Hiscox Underwriting Group Services Ltd (HUGS)
City, York
Job Type: Permanent The Role The Blue Team Leader works in our Cyber Fusion Centre, and plays a pivotal role in the protection of our business assets and interests from cyber threats. You will focus on the development of our proactive and defensive capabilities, orchestrating security operations and optimising the efforts of our Blue Team. You will support in the development and implementation of our overall cybersecurity strategy, and plan activities and initiatives to meet our business security objectives. You will need to be naturally inquisitive, have a comprehensive understanding of the latest cyber threats and how to counter them. You will also be a member of our Cyber Incident Response Team (CIRT) and will need to lead our initial response. You will work closely with our Red Team Leader and Cyber Delivery Leader to identify threats and vulnerabilities present in our network and systems, and turn these into a pipeline of continuous improvement for our cyber defences. You will also work closely with our Head of Cyber Fusion Centre to co ordinate daily activities in support of their primary objectives. You will also be responsible for working with project delivery teams from across our business, where you will provide expert technical security advice and guidance and support their onboarding activities to the Fusion Centre. You will need hands on experience working with a multitude of different security technologies, be able lead and coach your team of analysts and be able to work in a high paced operational environment. The role is based in either York (UK) or Lisbon (Portugal) and is a permanent position. Travel to other team locations will be required as necessary. Key Responsibilities Direct and guide the Blue Team in their daily operations, ensuring alignment with our business security objectives and latest threat intelligence. Oversee the continuous monitoring of our networks and systems for security breaches or anomalies. Design and maintain incident response plans to address and mitigate potential security breaches. Co ordinate Blue Team exercises to ensure analysts are confident in detecting and responding to cyber threats, and that we have the required data points needed to support detection of potential incidents. Allocate and manage resources effectively to ensure optimal team performance and address any skill, performance or resource gaps. Perform routine gap analysis of detection use cases and identify new data sources for onboarding to the SIEM platform to ensure observability of the latest TTPs. Leverage actionable threat intelligence to develop new detection use cases to support the ongoing continuous improvement of our SIEM capabilities. Ensure the operational resilience of our proactive and defensive cyber capabilities, including our technology, people and process used to support detection and response. Lead initial response to detection of security incidents, ensuring timely and effective resolution, escalation where necessary and perform any post incident analysis for lessons learned. Coach and mentor your team to support their professional development, fostering an environment of continuous learning and improvement. Develop and maintain our security operations policies, processes and playbooks. Maintain an up to date knowledge of the latest security tools and technologies, and how these could be used to mitigate our priority threats. Provide regular reports on security status, incidents and KRIs to senior management and stakeholders. Candidate Profile 6+ years experience in a security operations team, preferably 2 years in a management role. Demonstrable experience leading response to security incidents and breaches. Excellent understanding of defensive security strategies and cyber incident response processes. Excellent working knowledge of SIEM based tools and technologies. Excellent working knowledge of EDR and XDR technologies. Excellent working knowledge of firewalls and other network security appliances. Excellent problem solving and analytical skills, with the ability to make sound decisions under pressure. Excellent leadership and management skills, with strong communications and interpersonal skills. Good understanding of forensics technologies and processes. BSc or MSc in Cybersecurity is highly desirable. Advanced cyber certifications such as CISSP, CISM, GCIH and GPEN are desirable. Industry recognised security vendor certifications are desirable. Diversity & Benefits We hire the best people for the job and we're committed to diversity and creating a truly inclusive culture, which we believe drives success. Working life doesn't always have to be in the office, so we have introduced hybrid working to encourage a healthy work life balance. This hybrid working model is set by the team rather than the business to enable you to manage your own personal work life balance. Our benefits package includes a bonus, contributory pension, 25 days annual leave plus 2 Hiscox days and a 4 week paid sabbatical with every 5 years' worth of service, private medical for all the family and much more.
27/07/2026
Full time
Job Type: Permanent The Role The Blue Team Leader works in our Cyber Fusion Centre, and plays a pivotal role in the protection of our business assets and interests from cyber threats. You will focus on the development of our proactive and defensive capabilities, orchestrating security operations and optimising the efforts of our Blue Team. You will support in the development and implementation of our overall cybersecurity strategy, and plan activities and initiatives to meet our business security objectives. You will need to be naturally inquisitive, have a comprehensive understanding of the latest cyber threats and how to counter them. You will also be a member of our Cyber Incident Response Team (CIRT) and will need to lead our initial response. You will work closely with our Red Team Leader and Cyber Delivery Leader to identify threats and vulnerabilities present in our network and systems, and turn these into a pipeline of continuous improvement for our cyber defences. You will also work closely with our Head of Cyber Fusion Centre to co ordinate daily activities in support of their primary objectives. You will also be responsible for working with project delivery teams from across our business, where you will provide expert technical security advice and guidance and support their onboarding activities to the Fusion Centre. You will need hands on experience working with a multitude of different security technologies, be able lead and coach your team of analysts and be able to work in a high paced operational environment. The role is based in either York (UK) or Lisbon (Portugal) and is a permanent position. Travel to other team locations will be required as necessary. Key Responsibilities Direct and guide the Blue Team in their daily operations, ensuring alignment with our business security objectives and latest threat intelligence. Oversee the continuous monitoring of our networks and systems for security breaches or anomalies. Design and maintain incident response plans to address and mitigate potential security breaches. Co ordinate Blue Team exercises to ensure analysts are confident in detecting and responding to cyber threats, and that we have the required data points needed to support detection of potential incidents. Allocate and manage resources effectively to ensure optimal team performance and address any skill, performance or resource gaps. Perform routine gap analysis of detection use cases and identify new data sources for onboarding to the SIEM platform to ensure observability of the latest TTPs. Leverage actionable threat intelligence to develop new detection use cases to support the ongoing continuous improvement of our SIEM capabilities. Ensure the operational resilience of our proactive and defensive cyber capabilities, including our technology, people and process used to support detection and response. Lead initial response to detection of security incidents, ensuring timely and effective resolution, escalation where necessary and perform any post incident analysis for lessons learned. Coach and mentor your team to support their professional development, fostering an environment of continuous learning and improvement. Develop and maintain our security operations policies, processes and playbooks. Maintain an up to date knowledge of the latest security tools and technologies, and how these could be used to mitigate our priority threats. Provide regular reports on security status, incidents and KRIs to senior management and stakeholders. Candidate Profile 6+ years experience in a security operations team, preferably 2 years in a management role. Demonstrable experience leading response to security incidents and breaches. Excellent understanding of defensive security strategies and cyber incident response processes. Excellent working knowledge of SIEM based tools and technologies. Excellent working knowledge of EDR and XDR technologies. Excellent working knowledge of firewalls and other network security appliances. Excellent problem solving and analytical skills, with the ability to make sound decisions under pressure. Excellent leadership and management skills, with strong communications and interpersonal skills. Good understanding of forensics technologies and processes. BSc or MSc in Cybersecurity is highly desirable. Advanced cyber certifications such as CISSP, CISM, GCIH and GPEN are desirable. Industry recognised security vendor certifications are desirable. Diversity & Benefits We hire the best people for the job and we're committed to diversity and creating a truly inclusive culture, which we believe drives success. Working life doesn't always have to be in the office, so we have introduced hybrid working to encourage a healthy work life balance. This hybrid working model is set by the team rather than the business to enable you to manage your own personal work life balance. Our benefits package includes a bonus, contributory pension, 25 days annual leave plus 2 Hiscox days and a 4 week paid sabbatical with every 5 years' worth of service, private medical for all the family and much more.
Realty Income Limited is seeking a Senior Information Security Analyst to support their global Information Security program. This role involves monitoring security alerts, incident investigation, and optimizing security tooling for better operational effectiveness. The ideal candidate will have 4-8 years of experience in information security, strong analytical skills, and knowledge of security frameworks. The position offers hybrid work arrangements and a commitment to diversity and inclusion.
27/07/2026
Full time
Realty Income Limited is seeking a Senior Information Security Analyst to support their global Information Security program. This role involves monitoring security alerts, incident investigation, and optimizing security tooling for better operational effectiveness. The ideal candidate will have 4-8 years of experience in information security, strong analytical skills, and knowledge of security frameworks. The position offers hybrid work arrangements and a commitment to diversity and inclusion.
Morson Human Resources Limited is looking for an Incident Response (CSIRT) / SOC Level 3 Analyst based in Crawley. This 6-month contract role focuses on investigating and responding to high-severity cyber security incidents, and enhancing response playbooks and SOC procedures. The ideal candidate will have strong SOC and cyber defense expertise, a proactive mindset, and experience managing incidents. Onsite work will be required for 2-3 days a week.
27/07/2026
Full time
Morson Human Resources Limited is looking for an Incident Response (CSIRT) / SOC Level 3 Analyst based in Crawley. This 6-month contract role focuses on investigating and responding to high-severity cyber security incidents, and enhancing response playbooks and SOC procedures. The ideal candidate will have strong SOC and cyber defense expertise, a proactive mindset, and experience managing incidents. Onsite work will be required for 2-3 days a week.
We believe great work thrives in an environment where people feel genuinely supported and fairly rewarded. Our benefits are designed to create real value for every individual - fueling engagement, performance, and growth. By prioritizing well-being, we build a workplace where personal and organizational success grow together. The world is rapidly moving towards more efficient power distribution to support renewable, greener technologies. At Hitachi Energy, we are at the forefront of this revolution, delivering cutting-edge solutions to customers and countries across the globe. Our mission is not just a goal, but a passion that drives us every day. However, our journey to a greener future is challenged by an increasingly complex and disruptive cybersecurity landscape. This is where you come in. By joining our Cyber Defense Center (CDC) team as a Cybersecurity Incident Response Analyst, you will play a crucial role in protecting and advancing our mission. You will help safeguard our innovative work in renewable energy, ensuring our operations remain secure and uninterrupted. As part of this role, you will support Security Monitoring services alongside our MSSP, assist in responding to cybersecurity incidents, and collaborate with expert Incident Managers during high-priority events. You'll work with a diverse, multicultural team across the globe, contributing to our 24/7 response capabilities throughout the year. In our modern, hybrid environment, you will gain exposure to a wide range of cybersecurity incidents, including legacy IT, Cloud, OT/ICS, supply chain, and product security. You will also have the opportunity to work with the latest security tools, including next-generation AI-enabled platforms. How you'll make an impact: Monitor security systems and alerts to identify potential incidents. Assist in the initial investigation of security incidents, performing triage and escalating to senior team members as needed. Document and report on findings from security monitoring activities. Collaborate with the 24/7 Security Monitoring team to ensure timely detection and response to threats. Support Incident Response processes by gathering relevant information and aiding in analysis. Participate in the development and improvement of incident response playbooks, procedures, and workflows. Assist with post-incident reviews and the documentation of lessons learned. Assist in ensuring that incident response activities align with regulatory requirements and organisational policies. Your Background: Bachelor's Degree in Cyber Security, Information Technology, Computer Science, or a related field; OR equivalent experience with A Levels/BTEC. Experience in a cybersecurity-related role, such as Security Operations, Threat Detection, or IT Support, preferably within an enterprise environment. Familiarity with security monitoring tools, SIEM platforms, and basic threat detection techniques. Good communication and teamwork skills, with the ability to work collaboratively with technical and non-technical stakeholders. Flexibility to be on-call for duties and assist in response to incidents outside regular working hours as needed. Eagerness to grow within the cybersecurity field and contribute to the overall security posture of the organization. More about us: Hitachi Energy is dedicated to fostering an inclusive workplace where every team member can thrive and contribute their unique perspectives and skills. We provide competitive salaries, flexible working hours, professional development opportunities, and a supportive work environment that encourages growth and innovation through career development programs and Employee Resource Groups (ERGs). Specific benefits depend on the location and will be communicated during the interview process. We are a global leader in electrification, powering the electricity era to meet the energy demands of today, and the next 25 years. As the energy arm of Hitachi Group, over three billion people depend on our pioneering, mission-critical technologies to power their daily lives. With over a century of innovation, we are addressing the most urgent energy challenge of our time: driving the evolution of the world's energy system to ensure abundant, secure, affordable, and sustainable power for today's generation and the next. With an unparalleled installed base in over 140 countries, we are the grid ecosystem partner across the utility, industry, data center, and transportation sectors. Headquartered in Switzerland, we employ over 56,000 people in 60 countries and generate revenues of around $20 billion USD.
27/07/2026
Full time
We believe great work thrives in an environment where people feel genuinely supported and fairly rewarded. Our benefits are designed to create real value for every individual - fueling engagement, performance, and growth. By prioritizing well-being, we build a workplace where personal and organizational success grow together. The world is rapidly moving towards more efficient power distribution to support renewable, greener technologies. At Hitachi Energy, we are at the forefront of this revolution, delivering cutting-edge solutions to customers and countries across the globe. Our mission is not just a goal, but a passion that drives us every day. However, our journey to a greener future is challenged by an increasingly complex and disruptive cybersecurity landscape. This is where you come in. By joining our Cyber Defense Center (CDC) team as a Cybersecurity Incident Response Analyst, you will play a crucial role in protecting and advancing our mission. You will help safeguard our innovative work in renewable energy, ensuring our operations remain secure and uninterrupted. As part of this role, you will support Security Monitoring services alongside our MSSP, assist in responding to cybersecurity incidents, and collaborate with expert Incident Managers during high-priority events. You'll work with a diverse, multicultural team across the globe, contributing to our 24/7 response capabilities throughout the year. In our modern, hybrid environment, you will gain exposure to a wide range of cybersecurity incidents, including legacy IT, Cloud, OT/ICS, supply chain, and product security. You will also have the opportunity to work with the latest security tools, including next-generation AI-enabled platforms. How you'll make an impact: Monitor security systems and alerts to identify potential incidents. Assist in the initial investigation of security incidents, performing triage and escalating to senior team members as needed. Document and report on findings from security monitoring activities. Collaborate with the 24/7 Security Monitoring team to ensure timely detection and response to threats. Support Incident Response processes by gathering relevant information and aiding in analysis. Participate in the development and improvement of incident response playbooks, procedures, and workflows. Assist with post-incident reviews and the documentation of lessons learned. Assist in ensuring that incident response activities align with regulatory requirements and organisational policies. Your Background: Bachelor's Degree in Cyber Security, Information Technology, Computer Science, or a related field; OR equivalent experience with A Levels/BTEC. Experience in a cybersecurity-related role, such as Security Operations, Threat Detection, or IT Support, preferably within an enterprise environment. Familiarity with security monitoring tools, SIEM platforms, and basic threat detection techniques. Good communication and teamwork skills, with the ability to work collaboratively with technical and non-technical stakeholders. Flexibility to be on-call for duties and assist in response to incidents outside regular working hours as needed. Eagerness to grow within the cybersecurity field and contribute to the overall security posture of the organization. More about us: Hitachi Energy is dedicated to fostering an inclusive workplace where every team member can thrive and contribute their unique perspectives and skills. We provide competitive salaries, flexible working hours, professional development opportunities, and a supportive work environment that encourages growth and innovation through career development programs and Employee Resource Groups (ERGs). Specific benefits depend on the location and will be communicated during the interview process. We are a global leader in electrification, powering the electricity era to meet the energy demands of today, and the next 25 years. As the energy arm of Hitachi Group, over three billion people depend on our pioneering, mission-critical technologies to power their daily lives. With over a century of innovation, we are addressing the most urgent energy challenge of our time: driving the evolution of the world's energy system to ensure abundant, secure, affordable, and sustainable power for today's generation and the next. With an unparalleled installed base in over 140 countries, we are the grid ecosystem partner across the utility, industry, data center, and transportation sectors. Headquartered in Switzerland, we employ over 56,000 people in 60 countries and generate revenues of around $20 billion USD.
iomart Group's Atech division is seeking an experienced Level 3 SOC Analyst to join our Security Operations Centre. This senior role leads investigations, conducts threat hunting and mentors junior analysts to raise technical capability. You'll detect, analyse and respond to security incidents across endpoints, cloud and identity, reconstruct attack activity from multiple telemetry sources, and provide clear reports and recommendations to customers. A hybrid remote working model is available.
27/07/2026
Full time
iomart Group's Atech division is seeking an experienced Level 3 SOC Analyst to join our Security Operations Centre. This senior role leads investigations, conducts threat hunting and mentors junior analysts to raise technical capability. You'll detect, analyse and respond to security incidents across endpoints, cloud and identity, reconstruct attack activity from multiple telemetry sources, and provide clear reports and recommendations to customers. A hybrid remote working model is available.
What you'll be doing: At Atech, we believe cyber security is about more than reacting to threats - it's about staying ahead of them. As a leading provider of cloud, cyber security and managed services, we help organisations strengthen their security posture through innovation, expertise and a customer-first approach. We're looking for an experienced Level 3 SOC Analyst to join our growing Security Operations Centre (SOC). This is a senior technical role where you'll lead complex investigations, conduct advanced threat hunting activities and help shape the future of our SOC capability. You'll act as a technical authority during major security incidents while mentoring colleagues and driving continuous improvement across our security services. As a Level 3 SOC Analyst, you'll be: Leading complex cyber security incidents from initial investigation through to containment, eradication and recovery. Acting as the technical escalation point for high-priority and complex security events. Conducting advanced threat hunting activities across endpoint, cloud, identity and email environments. Correlating multiple telemetry sources to reconstruct attack chains, identify root causes and determine remediation actions. Providing clear and confident communication to customers and stakeholders during major security incidents. Developing and enhancing detection use cases, analytics and alert tuning within Microsoft Sentinel and Microsoft Defender XDR. Identifying opportunities to improve SOC processes, standards, tooling and operational maturity. Producing high-quality incident reports, lessons learned documentation and technical recommendations. Mentoring and coaching Level 1 and Level 2 SOC Analysts, helping to raise technical capability across the team. Supporting vulnerability assessment and security posture improvement activities when required. Collaborating with internal and customer technical teams to coordinate effective incident response and recovery. We want to hear from you if you: Have significant experience working within a Security Operations Centre environment. Possess advanced hands-on expertise with Microsoft Sentinel, Microsoft Defender XDR and Microsoft Entra ID Protection. Have a strong background in threat hunting, incident response and cyber security investigations. Can analyse and correlate data from multiple telemetry sources to uncover threats and reconstruct attack activity. Are confident leading major incidents and providing technical direction under pressure. Have experience improving detection logic, tuning security tools and enhancing SOC effectiveness. Can communicate complex technical information clearly to both technical and non-technical audiences. Enjoy mentoring others and sharing knowledge to develop team capability. Demonstrate a proactive, analytical and continuous improvement mindset. Must hold Microsoft SC-200 Desirable Certifications SC-300 or SC-400 Microsoft AZ-500 GIAC GCIA, GCFA or GCED CREST CRT or CCT Other advanced cloud or cyber security certifications What's in it for me? Competitive salary and benefits package. Flexible hybrid working model with remote working opportunities. Exposure to a broad range of cyber security technologies and customer environments. Opportunity to work on complex and high-impact security incidents. Ongoing learning, certification and professional development support. Clear career progression within a growing cyber security practice. A collaborative and supportive team environment where knowledge sharing is encouraged. The opportunity to influence SOC maturity, service innovation and security outcomes for our customers. Who you'll be doing it for: Atech part of the Iomart Group is a highly accredited Microsoft Partner who delivers transformed technology with managed services. Our team of certified Microsoft experts align with your team to deliver an excellent service tailored to your individual needs, 24/7/365. Our services support 25,000 users globally and proactively monitor 45,000+ devices in key areas: Azure infrastructure managed service Modern Workplace: Office 365, Microsoft 365, and Azure Virtual Desktop Managed Security and SOC with Microsoft Defender, Sentinel We're an equal opportunities employer and want our vacancies to be available to all, so if you need us to make any reasonable adjustments during the process then just let us know.
27/07/2026
Full time
What you'll be doing: At Atech, we believe cyber security is about more than reacting to threats - it's about staying ahead of them. As a leading provider of cloud, cyber security and managed services, we help organisations strengthen their security posture through innovation, expertise and a customer-first approach. We're looking for an experienced Level 3 SOC Analyst to join our growing Security Operations Centre (SOC). This is a senior technical role where you'll lead complex investigations, conduct advanced threat hunting activities and help shape the future of our SOC capability. You'll act as a technical authority during major security incidents while mentoring colleagues and driving continuous improvement across our security services. As a Level 3 SOC Analyst, you'll be: Leading complex cyber security incidents from initial investigation through to containment, eradication and recovery. Acting as the technical escalation point for high-priority and complex security events. Conducting advanced threat hunting activities across endpoint, cloud, identity and email environments. Correlating multiple telemetry sources to reconstruct attack chains, identify root causes and determine remediation actions. Providing clear and confident communication to customers and stakeholders during major security incidents. Developing and enhancing detection use cases, analytics and alert tuning within Microsoft Sentinel and Microsoft Defender XDR. Identifying opportunities to improve SOC processes, standards, tooling and operational maturity. Producing high-quality incident reports, lessons learned documentation and technical recommendations. Mentoring and coaching Level 1 and Level 2 SOC Analysts, helping to raise technical capability across the team. Supporting vulnerability assessment and security posture improvement activities when required. Collaborating with internal and customer technical teams to coordinate effective incident response and recovery. We want to hear from you if you: Have significant experience working within a Security Operations Centre environment. Possess advanced hands-on expertise with Microsoft Sentinel, Microsoft Defender XDR and Microsoft Entra ID Protection. Have a strong background in threat hunting, incident response and cyber security investigations. Can analyse and correlate data from multiple telemetry sources to uncover threats and reconstruct attack activity. Are confident leading major incidents and providing technical direction under pressure. Have experience improving detection logic, tuning security tools and enhancing SOC effectiveness. Can communicate complex technical information clearly to both technical and non-technical audiences. Enjoy mentoring others and sharing knowledge to develop team capability. Demonstrate a proactive, analytical and continuous improvement mindset. Must hold Microsoft SC-200 Desirable Certifications SC-300 or SC-400 Microsoft AZ-500 GIAC GCIA, GCFA or GCED CREST CRT or CCT Other advanced cloud or cyber security certifications What's in it for me? Competitive salary and benefits package. Flexible hybrid working model with remote working opportunities. Exposure to a broad range of cyber security technologies and customer environments. Opportunity to work on complex and high-impact security incidents. Ongoing learning, certification and professional development support. Clear career progression within a growing cyber security practice. A collaborative and supportive team environment where knowledge sharing is encouraged. The opportunity to influence SOC maturity, service innovation and security outcomes for our customers. Who you'll be doing it for: Atech part of the Iomart Group is a highly accredited Microsoft Partner who delivers transformed technology with managed services. Our team of certified Microsoft experts align with your team to deliver an excellent service tailored to your individual needs, 24/7/365. Our services support 25,000 users globally and proactively monitor 45,000+ devices in key areas: Azure infrastructure managed service Modern Workplace: Office 365, Microsoft 365, and Azure Virtual Desktop Managed Security and SOC with Microsoft Defender, Sentinel We're an equal opportunities employer and want our vacancies to be available to all, so if you need us to make any reasonable adjustments during the process then just let us know.
A global energy and natural resources consulting firm in Edinburgh is seeking a Cyber Security Lead Analyst with over 5 years of cybersecurity experience and at least 3 years focusing on cloud security. This role involves monitoring security events, investigating incidents, and leading cybersecurity initiatives across cloud platforms. The ideal candidate should have strong analytical skills, proficiency with various security tools, and the ability to work collaboratively within a team. A bachelor's degree in a related field is required, along with relevant certifications.
27/07/2026
Full time
A global energy and natural resources consulting firm in Edinburgh is seeking a Cyber Security Lead Analyst with over 5 years of cybersecurity experience and at least 3 years focusing on cloud security. This role involves monitoring security events, investigating incidents, and leading cybersecurity initiatives across cloud platforms. The ideal candidate should have strong analytical skills, proficiency with various security tools, and the ability to work collaboratively within a team. A bachelor's degree in a related field is required, along with relevant certifications.
Senior Information Security Analyst - Audit & Compliance ISO27001, SOC2, PCI-DSS, NIST, GDPR London (Barbican). Hybrid. 2 days a week onsite. Up to £100k plus 8% bonus, pension, private medical etc We're working with a global technology partner to find a certified Information Security Analyst. This is a fantastic opportunity to join a company that's setting the highest standards in cybersecurity and security compliance. You'll play a key role in ensuring compliance with leading security frameworks, preparing for and conducting audits, and contributing to security operations. You'll be joining a collaborative, ambitious team where there are genuine long-term career prospects and endless opportunities to develop. The Role Lead and conduct internal audits across ISO 27001, GDPR, DORA, Cyber Essentials & more. Prepare teams for external audits and manage the audit process end-to-end. Monitor changes in compliance frameworks and maintain alignment. Support the Cyber Security Operations Centre (CSOC) in incident monitoring and response. Develop and maintain policies, procedures, and security documentation. Collaborate with IT & Security teams to identify and remediate vulnerabilities. What We're Looking For Strong knowledge of audit & compliance frameworks (ISO 27001,SOC2, PCI DSS, Cyber Essentials) Experience with CSOC tools such as Rapid7 InsightIDR or other SIEM solutions. Hands-on experience with internal/external audits and compliance assessments. Relevant security/audit certifications (CISA, CISM, CISSP, ISO 27001 Lead Auditor, Cyber Essentials Assessor, or equivalent). Eligible for UK Security Clearance. What's In It For You? Salary approx £100,000 + 8% Bonus, Pension, Healthcare, Flexi-Working and much more. Hybrid working (2 days in the London office). Excellent long-term career growth with a global organisation.
27/07/2026
Full time
Senior Information Security Analyst - Audit & Compliance ISO27001, SOC2, PCI-DSS, NIST, GDPR London (Barbican). Hybrid. 2 days a week onsite. Up to £100k plus 8% bonus, pension, private medical etc We're working with a global technology partner to find a certified Information Security Analyst. This is a fantastic opportunity to join a company that's setting the highest standards in cybersecurity and security compliance. You'll play a key role in ensuring compliance with leading security frameworks, preparing for and conducting audits, and contributing to security operations. You'll be joining a collaborative, ambitious team where there are genuine long-term career prospects and endless opportunities to develop. The Role Lead and conduct internal audits across ISO 27001, GDPR, DORA, Cyber Essentials & more. Prepare teams for external audits and manage the audit process end-to-end. Monitor changes in compliance frameworks and maintain alignment. Support the Cyber Security Operations Centre (CSOC) in incident monitoring and response. Develop and maintain policies, procedures, and security documentation. Collaborate with IT & Security teams to identify and remediate vulnerabilities. What We're Looking For Strong knowledge of audit & compliance frameworks (ISO 27001,SOC2, PCI DSS, Cyber Essentials) Experience with CSOC tools such as Rapid7 InsightIDR or other SIEM solutions. Hands-on experience with internal/external audits and compliance assessments. Relevant security/audit certifications (CISA, CISM, CISSP, ISO 27001 Lead Auditor, Cyber Essentials Assessor, or equivalent). Eligible for UK Security Clearance. What's In It For You? Salary approx £100,000 + 8% Bonus, Pension, Healthcare, Flexi-Working and much more. Hybrid working (2 days in the London office). Excellent long-term career growth with a global organisation.
Sr. Software Engineer, Cloud (Hybrid, London)Applylocations: United Kingdom - Londontime type: Full timeposted on: Posted Todayjob requisition id: R29015As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn't changed - we're here to stop breaches, and we've redefined modern security with the world's most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We're always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you. About the Role: Does building systems that help security analysts close a critical incident before it becomes a breach excite you? Does correlating and analyzing data at trillions-of-events-per-day scale sound like the kind of challenge you want to wake up to? Do you care deeply about cybersecurity and want to play an active role in helping organizations defend themselves from sophisticated cyberattacks? We'd love to meet you.We are seeking a Senior Software Engineer, Cloud to join our Threat Detection and Incident Response (TDIR) team, helping revolutionize security management with our AI-native Falcon Next-Gen SIEM platform - enabling customers to detect, investigate, and hunt down threats 150x faster at Petabyte scale.You'll design, architect, and develop world-class case management and investigation capabilities in Go, empowering security analysts to be more effective at incident response, threat hunting, and collaborative investigations. You'll build intelligent workflows that connect detections, evidence, and response actions into cohesive cases. Leveraging advanced correlation, contextual enrichment, and AI/ML-powered insights, you'll help security teams work smarter through intelligent threat prioritization, automated investigation suggestions, and agentic analyst workflows - helping them respond faster to emerging threats. While Go experience is preferred, strong backend engineers from other languages who can demonstrate rapid adaptability and a track record of delivering at scale are welcome to apply. If this is the kind of scale and impact you're looking for, we'd love to hear from you. What You'll do: Own the engineering bar . Drive architectural improvements, set the standard for code quality, and ensure our systems are performant, reliable, and built to last - not just for today's scale, but for what's next Lead system design and architecture decisions, including design reviews and RFC processes Develop Go-based microservices supporting threat detection, case management, and incident response workflows, alongside RESTful APIs that power customer-facing capabilities Take end-to-end ownership of technical initiatives, both individually and as part of a team, across projects of increasing scope and complexity Work closely with designers, product managers, and engineers across product groups to understand, design, and implement solutions Mentor junior and mid-level engineers through pair programming, code reviews, and one-on-one knowledge sharing Contribute to AI-powered capabilities including LLM integration, agentic workflows, and intelligent analyst tooling Participate in the on-call rotation and drive improvements that reduce your teams toil and increase system reliability Operate with a high degree of autonomy - you'll be trusted to make decisions and drive outcomes What You'll Need: A collaborative team player who lifts those around them (We believe in: One team. One fight !) 8 + years of professional software engineering experience, with 5+ years building and operating distributed systems or cloud-native services at scale in production Solid understanding of distributed systems, scalability, RESTful patterns, and multithreading concepts Proficiency building and scaling resilient, low-latency services in production using Go, Python, Java, C++, or C# Hands-on experience with Docker, Kubernetes, and cloud platforms, preferably AWS or GCP Strong communicator and collaborator across functions and levels, with a bias for ownership and a customer-first mindset Proven ability to translate complex and ambiguous business requirements into technical solutions and deliver projects on schedule Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes. Bonus points: Currently developing Go-based microservices for scalable, high-throughput architectures Experience in cybersecurity, SIEM, SOAR, or adjacent security domains Hands-on experience with LLM integration, prompt engineering, RAG pipelines, or agentic AI frameworks Benefits of Working at CrowdStrike: Market leader in compensation and equity awards Comprehensive physical and mental wellness programs Competitive vacation and holidays for recharge Paid parental and adoption leaves Professional development opportunities for all employees regardless of level or role Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections Vibrant office culture with world class amenities Great Place to Work CertifiedTM across the globe CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program.CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs on valid job requirements. If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at for further assistance.
27/07/2026
Full time
Sr. Software Engineer, Cloud (Hybrid, London)Applylocations: United Kingdom - Londontime type: Full timeposted on: Posted Todayjob requisition id: R29015As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn't changed - we're here to stop breaches, and we've redefined modern security with the world's most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We're always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you. About the Role: Does building systems that help security analysts close a critical incident before it becomes a breach excite you? Does correlating and analyzing data at trillions-of-events-per-day scale sound like the kind of challenge you want to wake up to? Do you care deeply about cybersecurity and want to play an active role in helping organizations defend themselves from sophisticated cyberattacks? We'd love to meet you.We are seeking a Senior Software Engineer, Cloud to join our Threat Detection and Incident Response (TDIR) team, helping revolutionize security management with our AI-native Falcon Next-Gen SIEM platform - enabling customers to detect, investigate, and hunt down threats 150x faster at Petabyte scale.You'll design, architect, and develop world-class case management and investigation capabilities in Go, empowering security analysts to be more effective at incident response, threat hunting, and collaborative investigations. You'll build intelligent workflows that connect detections, evidence, and response actions into cohesive cases. Leveraging advanced correlation, contextual enrichment, and AI/ML-powered insights, you'll help security teams work smarter through intelligent threat prioritization, automated investigation suggestions, and agentic analyst workflows - helping them respond faster to emerging threats. While Go experience is preferred, strong backend engineers from other languages who can demonstrate rapid adaptability and a track record of delivering at scale are welcome to apply. If this is the kind of scale and impact you're looking for, we'd love to hear from you. What You'll do: Own the engineering bar . Drive architectural improvements, set the standard for code quality, and ensure our systems are performant, reliable, and built to last - not just for today's scale, but for what's next Lead system design and architecture decisions, including design reviews and RFC processes Develop Go-based microservices supporting threat detection, case management, and incident response workflows, alongside RESTful APIs that power customer-facing capabilities Take end-to-end ownership of technical initiatives, both individually and as part of a team, across projects of increasing scope and complexity Work closely with designers, product managers, and engineers across product groups to understand, design, and implement solutions Mentor junior and mid-level engineers through pair programming, code reviews, and one-on-one knowledge sharing Contribute to AI-powered capabilities including LLM integration, agentic workflows, and intelligent analyst tooling Participate in the on-call rotation and drive improvements that reduce your teams toil and increase system reliability Operate with a high degree of autonomy - you'll be trusted to make decisions and drive outcomes What You'll Need: A collaborative team player who lifts those around them (We believe in: One team. One fight !) 8 + years of professional software engineering experience, with 5+ years building and operating distributed systems or cloud-native services at scale in production Solid understanding of distributed systems, scalability, RESTful patterns, and multithreading concepts Proficiency building and scaling resilient, low-latency services in production using Go, Python, Java, C++, or C# Hands-on experience with Docker, Kubernetes, and cloud platforms, preferably AWS or GCP Strong communicator and collaborator across functions and levels, with a bias for ownership and a customer-first mindset Proven ability to translate complex and ambiguous business requirements into technical solutions and deliver projects on schedule Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes. Bonus points: Currently developing Go-based microservices for scalable, high-throughput architectures Experience in cybersecurity, SIEM, SOAR, or adjacent security domains Hands-on experience with LLM integration, prompt engineering, RAG pipelines, or agentic AI frameworks Benefits of Working at CrowdStrike: Market leader in compensation and equity awards Comprehensive physical and mental wellness programs Competitive vacation and holidays for recharge Paid parental and adoption leaves Professional development opportunities for all employees regardless of level or role Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections Vibrant office culture with world class amenities Great Place to Work CertifiedTM across the globe CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program.CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs on valid job requirements. If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at for further assistance.
Job Description To support the Head of Security Operations in delivering effective day-to-day security operations, ensuring AJ Bell maintains the appropriate capability to detect, investigate and respond to security events and incidents. The Security Operations Technical Lead is responsible for ensuring that security operations activities are executed efficiently, consistently and in line with defined SLAs and operational standards, through hands on technical leadership across SOC, Incident Response, Threat Intelligence, Insider Risk and Vulnerability Management. This role acts as a senior technical escalation point, supporting complex investigations and driving improvements in detection, response, automation and operational processes. The role holder is expected to lead through expertise, supporting analysts and ensuring Security Operations operates with discipline, quality and continuous improvement. The key responsibilities of the role are: Act as the primary technical escalation point for security events and incidents identified by the Security Operations team. Support the Head of Security Operations in ensuring AJ Bell has the appropriate capability to detect and respond to security events and incidents. Oversee the day to day execution of security operations, ensuring alerts and incidents are handled in line with defined processes and SLAs. Ensure security operations SLAs and OLAs are met, including alert triage, escalation and incident response timelines, highlighting and addressing risks where required. Ensure adherence to our KRI and KPI's and any variation in these are raised to the Head of Security Operations. Provide hands on support in the investigation and response to security incidents, including endpoint, identity, network, cloud and insider related threats. Ensure consistent execution and continuous improvement of incident response playbooks and operational runbooks, validating them through real incidents and simulations. Support the optimisation and tuning of security monitoring and detection capabilities, including SIEM and endpoint tooling, to improve signal quality and reduce false positives. Support the execution of the end to end vulnerability management process, including validation of findings and tracking remediation activities. Work closely with MSSP and security vendors to ensure effective delivery of security operations services. Challenge and validate vendor outputs, driving operational efficiency, quality improvements and better use of tooling capabilities. Actively design and implement automation and orchestration to reduce manual effort, repetitive or high volume tasks, improve response times and increase consistency across security operations processes. Work with the Security Engineering team to ensure tooling, logging and detection gaps are identified and addressed. Support the effective operation of 24x7 security monitoring, including coordination with third party providers. Contribute to the development and delivery of operational MI and reporting, ensuring accuracy and insight into security trends and performance. Maintain visibility of security incidents, trends and operational risks, escalating issues where required. Technical Skills: Strong hands on experience of Security Operations tools and capabilities, including SIEM and SOAR platforms (e.g. Sentinel, ServiceNow, Splunk SOAR, Cortex), Endpoint Detection & Response (EDR/XDR), Strong hands on experience of Threat Intelligence platforms (e.g. Recorded Future, Doppel, ZeroFox, Google Threat Intelligence), Vulnerability management solutions (e.g. Tenable, Rapid7), and Insider Risk and DLP tools (e.g. Purview, Netskope). Strong hands on experience with Network security solutions like Next Gen Firewalls, Network Anomaly, WAF & DDoS solutions. Experience of leading and responding to Cyber Incident Response aligned to NIST Knowledge of threat detection techniques and use case development Experience of applying threat intelligence in an operational context Strong experience with vulnerability management tools and processes Strong awareness of cloud services and supporting security controls and monitoring capabilities Working knowledge of Microsoft security stack (Defender, Sentinel, Purview), Active Directory and Azure AD, Windows and Linux environments. Experience with data loss prevention and insider risk tooling advantageous Hands on experience with automation and scripting (e.g. PowerShell, Python) highly desirable Competence Experience working within recognised Information Security frameworks and best practices such as ISO27001, NIST, MITRE ATT&CK Knowledge of relevant regulatory requirements (e.g. GDPR, FCA/PRA) Experience in an Information Security role gained in a financial services environment preferred Experience working in a Security Operations role for a minimum 7 years and operating within a Lead / Senior Analyst role for at least 3 years. Knowledge & Skills Strong analytical and investigative capability Ability to work under pressure and manage multiple concurrent incidents and priorities Strong ownership of tasks, attention to detail and follow through to conclusion Ability to provide technical leadership without formal line management responsibility Ability to challenge approach, tooling and processes to improve operational effectiveness Structured, self starting and able to work under own initiative Effective communication skills, both written and verbal Ability to plan, organise and deliver tasks with minimal supervision Collaborative approach to working with analysts, engineering teams and external partners Strong focus on quality, consistency and continuous improvement About AJ Bell At AJ Bell, we believe investing should feel good. Whether you're looking for an ISA, pension or dealing account, whether you want to invest with the help of a financial adviser or do it yourself, we have easy to use solutions to suit people from all walks of life. We're one of the UK's fastest growing investment platform businesses, trusted by everyone from professional financial advisers to first time investors. Today, over 723,000 customers trust us to manage more than £108.7 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures. We're proud to be recognised as one of the UK's Best 100 Companies to Work For for six consecutive years, and a Great Place to Work in 2025 and 2026, a reflection of our supportive and collaborative culture. What we offer Competitive starting salary 26days holiday, increasing with service + buy/sell scheme + bank holidays 7% Pension with matched contributions Discretionary bonus scheme Share schemes (including free shares and BAYE) Health Cash Plan and discounted private healthcare Free gym Enhanced family leave (subject to qualifying criteria) Travel and bike loan schemes Employee Assistance Programme Life at AJ Bell Regular social events including summer and Christmas parties Learning and development opportunities tailored to you Casual dress code Friendly, supportive team environment Our ways of working At AJ Bell, our people are the heart of our culture. We believe in building strong connections by working together. That's why we offer a hybrid working model, where you'll spend a minimum of 50% of working time per month in the office. For new team members, an initial period will be spent full time in the office to help you immerse yourself in our business and build valuable relationships with your colleagues. Inclusion & diversity We're committed to creating an inclusive environment where everyone feels respected, supported and able to be themselves at work. We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential. Agency information This vacancy is being managed exclusively by our in house Recruitment team. We are not partnering with recruitment agencies on this opportunity and will only accept applications submitted directly by candidates
27/07/2026
Full time
Job Description To support the Head of Security Operations in delivering effective day-to-day security operations, ensuring AJ Bell maintains the appropriate capability to detect, investigate and respond to security events and incidents. The Security Operations Technical Lead is responsible for ensuring that security operations activities are executed efficiently, consistently and in line with defined SLAs and operational standards, through hands on technical leadership across SOC, Incident Response, Threat Intelligence, Insider Risk and Vulnerability Management. This role acts as a senior technical escalation point, supporting complex investigations and driving improvements in detection, response, automation and operational processes. The role holder is expected to lead through expertise, supporting analysts and ensuring Security Operations operates with discipline, quality and continuous improvement. The key responsibilities of the role are: Act as the primary technical escalation point for security events and incidents identified by the Security Operations team. Support the Head of Security Operations in ensuring AJ Bell has the appropriate capability to detect and respond to security events and incidents. Oversee the day to day execution of security operations, ensuring alerts and incidents are handled in line with defined processes and SLAs. Ensure security operations SLAs and OLAs are met, including alert triage, escalation and incident response timelines, highlighting and addressing risks where required. Ensure adherence to our KRI and KPI's and any variation in these are raised to the Head of Security Operations. Provide hands on support in the investigation and response to security incidents, including endpoint, identity, network, cloud and insider related threats. Ensure consistent execution and continuous improvement of incident response playbooks and operational runbooks, validating them through real incidents and simulations. Support the optimisation and tuning of security monitoring and detection capabilities, including SIEM and endpoint tooling, to improve signal quality and reduce false positives. Support the execution of the end to end vulnerability management process, including validation of findings and tracking remediation activities. Work closely with MSSP and security vendors to ensure effective delivery of security operations services. Challenge and validate vendor outputs, driving operational efficiency, quality improvements and better use of tooling capabilities. Actively design and implement automation and orchestration to reduce manual effort, repetitive or high volume tasks, improve response times and increase consistency across security operations processes. Work with the Security Engineering team to ensure tooling, logging and detection gaps are identified and addressed. Support the effective operation of 24x7 security monitoring, including coordination with third party providers. Contribute to the development and delivery of operational MI and reporting, ensuring accuracy and insight into security trends and performance. Maintain visibility of security incidents, trends and operational risks, escalating issues where required. Technical Skills: Strong hands on experience of Security Operations tools and capabilities, including SIEM and SOAR platforms (e.g. Sentinel, ServiceNow, Splunk SOAR, Cortex), Endpoint Detection & Response (EDR/XDR), Strong hands on experience of Threat Intelligence platforms (e.g. Recorded Future, Doppel, ZeroFox, Google Threat Intelligence), Vulnerability management solutions (e.g. Tenable, Rapid7), and Insider Risk and DLP tools (e.g. Purview, Netskope). Strong hands on experience with Network security solutions like Next Gen Firewalls, Network Anomaly, WAF & DDoS solutions. Experience of leading and responding to Cyber Incident Response aligned to NIST Knowledge of threat detection techniques and use case development Experience of applying threat intelligence in an operational context Strong experience with vulnerability management tools and processes Strong awareness of cloud services and supporting security controls and monitoring capabilities Working knowledge of Microsoft security stack (Defender, Sentinel, Purview), Active Directory and Azure AD, Windows and Linux environments. Experience with data loss prevention and insider risk tooling advantageous Hands on experience with automation and scripting (e.g. PowerShell, Python) highly desirable Competence Experience working within recognised Information Security frameworks and best practices such as ISO27001, NIST, MITRE ATT&CK Knowledge of relevant regulatory requirements (e.g. GDPR, FCA/PRA) Experience in an Information Security role gained in a financial services environment preferred Experience working in a Security Operations role for a minimum 7 years and operating within a Lead / Senior Analyst role for at least 3 years. Knowledge & Skills Strong analytical and investigative capability Ability to work under pressure and manage multiple concurrent incidents and priorities Strong ownership of tasks, attention to detail and follow through to conclusion Ability to provide technical leadership without formal line management responsibility Ability to challenge approach, tooling and processes to improve operational effectiveness Structured, self starting and able to work under own initiative Effective communication skills, both written and verbal Ability to plan, organise and deliver tasks with minimal supervision Collaborative approach to working with analysts, engineering teams and external partners Strong focus on quality, consistency and continuous improvement About AJ Bell At AJ Bell, we believe investing should feel good. Whether you're looking for an ISA, pension or dealing account, whether you want to invest with the help of a financial adviser or do it yourself, we have easy to use solutions to suit people from all walks of life. We're one of the UK's fastest growing investment platform businesses, trusted by everyone from professional financial advisers to first time investors. Today, over 723,000 customers trust us to manage more than £108.7 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures. We're proud to be recognised as one of the UK's Best 100 Companies to Work For for six consecutive years, and a Great Place to Work in 2025 and 2026, a reflection of our supportive and collaborative culture. What we offer Competitive starting salary 26days holiday, increasing with service + buy/sell scheme + bank holidays 7% Pension with matched contributions Discretionary bonus scheme Share schemes (including free shares and BAYE) Health Cash Plan and discounted private healthcare Free gym Enhanced family leave (subject to qualifying criteria) Travel and bike loan schemes Employee Assistance Programme Life at AJ Bell Regular social events including summer and Christmas parties Learning and development opportunities tailored to you Casual dress code Friendly, supportive team environment Our ways of working At AJ Bell, our people are the heart of our culture. We believe in building strong connections by working together. That's why we offer a hybrid working model, where you'll spend a minimum of 50% of working time per month in the office. For new team members, an initial period will be spent full time in the office to help you immerse yourself in our business and build valuable relationships with your colleagues. Inclusion & diversity We're committed to creating an inclusive environment where everyone feels respected, supported and able to be themselves at work. We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential. Agency information This vacancy is being managed exclusively by our in house Recruitment team. We are not partnering with recruitment agencies on this opportunity and will only accept applications submitted directly by candidates
Yusen Logistics is working to become the world's preferred supply chain logistics company. Our complete offer is designed to forge better connections between businesses, customers and communities - through innovative supply chain management, freight forwarding, warehousing and distribution services. As a company we're dedicated to a culture of continuous improvement, ensuring everyone who works with us is committed, connected and creative in making us the world's preferred choice. We are looking for a proactive and customer-focused IT Support Analyst (2nd Line) to join our IT team in our Sustainable Distribution Centre in Northampton. This role is ideal for someone who enjoys solving technical challenges, improving user experiences, and contributing to business critical IT projects in the cutting edge logistics facility. What we offer: Base salary of £39,339.24 25 days' holiday (excluding bank holidays) and 5 days Volunteer Leave per year Opportunity for Unpaid Leave Up to 10 days international remote working Free Eye Test Employee Referral Scheme Cycle to Work scheme Critical Illness Cover Free online Fitness Platform i.e., Pilates & Yoga, Mindfulness/Meditation, 24/7 support, advice, diet and Nutrition On Site Mental health First Aiders Employee benefits i.e., Free eye test , up to 25% off gym membership, high street vouchers Free access to 24/7 online GP, mental health support service, Life Events Counselling, Care Concierge Service, Health Cash Plan, Karo Health. Tailored development and career opportunities Key Responsibilities 1. IT Infrastructure Support Manage local site IT projects from initial planning through to successful delivery. Work with project teams to transition new solutions into Business as Usual (BAU), ensuring documentation is completed and maintained. Provide 2nd line support for users, hardware, software, and network services across multiple locations through ServiceNow, telephone, and email channels. Investigate and resolve infrastructure issues relating to software, hardware, and networking in a timely manner. Perform network troubleshooting, including IP addressing, VLANs, wireless technologies, switching, routing, protocols, and diagnostic tools. Support ongoing maintenance activities including system updates, service packs, hotfixes, and software upgrades. Ensure endpoint security and anti virus solutions remain current across the IT estate. Share knowledge with colleagues, support the development of 1st line teams, and collaborate with 3rd line specialists to continually broaden technical expertise. Maintain clear, accurate, and consistent technical documentation and work instructions. Adhere to IT governance, change management processes, and operational policies. Participate in out of hours support activities where required. Provide on site support during normal business hours. 2. Stakeholder Support (On Site) Deliver a high quality, customer focused support experience to employees and stakeholders. Build strong working relationships across departments to understand operational needs and improve service delivery. Provide clear technical guidance and advice to users of varying technical abilities. Support senior stakeholders, VIP users, and business critical functions with professionalism and discretion. Manage stakeholder expectations effectively, ensuring requirements are clearly understood and communicated. 3. Project & Initiative Delivery Contribute to IT and operational projects including technology rollouts, upgrades, migrations, and infrastructure improvements. Assist with planning, testing, and implementation of new technologies and solutions. Work collaboratively with internal IT teams and external suppliers to achieve successful project outcomes. Identify opportunities for automation, process optimisation, and service enhancement. Support continuous improvement initiatives that increase efficiency, reliability, and customer satisfaction. 4. Continuous Improvement Stay up to date with emerging technologies, industry best practice, and market trends. Recommend and implement improvements that enhance operational effectiveness and customer experience. Continuously review processes and procedures to drive efficiency, innovation, and service excellence. Key Requirements Industry recognised IT qualification (MCSE or equivalent experience). ITIL Foundation knowledge, including Incident, Request, and Change Management processes. Experience working within a 2nd line IT support environment. Strong understanding of networking fundamentals including TCP/IP. Experience supporting Active Directory and Microsoft Entra user and group administration. Strong troubleshooting and diagnostic skills across hardware, software, and infrastructure environments. Experience with cloud based device management solutions such as Microsoft Intune or 42Gears. Infrastructure experience including cabling, hardware replacement, and network equipment support. Understanding of disaster recovery and business continuity principles. Experience managing or contributing to technical projects. Ability to independently investigate issues and implement effective solutions. Excellent customer service and service delivery focus. Strong attention to detail and ability to maintain accurate documentation. Excellent verbal and written communication skills, adapting communication style to different audiences. Ability to balance technical requirements with wider business and customer needs. Flexible, adaptable, and eager to learn new technologies. Full UK driving licence with willingness to travel occasionally within the UK. Strong understanding of network architecture, including DNS, reservations, and traffic management. Knowledge of resilient infrastructure design, including power, networking, and communications redundancy. Advanced experience supporting Zebra label printers, including ZPL configuration and troubleshooting. Experience with barcode scanning technologies and warehouse operations environments. Experience supporting senior business stakeholders and external customer representatives. Ability to challenge existing processes and implement best practice improvements. Experience working with third party suppliers and managing service delivery outcomes. Strong awareness of IT security principles and risk management practices. Understanding of Health & Safety requirements, RAMS, vendor management, and site compliance processes. Subject Matter Expert (SME) knowledge in one or more technical disciplines, with experience coaching colleagues and producing standard operating procedures. Experience handling escalated and complex technical incidents. We thank all applicants for their interest, however, only those under consideration will be contacted. Please note, applicants must have the legal right to work in the UK, as we are unable to offer visa sponsorship for this position. In Yusen Logistics, we understand the value of utilising AI and other technologies to support the application process but we encourage the candidates to use them to enhance their application and not replace their own effort and authenticity. Therefore, candidates should not rely on AI generated responses during the interview process. Yusen Logistics is an equal opportunities employer, who encourages applications from all suitably qualified and eligible applicants regardless of their personal circumstances. We make our recruiting decisions solely based on the skillset and experience. Diversity allows us to create an inclusive environment, where our employees can strive and grow their potential. Yusen Logistics are proud to be a 'Disability Confident Committed' employer.
26/07/2026
Full time
Yusen Logistics is working to become the world's preferred supply chain logistics company. Our complete offer is designed to forge better connections between businesses, customers and communities - through innovative supply chain management, freight forwarding, warehousing and distribution services. As a company we're dedicated to a culture of continuous improvement, ensuring everyone who works with us is committed, connected and creative in making us the world's preferred choice. We are looking for a proactive and customer-focused IT Support Analyst (2nd Line) to join our IT team in our Sustainable Distribution Centre in Northampton. This role is ideal for someone who enjoys solving technical challenges, improving user experiences, and contributing to business critical IT projects in the cutting edge logistics facility. What we offer: Base salary of £39,339.24 25 days' holiday (excluding bank holidays) and 5 days Volunteer Leave per year Opportunity for Unpaid Leave Up to 10 days international remote working Free Eye Test Employee Referral Scheme Cycle to Work scheme Critical Illness Cover Free online Fitness Platform i.e., Pilates & Yoga, Mindfulness/Meditation, 24/7 support, advice, diet and Nutrition On Site Mental health First Aiders Employee benefits i.e., Free eye test , up to 25% off gym membership, high street vouchers Free access to 24/7 online GP, mental health support service, Life Events Counselling, Care Concierge Service, Health Cash Plan, Karo Health. Tailored development and career opportunities Key Responsibilities 1. IT Infrastructure Support Manage local site IT projects from initial planning through to successful delivery. Work with project teams to transition new solutions into Business as Usual (BAU), ensuring documentation is completed and maintained. Provide 2nd line support for users, hardware, software, and network services across multiple locations through ServiceNow, telephone, and email channels. Investigate and resolve infrastructure issues relating to software, hardware, and networking in a timely manner. Perform network troubleshooting, including IP addressing, VLANs, wireless technologies, switching, routing, protocols, and diagnostic tools. Support ongoing maintenance activities including system updates, service packs, hotfixes, and software upgrades. Ensure endpoint security and anti virus solutions remain current across the IT estate. Share knowledge with colleagues, support the development of 1st line teams, and collaborate with 3rd line specialists to continually broaden technical expertise. Maintain clear, accurate, and consistent technical documentation and work instructions. Adhere to IT governance, change management processes, and operational policies. Participate in out of hours support activities where required. Provide on site support during normal business hours. 2. Stakeholder Support (On Site) Deliver a high quality, customer focused support experience to employees and stakeholders. Build strong working relationships across departments to understand operational needs and improve service delivery. Provide clear technical guidance and advice to users of varying technical abilities. Support senior stakeholders, VIP users, and business critical functions with professionalism and discretion. Manage stakeholder expectations effectively, ensuring requirements are clearly understood and communicated. 3. Project & Initiative Delivery Contribute to IT and operational projects including technology rollouts, upgrades, migrations, and infrastructure improvements. Assist with planning, testing, and implementation of new technologies and solutions. Work collaboratively with internal IT teams and external suppliers to achieve successful project outcomes. Identify opportunities for automation, process optimisation, and service enhancement. Support continuous improvement initiatives that increase efficiency, reliability, and customer satisfaction. 4. Continuous Improvement Stay up to date with emerging technologies, industry best practice, and market trends. Recommend and implement improvements that enhance operational effectiveness and customer experience. Continuously review processes and procedures to drive efficiency, innovation, and service excellence. Key Requirements Industry recognised IT qualification (MCSE or equivalent experience). ITIL Foundation knowledge, including Incident, Request, and Change Management processes. Experience working within a 2nd line IT support environment. Strong understanding of networking fundamentals including TCP/IP. Experience supporting Active Directory and Microsoft Entra user and group administration. Strong troubleshooting and diagnostic skills across hardware, software, and infrastructure environments. Experience with cloud based device management solutions such as Microsoft Intune or 42Gears. Infrastructure experience including cabling, hardware replacement, and network equipment support. Understanding of disaster recovery and business continuity principles. Experience managing or contributing to technical projects. Ability to independently investigate issues and implement effective solutions. Excellent customer service and service delivery focus. Strong attention to detail and ability to maintain accurate documentation. Excellent verbal and written communication skills, adapting communication style to different audiences. Ability to balance technical requirements with wider business and customer needs. Flexible, adaptable, and eager to learn new technologies. Full UK driving licence with willingness to travel occasionally within the UK. Strong understanding of network architecture, including DNS, reservations, and traffic management. Knowledge of resilient infrastructure design, including power, networking, and communications redundancy. Advanced experience supporting Zebra label printers, including ZPL configuration and troubleshooting. Experience with barcode scanning technologies and warehouse operations environments. Experience supporting senior business stakeholders and external customer representatives. Ability to challenge existing processes and implement best practice improvements. Experience working with third party suppliers and managing service delivery outcomes. Strong awareness of IT security principles and risk management practices. Understanding of Health & Safety requirements, RAMS, vendor management, and site compliance processes. Subject Matter Expert (SME) knowledge in one or more technical disciplines, with experience coaching colleagues and producing standard operating procedures. Experience handling escalated and complex technical incidents. We thank all applicants for their interest, however, only those under consideration will be contacted. Please note, applicants must have the legal right to work in the UK, as we are unable to offer visa sponsorship for this position. In Yusen Logistics, we understand the value of utilising AI and other technologies to support the application process but we encourage the candidates to use them to enhance their application and not replace their own effort and authenticity. Therefore, candidates should not rely on AI generated responses during the interview process. Yusen Logistics is an equal opportunities employer, who encourages applications from all suitably qualified and eligible applicants regardless of their personal circumstances. We make our recruiting decisions solely based on the skillset and experience. Diversity allows us to create an inclusive environment, where our employees can strive and grow their potential. Yusen Logistics are proud to be a 'Disability Confident Committed' employer.
Overview Job Description: We believe great work thrives in an environment where people feel genuinely supported and fairly rewarded. Our benefits are designed to create real value for every individual - fueling engagement, performance, and growth. By prioritizing well being, we build a workplace where personal and organizational success grow together. The world is rapidly moving towards more efficient power distribution to support renewable, greener technologies. At Hitachi Energy, we are at the forefront of this revolution, delivering cutting-edge solutions to customers and countries across the globe. Our mission is not just a goal, but a passion that drives us every day. However, our journey to a greener future is challenged by an increasingly complex and disruptive cybersecurity landscape. This is where you come in. By joining our Cyber Defense Center (CDC) team as a Cybersecurity Incident Response Analyst, you will play a crucial role in protecting and advancing our mission. You will help safeguard our innovative work in renewable energy, ensuring our operations remain secure and uninterrupted. As part of this role, you will support Security Monitoring services alongside our MSSP, assist in responding to cybersecurity incidents, and collaborate with expert Incident Managers during high-priority events. You'll work with a diverse, multicultural team across the globe, contributing to our 24/7 response capabilities throughout the year. In our modern, hybrid environment, you will gain exposure to a wide range of cybersecurity incidents, including legacy IT, Cloud, OT/ICS, supply chain, and product security. You will also have the opportunity to work with the latest security tools, including next-generation AI-enabled platforms. Responsibilities Monitor security systems and alerts to identify potential incidents. Assist in the initial investigation of security incidents, performing triage and escalating to senior team members as needed. Document and report on findings from security monitoring activities. Collaborate with the 24/7 Security Monitoring team to ensure timely detection and response to threats. Support Incident Response processes by gathering relevant information and aiding in analysis. Participate in the development and improvement of incident response playbooks, procedures, and workflows. Assist with post-incident reviews and the documentation of lessons learned. Assist in ensuring that incident response activities align with regulatory requirements and organisational policies. Qualifications Bachelor's Degree in Cyber Security, Information Technology, Computer Science, or a related field; OR equivalent experience with A Levels/BTEC. Experience in a cybersecurity-related role, such as Security Operations, Threat Detection, or IT Support, preferably within an enterprise environment. Familiarity with security monitoring tools, SIEM platforms, and basic threat detection techniques. Good communication and teamwork skills, with the ability to work collaboratively with technical and non-technical stakeholders. Flexibility to be on-call for duties and assist in response to incidents outside regular working hours as needed. Eagerness to grow within the cybersecurity field and contribute to the overall security posture of the organisation. More about us Hitachi Energy is dedicated to fostering an inclusive workplace where every team member can thrive and contribute their unique perspectives and skills. We provide competitive salaries, flexible working hours, professional development opportunities, and a supportive work environment that encourages growth and innovation through career development programs and Employee Resource Groups (ERGs). Specific benefits depend on the location and will be communicated during the interview process. Applications are open until insert date . Ready to make an impact? Apply now and join us to inspire the next era of sustainable energy! Accessibility and reasonable accommodation Qualified individuals with a disability may request a reasonable accommodation if you are unable or limited in your ability to use or access the Hitachi Energy career site as a result of your disability. You may request reasonable accommodations by completing a general inquiry form on our website. Please include your contact information and specific details about your required accommodation to support you during the job application process. This is solely for job seekers with disabilities requiring accessibility assistance or an accommodation in the job application process. Messages left for other purposes will not receive a response. Use of AI and automated tools in recruitment As part of our recruitment process, Hitachi Energy uses digital and automated tools, including AI-supported solutions, to assist with activities such as application screening, job matching, and interview scheduling. These tools are designed to support our recruiters and do not replace human decision-making. Candidate data is processed in accordance with applicable data protection and employment laws as well as Hitachi's Global Data Privacy Notice. Background Screening and Security Checks As part of the hiring process, Hitachi Energy conducts pre-employment background checks that may include verification of employment history, education, criminal records, and other relevant information, in accordance with applicable laws. For certain roles-particularly those involving access to sensitive information, financial responsibilities, client data, regulated environments, or security-sensitive functions-additional or more comprehensive background or security screenings may be required. These may include, but are not limited to, enhanced criminal history checks, credit history reviews (where legally permissible), sanctions screening, or other due diligence measures aligned with the responsibilities of the position. The scope and depth of any background or security review will be determined based on the nature of the role and business necessity, and will always be conducted in compliance with applicable federal, state, and local laws. Candidates will be notified and, where required, asked to provide consent prior to the initiation of any such checks.
26/07/2026
Full time
Overview Job Description: We believe great work thrives in an environment where people feel genuinely supported and fairly rewarded. Our benefits are designed to create real value for every individual - fueling engagement, performance, and growth. By prioritizing well being, we build a workplace where personal and organizational success grow together. The world is rapidly moving towards more efficient power distribution to support renewable, greener technologies. At Hitachi Energy, we are at the forefront of this revolution, delivering cutting-edge solutions to customers and countries across the globe. Our mission is not just a goal, but a passion that drives us every day. However, our journey to a greener future is challenged by an increasingly complex and disruptive cybersecurity landscape. This is where you come in. By joining our Cyber Defense Center (CDC) team as a Cybersecurity Incident Response Analyst, you will play a crucial role in protecting and advancing our mission. You will help safeguard our innovative work in renewable energy, ensuring our operations remain secure and uninterrupted. As part of this role, you will support Security Monitoring services alongside our MSSP, assist in responding to cybersecurity incidents, and collaborate with expert Incident Managers during high-priority events. You'll work with a diverse, multicultural team across the globe, contributing to our 24/7 response capabilities throughout the year. In our modern, hybrid environment, you will gain exposure to a wide range of cybersecurity incidents, including legacy IT, Cloud, OT/ICS, supply chain, and product security. You will also have the opportunity to work with the latest security tools, including next-generation AI-enabled platforms. Responsibilities Monitor security systems and alerts to identify potential incidents. Assist in the initial investigation of security incidents, performing triage and escalating to senior team members as needed. Document and report on findings from security monitoring activities. Collaborate with the 24/7 Security Monitoring team to ensure timely detection and response to threats. Support Incident Response processes by gathering relevant information and aiding in analysis. Participate in the development and improvement of incident response playbooks, procedures, and workflows. Assist with post-incident reviews and the documentation of lessons learned. Assist in ensuring that incident response activities align with regulatory requirements and organisational policies. Qualifications Bachelor's Degree in Cyber Security, Information Technology, Computer Science, or a related field; OR equivalent experience with A Levels/BTEC. Experience in a cybersecurity-related role, such as Security Operations, Threat Detection, or IT Support, preferably within an enterprise environment. Familiarity with security monitoring tools, SIEM platforms, and basic threat detection techniques. Good communication and teamwork skills, with the ability to work collaboratively with technical and non-technical stakeholders. Flexibility to be on-call for duties and assist in response to incidents outside regular working hours as needed. Eagerness to grow within the cybersecurity field and contribute to the overall security posture of the organisation. More about us Hitachi Energy is dedicated to fostering an inclusive workplace where every team member can thrive and contribute their unique perspectives and skills. We provide competitive salaries, flexible working hours, professional development opportunities, and a supportive work environment that encourages growth and innovation through career development programs and Employee Resource Groups (ERGs). Specific benefits depend on the location and will be communicated during the interview process. Applications are open until insert date . Ready to make an impact? Apply now and join us to inspire the next era of sustainable energy! Accessibility and reasonable accommodation Qualified individuals with a disability may request a reasonable accommodation if you are unable or limited in your ability to use or access the Hitachi Energy career site as a result of your disability. You may request reasonable accommodations by completing a general inquiry form on our website. Please include your contact information and specific details about your required accommodation to support you during the job application process. This is solely for job seekers with disabilities requiring accessibility assistance or an accommodation in the job application process. Messages left for other purposes will not receive a response. Use of AI and automated tools in recruitment As part of our recruitment process, Hitachi Energy uses digital and automated tools, including AI-supported solutions, to assist with activities such as application screening, job matching, and interview scheduling. These tools are designed to support our recruiters and do not replace human decision-making. Candidate data is processed in accordance with applicable data protection and employment laws as well as Hitachi's Global Data Privacy Notice. Background Screening and Security Checks As part of the hiring process, Hitachi Energy conducts pre-employment background checks that may include verification of employment history, education, criminal records, and other relevant information, in accordance with applicable laws. For certain roles-particularly those involving access to sensitive information, financial responsibilities, client data, regulated environments, or security-sensitive functions-additional or more comprehensive background or security screenings may be required. These may include, but are not limited to, enhanced criminal history checks, credit history reviews (where legally permissible), sanctions screening, or other due diligence measures aligned with the responsibilities of the position. The scope and depth of any background or security review will be determined based on the nature of the role and business necessity, and will always be conducted in compliance with applicable federal, state, and local laws. Candidates will be notified and, where required, asked to provide consent prior to the initiation of any such checks.
Job Description: Job Title: Security Detection & Response I Corporate Title: Up to Vice President Location: Chester Company Overview: At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being a diverse and inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us! Location Overview: Find us in the city of Chester, a destination renowned for its culture, history, and beauty. Working at Bank of America Chester offers a far-reaching global career for a world-renowned organisation, whilst being ideally situated against the backdrop of the rolling North Wales hills and the banks of the serene River Dee. Role Description: We are seeking a motivated and analytically driven Security Detection & Response Analyst (SDR I) to join the GIS Monitoring and Triage team. This role supports cybersecurity operations across threat detection, investigation, response, and continuous service improvement. The ideal candidate is an early-career security practitioner with strong analytical aptitude and foundational technical skills, who contributes to the detection and response lifecycle by supporting investigations and response activities under guidance. This role focuses on developing the ability to analyse security events, build contextual understanding of threats, and progressively operate with increasing independence across multiple security domains. The analyst will work alongside experienced practitioners to validate detections, investigate events, and execute response actions while building foundational skills in automation, orchestration, and AI-driven technologies. This team work on a follow the sun methodology with weekends and Bank holidays included, the shifts will be 4 10-hour shifts this will be Sunday - Wednesday or Wednesday to Saturday Responsibilities: Support the detection and response lifecycle (detect investigate respond improve) by triaging alerts and analysing logs and telemetry from multiple sources to assess potential security events Correlate and analyse data across endpoint, identity, network, and application sources to develop context and determine whether activity is benign or suspicious Assist in the investigation of security events by applying structured, hypothesis-driven analysis and escalating complex or high-risk findings to more senior analysts Perform guided response activities under supervision, including alert enrichment, containment support, documentation, and coordination with more senior team members during active investigations Validate alerts and contribute to improving detection fidelity by identifying false positives and providing feedback to enhance detection logic and coverage Contribute to the development and refinement of investigation guides, runbooks, and playbooks, while learning to leverage automation, SOAR workflows, and AI-assisted tools to improve efficiency Identify gaps in telemetry, monitoring, or processes and elevate improvement opportunities to support continuous enhancement of detection and response capabilities What we're looking for: Experience in cybersecurity, security operations, IT support, or related technical fields (internships, academic projects, or equivalent experience included) Foundational knowledge of security detection, investigation, or incident response principles, with a demonstrated ability to learn and apply concepts across multiple domains Basic experience with log analysis and telemetry interpretation, including familiarity with querying or analyzing data using tools such as SIEM platforms or query languages (KQL, SPL, SQL, or similar) Exposure to security platforms and technologies such as SIEM, EDR/XDR, identity systems, or cloud environments Foundational understanding of common attacker tactics, techniques, and procedures (TTPs), with familiarity of frameworks such as MITRE ATT&CK Analytical and problem-solving skills, with the ability to follow structured investigation processes and document findings clearly Effective communication skills, including the ability to provide clear updates and collaborate with team members during investigations Willingness to learn, take direction, and progressively develop independent decision making capabilities in security operations environments Skills that will help: Deep analytical and problem-solving skills, with the ability to follow structured investigation processes and document findings clearly Effective communication skills, including the ability to provide clear updates and collaborate with team members during investigations Willingness to learn, take direction, and progressively develop independent decision making capabilities in security operations environment Benefits of working at Bank of America: UK At Bank of America, we strive to prioritise employees' health and wellbeing - it's what makes us a Great Place to Work. Private healthcare for you and your family plus an annual health screen to help you manage your physical wellness with the option to purchase a screen for your partner Competitive pension plan, life assurance and group income protection cover if you become unable to work as a result of a disability or health reasons We offer 26-weeks paid maternity leave, 16-weeks paid paternity leave and inclusive family leave arrangements for working parents and carers including 20 days of back-up childcare including access to school holiday clubs and 20 days of back-up adult care per annum The ability to change your core benefits as well as the option of selecting a variety of flexible benefits to suit your personal circumstances including access to a wellbeing account, travel insurance, critical illness, cycle to work etc. Use of a flex fund to use towards benefits Access to an emotional wellbeing helpline, and virtual GP services Access to the Peppy App which provides 1:1 support, consultations and resources relating to men's health, women's health, fertility, menopause and pregnancy & parenthood Access to a range of gyms, exercise classes and wellbeing Apps through Wellhub, including Headspace and Calm Ability to donate to charities of your choice directly through payroll and the bank will match your contribution Opportunity to give back to your community, develop new skills and work with new groups of people by volunteering in your local area Good conduct and sound judgment is crucial to our long term success. It's important that all employees in the organisation understand the expected standards of conduct and how we manage conduct risk. Individual accountability and an ownership mind set are the cornerstones of our Code of Conduct and are at the heart of managing risk well. "We are an equal opportunities employer and ensure that no applicant is subject to less favourable treatment on the grounds of sex, gender identity or gender reassignment, marital or civil partner status, race, religious or similar philosophical belief, political opinion, colour, nationality, ethnic or national origins, age, sexual orientation, pregnancy or maternity, socio-economic background, responsibility for dependants or physical or mental disability. The Bank selects candidates for interview based on their skills, qualifications and experience." We strive to ensure that our recruitment processes are accessible for all candidates and encourage any candidates to tell us about any adjustment requirements.
26/07/2026
Full time
Job Description: Job Title: Security Detection & Response I Corporate Title: Up to Vice President Location: Chester Company Overview: At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being a diverse and inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us! Location Overview: Find us in the city of Chester, a destination renowned for its culture, history, and beauty. Working at Bank of America Chester offers a far-reaching global career for a world-renowned organisation, whilst being ideally situated against the backdrop of the rolling North Wales hills and the banks of the serene River Dee. Role Description: We are seeking a motivated and analytically driven Security Detection & Response Analyst (SDR I) to join the GIS Monitoring and Triage team. This role supports cybersecurity operations across threat detection, investigation, response, and continuous service improvement. The ideal candidate is an early-career security practitioner with strong analytical aptitude and foundational technical skills, who contributes to the detection and response lifecycle by supporting investigations and response activities under guidance. This role focuses on developing the ability to analyse security events, build contextual understanding of threats, and progressively operate with increasing independence across multiple security domains. The analyst will work alongside experienced practitioners to validate detections, investigate events, and execute response actions while building foundational skills in automation, orchestration, and AI-driven technologies. This team work on a follow the sun methodology with weekends and Bank holidays included, the shifts will be 4 10-hour shifts this will be Sunday - Wednesday or Wednesday to Saturday Responsibilities: Support the detection and response lifecycle (detect investigate respond improve) by triaging alerts and analysing logs and telemetry from multiple sources to assess potential security events Correlate and analyse data across endpoint, identity, network, and application sources to develop context and determine whether activity is benign or suspicious Assist in the investigation of security events by applying structured, hypothesis-driven analysis and escalating complex or high-risk findings to more senior analysts Perform guided response activities under supervision, including alert enrichment, containment support, documentation, and coordination with more senior team members during active investigations Validate alerts and contribute to improving detection fidelity by identifying false positives and providing feedback to enhance detection logic and coverage Contribute to the development and refinement of investigation guides, runbooks, and playbooks, while learning to leverage automation, SOAR workflows, and AI-assisted tools to improve efficiency Identify gaps in telemetry, monitoring, or processes and elevate improvement opportunities to support continuous enhancement of detection and response capabilities What we're looking for: Experience in cybersecurity, security operations, IT support, or related technical fields (internships, academic projects, or equivalent experience included) Foundational knowledge of security detection, investigation, or incident response principles, with a demonstrated ability to learn and apply concepts across multiple domains Basic experience with log analysis and telemetry interpretation, including familiarity with querying or analyzing data using tools such as SIEM platforms or query languages (KQL, SPL, SQL, or similar) Exposure to security platforms and technologies such as SIEM, EDR/XDR, identity systems, or cloud environments Foundational understanding of common attacker tactics, techniques, and procedures (TTPs), with familiarity of frameworks such as MITRE ATT&CK Analytical and problem-solving skills, with the ability to follow structured investigation processes and document findings clearly Effective communication skills, including the ability to provide clear updates and collaborate with team members during investigations Willingness to learn, take direction, and progressively develop independent decision making capabilities in security operations environments Skills that will help: Deep analytical and problem-solving skills, with the ability to follow structured investigation processes and document findings clearly Effective communication skills, including the ability to provide clear updates and collaborate with team members during investigations Willingness to learn, take direction, and progressively develop independent decision making capabilities in security operations environment Benefits of working at Bank of America: UK At Bank of America, we strive to prioritise employees' health and wellbeing - it's what makes us a Great Place to Work. Private healthcare for you and your family plus an annual health screen to help you manage your physical wellness with the option to purchase a screen for your partner Competitive pension plan, life assurance and group income protection cover if you become unable to work as a result of a disability or health reasons We offer 26-weeks paid maternity leave, 16-weeks paid paternity leave and inclusive family leave arrangements for working parents and carers including 20 days of back-up childcare including access to school holiday clubs and 20 days of back-up adult care per annum The ability to change your core benefits as well as the option of selecting a variety of flexible benefits to suit your personal circumstances including access to a wellbeing account, travel insurance, critical illness, cycle to work etc. Use of a flex fund to use towards benefits Access to an emotional wellbeing helpline, and virtual GP services Access to the Peppy App which provides 1:1 support, consultations and resources relating to men's health, women's health, fertility, menopause and pregnancy & parenthood Access to a range of gyms, exercise classes and wellbeing Apps through Wellhub, including Headspace and Calm Ability to donate to charities of your choice directly through payroll and the bank will match your contribution Opportunity to give back to your community, develop new skills and work with new groups of people by volunteering in your local area Good conduct and sound judgment is crucial to our long term success. It's important that all employees in the organisation understand the expected standards of conduct and how we manage conduct risk. Individual accountability and an ownership mind set are the cornerstones of our Code of Conduct and are at the heart of managing risk well. "We are an equal opportunities employer and ensure that no applicant is subject to less favourable treatment on the grounds of sex, gender identity or gender reassignment, marital or civil partner status, race, religious or similar philosophical belief, political opinion, colour, nationality, ethnic or national origins, age, sexual orientation, pregnancy or maternity, socio-economic background, responsibility for dependants or physical or mental disability. The Bank selects candidates for interview based on their skills, qualifications and experience." We strive to ensure that our recruitment processes are accessible for all candidates and encourage any candidates to tell us about any adjustment requirements.
Location(s):UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123212 Location: Leeds Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
26/07/2026
Full time
Location(s):UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123212 Location: Leeds Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
Littlepay seeks a Senior Technical Support Analyst to keep our global payments platform reliable, working with Engineering, Product and Delivery to investigate complex issues, support customers and drive improvements. You'll mentor teammates and lead incident responses while shaping support practices to reduce risk and improve outcomes. You'll report to the Technical Support Manager and play a key role in triaging, diagnosing and resolving issues, with a strong emphasis on customer outcomes and
26/07/2026
Full time
Littlepay seeks a Senior Technical Support Analyst to keep our global payments platform reliable, working with Engineering, Product and Delivery to investigate complex issues, support customers and drive improvements. You'll mentor teammates and lead incident responses while shaping support practices to reduce risk and improve outcomes. You'll report to the Technical Support Manager and play a key role in triaging, diagnosing and resolving issues, with a strong emphasis on customer outcomes and
BAE Systems Digital Intelligence in Leeds seeks a Senior SOC Analyst and Shift Lead to join our 24/7 security operations team. You will monitor and investigate incidents across Azure and AWS hosted networks, working with a blended customer and BAE staff team from our Leeds office. The role requires a minimum of security clearance and will support threat intelligence and incident response activities. Initial terms include 6- and 12-month contracts with potential extensions.
26/07/2026
Full time
BAE Systems Digital Intelligence in Leeds seeks a Senior SOC Analyst and Shift Lead to join our 24/7 security operations team. You will monitor and investigate incidents across Azure and AWS hosted networks, working with a blended customer and BAE staff team from our Leeds office. The role requires a minimum of security clearance and will support threat intelligence and incident response activities. Initial terms include 6- and 12-month contracts with potential extensions.
Cyber Security Operations Manager (Hybrid) Location: Bournemouth (2 days per week in-office) Salary: £65-75k + competitive bonus & benefits Lead and evolve a high-performing cyber security operations function within a fast-paced, values-driven environment. This role offers the opportunity to shape security strategy, strengthen incident response capabilities, and drive continuous improvement across monitoring, detection, and risk management. You'll take ownership of security operations, managing a team of analysts while working closely with senior stakeholders to enhance resilience, governance, and compliance. From leading incident response and threat hunting to influencing long-term security roadmaps, you'll play a key role in protecting critical systems and data. We're looking for a hands-on cyber leader with strong technical depth, proven experience in security operations, and the ability to translate complex risks into clear business impact. A background in frameworks such as ISO27001, NIST or similar, alongside relevant certifications, will be highly beneficial. Excellent benefits, flexible hybrid working, and the chance to make a genuine impact in a forward-thinking organisation.
26/07/2026
Full time
Cyber Security Operations Manager (Hybrid) Location: Bournemouth (2 days per week in-office) Salary: £65-75k + competitive bonus & benefits Lead and evolve a high-performing cyber security operations function within a fast-paced, values-driven environment. This role offers the opportunity to shape security strategy, strengthen incident response capabilities, and drive continuous improvement across monitoring, detection, and risk management. You'll take ownership of security operations, managing a team of analysts while working closely with senior stakeholders to enhance resilience, governance, and compliance. From leading incident response and threat hunting to influencing long-term security roadmaps, you'll play a key role in protecting critical systems and data. We're looking for a hands-on cyber leader with strong technical depth, proven experience in security operations, and the ability to translate complex risks into clear business impact. A background in frameworks such as ISO27001, NIST or similar, alongside relevant certifications, will be highly beneficial. Excellent benefits, flexible hybrid working, and the chance to make a genuine impact in a forward-thinking organisation.
Location(s):UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123212 Location: Leeds Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
26/07/2026
Full time
Location(s):UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123212 Location: Leeds Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
BAE Systems Digital Intelligence in Leeds is seeking a Senior SOC Analyst & Shift Lead to operate a 24/7 Security Operations Centre for a UK CNI client. You will monitor, triage and investigate alerts using SIEM tools, contribute to incident response and drive continuous improvement. Hybrid working with potential DV clearance; role requires hands-on security analytics, cloud experience in Azure/AWS and collaboration across teams.
26/07/2026
Full time
BAE Systems Digital Intelligence in Leeds is seeking a Senior SOC Analyst & Shift Lead to operate a 24/7 Security Operations Centre for a UK CNI client. You will monitor, triage and investigate alerts using SIEM tools, contribute to incident response and drive continuous improvement. Hybrid working with potential DV clearance; role requires hands-on security analytics, cloud experience in Azure/AWS and collaboration across teams.
Location(s):UK, Europe & Africa : UK : Manchester BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123208 Location: Manchester Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
26/07/2026
Full time
Location(s):UK, Europe & Africa : UK : Manchester BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123208 Location: Manchester Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.