it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

1186 jobs found

Email me jobs like this
Refine Search
Current Search
incident response lead
BAE Systems
External Attack Surface Management Analyst
BAE Systems Aldershot, Hampshire
Job Title: External Attack Surface Management Analyst Job Location: Preston or Frimley - Hybrid-2 days a month onsite. We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Circa £45,000 depending on skills and experience Who we are: Join BAE Systems and you'll be part of something bigger. As a valued member of our global colleague network, you'll bring your unique skills and perspectives to help pioneer progress and protect what matters most. You'll be trusted to play your part in delivering the advanced, technology-led defence, aerospace and security solutions of tomorrow - shaping a safer future, for all of us. Role Description: Working within Cyber Operations, you will help safeguard BAE Systems against evolving cyber threats by supporting and enhancing the External Attack Surface Management (EASM) capability across people, process, and technology. You will contribute to an intelligence-led approach to cyber operations, ensuring external assets are identified, assessed, and continuously tested. The role supports detection assurance by identifying shadow IT and unmanaged exposures, providing confidence to leadership that security controls and monitoring capabilities are effective and aligned to organisational security standards. Core Duties: Proactively discover, track, and maintain visibility of external attack surface assets, including unknown and shadow IT exposures Investigate and validate externally visible exposures, assessing real-world risk, attacker relevance, and exploitability Monitor changes in external exposure, identifying new assets, regressions, and emerging risks across the estate Collaborate with Threat Intelligence and Cyber Operations to align exposure findings with attacker activity and remediation priorities Produce clear, actionable reporting on external exposures, trends, and security posture to support risk reduction and decision -making Essential Skills: Good understanding of external reconnaissance techniques, OSINT, and how attackers identify and profile internet-facing assets Proven experience in attack surface discovery, asset enumeration, and identifying unknown or shadow IT exposures Good investigative mindset with the ability to analyse incomplete or ambiguous external data and determine genuine security risk Ability to assess and distinguish between observed external artefacts, misconfigurations, and true exploitable exposures from an attacker's perspective Experience working with internet-facing protocols and data sources (e.g. DNS, HTTP, TLS, certificate transparency, scanning datasets) to identify patterns, relationships, and anomalies The Cyber Operations team: Cyber Operations is responsible for protecting BAE Systems from Cyber Attack by various threat actors. Not only do we protect BAE Systems and its employees, indirectly we protect those who protect us - who serve in our military and rely on the products and services we create across Threat Intelligence, Detection, Incident Response and now Active Defence we work to evolve cyber operations as a world class capability. Why BAE Systems? Here you'll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work - this is a place where you can grow your career with confidence and be empowered to be your best. You'll be recognised for your contribution and enjoy rewards tailored to what's most important to you and your family - support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make. A place where everyone can thrive: We're committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role , to allow for meaningful security vetting checks. Closing Date: 14th July 2026 We reserve the right to close this vacancy early if we receive sufficient applications for the role . Therefore, if you are interested, please submit your application as early as possible.
10/07/2026
Full time
Job Title: External Attack Surface Management Analyst Job Location: Preston or Frimley - Hybrid-2 days a month onsite. We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Circa £45,000 depending on skills and experience Who we are: Join BAE Systems and you'll be part of something bigger. As a valued member of our global colleague network, you'll bring your unique skills and perspectives to help pioneer progress and protect what matters most. You'll be trusted to play your part in delivering the advanced, technology-led defence, aerospace and security solutions of tomorrow - shaping a safer future, for all of us. Role Description: Working within Cyber Operations, you will help safeguard BAE Systems against evolving cyber threats by supporting and enhancing the External Attack Surface Management (EASM) capability across people, process, and technology. You will contribute to an intelligence-led approach to cyber operations, ensuring external assets are identified, assessed, and continuously tested. The role supports detection assurance by identifying shadow IT and unmanaged exposures, providing confidence to leadership that security controls and monitoring capabilities are effective and aligned to organisational security standards. Core Duties: Proactively discover, track, and maintain visibility of external attack surface assets, including unknown and shadow IT exposures Investigate and validate externally visible exposures, assessing real-world risk, attacker relevance, and exploitability Monitor changes in external exposure, identifying new assets, regressions, and emerging risks across the estate Collaborate with Threat Intelligence and Cyber Operations to align exposure findings with attacker activity and remediation priorities Produce clear, actionable reporting on external exposures, trends, and security posture to support risk reduction and decision -making Essential Skills: Good understanding of external reconnaissance techniques, OSINT, and how attackers identify and profile internet-facing assets Proven experience in attack surface discovery, asset enumeration, and identifying unknown or shadow IT exposures Good investigative mindset with the ability to analyse incomplete or ambiguous external data and determine genuine security risk Ability to assess and distinguish between observed external artefacts, misconfigurations, and true exploitable exposures from an attacker's perspective Experience working with internet-facing protocols and data sources (e.g. DNS, HTTP, TLS, certificate transparency, scanning datasets) to identify patterns, relationships, and anomalies The Cyber Operations team: Cyber Operations is responsible for protecting BAE Systems from Cyber Attack by various threat actors. Not only do we protect BAE Systems and its employees, indirectly we protect those who protect us - who serve in our military and rely on the products and services we create across Threat Intelligence, Detection, Incident Response and now Active Defence we work to evolve cyber operations as a world class capability. Why BAE Systems? Here you'll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work - this is a place where you can grow your career with confidence and be empowered to be your best. You'll be recognised for your contribution and enjoy rewards tailored to what's most important to you and your family - support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make. A place where everyone can thrive: We're committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role , to allow for meaningful security vetting checks. Closing Date: 14th July 2026 We reserve the right to close this vacancy early if we receive sufficient applications for the role . Therefore, if you are interested, please submit your application as early as possible.
BAE Systems
External Attack Surface Management Analyst
BAE Systems Farnham, Surrey
Job Title: External Attack Surface Management Analyst Job Location: Preston or Frimley - Hybrid-2 days a month onsite. We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Circa £45,000 depending on skills and experience Who we are: Join BAE Systems and you'll be part of something bigger. As a valued member of our global colleague network, you'll bring your unique skills and perspectives to help pioneer progress and protect what matters most. You'll be trusted to play your part in delivering the advanced, technology-led defence, aerospace and security solutions of tomorrow - shaping a safer future, for all of us. Role Description: Working within Cyber Operations, you will help safeguard BAE Systems against evolving cyber threats by supporting and enhancing the External Attack Surface Management (EASM) capability across people, process, and technology. You will contribute to an intelligence-led approach to cyber operations, ensuring external assets are identified, assessed, and continuously tested. The role supports detection assurance by identifying shadow IT and unmanaged exposures, providing confidence to leadership that security controls and monitoring capabilities are effective and aligned to organisational security standards. Core Duties: Proactively discover, track, and maintain visibility of external attack surface assets, including unknown and shadow IT exposures Investigate and validate externally visible exposures, assessing real-world risk, attacker relevance, and exploitability Monitor changes in external exposure, identifying new assets, regressions, and emerging risks across the estate Collaborate with Threat Intelligence and Cyber Operations to align exposure findings with attacker activity and remediation priorities Produce clear, actionable reporting on external exposures, trends, and security posture to support risk reduction and decision -making Essential Skills: Good understanding of external reconnaissance techniques, OSINT, and how attackers identify and profile internet-facing assets Proven experience in attack surface discovery, asset enumeration, and identifying unknown or shadow IT exposures Good investigative mindset with the ability to analyse incomplete or ambiguous external data and determine genuine security risk Ability to assess and distinguish between observed external artefacts, misconfigurations, and true exploitable exposures from an attacker's perspective Experience working with internet-facing protocols and data sources (e.g. DNS, HTTP, TLS, certificate transparency, scanning datasets) to identify patterns, relationships, and anomalies The Cyber Operations team: Cyber Operations is responsible for protecting BAE Systems from Cyber Attack by various threat actors. Not only do we protect BAE Systems and its employees, indirectly we protect those who protect us - who serve in our military and rely on the products and services we create across Threat Intelligence, Detection, Incident Response and now Active Defence we work to evolve cyber operations as a world class capability. Why BAE Systems? Here you'll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work - this is a place where you can grow your career with confidence and be empowered to be your best. You'll be recognised for your contribution and enjoy rewards tailored to what's most important to you and your family - support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make. A place where everyone can thrive: We're committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role , to allow for meaningful security vetting checks. Closing Date: 14th July 2026 We reserve the right to close this vacancy early if we receive sufficient applications for the role . Therefore, if you are interested, please submit your application as early as possible.
10/07/2026
Full time
Job Title: External Attack Surface Management Analyst Job Location: Preston or Frimley - Hybrid-2 days a month onsite. We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Circa £45,000 depending on skills and experience Who we are: Join BAE Systems and you'll be part of something bigger. As a valued member of our global colleague network, you'll bring your unique skills and perspectives to help pioneer progress and protect what matters most. You'll be trusted to play your part in delivering the advanced, technology-led defence, aerospace and security solutions of tomorrow - shaping a safer future, for all of us. Role Description: Working within Cyber Operations, you will help safeguard BAE Systems against evolving cyber threats by supporting and enhancing the External Attack Surface Management (EASM) capability across people, process, and technology. You will contribute to an intelligence-led approach to cyber operations, ensuring external assets are identified, assessed, and continuously tested. The role supports detection assurance by identifying shadow IT and unmanaged exposures, providing confidence to leadership that security controls and monitoring capabilities are effective and aligned to organisational security standards. Core Duties: Proactively discover, track, and maintain visibility of external attack surface assets, including unknown and shadow IT exposures Investigate and validate externally visible exposures, assessing real-world risk, attacker relevance, and exploitability Monitor changes in external exposure, identifying new assets, regressions, and emerging risks across the estate Collaborate with Threat Intelligence and Cyber Operations to align exposure findings with attacker activity and remediation priorities Produce clear, actionable reporting on external exposures, trends, and security posture to support risk reduction and decision -making Essential Skills: Good understanding of external reconnaissance techniques, OSINT, and how attackers identify and profile internet-facing assets Proven experience in attack surface discovery, asset enumeration, and identifying unknown or shadow IT exposures Good investigative mindset with the ability to analyse incomplete or ambiguous external data and determine genuine security risk Ability to assess and distinguish between observed external artefacts, misconfigurations, and true exploitable exposures from an attacker's perspective Experience working with internet-facing protocols and data sources (e.g. DNS, HTTP, TLS, certificate transparency, scanning datasets) to identify patterns, relationships, and anomalies The Cyber Operations team: Cyber Operations is responsible for protecting BAE Systems from Cyber Attack by various threat actors. Not only do we protect BAE Systems and its employees, indirectly we protect those who protect us - who serve in our military and rely on the products and services we create across Threat Intelligence, Detection, Incident Response and now Active Defence we work to evolve cyber operations as a world class capability. Why BAE Systems? Here you'll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work - this is a place where you can grow your career with confidence and be empowered to be your best. You'll be recognised for your contribution and enjoy rewards tailored to what's most important to you and your family - support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make. A place where everyone can thrive: We're committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role , to allow for meaningful security vetting checks. Closing Date: 14th July 2026 We reserve the right to close this vacancy early if we receive sufficient applications for the role . Therefore, if you are interested, please submit your application as early as possible.
Staff Platform Engineer - Platform Engineering (UK & Ireland)
Fanatics Inc
Overview Fanatics Betting & Gaming (FBG) is seeking a Staff Platform Engineer to join our Platform Engineering team based in the UK or Ireland. This position plays a critical role within the EMEA Platform Engineering organization, partnering closely with teams across the UK, Ireland, and United States to build and operate the platforms that power Fanatics Betting & Gaming's global software ecosystem. As a Staff Engineer, you will operate with a high degree of autonomy and ownership, leading complex technical initiatives across cloud infrastructure, Kubernetes platforms, CI/CD systems, and internal developer tooling. You will influence platform architecture, define standards and best practices, and act as a force multiplier for engineering teams by improving reliability, scalability, and developer productivity. What You'll Do Help drive technical design and delivery of core platform capabilities spanning cloud infrastructure, Kubernetes platforms, Observability, CI/CD systems, and developer tooling Architect, build, and operate cloud-native platforms on AWS with a focus on reliability, security, scalability, and cost efficiency Lead the evolution of CI/CD pipelines and GitOps-based workflows Build and maintain internal platform services and tooling that improve developer experience and delivery velocity Continue to drive Infrastructure as Code and automation practices across teams Partner with application teams to unblock delivery and align platform capabilities with developer needs Participate in and/or lead complex, cross-team initiatives and provide technical clarity in ambiguous problem spaces Improve operational excellence through observability, automation, and incident response Mentor engineers and participate in on-call rotations What You Bring 8+ years of experience in platform, infrastructure, DevOps, or software engineering Proficiency with Python and Java. Familiarity with Kotlin, Go a plus Deep Kubernetes and container orchestration knowledge Proven CI/CD and GitOps experience Infrastructure as Code expertise (Terraform) Strong AWS and cloud-native experience Experience operating distributed, high-availability systems Ability to influence without authority and communicate effectively across regions Nice to Have Experience with internal developer platforms or portals FinOps or cloud cost management experience Regulated or high-availability environment experience Backend development experience Familiarity with AI-assisted development tools Why Platform Engineering at FBG Platform Engineering at FBG operates with a product-first mindset. Our mission is to empower developers with reliable, scalable, and intuitive platforms that accelerate innovation and delivery. Working Across Regions This role operates in a globally distributed environment, working closely with teams across the UK, Ireland, and the United States. Strong communication, time zone coordination, and shared ownership are essential for success. Travel Expectations Periodic travel to the United States is expected for offsites, planning sessions, and collaboration. Occasional travel within the UK and Ireland may also be required. Job Info Posting Date 01/20/2026, 04:02 PM Locations Richmond House, Leeds, LS16 6QY, GB (Remote)
10/07/2026
Full time
Overview Fanatics Betting & Gaming (FBG) is seeking a Staff Platform Engineer to join our Platform Engineering team based in the UK or Ireland. This position plays a critical role within the EMEA Platform Engineering organization, partnering closely with teams across the UK, Ireland, and United States to build and operate the platforms that power Fanatics Betting & Gaming's global software ecosystem. As a Staff Engineer, you will operate with a high degree of autonomy and ownership, leading complex technical initiatives across cloud infrastructure, Kubernetes platforms, CI/CD systems, and internal developer tooling. You will influence platform architecture, define standards and best practices, and act as a force multiplier for engineering teams by improving reliability, scalability, and developer productivity. What You'll Do Help drive technical design and delivery of core platform capabilities spanning cloud infrastructure, Kubernetes platforms, Observability, CI/CD systems, and developer tooling Architect, build, and operate cloud-native platforms on AWS with a focus on reliability, security, scalability, and cost efficiency Lead the evolution of CI/CD pipelines and GitOps-based workflows Build and maintain internal platform services and tooling that improve developer experience and delivery velocity Continue to drive Infrastructure as Code and automation practices across teams Partner with application teams to unblock delivery and align platform capabilities with developer needs Participate in and/or lead complex, cross-team initiatives and provide technical clarity in ambiguous problem spaces Improve operational excellence through observability, automation, and incident response Mentor engineers and participate in on-call rotations What You Bring 8+ years of experience in platform, infrastructure, DevOps, or software engineering Proficiency with Python and Java. Familiarity with Kotlin, Go a plus Deep Kubernetes and container orchestration knowledge Proven CI/CD and GitOps experience Infrastructure as Code expertise (Terraform) Strong AWS and cloud-native experience Experience operating distributed, high-availability systems Ability to influence without authority and communicate effectively across regions Nice to Have Experience with internal developer platforms or portals FinOps or cloud cost management experience Regulated or high-availability environment experience Backend development experience Familiarity with AI-assisted development tools Why Platform Engineering at FBG Platform Engineering at FBG operates with a product-first mindset. Our mission is to empower developers with reliable, scalable, and intuitive platforms that accelerate innovation and delivery. Working Across Regions This role operates in a globally distributed environment, working closely with teams across the UK, Ireland, and the United States. Strong communication, time zone coordination, and shared ownership are essential for success. Travel Expectations Periodic travel to the United States is expected for offsites, planning sessions, and collaboration. Occasional travel within the UK and Ireland may also be required. Job Info Posting Date 01/20/2026, 04:02 PM Locations Richmond House, Leeds, LS16 6QY, GB (Remote)
Planet Recruitment
3rd Line Engineer - MSP
Planet Recruitment Southmoor, Oxfordshire
Position: 3rd Line Engineer Location: Milton Park Salary: 38k-44k Hybrid: - 2 days per week in office Benefits 25+ Days Holiday and rising (plus bank holidays) Flexible working (WFH incentives) Bupa Cash Plan Electric Vehicle Scheme Cycle Scheme Discounted Gym Membership Paid Charity Day Car Parking Come and work for one of the UK's leading technology specialists, proudly recognised as a World Class Place to Work by Best Companies, a nationally respected benchmark for employee engagement and workplace excellence. We were also ranked as the Technology Company to Work For in the UK, reflecting our culture, our people, and our commitment to being an employer of choice. Primary Purpose: The Tier 3 team are tasked with handling the senior escalation of cases raised to the Service Delivery department. In addition, a successful applicant for the role of a Tier 3 engineer, in addition to being a highly skilled generalist, will be expected to pursue at least one line of specialisation within our supported baselines (Security, Backup & Disaster Recovery, Networking, Cloud Infrastructure etc.) Key Responsibilities Key Responsibilities: Manage incident and request tickets ensuring established SLA's are met. Being the first point of contact for escalations from Tier 2 engineers. Ensure all support requests/alerts are logged and that the client remains updated throughout the lifecycle of the request. Monitor and maintain client's Infrastructure and systems. Proactively respond to monitoring alerts and notifications. Servicing tasks within client on/offboarding processes. Ensuring that all role specific KPI's and targets are met as an individual and as a part of the wider team objectives. Providing a strong, coherent and proactive communication standard when engaging with internal departments. Providing a strong, coherent and proactive communication standard when engaging with current and prospective clients. Person Specification: Minimum: Experience with Microsoft Azure (Virtual Servers, Backup & Disaster Recovery, Networking, AVD, Hybrid deployments). Experience with current generation security technologies and services (AV, firewalls, CA policies, RBAC, managed threat response, identity threat, mail & web filter systems). Experience working with Backup & Disaster Recovery processes. Experience with internal networking infrastructure and management (DHCP, DNS, NPS/RADIUS, managed/unmanaged switches, firewalls, wireless, VPN technologies). Experience with cloud led identity/management/policy systems (Intune, Entra, ABM) Experience with physical and hybrid hypervisor technologies (VMWare, Hyper-V) Experience with Microsoft Server OS (management, maintenance, administrative tooling and deployment). Excellent knowledge of scripting and RPA automations Excellent communication skills. Excellent troubleshooting and problem resolution skills. Excellent client service. Strive to continuous improvement Able to work independently under pressure Minimum of 4 years' IT experience in a corporate or services environment Driving license and own transport essential Desirable: Experience or certification in any of the following technologies Watchguard, FortiGate, Sophos, Smoothwall firewalls Sophos Anti-Virus HPE/Aruba, Cisco, Dell, Unifi switching VMWare ESXI & Microsoft Hyper-V Microsoft Azure Apple Business Manager Google Workspace Ubiquiti, Meraki wireless Mimecast, Barracuda mail filtering Veeam, Datto, Acronis, Barracuda backup & disaster recovery INDIT Planet Recruitment acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers. Planet Recruitment is an Equal Opportunities Employer. By applying for this role your details will be submitted to Planet Recruitment. Our Candidate Privacy Information Statement explains how we will use your information. Only candidates with the relevant skills and experience will be contacted after application, if you do not hear back from us within 7 days you have unfortunately been unsuccessful in your application. Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and abilities to perform the duties of the position.
10/07/2026
Full time
Position: 3rd Line Engineer Location: Milton Park Salary: 38k-44k Hybrid: - 2 days per week in office Benefits 25+ Days Holiday and rising (plus bank holidays) Flexible working (WFH incentives) Bupa Cash Plan Electric Vehicle Scheme Cycle Scheme Discounted Gym Membership Paid Charity Day Car Parking Come and work for one of the UK's leading technology specialists, proudly recognised as a World Class Place to Work by Best Companies, a nationally respected benchmark for employee engagement and workplace excellence. We were also ranked as the Technology Company to Work For in the UK, reflecting our culture, our people, and our commitment to being an employer of choice. Primary Purpose: The Tier 3 team are tasked with handling the senior escalation of cases raised to the Service Delivery department. In addition, a successful applicant for the role of a Tier 3 engineer, in addition to being a highly skilled generalist, will be expected to pursue at least one line of specialisation within our supported baselines (Security, Backup & Disaster Recovery, Networking, Cloud Infrastructure etc.) Key Responsibilities Key Responsibilities: Manage incident and request tickets ensuring established SLA's are met. Being the first point of contact for escalations from Tier 2 engineers. Ensure all support requests/alerts are logged and that the client remains updated throughout the lifecycle of the request. Monitor and maintain client's Infrastructure and systems. Proactively respond to monitoring alerts and notifications. Servicing tasks within client on/offboarding processes. Ensuring that all role specific KPI's and targets are met as an individual and as a part of the wider team objectives. Providing a strong, coherent and proactive communication standard when engaging with internal departments. Providing a strong, coherent and proactive communication standard when engaging with current and prospective clients. Person Specification: Minimum: Experience with Microsoft Azure (Virtual Servers, Backup & Disaster Recovery, Networking, AVD, Hybrid deployments). Experience with current generation security technologies and services (AV, firewalls, CA policies, RBAC, managed threat response, identity threat, mail & web filter systems). Experience working with Backup & Disaster Recovery processes. Experience with internal networking infrastructure and management (DHCP, DNS, NPS/RADIUS, managed/unmanaged switches, firewalls, wireless, VPN technologies). Experience with cloud led identity/management/policy systems (Intune, Entra, ABM) Experience with physical and hybrid hypervisor technologies (VMWare, Hyper-V) Experience with Microsoft Server OS (management, maintenance, administrative tooling and deployment). Excellent knowledge of scripting and RPA automations Excellent communication skills. Excellent troubleshooting and problem resolution skills. Excellent client service. Strive to continuous improvement Able to work independently under pressure Minimum of 4 years' IT experience in a corporate or services environment Driving license and own transport essential Desirable: Experience or certification in any of the following technologies Watchguard, FortiGate, Sophos, Smoothwall firewalls Sophos Anti-Virus HPE/Aruba, Cisco, Dell, Unifi switching VMWare ESXI & Microsoft Hyper-V Microsoft Azure Apple Business Manager Google Workspace Ubiquiti, Meraki wireless Mimecast, Barracuda mail filtering Veeam, Datto, Acronis, Barracuda backup & disaster recovery INDIT Planet Recruitment acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers. Planet Recruitment is an Equal Opportunities Employer. By applying for this role your details will be submitted to Planet Recruitment. Our Candidate Privacy Information Statement explains how we will use your information. Only candidates with the relevant skills and experience will be contacted after application, if you do not hear back from us within 7 days you have unfortunately been unsuccessful in your application. Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and abilities to perform the duties of the position.
Starling Bank
Information Security Analyst - Cyber Threat Intelligence - 12 month FTC
Starling Bank
About the Role As a Cyber Threat Intelligence (CTI) analyst at Starling Bank you will be joining an established team covering all aspects of the cyber threat intelligence domain. The role is collaborative and you will be required to not only work individually but also collaborate with both internal and external stakeholders. As a member of the Cyber Threat Intelligence team you will be working with like-minded individuals with a passion for CTI in order to protect the bank from internal and external threats. Being a member of the CTI team, you will gain a strong understanding of the cyber threats to banking and FinTech not only in the UK but globally. Working with key stakeholders throughout the Bank, your research and analysis will lead to tangible security improvements. A successful candidate will be responsible for tracking and monitoring threats in an assigned thematic area with research contributing to the overall safety of the Bank and its entities as well as creating tactical and operational reporting, delivering presentations, and maintaining relationships with internal and external stakeholders. Important Note: This is a temporary position, expected to last approximately 12 months (with consideration of extension if required), covering a period of maternity leave. Hybrid Working: We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. What you'll be doing Maintain and stay abreast with the current understanding of the cyber threat landscape with a focus on the fintech sector Monitor and maintain awareness of assigned thematic areas, such as Nation State threat groups and Cybercrime focussed groups. Execute and produce written reports and provide verbal threat briefings that capture the relevance of external threats to Starling Bank or the Financial Industry Alert triage from CTI platforms, information sharing groups, and internal escalations Engage with industry peers to enable and strengthen Starling's security posture Support key stakeholders with contextualised threat analysis and recommendations We're open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. Ideally, we would like from you: Experience in a CTI team or information security experience with knowledge of the CTI process Ability to execute all areas of the intelligence cycle through triage, analyse and response to alerts generated via technology platforms Articulate with strong written communication skills A problem solver with ability to conduct thorough research and analysis Building effective relationships with internal and external stakeholders Ability to support the incident response process and collaborate with both technical and non-technical stakeholders Understand threat actors, tactics techniques and procedures (TTPs) whilst providing the so what for Starling and its environment A desire to learn, and the ability to apply technical security knowledge to new and unfamiliar areas CTI related qualifications, certifications (GCTI, CREST) or equivalent industry experience would be advantageous, but not essential. Interview Process Initial screening call with Recruiter - 30 minutes 1st interview with Information Security team - 60 minutes Presentation & Q&A - 45 minutes Final Interview - 45 minutes 25 days holiday (plus take your public holiday allowance whenever works best for you) An extra day's holiday for your birthday Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off 16 hours paid volunteering time a year Salary sacrifice, company enhanced pension scheme Life insurance at 4x your salary & group income protection Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr & Mrs Smith and Peloton Generous family-friendly policies Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing About us Starling Bank is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law. When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Starling Bank may collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we may process, where we may process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.
10/07/2026
Full time
About the Role As a Cyber Threat Intelligence (CTI) analyst at Starling Bank you will be joining an established team covering all aspects of the cyber threat intelligence domain. The role is collaborative and you will be required to not only work individually but also collaborate with both internal and external stakeholders. As a member of the Cyber Threat Intelligence team you will be working with like-minded individuals with a passion for CTI in order to protect the bank from internal and external threats. Being a member of the CTI team, you will gain a strong understanding of the cyber threats to banking and FinTech not only in the UK but globally. Working with key stakeholders throughout the Bank, your research and analysis will lead to tangible security improvements. A successful candidate will be responsible for tracking and monitoring threats in an assigned thematic area with research contributing to the overall safety of the Bank and its entities as well as creating tactical and operational reporting, delivering presentations, and maintaining relationships with internal and external stakeholders. Important Note: This is a temporary position, expected to last approximately 12 months (with consideration of extension if required), covering a period of maternity leave. Hybrid Working: We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. What you'll be doing Maintain and stay abreast with the current understanding of the cyber threat landscape with a focus on the fintech sector Monitor and maintain awareness of assigned thematic areas, such as Nation State threat groups and Cybercrime focussed groups. Execute and produce written reports and provide verbal threat briefings that capture the relevance of external threats to Starling Bank or the Financial Industry Alert triage from CTI platforms, information sharing groups, and internal escalations Engage with industry peers to enable and strengthen Starling's security posture Support key stakeholders with contextualised threat analysis and recommendations We're open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. Ideally, we would like from you: Experience in a CTI team or information security experience with knowledge of the CTI process Ability to execute all areas of the intelligence cycle through triage, analyse and response to alerts generated via technology platforms Articulate with strong written communication skills A problem solver with ability to conduct thorough research and analysis Building effective relationships with internal and external stakeholders Ability to support the incident response process and collaborate with both technical and non-technical stakeholders Understand threat actors, tactics techniques and procedures (TTPs) whilst providing the so what for Starling and its environment A desire to learn, and the ability to apply technical security knowledge to new and unfamiliar areas CTI related qualifications, certifications (GCTI, CREST) or equivalent industry experience would be advantageous, but not essential. Interview Process Initial screening call with Recruiter - 30 minutes 1st interview with Information Security team - 60 minutes Presentation & Q&A - 45 minutes Final Interview - 45 minutes 25 days holiday (plus take your public holiday allowance whenever works best for you) An extra day's holiday for your birthday Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off 16 hours paid volunteering time a year Salary sacrifice, company enhanced pension scheme Life insurance at 4x your salary & group income protection Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr & Mrs Smith and Peloton Generous family-friendly policies Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing About us Starling Bank is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law. When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Starling Bank may collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we may process, where we may process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.
Ryder Reid Legal Ltd
Applications Operations Analyst
Ryder Reid Legal Ltd
Applications Operations Analyst We are working with a leading global professional services organisation, renowned for partnering with some of the world's most high-profile businesses on complex, high-impact work. With a strong international presence and a reputation for excellence, they offer a collaborative and fast-paced environment where innovation and continuous improvement are key. They are now looking to hire an Applications Operations Analyst to join their London-based team. The Role This position sits within the Applications Operations team and plays a key role in ensuring the stability, performance, and security of enterprise application environments. You'll be responsible for the day-to-day support, maintenance, and optimisation of business-critical systems, while also contributing to ongoing improvements, automation, and process efficiencies. Key Responsibilities Perform system maintenance, patching, and upgrades in line with change management processes Manage user access (provisioning, de-provisioning, and access reviews) Monitor system performance and proactively address issues Respond to incidents and service requests, ensuring SLA adherence Troubleshoot and resolve application issues, conducting root cause analysis Support system configurations, integrations, and deployments Partner with Information Security to remediate vulnerabilities and support audits Contribute to post-incident reviews and continuous improvement initiatives Maintain documentation, runbooks, and knowledge base articles Track and report on KPIs, including system performance and ticket trends Identify opportunities for automation and process optimisation Support application performance tuning and capacity planning Collaborate with infrastructure and delivery teams to ensure scalability and resilience Monitor system usage and adoption, providing insights to improve user engagement About You 3+ years' experience in enterprise application support or IT operations Strong understanding of ITSM tools (e.g. ServiceNow) and monitoring platforms Knowledge of access management, patching, and vulnerability remediation Familiarity with ITIL processes (Incident, Problem, Change, Configuration) Excellent troubleshooting and analytical skills Strong communication skills and ability to work collaboratively Experience maintaining documentation and knowledge bases Desirable: Experience within legal, financial, or professional services environments Exposure to cloud platforms or scripting (e.g. PowerShell, Python) ITIL Foundation or similar certification What's on Offer The opportunity to join a globally respected organisation A collaborative and supportive team environment Exposure to complex systems and enterprise-scale technology Hybrid working model (minimum 3 days in-office) Competitive salary and benefits package If you're looking to build your career in a high-performing environment where you can make a tangible impact, we'd love to hear from you. Due to the high volume of applications, we are not able to respond to all enquiries. If you have not received a response within 72 hours, please assume you have not been shortlisted at this stage, however thank you for taking the time to apply. Ryder Reid Legal is a recruitment specialist. For over thirty years we've been connecting legal talent with many of the leading law firms in London and internationally. Follow our LinkedIn page for the latest vacancies.
10/07/2026
Full time
Applications Operations Analyst We are working with a leading global professional services organisation, renowned for partnering with some of the world's most high-profile businesses on complex, high-impact work. With a strong international presence and a reputation for excellence, they offer a collaborative and fast-paced environment where innovation and continuous improvement are key. They are now looking to hire an Applications Operations Analyst to join their London-based team. The Role This position sits within the Applications Operations team and plays a key role in ensuring the stability, performance, and security of enterprise application environments. You'll be responsible for the day-to-day support, maintenance, and optimisation of business-critical systems, while also contributing to ongoing improvements, automation, and process efficiencies. Key Responsibilities Perform system maintenance, patching, and upgrades in line with change management processes Manage user access (provisioning, de-provisioning, and access reviews) Monitor system performance and proactively address issues Respond to incidents and service requests, ensuring SLA adherence Troubleshoot and resolve application issues, conducting root cause analysis Support system configurations, integrations, and deployments Partner with Information Security to remediate vulnerabilities and support audits Contribute to post-incident reviews and continuous improvement initiatives Maintain documentation, runbooks, and knowledge base articles Track and report on KPIs, including system performance and ticket trends Identify opportunities for automation and process optimisation Support application performance tuning and capacity planning Collaborate with infrastructure and delivery teams to ensure scalability and resilience Monitor system usage and adoption, providing insights to improve user engagement About You 3+ years' experience in enterprise application support or IT operations Strong understanding of ITSM tools (e.g. ServiceNow) and monitoring platforms Knowledge of access management, patching, and vulnerability remediation Familiarity with ITIL processes (Incident, Problem, Change, Configuration) Excellent troubleshooting and analytical skills Strong communication skills and ability to work collaboratively Experience maintaining documentation and knowledge bases Desirable: Experience within legal, financial, or professional services environments Exposure to cloud platforms or scripting (e.g. PowerShell, Python) ITIL Foundation or similar certification What's on Offer The opportunity to join a globally respected organisation A collaborative and supportive team environment Exposure to complex systems and enterprise-scale technology Hybrid working model (minimum 3 days in-office) Competitive salary and benefits package If you're looking to build your career in a high-performing environment where you can make a tangible impact, we'd love to hear from you. Due to the high volume of applications, we are not able to respond to all enquiries. If you have not received a response within 72 hours, please assume you have not been shortlisted at this stage, however thank you for taking the time to apply. Ryder Reid Legal is a recruitment specialist. For over thirty years we've been connecting legal talent with many of the leading law firms in London and internationally. Follow our LinkedIn page for the latest vacancies.
Security GRC Manager
Humaans
About us Humaans is building the next generation of infrastructure for the workplace; software designed for companies that are scaling fast, operating globally, and pushing into new boundaries. What started as a system of record has evolved into a broader platform for operating people globally. With Athena, our agentic AI layer, Humaans moves beyond data management into intelligent orchestration, connecting workflows across HR, IT, Finance, and Operations so organisations can act faster and with greater confidence, redefining how work gets done. We work with ambitious teams across Europe and the US, from AI-native companies like Lovable, Poolside, Fyxer AI, and Tandem Health, to established, high-growth organisations scaling internationally and through acquisition, including Quantexa, Sellpy, Manychat, Gigs, Croud, and Threecolts. These teams don't buy software for features, they buy leverage. The ability to run faster, cleaner, and with more control as complexity compounds. To date, we've raised $20m in venture funding from some of the most respected founders, operators, and funds in technology: Lachy Groom (Physical Intelligence), Stewart Butterfield (Slack), Tobias Lütke (Shopify), Dylan Field (Figma), Jeff Weiner (LinkedIn), Claire Johnson (Stripe), Oliver Jay (OpenAI), Jay Simmons (Bond) as well as Y Combinator, Moonfire, Frontline Ventures, Pathlight Ventures, and Exor. If you have massive ambition and want to work on a hard problem, with a small team that moves fast, at a moment when the category is genuinely up for grabs - this is it. We're looking for a Security GRC Manager - Trust and Compliance, to own the systems, processes, audits, and customer facing trust work that help Humaans scale into more demanding markets. This is a hands on ownership role, built around AI. You'll run our security compliance programme throughout the year, not just during audit season. AI is how the work gets done here. It drafts policies, speeds up questionnaire responses, and keeps evidence current. You already use these tools daily and know how to get real leverage from them. You'll own the operating rhythm for frameworks like ISO 27001, SOC 1, SOC 2, HIPAA and future standards that matter to our customers. You'll keep evidence organised, controls running, policies up to date, vendors reviewed, risks visible, and audits moving smoothly. You'll also be close to revenue. You'll support Sales and Customer Success on security and compliance questions, help complete vendor security questionnaire, maintain reusable trust materials, and make sure enterprise buyers get accurate, fast, confidence building answers. This role sits at the intersection of Security, Legal, Product, Engineering, Revenue, and Operations. You don't need to be the person configuring every system yourself, but you do need to understand how modern SaaS companies operate, ask sharp questions, drive action across teams, and keep the bar high. Focus / Ownership You'll own Humaans' security compliance programme end to end, including ISO, SOC 1, SOC 2, HIPAA and future frameworks we choose to pursue. You'll manage audit cycles throughout the year, coordinating with external auditors, internal control owners, Engineering, People, Legal, Finance and Operations. You'll maintain the controls, evidence, policies, risk register, access reviews, vendor reviews, business continuity processes, and incident response documentation that support our certifications and customer commitments. AI drafts and updates these artefacts and keeps evidence current year round, not only at audit time. You'll support customer facing trust work, including sales calls, security reviews, procurement processes, vendor questionnaire, RFPs, DPAs, subprocessors, data protection questions, and enterprise diligence. You'll build AI assisted systems for answering repeated security questions quickly and accurately. The answer bank drafts responses. Trust collateral stays current. A review process holds quality as volume scales. You'll work with Product and Engineering to translate compliance requirements into practical operational controls without slowing the company down unnecessarily. You'll help the company make clear, risk based decisions, escalating when something matters and cutting through noise when it doesn't. You'll raise the maturity of how Humaans thinks about security, privacy, risk, and customer trust as we move upmarket. Requirements You have 4+ years of experience in security compliance, GRC, trust, audit, information security, privacy operations, or a closely related role. You've run or supported audits for frameworks such as SOC 2, ISO 27001, SOC 1, HIPAA, GDPR, or similar. You've used AI in security or compliance work and can speak to what you built and the outcome. Think drafting policies, speeding up questionnaire responses, or reviewing vendor documentation. You understand how modern B2B SaaS companies work, including cloud infrastructure, access management, vendor management, product development, customer data, and enterprise sales processes. You're comfortable being customer facing. You can join a sales call, answer security questions clearly, and give buyers confidence. You're strong at written communication. You can produce crisp policies, questionnaire responses, audit narratives, and internal guidance that people actually understand. You're organised and detail oriented. You can keep evidence, control owners, audit timelines, and customer commitments moving without dropping things. You're pragmatic. You know the difference between meaningful risk reduction and compliance theatre. You can work across teams and hold a high bar without becoming a blocker. You're excited by a high growth, high ownership environment where the playbook is still being written. Nice to have Experience in HR tech, fintech, healthtech, infrastructure, or another category where customer data and enterprise trust are central. Experience with security compliance platforms such as Vanta, Drata, Secureframe, Sprinto or similar. Experience reviewing DPAs, subprocessors, data residency questions, privacy documentation, and vendor contracts in partnership with Legal. Familiarity with US healthcare or HIPAA requirements. Experience building a trust centre, customer facing security portal, or security questionnaire answer library. Experience supporting enterprise sales, procurement, RFPs, or security reviews. What success looks like Within your first 90 days, you'll understand our current compliance posture, audit calendar, control owners, customer trust materials, and major gaps. Within six months, you'll have improved the operating rhythm of our compliance programme, reduced friction in sales security reviews, and made audits feel more predictable. Within twelve months, Humaans will have a more scalable trust function: stronger evidence, better controls, faster questionnaire turnaround, clearer ownership, and a security compliance programme that helps us win larger customers. This is an in person role. Our team comes together in the office Monday through Thursday, while most of the team collaborates in person on Mondays, Tuesdays, and Thursdays. Package & Benefits Early stage startups can be messy - we know that. We're putting effort in providing you with the best employee experience and a quality driven environment in exchange for trusting us. Market leading compensation that reflects your value 25 days paid time off each year plus public holidays Share Options with 5 year exercise window so you don't feel pressure to exercise if you leave Free Thursday lunches at HQ, quarterly team events, and company offsites. Top tier private coverage for health, vision and dental care A new MacBook and tools you need to do your best work Enhanced parental leave with up to 16 weeks for primary and 4 weeks for secondary Learning & development budget Why Join Humaans Today? HR tech is having its AI moment and we're positioned to own it. Humaans started as a next gen HRIS taking on large incumbents in a massive market. We've since evolved into something even bigger: an AI platform that sits across workforce data and automates the operational layer of HR entirely; the natural progression of what we've been building toward. The product is highly differentiated. It's built around a structured workforce data model that makes AI reliable in an HR context, something no one else has gotten right. Customers notice the difference immediately. We're backed by Y Combinator, Lachy Groom, Moonfire, Frontline Ventures, and operators who've built some of the most consequential software companies of the last decade: the founders of Slack, Figma, and Shopify, and Asana's former CRO and Head of OpenAI International. We're a small team with an unapologetically high bar. It shows up in the product, in how we communicate, and in the standards we hold each other to. Our Commitment to Diversity At Humaans we're looking for genuinely good people that are transparent and emphatic. We're committed to providing equal opportunities, a diverse and inclusive work environment, and ensuring a fair interview process for everyone. You're welcome to apply no matter your gender, ethnicity, sexual orientation, religion, civil or family status, age, disability, or race. Privacy notice We care about your privacy. When you apply for a role at Humaans, we'll collect and process your personal data as part of our recruitment process. This includes things like your CV, contact details . click apply for full job details
10/07/2026
Full time
About us Humaans is building the next generation of infrastructure for the workplace; software designed for companies that are scaling fast, operating globally, and pushing into new boundaries. What started as a system of record has evolved into a broader platform for operating people globally. With Athena, our agentic AI layer, Humaans moves beyond data management into intelligent orchestration, connecting workflows across HR, IT, Finance, and Operations so organisations can act faster and with greater confidence, redefining how work gets done. We work with ambitious teams across Europe and the US, from AI-native companies like Lovable, Poolside, Fyxer AI, and Tandem Health, to established, high-growth organisations scaling internationally and through acquisition, including Quantexa, Sellpy, Manychat, Gigs, Croud, and Threecolts. These teams don't buy software for features, they buy leverage. The ability to run faster, cleaner, and with more control as complexity compounds. To date, we've raised $20m in venture funding from some of the most respected founders, operators, and funds in technology: Lachy Groom (Physical Intelligence), Stewart Butterfield (Slack), Tobias Lütke (Shopify), Dylan Field (Figma), Jeff Weiner (LinkedIn), Claire Johnson (Stripe), Oliver Jay (OpenAI), Jay Simmons (Bond) as well as Y Combinator, Moonfire, Frontline Ventures, Pathlight Ventures, and Exor. If you have massive ambition and want to work on a hard problem, with a small team that moves fast, at a moment when the category is genuinely up for grabs - this is it. We're looking for a Security GRC Manager - Trust and Compliance, to own the systems, processes, audits, and customer facing trust work that help Humaans scale into more demanding markets. This is a hands on ownership role, built around AI. You'll run our security compliance programme throughout the year, not just during audit season. AI is how the work gets done here. It drafts policies, speeds up questionnaire responses, and keeps evidence current. You already use these tools daily and know how to get real leverage from them. You'll own the operating rhythm for frameworks like ISO 27001, SOC 1, SOC 2, HIPAA and future standards that matter to our customers. You'll keep evidence organised, controls running, policies up to date, vendors reviewed, risks visible, and audits moving smoothly. You'll also be close to revenue. You'll support Sales and Customer Success on security and compliance questions, help complete vendor security questionnaire, maintain reusable trust materials, and make sure enterprise buyers get accurate, fast, confidence building answers. This role sits at the intersection of Security, Legal, Product, Engineering, Revenue, and Operations. You don't need to be the person configuring every system yourself, but you do need to understand how modern SaaS companies operate, ask sharp questions, drive action across teams, and keep the bar high. Focus / Ownership You'll own Humaans' security compliance programme end to end, including ISO, SOC 1, SOC 2, HIPAA and future frameworks we choose to pursue. You'll manage audit cycles throughout the year, coordinating with external auditors, internal control owners, Engineering, People, Legal, Finance and Operations. You'll maintain the controls, evidence, policies, risk register, access reviews, vendor reviews, business continuity processes, and incident response documentation that support our certifications and customer commitments. AI drafts and updates these artefacts and keeps evidence current year round, not only at audit time. You'll support customer facing trust work, including sales calls, security reviews, procurement processes, vendor questionnaire, RFPs, DPAs, subprocessors, data protection questions, and enterprise diligence. You'll build AI assisted systems for answering repeated security questions quickly and accurately. The answer bank drafts responses. Trust collateral stays current. A review process holds quality as volume scales. You'll work with Product and Engineering to translate compliance requirements into practical operational controls without slowing the company down unnecessarily. You'll help the company make clear, risk based decisions, escalating when something matters and cutting through noise when it doesn't. You'll raise the maturity of how Humaans thinks about security, privacy, risk, and customer trust as we move upmarket. Requirements You have 4+ years of experience in security compliance, GRC, trust, audit, information security, privacy operations, or a closely related role. You've run or supported audits for frameworks such as SOC 2, ISO 27001, SOC 1, HIPAA, GDPR, or similar. You've used AI in security or compliance work and can speak to what you built and the outcome. Think drafting policies, speeding up questionnaire responses, or reviewing vendor documentation. You understand how modern B2B SaaS companies work, including cloud infrastructure, access management, vendor management, product development, customer data, and enterprise sales processes. You're comfortable being customer facing. You can join a sales call, answer security questions clearly, and give buyers confidence. You're strong at written communication. You can produce crisp policies, questionnaire responses, audit narratives, and internal guidance that people actually understand. You're organised and detail oriented. You can keep evidence, control owners, audit timelines, and customer commitments moving without dropping things. You're pragmatic. You know the difference between meaningful risk reduction and compliance theatre. You can work across teams and hold a high bar without becoming a blocker. You're excited by a high growth, high ownership environment where the playbook is still being written. Nice to have Experience in HR tech, fintech, healthtech, infrastructure, or another category where customer data and enterprise trust are central. Experience with security compliance platforms such as Vanta, Drata, Secureframe, Sprinto or similar. Experience reviewing DPAs, subprocessors, data residency questions, privacy documentation, and vendor contracts in partnership with Legal. Familiarity with US healthcare or HIPAA requirements. Experience building a trust centre, customer facing security portal, or security questionnaire answer library. Experience supporting enterprise sales, procurement, RFPs, or security reviews. What success looks like Within your first 90 days, you'll understand our current compliance posture, audit calendar, control owners, customer trust materials, and major gaps. Within six months, you'll have improved the operating rhythm of our compliance programme, reduced friction in sales security reviews, and made audits feel more predictable. Within twelve months, Humaans will have a more scalable trust function: stronger evidence, better controls, faster questionnaire turnaround, clearer ownership, and a security compliance programme that helps us win larger customers. This is an in person role. Our team comes together in the office Monday through Thursday, while most of the team collaborates in person on Mondays, Tuesdays, and Thursdays. Package & Benefits Early stage startups can be messy - we know that. We're putting effort in providing you with the best employee experience and a quality driven environment in exchange for trusting us. Market leading compensation that reflects your value 25 days paid time off each year plus public holidays Share Options with 5 year exercise window so you don't feel pressure to exercise if you leave Free Thursday lunches at HQ, quarterly team events, and company offsites. Top tier private coverage for health, vision and dental care A new MacBook and tools you need to do your best work Enhanced parental leave with up to 16 weeks for primary and 4 weeks for secondary Learning & development budget Why Join Humaans Today? HR tech is having its AI moment and we're positioned to own it. Humaans started as a next gen HRIS taking on large incumbents in a massive market. We've since evolved into something even bigger: an AI platform that sits across workforce data and automates the operational layer of HR entirely; the natural progression of what we've been building toward. The product is highly differentiated. It's built around a structured workforce data model that makes AI reliable in an HR context, something no one else has gotten right. Customers notice the difference immediately. We're backed by Y Combinator, Lachy Groom, Moonfire, Frontline Ventures, and operators who've built some of the most consequential software companies of the last decade: the founders of Slack, Figma, and Shopify, and Asana's former CRO and Head of OpenAI International. We're a small team with an unapologetically high bar. It shows up in the product, in how we communicate, and in the standards we hold each other to. Our Commitment to Diversity At Humaans we're looking for genuinely good people that are transparent and emphatic. We're committed to providing equal opportunities, a diverse and inclusive work environment, and ensuring a fair interview process for everyone. You're welcome to apply no matter your gender, ethnicity, sexual orientation, religion, civil or family status, age, disability, or race. Privacy notice We care about your privacy. When you apply for a role at Humaans, we'll collect and process your personal data as part of our recruitment process. This includes things like your CV, contact details . click apply for full job details
Software Engineer, Platform
AI Chopping Block, Inc.
Role Overview Scale's rapidly growing Global Public Sector team is focused on using AI to address critical challenges facing the public sector around the world. Our core work consists of: Creating custom AI applications that will impact millions of citizens Generating high-quality training data for national LLMs Upskilling and advisory services to spread the impact of AI As a Production AI Ops Lead, you will design and develop the production lifecycle of full-stack AI applications, while supporting end-to-end system reliability, real-time inference observability, sovereign data orchestration, high-security software integration, and the resilient cloud infrastructure required for our international government partners. At Scale, we're not just building AI solutions-we're enabling the public sector to transform their operations and better serve citizens through cutting edge technology. If you're ready to shape the future of AI in the public sector and be a founding member of our team, we'd love to hear from you. You will: Own the production outcome: Take full accountability for the long term performance and reliability of AI use cases deployed across international government agencies. Ensure Full-Stack integrity: Oversee the end to end health of the platform, ensuring seamless integration between the AI core and all full stack components, from APIs to UI, to maintain a responsive and production ready environment. Scale the feedback loop: Build automated systems to monitor model performance and data drift across geographically dispersed environments, ensuring the right levels of reliability. Navigate global compliance: Manage the technical lifecycle within diverse regulatory frameworks. Incident command: Lead the response for production issues in mission critical environments, ensuring rapid resolution and building the guardrails to prevent them from happening again. Bridge the gap: Translate deep technical performance metrics into clear insights for senior international government officials. Drive product evolution: Partner with our Engineering and ML teams to ensure the lessons learned in the field directly influence the technical architecture and decisions of future use cases. Ideally, you have: Experience: 6+ years in a high impact technical role (SRE, FDE or MLOps) with experience in the public sector. Global perspective: Familiarity with international government security standards and the complexities of deploying sovereign AI. System architecture proficiency: Proven experience maintaining production grade applications with a deep understanding of the full request lifecycle connecting frontend/API layers to the backend and AI core. Modern AI Stack expertise: Proficiency in coding and the modern AI infrastructure, including Kubernetes, vector databases, agentic development, and LLM observability tools. Ownership: You treat every production deployment as your own. You race toward solving hard problems before the customer even sees them. Reliability: You understand that in the public sector, a model failure may be a risk to public safety or privacy. Customer communication: The ability to explain to a high ranking official why the performance of the system has degraded and how we are fixing it. PLEASE NOTE: Our policy requires a 90 day waiting period before reconsidering candidates for the same role. This allows us to ensure a fair and thorough evaluation of all applicants. We are proud to be an inclusive and equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability status, gender identity or Veteran status. We are committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. Please see the United States Department of Labor's Know Your Rights poster for additional information. We comply with the United States Department of Labor's Pay Transparency provision. We collect, retain and use personal data for our professional business purposes, including notifying you of job opportunities that may be of interest and sharing with our affiliates. We limit the personal data we collect to that which we believe is appropriate and necessary to manage applicants' needs, provide our services, and comply with applicable laws. Any information we collect in connection with your application will be treated in accordance with our internal policies and programs designed to protect personal data. Please see our privacy policy for additional information.
10/07/2026
Full time
Role Overview Scale's rapidly growing Global Public Sector team is focused on using AI to address critical challenges facing the public sector around the world. Our core work consists of: Creating custom AI applications that will impact millions of citizens Generating high-quality training data for national LLMs Upskilling and advisory services to spread the impact of AI As a Production AI Ops Lead, you will design and develop the production lifecycle of full-stack AI applications, while supporting end-to-end system reliability, real-time inference observability, sovereign data orchestration, high-security software integration, and the resilient cloud infrastructure required for our international government partners. At Scale, we're not just building AI solutions-we're enabling the public sector to transform their operations and better serve citizens through cutting edge technology. If you're ready to shape the future of AI in the public sector and be a founding member of our team, we'd love to hear from you. You will: Own the production outcome: Take full accountability for the long term performance and reliability of AI use cases deployed across international government agencies. Ensure Full-Stack integrity: Oversee the end to end health of the platform, ensuring seamless integration between the AI core and all full stack components, from APIs to UI, to maintain a responsive and production ready environment. Scale the feedback loop: Build automated systems to monitor model performance and data drift across geographically dispersed environments, ensuring the right levels of reliability. Navigate global compliance: Manage the technical lifecycle within diverse regulatory frameworks. Incident command: Lead the response for production issues in mission critical environments, ensuring rapid resolution and building the guardrails to prevent them from happening again. Bridge the gap: Translate deep technical performance metrics into clear insights for senior international government officials. Drive product evolution: Partner with our Engineering and ML teams to ensure the lessons learned in the field directly influence the technical architecture and decisions of future use cases. Ideally, you have: Experience: 6+ years in a high impact technical role (SRE, FDE or MLOps) with experience in the public sector. Global perspective: Familiarity with international government security standards and the complexities of deploying sovereign AI. System architecture proficiency: Proven experience maintaining production grade applications with a deep understanding of the full request lifecycle connecting frontend/API layers to the backend and AI core. Modern AI Stack expertise: Proficiency in coding and the modern AI infrastructure, including Kubernetes, vector databases, agentic development, and LLM observability tools. Ownership: You treat every production deployment as your own. You race toward solving hard problems before the customer even sees them. Reliability: You understand that in the public sector, a model failure may be a risk to public safety or privacy. Customer communication: The ability to explain to a high ranking official why the performance of the system has degraded and how we are fixing it. PLEASE NOTE: Our policy requires a 90 day waiting period before reconsidering candidates for the same role. This allows us to ensure a fair and thorough evaluation of all applicants. We are proud to be an inclusive and equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability status, gender identity or Veteran status. We are committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. Please see the United States Department of Labor's Know Your Rights poster for additional information. We comply with the United States Department of Labor's Pay Transparency provision. We collect, retain and use personal data for our professional business purposes, including notifying you of job opportunities that may be of interest and sharing with our affiliates. We limit the personal data we collect to that which we believe is appropriate and necessary to manage applicants' needs, provide our services, and comply with applicable laws. Any information we collect in connection with your application will be treated in accordance with our internal policies and programs designed to protect personal data. Please see our privacy policy for additional information.
InfoSec
AI Staff Security Engineer
InfoSec
About the Role We are seeking a versatile and senior AI Staff Security Engineer to serve as the linchpin of our security posture. You will be responsible for moving our organization toward a highly proactive security stance by engineering automated workflows that replace manual overhead. This role will be critical in managing the systemic risk of Shadow AI agentic frameworks and enforcing the principle of least privilege by leveraging configuration management to programmatically control software across the enterprise. You will secure our core AI-driven platforms and protect them from advanced threats. Key Responsibilities Augment the complete vulnerability management lifecycle to prioritize AI-centric risks, including supply chain attacks using tools for SBOM tracking, and targeting critical unpatched legacy infrastructure. Design, deploy, and operationalize AI Detection and Response (AIDR) solutions to protect proprietary models and systems from novel threats like prompt injection, data poisoning, and model inversion/extraction. Automate critical security workflows using Agentic/SIEM integration to achieve high operational velocity and enable rapid response to millisecond attack speeds generated by autonomous adversary AI. Execute regular offensive security operations, including AI Red Teaming and penetration testing of generative and agentic systems. Lead the defense against Shadow AI by developing and deploying AI access governance tools and enforcing strict adherence to our review process for all new tools. Drive security compliance and AI governance by aligning systems with frameworks like Google's SAIF and CSA's AICM, focusing on data privacy (GDPR/PII) and ethical AI principles. Enforce secure-by-design principles and integrate security checks into the continuous AI development lifecycle (CI/CD), ensuring coverage for all AI system testing pre and post-deployment. Present complex security concepts (e.g., prompt injection, model drift) to non-technical audiences to drive security awareness and culture across the broader organization. Required Qualifications Proven experience in offensive security, including AI Red Teaming/Penetration Testing against agentic frameworks and LLM integrations. Demonstrated ability to engineer or deploy AI Detection and Response (AIDR) workflows utilizing agentic and SIEM technologies, with a strong focus on AI-native threat modeling (e.g., MAESTRO framework). Understanding of Governance, Risk, and Compliance (GRC), specifically managing AI governance policies and enforcing the principle of least privilege for human and AI identities. Upper-Intermediate English fluency to ensure world-class communication. Strong presentation skills with the ability to translate technical security data for non-technical stakeholders. Ability to work in time zone alignment (EST/PST) to seamlessly integrate with cross-functional teams for agile project execution and incident response. A self-directed, passionate thinker dedicated to continuous innovation and modernized security solutions.
10/07/2026
Full time
About the Role We are seeking a versatile and senior AI Staff Security Engineer to serve as the linchpin of our security posture. You will be responsible for moving our organization toward a highly proactive security stance by engineering automated workflows that replace manual overhead. This role will be critical in managing the systemic risk of Shadow AI agentic frameworks and enforcing the principle of least privilege by leveraging configuration management to programmatically control software across the enterprise. You will secure our core AI-driven platforms and protect them from advanced threats. Key Responsibilities Augment the complete vulnerability management lifecycle to prioritize AI-centric risks, including supply chain attacks using tools for SBOM tracking, and targeting critical unpatched legacy infrastructure. Design, deploy, and operationalize AI Detection and Response (AIDR) solutions to protect proprietary models and systems from novel threats like prompt injection, data poisoning, and model inversion/extraction. Automate critical security workflows using Agentic/SIEM integration to achieve high operational velocity and enable rapid response to millisecond attack speeds generated by autonomous adversary AI. Execute regular offensive security operations, including AI Red Teaming and penetration testing of generative and agentic systems. Lead the defense against Shadow AI by developing and deploying AI access governance tools and enforcing strict adherence to our review process for all new tools. Drive security compliance and AI governance by aligning systems with frameworks like Google's SAIF and CSA's AICM, focusing on data privacy (GDPR/PII) and ethical AI principles. Enforce secure-by-design principles and integrate security checks into the continuous AI development lifecycle (CI/CD), ensuring coverage for all AI system testing pre and post-deployment. Present complex security concepts (e.g., prompt injection, model drift) to non-technical audiences to drive security awareness and culture across the broader organization. Required Qualifications Proven experience in offensive security, including AI Red Teaming/Penetration Testing against agentic frameworks and LLM integrations. Demonstrated ability to engineer or deploy AI Detection and Response (AIDR) workflows utilizing agentic and SIEM technologies, with a strong focus on AI-native threat modeling (e.g., MAESTRO framework). Understanding of Governance, Risk, and Compliance (GRC), specifically managing AI governance policies and enforcing the principle of least privilege for human and AI identities. Upper-Intermediate English fluency to ensure world-class communication. Strong presentation skills with the ability to translate technical security data for non-technical stakeholders. Ability to work in time zone alignment (EST/PST) to seamlessly integrate with cross-functional teams for agile project execution and incident response. A self-directed, passionate thinker dedicated to continuous innovation and modernized security solutions.
Elsevier
Cyber Security Business Information Officer (BISO)
Elsevier
.Cyber Security Business Information Officer (BISO) page is loaded Cyber Security Business Information Officer (BISO)locations: Oxford: Londontime type: Full timeposted on: Posted Todayjob requisition id: R112581 About Our Team The Business Information Security Office (BISO) team partners with business, product, and technology leaders to deliver measurable security outcomes that support enterprise objectives. We focus on managing complex risk, embedding secure by design practices, and driving long term cybersecurity maturity. Our work enables trusted innovation, operational resilience, and informed risk decision making across the organization. About the Role As a Business Information Security Officer (BISO), you act as the primary security partner for assigned business units, bridging business strategy and enterprise cybersecurity. You are accountable for planning and executing security initiatives that reduce risk, strengthen cyber defenses, and enable delivery at scale. The role is highly collaborative, advisory, and outcome focused-ensuring security is embedded early and pragmatically across products, platforms, and major initiatives. Responsibilities: Act as the primary security partner for assigned business units, building trusted senior stakeholder relationships. Embed security early into business initiatives, product development, and technology delivery. Sponsor and support enterprise and business aligned security initiatives end to end. Provide expert security guidance across concurrent IT, engineering, and business projects. Oversee security assessments including vulnerability management, penetration testing, and third party risk. Translate security findings into prioritized, actionable remediation plans with clear ownership. Provide security input into solution architecture and major technology decisions. Serve as the security point of contact for customer facing inquiries, audits, and due diligence. Identify, document, and govern cyber risks, supporting risk acceptance and escalation processes. Develop and report meaningful security metrics to inform leadership decisions and continuous improvement. Requirements: Several years' experience in a BISO or senior security leadership / advisory role. Strong cloud and application security experience (AWS, Azure, GCP; secure SDLC). Hands on knowledge of security tooling (SIEM, SOAR, EDR/XDR, CSPM, SAST/DAST). Experience embedding security into CI/CD pipelines and DevSecOps practices. Proven capability in risk assessments, threat modeling, and control gap analysis. Experience collaborating with SOC and Incident Response teams during security events. Working knowledge of security frameworks and regulations (NIST, ISO 27001, CIS, GDPR, etc.). Ability to translate technical risk into clear, business relevant language. Strong stakeholder management skills with the ability to influence without authority. Bachelor's degree in Engineering, Computer Science, or equivalent experience, plus relevant certifications (CISSP, CISM, GIAC, or similar). We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click to access benefits specific to your location. We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our or please contact 1-. Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams . Please read our .We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law. USA Job Seekers: .Elsevier is a global leader in advanced information and decision support for science and healthcare. We believe that by working together with the communities we serve, we can shape human progress to go further, happen faster, and benefit all.We support continuous discovery and uphold the highest standards of content integrity, reliability, and reproducibility so the communities we serve can advance their field of science, healthcare or innovation with confidence. By combining high-quality content with powerful analytics, we transform complexity into clarity and deliver mission-critical insights that help professionals make better decisions when it matters most.We deliver insights that help research institutions, governments, and funders achieve their goals. We help researchers discover and share knowledge, collaborate, and accelerate innovation. We help librarians provide verified, quality information to universities. We help innovators turn knowledge into new products. We help health professionals improve patient care and educators train the next generation of doctors and nurses. Connecting quality content and innovative technologies, we make progress go further and happen faster. And by championing inclusion and sustainability, we ensure progress benefits all.With 9,500 employees, over 2,300 technologists in 5 major tech hubs, and more than 60 locations across the globe, we are committed to supporting the scientific and healthcare communities around the world. We offer a diverse range of opportunities across technology, commercial, business, and early career jobs. If you are looking for a career that inspires progress in science, innovation and health, and allows you to grow every day, find your team at Elsevier.Elsevier is part of RELX Group.Let's shape progress together. Join
10/07/2026
Full time
.Cyber Security Business Information Officer (BISO) page is loaded Cyber Security Business Information Officer (BISO)locations: Oxford: Londontime type: Full timeposted on: Posted Todayjob requisition id: R112581 About Our Team The Business Information Security Office (BISO) team partners with business, product, and technology leaders to deliver measurable security outcomes that support enterprise objectives. We focus on managing complex risk, embedding secure by design practices, and driving long term cybersecurity maturity. Our work enables trusted innovation, operational resilience, and informed risk decision making across the organization. About the Role As a Business Information Security Officer (BISO), you act as the primary security partner for assigned business units, bridging business strategy and enterprise cybersecurity. You are accountable for planning and executing security initiatives that reduce risk, strengthen cyber defenses, and enable delivery at scale. The role is highly collaborative, advisory, and outcome focused-ensuring security is embedded early and pragmatically across products, platforms, and major initiatives. Responsibilities: Act as the primary security partner for assigned business units, building trusted senior stakeholder relationships. Embed security early into business initiatives, product development, and technology delivery. Sponsor and support enterprise and business aligned security initiatives end to end. Provide expert security guidance across concurrent IT, engineering, and business projects. Oversee security assessments including vulnerability management, penetration testing, and third party risk. Translate security findings into prioritized, actionable remediation plans with clear ownership. Provide security input into solution architecture and major technology decisions. Serve as the security point of contact for customer facing inquiries, audits, and due diligence. Identify, document, and govern cyber risks, supporting risk acceptance and escalation processes. Develop and report meaningful security metrics to inform leadership decisions and continuous improvement. Requirements: Several years' experience in a BISO or senior security leadership / advisory role. Strong cloud and application security experience (AWS, Azure, GCP; secure SDLC). Hands on knowledge of security tooling (SIEM, SOAR, EDR/XDR, CSPM, SAST/DAST). Experience embedding security into CI/CD pipelines and DevSecOps practices. Proven capability in risk assessments, threat modeling, and control gap analysis. Experience collaborating with SOC and Incident Response teams during security events. Working knowledge of security frameworks and regulations (NIST, ISO 27001, CIS, GDPR, etc.). Ability to translate technical risk into clear, business relevant language. Strong stakeholder management skills with the ability to influence without authority. Bachelor's degree in Engineering, Computer Science, or equivalent experience, plus relevant certifications (CISSP, CISM, GIAC, or similar). We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click to access benefits specific to your location. We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our or please contact 1-. Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams . Please read our .We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law. USA Job Seekers: .Elsevier is a global leader in advanced information and decision support for science and healthcare. We believe that by working together with the communities we serve, we can shape human progress to go further, happen faster, and benefit all.We support continuous discovery and uphold the highest standards of content integrity, reliability, and reproducibility so the communities we serve can advance their field of science, healthcare or innovation with confidence. By combining high-quality content with powerful analytics, we transform complexity into clarity and deliver mission-critical insights that help professionals make better decisions when it matters most.We deliver insights that help research institutions, governments, and funders achieve their goals. We help researchers discover and share knowledge, collaborate, and accelerate innovation. We help librarians provide verified, quality information to universities. We help innovators turn knowledge into new products. We help health professionals improve patient care and educators train the next generation of doctors and nurses. Connecting quality content and innovative technologies, we make progress go further and happen faster. And by championing inclusion and sustainability, we ensure progress benefits all.With 9,500 employees, over 2,300 technologists in 5 major tech hubs, and more than 60 locations across the globe, we are committed to supporting the scientific and healthcare communities around the world. We offer a diverse range of opportunities across technology, commercial, business, and early career jobs. If you are looking for a career that inspires progress in science, innovation and health, and allows you to grow every day, find your team at Elsevier.Elsevier is part of RELX Group.Let's shape progress together. Join
Stott and May
SAP Operations Manager - Service Delivery & Incident Management
Stott and May
SAP Operations Manager - Service Delivery & Incident Management Location: London Drive operational excellence behind world-class customer experiences. We are looking for an experienced SAP Operations Manager with a strong background in Service Delivery, Incident Management, and team leadership to join a prestigious brand. This is a high-impact role where you will take ownership of critical SAP platforms, ensuring stability, performance, and continuous improvement in a fast-paced, customer-centric environment. In this role, you will lead the end-to-end service operations lifecycle, from incident response and problem management to continuous service optimisation. You'll play a key role in building and scaling high-performing teams, embedding best-in-class ITIL practices, and ensuring a consistently high level of service delivery across the organisation. What You'll Do Own SAP service operations, ensuring high availability and performance across Customer Data Cloud, Data Platform, Sales & Service Cloud, and Marketing Cloud (Emarsys) Lead service delivery and incident management, driving rapid resolution, root cause analysis, and continuous improvement Establish and optimise ITIL processes, including incident, problem, and change management Build, mentor, and grow a high-performing support and operations team, developing capability and driving engagement Drive operational resilience, managing releases, upgrades, and system improvements with minimal disruption Collaborate with internal stakeholders and business teams, ensuring technology enables exceptional customer experiences Manage third-party vendors and partners, holding them accountable for service quality and delivery standards Champion a proactive support model, shifting from reactive incident handling to predictive and preventative operations What You'll Bring Proven experience as an SAP Operations Manager / Service Delivery Manager within complex environments Strong expertise in incident management, service delivery, and ITIL frameworks Demonstrated ability to build, scale, and lead high-performing teams Experience driving continuous service improvement and operational excellence Strong stakeholder management, with the ability to bridge technical and business teams Familiarity with agile tools and delivery environments (e.g., Jira, Azure DevOps) Analytical mindset with a focus on performance metrics, SLAs, and service quality Additional Information Involvement in out-of-hours incident management for critical issues Opportunity to work closely with global partners and vendors Ongoing investment in learning, development, and process maturity Why Join? Ready to lead service delivery, strengthen operations, and build exceptional teams? Join a business where technology, service excellence, and luxury customer experience intersect. You'll have the opportunity to shape service operations, build a high-performing function, and make a tangible impact on how customers engage with a globally recognised brand.
10/07/2026
Full time
SAP Operations Manager - Service Delivery & Incident Management Location: London Drive operational excellence behind world-class customer experiences. We are looking for an experienced SAP Operations Manager with a strong background in Service Delivery, Incident Management, and team leadership to join a prestigious brand. This is a high-impact role where you will take ownership of critical SAP platforms, ensuring stability, performance, and continuous improvement in a fast-paced, customer-centric environment. In this role, you will lead the end-to-end service operations lifecycle, from incident response and problem management to continuous service optimisation. You'll play a key role in building and scaling high-performing teams, embedding best-in-class ITIL practices, and ensuring a consistently high level of service delivery across the organisation. What You'll Do Own SAP service operations, ensuring high availability and performance across Customer Data Cloud, Data Platform, Sales & Service Cloud, and Marketing Cloud (Emarsys) Lead service delivery and incident management, driving rapid resolution, root cause analysis, and continuous improvement Establish and optimise ITIL processes, including incident, problem, and change management Build, mentor, and grow a high-performing support and operations team, developing capability and driving engagement Drive operational resilience, managing releases, upgrades, and system improvements with minimal disruption Collaborate with internal stakeholders and business teams, ensuring technology enables exceptional customer experiences Manage third-party vendors and partners, holding them accountable for service quality and delivery standards Champion a proactive support model, shifting from reactive incident handling to predictive and preventative operations What You'll Bring Proven experience as an SAP Operations Manager / Service Delivery Manager within complex environments Strong expertise in incident management, service delivery, and ITIL frameworks Demonstrated ability to build, scale, and lead high-performing teams Experience driving continuous service improvement and operational excellence Strong stakeholder management, with the ability to bridge technical and business teams Familiarity with agile tools and delivery environments (e.g., Jira, Azure DevOps) Analytical mindset with a focus on performance metrics, SLAs, and service quality Additional Information Involvement in out-of-hours incident management for critical issues Opportunity to work closely with global partners and vendors Ongoing investment in learning, development, and process maturity Why Join? Ready to lead service delivery, strengthen operations, and build exceptional teams? Join a business where technology, service excellence, and luxury customer experience intersect. You'll have the opportunity to shape service operations, build a high-performing function, and make a tangible impact on how customers engage with a globally recognised brand.
BAE Systems
External Attack Surface Management Analyst
BAE Systems Farnborough, Hampshire
Job Title: External Attack Surface Management Analyst Job Location: Preston or Frimley - Hybrid-2 days a month onsite. We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Circa £45,000 depending on skills and experience Who we are: Join BAE Systems and you'll be part of something bigger. As a valued member of our global colleague network, you'll bring your unique skills and perspectives to help pioneer progress and protect what matters most. You'll be trusted to play your part in delivering the advanced, technology-led defence, aerospace and security solutions of tomorrow - shaping a safer future, for all of us. Role Description: Working within Cyber Operations, you will help safeguard BAE Systems against evolving cyber threats by supporting and enhancing the External Attack Surface Management (EASM) capability across people, process, and technology. You will contribute to an intelligence-led approach to cyber operations, ensuring external assets are identified, assessed, and continuously tested. The role supports detection assurance by identifying shadow IT and unmanaged exposures, providing confidence to leadership that security controls and monitoring capabilities are effective and aligned to organisational security standards. Core Duties: Proactively discover, track, and maintain visibility of external attack surface assets, including unknown and shadow IT exposures Investigate and validate externally visible exposures, assessing real-world risk, attacker relevance, and exploitability Monitor changes in external exposure, identifying new assets, regressions, and emerging risks across the estate Collaborate with Threat Intelligence and Cyber Operations to align exposure findings with attacker activity and remediation priorities Produce clear, actionable reporting on external exposures, trends, and security posture to support risk reduction and decision -making Essential Skills: Good understanding of external reconnaissance techniques, OSINT, and how attackers identify and profile internet-facing assets Proven experience in attack surface discovery, asset enumeration, and identifying unknown or shadow IT exposures Good investigative mindset with the ability to analyse incomplete or ambiguous external data and determine genuine security risk Ability to assess and distinguish between observed external artefacts, misconfigurations, and true exploitable exposures from an attacker's perspective Experience working with internet-facing protocols and data sources (e.g. DNS, HTTP, TLS, certificate transparency, scanning datasets) to identify patterns, relationships, and anomalies The Cyber Operations team: Cyber Operations is responsible for protecting BAE Systems from Cyber Attack by various threat actors. Not only do we protect BAE Systems and its employees, indirectly we protect those who protect us - who serve in our military and rely on the products and services we create across Threat Intelligence, Detection, Incident Response and now Active Defence we work to evolve cyber operations as a world class capability. Why BAE Systems? Here you'll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work - this is a place where you can grow your career with confidence and be empowered to be your best. You'll be recognised for your contribution and enjoy rewards tailored to what's most important to you and your family - support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make. A place where everyone can thrive: We're committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role , to allow for meaningful security vetting checks. Closing Date: 14th July 2026 We reserve the right to close this vacancy early if we receive sufficient applications for the role . Therefore, if you are interested, please submit your application as early as possible.
10/07/2026
Full time
Job Title: External Attack Surface Management Analyst Job Location: Preston or Frimley - Hybrid-2 days a month onsite. We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Circa £45,000 depending on skills and experience Who we are: Join BAE Systems and you'll be part of something bigger. As a valued member of our global colleague network, you'll bring your unique skills and perspectives to help pioneer progress and protect what matters most. You'll be trusted to play your part in delivering the advanced, technology-led defence, aerospace and security solutions of tomorrow - shaping a safer future, for all of us. Role Description: Working within Cyber Operations, you will help safeguard BAE Systems against evolving cyber threats by supporting and enhancing the External Attack Surface Management (EASM) capability across people, process, and technology. You will contribute to an intelligence-led approach to cyber operations, ensuring external assets are identified, assessed, and continuously tested. The role supports detection assurance by identifying shadow IT and unmanaged exposures, providing confidence to leadership that security controls and monitoring capabilities are effective and aligned to organisational security standards. Core Duties: Proactively discover, track, and maintain visibility of external attack surface assets, including unknown and shadow IT exposures Investigate and validate externally visible exposures, assessing real-world risk, attacker relevance, and exploitability Monitor changes in external exposure, identifying new assets, regressions, and emerging risks across the estate Collaborate with Threat Intelligence and Cyber Operations to align exposure findings with attacker activity and remediation priorities Produce clear, actionable reporting on external exposures, trends, and security posture to support risk reduction and decision -making Essential Skills: Good understanding of external reconnaissance techniques, OSINT, and how attackers identify and profile internet-facing assets Proven experience in attack surface discovery, asset enumeration, and identifying unknown or shadow IT exposures Good investigative mindset with the ability to analyse incomplete or ambiguous external data and determine genuine security risk Ability to assess and distinguish between observed external artefacts, misconfigurations, and true exploitable exposures from an attacker's perspective Experience working with internet-facing protocols and data sources (e.g. DNS, HTTP, TLS, certificate transparency, scanning datasets) to identify patterns, relationships, and anomalies The Cyber Operations team: Cyber Operations is responsible for protecting BAE Systems from Cyber Attack by various threat actors. Not only do we protect BAE Systems and its employees, indirectly we protect those who protect us - who serve in our military and rely on the products and services we create across Threat Intelligence, Detection, Incident Response and now Active Defence we work to evolve cyber operations as a world class capability. Why BAE Systems? Here you'll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work - this is a place where you can grow your career with confidence and be empowered to be your best. You'll be recognised for your contribution and enjoy rewards tailored to what's most important to you and your family - support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make. A place where everyone can thrive: We're committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role , to allow for meaningful security vetting checks. Closing Date: 14th July 2026 We reserve the right to close this vacancy early if we receive sufficient applications for the role . Therefore, if you are interested, please submit your application as early as possible.
BAE Systems
External Attack Surface Management Analyst
BAE Systems Farnborough, Hampshire
Job Title: External Attack Surface Management Analyst Job Location: Preston or Frimley - Hybrid-2 days a month onsite. We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Circa £45,000 depending on skills and experience Who we are: Join BAE Systems and you'll be part of something bigger. As a valued member of our global colleague network, you'll bring your unique skills and perspectives to help pioneer progress and protect what matters most. You'll be trusted to play your part in delivering the advanced, technology-led defence, aerospace and security solutions of tomorrow - shaping a safer future, for all of us. Role Description: Working within Cyber Operations, you will help safeguard BAE Systems against evolving cyber threats by supporting and enhancing the External Attack Surface Management (EASM) capability across people, process, and technology. You will contribute to an intelligence-led approach to cyber operations, ensuring external assets are identified, assessed, and continuously tested. The role supports detection assurance by identifying shadow IT and unmanaged exposures, providing confidence to leadership that security controls and monitoring capabilities are effective and aligned to organisational security standards. Core Duties: Proactively discover, track, and maintain visibility of external attack surface assets, including unknown and shadow IT exposures Investigate and validate externally visible exposures, assessing real-world risk, attacker relevance, and exploitability Monitor changes in external exposure, identifying new assets, regressions, and emerging risks across the estate Collaborate with Threat Intelligence and Cyber Operations to align exposure findings with attacker activity and remediation priorities Produce clear, actionable reporting on external exposures, trends, and security posture to support risk reduction and decision -making Essential Skills: Good understanding of external reconnaissance techniques, OSINT, and how attackers identify and profile internet-facing assets Proven experience in attack surface discovery, asset enumeration, and identifying unknown or shadow IT exposures Good investigative mindset with the ability to analyse incomplete or ambiguous external data and determine genuine security risk Ability to assess and distinguish between observed external artefacts, misconfigurations, and true exploitable exposures from an attacker's perspective Experience working with internet-facing protocols and data sources (e.g. DNS, HTTP, TLS, certificate transparency, scanning datasets) to identify patterns, relationships, and anomalies The Cyber Operations team: Cyber Operations is responsible for protecting BAE Systems from Cyber Attack by various threat actors. Not only do we protect BAE Systems and its employees, indirectly we protect those who protect us - who serve in our military and rely on the products and services we create across Threat Intelligence, Detection, Incident Response and now Active Defence we work to evolve cyber operations as a world class capability. Why BAE Systems? Here you'll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work - this is a place where you can grow your career with confidence and be empowered to be your best. You'll be recognised for your contribution and enjoy rewards tailored to what's most important to you and your family - support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make. A place where everyone can thrive: We're committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role , to allow for meaningful security vetting checks. Closing Date: 14th July 2026 We reserve the right to close this vacancy early if we receive sufficient applications for the role . Therefore, if you are interested, please submit your application as early as possible.
10/07/2026
Full time
Job Title: External Attack Surface Management Analyst Job Location: Preston or Frimley - Hybrid-2 days a month onsite. We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Circa £45,000 depending on skills and experience Who we are: Join BAE Systems and you'll be part of something bigger. As a valued member of our global colleague network, you'll bring your unique skills and perspectives to help pioneer progress and protect what matters most. You'll be trusted to play your part in delivering the advanced, technology-led defence, aerospace and security solutions of tomorrow - shaping a safer future, for all of us. Role Description: Working within Cyber Operations, you will help safeguard BAE Systems against evolving cyber threats by supporting and enhancing the External Attack Surface Management (EASM) capability across people, process, and technology. You will contribute to an intelligence-led approach to cyber operations, ensuring external assets are identified, assessed, and continuously tested. The role supports detection assurance by identifying shadow IT and unmanaged exposures, providing confidence to leadership that security controls and monitoring capabilities are effective and aligned to organisational security standards. Core Duties: Proactively discover, track, and maintain visibility of external attack surface assets, including unknown and shadow IT exposures Investigate and validate externally visible exposures, assessing real-world risk, attacker relevance, and exploitability Monitor changes in external exposure, identifying new assets, regressions, and emerging risks across the estate Collaborate with Threat Intelligence and Cyber Operations to align exposure findings with attacker activity and remediation priorities Produce clear, actionable reporting on external exposures, trends, and security posture to support risk reduction and decision -making Essential Skills: Good understanding of external reconnaissance techniques, OSINT, and how attackers identify and profile internet-facing assets Proven experience in attack surface discovery, asset enumeration, and identifying unknown or shadow IT exposures Good investigative mindset with the ability to analyse incomplete or ambiguous external data and determine genuine security risk Ability to assess and distinguish between observed external artefacts, misconfigurations, and true exploitable exposures from an attacker's perspective Experience working with internet-facing protocols and data sources (e.g. DNS, HTTP, TLS, certificate transparency, scanning datasets) to identify patterns, relationships, and anomalies The Cyber Operations team: Cyber Operations is responsible for protecting BAE Systems from Cyber Attack by various threat actors. Not only do we protect BAE Systems and its employees, indirectly we protect those who protect us - who serve in our military and rely on the products and services we create across Threat Intelligence, Detection, Incident Response and now Active Defence we work to evolve cyber operations as a world class capability. Why BAE Systems? Here you'll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work - this is a place where you can grow your career with confidence and be empowered to be your best. You'll be recognised for your contribution and enjoy rewards tailored to what's most important to you and your family - support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make. A place where everyone can thrive: We're committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role , to allow for meaningful security vetting checks. Closing Date: 14th July 2026 We reserve the right to close this vacancy early if we receive sufficient applications for the role . Therefore, if you are interested, please submit your application as early as possible.
Morgan Hunt UK Limited
Head of Cyber Security
Morgan Hunt UK Limited
Head of Cyber Security Permanent £88,000-£97,000 London (Hybrid - 2 days onsite) 30 days holiday + 8% pension + other benefits A leading regulatory organisation is seeking an experienced Head of Cyber Security to provide strategic leadership and direction across its cyber and information security function. This is a senior, cross functional leadership role responsible for shaping and delivering a comprehensive cyber security strategy, ensuring organisational resilience against evolving cyber threats while enabling secure digital innovation. The Role You will lead the development and implementation of a forward thinking cyber security strategy, ensuring systems, data, and services are protected through robust controls, governance, and risk management practices. Working closely with senior stakeholders, you will act as the organisation's subject matter expert on cyber security, providing clear, actionable advice on risks, threats, and mitigation strategies. Key Responsibilities Define and deliver the organisation wide cyber security strategy and roadmap Establish and evolve the cyber security operating model, including team structure Develop and implement security policies, standards, and best practices Provide expert advice to senior leadership on cyber risk and resilience Lead cyber risk identification, assessment, and mitigation activities Oversee security architecture to ensure alignment with wider technology strategy Drive continuous improvement through security assessments, testing, and reporting Ensure effective incident detection, response, and recovery capabilities Lead vulnerability management and remediation across all technology environments Oversee third party security testing, including penetration testing and phishing simulations Promote a strong cyber security culture through training and awareness initiatives Monitor and report on threat intelligence trends and emerging risks About You You will be a strategic and influential cyber security leader with a strong track record of operating at senior level within complex organisations. Key Skills & Experience Proven experience developing and delivering cyber security strategies Strong understanding of security frameworks such as ISO 27001, NIST, Cyber Essentials Expertise in risk management, vulnerability assessment, and incident response Experience with enterprise security tools (e.g. SIEM, IDS, firewalls, encryption technologies) Knowledge of cloud and hybrid security environments Ability to communicate complex technical risks to non technical stakeholders Experience influencing senior leadership and driving organisation wide change Desirable Professional certifications such as CISSP, CISM, or CISO Experience within regulated or public sector environments Leadership & Behaviours Strong decision making in high risk, high impact environments Ability to lead with purpose and set strategic direction Excellent communication and stakeholder engagement skills Focus on delivering measurable outcomes and organisational resilience Additional Information Hybrid working: 2 days per week in London 30 days annual leave 8% pension contribution + other benefits Participation in an on call rota may be required Morgan Hunt is a multi award winning recruitment business for interim, contract and temporary recruitment and acts as an Employment Agency in relation to permanent vacancies. Morgan Hunt is an equal opportunities employer. Job suitability is assessed on merit in accordance with the individual's skills, qualifications and abilities to perform the relevant duties required in a particular role.
10/07/2026
Full time
Head of Cyber Security Permanent £88,000-£97,000 London (Hybrid - 2 days onsite) 30 days holiday + 8% pension + other benefits A leading regulatory organisation is seeking an experienced Head of Cyber Security to provide strategic leadership and direction across its cyber and information security function. This is a senior, cross functional leadership role responsible for shaping and delivering a comprehensive cyber security strategy, ensuring organisational resilience against evolving cyber threats while enabling secure digital innovation. The Role You will lead the development and implementation of a forward thinking cyber security strategy, ensuring systems, data, and services are protected through robust controls, governance, and risk management practices. Working closely with senior stakeholders, you will act as the organisation's subject matter expert on cyber security, providing clear, actionable advice on risks, threats, and mitigation strategies. Key Responsibilities Define and deliver the organisation wide cyber security strategy and roadmap Establish and evolve the cyber security operating model, including team structure Develop and implement security policies, standards, and best practices Provide expert advice to senior leadership on cyber risk and resilience Lead cyber risk identification, assessment, and mitigation activities Oversee security architecture to ensure alignment with wider technology strategy Drive continuous improvement through security assessments, testing, and reporting Ensure effective incident detection, response, and recovery capabilities Lead vulnerability management and remediation across all technology environments Oversee third party security testing, including penetration testing and phishing simulations Promote a strong cyber security culture through training and awareness initiatives Monitor and report on threat intelligence trends and emerging risks About You You will be a strategic and influential cyber security leader with a strong track record of operating at senior level within complex organisations. Key Skills & Experience Proven experience developing and delivering cyber security strategies Strong understanding of security frameworks such as ISO 27001, NIST, Cyber Essentials Expertise in risk management, vulnerability assessment, and incident response Experience with enterprise security tools (e.g. SIEM, IDS, firewalls, encryption technologies) Knowledge of cloud and hybrid security environments Ability to communicate complex technical risks to non technical stakeholders Experience influencing senior leadership and driving organisation wide change Desirable Professional certifications such as CISSP, CISM, or CISO Experience within regulated or public sector environments Leadership & Behaviours Strong decision making in high risk, high impact environments Ability to lead with purpose and set strategic direction Excellent communication and stakeholder engagement skills Focus on delivering measurable outcomes and organisational resilience Additional Information Hybrid working: 2 days per week in London 30 days annual leave 8% pension contribution + other benefits Participation in an on call rota may be required Morgan Hunt is a multi award winning recruitment business for interim, contract and temporary recruitment and acts as an Employment Agency in relation to permanent vacancies. Morgan Hunt is an equal opportunities employer. Job suitability is assessed on merit in accordance with the individual's skills, qualifications and abilities to perform the relevant duties required in a particular role.
Technical Project Manager
Oxford Dynamics
Role Summary Oxford Dynamics seeks a Senior Technical Project Manager to own end to end delivery of AI driven software programmes, coordinating multi team execution from scope and planning through production launch with clear SLAs, budgets, and timelines. The role bridges cutting edge AI research and practical deployment, ensuring agentic/LLM features ship safely, on time, and to quality in regulated environments where security and compliance matter. Key Responsibilities Lead multi project roadmaps managing scope, budgets, risks, RAID, milestones, and change control to deliver on time and within cost. Run Agile ceremonies (Scrum/Kanban), track burn up/burn down, and drive decisions with clear acceptance criteria and measurable outcomes for each increment. Produce crisp client and leadership reporting, acting as the single point of contact to unblock issues across internal teams, suppliers, and stakeholders. Orchestrate delivery of AI features spanning LLMs, RAG, and multi agent workflows from ingestion to inference, including offline/edge constraints where required. Partner with Tech Leads to make trade offs in design and architecture, aligning research prototypes with production requirements and service levels. Coordinate release readiness across testing, evaluation, and go live plans. Align engineering and DevOps on environments, observability, and incident response, ensuring deployments are auditable, cost aware, and reversible. Oversee vendor and subcontractor deliverables, ensuring integrations meet contractual, performance, and compliance requirements. Own risk mitigation for compliance and security constraints typical of regulated sectors, escalating early with clear options and impacts. Translate product goals into executable backlogs and milestones, sequencing dependencies across AI, frontend, backend, and platform teams. Review GitHub PRs alongside Tech Leads to validate scope, surface trade offs, and maintain momentum without compromising quality. Represent Oxford Dynamics with customers and partners, including contributions to bids and programme inputs where needed. Drive adherence to security and quality management processes appropriate to regulated domains such as defence, aerospace, healthcare, and finance. Ensure projects maintain audit evidence for decisions, testing, and releases, with recovery plans and responsibilities defined prior to go live. Qualifications 5+ years managing software and AI programmes with multiple stakeholders, delivering production releases in fast moving environments. Proven delivery across teams using React and Python stacks (e.g., Django, FastAPI, Flask) or equivalent modern frameworks. Hands on experience coordinating projects that integrate LLMs, RAG, and related AI components into shipped products. Strong scope, requirements, and budget control; confident discussing technical trade offs and reviewing PRs with engineers. Experience in regulated environments with security and compliance responsibilities across the delivery lifecycle. SC clearance or eligibility for UK national security vetting as required by programmes. Preferred / Bonus Portfolio of shipped AI/robotics/software projects with measurable outcomes and references to regulated work where applicable. Knowledge of data security and accreditation processes; experience with offline/edge solutions or constrained deployments. Comfort presenting to senior stakeholders and contributing to business development activities and bids. Soft Skills High agency ownership from concept to launch, with a bias to clarity, iteration, and decision making under uncertainty. Excellent communication across technical and non technical audiences, enabling fast, safe progress across disciplines. Calm, structured problem solving during incidents and changing constraints, with clear follow through on actions and learning. Benefits Salary: negotiable based on experience and attitudes. Rapid career progression with meaningful ownership of core systems. Opportunity to shape the future of a fast growing, successful, early stage business. Flexible working hours. Hybrid working model. Company pension (UK Government NEST scheme) with company contributions at 4%. Private healthcare. 29 days holiday in addition to public holidays (Full Time Equivalent). Inclusive team experience for all; we believe our work is at its best when everyone feels free to be their authentic self.
10/07/2026
Full time
Role Summary Oxford Dynamics seeks a Senior Technical Project Manager to own end to end delivery of AI driven software programmes, coordinating multi team execution from scope and planning through production launch with clear SLAs, budgets, and timelines. The role bridges cutting edge AI research and practical deployment, ensuring agentic/LLM features ship safely, on time, and to quality in regulated environments where security and compliance matter. Key Responsibilities Lead multi project roadmaps managing scope, budgets, risks, RAID, milestones, and change control to deliver on time and within cost. Run Agile ceremonies (Scrum/Kanban), track burn up/burn down, and drive decisions with clear acceptance criteria and measurable outcomes for each increment. Produce crisp client and leadership reporting, acting as the single point of contact to unblock issues across internal teams, suppliers, and stakeholders. Orchestrate delivery of AI features spanning LLMs, RAG, and multi agent workflows from ingestion to inference, including offline/edge constraints where required. Partner with Tech Leads to make trade offs in design and architecture, aligning research prototypes with production requirements and service levels. Coordinate release readiness across testing, evaluation, and go live plans. Align engineering and DevOps on environments, observability, and incident response, ensuring deployments are auditable, cost aware, and reversible. Oversee vendor and subcontractor deliverables, ensuring integrations meet contractual, performance, and compliance requirements. Own risk mitigation for compliance and security constraints typical of regulated sectors, escalating early with clear options and impacts. Translate product goals into executable backlogs and milestones, sequencing dependencies across AI, frontend, backend, and platform teams. Review GitHub PRs alongside Tech Leads to validate scope, surface trade offs, and maintain momentum without compromising quality. Represent Oxford Dynamics with customers and partners, including contributions to bids and programme inputs where needed. Drive adherence to security and quality management processes appropriate to regulated domains such as defence, aerospace, healthcare, and finance. Ensure projects maintain audit evidence for decisions, testing, and releases, with recovery plans and responsibilities defined prior to go live. Qualifications 5+ years managing software and AI programmes with multiple stakeholders, delivering production releases in fast moving environments. Proven delivery across teams using React and Python stacks (e.g., Django, FastAPI, Flask) or equivalent modern frameworks. Hands on experience coordinating projects that integrate LLMs, RAG, and related AI components into shipped products. Strong scope, requirements, and budget control; confident discussing technical trade offs and reviewing PRs with engineers. Experience in regulated environments with security and compliance responsibilities across the delivery lifecycle. SC clearance or eligibility for UK national security vetting as required by programmes. Preferred / Bonus Portfolio of shipped AI/robotics/software projects with measurable outcomes and references to regulated work where applicable. Knowledge of data security and accreditation processes; experience with offline/edge solutions or constrained deployments. Comfort presenting to senior stakeholders and contributing to business development activities and bids. Soft Skills High agency ownership from concept to launch, with a bias to clarity, iteration, and decision making under uncertainty. Excellent communication across technical and non technical audiences, enabling fast, safe progress across disciplines. Calm, structured problem solving during incidents and changing constraints, with clear follow through on actions and learning. Benefits Salary: negotiable based on experience and attitudes. Rapid career progression with meaningful ownership of core systems. Opportunity to shape the future of a fast growing, successful, early stage business. Flexible working hours. Hybrid working model. Company pension (UK Government NEST scheme) with company contributions at 4%. Private healthcare. 29 days holiday in addition to public holidays (Full Time Equivalent). Inclusive team experience for all; we believe our work is at its best when everyone feels free to be their authentic self.
Security Engineer (Institutional Trading)
Prudence Holdings
You'll be the hands on security engineer embedded with the Institutional Trading and Financial Operations (FinOps) team. Your focus is the secure operation of off chain trading processes and infrastructure that empowers our institutional business: integrations, signing flows, key custody interfaces, middle office workflows, order routing and settle pipelines that handle significant capital. You will support risk assessments, operating controls, automation to detect operational anomalies and remediation coordination. This is a high visibility role where you will focus on operational security engineering-ensuring that the tools and processes our traders use are resilient against both external threats and internal errors. This role does not require smart contract auditing. What You Will Do Partner with Trading, Middle Office and Quant (Institutional FinOps) teams to map out inventory trading systems, data flows, third party integrations and custody/settlement touchpoints. Conduct deep dive assessments mapping critical assets and workflows to identify structural vulnerabilities. You will be responsible for defining the Target State and drafting the strategic Risk Treatment Plans (RTP) required to meet institutional grade standards (e.g., CCSS, NIST, DORA). Act as the primary security liaison for Senior Management and third party vendors. You will translate complex technical gaps into actionable business risk summaries, drive vendor evaluations for core security infrastructure, and manage the project lifecycle for high impact posture uplifts. Implement and maintain monitoring for FinOps specific security signals such as abnormal order patterns, signature misuse, unusual settlements. You will integrate these signals into our SIEM/SOAR for real time response. Support secrets and key management hygiene. You will ensure app/service keys are stored in KMS/Vault, scoped to least privilege and rotated automatically to prevent credential leakage. Assist product security in triage of SAST/SCA findings for FinOps related repositories. You will help implement CI checks and remediation playbooks. Participate in incident exercises, post incident reviews and remediation tracking for trading incidents. Document controls and produce concise risk summaries for FinOps leads and the Security. What You Will Need 5+ years in security engineering, platform security, or application security experience. Proven expertise in Threat Modeling. Ability to perform structured reviews (e.g., STRIDE) of complex data flows and operational processes. Experience with observability and detection tooling (SIEM, logs, metrics) and ability to write basic detection rules. Practical experience with KMS/HSM, secrets management platforms (Vault, 1Password, AWS/GCP KMS), IAM patterns and least privilege. Exceptional ability to translate "Technical Debt" into Business Risk for C suite stakeholders (CFO, CTO, Head of Trading). Ability to raise, read and audit Pull Requests in at least one language used in our stack (TypeScript, Java/Kotlin, Python). Experience conducting technical due diligence and scoping for third party security integrations. Nice to Have Familiarity with trading systems or financial operations (market making, execution, settlement) or close collaboration background with trading/quant teams. Exposure to blockchain on chain concepts (wallets, addresses, transactions) but no requirement to audit contracts. Familiarity with SOC operations, and post incident forensic analysis. Familiarity with SOC2, ISO 27001, or financial audit requirements Any relevant industry certification Blockchain is committed to diversity and inclusion in the workplace and is proud to be an equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, religion, color, national origin, gender, gender expression, sex, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law. This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, and apprenticeship. Blockchain makes hiring decisions based solely on qualifications, merit, and business needs at the time. You may contact our Data Protection Officer by email at . Your personal data will be processed for the purposes of managing Controller's recruitment related activities, which include setting up and conducting interviews and tests for applicants, evaluating and assessing the results thereto, and as is otherwise needed in the recruitment and hiring processes. Such processing is legally permissible under Art. 6(1)(f) of Regulation (EU) 2016/679 (General Data Protection Regulation) as necessary for the purposes of the legitimate interests pursued by the Controller, which are the solicitation, evaluation, and selection of applicants for employment. Your personal data will be shared with Greenhouse Software, Inc., a cloud services provider located in the United States of America and engaged by Controller to help manage its recruitment and hiring process on Controller's behalf. Accordingly, if you are located outside of the United States, your personal data will be transferred to the United States once you submit it through this site. Because the European Union Commission has determined that United States data privacy laws do not ensure an adequate level of protection for personal data collected from EU data subjects, the transfer will be subject to appropriate additional safeguards under the standard contractual clauses. Your personal data will be retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.
10/07/2026
Full time
You'll be the hands on security engineer embedded with the Institutional Trading and Financial Operations (FinOps) team. Your focus is the secure operation of off chain trading processes and infrastructure that empowers our institutional business: integrations, signing flows, key custody interfaces, middle office workflows, order routing and settle pipelines that handle significant capital. You will support risk assessments, operating controls, automation to detect operational anomalies and remediation coordination. This is a high visibility role where you will focus on operational security engineering-ensuring that the tools and processes our traders use are resilient against both external threats and internal errors. This role does not require smart contract auditing. What You Will Do Partner with Trading, Middle Office and Quant (Institutional FinOps) teams to map out inventory trading systems, data flows, third party integrations and custody/settlement touchpoints. Conduct deep dive assessments mapping critical assets and workflows to identify structural vulnerabilities. You will be responsible for defining the Target State and drafting the strategic Risk Treatment Plans (RTP) required to meet institutional grade standards (e.g., CCSS, NIST, DORA). Act as the primary security liaison for Senior Management and third party vendors. You will translate complex technical gaps into actionable business risk summaries, drive vendor evaluations for core security infrastructure, and manage the project lifecycle for high impact posture uplifts. Implement and maintain monitoring for FinOps specific security signals such as abnormal order patterns, signature misuse, unusual settlements. You will integrate these signals into our SIEM/SOAR for real time response. Support secrets and key management hygiene. You will ensure app/service keys are stored in KMS/Vault, scoped to least privilege and rotated automatically to prevent credential leakage. Assist product security in triage of SAST/SCA findings for FinOps related repositories. You will help implement CI checks and remediation playbooks. Participate in incident exercises, post incident reviews and remediation tracking for trading incidents. Document controls and produce concise risk summaries for FinOps leads and the Security. What You Will Need 5+ years in security engineering, platform security, or application security experience. Proven expertise in Threat Modeling. Ability to perform structured reviews (e.g., STRIDE) of complex data flows and operational processes. Experience with observability and detection tooling (SIEM, logs, metrics) and ability to write basic detection rules. Practical experience with KMS/HSM, secrets management platforms (Vault, 1Password, AWS/GCP KMS), IAM patterns and least privilege. Exceptional ability to translate "Technical Debt" into Business Risk for C suite stakeholders (CFO, CTO, Head of Trading). Ability to raise, read and audit Pull Requests in at least one language used in our stack (TypeScript, Java/Kotlin, Python). Experience conducting technical due diligence and scoping for third party security integrations. Nice to Have Familiarity with trading systems or financial operations (market making, execution, settlement) or close collaboration background with trading/quant teams. Exposure to blockchain on chain concepts (wallets, addresses, transactions) but no requirement to audit contracts. Familiarity with SOC operations, and post incident forensic analysis. Familiarity with SOC2, ISO 27001, or financial audit requirements Any relevant industry certification Blockchain is committed to diversity and inclusion in the workplace and is proud to be an equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, religion, color, national origin, gender, gender expression, sex, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law. This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, and apprenticeship. Blockchain makes hiring decisions based solely on qualifications, merit, and business needs at the time. You may contact our Data Protection Officer by email at . Your personal data will be processed for the purposes of managing Controller's recruitment related activities, which include setting up and conducting interviews and tests for applicants, evaluating and assessing the results thereto, and as is otherwise needed in the recruitment and hiring processes. Such processing is legally permissible under Art. 6(1)(f) of Regulation (EU) 2016/679 (General Data Protection Regulation) as necessary for the purposes of the legitimate interests pursued by the Controller, which are the solicitation, evaluation, and selection of applicants for employment. Your personal data will be shared with Greenhouse Software, Inc., a cloud services provider located in the United States of America and engaged by Controller to help manage its recruitment and hiring process on Controller's behalf. Accordingly, if you are located outside of the United States, your personal data will be transferred to the United States once you submit it through this site. Because the European Union Commission has determined that United States data privacy laws do not ensure an adequate level of protection for personal data collected from EU data subjects, the transfer will be subject to appropriate additional safeguards under the standard contractual clauses. Your personal data will be retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.
Senior Manager - Technology Resilience & Risk Improvement
Threadneedle group
Job Description Where you'll fit in & what our team goals are You will lead the implementation and ongoing maturity of the Enterprise Technology Resilience Programme across EMEA/APAC, while driving targeted continuous improvement initiatives across Technology Risk and resilience capabilities. Your role ensures risk and resilience outcomes are delivered consistently during business-as-usual activities and effective response during operational disruption events. Enterprise Technology Resilience Programme Leadership (EMEA) Lead delivery and ongoing maturity of the Enterprise Technology Resilience Programme across EMEA/APAC Ensure effective execution of core resilience activities (e.g. exercises, scenario testing, plan validation, recovery readiness) Coordinate (not lead) regional response in alignment with global event management structure. Act as resilience SME within incident response. Maintain oversight of resilience capability health, including tracking risks, gaps and remediation Partner with Business, Risk and Technology partners, to embed resilience into operational processes Drive continuous improvement by incorporating lessons learned from exercises, incidents, and reviews Provide clear, concise reporting on resilience posture, risks, and progress to senior stakeholders Act as subject matter expert between 1st Line Operational Resilience and Technology to align enterprise and operational testing strategies Support client, regulatory, and due diligence reviews relating to resilience and technology risk Technology Risk & Resilience Improvement Coordinate technology risk and resilience engagement into technology projects Identify and prioritise improvement initiatives across technology risk and resilience Deliver initiatives to strengthen control effectiveness, resilience testing, recovery outcomes, and automation Translate regulatory, audit, and incident findings into actionable improvement plans Track and report measurable improvements in resilience maturity, control effectiveness, and risk reduction Support broader Technology Risk Office (TRO) priorities and transformation initiatives To be successful in this role you will have Experience leading regional/global programs Experience with: scenario testing crisis / incident management regulatory engagement Experience driving measurable improvements (not just participation) Proven ability to lead regional programmes and deliver measurable improvement outcomes Experience managing resilience events, exercises, or incident response coordination Engage senior technology and business stakeholders to drive accountability for resilience outcomes Ability to help translate complex regulatory expectations into practical execution Highly structured, delivery-focused, and comfortable working across multiple priorities In-Office Collaboration We are a client centric, relationship based business. Working together, in person, is foundational to how we achieve results. By fostering a culture of face to face collaboration, idea sharing, productivity and personal connection, we deliver for our stakeholders - clients, advisors, employees and shareholders. Employees work in the office at least four (4) days per week, with flexibility to work from home one (1) day per week. Some roles may require additional in office time or different in office expectations, and specific requirements will be discussed during the hiring process. Employee Statements Columbia Threadneedle is a people business, and we recognise that our success is due to our talented people, who bring diversity of thought, complementary skills and capabilities. We are committed to fostering an inclusive and performance based culture where everyone can belong, grow, contribute and realise their potential. We appreciate that work life balance is an important factor for many when considering their next move so please discuss any flexible working requires directly with your recruiter. Columbia Threadneedle Investments is an equal opportunity employer. We consider all qualified applicants without regard to racial or ethnic background, religion or belief, sex or gender, nationality, genetic information, age, sexual orientation, gender identity, disability, marital status, pregnancy or maternity or any other basis prohibited by law. We are committed to fostering an inclusive and accessible recruitment process for individuals with disabilities. If you require a reasonable accommodation to aid your participation in the application or interview process, speak to your recruiter to discuss how we can support you.
10/07/2026
Full time
Job Description Where you'll fit in & what our team goals are You will lead the implementation and ongoing maturity of the Enterprise Technology Resilience Programme across EMEA/APAC, while driving targeted continuous improvement initiatives across Technology Risk and resilience capabilities. Your role ensures risk and resilience outcomes are delivered consistently during business-as-usual activities and effective response during operational disruption events. Enterprise Technology Resilience Programme Leadership (EMEA) Lead delivery and ongoing maturity of the Enterprise Technology Resilience Programme across EMEA/APAC Ensure effective execution of core resilience activities (e.g. exercises, scenario testing, plan validation, recovery readiness) Coordinate (not lead) regional response in alignment with global event management structure. Act as resilience SME within incident response. Maintain oversight of resilience capability health, including tracking risks, gaps and remediation Partner with Business, Risk and Technology partners, to embed resilience into operational processes Drive continuous improvement by incorporating lessons learned from exercises, incidents, and reviews Provide clear, concise reporting on resilience posture, risks, and progress to senior stakeholders Act as subject matter expert between 1st Line Operational Resilience and Technology to align enterprise and operational testing strategies Support client, regulatory, and due diligence reviews relating to resilience and technology risk Technology Risk & Resilience Improvement Coordinate technology risk and resilience engagement into technology projects Identify and prioritise improvement initiatives across technology risk and resilience Deliver initiatives to strengthen control effectiveness, resilience testing, recovery outcomes, and automation Translate regulatory, audit, and incident findings into actionable improvement plans Track and report measurable improvements in resilience maturity, control effectiveness, and risk reduction Support broader Technology Risk Office (TRO) priorities and transformation initiatives To be successful in this role you will have Experience leading regional/global programs Experience with: scenario testing crisis / incident management regulatory engagement Experience driving measurable improvements (not just participation) Proven ability to lead regional programmes and deliver measurable improvement outcomes Experience managing resilience events, exercises, or incident response coordination Engage senior technology and business stakeholders to drive accountability for resilience outcomes Ability to help translate complex regulatory expectations into practical execution Highly structured, delivery-focused, and comfortable working across multiple priorities In-Office Collaboration We are a client centric, relationship based business. Working together, in person, is foundational to how we achieve results. By fostering a culture of face to face collaboration, idea sharing, productivity and personal connection, we deliver for our stakeholders - clients, advisors, employees and shareholders. Employees work in the office at least four (4) days per week, with flexibility to work from home one (1) day per week. Some roles may require additional in office time or different in office expectations, and specific requirements will be discussed during the hiring process. Employee Statements Columbia Threadneedle is a people business, and we recognise that our success is due to our talented people, who bring diversity of thought, complementary skills and capabilities. We are committed to fostering an inclusive and performance based culture where everyone can belong, grow, contribute and realise their potential. We appreciate that work life balance is an important factor for many when considering their next move so please discuss any flexible working requires directly with your recruiter. Columbia Threadneedle Investments is an equal opportunity employer. We consider all qualified applicants without regard to racial or ethnic background, religion or belief, sex or gender, nationality, genetic information, age, sexual orientation, gender identity, disability, marital status, pregnancy or maternity or any other basis prohibited by law. We are committed to fostering an inclusive and accessible recruitment process for individuals with disabilities. If you require a reasonable accommodation to aid your participation in the application or interview process, speak to your recruiter to discuss how we can support you.
Head of Security
ClearCourse Partnership LLP
Chief Information Security Officer (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Chief Information Security Officer (CISO) to lead and evolve our group wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI-DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
10/07/2026
Full time
Chief Information Security Officer (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Chief Information Security Officer (CISO) to lead and evolve our group wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI-DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
La Fosse Associates
Security Operations Leader - SOC & IR, Hybrid (London)
La Fosse Associates
La Fosse Associates is seeking an IT Security Manager to lead a team of 11 in Greater London. The ideal candidate will have extensive SecOps and Incident Response experience, overseeing security operations and initiatives across diverse environments. Key responsibilities include team management, threat detection, and strategic alignment of security efforts with business goals. The position offers a day rate between £800 and £850 inside IR35, with some remote flexibility.
10/07/2026
Full time
La Fosse Associates is seeking an IT Security Manager to lead a team of 11 in Greater London. The ideal candidate will have extensive SecOps and Incident Response experience, overseeing security operations and initiatives across diverse environments. Key responsibilities include team management, threat detection, and strategic alignment of security efforts with business goals. The position offers a day rate between £800 and £850 inside IR35, with some remote flexibility.
La Fosse Associates
IT Security Manager
La Fosse Associates
IT Security Manager IT Security Manager opportunity for a security leader with a strong SecOps/Incident Response background and broad cyber security management experience to lead a team of 11 across SecOps, Engineering, Architecture and MSSP management, driving security operations and strategic initiatives across on-premises and cloud environments. Day Rate: £800 - £850pd IR35 Status: Inside Travel: 3 days a week in Central London (2 days WFH) Duration: Initial 6 months Responsibilities Lead an established cyber security function across both on-premises and cloud environments, ensuring the effective delivery of security operations and strategic security initiatives. Leverage your strong SOC and Incident Response background to oversee threat detection, incident management, vulnerability management, and the continuous enhancement of security capabilities. Manage and develop a team of circa 11 security professionals across Security Operations, Security Engineering, Security Architecture, and MSSP relationships, fostering a high performance security culture. Work closely with senior stakeholders to prioritise security activities, manage risk, and ensure security objectives are aligned with wider business goals. Provide broad oversight across technical security disciplines, with exposure to governance, risk, and compliance, while driving operational excellence and continuous improvement across the security function.
10/07/2026
Full time
IT Security Manager IT Security Manager opportunity for a security leader with a strong SecOps/Incident Response background and broad cyber security management experience to lead a team of 11 across SecOps, Engineering, Architecture and MSSP management, driving security operations and strategic initiatives across on-premises and cloud environments. Day Rate: £800 - £850pd IR35 Status: Inside Travel: 3 days a week in Central London (2 days WFH) Duration: Initial 6 months Responsibilities Lead an established cyber security function across both on-premises and cloud environments, ensuring the effective delivery of security operations and strategic security initiatives. Leverage your strong SOC and Incident Response background to oversee threat detection, incident management, vulnerability management, and the continuous enhancement of security capabilities. Manage and develop a team of circa 11 security professionals across Security Operations, Security Engineering, Security Architecture, and MSSP relationships, fostering a high performance security culture. Work closely with senior stakeholders to prioritise security activities, manage risk, and ensure security objectives are aligned with wider business goals. Provide broad oversight across technical security disciplines, with exposure to governance, risk, and compliance, while driving operational excellence and continuous improvement across the security function.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board