it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

325 jobs found

Email me jobs like this
Refine Search
Current Search
cyber security specialist operational
AI Compliance and Governance Specialist
Sabio Group
AI Compliance and Governance Specialist Department: IT Employment Type: Permanent - Full Time Location: London Reporting To: Stephen Smith Description At Sabio Group, we are building the next generation of AI powered customer experience for some of the world's most demanding enterprise brands. We deliver significant volumes of agentic AI, LLM and conversational solutions into regulated industries - which means governance and compliance aren't a back office function for us, they're a competitive advantage and a customer expectation. We are hiring an AI Compliance & Governance Specialist to join our Internal AI Team and add capacity to our existing governance and compliance function. We already ISO 27001 and SOC 2 Type II certified, we operate under the EU AI Act, and we are working towards ISO 42001. You will play a key part in evolving that posture - across the solutions we ship to customers, the policies and procedures we run internally, and the way we evidence trust to regulators and clients. This is a hands on role for someone who is genuinely curious about AI, comfortable using AI tooling to amplify their own output, and thoughtful about how to govern it responsibly. It's a fun, fast paced environment with a high growth business area behind it - and a strong remit to shape how AI is built and deployed across the Sabio group. Key Responsibilities Customer Solution Assurance Review and assure the AI solutions we deliver to customers against EU AI Act obligations, ISO 42001 controls, customer specific regulatory requirements and Sabio's internal standards. Partner with delivery teams during discovery, design and deployment to ensure bias, hallucination, prompt injection, misuse and other AI specific risks are identified and mitigated by design - not patched in later. Support pre sales and customer conversations on compliance posture, certifications and responsible AI commitments. Policy, Procedure & Strategy Draft, maintain and evolve internal AI policies, procedures, standards and control frameworks. Contribute to the strategic direction of Sabio's AI governance programme - including roadmap to ISO 42001 certification and ongoing alignment with EU AI Act, ISO 27001 and SOC 2 Type II. Translate regulatory change (EU AI Act guidance, national implementations, sector specific rules) into practical, actionable internal guidance. Audit & Assurance Audit Sabio's AI deployment and support methodologies against internal standards and external frameworks. Support external audits from customers, certification bodies and regulators - preparing evidence, running walkthroughs and remediating findings. Build and report on AI governance KPIs that give leadership and customers a clear, honest view of compliance posture. Responsible AI in Practice Operationalise responsible AI principles - fairness, transparency, accountability, robustness, human oversight - across solution lifecycles. Work with engineering and AI teams on practical mitigations for bias, hallucination, jailbreak resistance, data leakage and acceptable use boundaries. Help define and evolve our approach to evaluation, red teaming and ongoing monitoring of deployed AI systems. Enablement & Communication Run working sessions, training and clinics that lift AI governance literacy across engineering, delivery, sales and operations. Bring people together across geographies and disciplines to land decisions and unblock initiatives. Produce high quality written content - policies, briefings, customer facing assurance materials, internal comms. Working with AI Use AI tooling (Microsoft Copilot, Microsoft Cowork and others) as a core part of how you deliver - drafting, analysing, summarising, reviewing - to materially amplify your output. Skills Knowledge and Expertise Required Demonstrable experience in AI compliance, AI governance or AI risk - either as a dedicated focus or as a major component of a broader compliance, legal, infosec, cyber or engineering role that you've since pivoted toward AI. Strong working knowledge of the EU AI Act and a clear understanding of how risk classification, obligations and timelines apply to real world AI systems. Familiarity with ISO/IEC 42001, ISO/IEC 27001 and SOC 2 Type II - what they require, how they interlock, and how to evidence compliance in practice. A genuine grasp of the core principles of modern AI: LLMs, prompt engineering, context engineering, retrieval augmented generation, and agentic frameworks - enough to challenge engineers credibly and apply governance to what's actually being built, not a generic abstraction of it. Hands on experience using AI tooling as part of your day job - using AI co work / copilots to draft, review, analyse and accelerate your own output. Awareness of bias, hallucination, prompt injection, data leakage and misuse risks in deployed AI systems, with practical experience helping to mitigate them. Excellent written and verbal communication - able to draft a board grade policy, run a workshop, brief a customer auditor and write a sharp internal memo. Ability to run meetings, bring groups together and drive outcomes across geographically dispersed teams and different business functions. Comfort with high pace, multi stakeholder environments - motivated, flexible, and able to build effective working relationships across cultures and time zones. A passion for raising the bar in others - coaching, enabling and growing AI governance literacy across the organisation. Desirable Working proficiency in Spanish alongside English. Familiarity with Microsoft Copilot, Microsoft Cowork and the broader Microsoft AI ecosystem. Hands on familiarity with AI offerings from Anthropic, OpenAI, Google and conversational AI platforms such as Cognigy, and a practical sense of how their governance characteristics differ. Prior career stage in legal, information security, cyber security, audit or software engineering - now focused on AI governance and compliance. Experience supporting customer facing audits or regulator engagement in a B2B / enterprise context. Exposure to AI evaluation, red teaming or model assurance practices. Experience working in or with contact centre, customer experience or other regulated enterprise domains. Nice to Have Experience contributing to an ISO 42001 certification journey end to end. Familiarity with NIST AI RMF, UK AI regulatory developments, or sector specific AI guidance (financial services, healthcare, public sector). Exposure to emerging agent interoperability and safety standards (e.g. MCP, A2A) and human in the loop patterns. A track record of writing publicly - blogs, talks, whitepapers - on AI governance, responsible AI or adjacent topics. Benefits This is your chance to join and friendly and passionate team that will motivate you to learn and develop your career in the company. Benefits may include: Pension Scheme Remote/Flexible work Life insurance Private health and dental care Cycle to work 28 days paid holiday a year (this includes three Sabio days) LinkedIn Learning Plus many more! (Benefits are dependant on your base location.) The Small Print Strictly No Agencies; any submission of resumes without prior request from Sabio Group will not be deemed as an introduction and therefore will not warrant an introduction fee. All applicants must have the right to work in the territory to which the role relates (UK & EU). Sabio Group are unable to offer sponsorship on any roles advertised.
20/07/2026
Full time
AI Compliance and Governance Specialist Department: IT Employment Type: Permanent - Full Time Location: London Reporting To: Stephen Smith Description At Sabio Group, we are building the next generation of AI powered customer experience for some of the world's most demanding enterprise brands. We deliver significant volumes of agentic AI, LLM and conversational solutions into regulated industries - which means governance and compliance aren't a back office function for us, they're a competitive advantage and a customer expectation. We are hiring an AI Compliance & Governance Specialist to join our Internal AI Team and add capacity to our existing governance and compliance function. We already ISO 27001 and SOC 2 Type II certified, we operate under the EU AI Act, and we are working towards ISO 42001. You will play a key part in evolving that posture - across the solutions we ship to customers, the policies and procedures we run internally, and the way we evidence trust to regulators and clients. This is a hands on role for someone who is genuinely curious about AI, comfortable using AI tooling to amplify their own output, and thoughtful about how to govern it responsibly. It's a fun, fast paced environment with a high growth business area behind it - and a strong remit to shape how AI is built and deployed across the Sabio group. Key Responsibilities Customer Solution Assurance Review and assure the AI solutions we deliver to customers against EU AI Act obligations, ISO 42001 controls, customer specific regulatory requirements and Sabio's internal standards. Partner with delivery teams during discovery, design and deployment to ensure bias, hallucination, prompt injection, misuse and other AI specific risks are identified and mitigated by design - not patched in later. Support pre sales and customer conversations on compliance posture, certifications and responsible AI commitments. Policy, Procedure & Strategy Draft, maintain and evolve internal AI policies, procedures, standards and control frameworks. Contribute to the strategic direction of Sabio's AI governance programme - including roadmap to ISO 42001 certification and ongoing alignment with EU AI Act, ISO 27001 and SOC 2 Type II. Translate regulatory change (EU AI Act guidance, national implementations, sector specific rules) into practical, actionable internal guidance. Audit & Assurance Audit Sabio's AI deployment and support methodologies against internal standards and external frameworks. Support external audits from customers, certification bodies and regulators - preparing evidence, running walkthroughs and remediating findings. Build and report on AI governance KPIs that give leadership and customers a clear, honest view of compliance posture. Responsible AI in Practice Operationalise responsible AI principles - fairness, transparency, accountability, robustness, human oversight - across solution lifecycles. Work with engineering and AI teams on practical mitigations for bias, hallucination, jailbreak resistance, data leakage and acceptable use boundaries. Help define and evolve our approach to evaluation, red teaming and ongoing monitoring of deployed AI systems. Enablement & Communication Run working sessions, training and clinics that lift AI governance literacy across engineering, delivery, sales and operations. Bring people together across geographies and disciplines to land decisions and unblock initiatives. Produce high quality written content - policies, briefings, customer facing assurance materials, internal comms. Working with AI Use AI tooling (Microsoft Copilot, Microsoft Cowork and others) as a core part of how you deliver - drafting, analysing, summarising, reviewing - to materially amplify your output. Skills Knowledge and Expertise Required Demonstrable experience in AI compliance, AI governance or AI risk - either as a dedicated focus or as a major component of a broader compliance, legal, infosec, cyber or engineering role that you've since pivoted toward AI. Strong working knowledge of the EU AI Act and a clear understanding of how risk classification, obligations and timelines apply to real world AI systems. Familiarity with ISO/IEC 42001, ISO/IEC 27001 and SOC 2 Type II - what they require, how they interlock, and how to evidence compliance in practice. A genuine grasp of the core principles of modern AI: LLMs, prompt engineering, context engineering, retrieval augmented generation, and agentic frameworks - enough to challenge engineers credibly and apply governance to what's actually being built, not a generic abstraction of it. Hands on experience using AI tooling as part of your day job - using AI co work / copilots to draft, review, analyse and accelerate your own output. Awareness of bias, hallucination, prompt injection, data leakage and misuse risks in deployed AI systems, with practical experience helping to mitigate them. Excellent written and verbal communication - able to draft a board grade policy, run a workshop, brief a customer auditor and write a sharp internal memo. Ability to run meetings, bring groups together and drive outcomes across geographically dispersed teams and different business functions. Comfort with high pace, multi stakeholder environments - motivated, flexible, and able to build effective working relationships across cultures and time zones. A passion for raising the bar in others - coaching, enabling and growing AI governance literacy across the organisation. Desirable Working proficiency in Spanish alongside English. Familiarity with Microsoft Copilot, Microsoft Cowork and the broader Microsoft AI ecosystem. Hands on familiarity with AI offerings from Anthropic, OpenAI, Google and conversational AI platforms such as Cognigy, and a practical sense of how their governance characteristics differ. Prior career stage in legal, information security, cyber security, audit or software engineering - now focused on AI governance and compliance. Experience supporting customer facing audits or regulator engagement in a B2B / enterprise context. Exposure to AI evaluation, red teaming or model assurance practices. Experience working in or with contact centre, customer experience or other regulated enterprise domains. Nice to Have Experience contributing to an ISO 42001 certification journey end to end. Familiarity with NIST AI RMF, UK AI regulatory developments, or sector specific AI guidance (financial services, healthcare, public sector). Exposure to emerging agent interoperability and safety standards (e.g. MCP, A2A) and human in the loop patterns. A track record of writing publicly - blogs, talks, whitepapers - on AI governance, responsible AI or adjacent topics. Benefits This is your chance to join and friendly and passionate team that will motivate you to learn and develop your career in the company. Benefits may include: Pension Scheme Remote/Flexible work Life insurance Private health and dental care Cycle to work 28 days paid holiday a year (this includes three Sabio days) LinkedIn Learning Plus many more! (Benefits are dependant on your base location.) The Small Print Strictly No Agencies; any submission of resumes without prior request from Sabio Group will not be deemed as an introduction and therefore will not warrant an introduction fee. All applicants must have the right to work in the territory to which the role relates (UK & EU). Sabio Group are unable to offer sponsorship on any roles advertised.
Senior Identity Protection Specialist
FujiFilm Billingham, Yorkshire
Protect identities at global scale. We're hiring a hands-on Senior Identity Protection Engineer/Specialist to lead detection, investigation, and response for identity-based threats across Microsoft Entra ID/Azure AD, on prem Active Directory, and connected SaaS/IaaS. You'll serve as the enterprise SME/administrator for CrowdStrike Identity Protection, tune high-fidelity detections, integrate dark web intelligence, and orchestrate automation that measurably reduces MTTD/MTTR and risk.What you'll doLead identity threat monitoring and triageOperate and tune CrowdStrike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks like impossible travel, atypical sign ins, MFA fatigue, and session hijackingValidate true/false positives, prioritize by business impact, and escalate per playbooks/SLAsDrive rapid containment and remediationExecute containment actions (disable accounts, revoke sessions/tokens, isolate hosts)Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closureOwn identity-focused incident responseLead IR for credential compromise, privilege escalation, directory persistence, and lateral movementEnsure evidence handling, root cause analysis, post incident reviews, and lessons learnedEngineer detections and hunt for threatsBuild and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CKClose visibility gaps, reduce false positives, and expand privileged activity monitoringStrengthen privileged access controlsDetect anomalous privileged behavior via SIEM/UEBA and Netskope telemetryRecommend/enforce JIT, break glass patterns, and mover/leaver privilege hygiene with IAMRespond to dark web/credential exposureIntegrate sources like CyberInt; assess exposure and targeted campaignsOrchestrate takedowns, forced resets, token revocation, and Conditional Access updatesAdminister platforms and sustain hygieneMaintain coverage/health for identity monitoring; manage upgrades and changes via CABKeep operational runbooks, SOPs, and playbooks currentAutomate and orchestrate at scaleUse PowerShell/Python and REST/Graph/CrowdStrike APIs (and SOAR where applicable) to automate enrichment and response, standardize workflows, and improve signal fidelityShape identity policy and controlsAdvise on Conditional Access, MFA exceptions, SSO/SCIM patterns, and session controls under the shared responsibility model with IAMReport outcomes and support auditsProduce executive-ready dashboards and KPIs (identity incident volume, MTTD/MTTR, CA/MFA efficacy, exposure/takedown cycle time)Maintain audit-ready evidence and support internal/external auditsWhat you'll bringBachelor's degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience8+ years in IT/cybersecurity, including 3+ years focused on identity security/operations (Entra ID/Azure AD, on prem AD, MFA, Conditional Access, SSO/SCIM)Hands-on enterprise experience administering/operating CrowdStrike Identity ProtectionProficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms (e.g., Netskope) for identity telemetry, detection, and investigationsDemonstrated experience in identity centric IR, threat hunting, and detection engineering (KQL/SQL/regex/Sigma)Scripting/automation with PowerShell and Python; experience with REST/Graph/CrowdStrike APIs and SOARClear communication and documentation skills; comfortable producing executive ready reports and audit evidenceOperates effectively within change control/CAB and under pressure during high severity incidentsBonus pointsCertifications: Microsoft SC 200/SC 300; Okta Certified Administrator/Professional; CISSP, SSCP, Security+; GIAC (GMON, GCIH, GCDA) or equivalentDeep knowledge of identity attack paths and protocols (Kerberos/NTLM), token/session abuse, and persistence techniques (e.g., Golden/Silver Ticket, DCShadow)Experience with JIT/JEA, PAM concepts, and global on call rotationsLocation, work style, and travelOpportunities in the United States, United Kingdom, and DenmarkOnsite or hybrid depending on location and business needsOccasional on call coverage may be requiredWhy you'll love it hereOwn a mission critical identity defense stack and make measurable impact on MTTD/MTTR and privilege hygieneSolve complex problems from dark web exposure to directory persistence and lateral movementCollaborate with experienced global teams and leading vendors to continuously raise the barGrow your career in a modern, data driven security operations environmentThis is a global position that will support all our FUJIFILM Biotechnologies sites. This position can be based at any of our locations around the globe. Benefits and compensation will be governed by the location that you are based from and considered your home site.As part of any recruitment process, FUJIFILM Diosynth Biotechnologies collects and processes personal data relating to job applicants. The organization is committed to being transparent about how it collects and uses that data and to meeting its data protection obligations and may share this as part of the global recruitment process with hiring managers in Europe and the United States.Please, no phone calls or emails to any employee of FUJIFILM about this requisition. All resumes submitted by search firms/employment agencies to any employee at FUJIFILM via-email, the internet or in any form and/or method will be deemed the sole property of FUJIFILM, unless such search firms/employment agencies were engaged by FUJIFILM for this requisition and a valid agreement with FUJIFILM is in place. In the event a candidate who was submitted outside of the FUJIFILM agency engagement process is hired, no fee or payment of any kind will be paid.
19/07/2026
Full time
Protect identities at global scale. We're hiring a hands-on Senior Identity Protection Engineer/Specialist to lead detection, investigation, and response for identity-based threats across Microsoft Entra ID/Azure AD, on prem Active Directory, and connected SaaS/IaaS. You'll serve as the enterprise SME/administrator for CrowdStrike Identity Protection, tune high-fidelity detections, integrate dark web intelligence, and orchestrate automation that measurably reduces MTTD/MTTR and risk.What you'll doLead identity threat monitoring and triageOperate and tune CrowdStrike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks like impossible travel, atypical sign ins, MFA fatigue, and session hijackingValidate true/false positives, prioritize by business impact, and escalate per playbooks/SLAsDrive rapid containment and remediationExecute containment actions (disable accounts, revoke sessions/tokens, isolate hosts)Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closureOwn identity-focused incident responseLead IR for credential compromise, privilege escalation, directory persistence, and lateral movementEnsure evidence handling, root cause analysis, post incident reviews, and lessons learnedEngineer detections and hunt for threatsBuild and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CKClose visibility gaps, reduce false positives, and expand privileged activity monitoringStrengthen privileged access controlsDetect anomalous privileged behavior via SIEM/UEBA and Netskope telemetryRecommend/enforce JIT, break glass patterns, and mover/leaver privilege hygiene with IAMRespond to dark web/credential exposureIntegrate sources like CyberInt; assess exposure and targeted campaignsOrchestrate takedowns, forced resets, token revocation, and Conditional Access updatesAdminister platforms and sustain hygieneMaintain coverage/health for identity monitoring; manage upgrades and changes via CABKeep operational runbooks, SOPs, and playbooks currentAutomate and orchestrate at scaleUse PowerShell/Python and REST/Graph/CrowdStrike APIs (and SOAR where applicable) to automate enrichment and response, standardize workflows, and improve signal fidelityShape identity policy and controlsAdvise on Conditional Access, MFA exceptions, SSO/SCIM patterns, and session controls under the shared responsibility model with IAMReport outcomes and support auditsProduce executive-ready dashboards and KPIs (identity incident volume, MTTD/MTTR, CA/MFA efficacy, exposure/takedown cycle time)Maintain audit-ready evidence and support internal/external auditsWhat you'll bringBachelor's degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience8+ years in IT/cybersecurity, including 3+ years focused on identity security/operations (Entra ID/Azure AD, on prem AD, MFA, Conditional Access, SSO/SCIM)Hands-on enterprise experience administering/operating CrowdStrike Identity ProtectionProficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms (e.g., Netskope) for identity telemetry, detection, and investigationsDemonstrated experience in identity centric IR, threat hunting, and detection engineering (KQL/SQL/regex/Sigma)Scripting/automation with PowerShell and Python; experience with REST/Graph/CrowdStrike APIs and SOARClear communication and documentation skills; comfortable producing executive ready reports and audit evidenceOperates effectively within change control/CAB and under pressure during high severity incidentsBonus pointsCertifications: Microsoft SC 200/SC 300; Okta Certified Administrator/Professional; CISSP, SSCP, Security+; GIAC (GMON, GCIH, GCDA) or equivalentDeep knowledge of identity attack paths and protocols (Kerberos/NTLM), token/session abuse, and persistence techniques (e.g., Golden/Silver Ticket, DCShadow)Experience with JIT/JEA, PAM concepts, and global on call rotationsLocation, work style, and travelOpportunities in the United States, United Kingdom, and DenmarkOnsite or hybrid depending on location and business needsOccasional on call coverage may be requiredWhy you'll love it hereOwn a mission critical identity defense stack and make measurable impact on MTTD/MTTR and privilege hygieneSolve complex problems from dark web exposure to directory persistence and lateral movementCollaborate with experienced global teams and leading vendors to continuously raise the barGrow your career in a modern, data driven security operations environmentThis is a global position that will support all our FUJIFILM Biotechnologies sites. This position can be based at any of our locations around the globe. Benefits and compensation will be governed by the location that you are based from and considered your home site.As part of any recruitment process, FUJIFILM Diosynth Biotechnologies collects and processes personal data relating to job applicants. The organization is committed to being transparent about how it collects and uses that data and to meeting its data protection obligations and may share this as part of the global recruitment process with hiring managers in Europe and the United States.Please, no phone calls or emails to any employee of FUJIFILM about this requisition. All resumes submitted by search firms/employment agencies to any employee at FUJIFILM via-email, the internet or in any form and/or method will be deemed the sole property of FUJIFILM, unless such search firms/employment agencies were engaged by FUJIFILM for this requisition and a valid agreement with FUJIFILM is in place. In the event a candidate who was submitted outside of the FUJIFILM agency engagement process is hired, no fee or payment of any kind will be paid.
Senior Manager, Center of Expertise
Veeam Software
Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world's biggest brands. About the Role The Senior Manager, Center of Expertise will lead a team of elite product and domain experts who drive measurable outcomes on strategic customer engagements. This role is built for a technically fluent, decisive leader who thrives at the intersection of modern data protection, cloud infrastructure, and AI driven operations-someone who can translate complex architectures into executive level narratives and who genuinely cares about the people they lead and the customers they serve. You will lead a team of Domain Engineering Specialists (DES) who serve as subject matter experts across Veeam Data Platform (VDP), Veeam Data Cloud (VDC), Vault, and Kasten, as well as the broader cloud native and AI/ML ecosystem surrounding them. This is a team that sets the standard-not just within Veeam, but across the industry-and the right leader will take pride in keeping it that way. Your team partners with customer facing teams to lead complex, large scale technical onboardings involving intricate multi environment architectures, data modeling, telemetry analysis, and risk discussions with C suite stakeholders (CISO/CIO/CTO). You will align customer posture against the Veeam Data Resilience Maturity Model (DRMM) and industry frameworks (NIST CSF, CIS Controls, Zero Trust Architecture) to surface optimization opportunities and drive expansion. Success requires deep cross functional alignment, the ability to manage competing priorities at scale, and a bias toward outcomes over activity. What You'll Do Lead and develop a team of 6-10 Domain Engineering Specialists, investing genuinely in their growth through technical coaching, structured career development, and a culture where people feel challenged, valued, and proud of the work they do. Define and execute the team's technical enablement roadmap, with a strong focus on emerging capabilities in AI/ML, cloud native architectures, and cyber resilience. Own the team's involvement in complex, large scale customer onboardings-multi environment migrations, hybrid and multi cloud transformations, and enterprise wide resilience deployments that require deep architectural engagement and precise coordination. Coach specialists to deepen expertise in ransomware recovery, immutable storage, multi cloud data protection, and Kubernetes native backup-and create clear paths for them to grow into recognized experts inside and outside of Veeam. Build and scale a content and resource hub that extends the team's reach beyond 1:1 customer engagements-including technical playbooks, reference architectures, self service assessment tools, and evergreen enablement content. Develop and run high impact customer engagement programs-webinars, roundtables, virtual workshops, executive briefings, and community forums-that position Veeam's expertise in front of broader audiences and create scalable touchpoints across the customer lifecycle. Establish and maintain the team's position as a credible technical authority in conversations with customer engineering, architecture, and executive stakeholders. Drive process improvements and playbooks that scale impact without scaling headcount linearly. Monitor operational KPIs and use data to identify coaching opportunities, capacity gaps, and emerging risk patterns across the customer portfolio. Influence product and engineering roadmaps by synthesizing field level insights into structured feedback loops. Build and maintain cross functional relationships with Sales, Product, Engineering, and Customer Success to ensure coordinated customer outcomes. Serve as an executive level escalation point for complex technical and strategic customer situations. Model and reinforce a high performance culture anchored in intellectual curiosity, ownership, and genuine care for customers and teammates alike. And other responsibilities as needed as the business evolves and grows. What You'll Bring 8+ years of experience in technical customer success, solutions engineering, or related customer facing technical roles-ideally within enterprise SaaS, cloud infrastructure, or data management. 4+ years of people management experience, with a track record of building and scaling high performing technical teams where culture is a competitive advantage, not an afterthought. Deep expertise in data protection and cyber resilience-including ransomware recovery architectures, immutability strategies, air gapped backup, and recovery time/point objectives at enterprise scale. Hands on familiarity with AI and machine learning concepts, including how organizations are operationalizing AI workloads and the data infrastructure that supports them (data pipelines, model training environments, vector databases, LLMOps). Strong working knowledge of major cloud platforms (AWS, Azure, GCP) and cloud native patterns-Kubernetes, containers, serverless, IaC (Terraform/Pulumi), and multi cloud data governance. Fluency in modern infrastructure concepts: hybrid cloud architectures, software defined storage, disaster recovery as code, and observability stacks. Ability to engage credibly in security framework discussions-Zero Trust, NIST CSF, CIS Controls, SOC 2, and regulatory environments (GDPR, HIPAA, FedRAMP). Experience leading or owning large scale, complex customer onboardings with multiple stakeholders, integrated environments, and significant technical and organizational complexity. Proven ability to build scalable content programs-technical resource hubs, reference architectures, webinars, workshops-that extend expert knowledge to audiences well beyond direct engagement. Demonstrated ability to lead teams through ambiguity in fast moving, high growth environments. Strong executive communication skills-able to distill complex technical risk into business impact narratives for CISO, CIO, and board level audiences. Experience using data and telemetry to drive coaching decisions and team performance improvements. Adaptable, high agency operator who sets direction without waiting for perfect information-and brings others along with them. What you'll get 25 paid vacation days, plus 4 extra global VeeaMe Days for self care and 24 paid volunteer hours annually through Veeam Cares. Private medical, dental, and vision insurance with dependent enrolment. Life insurance with enhanced coverage and global 24/7 protection. Income protection after 26 weeks, covering a portion of salary. Defined contribution pension plan with employer match. Worldwide travel insurance for business and leisure, with option to enroll dependents. Employee Assistance Program with therapy, legal, and financial support, plus online GP services and wellbeing programs. Opportunities to learn and grow through on demand libraries (LinkedIn Learning, O'Reilly), mentoring, workshops and learning events like our annual Global Day of Learning. Veeam Software is an equal opportunity employer Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.
19/07/2026
Full time
Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world's biggest brands. About the Role The Senior Manager, Center of Expertise will lead a team of elite product and domain experts who drive measurable outcomes on strategic customer engagements. This role is built for a technically fluent, decisive leader who thrives at the intersection of modern data protection, cloud infrastructure, and AI driven operations-someone who can translate complex architectures into executive level narratives and who genuinely cares about the people they lead and the customers they serve. You will lead a team of Domain Engineering Specialists (DES) who serve as subject matter experts across Veeam Data Platform (VDP), Veeam Data Cloud (VDC), Vault, and Kasten, as well as the broader cloud native and AI/ML ecosystem surrounding them. This is a team that sets the standard-not just within Veeam, but across the industry-and the right leader will take pride in keeping it that way. Your team partners with customer facing teams to lead complex, large scale technical onboardings involving intricate multi environment architectures, data modeling, telemetry analysis, and risk discussions with C suite stakeholders (CISO/CIO/CTO). You will align customer posture against the Veeam Data Resilience Maturity Model (DRMM) and industry frameworks (NIST CSF, CIS Controls, Zero Trust Architecture) to surface optimization opportunities and drive expansion. Success requires deep cross functional alignment, the ability to manage competing priorities at scale, and a bias toward outcomes over activity. What You'll Do Lead and develop a team of 6-10 Domain Engineering Specialists, investing genuinely in their growth through technical coaching, structured career development, and a culture where people feel challenged, valued, and proud of the work they do. Define and execute the team's technical enablement roadmap, with a strong focus on emerging capabilities in AI/ML, cloud native architectures, and cyber resilience. Own the team's involvement in complex, large scale customer onboardings-multi environment migrations, hybrid and multi cloud transformations, and enterprise wide resilience deployments that require deep architectural engagement and precise coordination. Coach specialists to deepen expertise in ransomware recovery, immutable storage, multi cloud data protection, and Kubernetes native backup-and create clear paths for them to grow into recognized experts inside and outside of Veeam. Build and scale a content and resource hub that extends the team's reach beyond 1:1 customer engagements-including technical playbooks, reference architectures, self service assessment tools, and evergreen enablement content. Develop and run high impact customer engagement programs-webinars, roundtables, virtual workshops, executive briefings, and community forums-that position Veeam's expertise in front of broader audiences and create scalable touchpoints across the customer lifecycle. Establish and maintain the team's position as a credible technical authority in conversations with customer engineering, architecture, and executive stakeholders. Drive process improvements and playbooks that scale impact without scaling headcount linearly. Monitor operational KPIs and use data to identify coaching opportunities, capacity gaps, and emerging risk patterns across the customer portfolio. Influence product and engineering roadmaps by synthesizing field level insights into structured feedback loops. Build and maintain cross functional relationships with Sales, Product, Engineering, and Customer Success to ensure coordinated customer outcomes. Serve as an executive level escalation point for complex technical and strategic customer situations. Model and reinforce a high performance culture anchored in intellectual curiosity, ownership, and genuine care for customers and teammates alike. And other responsibilities as needed as the business evolves and grows. What You'll Bring 8+ years of experience in technical customer success, solutions engineering, or related customer facing technical roles-ideally within enterprise SaaS, cloud infrastructure, or data management. 4+ years of people management experience, with a track record of building and scaling high performing technical teams where culture is a competitive advantage, not an afterthought. Deep expertise in data protection and cyber resilience-including ransomware recovery architectures, immutability strategies, air gapped backup, and recovery time/point objectives at enterprise scale. Hands on familiarity with AI and machine learning concepts, including how organizations are operationalizing AI workloads and the data infrastructure that supports them (data pipelines, model training environments, vector databases, LLMOps). Strong working knowledge of major cloud platforms (AWS, Azure, GCP) and cloud native patterns-Kubernetes, containers, serverless, IaC (Terraform/Pulumi), and multi cloud data governance. Fluency in modern infrastructure concepts: hybrid cloud architectures, software defined storage, disaster recovery as code, and observability stacks. Ability to engage credibly in security framework discussions-Zero Trust, NIST CSF, CIS Controls, SOC 2, and regulatory environments (GDPR, HIPAA, FedRAMP). Experience leading or owning large scale, complex customer onboardings with multiple stakeholders, integrated environments, and significant technical and organizational complexity. Proven ability to build scalable content programs-technical resource hubs, reference architectures, webinars, workshops-that extend expert knowledge to audiences well beyond direct engagement. Demonstrated ability to lead teams through ambiguity in fast moving, high growth environments. Strong executive communication skills-able to distill complex technical risk into business impact narratives for CISO, CIO, and board level audiences. Experience using data and telemetry to drive coaching decisions and team performance improvements. Adaptable, high agency operator who sets direction without waiting for perfect information-and brings others along with them. What you'll get 25 paid vacation days, plus 4 extra global VeeaMe Days for self care and 24 paid volunteer hours annually through Veeam Cares. Private medical, dental, and vision insurance with dependent enrolment. Life insurance with enhanced coverage and global 24/7 protection. Income protection after 26 weeks, covering a portion of salary. Defined contribution pension plan with employer match. Worldwide travel insurance for business and leisure, with option to enroll dependents. Employee Assistance Program with therapy, legal, and financial support, plus online GP services and wellbeing programs. Opportunities to learn and grow through on demand libraries (LinkedIn Learning, O'Reilly), mentoring, workshops and learning events like our annual Global Day of Learning. Veeam Software is an equal opportunity employer Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.
Identity & Access Specialist
Automobile Association Basingstoke, Hampshire
Location: Basingstoke (hybrid working 3 office days per week) Employment Type: Permanent, full time Think the AA is just about roadside assistance? Think again. For over a century, we've been evolving and adapting. Today, as the nation's leading motoring organisation, we offer a wide range of products and services to millions of customers. From roadside assistance to home and motor insurance, and the latest driving technologies, we have it all. As we continue to expand, diversify, and modernise, joining us as an Identity & Access Specialist means you'll play a crucial role in our success and be part of this exciting motoring journey. Our Chief Operating Office (COO) are the backbone of The AA, providing both stability and structure to support growth and innovation. We are the drivers of change. This is the job Help shape the future of identity security at one of the UK's most trusted brands Identity is central to cyber security, and at The AA you will play a key role in protecting the technology that underpins how colleagues, partners and systems securely connect and operate. As our Identity & Access Specialist, you will be a trusted technical expert within Group Security, working closely with the Identity & Access Manager and senior colleagues across Cyber Security, Technology and Architecture. You will bring deep IAM expertise to strengthen secure solutions, improve governance and reduce risk across a complex enterprise environment. This is an outstanding opportunity for an experienced IAM professional who wants to stay close to the technical detail while influencing meaningful security outcomes, driving improvement and making a visible impact on the future of identity security at The AA. What will I be doing? Act as a trusted subject matter expert across Identity & Access Management, supporting the design, enhancement and assurance of secure identity and privileged access controls. Provide technical guidance across Microsoft Entra ID, Conditional Access, MFA, identity governance, SSO, federation and privileged access, helping teams deliver secure and scalable solutions. Partner with Technology, Architecture, Platform, Risk and Compliance teams to review solutions, provide pragmatic security advice and support the successful delivery of change. Contribute to the development of IAM standards, technical guidance, governance documentation and audit evidence, helping strengthen the organisation's overall security posture. Support identity related risk assessments, investigations and remediation activities, providing practical recommendations that balance security, operational effectiveness and user experience. Identify opportunities to improve IAM processes, controls and ways of working, contributing to the continued maturity of the organisation's identity capability. What do I need? Strong technical experience within Identity & Access Management, Identity Governance, Privileged Access Management or a closely related cyber security discipline within a complex enterprise environment. Demonstrable expertise with Microsoft identity technologies, including Microsoft Entra ID and modern IAM capabilities such as Conditional Access, MFA, federation, SSO and privileged access management. Experience supporting governance, risk and compliance activities, including developing standards, producing assurance evidence and helping organisations strengthen security controls. Experience within GRC would be particularly valuable. Confident stakeholder management skills, with the ability to build trusted relationships and influence technical teams, managers and Heads of Function through clear, pragmatic advice. Strong analytical and problem-solving capability, with the confidence to assess technical challenges, understand business risk and recommend balanced, practical solutions. Relevant industry certifications such as Microsoft SC 300, SC 100, CISSP, CCSP, CIAM or equivalent practical experience would be advantageous, although we value demonstrable capability just as highly. Additional information We're always looking to recognise and reward our employees for the work they do. As a valued member of The AA team, you'll have access to a range of benefits including: 25 days annual leave plus bank holidays + holiday buying scheme Worksave pension scheme with up to 7% employer contribution Free AA breakdown membership from Day 1 plus 50% discount for family and friends Discounts on AA products including car and home insurance Employee discount scheme that gives you access to a car salary sacrifice scheme plus great discounts on healthcare, shopping, holidays and more Company funded life assurance Diverse learning and development opportunities to support you to progress in your career Dedicated Employee Assistance Programme and a 24/7 remote GP service for you and your family Plus, so much more! We're an equal opportunities employer and welcome applications from everyone. The AA values diversity and the difference this brings to our culture and our customers. We actively seek people from diverse backgrounds to join us and become part of an inclusive company where you can be yourself, be empowered to be your best and feel like you truly belong. We have five communities to bring together people with shared characteristics and backgrounds and drive positive change.
19/07/2026
Full time
Location: Basingstoke (hybrid working 3 office days per week) Employment Type: Permanent, full time Think the AA is just about roadside assistance? Think again. For over a century, we've been evolving and adapting. Today, as the nation's leading motoring organisation, we offer a wide range of products and services to millions of customers. From roadside assistance to home and motor insurance, and the latest driving technologies, we have it all. As we continue to expand, diversify, and modernise, joining us as an Identity & Access Specialist means you'll play a crucial role in our success and be part of this exciting motoring journey. Our Chief Operating Office (COO) are the backbone of The AA, providing both stability and structure to support growth and innovation. We are the drivers of change. This is the job Help shape the future of identity security at one of the UK's most trusted brands Identity is central to cyber security, and at The AA you will play a key role in protecting the technology that underpins how colleagues, partners and systems securely connect and operate. As our Identity & Access Specialist, you will be a trusted technical expert within Group Security, working closely with the Identity & Access Manager and senior colleagues across Cyber Security, Technology and Architecture. You will bring deep IAM expertise to strengthen secure solutions, improve governance and reduce risk across a complex enterprise environment. This is an outstanding opportunity for an experienced IAM professional who wants to stay close to the technical detail while influencing meaningful security outcomes, driving improvement and making a visible impact on the future of identity security at The AA. What will I be doing? Act as a trusted subject matter expert across Identity & Access Management, supporting the design, enhancement and assurance of secure identity and privileged access controls. Provide technical guidance across Microsoft Entra ID, Conditional Access, MFA, identity governance, SSO, federation and privileged access, helping teams deliver secure and scalable solutions. Partner with Technology, Architecture, Platform, Risk and Compliance teams to review solutions, provide pragmatic security advice and support the successful delivery of change. Contribute to the development of IAM standards, technical guidance, governance documentation and audit evidence, helping strengthen the organisation's overall security posture. Support identity related risk assessments, investigations and remediation activities, providing practical recommendations that balance security, operational effectiveness and user experience. Identify opportunities to improve IAM processes, controls and ways of working, contributing to the continued maturity of the organisation's identity capability. What do I need? Strong technical experience within Identity & Access Management, Identity Governance, Privileged Access Management or a closely related cyber security discipline within a complex enterprise environment. Demonstrable expertise with Microsoft identity technologies, including Microsoft Entra ID and modern IAM capabilities such as Conditional Access, MFA, federation, SSO and privileged access management. Experience supporting governance, risk and compliance activities, including developing standards, producing assurance evidence and helping organisations strengthen security controls. Experience within GRC would be particularly valuable. Confident stakeholder management skills, with the ability to build trusted relationships and influence technical teams, managers and Heads of Function through clear, pragmatic advice. Strong analytical and problem-solving capability, with the confidence to assess technical challenges, understand business risk and recommend balanced, practical solutions. Relevant industry certifications such as Microsoft SC 300, SC 100, CISSP, CCSP, CIAM or equivalent practical experience would be advantageous, although we value demonstrable capability just as highly. Additional information We're always looking to recognise and reward our employees for the work they do. As a valued member of The AA team, you'll have access to a range of benefits including: 25 days annual leave plus bank holidays + holiday buying scheme Worksave pension scheme with up to 7% employer contribution Free AA breakdown membership from Day 1 plus 50% discount for family and friends Discounts on AA products including car and home insurance Employee discount scheme that gives you access to a car salary sacrifice scheme plus great discounts on healthcare, shopping, holidays and more Company funded life assurance Diverse learning and development opportunities to support you to progress in your career Dedicated Employee Assistance Programme and a 24/7 remote GP service for you and your family Plus, so much more! We're an equal opportunities employer and welcome applications from everyone. The AA values diversity and the difference this brings to our culture and our customers. We actively seek people from diverse backgrounds to join us and become part of an inclusive company where you can be yourself, be empowered to be your best and feel like you truly belong. We have five communities to bring together people with shared characteristics and backgrounds and drive positive change.
MI5
International Technical Director Cyber Security Strategy
MI5 Cheltenham, Gloucestershire
Cheltenham, London, Manchester Job description About us GCHQ is an intelligence, cyber and security agency with a mission to keep the UK safe. We use cutting-edge technology, ingenuity and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners MI5 and MI6, we protect the UK from terrorism, cyber-attacks and espionage. At GCHQ you'll do varied and fascinating work in a supportive and inclusive environment that puts the emphasis on teamwork. The National Cyber Security Centre (NCSC), part of GCHQ, is the UK Government's lead authority on cyber security. The organisation is at the heart of the Government's cyber security strategy and has the aim of making the UK the safest place to live and work online. Job description We're currently looking for an International Technical Director to join our team within NCSC's Office of the Chief Technical Officer. In this role, you'll work alongside technical specialists who explore the core security attributes of the UK's critical systems and technologies. Together, we identify vulnerabilities and create resilient, long-term solutions that help protect the nation's digital infrastructure. What will the successful candidate be doing? You'll be at the centre of meaningful, technical work that drives real-world impact on an international stage. You'll work both independently and collaboratively, reporting to a senior colleague while offering expert advice on specific projects. You'll have responsibility for mentoring others, engaging with senior leaders and specialists, and providing strategic insight, especially when navigating complex challenges. You'll be expected to undertake frequent international travel, potentially leading to a full-time posting overseas in 12 months' time for approximately 2 years. The successful candidate will support the development of the Memorandum of Understandings (MoUs) with international partners. Person Specification The successful applicant will need to have: We're looking for someone (preferably with an existing security clearance) with: at least five years of practical experience in cyber security. significant experience working both with a government department and in international settings. ability to work confidently across a broad range of technical cyber security topics such as: Designing secure architectures for IT, Operational Technology, or AI systems. Analysing hardware and device-level security features. Research software vulnerabilities and secure development practices. Application of Cryptographic protocols or the security of networking and telecommunications technologies. deep technical expertise in one or more areas of cyber security. knowledge on how technological vulnerabilities occur, how they are discovered, and how they may be exploited experience of applying specialist technical security capabilities to help solve customer security problems GCHQ Competencies As part of the selection process, the NCSC will assess you using competencies aligned with those used across the UK Intelligence Community. These are closely based on the Civil Service Behaviours , so if you're familiar with those, you're already on the right track. At Level 4, we'll be looking at how you demonstrate the following: Seeing the Big Picture (Civil Service Behaviour Equivalent: Seeing the Big Picture) Communicating and Influencing (Civil Service Behaviour Equivalent: Communicating and Influencing) Working Collaboratively (Civil Service Behaviour Equivalent: Working Together) Providing Customer Value (Civil Service Behaviour Equivalent: Managing a Quality Service) Further information on Civil Service Behaviours Benefits and rewards At NCSC and GCHQ, we are proud of our inclusive and supportive working environment which is designed to encourage open minds and attitudes. As an organisation that values and nurtures talent, we are committed to helping you fulfil your potential. With comprehensive training and development opportunities, tailored to your needs and the requirements of your work, we will enable you to flourish in your role and perform to the very best of your abilities. You'll receive a starting salary of £71,889 (including a concessionary payment of £3,144). This role may attract a skills payment, for which you'll be evaluated for during the interview. The criteria for the skills assessment will be provided when you are invited to interview. If you are assessed to qualify for a skills payment, these payments start at £6,552 per annum. For roles based in London, you'll receive an additional £6,250 London Allowance. Other benefits include: 25 Days Annual Leave automatically rising to 30 days after 5 years' service, and an additional 10.5 days' public and privilege holidays Opportunities to be recognised through our employee performance scheme Interest-free season ticket loan Cycle to work scheme Facilities such as a gym, restaurant and on-site coffee bars (at some locations) Paid parental and adoption leave Excellent pension scheme - Civil Service pension Equal Opportunities At GCHQ diversity and inclusion are critical to our mission. To protect the UK, we need a truly diverse workforce that reflects the society we serve. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under-represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio-economic backgrounds. Find out more about our culture, working environment and diversity on our website . Disability Confident GCHQ is proud to have achieved Leader status within the DWP's Disability Confident scheme. This is aimed at encouraging employers to think differently about disability and take action to improve how they recruit, retain and develop disabled people. As a Disability Confident Leader we aim to ensure that a fair and proportionate number of disabled applicants who best meet the essential minimum criteria for this position, will be offered an interview, if it is practical for us to do so. (This is known as Offer of an Interview.) To secure an interview for this role, the minimum criteria, which will be assessed at the CV sift stage: You'll be required to reach the minimum pass mark for the online Situational Judgement Test (SJT), which assesses criteria important for all roles in our organisation. Demonstrate experience of applying specialist technical security capabilities to help solve customer security problems. Assessed at application sift. Demonstrate how technological vulnerabilities occur, how they are discovered, and how they may be exploited. Assessed at application sift. Demonstrate experience of leading a technical team. Assessed at CV sift. There is a wide range of extra support available throughout the recruitment process to enable you to do your best, see o ur website for information on reasonable adjustments we can offer . What to Expect Our recruitment process is fair, transparent, and based on merit. Here is a brief overview of each stage, in order:Initial online application.Online Situational Judgement Test (SJT) rating the appropriateness of your response to a series of short scenarios.Application sift.Online Interview.If successful, you'll receive a conditional offer of employment. Please note, you must successfully pass each stage of the process to progress to the next. Your application may take around 6 - 9 months to process including vetting, so we advise you to continue any current employment until you have received your final job offer. Before You Apply To work at NCSC, you need to be a British citizen or hold dual British nationality. You can read our full eligibility criteria here . This role requires the highest security clearance, known as Developed Vetting (DV). It's something everyone in the UK Intelligence Community undertakes. You can find out more about the vetting process here . Please note we have a strict drugs policy, so once you start your application, you can't take any recreational drugs and you'll need to declare your previous drug usage at the relevant stage. Before you apply, recommend setting up a separate email address for your contact with us, to ensure your personal and application correspondence remain separate. Try to avoid having identifying features in your email address, such as your first and/or surname and date of birth. This is good practice and will help you to manage your application with us more securely. The role is based either London, Cheltenham or Manchester, so you'll need to live within a commutable distance. Please consider any financial implications and practicalities before submitting an application, as we do not offer relocation costs. We offer reasonable reimbursement of travel costs for candidates attending in-person appointments during the recruitment and vetting process . click apply for full job details
19/07/2026
Full time
Cheltenham, London, Manchester Job description About us GCHQ is an intelligence, cyber and security agency with a mission to keep the UK safe. We use cutting-edge technology, ingenuity and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners MI5 and MI6, we protect the UK from terrorism, cyber-attacks and espionage. At GCHQ you'll do varied and fascinating work in a supportive and inclusive environment that puts the emphasis on teamwork. The National Cyber Security Centre (NCSC), part of GCHQ, is the UK Government's lead authority on cyber security. The organisation is at the heart of the Government's cyber security strategy and has the aim of making the UK the safest place to live and work online. Job description We're currently looking for an International Technical Director to join our team within NCSC's Office of the Chief Technical Officer. In this role, you'll work alongside technical specialists who explore the core security attributes of the UK's critical systems and technologies. Together, we identify vulnerabilities and create resilient, long-term solutions that help protect the nation's digital infrastructure. What will the successful candidate be doing? You'll be at the centre of meaningful, technical work that drives real-world impact on an international stage. You'll work both independently and collaboratively, reporting to a senior colleague while offering expert advice on specific projects. You'll have responsibility for mentoring others, engaging with senior leaders and specialists, and providing strategic insight, especially when navigating complex challenges. You'll be expected to undertake frequent international travel, potentially leading to a full-time posting overseas in 12 months' time for approximately 2 years. The successful candidate will support the development of the Memorandum of Understandings (MoUs) with international partners. Person Specification The successful applicant will need to have: We're looking for someone (preferably with an existing security clearance) with: at least five years of practical experience in cyber security. significant experience working both with a government department and in international settings. ability to work confidently across a broad range of technical cyber security topics such as: Designing secure architectures for IT, Operational Technology, or AI systems. Analysing hardware and device-level security features. Research software vulnerabilities and secure development practices. Application of Cryptographic protocols or the security of networking and telecommunications technologies. deep technical expertise in one or more areas of cyber security. knowledge on how technological vulnerabilities occur, how they are discovered, and how they may be exploited experience of applying specialist technical security capabilities to help solve customer security problems GCHQ Competencies As part of the selection process, the NCSC will assess you using competencies aligned with those used across the UK Intelligence Community. These are closely based on the Civil Service Behaviours , so if you're familiar with those, you're already on the right track. At Level 4, we'll be looking at how you demonstrate the following: Seeing the Big Picture (Civil Service Behaviour Equivalent: Seeing the Big Picture) Communicating and Influencing (Civil Service Behaviour Equivalent: Communicating and Influencing) Working Collaboratively (Civil Service Behaviour Equivalent: Working Together) Providing Customer Value (Civil Service Behaviour Equivalent: Managing a Quality Service) Further information on Civil Service Behaviours Benefits and rewards At NCSC and GCHQ, we are proud of our inclusive and supportive working environment which is designed to encourage open minds and attitudes. As an organisation that values and nurtures talent, we are committed to helping you fulfil your potential. With comprehensive training and development opportunities, tailored to your needs and the requirements of your work, we will enable you to flourish in your role and perform to the very best of your abilities. You'll receive a starting salary of £71,889 (including a concessionary payment of £3,144). This role may attract a skills payment, for which you'll be evaluated for during the interview. The criteria for the skills assessment will be provided when you are invited to interview. If you are assessed to qualify for a skills payment, these payments start at £6,552 per annum. For roles based in London, you'll receive an additional £6,250 London Allowance. Other benefits include: 25 Days Annual Leave automatically rising to 30 days after 5 years' service, and an additional 10.5 days' public and privilege holidays Opportunities to be recognised through our employee performance scheme Interest-free season ticket loan Cycle to work scheme Facilities such as a gym, restaurant and on-site coffee bars (at some locations) Paid parental and adoption leave Excellent pension scheme - Civil Service pension Equal Opportunities At GCHQ diversity and inclusion are critical to our mission. To protect the UK, we need a truly diverse workforce that reflects the society we serve. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under-represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio-economic backgrounds. Find out more about our culture, working environment and diversity on our website . Disability Confident GCHQ is proud to have achieved Leader status within the DWP's Disability Confident scheme. This is aimed at encouraging employers to think differently about disability and take action to improve how they recruit, retain and develop disabled people. As a Disability Confident Leader we aim to ensure that a fair and proportionate number of disabled applicants who best meet the essential minimum criteria for this position, will be offered an interview, if it is practical for us to do so. (This is known as Offer of an Interview.) To secure an interview for this role, the minimum criteria, which will be assessed at the CV sift stage: You'll be required to reach the minimum pass mark for the online Situational Judgement Test (SJT), which assesses criteria important for all roles in our organisation. Demonstrate experience of applying specialist technical security capabilities to help solve customer security problems. Assessed at application sift. Demonstrate how technological vulnerabilities occur, how they are discovered, and how they may be exploited. Assessed at application sift. Demonstrate experience of leading a technical team. Assessed at CV sift. There is a wide range of extra support available throughout the recruitment process to enable you to do your best, see o ur website for information on reasonable adjustments we can offer . What to Expect Our recruitment process is fair, transparent, and based on merit. Here is a brief overview of each stage, in order:Initial online application.Online Situational Judgement Test (SJT) rating the appropriateness of your response to a series of short scenarios.Application sift.Online Interview.If successful, you'll receive a conditional offer of employment. Please note, you must successfully pass each stage of the process to progress to the next. Your application may take around 6 - 9 months to process including vetting, so we advise you to continue any current employment until you have received your final job offer. Before You Apply To work at NCSC, you need to be a British citizen or hold dual British nationality. You can read our full eligibility criteria here . This role requires the highest security clearance, known as Developed Vetting (DV). It's something everyone in the UK Intelligence Community undertakes. You can find out more about the vetting process here . Please note we have a strict drugs policy, so once you start your application, you can't take any recreational drugs and you'll need to declare your previous drug usage at the relevant stage. Before you apply, recommend setting up a separate email address for your contact with us, to ensure your personal and application correspondence remain separate. Try to avoid having identifying features in your email address, such as your first and/or surname and date of birth. This is good practice and will help you to manage your application with us more securely. The role is based either London, Cheltenham or Manchester, so you'll need to live within a commutable distance. Please consider any financial implications and practicalities before submitting an application, as we do not offer relocation costs. We offer reasonable reimbursement of travel costs for candidates attending in-person appointments during the recruitment and vetting process . click apply for full job details
MI5
International Technical Director Cyber Security Strategy
MI5
Cheltenham, London, Manchester Job description About us GCHQ is an intelligence, cyber and security agency with a mission to keep the UK safe. We use cutting-edge technology, ingenuity and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners MI5 and MI6, we protect the UK from terrorism, cyber-attacks and espionage. At GCHQ you'll do varied and fascinating work in a supportive and inclusive environment that puts the emphasis on teamwork. The National Cyber Security Centre (NCSC), part of GCHQ, is the UK Government's lead authority on cyber security. The organisation is at the heart of the Government's cyber security strategy and has the aim of making the UK the safest place to live and work online. Job description We're currently looking for an International Technical Director to join our team within NCSC's Office of the Chief Technical Officer. In this role, you'll work alongside technical specialists who explore the core security attributes of the UK's critical systems and technologies. Together, we identify vulnerabilities and create resilient, long-term solutions that help protect the nation's digital infrastructure. What will the successful candidate be doing? You'll be at the centre of meaningful, technical work that drives real-world impact on an international stage. You'll work both independently and collaboratively, reporting to a senior colleague while offering expert advice on specific projects. You'll have responsibility for mentoring others, engaging with senior leaders and specialists, and providing strategic insight, especially when navigating complex challenges. You'll be expected to undertake frequent international travel, potentially leading to a full-time posting overseas in 12 months' time for approximately 2 years. The successful candidate will support the development of the Memorandum of Understandings (MoUs) with international partners. Person Specification The successful applicant will need to have: We're looking for someone (preferably with an existing security clearance) with: at least five years of practical experience in cyber security. significant experience working both with a government department and in international settings. ability to work confidently across a broad range of technical cyber security topics such as: Designing secure architectures for IT, Operational Technology, or AI systems. Analysing hardware and device-level security features. Research software vulnerabilities and secure development practices. Application of Cryptographic protocols or the security of networking and telecommunications technologies. deep technical expertise in one or more areas of cyber security. knowledge on how technological vulnerabilities occur, how they are discovered, and how they may be exploited experience of applying specialist technical security capabilities to help solve customer security problems GCHQ Competencies As part of the selection process, the NCSC will assess you using competencies aligned with those used across the UK Intelligence Community. These are closely based on the Civil Service Behaviours , so if you're familiar with those, you're already on the right track. At Level 4, we'll be looking at how you demonstrate the following: Seeing the Big Picture (Civil Service Behaviour Equivalent: Seeing the Big Picture) Communicating and Influencing (Civil Service Behaviour Equivalent: Communicating and Influencing) Working Collaboratively (Civil Service Behaviour Equivalent: Working Together) Providing Customer Value (Civil Service Behaviour Equivalent: Managing a Quality Service) Further information on Civil Service Behaviours Benefits and rewards At NCSC and GCHQ, we are proud of our inclusive and supportive working environment which is designed to encourage open minds and attitudes. As an organisation that values and nurtures talent, we are committed to helping you fulfil your potential. With comprehensive training and development opportunities, tailored to your needs and the requirements of your work, we will enable you to flourish in your role and perform to the very best of your abilities. You'll receive a starting salary of £71,889 (including a concessionary payment of £3,144). This role may attract a skills payment, for which you'll be evaluated for during the interview. The criteria for the skills assessment will be provided when you are invited to interview. If you are assessed to qualify for a skills payment, these payments start at £6,552 per annum. For roles based in London, you'll receive an additional £6,250 London Allowance. Other benefits include: 25 Days Annual Leave automatically rising to 30 days after 5 years' service, and an additional 10.5 days' public and privilege holidays Opportunities to be recognised through our employee performance scheme Interest-free season ticket loan Cycle to work scheme Facilities such as a gym, restaurant and on-site coffee bars (at some locations) Paid parental and adoption leave Excellent pension scheme - Civil Service pension Equal Opportunities At GCHQ diversity and inclusion are critical to our mission. To protect the UK, we need a truly diverse workforce that reflects the society we serve. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under-represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio-economic backgrounds. Find out more about our culture, working environment and diversity on our website . Disability Confident GCHQ is proud to have achieved Leader status within the DWP's Disability Confident scheme. This is aimed at encouraging employers to think differently about disability and take action to improve how they recruit, retain and develop disabled people. As a Disability Confident Leader we aim to ensure that a fair and proportionate number of disabled applicants who best meet the essential minimum criteria for this position, will be offered an interview, if it is practical for us to do so. (This is known as Offer of an Interview.) To secure an interview for this role, the minimum criteria, which will be assessed at the CV sift stage: You'll be required to reach the minimum pass mark for the online Situational Judgement Test (SJT), which assesses criteria important for all roles in our organisation. Demonstrate experience of applying specialist technical security capabilities to help solve customer security problems. Assessed at application sift. Demonstrate how technological vulnerabilities occur, how they are discovered, and how they may be exploited. Assessed at application sift. Demonstrate experience of leading a technical team. Assessed at CV sift. There is a wide range of extra support available throughout the recruitment process to enable you to do your best, see o ur website for information on reasonable adjustments we can offer . What to Expect Our recruitment process is fair, transparent, and based on merit. Here is a brief overview of each stage, in order:Initial online application.Online Situational Judgement Test (SJT) rating the appropriateness of your response to a series of short scenarios.Application sift.Online Interview.If successful, you'll receive a conditional offer of employment. Please note, you must successfully pass each stage of the process to progress to the next. Your application may take around 6 - 9 months to process including vetting, so we advise you to continue any current employment until you have received your final job offer. Before You Apply To work at NCSC, you need to be a British citizen or hold dual British nationality. You can read our full eligibility criteria here . This role requires the highest security clearance, known as Developed Vetting (DV). It's something everyone in the UK Intelligence Community undertakes. You can find out more about the vetting process here . Please note we have a strict drugs policy, so once you start your application, you can't take any recreational drugs and you'll need to declare your previous drug usage at the relevant stage. Before you apply, recommend setting up a separate email address for your contact with us, to ensure your personal and application correspondence remain separate. Try to avoid having identifying features in your email address, such as your first and/or surname and date of birth. This is good practice and will help you to manage your application with us more securely. The role is based either London, Cheltenham or Manchester, so you'll need to live within a commutable distance. Please consider any financial implications and practicalities before submitting an application, as we do not offer relocation costs. We offer reasonable reimbursement of travel costs for candidates attending in-person appointments during the recruitment and vetting process . click apply for full job details
19/07/2026
Full time
Cheltenham, London, Manchester Job description About us GCHQ is an intelligence, cyber and security agency with a mission to keep the UK safe. We use cutting-edge technology, ingenuity and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners MI5 and MI6, we protect the UK from terrorism, cyber-attacks and espionage. At GCHQ you'll do varied and fascinating work in a supportive and inclusive environment that puts the emphasis on teamwork. The National Cyber Security Centre (NCSC), part of GCHQ, is the UK Government's lead authority on cyber security. The organisation is at the heart of the Government's cyber security strategy and has the aim of making the UK the safest place to live and work online. Job description We're currently looking for an International Technical Director to join our team within NCSC's Office of the Chief Technical Officer. In this role, you'll work alongside technical specialists who explore the core security attributes of the UK's critical systems and technologies. Together, we identify vulnerabilities and create resilient, long-term solutions that help protect the nation's digital infrastructure. What will the successful candidate be doing? You'll be at the centre of meaningful, technical work that drives real-world impact on an international stage. You'll work both independently and collaboratively, reporting to a senior colleague while offering expert advice on specific projects. You'll have responsibility for mentoring others, engaging with senior leaders and specialists, and providing strategic insight, especially when navigating complex challenges. You'll be expected to undertake frequent international travel, potentially leading to a full-time posting overseas in 12 months' time for approximately 2 years. The successful candidate will support the development of the Memorandum of Understandings (MoUs) with international partners. Person Specification The successful applicant will need to have: We're looking for someone (preferably with an existing security clearance) with: at least five years of practical experience in cyber security. significant experience working both with a government department and in international settings. ability to work confidently across a broad range of technical cyber security topics such as: Designing secure architectures for IT, Operational Technology, or AI systems. Analysing hardware and device-level security features. Research software vulnerabilities and secure development practices. Application of Cryptographic protocols or the security of networking and telecommunications technologies. deep technical expertise in one or more areas of cyber security. knowledge on how technological vulnerabilities occur, how they are discovered, and how they may be exploited experience of applying specialist technical security capabilities to help solve customer security problems GCHQ Competencies As part of the selection process, the NCSC will assess you using competencies aligned with those used across the UK Intelligence Community. These are closely based on the Civil Service Behaviours , so if you're familiar with those, you're already on the right track. At Level 4, we'll be looking at how you demonstrate the following: Seeing the Big Picture (Civil Service Behaviour Equivalent: Seeing the Big Picture) Communicating and Influencing (Civil Service Behaviour Equivalent: Communicating and Influencing) Working Collaboratively (Civil Service Behaviour Equivalent: Working Together) Providing Customer Value (Civil Service Behaviour Equivalent: Managing a Quality Service) Further information on Civil Service Behaviours Benefits and rewards At NCSC and GCHQ, we are proud of our inclusive and supportive working environment which is designed to encourage open minds and attitudes. As an organisation that values and nurtures talent, we are committed to helping you fulfil your potential. With comprehensive training and development opportunities, tailored to your needs and the requirements of your work, we will enable you to flourish in your role and perform to the very best of your abilities. You'll receive a starting salary of £71,889 (including a concessionary payment of £3,144). This role may attract a skills payment, for which you'll be evaluated for during the interview. The criteria for the skills assessment will be provided when you are invited to interview. If you are assessed to qualify for a skills payment, these payments start at £6,552 per annum. For roles based in London, you'll receive an additional £6,250 London Allowance. Other benefits include: 25 Days Annual Leave automatically rising to 30 days after 5 years' service, and an additional 10.5 days' public and privilege holidays Opportunities to be recognised through our employee performance scheme Interest-free season ticket loan Cycle to work scheme Facilities such as a gym, restaurant and on-site coffee bars (at some locations) Paid parental and adoption leave Excellent pension scheme - Civil Service pension Equal Opportunities At GCHQ diversity and inclusion are critical to our mission. To protect the UK, we need a truly diverse workforce that reflects the society we serve. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under-represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio-economic backgrounds. Find out more about our culture, working environment and diversity on our website . Disability Confident GCHQ is proud to have achieved Leader status within the DWP's Disability Confident scheme. This is aimed at encouraging employers to think differently about disability and take action to improve how they recruit, retain and develop disabled people. As a Disability Confident Leader we aim to ensure that a fair and proportionate number of disabled applicants who best meet the essential minimum criteria for this position, will be offered an interview, if it is practical for us to do so. (This is known as Offer of an Interview.) To secure an interview for this role, the minimum criteria, which will be assessed at the CV sift stage: You'll be required to reach the minimum pass mark for the online Situational Judgement Test (SJT), which assesses criteria important for all roles in our organisation. Demonstrate experience of applying specialist technical security capabilities to help solve customer security problems. Assessed at application sift. Demonstrate how technological vulnerabilities occur, how they are discovered, and how they may be exploited. Assessed at application sift. Demonstrate experience of leading a technical team. Assessed at CV sift. There is a wide range of extra support available throughout the recruitment process to enable you to do your best, see o ur website for information on reasonable adjustments we can offer . What to Expect Our recruitment process is fair, transparent, and based on merit. Here is a brief overview of each stage, in order:Initial online application.Online Situational Judgement Test (SJT) rating the appropriateness of your response to a series of short scenarios.Application sift.Online Interview.If successful, you'll receive a conditional offer of employment. Please note, you must successfully pass each stage of the process to progress to the next. Your application may take around 6 - 9 months to process including vetting, so we advise you to continue any current employment until you have received your final job offer. Before You Apply To work at NCSC, you need to be a British citizen or hold dual British nationality. You can read our full eligibility criteria here . This role requires the highest security clearance, known as Developed Vetting (DV). It's something everyone in the UK Intelligence Community undertakes. You can find out more about the vetting process here . Please note we have a strict drugs policy, so once you start your application, you can't take any recreational drugs and you'll need to declare your previous drug usage at the relevant stage. Before you apply, recommend setting up a separate email address for your contact with us, to ensure your personal and application correspondence remain separate. Try to avoid having identifying features in your email address, such as your first and/or surname and date of birth. This is good practice and will help you to manage your application with us more securely. The role is based either London, Cheltenham or Manchester, so you'll need to live within a commutable distance. Please consider any financial implications and practicalities before submitting an application, as we do not offer relocation costs. We offer reasonable reimbursement of travel costs for candidates attending in-person appointments during the recruitment and vetting process . click apply for full job details
Full Stack Engineer - APIM
Centrica plc
Full Stack Engineer - APIMApplylocations: Windsortime type: Full timeposted on: Posted 8 Days Agotime left to apply: End Date: May 25, 2026 (5 days left to apply)job requisition id: R Join us, be part of more. We're so much more than an energy company. We're a family of brands revolutionising how we power the planet. We're energisers. One team of 21,000 colleagues that's energising a greener, fairer future by creating an energy system that doesn't rely on fossil fuels, whilst living our powerful commitment to igniting positive change in our communities. Here, you can find more purpose, more passion, and more potential. That's why working here is . We do energy differently - we do it all. We make it, store it, move it, sell it, and mend it. Centrica, Technology is a core driver of how we deliver our strategy. You'll join a team modernising our platforms, strengthening cyber and operational resilience, and advancing a product led way of working that brings engineers, data specialists and business experts together to deliver meaningful outcomes at pace.We're scaling automation and AI from proof of concept into real, end to end change - improving customer journeys, reducing cost to serve, accelerating delivery, and building the digital foundations that underpin everything from energy trading and risk to field operations and critical infrastructure.If you want to work on complex, high impact problems using modern engineering practices, and help build reusable platforms that will shape how Centrica operates over the next decade, this is the place to do it. An opportunity to play your part. Centrica, Technology is a core driver of how we deliver our strategy. You'll join a team modernising our platforms, strengthening cyber and operational resilience, and advancing a product-led way of working that brings engineers, data specialists and business experts together to deliver meaningful outcomes at pace.We're scaling automation and AI from proof-of-concept into real, end-to-end change - improving customer journeys, reducing cost-to-serve, accelerating delivery, and building the digital foundations that underpin everything from energy trading and risk to field operations and critical infrastructure.If you want to work on complex, high-impact problems using modern engineering practices, and help build reusable platforms that will shape how Centrica operates over the next decade, this is the place to do it.As a Software Engineer within the Centrica Field Operations Platform, you will play an integral role on the team responsible for enhancing our ability to forecast and schedule colleague availability to effectively meet customer demand. This involves ensuring engineers with the appropriate skill sets are dispatched efficiently to customer locations. You will collaborate as a member of Field Platform Engineering squads, supporting the efficient building, testing, and deployment of software solutions Day to day: Design, build, test, and maintain high-quality software solutions across the Field Operations Platform Deliver well-structured, secure, and maintainable code that meets agreed functional and non-functional requirements, adhering to established engineering standards and best practices. Work as part of a cross-functional squad, collaborating closely with Product, QA, Architecture, and Operations to deliver customer and business outcomes. Participate in code reviews, design discussions, and technical refinement sessions, providing constructive input and learning from others. Own the quality of your work through automated testing, peer review, and proactive defect resolution. Support the operation of live services by contributing to incident investigation, root cause analysis, and ongoing platform improvements. Continuously improve your technical skills and understanding of the platform, tools, and domain, applying a growth mindset to both delivery and learning. Follow security, compliance, and data protection requirements, ensuring customer and business data is handled responsibly. Take ownership for delivering agreed work items to a high standard, raising risks and blockers early, and contributing positively to team delivery. Key Stakeholders: Software Engineering Managers, Principal Software Engineers, Product teams, Security teams, Infrastructure teams Problem Solving & Decision Making: Applies strong technical and product judgement to evaluate trade-offs and make decisions that optimise customer impact, performance, reliability, and development efficiency. Owns technical decisions relating to application development, while influencing architectural and strategic decisions across the broader product space. Uses data, analytics, insight, and automated testing outputs to inform decisions and prioritise improvements. Operates within established engineering, security, privacy, and governance frameworks, while helping to refine them to support faster, safer delivery. Makes timely decisions that balance innovation with risk, enabling the team to deliver value quickly without compromising quality. Applies judgement and engineering expertise to validate automated outputs, ensuring accuracy, safety, and ethical use. Focuses on principles such as robustness, privacy, maintainability, and customer trust, without tying the role to specific technologies that may change over time. What We Need From You: Demonstrated experience working as a software engineer within a cross-functional delivery team in a modern product or platform environment. Working knowledge of modern software engineering practices including source control, CI/CD pipelines, automated testing and code review. Experience writing secure, maintainable and well-tested code, with an understanding of non-functional requirements such as performance, resilience and scalability. Familiarity with cloud-native concepts such as event-driven architectures, asynchronous processing and managed services. Experience supporting live services, including participation in incident investigation, defect resolution and continuous improvement activities. Understanding of security, data protection and compliance principles relevant to customer platforms and enterprise systems. Ability to analyse problems, troubleshoot issues and contribute to technical solutions with appropriate guidance. Strong communication skills, with the ability to collaborate effectively with engineers, product managers, QE and other stakeholders.Hands on experience in: C# .NET Core SQL NOSQL Azure API Management Azure Functions Azure Data Factory Logic Apps Service bus queue Storage Account Application Insights Key Vault Event Grid Container Registry Batch account Core Competencies & Technical Skills (AI and emerging technology): Designs, integrates and operates AI-enabled solutions within enterprise environments, including prompt-driven workflows, retrieval-augmented systems and AI agents. Applies structured evaluation, testing and monitoring practices to ensure AI outputs are reliable, secure and compliant with organisational guardrails. Prepares and manages data used in AI workflows and takes responsibility for the responsible lifecycle of AI features from experimentation through deployment and continuous improvement. Why should you apply? We're not a perfect place - but we're a people place. Our priority is supporting all of the different realities our people face. Life is about so much more than work. We get it. That's why we've designed our total rewards to give you the flexibility to choose what you need, when you need it, making sure that you and your family are supported not only financially, but physically and emotionally too. Visit the link below to discover why we're a great place to work and what being part of more means for you. you're full of energy, fired up about sustainability, and ready to craft not only a better tomorrow, but a better you, then come and find your purpose in a team where your voice matters, your growth is non-negotiable, and your ambitions are our priority.Help us, help you. We would love for you to share any information about yourself throughout our recruitment process so that we can better understand you and help shape your journey.
19/07/2026
Full time
Full Stack Engineer - APIMApplylocations: Windsortime type: Full timeposted on: Posted 8 Days Agotime left to apply: End Date: May 25, 2026 (5 days left to apply)job requisition id: R Join us, be part of more. We're so much more than an energy company. We're a family of brands revolutionising how we power the planet. We're energisers. One team of 21,000 colleagues that's energising a greener, fairer future by creating an energy system that doesn't rely on fossil fuels, whilst living our powerful commitment to igniting positive change in our communities. Here, you can find more purpose, more passion, and more potential. That's why working here is . We do energy differently - we do it all. We make it, store it, move it, sell it, and mend it. Centrica, Technology is a core driver of how we deliver our strategy. You'll join a team modernising our platforms, strengthening cyber and operational resilience, and advancing a product led way of working that brings engineers, data specialists and business experts together to deliver meaningful outcomes at pace.We're scaling automation and AI from proof of concept into real, end to end change - improving customer journeys, reducing cost to serve, accelerating delivery, and building the digital foundations that underpin everything from energy trading and risk to field operations and critical infrastructure.If you want to work on complex, high impact problems using modern engineering practices, and help build reusable platforms that will shape how Centrica operates over the next decade, this is the place to do it. An opportunity to play your part. Centrica, Technology is a core driver of how we deliver our strategy. You'll join a team modernising our platforms, strengthening cyber and operational resilience, and advancing a product-led way of working that brings engineers, data specialists and business experts together to deliver meaningful outcomes at pace.We're scaling automation and AI from proof-of-concept into real, end-to-end change - improving customer journeys, reducing cost-to-serve, accelerating delivery, and building the digital foundations that underpin everything from energy trading and risk to field operations and critical infrastructure.If you want to work on complex, high-impact problems using modern engineering practices, and help build reusable platforms that will shape how Centrica operates over the next decade, this is the place to do it.As a Software Engineer within the Centrica Field Operations Platform, you will play an integral role on the team responsible for enhancing our ability to forecast and schedule colleague availability to effectively meet customer demand. This involves ensuring engineers with the appropriate skill sets are dispatched efficiently to customer locations. You will collaborate as a member of Field Platform Engineering squads, supporting the efficient building, testing, and deployment of software solutions Day to day: Design, build, test, and maintain high-quality software solutions across the Field Operations Platform Deliver well-structured, secure, and maintainable code that meets agreed functional and non-functional requirements, adhering to established engineering standards and best practices. Work as part of a cross-functional squad, collaborating closely with Product, QA, Architecture, and Operations to deliver customer and business outcomes. Participate in code reviews, design discussions, and technical refinement sessions, providing constructive input and learning from others. Own the quality of your work through automated testing, peer review, and proactive defect resolution. Support the operation of live services by contributing to incident investigation, root cause analysis, and ongoing platform improvements. Continuously improve your technical skills and understanding of the platform, tools, and domain, applying a growth mindset to both delivery and learning. Follow security, compliance, and data protection requirements, ensuring customer and business data is handled responsibly. Take ownership for delivering agreed work items to a high standard, raising risks and blockers early, and contributing positively to team delivery. Key Stakeholders: Software Engineering Managers, Principal Software Engineers, Product teams, Security teams, Infrastructure teams Problem Solving & Decision Making: Applies strong technical and product judgement to evaluate trade-offs and make decisions that optimise customer impact, performance, reliability, and development efficiency. Owns technical decisions relating to application development, while influencing architectural and strategic decisions across the broader product space. Uses data, analytics, insight, and automated testing outputs to inform decisions and prioritise improvements. Operates within established engineering, security, privacy, and governance frameworks, while helping to refine them to support faster, safer delivery. Makes timely decisions that balance innovation with risk, enabling the team to deliver value quickly without compromising quality. Applies judgement and engineering expertise to validate automated outputs, ensuring accuracy, safety, and ethical use. Focuses on principles such as robustness, privacy, maintainability, and customer trust, without tying the role to specific technologies that may change over time. What We Need From You: Demonstrated experience working as a software engineer within a cross-functional delivery team in a modern product or platform environment. Working knowledge of modern software engineering practices including source control, CI/CD pipelines, automated testing and code review. Experience writing secure, maintainable and well-tested code, with an understanding of non-functional requirements such as performance, resilience and scalability. Familiarity with cloud-native concepts such as event-driven architectures, asynchronous processing and managed services. Experience supporting live services, including participation in incident investigation, defect resolution and continuous improvement activities. Understanding of security, data protection and compliance principles relevant to customer platforms and enterprise systems. Ability to analyse problems, troubleshoot issues and contribute to technical solutions with appropriate guidance. Strong communication skills, with the ability to collaborate effectively with engineers, product managers, QE and other stakeholders.Hands on experience in: C# .NET Core SQL NOSQL Azure API Management Azure Functions Azure Data Factory Logic Apps Service bus queue Storage Account Application Insights Key Vault Event Grid Container Registry Batch account Core Competencies & Technical Skills (AI and emerging technology): Designs, integrates and operates AI-enabled solutions within enterprise environments, including prompt-driven workflows, retrieval-augmented systems and AI agents. Applies structured evaluation, testing and monitoring practices to ensure AI outputs are reliable, secure and compliant with organisational guardrails. Prepares and manages data used in AI workflows and takes responsibility for the responsible lifecycle of AI features from experimentation through deployment and continuous improvement. Why should you apply? We're not a perfect place - but we're a people place. Our priority is supporting all of the different realities our people face. Life is about so much more than work. We get it. That's why we've designed our total rewards to give you the flexibility to choose what you need, when you need it, making sure that you and your family are supported not only financially, but physically and emotionally too. Visit the link below to discover why we're a great place to work and what being part of more means for you. you're full of energy, fired up about sustainability, and ready to craft not only a better tomorrow, but a better you, then come and find your purpose in a team where your voice matters, your growth is non-negotiable, and your ambitions are our priority.Help us, help you. We would love for you to share any information about yourself throughout our recruitment process so that we can better understand you and help shape your journey.
MI5
International Technical Director Cyber Security Strategy
MI5 Manchester, Lancashire
Cheltenham, London, Manchester Job description About us GCHQ is an intelligence, cyber and security agency with a mission to keep the UK safe. We use cutting-edge technology, ingenuity and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners MI5 and MI6, we protect the UK from terrorism, cyber-attacks and espionage. At GCHQ you'll do varied and fascinating work in a supportive and inclusive environment that puts the emphasis on teamwork. The National Cyber Security Centre (NCSC), part of GCHQ, is the UK Government's lead authority on cyber security. The organisation is at the heart of the Government's cyber security strategy and has the aim of making the UK the safest place to live and work online. Job description We're currently looking for an International Technical Director to join our team within NCSC's Office of the Chief Technical Officer. In this role, you'll work alongside technical specialists who explore the core security attributes of the UK's critical systems and technologies. Together, we identify vulnerabilities and create resilient, long-term solutions that help protect the nation's digital infrastructure. What will the successful candidate be doing? You'll be at the centre of meaningful, technical work that drives real-world impact on an international stage. You'll work both independently and collaboratively, reporting to a senior colleague while offering expert advice on specific projects. You'll have responsibility for mentoring others, engaging with senior leaders and specialists, and providing strategic insight, especially when navigating complex challenges. You'll be expected to undertake frequent international travel, potentially leading to a full-time posting overseas in 12 months' time for approximately 2 years. The successful candidate will support the development of the Memorandum of Understandings (MoUs) with international partners. Person Specification The successful applicant will need to have: We're looking for someone (preferably with an existing security clearance) with: at least five years of practical experience in cyber security. significant experience working both with a government department and in international settings. ability to work confidently across a broad range of technical cyber security topics such as: Designing secure architectures for IT, Operational Technology, or AI systems. Analysing hardware and device-level security features. Research software vulnerabilities and secure development practices. Application of Cryptographic protocols or the security of networking and telecommunications technologies. deep technical expertise in one or more areas of cyber security. knowledge on how technological vulnerabilities occur, how they are discovered, and how they may be exploited experience of applying specialist technical security capabilities to help solve customer security problems GCHQ Competencies As part of the selection process, the NCSC will assess you using competencies aligned with those used across the UK Intelligence Community. These are closely based on the Civil Service Behaviours , so if you're familiar with those, you're already on the right track. At Level 4, we'll be looking at how you demonstrate the following: Seeing the Big Picture (Civil Service Behaviour Equivalent: Seeing the Big Picture) Communicating and Influencing (Civil Service Behaviour Equivalent: Communicating and Influencing) Working Collaboratively (Civil Service Behaviour Equivalent: Working Together) Providing Customer Value (Civil Service Behaviour Equivalent: Managing a Quality Service) Further information on Civil Service Behaviours Benefits and rewards At NCSC and GCHQ, we are proud of our inclusive and supportive working environment which is designed to encourage open minds and attitudes. As an organisation that values and nurtures talent, we are committed to helping you fulfil your potential. With comprehensive training and development opportunities, tailored to your needs and the requirements of your work, we will enable you to flourish in your role and perform to the very best of your abilities. You'll receive a starting salary of £71,889 (including a concessionary payment of £3,144). This role may attract a skills payment, for which you'll be evaluated for during the interview. The criteria for the skills assessment will be provided when you are invited to interview. If you are assessed to qualify for a skills payment, these payments start at £6,552 per annum. For roles based in London, you'll receive an additional £6,250 London Allowance. Other benefits include: 25 Days Annual Leave automatically rising to 30 days after 5 years' service, and an additional 10.5 days' public and privilege holidays Opportunities to be recognised through our employee performance scheme Interest-free season ticket loan Cycle to work scheme Facilities such as a gym, restaurant and on-site coffee bars (at some locations) Paid parental and adoption leave Excellent pension scheme - Civil Service pension Equal Opportunities At GCHQ diversity and inclusion are critical to our mission. To protect the UK, we need a truly diverse workforce that reflects the society we serve. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under-represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio-economic backgrounds. Find out more about our culture, working environment and diversity on our website . Disability Confident GCHQ is proud to have achieved Leader status within the DWP's Disability Confident scheme. This is aimed at encouraging employers to think differently about disability and take action to improve how they recruit, retain and develop disabled people. As a Disability Confident Leader we aim to ensure that a fair and proportionate number of disabled applicants who best meet the essential minimum criteria for this position, will be offered an interview, if it is practical for us to do so. (This is known as Offer of an Interview.) To secure an interview for this role, the minimum criteria, which will be assessed at the CV sift stage: You'll be required to reach the minimum pass mark for the online Situational Judgement Test (SJT), which assesses criteria important for all roles in our organisation. Demonstrate experience of applying specialist technical security capabilities to help solve customer security problems. Assessed at application sift. Demonstrate how technological vulnerabilities occur, how they are discovered, and how they may be exploited. Assessed at application sift. Demonstrate experience of leading a technical team. Assessed at CV sift. There is a wide range of extra support available throughout the recruitment process to enable you to do your best, see o ur website for information on reasonable adjustments we can offer . What to Expect Our recruitment process is fair, transparent, and based on merit. Here is a brief overview of each stage, in order:Initial online application.Online Situational Judgement Test (SJT) rating the appropriateness of your response to a series of short scenarios.Application sift.Online Interview.If successful, you'll receive a conditional offer of employment. Please note, you must successfully pass each stage of the process to progress to the next. Your application may take around 6 - 9 months to process including vetting, so we advise you to continue any current employment until you have received your final job offer. Before You Apply To work at NCSC, you need to be a British citizen or hold dual British nationality. You can read our full eligibility criteria here . This role requires the highest security clearance, known as Developed Vetting (DV). It's something everyone in the UK Intelligence Community undertakes. You can find out more about the vetting process here . Please note we have a strict drugs policy, so once you start your application, you can't take any recreational drugs and you'll need to declare your previous drug usage at the relevant stage. Before you apply, recommend setting up a separate email address for your contact with us, to ensure your personal and application correspondence remain separate. Try to avoid having identifying features in your email address, such as your first and/or surname and date of birth. This is good practice and will help you to manage your application with us more securely. The role is based either London, Cheltenham or Manchester, so you'll need to live within a commutable distance. Please consider any financial implications and practicalities before submitting an application, as we do not offer relocation costs. We offer reasonable reimbursement of travel costs for candidates attending in-person appointments during the recruitment and vetting process . click apply for full job details
19/07/2026
Full time
Cheltenham, London, Manchester Job description About us GCHQ is an intelligence, cyber and security agency with a mission to keep the UK safe. We use cutting-edge technology, ingenuity and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners MI5 and MI6, we protect the UK from terrorism, cyber-attacks and espionage. At GCHQ you'll do varied and fascinating work in a supportive and inclusive environment that puts the emphasis on teamwork. The National Cyber Security Centre (NCSC), part of GCHQ, is the UK Government's lead authority on cyber security. The organisation is at the heart of the Government's cyber security strategy and has the aim of making the UK the safest place to live and work online. Job description We're currently looking for an International Technical Director to join our team within NCSC's Office of the Chief Technical Officer. In this role, you'll work alongside technical specialists who explore the core security attributes of the UK's critical systems and technologies. Together, we identify vulnerabilities and create resilient, long-term solutions that help protect the nation's digital infrastructure. What will the successful candidate be doing? You'll be at the centre of meaningful, technical work that drives real-world impact on an international stage. You'll work both independently and collaboratively, reporting to a senior colleague while offering expert advice on specific projects. You'll have responsibility for mentoring others, engaging with senior leaders and specialists, and providing strategic insight, especially when navigating complex challenges. You'll be expected to undertake frequent international travel, potentially leading to a full-time posting overseas in 12 months' time for approximately 2 years. The successful candidate will support the development of the Memorandum of Understandings (MoUs) with international partners. Person Specification The successful applicant will need to have: We're looking for someone (preferably with an existing security clearance) with: at least five years of practical experience in cyber security. significant experience working both with a government department and in international settings. ability to work confidently across a broad range of technical cyber security topics such as: Designing secure architectures for IT, Operational Technology, or AI systems. Analysing hardware and device-level security features. Research software vulnerabilities and secure development practices. Application of Cryptographic protocols or the security of networking and telecommunications technologies. deep technical expertise in one or more areas of cyber security. knowledge on how technological vulnerabilities occur, how they are discovered, and how they may be exploited experience of applying specialist technical security capabilities to help solve customer security problems GCHQ Competencies As part of the selection process, the NCSC will assess you using competencies aligned with those used across the UK Intelligence Community. These are closely based on the Civil Service Behaviours , so if you're familiar with those, you're already on the right track. At Level 4, we'll be looking at how you demonstrate the following: Seeing the Big Picture (Civil Service Behaviour Equivalent: Seeing the Big Picture) Communicating and Influencing (Civil Service Behaviour Equivalent: Communicating and Influencing) Working Collaboratively (Civil Service Behaviour Equivalent: Working Together) Providing Customer Value (Civil Service Behaviour Equivalent: Managing a Quality Service) Further information on Civil Service Behaviours Benefits and rewards At NCSC and GCHQ, we are proud of our inclusive and supportive working environment which is designed to encourage open minds and attitudes. As an organisation that values and nurtures talent, we are committed to helping you fulfil your potential. With comprehensive training and development opportunities, tailored to your needs and the requirements of your work, we will enable you to flourish in your role and perform to the very best of your abilities. You'll receive a starting salary of £71,889 (including a concessionary payment of £3,144). This role may attract a skills payment, for which you'll be evaluated for during the interview. The criteria for the skills assessment will be provided when you are invited to interview. If you are assessed to qualify for a skills payment, these payments start at £6,552 per annum. For roles based in London, you'll receive an additional £6,250 London Allowance. Other benefits include: 25 Days Annual Leave automatically rising to 30 days after 5 years' service, and an additional 10.5 days' public and privilege holidays Opportunities to be recognised through our employee performance scheme Interest-free season ticket loan Cycle to work scheme Facilities such as a gym, restaurant and on-site coffee bars (at some locations) Paid parental and adoption leave Excellent pension scheme - Civil Service pension Equal Opportunities At GCHQ diversity and inclusion are critical to our mission. To protect the UK, we need a truly diverse workforce that reflects the society we serve. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under-represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio-economic backgrounds. Find out more about our culture, working environment and diversity on our website . Disability Confident GCHQ is proud to have achieved Leader status within the DWP's Disability Confident scheme. This is aimed at encouraging employers to think differently about disability and take action to improve how they recruit, retain and develop disabled people. As a Disability Confident Leader we aim to ensure that a fair and proportionate number of disabled applicants who best meet the essential minimum criteria for this position, will be offered an interview, if it is practical for us to do so. (This is known as Offer of an Interview.) To secure an interview for this role, the minimum criteria, which will be assessed at the CV sift stage: You'll be required to reach the minimum pass mark for the online Situational Judgement Test (SJT), which assesses criteria important for all roles in our organisation. Demonstrate experience of applying specialist technical security capabilities to help solve customer security problems. Assessed at application sift. Demonstrate how technological vulnerabilities occur, how they are discovered, and how they may be exploited. Assessed at application sift. Demonstrate experience of leading a technical team. Assessed at CV sift. There is a wide range of extra support available throughout the recruitment process to enable you to do your best, see o ur website for information on reasonable adjustments we can offer . What to Expect Our recruitment process is fair, transparent, and based on merit. Here is a brief overview of each stage, in order:Initial online application.Online Situational Judgement Test (SJT) rating the appropriateness of your response to a series of short scenarios.Application sift.Online Interview.If successful, you'll receive a conditional offer of employment. Please note, you must successfully pass each stage of the process to progress to the next. Your application may take around 6 - 9 months to process including vetting, so we advise you to continue any current employment until you have received your final job offer. Before You Apply To work at NCSC, you need to be a British citizen or hold dual British nationality. You can read our full eligibility criteria here . This role requires the highest security clearance, known as Developed Vetting (DV). It's something everyone in the UK Intelligence Community undertakes. You can find out more about the vetting process here . Please note we have a strict drugs policy, so once you start your application, you can't take any recreational drugs and you'll need to declare your previous drug usage at the relevant stage. Before you apply, recommend setting up a separate email address for your contact with us, to ensure your personal and application correspondence remain separate. Try to avoid having identifying features in your email address, such as your first and/or surname and date of birth. This is good practice and will help you to manage your application with us more securely. The role is based either London, Cheltenham or Manchester, so you'll need to live within a commutable distance. Please consider any financial implications and practicalities before submitting an application, as we do not offer relocation costs. We offer reasonable reimbursement of travel costs for candidates attending in-person appointments during the recruitment and vetting process . click apply for full job details
Tech Audit Specialist: IT Risks & Controls
Quilter plc
Quilter plc is a leading provider of financial advice, investments and wealth management, committed to being the UK's best wealth manager for clients and their advisers. The role focuses on IT and business audits across the Internal Audit Plan, including cyber security, third-party risk, data privacy and operational resilience, with location in London/Southampton. Deliver audits end-to-end, engage stakeholders, perform risk-based testing, and produce actionable findings.
19/07/2026
Full time
Quilter plc is a leading provider of financial advice, investments and wealth management, committed to being the UK's best wealth manager for clients and their advisers. The role focuses on IT and business audits across the Internal Audit Plan, including cyber security, third-party risk, data privacy and operational resilience, with location in London/Southampton. Deliver audits end-to-end, engage stakeholders, perform risk-based testing, and produce actionable findings.
Identity & Access Manager
Automobile Association Basingstoke, Hampshire
Location: Basingstoke (hybrid working 3 office days per week) Employment Type: Permanent, full time Additional Benefits: Annual Bonus, Cash-Car Allowance & Private Medical Insurance Think the AA is just about roadside assistance? Think again. For over a century, we've been evolving and adapting. Today, as the nation's leading motoring organisation, we offer a wide range of products and services to millions of customers. From roadside assistance to home and motor insurance, and the latest driving technologies, we have it all. As we continue to expand, diversify, and modernise, joining us as an Identity & Access Manager means you'll play a crucial role in our success and be part of this exciting motoring journey. Our Chief Operating Office (COO) are the backbone of The AA, providing both stability and structure to support growth and innovation. We are the drivers of change. This is the job Lead the transformation of identity security at one of the UK's most trusted brands Identity is central to secure digital transformation, and at The AA we are investing in the future of our Identity and Access Management capability. We are looking for an Identity & Access Manager to help shape that journey. This is a strategic opportunity to lead the evolution of our enterprise IAM capability, driving governance, technical direction and measurable security outcomes across a complex technology landscape. Working closely with senior technology and business leaders, you will help ensure our identity services remain secure, scalable and aligned to the needs of a modern organisation. Whether you are already leading an IAM function or are an experienced senior specialist ready to step into your first people leadership role, this is a chance to make a genuine impact on a growing cyber security team. You will help shape enterprise technology decisions and influence how identity security evolves across one of the UK's most recognised brands. What will I be doing? Lead the ongoing transformation and maturity of The AA's Identity & Access Management capability, defining strategy, governance, standards and technical direction. Shape and deliver the IAM roadmap, ensuring identity services support business priorities, regulatory expectations and evolving cyber security risks. Act as the senior authority for identity security, influencing executive stakeholders, technology leaders, architects, suppliers and delivery teams to drive secure outcomes. Lead the development of modern identity capabilities across areas including privileged access, identity governance, Zero Trust, non-human identities and cloud-based authentication. Establish effective governance, assurance and reporting that demonstrates control effectiveness while driving continual improvement across the IAM estate. Lead and develop a growing IAM capability, coaching technical specialists and creating an environment where expertise and innovation can thrive. What do I need? Strong experience within cyber security, with significant expertise in Identity & Access Management gained within a complex enterprise environment. A proven track record of leading or driving IAM transformation, delivering improvements to capability, governance or operating models rather than simply supporting an already mature environment. Excellent executive stakeholder management skills, with the ability to influence senior business and technology leaders, balancing security requirements with commercial and operational priorities. Strong knowledge of modern IAM technologies and principles, including Microsoft Entra ID, identity governance, privileged access, Zero Trust and cloud identity services. Good understanding of non-human identity, including service accounts, workload identities, machine identities or related governance, with an appreciation of its growing importance within modern security architectures. Experience leading, mentoring or coaching technical professionals, or the ambition and capability to step into your first formal people leadership role. Additional information We're always looking to recognise and reward our employees for the work they do. As a valued member of The AA team, you'll have access to a range of benefits including: 25 days annual leave plus bank holidays + holiday buying scheme Worksave pension scheme with up to 7% employer contribution Free AA breakdown membership from Day 1 plus 50% discount for family and friends Discounts on AA products including car and home insurance Employee discount scheme that gives you access to a car salary sacrifice scheme plus great discounts on healthcare, shopping, holidays and more Company funded life assurance Diverse learning and development opportunities to support you to progress in your career Dedicated Employee Assistance Programme and a 24/7 remote GP service for you and your family Plus, so much more! We're an equal opportunities employer and welcome applications from everyone. The AA values diversity and the difference this brings to our culture and our customers. We actively seek people from diverse backgrounds to join us and become part of an inclusive company where you can be yourself, be empowered to be your best and feel like you truly belong. We have five communities to bring together people with shared characteristics and backgrounds and drive positive change.
19/07/2026
Full time
Location: Basingstoke (hybrid working 3 office days per week) Employment Type: Permanent, full time Additional Benefits: Annual Bonus, Cash-Car Allowance & Private Medical Insurance Think the AA is just about roadside assistance? Think again. For over a century, we've been evolving and adapting. Today, as the nation's leading motoring organisation, we offer a wide range of products and services to millions of customers. From roadside assistance to home and motor insurance, and the latest driving technologies, we have it all. As we continue to expand, diversify, and modernise, joining us as an Identity & Access Manager means you'll play a crucial role in our success and be part of this exciting motoring journey. Our Chief Operating Office (COO) are the backbone of The AA, providing both stability and structure to support growth and innovation. We are the drivers of change. This is the job Lead the transformation of identity security at one of the UK's most trusted brands Identity is central to secure digital transformation, and at The AA we are investing in the future of our Identity and Access Management capability. We are looking for an Identity & Access Manager to help shape that journey. This is a strategic opportunity to lead the evolution of our enterprise IAM capability, driving governance, technical direction and measurable security outcomes across a complex technology landscape. Working closely with senior technology and business leaders, you will help ensure our identity services remain secure, scalable and aligned to the needs of a modern organisation. Whether you are already leading an IAM function or are an experienced senior specialist ready to step into your first people leadership role, this is a chance to make a genuine impact on a growing cyber security team. You will help shape enterprise technology decisions and influence how identity security evolves across one of the UK's most recognised brands. What will I be doing? Lead the ongoing transformation and maturity of The AA's Identity & Access Management capability, defining strategy, governance, standards and technical direction. Shape and deliver the IAM roadmap, ensuring identity services support business priorities, regulatory expectations and evolving cyber security risks. Act as the senior authority for identity security, influencing executive stakeholders, technology leaders, architects, suppliers and delivery teams to drive secure outcomes. Lead the development of modern identity capabilities across areas including privileged access, identity governance, Zero Trust, non-human identities and cloud-based authentication. Establish effective governance, assurance and reporting that demonstrates control effectiveness while driving continual improvement across the IAM estate. Lead and develop a growing IAM capability, coaching technical specialists and creating an environment where expertise and innovation can thrive. What do I need? Strong experience within cyber security, with significant expertise in Identity & Access Management gained within a complex enterprise environment. A proven track record of leading or driving IAM transformation, delivering improvements to capability, governance or operating models rather than simply supporting an already mature environment. Excellent executive stakeholder management skills, with the ability to influence senior business and technology leaders, balancing security requirements with commercial and operational priorities. Strong knowledge of modern IAM technologies and principles, including Microsoft Entra ID, identity governance, privileged access, Zero Trust and cloud identity services. Good understanding of non-human identity, including service accounts, workload identities, machine identities or related governance, with an appreciation of its growing importance within modern security architectures. Experience leading, mentoring or coaching technical professionals, or the ambition and capability to step into your first formal people leadership role. Additional information We're always looking to recognise and reward our employees for the work they do. As a valued member of The AA team, you'll have access to a range of benefits including: 25 days annual leave plus bank holidays + holiday buying scheme Worksave pension scheme with up to 7% employer contribution Free AA breakdown membership from Day 1 plus 50% discount for family and friends Discounts on AA products including car and home insurance Employee discount scheme that gives you access to a car salary sacrifice scheme plus great discounts on healthcare, shopping, holidays and more Company funded life assurance Diverse learning and development opportunities to support you to progress in your career Dedicated Employee Assistance Programme and a 24/7 remote GP service for you and your family Plus, so much more! We're an equal opportunities employer and welcome applications from everyone. The AA values diversity and the difference this brings to our culture and our customers. We actively seek people from diverse backgrounds to join us and become part of an inclusive company where you can be yourself, be empowered to be your best and feel like you truly belong. We have five communities to bring together people with shared characteristics and backgrounds and drive positive change.
Head of LFPSE (Delivery and Innovation)
NHS
The National Patient Safety Team is seeking an experienced and strategic leader to lead the delivery, development and continuous improvement of the Learn from Patient Safety Events (LFPSE) service - England's national patient safety reporting and learning system. Reporting to the Deputy Director of Patient Safety (Digital), you will lead the service responsible for the collection, quality assurance and stewardship of patient safety event data from across NHS funded care. You will drive innovation in how patient safety data is used to support learning, improvement and risk reduction, ensuring the service continues to meet the needs of patients, providers, policymakers and the wider health and care system. Main duties of the job Working collaboratively with national and local stakeholders, suppliers, analysts, clinicians and digital teams, you will oversee service delivery, data quality, user engagement, system development and strategic improvement. You will play a key role in shaping the future use of patient safety data and ensuring that insights generated through LFPSE support the delivery of safer care for patients across England. Key responsibilities Leading the delivery and strategic development of the national LFPSE service. Driving innovation in patient safety reporting, learning and data use across the NHS. Ensuring high standards of data quality, governance, access and information management. Building strong relationships with NHS organisations, system suppliers, policymakers and patient safety partners. Leading and developing a multidisciplinary team to deliver high quality services and continuous improvement. Supporting the development of national patient safety policy, reporting systems and learning initiatives. Overseeing service performance, budgets, business planning, risks and stakeholder engagement. Ensuring patient safety data is translated into actionable insight that supports safer care and improved outcomes for patients. About us NHS England has a wide range of statutory functions, responsibilities and regulatory powers. These are focused on supporting the wider NHS to deliver high quality care, as well as doing those things that are best done once for the whole NHS. Our staff bring expertise across clinical, operational, commissioning, technology, data science, cyber security, software engineering, education, and commercial specialisms - enabling us to design and deliver high quality NHS services. In March 2025, the Government announced that NHS England and the Department of Health and Social Care will increasingly merge functions, ultimately leading to NHS England being fully integrated into the department. Secondments Applicants from within the NHS will be offered on a secondment basis only. Agreement should be obtained from their employer prior to submitting the application. Person Specification Qualifications Educated to masters level or equivalent level of experience of working at a senior level in a specialist area. Knowledge and experience Experience of working with large datasets and analysing, interpreting, presenting and publishing potentially controversial statistics/information. Experience of designing, developing and maintaining major information systems; knowledge of patient safety reporting systems (nationally and internationally). Experience of statistical techniques and their application including relevant software (SAS or similar). Skills, capabilities and attributes Provide and receive highly complex, sensitive and contentious information, negotiate with senior stakeholders on difficult and controversial issues, and present complex and sensitive information to large and influential groups. Persuade board and senior managers of the respective merits of different options, innovation and new market opportunities. Problem solving skills and ability to respond to sudden unexpected demands. Values and Behaviours Consistently thinks about how their work can help and support clinicians and frontline staff deliver better outcomes for patients. Values diversity and difference, operates with integrity and openness. Salary and employment details Salary: £79,504 to £91,609 per annum (exclusive of London weighting). Contract: Fixed term, 7 months. Working pattern: Full time, Part time, Job share, Flexible working. We cannot offer visa sponsorship for any vacancies.
19/07/2026
Full time
The National Patient Safety Team is seeking an experienced and strategic leader to lead the delivery, development and continuous improvement of the Learn from Patient Safety Events (LFPSE) service - England's national patient safety reporting and learning system. Reporting to the Deputy Director of Patient Safety (Digital), you will lead the service responsible for the collection, quality assurance and stewardship of patient safety event data from across NHS funded care. You will drive innovation in how patient safety data is used to support learning, improvement and risk reduction, ensuring the service continues to meet the needs of patients, providers, policymakers and the wider health and care system. Main duties of the job Working collaboratively with national and local stakeholders, suppliers, analysts, clinicians and digital teams, you will oversee service delivery, data quality, user engagement, system development and strategic improvement. You will play a key role in shaping the future use of patient safety data and ensuring that insights generated through LFPSE support the delivery of safer care for patients across England. Key responsibilities Leading the delivery and strategic development of the national LFPSE service. Driving innovation in patient safety reporting, learning and data use across the NHS. Ensuring high standards of data quality, governance, access and information management. Building strong relationships with NHS organisations, system suppliers, policymakers and patient safety partners. Leading and developing a multidisciplinary team to deliver high quality services and continuous improvement. Supporting the development of national patient safety policy, reporting systems and learning initiatives. Overseeing service performance, budgets, business planning, risks and stakeholder engagement. Ensuring patient safety data is translated into actionable insight that supports safer care and improved outcomes for patients. About us NHS England has a wide range of statutory functions, responsibilities and regulatory powers. These are focused on supporting the wider NHS to deliver high quality care, as well as doing those things that are best done once for the whole NHS. Our staff bring expertise across clinical, operational, commissioning, technology, data science, cyber security, software engineering, education, and commercial specialisms - enabling us to design and deliver high quality NHS services. In March 2025, the Government announced that NHS England and the Department of Health and Social Care will increasingly merge functions, ultimately leading to NHS England being fully integrated into the department. Secondments Applicants from within the NHS will be offered on a secondment basis only. Agreement should be obtained from their employer prior to submitting the application. Person Specification Qualifications Educated to masters level or equivalent level of experience of working at a senior level in a specialist area. Knowledge and experience Experience of working with large datasets and analysing, interpreting, presenting and publishing potentially controversial statistics/information. Experience of designing, developing and maintaining major information systems; knowledge of patient safety reporting systems (nationally and internationally). Experience of statistical techniques and their application including relevant software (SAS or similar). Skills, capabilities and attributes Provide and receive highly complex, sensitive and contentious information, negotiate with senior stakeholders on difficult and controversial issues, and present complex and sensitive information to large and influential groups. Persuade board and senior managers of the respective merits of different options, innovation and new market opportunities. Problem solving skills and ability to respond to sudden unexpected demands. Values and Behaviours Consistently thinks about how their work can help and support clinicians and frontline staff deliver better outcomes for patients. Values diversity and difference, operates with integrity and openness. Salary and employment details Salary: £79,504 to £91,609 per annum (exclusive of London weighting). Contract: Fixed term, 7 months. Working pattern: Full time, Part time, Job share, Flexible working. We cannot offer visa sponsorship for any vacancies.
Identity & Access Specialist
Automobile Association
Location: London (hybrid working 3 office days per week) Employment Type: Permanent, full time Think the AA is just about roadside assistance? Think again. For over a century, we've been evolving and adapting. Today, as the nation's leading motoring organisation, we offer a wide range of products and services to millions of customers. From roadside assistance to home and motor insurance, and the latest driving technologies, we have it all. As we continue to expand, diversify, and modernise, joining us as an Identity & Access Specialist means you'll play a crucial role in our success and be part of this exciting motoring journey. Our Chief Operating Office (COO) are the backbone of The AA, providing both stability and structure to support growth and innovation. We are the drivers of change. This is the job Help shape the future of identity security at one of the UK's most trusted brands Identity is central to cyber security, and at The AA you will play a key role in protecting the technology that underpins how colleagues, partners and systems securely connect and operate. As our Identity & Access Specialist, you will be a trusted technical expert within Group Security, working closely with the Identity & Access Manager and senior colleagues across Cyber Security, Technology and Architecture. You will bring deep IAM expertise to strengthen secure solutions, improve governance and reduce risk across a complex enterprise environment. This is an outstanding opportunity for an experienced IAM professional who wants to stay close to the technical detail while influencing meaningful security outcomes, driving improvement and making a visible impact on the future of identity security at The AA. What will I be doing? Act as a trusted subject matter expert across Identity & Access Management, supporting the design, enhancement and assurance of secure identity and privileged access controls. Provide technical guidance across Microsoft Entra ID, Conditional Access, MFA, identity governance, SSO, federation and privileged access, helping teams deliver secure and scalable solutions. Partner with Technology, Architecture, Platform, Risk and Compliance teams to review solutions, provide pragmatic security advice and support the successful delivery of change. Contribute to the development of IAM standards, technical guidance, governance documentation and audit evidence, helping strengthen the organisation's overall security posture. Support identity related risk assessments, investigations and remediation activities, providing practical recommendations that balance security, operational effectiveness and user experience. Identify opportunities to improve IAM processes, controls and ways of working, contributing to the continued maturity of the organisation's identity capability. What do I need? Strong technical experience within Identity & Access Management, Identity Governance, Privileged Access Management or a closely related cyber security discipline within a complex enterprise environment. Demonstrable expertise with Microsoft identity technologies, including Microsoft Entra ID and modern IAM capabilities such as Conditional Access, MFA, federation, SSO and privileged access management. Experience supporting governance, risk and compliance activities, including developing standards, producing assurance evidence and helping organisations strengthen security controls. Experience within GRC would be particularly valuable. Confident stakeholder management skills, with the ability to build trusted relationships and influence technical teams, managers and Heads of Function through clear, pragmatic advice. Strong analytical and problem-solving capability, with the confidence to assess technical challenges, understand business risk and recommend balanced, practical solutions. Relevant industry certifications such as Microsoft SC 300, SC 100, CISSP, CCSP, CIAM or equivalent practical experience would be advantageous, although we value demonstrable capability just as highly. Additional information We're always looking to recognise and reward our employees for the work they do. As a valued member of The AA team, you'll have access to a range of benefits including: 25 days annual leave plus bank holidays + holiday buying scheme Worksave pension scheme with up to 7% employer contribution Free AA breakdown membership from Day 1 plus 50% discount for family and friends Discounts on AA products including car and home insurance Employee discount scheme that gives you access to a car salary sacrifice scheme plus great discounts on healthcare, shopping, holidays and more Company funded life assurance Diverse learning and development opportunities to support you to progress in your career Dedicated Employee Assistance Programme and a 24/7 remote GP service for you and your family Plus, so much more! We're an equal opportunities employer and welcome applications from everyone. The AA values diversity and the difference this brings to our culture and our customers. We actively seek people from diverse backgrounds to join us and become part of an inclusive company where you can be yourself, be empowered to be your best and feel like you truly belong. We have five communities to bring together people with shared characteristics and backgrounds and drive positive change.
19/07/2026
Full time
Location: London (hybrid working 3 office days per week) Employment Type: Permanent, full time Think the AA is just about roadside assistance? Think again. For over a century, we've been evolving and adapting. Today, as the nation's leading motoring organisation, we offer a wide range of products and services to millions of customers. From roadside assistance to home and motor insurance, and the latest driving technologies, we have it all. As we continue to expand, diversify, and modernise, joining us as an Identity & Access Specialist means you'll play a crucial role in our success and be part of this exciting motoring journey. Our Chief Operating Office (COO) are the backbone of The AA, providing both stability and structure to support growth and innovation. We are the drivers of change. This is the job Help shape the future of identity security at one of the UK's most trusted brands Identity is central to cyber security, and at The AA you will play a key role in protecting the technology that underpins how colleagues, partners and systems securely connect and operate. As our Identity & Access Specialist, you will be a trusted technical expert within Group Security, working closely with the Identity & Access Manager and senior colleagues across Cyber Security, Technology and Architecture. You will bring deep IAM expertise to strengthen secure solutions, improve governance and reduce risk across a complex enterprise environment. This is an outstanding opportunity for an experienced IAM professional who wants to stay close to the technical detail while influencing meaningful security outcomes, driving improvement and making a visible impact on the future of identity security at The AA. What will I be doing? Act as a trusted subject matter expert across Identity & Access Management, supporting the design, enhancement and assurance of secure identity and privileged access controls. Provide technical guidance across Microsoft Entra ID, Conditional Access, MFA, identity governance, SSO, federation and privileged access, helping teams deliver secure and scalable solutions. Partner with Technology, Architecture, Platform, Risk and Compliance teams to review solutions, provide pragmatic security advice and support the successful delivery of change. Contribute to the development of IAM standards, technical guidance, governance documentation and audit evidence, helping strengthen the organisation's overall security posture. Support identity related risk assessments, investigations and remediation activities, providing practical recommendations that balance security, operational effectiveness and user experience. Identify opportunities to improve IAM processes, controls and ways of working, contributing to the continued maturity of the organisation's identity capability. What do I need? Strong technical experience within Identity & Access Management, Identity Governance, Privileged Access Management or a closely related cyber security discipline within a complex enterprise environment. Demonstrable expertise with Microsoft identity technologies, including Microsoft Entra ID and modern IAM capabilities such as Conditional Access, MFA, federation, SSO and privileged access management. Experience supporting governance, risk and compliance activities, including developing standards, producing assurance evidence and helping organisations strengthen security controls. Experience within GRC would be particularly valuable. Confident stakeholder management skills, with the ability to build trusted relationships and influence technical teams, managers and Heads of Function through clear, pragmatic advice. Strong analytical and problem-solving capability, with the confidence to assess technical challenges, understand business risk and recommend balanced, practical solutions. Relevant industry certifications such as Microsoft SC 300, SC 100, CISSP, CCSP, CIAM or equivalent practical experience would be advantageous, although we value demonstrable capability just as highly. Additional information We're always looking to recognise and reward our employees for the work they do. As a valued member of The AA team, you'll have access to a range of benefits including: 25 days annual leave plus bank holidays + holiday buying scheme Worksave pension scheme with up to 7% employer contribution Free AA breakdown membership from Day 1 plus 50% discount for family and friends Discounts on AA products including car and home insurance Employee discount scheme that gives you access to a car salary sacrifice scheme plus great discounts on healthcare, shopping, holidays and more Company funded life assurance Diverse learning and development opportunities to support you to progress in your career Dedicated Employee Assistance Programme and a 24/7 remote GP service for you and your family Plus, so much more! We're an equal opportunities employer and welcome applications from everyone. The AA values diversity and the difference this brings to our culture and our customers. We actively seek people from diverse backgrounds to join us and become part of an inclusive company where you can be yourself, be empowered to be your best and feel like you truly belong. We have five communities to bring together people with shared characteristics and backgrounds and drive positive change.
Identity & Access Manager
Automobile Association
Location: London (hybrid working 3 office days per week) Employment Type: Permanent, full time Additional Benefits: Annual Bonus, Cash-Car Allowance & Private Medical Insurance Think the AA is just about roadside assistance? Think again. For over a century, we've been evolving and adapting. Today, as the nation's leading motoring organisation, we offer a wide range of products and services to millions of customers. From roadside assistance to home and motor insurance, and the latest driving technologies, we have it all. As we continue to expand, diversify, and modernise, joining us as an Identity & Access Manager means you'll play a crucial role in our success and be part of this exciting motoring journey. Our Chief Operating Office (COO) are the backbone of The AA, providing both stability and structure to support growth and innovation. We are the drivers of change. This is the job Lead the transformation of identity security at one of the UK's most trusted brands Identity is central to secure digital transformation, and at The AA we are investing in the future of our Identity and Access Management capability. We are looking for an Identity & Access Manager to help shape that journey. This is a strategic opportunity to lead the evolution of our enterprise IAM capability, driving governance, technical direction and measurable security outcomes across a complex technology landscape. Working closely with senior technology and business leaders, you will help ensure our identity services remain secure, scalable and aligned to the needs of a modern organisation. Whether you are already leading an IAM function or are an experienced senior specialist ready to step into your first people leadership role, this is a chance to make a genuine impact on a growing cyber security team. You will help shape enterprise technology decisions and influence how identity security evolves across one of the UK's most recognised brands. What will I be doing? Lead the ongoing transformation and maturity of The AA's Identity & Access Management capability, defining strategy, governance, standards and technical direction. Shape and deliver the IAM roadmap, ensuring identity services support business priorities, regulatory expectations and evolving cyber security risks. Act as the senior authority for identity security, influencing executive stakeholders, technology leaders, architects, suppliers and delivery teams to drive secure outcomes. Lead the development of modern identity capabilities across areas including privileged access, identity governance, Zero Trust, non-human identities and cloud-based authentication. Establish effective governance, assurance and reporting that demonstrates control effectiveness while driving continual improvement across the IAM estate. Lead and develop a growing IAM capability, coaching technical specialists and creating an environment where expertise and innovation can thrive. What do I need? Strong experience within cyber security, with significant expertise in Identity & Access Management gained within a complex enterprise environment. A proven track record of leading or driving IAM transformation, delivering improvements to capability, governance or operating models rather than simply supporting an already mature environment. Excellent executive stakeholder management skills, with the ability to influence senior business and technology leaders, balancing security requirements with commercial and operational priorities. Strong knowledge of modern IAM technologies and principles, including Microsoft Entra ID, identity governance, privileged access, Zero Trust and cloud identity services. Good understanding of non-human identity, including service accounts, workload identities, machine identities or related governance, with an appreciation of its growing importance within modern security architectures. Experience leading, mentoring or coaching technical professionals, or the ambition and capability to step into your first formal people leadership role. Additional information We're always looking to recognise and reward our employees for the work they do. As a valued member of The AA team, you'll have access to a range of benefits including: 25 days annual leave plus bank holidays + holiday buying scheme Worksave pension scheme with up to 7% employer contribution Free AA breakdown membership from Day 1 plus 50% discount for family and friends Discounts on AA products including car and home insurance Employee discount scheme that gives you access to a car salary sacrifice scheme plus great discounts on healthcare, shopping, holidays and more Company funded life assurance Diverse learning and development opportunities to support you to progress in your career Dedicated Employee Assistance Programme and a 24/7 remote GP service for you and your family Plus, so much more! We're an equal opportunities employer and welcome applications from everyone. The AA values diversity and the difference this brings to our culture and our customers. We actively seek people from diverse backgrounds to join us and become part of an inclusive company where you can be yourself, be empowered to be your best and feel like you truly belong. We have five communities to bring together people with shared characteristics and backgrounds and drive positive change.
19/07/2026
Full time
Location: London (hybrid working 3 office days per week) Employment Type: Permanent, full time Additional Benefits: Annual Bonus, Cash-Car Allowance & Private Medical Insurance Think the AA is just about roadside assistance? Think again. For over a century, we've been evolving and adapting. Today, as the nation's leading motoring organisation, we offer a wide range of products and services to millions of customers. From roadside assistance to home and motor insurance, and the latest driving technologies, we have it all. As we continue to expand, diversify, and modernise, joining us as an Identity & Access Manager means you'll play a crucial role in our success and be part of this exciting motoring journey. Our Chief Operating Office (COO) are the backbone of The AA, providing both stability and structure to support growth and innovation. We are the drivers of change. This is the job Lead the transformation of identity security at one of the UK's most trusted brands Identity is central to secure digital transformation, and at The AA we are investing in the future of our Identity and Access Management capability. We are looking for an Identity & Access Manager to help shape that journey. This is a strategic opportunity to lead the evolution of our enterprise IAM capability, driving governance, technical direction and measurable security outcomes across a complex technology landscape. Working closely with senior technology and business leaders, you will help ensure our identity services remain secure, scalable and aligned to the needs of a modern organisation. Whether you are already leading an IAM function or are an experienced senior specialist ready to step into your first people leadership role, this is a chance to make a genuine impact on a growing cyber security team. You will help shape enterprise technology decisions and influence how identity security evolves across one of the UK's most recognised brands. What will I be doing? Lead the ongoing transformation and maturity of The AA's Identity & Access Management capability, defining strategy, governance, standards and technical direction. Shape and deliver the IAM roadmap, ensuring identity services support business priorities, regulatory expectations and evolving cyber security risks. Act as the senior authority for identity security, influencing executive stakeholders, technology leaders, architects, suppliers and delivery teams to drive secure outcomes. Lead the development of modern identity capabilities across areas including privileged access, identity governance, Zero Trust, non-human identities and cloud-based authentication. Establish effective governance, assurance and reporting that demonstrates control effectiveness while driving continual improvement across the IAM estate. Lead and develop a growing IAM capability, coaching technical specialists and creating an environment where expertise and innovation can thrive. What do I need? Strong experience within cyber security, with significant expertise in Identity & Access Management gained within a complex enterprise environment. A proven track record of leading or driving IAM transformation, delivering improvements to capability, governance or operating models rather than simply supporting an already mature environment. Excellent executive stakeholder management skills, with the ability to influence senior business and technology leaders, balancing security requirements with commercial and operational priorities. Strong knowledge of modern IAM technologies and principles, including Microsoft Entra ID, identity governance, privileged access, Zero Trust and cloud identity services. Good understanding of non-human identity, including service accounts, workload identities, machine identities or related governance, with an appreciation of its growing importance within modern security architectures. Experience leading, mentoring or coaching technical professionals, or the ambition and capability to step into your first formal people leadership role. Additional information We're always looking to recognise and reward our employees for the work they do. As a valued member of The AA team, you'll have access to a range of benefits including: 25 days annual leave plus bank holidays + holiday buying scheme Worksave pension scheme with up to 7% employer contribution Free AA breakdown membership from Day 1 plus 50% discount for family and friends Discounts on AA products including car and home insurance Employee discount scheme that gives you access to a car salary sacrifice scheme plus great discounts on healthcare, shopping, holidays and more Company funded life assurance Diverse learning and development opportunities to support you to progress in your career Dedicated Employee Assistance Programme and a 24/7 remote GP service for you and your family Plus, so much more! We're an equal opportunities employer and welcome applications from everyone. The AA values diversity and the difference this brings to our culture and our customers. We actively seek people from diverse backgrounds to join us and become part of an inclusive company where you can be yourself, be empowered to be your best and feel like you truly belong. We have five communities to bring together people with shared characteristics and backgrounds and drive positive change.
Global Banking & Markets - London - Associate / Vice President - Business Analyst
Goldman Sachs Group, Inc.
Global Banking & Markets - London - Associate / Vice President - Business Analyst Job Description Payments Engineering Business Analyst (Associate / VicePresident) WHO WE ARE At Goldman Sachs, our Engineers don't just make things - we make things possible. Change the world by connecting people and capital with ideas. Solve the most challenging and pressing engineering problems for our clients. Join our engineering teams that build massively scalable software and systems, architect low latency infrastructure solutions, proactively guard against cyber threats, and leverage machine learning alongside financial engineering to continuously turn data into action. Create new businesses, transform finance, and explore a world of opportunity at the speed of markets. Engineering, which is comprised of our Technology Division and global strategists groups, is at the critical center of our business, and our dynamic environment requires innovative strategic thinking and immediate, real solutions. Want to push the limit of digital possibilities? Start here. Goldman Sachs Engineers are innovators and problem-solvers, building solutions in risk management, big data, mobile and more. We look for creative collaborators who evolve, adapt to change and thrive in a fast-paced global environment. Transaction Banking (TxB) aims to bring innovative solutions to traditional banking and lending activities. We are a global team of lenders, investors, risk managers, skilled marketers, web experts and banking specialists. We provide a suite of solutions to help our customers meet their financial goals. We make direct investments in and manage risk for a portfolio of corporate loans and securities. We help transform distressed communities through investments and loans of private capital. THE TEAM Payments lay at the heart of what we are doing in Corporate Cash Management and our mission is to build a market leading payment platform that meets our corporate client's needs. We are starting with a clean slate and one singular goal in mind: Build a highly scalable, resilient, 24x7 available cloud-based payment platform that our corporate clients can run rely on to run and grow their businesses. HOW YOU WILL FULFILL YOUR POTENTIAL As a Technical Payments Business Analyst (Associate / Vice President) within our Payments Engineering organization, you will bridge the gap between business strategy and technical execution. Leveraging your software engineering or technical background, you will dive deep into the system architecture, understand complex data flows, and translate high-level business and product requirements into robust technical specifications and system designs. You will collaborate closely with developers, architects, product managers, and operations teams to design scalable payment solutions. Your domain expertise in global payment rails and messaging standards (such as ISO 20022) will enable you to guide the engineering team through complex implementations, manage application lifecycles, and coordinate key compliance and attestation processes. This is a highly flexible role with significant growth potential, offering a clear path to transition into technical leadership or management. RESPONSIBILITIES AND QUALIFICATIONS Key Responsibilities: Technical Requirements & Design: Partner with product managers and business stakeholders to elicit requirements, and translate them into detailed technical specifications, system designs, and clear user stories for the engineering team. System & Architecture Understanding: Leverage your technical background to understand system dependencies, data models, and API integrations, ensuring proposed solutions are technically feasible and align with platform architecture. Stakeholder Management: Act as a key liaison and trusted partner between Payments Engineering, Product Management, Operations, and Compliance to align on priorities, manage expectations, and drive delivery. Payment Domain Leadership: Serve as a subject matter expert on payment processing, messaging standards (e.g., ISO 20022), and clearing networks, helping to guide the technical implementation of payment features. Compliance & Attestation Support: Coordinate and support annual scheme attestations, audits, and evidence collection for key payment rails, ensuring the platform meets all regulatory and operational standards. Agile Delivery: Actively participate in and drive Agile ceremonies (Scrum/Kanban), manage the technical backlog, and help unblock developers during the implementation phase. Basic Qualifications: Education & Background: B.S. or higher in Computer Science, Software Engineering, or a related technical field (or equivalent practical technical experience). Experience: Minimum 3 years of professional experience in a technical business analyst, systems analyst, or techno-functional product role within a payments or financial technology environment. Technical Acumen: Strong understanding of software development lifecycles (SDLC), system architecture, APIs, and data modeling, with the ability to read technical documentation and discuss system designs with developers. Payments Expertise: Deep knowledge of payment processing, transaction lifecycles, and messaging standards, specifically ISO 20022 and global/domestic payment rails. Stakeholder Management: Proven track record of managing diverse stakeholders, bridging the gap between highly technical engineering teams and non-technical business partners. Agile Methodologies: Comfort working in Agile operating models (practical experience with Scrum / Kanban, Jira, and Confluence). Preferred Qualifications: Prior experience as a software developer or systems engineer before transitioning into a business analyst or product role. Familiarity with UK domestic payment rails (FPS, CHAPS, BACS) and experience handling annual scheme attestations or compliance audits. Experience with payment vendor products (e.g., Finastra GPP, Volante, Fircosoft) or cloud-native payment architectures (e.g., AWS). Understanding of payment regulations (e.g., PSD2/PSD3, Open Banking) and AML/sanctions screening. Ambition and capability to grow into a leadership or people management role within a fast paced engineering organization ABOUT GOLDMAN SACHS At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has a number of opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. Learn more about our culture, benefits, and people at We're committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veterans status, disability, or any other characteristic protected by applicable law. Job Info Job Identification 178602 Job Category Associate Posting Date 07/16/2026, 04:14 PM Locations London, Greater London, England, United Kingdom Healthcare & Medical Services We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has a number of opportunities to grow professionally and personally We offer competitive vacation policies based on employee level and office location. We promote time off from work to recharge by providing generous vacation entitlements and a minimum of three weeks expected vacation usage each year. Financial Wellness & Retirement We assist employees in saving and planning for retirement, offer financial support for higher education, and provide a number of benefits to help employees prepare for the unexpected. We offer live financial education and content on a variety of topics to address the spectrum of employees' priorities. Health We offer a medical advocacy service for employees and family members facing critical health situations, and counseling and referral services through the Employee Assistance Program (EAP). We provide Global Medical, Security and Travel Assistance and a Workplace Ergonomics Program. We also offer state-of-the-art on-site health centers in certain offices. Fitness To encourage employees to live a healthy and active lifestyle, some of our offices feature on-site fitness centers. For eligible employees we typically reimburse fees paid for a fitness club membership or activity (up to a pre-approved amount). We offer on-site child care centers that provide full-time and emergency back-up care, as well as mother and baby rooms and homework rooms. In every office, we provide advice and counseling services, expectant parent resources and transitional programs for parents returning from parental leave. Adoption, surrogacy . click apply for full job details
19/07/2026
Full time
Global Banking & Markets - London - Associate / Vice President - Business Analyst Job Description Payments Engineering Business Analyst (Associate / VicePresident) WHO WE ARE At Goldman Sachs, our Engineers don't just make things - we make things possible. Change the world by connecting people and capital with ideas. Solve the most challenging and pressing engineering problems for our clients. Join our engineering teams that build massively scalable software and systems, architect low latency infrastructure solutions, proactively guard against cyber threats, and leverage machine learning alongside financial engineering to continuously turn data into action. Create new businesses, transform finance, and explore a world of opportunity at the speed of markets. Engineering, which is comprised of our Technology Division and global strategists groups, is at the critical center of our business, and our dynamic environment requires innovative strategic thinking and immediate, real solutions. Want to push the limit of digital possibilities? Start here. Goldman Sachs Engineers are innovators and problem-solvers, building solutions in risk management, big data, mobile and more. We look for creative collaborators who evolve, adapt to change and thrive in a fast-paced global environment. Transaction Banking (TxB) aims to bring innovative solutions to traditional banking and lending activities. We are a global team of lenders, investors, risk managers, skilled marketers, web experts and banking specialists. We provide a suite of solutions to help our customers meet their financial goals. We make direct investments in and manage risk for a portfolio of corporate loans and securities. We help transform distressed communities through investments and loans of private capital. THE TEAM Payments lay at the heart of what we are doing in Corporate Cash Management and our mission is to build a market leading payment platform that meets our corporate client's needs. We are starting with a clean slate and one singular goal in mind: Build a highly scalable, resilient, 24x7 available cloud-based payment platform that our corporate clients can run rely on to run and grow their businesses. HOW YOU WILL FULFILL YOUR POTENTIAL As a Technical Payments Business Analyst (Associate / Vice President) within our Payments Engineering organization, you will bridge the gap between business strategy and technical execution. Leveraging your software engineering or technical background, you will dive deep into the system architecture, understand complex data flows, and translate high-level business and product requirements into robust technical specifications and system designs. You will collaborate closely with developers, architects, product managers, and operations teams to design scalable payment solutions. Your domain expertise in global payment rails and messaging standards (such as ISO 20022) will enable you to guide the engineering team through complex implementations, manage application lifecycles, and coordinate key compliance and attestation processes. This is a highly flexible role with significant growth potential, offering a clear path to transition into technical leadership or management. RESPONSIBILITIES AND QUALIFICATIONS Key Responsibilities: Technical Requirements & Design: Partner with product managers and business stakeholders to elicit requirements, and translate them into detailed technical specifications, system designs, and clear user stories for the engineering team. System & Architecture Understanding: Leverage your technical background to understand system dependencies, data models, and API integrations, ensuring proposed solutions are technically feasible and align with platform architecture. Stakeholder Management: Act as a key liaison and trusted partner between Payments Engineering, Product Management, Operations, and Compliance to align on priorities, manage expectations, and drive delivery. Payment Domain Leadership: Serve as a subject matter expert on payment processing, messaging standards (e.g., ISO 20022), and clearing networks, helping to guide the technical implementation of payment features. Compliance & Attestation Support: Coordinate and support annual scheme attestations, audits, and evidence collection for key payment rails, ensuring the platform meets all regulatory and operational standards. Agile Delivery: Actively participate in and drive Agile ceremonies (Scrum/Kanban), manage the technical backlog, and help unblock developers during the implementation phase. Basic Qualifications: Education & Background: B.S. or higher in Computer Science, Software Engineering, or a related technical field (or equivalent practical technical experience). Experience: Minimum 3 years of professional experience in a technical business analyst, systems analyst, or techno-functional product role within a payments or financial technology environment. Technical Acumen: Strong understanding of software development lifecycles (SDLC), system architecture, APIs, and data modeling, with the ability to read technical documentation and discuss system designs with developers. Payments Expertise: Deep knowledge of payment processing, transaction lifecycles, and messaging standards, specifically ISO 20022 and global/domestic payment rails. Stakeholder Management: Proven track record of managing diverse stakeholders, bridging the gap between highly technical engineering teams and non-technical business partners. Agile Methodologies: Comfort working in Agile operating models (practical experience with Scrum / Kanban, Jira, and Confluence). Preferred Qualifications: Prior experience as a software developer or systems engineer before transitioning into a business analyst or product role. Familiarity with UK domestic payment rails (FPS, CHAPS, BACS) and experience handling annual scheme attestations or compliance audits. Experience with payment vendor products (e.g., Finastra GPP, Volante, Fircosoft) or cloud-native payment architectures (e.g., AWS). Understanding of payment regulations (e.g., PSD2/PSD3, Open Banking) and AML/sanctions screening. Ambition and capability to grow into a leadership or people management role within a fast paced engineering organization ABOUT GOLDMAN SACHS At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has a number of opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. Learn more about our culture, benefits, and people at We're committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veterans status, disability, or any other characteristic protected by applicable law. Job Info Job Identification 178602 Job Category Associate Posting Date 07/16/2026, 04:14 PM Locations London, Greater London, England, United Kingdom Healthcare & Medical Services We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has a number of opportunities to grow professionally and personally We offer competitive vacation policies based on employee level and office location. We promote time off from work to recharge by providing generous vacation entitlements and a minimum of three weeks expected vacation usage each year. Financial Wellness & Retirement We assist employees in saving and planning for retirement, offer financial support for higher education, and provide a number of benefits to help employees prepare for the unexpected. We offer live financial education and content on a variety of topics to address the spectrum of employees' priorities. Health We offer a medical advocacy service for employees and family members facing critical health situations, and counseling and referral services through the Employee Assistance Program (EAP). We provide Global Medical, Security and Travel Assistance and a Workplace Ergonomics Program. We also offer state-of-the-art on-site health centers in certain offices. Fitness To encourage employees to live a healthy and active lifestyle, some of our offices feature on-site fitness centers. For eligible employees we typically reimburse fees paid for a fitness club membership or activity (up to a pre-approved amount). We offer on-site child care centers that provide full-time and emergency back-up care, as well as mother and baby rooms and homework rooms. In every office, we provide advice and counseling services, expectant parent resources and transitional programs for parents returning from parental leave. Adoption, surrogacy . click apply for full job details
Principal Penetration Tester (9 Month FTC)
Allwyn UK Watford, Hertfordshire
At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact. We are Allwyn UK, part of the Allwyn Entertainment Group - a multi-national lottery operator with a market-leading presence across the USA (Michigan and Illinois) and Europe, including Czech Republic, Austria, Greece, Cyprus and Italy. While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do. Join us as we embark on a once-in-a-lifetime, largescale transformation journey by creating a National Lottery that delivers more money to good causes. We'll talk a bit more about us further down the page, but for now - let's talk about the role and who we're looking for A bit about the role This role strengthens the Security Testing function by adding senior hands on capability across application security testing and targeted offensive security work. The main purpose of the role is to improve the depth, consistency and practical value of security testing across Allwyn systems and services, while building enough internal offensive capability to support purple team activity, adversary led testing and better detection and response outcomes. The role is weighted towards application security. Around 70 percent of the time will be spent on testing and assuring modern applications, APIs, backend services and cloud hosted workloads. Around 30 percent will be spent on offensive security activity that supports purple team development, adversary informed assessments and selected deeper technical work such as binary analysis, operating system exploitation and ATT&CK aligned testing. What you'll be doing Application security testing and assurance, around 70 percent Lead and deliver advanced penetration testing across web applications, RESTful APIs, backend services, mobile connected services and supporting application platforms. Assess Java based backend systems, especially Spring Boot services, microservice architectures, API gateways and Backend for Frontend layers. Test authentication, authorisation, orchestration, input validation, session handling, token management and data exposure risks across modern digital journeys. Carry out security testing across cloud hosted and containerised application environments, ideally on AWS, where platform or configuration weaknesses affect application risk. Review outputs from SAST, DAST and related controls, separate noise from genuine risk, and help development teams understand what matters and what should be fixed first. Support threat modelling and design review activity by translating design and architecture decisions into sensible testing scope and coverage. Support release and project assurance by providing clear views on testing depth, remediation expectations and risk based sign off inputs. Help develop practical application security testing standards, playbooks and ways of working that can be applied across BAU and project delivery. Offensive security and purple team development, around 30 percent Develop and mature an internal purple team methodology that can be used alongside security testing activity and external red team exercises. Support offensive security planning with Security Testing leadership and Cyber Defence so that simulations and adversary led assessments are tied to the maturity of defensive controls and operational priorities. Use strong Linux and Windows knowledge to identify realistic exploitation paths across hosts, applications and supporting services. Bring practical knowledge of binary exploitation and lower level technical analysis where it adds value to application, platform or software component assessments. Apply ATT&CK aligned thinking when shaping offensive scenarios, attack paths and purple team test cases. Use knowledge of exploit chaining, post exploitation tradecraft, EDR and AV evasion concepts, and other offensive security techniques where they improve the realism and value of testing. Contribute to selected specialist work, including hardware focused testing or low level technical analysis, where there is a clear business need and the activity supports the wider security testing plan. Work with external offensive security partners and turn outputs into practical lessons, follow up actions and measurable improvements. Team contribution and capability building Act as a senior technical point of reference within the Security Testing function. Coach others in the team and help raise the standard of testing, reporting and technical analysis. Improve internal methods, test approaches and reporting so that the function becomes more consistent and easier to scale What experience we're looking for Essential Strong hands on experience in application penetration testing across web applications, APIs and service based architectures. Strong understanding of Java based backend systems, especially Spring Boot, RESTful APIs and microservice patterns. Experience testing API gateways and Backend for Frontend layers, including authentication, authorisation, orchestration and data validation. Practical knowledge of cloud hosted applications, ideally on AWS, including containerised services and common platform security controls. Good understanding of modern web and mobile application patterns, enough to assess API consumption, session handling, trust boundaries and data exposure risk. Strong practical knowledge of Linux and Windows operating systems, including privilege escalation paths, host weaknesses, credential handling risks and exploitation approaches relevant to application environments. Working knowledge of binary exploitation and lower level vulnerability analysis where relevant to application, runtime or platform risk. Ability to carry out manual testing beyond automated tooling, including business logic weakness, exploit chaining and cross layer issues. Ability to explain findings clearly to both technical and non technical stakeholders and provide practical remediation advice. Experience shaping testing approach, methodology or standards rather than only delivering assessments. Desirable Experience with mobile application assessment. Experience with secure code review or code assisted testing. Experience with ATT&CK informed assessments, adversary emulation support or purple team exercises. Familiarity with EDR and AV evasion concepts, exploit development, vulnerability research or offensive tooling beyond standard application testing. Exposure to hardware, embedded or other specialist low level testing techniques. Experience in regulated, high availability or transaction critical environments. Relevant certifications such as CREST, OSCP, OSWE, OSEP or equivalent demonstrable experience. Experience with WAF technology and implementation About us At Allwyn, we are dedicated to changing lives and growing the National Lottery responsibly, championing its positive impact on people, places, and the planet. Innovation - We pride ourselves on it! We're constantly looking for new ways to excite our customers, bringing new products to market to enjoy which is all supported by our responsible play values and making them accessible to all. Giving back - Did you know that playing the lottery generates around £30m a week for charities and good causes in the UK? Our aim is to have doubled this number by the end of the first 10-year license. Sustainability - Our aim is to become a net zero national lottery. We have 2030 targets to decarbonise our operations and energy. We've already transitioned to renewable energy providers, made our London and Watford offices zero gas, and ensured our fleet consists of low-emission vehicles. In addition, we're working with our value chain partners to develop a net zero target date. Empowering every voice - We believe in creating a culture where everyone feels they belong, can be themselves, has access to opportunities and can thrive for the benefit of good causes. Our diverse teams are working hard to make all parts of The National Lottery inclusive - whether people play a game in a store or online, because when everyone can play, everyone wins. An inclusive reward offering with wellbeing at the centre At Allwyn, inclusion is built into how we care for our people. Our benefits and policies support colleagues and their families at every stage of life and career. By prioritising wellbeing and belonging, we create a workplace where everyone feels valued, rewarded, and empowered to succeed. Our people are more than colleagues - they're winners, driving positive change and making a real difference in communities. Benefits Company Bonus Scheme Matched pension contributions up to 8.5% 26 days annual leave + 2 Life Days (and bank holidays) Single Private Health Cover Complimentary Private Medical Income Protection Flexible Benefits - EV Scheme, Money Coach, Will Writing, Mortgage Advice, Dental and Eye Care Schemes. Enhanced Family Leave (Maternity, Paternity, Adoption) Wellness Allowance £500 Employee Assistance Programme Discounted Health Assessments Volunteering Days Matched Funding . click apply for full job details
19/07/2026
Full time
At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact. We are Allwyn UK, part of the Allwyn Entertainment Group - a multi-national lottery operator with a market-leading presence across the USA (Michigan and Illinois) and Europe, including Czech Republic, Austria, Greece, Cyprus and Italy. While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do. Join us as we embark on a once-in-a-lifetime, largescale transformation journey by creating a National Lottery that delivers more money to good causes. We'll talk a bit more about us further down the page, but for now - let's talk about the role and who we're looking for A bit about the role This role strengthens the Security Testing function by adding senior hands on capability across application security testing and targeted offensive security work. The main purpose of the role is to improve the depth, consistency and practical value of security testing across Allwyn systems and services, while building enough internal offensive capability to support purple team activity, adversary led testing and better detection and response outcomes. The role is weighted towards application security. Around 70 percent of the time will be spent on testing and assuring modern applications, APIs, backend services and cloud hosted workloads. Around 30 percent will be spent on offensive security activity that supports purple team development, adversary informed assessments and selected deeper technical work such as binary analysis, operating system exploitation and ATT&CK aligned testing. What you'll be doing Application security testing and assurance, around 70 percent Lead and deliver advanced penetration testing across web applications, RESTful APIs, backend services, mobile connected services and supporting application platforms. Assess Java based backend systems, especially Spring Boot services, microservice architectures, API gateways and Backend for Frontend layers. Test authentication, authorisation, orchestration, input validation, session handling, token management and data exposure risks across modern digital journeys. Carry out security testing across cloud hosted and containerised application environments, ideally on AWS, where platform or configuration weaknesses affect application risk. Review outputs from SAST, DAST and related controls, separate noise from genuine risk, and help development teams understand what matters and what should be fixed first. Support threat modelling and design review activity by translating design and architecture decisions into sensible testing scope and coverage. Support release and project assurance by providing clear views on testing depth, remediation expectations and risk based sign off inputs. Help develop practical application security testing standards, playbooks and ways of working that can be applied across BAU and project delivery. Offensive security and purple team development, around 30 percent Develop and mature an internal purple team methodology that can be used alongside security testing activity and external red team exercises. Support offensive security planning with Security Testing leadership and Cyber Defence so that simulations and adversary led assessments are tied to the maturity of defensive controls and operational priorities. Use strong Linux and Windows knowledge to identify realistic exploitation paths across hosts, applications and supporting services. Bring practical knowledge of binary exploitation and lower level technical analysis where it adds value to application, platform or software component assessments. Apply ATT&CK aligned thinking when shaping offensive scenarios, attack paths and purple team test cases. Use knowledge of exploit chaining, post exploitation tradecraft, EDR and AV evasion concepts, and other offensive security techniques where they improve the realism and value of testing. Contribute to selected specialist work, including hardware focused testing or low level technical analysis, where there is a clear business need and the activity supports the wider security testing plan. Work with external offensive security partners and turn outputs into practical lessons, follow up actions and measurable improvements. Team contribution and capability building Act as a senior technical point of reference within the Security Testing function. Coach others in the team and help raise the standard of testing, reporting and technical analysis. Improve internal methods, test approaches and reporting so that the function becomes more consistent and easier to scale What experience we're looking for Essential Strong hands on experience in application penetration testing across web applications, APIs and service based architectures. Strong understanding of Java based backend systems, especially Spring Boot, RESTful APIs and microservice patterns. Experience testing API gateways and Backend for Frontend layers, including authentication, authorisation, orchestration and data validation. Practical knowledge of cloud hosted applications, ideally on AWS, including containerised services and common platform security controls. Good understanding of modern web and mobile application patterns, enough to assess API consumption, session handling, trust boundaries and data exposure risk. Strong practical knowledge of Linux and Windows operating systems, including privilege escalation paths, host weaknesses, credential handling risks and exploitation approaches relevant to application environments. Working knowledge of binary exploitation and lower level vulnerability analysis where relevant to application, runtime or platform risk. Ability to carry out manual testing beyond automated tooling, including business logic weakness, exploit chaining and cross layer issues. Ability to explain findings clearly to both technical and non technical stakeholders and provide practical remediation advice. Experience shaping testing approach, methodology or standards rather than only delivering assessments. Desirable Experience with mobile application assessment. Experience with secure code review or code assisted testing. Experience with ATT&CK informed assessments, adversary emulation support or purple team exercises. Familiarity with EDR and AV evasion concepts, exploit development, vulnerability research or offensive tooling beyond standard application testing. Exposure to hardware, embedded or other specialist low level testing techniques. Experience in regulated, high availability or transaction critical environments. Relevant certifications such as CREST, OSCP, OSWE, OSEP or equivalent demonstrable experience. Experience with WAF technology and implementation About us At Allwyn, we are dedicated to changing lives and growing the National Lottery responsibly, championing its positive impact on people, places, and the planet. Innovation - We pride ourselves on it! We're constantly looking for new ways to excite our customers, bringing new products to market to enjoy which is all supported by our responsible play values and making them accessible to all. Giving back - Did you know that playing the lottery generates around £30m a week for charities and good causes in the UK? Our aim is to have doubled this number by the end of the first 10-year license. Sustainability - Our aim is to become a net zero national lottery. We have 2030 targets to decarbonise our operations and energy. We've already transitioned to renewable energy providers, made our London and Watford offices zero gas, and ensured our fleet consists of low-emission vehicles. In addition, we're working with our value chain partners to develop a net zero target date. Empowering every voice - We believe in creating a culture where everyone feels they belong, can be themselves, has access to opportunities and can thrive for the benefit of good causes. Our diverse teams are working hard to make all parts of The National Lottery inclusive - whether people play a game in a store or online, because when everyone can play, everyone wins. An inclusive reward offering with wellbeing at the centre At Allwyn, inclusion is built into how we care for our people. Our benefits and policies support colleagues and their families at every stage of life and career. By prioritising wellbeing and belonging, we create a workplace where everyone feels valued, rewarded, and empowered to succeed. Our people are more than colleagues - they're winners, driving positive change and making a real difference in communities. Benefits Company Bonus Scheme Matched pension contributions up to 8.5% 26 days annual leave + 2 Life Days (and bank holidays) Single Private Health Cover Complimentary Private Medical Income Protection Flexible Benefits - EV Scheme, Money Coach, Will Writing, Mortgage Advice, Dental and Eye Care Schemes. Enhanced Family Leave (Maternity, Paternity, Adoption) Wellness Allowance £500 Employee Assistance Programme Discounted Health Assessments Volunteering Days Matched Funding . click apply for full job details
Principal Platform Security Engineer
Hiscox SA
Principal Platform Security EngineerApplyremote type: Hybridlocations: York: Lisbon: Londontime type: Full timeposted on: Posted Todayjob requisition id: R Job Type: Permanent Build a brilliant future with Hiscox Position : Principal Platform Security Engineer, London MarketAs a senior and influential member of the London Platform Engineering Chapter, the Principal Platform Security Engineer will set direction and lead by example in maturing our platform security practices. You will guide multiple Innovation squads and Engineering Chapters, driving cloud-first adoption and championing secure-by-design initiatives.You will be an integral member of a Chapter spanning Platform, DevOps, and Site Reliability Engineers, and a core contributor to a Platform Engineering squad focused on continuous improvement across our cloud and on-premises platforms. You will raise engineering standards through automation, reliable design, and pragmatic governance, helping to deliver smarter, more cost-effective, and faster solutions that are reusable across squads.With security embedded across all squads, you will provide visible leadership to strengthen our platform security posture. You will influence priorities, drive the change needed to embed modern DevOps and security ways of working, and ensure teams have the patterns, tooling, and guidance to succeed.As the chapter grows, this role also offers the opportunity to take on people leadership responsibilities, including day-to-day management of third-party security engineers and partner resources. Key Responsibilities Coach and mentor chapter members, and support the Head of Platform Engineering with overall chapter management, particularly across partner resources. Design, implement, and automate security controls and security testing within the SDLC. Lead application security practices, ensuring secure design and build, and coordinate effectively between engineering and security teams. Apply Security-as-Code principles by providing training, creating reusable patterns, and establishing best practices for teams. Support the investigation and future implementation of agentic workflows and agents, ensuring proposed solutions are secure-by-design and comply with Hiscox AI governance. Respond swiftly to new and emerging security threats and vulnerabilities, investigate suspected attacks, and help manage security incidents, including post-incident reviews to identify root causes, implement solutions, and prevent recurrence. Produce clear, actionable security reporting for senior leadership Act as the primary point of contact for security-related inquiries across London Market technology and change initiatives, coordinating with Group, other Business Units, and Cyber teams to advance security practices across Hiscox. Influence key architectural decisions early, balancing business requirements, budgets, security, and resilience. Partner with squads to take solutions from proof of concept (PoC) through to a production-ready platform. Build and maintain secure Azure and GCP infrastructure across all environments using Azure DevOps Pipelines and Terraform. Oversee and coach squads on intra-day deployment mechanisms, advocating for cloud-informed improvements that increase security, reliability, and delivery speed. Build and maintain monitoring and alerting at all levels (infrastructure, application, and data), ensuring actionable signals and secure operational practices. Person Specification : Mandatory skillset: 5+ years' DevOps/Platform Engineering experience delivering solutions in Azure and/or GCP. Full stack application and infrastructure solution design, ensuring robust security controls, high availability, and operational resilience throughout. Working knowledge of vulnerability and compliance management (scanning through to remediation), patch management, endpoint protection/anti-malware, and access control management (e.g., IAM/PAM), including driving findings to closure. Working knowledge of threat modelling and risk assessment, applied to cloud architectures and CI/CD pipelines to guide secure design and prioritised risk treatment. Experience with AppSec tooling, including CI/CD integration, tuning to reduce noise, and triaging results with engineers to prioritise remediation and prevent regressions. Strong leadership skills. You will help lead the wider technology and change teams to improve our DevOps and Security maturity by educating others and delegating responsibilities across your chapter, other engineering chapters, and Group IT teams. Experience with Terraform, and platform solutions. Experience working on solutions with integrations between GCP and Azure. Knowledge of Cloud native, microservices and containerised systems. To have a strong desire for continuous improvement and an Agile way of working. Ideally in addition: Knowledge of the insurance and London Market ecosystem; Lloyd's market experience is particularly valuable. Proven, hands-on software delivery experience, including platform engineering and/or build, release, and deployment engineering using modern DevOps practices. Experience delivering and operating technology in regulated environments, with a strong understanding of controls, audit expectations, and evidence-based compliance. Able to clearly explain the processes, patterns, and tooling used to ensure quality, stability, performance, scalability, secure deployment, maintainability, and effective documentation. Broad awareness of major cloud providers and services, with curiosity to evaluate and adopt capabilities that improve security, reliability, and cost efficiency. Proactive and improvement-focused, challenging the status quo and driving automation and simplification wherever it adds value. Strong delivery focus, able to prioritise effectively and deliver outcomes in a fast-paced environment with shifting demands. Able to operate effectively in a small, high-impact team while collaborating across a wider product/engineering organisation. Excellent communication and stakeholder-management skills, able to influence at all levels and present complex topics clearly. Comfortable working in ambiguity and adapting quickly as priorities, technology, and threats evolve. Up-to-date knowledge of security practices, processes, and tooling, with the judgement to apply emerging approaches pragmatically. Why Hiscox? This is a fantastic opportunity to join Hiscox during a time of focused growth where you will have the remit to make a real difference.At Hiscox we care about our people. We hire the best people for the job and we're committed to diversity and creating a truly inclusive culture, which we believe drives success. Work with amazing people and be part of a unique culture Why work here?If you want to help build a brilliant future; work with amazing people; be part of a unique company culture; and, of course, enjoy great employee benefits that take care of your mental and physical wellbeing, come and join us. Get in touchIf this is your first time visiting our career site and you wish to stay in touch please select the 'Introduce yourself' button on the top right. This will allow us to contact you with suitable vacancies. If you are a returning prospect and wish to view our current vacancies please Search for Jobs using the link on the top right. About usWe're a global, specialist insurer headquartered in Bermuda and listed on the London Stock Exchange. With 3,000 employees and 32 offices in 12 countries we're a business with lots of opportunity for people with talent, spark and lots of ambition. If you want to build a great career with a company that prioritises strong values - such as integrity and courage - where our people always pull together to do the right thing for each other and our customers, then we'd love to hear from you.
18/07/2026
Full time
Principal Platform Security EngineerApplyremote type: Hybridlocations: York: Lisbon: Londontime type: Full timeposted on: Posted Todayjob requisition id: R Job Type: Permanent Build a brilliant future with Hiscox Position : Principal Platform Security Engineer, London MarketAs a senior and influential member of the London Platform Engineering Chapter, the Principal Platform Security Engineer will set direction and lead by example in maturing our platform security practices. You will guide multiple Innovation squads and Engineering Chapters, driving cloud-first adoption and championing secure-by-design initiatives.You will be an integral member of a Chapter spanning Platform, DevOps, and Site Reliability Engineers, and a core contributor to a Platform Engineering squad focused on continuous improvement across our cloud and on-premises platforms. You will raise engineering standards through automation, reliable design, and pragmatic governance, helping to deliver smarter, more cost-effective, and faster solutions that are reusable across squads.With security embedded across all squads, you will provide visible leadership to strengthen our platform security posture. You will influence priorities, drive the change needed to embed modern DevOps and security ways of working, and ensure teams have the patterns, tooling, and guidance to succeed.As the chapter grows, this role also offers the opportunity to take on people leadership responsibilities, including day-to-day management of third-party security engineers and partner resources. Key Responsibilities Coach and mentor chapter members, and support the Head of Platform Engineering with overall chapter management, particularly across partner resources. Design, implement, and automate security controls and security testing within the SDLC. Lead application security practices, ensuring secure design and build, and coordinate effectively between engineering and security teams. Apply Security-as-Code principles by providing training, creating reusable patterns, and establishing best practices for teams. Support the investigation and future implementation of agentic workflows and agents, ensuring proposed solutions are secure-by-design and comply with Hiscox AI governance. Respond swiftly to new and emerging security threats and vulnerabilities, investigate suspected attacks, and help manage security incidents, including post-incident reviews to identify root causes, implement solutions, and prevent recurrence. Produce clear, actionable security reporting for senior leadership Act as the primary point of contact for security-related inquiries across London Market technology and change initiatives, coordinating with Group, other Business Units, and Cyber teams to advance security practices across Hiscox. Influence key architectural decisions early, balancing business requirements, budgets, security, and resilience. Partner with squads to take solutions from proof of concept (PoC) through to a production-ready platform. Build and maintain secure Azure and GCP infrastructure across all environments using Azure DevOps Pipelines and Terraform. Oversee and coach squads on intra-day deployment mechanisms, advocating for cloud-informed improvements that increase security, reliability, and delivery speed. Build and maintain monitoring and alerting at all levels (infrastructure, application, and data), ensuring actionable signals and secure operational practices. Person Specification : Mandatory skillset: 5+ years' DevOps/Platform Engineering experience delivering solutions in Azure and/or GCP. Full stack application and infrastructure solution design, ensuring robust security controls, high availability, and operational resilience throughout. Working knowledge of vulnerability and compliance management (scanning through to remediation), patch management, endpoint protection/anti-malware, and access control management (e.g., IAM/PAM), including driving findings to closure. Working knowledge of threat modelling and risk assessment, applied to cloud architectures and CI/CD pipelines to guide secure design and prioritised risk treatment. Experience with AppSec tooling, including CI/CD integration, tuning to reduce noise, and triaging results with engineers to prioritise remediation and prevent regressions. Strong leadership skills. You will help lead the wider technology and change teams to improve our DevOps and Security maturity by educating others and delegating responsibilities across your chapter, other engineering chapters, and Group IT teams. Experience with Terraform, and platform solutions. Experience working on solutions with integrations between GCP and Azure. Knowledge of Cloud native, microservices and containerised systems. To have a strong desire for continuous improvement and an Agile way of working. Ideally in addition: Knowledge of the insurance and London Market ecosystem; Lloyd's market experience is particularly valuable. Proven, hands-on software delivery experience, including platform engineering and/or build, release, and deployment engineering using modern DevOps practices. Experience delivering and operating technology in regulated environments, with a strong understanding of controls, audit expectations, and evidence-based compliance. Able to clearly explain the processes, patterns, and tooling used to ensure quality, stability, performance, scalability, secure deployment, maintainability, and effective documentation. Broad awareness of major cloud providers and services, with curiosity to evaluate and adopt capabilities that improve security, reliability, and cost efficiency. Proactive and improvement-focused, challenging the status quo and driving automation and simplification wherever it adds value. Strong delivery focus, able to prioritise effectively and deliver outcomes in a fast-paced environment with shifting demands. Able to operate effectively in a small, high-impact team while collaborating across a wider product/engineering organisation. Excellent communication and stakeholder-management skills, able to influence at all levels and present complex topics clearly. Comfortable working in ambiguity and adapting quickly as priorities, technology, and threats evolve. Up-to-date knowledge of security practices, processes, and tooling, with the judgement to apply emerging approaches pragmatically. Why Hiscox? This is a fantastic opportunity to join Hiscox during a time of focused growth where you will have the remit to make a real difference.At Hiscox we care about our people. We hire the best people for the job and we're committed to diversity and creating a truly inclusive culture, which we believe drives success. Work with amazing people and be part of a unique culture Why work here?If you want to help build a brilliant future; work with amazing people; be part of a unique company culture; and, of course, enjoy great employee benefits that take care of your mental and physical wellbeing, come and join us. Get in touchIf this is your first time visiting our career site and you wish to stay in touch please select the 'Introduce yourself' button on the top right. This will allow us to contact you with suitable vacancies. If you are a returning prospect and wish to view our current vacancies please Search for Jobs using the link on the top right. About usWe're a global, specialist insurer headquartered in Bermuda and listed on the London Stock Exchange. With 3,000 employees and 32 offices in 12 countries we're a business with lots of opportunity for people with talent, spark and lots of ambition. If you want to build a great career with a company that prioritises strong values - such as integrity and courage - where our people always pull together to do the right thing for each other and our customers, then we'd love to hear from you.
Senior Identity Protection Specialist
FLBK FUJIFILM Diosynth Biotechnologies UK Limited Billingham, Yorkshire
Protect identities at global scale. We're hiring a hands on Senior Identity Protection Engineer/Specialist to lead detection, investigation, and response for identity based threats across Microsoft Entra ID/Azure AD, on prem Active Directory, and connected SaaS/IaaS. What you'll do Lead identity threat monitoring and triage Operate and tune CrowdStrike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks like impossible travel, atypical sign ins, MFA fatigue, and session hijacking Validate true/false positives, prioritize by business impact, and expedite per playbooks/SLAs Drive rapid containment and remediation Execute containment actions (disable accounts, revoke sessions/tokens, isolate hosts) Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closure Own identity focused incident response; lead IR for credential compromise, privilege escalation, directory persistence, and lateral movement Ensure evidence handling, root cause analysis, post incident reviews, and lessons learned Engineer detections and hunt for threats Build and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CK Close visibility gaps, reduce false positives, and expand privileged activity monitoring Strengthen privileged access controls; detect anomalous privileged behavior via SIEM/UEBA and Netskope telemetry Recommend/enforce JIT, break glass patterns, and mover/leaver privilege hygiene with IAM Respond to dark web/credential exposure; integrate sources like CyberInt; assess exposure and targeted campaigns Orchestrate takedowns, forced resets, token revocation, and Conditional Access updates Administer platforms and sustain hygiene; maintain coverage/health for identity monitoring; manage upgrades and changes via CAB Keep operational runbooks, SOPs, and playbooks current Automate and orchestrate at scale using PowerShell/Python and REST/Graph/CrowdStrike APIs (and SOAR where applicable) Shape identity policy and controls; advise on Conditional Access, MFA exceptions, SSO/SCIM patterns, and session controls under the shared responsibility model with IAM Report outcomes and support audits; produce executive ready dashboards and KPIs (identity incident volume, MTTD/MTTR, CA/MFA efficacy, exposure/takedown cycle time) Maintain audit ready evidence and support internal/external audits What you'll bring Bachelor's degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience 8+ years in IT/cybersecurity, including 3+ years focused on identity security/operations (Entra ID/Azure AD, on prem AD, MFA, Conditional Access, SSO/SCIM) Hands on enterprise experience administering/operating CrowdStrike Identity Protection Proficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms (e.g., Netskope) for identity telemetry, detection, and investigations Demonstrated experience in identity centric IR, threat hunting, and detection engineering (KQL/SQL/regex/Sigma) Scripting/automation with PowerShell and Python; experience with REST/Graph/CrowdStrike APIs and SOAR Clear communication and documentation skills; comfortable producing executive ready reports and audit evidence Operates effectively within change control/CAB and under pressure during high severity incidents Bonus points Certifications: Microsoft SC 200/SC 300; Okta Certified Administrator/Professional; CISSP, SSCP, Security+; GIAC (GMON, GCIH, GCDA) or equivalent Deep knowledge of identity attack paths and protocols (Kerberos/NTLM), token/session abuse, and persistence techniques (e.g., Golden/Silver Ticket, DCShadow) Experience with JIT/JEA, PAM concepts, and global on call rotations Location, work style, and travel Opportunities in the United States, United Kingdom, and Denmark. Onsite or hybrid depending on location and business needs. Occasional on call coverage may be required. Why you'll love it here Own a mission critical identity defense stack and make measurable impact on MTTD/MTTR and privilege hygiene Solve complex problems from dark web exposure to directory persistence and lateral movement Collaborate with experienced global teams and leading vendors to continuously raise the bar Grow your career in a modern, data driven security operations environment Benefits and compensation will be governed by the location where you are based and considered your home site. This is a global position that will support all our FUJIFILM Biotechnologies sites.
18/07/2026
Full time
Protect identities at global scale. We're hiring a hands on Senior Identity Protection Engineer/Specialist to lead detection, investigation, and response for identity based threats across Microsoft Entra ID/Azure AD, on prem Active Directory, and connected SaaS/IaaS. What you'll do Lead identity threat monitoring and triage Operate and tune CrowdStrike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks like impossible travel, atypical sign ins, MFA fatigue, and session hijacking Validate true/false positives, prioritize by business impact, and expedite per playbooks/SLAs Drive rapid containment and remediation Execute containment actions (disable accounts, revoke sessions/tokens, isolate hosts) Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closure Own identity focused incident response; lead IR for credential compromise, privilege escalation, directory persistence, and lateral movement Ensure evidence handling, root cause analysis, post incident reviews, and lessons learned Engineer detections and hunt for threats Build and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CK Close visibility gaps, reduce false positives, and expand privileged activity monitoring Strengthen privileged access controls; detect anomalous privileged behavior via SIEM/UEBA and Netskope telemetry Recommend/enforce JIT, break glass patterns, and mover/leaver privilege hygiene with IAM Respond to dark web/credential exposure; integrate sources like CyberInt; assess exposure and targeted campaigns Orchestrate takedowns, forced resets, token revocation, and Conditional Access updates Administer platforms and sustain hygiene; maintain coverage/health for identity monitoring; manage upgrades and changes via CAB Keep operational runbooks, SOPs, and playbooks current Automate and orchestrate at scale using PowerShell/Python and REST/Graph/CrowdStrike APIs (and SOAR where applicable) Shape identity policy and controls; advise on Conditional Access, MFA exceptions, SSO/SCIM patterns, and session controls under the shared responsibility model with IAM Report outcomes and support audits; produce executive ready dashboards and KPIs (identity incident volume, MTTD/MTTR, CA/MFA efficacy, exposure/takedown cycle time) Maintain audit ready evidence and support internal/external audits What you'll bring Bachelor's degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience 8+ years in IT/cybersecurity, including 3+ years focused on identity security/operations (Entra ID/Azure AD, on prem AD, MFA, Conditional Access, SSO/SCIM) Hands on enterprise experience administering/operating CrowdStrike Identity Protection Proficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms (e.g., Netskope) for identity telemetry, detection, and investigations Demonstrated experience in identity centric IR, threat hunting, and detection engineering (KQL/SQL/regex/Sigma) Scripting/automation with PowerShell and Python; experience with REST/Graph/CrowdStrike APIs and SOAR Clear communication and documentation skills; comfortable producing executive ready reports and audit evidence Operates effectively within change control/CAB and under pressure during high severity incidents Bonus points Certifications: Microsoft SC 200/SC 300; Okta Certified Administrator/Professional; CISSP, SSCP, Security+; GIAC (GMON, GCIH, GCDA) or equivalent Deep knowledge of identity attack paths and protocols (Kerberos/NTLM), token/session abuse, and persistence techniques (e.g., Golden/Silver Ticket, DCShadow) Experience with JIT/JEA, PAM concepts, and global on call rotations Location, work style, and travel Opportunities in the United States, United Kingdom, and Denmark. Onsite or hybrid depending on location and business needs. Occasional on call coverage may be required. Why you'll love it here Own a mission critical identity defense stack and make measurable impact on MTTD/MTTR and privilege hygiene Solve complex problems from dark web exposure to directory persistence and lateral movement Collaborate with experienced global teams and leading vendors to continuously raise the bar Grow your career in a modern, data driven security operations environment Benefits and compensation will be governed by the location where you are based and considered your home site. This is a global position that will support all our FUJIFILM Biotechnologies sites.
Information Security Analyst, Vulnerability Management
BET365 GROUP Stoke-on-trent, Staffordshire
Information Security Analyst, Vulnerability Management Stoke-on-Trent Technology As an Information Security Analyst in our vulnerability management team, you will ensure IT systems are operating in a secure manner in line with regulatory requirements. Full-time Closes 12/08/2026 Join our vulnerability management team as an Information Security Analyst. You keep our IT systems secure and compliant while protecting our live operation. Our Information Security team monitors our live operation around the clock. We spot anomalies and manage vulnerability scanning across all endpoints. You assess risk, plan specialist testing, and help the business understand the urgency of patching. You also work with governance teams to keep us compliant. This role is eligible for inclusion in the Company's hybrid working from home policy. Preferred Skills and Experience Strong understanding of information and cyber security principles. Hands-on experience with vulnerability scanning tools and risk assessment. Proven ability to explain technical risk to non-technical teams. Experience with security-related technical investigations. Working knowledge of industry-standard security practices. Awareness of the current Payment Card Industry Data Security Standard (PCI DSS) version. Excellent attention to detail and documentation skills. Strong organisational skills with the ability to meet deadlines. Pragmatic approach to governance and risk administration. Committed and flexible attitude towards work. What you will be doing Running vulnerability scans using industry-leading tools. Scheduling scanning across the Business to minimise operational impact. Explaining Business risk to technical and non-technical colleagues. Coordinating internal and external resources to meet targets. Embedding security requirements throughout the project lifecycle. Liaising with the Business to ensure we meet all security requirements. Acting as an escalation point for security queries. Creating clear and accurate technical documentation. Monitoring emerging threats and escalate findings to the relevant teams. Supporting internal and external audits. Bonus Eye care and Flu Vaccinations Life Assurance Life at bet365 We are a unique global operator with passion and drive to be the best in the industry. Our values form the foundation of culture and shape the unique way that we work. People are our superpower and we support you to be the best you can be.
18/07/2026
Full time
Information Security Analyst, Vulnerability Management Stoke-on-Trent Technology As an Information Security Analyst in our vulnerability management team, you will ensure IT systems are operating in a secure manner in line with regulatory requirements. Full-time Closes 12/08/2026 Join our vulnerability management team as an Information Security Analyst. You keep our IT systems secure and compliant while protecting our live operation. Our Information Security team monitors our live operation around the clock. We spot anomalies and manage vulnerability scanning across all endpoints. You assess risk, plan specialist testing, and help the business understand the urgency of patching. You also work with governance teams to keep us compliant. This role is eligible for inclusion in the Company's hybrid working from home policy. Preferred Skills and Experience Strong understanding of information and cyber security principles. Hands-on experience with vulnerability scanning tools and risk assessment. Proven ability to explain technical risk to non-technical teams. Experience with security-related technical investigations. Working knowledge of industry-standard security practices. Awareness of the current Payment Card Industry Data Security Standard (PCI DSS) version. Excellent attention to detail and documentation skills. Strong organisational skills with the ability to meet deadlines. Pragmatic approach to governance and risk administration. Committed and flexible attitude towards work. What you will be doing Running vulnerability scans using industry-leading tools. Scheduling scanning across the Business to minimise operational impact. Explaining Business risk to technical and non-technical colleagues. Coordinating internal and external resources to meet targets. Embedding security requirements throughout the project lifecycle. Liaising with the Business to ensure we meet all security requirements. Acting as an escalation point for security queries. Creating clear and accurate technical documentation. Monitoring emerging threats and escalate findings to the relevant teams. Supporting internal and external audits. Bonus Eye care and Flu Vaccinations Life Assurance Life at bet365 We are a unique global operator with passion and drive to be the best in the industry. Our values form the foundation of culture and shape the unique way that we work. People are our superpower and we support you to be the best you can be.
MI5
NCSC International Technical Director Ref. 3792
MI5
Cheltenham, London, Manchester About us GCHQ is an intelligence, cyber and security agency with a mission to keep the UK safe. We use cutting edge technology, ingenuity and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners MI5 and MI6, we protect the UK from terrorism, cyber attacks and espionage. At GCHQ you'll do varied and fascinating work in a supportive and inclusive environment that puts the emphasis on teamwork. The National Cyber Security Centre (NCSC), part of GCHQ, is the UK Government's lead authority on cyber security. The organisation is at the heart of the Government's cyber security strategy and has the aim of making the UK the safest place to live and work online. Job description We're currently looking for an International Technical Director to join our team within NCSC's Office of the Chief Technical Officer. In this role, you'll work alongside technical specialists who explore the core security attributes of the UK's critical systems and technologies. Together, we identify vulnerabilities and create resilient, long term solutions that help protect the nation's digital infrastructure. What will the successful candidate be doing? You'll be at the centre of meaningful, technical work that drives real world impact on an international stage. You'll work both independently and collaboratively, reporting to a senior colleague while offering expert advice on specific projects. You'll have responsibility for mentoring others, engaging with senior leaders and specialists, and providing strategic insight, especially when navigating complex challenges. You'll be expected to undertake frequent international travel, potentially leading to a full time posting overseas in 12 months' time for approximately 2 years. The successful candidate will support the development of the Memorandum of Understandings (MoUs) with international partners. Person Specification The successful applicant will need to have: At least five years of practical experience in cyber security. Significant experience working both with a government department and in international settings. Ability to work confidently across a broad range of technical cyber security topics such as: Designing secure architectures for IT, Operational Technology, or AI systems. Analysing hardware and device level security features. Researching software vulnerabilities and secure development practices. Application of cryptographic protocols or the security of networking and telecommunications technologies. Deep technical expertise in one or more areas of cyber security. Knowledge of how technological vulnerabilities occur, how they are discovered, and how they may be exploited. Experience of applying specialist technical security capabilities to help solve customer security problems. GCHQ Competencies As part of the selection process, the NCSC will assess you using competencies aligned with those used across the UK Intelligence Community. These are closely based on the Civil Service Behaviours, so if you're familiar with those, you're already on the right track. At Level 4, we'll be looking at how you demonstrate the following: Seeing the Big Picture Communicating and Influencing Working Collaboratively Providing Customer Value Benefits and rewards At NCSC and GCHQ, we are proud of our inclusive and supportive working environment which is designed to encourage open minds and attitudes. As an organisation that values and nurtures talent, we are committed to helping you fulfil your potential. With comprehensive training and development opportunities, tailored to your needs and the requirements of your work, we will enable you to flourish in your role and perform to the very best of your abilities. You'll receive a starting salary of £71,889 (including a concessionary payment of £3,144). This role may attract a skills payment, for which you'll be evaluated for during the interview. The criteria for the skills assessment will be provided when you are invited to interview. If you are assessed to qualify for a skills payment, these payments start at £6,552 per annum. For roles based in London, you'll receive an additional £6,250 London Allowance. Other benefits include: 25 Days Annual Leave automatically rising to 30 days after 5 years' service, and an additional 10.5 days public and privilege holidays Opportunities to be recognised through our employee performance scheme Interest free season ticket loan Cycle to work scheme Facilities such as a gym, restaurant and on site coffee bars (at some locations) Paid parental and adoption leave Excellent pension scheme - Civil Service pension Equal Opportunities At GCHQ diversity and inclusion are critical to our mission. To protect the UK, we need a truly diverse workforce that reflects the society we serve. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio economic backgrounds. Disability Confident GCHQ is proud to have achieved Leader status within the DWP's Disability Confident scheme. This is aimed at encouraging employers to think differently about disability and take action to improve how they recruit, retain and develop disabled people. As a Disability Confident Leader we aim to ensure that a fair and proportionate number of disabled applicants who best meet the essential minimum criteria for this position, will be offered an interview, if it is practical for us to do so. (This is known as Offer of an Interview.) To secure an interview for this role, the minimum criteria, which will be assessed at the CV sift stage: You'll be required to reach the minimum pass mark for the online Situational Judgement Test (SJT), which assesses criteria important for all roles in our organisation. Demonstrate experience of applying specialist technical security capabilities to help solve customer security problems. Assessed at application sift. Demonstrate how technological vulnerabilities occur, how they are discovered, and how they may be exploited. Assessed at application sift. Demonstrate experience of leading a technical team. Assessed at CV sift. What to Expect Our recruitment process is fair, transparent, and based on merit. Here is a brief overview of each stage, in order: Initial online application. Online Situational Judgement Test (SJT) rating the appropriateness of your response to a series of short scenarios. Application sift. Online interview. If successful, you'll receive a conditional offer of employment. Please note, you must successfully pass each stage of the process to progress to the next. Your application may take around 6 9 months to process including vetting, so we advise you to continue any current employment until you have received your final job offer. Before You Apply To work at NCSC, you need to be a British citizen or hold dual British nationality. You can read our full eligibility criteria here. This role requires the highest security clearance, known as Developed Vetting (DV). It's something everyone in the UK Intelligence Community undertakes. You can find out more about the vetting process here. Please note we have a strict drugs policy, so once you start your application, you can't take any recreational drugs and you'll need to declare your previous drug usage at the relevant stage. Before you apply, recommend setting up a separate email address for your contact with us, to ensure your personal and application correspondence remain separate. Try to avoid having identifying features in your email address, such as your first and/or surname and date of birth. This is good practice and will help you to manage your application with us more securely. The role is based either London, Cheltenham or Manchester, so you'll need to live within a commutable distance. Please consider any financial implications and practicalities before submitting an application, as we do not offer relocation costs. We offer reasonable reimbursement of travel costs for candidates attending in person appointments during the recruitment and vetting process. Full details will be provided with your interview or assessment invitation. Reimbursement is discretionary and will only be made in line with the Candidate Expenses Policy, as amended from time to time. Candidates must book their own travel, using the most economical option, and provide original hardcopy receipts for reimbursement. Please note, you should only launch your application from within the UK. If you are based overseas, you should wait until you visit the UK to launch an application. Applying from outside the UK will impact on our ability to progress your application. You should not discuss your application, other than with your partner or a close family member. Closing date for this role is: 4th August 2026 at 23:55 . click apply for full job details
18/07/2026
Full time
Cheltenham, London, Manchester About us GCHQ is an intelligence, cyber and security agency with a mission to keep the UK safe. We use cutting edge technology, ingenuity and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners MI5 and MI6, we protect the UK from terrorism, cyber attacks and espionage. At GCHQ you'll do varied and fascinating work in a supportive and inclusive environment that puts the emphasis on teamwork. The National Cyber Security Centre (NCSC), part of GCHQ, is the UK Government's lead authority on cyber security. The organisation is at the heart of the Government's cyber security strategy and has the aim of making the UK the safest place to live and work online. Job description We're currently looking for an International Technical Director to join our team within NCSC's Office of the Chief Technical Officer. In this role, you'll work alongside technical specialists who explore the core security attributes of the UK's critical systems and technologies. Together, we identify vulnerabilities and create resilient, long term solutions that help protect the nation's digital infrastructure. What will the successful candidate be doing? You'll be at the centre of meaningful, technical work that drives real world impact on an international stage. You'll work both independently and collaboratively, reporting to a senior colleague while offering expert advice on specific projects. You'll have responsibility for mentoring others, engaging with senior leaders and specialists, and providing strategic insight, especially when navigating complex challenges. You'll be expected to undertake frequent international travel, potentially leading to a full time posting overseas in 12 months' time for approximately 2 years. The successful candidate will support the development of the Memorandum of Understandings (MoUs) with international partners. Person Specification The successful applicant will need to have: At least five years of practical experience in cyber security. Significant experience working both with a government department and in international settings. Ability to work confidently across a broad range of technical cyber security topics such as: Designing secure architectures for IT, Operational Technology, or AI systems. Analysing hardware and device level security features. Researching software vulnerabilities and secure development practices. Application of cryptographic protocols or the security of networking and telecommunications technologies. Deep technical expertise in one or more areas of cyber security. Knowledge of how technological vulnerabilities occur, how they are discovered, and how they may be exploited. Experience of applying specialist technical security capabilities to help solve customer security problems. GCHQ Competencies As part of the selection process, the NCSC will assess you using competencies aligned with those used across the UK Intelligence Community. These are closely based on the Civil Service Behaviours, so if you're familiar with those, you're already on the right track. At Level 4, we'll be looking at how you demonstrate the following: Seeing the Big Picture Communicating and Influencing Working Collaboratively Providing Customer Value Benefits and rewards At NCSC and GCHQ, we are proud of our inclusive and supportive working environment which is designed to encourage open minds and attitudes. As an organisation that values and nurtures talent, we are committed to helping you fulfil your potential. With comprehensive training and development opportunities, tailored to your needs and the requirements of your work, we will enable you to flourish in your role and perform to the very best of your abilities. You'll receive a starting salary of £71,889 (including a concessionary payment of £3,144). This role may attract a skills payment, for which you'll be evaluated for during the interview. The criteria for the skills assessment will be provided when you are invited to interview. If you are assessed to qualify for a skills payment, these payments start at £6,552 per annum. For roles based in London, you'll receive an additional £6,250 London Allowance. Other benefits include: 25 Days Annual Leave automatically rising to 30 days after 5 years' service, and an additional 10.5 days public and privilege holidays Opportunities to be recognised through our employee performance scheme Interest free season ticket loan Cycle to work scheme Facilities such as a gym, restaurant and on site coffee bars (at some locations) Paid parental and adoption leave Excellent pension scheme - Civil Service pension Equal Opportunities At GCHQ diversity and inclusion are critical to our mission. To protect the UK, we need a truly diverse workforce that reflects the society we serve. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio economic backgrounds. Disability Confident GCHQ is proud to have achieved Leader status within the DWP's Disability Confident scheme. This is aimed at encouraging employers to think differently about disability and take action to improve how they recruit, retain and develop disabled people. As a Disability Confident Leader we aim to ensure that a fair and proportionate number of disabled applicants who best meet the essential minimum criteria for this position, will be offered an interview, if it is practical for us to do so. (This is known as Offer of an Interview.) To secure an interview for this role, the minimum criteria, which will be assessed at the CV sift stage: You'll be required to reach the minimum pass mark for the online Situational Judgement Test (SJT), which assesses criteria important for all roles in our organisation. Demonstrate experience of applying specialist technical security capabilities to help solve customer security problems. Assessed at application sift. Demonstrate how technological vulnerabilities occur, how they are discovered, and how they may be exploited. Assessed at application sift. Demonstrate experience of leading a technical team. Assessed at CV sift. What to Expect Our recruitment process is fair, transparent, and based on merit. Here is a brief overview of each stage, in order: Initial online application. Online Situational Judgement Test (SJT) rating the appropriateness of your response to a series of short scenarios. Application sift. Online interview. If successful, you'll receive a conditional offer of employment. Please note, you must successfully pass each stage of the process to progress to the next. Your application may take around 6 9 months to process including vetting, so we advise you to continue any current employment until you have received your final job offer. Before You Apply To work at NCSC, you need to be a British citizen or hold dual British nationality. You can read our full eligibility criteria here. This role requires the highest security clearance, known as Developed Vetting (DV). It's something everyone in the UK Intelligence Community undertakes. You can find out more about the vetting process here. Please note we have a strict drugs policy, so once you start your application, you can't take any recreational drugs and you'll need to declare your previous drug usage at the relevant stage. Before you apply, recommend setting up a separate email address for your contact with us, to ensure your personal and application correspondence remain separate. Try to avoid having identifying features in your email address, such as your first and/or surname and date of birth. This is good practice and will help you to manage your application with us more securely. The role is based either London, Cheltenham or Manchester, so you'll need to live within a commutable distance. Please consider any financial implications and practicalities before submitting an application, as we do not offer relocation costs. We offer reasonable reimbursement of travel costs for candidates attending in person appointments during the recruitment and vetting process. Full details will be provided with your interview or assessment invitation. Reimbursement is discretionary and will only be made in line with the Candidate Expenses Policy, as amended from time to time. Candidates must book their own travel, using the most economical option, and provide original hardcopy receipts for reimbursement. Please note, you should only launch your application from within the UK. If you are based overseas, you should wait until you visit the UK to launch an application. Applying from outside the UK will impact on our ability to progress your application. You should not discuss your application, other than with your partner or a close family member. Closing date for this role is: 4th August 2026 at 23:55 . click apply for full job details
Audit Specialist - COO & Technology
Quilter plc
Quilter plc is a leading provider of financial advice, investments and wealth management, committed to being the UK's best wealth manager for clients and their advisers. About the Role Level - 4 Department: Internal Audit Location: London / Southampton Contract - Permanent Regulated/Non-Regulated: Non-Regulated The role supports the delivery of IT and business audits across the Internal Audit Plan, helping protect the organisation's assets, reputation, and sustainability. The focus is on technology audits (applications, infrastructure, thematic reviews) and related areas including cyber security, third party risk, data privacy, and operational resilience. Key Responsibilities Deliver audits end to end across planning, fieldwork, and reporting. Engage stakeholders to understand processes and key risks. Perform risk focused testing and root cause analysis. Produce clear, practical audit findings and recommendations. Keep stakeholders informed and build strong working relationships. Deliver work in line with methodology, timelines, and budgets. Perform quarterly issue assurance reviews. Support risk monitoring and audit planning. Review business MI (e.g., financials, incidents, complaints). Contribute to team initiatives, including continuous improvement and data/analytics use. About You Experience in a risk and controls focused role (e.g., Internal/External Audit, Risk, or Compliance). Good understanding of IT and business risk and controls within Wealth and Asset Management. Knowledge of relevant Technology and Security regulations, frameworks, and best practices. Solid understanding of IT General Controls (e.g., access, change management, IT operations). Ability to clearly articulate audit findings in a business context. Ideally holds a relevant qualification (e.g., CISA, CISM, CRISC, ACA, ACCA, IMC, CFA or similar). Desirable: Experience in third party risk, business continuity, cyber security, and data/privacy controls. Desirable: Exposure to auditing emerging technologies, IT infrastructure, and disaster recovery. Desirable: Experience using data analytics in audit testing. Inclusion & Diversity We value diversity and strive to promote inclusivity in all aspects of our culture. We believe in equal opportunities for all, ensuring that no applicant encounters less favourable treatment based on skills, qualifications, experience, or potential. The company is committed to treating all job applicants fairly and with respect, welcoming applications regardless of beliefs, culture, gender identity, ethnicity, sexual orientation, or disability. Core Benefits Holiday: 182 hours (26 days) Quilter Incentive Scheme: All employees eligible to participate, incentivising business performance and contribution. Pension Scheme: Non contributory company pension, boostable through personal contributions. Private Medical Insurance: Single cover as standard, option to increase cover. Life Assurance: 4 your salary. Income Protection: 75% of salary (excluding state benefits), payable after 26 weeks of absence. Healthcare Cash Plan: Available to Jersey employees only.
18/07/2026
Full time
Quilter plc is a leading provider of financial advice, investments and wealth management, committed to being the UK's best wealth manager for clients and their advisers. About the Role Level - 4 Department: Internal Audit Location: London / Southampton Contract - Permanent Regulated/Non-Regulated: Non-Regulated The role supports the delivery of IT and business audits across the Internal Audit Plan, helping protect the organisation's assets, reputation, and sustainability. The focus is on technology audits (applications, infrastructure, thematic reviews) and related areas including cyber security, third party risk, data privacy, and operational resilience. Key Responsibilities Deliver audits end to end across planning, fieldwork, and reporting. Engage stakeholders to understand processes and key risks. Perform risk focused testing and root cause analysis. Produce clear, practical audit findings and recommendations. Keep stakeholders informed and build strong working relationships. Deliver work in line with methodology, timelines, and budgets. Perform quarterly issue assurance reviews. Support risk monitoring and audit planning. Review business MI (e.g., financials, incidents, complaints). Contribute to team initiatives, including continuous improvement and data/analytics use. About You Experience in a risk and controls focused role (e.g., Internal/External Audit, Risk, or Compliance). Good understanding of IT and business risk and controls within Wealth and Asset Management. Knowledge of relevant Technology and Security regulations, frameworks, and best practices. Solid understanding of IT General Controls (e.g., access, change management, IT operations). Ability to clearly articulate audit findings in a business context. Ideally holds a relevant qualification (e.g., CISA, CISM, CRISC, ACA, ACCA, IMC, CFA or similar). Desirable: Experience in third party risk, business continuity, cyber security, and data/privacy controls. Desirable: Exposure to auditing emerging technologies, IT infrastructure, and disaster recovery. Desirable: Experience using data analytics in audit testing. Inclusion & Diversity We value diversity and strive to promote inclusivity in all aspects of our culture. We believe in equal opportunities for all, ensuring that no applicant encounters less favourable treatment based on skills, qualifications, experience, or potential. The company is committed to treating all job applicants fairly and with respect, welcoming applications regardless of beliefs, culture, gender identity, ethnicity, sexual orientation, or disability. Core Benefits Holiday: 182 hours (26 days) Quilter Incentive Scheme: All employees eligible to participate, incentivising business performance and contribution. Pension Scheme: Non contributory company pension, boostable through personal contributions. Private Medical Insurance: Single cover as standard, option to increase cover. Life Assurance: 4 your salary. Income Protection: 75% of salary (excluding state benefits), payable after 26 weeks of absence. Healthcare Cash Plan: Available to Jersey employees only.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board