive healthcare.
Overview This is a hands on security position within the Information Security group, focused on ensuring consistent, measurable end to end delivery of security services. The successful candidate will develop and deploy capabilities that protect enterprise systems and data through the necessary security controls and tools, supporting a fast paced, technology forward environment that includes early adoption of cloud services. Responsibilities Support a Technology Vendor Management program, ensuring technology risk reviews across multiple disciplines, monitoring renewals and savings opportunities. Participate in risk reviews of the IT control framework (NIST CSF, CIS, ITIL, ISO 270001, etc.). Conduct thorough vendor, product and application security assessments in partnership with systems owners to integrate security early during the project lifecycle. Partner with business groups to review workflows, producing output to enhance security processes in support of those workflows. Coordinate, across service owners, the implementation of core security integrations (SSO, event logs, secrets, alerting, threat modeling and backup/recovery) with applications developed in house and in externally/SaaS hosted environments. Ensure the security considerations identified are implemented and solutions are configured securely. Coordinate with IRM leadership to develop and deliver key security metrics, ensuring technical security controls meet desired objectives and demonstrating measurable effectiveness. Qualifications At least 3+ years' experience in Information Technology. At least 2 years' experience in cybersecurity risk management. Bachelor's or master's degree in a relevant field. Strong analytical skills in conducting due diligence to identify, assess and prioritise vendor risks. Familiarity with information security frameworks (NIST, ISO27001), data privacy regulations (GDPR, CCPA), and information security certifications (SOC, ISO, PCIDSS, FedRAMP). Experience coordinating technical integrations for security tooling and processes. Ability to review complex systems architectures to identify key security integration opportunities. Produce comprehensive written security assessments of vendor security postures. Experience using security analytics tooling to produce operational metrics and dashboards. Strong understanding of the fundamental operations of servers, operating systems, cloud applications and infrastructure. Core skills in cybersecurity fundamentals and third party risk management. Familiarity with third party risk management tools/processes such as One Trust, SIG or similar GRC platforms. Hands on experience in Azure, AWS cloud environments and familiarity with core cloud services and architecture. Familiarity with core security concepts of single sign on (e.g., PingFed, SAML), identity and access administration (Active Directory, Azure AD, AWS IAM), event management (Splunk). Expertise in Microsoft Office suite and JIRA. Equal Opportunity Employer Creative Artists Agency ("CAA") is committed to promoting equal opportunities in employment and creating a workplace culture in which diversity and inclusion is valued and everyone is treated with dignity and respect. As part of its zero tolerance approach to discrimination in any form, applicants will receive equal treatment regardless of age, disability, gender reassignment, marital or civil partner status, pregnancy or maternity, race, colour, nationality, ethnic or national origin, religion or belief, sex or sexual orientation, or any other legally recognised protected basis under UK law.
28/07/2026
Full time
Overview This is a hands on security position within the Information Security group, focused on ensuring consistent, measurable end to end delivery of security services. The successful candidate will develop and deploy capabilities that protect enterprise systems and data through the necessary security controls and tools, supporting a fast paced, technology forward environment that includes early adoption of cloud services. Responsibilities Support a Technology Vendor Management program, ensuring technology risk reviews across multiple disciplines, monitoring renewals and savings opportunities. Participate in risk reviews of the IT control framework (NIST CSF, CIS, ITIL, ISO 270001, etc.). Conduct thorough vendor, product and application security assessments in partnership with systems owners to integrate security early during the project lifecycle. Partner with business groups to review workflows, producing output to enhance security processes in support of those workflows. Coordinate, across service owners, the implementation of core security integrations (SSO, event logs, secrets, alerting, threat modeling and backup/recovery) with applications developed in house and in externally/SaaS hosted environments. Ensure the security considerations identified are implemented and solutions are configured securely. Coordinate with IRM leadership to develop and deliver key security metrics, ensuring technical security controls meet desired objectives and demonstrating measurable effectiveness. Qualifications At least 3+ years' experience in Information Technology. At least 2 years' experience in cybersecurity risk management. Bachelor's or master's degree in a relevant field. Strong analytical skills in conducting due diligence to identify, assess and prioritise vendor risks. Familiarity with information security frameworks (NIST, ISO27001), data privacy regulations (GDPR, CCPA), and information security certifications (SOC, ISO, PCIDSS, FedRAMP). Experience coordinating technical integrations for security tooling and processes. Ability to review complex systems architectures to identify key security integration opportunities. Produce comprehensive written security assessments of vendor security postures. Experience using security analytics tooling to produce operational metrics and dashboards. Strong understanding of the fundamental operations of servers, operating systems, cloud applications and infrastructure. Core skills in cybersecurity fundamentals and third party risk management. Familiarity with third party risk management tools/processes such as One Trust, SIG or similar GRC platforms. Hands on experience in Azure, AWS cloud environments and familiarity with core cloud services and architecture. Familiarity with core security concepts of single sign on (e.g., PingFed, SAML), identity and access administration (Active Directory, Azure AD, AWS IAM), event management (Splunk). Expertise in Microsoft Office suite and JIRA. Equal Opportunity Employer Creative Artists Agency ("CAA") is committed to promoting equal opportunities in employment and creating a workplace culture in which diversity and inclusion is valued and everyone is treated with dignity and respect. As part of its zero tolerance approach to discrimination in any form, applicants will receive equal treatment regardless of age, disability, gender reassignment, marital or civil partner status, pregnancy or maternity, race, colour, nationality, ethnic or national origin, religion or belief, sex or sexual orientation, or any other legally recognised protected basis under UK law.
Launch Your IT Career with Belfast City Council Assistant Digital Analyst Cloud Services & Server Administration Cyber Security Wage 17.18 per hour Belfast City Council is looking for motivated, curious and customer-focused Assistant Digital Analysts to join our Digital Services team. Whether your passion lies in Cyber Security or Cloud Services & Server Administration, this is an exciting opportunity to develop your technical expertise while helping deliver the digital services that thousands of people rely on every day. What You'll Be Doing As an Assistant Digital Analyst, you'll play a key role in supporting the Council's digital infrastructure and ensuring our technology services remain secure, reliable and efficient. Depending on your placement, you'll work within either: Cloud Services & Server Administration Support physical and virtual server infrastructure Administer operating systems and backup environments Help maintain both on-premise and cloud-hosted services Monitor, troubleshoot and optimise critical systems Contribute to infrastructure improvements and future technology projects Cyber Security Support enterprise security systems and technologies Assist in managing firewalls and security applications Help protect Council systems against cyber threats Monitor security alerts and investigate potential incidents Contribute to maintaining a secure digital environment across the organisation Essential Requirements You must have: Five GCSEs (Grades A-C), including English (or equivalent) AND EITHER Successfully completed an ICT training and development programme designed to prepare candidates for a career in Information Technology OR At least one year's relevant experience in Information Systems or Information Technology. Desirable Experience Applications will be particularly welcomed from candidates with experience in: Server Administration Server configuration and support Hardware support Operating systems Backup technologies Cloud infrastructure Cyber Security Security administration Firewalls Endpoint security Cyber security technologies Security monitoring A relevant third-level IT qualification is also desirable. Apply today and help shape the future of digital services at Belfast City Council.
28/07/2026
Seasonal
Launch Your IT Career with Belfast City Council Assistant Digital Analyst Cloud Services & Server Administration Cyber Security Wage 17.18 per hour Belfast City Council is looking for motivated, curious and customer-focused Assistant Digital Analysts to join our Digital Services team. Whether your passion lies in Cyber Security or Cloud Services & Server Administration, this is an exciting opportunity to develop your technical expertise while helping deliver the digital services that thousands of people rely on every day. What You'll Be Doing As an Assistant Digital Analyst, you'll play a key role in supporting the Council's digital infrastructure and ensuring our technology services remain secure, reliable and efficient. Depending on your placement, you'll work within either: Cloud Services & Server Administration Support physical and virtual server infrastructure Administer operating systems and backup environments Help maintain both on-premise and cloud-hosted services Monitor, troubleshoot and optimise critical systems Contribute to infrastructure improvements and future technology projects Cyber Security Support enterprise security systems and technologies Assist in managing firewalls and security applications Help protect Council systems against cyber threats Monitor security alerts and investigate potential incidents Contribute to maintaining a secure digital environment across the organisation Essential Requirements You must have: Five GCSEs (Grades A-C), including English (or equivalent) AND EITHER Successfully completed an ICT training and development programme designed to prepare candidates for a career in Information Technology OR At least one year's relevant experience in Information Systems or Information Technology. Desirable Experience Applications will be particularly welcomed from candidates with experience in: Server Administration Server configuration and support Hardware support Operating systems Backup technologies Cloud infrastructure Cyber Security Security administration Firewalls Endpoint security Cyber security technologies Security monitoring A relevant third-level IT qualification is also desirable. Apply today and help shape the future of digital services at Belfast City Council.
Role Overview Information Security is responsible for the stability, maturity, and continuous improvement of the firm's operational security and privacy controls. This includes leading the monitoring, detection, response, and management of cyber and data related risks while ensuring compliance with UK GDPR, industry standards (ISO27001), and client expectations. The role plays a key role in the operational management of security and privacy risk across the firm's technology environment and works with third party service providers to ensure effective threat detection, incident response, data protection controls, and operational workflows for GDPR compliance. It is a hands on technical role requiring strong analytical skills, attention to detail, and a proactive mindset. The ideal candidate will have practical experience with Microsoft security and compliance technologies, an interest in learning advanced detection and automation techniques, and a desire to contribute to a growing, high performing security operations capability. Key Responsibilities Monitor security event identification via the third party security operations service. Triage, analyse, and investigate incidents to validate potential threats, anomalies, or policy violations. Coordinate incident response activities including containment, evidence collection, documentation, and recovery support. Contribute to threat hunting activities using KQL queries and intelligence led techniques. Maintain accurate incident records, ensuring actions and outcomes are logged to a high standard. Facilitate security testing and awareness through threat simulations. Support the triage and processing of data subject rights (DSR) requests, including subject access requests (SARs). Conduct data discovery and collection across systems, ensuring completeness and accuracy. Support DPIA processes through data mapping, evidence gathering, and risk assessment input. Help maintain and tune Microsoft Defender, Sentinel, and Purview policies, analytics rules, alerts, and workflows. Support the development, testing, and maintenance of automated playbooks and response actions (e.g., Logic Apps). Verify compliance with expected practice in the operation of technology services, including security baseline and access right reviews. Support vulnerability management by tracking remediation, validating fixes, and assisting with reporting. Gather and analyse data to help identify trends, gaps, and areas for control improvement. Assist with periodic control reviews, audits, and compliance checks as required. Prepare operational reports, dashboards, and metrics for the Team Lead and wider stakeholders. Develop and maintain playbooks, runbooks, and procedural documentation. Contribute to continuous improvement activities, including identifying opportunities to streamline operations. Ensure all actions adhere to internal policies, regulatory requirements, and industry best practice. Essential Qualifications and Experience 3+ years' experience working in a security operations, IT security, privacy operations, or related technical role. Familiarity with Microsoft Defender XDR, Microsoft Sentinel (SIEM/SOAR), Privacy Management Solutions (e.g., Purview, OneTrust). Basic understanding of key cybersecurity and privacy concepts, such as threat detection and analysis, incident response lifecycle, vulnerability and exposure management, data privacy principles and data subject rights. Experience analysing logs, alerts, or data from security tools. Strong documentation, investigation, and analytical skills. Desirable Qualifications and Experience Hands on experience writing KQL queries, PowerShell, or CLI commands. Exposure to automation or playbooks (Logic Apps, Defender workflows). Knowledge of frameworks such as MITRE ATT&CK or NIST CSF. Relevant certifications such as SC 900, SC 200 (or working toward), AZ 900, AZ 500, CISSP, CIPP/E, CompTIA Security+, Foundation level data privacy certifications (e.g., BCS Certificate in Data Protection). Key Skills and Attributes Strong problem solving ability and attention to detail. Curious and proactive mindset with willingness to learn. Effective communicator able to document findings clearly and concisely. Highly organised and able to manage multiple tasks with competing priorities. Collaborative team player with a commitment to continuous improvement. Ability to work with sensitive data responsibly and confidentially.
27/07/2026
Full time
Role Overview Information Security is responsible for the stability, maturity, and continuous improvement of the firm's operational security and privacy controls. This includes leading the monitoring, detection, response, and management of cyber and data related risks while ensuring compliance with UK GDPR, industry standards (ISO27001), and client expectations. The role plays a key role in the operational management of security and privacy risk across the firm's technology environment and works with third party service providers to ensure effective threat detection, incident response, data protection controls, and operational workflows for GDPR compliance. It is a hands on technical role requiring strong analytical skills, attention to detail, and a proactive mindset. The ideal candidate will have practical experience with Microsoft security and compliance technologies, an interest in learning advanced detection and automation techniques, and a desire to contribute to a growing, high performing security operations capability. Key Responsibilities Monitor security event identification via the third party security operations service. Triage, analyse, and investigate incidents to validate potential threats, anomalies, or policy violations. Coordinate incident response activities including containment, evidence collection, documentation, and recovery support. Contribute to threat hunting activities using KQL queries and intelligence led techniques. Maintain accurate incident records, ensuring actions and outcomes are logged to a high standard. Facilitate security testing and awareness through threat simulations. Support the triage and processing of data subject rights (DSR) requests, including subject access requests (SARs). Conduct data discovery and collection across systems, ensuring completeness and accuracy. Support DPIA processes through data mapping, evidence gathering, and risk assessment input. Help maintain and tune Microsoft Defender, Sentinel, and Purview policies, analytics rules, alerts, and workflows. Support the development, testing, and maintenance of automated playbooks and response actions (e.g., Logic Apps). Verify compliance with expected practice in the operation of technology services, including security baseline and access right reviews. Support vulnerability management by tracking remediation, validating fixes, and assisting with reporting. Gather and analyse data to help identify trends, gaps, and areas for control improvement. Assist with periodic control reviews, audits, and compliance checks as required. Prepare operational reports, dashboards, and metrics for the Team Lead and wider stakeholders. Develop and maintain playbooks, runbooks, and procedural documentation. Contribute to continuous improvement activities, including identifying opportunities to streamline operations. Ensure all actions adhere to internal policies, regulatory requirements, and industry best practice. Essential Qualifications and Experience 3+ years' experience working in a security operations, IT security, privacy operations, or related technical role. Familiarity with Microsoft Defender XDR, Microsoft Sentinel (SIEM/SOAR), Privacy Management Solutions (e.g., Purview, OneTrust). Basic understanding of key cybersecurity and privacy concepts, such as threat detection and analysis, incident response lifecycle, vulnerability and exposure management, data privacy principles and data subject rights. Experience analysing logs, alerts, or data from security tools. Strong documentation, investigation, and analytical skills. Desirable Qualifications and Experience Hands on experience writing KQL queries, PowerShell, or CLI commands. Exposure to automation or playbooks (Logic Apps, Defender workflows). Knowledge of frameworks such as MITRE ATT&CK or NIST CSF. Relevant certifications such as SC 900, SC 200 (or working toward), AZ 900, AZ 500, CISSP, CIPP/E, CompTIA Security+, Foundation level data privacy certifications (e.g., BCS Certificate in Data Protection). Key Skills and Attributes Strong problem solving ability and attention to detail. Curious and proactive mindset with willingness to learn. Effective communicator able to document findings clearly and concisely. Highly organised and able to manage multiple tasks with competing priorities. Collaborative team player with a commitment to continuous improvement. Ability to work with sensitive data responsibly and confidentially.
As a Product Manager in Cybersecurity & Technology Controls, you will lead the end-to-end product lifecycle for a blockchain detection and prevention capability serving our SOC. You will translate SOC needs into a prioritized roadmap and backlog, partner closely with engineering and threat SMEs, and ensure detections are accurate, explainable, and operationally effective. Success means improving time-to-detect and time-to-respond while managing false positives and meeting reliability and resiliency expectations. Job Responsibilities Define product vision, strategy, and roadmap for SOC-focused blockchain detection and prevention Lead discovery with SOC analysts and incident responders: workflows, pain points, alert usability, escalation paths, and runbooks Own and refine the backlog: detection use cases, requirements, acceptance criteria, and prioritization tradeoffs Partner with engineering/threat teams to deliver end-to-end capability: signal ingestion, enrichment, alerting, triage experience, and response automation where appropriate Establish and track success metrics (e.g., precision/false positive rate, coverage, latency, time-to-detect/time-to-respond, alert volume, reliability/SLA) and drive continuous improvement Drive launch readiness: documentation, training, operational handoffs, and feedback loops with the SOC Required Qualifications, Capabilities, and Skills Product management experience delivering security detections, SOC tooling, or data/analytics products Strong understanding of SOC operations (alert lifecycle, triage, escalations, incident response) Background in blockchain fundamentals and common threat patterns/abuse cases Ability to use data to prioritize, measure detection efficacy, and manage false positives Preferred Experience with SIEM/SOAR and detection engineering programs Experience operating in a highly matrixed, complex organization
27/07/2026
Full time
As a Product Manager in Cybersecurity & Technology Controls, you will lead the end-to-end product lifecycle for a blockchain detection and prevention capability serving our SOC. You will translate SOC needs into a prioritized roadmap and backlog, partner closely with engineering and threat SMEs, and ensure detections are accurate, explainable, and operationally effective. Success means improving time-to-detect and time-to-respond while managing false positives and meeting reliability and resiliency expectations. Job Responsibilities Define product vision, strategy, and roadmap for SOC-focused blockchain detection and prevention Lead discovery with SOC analysts and incident responders: workflows, pain points, alert usability, escalation paths, and runbooks Own and refine the backlog: detection use cases, requirements, acceptance criteria, and prioritization tradeoffs Partner with engineering/threat teams to deliver end-to-end capability: signal ingestion, enrichment, alerting, triage experience, and response automation where appropriate Establish and track success metrics (e.g., precision/false positive rate, coverage, latency, time-to-detect/time-to-respond, alert volume, reliability/SLA) and drive continuous improvement Drive launch readiness: documentation, training, operational handoffs, and feedback loops with the SOC Required Qualifications, Capabilities, and Skills Product management experience delivering security detections, SOC tooling, or data/analytics products Strong understanding of SOC operations (alert lifecycle, triage, escalations, incident response) Background in blockchain fundamentals and common threat patterns/abuse cases Ability to use data to prioritize, measure detection efficacy, and manage false positives Preferred Experience with SIEM/SOAR and detection engineering programs Experience operating in a highly matrixed, complex organization
Hiscox Underwriting Group Services Ltd (HUGS)
City, York
Job Type: Permanent The Role The Blue Team Leader works in our Cyber Fusion Centre, and plays a pivotal role in the protection of our business assets and interests from cyber threats. You will focus on the development of our proactive and defensive capabilities, orchestrating security operations and optimising the efforts of our Blue Team. You will support in the development and implementation of our overall cybersecurity strategy, and plan activities and initiatives to meet our business security objectives. You will need to be naturally inquisitive, have a comprehensive understanding of the latest cyber threats and how to counter them. You will also be a member of our Cyber Incident Response Team (CIRT) and will need to lead our initial response. You will work closely with our Red Team Leader and Cyber Delivery Leader to identify threats and vulnerabilities present in our network and systems, and turn these into a pipeline of continuous improvement for our cyber defences. You will also work closely with our Head of Cyber Fusion Centre to co ordinate daily activities in support of their primary objectives. You will also be responsible for working with project delivery teams from across our business, where you will provide expert technical security advice and guidance and support their onboarding activities to the Fusion Centre. You will need hands on experience working with a multitude of different security technologies, be able lead and coach your team of analysts and be able to work in a high paced operational environment. The role is based in either York (UK) or Lisbon (Portugal) and is a permanent position. Travel to other team locations will be required as necessary. Key Responsibilities Direct and guide the Blue Team in their daily operations, ensuring alignment with our business security objectives and latest threat intelligence. Oversee the continuous monitoring of our networks and systems for security breaches or anomalies. Design and maintain incident response plans to address and mitigate potential security breaches. Co ordinate Blue Team exercises to ensure analysts are confident in detecting and responding to cyber threats, and that we have the required data points needed to support detection of potential incidents. Allocate and manage resources effectively to ensure optimal team performance and address any skill, performance or resource gaps. Perform routine gap analysis of detection use cases and identify new data sources for onboarding to the SIEM platform to ensure observability of the latest TTPs. Leverage actionable threat intelligence to develop new detection use cases to support the ongoing continuous improvement of our SIEM capabilities. Ensure the operational resilience of our proactive and defensive cyber capabilities, including our technology, people and process used to support detection and response. Lead initial response to detection of security incidents, ensuring timely and effective resolution, escalation where necessary and perform any post incident analysis for lessons learned. Coach and mentor your team to support their professional development, fostering an environment of continuous learning and improvement. Develop and maintain our security operations policies, processes and playbooks. Maintain an up to date knowledge of the latest security tools and technologies, and how these could be used to mitigate our priority threats. Provide regular reports on security status, incidents and KRIs to senior management and stakeholders. Candidate Profile 6+ years experience in a security operations team, preferably 2 years in a management role. Demonstrable experience leading response to security incidents and breaches. Excellent understanding of defensive security strategies and cyber incident response processes. Excellent working knowledge of SIEM based tools and technologies. Excellent working knowledge of EDR and XDR technologies. Excellent working knowledge of firewalls and other network security appliances. Excellent problem solving and analytical skills, with the ability to make sound decisions under pressure. Excellent leadership and management skills, with strong communications and interpersonal skills. Good understanding of forensics technologies and processes. BSc or MSc in Cybersecurity is highly desirable. Advanced cyber certifications such as CISSP, CISM, GCIH and GPEN are desirable. Industry recognised security vendor certifications are desirable. Diversity & Benefits We hire the best people for the job and we're committed to diversity and creating a truly inclusive culture, which we believe drives success. Working life doesn't always have to be in the office, so we have introduced hybrid working to encourage a healthy work life balance. This hybrid working model is set by the team rather than the business to enable you to manage your own personal work life balance. Our benefits package includes a bonus, contributory pension, 25 days annual leave plus 2 Hiscox days and a 4 week paid sabbatical with every 5 years' worth of service, private medical for all the family and much more.
27/07/2026
Full time
Job Type: Permanent The Role The Blue Team Leader works in our Cyber Fusion Centre, and plays a pivotal role in the protection of our business assets and interests from cyber threats. You will focus on the development of our proactive and defensive capabilities, orchestrating security operations and optimising the efforts of our Blue Team. You will support in the development and implementation of our overall cybersecurity strategy, and plan activities and initiatives to meet our business security objectives. You will need to be naturally inquisitive, have a comprehensive understanding of the latest cyber threats and how to counter them. You will also be a member of our Cyber Incident Response Team (CIRT) and will need to lead our initial response. You will work closely with our Red Team Leader and Cyber Delivery Leader to identify threats and vulnerabilities present in our network and systems, and turn these into a pipeline of continuous improvement for our cyber defences. You will also work closely with our Head of Cyber Fusion Centre to co ordinate daily activities in support of their primary objectives. You will also be responsible for working with project delivery teams from across our business, where you will provide expert technical security advice and guidance and support their onboarding activities to the Fusion Centre. You will need hands on experience working with a multitude of different security technologies, be able lead and coach your team of analysts and be able to work in a high paced operational environment. The role is based in either York (UK) or Lisbon (Portugal) and is a permanent position. Travel to other team locations will be required as necessary. Key Responsibilities Direct and guide the Blue Team in their daily operations, ensuring alignment with our business security objectives and latest threat intelligence. Oversee the continuous monitoring of our networks and systems for security breaches or anomalies. Design and maintain incident response plans to address and mitigate potential security breaches. Co ordinate Blue Team exercises to ensure analysts are confident in detecting and responding to cyber threats, and that we have the required data points needed to support detection of potential incidents. Allocate and manage resources effectively to ensure optimal team performance and address any skill, performance or resource gaps. Perform routine gap analysis of detection use cases and identify new data sources for onboarding to the SIEM platform to ensure observability of the latest TTPs. Leverage actionable threat intelligence to develop new detection use cases to support the ongoing continuous improvement of our SIEM capabilities. Ensure the operational resilience of our proactive and defensive cyber capabilities, including our technology, people and process used to support detection and response. Lead initial response to detection of security incidents, ensuring timely and effective resolution, escalation where necessary and perform any post incident analysis for lessons learned. Coach and mentor your team to support their professional development, fostering an environment of continuous learning and improvement. Develop and maintain our security operations policies, processes and playbooks. Maintain an up to date knowledge of the latest security tools and technologies, and how these could be used to mitigate our priority threats. Provide regular reports on security status, incidents and KRIs to senior management and stakeholders. Candidate Profile 6+ years experience in a security operations team, preferably 2 years in a management role. Demonstrable experience leading response to security incidents and breaches. Excellent understanding of defensive security strategies and cyber incident response processes. Excellent working knowledge of SIEM based tools and technologies. Excellent working knowledge of EDR and XDR technologies. Excellent working knowledge of firewalls and other network security appliances. Excellent problem solving and analytical skills, with the ability to make sound decisions under pressure. Excellent leadership and management skills, with strong communications and interpersonal skills. Good understanding of forensics technologies and processes. BSc or MSc in Cybersecurity is highly desirable. Advanced cyber certifications such as CISSP, CISM, GCIH and GPEN are desirable. Industry recognised security vendor certifications are desirable. Diversity & Benefits We hire the best people for the job and we're committed to diversity and creating a truly inclusive culture, which we believe drives success. Working life doesn't always have to be in the office, so we have introduced hybrid working to encourage a healthy work life balance. This hybrid working model is set by the team rather than the business to enable you to manage your own personal work life balance. Our benefits package includes a bonus, contributory pension, 25 days annual leave plus 2 Hiscox days and a 4 week paid sabbatical with every 5 years' worth of service, private medical for all the family and much more.
LA International Computer Consultants Ltd
Bracknell, Berkshire
Level 1 Cyber Security Analyst Must have an Active DV Clearance as immediate starts available Level 1 Cyber Security Analyst Responsibilities Monitor SIEM tooling to identify potential security threats. Perform initial investigation and triage of security alerts. Escalate incidents in line with defined processes. Oversee Security Operators during shift activities. Identify and report faults within monitoring tools. Support continuous security monitoring across a 24x7 operation. Follow incident management processes to ensure timely response. Level 1 Cyber Security Analyst Skills and Experience Experience within cyber security or security operations environments. Strong understanding of SIEM tools and alert handling. Technical knowledge across enterprise IT such as networks or Servers. Ability to lead activities within a shift environment. Strong communication skills across technical teams. Level 1 Cyber Security Analyst Additional Information To apply, please send your CV by pressing the apply button Due to the nature and urgency of this post, candidates holding or who have held high level security clearance in the past are most welcome to apply. Please note successful applicants will be required to be security cleared prior to appointment which can take a minimum 18 weeks. LA International is an award-winning partner of choice for many of the world's most influential companies and government organisations. Holding Enhanced Government Security Accreditation, we are recognised as the European market leader in the delivery of Security Cleared talent to organisations that demand the very highest levels of security, compliance and assurance. An award-winning organisation, having secured the prestigious Queens Award for Enterprise: International Trade over multiple years. We are committed to fostering an inclusive, equitable and accessible workplace where everyone feels valued and supported. We welcome applications from all individuals, regardless of background or identity, and we encourage candidates who may not meet every listed requirement to still apply. If you require any adjustments or support during the recruitment process, please let us know and we will work with you to ensure a fair and accessible experience. Please Note: If a high volume of applications is received, only candidates shortlisted will be contacted.
27/07/2026
Contractor
Level 1 Cyber Security Analyst Must have an Active DV Clearance as immediate starts available Level 1 Cyber Security Analyst Responsibilities Monitor SIEM tooling to identify potential security threats. Perform initial investigation and triage of security alerts. Escalate incidents in line with defined processes. Oversee Security Operators during shift activities. Identify and report faults within monitoring tools. Support continuous security monitoring across a 24x7 operation. Follow incident management processes to ensure timely response. Level 1 Cyber Security Analyst Skills and Experience Experience within cyber security or security operations environments. Strong understanding of SIEM tools and alert handling. Technical knowledge across enterprise IT such as networks or Servers. Ability to lead activities within a shift environment. Strong communication skills across technical teams. Level 1 Cyber Security Analyst Additional Information To apply, please send your CV by pressing the apply button Due to the nature and urgency of this post, candidates holding or who have held high level security clearance in the past are most welcome to apply. Please note successful applicants will be required to be security cleared prior to appointment which can take a minimum 18 weeks. LA International is an award-winning partner of choice for many of the world's most influential companies and government organisations. Holding Enhanced Government Security Accreditation, we are recognised as the European market leader in the delivery of Security Cleared talent to organisations that demand the very highest levels of security, compliance and assurance. An award-winning organisation, having secured the prestigious Queens Award for Enterprise: International Trade over multiple years. We are committed to fostering an inclusive, equitable and accessible workplace where everyone feels valued and supported. We welcome applications from all individuals, regardless of background or identity, and we encourage candidates who may not meet every listed requirement to still apply. If you require any adjustments or support during the recruitment process, please let us know and we will work with you to ensure a fair and accessible experience. Please Note: If a high volume of applications is received, only candidates shortlisted will be contacted.
Cyber Security Engineer - CrowdStrike Falcon Specialist Contract | £425 per day Outside IR35 | Remote UK We are supporting a major enterprise organisation with the rollout and optimisation of CrowdStrike Falcon across a complex technology estate and are looking for an experienced Cyber Security Engineer with proven, hands-on CrowdStrike implementation expertise. This is an engineering-focused role, not a SOC Analyst position. We are looking for someone who has been responsible for deploying, configuring and enhancing CrowdStrike within large enterprise environments. The Role You'll join an established cyber security programme, taking ownership of CrowdStrike engineering activities across enterprise infrastructure, working closely with security, infrastructure and cloud teams. Key responsibilities include: Deploying and configuring CrowdStrike Falcon across enterprise environments Managing CrowdStrike policies, sensor deployments and platform optimisation Designing and implementing endpoint security controls Integrating CrowdStrike with technologies including Active Directory, ServiceNow, SIEM and SOAR platforms Developing detection rules, response workflows and security policies Supporting threat hunting and improving endpoint visibility Working across Windows server, desktop and cloud workloads Providing technical expertise throughout implementation and operational phases Essential Experience We're particularly interested in candidates who have demonstrable hands-on experience with: Enterprise deployment of CrowdStrike Falcon Falcon sensor rollout and life cycle management Policy creation and tuning Host groups, prevention policies and detection management Incident response and threat hunting using CrowdStrike Falcon Complete, Falcon Insight or Falcon Prevent Integration with Microsoft Sentinel, Splunk, QRadar or similar SIEM platforms Active Directory integration Enterprise-scale security engineering Desirable Experience Microsoft Defender for Endpoint (MDE) SentinelOne Rapid7 Carbon Black Microsoft Sentinel XSOAR or other SOAR platforms Azure, AWS or GCP security PowerShell or Python automation Zero Trust or enterprise security architecture
27/07/2026
Contractor
Cyber Security Engineer - CrowdStrike Falcon Specialist Contract | £425 per day Outside IR35 | Remote UK We are supporting a major enterprise organisation with the rollout and optimisation of CrowdStrike Falcon across a complex technology estate and are looking for an experienced Cyber Security Engineer with proven, hands-on CrowdStrike implementation expertise. This is an engineering-focused role, not a SOC Analyst position. We are looking for someone who has been responsible for deploying, configuring and enhancing CrowdStrike within large enterprise environments. The Role You'll join an established cyber security programme, taking ownership of CrowdStrike engineering activities across enterprise infrastructure, working closely with security, infrastructure and cloud teams. Key responsibilities include: Deploying and configuring CrowdStrike Falcon across enterprise environments Managing CrowdStrike policies, sensor deployments and platform optimisation Designing and implementing endpoint security controls Integrating CrowdStrike with technologies including Active Directory, ServiceNow, SIEM and SOAR platforms Developing detection rules, response workflows and security policies Supporting threat hunting and improving endpoint visibility Working across Windows server, desktop and cloud workloads Providing technical expertise throughout implementation and operational phases Essential Experience We're particularly interested in candidates who have demonstrable hands-on experience with: Enterprise deployment of CrowdStrike Falcon Falcon sensor rollout and life cycle management Policy creation and tuning Host groups, prevention policies and detection management Incident response and threat hunting using CrowdStrike Falcon Complete, Falcon Insight or Falcon Prevent Integration with Microsoft Sentinel, Splunk, QRadar or similar SIEM platforms Active Directory integration Enterprise-scale security engineering Desirable Experience Microsoft Defender for Endpoint (MDE) SentinelOne Rapid7 Carbon Black Microsoft Sentinel XSOAR or other SOAR platforms Azure, AWS or GCP security PowerShell or Python automation Zero Trust or enterprise security architecture
Wood Mackenzie Limited is seeking an experienced Cyber Security Analyst to enhance their cyber security team in Edinburgh. The position demands at least 5 years of cyber security expertise and significant experience in cloud and application security. The successful candidate will lead security initiatives to safeguard enterprise environments against evolving cyber threats. Responsibilities include monitoring security events, managing incident response, and collaborating with teams to integrate security measures into development processes. A flexible remote work environment is supported.
27/07/2026
Full time
Wood Mackenzie Limited is seeking an experienced Cyber Security Analyst to enhance their cyber security team in Edinburgh. The position demands at least 5 years of cyber security expertise and significant experience in cloud and application security. The successful candidate will lead security initiatives to safeguard enterprise environments against evolving cyber threats. Responsibilities include monitoring security events, managing incident response, and collaborating with teams to integrate security measures into development processes. A flexible remote work environment is supported.
Business Unit: Cubic Defense Company Cubic is a global organization that delivers technology solutions in transportation and defense. It provides command, control, communications, computers, cyber, intelligence, surveillance, and reconnaissance (C5ISR) solutions, as well as live, virtual, constructive, and game-based training to serve U.S. and allied forces. Summary The Deputy Programme Manager (DPM) for the ILT-A Programme supports senior programme leadership during a period of rapid growth and change. The candidate will work with programme and project managers, the Regional General Manager, and the ILT-A Programme Manager to ensure successful delivery of the existing business portfolio across Cubic UK (CDUK). The role is primarily office based with occasional field based delivery and operational oversight in the UK and overseas. Key Responsibilities Assist the Programme Manager in planning, scheduling, execution, and delivery of design and build projects. Coordinate multiple parallel projects, ensuring alignment with programme objectives, budget constraints, and timelines. Engage cross functional teams, including engineering, supply chain, procurement, and manufacturing, to develop strategies. Support stakeholder communication and engagement, providing regular updates on project progress, risks, and opportunities. Manage project resources effectively, including financial budgets and personnel allocation. Develop and track key performance indicators (KPIs) to measure project success and continuous improvement. Support the implementation, monitoring, and continuous improvement of security controls across the CDUK IT infrastructure and business systems. Manage risk registers and assist in the identification of risks, including security risks, and implement mitigation plans. Implement and enhance the security strategy, championing a culture of cyber security awareness and best practice across CDUK. Contribute to the upkeep of security certifications in alignment with frameworks such as Cyber Essentials and the Cyber Assessment Framework (CAF). Work with third party providers on security audits and reviews, and support continual improvement of cyber security policies. Maintain contemporary knowledge of current threats and cyber trends. Essential Requirements Proven experience and understanding of programme or project management within an engineering, manufacturing, or defence environment. Ability to manage multiple design and build projects simultaneously. Excellent stakeholder management skills, with experience engaging internal and external partners. Strong problem solving and risk management capabilities. Experience managing risk registers. Proficiency in project management methodologies and tools, including scheduling (e.g., Agile, PRINCE2, PMP, MS Project, P6). Understanding of cyber and information security best practice frameworks, standards, and certifications such as NIST, ISO27001, SbD, and ideally PSN, Cyber Essentials, and CAF. Experience providing security advice across a variety of projects. Strong Governance Risk and Compliance (GRC) knowledge, understanding, and skillset. Experience with budgeting, financial reporting, and resource planning. Desirable Requirements Typically 8+ years of relevant experience. Experience as an information security analyst (IT audit, governance, risk and compliance) within the public or private sector. Degree in Engineering, Project Management, or a related discipline. Experience within defence, aerospace, or highly regulated industries. Familiarity with regulatory and compliance requirements. Membership of a relevant professional body (e.g., APM, PMI, INCOSE). Background in IT (infrastructure, networks, software or cyber security). Personal Qualities Self motivated, proactive, and able to work under pressure to meet challenging deadlines with minimal supervision. Strong relationship building and influencing skills. Excellent communication skills (written and verbal), proactive and solution focused mindset. Ability to lead teams and quickly acquire new skills. Willingness to travel. Worker Type Employee You are committed to hiring and retaining a diverse workforce and are proud to be an Equal Opportunity/Affirmative Action Employer. We are committed to ensuring a workplace free of discrimination based on race, color, religion, age, disability, genetic information, sex, sexual orientation, gender identity, national origin, military or veteran status, or any other basis protected by applicable law. For more information on Equal Employment please visit:
27/07/2026
Full time
Business Unit: Cubic Defense Company Cubic is a global organization that delivers technology solutions in transportation and defense. It provides command, control, communications, computers, cyber, intelligence, surveillance, and reconnaissance (C5ISR) solutions, as well as live, virtual, constructive, and game-based training to serve U.S. and allied forces. Summary The Deputy Programme Manager (DPM) for the ILT-A Programme supports senior programme leadership during a period of rapid growth and change. The candidate will work with programme and project managers, the Regional General Manager, and the ILT-A Programme Manager to ensure successful delivery of the existing business portfolio across Cubic UK (CDUK). The role is primarily office based with occasional field based delivery and operational oversight in the UK and overseas. Key Responsibilities Assist the Programme Manager in planning, scheduling, execution, and delivery of design and build projects. Coordinate multiple parallel projects, ensuring alignment with programme objectives, budget constraints, and timelines. Engage cross functional teams, including engineering, supply chain, procurement, and manufacturing, to develop strategies. Support stakeholder communication and engagement, providing regular updates on project progress, risks, and opportunities. Manage project resources effectively, including financial budgets and personnel allocation. Develop and track key performance indicators (KPIs) to measure project success and continuous improvement. Support the implementation, monitoring, and continuous improvement of security controls across the CDUK IT infrastructure and business systems. Manage risk registers and assist in the identification of risks, including security risks, and implement mitigation plans. Implement and enhance the security strategy, championing a culture of cyber security awareness and best practice across CDUK. Contribute to the upkeep of security certifications in alignment with frameworks such as Cyber Essentials and the Cyber Assessment Framework (CAF). Work with third party providers on security audits and reviews, and support continual improvement of cyber security policies. Maintain contemporary knowledge of current threats and cyber trends. Essential Requirements Proven experience and understanding of programme or project management within an engineering, manufacturing, or defence environment. Ability to manage multiple design and build projects simultaneously. Excellent stakeholder management skills, with experience engaging internal and external partners. Strong problem solving and risk management capabilities. Experience managing risk registers. Proficiency in project management methodologies and tools, including scheduling (e.g., Agile, PRINCE2, PMP, MS Project, P6). Understanding of cyber and information security best practice frameworks, standards, and certifications such as NIST, ISO27001, SbD, and ideally PSN, Cyber Essentials, and CAF. Experience providing security advice across a variety of projects. Strong Governance Risk and Compliance (GRC) knowledge, understanding, and skillset. Experience with budgeting, financial reporting, and resource planning. Desirable Requirements Typically 8+ years of relevant experience. Experience as an information security analyst (IT audit, governance, risk and compliance) within the public or private sector. Degree in Engineering, Project Management, or a related discipline. Experience within defence, aerospace, or highly regulated industries. Familiarity with regulatory and compliance requirements. Membership of a relevant professional body (e.g., APM, PMI, INCOSE). Background in IT (infrastructure, networks, software or cyber security). Personal Qualities Self motivated, proactive, and able to work under pressure to meet challenging deadlines with minimal supervision. Strong relationship building and influencing skills. Excellent communication skills (written and verbal), proactive and solution focused mindset. Ability to lead teams and quickly acquire new skills. Willingness to travel. Worker Type Employee You are committed to hiring and retaining a diverse workforce and are proud to be an Equal Opportunity/Affirmative Action Employer. We are committed to ensuring a workplace free of discrimination based on race, color, religion, age, disability, genetic information, sex, sexual orientation, gender identity, national origin, military or veteran status, or any other basis protected by applicable law. For more information on Equal Employment please visit:
Position Overview We are seeking an experienced Cyber Security Analyst to join our cyber security team. The ideal candidate will have a minimum of 5 years cyber security experience and 3+ years in cloud security and/or application security. The candidate will be able to demonstrate a proven track record of protecting enterprise environments against evolving cyber threats. This role requires a technically proficient lead analyst who can lead security initiatives and ensure our cloud and application infrastructure maintains the highest security standards, whilst maintaining business partnerships across the group. Key Responsibilities Monitor and analyze security events across cloud and on premises environments using SIEM and security analytics tools Conduct thorough investigations of security incidents and provide detailed incident reports Develop and maintain incident response playbooks and procedures Experience with threat intelligence platforms and threat hunting Experience with security orchestration, automation and response (SOAR) platforms Understanding of data protection and encryption technologies Experience in regulated industries (financial services, healthcare, energy) Background in offensive security or penetration testing Design, implement, and maintain security controls across cloud platforms (AWS, Azure, GCP) Conduct cloud security assessments and architecture reviews Ensure compliance with cloud security best practices and frameworks (CIS Benchmarks, CSA CCM, NIST) Manage cloud native security tools including CSPM, CWPP, and cloud WAF solutions Implement and maintain identity and access management (IAM) policies and controls Lead cyber security programs and coordinate remediation efforts Collaborate with DevOps teams to integrate security into CI/CD pipelines (DevSecOps) Stay current with emerging threats, vulnerabilities, and security technologies Contribute to security awareness training and documentation Facilitate Supplier Management and security input into bids Support compliance initiatives (SOC2, ISO27001, PCI DSS, GDPR, etc.) Develop and enforce security policies, standards, and procedures Conduct security audits and risk assessments Maintain security documentation and metrics reporting Required Qualifications Minimum of 5 years cyber security experience 3+ years of hands on experience with cloud security (AWS, Azure, or GCP) Proven experience leading security incidents and coordinating response efforts Experience with security frameworks such as NIST CSF, MITRE ATT&CK, or Zero Trust architecture Technical Skills Strong expertise in cloud security services and tools (AWS & Azure) Experience working with SIEM platforms (Splunk, Sentinel) Understanding of network security, firewalls, IDS/IPS, and VPN technologies Familiarity with security testing tools (vulnerability scanners, SAST/DAST, penetration testing tools) Experience with endpoint detection and response (EDR) solutions Soft Skills Strong analytical and problem solving abilities Excellent written and verbal communication skills Ability to explain complex security concepts to technical and non technical audiences Leadership capabilities and experience mentoring team members Strong attention to detail and ability to work under pressure Collaborative mindset with cross functional teams Business partnering experience Certifications (one or more preferred) CISSP (Certified Information Systems Security Professional) CCSP (Certified Cloud Security Professional) AWS Certified Security - Specialty Microsoft Certified: Azure Security Engineer Associate Education: Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) Working Conditions Some flexibility for remote work - 2 days minimum in office (Edinburgh preferred) Equal Opportunities We are an equal opportunities employer. This means we are committed to recruiting the best people regardless of their race, colour, religion, age, sex, national origin, disability or protected veteran status. We can support you with your application or through the hiring process if you have a physical or mental disability. You can find out more about your rights under the law at .
27/07/2026
Full time
Position Overview We are seeking an experienced Cyber Security Analyst to join our cyber security team. The ideal candidate will have a minimum of 5 years cyber security experience and 3+ years in cloud security and/or application security. The candidate will be able to demonstrate a proven track record of protecting enterprise environments against evolving cyber threats. This role requires a technically proficient lead analyst who can lead security initiatives and ensure our cloud and application infrastructure maintains the highest security standards, whilst maintaining business partnerships across the group. Key Responsibilities Monitor and analyze security events across cloud and on premises environments using SIEM and security analytics tools Conduct thorough investigations of security incidents and provide detailed incident reports Develop and maintain incident response playbooks and procedures Experience with threat intelligence platforms and threat hunting Experience with security orchestration, automation and response (SOAR) platforms Understanding of data protection and encryption technologies Experience in regulated industries (financial services, healthcare, energy) Background in offensive security or penetration testing Design, implement, and maintain security controls across cloud platforms (AWS, Azure, GCP) Conduct cloud security assessments and architecture reviews Ensure compliance with cloud security best practices and frameworks (CIS Benchmarks, CSA CCM, NIST) Manage cloud native security tools including CSPM, CWPP, and cloud WAF solutions Implement and maintain identity and access management (IAM) policies and controls Lead cyber security programs and coordinate remediation efforts Collaborate with DevOps teams to integrate security into CI/CD pipelines (DevSecOps) Stay current with emerging threats, vulnerabilities, and security technologies Contribute to security awareness training and documentation Facilitate Supplier Management and security input into bids Support compliance initiatives (SOC2, ISO27001, PCI DSS, GDPR, etc.) Develop and enforce security policies, standards, and procedures Conduct security audits and risk assessments Maintain security documentation and metrics reporting Required Qualifications Minimum of 5 years cyber security experience 3+ years of hands on experience with cloud security (AWS, Azure, or GCP) Proven experience leading security incidents and coordinating response efforts Experience with security frameworks such as NIST CSF, MITRE ATT&CK, or Zero Trust architecture Technical Skills Strong expertise in cloud security services and tools (AWS & Azure) Experience working with SIEM platforms (Splunk, Sentinel) Understanding of network security, firewalls, IDS/IPS, and VPN technologies Familiarity with security testing tools (vulnerability scanners, SAST/DAST, penetration testing tools) Experience with endpoint detection and response (EDR) solutions Soft Skills Strong analytical and problem solving abilities Excellent written and verbal communication skills Ability to explain complex security concepts to technical and non technical audiences Leadership capabilities and experience mentoring team members Strong attention to detail and ability to work under pressure Collaborative mindset with cross functional teams Business partnering experience Certifications (one or more preferred) CISSP (Certified Information Systems Security Professional) CCSP (Certified Cloud Security Professional) AWS Certified Security - Specialty Microsoft Certified: Azure Security Engineer Associate Education: Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) Working Conditions Some flexibility for remote work - 2 days minimum in office (Edinburgh preferred) Equal Opportunities We are an equal opportunities employer. This means we are committed to recruiting the best people regardless of their race, colour, religion, age, sex, national origin, disability or protected veteran status. We can support you with your application or through the hiring process if you have a physical or mental disability. You can find out more about your rights under the law at .
Security Analyst Cardiff, London, Belfast, Glasgow, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
27/07/2026
Full time
Security Analyst Cardiff, London, Belfast, Glasgow, Leeds, Manchester or Oxford Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Morson Human Resources Limited is looking for an Incident Response (CSIRT) / SOC Level 3 Analyst based in Crawley. This 6-month contract role focuses on investigating and responding to high-severity cyber security incidents, and enhancing response playbooks and SOC procedures. The ideal candidate will have strong SOC and cyber defense expertise, a proactive mindset, and experience managing incidents. Onsite work will be required for 2-3 days a week.
27/07/2026
Full time
Morson Human Resources Limited is looking for an Incident Response (CSIRT) / SOC Level 3 Analyst based in Crawley. This 6-month contract role focuses on investigating and responding to high-severity cyber security incidents, and enhancing response playbooks and SOC procedures. The ideal candidate will have strong SOC and cyber defense expertise, a proactive mindset, and experience managing incidents. Onsite work will be required for 2-3 days a week.
Contract Civic Recruitment Limited United Kingdom Posted On 23/07/2026 Job Information Technology / IT / Internet City Milton Keynes Province Milton Keynes Postal Code MK6 Job Description ICT Security Analyst - 3 Month Contract (Potential Extension) Location: Civic Offices, Milton Keynes Contract: Up to 3 Months (Potential Extension) Hours: Full Time Equipment: Laptop Provided Summary We are seeking an ICT Security Analyst to join our dynamic Local Authority ICT Security team. This role is pivotal in safeguarding critical systems, digital services, and sensitive information within a large and multifaceted organization that delivers over 200 essential public services. The successful candidate will manage cyber security risks, investigate incidents, monitor threats, and provide security guidance to internal stakeholders. Collaboration with ICT teams, service areas, suppliers, and partners is essential to integrate security into projects, operational services, and digital transformation initiatives. Responsibilities Security Monitoring & Threat Management Monitor ICT systems for cyber threats and vulnerabilities. Identify security risks and recommend mitigation strategies. Investigate suspicious activities and escalation incidents as needed. Support the ongoing monitoring of security controls. Assist in investigating and managing cyber security incidents. Support containment, recovery, and remediation activities. Document incidents and contribute to post-incident reviews. Support the management of cyber security risks. Assist with compliance against security standards and frameworks. Maintain security documentation and support audits. Security Advice & Guidance Provide security advice to ICT teams and stakeholders. Ensure security considerations are integrated into projects. Promote security best practices across the organization. Vulnerability Management Support vulnerability assessment activities. Recommend corrective actions for security findings. Ensure timely remediation of vulnerabilities. Security Awareness & Resilience Support cyber security awareness initiatives. Contribute to training and promote a positive security culture. Collaborate with suppliers and partners for secure service delivery. Support security reviews of technologies and services. Documentation & Reporting Prepare security reports and maintain accurate records. Provide updates and recommendations to senior colleagues. Requirements Requirements: Experience in ICT Security, Information Security, or Cyber Security roles. Experience monitoring and responding to security incidents. Knowledge of cyber security principles and best practices. Experience with security tools and incident management processes. Strong analytical and problem-solving skills. Excellent written and verbal communication skills. Experience in Local Authority or Public Sector. Familiarity with security frameworks like Cyber Essentials, ISO 27001, or NIST. Experience with cloud technologies and modern digital platforms. Security related certifications (e.g., CompTIA Security+, CISSP, CISM, CEH, Microsoft Security Certifications). What's on Offer? Competitive hourly rate of £24.75 (Umbrella). Contract duration of up to 3 months with potential for extension. Full-time role based in Civic Offices, Milton Keynes. Laptop provided and bi-weekly pay. Opportunity to work in a large Local Authority environment with exposure to cyber security, risk management, and digital transformation projects. Applications are encouraged from candidates with experience as an ICT Security Analyst, Information Security Analyst, Cyber Security Analyst, Security Operations Analyst, IT Risk Analyst, Cyber Security Officer, Information Governance Security Officer, or Security Compliance Analyst.
27/07/2026
Full time
Contract Civic Recruitment Limited United Kingdom Posted On 23/07/2026 Job Information Technology / IT / Internet City Milton Keynes Province Milton Keynes Postal Code MK6 Job Description ICT Security Analyst - 3 Month Contract (Potential Extension) Location: Civic Offices, Milton Keynes Contract: Up to 3 Months (Potential Extension) Hours: Full Time Equipment: Laptop Provided Summary We are seeking an ICT Security Analyst to join our dynamic Local Authority ICT Security team. This role is pivotal in safeguarding critical systems, digital services, and sensitive information within a large and multifaceted organization that delivers over 200 essential public services. The successful candidate will manage cyber security risks, investigate incidents, monitor threats, and provide security guidance to internal stakeholders. Collaboration with ICT teams, service areas, suppliers, and partners is essential to integrate security into projects, operational services, and digital transformation initiatives. Responsibilities Security Monitoring & Threat Management Monitor ICT systems for cyber threats and vulnerabilities. Identify security risks and recommend mitigation strategies. Investigate suspicious activities and escalation incidents as needed. Support the ongoing monitoring of security controls. Assist in investigating and managing cyber security incidents. Support containment, recovery, and remediation activities. Document incidents and contribute to post-incident reviews. Support the management of cyber security risks. Assist with compliance against security standards and frameworks. Maintain security documentation and support audits. Security Advice & Guidance Provide security advice to ICT teams and stakeholders. Ensure security considerations are integrated into projects. Promote security best practices across the organization. Vulnerability Management Support vulnerability assessment activities. Recommend corrective actions for security findings. Ensure timely remediation of vulnerabilities. Security Awareness & Resilience Support cyber security awareness initiatives. Contribute to training and promote a positive security culture. Collaborate with suppliers and partners for secure service delivery. Support security reviews of technologies and services. Documentation & Reporting Prepare security reports and maintain accurate records. Provide updates and recommendations to senior colleagues. Requirements Requirements: Experience in ICT Security, Information Security, or Cyber Security roles. Experience monitoring and responding to security incidents. Knowledge of cyber security principles and best practices. Experience with security tools and incident management processes. Strong analytical and problem-solving skills. Excellent written and verbal communication skills. Experience in Local Authority or Public Sector. Familiarity with security frameworks like Cyber Essentials, ISO 27001, or NIST. Experience with cloud technologies and modern digital platforms. Security related certifications (e.g., CompTIA Security+, CISSP, CISM, CEH, Microsoft Security Certifications). What's on Offer? Competitive hourly rate of £24.75 (Umbrella). Contract duration of up to 3 months with potential for extension. Full-time role based in Civic Offices, Milton Keynes. Laptop provided and bi-weekly pay. Opportunity to work in a large Local Authority environment with exposure to cyber security, risk management, and digital transformation projects. Applications are encouraged from candidates with experience as an ICT Security Analyst, Information Security Analyst, Cyber Security Analyst, Security Operations Analyst, IT Risk Analyst, Cyber Security Officer, Information Governance Security Officer, or Security Compliance Analyst.
Civic Recruitment Limited in Milton Keynes is seeking an ICT Security Analyst for a 3-month contract in a large Local Authority ICT Security team. You will monitor threats, investigate incidents, advise on security, and help integrate security into projects and digital transformation initiatives. Strong collaboration with internal teams, suppliers, and partners is essential. The role requires experience in ICT security, incident response, and familiarity with Cyber Essentials, ISO 27001, or
27/07/2026
Full time
Civic Recruitment Limited in Milton Keynes is seeking an ICT Security Analyst for a 3-month contract in a large Local Authority ICT Security team. You will monitor threats, investigate incidents, advise on security, and help integrate security into projects and digital transformation initiatives. Strong collaboration with internal teams, suppliers, and partners is essential. The role requires experience in ICT security, incident response, and familiarity with Cyber Essentials, ISO 27001, or
University of Bath is seeking an Information Security Assurance Manager to lead a team of assurance analysts and oversee information risk management. The role partners with the CISO and senior InfoSec leadership to meet compliance states for ISO27001 and funder requirements, building trust across the DDaT and wider university. The successful candidate will coordinate risk activities, drive remediation of vulnerabilities, and evolve security processes to counter emerging threats in education.
27/07/2026
Full time
University of Bath is seeking an Information Security Assurance Manager to lead a team of assurance analysts and oversee information risk management. The role partners with the CISO and senior InfoSec leadership to meet compliance states for ISO27001 and funder requirements, building trust across the DDaT and wider university. The successful candidate will coordinate risk activities, drive remediation of vulnerabilities, and evolve security processes to counter emerging threats in education.
We're looking for a Senior Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high impact work that shapes how we detect and respond to threats at scale. You'll collaborate closely with our inhouse Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of it's kind at this scale, then this is the role for you. At Our Future Health, our mission is to transform the prevention,detectionand treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you. What you'll be doing Developing new threat-led detections in collaboration with our threat teambased on both threat intelligenceand the results of threat hunts. Creating novel analytic methods and techniques for incident detection. Working with our MSP provided SOC tomaintainour detectioncatalogueand tune existing rules. Developing and tuning Data Loss Prevention, Insider RiskManagementand other types of security rules withinMicrosoft Purviewand other key security monitoring tools. Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided,detections and other types of engineering work are delivered to theappropriate standardand that the maturity (inc. efficiency) of our security monitoring is continually improving. Supporting the development ofautomated custom reports on security operational performance and broader security topics (using Sentinel workbooks). Collaborating with wider tech and security teams on theappropriatesecuritymonitoringfor our various systems, including cloud platforms, SaaS applications and inhouse developed systems. Documenting securityprocesses and security tool low-level design/configuration. Contributing to the development of security service delivery and operation documentation. Supporting the security engineers, threatanalystsand wider security team with their various responsibilities, including achieving andmaintainingISO 27001 certification andanything that involves KQL. What you won't be doing Working in a siloed environment with no freedom to make decisions. Working in a place where you can't see the impact your expertise makes. To succeed in this role you will be able to demonstrate some of the following skills and experience: Highly proficient in writing KQL and ideallysome level ofproficiencyinPythonand Terraform. Significant hands on experience with Microsoft Sentinel. Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365. Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities. Experience withMicrosoft Purview tooling, in particular MPIP and Purview Data Loss Prevention. Experience with cloud-native logging(in particular Azureand Kubernetes). Experience of an 'everything-as-code',or at least a 'detection-as-code'approach, including CI/CD pipelines. Exposure to working with/inside an MSP SOC. Exposure to Agile working. Knowledge of attacker Tactics, Techniques and Procedures (TTPs). Knowledge of statistics, datascienceand AI/ML,in particular whenapplied to cyber security. Knowledge ofISO 27001. Desire to be part of a small fast paced team. Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK. Salary from £65,000 per annum. Generous Pension Scheme - We invest in your future with employer contributions of up to 12%. 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you. Enhanced Parental Leave - Supporting you during life's biggest moments. Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice. Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board! Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family. A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements. Join us - let'sprevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at
27/07/2026
Full time
We're looking for a Senior Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high impact work that shapes how we detect and respond to threats at scale. You'll collaborate closely with our inhouse Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of it's kind at this scale, then this is the role for you. At Our Future Health, our mission is to transform the prevention,detectionand treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you. What you'll be doing Developing new threat-led detections in collaboration with our threat teambased on both threat intelligenceand the results of threat hunts. Creating novel analytic methods and techniques for incident detection. Working with our MSP provided SOC tomaintainour detectioncatalogueand tune existing rules. Developing and tuning Data Loss Prevention, Insider RiskManagementand other types of security rules withinMicrosoft Purviewand other key security monitoring tools. Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided,detections and other types of engineering work are delivered to theappropriate standardand that the maturity (inc. efficiency) of our security monitoring is continually improving. Supporting the development ofautomated custom reports on security operational performance and broader security topics (using Sentinel workbooks). Collaborating with wider tech and security teams on theappropriatesecuritymonitoringfor our various systems, including cloud platforms, SaaS applications and inhouse developed systems. Documenting securityprocesses and security tool low-level design/configuration. Contributing to the development of security service delivery and operation documentation. Supporting the security engineers, threatanalystsand wider security team with their various responsibilities, including achieving andmaintainingISO 27001 certification andanything that involves KQL. What you won't be doing Working in a siloed environment with no freedom to make decisions. Working in a place where you can't see the impact your expertise makes. To succeed in this role you will be able to demonstrate some of the following skills and experience: Highly proficient in writing KQL and ideallysome level ofproficiencyinPythonand Terraform. Significant hands on experience with Microsoft Sentinel. Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365. Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities. Experience withMicrosoft Purview tooling, in particular MPIP and Purview Data Loss Prevention. Experience with cloud-native logging(in particular Azureand Kubernetes). Experience of an 'everything-as-code',or at least a 'detection-as-code'approach, including CI/CD pipelines. Exposure to working with/inside an MSP SOC. Exposure to Agile working. Knowledge of attacker Tactics, Techniques and Procedures (TTPs). Knowledge of statistics, datascienceand AI/ML,in particular whenapplied to cyber security. Knowledge ofISO 27001. Desire to be part of a small fast paced team. Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK. Salary from £65,000 per annum. Generous Pension Scheme - We invest in your future with employer contributions of up to 12%. 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you. Enhanced Parental Leave - Supporting you during life's biggest moments. Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice. Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board! Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family. A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements. Join us - let'sprevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at
We believe great work thrives in an environment where people feel genuinely supported and fairly rewarded. Our benefits are designed to create real value for every individual - fueling engagement, performance, and growth. By prioritizing well-being, we build a workplace where personal and organizational success grow together. The world is rapidly moving towards more efficient power distribution to support renewable, greener technologies. At Hitachi Energy, we are at the forefront of this revolution, delivering cutting-edge solutions to customers and countries across the globe. Our mission is not just a goal, but a passion that drives us every day. However, our journey to a greener future is challenged by an increasingly complex and disruptive cybersecurity landscape. This is where you come in. By joining our Cyber Defense Center (CDC) team as a Cybersecurity Incident Response Analyst, you will play a crucial role in protecting and advancing our mission. You will help safeguard our innovative work in renewable energy, ensuring our operations remain secure and uninterrupted. As part of this role, you will support Security Monitoring services alongside our MSSP, assist in responding to cybersecurity incidents, and collaborate with expert Incident Managers during high-priority events. You'll work with a diverse, multicultural team across the globe, contributing to our 24/7 response capabilities throughout the year. In our modern, hybrid environment, you will gain exposure to a wide range of cybersecurity incidents, including legacy IT, Cloud, OT/ICS, supply chain, and product security. You will also have the opportunity to work with the latest security tools, including next-generation AI-enabled platforms. How you'll make an impact: Monitor security systems and alerts to identify potential incidents. Assist in the initial investigation of security incidents, performing triage and escalating to senior team members as needed. Document and report on findings from security monitoring activities. Collaborate with the 24/7 Security Monitoring team to ensure timely detection and response to threats. Support Incident Response processes by gathering relevant information and aiding in analysis. Participate in the development and improvement of incident response playbooks, procedures, and workflows. Assist with post-incident reviews and the documentation of lessons learned. Assist in ensuring that incident response activities align with regulatory requirements and organisational policies. Your Background: Bachelor's Degree in Cyber Security, Information Technology, Computer Science, or a related field; OR equivalent experience with A Levels/BTEC. Experience in a cybersecurity-related role, such as Security Operations, Threat Detection, or IT Support, preferably within an enterprise environment. Familiarity with security monitoring tools, SIEM platforms, and basic threat detection techniques. Good communication and teamwork skills, with the ability to work collaboratively with technical and non-technical stakeholders. Flexibility to be on-call for duties and assist in response to incidents outside regular working hours as needed. Eagerness to grow within the cybersecurity field and contribute to the overall security posture of the organization. More about us: Hitachi Energy is dedicated to fostering an inclusive workplace where every team member can thrive and contribute their unique perspectives and skills. We provide competitive salaries, flexible working hours, professional development opportunities, and a supportive work environment that encourages growth and innovation through career development programs and Employee Resource Groups (ERGs). Specific benefits depend on the location and will be communicated during the interview process. We are a global leader in electrification, powering the electricity era to meet the energy demands of today, and the next 25 years. As the energy arm of Hitachi Group, over three billion people depend on our pioneering, mission-critical technologies to power their daily lives. With over a century of innovation, we are addressing the most urgent energy challenge of our time: driving the evolution of the world's energy system to ensure abundant, secure, affordable, and sustainable power for today's generation and the next. With an unparalleled installed base in over 140 countries, we are the grid ecosystem partner across the utility, industry, data center, and transportation sectors. Headquartered in Switzerland, we employ over 56,000 people in 60 countries and generate revenues of around $20 billion USD.
27/07/2026
Full time
We believe great work thrives in an environment where people feel genuinely supported and fairly rewarded. Our benefits are designed to create real value for every individual - fueling engagement, performance, and growth. By prioritizing well-being, we build a workplace where personal and organizational success grow together. The world is rapidly moving towards more efficient power distribution to support renewable, greener technologies. At Hitachi Energy, we are at the forefront of this revolution, delivering cutting-edge solutions to customers and countries across the globe. Our mission is not just a goal, but a passion that drives us every day. However, our journey to a greener future is challenged by an increasingly complex and disruptive cybersecurity landscape. This is where you come in. By joining our Cyber Defense Center (CDC) team as a Cybersecurity Incident Response Analyst, you will play a crucial role in protecting and advancing our mission. You will help safeguard our innovative work in renewable energy, ensuring our operations remain secure and uninterrupted. As part of this role, you will support Security Monitoring services alongside our MSSP, assist in responding to cybersecurity incidents, and collaborate with expert Incident Managers during high-priority events. You'll work with a diverse, multicultural team across the globe, contributing to our 24/7 response capabilities throughout the year. In our modern, hybrid environment, you will gain exposure to a wide range of cybersecurity incidents, including legacy IT, Cloud, OT/ICS, supply chain, and product security. You will also have the opportunity to work with the latest security tools, including next-generation AI-enabled platforms. How you'll make an impact: Monitor security systems and alerts to identify potential incidents. Assist in the initial investigation of security incidents, performing triage and escalating to senior team members as needed. Document and report on findings from security monitoring activities. Collaborate with the 24/7 Security Monitoring team to ensure timely detection and response to threats. Support Incident Response processes by gathering relevant information and aiding in analysis. Participate in the development and improvement of incident response playbooks, procedures, and workflows. Assist with post-incident reviews and the documentation of lessons learned. Assist in ensuring that incident response activities align with regulatory requirements and organisational policies. Your Background: Bachelor's Degree in Cyber Security, Information Technology, Computer Science, or a related field; OR equivalent experience with A Levels/BTEC. Experience in a cybersecurity-related role, such as Security Operations, Threat Detection, or IT Support, preferably within an enterprise environment. Familiarity with security monitoring tools, SIEM platforms, and basic threat detection techniques. Good communication and teamwork skills, with the ability to work collaboratively with technical and non-technical stakeholders. Flexibility to be on-call for duties and assist in response to incidents outside regular working hours as needed. Eagerness to grow within the cybersecurity field and contribute to the overall security posture of the organization. More about us: Hitachi Energy is dedicated to fostering an inclusive workplace where every team member can thrive and contribute their unique perspectives and skills. We provide competitive salaries, flexible working hours, professional development opportunities, and a supportive work environment that encourages growth and innovation through career development programs and Employee Resource Groups (ERGs). Specific benefits depend on the location and will be communicated during the interview process. We are a global leader in electrification, powering the electricity era to meet the energy demands of today, and the next 25 years. As the energy arm of Hitachi Group, over three billion people depend on our pioneering, mission-critical technologies to power their daily lives. With over a century of innovation, we are addressing the most urgent energy challenge of our time: driving the evolution of the world's energy system to ensure abundant, secure, affordable, and sustainable power for today's generation and the next. With an unparalleled installed base in over 140 countries, we are the grid ecosystem partner across the utility, industry, data center, and transportation sectors. Headquartered in Switzerland, we employ over 56,000 people in 60 countries and generate revenues of around $20 billion USD.
What you'll be doing: At Atech, we believe cyber security is about more than reacting to threats - it's about staying ahead of them. As a leading provider of cloud, cyber security and managed services, we help organisations strengthen their security posture through innovation, expertise and a customer-first approach. We're looking for an experienced Level 3 SOC Analyst to join our growing Security Operations Centre (SOC). This is a senior technical role where you'll lead complex investigations, conduct advanced threat hunting activities and help shape the future of our SOC capability. You'll act as a technical authority during major security incidents while mentoring colleagues and driving continuous improvement across our security services. As a Level 3 SOC Analyst, you'll be: Leading complex cyber security incidents from initial investigation through to containment, eradication and recovery. Acting as the technical escalation point for high-priority and complex security events. Conducting advanced threat hunting activities across endpoint, cloud, identity and email environments. Correlating multiple telemetry sources to reconstruct attack chains, identify root causes and determine remediation actions. Providing clear and confident communication to customers and stakeholders during major security incidents. Developing and enhancing detection use cases, analytics and alert tuning within Microsoft Sentinel and Microsoft Defender XDR. Identifying opportunities to improve SOC processes, standards, tooling and operational maturity. Producing high-quality incident reports, lessons learned documentation and technical recommendations. Mentoring and coaching Level 1 and Level 2 SOC Analysts, helping to raise technical capability across the team. Supporting vulnerability assessment and security posture improvement activities when required. Collaborating with internal and customer technical teams to coordinate effective incident response and recovery. We want to hear from you if you: Have significant experience working within a Security Operations Centre environment. Possess advanced hands-on expertise with Microsoft Sentinel, Microsoft Defender XDR and Microsoft Entra ID Protection. Have a strong background in threat hunting, incident response and cyber security investigations. Can analyse and correlate data from multiple telemetry sources to uncover threats and reconstruct attack activity. Are confident leading major incidents and providing technical direction under pressure. Have experience improving detection logic, tuning security tools and enhancing SOC effectiveness. Can communicate complex technical information clearly to both technical and non-technical audiences. Enjoy mentoring others and sharing knowledge to develop team capability. Demonstrate a proactive, analytical and continuous improvement mindset. Must hold Microsoft SC-200 Desirable Certifications SC-300 or SC-400 Microsoft AZ-500 GIAC GCIA, GCFA or GCED CREST CRT or CCT Other advanced cloud or cyber security certifications What's in it for me? Competitive salary and benefits package. Flexible hybrid working model with remote working opportunities. Exposure to a broad range of cyber security technologies and customer environments. Opportunity to work on complex and high-impact security incidents. Ongoing learning, certification and professional development support. Clear career progression within a growing cyber security practice. A collaborative and supportive team environment where knowledge sharing is encouraged. The opportunity to influence SOC maturity, service innovation and security outcomes for our customers. Who you'll be doing it for: Atech part of the Iomart Group is a highly accredited Microsoft Partner who delivers transformed technology with managed services. Our team of certified Microsoft experts align with your team to deliver an excellent service tailored to your individual needs, 24/7/365. Our services support 25,000 users globally and proactively monitor 45,000+ devices in key areas: Azure infrastructure managed service Modern Workplace: Office 365, Microsoft 365, and Azure Virtual Desktop Managed Security and SOC with Microsoft Defender, Sentinel We're an equal opportunities employer and want our vacancies to be available to all, so if you need us to make any reasonable adjustments during the process then just let us know.
27/07/2026
Full time
What you'll be doing: At Atech, we believe cyber security is about more than reacting to threats - it's about staying ahead of them. As a leading provider of cloud, cyber security and managed services, we help organisations strengthen their security posture through innovation, expertise and a customer-first approach. We're looking for an experienced Level 3 SOC Analyst to join our growing Security Operations Centre (SOC). This is a senior technical role where you'll lead complex investigations, conduct advanced threat hunting activities and help shape the future of our SOC capability. You'll act as a technical authority during major security incidents while mentoring colleagues and driving continuous improvement across our security services. As a Level 3 SOC Analyst, you'll be: Leading complex cyber security incidents from initial investigation through to containment, eradication and recovery. Acting as the technical escalation point for high-priority and complex security events. Conducting advanced threat hunting activities across endpoint, cloud, identity and email environments. Correlating multiple telemetry sources to reconstruct attack chains, identify root causes and determine remediation actions. Providing clear and confident communication to customers and stakeholders during major security incidents. Developing and enhancing detection use cases, analytics and alert tuning within Microsoft Sentinel and Microsoft Defender XDR. Identifying opportunities to improve SOC processes, standards, tooling and operational maturity. Producing high-quality incident reports, lessons learned documentation and technical recommendations. Mentoring and coaching Level 1 and Level 2 SOC Analysts, helping to raise technical capability across the team. Supporting vulnerability assessment and security posture improvement activities when required. Collaborating with internal and customer technical teams to coordinate effective incident response and recovery. We want to hear from you if you: Have significant experience working within a Security Operations Centre environment. Possess advanced hands-on expertise with Microsoft Sentinel, Microsoft Defender XDR and Microsoft Entra ID Protection. Have a strong background in threat hunting, incident response and cyber security investigations. Can analyse and correlate data from multiple telemetry sources to uncover threats and reconstruct attack activity. Are confident leading major incidents and providing technical direction under pressure. Have experience improving detection logic, tuning security tools and enhancing SOC effectiveness. Can communicate complex technical information clearly to both technical and non-technical audiences. Enjoy mentoring others and sharing knowledge to develop team capability. Demonstrate a proactive, analytical and continuous improvement mindset. Must hold Microsoft SC-200 Desirable Certifications SC-300 or SC-400 Microsoft AZ-500 GIAC GCIA, GCFA or GCED CREST CRT or CCT Other advanced cloud or cyber security certifications What's in it for me? Competitive salary and benefits package. Flexible hybrid working model with remote working opportunities. Exposure to a broad range of cyber security technologies and customer environments. Opportunity to work on complex and high-impact security incidents. Ongoing learning, certification and professional development support. Clear career progression within a growing cyber security practice. A collaborative and supportive team environment where knowledge sharing is encouraged. The opportunity to influence SOC maturity, service innovation and security outcomes for our customers. Who you'll be doing it for: Atech part of the Iomart Group is a highly accredited Microsoft Partner who delivers transformed technology with managed services. Our team of certified Microsoft experts align with your team to deliver an excellent service tailored to your individual needs, 24/7/365. Our services support 25,000 users globally and proactively monitor 45,000+ devices in key areas: Azure infrastructure managed service Modern Workplace: Office 365, Microsoft 365, and Azure Virtual Desktop Managed Security and SOC with Microsoft Defender, Sentinel We're an equal opportunities employer and want our vacancies to be available to all, so if you need us to make any reasonable adjustments during the process then just let us know.
We're looking for a Senior Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high impact work that shapes how we detect and respond to threats at scale. You'll collaborate closely with our inhouse Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of it's kind at this scale, then this is the role for you. At Our Future Health, our mission is to transform the prevention,detectionand treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you. What you'll be doing Developing new threat-led detections in collaboration with our threat teambased on both threat intelligenceand the results of threat hunts. Creating novel analytic methods and techniques for incident detection. Working with our MSP provided SOC tomaintainour detectioncatalogueand tune existing rules. Developing and tuning Data Loss Prevention, Insider RiskManagementand other types of security rules withinMicrosoft Purviewand other key security monitoring tools. Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided,detections and other types of engineering work are delivered to theappropriate standardand that the maturity (inc. efficiency) of our security monitoring is continually improving. Supporting the development ofautomated custom reports on security operational performance and broader security topics (using Sentinel workbooks). Collaborating with wider tech and security teams on theappropriatesecuritymonitoringfor our various systems, including cloud platforms, SaaS applications and inhouse developed systems. Documenting securityprocesses and security tool low-level design/configuration. Contributing to the development of security service delivery and operation documentation. Supporting the security engineers, threatanalystsand wider security team with their various responsibilities, including achieving andmaintainingISO 27001 certification andanything that involves KQL. What you won't be doing Working in a siloed environment with no freedom to make decisions. Working in a place where you can't see the impact your expertise makes. To succeed in this role you will be able to demonstrate some of the following skills and experience: Highly proficient in writing KQL and ideallysome level ofproficiencyinPythonand Terraform. Significant hands on experience with Microsoft Sentinel. Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365. Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities. Experience withMicrosoft Purview tooling, in particular MPIP and Purview Data Loss Prevention. Experience with cloud-native logging(in particular Azureand Kubernetes). Experience of an 'everything-as-code',or at least a 'detection-as-code'approach, including CI/CD pipelines. Exposure to working with/inside an MSP SOC. Exposure to Agile working. Knowledge of attacker Tactics, Techniques and Procedures (TTPs). Knowledge of statistics, datascienceand AI/ML,in particular whenapplied to cyber security. Knowledge ofISO 27001. Desire to be part of a small fast paced team. Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK. Salary from £65,000 per annum. Generous Pension Scheme - We invest in your future with employer contributions of up to 12%. 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you. Enhanced Parental Leave - Supporting you during life's biggest moments. Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice. Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board! Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family. A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements. Join us - let'sprevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at
27/07/2026
Full time
We're looking for a Senior Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high impact work that shapes how we detect and respond to threats at scale. You'll collaborate closely with our inhouse Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of it's kind at this scale, then this is the role for you. At Our Future Health, our mission is to transform the prevention,detectionand treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you. What you'll be doing Developing new threat-led detections in collaboration with our threat teambased on both threat intelligenceand the results of threat hunts. Creating novel analytic methods and techniques for incident detection. Working with our MSP provided SOC tomaintainour detectioncatalogueand tune existing rules. Developing and tuning Data Loss Prevention, Insider RiskManagementand other types of security rules withinMicrosoft Purviewand other key security monitoring tools. Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided,detections and other types of engineering work are delivered to theappropriate standardand that the maturity (inc. efficiency) of our security monitoring is continually improving. Supporting the development ofautomated custom reports on security operational performance and broader security topics (using Sentinel workbooks). Collaborating with wider tech and security teams on theappropriatesecuritymonitoringfor our various systems, including cloud platforms, SaaS applications and inhouse developed systems. Documenting securityprocesses and security tool low-level design/configuration. Contributing to the development of security service delivery and operation documentation. Supporting the security engineers, threatanalystsand wider security team with their various responsibilities, including achieving andmaintainingISO 27001 certification andanything that involves KQL. What you won't be doing Working in a siloed environment with no freedom to make decisions. Working in a place where you can't see the impact your expertise makes. To succeed in this role you will be able to demonstrate some of the following skills and experience: Highly proficient in writing KQL and ideallysome level ofproficiencyinPythonand Terraform. Significant hands on experience with Microsoft Sentinel. Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365. Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities. Experience withMicrosoft Purview tooling, in particular MPIP and Purview Data Loss Prevention. Experience with cloud-native logging(in particular Azureand Kubernetes). Experience of an 'everything-as-code',or at least a 'detection-as-code'approach, including CI/CD pipelines. Exposure to working with/inside an MSP SOC. Exposure to Agile working. Knowledge of attacker Tactics, Techniques and Procedures (TTPs). Knowledge of statistics, datascienceand AI/ML,in particular whenapplied to cyber security. Knowledge ofISO 27001. Desire to be part of a small fast paced team. Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK. Salary from £65,000 per annum. Generous Pension Scheme - We invest in your future with employer contributions of up to 12%. 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you. Enhanced Parental Leave - Supporting you during life's biggest moments. Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice. Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board! Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family. A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements. Join us - let'sprevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at