it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

357 jobs found

Email me jobs like this
Refine Search
Current Search
threat detection engineer
Michael Page
Cyber Security Specialist (SecOps / Liverpool)
Michael Page City, Liverpool
This position focuses on security monitoring, incident investigation, threat analysis, and operational security improvement. The successful candidate will act as a subject matter expert for cyber security operations, supporting both proactive and reactive security activities while helping to enhance the organisation's overall security maturity. Client Details Our client is a well-established and respected professional services organisation with a strong national presence and a reputation for delivering high-quality solutions to a broad client base. With ongoing investment in technology and cybersecurity, they are committed to maintaining a secure and resilient environment that supports business growth, innovation, and operational excellence. Description Investigating and responding to security incidents escalated through the Security Operations function. Performing detailed security event analysis and identifying potential threats or areas requiring further investigation. Working closely with external security service providers to ensure effective monitoring, alert management, and incident handling. Supporting cyber incident response activities as a technical security specialist. Analysing security metrics and trends, providing recommendations to improve security controls and reduce risk. Delivering and managing security awareness initiatives, including phishing simulations and remediation activities. Maintaining and optimising security monitoring and protection platforms across the technology estate. Conducting security reviews of systems, infrastructure, and operational processes. Collaborating with technology and business teams to drive continuous security improvements. Ensuring security operations align with relevant regulatory, governance, and industry best practice requirements. Contributing to the development and implementation of operational security controls and procedures. Profile Previous experience working within a Security Operations Centre (SOC) or equivalent cyber security environment. Demonstrated experience in security operations, cyber defence, incident response, threat detection, or a related security discipline. Strong understanding of cyber attack techniques, threat actor methodologies, and appropriate mitigation strategies. Experience investigating security incidents and coordinating response activities. Knowledge of Security Information and Event Management (SIEM), Identity and Access Management (IAM), and Data Loss Prevention (DLP) technologies. Good understanding of modern security frameworks, detection engineering concepts, and operational security best practices. Experience securing cloud-based and enterprise collaboration environments. Familiarity with cyber threat intelligence and attack frameworks such as MITRE ATT&CK. Strong analytical and problem-solving skills with the ability to assess security risks effectively. A proactive approach to continuous learning and staying current with emerging threats and security trends. Desirable Degree in Cyber Security, Information Technology, Computer Science, or a related discipline. Relevant industry certifications such as CISSP, GIAC, CompTIA Security+, SC-200, AZ-500, or equivalent. Experience working within regulated or enterprise-scale environments. Job Offer Private healthcare. Life assurance. hybrid working 3 days in offices (Liverpool, Glasgow, London) Ongoing training and professional development opportunities.
28/07/2026
Full time
This position focuses on security monitoring, incident investigation, threat analysis, and operational security improvement. The successful candidate will act as a subject matter expert for cyber security operations, supporting both proactive and reactive security activities while helping to enhance the organisation's overall security maturity. Client Details Our client is a well-established and respected professional services organisation with a strong national presence and a reputation for delivering high-quality solutions to a broad client base. With ongoing investment in technology and cybersecurity, they are committed to maintaining a secure and resilient environment that supports business growth, innovation, and operational excellence. Description Investigating and responding to security incidents escalated through the Security Operations function. Performing detailed security event analysis and identifying potential threats or areas requiring further investigation. Working closely with external security service providers to ensure effective monitoring, alert management, and incident handling. Supporting cyber incident response activities as a technical security specialist. Analysing security metrics and trends, providing recommendations to improve security controls and reduce risk. Delivering and managing security awareness initiatives, including phishing simulations and remediation activities. Maintaining and optimising security monitoring and protection platforms across the technology estate. Conducting security reviews of systems, infrastructure, and operational processes. Collaborating with technology and business teams to drive continuous security improvements. Ensuring security operations align with relevant regulatory, governance, and industry best practice requirements. Contributing to the development and implementation of operational security controls and procedures. Profile Previous experience working within a Security Operations Centre (SOC) or equivalent cyber security environment. Demonstrated experience in security operations, cyber defence, incident response, threat detection, or a related security discipline. Strong understanding of cyber attack techniques, threat actor methodologies, and appropriate mitigation strategies. Experience investigating security incidents and coordinating response activities. Knowledge of Security Information and Event Management (SIEM), Identity and Access Management (IAM), and Data Loss Prevention (DLP) technologies. Good understanding of modern security frameworks, detection engineering concepts, and operational security best practices. Experience securing cloud-based and enterprise collaboration environments. Familiarity with cyber threat intelligence and attack frameworks such as MITRE ATT&CK. Strong analytical and problem-solving skills with the ability to assess security risks effectively. A proactive approach to continuous learning and staying current with emerging threats and security trends. Desirable Degree in Cyber Security, Information Technology, Computer Science, or a related discipline. Relevant industry certifications such as CISSP, GIAC, CompTIA Security+, SC-200, AZ-500, or equivalent. Experience working within regulated or enterprise-scale environments. Job Offer Private healthcare. Life assurance. hybrid working 3 days in offices (Liverpool, Glasgow, London) Ongoing training and professional development opportunities.
Product Manager - Cyber Security
JPMorgan Chase & Co. Bournemouth, Dorset
As a Product Manager in Cybersecurity & Technology Controls, you will lead the end-to-end product lifecycle for a blockchain detection and prevention capability serving our SOC. You will translate SOC needs into a prioritized roadmap and backlog, partner closely with engineering and threat SMEs, and ensure detections are accurate, explainable, and operationally effective. Success means improving time-to-detect and time-to-respond while managing false positives and meeting reliability and resiliency expectations. Job Responsibilities Define product vision, strategy, and roadmap for SOC-focused blockchain detection and prevention Lead discovery with SOC analysts and incident responders: workflows, pain points, alert usability, escalation paths, and runbooks Own and refine the backlog: detection use cases, requirements, acceptance criteria, and prioritization tradeoffs Partner with engineering/threat teams to deliver end-to-end capability: signal ingestion, enrichment, alerting, triage experience, and response automation where appropriate Establish and track success metrics (e.g., precision/false positive rate, coverage, latency, time-to-detect/time-to-respond, alert volume, reliability/SLA) and drive continuous improvement Drive launch readiness: documentation, training, operational handoffs, and feedback loops with the SOC Required Qualifications, Capabilities, and Skills Product management experience delivering security detections, SOC tooling, or data/analytics products Strong understanding of SOC operations (alert lifecycle, triage, escalations, incident response) Background in blockchain fundamentals and common threat patterns/abuse cases Ability to use data to prioritize, measure detection efficacy, and manage false positives Preferred Experience with SIEM/SOAR and detection engineering programs Experience operating in a highly matrixed, complex organization
27/07/2026
Full time
As a Product Manager in Cybersecurity & Technology Controls, you will lead the end-to-end product lifecycle for a blockchain detection and prevention capability serving our SOC. You will translate SOC needs into a prioritized roadmap and backlog, partner closely with engineering and threat SMEs, and ensure detections are accurate, explainable, and operationally effective. Success means improving time-to-detect and time-to-respond while managing false positives and meeting reliability and resiliency expectations. Job Responsibilities Define product vision, strategy, and roadmap for SOC-focused blockchain detection and prevention Lead discovery with SOC analysts and incident responders: workflows, pain points, alert usability, escalation paths, and runbooks Own and refine the backlog: detection use cases, requirements, acceptance criteria, and prioritization tradeoffs Partner with engineering/threat teams to deliver end-to-end capability: signal ingestion, enrichment, alerting, triage experience, and response automation where appropriate Establish and track success metrics (e.g., precision/false positive rate, coverage, latency, time-to-detect/time-to-respond, alert volume, reliability/SLA) and drive continuous improvement Drive launch readiness: documentation, training, operational handoffs, and feedback loops with the SOC Required Qualifications, Capabilities, and Skills Product management experience delivering security detections, SOC tooling, or data/analytics products Strong understanding of SOC operations (alert lifecycle, triage, escalations, incident response) Background in blockchain fundamentals and common threat patterns/abuse cases Ability to use data to prioritize, measure detection efficacy, and manage false positives Preferred Experience with SIEM/SOAR and detection engineering programs Experience operating in a highly matrixed, complex organization
IDPP
CrowdStrike Falcon Specialist
IDPP
Cyber Security Engineer - CrowdStrike Falcon Specialist Contract | £425 per day Outside IR35 | Remote UK We are supporting a major enterprise organisation with the rollout and optimisation of CrowdStrike Falcon across a complex technology estate and are looking for an experienced Cyber Security Engineer with proven, hands-on CrowdStrike implementation expertise. This is an engineering-focused role, not a SOC Analyst position. We are looking for someone who has been responsible for deploying, configuring and enhancing CrowdStrike within large enterprise environments. The Role You'll join an established cyber security programme, taking ownership of CrowdStrike engineering activities across enterprise infrastructure, working closely with security, infrastructure and cloud teams. Key responsibilities include: Deploying and configuring CrowdStrike Falcon across enterprise environments Managing CrowdStrike policies, sensor deployments and platform optimisation Designing and implementing endpoint security controls Integrating CrowdStrike with technologies including Active Directory, ServiceNow, SIEM and SOAR platforms Developing detection rules, response workflows and security policies Supporting threat hunting and improving endpoint visibility Working across Windows server, desktop and cloud workloads Providing technical expertise throughout implementation and operational phases Essential Experience We're particularly interested in candidates who have demonstrable hands-on experience with: Enterprise deployment of CrowdStrike Falcon Falcon sensor rollout and life cycle management Policy creation and tuning Host groups, prevention policies and detection management Incident response and threat hunting using CrowdStrike Falcon Complete, Falcon Insight or Falcon Prevent Integration with Microsoft Sentinel, Splunk, QRadar or similar SIEM platforms Active Directory integration Enterprise-scale security engineering Desirable Experience Microsoft Defender for Endpoint (MDE) SentinelOne Rapid7 Carbon Black Microsoft Sentinel XSOAR or other SOAR platforms Azure, AWS or GCP security PowerShell or Python automation Zero Trust or enterprise security architecture
27/07/2026
Contractor
Cyber Security Engineer - CrowdStrike Falcon Specialist Contract | £425 per day Outside IR35 | Remote UK We are supporting a major enterprise organisation with the rollout and optimisation of CrowdStrike Falcon across a complex technology estate and are looking for an experienced Cyber Security Engineer with proven, hands-on CrowdStrike implementation expertise. This is an engineering-focused role, not a SOC Analyst position. We are looking for someone who has been responsible for deploying, configuring and enhancing CrowdStrike within large enterprise environments. The Role You'll join an established cyber security programme, taking ownership of CrowdStrike engineering activities across enterprise infrastructure, working closely with security, infrastructure and cloud teams. Key responsibilities include: Deploying and configuring CrowdStrike Falcon across enterprise environments Managing CrowdStrike policies, sensor deployments and platform optimisation Designing and implementing endpoint security controls Integrating CrowdStrike with technologies including Active Directory, ServiceNow, SIEM and SOAR platforms Developing detection rules, response workflows and security policies Supporting threat hunting and improving endpoint visibility Working across Windows server, desktop and cloud workloads Providing technical expertise throughout implementation and operational phases Essential Experience We're particularly interested in candidates who have demonstrable hands-on experience with: Enterprise deployment of CrowdStrike Falcon Falcon sensor rollout and life cycle management Policy creation and tuning Host groups, prevention policies and detection management Incident response and threat hunting using CrowdStrike Falcon Complete, Falcon Insight or Falcon Prevent Integration with Microsoft Sentinel, Splunk, QRadar or similar SIEM platforms Active Directory integration Enterprise-scale security engineering Desirable Experience Microsoft Defender for Endpoint (MDE) SentinelOne Rapid7 Carbon Black Microsoft Sentinel XSOAR or other SOAR platforms Azure, AWS or GCP security PowerShell or Python automation Zero Trust or enterprise security architecture
TXP
MS Sentinel Engineer
TXP
Sentinel & Defender Consultant UK | Remote | 3-Month Contract | Inside IR35 Are you a Microsoft Security specialist with proven experience across Microsoft Sentinel and the Microsoft Defender suite? We're seeking a Sentinel & Defender Consultant to lead the design, deployment, configuration, and optimisation of enterprise-scale Microsoft security solutions. You'll work across the full project life cycle, from architecture and implementation through to automation, threat detection, and stakeholder engagement. ? Strong experience with Microsoft Sentinel & Defender ? SIEM, XDR & SOAR expertise ? Security architecture and deployment experience ? Scripting and automation skills ? SC-200, SC-100 or AZ-500 certifications desirable You'll act as a trusted advisor, helping organisations strengthen their security posture while delivering scalable, resilient Microsoft security solutions. Interested? Click on the link to apply for immediate consideration.
27/07/2026
Contractor
Sentinel & Defender Consultant UK | Remote | 3-Month Contract | Inside IR35 Are you a Microsoft Security specialist with proven experience across Microsoft Sentinel and the Microsoft Defender suite? We're seeking a Sentinel & Defender Consultant to lead the design, deployment, configuration, and optimisation of enterprise-scale Microsoft security solutions. You'll work across the full project life cycle, from architecture and implementation through to automation, threat detection, and stakeholder engagement. ? Strong experience with Microsoft Sentinel & Defender ? SIEM, XDR & SOAR expertise ? Security architecture and deployment experience ? Scripting and automation skills ? SC-200, SC-100 or AZ-500 certifications desirable You'll act as a trusted advisor, helping organisations strengthen their security posture while delivering scalable, resilient Microsoft security solutions. Interested? Click on the link to apply for immediate consideration.
C++ AI/ML Software Engineer
United States Digital Space LLC Cambridge, Cambridgeshire
C++ AI/ML Software Engineer HP Wolf Security is changing the future of endpoint security through delivering secure PCs with advanced hardware enforced security features. As AI becomes increasingly important in cybersecurity, we are expanding our R&D team in Cambridge, UK and are looking for an experienced C++ AI/ML Software Engineer to help develop the next generation of intelligent security solutions. You will be designing, developing, and optimizing AI and machine learning capabilities within our security platform, contributing to innovative features that leverage advanced analytics, behavioural detection, and intelligent threat prevention. Working as part of a highly collaborative engineering team, you will help bridge the gap between cutting edge machine learning research and production grade security software. To see what our engineering teams are working on, visit our technical blogs: We're looking for a talented software engineer with a strong background in modern C++ development and experience applying machine learning and AI techniques within commercial software products. This is a fantastic full time opportunity for a collaborative, hands on, and experienced developer to join a growing team working at the intersection of cybersecurity, systems software, and artificial intelligence. We offer a comprehensive benefits package and excellent career development opportunities. Responsibilities Design, develop, and maintain AI/ML driven features within HP Wolf Security products. Develop high performance C++ components that integrate machine learning models into endpoint security solutions. Collaborate with data scientists and security researchers to productionise AI and machine learning algorithms. Optimise model inference, performance, scalability, and resource utilisation on endpoint devices. Develop data processing, evaluation, and automation tools using Python. Contribute to the design and implementation of intelligent threat detection, behavioural analysis, and anomaly detection capabilities. Participate in architecture discussions, code reviews, testing, and continuous improvement of engineering practices. Evaluate emerging AI technologies and contribute to future product innovation. Qualifications Strong proficiency in modern C++ design, development, debugging, testing, and performance optimisation. Experience developing and deploying machine learning or AI based software solutions. Excellent analytical, problem solving, and software engineering skills. Experience working with Python for machine learning workflows, automation, or tooling. Understanding of software development lifecycle, testing methodologies, and version control systems. Bachelor's or Master's degree in Computer Science, Artificial Intelligence, Machine Learning, Software Engineering, or equivalent experience. Desired Additional Experience Machine learning frameworks such as TensorFlow, PyTorch, ONNX Runtime, or similar. AI model deployment, optimisation, and inference in production environments. Data processing, feature engineering, and model evaluation techniques. Security, cybersecurity, or threat detection applications of AI/ML. Large Language Models (LLMs), Generative AI, or AI assisted security technologies. High performance, multi threaded, or systems level C++ development. Cloud based AI/ML services and MLOps practices. Location & Working Model This role is based in HP's Cambridge office under a hybrid working arrangement, with a minimum requirement to be onsite three days per week. As a people focused senior role, regular in person collaboration is encouraged. About You You're out to reimagine and reinvent what's possible - in your career as well as the world around you. We love taking on tough challenges, disrupting the status quo, and creating what's next. We're in search of talented people who are inspired by big challenges, driven to learn and grow, and dedicated to making a meaningful difference. Why Join HP Wolf Security HP Wolf Security is central to HP's strategy in the PC market, with security designed into hardware, firmware, and software. This integrated approach enables HP to differentiate through built in, enterprise grade protection and manageability. This role sits at the heart of that strategy, helping deliver the tools that allow customers to deploy, manage, and trust secure PCs at scale. The primary focus of the HP Wolf Security team is developing cyber security solutions to protect our customers' devices and data. The digital threat landscape is ever changing and as the cybersecurity industry reacts and adapts to changes, so too do the malware authors. Our unique micro virtualization technology ensures customers are protected from even the most bleeding edge cyber security threats. That micro virtualization technology forms a key pillar in a wider cyber security suite that we're actively developing. Our History Inspired by the isolation principles of traditional virtualization, HP's team known then as Bromium created a game changing technology called micro virtualization to protect end users against advanced malware. Every task the user performs, such as opening a document or clicking on a link, is isolated in its own micro VM, with access to just the resources required for that task, and existing just for the life of the task. Protection is thus provided through isolation, without relying on detection, hence reliably defending the user from polymorphic and even zero day malware. Bromium was acquired by HP Inc on 19 September 2019 forming HP Wolf Security. For more information, visit our website: Equal Opportunity Employer (EEO) HP, Inc. provides equal employment opportunity to all employees and prospective employees, without regard to race, color, religion, sex, national origin, ancestry, citizenship, sexual orientation, age, disability, or status as a protected veteran, marital status, familial status, physical or mental disability, medical condition, pregnancy, genetic predisposition or carrier status, uniformed service status, political affiliation, or any other characteristic protected by applicable national, federal, state, and local law(s). Please be assured that you will not be subject to any adverse treatment if you choose to disclose the information requested. The information obtained will be kept in strict confidence. For more information, review HP's EEO Policy or read about your rights as an applicant under the law here: "Know Your Rights: Workplace Discrimination is Illegal".
27/07/2026
Full time
C++ AI/ML Software Engineer HP Wolf Security is changing the future of endpoint security through delivering secure PCs with advanced hardware enforced security features. As AI becomes increasingly important in cybersecurity, we are expanding our R&D team in Cambridge, UK and are looking for an experienced C++ AI/ML Software Engineer to help develop the next generation of intelligent security solutions. You will be designing, developing, and optimizing AI and machine learning capabilities within our security platform, contributing to innovative features that leverage advanced analytics, behavioural detection, and intelligent threat prevention. Working as part of a highly collaborative engineering team, you will help bridge the gap between cutting edge machine learning research and production grade security software. To see what our engineering teams are working on, visit our technical blogs: We're looking for a talented software engineer with a strong background in modern C++ development and experience applying machine learning and AI techniques within commercial software products. This is a fantastic full time opportunity for a collaborative, hands on, and experienced developer to join a growing team working at the intersection of cybersecurity, systems software, and artificial intelligence. We offer a comprehensive benefits package and excellent career development opportunities. Responsibilities Design, develop, and maintain AI/ML driven features within HP Wolf Security products. Develop high performance C++ components that integrate machine learning models into endpoint security solutions. Collaborate with data scientists and security researchers to productionise AI and machine learning algorithms. Optimise model inference, performance, scalability, and resource utilisation on endpoint devices. Develop data processing, evaluation, and automation tools using Python. Contribute to the design and implementation of intelligent threat detection, behavioural analysis, and anomaly detection capabilities. Participate in architecture discussions, code reviews, testing, and continuous improvement of engineering practices. Evaluate emerging AI technologies and contribute to future product innovation. Qualifications Strong proficiency in modern C++ design, development, debugging, testing, and performance optimisation. Experience developing and deploying machine learning or AI based software solutions. Excellent analytical, problem solving, and software engineering skills. Experience working with Python for machine learning workflows, automation, or tooling. Understanding of software development lifecycle, testing methodologies, and version control systems. Bachelor's or Master's degree in Computer Science, Artificial Intelligence, Machine Learning, Software Engineering, or equivalent experience. Desired Additional Experience Machine learning frameworks such as TensorFlow, PyTorch, ONNX Runtime, or similar. AI model deployment, optimisation, and inference in production environments. Data processing, feature engineering, and model evaluation techniques. Security, cybersecurity, or threat detection applications of AI/ML. Large Language Models (LLMs), Generative AI, or AI assisted security technologies. High performance, multi threaded, or systems level C++ development. Cloud based AI/ML services and MLOps practices. Location & Working Model This role is based in HP's Cambridge office under a hybrid working arrangement, with a minimum requirement to be onsite three days per week. As a people focused senior role, regular in person collaboration is encouraged. About You You're out to reimagine and reinvent what's possible - in your career as well as the world around you. We love taking on tough challenges, disrupting the status quo, and creating what's next. We're in search of talented people who are inspired by big challenges, driven to learn and grow, and dedicated to making a meaningful difference. Why Join HP Wolf Security HP Wolf Security is central to HP's strategy in the PC market, with security designed into hardware, firmware, and software. This integrated approach enables HP to differentiate through built in, enterprise grade protection and manageability. This role sits at the heart of that strategy, helping deliver the tools that allow customers to deploy, manage, and trust secure PCs at scale. The primary focus of the HP Wolf Security team is developing cyber security solutions to protect our customers' devices and data. The digital threat landscape is ever changing and as the cybersecurity industry reacts and adapts to changes, so too do the malware authors. Our unique micro virtualization technology ensures customers are protected from even the most bleeding edge cyber security threats. That micro virtualization technology forms a key pillar in a wider cyber security suite that we're actively developing. Our History Inspired by the isolation principles of traditional virtualization, HP's team known then as Bromium created a game changing technology called micro virtualization to protect end users against advanced malware. Every task the user performs, such as opening a document or clicking on a link, is isolated in its own micro VM, with access to just the resources required for that task, and existing just for the life of the task. Protection is thus provided through isolation, without relying on detection, hence reliably defending the user from polymorphic and even zero day malware. Bromium was acquired by HP Inc on 19 September 2019 forming HP Wolf Security. For more information, visit our website: Equal Opportunity Employer (EEO) HP, Inc. provides equal employment opportunity to all employees and prospective employees, without regard to race, color, religion, sex, national origin, ancestry, citizenship, sexual orientation, age, disability, or status as a protected veteran, marital status, familial status, physical or mental disability, medical condition, pregnancy, genetic predisposition or carrier status, uniformed service status, political affiliation, or any other characteristic protected by applicable national, federal, state, and local law(s). Please be assured that you will not be subject to any adverse treatment if you choose to disclose the information requested. The information obtained will be kept in strict confidence. For more information, review HP's EEO Policy or read about your rights as an applicant under the law here: "Know Your Rights: Workplace Discrimination is Illegal".
Cloud Security Specialist
Wood Mackenzie Limited Edinburgh, Midlothian
Position Overview We are seeking an experienced Cyber Security Analyst to join our cyber security team. The ideal candidate will have a minimum of 5 years cyber security experience and 3+ years in cloud security and/or application security. The candidate will be able to demonstrate a proven track record of protecting enterprise environments against evolving cyber threats. This role requires a technically proficient lead analyst who can lead security initiatives and ensure our cloud and application infrastructure maintains the highest security standards, whilst maintaining business partnerships across the group. Key Responsibilities Monitor and analyze security events across cloud and on premises environments using SIEM and security analytics tools Conduct thorough investigations of security incidents and provide detailed incident reports Develop and maintain incident response playbooks and procedures Experience with threat intelligence platforms and threat hunting Experience with security orchestration, automation and response (SOAR) platforms Understanding of data protection and encryption technologies Experience in regulated industries (financial services, healthcare, energy) Background in offensive security or penetration testing Design, implement, and maintain security controls across cloud platforms (AWS, Azure, GCP) Conduct cloud security assessments and architecture reviews Ensure compliance with cloud security best practices and frameworks (CIS Benchmarks, CSA CCM, NIST) Manage cloud native security tools including CSPM, CWPP, and cloud WAF solutions Implement and maintain identity and access management (IAM) policies and controls Lead cyber security programs and coordinate remediation efforts Collaborate with DevOps teams to integrate security into CI/CD pipelines (DevSecOps) Stay current with emerging threats, vulnerabilities, and security technologies Contribute to security awareness training and documentation Facilitate Supplier Management and security input into bids Support compliance initiatives (SOC2, ISO27001, PCI DSS, GDPR, etc.) Develop and enforce security policies, standards, and procedures Conduct security audits and risk assessments Maintain security documentation and metrics reporting Required Qualifications Minimum of 5 years cyber security experience 3+ years of hands on experience with cloud security (AWS, Azure, or GCP) Proven experience leading security incidents and coordinating response efforts Experience with security frameworks such as NIST CSF, MITRE ATT&CK, or Zero Trust architecture Technical Skills Strong expertise in cloud security services and tools (AWS & Azure) Experience working with SIEM platforms (Splunk, Sentinel) Understanding of network security, firewalls, IDS/IPS, and VPN technologies Familiarity with security testing tools (vulnerability scanners, SAST/DAST, penetration testing tools) Experience with endpoint detection and response (EDR) solutions Soft Skills Strong analytical and problem solving abilities Excellent written and verbal communication skills Ability to explain complex security concepts to technical and non technical audiences Leadership capabilities and experience mentoring team members Strong attention to detail and ability to work under pressure Collaborative mindset with cross functional teams Business partnering experience Certifications (one or more preferred) CISSP (Certified Information Systems Security Professional) CCSP (Certified Cloud Security Professional) AWS Certified Security - Specialty Microsoft Certified: Azure Security Engineer Associate Education: Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) Working Conditions Some flexibility for remote work - 2 days minimum in office (Edinburgh preferred) Equal Opportunities We are an equal opportunities employer. This means we are committed to recruiting the best people regardless of their race, colour, religion, age, sex, national origin, disability or protected veteran status. We can support you with your application or through the hiring process if you have a physical or mental disability. You can find out more about your rights under the law at .
27/07/2026
Full time
Position Overview We are seeking an experienced Cyber Security Analyst to join our cyber security team. The ideal candidate will have a minimum of 5 years cyber security experience and 3+ years in cloud security and/or application security. The candidate will be able to demonstrate a proven track record of protecting enterprise environments against evolving cyber threats. This role requires a technically proficient lead analyst who can lead security initiatives and ensure our cloud and application infrastructure maintains the highest security standards, whilst maintaining business partnerships across the group. Key Responsibilities Monitor and analyze security events across cloud and on premises environments using SIEM and security analytics tools Conduct thorough investigations of security incidents and provide detailed incident reports Develop and maintain incident response playbooks and procedures Experience with threat intelligence platforms and threat hunting Experience with security orchestration, automation and response (SOAR) platforms Understanding of data protection and encryption technologies Experience in regulated industries (financial services, healthcare, energy) Background in offensive security or penetration testing Design, implement, and maintain security controls across cloud platforms (AWS, Azure, GCP) Conduct cloud security assessments and architecture reviews Ensure compliance with cloud security best practices and frameworks (CIS Benchmarks, CSA CCM, NIST) Manage cloud native security tools including CSPM, CWPP, and cloud WAF solutions Implement and maintain identity and access management (IAM) policies and controls Lead cyber security programs and coordinate remediation efforts Collaborate with DevOps teams to integrate security into CI/CD pipelines (DevSecOps) Stay current with emerging threats, vulnerabilities, and security technologies Contribute to security awareness training and documentation Facilitate Supplier Management and security input into bids Support compliance initiatives (SOC2, ISO27001, PCI DSS, GDPR, etc.) Develop and enforce security policies, standards, and procedures Conduct security audits and risk assessments Maintain security documentation and metrics reporting Required Qualifications Minimum of 5 years cyber security experience 3+ years of hands on experience with cloud security (AWS, Azure, or GCP) Proven experience leading security incidents and coordinating response efforts Experience with security frameworks such as NIST CSF, MITRE ATT&CK, or Zero Trust architecture Technical Skills Strong expertise in cloud security services and tools (AWS & Azure) Experience working with SIEM platforms (Splunk, Sentinel) Understanding of network security, firewalls, IDS/IPS, and VPN technologies Familiarity with security testing tools (vulnerability scanners, SAST/DAST, penetration testing tools) Experience with endpoint detection and response (EDR) solutions Soft Skills Strong analytical and problem solving abilities Excellent written and verbal communication skills Ability to explain complex security concepts to technical and non technical audiences Leadership capabilities and experience mentoring team members Strong attention to detail and ability to work under pressure Collaborative mindset with cross functional teams Business partnering experience Certifications (one or more preferred) CISSP (Certified Information Systems Security Professional) CCSP (Certified Cloud Security Professional) AWS Certified Security - Specialty Microsoft Certified: Azure Security Engineer Associate Education: Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) Working Conditions Some flexibility for remote work - 2 days minimum in office (Edinburgh preferred) Equal Opportunities We are an equal opportunities employer. This means we are committed to recruiting the best people regardless of their race, colour, religion, age, sex, national origin, disability or protected veteran status. We can support you with your application or through the hiring process if you have a physical or mental disability. You can find out more about your rights under the law at .
Cyber Security Engineer
Noble Foods Limited Tring, Hertfordshire
Cyber Security Engineer (Hybrid UK) Hybrid & Tring, Hertfordshire 2 days a week Cloud • On-Prem • Network Security Security isn't a toolset anymore. It's an operating model. At Noble Foods, we're building security that works across Azure, VMware, and our network estate-and we need someone who can make it real, not theoretical. What you'll be doing Securing and governing our Azure environment (identity, policy, logging, controls) Hardening and protecting VMware infrastructure Strengthening network security across Cisco Meraki Working with Sophos MDR to detect, respond, and contain threats Driving vulnerability management and secure configuration Supporting DR testing and business continuity readiness This is hands on security engineering-where visibility, resilience, and response actually matter. You'll need Experience in hybrid security environments (cloud + on prem) Strong understanding of Azure security fundamentals Networking and segmentation knowledge (firewalls, VLANs, VPNs) Incident response / SOC collaboration experience A structured, calm, problem solving mindset Flexible working depends on the needs of the business Excellent written and verbal communication skills Why this role exists Newly created additional headcount - because security isn't just about preventing attacks-it's about how quickly you recover when things go wrong. You'll help shape detection, response, and resilience across the entire estate. If you want a role where security is operational, visible, and impactful-this is it. Why join us You'll work with well loved, purpose led brands, all within a collaborative, values driven culture.Noble Foods is a family owned company which began in 1920 and includes successful, milling, poultry, agriculture and consumer foods businesses.Within this, Noble Foods owns several successful brands, including the UK's biggest free range egg brand the Happy Egg co., Big & Fresh and Purely Organic. In a recent survey by Best Companies we were rated as one to the Top 10 companies to work for in the Food and Drink industry. What can we offer you? Competitive basic salary Service Awards Enhanced paternity and maternity Free life insurance Enhanced Sick Pay Scheme Access to Perkbox with a variety of discounts including a monthly freebie from Greggs or Café Nero Discounted eggs and chicken A Celebration day after 1 years service enjoy an extra day off to celebrate a life event, such as your birthday Access to DigiCare + - Annual Health Check, Digital GP Consultations, Nutritional Consultations, Second Health Opinion and Mental Health Consultations. Discounted Gym Memberships Free Eye Test every two years Discounted mobile phone contracts Share in our success with the People Partnership - after 6 months service you will be eligible for a yearly bonus Additional Allowances for First Aiders and Mental Health First Aiders Wellness programme Employee Charity Matching Scheme If you consider yourself to require reasonable adjustments to any part of our recruitment process, we invite you to share those requirements with us when completing your application. We will make every effort to ensure your needs are met to provide a fair and transparent process of assessment.
27/07/2026
Full time
Cyber Security Engineer (Hybrid UK) Hybrid & Tring, Hertfordshire 2 days a week Cloud • On-Prem • Network Security Security isn't a toolset anymore. It's an operating model. At Noble Foods, we're building security that works across Azure, VMware, and our network estate-and we need someone who can make it real, not theoretical. What you'll be doing Securing and governing our Azure environment (identity, policy, logging, controls) Hardening and protecting VMware infrastructure Strengthening network security across Cisco Meraki Working with Sophos MDR to detect, respond, and contain threats Driving vulnerability management and secure configuration Supporting DR testing and business continuity readiness This is hands on security engineering-where visibility, resilience, and response actually matter. You'll need Experience in hybrid security environments (cloud + on prem) Strong understanding of Azure security fundamentals Networking and segmentation knowledge (firewalls, VLANs, VPNs) Incident response / SOC collaboration experience A structured, calm, problem solving mindset Flexible working depends on the needs of the business Excellent written and verbal communication skills Why this role exists Newly created additional headcount - because security isn't just about preventing attacks-it's about how quickly you recover when things go wrong. You'll help shape detection, response, and resilience across the entire estate. If you want a role where security is operational, visible, and impactful-this is it. Why join us You'll work with well loved, purpose led brands, all within a collaborative, values driven culture.Noble Foods is a family owned company which began in 1920 and includes successful, milling, poultry, agriculture and consumer foods businesses.Within this, Noble Foods owns several successful brands, including the UK's biggest free range egg brand the Happy Egg co., Big & Fresh and Purely Organic. In a recent survey by Best Companies we were rated as one to the Top 10 companies to work for in the Food and Drink industry. What can we offer you? Competitive basic salary Service Awards Enhanced paternity and maternity Free life insurance Enhanced Sick Pay Scheme Access to Perkbox with a variety of discounts including a monthly freebie from Greggs or Café Nero Discounted eggs and chicken A Celebration day after 1 years service enjoy an extra day off to celebrate a life event, such as your birthday Access to DigiCare + - Annual Health Check, Digital GP Consultations, Nutritional Consultations, Second Health Opinion and Mental Health Consultations. Discounted Gym Memberships Free Eye Test every two years Discounted mobile phone contracts Share in our success with the People Partnership - after 6 months service you will be eligible for a yearly bonus Additional Allowances for First Aiders and Mental Health First Aiders Wellness programme Employee Charity Matching Scheme If you consider yourself to require reasonable adjustments to any part of our recruitment process, we invite you to share those requirements with us when completing your application. We will make every effort to ensure your needs are met to provide a fair and transparent process of assessment.
Cyber Security Engineer
Noble Foods Limited
Cyber Security Engineer (Hybrid UK) Hybrid & Tring, Hertfordshire 2 days a week Cloud • On-Prem • Network Security Security isn't a toolset anymore. It's an operating model. At Noble Foods, we're building security that works across Azure, VMware, and our network estate-and we need someone who can make it real, not theoretical. What you'll be doing Securing and governing our Azure environment (identity, policy, logging, controls) Hardening and protecting VMware infrastructure Strengthening network security across Cisco Meraki Working with Sophos MDR to detect, respond, and contain threats Driving vulnerability management and secure configuration Supporting DR testing and business continuity readiness This is hands on security engineering-where visibility, resilience, and response actually matter. You'll need Experience in hybrid security environments (cloud + on prem) Strong understanding of Azure security fundamentals Networking and segmentation knowledge (firewalls, VLANs, VPNs) Incident response / SOC collaboration experience A structured, calm, problem solving mindset Flexible working depends on the needs of the business Excellent written and verbal communication skills Why this role exists Newly created additional headcount - because security isn't just about preventing attacks-it's about how quickly you recover when things go wrong. You'll help shape detection, response, and resilience across the entire estate. If you want a role where security is operational, visible, and impactful-this is it. Why join us You'll work with well loved, purpose led brands, all within a collaborative, values driven culture.Noble Foods is a family owned company which began in 1920 and includes successful, milling, poultry, agriculture and consumer foods businesses.Within this, Noble Foods owns several successful brands, including the UK's biggest free range egg brand the Happy Egg co., Big & Fresh and Purely Organic. In a recent survey by Best Companies we were rated as one to the Top 10 companies to work for in the Food and Drink industry. What can we offer you? Competitive basic salary Service Awards Enhanced paternity and maternity Free life insurance Enhanced Sick Pay Scheme Access to Perkbox with a variety of discounts including a monthly freebie from Greggs or Café Nero Discounted eggs and chicken A Celebration day after 1 years service enjoy an extra day off to celebrate a life event, such as your birthday Access to DigiCare + - Annual Health Check, Digital GP Consultations, Nutritional Consultations, Second Health Opinion and Mental Health Consultations. Discounted Gym Memberships Free Eye Test every two years Discounted mobile phone contracts Share in our success with the People Partnership - after 6 months service you will be eligible for a yearly bonus Additional Allowances for First Aiders and Mental Health First Aiders Wellness programme Employee Charity Matching Scheme If you consider yourself to require reasonable adjustments to any part of our recruitment process, we invite you to share those requirements with us when completing your application. We will make every effort to ensure your needs are met to provide a fair and transparent process of assessment.
27/07/2026
Full time
Cyber Security Engineer (Hybrid UK) Hybrid & Tring, Hertfordshire 2 days a week Cloud • On-Prem • Network Security Security isn't a toolset anymore. It's an operating model. At Noble Foods, we're building security that works across Azure, VMware, and our network estate-and we need someone who can make it real, not theoretical. What you'll be doing Securing and governing our Azure environment (identity, policy, logging, controls) Hardening and protecting VMware infrastructure Strengthening network security across Cisco Meraki Working with Sophos MDR to detect, respond, and contain threats Driving vulnerability management and secure configuration Supporting DR testing and business continuity readiness This is hands on security engineering-where visibility, resilience, and response actually matter. You'll need Experience in hybrid security environments (cloud + on prem) Strong understanding of Azure security fundamentals Networking and segmentation knowledge (firewalls, VLANs, VPNs) Incident response / SOC collaboration experience A structured, calm, problem solving mindset Flexible working depends on the needs of the business Excellent written and verbal communication skills Why this role exists Newly created additional headcount - because security isn't just about preventing attacks-it's about how quickly you recover when things go wrong. You'll help shape detection, response, and resilience across the entire estate. If you want a role where security is operational, visible, and impactful-this is it. Why join us You'll work with well loved, purpose led brands, all within a collaborative, values driven culture.Noble Foods is a family owned company which began in 1920 and includes successful, milling, poultry, agriculture and consumer foods businesses.Within this, Noble Foods owns several successful brands, including the UK's biggest free range egg brand the Happy Egg co., Big & Fresh and Purely Organic. In a recent survey by Best Companies we were rated as one to the Top 10 companies to work for in the Food and Drink industry. What can we offer you? Competitive basic salary Service Awards Enhanced paternity and maternity Free life insurance Enhanced Sick Pay Scheme Access to Perkbox with a variety of discounts including a monthly freebie from Greggs or Café Nero Discounted eggs and chicken A Celebration day after 1 years service enjoy an extra day off to celebrate a life event, such as your birthday Access to DigiCare + - Annual Health Check, Digital GP Consultations, Nutritional Consultations, Second Health Opinion and Mental Health Consultations. Discounted Gym Memberships Free Eye Test every two years Discounted mobile phone contracts Share in our success with the People Partnership - after 6 months service you will be eligible for a yearly bonus Additional Allowances for First Aiders and Mental Health First Aiders Wellness programme Employee Charity Matching Scheme If you consider yourself to require reasonable adjustments to any part of our recruitment process, we invite you to share those requirements with us when completing your application. We will make every effort to ensure your needs are met to provide a fair and transparent process of assessment.
Vulnerability Management Analyst
Inspired Thinking Group (ITG) Birmingham, Staffordshire
We are looking for an enthusiastic and detail-oriented Vulnerability Management Analyst to join our information security and data protection team. This is an ideal opportunity for someone with real-world experience in information security and data protection. It's a great opportunity to get hands-on with the tools and processes that keep all our products secure, and to make a genuinely visible difference to how we manage risk day to day. The Role: The Vulnerability Management Analyst will help us find, prioritise, and fix security vulnerabilities across our global business and all our products. You'll configure and tune our vulnerability tools, risk assessing detections, and prioritising findings for fix. You'll cover code vulnerabilities (SAST, DAST, SCA, OSS licencing), Cloud Security Posture Management (CSPM), Internal Vulnerability Scanning (IVS), and penetration testing. You'll also help design and report on our detection and remediation activities. This is a full-time position. Occasional after-hours work may be required for incident response or urgent security tasks. Successful candidates will be enrolled on a fully funded training pathway and will be provided with mentoring support to help them grow and learn. Responsibilities: 1. Configuring and tuning our tools Help configure, tune, and maintain our vulnerability tooling across scanning tools, working with platform and engineering teams to keep coverage accurate Support day-to-day scanning schedules and tooling integrations, including ticketing and CI/CD pipelines Look for opportunities to automate reporting, validation, and other repetitive tasks across the whole vulnerability lifecycle 2. Triage and risk assessment Triage findings from vulnerability sources, confirming genuine issues and filtering out false positives Risk-assess confirmed findings against severity, exploitability, and business context, to prioritise fixes Apply a consistent risk-scoring approach so findings are prioritised effectively, regardless of source Stay on top of current threats and trends (e.g. threat actors, new vulnerabilities etc.) to inform vulnerability management activities 3. Designing secure benchmarks and guidelines Develop and maintain secure configuration benchmarks and hardening guidelines for our software, infrastructure, and tooling Align benchmarks and guidelines to recognised industry frameworks for business Work with the right teams to help implement the secure configurations, providing practical advice, and facilitating deviations within our broader risk management framework 4. Working with Developers and Engineers Act as a primary contact point for Developers and Engineers to help them understand and fix issues Track remediation progress, chase owners on overdue items, escalate where necessary Support teams with practical remediation guidance, drawing on the OWASP Top 10, the Mitre Att&ck Framework, and our secure coding standards 5. Coordinating IVS, web application testing, and penetration testing Organise our externally delivered IVS and Penetration Testing programmes, from scheduling and scoping, through to day-to-day contact with our testing partners Help manage our relationships with testing providers, including engagement administration and reporting 6. SLAs, outcome driven metrics, and reporting Help design and report on remediation SLAs across vulnerability classes, severities, and products Produce regular reporting (monthly, quarterly, and ad-hoc) on SLA performance, open findings, and trends Feed data and insight into our wider security metrics and reporting processes 7. Continuous improvement and team support Suggest ways to improve how we manage vulnerabilities and the tools we use to do it Support the rollout of new scanning tools or process changes across our global product estate Help create and maintain our vulnerability management policies, standards, and procedures Requirements: 2+ years' experience in vulnerability management, security operations, development, or a related security/IT role Hands-on experience with vulnerability scanning and management tooling (e.g. SAST, DAST, SCA, CSPM, or IVS) Solid understanding of common vulnerability types and remediation approaches, including familiarity with the Mitre ATT&CK Framework and OWASP Top 10 Experience triaging and risk-assessing security findings, helping teams to prioritise remediation based on severity and business impact Comfortable coordinating third-party engagements, such as scheduling and scoping penetration tests Comfortable explaining technical findings to both Developers and non-technical stakeholders Organised enough to manage several scanning programmes, testing engagements, and remediation workstreams in parallel Comfortable working across a global, multi-product environment Comfortable working within an agile enterprise environment Ability to read and understand common coding languages is essential, the ability to write scripts and/or code is preferred Relevant certifications (e.g. CompTIA Security+, CompTIA CySA+, GIAC GFACT/GPEN, or CEH) are preferred but not essential Strong analytical and problem-solving mindset, with real attention to detail Ability to work autonomously, use good judgement, and know when to escalate Perks at ITG - alongside a competitive salary, here's what you can look forward to: Time off that works for you - 25 days' holiday + bank holidays, a paid Wellbeing Day, flexible bank holidays to honour cultural or religious observances, and the option to buy or carry over up to 5 extra days. Family & life milestones - Enhanced family friendly leave, 3 extra days for your wedding/honeymoon, and an Employee Assistance Programme whenever you need support. Financial perks - Pension scheme, Corporate Medical Cash Plan, electric car salary sacrifice scheme, and tax-efficient payroll giving to your favourite charities. Growth & recognition - Funding for professional qualifications, monthly Employee of the Month awards (£250 bonus), and referral bonuses of up to £1,500. Community & wellbeing - Regular Wellbeing Workshops, 30+ Wellbeing Champions, a paid Volunteer Day, and an online perks platform with discounts on top brands, days out, and gym memberships. What next? Like what you see? Drop us your application and someone from our team will be in touch. We Value Diversity We champion and welcome diversity in our workforce and ensure all job applicants receive equal and fair treatment, regardless of age, race, gender or gender identity, religion, sexual orientation, disability, or nationality. We are not only committed to increasing the visibility and recognition of talent from under-represented groups within our organisation, but the wider industry too. At the end of the day, we make sure we take time to look after ourselves, each other, and the planet, because we're always stronger together. ITG have a number of community groups available to employees and exist to offer a safe space for like-minded colleagues, with shared interests to connect, socialise and check in with each other. What next? If you found yourself interested in knowing more, drop us your application and someone from our team will be in touch.
27/07/2026
Full time
We are looking for an enthusiastic and detail-oriented Vulnerability Management Analyst to join our information security and data protection team. This is an ideal opportunity for someone with real-world experience in information security and data protection. It's a great opportunity to get hands-on with the tools and processes that keep all our products secure, and to make a genuinely visible difference to how we manage risk day to day. The Role: The Vulnerability Management Analyst will help us find, prioritise, and fix security vulnerabilities across our global business and all our products. You'll configure and tune our vulnerability tools, risk assessing detections, and prioritising findings for fix. You'll cover code vulnerabilities (SAST, DAST, SCA, OSS licencing), Cloud Security Posture Management (CSPM), Internal Vulnerability Scanning (IVS), and penetration testing. You'll also help design and report on our detection and remediation activities. This is a full-time position. Occasional after-hours work may be required for incident response or urgent security tasks. Successful candidates will be enrolled on a fully funded training pathway and will be provided with mentoring support to help them grow and learn. Responsibilities: 1. Configuring and tuning our tools Help configure, tune, and maintain our vulnerability tooling across scanning tools, working with platform and engineering teams to keep coverage accurate Support day-to-day scanning schedules and tooling integrations, including ticketing and CI/CD pipelines Look for opportunities to automate reporting, validation, and other repetitive tasks across the whole vulnerability lifecycle 2. Triage and risk assessment Triage findings from vulnerability sources, confirming genuine issues and filtering out false positives Risk-assess confirmed findings against severity, exploitability, and business context, to prioritise fixes Apply a consistent risk-scoring approach so findings are prioritised effectively, regardless of source Stay on top of current threats and trends (e.g. threat actors, new vulnerabilities etc.) to inform vulnerability management activities 3. Designing secure benchmarks and guidelines Develop and maintain secure configuration benchmarks and hardening guidelines for our software, infrastructure, and tooling Align benchmarks and guidelines to recognised industry frameworks for business Work with the right teams to help implement the secure configurations, providing practical advice, and facilitating deviations within our broader risk management framework 4. Working with Developers and Engineers Act as a primary contact point for Developers and Engineers to help them understand and fix issues Track remediation progress, chase owners on overdue items, escalate where necessary Support teams with practical remediation guidance, drawing on the OWASP Top 10, the Mitre Att&ck Framework, and our secure coding standards 5. Coordinating IVS, web application testing, and penetration testing Organise our externally delivered IVS and Penetration Testing programmes, from scheduling and scoping, through to day-to-day contact with our testing partners Help manage our relationships with testing providers, including engagement administration and reporting 6. SLAs, outcome driven metrics, and reporting Help design and report on remediation SLAs across vulnerability classes, severities, and products Produce regular reporting (monthly, quarterly, and ad-hoc) on SLA performance, open findings, and trends Feed data and insight into our wider security metrics and reporting processes 7. Continuous improvement and team support Suggest ways to improve how we manage vulnerabilities and the tools we use to do it Support the rollout of new scanning tools or process changes across our global product estate Help create and maintain our vulnerability management policies, standards, and procedures Requirements: 2+ years' experience in vulnerability management, security operations, development, or a related security/IT role Hands-on experience with vulnerability scanning and management tooling (e.g. SAST, DAST, SCA, CSPM, or IVS) Solid understanding of common vulnerability types and remediation approaches, including familiarity with the Mitre ATT&CK Framework and OWASP Top 10 Experience triaging and risk-assessing security findings, helping teams to prioritise remediation based on severity and business impact Comfortable coordinating third-party engagements, such as scheduling and scoping penetration tests Comfortable explaining technical findings to both Developers and non-technical stakeholders Organised enough to manage several scanning programmes, testing engagements, and remediation workstreams in parallel Comfortable working across a global, multi-product environment Comfortable working within an agile enterprise environment Ability to read and understand common coding languages is essential, the ability to write scripts and/or code is preferred Relevant certifications (e.g. CompTIA Security+, CompTIA CySA+, GIAC GFACT/GPEN, or CEH) are preferred but not essential Strong analytical and problem-solving mindset, with real attention to detail Ability to work autonomously, use good judgement, and know when to escalate Perks at ITG - alongside a competitive salary, here's what you can look forward to: Time off that works for you - 25 days' holiday + bank holidays, a paid Wellbeing Day, flexible bank holidays to honour cultural or religious observances, and the option to buy or carry over up to 5 extra days. Family & life milestones - Enhanced family friendly leave, 3 extra days for your wedding/honeymoon, and an Employee Assistance Programme whenever you need support. Financial perks - Pension scheme, Corporate Medical Cash Plan, electric car salary sacrifice scheme, and tax-efficient payroll giving to your favourite charities. Growth & recognition - Funding for professional qualifications, monthly Employee of the Month awards (£250 bonus), and referral bonuses of up to £1,500. Community & wellbeing - Regular Wellbeing Workshops, 30+ Wellbeing Champions, a paid Volunteer Day, and an online perks platform with discounts on top brands, days out, and gym memberships. What next? Like what you see? Drop us your application and someone from our team will be in touch. We Value Diversity We champion and welcome diversity in our workforce and ensure all job applicants receive equal and fair treatment, regardless of age, race, gender or gender identity, religion, sexual orientation, disability, or nationality. We are not only committed to increasing the visibility and recognition of talent from under-represented groups within our organisation, but the wider industry too. At the end of the day, we make sure we take time to look after ourselves, each other, and the planet, because we're always stronger together. ITG have a number of community groups available to employees and exist to offer a safe space for like-minded colleagues, with shared interests to connect, socialise and check in with each other. What next? If you found yourself interested in knowing more, drop us your application and someone from our team will be in touch.
Senior Detection Engineer - Threat-Led, Cloud-Native Remote
Our Future Health Limited
Our Future Health Limited in London is seeking a Senior Detection Engineer to join our expanding Information Security team. You will own detections, collaborate with threat and MSP SOC partners, and shape how we detect threats at scale using MITRE-aligned methods. You'll dive into KQL scripting, Azure and Kubernetes, build novel analytic techniques, and help tune DLP and other controls to stay ahead of the threat landscape. This is a unique, high-impact role at scale.
27/07/2026
Full time
Our Future Health Limited in London is seeking a Senior Detection Engineer to join our expanding Information Security team. You will own detections, collaborate with threat and MSP SOC partners, and shape how we detect threats at scale using MITRE-aligned methods. You'll dive into KQL scripting, Azure and Kubernetes, build novel analytic techniques, and help tune DLP and other controls to stay ahead of the threat landscape. This is a unique, high-impact role at scale.
Senior Detection Engineer
Our Future Health
We're looking for a Senior Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high impact work that shapes how we detect and respond to threats at scale. You'll collaborate closely with our inhouse Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of it's kind at this scale, then this is the role for you. At Our Future Health, our mission is to transform the prevention,detectionand treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you. What you'll be doing Developing new threat-led detections in collaboration with our threat teambased on both threat intelligenceand the results of threat hunts. Creating novel analytic methods and techniques for incident detection. Working with our MSP provided SOC tomaintainour detectioncatalogueand tune existing rules. Developing and tuning Data Loss Prevention, Insider RiskManagementand other types of security rules withinMicrosoft Purviewand other key security monitoring tools. Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided,detections and other types of engineering work are delivered to theappropriate standardand that the maturity (inc. efficiency) of our security monitoring is continually improving. Supporting the development ofautomated custom reports on security operational performance and broader security topics (using Sentinel workbooks). Collaborating with wider tech and security teams on theappropriatesecuritymonitoringfor our various systems, including cloud platforms, SaaS applications and inhouse developed systems. Documenting securityprocesses and security tool low-level design/configuration. Contributing to the development of security service delivery and operation documentation. Supporting the security engineers, threatanalystsand wider security team with their various responsibilities, including achieving andmaintainingISO 27001 certification andanything that involves KQL. What you won't be doing Working in a siloed environment with no freedom to make decisions. Working in a place where you can't see the impact your expertise makes. To succeed in this role you will be able to demonstrate some of the following skills and experience: Highly proficient in writing KQL and ideallysome level ofproficiencyinPythonand Terraform. Significant hands on experience with Microsoft Sentinel. Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365. Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities. Experience withMicrosoft Purview tooling, in particular MPIP and Purview Data Loss Prevention. Experience with cloud-native logging(in particular Azureand Kubernetes). Experience of an 'everything-as-code',or at least a 'detection-as-code'approach, including CI/CD pipelines. Exposure to working with/inside an MSP SOC. Exposure to Agile working. Knowledge of attacker Tactics, Techniques and Procedures (TTPs). Knowledge of statistics, datascienceand AI/ML,in particular whenapplied to cyber security. Knowledge ofISO 27001. Desire to be part of a small fast paced team. Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK. Salary from £65,000 per annum. Generous Pension Scheme - We invest in your future with employer contributions of up to 12%. 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you. Enhanced Parental Leave - Supporting you during life's biggest moments. Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice. Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board! Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family. A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements. Join us - let'sprevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at
27/07/2026
Full time
We're looking for a Senior Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high impact work that shapes how we detect and respond to threats at scale. You'll collaborate closely with our inhouse Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of it's kind at this scale, then this is the role for you. At Our Future Health, our mission is to transform the prevention,detectionand treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you. What you'll be doing Developing new threat-led detections in collaboration with our threat teambased on both threat intelligenceand the results of threat hunts. Creating novel analytic methods and techniques for incident detection. Working with our MSP provided SOC tomaintainour detectioncatalogueand tune existing rules. Developing and tuning Data Loss Prevention, Insider RiskManagementand other types of security rules withinMicrosoft Purviewand other key security monitoring tools. Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided,detections and other types of engineering work are delivered to theappropriate standardand that the maturity (inc. efficiency) of our security monitoring is continually improving. Supporting the development ofautomated custom reports on security operational performance and broader security topics (using Sentinel workbooks). Collaborating with wider tech and security teams on theappropriatesecuritymonitoringfor our various systems, including cloud platforms, SaaS applications and inhouse developed systems. Documenting securityprocesses and security tool low-level design/configuration. Contributing to the development of security service delivery and operation documentation. Supporting the security engineers, threatanalystsand wider security team with their various responsibilities, including achieving andmaintainingISO 27001 certification andanything that involves KQL. What you won't be doing Working in a siloed environment with no freedom to make decisions. Working in a place where you can't see the impact your expertise makes. To succeed in this role you will be able to demonstrate some of the following skills and experience: Highly proficient in writing KQL and ideallysome level ofproficiencyinPythonand Terraform. Significant hands on experience with Microsoft Sentinel. Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365. Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities. Experience withMicrosoft Purview tooling, in particular MPIP and Purview Data Loss Prevention. Experience with cloud-native logging(in particular Azureand Kubernetes). Experience of an 'everything-as-code',or at least a 'detection-as-code'approach, including CI/CD pipelines. Exposure to working with/inside an MSP SOC. Exposure to Agile working. Knowledge of attacker Tactics, Techniques and Procedures (TTPs). Knowledge of statistics, datascienceand AI/ML,in particular whenapplied to cyber security. Knowledge ofISO 27001. Desire to be part of a small fast paced team. Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK. Salary from £65,000 per annum. Generous Pension Scheme - We invest in your future with employer contributions of up to 12%. 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you. Enhanced Parental Leave - Supporting you during life's biggest moments. Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice. Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board! Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family. A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements. Join us - let'sprevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at
Senior Detection Engineer
Our Future Health Limited
We're looking for a Senior Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high impact work that shapes how we detect and respond to threats at scale. You'll collaborate closely with our inhouse Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of it's kind at this scale, then this is the role for you. At Our Future Health, our mission is to transform the prevention,detectionand treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you. What you'll be doing Developing new threat-led detections in collaboration with our threat teambased on both threat intelligenceand the results of threat hunts. Creating novel analytic methods and techniques for incident detection. Working with our MSP provided SOC tomaintainour detectioncatalogueand tune existing rules. Developing and tuning Data Loss Prevention, Insider RiskManagementand other types of security rules withinMicrosoft Purviewand other key security monitoring tools. Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided,detections and other types of engineering work are delivered to theappropriate standardand that the maturity (inc. efficiency) of our security monitoring is continually improving. Supporting the development ofautomated custom reports on security operational performance and broader security topics (using Sentinel workbooks). Collaborating with wider tech and security teams on theappropriatesecuritymonitoringfor our various systems, including cloud platforms, SaaS applications and inhouse developed systems. Documenting securityprocesses and security tool low-level design/configuration. Contributing to the development of security service delivery and operation documentation. Supporting the security engineers, threatanalystsand wider security team with their various responsibilities, including achieving andmaintainingISO 27001 certification andanything that involves KQL. What you won't be doing Working in a siloed environment with no freedom to make decisions. Working in a place where you can't see the impact your expertise makes. To succeed in this role you will be able to demonstrate some of the following skills and experience: Highly proficient in writing KQL and ideallysome level ofproficiencyinPythonand Terraform. Significant hands on experience with Microsoft Sentinel. Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365. Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities. Experience withMicrosoft Purview tooling, in particular MPIP and Purview Data Loss Prevention. Experience with cloud-native logging(in particular Azureand Kubernetes). Experience of an 'everything-as-code',or at least a 'detection-as-code'approach, including CI/CD pipelines. Exposure to working with/inside an MSP SOC. Exposure to Agile working. Knowledge of attacker Tactics, Techniques and Procedures (TTPs). Knowledge of statistics, datascienceand AI/ML,in particular whenapplied to cyber security. Knowledge ofISO 27001. Desire to be part of a small fast paced team. Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK. Salary from £65,000 per annum. Generous Pension Scheme - We invest in your future with employer contributions of up to 12%. 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you. Enhanced Parental Leave - Supporting you during life's biggest moments. Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice. Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board! Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family. A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements. Join us - let'sprevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at
27/07/2026
Full time
We're looking for a Senior Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high impact work that shapes how we detect and respond to threats at scale. You'll collaborate closely with our inhouse Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of it's kind at this scale, then this is the role for you. At Our Future Health, our mission is to transform the prevention,detectionand treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you. What you'll be doing Developing new threat-led detections in collaboration with our threat teambased on both threat intelligenceand the results of threat hunts. Creating novel analytic methods and techniques for incident detection. Working with our MSP provided SOC tomaintainour detectioncatalogueand tune existing rules. Developing and tuning Data Loss Prevention, Insider RiskManagementand other types of security rules withinMicrosoft Purviewand other key security monitoring tools. Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided,detections and other types of engineering work are delivered to theappropriate standardand that the maturity (inc. efficiency) of our security monitoring is continually improving. Supporting the development ofautomated custom reports on security operational performance and broader security topics (using Sentinel workbooks). Collaborating with wider tech and security teams on theappropriatesecuritymonitoringfor our various systems, including cloud platforms, SaaS applications and inhouse developed systems. Documenting securityprocesses and security tool low-level design/configuration. Contributing to the development of security service delivery and operation documentation. Supporting the security engineers, threatanalystsand wider security team with their various responsibilities, including achieving andmaintainingISO 27001 certification andanything that involves KQL. What you won't be doing Working in a siloed environment with no freedom to make decisions. Working in a place where you can't see the impact your expertise makes. To succeed in this role you will be able to demonstrate some of the following skills and experience: Highly proficient in writing KQL and ideallysome level ofproficiencyinPythonand Terraform. Significant hands on experience with Microsoft Sentinel. Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365. Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities. Experience withMicrosoft Purview tooling, in particular MPIP and Purview Data Loss Prevention. Experience with cloud-native logging(in particular Azureand Kubernetes). Experience of an 'everything-as-code',or at least a 'detection-as-code'approach, including CI/CD pipelines. Exposure to working with/inside an MSP SOC. Exposure to Agile working. Knowledge of attacker Tactics, Techniques and Procedures (TTPs). Knowledge of statistics, datascienceand AI/ML,in particular whenapplied to cyber security. Knowledge ofISO 27001. Desire to be part of a small fast paced team. Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK. Salary from £65,000 per annum. Generous Pension Scheme - We invest in your future with employer contributions of up to 12%. 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you. Enhanced Parental Leave - Supporting you during life's biggest moments. Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice. Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board! Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family. A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements. Join us - let'sprevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at
Senior Security Engineer
P2P
THE WORK As a Senior Security Engineer focusing on anti-abuse and threat intelligence, you will lead the design and development of systems and automation to detect, mitigate, and prevent threats targeting Ripple's staff, products, and users. This includes identifying and advising on Advanced Persistent Threats (APTs) targeting the crypto ecosystem, phishing campaigns, impersonation attempts, and social engineering campaigns across web, mobile, and social platforms. You will collaborate closely with Legal, Communications, Brand Security, and third party vendors to build a scalable and proactive threat intelligence capability. WHAT YOU'LL DO Operationalize threat intelligence: Develop systems to detect and disseminate intelligence on threats impacting Ripple and Ripple customers. Automate intelligence sharing: Build tooling, workflows and AI agents to streamline the integration and interpretation of intelligence across Ripple orgs. Analyze attack patterns: Investigate attacker infrastructure and threat trends to advise proactive defenses. Develop internal visibility tools: Create dashboards and alerts to supervise threat detection and public awareness on emerging threats. Assist with incident response: Assist in investigations for sophisticated abuse cases and help implement long term preventative measures. Guide strategy: Advise on threat intelligence standard methodologies, tooling decisions, and vendor integrations to improve Ripple's external security posture. WHAT YOU'LL BRING 5+ years of experience working within a security, abuse prevention, or threat detection domain, ideally with exposure to large scale platforms, FinTech, or crypto environments. Proficiency in Python, Go, or similar languages for building automation and detection systems. Experience investigating cyber threats, phishing, impersonation, or abuse at scale - ideally in FinTech, crypto, or social platforms. Ability to analyze attack trends, extract insights, and drive detection improvements through data. Familiarity with abuse reporting and enforcement APIs (e.g., threat intelligence feeds, social platforms, domain registrars). Strong communication skills and an ability to tailor them to various technical/non technical audiences. Passion for stopping bad actors and building trust in crypto ecosystems. Above all, a teammate that can handle ambitious situations, a rapidly maturing security culture, and an eagerness to mentor less expert engineers. Other common names for this role: Senior Threat Intelligence Engineer, Senior Trust & Safety Engineer. BENEFITS Competitive salary, bonuses, and equity Competitive benefits that cover physical and mental healthcare, retirement, family forming, and family support Employee giving match Mobile phone stipend RR days so you can rest and recharge Generous wellness reimbursement and weekly onsite & virtual programming Generous vacation policy - work with your manager to take time off when you need it Industry leading parental leave policies. Family planning benefits. Catered lunches, fully stocked kitchens with premium snacks/beverages, and plenty of fun events Benefits listed above are for full time employees. LEGAL Ripple is an Equal Opportunity Employer. We're committed to building a diverse and inclusive team. We do not discriminate against qualified employees or applicants because of race, color, religion, gender identity, sex, sexual identity, pregnancy, national origin, ancestry, citizenship, age, marital status, physical disability, mental disability, medical condition, military status, or any other characteristic protected by local law or ordinance. Please find our UK/EU Applicant Privacy Notice and California Applicant Privacy Notice for reference.
27/07/2026
Full time
THE WORK As a Senior Security Engineer focusing on anti-abuse and threat intelligence, you will lead the design and development of systems and automation to detect, mitigate, and prevent threats targeting Ripple's staff, products, and users. This includes identifying and advising on Advanced Persistent Threats (APTs) targeting the crypto ecosystem, phishing campaigns, impersonation attempts, and social engineering campaigns across web, mobile, and social platforms. You will collaborate closely with Legal, Communications, Brand Security, and third party vendors to build a scalable and proactive threat intelligence capability. WHAT YOU'LL DO Operationalize threat intelligence: Develop systems to detect and disseminate intelligence on threats impacting Ripple and Ripple customers. Automate intelligence sharing: Build tooling, workflows and AI agents to streamline the integration and interpretation of intelligence across Ripple orgs. Analyze attack patterns: Investigate attacker infrastructure and threat trends to advise proactive defenses. Develop internal visibility tools: Create dashboards and alerts to supervise threat detection and public awareness on emerging threats. Assist with incident response: Assist in investigations for sophisticated abuse cases and help implement long term preventative measures. Guide strategy: Advise on threat intelligence standard methodologies, tooling decisions, and vendor integrations to improve Ripple's external security posture. WHAT YOU'LL BRING 5+ years of experience working within a security, abuse prevention, or threat detection domain, ideally with exposure to large scale platforms, FinTech, or crypto environments. Proficiency in Python, Go, or similar languages for building automation and detection systems. Experience investigating cyber threats, phishing, impersonation, or abuse at scale - ideally in FinTech, crypto, or social platforms. Ability to analyze attack trends, extract insights, and drive detection improvements through data. Familiarity with abuse reporting and enforcement APIs (e.g., threat intelligence feeds, social platforms, domain registrars). Strong communication skills and an ability to tailor them to various technical/non technical audiences. Passion for stopping bad actors and building trust in crypto ecosystems. Above all, a teammate that can handle ambitious situations, a rapidly maturing security culture, and an eagerness to mentor less expert engineers. Other common names for this role: Senior Threat Intelligence Engineer, Senior Trust & Safety Engineer. BENEFITS Competitive salary, bonuses, and equity Competitive benefits that cover physical and mental healthcare, retirement, family forming, and family support Employee giving match Mobile phone stipend RR days so you can rest and recharge Generous wellness reimbursement and weekly onsite & virtual programming Generous vacation policy - work with your manager to take time off when you need it Industry leading parental leave policies. Family planning benefits. Catered lunches, fully stocked kitchens with premium snacks/beverages, and plenty of fun events Benefits listed above are for full time employees. LEGAL Ripple is an Equal Opportunity Employer. We're committed to building a diverse and inclusive team. We do not discriminate against qualified employees or applicants because of race, color, religion, gender identity, sex, sexual identity, pregnancy, national origin, ancestry, citizenship, age, marital status, physical disability, mental disability, medical condition, military status, or any other characteristic protected by local law or ordinance. Please find our UK/EU Applicant Privacy Notice and California Applicant Privacy Notice for reference.
Cloud Security Engineer
Intercom
Fin is the AI Customer Agent company on a mission to help businesses provide perfect customer experiences. Our AI Agent Fin is the highest-performing AI Customer Agent on the market today, enabling businesses to deliver impeccable, always-on customer support across the customer journey - from service, to sales, to ecommerce. Powered by our own AI models, Fin resolves complex customer issues end-to-end across every channel, with minimal set-up and integration. Fin can also be combined with our natively integrated Intercom help desk for one single system that is designed to meet the needs of modern day support teams. Founded in 2011, Fin became one of the fastest growing companies and remains one of the largest private software companies in the world with nearly 30,000 global businesses using our products to transform their customer support. Driven by our core values, we push boundaries, build with speed and intensity, and relentlessly deliver incredible value to our customers. What's the opportunity? Fin is transforming customer service through AI, helping businesses deliver fast, accurate, and reliable support at scale. Trust is foundational to that mission. The Cloud Security team is responsible for protecting the platforms that power Fin. We partner closely with infrastructure and product engineering teams to secure cloud environments, detect emerging threats, respond to incidents, and build the security foundations that enable teams to move quickly with confidence. The team owns critical cloud security capabilities including detection engineering, cloud security monitoring, incident response, cloud security controls, and the security tooling that protects Fin's production environments. The team is responsible for securing the cloud platforms and production systems that underpin every Fin customer interaction. The mission of the team is to help Fin build and operate trusted AI-powered customer service experiences by making security a natural part of how our cloud platforms, production systems, and engineering workflows are designed, deployed, and operated. As Fin continues to expand its capabilities and adoption, you'll help define how cloud security evolves alongside increasingly sophisticated systems and threat models. We're taking an AI-first approach to security, investing in areas such as AI-assisted detection engineering, automated investigations, continuous monitoring, and emerging defensive capabilities to help meet an evolving threat landscape. What will I be doing? Design and implement secure cloud architectures across our AWS environments. Build and maintain protective and detective controls that improve visibility into threats across our cloud environments. Develop detection engineering capabilities that identify attacker behaviour and reduce time to detection and response. Lead cloud security investigations and incident response activities in partnership with engineering teams. Participate in a shared on call rotation and help coordinate containment, remediation, and recovery efforts during security incidents. Build automation that improves the scalability, reliability, and effectiveness of security controls. Partner with infrastructure teams to embed security into cloud platforms, infrastructure as code workflows, and engineering practices. Develop and improve cloud security standards, guidance, and best practices across Fin. Drive security initiatives from problem definition through design, implementation, and measurable outcomes. Assess emerging threats to cloud environments and help evolve our defensive capabilities. Help shape Fin's AI-first approach to security, including AI-assisted detection, automated investigations, continuous monitoring, and emerging defensive capabilities. Support the secure adoption of AI-assisted software development tools and engineering workflows. What skills do I need? Proven experience in cloud security, security engineering, detection engineering, or a closely related field. Strong experience securing and operating production AWS environments. Deep understanding of cloud security principles, modern attack techniques, and security best practices. Experience building or operating detection, monitoring, or threat detection capabilities. Hands on experience investigating security incidents, leading technical investigations, and driving remediation efforts. Experience implementing security controls across cloud platforms and production environments. Strong programming skills and experience building automation, tooling, or operational workflows. Experience working with infrastructure as code practices and modern cloud-native technologies. Comfortable using modern AI assisted development tools to improve productivity and engineering effectiveness. Ability to communicate security concepts clearly and collaborate effectively with engineering teams. A pragmatic approach to balancing security, customer impact, and engineering velocity. Experience building detection engineering, threat hunting, or security operations capabilities at scale. Experience with cloud-native security platforms, CNAPP technologies, or large-scale cloud security monitoring. Experience applying AI to detection, response, threat analysis, or security operations workflows. Familiarity with AWS networking, identity, and cloud security patterns. Experience working across both large scale SaaS environments and high growth companies. We are a well treated bunch, with awesome benefits! If there's something important to you that's not on this list, talk to us! Competitive salary and equity in a fast-growing start up We serve lunch every weekday, plus a variety of snack foods and a fully stocked kitchen Unlimited access to Claude Code and best in class AI tools; experimentation & building is encouraged & celebrated. Pension scheme & match up to 4% Peace of mind with life assurance, as well as comprehensive health and dental insurance for you and your dependents Flexible paid time off policy Paid maternity leave, as well as 6 weeks paternity leave for fathers, to let you spend valuable time with your loved ones If you're cycling, we've got you covered on the Cycle to Work Scheme. With secure bike storage too MacBooks are our standard, but we also offer Windows for certain roles when needed. Fin has a hybrid working policy. We believe that working in person helps us stay connected, collaborate easier and create a great culture while still providing flexibility to work from home. We expect employees to be in the office at least three days per week. Fin values diversity and is committed to a policy of Equal Employment Opportunity. Fin will not discriminate against an applicant or employee on the basis of race, color, religion, creed, national origin, ancestry, sex, gender, age, physical or mental disability, veteran or military status, genetic information, sexual orientation, gender identity, gender expression, marital status, or any other legally recognized protected basis under federal, state, or local law.
27/07/2026
Full time
Fin is the AI Customer Agent company on a mission to help businesses provide perfect customer experiences. Our AI Agent Fin is the highest-performing AI Customer Agent on the market today, enabling businesses to deliver impeccable, always-on customer support across the customer journey - from service, to sales, to ecommerce. Powered by our own AI models, Fin resolves complex customer issues end-to-end across every channel, with minimal set-up and integration. Fin can also be combined with our natively integrated Intercom help desk for one single system that is designed to meet the needs of modern day support teams. Founded in 2011, Fin became one of the fastest growing companies and remains one of the largest private software companies in the world with nearly 30,000 global businesses using our products to transform their customer support. Driven by our core values, we push boundaries, build with speed and intensity, and relentlessly deliver incredible value to our customers. What's the opportunity? Fin is transforming customer service through AI, helping businesses deliver fast, accurate, and reliable support at scale. Trust is foundational to that mission. The Cloud Security team is responsible for protecting the platforms that power Fin. We partner closely with infrastructure and product engineering teams to secure cloud environments, detect emerging threats, respond to incidents, and build the security foundations that enable teams to move quickly with confidence. The team owns critical cloud security capabilities including detection engineering, cloud security monitoring, incident response, cloud security controls, and the security tooling that protects Fin's production environments. The team is responsible for securing the cloud platforms and production systems that underpin every Fin customer interaction. The mission of the team is to help Fin build and operate trusted AI-powered customer service experiences by making security a natural part of how our cloud platforms, production systems, and engineering workflows are designed, deployed, and operated. As Fin continues to expand its capabilities and adoption, you'll help define how cloud security evolves alongside increasingly sophisticated systems and threat models. We're taking an AI-first approach to security, investing in areas such as AI-assisted detection engineering, automated investigations, continuous monitoring, and emerging defensive capabilities to help meet an evolving threat landscape. What will I be doing? Design and implement secure cloud architectures across our AWS environments. Build and maintain protective and detective controls that improve visibility into threats across our cloud environments. Develop detection engineering capabilities that identify attacker behaviour and reduce time to detection and response. Lead cloud security investigations and incident response activities in partnership with engineering teams. Participate in a shared on call rotation and help coordinate containment, remediation, and recovery efforts during security incidents. Build automation that improves the scalability, reliability, and effectiveness of security controls. Partner with infrastructure teams to embed security into cloud platforms, infrastructure as code workflows, and engineering practices. Develop and improve cloud security standards, guidance, and best practices across Fin. Drive security initiatives from problem definition through design, implementation, and measurable outcomes. Assess emerging threats to cloud environments and help evolve our defensive capabilities. Help shape Fin's AI-first approach to security, including AI-assisted detection, automated investigations, continuous monitoring, and emerging defensive capabilities. Support the secure adoption of AI-assisted software development tools and engineering workflows. What skills do I need? Proven experience in cloud security, security engineering, detection engineering, or a closely related field. Strong experience securing and operating production AWS environments. Deep understanding of cloud security principles, modern attack techniques, and security best practices. Experience building or operating detection, monitoring, or threat detection capabilities. Hands on experience investigating security incidents, leading technical investigations, and driving remediation efforts. Experience implementing security controls across cloud platforms and production environments. Strong programming skills and experience building automation, tooling, or operational workflows. Experience working with infrastructure as code practices and modern cloud-native technologies. Comfortable using modern AI assisted development tools to improve productivity and engineering effectiveness. Ability to communicate security concepts clearly and collaborate effectively with engineering teams. A pragmatic approach to balancing security, customer impact, and engineering velocity. Experience building detection engineering, threat hunting, or security operations capabilities at scale. Experience with cloud-native security platforms, CNAPP technologies, or large-scale cloud security monitoring. Experience applying AI to detection, response, threat analysis, or security operations workflows. Familiarity with AWS networking, identity, and cloud security patterns. Experience working across both large scale SaaS environments and high growth companies. We are a well treated bunch, with awesome benefits! If there's something important to you that's not on this list, talk to us! Competitive salary and equity in a fast-growing start up We serve lunch every weekday, plus a variety of snack foods and a fully stocked kitchen Unlimited access to Claude Code and best in class AI tools; experimentation & building is encouraged & celebrated. Pension scheme & match up to 4% Peace of mind with life assurance, as well as comprehensive health and dental insurance for you and your dependents Flexible paid time off policy Paid maternity leave, as well as 6 weeks paternity leave for fathers, to let you spend valuable time with your loved ones If you're cycling, we've got you covered on the Cycle to Work Scheme. With secure bike storage too MacBooks are our standard, but we also offer Windows for certain roles when needed. Fin has a hybrid working policy. We believe that working in person helps us stay connected, collaborate easier and create a great culture while still providing flexibility to work from home. We expect employees to be in the office at least three days per week. Fin values diversity and is committed to a policy of Equal Employment Opportunity. Fin will not discriminate against an applicant or employee on the basis of race, color, religion, creed, national origin, ancestry, sex, gender, age, physical or mental disability, veteran or military status, genetic information, sexual orientation, gender identity, gender expression, marital status, or any other legally recognized protected basis under federal, state, or local law.
Cloud Security Engineer
United States Digital Space LLC
Fin is the AI Customer Agent company on a mission to help businesses provide perfect customer experiences. Our AI Agent Fin is the highest-performing AI Customer Agent on the market today, enabling businesses to deliver impeccable, always-on customer support across the customer journey - from service, to sales, to ecommerce. Powered by our own AI models, Fin resolves complex customer issues end-to-end across every channel, with minimal set-up and integration. Fin can also be combined with our natively integrated the company help desk for one single system that is designed to meet the needs of modern day support teams. Founded in 2011, Fin became one of the fastest growing companies and remains one of the largest private software companies in the world with nearly 30,000 global businesses using our products to transform their customer support. Driven by our core values, we push boundaries, build with speed and intensity, and relentlessly deliver incredible value to our customers. What's the opportunity? Fin is transforming customer service through AI, helping businesses deliver fast, accurate, and reliable support at scale. Trust is foundational to that mission. The Cloud Security team is responsible for protecting the platforms that power Fin. We partner closely with infrastructure and product engineering teams to secure cloud environments, detect emerging threats, respond to incidents, and build the security foundations that enable teams to move quickly with confidence. The team owns critical cloud security capabilities including detection engineering, cloud security monitoring, incident response, cloud security controls, and the security tooling that protects Fin's production environments. The team is responsible for securing the cloud platforms and production systems that underpin every Fin customer interaction. The mission of the team is to help Fin build and operate trusted AI-powered customer service experiences by making security a natural part of how our cloud platforms, production systems, and engineering workflows are designed, deployed, and operated. As Fin continues to expand its capabilities and adoption, you'll help define how cloud security evolves alongside increasingly sophisticated systems and threat models. We're taking an AI first approach to security, investing in areas such as AI assisted detection engineering, automated investigations, continuous monitoring, and emerging defensive capabilities to help meet an evolving threat landscape. What will I be doing? Design and implement secure cloud architectures across our AWS environments. Build and maintain protective and detective controls that improve visibility into threats across our cloud environments. Develop detection engineering capabilities that identify attacker behaviour and reduce time to detection and response. Lead cloud security investigations and incident response activities in partnership with engineering teams. Participate in a shared on call rotation and help coordinate containment, remediation, and recovery efforts during security incidents. Build automation that improves the scalability, reliability, and effectiveness of security controls. Partner with infrastructure teams to embed security into cloud platforms, infrastructure as code workflows, and engineering practices. Develop and improve cloud security standards, guidance, and best practices across Fin. Drive security initiatives from problem definition through design, implementation, and measurable outcomes. Assess emerging threats to cloud environments and help evolve our defensive capabilities. Help shape Fin's AI first approach to security, including AI assisted detection, automated investigations, continuous monitoring, and emerging defensive capabilities. Support the secure adoption of AI assisted software development tools and engineering workflows. What skills do I need? Proven experience in cloud security, security engineering, detection engineering, or a closely related field. Strong experience securing and operating production AWS environments. Deep understanding of cloud security principles, modern attack techniques, and security best practices. Experience building or operating detection, monitoring, or threat detection capabilities. Hands on experience investigating security incidents, leading technical investigations, and driving remediation efforts. Experience implementing security controls across cloud platforms and production environments. Strong programming skills and experience building automation, tooling, or operational workflows. Experience working with infrastructure as code practices and modern cloud native technologies. Comfortable using modern AI assisted development tools to improve productivity and engineering effectiveness. Ability to communicate security concepts clearly and collaborate effectively with engineering teams. A pragmatic approach to balancing security, customer impact, and engineering velocity. Bonus skills & attributes Experience building detection engineering, threat hunting, or security operations capabilities at scale. Experience with cloud native security platforms, CNAPP technologies, or large scale cloud security monitoring. Experience applying AI to detection, response, threat analysis, or security operations workflows. Familiarity with AWS networking, identity, and cloud security patterns. Experience working across both large scale SaaS environments and high growth companies. Benefits We are a well treated bunch, with awesome benefits! If there's something important to you that's not on this list, talk to us! Competitive salary and equity in a fast growing start up We serve lunch every weekday, plus a variety of snack foods and a fully stocked kitchen Regular compensation reviews - we reward great work! Unlimited access to Claude Code and best in class AI tools; experimentation & building is encouraged & celebrated. Pension scheme & match up to 4% Peace of mind with life assurance, as well as comprehensive health and dental insurance for you and your dependents Flexible paid time off policy Paid maternity leave, as well as 6 weeks paternity leave for fathers, to let you spend valuable time with your loved ones If you're cycling, we've got you covered on the Cycle to Work Scheme. With secure bike storage too MacBooks are our standard, but we also offer Windows for certain roles when needed.
27/07/2026
Full time
Fin is the AI Customer Agent company on a mission to help businesses provide perfect customer experiences. Our AI Agent Fin is the highest-performing AI Customer Agent on the market today, enabling businesses to deliver impeccable, always-on customer support across the customer journey - from service, to sales, to ecommerce. Powered by our own AI models, Fin resolves complex customer issues end-to-end across every channel, with minimal set-up and integration. Fin can also be combined with our natively integrated the company help desk for one single system that is designed to meet the needs of modern day support teams. Founded in 2011, Fin became one of the fastest growing companies and remains one of the largest private software companies in the world with nearly 30,000 global businesses using our products to transform their customer support. Driven by our core values, we push boundaries, build with speed and intensity, and relentlessly deliver incredible value to our customers. What's the opportunity? Fin is transforming customer service through AI, helping businesses deliver fast, accurate, and reliable support at scale. Trust is foundational to that mission. The Cloud Security team is responsible for protecting the platforms that power Fin. We partner closely with infrastructure and product engineering teams to secure cloud environments, detect emerging threats, respond to incidents, and build the security foundations that enable teams to move quickly with confidence. The team owns critical cloud security capabilities including detection engineering, cloud security monitoring, incident response, cloud security controls, and the security tooling that protects Fin's production environments. The team is responsible for securing the cloud platforms and production systems that underpin every Fin customer interaction. The mission of the team is to help Fin build and operate trusted AI-powered customer service experiences by making security a natural part of how our cloud platforms, production systems, and engineering workflows are designed, deployed, and operated. As Fin continues to expand its capabilities and adoption, you'll help define how cloud security evolves alongside increasingly sophisticated systems and threat models. We're taking an AI first approach to security, investing in areas such as AI assisted detection engineering, automated investigations, continuous monitoring, and emerging defensive capabilities to help meet an evolving threat landscape. What will I be doing? Design and implement secure cloud architectures across our AWS environments. Build and maintain protective and detective controls that improve visibility into threats across our cloud environments. Develop detection engineering capabilities that identify attacker behaviour and reduce time to detection and response. Lead cloud security investigations and incident response activities in partnership with engineering teams. Participate in a shared on call rotation and help coordinate containment, remediation, and recovery efforts during security incidents. Build automation that improves the scalability, reliability, and effectiveness of security controls. Partner with infrastructure teams to embed security into cloud platforms, infrastructure as code workflows, and engineering practices. Develop and improve cloud security standards, guidance, and best practices across Fin. Drive security initiatives from problem definition through design, implementation, and measurable outcomes. Assess emerging threats to cloud environments and help evolve our defensive capabilities. Help shape Fin's AI first approach to security, including AI assisted detection, automated investigations, continuous monitoring, and emerging defensive capabilities. Support the secure adoption of AI assisted software development tools and engineering workflows. What skills do I need? Proven experience in cloud security, security engineering, detection engineering, or a closely related field. Strong experience securing and operating production AWS environments. Deep understanding of cloud security principles, modern attack techniques, and security best practices. Experience building or operating detection, monitoring, or threat detection capabilities. Hands on experience investigating security incidents, leading technical investigations, and driving remediation efforts. Experience implementing security controls across cloud platforms and production environments. Strong programming skills and experience building automation, tooling, or operational workflows. Experience working with infrastructure as code practices and modern cloud native technologies. Comfortable using modern AI assisted development tools to improve productivity and engineering effectiveness. Ability to communicate security concepts clearly and collaborate effectively with engineering teams. A pragmatic approach to balancing security, customer impact, and engineering velocity. Bonus skills & attributes Experience building detection engineering, threat hunting, or security operations capabilities at scale. Experience with cloud native security platforms, CNAPP technologies, or large scale cloud security monitoring. Experience applying AI to detection, response, threat analysis, or security operations workflows. Familiarity with AWS networking, identity, and cloud security patterns. Experience working across both large scale SaaS environments and high growth companies. Benefits We are a well treated bunch, with awesome benefits! If there's something important to you that's not on this list, talk to us! Competitive salary and equity in a fast growing start up We serve lunch every weekday, plus a variety of snack foods and a fully stocked kitchen Regular compensation reviews - we reward great work! Unlimited access to Claude Code and best in class AI tools; experimentation & building is encouraged & celebrated. Pension scheme & match up to 4% Peace of mind with life assurance, as well as comprehensive health and dental insurance for you and your dependents Flexible paid time off policy Paid maternity leave, as well as 6 weeks paternity leave for fathers, to let you spend valuable time with your loved ones If you're cycling, we've got you covered on the Cycle to Work Scheme. With secure bike storage too MacBooks are our standard, but we also offer Windows for certain roles when needed.
Security Operations Analyst, UK
Triwill Group
Description: Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril's family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years. ABOUT THE TEAM Anduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defence technologies. As a SecOps analyst on the detection and response team, you'll be responsible for monitoring and responding to adversarial activity while helping incorporate key detection feedback loops with the detection engineering team. When not responding to threats, you'll be asking questions of our data sets, conducting threat hunting and data normalisation operations across the organization to understand user behavior and identify anomalies. WHAT YOU'LL DO Triage and respond to alerts / incidents covering multiple disciplines including, but not limited to, phishing, endpoints, cloud infrastructure and services, and SaaS applications Build and optimise tailored detection signatures, response playbooks, and response automation using detection-as-code principles As the frontline of DNR, you will lead the feedback loop for detections, ensuring alerts are fine tuned to reduce false positives Participate in threat modeling scenarios with cross-functional partners to understand weaknesses across Cloud, Mobile, Endpoints, and other environments incorporating findings into security controls and/or detection signatures Organise and conduct threat hunting and data baselines to identify anomalous patterns in data Participate in an on-call rotation responding to security events and conducting incident response investigations while effectively communicating findings to key stakeholders Proactively collaborate with a wide range of stakeholders REQUIRED QUALIFICATIONS Experience in security monitoring, log analysis, and detection engineering within large data sets across endpoint, network, and a wide variety of application log sources Experience in Python development, specifically contributing to a shared codebase used for automating SOC operations Must have experience with one or more SIEM languages (SPL, KQL, SQL) Broad range of practical security knowledge across the spectrum of endpoint, network, identity, application, and cloud infrastructure Knowledge of attacker tactics, techniques, and procedures (TTPs) across Windows, Linux, MacOS, AWS/Azure, etc. Strong communication skills and experience collaborating with internal and external stakeholders Eligible to obtain and maintain an Australian NV2 clearance PREFERRED QUALIFICATIONS Experience conducting incident response in the Cloud (AWS, Azure, GCP) Digital Forensics and/or reverse engineering experience is a plus! Benefits At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you're supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits. Data Privacy To view Anduril's candidate data privacy policy, you can visit By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.
27/07/2026
Full time
Description: Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril's family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years. ABOUT THE TEAM Anduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defence technologies. As a SecOps analyst on the detection and response team, you'll be responsible for monitoring and responding to adversarial activity while helping incorporate key detection feedback loops with the detection engineering team. When not responding to threats, you'll be asking questions of our data sets, conducting threat hunting and data normalisation operations across the organization to understand user behavior and identify anomalies. WHAT YOU'LL DO Triage and respond to alerts / incidents covering multiple disciplines including, but not limited to, phishing, endpoints, cloud infrastructure and services, and SaaS applications Build and optimise tailored detection signatures, response playbooks, and response automation using detection-as-code principles As the frontline of DNR, you will lead the feedback loop for detections, ensuring alerts are fine tuned to reduce false positives Participate in threat modeling scenarios with cross-functional partners to understand weaknesses across Cloud, Mobile, Endpoints, and other environments incorporating findings into security controls and/or detection signatures Organise and conduct threat hunting and data baselines to identify anomalous patterns in data Participate in an on-call rotation responding to security events and conducting incident response investigations while effectively communicating findings to key stakeholders Proactively collaborate with a wide range of stakeholders REQUIRED QUALIFICATIONS Experience in security monitoring, log analysis, and detection engineering within large data sets across endpoint, network, and a wide variety of application log sources Experience in Python development, specifically contributing to a shared codebase used for automating SOC operations Must have experience with one or more SIEM languages (SPL, KQL, SQL) Broad range of practical security knowledge across the spectrum of endpoint, network, identity, application, and cloud infrastructure Knowledge of attacker tactics, techniques, and procedures (TTPs) across Windows, Linux, MacOS, AWS/Azure, etc. Strong communication skills and experience collaborating with internal and external stakeholders Eligible to obtain and maintain an Australian NV2 clearance PREFERRED QUALIFICATIONS Experience conducting incident response in the Cloud (AWS, Azure, GCP) Digital Forensics and/or reverse engineering experience is a plus! Benefits At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you're supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits. Data Privacy To view Anduril's candidate data privacy policy, you can visit By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.
Endpoint Security & Exposure Engineer
Jacobs Engineering Group Inc.
At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for thriving cities, resilient environments, mission-critical outcomes, operational advancement, scientific discovery and cutting-edge manufacturing, turning abstract ideas into realities that transform the world for good. Your impact This is an exciting opportunity to join Jacobs' Cyber Security team as an Endpoint Security & Exposure Management Engineer. You'll play a key role in reducing cyber risk by driving vulnerability remediation, strengthening endpoint security controls, and improving visibility of security exposure across a global technology estate. Working across infrastructure, cloud, desktop engineering, and security teams, you'll help ensure vulnerabilities are identified, prioritised, and remediated effectively while supporting key security capabilities including application control, privilege management, and endpoint hardening. If you're passionate about vulnerability management, exposure reduction, and delivering measurable security outcomes, this is an opportunity to make a real impact within a global organisation. Day to Day Lead vulnerability and exposure management activities across enterprise environments, ensuring security risks are identified, prioritised, and remediated effectively Work closely with technology teams to drive remediation programmes and reduce organisational cyber risk Support and enhance endpoint security capabilities, including application control, allowlisting, privilege management, and endpoint hardening Use data, reporting, and dashboards to provide visibility of cyber exposure, remediation performance, and security outcomes Assess emerging vulnerabilities and threats, providing risk-based recommendations and guidance to stakeholders Act as a trusted security partner across infrastructure, cloud, application, and operational teams, helping embed secure practices and improve resilience What You'll Bring Experience in cybersecurity, vulnerability management, security engineering, or endpoint security Strong understanding of risk-based vulnerability management and remediation prioritisation Experience working with vulnerability management platforms such as Tenable, Qualys, or Rapid7 Experience with ServiceNow Vulnerability Response or similar remediation workflow platforms Knowledge of endpoint security technologies including application control, privilege management, and endpoint protection A collaborative approach with strong stakeholder engagement and communication skills The ability to translate technical security risks into meaningful business outcomes Experience implementing Zero Trust principles Exposure to Microsoft Defender for Endpoint, Intune, Active Directory, and Entra ID Experience working within cloud environments including Azure, AWS, or Google Cloud Knowledge of frameworks such as NIST, ISO 27001, CIS Controls, Cyber Essentials Plus, and NCSC CAF Industry certifications including CISSP, CISM, Security+, GIAC, Microsoft Security, or ServiceNow certifications What's In It For You Shape how cyber risk is managed across a global organisation Take ownership of a critical vulnerability and exposure management capability Work with leading security technologies across endpoint, cloud, and enterprise environments Influence security strategy and drive measurable improvements to Jacobs' security posture Collaborate with talented cybersecurity, infrastructure, cloud, and engineering professionals around the world Enjoy genuine flexibility with remote and hybrid working options and no mandated office attendance requirements Be part of a team committed to innovation, continuous improvement, and security excellence A global network of expertise and opportunity A culture founded on safety, integrity, inclusion, and belonging Flexible working arrangements that support your well-being and potential Opportunities to make a real-world impact through our global giving and volunteering programs Up to 10% pension 24 days ( days bought) holidays Free medical and income protection insurance and many more! &Data Here's what you'll need Technical Skills Application control and allowlisting technologies Privilege management solutions Endpoint hardening methodologies Zero Trust security principles Endpoint security architecture Vulnerability & Exposure Management Vulnerability assessment and management Risk prioritization frameworks Patch and remediation management Security risk analysis Platforms & Technologies Microsoft Windows Server and Windows 11 Active Directory and Entra ID Microsoft Defender for Endpoint Cloud platforms (Azure, AWS, or Google Cloud) ServiceNow Vulnerability Response Scripting & Automation API integrations and workflow automation Security reporting and dashboard development Preferred Qualifications Experience implementing Zero Trust security controls. Experience with endpoint detection and response (EDR) platforms. Familiarity with security frameworks including: oNIST Cybersecurity Framework oCIS Controls oISO 27001 oNCSC Cyber Assessment Framework Experience with cloud security and hybrid infrastructure environments. Experience leading vulnerability remediation programs across multiple technology domains. Preferred Certifications GIAC Security Certifications Certified Information Security Manager (CISM) Microsoft Security Certifications Strong analytical and problem-solving skills. Excellent stakeholder management and communication abilities. Ability to translate technical risk into business impact. Strong organizational and prioritization skills. Collaborative approach to driving remediation and risk reduction. Continuous improvement mindset focused on measurable security outcomes. Success Measures Reduction in privileged access risk. Increased endpoint security control coverage. Reduction in critical and high-risk vulnerabilities. Improved vulnerability remediation performance and SLA compliance. Improved visibility of enterprise cyber exposure. Successful implementation of least-privilege principles across the endpoint estate. Measurable reduction in organizational attack surface and cyber risk Joining Jacobs not only connects you locally but globally. Our values stand on a foundation of safety, integrity, inclusion and belonging. We put people at the heart of our business, and we truly believe that by supporting one another through our culture of caring, we all succeed. We value positive mental health and a sense of belonging for all employees. With safety and flexibility always top of mind, we've gone beyond traditional ways of working so you have the support, means and space to maximize your potential. You'll uncover flexible working arrangements, benefits, and opportunities, from well-being benefits to our global giving and volunteering program, to exploring new and inventive ways to help our clients make the world a better place. No matter what drives you, you'll discover how you can cultivate, nurture, and achieve your goals - all at a single global company. Find out more about life at Jacobs . We aim to embed inclusion and belonging in everything we do. We know that if we are inclusive, we're more connected and creative. We accept people for who they are, and we champion the richness of different perspectives, lived experiences and backgrounds in the workplace, as a source of learning and innovation. We are committed to building vibrant communities within Jacobs, including through our Jacobs Employee Networks, Communities of Practice and our Find Your Community initiatives, allowing every employee to find connection, purpose, and belonging.Find out more about ourJacobs Employee Networks here . Jacobs partners with VERCIDA to help us attract and retain talent from a wide range of backgrounds. For greater online accessibility please visit to view and access our roles. As a disability confident employer, we will interview disabled candidates who best meet the criteria. We welcome applications from candidates who are seeking flexible working and from those who may not meet all the listed requirements for a role. We value collaboration and believe that in-person interactions are crucial for both our culture and client delivery. We empower employees with our hybrid working policy, allowing them to split their work week between Jacobs offices/projects and remote locations enabling them to deliver their best work. Your application experience is important to us, and we're keen to adapt to make every interaction even better. If you require further support or reasonable adjustments with regards to the recruitment process (for example, you require the application form in a different format), please contact the team via Careers Support .
27/07/2026
Full time
At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for thriving cities, resilient environments, mission-critical outcomes, operational advancement, scientific discovery and cutting-edge manufacturing, turning abstract ideas into realities that transform the world for good. Your impact This is an exciting opportunity to join Jacobs' Cyber Security team as an Endpoint Security & Exposure Management Engineer. You'll play a key role in reducing cyber risk by driving vulnerability remediation, strengthening endpoint security controls, and improving visibility of security exposure across a global technology estate. Working across infrastructure, cloud, desktop engineering, and security teams, you'll help ensure vulnerabilities are identified, prioritised, and remediated effectively while supporting key security capabilities including application control, privilege management, and endpoint hardening. If you're passionate about vulnerability management, exposure reduction, and delivering measurable security outcomes, this is an opportunity to make a real impact within a global organisation. Day to Day Lead vulnerability and exposure management activities across enterprise environments, ensuring security risks are identified, prioritised, and remediated effectively Work closely with technology teams to drive remediation programmes and reduce organisational cyber risk Support and enhance endpoint security capabilities, including application control, allowlisting, privilege management, and endpoint hardening Use data, reporting, and dashboards to provide visibility of cyber exposure, remediation performance, and security outcomes Assess emerging vulnerabilities and threats, providing risk-based recommendations and guidance to stakeholders Act as a trusted security partner across infrastructure, cloud, application, and operational teams, helping embed secure practices and improve resilience What You'll Bring Experience in cybersecurity, vulnerability management, security engineering, or endpoint security Strong understanding of risk-based vulnerability management and remediation prioritisation Experience working with vulnerability management platforms such as Tenable, Qualys, or Rapid7 Experience with ServiceNow Vulnerability Response or similar remediation workflow platforms Knowledge of endpoint security technologies including application control, privilege management, and endpoint protection A collaborative approach with strong stakeholder engagement and communication skills The ability to translate technical security risks into meaningful business outcomes Experience implementing Zero Trust principles Exposure to Microsoft Defender for Endpoint, Intune, Active Directory, and Entra ID Experience working within cloud environments including Azure, AWS, or Google Cloud Knowledge of frameworks such as NIST, ISO 27001, CIS Controls, Cyber Essentials Plus, and NCSC CAF Industry certifications including CISSP, CISM, Security+, GIAC, Microsoft Security, or ServiceNow certifications What's In It For You Shape how cyber risk is managed across a global organisation Take ownership of a critical vulnerability and exposure management capability Work with leading security technologies across endpoint, cloud, and enterprise environments Influence security strategy and drive measurable improvements to Jacobs' security posture Collaborate with talented cybersecurity, infrastructure, cloud, and engineering professionals around the world Enjoy genuine flexibility with remote and hybrid working options and no mandated office attendance requirements Be part of a team committed to innovation, continuous improvement, and security excellence A global network of expertise and opportunity A culture founded on safety, integrity, inclusion, and belonging Flexible working arrangements that support your well-being and potential Opportunities to make a real-world impact through our global giving and volunteering programs Up to 10% pension 24 days ( days bought) holidays Free medical and income protection insurance and many more! &Data Here's what you'll need Technical Skills Application control and allowlisting technologies Privilege management solutions Endpoint hardening methodologies Zero Trust security principles Endpoint security architecture Vulnerability & Exposure Management Vulnerability assessment and management Risk prioritization frameworks Patch and remediation management Security risk analysis Platforms & Technologies Microsoft Windows Server and Windows 11 Active Directory and Entra ID Microsoft Defender for Endpoint Cloud platforms (Azure, AWS, or Google Cloud) ServiceNow Vulnerability Response Scripting & Automation API integrations and workflow automation Security reporting and dashboard development Preferred Qualifications Experience implementing Zero Trust security controls. Experience with endpoint detection and response (EDR) platforms. Familiarity with security frameworks including: oNIST Cybersecurity Framework oCIS Controls oISO 27001 oNCSC Cyber Assessment Framework Experience with cloud security and hybrid infrastructure environments. Experience leading vulnerability remediation programs across multiple technology domains. Preferred Certifications GIAC Security Certifications Certified Information Security Manager (CISM) Microsoft Security Certifications Strong analytical and problem-solving skills. Excellent stakeholder management and communication abilities. Ability to translate technical risk into business impact. Strong organizational and prioritization skills. Collaborative approach to driving remediation and risk reduction. Continuous improvement mindset focused on measurable security outcomes. Success Measures Reduction in privileged access risk. Increased endpoint security control coverage. Reduction in critical and high-risk vulnerabilities. Improved vulnerability remediation performance and SLA compliance. Improved visibility of enterprise cyber exposure. Successful implementation of least-privilege principles across the endpoint estate. Measurable reduction in organizational attack surface and cyber risk Joining Jacobs not only connects you locally but globally. Our values stand on a foundation of safety, integrity, inclusion and belonging. We put people at the heart of our business, and we truly believe that by supporting one another through our culture of caring, we all succeed. We value positive mental health and a sense of belonging for all employees. With safety and flexibility always top of mind, we've gone beyond traditional ways of working so you have the support, means and space to maximize your potential. You'll uncover flexible working arrangements, benefits, and opportunities, from well-being benefits to our global giving and volunteering program, to exploring new and inventive ways to help our clients make the world a better place. No matter what drives you, you'll discover how you can cultivate, nurture, and achieve your goals - all at a single global company. Find out more about life at Jacobs . We aim to embed inclusion and belonging in everything we do. We know that if we are inclusive, we're more connected and creative. We accept people for who they are, and we champion the richness of different perspectives, lived experiences and backgrounds in the workplace, as a source of learning and innovation. We are committed to building vibrant communities within Jacobs, including through our Jacobs Employee Networks, Communities of Practice and our Find Your Community initiatives, allowing every employee to find connection, purpose, and belonging.Find out more about ourJacobs Employee Networks here . Jacobs partners with VERCIDA to help us attract and retain talent from a wide range of backgrounds. For greater online accessibility please visit to view and access our roles. As a disability confident employer, we will interview disabled candidates who best meet the criteria. We welcome applications from candidates who are seeking flexible working and from those who may not meet all the listed requirements for a role. We value collaboration and believe that in-person interactions are crucial for both our culture and client delivery. We empower employees with our hybrid working policy, allowing them to split their work week between Jacobs offices/projects and remote locations enabling them to deliver their best work. Your application experience is important to us, and we're keen to adapt to make every interaction even better. If you require further support or reasonable adjustments with regards to the recruitment process (for example, you require the application form in a different format), please contact the team via Careers Support .
Senior AppSec Engineer - Remote, Impactful Security
aitrainer
Prolific is seeking a Senior Application Security Engineer to work remotely within the UK, joining a team that protects participant data, researcher credentials, and payment flows. You'll be hands-on, reviewing pull requests, threat modeling new features, and building security automation to keep pace with scaling. You'll collaborate with product engineering, platform, data, and TechOps to embed secure development practices across the SDLC and improve detection of evolving threats.
27/07/2026
Full time
Prolific is seeking a Senior Application Security Engineer to work remotely within the UK, joining a team that protects participant data, researcher credentials, and payment flows. You'll be hands-on, reviewing pull requests, threat modeling new features, and building security automation to keep pace with scaling. You'll collaborate with product engineering, platform, data, and TechOps to embed secure development practices across the SDLC and improve detection of evolving threats.
Cyber Projects Lead
Essar Oil Limited Ellesmere Port, Cheshire
Select how often (in days) to receive an alert: Stanlow Manufacturing Complex, Ellesmere Port 10% Company Contribution Pension rising to 15% with service 25 days Holiday, increasing with service Private Medical Insurance Additional Flex Benefits- including Holiday Purchase Access to Employee Assistance Programme with Exclusive access to a range of Discounts Free Secure On-Site Car Parking About the Company Do you want to work for the company that's playing a leading role in delivering the North West's low carbon future? EET Fuels (Trading name of Essar Oil (UK) Limited) produces over 16% of the UK's road transport fuels, provides key feedstocks to Britain's petrochemical industry and is investing in developing low carbon fuels. We are a major supplier in the North West and beyond with customers including most of the major retail brands operated by international oil companies and supermarkets, Manchester Airport, leading commercial airlines and the region's trains and buses. And we're central to the innovative HyNet project which is redefining energy to achieve our regional low carbon ambitions and national policy targets. We employ over 800 expert and engaged colleagues, who are at the heart of everything we do. The company has an embedded safety culture, technically challenging work across all the different parts of the business and some of the best training available in the energy industry. Please Note, we work with a carefully selected set of recruitment agencies, and we are not looking to add to the current preferred suppliers list. We are unable to accept representations from agencies that are not on that preferred supplier list. The Role We currently have an exciting opportunity for a Cyber Security Project Manager who will be responsible for planning, executing, and delivering cybersecurity initiatives aligned with the NIST Cybersecurity Framework (CSF). This role ensures that cyber projects support the organization's strategic objectives across the five NIST CSF functions: Identify, Protect, Detect, Respond, and Recover. Primary Accountabilities Develop and maintain project documentation, including plans, reports, and dashboards Coordinate with stakeholders to define project scope, timelines, and deliverables Coordinate risk assessments and asset inventories to inform project scope and priorities Lead implementation of security controls and awareness programs within project deliverables Become the 'go to' person for Cyber Security solutions Embed secure by design into IT/Business Projects Conduct threat modelling & architecture reviews Define secure configuration baselines, security architecture and patterns Ensure integration of monitoring and detection capabilities in new systems and upgrades Develop incident response capabilities and ensure readiness as part of project outcomes Support recovery planning and resilience measures in all cybersecurity initiatives Be an active member of the CAB, assessing each request from a cybersecurity perspective to make informed decisions on what controls need to be applied About You Our ideal candidate will hold a degree in Cybersecurity, Information Security, Computer Science, IT, Systems Engineering, or another relevant discipline within the fields of information security or information technology. You will hold Cybersecurity certifications such as CISSP, CISM, or equivalent and a Project Management Professional (PMP) or PRINCE2 certification. Industry relevant professional qualifications e.g., Sec+, CySa+, Vendor Specific are not essential but highly desirable. You will bring proven experience in managing cybersecurity projects and programs, with strong knowledge of the NIST Cybersecurity Framework, project management methodologies, and cloud security best practices. A solid understanding of Azure architecture, networking, and identity management is essential, along with familiarity with cybersecurity technologies and risk management practices. You will be confident coordinating cross functional teams, managing stakeholder expectations, and communicating clearly at all levels. Experience working in regulated industries such as finance, healthcare, or energy is important, as is a good understanding of key compliance standards including GDPR, NIS CAF, NIST CSF, and ISO 27001. Closing Date This vacancy will be advertised for a minimum period of two weeks and will remain open to applications until an offer has been made and accepted. Therefore, the vacancy may close at any time after 17/08/2026, and we encourage interested candidates to apply as early as possible.
27/07/2026
Full time
Select how often (in days) to receive an alert: Stanlow Manufacturing Complex, Ellesmere Port 10% Company Contribution Pension rising to 15% with service 25 days Holiday, increasing with service Private Medical Insurance Additional Flex Benefits- including Holiday Purchase Access to Employee Assistance Programme with Exclusive access to a range of Discounts Free Secure On-Site Car Parking About the Company Do you want to work for the company that's playing a leading role in delivering the North West's low carbon future? EET Fuels (Trading name of Essar Oil (UK) Limited) produces over 16% of the UK's road transport fuels, provides key feedstocks to Britain's petrochemical industry and is investing in developing low carbon fuels. We are a major supplier in the North West and beyond with customers including most of the major retail brands operated by international oil companies and supermarkets, Manchester Airport, leading commercial airlines and the region's trains and buses. And we're central to the innovative HyNet project which is redefining energy to achieve our regional low carbon ambitions and national policy targets. We employ over 800 expert and engaged colleagues, who are at the heart of everything we do. The company has an embedded safety culture, technically challenging work across all the different parts of the business and some of the best training available in the energy industry. Please Note, we work with a carefully selected set of recruitment agencies, and we are not looking to add to the current preferred suppliers list. We are unable to accept representations from agencies that are not on that preferred supplier list. The Role We currently have an exciting opportunity for a Cyber Security Project Manager who will be responsible for planning, executing, and delivering cybersecurity initiatives aligned with the NIST Cybersecurity Framework (CSF). This role ensures that cyber projects support the organization's strategic objectives across the five NIST CSF functions: Identify, Protect, Detect, Respond, and Recover. Primary Accountabilities Develop and maintain project documentation, including plans, reports, and dashboards Coordinate with stakeholders to define project scope, timelines, and deliverables Coordinate risk assessments and asset inventories to inform project scope and priorities Lead implementation of security controls and awareness programs within project deliverables Become the 'go to' person for Cyber Security solutions Embed secure by design into IT/Business Projects Conduct threat modelling & architecture reviews Define secure configuration baselines, security architecture and patterns Ensure integration of monitoring and detection capabilities in new systems and upgrades Develop incident response capabilities and ensure readiness as part of project outcomes Support recovery planning and resilience measures in all cybersecurity initiatives Be an active member of the CAB, assessing each request from a cybersecurity perspective to make informed decisions on what controls need to be applied About You Our ideal candidate will hold a degree in Cybersecurity, Information Security, Computer Science, IT, Systems Engineering, or another relevant discipline within the fields of information security or information technology. You will hold Cybersecurity certifications such as CISSP, CISM, or equivalent and a Project Management Professional (PMP) or PRINCE2 certification. Industry relevant professional qualifications e.g., Sec+, CySa+, Vendor Specific are not essential but highly desirable. You will bring proven experience in managing cybersecurity projects and programs, with strong knowledge of the NIST Cybersecurity Framework, project management methodologies, and cloud security best practices. A solid understanding of Azure architecture, networking, and identity management is essential, along with familiarity with cybersecurity technologies and risk management practices. You will be confident coordinating cross functional teams, managing stakeholder expectations, and communicating clearly at all levels. Experience working in regulated industries such as finance, healthcare, or energy is important, as is a good understanding of key compliance standards including GDPR, NIS CAF, NIST CSF, and ISO 27001. Closing Date This vacancy will be advertised for a minimum period of two weeks and will remain open to applications until an offer has been made and accepted. Therefore, the vacancy may close at any time after 17/08/2026, and we encourage interested candidates to apply as early as possible.
Sainsbury's
Senior PAM & AI Engineer (Privileged Access Management)
Sainsbury's
Senior Identity and Access Management Engineer (PAM) Essential Criteria Proven experience applying Identity & Access Management (IAM) principles including Authentication, Authorisation, Access control models (RBAC / ABAC / PBAC), identity lifecycle management (Joiners / Movers / Leavers) and Zero Trust. Hands-on experience designing or leading AI driven initiatives within IAM or Cybersecurity. Strong ability to analyse identity telemetry (audit logs, sign in- logs, access data) and translate insights into actionable improvements Extensive hands-on- experience with Microsoft Entra ID (Azure AD), including: Users, Groups (static & dynamic), roles, service principals, app registrations Directories, Tenants, Objects, and Attribute Structures Conditional Access policies, SSO (SAML & OIDC), Access Packages, MFA and Passwordless authentication (e.g. Windows Hello for Business, FIDO2) Identity governance activities including Access reviews, Entitlement Management and access control models. MS and 3rd party Agentic AI agents governance and lifecycle management. Solid engineering experience in Privileged Access Management (PAM) such as CyberArk, StrongDM: User and group management, OU design, Group Policy Objects (GPOs) Hybrid identity integration (Azure AD Connect / Cloud Sync) Password rotation policies Different types of service accounts for on-premises and cloud use cases (SVC, gMSA, MI, SPN, RPA) Working knowledge of how privileges and account types are secured within different operating systems, databases, servers, cloud resources. Experience working with Identity Governance tooling such as Saviynt / SailPoint or any other similar product. Experience with securing access within cloud platforms and technologies (Azure, AWS, GCP). Ability to define AI use cases and requirements aligned to Agent identity governance, Agent lifecycle management, designing controls for effective risk reduction Strong understanding of identity threat landscape and how AI can be applied to detect and mitigate risks Experience in gathering high level technical requirements, discuss with stakeholders to break it down to detailed requirements along with timeline and communicate to the engineers Experience mentoring or coaching engineers, provide technical advice to the team and contributing to team standards and best practices Work with Engineering and Product Manager to deliver technical milestones in line with product and business strategy. Work collaboratively with IT, product teams, Security Operations Centre, Security Analysts, Security Architects and end users to support IAM & PAM solutions and to ensure secure delivery, safeguarding both colleague and customer data. Exhibit excellent communication and presentation skills, able to convey complex issues and findings clearly and effectively. Demonstrates a strong technical mindset with the ability to analyse complex IAM, PAM and AI challenges, make sound architectural and engineering decisions, and proactively remove technical or organisational blockers to enable effective and timely delivery. Maintains a commitment to continuous learning while building strong, trusted relationships with technical teams, security partners, and business stakeholders to drive collaboration, capability uplift, and shared ownership of outcomes. Additional Criteria Experience using AI and machine learning concepts to analyse identity related data (e.g. -sign in- logs, access patterns, usage trends) Knowledge of AI assisted- automation use cases within IAM: Access or sign in anomaly detection Risk based- access decisions Intelligent access reviews or entitlement recommendations Experience with Microsoft security and analytics tools (e.g. Entra ID logs, Azure Monitor, Log Analytics, Sentinel). Understanding of ethical AI and responsible use of AI, especially in security sensitive and -personal data- contexts. Familiarity with data governance, data quality, and information security principles, particularly where AI models consume identity data. Strong focus on security, governance, and continuous improvement Relevant professional certifications (or actively working towards), such as: Microsoft Identity or Security certifications Privileged Access Management certifications AI / data analytics certifications CISSP, CISM, or equivalent
27/07/2026
Full time
Senior Identity and Access Management Engineer (PAM) Essential Criteria Proven experience applying Identity & Access Management (IAM) principles including Authentication, Authorisation, Access control models (RBAC / ABAC / PBAC), identity lifecycle management (Joiners / Movers / Leavers) and Zero Trust. Hands-on experience designing or leading AI driven initiatives within IAM or Cybersecurity. Strong ability to analyse identity telemetry (audit logs, sign in- logs, access data) and translate insights into actionable improvements Extensive hands-on- experience with Microsoft Entra ID (Azure AD), including: Users, Groups (static & dynamic), roles, service principals, app registrations Directories, Tenants, Objects, and Attribute Structures Conditional Access policies, SSO (SAML & OIDC), Access Packages, MFA and Passwordless authentication (e.g. Windows Hello for Business, FIDO2) Identity governance activities including Access reviews, Entitlement Management and access control models. MS and 3rd party Agentic AI agents governance and lifecycle management. Solid engineering experience in Privileged Access Management (PAM) such as CyberArk, StrongDM: User and group management, OU design, Group Policy Objects (GPOs) Hybrid identity integration (Azure AD Connect / Cloud Sync) Password rotation policies Different types of service accounts for on-premises and cloud use cases (SVC, gMSA, MI, SPN, RPA) Working knowledge of how privileges and account types are secured within different operating systems, databases, servers, cloud resources. Experience working with Identity Governance tooling such as Saviynt / SailPoint or any other similar product. Experience with securing access within cloud platforms and technologies (Azure, AWS, GCP). Ability to define AI use cases and requirements aligned to Agent identity governance, Agent lifecycle management, designing controls for effective risk reduction Strong understanding of identity threat landscape and how AI can be applied to detect and mitigate risks Experience in gathering high level technical requirements, discuss with stakeholders to break it down to detailed requirements along with timeline and communicate to the engineers Experience mentoring or coaching engineers, provide technical advice to the team and contributing to team standards and best practices Work with Engineering and Product Manager to deliver technical milestones in line with product and business strategy. Work collaboratively with IT, product teams, Security Operations Centre, Security Analysts, Security Architects and end users to support IAM & PAM solutions and to ensure secure delivery, safeguarding both colleague and customer data. Exhibit excellent communication and presentation skills, able to convey complex issues and findings clearly and effectively. Demonstrates a strong technical mindset with the ability to analyse complex IAM, PAM and AI challenges, make sound architectural and engineering decisions, and proactively remove technical or organisational blockers to enable effective and timely delivery. Maintains a commitment to continuous learning while building strong, trusted relationships with technical teams, security partners, and business stakeholders to drive collaboration, capability uplift, and shared ownership of outcomes. Additional Criteria Experience using AI and machine learning concepts to analyse identity related data (e.g. -sign in- logs, access patterns, usage trends) Knowledge of AI assisted- automation use cases within IAM: Access or sign in anomaly detection Risk based- access decisions Intelligent access reviews or entitlement recommendations Experience with Microsoft security and analytics tools (e.g. Entra ID logs, Azure Monitor, Log Analytics, Sentinel). Understanding of ethical AI and responsible use of AI, especially in security sensitive and -personal data- contexts. Familiarity with data governance, data quality, and information security principles, particularly where AI models consume identity data. Strong focus on security, governance, and continuous improvement Relevant professional certifications (or actively working towards), such as: Microsoft Identity or Security certifications Privileged Access Management certifications AI / data analytics certifications CISSP, CISM, or equivalent

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board