At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for thriving cities, resilient environments, mission-critical outcomes, operational advancement, scientific discovery and cutting-edge manufacturing, turning abstract ideas into realities that transform the world for good. Your impact This is an exciting opportunity to join Jacobs' Cyber Security team as an Endpoint Security & Exposure Management Engineer. You'll play a key role in reducing cyber risk by driving vulnerability remediation, strengthening endpoint security controls, and improving visibility of security exposure across a global technology estate. Working across infrastructure, cloud, desktop engineering, and security teams, you'll help ensure vulnerabilities are identified, prioritised, and remediated effectively while supporting key security capabilities including application control, privilege management, and endpoint hardening. If you're passionate about vulnerability management, exposure reduction, and delivering measurable security outcomes, this is an opportunity to make a real impact within a global organisation. Day to Day Lead vulnerability and exposure management activities across enterprise environments, ensuring security risks are identified, prioritised, and remediated effectively Work closely with technology teams to drive remediation programmes and reduce organisational cyber risk Support and enhance endpoint security capabilities, including application control, allowlisting, privilege management, and endpoint hardening Use data, reporting, and dashboards to provide visibility of cyber exposure, remediation performance, and security outcomes Assess emerging vulnerabilities and threats, providing risk-based recommendations and guidance to stakeholders Act as a trusted security partner across infrastructure, cloud, application, and operational teams, helping embed secure practices and improve resilience What You'll Bring Experience in cybersecurity, vulnerability management, security engineering, or endpoint security Strong understanding of risk-based vulnerability management and remediation prioritisation Experience working with vulnerability management platforms such as Tenable, Qualys, or Rapid7 Experience with ServiceNow Vulnerability Response or similar remediation workflow platforms Knowledge of endpoint security technologies including application control, privilege management, and endpoint protection A collaborative approach with strong stakeholder engagement and communication skills The ability to translate technical security risks into meaningful business outcomes Experience implementing Zero Trust principles Exposure to Microsoft Defender for Endpoint, Intune, Active Directory, and Entra ID Experience working within cloud environments including Azure, AWS, or Google Cloud Knowledge of frameworks such as NIST, ISO 27001, CIS Controls, Cyber Essentials Plus, and NCSC CAF Industry certifications including CISSP, CISM, Security+, GIAC, Microsoft Security, or ServiceNow certifications What's In It For You Shape how cyber risk is managed across a global organisation Take ownership of a critical vulnerability and exposure management capability Work with leading security technologies across endpoint, cloud, and enterprise environments Influence security strategy and drive measurable improvements to Jacobs' security posture Collaborate with talented cybersecurity, infrastructure, cloud, and engineering professionals around the world Enjoy genuine flexibility with remote and hybrid working options and no mandated office attendance requirements Be part of a team committed to innovation, continuous improvement, and security excellence A global network of expertise and opportunity A culture founded on safety, integrity, inclusion, and belonging Flexible working arrangements that support your well-being and potential Opportunities to make a real-world impact through our global giving and volunteering programs Up to 10% pension 24 days ( days bought) holidays Free medical and income protection insurance and many more! &Data Here's what you'll need Technical Skills Application control and allowlisting technologies Privilege management solutions Endpoint hardening methodologies Zero Trust security principles Endpoint security architecture Vulnerability & Exposure Management Vulnerability assessment and management Risk prioritization frameworks Patch and remediation management Security risk analysis Platforms & Technologies Microsoft Windows Server and Windows 11 Active Directory and Entra ID Microsoft Defender for Endpoint Cloud platforms (Azure, AWS, or Google Cloud) ServiceNow Vulnerability Response Scripting & Automation API integrations and workflow automation Security reporting and dashboard development Preferred Qualifications Experience implementing Zero Trust security controls. Experience with endpoint detection and response (EDR) platforms. Familiarity with security frameworks including: oNIST Cybersecurity Framework oCIS Controls oISO 27001 oNCSC Cyber Assessment Framework Experience with cloud security and hybrid infrastructure environments. Experience leading vulnerability remediation programs across multiple technology domains. Preferred Certifications GIAC Security Certifications Certified Information Security Manager (CISM) Microsoft Security Certifications Strong analytical and problem-solving skills. Excellent stakeholder management and communication abilities. Ability to translate technical risk into business impact. Strong organizational and prioritization skills. Collaborative approach to driving remediation and risk reduction. Continuous improvement mindset focused on measurable security outcomes. Success Measures Reduction in privileged access risk. Increased endpoint security control coverage. Reduction in critical and high-risk vulnerabilities. Improved vulnerability remediation performance and SLA compliance. Improved visibility of enterprise cyber exposure. Successful implementation of least-privilege principles across the endpoint estate. Measurable reduction in organizational attack surface and cyber risk Joining Jacobs not only connects you locally but globally. Our values stand on a foundation of safety, integrity, inclusion and belonging. We put people at the heart of our business, and we truly believe that by supporting one another through our culture of caring, we all succeed. We value positive mental health and a sense of belonging for all employees. With safety and flexibility always top of mind, we've gone beyond traditional ways of working so you have the support, means and space to maximize your potential. You'll uncover flexible working arrangements, benefits, and opportunities, from well-being benefits to our global giving and volunteering program, to exploring new and inventive ways to help our clients make the world a better place. No matter what drives you, you'll discover how you can cultivate, nurture, and achieve your goals - all at a single global company. Find out more about life at Jacobs . We aim to embed inclusion and belonging in everything we do. We know that if we are inclusive, we're more connected and creative. We accept people for who they are, and we champion the richness of different perspectives, lived experiences and backgrounds in the workplace, as a source of learning and innovation. We are committed to building vibrant communities within Jacobs, including through our Jacobs Employee Networks, Communities of Practice and our Find Your Community initiatives, allowing every employee to find connection, purpose, and belonging.Find out more about ourJacobs Employee Networks here . Jacobs partners with VERCIDA to help us attract and retain talent from a wide range of backgrounds. For greater online accessibility please visit to view and access our roles. As a disability confident employer, we will interview disabled candidates who best meet the criteria. We welcome applications from candidates who are seeking flexible working and from those who may not meet all the listed requirements for a role. We value collaboration and believe that in-person interactions are crucial for both our culture and client delivery. We empower employees with our hybrid working policy, allowing them to split their work week between Jacobs offices/projects and remote locations enabling them to deliver their best work. Your application experience is important to us, and we're keen to adapt to make every interaction even better. If you require further support or reasonable adjustments with regards to the recruitment process (for example, you require the application form in a different format), please contact the team via Careers Support .
27/07/2026
Full time
At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for thriving cities, resilient environments, mission-critical outcomes, operational advancement, scientific discovery and cutting-edge manufacturing, turning abstract ideas into realities that transform the world for good. Your impact This is an exciting opportunity to join Jacobs' Cyber Security team as an Endpoint Security & Exposure Management Engineer. You'll play a key role in reducing cyber risk by driving vulnerability remediation, strengthening endpoint security controls, and improving visibility of security exposure across a global technology estate. Working across infrastructure, cloud, desktop engineering, and security teams, you'll help ensure vulnerabilities are identified, prioritised, and remediated effectively while supporting key security capabilities including application control, privilege management, and endpoint hardening. If you're passionate about vulnerability management, exposure reduction, and delivering measurable security outcomes, this is an opportunity to make a real impact within a global organisation. Day to Day Lead vulnerability and exposure management activities across enterprise environments, ensuring security risks are identified, prioritised, and remediated effectively Work closely with technology teams to drive remediation programmes and reduce organisational cyber risk Support and enhance endpoint security capabilities, including application control, allowlisting, privilege management, and endpoint hardening Use data, reporting, and dashboards to provide visibility of cyber exposure, remediation performance, and security outcomes Assess emerging vulnerabilities and threats, providing risk-based recommendations and guidance to stakeholders Act as a trusted security partner across infrastructure, cloud, application, and operational teams, helping embed secure practices and improve resilience What You'll Bring Experience in cybersecurity, vulnerability management, security engineering, or endpoint security Strong understanding of risk-based vulnerability management and remediation prioritisation Experience working with vulnerability management platforms such as Tenable, Qualys, or Rapid7 Experience with ServiceNow Vulnerability Response or similar remediation workflow platforms Knowledge of endpoint security technologies including application control, privilege management, and endpoint protection A collaborative approach with strong stakeholder engagement and communication skills The ability to translate technical security risks into meaningful business outcomes Experience implementing Zero Trust principles Exposure to Microsoft Defender for Endpoint, Intune, Active Directory, and Entra ID Experience working within cloud environments including Azure, AWS, or Google Cloud Knowledge of frameworks such as NIST, ISO 27001, CIS Controls, Cyber Essentials Plus, and NCSC CAF Industry certifications including CISSP, CISM, Security+, GIAC, Microsoft Security, or ServiceNow certifications What's In It For You Shape how cyber risk is managed across a global organisation Take ownership of a critical vulnerability and exposure management capability Work with leading security technologies across endpoint, cloud, and enterprise environments Influence security strategy and drive measurable improvements to Jacobs' security posture Collaborate with talented cybersecurity, infrastructure, cloud, and engineering professionals around the world Enjoy genuine flexibility with remote and hybrid working options and no mandated office attendance requirements Be part of a team committed to innovation, continuous improvement, and security excellence A global network of expertise and opportunity A culture founded on safety, integrity, inclusion, and belonging Flexible working arrangements that support your well-being and potential Opportunities to make a real-world impact through our global giving and volunteering programs Up to 10% pension 24 days ( days bought) holidays Free medical and income protection insurance and many more! &Data Here's what you'll need Technical Skills Application control and allowlisting technologies Privilege management solutions Endpoint hardening methodologies Zero Trust security principles Endpoint security architecture Vulnerability & Exposure Management Vulnerability assessment and management Risk prioritization frameworks Patch and remediation management Security risk analysis Platforms & Technologies Microsoft Windows Server and Windows 11 Active Directory and Entra ID Microsoft Defender for Endpoint Cloud platforms (Azure, AWS, or Google Cloud) ServiceNow Vulnerability Response Scripting & Automation API integrations and workflow automation Security reporting and dashboard development Preferred Qualifications Experience implementing Zero Trust security controls. Experience with endpoint detection and response (EDR) platforms. Familiarity with security frameworks including: oNIST Cybersecurity Framework oCIS Controls oISO 27001 oNCSC Cyber Assessment Framework Experience with cloud security and hybrid infrastructure environments. Experience leading vulnerability remediation programs across multiple technology domains. Preferred Certifications GIAC Security Certifications Certified Information Security Manager (CISM) Microsoft Security Certifications Strong analytical and problem-solving skills. Excellent stakeholder management and communication abilities. Ability to translate technical risk into business impact. Strong organizational and prioritization skills. Collaborative approach to driving remediation and risk reduction. Continuous improvement mindset focused on measurable security outcomes. Success Measures Reduction in privileged access risk. Increased endpoint security control coverage. Reduction in critical and high-risk vulnerabilities. Improved vulnerability remediation performance and SLA compliance. Improved visibility of enterprise cyber exposure. Successful implementation of least-privilege principles across the endpoint estate. Measurable reduction in organizational attack surface and cyber risk Joining Jacobs not only connects you locally but globally. Our values stand on a foundation of safety, integrity, inclusion and belonging. We put people at the heart of our business, and we truly believe that by supporting one another through our culture of caring, we all succeed. We value positive mental health and a sense of belonging for all employees. With safety and flexibility always top of mind, we've gone beyond traditional ways of working so you have the support, means and space to maximize your potential. You'll uncover flexible working arrangements, benefits, and opportunities, from well-being benefits to our global giving and volunteering program, to exploring new and inventive ways to help our clients make the world a better place. No matter what drives you, you'll discover how you can cultivate, nurture, and achieve your goals - all at a single global company. Find out more about life at Jacobs . We aim to embed inclusion and belonging in everything we do. We know that if we are inclusive, we're more connected and creative. We accept people for who they are, and we champion the richness of different perspectives, lived experiences and backgrounds in the workplace, as a source of learning and innovation. We are committed to building vibrant communities within Jacobs, including through our Jacobs Employee Networks, Communities of Practice and our Find Your Community initiatives, allowing every employee to find connection, purpose, and belonging.Find out more about ourJacobs Employee Networks here . Jacobs partners with VERCIDA to help us attract and retain talent from a wide range of backgrounds. For greater online accessibility please visit to view and access our roles. As a disability confident employer, we will interview disabled candidates who best meet the criteria. We welcome applications from candidates who are seeking flexible working and from those who may not meet all the listed requirements for a role. We value collaboration and believe that in-person interactions are crucial for both our culture and client delivery. We empower employees with our hybrid working policy, allowing them to split their work week between Jacobs offices/projects and remote locations enabling them to deliver their best work. Your application experience is important to us, and we're keen to adapt to make every interaction even better. If you require further support or reasonable adjustments with regards to the recruitment process (for example, you require the application form in a different format), please contact the team via Careers Support .
Senior Manager Cyber RiskApplylocations: London, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: R Cyber Risk Senior Manager LSEG is investing heavily in technology innovation including Cloud and AI. We need a Senior Manager, Group Cyber Risk who will be responsible for providing independent second-line oversight, review and challenge of the Group's cyber risk profile and cyber control environment. The role supports effective cyber risk management across the organisation, ensuring risks are understood, managed and appropriately reported to senior management and governance forums.This role provides an opportunity to influence Cyber Security at one of the world's leading financial market infrastructure providers. The successful candidate will gain exposure to complex global technology environments including Cloud, Artificial Intelligence, critical market infrastructure, operational resilience, cybersecurity and technology transformation programmes. The role offers engagement with senior leadership, risk committees, and regulatory forums, providing a platform to shape strategic decisions and drive meaningful risk outcomes across the Group and Sector.As cyber threats, regulation, and technology continue to evolve, the role provides significant opportunities for professional growth, thought leadership and industry engagement. The successful candidate will be engaged in key cyber risk topics including AI governance, cloud risk management, cyber resilience, supply chain security and evolving regulatory expectations.Group Cyber Risk is the independent second line of defence function responsible for oversight, review and challenge of cyber risk management across LSEG. The role operates in a lean team that works closely with Cyber Security, Technology, Operational Resilience, Risk and Audit teams, providing expert cyber risk guidance, challenge and thought leadership on emerging threats and industry developments. Key elements of the role include: Cyber Risk Oversight : Provide independent oversight, review and challenge of the cyber risk profile and cyber control environment. Oversight of LSEG cyber risk management practices, governance, and risk reporting. Provide oversight during cyber incidents, ensuring timely action, effective risk management and appropriate governance. The team ensures accurate articulation of inherent and residual risks and assessment of controls. Oversight of the group cybersecurity program, Issue management, Key Risk Indicators (KRIs) and compliance to Policy. Review of KRIs and other risk telemetry to identify thematic cyber risks and control deficiencies. Risk Reviews, Briefings and Position Papers : Thematic reviews and assessments on controls, risks and emerging risks. Briefings on material external market events / incidents, 'could this happen here?'. Analysis of new cyber risk management practices and approaches. Stakeholder Management : Build positive relationships with security, technology, risk, audit, and business partners. Influence decision-making through effective communication of cyber risk issues. Provide subject matter expertise on cyber risk and industry developments and act as a trusted advisor to senior stakeholders on cyber risk matters. Preferred Qualifications & Experience: A deep technical understanding of cybersecurity Experience and qualifications related to Information Security and Cyber Risk e.g. CISSP, CISA, CISM, CRISC. Experience in the financial services or consultancy sectors will be useful. Experience of Cyber risk frameworks, regulations and an understanding of good practice. Understanding of the core controls and metrics used to manage cyber risks. Knowledge and experience of Cloud Services and AI is useful, particularly the security risks and how to mitigate them Career Stage: Manager London Stock Exchange Group (LSEG) Information: Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership , Excellence and Change underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce.We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyone's race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.You will be part of a collaborative and creative culture where we encourage new ideas. We are committed to sustainability across our global business and we are proud to partner with our customers to help them meet their sustainability objectives. Our charity, the LSEG Foundation provides charitable grants to community groups that help people access economic opportunities and build a secure future with financial independence. Colleagues can get involved through fundraising and volunteering.LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.Please take a moment to read this privacy notice carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what it's used for, and how it's obtained, your rights and how to contact us as a data subject.If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice. HOW TO APPLY?If you want to apply for a job, please click the Apply button. You will then be redirected to our Careers sign-in page where you can enter your existing credentials or set up an account with us.
27/07/2026
Full time
Senior Manager Cyber RiskApplylocations: London, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: R Cyber Risk Senior Manager LSEG is investing heavily in technology innovation including Cloud and AI. We need a Senior Manager, Group Cyber Risk who will be responsible for providing independent second-line oversight, review and challenge of the Group's cyber risk profile and cyber control environment. The role supports effective cyber risk management across the organisation, ensuring risks are understood, managed and appropriately reported to senior management and governance forums.This role provides an opportunity to influence Cyber Security at one of the world's leading financial market infrastructure providers. The successful candidate will gain exposure to complex global technology environments including Cloud, Artificial Intelligence, critical market infrastructure, operational resilience, cybersecurity and technology transformation programmes. The role offers engagement with senior leadership, risk committees, and regulatory forums, providing a platform to shape strategic decisions and drive meaningful risk outcomes across the Group and Sector.As cyber threats, regulation, and technology continue to evolve, the role provides significant opportunities for professional growth, thought leadership and industry engagement. The successful candidate will be engaged in key cyber risk topics including AI governance, cloud risk management, cyber resilience, supply chain security and evolving regulatory expectations.Group Cyber Risk is the independent second line of defence function responsible for oversight, review and challenge of cyber risk management across LSEG. The role operates in a lean team that works closely with Cyber Security, Technology, Operational Resilience, Risk and Audit teams, providing expert cyber risk guidance, challenge and thought leadership on emerging threats and industry developments. Key elements of the role include: Cyber Risk Oversight : Provide independent oversight, review and challenge of the cyber risk profile and cyber control environment. Oversight of LSEG cyber risk management practices, governance, and risk reporting. Provide oversight during cyber incidents, ensuring timely action, effective risk management and appropriate governance. The team ensures accurate articulation of inherent and residual risks and assessment of controls. Oversight of the group cybersecurity program, Issue management, Key Risk Indicators (KRIs) and compliance to Policy. Review of KRIs and other risk telemetry to identify thematic cyber risks and control deficiencies. Risk Reviews, Briefings and Position Papers : Thematic reviews and assessments on controls, risks and emerging risks. Briefings on material external market events / incidents, 'could this happen here?'. Analysis of new cyber risk management practices and approaches. Stakeholder Management : Build positive relationships with security, technology, risk, audit, and business partners. Influence decision-making through effective communication of cyber risk issues. Provide subject matter expertise on cyber risk and industry developments and act as a trusted advisor to senior stakeholders on cyber risk matters. Preferred Qualifications & Experience: A deep technical understanding of cybersecurity Experience and qualifications related to Information Security and Cyber Risk e.g. CISSP, CISA, CISM, CRISC. Experience in the financial services or consultancy sectors will be useful. Experience of Cyber risk frameworks, regulations and an understanding of good practice. Understanding of the core controls and metrics used to manage cyber risks. Knowledge and experience of Cloud Services and AI is useful, particularly the security risks and how to mitigate them Career Stage: Manager London Stock Exchange Group (LSEG) Information: Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership , Excellence and Change underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce.We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyone's race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.You will be part of a collaborative and creative culture where we encourage new ideas. We are committed to sustainability across our global business and we are proud to partner with our customers to help them meet their sustainability objectives. Our charity, the LSEG Foundation provides charitable grants to community groups that help people access economic opportunities and build a secure future with financial independence. Colleagues can get involved through fundraising and volunteering.LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.Please take a moment to read this privacy notice carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what it's used for, and how it's obtained, your rights and how to contact us as a data subject.If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice. HOW TO APPLY?If you want to apply for a job, please click the Apply button. You will then be redirected to our Careers sign-in page where you can enter your existing credentials or set up an account with us.
About The Role We're looking for an experienced Vulnerability & Exposure Manager to lead and mature our vulnerability management capability. As a leading UK life and pensions mutual insurer with a proud history dating back to 1843, we exist to help people live financially confident lives - protecting their income while they work and maximising it when they stop. Today, over one million members and customers trust us to look after their futures, families and finances. Joining us means becoming part of a team that puts our members, customers and advisers at the heart of everything we do. We're committed to creating an inclusive culture where colleagues can thrive. We are proud to have built a workplace where our colleagues feel welcomed, respected, supported and valued - reflected in our recognition as one of the Financial Times UK's Best Employers in 2025 and 2026. We celebrate individuality and believe our differences make us stronger, so bring your true self and help shape the future of LV=. This is a highly visible role responsible for identifying, prioritising and driving the remediation of vulnerabilities across infrastructure, cloud platforms, applications, containers and third-party services. Working closely with Security Operations, Cloud Engineering, Platform Teams, Development Teams, Architecture and Technology leadership, you'll ensure that cyber risks are understood, prioritised and reduced through effective governance, intelligence-led decision making and strong stakeholder engagement. This is an excellent opportunity for someone who enjoys combining technical expertise, data-driven analysis and influencing skills to deliver measurable security outcomes. The role follows a hybrid working pattern, with regular attendance required at our Bournemouth office. Key Responsibilities Lead the organisation's end-to-end vulnerability management programme. Manage vulnerability scanning, analysis, prioritisation, reporting and remediation governance. Drive risk-based remediation using threat intelligence, exploitability data and business context. Partner with technology teams to reduce exposure across cloud, infrastructure, applications and endpoints. Maintain and optimise vulnerability management tooling and asset coverage. Produce executive-level reporting, dashboards and KPI metrics demonstrating risk reduction and programme effectiveness. Escalate high-risk or overdue vulnerabilities and influence remediation priorities. Identify systemic weaknesses and recommend strategic improvements to security architecture and operating practices. Support continuous improvement through automation, integration and enhanced asset visibility. About You You'll be comfortable operating at both a technical and strategic level, translating complex vulnerability data into clear risk-based actions. Essential Experience Proven experience in vulnerability management, security operations or security engineering Hands-on experience with vulnerability scanning platforms and remediation workflows Strong understanding of CVEs, CVSS, exploitability, patch management and security configuration practices Experience working with cloud technologies, modern infrastructure and enterprise applications Ability to analyse large datasets and identify trends, risks and systemic issues Strong stakeholder management skills with the confidence to challenge constructively and drive action Experience producing reports and presentations for senior stakeholders Technical Knowledge Experience with some of the following: Vulnerability platforms such as Rapid7, Tenable, Qualys or Microsoft Defender TVM Azure cloud environments Endpoint and patch management technologies SIEM, EDR and threat intelligence platforms Security tools supporting application and container security ITSM, ticketing and reporting solutions such as ServiceNow, Jira or Power BI Desirable Certifications CompTIA Security+ or CySA+ GIAC certifications (GSEC, GCIH, GSTRT) Microsoft SC-200 and/or AZ-500 Tenable, Qualys or Rapid7 certifications ITIL Foundation Rewards and Benefits At LV= Savings and Retirement, you'll go above and beyond to do the right thing for our customers. We'll reward your hard work with an attractive, competitive salary and benefits package, which includes: 30 days' holiday, with the option to buy up to 5 additional days Competitive pension scheme - LV= Life and Pensions will double-match the amount you pay, up to 14% (subject to National Minimum Wage requirements) An annual bonus scheme based on personal performance Single-cover private medical insurance (with the option for you to upgrade to family cover) Flexible benefits, including a cycle to work scheme, personal accident insurance, critical illness cover and dental insurance Up to 20% discount on our life products for you and your immediate family A group life assurance policy with 4 x your basic pay to go to your dependents (you'll have the option to increase to 8 x cover) Group Income Protection (if you become a member of the Pension scheme and reach 5 years of service) Access to our Employee Assistance Programme (EAP) for support when you need it A virtual GP service Shared parental leave Up to 20% discount on our life products for you and your immediate family. Please note that we are unable to offer Skilled Worker Visa Sponsorship for this role. Therefore, you must ensure that you are eligible to work in the UK without our sponsorship for your application to be considered. About Us We're proud of our inclusive culture at LV= and, as an equal-opportunity employer, we continually work to remove unconscious bias from our recruitment process. We value our colleagues for what they bring to our team regardless of any protected status or characteristics they may have. Talk to us about flexible working as part of your application; if it's right for you, our members and customers, and our business, then we'll do everything we can to make it happen.
26/07/2026
Full time
About The Role We're looking for an experienced Vulnerability & Exposure Manager to lead and mature our vulnerability management capability. As a leading UK life and pensions mutual insurer with a proud history dating back to 1843, we exist to help people live financially confident lives - protecting their income while they work and maximising it when they stop. Today, over one million members and customers trust us to look after their futures, families and finances. Joining us means becoming part of a team that puts our members, customers and advisers at the heart of everything we do. We're committed to creating an inclusive culture where colleagues can thrive. We are proud to have built a workplace where our colleagues feel welcomed, respected, supported and valued - reflected in our recognition as one of the Financial Times UK's Best Employers in 2025 and 2026. We celebrate individuality and believe our differences make us stronger, so bring your true self and help shape the future of LV=. This is a highly visible role responsible for identifying, prioritising and driving the remediation of vulnerabilities across infrastructure, cloud platforms, applications, containers and third-party services. Working closely with Security Operations, Cloud Engineering, Platform Teams, Development Teams, Architecture and Technology leadership, you'll ensure that cyber risks are understood, prioritised and reduced through effective governance, intelligence-led decision making and strong stakeholder engagement. This is an excellent opportunity for someone who enjoys combining technical expertise, data-driven analysis and influencing skills to deliver measurable security outcomes. The role follows a hybrid working pattern, with regular attendance required at our Bournemouth office. Key Responsibilities Lead the organisation's end-to-end vulnerability management programme. Manage vulnerability scanning, analysis, prioritisation, reporting and remediation governance. Drive risk-based remediation using threat intelligence, exploitability data and business context. Partner with technology teams to reduce exposure across cloud, infrastructure, applications and endpoints. Maintain and optimise vulnerability management tooling and asset coverage. Produce executive-level reporting, dashboards and KPI metrics demonstrating risk reduction and programme effectiveness. Escalate high-risk or overdue vulnerabilities and influence remediation priorities. Identify systemic weaknesses and recommend strategic improvements to security architecture and operating practices. Support continuous improvement through automation, integration and enhanced asset visibility. About You You'll be comfortable operating at both a technical and strategic level, translating complex vulnerability data into clear risk-based actions. Essential Experience Proven experience in vulnerability management, security operations or security engineering Hands-on experience with vulnerability scanning platforms and remediation workflows Strong understanding of CVEs, CVSS, exploitability, patch management and security configuration practices Experience working with cloud technologies, modern infrastructure and enterprise applications Ability to analyse large datasets and identify trends, risks and systemic issues Strong stakeholder management skills with the confidence to challenge constructively and drive action Experience producing reports and presentations for senior stakeholders Technical Knowledge Experience with some of the following: Vulnerability platforms such as Rapid7, Tenable, Qualys or Microsoft Defender TVM Azure cloud environments Endpoint and patch management technologies SIEM, EDR and threat intelligence platforms Security tools supporting application and container security ITSM, ticketing and reporting solutions such as ServiceNow, Jira or Power BI Desirable Certifications CompTIA Security+ or CySA+ GIAC certifications (GSEC, GCIH, GSTRT) Microsoft SC-200 and/or AZ-500 Tenable, Qualys or Rapid7 certifications ITIL Foundation Rewards and Benefits At LV= Savings and Retirement, you'll go above and beyond to do the right thing for our customers. We'll reward your hard work with an attractive, competitive salary and benefits package, which includes: 30 days' holiday, with the option to buy up to 5 additional days Competitive pension scheme - LV= Life and Pensions will double-match the amount you pay, up to 14% (subject to National Minimum Wage requirements) An annual bonus scheme based on personal performance Single-cover private medical insurance (with the option for you to upgrade to family cover) Flexible benefits, including a cycle to work scheme, personal accident insurance, critical illness cover and dental insurance Up to 20% discount on our life products for you and your immediate family A group life assurance policy with 4 x your basic pay to go to your dependents (you'll have the option to increase to 8 x cover) Group Income Protection (if you become a member of the Pension scheme and reach 5 years of service) Access to our Employee Assistance Programme (EAP) for support when you need it A virtual GP service Shared parental leave Up to 20% discount on our life products for you and your immediate family. Please note that we are unable to offer Skilled Worker Visa Sponsorship for this role. Therefore, you must ensure that you are eligible to work in the UK without our sponsorship for your application to be considered. About Us We're proud of our inclusive culture at LV= and, as an equal-opportunity employer, we continually work to remove unconscious bias from our recruitment process. We value our colleagues for what they bring to our team regardless of any protected status or characteristics they may have. Talk to us about flexible working as part of your application; if it's right for you, our members and customers, and our business, then we'll do everything we can to make it happen.
Overview We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity. From our London HQ, we unite world class researchers and engineers in an environment that values deep exploration and methodical execution - because the best ideas take time to evolve. Together we're building a world class platform to amplify our teams' most powerful ideas. Security is foundational to this mission and must be delivered in a way that supports how our engineering teams build and operate complex systems at scale. Take the next step in your career. Key Responsibilities Leading, developing and growing a team of offensive security engineers and penetration testers. Owning and delivering the offensive security testing programme across the firm's highest priority systems, balancing recurring assessments with testing of new and changing services. Managing testing intake, prioritisation and resourcing, including coordinating external testing partners where required. Driving offensive testing methodologies, from scope definition through to safe validation of real world attack paths and control effectiveness. Establishing attack chain validation and continuous purple teaming with detection and response teams. Introducing automated assurance capabilities, including breach and attack simulation and adversary emulation tooling. Overseeing physical and social engineering assessment where appropriate. Reporting meaningful security metrics to demonstrate control effectiveness and drive continuous improvement. Building strong working relationships across engineering, risk and incident response teams, communicating findings and influencing decisions through evidence and technical credibility. Qualifications Strong hands on experience in offensive security and penetration testing across networks, web and APIs, cloud and infrastructure. Experience with CI/CD, Kubernetes and identity systems, with exposure to AI or agentic systems. Experience defining testing scope, rules of engagement and threat led, attack chain based assessments. Familiarity with automation, breach and attack simulation tooling or other approaches to scaling offensive testing. Experience leading or developing technical teams, including performance management and coaching. Strong judgement in prioritising work, balancing risk, impact and competing demands. Experience building teams and evolving ways of working as the function matures. Strong communication skills, with the ability to explain offensive findings and drive remediation. Ability to influence technical decisions through credibility, evidence and collaboration. Benefits Highly competitive compensation plus annual discretionary bonus. Lunch provided via Just Eat for Business and dedicated barista bar. 35 days' annual leave. 9% company pension contributions. Informal dress code and excellent work life balance. Comprehensive healthcare and life assurance. Cycle to work scheme. Monthly company events. G-Research is committed to cultivating and preserving an inclusive work environment. We place great value on diversity of experience and opinions and want to ensure that applicants receive a recruitment experience that enables them to perform at their best. If you have a disability or special need that requires accommodation, please let us know in the relevant section.
25/07/2026
Full time
Overview We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity. From our London HQ, we unite world class researchers and engineers in an environment that values deep exploration and methodical execution - because the best ideas take time to evolve. Together we're building a world class platform to amplify our teams' most powerful ideas. Security is foundational to this mission and must be delivered in a way that supports how our engineering teams build and operate complex systems at scale. Take the next step in your career. Key Responsibilities Leading, developing and growing a team of offensive security engineers and penetration testers. Owning and delivering the offensive security testing programme across the firm's highest priority systems, balancing recurring assessments with testing of new and changing services. Managing testing intake, prioritisation and resourcing, including coordinating external testing partners where required. Driving offensive testing methodologies, from scope definition through to safe validation of real world attack paths and control effectiveness. Establishing attack chain validation and continuous purple teaming with detection and response teams. Introducing automated assurance capabilities, including breach and attack simulation and adversary emulation tooling. Overseeing physical and social engineering assessment where appropriate. Reporting meaningful security metrics to demonstrate control effectiveness and drive continuous improvement. Building strong working relationships across engineering, risk and incident response teams, communicating findings and influencing decisions through evidence and technical credibility. Qualifications Strong hands on experience in offensive security and penetration testing across networks, web and APIs, cloud and infrastructure. Experience with CI/CD, Kubernetes and identity systems, with exposure to AI or agentic systems. Experience defining testing scope, rules of engagement and threat led, attack chain based assessments. Familiarity with automation, breach and attack simulation tooling or other approaches to scaling offensive testing. Experience leading or developing technical teams, including performance management and coaching. Strong judgement in prioritising work, balancing risk, impact and competing demands. Experience building teams and evolving ways of working as the function matures. Strong communication skills, with the ability to explain offensive findings and drive remediation. Ability to influence technical decisions through credibility, evidence and collaboration. Benefits Highly competitive compensation plus annual discretionary bonus. Lunch provided via Just Eat for Business and dedicated barista bar. 35 days' annual leave. 9% company pension contributions. Informal dress code and excellent work life balance. Comprehensive healthcare and life assurance. Cycle to work scheme. Monthly company events. G-Research is committed to cultivating and preserving an inclusive work environment. We place great value on diversity of experience and opinions and want to ensure that applicants receive a recruitment experience that enables them to perform at their best. If you have a disability or special need that requires accommodation, please let us know in the relevant section.
IT Security Analyst Leatherhead, Surrey (Hybrid) £413.40 per day PAYE (Inclusive of Holiday Pay) 16-Week Contract Immediate Start BPSS Required Looking for your next cyber security contract with genuine enterprise-scale exposure? We are recruiting an experienced IT Security Analyst to join the cyber security team of a leading UK organisation, where you will play a pivotal role in protecting critical business systems, responding to emerging threats and driving cyber security best practice across the business. This is an excellent opportunity to work within a mature security environment, collaborating with experienced Security Operations teams and utilising the latest Microsoft Defender technologies to strengthen security operations, improve cyber resilience and influence security awareness across a large and complex organisation. If you enjoy combining technical security expertise with threat intelligence, incident response and user engagement, this contract offers the opportunity to make a visible impact from day one. What's on Offer? £413.40 per day PAYE (inclusive of holiday pay) Weekly PAYE payments with no umbrella company required. Transparent PAYE pay with no hidden umbrella fees or administration charges. Hybrid working with an excellent work-life balance. Exposure to enterprise-scale Microsoft security technologies. Opportunity to work alongside experienced cyber security professionals within a mature security function. Broad, varied role covering Security Operations, Threat Intelligence, Security Awareness and Incident Response. A high-profile enterprise environment that will strengthen your CV. Immediate start with the potential for contract extension. The Role Working closely with the IT Security Manager, you will support the delivery and continuous improvement of the organisation's cyber security programme. Your responsibilities will include: Supporting security operations, incident investigations and response activities. Working with the Security Operations Centre (SOC) to investigate threats and security alerts. Conducting cyber threat intelligence research, identifying emerging risks, Indicators of Compromise (IOCs) and attacker Tactics, Techniques and Procedures (TTPs). Supporting investigations and remediation using Microsoft Defender XDR and the wider Microsoft Defender security suite. Leading cyber security awareness campaigns and phishing simulations using KnowBe4. Producing regular compliance reporting and user engagement metrics. Creating engaging security awareness content across email, intranet, internal communications and face-to-face sessions. Improving operational security processes, including access management, vulnerability management and incident management. Producing meaningful dashboards, reports and KPIs for technical and non-technical stakeholders. Promoting a positive cyber security culture through collaboration, communication and education. What You'll Bring Experience as an IT Security Analyst or within a Cyber Security environment. Experience working with a Security Operations Centre (SOC), Managed Security Service Provider (MSSP) or security operations team. Strong knowledge of cyber threat intelligence, including IOCs, TTPs and threat analysis. Experience delivering cyber security awareness programmes and phishing simulations using KnowBe4 or similar platforms. Good understanding of Cyber Essentials and recognised cyber security frameworks. Hands-on experience with the Microsoft Defender security suite, including Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Identity and Defender for Cloud Apps. Strong analytical, reporting and problem-solving skills. Excellent communication skills with the ability to engage both technical and non-technical stakeholders. Apply If you are looking for your next IT Security contract where you can contribute to meaningful cyber security initiatives within a large-scale enterprise environment, we would be delighted to hear from you. Apply now for immediate consideration. Should your application be successful, you will be contacted shortly. Please note: The job title shown above may be different to local job titles used in the client's business and issued on their contract of employment. Thank you for your interest in our role. E Personnel Recruitment endeavours to respond to all applications; however, due to the volume of CVs received, this may not always be possible. Apply in the strictest of confidence to E Personnel Recruitment, specialists in Permanent & Temporary Recruitment and a member of the Recruitment & Employment Confederation (REC) which is the professional body for the recruitment industry.
20/07/2026
Seasonal
IT Security Analyst Leatherhead, Surrey (Hybrid) £413.40 per day PAYE (Inclusive of Holiday Pay) 16-Week Contract Immediate Start BPSS Required Looking for your next cyber security contract with genuine enterprise-scale exposure? We are recruiting an experienced IT Security Analyst to join the cyber security team of a leading UK organisation, where you will play a pivotal role in protecting critical business systems, responding to emerging threats and driving cyber security best practice across the business. This is an excellent opportunity to work within a mature security environment, collaborating with experienced Security Operations teams and utilising the latest Microsoft Defender technologies to strengthen security operations, improve cyber resilience and influence security awareness across a large and complex organisation. If you enjoy combining technical security expertise with threat intelligence, incident response and user engagement, this contract offers the opportunity to make a visible impact from day one. What's on Offer? £413.40 per day PAYE (inclusive of holiday pay) Weekly PAYE payments with no umbrella company required. Transparent PAYE pay with no hidden umbrella fees or administration charges. Hybrid working with an excellent work-life balance. Exposure to enterprise-scale Microsoft security technologies. Opportunity to work alongside experienced cyber security professionals within a mature security function. Broad, varied role covering Security Operations, Threat Intelligence, Security Awareness and Incident Response. A high-profile enterprise environment that will strengthen your CV. Immediate start with the potential for contract extension. The Role Working closely with the IT Security Manager, you will support the delivery and continuous improvement of the organisation's cyber security programme. Your responsibilities will include: Supporting security operations, incident investigations and response activities. Working with the Security Operations Centre (SOC) to investigate threats and security alerts. Conducting cyber threat intelligence research, identifying emerging risks, Indicators of Compromise (IOCs) and attacker Tactics, Techniques and Procedures (TTPs). Supporting investigations and remediation using Microsoft Defender XDR and the wider Microsoft Defender security suite. Leading cyber security awareness campaigns and phishing simulations using KnowBe4. Producing regular compliance reporting and user engagement metrics. Creating engaging security awareness content across email, intranet, internal communications and face-to-face sessions. Improving operational security processes, including access management, vulnerability management and incident management. Producing meaningful dashboards, reports and KPIs for technical and non-technical stakeholders. Promoting a positive cyber security culture through collaboration, communication and education. What You'll Bring Experience as an IT Security Analyst or within a Cyber Security environment. Experience working with a Security Operations Centre (SOC), Managed Security Service Provider (MSSP) or security operations team. Strong knowledge of cyber threat intelligence, including IOCs, TTPs and threat analysis. Experience delivering cyber security awareness programmes and phishing simulations using KnowBe4 or similar platforms. Good understanding of Cyber Essentials and recognised cyber security frameworks. Hands-on experience with the Microsoft Defender security suite, including Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Identity and Defender for Cloud Apps. Strong analytical, reporting and problem-solving skills. Excellent communication skills with the ability to engage both technical and non-technical stakeholders. Apply If you are looking for your next IT Security contract where you can contribute to meaningful cyber security initiatives within a large-scale enterprise environment, we would be delighted to hear from you. Apply now for immediate consideration. Should your application be successful, you will be contacted shortly. Please note: The job title shown above may be different to local job titles used in the client's business and issued on their contract of employment. Thank you for your interest in our role. E Personnel Recruitment endeavours to respond to all applications; however, due to the volume of CVs received, this may not always be possible. Apply in the strictest of confidence to E Personnel Recruitment, specialists in Permanent & Temporary Recruitment and a member of the Recruitment & Employment Confederation (REC) which is the professional body for the recruitment industry.
Manchester, Glasgow, London or Newbury/Hybrid A bit about us At Gamma, we're a dynamic, forward-thinking team revolutionizing the way businesses connect and communicate. We provide voice, data, and mobile solutions to businesses across the UK, Germany, Spain, and the Benelux region. We're expanding rapidly to bring digital automation and Gamma-powered services to Enterprise, Public Sector and Small to medium businesses, both direct and through a growing network of channel partners. We move fast with a start up mindset, but we have the stability of a leading European business. Our team thrives on collaboration, innovation, and the belief that diverse perspectives make us stronger. Join us, and you'll have the opportunity to make an impact, grow your career, and be part of a company that celebrates inclusivity and fresh ideas. Who are we looking for? We are seeking a skilled and client focused Security Engineer with strong expertise in Vulnerability Management and Network Security engineering. This role operates within a managed service provider environment, delivering security services to enterprise clients, with a primary focus on risk based vulnerability management alongside network security, firewall optimisation and access control. The successful candidate will be responsible for identifying, assessing, prioritising and driving remediation of vulnerabilities across complex enterprise environments. In addition, they will contribute to strengthening overall cyber resilience by aligning vulnerability management with Managed Detection and Response (MDR) operations, supporting Secure Access Service Edge (SASE) frameworks and advancing Zero Trust security models across network, identity and access control layers. This is a hands on engineering role requiring deep technical expertise across vulnerability management and network security, combined with strong stakeholder engagement. The role ensures security risks are proactively reduced, controls are optimised and remediation is delivered in line with contractual SLAs and cyber security best practices. What will you be doing day to day? Key Responsibilities Vulnerability Management Services Deliver end to end vulnerability management services to clients, including discovery, assessment, prioritisation, reporting and remediation tracking Operate and maintain vulnerability scanning tools (e.g. Qualys, Nessus, Rapid7) across multiple client environments Perform regular vulnerability scans, validation and re testing to ensure remediation effectiveness Analyse vulnerability data, eliminate false positives and provide actionable remediation guidance tailored to client environments Prioritise vulnerabilities using risk based methodologies (CVSS, exploitability, business impact, threat intelligence) Track remediation activities and ensure closure within agreed SLAs and service metrics Produce client facing reports, dashboards and service reviews, highlighting risk posture, trends and key improvement areas Act as a trusted advisor to clients, providing best practice recommendations on vulnerability and risk reduction strategies Security Engineering & Detection Support deployment and optimisation of Microsoft Sentinel and SIEM/XDR platforms Contribute to detection engineering (use case development, rule tuning, alert optimisation) Onboard and integrate telemetry across network, endpoint, cloud and identity sources Support threat detection across SIEM, NDR and identity platforms Collaborate with SOC teams to improve detection coverage and reduce false positives Align vulnerability insights with MDR workflows and threat detection use cases Network Security & Remediation Identify, analyse and manage network and system vulnerabilities across enterprise environments Collaborate with infrastructure, cloud and application teams to drive remediation activities to completion Troubleshoot and resolve network/security issues linked to vulnerabilities and access controls Support secure network architecture and ensure adherence to security and compliance standards Support SASE architectures (e.g. Prisma, Cisco Secure) and secure connectivity models Contribute to Zero Trust implementation, including least privilege and identity controls Strengthen security posture across hybrid environments (network, cloud, SaaS, identity) Support pre sales activities, including solution design and vulnerability management offerings Provide SME input into RFPs, bids and technical workshops Assist with onboarding clients and transitioning services into BAU Build strong client relationships and act as a trusted technical advisor Support service adoption and continuous improvement initiatives Governance, Reporting & Documentation Maintain accurate records of vulnerabilities, remediation plans and audit evidence Support client audits, compliance requirements and security assessments Contribute to service improvement initiatives, automation and process optimisation Ensure adherence to ITIL based service management practices where applicable Breach Attack Simulation (BAS) Design, implement and maintain BAS scenarios to continuously validate the effectiveness of security controls across the enterprise Configure and operate BAS platforms to simulate real world threat actor techniques (MITRE ATT&CK aligned) and identify control gaps Analyse BAS results to prioritise vulnerabilities, misconfigurations and detection gaps, feeding findings into the vulnerability management lifecycle What you'll need: Strong experience in delivering vulnerability management services, ideally within a managed service or consultancy environment Deep understanding of vulnerability lifecycle management (discovery / assessment / remediation / validation / reporting) Hands on experience with Tufin (SecureTrack / SecureChange) or similar tools such as Palo Alto Panorama or Cisco Defense Orchestrator Proficiency with vulnerability scanning tools (Qualys, Nessus, Rapid7) Solid knowledge of network security principles (firewalls, VPNs, segmentation, protocols) Experience working with client stakeholders and managing competing priorities Ability to translate technical vulnerabilities into business risk and remediation actions Strong analytical, troubleshooting and communication skills Nice to haves Certifications such as CCNA / Security+ / CEH / CISSP (or working towards) Experience in multi client or managed security service provider (MSSP) environments Familiarity with multi vendor firewalls (Cisco, Palo Alto, Check Point) Knowledge of compliance frameworks (ISO 27001, NIST, CIS, PCI DSS) Exposure to risk based vulnerability management and threat intelligence integration Understanding of ITIL service delivery and SLA driven environments Experience with SASE, Zero Trust, MDR/XDR platforms Experience with RSA Authentication Manager or similar IAM solutions What do we offer you? At Gamma, we believe in work life balance, which is why we offer 25 days of annual leave, plus an extra day off for your birthday. Giving back is important to us, so we also provide a volunteer day to support a charity that matters to you. Family matters, too. With enhanced maternity and paternity pay and childcare vouchers, we're here to support you as a parent and help you thrive in your career. We care about your future, so our pension plan helps you save for the years ahead with contributions of 4.59% from Gamma, alongside your own contributions. Your well being is our priority. We offer group income protection and life assurance (four times your salary) to ensure peace of mind for you and your loved ones. We want you to share in our success. That's why we offer tax efficient share save and share incentive plans, giving you the opportunity to benefit from Gamma's growth. We're committed to health, both physical and mental, and provide private medical insurance through Vitality, which extends to your immediate family. And, because we care about the environment, we offer an Electric Vehicle scheme through Octopus and a Cycle to Work scheme, making it easier to get around sustainably. A few things to note Unfortunately, we can't offer visa sponsorship or relocation support for this role. This role is hybrid but with 3 days a week onsite at either our Manchester, Glasgow, London or Newbury sites. If you feel you could be a good fit for Gamma but do not think that you meet all the requirements, we still encourage you to apply as you could be the person that we are looking for! Gamma is an equal opportunity employer. We care about inclusion and believe in having diverse teams where everyone can be their true authentic selves. We value each person and their range of backgrounds and actively encourage people from underrepresented backgrounds to apply. We don't discriminate based on any protected characteristics e.g., race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, marital status, disability or age. We are a family friendly employer with a culture based on trust, autonomy and flexibility to help you create a work life balance and enjoy working here at Gamma. . click apply for full job details
20/07/2026
Full time
Manchester, Glasgow, London or Newbury/Hybrid A bit about us At Gamma, we're a dynamic, forward-thinking team revolutionizing the way businesses connect and communicate. We provide voice, data, and mobile solutions to businesses across the UK, Germany, Spain, and the Benelux region. We're expanding rapidly to bring digital automation and Gamma-powered services to Enterprise, Public Sector and Small to medium businesses, both direct and through a growing network of channel partners. We move fast with a start up mindset, but we have the stability of a leading European business. Our team thrives on collaboration, innovation, and the belief that diverse perspectives make us stronger. Join us, and you'll have the opportunity to make an impact, grow your career, and be part of a company that celebrates inclusivity and fresh ideas. Who are we looking for? We are seeking a skilled and client focused Security Engineer with strong expertise in Vulnerability Management and Network Security engineering. This role operates within a managed service provider environment, delivering security services to enterprise clients, with a primary focus on risk based vulnerability management alongside network security, firewall optimisation and access control. The successful candidate will be responsible for identifying, assessing, prioritising and driving remediation of vulnerabilities across complex enterprise environments. In addition, they will contribute to strengthening overall cyber resilience by aligning vulnerability management with Managed Detection and Response (MDR) operations, supporting Secure Access Service Edge (SASE) frameworks and advancing Zero Trust security models across network, identity and access control layers. This is a hands on engineering role requiring deep technical expertise across vulnerability management and network security, combined with strong stakeholder engagement. The role ensures security risks are proactively reduced, controls are optimised and remediation is delivered in line with contractual SLAs and cyber security best practices. What will you be doing day to day? Key Responsibilities Vulnerability Management Services Deliver end to end vulnerability management services to clients, including discovery, assessment, prioritisation, reporting and remediation tracking Operate and maintain vulnerability scanning tools (e.g. Qualys, Nessus, Rapid7) across multiple client environments Perform regular vulnerability scans, validation and re testing to ensure remediation effectiveness Analyse vulnerability data, eliminate false positives and provide actionable remediation guidance tailored to client environments Prioritise vulnerabilities using risk based methodologies (CVSS, exploitability, business impact, threat intelligence) Track remediation activities and ensure closure within agreed SLAs and service metrics Produce client facing reports, dashboards and service reviews, highlighting risk posture, trends and key improvement areas Act as a trusted advisor to clients, providing best practice recommendations on vulnerability and risk reduction strategies Security Engineering & Detection Support deployment and optimisation of Microsoft Sentinel and SIEM/XDR platforms Contribute to detection engineering (use case development, rule tuning, alert optimisation) Onboard and integrate telemetry across network, endpoint, cloud and identity sources Support threat detection across SIEM, NDR and identity platforms Collaborate with SOC teams to improve detection coverage and reduce false positives Align vulnerability insights with MDR workflows and threat detection use cases Network Security & Remediation Identify, analyse and manage network and system vulnerabilities across enterprise environments Collaborate with infrastructure, cloud and application teams to drive remediation activities to completion Troubleshoot and resolve network/security issues linked to vulnerabilities and access controls Support secure network architecture and ensure adherence to security and compliance standards Support SASE architectures (e.g. Prisma, Cisco Secure) and secure connectivity models Contribute to Zero Trust implementation, including least privilege and identity controls Strengthen security posture across hybrid environments (network, cloud, SaaS, identity) Support pre sales activities, including solution design and vulnerability management offerings Provide SME input into RFPs, bids and technical workshops Assist with onboarding clients and transitioning services into BAU Build strong client relationships and act as a trusted technical advisor Support service adoption and continuous improvement initiatives Governance, Reporting & Documentation Maintain accurate records of vulnerabilities, remediation plans and audit evidence Support client audits, compliance requirements and security assessments Contribute to service improvement initiatives, automation and process optimisation Ensure adherence to ITIL based service management practices where applicable Breach Attack Simulation (BAS) Design, implement and maintain BAS scenarios to continuously validate the effectiveness of security controls across the enterprise Configure and operate BAS platforms to simulate real world threat actor techniques (MITRE ATT&CK aligned) and identify control gaps Analyse BAS results to prioritise vulnerabilities, misconfigurations and detection gaps, feeding findings into the vulnerability management lifecycle What you'll need: Strong experience in delivering vulnerability management services, ideally within a managed service or consultancy environment Deep understanding of vulnerability lifecycle management (discovery / assessment / remediation / validation / reporting) Hands on experience with Tufin (SecureTrack / SecureChange) or similar tools such as Palo Alto Panorama or Cisco Defense Orchestrator Proficiency with vulnerability scanning tools (Qualys, Nessus, Rapid7) Solid knowledge of network security principles (firewalls, VPNs, segmentation, protocols) Experience working with client stakeholders and managing competing priorities Ability to translate technical vulnerabilities into business risk and remediation actions Strong analytical, troubleshooting and communication skills Nice to haves Certifications such as CCNA / Security+ / CEH / CISSP (or working towards) Experience in multi client or managed security service provider (MSSP) environments Familiarity with multi vendor firewalls (Cisco, Palo Alto, Check Point) Knowledge of compliance frameworks (ISO 27001, NIST, CIS, PCI DSS) Exposure to risk based vulnerability management and threat intelligence integration Understanding of ITIL service delivery and SLA driven environments Experience with SASE, Zero Trust, MDR/XDR platforms Experience with RSA Authentication Manager or similar IAM solutions What do we offer you? At Gamma, we believe in work life balance, which is why we offer 25 days of annual leave, plus an extra day off for your birthday. Giving back is important to us, so we also provide a volunteer day to support a charity that matters to you. Family matters, too. With enhanced maternity and paternity pay and childcare vouchers, we're here to support you as a parent and help you thrive in your career. We care about your future, so our pension plan helps you save for the years ahead with contributions of 4.59% from Gamma, alongside your own contributions. Your well being is our priority. We offer group income protection and life assurance (four times your salary) to ensure peace of mind for you and your loved ones. We want you to share in our success. That's why we offer tax efficient share save and share incentive plans, giving you the opportunity to benefit from Gamma's growth. We're committed to health, both physical and mental, and provide private medical insurance through Vitality, which extends to your immediate family. And, because we care about the environment, we offer an Electric Vehicle scheme through Octopus and a Cycle to Work scheme, making it easier to get around sustainably. A few things to note Unfortunately, we can't offer visa sponsorship or relocation support for this role. This role is hybrid but with 3 days a week onsite at either our Manchester, Glasgow, London or Newbury sites. If you feel you could be a good fit for Gamma but do not think that you meet all the requirements, we still encourage you to apply as you could be the person that we are looking for! Gamma is an equal opportunity employer. We care about inclusion and believe in having diverse teams where everyone can be their true authentic selves. We value each person and their range of backgrounds and actively encourage people from underrepresented backgrounds to apply. We don't discriminate based on any protected characteristics e.g., race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, marital status, disability or age. We are a family friendly employer with a culture based on trust, autonomy and flexibility to help you create a work life balance and enjoy working here at Gamma. . click apply for full job details
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle. The Senior Vulnerability Management Engineer owns the enterprise vulnerability management program across cloud, endpoint, and application surfaces, driving risk-based identification, prioritization, automated remediation, and verified closure in partnership with IT, Cloud, and Product teams. Operating with minimal guidance, this role combines hands on technical engineering depth with program ownership-designing and implementing scanning architectures, automated patching workflows, and data pipelines alongside governing the policies, SLAs, and metrics that drive measurable risk reduction. The role leads others to solve complex, cross-domain problems, shapes program methods and measures, and influences adjacent teams to achieve remediation SLAs and reduce measurable exposure. It aligns with company standards for vulnerability governance, remediation schedules, and exception management. Essential Functions/Responsibilities Govern the end-to-end vulnerability management lifecycle-intake, scanning, triage, risk scoring, remediation orchestration, verification, and reporting-in alignment with the company Vulnerability & Patch Management Security Standard. Apply CVSS, EPSS, and CISA KEV signals for risk-based vulnerability prioritization; codify triage logic into policy, SOPs, and dashboards. Enforce remediation SLAs; manage risk acceptances and time-bound exceptions; report exception aging trends to leadership. Drive complete and accurate asset coverage across servers, endpoints, containers, cloud services, and applications; partner with CMDB and asset owners to close inventory gaps. Design, administer, and optimize enterprise vulnerability scanners for infrastructure, cloud, container, and application layers; integrate scan results into ITSM workflows for timely remediation. Design, implement, and maintain enterprise automated patching capabilities across server, endpoint, and cloud workloads; integrate with change management and ITSM processes; validate patch success rates and drive MTTR reduction aligned to NIST SP 800-40r4. Collaborate with Threat Intelligence and Incident Response to dynamically adjust priority queues based on active exploitation, KEV entries, and zero day disclosures. Partner with IT/Cloud Ops and Product/SWE teams to integrate patch and mitigation planning into CI/CD and infrastructure as code pipelines; champion automated remediation over manual processes. Maintain executive ready metrics covering exposure, SLA adherence, backlog, exception aging, asset coverage, and patch automation coverage; deliver regular status and risk narratives to Directors and Vice Presidents. Tune risk models, scanning frequency, authenticated coverage, change windows, and patch validation methods to continuously reduce exposure and MTTR; lead automation initiatives that eliminate manual toil across the vulnerability lifecycle. Serve as a technical resource and mentor for less experienced team members; lead cross team workstreams and champion engineering best practices and program rigor consistent with senior IC leadership. Maintain program evidence-findings, decisions, exceptions, verifications, and patch records-in audit ready condition to support internal and external compliance reviews. Proactively identify, assess, and remediate configuration weaknesses in enterprise SaaS applications and cloud platforms; enforce compliance with security baselines through automated and manual review. Other tasks and activities as assigned. Required Education/Experience & Skills 5-7+ years in vulnerability management or closely related cybersecurity/IT engineering roles, operating independently and leading others to solve complex, cross domain problems. Proven hands on experience with enterprise vulnerability scanning technologies (infrastructure, cloud, container, application), authenticated scanning, and ITSM/CMDB integrations. Hands on design and operation of enterprise automated patching Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.
19/07/2026
Full time
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle. The Senior Vulnerability Management Engineer owns the enterprise vulnerability management program across cloud, endpoint, and application surfaces, driving risk-based identification, prioritization, automated remediation, and verified closure in partnership with IT, Cloud, and Product teams. Operating with minimal guidance, this role combines hands on technical engineering depth with program ownership-designing and implementing scanning architectures, automated patching workflows, and data pipelines alongside governing the policies, SLAs, and metrics that drive measurable risk reduction. The role leads others to solve complex, cross-domain problems, shapes program methods and measures, and influences adjacent teams to achieve remediation SLAs and reduce measurable exposure. It aligns with company standards for vulnerability governance, remediation schedules, and exception management. Essential Functions/Responsibilities Govern the end-to-end vulnerability management lifecycle-intake, scanning, triage, risk scoring, remediation orchestration, verification, and reporting-in alignment with the company Vulnerability & Patch Management Security Standard. Apply CVSS, EPSS, and CISA KEV signals for risk-based vulnerability prioritization; codify triage logic into policy, SOPs, and dashboards. Enforce remediation SLAs; manage risk acceptances and time-bound exceptions; report exception aging trends to leadership. Drive complete and accurate asset coverage across servers, endpoints, containers, cloud services, and applications; partner with CMDB and asset owners to close inventory gaps. Design, administer, and optimize enterprise vulnerability scanners for infrastructure, cloud, container, and application layers; integrate scan results into ITSM workflows for timely remediation. Design, implement, and maintain enterprise automated patching capabilities across server, endpoint, and cloud workloads; integrate with change management and ITSM processes; validate patch success rates and drive MTTR reduction aligned to NIST SP 800-40r4. Collaborate with Threat Intelligence and Incident Response to dynamically adjust priority queues based on active exploitation, KEV entries, and zero day disclosures. Partner with IT/Cloud Ops and Product/SWE teams to integrate patch and mitigation planning into CI/CD and infrastructure as code pipelines; champion automated remediation over manual processes. Maintain executive ready metrics covering exposure, SLA adherence, backlog, exception aging, asset coverage, and patch automation coverage; deliver regular status and risk narratives to Directors and Vice Presidents. Tune risk models, scanning frequency, authenticated coverage, change windows, and patch validation methods to continuously reduce exposure and MTTR; lead automation initiatives that eliminate manual toil across the vulnerability lifecycle. Serve as a technical resource and mentor for less experienced team members; lead cross team workstreams and champion engineering best practices and program rigor consistent with senior IC leadership. Maintain program evidence-findings, decisions, exceptions, verifications, and patch records-in audit ready condition to support internal and external compliance reviews. Proactively identify, assess, and remediate configuration weaknesses in enterprise SaaS applications and cloud platforms; enforce compliance with security baselines through automated and manual review. Other tasks and activities as assigned. Required Education/Experience & Skills 5-7+ years in vulnerability management or closely related cybersecurity/IT engineering roles, operating independently and leading others to solve complex, cross domain problems. Proven hands on experience with enterprise vulnerability scanning technologies (infrastructure, cloud, container, application), authenticated scanning, and ITSM/CMDB integrations. Hands on design and operation of enterprise automated patching Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.
Role Summary Sophos is seeking an experienced MDR Manager to support its Managed Detection and Response customers. The successful candidate will lead MDR analysts and day-to-day operations, ensuring operational quality, timely incident handling, effective customer communication, consistent reporting, and continuous service improvement. As part of the Managed Detection and Response team, you will help deliver best-in-class monitoring, detection, and response services that proactively defend customer environments. You will guide investigations, review quality, coach analysts, manage escalations, and use operational insights to improve team performance, investigation consistency, and customer outcomes. What you will do Lead day-to-day MDR operations, overseeing case queues, analyst workloads, SLA performance, escalations, and resource allocation to ensure consistent service delivery. Guide and review incident investigations, validating findings, assessing business impact, recommending response actions, and ensuring appropriate escalation management. Serve as a key point of coordination during customer and internal escalations, providing clear updates, risk assessments, recommendations, and resolution plans. Coach, mentor, and develop MDR analysts through case reviews, feedback, skills development, and performance management. Conduct quality reviews of investigations, customer communications, documentation, and calls to drive operational excellence and continuous improvement. Analyse operational metrics and dashboards to identify trends, risks, capacity constraints, and opportunities to improve service quality, efficiency, and customer outcomes. Develop and maintain SOPs, playbooks, workflows, and knowledge-base content to improve consistency and operational readiness. Provide technical leadership in intrusion analysis, incident response, digital forensics, malware investigations, and threat hunting activities. Lead response efforts during significant security incidents, ensuring effective coordination, decision-making, and ownership through resolution. Stay current on threat actor tactics, techniques, and procedures (TTPs), leveraging threat intelligence to enhance investigations, detections, and response capabilities. Partner with Engineering, Labs, and Content teams to improve detection quality, reduce false positives, and address recurring investigation gaps. What you will bring Up to 12 years of total work experience. 5+ years of experience in cybersecurity, with a minimum of 2-3 years leading, mentoring, or coordinating analysts in a SOC, MDR, Incident Response, or similar environment. Bachelor's degree in Information Technology, Computer Science, or a related field, or equivalent practical experience. Hands on experience in security operations, including threat detection, incident investigation, and response. Strong understanding of endpoint and network security technologies, including IDS/IPS, EDR, ATP, malware protection, and monitoring platforms. Experience with threat hunting methodologies and familiarity with the MITRE ATT&CK framework preferred. Working knowledge of incident response processes, adversary tactics and techniques, and cyber threat intelligence. Strong technical expertise in Windows environments, including host artefacts, endpoint telemetry, event log analysis, and operating system security events; exposure to macOS and Linux is a plus. Solid understanding of network fundamentals, including TCP/IP, routing, switching, and traffic analysis. Experience with SIEM platforms and enterprise security data management; database querying skills are advantageous. Working knowledge of PowerShell and Python for automation and investigation support. Strong analytical, troubleshooting, and decision making skills, with the ability to prioritise effectively in high pressure situations. Excellent written and verbal communication skills, including the ability to produce clear reports, case summaries, operational updates, and executive ready communications. Experience performing quality reviews and providing actionable feedback that improves investigation outcomes and analyst performance. Proven ability to build team capability through coaching, onboarding, training, and knowledge sharing. Strong stakeholder management and customer facing skills, with the capability to explain technical findings, risks, and recommendations to both technical and non technical audiences. Advanced cybersecurity certifications are preferred but not required. Equal Opportunity Employer All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos' data protection practices, please consult our Privacy Policy.
10/07/2026
Full time
Role Summary Sophos is seeking an experienced MDR Manager to support its Managed Detection and Response customers. The successful candidate will lead MDR analysts and day-to-day operations, ensuring operational quality, timely incident handling, effective customer communication, consistent reporting, and continuous service improvement. As part of the Managed Detection and Response team, you will help deliver best-in-class monitoring, detection, and response services that proactively defend customer environments. You will guide investigations, review quality, coach analysts, manage escalations, and use operational insights to improve team performance, investigation consistency, and customer outcomes. What you will do Lead day-to-day MDR operations, overseeing case queues, analyst workloads, SLA performance, escalations, and resource allocation to ensure consistent service delivery. Guide and review incident investigations, validating findings, assessing business impact, recommending response actions, and ensuring appropriate escalation management. Serve as a key point of coordination during customer and internal escalations, providing clear updates, risk assessments, recommendations, and resolution plans. Coach, mentor, and develop MDR analysts through case reviews, feedback, skills development, and performance management. Conduct quality reviews of investigations, customer communications, documentation, and calls to drive operational excellence and continuous improvement. Analyse operational metrics and dashboards to identify trends, risks, capacity constraints, and opportunities to improve service quality, efficiency, and customer outcomes. Develop and maintain SOPs, playbooks, workflows, and knowledge-base content to improve consistency and operational readiness. Provide technical leadership in intrusion analysis, incident response, digital forensics, malware investigations, and threat hunting activities. Lead response efforts during significant security incidents, ensuring effective coordination, decision-making, and ownership through resolution. Stay current on threat actor tactics, techniques, and procedures (TTPs), leveraging threat intelligence to enhance investigations, detections, and response capabilities. Partner with Engineering, Labs, and Content teams to improve detection quality, reduce false positives, and address recurring investigation gaps. What you will bring Up to 12 years of total work experience. 5+ years of experience in cybersecurity, with a minimum of 2-3 years leading, mentoring, or coordinating analysts in a SOC, MDR, Incident Response, or similar environment. Bachelor's degree in Information Technology, Computer Science, or a related field, or equivalent practical experience. Hands on experience in security operations, including threat detection, incident investigation, and response. Strong understanding of endpoint and network security technologies, including IDS/IPS, EDR, ATP, malware protection, and monitoring platforms. Experience with threat hunting methodologies and familiarity with the MITRE ATT&CK framework preferred. Working knowledge of incident response processes, adversary tactics and techniques, and cyber threat intelligence. Strong technical expertise in Windows environments, including host artefacts, endpoint telemetry, event log analysis, and operating system security events; exposure to macOS and Linux is a plus. Solid understanding of network fundamentals, including TCP/IP, routing, switching, and traffic analysis. Experience with SIEM platforms and enterprise security data management; database querying skills are advantageous. Working knowledge of PowerShell and Python for automation and investigation support. Strong analytical, troubleshooting, and decision making skills, with the ability to prioritise effectively in high pressure situations. Excellent written and verbal communication skills, including the ability to produce clear reports, case summaries, operational updates, and executive ready communications. Experience performing quality reviews and providing actionable feedback that improves investigation outcomes and analyst performance. Proven ability to build team capability through coaching, onboarding, training, and knowledge sharing. Strong stakeholder management and customer facing skills, with the capability to explain technical findings, risks, and recommendations to both technical and non technical audiences. Advanced cybersecurity certifications are preferred but not required. Equal Opportunity Employer All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos' data protection practices, please consult our Privacy Policy.
" Senior IT Support Analyst Salary: £32,000 - £37,000 depending on experience. Hours: 37.5 hours per week - Monday to Friday, 08:00-16:30. Location: Hybrid - Coventry office base preferred; nationwide applications welcome. Start Date: ASAP. At Macfarlane Packaging, we protect what matters - our people, customers and the environment. With over 75 years of expertise, we offer a stable, supportive workplace where you can build a long term career. Role Overview This is an exciting opportunity for an experienced IT support professional to join a forward thinking IT team at a pivotal point in how we deliver and evolve our helpdesk function. We are investing in AI tooling - including Freshservice Freddy AI and Microsoft Copilot - to enhance first contact resolution, automate triage, and free our analysts to focus on complex problem solving and user experience. This role sits at the centre of that transition: you will be both a skilled technical responder and a key contributor to building a smarter, more efficient support service. You will operate with a high degree of autonomy, acting as the de facto lead across the helpdesk queue, and will work closely with the IT Manager to develop and continuously improve our AI augmented support model. Helpdesk Operations Own the day to day management of the Freshservice helpdesk queue, ensuring tickets are triaged, prioritised, and resolved in line with SLAs Provide 2nd line technical support across the Microsoft 365 stack (Entra ID, Intune, Exchange Online, SharePoint, Teams) and core business applications Act as the first point of escalation for the helpdesk team, providing technical guidance and quality oversight Maintain and improve the Freshservice knowledge base, ensuring articles are accurate, current, and structured for AI consumption Core working hours are Monday to Friday, 08 30 (37.5 hours per week). Out of hours availability is not a routine requirement of this role; however, the postholder may occasionally be contacted outside these hours in the event of a critical IT incident such as a significant cybersecurity threat or major service outage AI & Automation Champion the use of Freshservice Freddy AI, including auto triage, auto categorisation, and automated response workflows Work with the IT Manager to identify and implement automation opportunities that reduce manual ticket handling Monitor AI deflection rates and first contact resolution metrics, making data driven recommendations for improvement Leverage Microsoft Copilot and Claude Enterprise for drafting technical responses, summarising incident trends, and knowledge base creation User Experience & Communication Ensure all users receive timely, clear, and professional communication throughout their ticket lifecycle Identify recurring issues and proactively communicate workarounds or solutions to the wider business Assist with onboarding and offboarding processes, device provisioning, and licence management Continuous Improvement Produce regular reporting on helpdesk performance, SLA adherence, and ticket trends, presenting insights to the IT Manager Contribute to IT projects and initiatives as required, including site integrations and system rollouts Maintain and improve standard operating procedures and runbooks Personal Specification 3+ years' experience in an IT support or service desk role, including 2nd line technical work Strong working knowledge of Microsoft 365 - particularly Entra ID, Intune, Exchange Online, and Teams Experience with an ITSM platform (Freshservice, ServiceNow, Zendesk, Jira Service Management, or similar) Confident communicator with the ability to explain technical issues clearly to non technical users Self motivated with the ability to manage a busy queue independently and prioritise effectively A genuine interest in AI tooling and how it can improve IT service delivery Full UK Driving Licence (occasional travel to UK sites is required) Desirable Hands on experience with Freshservice and/or Freddy AI Familiarity with Microsoft Copilot, Copilot Studio, or similar AI productivity tools Experience using NinjaOne, Microsoft Intune, or other RMM/MDM platforms Microsoft certifications (e.g. MS 900, MD 102, MS 102) or equivalent practical experience ITIL Foundation certification or working knowledge of ITIL service management principles Familiarity with cybersecurity practices relevant to end user computing (e.g. MFA, endpoint protection, phishing awareness) Exposure to IT project work - system rollouts, site integrations, or technology migrations Experience in a multi site or distributed business environment Employee Benefits £32,000 - £37,000 per annum, depending on experience Hybrid / flexible working arrangements Pension scheme 25 days holiday plus bank holidays Access to Group employee benefits and discount schemes Structured professional development and support for relevant certifications Exposure to a modern Microsoft 365 centric environment with real investment in AI tooling Equal Opportunities Macfarlane Packaging is an equal opportunities employer. We are committed to creating an inclusive environment for all employees and welcome applications from candidates of all backgrounds. "
07/07/2026
Full time
" Senior IT Support Analyst Salary: £32,000 - £37,000 depending on experience. Hours: 37.5 hours per week - Monday to Friday, 08:00-16:30. Location: Hybrid - Coventry office base preferred; nationwide applications welcome. Start Date: ASAP. At Macfarlane Packaging, we protect what matters - our people, customers and the environment. With over 75 years of expertise, we offer a stable, supportive workplace where you can build a long term career. Role Overview This is an exciting opportunity for an experienced IT support professional to join a forward thinking IT team at a pivotal point in how we deliver and evolve our helpdesk function. We are investing in AI tooling - including Freshservice Freddy AI and Microsoft Copilot - to enhance first contact resolution, automate triage, and free our analysts to focus on complex problem solving and user experience. This role sits at the centre of that transition: you will be both a skilled technical responder and a key contributor to building a smarter, more efficient support service. You will operate with a high degree of autonomy, acting as the de facto lead across the helpdesk queue, and will work closely with the IT Manager to develop and continuously improve our AI augmented support model. Helpdesk Operations Own the day to day management of the Freshservice helpdesk queue, ensuring tickets are triaged, prioritised, and resolved in line with SLAs Provide 2nd line technical support across the Microsoft 365 stack (Entra ID, Intune, Exchange Online, SharePoint, Teams) and core business applications Act as the first point of escalation for the helpdesk team, providing technical guidance and quality oversight Maintain and improve the Freshservice knowledge base, ensuring articles are accurate, current, and structured for AI consumption Core working hours are Monday to Friday, 08 30 (37.5 hours per week). Out of hours availability is not a routine requirement of this role; however, the postholder may occasionally be contacted outside these hours in the event of a critical IT incident such as a significant cybersecurity threat or major service outage AI & Automation Champion the use of Freshservice Freddy AI, including auto triage, auto categorisation, and automated response workflows Work with the IT Manager to identify and implement automation opportunities that reduce manual ticket handling Monitor AI deflection rates and first contact resolution metrics, making data driven recommendations for improvement Leverage Microsoft Copilot and Claude Enterprise for drafting technical responses, summarising incident trends, and knowledge base creation User Experience & Communication Ensure all users receive timely, clear, and professional communication throughout their ticket lifecycle Identify recurring issues and proactively communicate workarounds or solutions to the wider business Assist with onboarding and offboarding processes, device provisioning, and licence management Continuous Improvement Produce regular reporting on helpdesk performance, SLA adherence, and ticket trends, presenting insights to the IT Manager Contribute to IT projects and initiatives as required, including site integrations and system rollouts Maintain and improve standard operating procedures and runbooks Personal Specification 3+ years' experience in an IT support or service desk role, including 2nd line technical work Strong working knowledge of Microsoft 365 - particularly Entra ID, Intune, Exchange Online, and Teams Experience with an ITSM platform (Freshservice, ServiceNow, Zendesk, Jira Service Management, or similar) Confident communicator with the ability to explain technical issues clearly to non technical users Self motivated with the ability to manage a busy queue independently and prioritise effectively A genuine interest in AI tooling and how it can improve IT service delivery Full UK Driving Licence (occasional travel to UK sites is required) Desirable Hands on experience with Freshservice and/or Freddy AI Familiarity with Microsoft Copilot, Copilot Studio, or similar AI productivity tools Experience using NinjaOne, Microsoft Intune, or other RMM/MDM platforms Microsoft certifications (e.g. MS 900, MD 102, MS 102) or equivalent practical experience ITIL Foundation certification or working knowledge of ITIL service management principles Familiarity with cybersecurity practices relevant to end user computing (e.g. MFA, endpoint protection, phishing awareness) Exposure to IT project work - system rollouts, site integrations, or technology migrations Experience in a multi site or distributed business environment Employee Benefits £32,000 - £37,000 per annum, depending on experience Hybrid / flexible working arrangements Pension scheme 25 days holiday plus bank holidays Access to Group employee benefits and discount schemes Structured professional development and support for relevant certifications Exposure to a modern Microsoft 365 centric environment with real investment in AI tooling Equal Opportunities Macfarlane Packaging is an equal opportunities employer. We are committed to creating an inclusive environment for all employees and welcome applications from candidates of all backgrounds. "