Role Overview Information Security is responsible for the stability, maturity, and continuous improvement of the firm's operational security and privacy controls. This includes leading the monitoring, detection, response, and management of cyber and data related risks while ensuring compliance with UK GDPR, industry standards (ISO27001), and client expectations. The role plays a key role in the operational management of security and privacy risk across the firm's technology environment and works with third party service providers to ensure effective threat detection, incident response, data protection controls, and operational workflows for GDPR compliance. It is a hands on technical role requiring strong analytical skills, attention to detail, and a proactive mindset. The ideal candidate will have practical experience with Microsoft security and compliance technologies, an interest in learning advanced detection and automation techniques, and a desire to contribute to a growing, high performing security operations capability. Key Responsibilities Monitor security event identification via the third party security operations service. Triage, analyse, and investigate incidents to validate potential threats, anomalies, or policy violations. Coordinate incident response activities including containment, evidence collection, documentation, and recovery support. Contribute to threat hunting activities using KQL queries and intelligence led techniques. Maintain accurate incident records, ensuring actions and outcomes are logged to a high standard. Facilitate security testing and awareness through threat simulations. Support the triage and processing of data subject rights (DSR) requests, including subject access requests (SARs). Conduct data discovery and collection across systems, ensuring completeness and accuracy. Support DPIA processes through data mapping, evidence gathering, and risk assessment input. Help maintain and tune Microsoft Defender, Sentinel, and Purview policies, analytics rules, alerts, and workflows. Support the development, testing, and maintenance of automated playbooks and response actions (e.g., Logic Apps). Verify compliance with expected practice in the operation of technology services, including security baseline and access right reviews. Support vulnerability management by tracking remediation, validating fixes, and assisting with reporting. Gather and analyse data to help identify trends, gaps, and areas for control improvement. Assist with periodic control reviews, audits, and compliance checks as required. Prepare operational reports, dashboards, and metrics for the Team Lead and wider stakeholders. Develop and maintain playbooks, runbooks, and procedural documentation. Contribute to continuous improvement activities, including identifying opportunities to streamline operations. Ensure all actions adhere to internal policies, regulatory requirements, and industry best practice. Essential Qualifications and Experience 3+ years' experience working in a security operations, IT security, privacy operations, or related technical role. Familiarity with Microsoft Defender XDR, Microsoft Sentinel (SIEM/SOAR), Privacy Management Solutions (e.g., Purview, OneTrust). Basic understanding of key cybersecurity and privacy concepts, such as threat detection and analysis, incident response lifecycle, vulnerability and exposure management, data privacy principles and data subject rights. Experience analysing logs, alerts, or data from security tools. Strong documentation, investigation, and analytical skills. Desirable Qualifications and Experience Hands on experience writing KQL queries, PowerShell, or CLI commands. Exposure to automation or playbooks (Logic Apps, Defender workflows). Knowledge of frameworks such as MITRE ATT&CK or NIST CSF. Relevant certifications such as SC 900, SC 200 (or working toward), AZ 900, AZ 500, CISSP, CIPP/E, CompTIA Security+, Foundation level data privacy certifications (e.g., BCS Certificate in Data Protection). Key Skills and Attributes Strong problem solving ability and attention to detail. Curious and proactive mindset with willingness to learn. Effective communicator able to document findings clearly and concisely. Highly organised and able to manage multiple tasks with competing priorities. Collaborative team player with a commitment to continuous improvement. Ability to work with sensitive data responsibly and confidentially.
27/07/2026
Full time
Role Overview Information Security is responsible for the stability, maturity, and continuous improvement of the firm's operational security and privacy controls. This includes leading the monitoring, detection, response, and management of cyber and data related risks while ensuring compliance with UK GDPR, industry standards (ISO27001), and client expectations. The role plays a key role in the operational management of security and privacy risk across the firm's technology environment and works with third party service providers to ensure effective threat detection, incident response, data protection controls, and operational workflows for GDPR compliance. It is a hands on technical role requiring strong analytical skills, attention to detail, and a proactive mindset. The ideal candidate will have practical experience with Microsoft security and compliance technologies, an interest in learning advanced detection and automation techniques, and a desire to contribute to a growing, high performing security operations capability. Key Responsibilities Monitor security event identification via the third party security operations service. Triage, analyse, and investigate incidents to validate potential threats, anomalies, or policy violations. Coordinate incident response activities including containment, evidence collection, documentation, and recovery support. Contribute to threat hunting activities using KQL queries and intelligence led techniques. Maintain accurate incident records, ensuring actions and outcomes are logged to a high standard. Facilitate security testing and awareness through threat simulations. Support the triage and processing of data subject rights (DSR) requests, including subject access requests (SARs). Conduct data discovery and collection across systems, ensuring completeness and accuracy. Support DPIA processes through data mapping, evidence gathering, and risk assessment input. Help maintain and tune Microsoft Defender, Sentinel, and Purview policies, analytics rules, alerts, and workflows. Support the development, testing, and maintenance of automated playbooks and response actions (e.g., Logic Apps). Verify compliance with expected practice in the operation of technology services, including security baseline and access right reviews. Support vulnerability management by tracking remediation, validating fixes, and assisting with reporting. Gather and analyse data to help identify trends, gaps, and areas for control improvement. Assist with periodic control reviews, audits, and compliance checks as required. Prepare operational reports, dashboards, and metrics for the Team Lead and wider stakeholders. Develop and maintain playbooks, runbooks, and procedural documentation. Contribute to continuous improvement activities, including identifying opportunities to streamline operations. Ensure all actions adhere to internal policies, regulatory requirements, and industry best practice. Essential Qualifications and Experience 3+ years' experience working in a security operations, IT security, privacy operations, or related technical role. Familiarity with Microsoft Defender XDR, Microsoft Sentinel (SIEM/SOAR), Privacy Management Solutions (e.g., Purview, OneTrust). Basic understanding of key cybersecurity and privacy concepts, such as threat detection and analysis, incident response lifecycle, vulnerability and exposure management, data privacy principles and data subject rights. Experience analysing logs, alerts, or data from security tools. Strong documentation, investigation, and analytical skills. Desirable Qualifications and Experience Hands on experience writing KQL queries, PowerShell, or CLI commands. Exposure to automation or playbooks (Logic Apps, Defender workflows). Knowledge of frameworks such as MITRE ATT&CK or NIST CSF. Relevant certifications such as SC 900, SC 200 (or working toward), AZ 900, AZ 500, CISSP, CIPP/E, CompTIA Security+, Foundation level data privacy certifications (e.g., BCS Certificate in Data Protection). Key Skills and Attributes Strong problem solving ability and attention to detail. Curious and proactive mindset with willingness to learn. Effective communicator able to document findings clearly and concisely. Highly organised and able to manage multiple tasks with competing priorities. Collaborative team player with a commitment to continuous improvement. Ability to work with sensitive data responsibly and confidentially.
Hiscox Underwriting Group Services Ltd (HUGS)
City, York
Job Type: Permanent The Role The Blue Team Leader works in our Cyber Fusion Centre, and plays a pivotal role in the protection of our business assets and interests from cyber threats. You will focus on the development of our proactive and defensive capabilities, orchestrating security operations and optimising the efforts of our Blue Team. You will support in the development and implementation of our overall cybersecurity strategy, and plan activities and initiatives to meet our business security objectives. You will need to be naturally inquisitive, have a comprehensive understanding of the latest cyber threats and how to counter them. You will also be a member of our Cyber Incident Response Team (CIRT) and will need to lead our initial response. You will work closely with our Red Team Leader and Cyber Delivery Leader to identify threats and vulnerabilities present in our network and systems, and turn these into a pipeline of continuous improvement for our cyber defences. You will also work closely with our Head of Cyber Fusion Centre to co ordinate daily activities in support of their primary objectives. You will also be responsible for working with project delivery teams from across our business, where you will provide expert technical security advice and guidance and support their onboarding activities to the Fusion Centre. You will need hands on experience working with a multitude of different security technologies, be able lead and coach your team of analysts and be able to work in a high paced operational environment. The role is based in either York (UK) or Lisbon (Portugal) and is a permanent position. Travel to other team locations will be required as necessary. Key Responsibilities Direct and guide the Blue Team in their daily operations, ensuring alignment with our business security objectives and latest threat intelligence. Oversee the continuous monitoring of our networks and systems for security breaches or anomalies. Design and maintain incident response plans to address and mitigate potential security breaches. Co ordinate Blue Team exercises to ensure analysts are confident in detecting and responding to cyber threats, and that we have the required data points needed to support detection of potential incidents. Allocate and manage resources effectively to ensure optimal team performance and address any skill, performance or resource gaps. Perform routine gap analysis of detection use cases and identify new data sources for onboarding to the SIEM platform to ensure observability of the latest TTPs. Leverage actionable threat intelligence to develop new detection use cases to support the ongoing continuous improvement of our SIEM capabilities. Ensure the operational resilience of our proactive and defensive cyber capabilities, including our technology, people and process used to support detection and response. Lead initial response to detection of security incidents, ensuring timely and effective resolution, escalation where necessary and perform any post incident analysis for lessons learned. Coach and mentor your team to support their professional development, fostering an environment of continuous learning and improvement. Develop and maintain our security operations policies, processes and playbooks. Maintain an up to date knowledge of the latest security tools and technologies, and how these could be used to mitigate our priority threats. Provide regular reports on security status, incidents and KRIs to senior management and stakeholders. Candidate Profile 6+ years experience in a security operations team, preferably 2 years in a management role. Demonstrable experience leading response to security incidents and breaches. Excellent understanding of defensive security strategies and cyber incident response processes. Excellent working knowledge of SIEM based tools and technologies. Excellent working knowledge of EDR and XDR technologies. Excellent working knowledge of firewalls and other network security appliances. Excellent problem solving and analytical skills, with the ability to make sound decisions under pressure. Excellent leadership and management skills, with strong communications and interpersonal skills. Good understanding of forensics technologies and processes. BSc or MSc in Cybersecurity is highly desirable. Advanced cyber certifications such as CISSP, CISM, GCIH and GPEN are desirable. Industry recognised security vendor certifications are desirable. Diversity & Benefits We hire the best people for the job and we're committed to diversity and creating a truly inclusive culture, which we believe drives success. Working life doesn't always have to be in the office, so we have introduced hybrid working to encourage a healthy work life balance. This hybrid working model is set by the team rather than the business to enable you to manage your own personal work life balance. Our benefits package includes a bonus, contributory pension, 25 days annual leave plus 2 Hiscox days and a 4 week paid sabbatical with every 5 years' worth of service, private medical for all the family and much more.
27/07/2026
Full time
Job Type: Permanent The Role The Blue Team Leader works in our Cyber Fusion Centre, and plays a pivotal role in the protection of our business assets and interests from cyber threats. You will focus on the development of our proactive and defensive capabilities, orchestrating security operations and optimising the efforts of our Blue Team. You will support in the development and implementation of our overall cybersecurity strategy, and plan activities and initiatives to meet our business security objectives. You will need to be naturally inquisitive, have a comprehensive understanding of the latest cyber threats and how to counter them. You will also be a member of our Cyber Incident Response Team (CIRT) and will need to lead our initial response. You will work closely with our Red Team Leader and Cyber Delivery Leader to identify threats and vulnerabilities present in our network and systems, and turn these into a pipeline of continuous improvement for our cyber defences. You will also work closely with our Head of Cyber Fusion Centre to co ordinate daily activities in support of their primary objectives. You will also be responsible for working with project delivery teams from across our business, where you will provide expert technical security advice and guidance and support their onboarding activities to the Fusion Centre. You will need hands on experience working with a multitude of different security technologies, be able lead and coach your team of analysts and be able to work in a high paced operational environment. The role is based in either York (UK) or Lisbon (Portugal) and is a permanent position. Travel to other team locations will be required as necessary. Key Responsibilities Direct and guide the Blue Team in their daily operations, ensuring alignment with our business security objectives and latest threat intelligence. Oversee the continuous monitoring of our networks and systems for security breaches or anomalies. Design and maintain incident response plans to address and mitigate potential security breaches. Co ordinate Blue Team exercises to ensure analysts are confident in detecting and responding to cyber threats, and that we have the required data points needed to support detection of potential incidents. Allocate and manage resources effectively to ensure optimal team performance and address any skill, performance or resource gaps. Perform routine gap analysis of detection use cases and identify new data sources for onboarding to the SIEM platform to ensure observability of the latest TTPs. Leverage actionable threat intelligence to develop new detection use cases to support the ongoing continuous improvement of our SIEM capabilities. Ensure the operational resilience of our proactive and defensive cyber capabilities, including our technology, people and process used to support detection and response. Lead initial response to detection of security incidents, ensuring timely and effective resolution, escalation where necessary and perform any post incident analysis for lessons learned. Coach and mentor your team to support their professional development, fostering an environment of continuous learning and improvement. Develop and maintain our security operations policies, processes and playbooks. Maintain an up to date knowledge of the latest security tools and technologies, and how these could be used to mitigate our priority threats. Provide regular reports on security status, incidents and KRIs to senior management and stakeholders. Candidate Profile 6+ years experience in a security operations team, preferably 2 years in a management role. Demonstrable experience leading response to security incidents and breaches. Excellent understanding of defensive security strategies and cyber incident response processes. Excellent working knowledge of SIEM based tools and technologies. Excellent working knowledge of EDR and XDR technologies. Excellent working knowledge of firewalls and other network security appliances. Excellent problem solving and analytical skills, with the ability to make sound decisions under pressure. Excellent leadership and management skills, with strong communications and interpersonal skills. Good understanding of forensics technologies and processes. BSc or MSc in Cybersecurity is highly desirable. Advanced cyber certifications such as CISSP, CISM, GCIH and GPEN are desirable. Industry recognised security vendor certifications are desirable. Diversity & Benefits We hire the best people for the job and we're committed to diversity and creating a truly inclusive culture, which we believe drives success. Working life doesn't always have to be in the office, so we have introduced hybrid working to encourage a healthy work life balance. This hybrid working model is set by the team rather than the business to enable you to manage your own personal work life balance. Our benefits package includes a bonus, contributory pension, 25 days annual leave plus 2 Hiscox days and a 4 week paid sabbatical with every 5 years' worth of service, private medical for all the family and much more.
Business Unit: Cubic Defense Company Cubic is a global organization that delivers technology solutions in transportation and defense. It provides command, control, communications, computers, cyber, intelligence, surveillance, and reconnaissance (C5ISR) solutions, as well as live, virtual, constructive, and game-based training to serve U.S. and allied forces. Summary The Deputy Programme Manager (DPM) for the ILT-A Programme supports senior programme leadership during a period of rapid growth and change. The candidate will work with programme and project managers, the Regional General Manager, and the ILT-A Programme Manager to ensure successful delivery of the existing business portfolio across Cubic UK (CDUK). The role is primarily office based with occasional field based delivery and operational oversight in the UK and overseas. Key Responsibilities Assist the Programme Manager in planning, scheduling, execution, and delivery of design and build projects. Coordinate multiple parallel projects, ensuring alignment with programme objectives, budget constraints, and timelines. Engage cross functional teams, including engineering, supply chain, procurement, and manufacturing, to develop strategies. Support stakeholder communication and engagement, providing regular updates on project progress, risks, and opportunities. Manage project resources effectively, including financial budgets and personnel allocation. Develop and track key performance indicators (KPIs) to measure project success and continuous improvement. Support the implementation, monitoring, and continuous improvement of security controls across the CDUK IT infrastructure and business systems. Manage risk registers and assist in the identification of risks, including security risks, and implement mitigation plans. Implement and enhance the security strategy, championing a culture of cyber security awareness and best practice across CDUK. Contribute to the upkeep of security certifications in alignment with frameworks such as Cyber Essentials and the Cyber Assessment Framework (CAF). Work with third party providers on security audits and reviews, and support continual improvement of cyber security policies. Maintain contemporary knowledge of current threats and cyber trends. Essential Requirements Proven experience and understanding of programme or project management within an engineering, manufacturing, or defence environment. Ability to manage multiple design and build projects simultaneously. Excellent stakeholder management skills, with experience engaging internal and external partners. Strong problem solving and risk management capabilities. Experience managing risk registers. Proficiency in project management methodologies and tools, including scheduling (e.g., Agile, PRINCE2, PMP, MS Project, P6). Understanding of cyber and information security best practice frameworks, standards, and certifications such as NIST, ISO27001, SbD, and ideally PSN, Cyber Essentials, and CAF. Experience providing security advice across a variety of projects. Strong Governance Risk and Compliance (GRC) knowledge, understanding, and skillset. Experience with budgeting, financial reporting, and resource planning. Desirable Requirements Typically 8+ years of relevant experience. Experience as an information security analyst (IT audit, governance, risk and compliance) within the public or private sector. Degree in Engineering, Project Management, or a related discipline. Experience within defence, aerospace, or highly regulated industries. Familiarity with regulatory and compliance requirements. Membership of a relevant professional body (e.g., APM, PMI, INCOSE). Background in IT (infrastructure, networks, software or cyber security). Personal Qualities Self motivated, proactive, and able to work under pressure to meet challenging deadlines with minimal supervision. Strong relationship building and influencing skills. Excellent communication skills (written and verbal), proactive and solution focused mindset. Ability to lead teams and quickly acquire new skills. Willingness to travel. Worker Type Employee You are committed to hiring and retaining a diverse workforce and are proud to be an Equal Opportunity/Affirmative Action Employer. We are committed to ensuring a workplace free of discrimination based on race, color, religion, age, disability, genetic information, sex, sexual orientation, gender identity, national origin, military or veteran status, or any other basis protected by applicable law. For more information on Equal Employment please visit:
27/07/2026
Full time
Business Unit: Cubic Defense Company Cubic is a global organization that delivers technology solutions in transportation and defense. It provides command, control, communications, computers, cyber, intelligence, surveillance, and reconnaissance (C5ISR) solutions, as well as live, virtual, constructive, and game-based training to serve U.S. and allied forces. Summary The Deputy Programme Manager (DPM) for the ILT-A Programme supports senior programme leadership during a period of rapid growth and change. The candidate will work with programme and project managers, the Regional General Manager, and the ILT-A Programme Manager to ensure successful delivery of the existing business portfolio across Cubic UK (CDUK). The role is primarily office based with occasional field based delivery and operational oversight in the UK and overseas. Key Responsibilities Assist the Programme Manager in planning, scheduling, execution, and delivery of design and build projects. Coordinate multiple parallel projects, ensuring alignment with programme objectives, budget constraints, and timelines. Engage cross functional teams, including engineering, supply chain, procurement, and manufacturing, to develop strategies. Support stakeholder communication and engagement, providing regular updates on project progress, risks, and opportunities. Manage project resources effectively, including financial budgets and personnel allocation. Develop and track key performance indicators (KPIs) to measure project success and continuous improvement. Support the implementation, monitoring, and continuous improvement of security controls across the CDUK IT infrastructure and business systems. Manage risk registers and assist in the identification of risks, including security risks, and implement mitigation plans. Implement and enhance the security strategy, championing a culture of cyber security awareness and best practice across CDUK. Contribute to the upkeep of security certifications in alignment with frameworks such as Cyber Essentials and the Cyber Assessment Framework (CAF). Work with third party providers on security audits and reviews, and support continual improvement of cyber security policies. Maintain contemporary knowledge of current threats and cyber trends. Essential Requirements Proven experience and understanding of programme or project management within an engineering, manufacturing, or defence environment. Ability to manage multiple design and build projects simultaneously. Excellent stakeholder management skills, with experience engaging internal and external partners. Strong problem solving and risk management capabilities. Experience managing risk registers. Proficiency in project management methodologies and tools, including scheduling (e.g., Agile, PRINCE2, PMP, MS Project, P6). Understanding of cyber and information security best practice frameworks, standards, and certifications such as NIST, ISO27001, SbD, and ideally PSN, Cyber Essentials, and CAF. Experience providing security advice across a variety of projects. Strong Governance Risk and Compliance (GRC) knowledge, understanding, and skillset. Experience with budgeting, financial reporting, and resource planning. Desirable Requirements Typically 8+ years of relevant experience. Experience as an information security analyst (IT audit, governance, risk and compliance) within the public or private sector. Degree in Engineering, Project Management, or a related discipline. Experience within defence, aerospace, or highly regulated industries. Familiarity with regulatory and compliance requirements. Membership of a relevant professional body (e.g., APM, PMI, INCOSE). Background in IT (infrastructure, networks, software or cyber security). Personal Qualities Self motivated, proactive, and able to work under pressure to meet challenging deadlines with minimal supervision. Strong relationship building and influencing skills. Excellent communication skills (written and verbal), proactive and solution focused mindset. Ability to lead teams and quickly acquire new skills. Willingness to travel. Worker Type Employee You are committed to hiring and retaining a diverse workforce and are proud to be an Equal Opportunity/Affirmative Action Employer. We are committed to ensuring a workplace free of discrimination based on race, color, religion, age, disability, genetic information, sex, sexual orientation, gender identity, national origin, military or veteran status, or any other basis protected by applicable law. For more information on Equal Employment please visit:
Position Overview We are seeking an experienced Cyber Security Analyst to join our cyber security team. The ideal candidate will have a minimum of 5 years cyber security experience and 3+ years in cloud security and/or application security. The candidate will be able to demonstrate a proven track record of protecting enterprise environments against evolving cyber threats. This role requires a technically proficient lead analyst who can lead security initiatives and ensure our cloud and application infrastructure maintains the highest security standards, whilst maintaining business partnerships across the group. Key Responsibilities Monitor and analyze security events across cloud and on premises environments using SIEM and security analytics tools Conduct thorough investigations of security incidents and provide detailed incident reports Develop and maintain incident response playbooks and procedures Experience with threat intelligence platforms and threat hunting Experience with security orchestration, automation and response (SOAR) platforms Understanding of data protection and encryption technologies Experience in regulated industries (financial services, healthcare, energy) Background in offensive security or penetration testing Design, implement, and maintain security controls across cloud platforms (AWS, Azure, GCP) Conduct cloud security assessments and architecture reviews Ensure compliance with cloud security best practices and frameworks (CIS Benchmarks, CSA CCM, NIST) Manage cloud native security tools including CSPM, CWPP, and cloud WAF solutions Implement and maintain identity and access management (IAM) policies and controls Lead cyber security programs and coordinate remediation efforts Collaborate with DevOps teams to integrate security into CI/CD pipelines (DevSecOps) Stay current with emerging threats, vulnerabilities, and security technologies Contribute to security awareness training and documentation Facilitate Supplier Management and security input into bids Support compliance initiatives (SOC2, ISO27001, PCI DSS, GDPR, etc.) Develop and enforce security policies, standards, and procedures Conduct security audits and risk assessments Maintain security documentation and metrics reporting Required Qualifications Minimum of 5 years cyber security experience 3+ years of hands on experience with cloud security (AWS, Azure, or GCP) Proven experience leading security incidents and coordinating response efforts Experience with security frameworks such as NIST CSF, MITRE ATT&CK, or Zero Trust architecture Technical Skills Strong expertise in cloud security services and tools (AWS & Azure) Experience working with SIEM platforms (Splunk, Sentinel) Understanding of network security, firewalls, IDS/IPS, and VPN technologies Familiarity with security testing tools (vulnerability scanners, SAST/DAST, penetration testing tools) Experience with endpoint detection and response (EDR) solutions Soft Skills Strong analytical and problem solving abilities Excellent written and verbal communication skills Ability to explain complex security concepts to technical and non technical audiences Leadership capabilities and experience mentoring team members Strong attention to detail and ability to work under pressure Collaborative mindset with cross functional teams Business partnering experience Certifications (one or more preferred) CISSP (Certified Information Systems Security Professional) CCSP (Certified Cloud Security Professional) AWS Certified Security - Specialty Microsoft Certified: Azure Security Engineer Associate Education: Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) Working Conditions Some flexibility for remote work - 2 days minimum in office (Edinburgh preferred) Equal Opportunities We are an equal opportunities employer. This means we are committed to recruiting the best people regardless of their race, colour, religion, age, sex, national origin, disability or protected veteran status. We can support you with your application or through the hiring process if you have a physical or mental disability. You can find out more about your rights under the law at .
27/07/2026
Full time
Position Overview We are seeking an experienced Cyber Security Analyst to join our cyber security team. The ideal candidate will have a minimum of 5 years cyber security experience and 3+ years in cloud security and/or application security. The candidate will be able to demonstrate a proven track record of protecting enterprise environments against evolving cyber threats. This role requires a technically proficient lead analyst who can lead security initiatives and ensure our cloud and application infrastructure maintains the highest security standards, whilst maintaining business partnerships across the group. Key Responsibilities Monitor and analyze security events across cloud and on premises environments using SIEM and security analytics tools Conduct thorough investigations of security incidents and provide detailed incident reports Develop and maintain incident response playbooks and procedures Experience with threat intelligence platforms and threat hunting Experience with security orchestration, automation and response (SOAR) platforms Understanding of data protection and encryption technologies Experience in regulated industries (financial services, healthcare, energy) Background in offensive security or penetration testing Design, implement, and maintain security controls across cloud platforms (AWS, Azure, GCP) Conduct cloud security assessments and architecture reviews Ensure compliance with cloud security best practices and frameworks (CIS Benchmarks, CSA CCM, NIST) Manage cloud native security tools including CSPM, CWPP, and cloud WAF solutions Implement and maintain identity and access management (IAM) policies and controls Lead cyber security programs and coordinate remediation efforts Collaborate with DevOps teams to integrate security into CI/CD pipelines (DevSecOps) Stay current with emerging threats, vulnerabilities, and security technologies Contribute to security awareness training and documentation Facilitate Supplier Management and security input into bids Support compliance initiatives (SOC2, ISO27001, PCI DSS, GDPR, etc.) Develop and enforce security policies, standards, and procedures Conduct security audits and risk assessments Maintain security documentation and metrics reporting Required Qualifications Minimum of 5 years cyber security experience 3+ years of hands on experience with cloud security (AWS, Azure, or GCP) Proven experience leading security incidents and coordinating response efforts Experience with security frameworks such as NIST CSF, MITRE ATT&CK, or Zero Trust architecture Technical Skills Strong expertise in cloud security services and tools (AWS & Azure) Experience working with SIEM platforms (Splunk, Sentinel) Understanding of network security, firewalls, IDS/IPS, and VPN technologies Familiarity with security testing tools (vulnerability scanners, SAST/DAST, penetration testing tools) Experience with endpoint detection and response (EDR) solutions Soft Skills Strong analytical and problem solving abilities Excellent written and verbal communication skills Ability to explain complex security concepts to technical and non technical audiences Leadership capabilities and experience mentoring team members Strong attention to detail and ability to work under pressure Collaborative mindset with cross functional teams Business partnering experience Certifications (one or more preferred) CISSP (Certified Information Systems Security Professional) CCSP (Certified Cloud Security Professional) AWS Certified Security - Specialty Microsoft Certified: Azure Security Engineer Associate Education: Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) Working Conditions Some flexibility for remote work - 2 days minimum in office (Edinburgh preferred) Equal Opportunities We are an equal opportunities employer. This means we are committed to recruiting the best people regardless of their race, colour, religion, age, sex, national origin, disability or protected veteran status. We can support you with your application or through the hiring process if you have a physical or mental disability. You can find out more about your rights under the law at .
We're looking for a Senior Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high impact work that shapes how we detect and respond to threats at scale. You'll collaborate closely with our inhouse Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of it's kind at this scale, then this is the role for you. At Our Future Health, our mission is to transform the prevention,detectionand treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you. What you'll be doing Developing new threat-led detections in collaboration with our threat teambased on both threat intelligenceand the results of threat hunts. Creating novel analytic methods and techniques for incident detection. Working with our MSP provided SOC tomaintainour detectioncatalogueand tune existing rules. Developing and tuning Data Loss Prevention, Insider RiskManagementand other types of security rules withinMicrosoft Purviewand other key security monitoring tools. Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided,detections and other types of engineering work are delivered to theappropriate standardand that the maturity (inc. efficiency) of our security monitoring is continually improving. Supporting the development ofautomated custom reports on security operational performance and broader security topics (using Sentinel workbooks). Collaborating with wider tech and security teams on theappropriatesecuritymonitoringfor our various systems, including cloud platforms, SaaS applications and inhouse developed systems. Documenting securityprocesses and security tool low-level design/configuration. Contributing to the development of security service delivery and operation documentation. Supporting the security engineers, threatanalystsand wider security team with their various responsibilities, including achieving andmaintainingISO 27001 certification andanything that involves KQL. What you won't be doing Working in a siloed environment with no freedom to make decisions. Working in a place where you can't see the impact your expertise makes. To succeed in this role you will be able to demonstrate some of the following skills and experience: Highly proficient in writing KQL and ideallysome level ofproficiencyinPythonand Terraform. Significant hands on experience with Microsoft Sentinel. Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365. Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities. Experience withMicrosoft Purview tooling, in particular MPIP and Purview Data Loss Prevention. Experience with cloud-native logging(in particular Azureand Kubernetes). Experience of an 'everything-as-code',or at least a 'detection-as-code'approach, including CI/CD pipelines. Exposure to working with/inside an MSP SOC. Exposure to Agile working. Knowledge of attacker Tactics, Techniques and Procedures (TTPs). Knowledge of statistics, datascienceand AI/ML,in particular whenapplied to cyber security. Knowledge ofISO 27001. Desire to be part of a small fast paced team. Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK. Salary from £65,000 per annum. Generous Pension Scheme - We invest in your future with employer contributions of up to 12%. 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you. Enhanced Parental Leave - Supporting you during life's biggest moments. Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice. Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board! Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family. A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements. Join us - let'sprevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at
27/07/2026
Full time
We're looking for a Senior Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high impact work that shapes how we detect and respond to threats at scale. You'll collaborate closely with our inhouse Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of it's kind at this scale, then this is the role for you. At Our Future Health, our mission is to transform the prevention,detectionand treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you. What you'll be doing Developing new threat-led detections in collaboration with our threat teambased on both threat intelligenceand the results of threat hunts. Creating novel analytic methods and techniques for incident detection. Working with our MSP provided SOC tomaintainour detectioncatalogueand tune existing rules. Developing and tuning Data Loss Prevention, Insider RiskManagementand other types of security rules withinMicrosoft Purviewand other key security monitoring tools. Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided,detections and other types of engineering work are delivered to theappropriate standardand that the maturity (inc. efficiency) of our security monitoring is continually improving. Supporting the development ofautomated custom reports on security operational performance and broader security topics (using Sentinel workbooks). Collaborating with wider tech and security teams on theappropriatesecuritymonitoringfor our various systems, including cloud platforms, SaaS applications and inhouse developed systems. Documenting securityprocesses and security tool low-level design/configuration. Contributing to the development of security service delivery and operation documentation. Supporting the security engineers, threatanalystsand wider security team with their various responsibilities, including achieving andmaintainingISO 27001 certification andanything that involves KQL. What you won't be doing Working in a siloed environment with no freedom to make decisions. Working in a place where you can't see the impact your expertise makes. To succeed in this role you will be able to demonstrate some of the following skills and experience: Highly proficient in writing KQL and ideallysome level ofproficiencyinPythonand Terraform. Significant hands on experience with Microsoft Sentinel. Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365. Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities. Experience withMicrosoft Purview tooling, in particular MPIP and Purview Data Loss Prevention. Experience with cloud-native logging(in particular Azureand Kubernetes). Experience of an 'everything-as-code',or at least a 'detection-as-code'approach, including CI/CD pipelines. Exposure to working with/inside an MSP SOC. Exposure to Agile working. Knowledge of attacker Tactics, Techniques and Procedures (TTPs). Knowledge of statistics, datascienceand AI/ML,in particular whenapplied to cyber security. Knowledge ofISO 27001. Desire to be part of a small fast paced team. Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK. Salary from £65,000 per annum. Generous Pension Scheme - We invest in your future with employer contributions of up to 12%. 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you. Enhanced Parental Leave - Supporting you during life's biggest moments. Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice. Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board! Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family. A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements. Join us - let'sprevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at
We're looking for a Senior Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high impact work that shapes how we detect and respond to threats at scale. You'll collaborate closely with our inhouse Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of it's kind at this scale, then this is the role for you. At Our Future Health, our mission is to transform the prevention,detectionand treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you. What you'll be doing Developing new threat-led detections in collaboration with our threat teambased on both threat intelligenceand the results of threat hunts. Creating novel analytic methods and techniques for incident detection. Working with our MSP provided SOC tomaintainour detectioncatalogueand tune existing rules. Developing and tuning Data Loss Prevention, Insider RiskManagementand other types of security rules withinMicrosoft Purviewand other key security monitoring tools. Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided,detections and other types of engineering work are delivered to theappropriate standardand that the maturity (inc. efficiency) of our security monitoring is continually improving. Supporting the development ofautomated custom reports on security operational performance and broader security topics (using Sentinel workbooks). Collaborating with wider tech and security teams on theappropriatesecuritymonitoringfor our various systems, including cloud platforms, SaaS applications and inhouse developed systems. Documenting securityprocesses and security tool low-level design/configuration. Contributing to the development of security service delivery and operation documentation. Supporting the security engineers, threatanalystsand wider security team with their various responsibilities, including achieving andmaintainingISO 27001 certification andanything that involves KQL. What you won't be doing Working in a siloed environment with no freedom to make decisions. Working in a place where you can't see the impact your expertise makes. To succeed in this role you will be able to demonstrate some of the following skills and experience: Highly proficient in writing KQL and ideallysome level ofproficiencyinPythonand Terraform. Significant hands on experience with Microsoft Sentinel. Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365. Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities. Experience withMicrosoft Purview tooling, in particular MPIP and Purview Data Loss Prevention. Experience with cloud-native logging(in particular Azureand Kubernetes). Experience of an 'everything-as-code',or at least a 'detection-as-code'approach, including CI/CD pipelines. Exposure to working with/inside an MSP SOC. Exposure to Agile working. Knowledge of attacker Tactics, Techniques and Procedures (TTPs). Knowledge of statistics, datascienceand AI/ML,in particular whenapplied to cyber security. Knowledge ofISO 27001. Desire to be part of a small fast paced team. Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK. Salary from £65,000 per annum. Generous Pension Scheme - We invest in your future with employer contributions of up to 12%. 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you. Enhanced Parental Leave - Supporting you during life's biggest moments. Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice. Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board! Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family. A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements. Join us - let'sprevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at
27/07/2026
Full time
We're looking for a Senior Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high impact work that shapes how we detect and respond to threats at scale. You'll collaborate closely with our inhouse Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of it's kind at this scale, then this is the role for you. At Our Future Health, our mission is to transform the prevention,detectionand treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you. What you'll be doing Developing new threat-led detections in collaboration with our threat teambased on both threat intelligenceand the results of threat hunts. Creating novel analytic methods and techniques for incident detection. Working with our MSP provided SOC tomaintainour detectioncatalogueand tune existing rules. Developing and tuning Data Loss Prevention, Insider RiskManagementand other types of security rules withinMicrosoft Purviewand other key security monitoring tools. Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided,detections and other types of engineering work are delivered to theappropriate standardand that the maturity (inc. efficiency) of our security monitoring is continually improving. Supporting the development ofautomated custom reports on security operational performance and broader security topics (using Sentinel workbooks). Collaborating with wider tech and security teams on theappropriatesecuritymonitoringfor our various systems, including cloud platforms, SaaS applications and inhouse developed systems. Documenting securityprocesses and security tool low-level design/configuration. Contributing to the development of security service delivery and operation documentation. Supporting the security engineers, threatanalystsand wider security team with their various responsibilities, including achieving andmaintainingISO 27001 certification andanything that involves KQL. What you won't be doing Working in a siloed environment with no freedom to make decisions. Working in a place where you can't see the impact your expertise makes. To succeed in this role you will be able to demonstrate some of the following skills and experience: Highly proficient in writing KQL and ideallysome level ofproficiencyinPythonand Terraform. Significant hands on experience with Microsoft Sentinel. Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365. Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities. Experience withMicrosoft Purview tooling, in particular MPIP and Purview Data Loss Prevention. Experience with cloud-native logging(in particular Azureand Kubernetes). Experience of an 'everything-as-code',or at least a 'detection-as-code'approach, including CI/CD pipelines. Exposure to working with/inside an MSP SOC. Exposure to Agile working. Knowledge of attacker Tactics, Techniques and Procedures (TTPs). Knowledge of statistics, datascienceand AI/ML,in particular whenapplied to cyber security. Knowledge ofISO 27001. Desire to be part of a small fast paced team. Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK. Salary from £65,000 per annum. Generous Pension Scheme - We invest in your future with employer contributions of up to 12%. 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you. Enhanced Parental Leave - Supporting you during life's biggest moments. Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice. Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board! Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family. A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements. Join us - let'sprevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at
Description: Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril's family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years. ABOUT THE TEAM Anduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defence technologies. As a SecOps analyst on the detection and response team, you'll be responsible for monitoring and responding to adversarial activity while helping incorporate key detection feedback loops with the detection engineering team. When not responding to threats, you'll be asking questions of our data sets, conducting threat hunting and data normalisation operations across the organization to understand user behavior and identify anomalies. WHAT YOU'LL DO Triage and respond to alerts / incidents covering multiple disciplines including, but not limited to, phishing, endpoints, cloud infrastructure and services, and SaaS applications Build and optimise tailored detection signatures, response playbooks, and response automation using detection-as-code principles As the frontline of DNR, you will lead the feedback loop for detections, ensuring alerts are fine tuned to reduce false positives Participate in threat modeling scenarios with cross-functional partners to understand weaknesses across Cloud, Mobile, Endpoints, and other environments incorporating findings into security controls and/or detection signatures Organise and conduct threat hunting and data baselines to identify anomalous patterns in data Participate in an on-call rotation responding to security events and conducting incident response investigations while effectively communicating findings to key stakeholders Proactively collaborate with a wide range of stakeholders REQUIRED QUALIFICATIONS Experience in security monitoring, log analysis, and detection engineering within large data sets across endpoint, network, and a wide variety of application log sources Experience in Python development, specifically contributing to a shared codebase used for automating SOC operations Must have experience with one or more SIEM languages (SPL, KQL, SQL) Broad range of practical security knowledge across the spectrum of endpoint, network, identity, application, and cloud infrastructure Knowledge of attacker tactics, techniques, and procedures (TTPs) across Windows, Linux, MacOS, AWS/Azure, etc. Strong communication skills and experience collaborating with internal and external stakeholders Eligible to obtain and maintain an Australian NV2 clearance PREFERRED QUALIFICATIONS Experience conducting incident response in the Cloud (AWS, Azure, GCP) Digital Forensics and/or reverse engineering experience is a plus! Benefits At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you're supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits. Data Privacy To view Anduril's candidate data privacy policy, you can visit By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.
27/07/2026
Full time
Description: Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril's family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years. ABOUT THE TEAM Anduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defence technologies. As a SecOps analyst on the detection and response team, you'll be responsible for monitoring and responding to adversarial activity while helping incorporate key detection feedback loops with the detection engineering team. When not responding to threats, you'll be asking questions of our data sets, conducting threat hunting and data normalisation operations across the organization to understand user behavior and identify anomalies. WHAT YOU'LL DO Triage and respond to alerts / incidents covering multiple disciplines including, but not limited to, phishing, endpoints, cloud infrastructure and services, and SaaS applications Build and optimise tailored detection signatures, response playbooks, and response automation using detection-as-code principles As the frontline of DNR, you will lead the feedback loop for detections, ensuring alerts are fine tuned to reduce false positives Participate in threat modeling scenarios with cross-functional partners to understand weaknesses across Cloud, Mobile, Endpoints, and other environments incorporating findings into security controls and/or detection signatures Organise and conduct threat hunting and data baselines to identify anomalous patterns in data Participate in an on-call rotation responding to security events and conducting incident response investigations while effectively communicating findings to key stakeholders Proactively collaborate with a wide range of stakeholders REQUIRED QUALIFICATIONS Experience in security monitoring, log analysis, and detection engineering within large data sets across endpoint, network, and a wide variety of application log sources Experience in Python development, specifically contributing to a shared codebase used for automating SOC operations Must have experience with one or more SIEM languages (SPL, KQL, SQL) Broad range of practical security knowledge across the spectrum of endpoint, network, identity, application, and cloud infrastructure Knowledge of attacker tactics, techniques, and procedures (TTPs) across Windows, Linux, MacOS, AWS/Azure, etc. Strong communication skills and experience collaborating with internal and external stakeholders Eligible to obtain and maintain an Australian NV2 clearance PREFERRED QUALIFICATIONS Experience conducting incident response in the Cloud (AWS, Azure, GCP) Digital Forensics and/or reverse engineering experience is a plus! Benefits At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you're supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits. Data Privacy To view Anduril's candidate data privacy policy, you can visit By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.
Job Description To support the Head of Security Operations in delivering effective day-to-day security operations, ensuring AJ Bell maintains the appropriate capability to detect, investigate and respond to security events and incidents. The Security Operations Technical Lead is responsible for ensuring that security operations activities are executed efficiently, consistently and in line with defined SLAs and operational standards, through hands on technical leadership across SOC, Incident Response, Threat Intelligence, Insider Risk and Vulnerability Management. This role acts as a senior technical escalation point, supporting complex investigations and driving improvements in detection, response, automation and operational processes. The role holder is expected to lead through expertise, supporting analysts and ensuring Security Operations operates with discipline, quality and continuous improvement. The key responsibilities of the role are: Act as the primary technical escalation point for security events and incidents identified by the Security Operations team. Support the Head of Security Operations in ensuring AJ Bell has the appropriate capability to detect and respond to security events and incidents. Oversee the day to day execution of security operations, ensuring alerts and incidents are handled in line with defined processes and SLAs. Ensure security operations SLAs and OLAs are met, including alert triage, escalation and incident response timelines, highlighting and addressing risks where required. Ensure adherence to our KRI and KPI's and any variation in these are raised to the Head of Security Operations. Provide hands on support in the investigation and response to security incidents, including endpoint, identity, network, cloud and insider related threats. Ensure consistent execution and continuous improvement of incident response playbooks and operational runbooks, validating them through real incidents and simulations. Support the optimisation and tuning of security monitoring and detection capabilities, including SIEM and endpoint tooling, to improve signal quality and reduce false positives. Support the execution of the end to end vulnerability management process, including validation of findings and tracking remediation activities. Work closely with MSSP and security vendors to ensure effective delivery of security operations services. Challenge and validate vendor outputs, driving operational efficiency, quality improvements and better use of tooling capabilities. Actively design and implement automation and orchestration to reduce manual effort, repetitive or high volume tasks, improve response times and increase consistency across security operations processes. Work with the Security Engineering team to ensure tooling, logging and detection gaps are identified and addressed. Support the effective operation of 24x7 security monitoring, including coordination with third party providers. Contribute to the development and delivery of operational MI and reporting, ensuring accuracy and insight into security trends and performance. Maintain visibility of security incidents, trends and operational risks, escalating issues where required. Technical Skills: Strong hands on experience of Security Operations tools and capabilities, including SIEM and SOAR platforms (e.g. Sentinel, ServiceNow, Splunk SOAR, Cortex), Endpoint Detection & Response (EDR/XDR), Strong hands on experience of Threat Intelligence platforms (e.g. Recorded Future, Doppel, ZeroFox, Google Threat Intelligence), Vulnerability management solutions (e.g. Tenable, Rapid7), and Insider Risk and DLP tools (e.g. Purview, Netskope). Strong hands on experience with Network security solutions like Next Gen Firewalls, Network Anomaly, WAF & DDoS solutions. Experience of leading and responding to Cyber Incident Response aligned to NIST Knowledge of threat detection techniques and use case development Experience of applying threat intelligence in an operational context Strong experience with vulnerability management tools and processes Strong awareness of cloud services and supporting security controls and monitoring capabilities Working knowledge of Microsoft security stack (Defender, Sentinel, Purview), Active Directory and Azure AD, Windows and Linux environments. Experience with data loss prevention and insider risk tooling advantageous Hands on experience with automation and scripting (e.g. PowerShell, Python) highly desirable Competence Experience working within recognised Information Security frameworks and best practices such as ISO27001, NIST, MITRE ATT&CK Knowledge of relevant regulatory requirements (e.g. GDPR, FCA/PRA) Experience in an Information Security role gained in a financial services environment preferred Experience working in a Security Operations role for a minimum 7 years and operating within a Lead / Senior Analyst role for at least 3 years. Knowledge & Skills Strong analytical and investigative capability Ability to work under pressure and manage multiple concurrent incidents and priorities Strong ownership of tasks, attention to detail and follow through to conclusion Ability to provide technical leadership without formal line management responsibility Ability to challenge approach, tooling and processes to improve operational effectiveness Structured, self starting and able to work under own initiative Effective communication skills, both written and verbal Ability to plan, organise and deliver tasks with minimal supervision Collaborative approach to working with analysts, engineering teams and external partners Strong focus on quality, consistency and continuous improvement About AJ Bell At AJ Bell, we believe investing should feel good. Whether you're looking for an ISA, pension or dealing account, whether you want to invest with the help of a financial adviser or do it yourself, we have easy to use solutions to suit people from all walks of life. We're one of the UK's fastest growing investment platform businesses, trusted by everyone from professional financial advisers to first time investors. Today, over 723,000 customers trust us to manage more than £108.7 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures. We're proud to be recognised as one of the UK's Best 100 Companies to Work For for six consecutive years, and a Great Place to Work in 2025 and 2026, a reflection of our supportive and collaborative culture. What we offer Competitive starting salary 26days holiday, increasing with service + buy/sell scheme + bank holidays 7% Pension with matched contributions Discretionary bonus scheme Share schemes (including free shares and BAYE) Health Cash Plan and discounted private healthcare Free gym Enhanced family leave (subject to qualifying criteria) Travel and bike loan schemes Employee Assistance Programme Life at AJ Bell Regular social events including summer and Christmas parties Learning and development opportunities tailored to you Casual dress code Friendly, supportive team environment Our ways of working At AJ Bell, our people are the heart of our culture. We believe in building strong connections by working together. That's why we offer a hybrid working model, where you'll spend a minimum of 50% of working time per month in the office. For new team members, an initial period will be spent full time in the office to help you immerse yourself in our business and build valuable relationships with your colleagues. Inclusion & diversity We're committed to creating an inclusive environment where everyone feels respected, supported and able to be themselves at work. We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential. Agency information This vacancy is being managed exclusively by our in house Recruitment team. We are not partnering with recruitment agencies on this opportunity and will only accept applications submitted directly by candidates
27/07/2026
Full time
Job Description To support the Head of Security Operations in delivering effective day-to-day security operations, ensuring AJ Bell maintains the appropriate capability to detect, investigate and respond to security events and incidents. The Security Operations Technical Lead is responsible for ensuring that security operations activities are executed efficiently, consistently and in line with defined SLAs and operational standards, through hands on technical leadership across SOC, Incident Response, Threat Intelligence, Insider Risk and Vulnerability Management. This role acts as a senior technical escalation point, supporting complex investigations and driving improvements in detection, response, automation and operational processes. The role holder is expected to lead through expertise, supporting analysts and ensuring Security Operations operates with discipline, quality and continuous improvement. The key responsibilities of the role are: Act as the primary technical escalation point for security events and incidents identified by the Security Operations team. Support the Head of Security Operations in ensuring AJ Bell has the appropriate capability to detect and respond to security events and incidents. Oversee the day to day execution of security operations, ensuring alerts and incidents are handled in line with defined processes and SLAs. Ensure security operations SLAs and OLAs are met, including alert triage, escalation and incident response timelines, highlighting and addressing risks where required. Ensure adherence to our KRI and KPI's and any variation in these are raised to the Head of Security Operations. Provide hands on support in the investigation and response to security incidents, including endpoint, identity, network, cloud and insider related threats. Ensure consistent execution and continuous improvement of incident response playbooks and operational runbooks, validating them through real incidents and simulations. Support the optimisation and tuning of security monitoring and detection capabilities, including SIEM and endpoint tooling, to improve signal quality and reduce false positives. Support the execution of the end to end vulnerability management process, including validation of findings and tracking remediation activities. Work closely with MSSP and security vendors to ensure effective delivery of security operations services. Challenge and validate vendor outputs, driving operational efficiency, quality improvements and better use of tooling capabilities. Actively design and implement automation and orchestration to reduce manual effort, repetitive or high volume tasks, improve response times and increase consistency across security operations processes. Work with the Security Engineering team to ensure tooling, logging and detection gaps are identified and addressed. Support the effective operation of 24x7 security monitoring, including coordination with third party providers. Contribute to the development and delivery of operational MI and reporting, ensuring accuracy and insight into security trends and performance. Maintain visibility of security incidents, trends and operational risks, escalating issues where required. Technical Skills: Strong hands on experience of Security Operations tools and capabilities, including SIEM and SOAR platforms (e.g. Sentinel, ServiceNow, Splunk SOAR, Cortex), Endpoint Detection & Response (EDR/XDR), Strong hands on experience of Threat Intelligence platforms (e.g. Recorded Future, Doppel, ZeroFox, Google Threat Intelligence), Vulnerability management solutions (e.g. Tenable, Rapid7), and Insider Risk and DLP tools (e.g. Purview, Netskope). Strong hands on experience with Network security solutions like Next Gen Firewalls, Network Anomaly, WAF & DDoS solutions. Experience of leading and responding to Cyber Incident Response aligned to NIST Knowledge of threat detection techniques and use case development Experience of applying threat intelligence in an operational context Strong experience with vulnerability management tools and processes Strong awareness of cloud services and supporting security controls and monitoring capabilities Working knowledge of Microsoft security stack (Defender, Sentinel, Purview), Active Directory and Azure AD, Windows and Linux environments. Experience with data loss prevention and insider risk tooling advantageous Hands on experience with automation and scripting (e.g. PowerShell, Python) highly desirable Competence Experience working within recognised Information Security frameworks and best practices such as ISO27001, NIST, MITRE ATT&CK Knowledge of relevant regulatory requirements (e.g. GDPR, FCA/PRA) Experience in an Information Security role gained in a financial services environment preferred Experience working in a Security Operations role for a minimum 7 years and operating within a Lead / Senior Analyst role for at least 3 years. Knowledge & Skills Strong analytical and investigative capability Ability to work under pressure and manage multiple concurrent incidents and priorities Strong ownership of tasks, attention to detail and follow through to conclusion Ability to provide technical leadership without formal line management responsibility Ability to challenge approach, tooling and processes to improve operational effectiveness Structured, self starting and able to work under own initiative Effective communication skills, both written and verbal Ability to plan, organise and deliver tasks with minimal supervision Collaborative approach to working with analysts, engineering teams and external partners Strong focus on quality, consistency and continuous improvement About AJ Bell At AJ Bell, we believe investing should feel good. Whether you're looking for an ISA, pension or dealing account, whether you want to invest with the help of a financial adviser or do it yourself, we have easy to use solutions to suit people from all walks of life. We're one of the UK's fastest growing investment platform businesses, trusted by everyone from professional financial advisers to first time investors. Today, over 723,000 customers trust us to manage more than £108.7 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures. We're proud to be recognised as one of the UK's Best 100 Companies to Work For for six consecutive years, and a Great Place to Work in 2025 and 2026, a reflection of our supportive and collaborative culture. What we offer Competitive starting salary 26days holiday, increasing with service + buy/sell scheme + bank holidays 7% Pension with matched contributions Discretionary bonus scheme Share schemes (including free shares and BAYE) Health Cash Plan and discounted private healthcare Free gym Enhanced family leave (subject to qualifying criteria) Travel and bike loan schemes Employee Assistance Programme Life at AJ Bell Regular social events including summer and Christmas parties Learning and development opportunities tailored to you Casual dress code Friendly, supportive team environment Our ways of working At AJ Bell, our people are the heart of our culture. We believe in building strong connections by working together. That's why we offer a hybrid working model, where you'll spend a minimum of 50% of working time per month in the office. For new team members, an initial period will be spent full time in the office to help you immerse yourself in our business and build valuable relationships with your colleagues. Inclusion & diversity We're committed to creating an inclusive environment where everyone feels respected, supported and able to be themselves at work. We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential. Agency information This vacancy is being managed exclusively by our in house Recruitment team. We are not partnering with recruitment agencies on this opportunity and will only accept applications submitted directly by candidates
About us GCHQ is an intelligence, cyber and security agency with a mission to keep the UK safe. We use cutting edge technology, ingenuity, and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners, MI5 and MI6, we protect the UK from terrorism, cyber attacks and espionage. At GCHQ you'll do varied and fascinating work in a supportive and inclusive environment that emphasises teamwork. The National Cyber Security Centre (NCSC), part of GCHQ, is the UK Government's lead authority on cyber security. The organisation is at the heart of the Government's cyber security strategy and aims to make the UK the safest place to live and work online. The role As a Cyber Security Analyst at the NCSC, you'll be at the heart of the UK's cyber defence. Working alongside industry, intelligence partners, international allies, and law enforcement, you'll help prevent, disrupt and investigate the most serious cyber threats facing the UK. In this role you will tackle complex challenges using a range of techniques supported by our unique access to data, capabilities and legal authorities. Working in an Agile environment, you will: Create detailed understanding of how hostile cyber actors operate and deliver evidence based guidance to expert communities across the UK and internationally. Build insight into adversaries' intent, capabilities and the vulnerabilities they target by analysing threats and trends and identifying patterns and connections. Share insights to strengthen defences and counter those who seek to do harm to the UK. Specialise in areas such as intrusion analysis, operational technology, penetration testing, malware analysis, or networking and telecommunications security. About you We're looking for someone with a genuine enthusiasm to learn, who can develop, adapt and apply their skills across a wide range of investigative problems to deliver meaningful impact and help protect the UK. Requirements: Hold a degree (minimum 2:2) or equivalent qualification in a STEM subject, or relevant work experience in a technical or cyber security role with GCSEs (grade C/4 or above, or equivalent) in English Language and Maths. A keen interest in cyber security supported by an analytical approach and a proactive, problem solving mindset. Comfortable working both collaboratively and independently, with the ability to explore, understand and communicate complex technical concepts clearly. A tenacious and naturally curious approach to continuously learning and deepening understanding of the UK's cyber adversaries. Competencies Continuously Developing Communicating and Influencing Working Collaboratively Making Effective Decisions Delivering Outcomes Learning and development At NCSC and GCHQ we offer inclusive and supportive training and development opportunities tailored to your needs and role requirements to help you flourish and perform to the best of your abilities. Rewards and benefits You'll receive a starting salary of £37,892, which includes a concessionary payment of £2,758. The role attracts a specialist skills payment. Other benefits include: 25 days' annual leave, rising to 30 days after 5 years of service, plus 10.5 days of public and privilege holidays. Recognition through our employee performance scheme. Interest free season ticket loan. Cycle to work scheme. Facilities such as a gym, restaurant, and on site coffee bars (availability varies by location). Paid parental and adoption leave. Excellent pension scheme - Civil Service pension. Equal opportunities At GCHQ we welcome and encourage applications from everyone, including those from groups under represented in our workforce such as women, ethnic minorities, people with disabilities, and those from low socio economic backgrounds. Disability Confident GCHQ is a Disability Confident Leader, ensuring a fair and proportionate number of disabled applicants who best meet the essential minimum criteria will be offered an interview. Minimum criteria include a competent implementation of problem solving skills and a degree or equivalent with GCSEs in English Language and Maths. Eligibility and Security To work at NCSC you must be a British citizen or hold dual British nationality and hold the highest security clearance, Developed Vetting (DV).
26/07/2026
Full time
About us GCHQ is an intelligence, cyber and security agency with a mission to keep the UK safe. We use cutting edge technology, ingenuity, and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners, MI5 and MI6, we protect the UK from terrorism, cyber attacks and espionage. At GCHQ you'll do varied and fascinating work in a supportive and inclusive environment that emphasises teamwork. The National Cyber Security Centre (NCSC), part of GCHQ, is the UK Government's lead authority on cyber security. The organisation is at the heart of the Government's cyber security strategy and aims to make the UK the safest place to live and work online. The role As a Cyber Security Analyst at the NCSC, you'll be at the heart of the UK's cyber defence. Working alongside industry, intelligence partners, international allies, and law enforcement, you'll help prevent, disrupt and investigate the most serious cyber threats facing the UK. In this role you will tackle complex challenges using a range of techniques supported by our unique access to data, capabilities and legal authorities. Working in an Agile environment, you will: Create detailed understanding of how hostile cyber actors operate and deliver evidence based guidance to expert communities across the UK and internationally. Build insight into adversaries' intent, capabilities and the vulnerabilities they target by analysing threats and trends and identifying patterns and connections. Share insights to strengthen defences and counter those who seek to do harm to the UK. Specialise in areas such as intrusion analysis, operational technology, penetration testing, malware analysis, or networking and telecommunications security. About you We're looking for someone with a genuine enthusiasm to learn, who can develop, adapt and apply their skills across a wide range of investigative problems to deliver meaningful impact and help protect the UK. Requirements: Hold a degree (minimum 2:2) or equivalent qualification in a STEM subject, or relevant work experience in a technical or cyber security role with GCSEs (grade C/4 or above, or equivalent) in English Language and Maths. A keen interest in cyber security supported by an analytical approach and a proactive, problem solving mindset. Comfortable working both collaboratively and independently, with the ability to explore, understand and communicate complex technical concepts clearly. A tenacious and naturally curious approach to continuously learning and deepening understanding of the UK's cyber adversaries. Competencies Continuously Developing Communicating and Influencing Working Collaboratively Making Effective Decisions Delivering Outcomes Learning and development At NCSC and GCHQ we offer inclusive and supportive training and development opportunities tailored to your needs and role requirements to help you flourish and perform to the best of your abilities. Rewards and benefits You'll receive a starting salary of £37,892, which includes a concessionary payment of £2,758. The role attracts a specialist skills payment. Other benefits include: 25 days' annual leave, rising to 30 days after 5 years of service, plus 10.5 days of public and privilege holidays. Recognition through our employee performance scheme. Interest free season ticket loan. Cycle to work scheme. Facilities such as a gym, restaurant, and on site coffee bars (availability varies by location). Paid parental and adoption leave. Excellent pension scheme - Civil Service pension. Equal opportunities At GCHQ we welcome and encourage applications from everyone, including those from groups under represented in our workforce such as women, ethnic minorities, people with disabilities, and those from low socio economic backgrounds. Disability Confident GCHQ is a Disability Confident Leader, ensuring a fair and proportionate number of disabled applicants who best meet the essential minimum criteria will be offered an interview. Minimum criteria include a competent implementation of problem solving skills and a degree or equivalent with GCSEs in English Language and Maths. Eligibility and Security To work at NCSC you must be a British citizen or hold dual British nationality and hold the highest security clearance, Developed Vetting (DV).
We're waving goodbye to the complicated and confusing ways of traditional banking. After starting as a prepaid card, our product offering has grown a lot in the last 10 years in the UK. As well as personal and business bank accounts, we offer joint accounts, accounts for 16-17 year olds, a free kids account and credit cards in the UK, with more exciting things to come beyond. Our UK customers can also save, invest and combine their pensions with us. With our hot coral cards and get-paid-early feature, combined with financial education on social media and our award winning customer service, we have a long history of creating magical moments for our customers! We're not about selling products - we want to solve problems and change lives through Monzo Cardiff/London/UK Remote 0.5 FTE Part time £40,000 - £50,000 (full-time equivalent) + Incentive Awards tied to your performance + Benefits Our People Centred Security Squad This is a very exciting opportunity to join our People Centred Security Squad. We're focused on building security processes that allow the bank to move at pace, while protecting our customers. We're never afraid to do things differently. You'll be working closely with a full time Security Awareness Analyst and the Security Awareness Manager You'll be in a team of people who look after the human side of security You'll work with teams from all across Security and all across Monzo You'll play a key role by Create engaging security awareness content across channels including Slack, email, presentations, training, and events. Develop micro-learning, behavioural nudges, and awareness campaigns that encourage secure habits across Monzo. Manage the day-to-day delivery of the security awareness programme, including campaigns, content, documentation, and reporting. Translate complex security topics into clear, practical guidance that helps Monzonauts make confident decisions. Use behavioural insights, metrics, and user feedback to continuously improve security awareness and influence the roadmap. Partner with Security, People, Tech, Risk, and Customer Operations to improve security behaviours, reduce user friction, and communicate emerging threats. We'd love to hear from you if Experience in security awareness, internal communications, or influencing behaviour change. Excellent communication skills, with the ability to translate technical concepts into clear, engaging guidance. Highly organised, able to manage priorities independently and deliver high-quality work. Good understanding of common security risks, including phishing, social engineering, password security, and data handling. Strong collaborator who builds relationships, seeks feedback, and works effectively across teams. Bonus: Experience with behavioural science, LMS platforms, content creation, presentations, campaign analytics, or tools such as Google Workspace, Slack, and Notion. Drop us your application, we'd love to hear from you! What's in it for you 0.5 FTE Part time £40,000 - £50,000 (full-time equivalent) + Incentive Awards tied to your performance This role can be based in our London or Cardiff office, but we're open to distributed working within the UK (with ad hoc meetings in London) We offer flexible working hours and trust you to work enough hours to do your job well, and at times that suit you and your team. £1,000 learning budget each year to use on books, training courses and conferences. We will set you up to work from home; all employees are given Macbooks and for fully remote workers we will provide extra support for your work-from-home setup. Plus lots more! Read our full list of benefits. The application journey has 3 key steps 30 min recruiter call 30 min call with the hiring manager 2 hours of technical and behavioural interviews This process should take around 2-3 weeks - your schedule is really important to us, so we promise to be as flexible as possible! We have some guidelines on using Artificial Intelligence (AI) to ace an application and interview at Monzo. You can read them here. We'll only close this role once we have enough applications for the next stage. Please submit your application as soon as possible to make sure you don't miss out. Equal opportunities for everyone Diversity and inclusion are a priority for us and we're making sure we have lots of support for all of our people to grow at Monzo. At Monzo, we're embracing diversity by fostering an inclusive environment for all people to do the best work of their lives with us. This is integral to our mission of making money work for everyone. You can read more in our blog, Diversity and Inclusion Report and Gender Pay Gap Report. We're an equal opportunity employer. All applicants will be considered for employment without attention to age, ethnicity, religion, sex, sexual orientation, gender identity, family or parental status, national origin, or veteran, neurodiversity or disability status. If you have a preferred name, please use it to apply. We don't need full or birth names at application stage
26/07/2026
Full time
We're waving goodbye to the complicated and confusing ways of traditional banking. After starting as a prepaid card, our product offering has grown a lot in the last 10 years in the UK. As well as personal and business bank accounts, we offer joint accounts, accounts for 16-17 year olds, a free kids account and credit cards in the UK, with more exciting things to come beyond. Our UK customers can also save, invest and combine their pensions with us. With our hot coral cards and get-paid-early feature, combined with financial education on social media and our award winning customer service, we have a long history of creating magical moments for our customers! We're not about selling products - we want to solve problems and change lives through Monzo Cardiff/London/UK Remote 0.5 FTE Part time £40,000 - £50,000 (full-time equivalent) + Incentive Awards tied to your performance + Benefits Our People Centred Security Squad This is a very exciting opportunity to join our People Centred Security Squad. We're focused on building security processes that allow the bank to move at pace, while protecting our customers. We're never afraid to do things differently. You'll be working closely with a full time Security Awareness Analyst and the Security Awareness Manager You'll be in a team of people who look after the human side of security You'll work with teams from all across Security and all across Monzo You'll play a key role by Create engaging security awareness content across channels including Slack, email, presentations, training, and events. Develop micro-learning, behavioural nudges, and awareness campaigns that encourage secure habits across Monzo. Manage the day-to-day delivery of the security awareness programme, including campaigns, content, documentation, and reporting. Translate complex security topics into clear, practical guidance that helps Monzonauts make confident decisions. Use behavioural insights, metrics, and user feedback to continuously improve security awareness and influence the roadmap. Partner with Security, People, Tech, Risk, and Customer Operations to improve security behaviours, reduce user friction, and communicate emerging threats. We'd love to hear from you if Experience in security awareness, internal communications, or influencing behaviour change. Excellent communication skills, with the ability to translate technical concepts into clear, engaging guidance. Highly organised, able to manage priorities independently and deliver high-quality work. Good understanding of common security risks, including phishing, social engineering, password security, and data handling. Strong collaborator who builds relationships, seeks feedback, and works effectively across teams. Bonus: Experience with behavioural science, LMS platforms, content creation, presentations, campaign analytics, or tools such as Google Workspace, Slack, and Notion. Drop us your application, we'd love to hear from you! What's in it for you 0.5 FTE Part time £40,000 - £50,000 (full-time equivalent) + Incentive Awards tied to your performance This role can be based in our London or Cardiff office, but we're open to distributed working within the UK (with ad hoc meetings in London) We offer flexible working hours and trust you to work enough hours to do your job well, and at times that suit you and your team. £1,000 learning budget each year to use on books, training courses and conferences. We will set you up to work from home; all employees are given Macbooks and for fully remote workers we will provide extra support for your work-from-home setup. Plus lots more! Read our full list of benefits. The application journey has 3 key steps 30 min recruiter call 30 min call with the hiring manager 2 hours of technical and behavioural interviews This process should take around 2-3 weeks - your schedule is really important to us, so we promise to be as flexible as possible! We have some guidelines on using Artificial Intelligence (AI) to ace an application and interview at Monzo. You can read them here. We'll only close this role once we have enough applications for the next stage. Please submit your application as soon as possible to make sure you don't miss out. Equal opportunities for everyone Diversity and inclusion are a priority for us and we're making sure we have lots of support for all of our people to grow at Monzo. At Monzo, we're embracing diversity by fostering an inclusive environment for all people to do the best work of their lives with us. This is integral to our mission of making money work for everyone. You can read more in our blog, Diversity and Inclusion Report and Gender Pay Gap Report. We're an equal opportunity employer. All applicants will be considered for employment without attention to age, ethnicity, religion, sex, sexual orientation, gender identity, family or parental status, national origin, or veteran, neurodiversity or disability status. If you have a preferred name, please use it to apply. We don't need full or birth names at application stage
We're waving goodbye to the complicated and confusing ways of traditional banking. After starting as a prepaid card, our product offering has grown a lot in the last 10 years in the UK. As well as personal and business bank accounts, we offer joint accounts, accounts for 16-17 year olds, a free kids account and credit cards in the UK, with more exciting things to come beyond. Our UK customers can also save, invest and combine their pensions with us. With our hot coral cards and get-paid-early feature, combined with financial education on social media and our award winning customer service, we have a long history of creating magical moments for our customers! We're not about selling products - we want to solve problems and change lives through Monzo Cardiff/London/UK Remote 0.5 FTE Part time £40,000 - £50,000 (full-time equivalent) + Incentive Awards tied to your performance + Benefits Our People Centred Security Squad This is a very exciting opportunity to join our People Centred Security Squad. We're focused on building security processes that allow the bank to move at pace, while protecting our customers. We're never afraid to do things differently. You'll be working closely with a full time Security Awareness Analyst and the Security Awareness Manager You'll be in a team of people who look after the human side of security You'll work with teams from all across Security and all across Monzo You'll play a key role by Create engaging security awareness content across channels including Slack, email, presentations, training, and events. Develop micro-learning, behavioural nudges, and awareness campaigns that encourage secure habits across Monzo. Manage the day-to-day delivery of the security awareness programme, including campaigns, content, documentation, and reporting. Translate complex security topics into clear, practical guidance that helps Monzonauts make confident decisions. Use behavioural insights, metrics, and user feedback to continuously improve security awareness and influence the roadmap. Partner with Security, People, Tech, Risk, and Customer Operations to improve security behaviours, reduce user friction, and communicate emerging threats. We'd love to hear from you if Experience in security awareness, internal communications, or influencing behaviour change. Excellent communication skills, with the ability to translate technical concepts into clear, engaging guidance. Highly organised, able to manage priorities independently and deliver high-quality work. Good understanding of common security risks, including phishing, social engineering, password security, and data handling. Strong collaborator who builds relationships, seeks feedback, and works effectively across teams. Bonus: Experience with behavioural science, LMS platforms, content creation, presentations, campaign analytics, or tools such as Google Workspace, Slack, and Notion. Drop us your application, we'd love to hear from you! What's in it for you 0.5 FTE Part time £40,000 - £50,000 (full-time equivalent) + Incentive Awards tied to your performance This role can be based in our London or Cardiff office, but we're open to distributed working within the UK (with ad hoc meetings in London) We offer flexible working hours and trust you to work enough hours to do your job well, and at times that suit you and your team. £1,000 learning budget each year to use on books, training courses and conferences. We will set you up to work from home; all employees are given Macbooks and for fully remote workers we will provide extra support for your work-from-home setup. Plus lots more! Read our full list of benefits. The application journey has 3 key steps 30 min recruiter call 30 min call with the hiring manager 2 hours of technical and behavioural interviews This process should take around 2-3 weeks - your schedule is really important to us, so we promise to be as flexible as possible! We have some guidelines on using Artificial Intelligence (AI) to ace an application and interview at Monzo. You can read them here. We'll only close this role once we have enough applications for the next stage. Please submit your application as soon as possible to make sure you don't miss out. Equal opportunities for everyone Diversity and inclusion are a priority for us and we're making sure we have lots of support for all of our people to grow at Monzo. At Monzo, we're embracing diversity by fostering an inclusive environment for all people to do the best work of their lives with us. This is integral to our mission of making money work for everyone. You can read more in our blog, Diversity and Inclusion Report and Gender Pay Gap Report. We're an equal opportunity employer. All applicants will be considered for employment without attention to age, ethnicity, religion, sex, sexual orientation, gender identity, family or parental status, national origin, or veteran, neurodiversity or disability status. If you have a preferred name, please use it to apply. We don't need full or birth names at application stage
26/07/2026
Full time
We're waving goodbye to the complicated and confusing ways of traditional banking. After starting as a prepaid card, our product offering has grown a lot in the last 10 years in the UK. As well as personal and business bank accounts, we offer joint accounts, accounts for 16-17 year olds, a free kids account and credit cards in the UK, with more exciting things to come beyond. Our UK customers can also save, invest and combine their pensions with us. With our hot coral cards and get-paid-early feature, combined with financial education on social media and our award winning customer service, we have a long history of creating magical moments for our customers! We're not about selling products - we want to solve problems and change lives through Monzo Cardiff/London/UK Remote 0.5 FTE Part time £40,000 - £50,000 (full-time equivalent) + Incentive Awards tied to your performance + Benefits Our People Centred Security Squad This is a very exciting opportunity to join our People Centred Security Squad. We're focused on building security processes that allow the bank to move at pace, while protecting our customers. We're never afraid to do things differently. You'll be working closely with a full time Security Awareness Analyst and the Security Awareness Manager You'll be in a team of people who look after the human side of security You'll work with teams from all across Security and all across Monzo You'll play a key role by Create engaging security awareness content across channels including Slack, email, presentations, training, and events. Develop micro-learning, behavioural nudges, and awareness campaigns that encourage secure habits across Monzo. Manage the day-to-day delivery of the security awareness programme, including campaigns, content, documentation, and reporting. Translate complex security topics into clear, practical guidance that helps Monzonauts make confident decisions. Use behavioural insights, metrics, and user feedback to continuously improve security awareness and influence the roadmap. Partner with Security, People, Tech, Risk, and Customer Operations to improve security behaviours, reduce user friction, and communicate emerging threats. We'd love to hear from you if Experience in security awareness, internal communications, or influencing behaviour change. Excellent communication skills, with the ability to translate technical concepts into clear, engaging guidance. Highly organised, able to manage priorities independently and deliver high-quality work. Good understanding of common security risks, including phishing, social engineering, password security, and data handling. Strong collaborator who builds relationships, seeks feedback, and works effectively across teams. Bonus: Experience with behavioural science, LMS platforms, content creation, presentations, campaign analytics, or tools such as Google Workspace, Slack, and Notion. Drop us your application, we'd love to hear from you! What's in it for you 0.5 FTE Part time £40,000 - £50,000 (full-time equivalent) + Incentive Awards tied to your performance This role can be based in our London or Cardiff office, but we're open to distributed working within the UK (with ad hoc meetings in London) We offer flexible working hours and trust you to work enough hours to do your job well, and at times that suit you and your team. £1,000 learning budget each year to use on books, training courses and conferences. We will set you up to work from home; all employees are given Macbooks and for fully remote workers we will provide extra support for your work-from-home setup. Plus lots more! Read our full list of benefits. The application journey has 3 key steps 30 min recruiter call 30 min call with the hiring manager 2 hours of technical and behavioural interviews This process should take around 2-3 weeks - your schedule is really important to us, so we promise to be as flexible as possible! We have some guidelines on using Artificial Intelligence (AI) to ace an application and interview at Monzo. You can read them here. We'll only close this role once we have enough applications for the next stage. Please submit your application as soon as possible to make sure you don't miss out. Equal opportunities for everyone Diversity and inclusion are a priority for us and we're making sure we have lots of support for all of our people to grow at Monzo. At Monzo, we're embracing diversity by fostering an inclusive environment for all people to do the best work of their lives with us. This is integral to our mission of making money work for everyone. You can read more in our blog, Diversity and Inclusion Report and Gender Pay Gap Report. We're an equal opportunity employer. All applicants will be considered for employment without attention to age, ethnicity, religion, sex, sexual orientation, gender identity, family or parental status, national origin, or veteran, neurodiversity or disability status. If you have a preferred name, please use it to apply. We don't need full or birth names at application stage
Location(s):UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123212 Location: Leeds Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
26/07/2026
Full time
Location(s):UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123212 Location: Leeds Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
BAE Systems Digital Intelligence in Leeds seeks a Senior SOC Analyst and Shift Lead to join our 24/7 security operations team. You will monitor and investigate incidents across Azure and AWS hosted networks, working with a blended customer and BAE staff team from our Leeds office. The role requires a minimum of security clearance and will support threat intelligence and incident response activities. Initial terms include 6- and 12-month contracts with potential extensions.
26/07/2026
Full time
BAE Systems Digital Intelligence in Leeds seeks a Senior SOC Analyst and Shift Lead to join our 24/7 security operations team. You will monitor and investigate incidents across Azure and AWS hosted networks, working with a blended customer and BAE staff team from our Leeds office. The role requires a minimum of security clearance and will support threat intelligence and incident response activities. Initial terms include 6- and 12-month contracts with potential extensions.
Location(s):UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123212 Location: Leeds Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
26/07/2026
Full time
Location(s):UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123212 Location: Leeds Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
Location(s):UK, Europe & Africa : UK : Manchester BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123208 Location: Manchester Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
26/07/2026
Full time
Location(s):UK, Europe & Africa : UK : Manchester BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments. Job Title: Senior SOC Analyst Requisition ID: 123208 Location: Manchester Grade: GG09-GG10 Referral Bonus: £5,000 SOC Senior Analyst & Shift Lead Role description BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to. The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). The SOC Analyst roles are 'hands-on' shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance and be prepared to undergo DV clearance. Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis. Responsibilities Ensure that the shift handover brief is prepared and delivered to the incoming shift Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks / security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. Write up high quality security incident tickets using a combination of existing knowledge resources and independent research. Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber-attacks, clean up IT systems and secure networks against repeat attacks. Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review. Understand Threat Intelligence and its use in an operational environment Support incident response to national scale incidents in a coaching capacity Work with other teams within BAE to improve services on the basis of customer needs. Produce new workflows for automation into SOAR tools for common attack types. Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat. Requirements Technical Basic Python and/or scripting skills, Windows, OS X, and Linux Experience using Splunk and Sentinal Working with a range of security tooling/technology Strong understanding of security architecture, in particular networking Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence. Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks). Understand TCP/IP component layers to identify normal and abnormal traffic Understanding of AWS &/or Azure cloud services Experience of Splunk (with ES) &/or Sentinel, content development experience desirable Non-technical Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing) Coaching mindset - Mentor team. Security process development Able to understand and adapt to different cultures and hierarchical structures. Self-starter and capable of independent working Team player and adept at working in multi-disciplinary and diverse teams Desirable Software engineering experience Penetration testing skills Life at BAE Systems Digital Intelligence We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being. Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.
About us GCHQ is an intelligence, cyber and security agency with a mission to keep the UK safe. We use cutting edge technology, ingenuity, and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners, MI5 and MI6, we protect the UK from terrorism, cyber attacks and espionage. At GCHQ you'll do varied and fascinating work in a supportive and inclusive environment that emphasises teamwork. The National Cyber Security Centre (NCSC), part of GCHQ, is the UK Government's lead authority on cyber security. The organisation is at the heart of the Government's cyber security strategy and aims to make the UK the safest place to live and work online. The role As a Cyber Security Analyst at the NCSC, you'll be at the heart of the UK's cyber defence. Working alongside industry, intelligence partners, international allies, and law enforcement, you'll help prevent, disrupt and investigate the most serious cyber threats facing the UK. In this role you will tackle complex challenges using a range of techniques supported by our unique access to data, capabilities and legal authorities. Working in an Agile environment, you will: Create detailed understanding of how hostile cyber actors operate and deliver evidence based guidance to expert communities across the UK and internationally. Build insight into adversaries' intent, capabilities and the vulnerabilities they target by analysing threats and trends and identifying patterns and connections. Share insights to strengthen defences and counter those who seek to do harm to the UK. Specialise in areas such as intrusion analysis, operational technology, penetration testing, malware analysis, or networking and telecommunications security. About you We're looking for someone with a genuine enthusiasm to learn, who can develop, adapt and apply their skills across a wide range of investigative problems to deliver meaningful impact and help protect the UK. Requirements: Hold a degree (minimum 2:2) or equivalent qualification in a STEM subject, or relevant work experience in a technical or cyber security role with GCSEs (grade C/4 or above, or equivalent) in English Language and Maths. A keen interest in cyber security supported by an analytical approach and a proactive, problem solving mindset. Comfortable working both collaboratively and independently, with the ability to explore, understand and communicate complex technical concepts clearly. A tenacious and naturally curious approach to continuously learning and deepening understanding of the UK's cyber adversaries. Competencies Continuously Developing Communicating and Influencing Working Collaboratively Making Effective Decisions Delivering Outcomes Learning and development At NCSC and GCHQ we offer inclusive and supportive training and development opportunities tailored to your needs and role requirements to help you flourish and perform to the best of your abilities. Rewards and benefits You'll receive a starting salary of £37,892, which includes a concessionary payment of £2,758. The role attracts a specialist skills payment. Other benefits include: 25 days' annual leave, rising to 30 days after 5 years of service, plus 10.5 days of public and privilege holidays. Recognition through our employee performance scheme. Interest free season ticket loan. Cycle to work scheme. Facilities such as a gym, restaurant, and on site coffee bars (availability varies by location). Paid parental and adoption leave. Excellent pension scheme - Civil Service pension. Equal opportunities At GCHQ we welcome and encourage applications from everyone, including those from groups under represented in our workforce such as women, ethnic minorities, people with disabilities, and those from low socio economic backgrounds. Disability Confident GCHQ is a Disability Confident Leader, ensuring a fair and proportionate number of disabled applicants who best meet the essential minimum criteria will be offered an interview. Minimum criteria include a competent implementation of problem solving skills and a degree or equivalent with GCSEs in English Language and Maths. Eligibility and Security To work at NCSC you must be a British citizen or hold dual British nationality and hold the highest security clearance, Developed Vetting (DV).
26/07/2026
Full time
About us GCHQ is an intelligence, cyber and security agency with a mission to keep the UK safe. We use cutting edge technology, ingenuity, and partnerships to identify, analyse and disrupt threats. Working with our intelligence partners, MI5 and MI6, we protect the UK from terrorism, cyber attacks and espionage. At GCHQ you'll do varied and fascinating work in a supportive and inclusive environment that emphasises teamwork. The National Cyber Security Centre (NCSC), part of GCHQ, is the UK Government's lead authority on cyber security. The organisation is at the heart of the Government's cyber security strategy and aims to make the UK the safest place to live and work online. The role As a Cyber Security Analyst at the NCSC, you'll be at the heart of the UK's cyber defence. Working alongside industry, intelligence partners, international allies, and law enforcement, you'll help prevent, disrupt and investigate the most serious cyber threats facing the UK. In this role you will tackle complex challenges using a range of techniques supported by our unique access to data, capabilities and legal authorities. Working in an Agile environment, you will: Create detailed understanding of how hostile cyber actors operate and deliver evidence based guidance to expert communities across the UK and internationally. Build insight into adversaries' intent, capabilities and the vulnerabilities they target by analysing threats and trends and identifying patterns and connections. Share insights to strengthen defences and counter those who seek to do harm to the UK. Specialise in areas such as intrusion analysis, operational technology, penetration testing, malware analysis, or networking and telecommunications security. About you We're looking for someone with a genuine enthusiasm to learn, who can develop, adapt and apply their skills across a wide range of investigative problems to deliver meaningful impact and help protect the UK. Requirements: Hold a degree (minimum 2:2) or equivalent qualification in a STEM subject, or relevant work experience in a technical or cyber security role with GCSEs (grade C/4 or above, or equivalent) in English Language and Maths. A keen interest in cyber security supported by an analytical approach and a proactive, problem solving mindset. Comfortable working both collaboratively and independently, with the ability to explore, understand and communicate complex technical concepts clearly. A tenacious and naturally curious approach to continuously learning and deepening understanding of the UK's cyber adversaries. Competencies Continuously Developing Communicating and Influencing Working Collaboratively Making Effective Decisions Delivering Outcomes Learning and development At NCSC and GCHQ we offer inclusive and supportive training and development opportunities tailored to your needs and role requirements to help you flourish and perform to the best of your abilities. Rewards and benefits You'll receive a starting salary of £37,892, which includes a concessionary payment of £2,758. The role attracts a specialist skills payment. Other benefits include: 25 days' annual leave, rising to 30 days after 5 years of service, plus 10.5 days of public and privilege holidays. Recognition through our employee performance scheme. Interest free season ticket loan. Cycle to work scheme. Facilities such as a gym, restaurant, and on site coffee bars (availability varies by location). Paid parental and adoption leave. Excellent pension scheme - Civil Service pension. Equal opportunities At GCHQ we welcome and encourage applications from everyone, including those from groups under represented in our workforce such as women, ethnic minorities, people with disabilities, and those from low socio economic backgrounds. Disability Confident GCHQ is a Disability Confident Leader, ensuring a fair and proportionate number of disabled applicants who best meet the essential minimum criteria will be offered an interview. Minimum criteria include a competent implementation of problem solving skills and a degree or equivalent with GCSEs in English Language and Maths. Eligibility and Security To work at NCSC you must be a British citizen or hold dual British nationality and hold the highest security clearance, Developed Vetting (DV).
Flexible Working During your initial nine month training period you will commit to full time hours, Monday to Friday (37 hours per week). After that period you may adjust your hours. We offer flexitime, part time, job share and compressed hours. The role is fully office based. Expected Start Dates Between July and September 2027. About Us GCHQ is an intelligence, cyber and security agency dedicated to keeping the UK safe. We use cutting edge technology and partnerships to identify, analyse and disrupt threats, working with MI5 and MI6 to protect the UK from terrorism, cyber attacks and espionage. The role offers varied, interesting work within a supportive, inclusive environment that emphasises teamwork. The role can be based at several locations, including the National Cyber Force (NCF) in Samlesbury. The NCF operates across cyberspace to counter, disrupt and contest those who could threaten the UK or its allies, protecting the UK's interests at home and abroad. The Role As an Intelligence Data Analyst you will support real world events and gain unique insight into what happens behind the news headlines. You will gather information from a variety of sources, including high volumes of data from internet connected devices, and use your analytical and interpretive skills to synthesize this information. Your work may involve short or long term projects, finding and tracking adversaries and using analysis to inform foreign policy, law enforcement and national security. About You You enjoy making sense of complex information and asking questions. Curiosity drives you to investigate further, and you are resilient and persistent. You are eager to learn new things, including emerging technologies, and you do not need a technical background. We welcome people of all ages and backgrounds who offer diverse perspectives. No degree or previous experience is required. All that matters is a Level 2 (GCSE or equivalent) qualification in English Language and Maths at Grade 4/C or above. A higher qualification is welcome but not essential. Training and Development You will start your training in the Comprehensive Analysis Development Programme, which begins immediately after induction. This bespoke programme is designed for new entrants with no intelligence data analysis experience. You will train in a classroom and on the job with tutors, mentors and colleagues, gaining exposure to real life problems. Rewards and Benefits You will receive a starting salary of £37,892 and the following benefits: 25 days annual leave rising to 30 days after five years of service, plus 10.5 public and private holidays Recognition through the employee performance scheme Interest free season ticket loan Excellent pension scheme Cycle to work scheme On site facilities such as a gym, restaurant and coffee bars (selected locations) Paid parental and adoption leave Equal Opportunities GCHQ seeks a diverse workforce that reflects our society, including people of all ages, ethnicities, gender identities, sexual orientations, neurodivergent conditions and those with disabilities. We encourage applications from under represented groups such as women, ethnic minorities, people with disabilities and those from low socio economic backgrounds. We're Disability Confident GCHQ is a Leader in the Department for Work and Pensions' Disability Confident scheme. We aim to provide fair and proportionate opportunities for disabled applicants who meet the essential minimum criteria for this position. Eligibility criteria for interview include a Level 2 qualification in English Language and Maths, passing the online Situational Judgement Test, meeting the minimum pass marks for application questions, bespoke analysis exercise and test, and the analysis test prior to interview. Additional support is available throughout recruitment to allow everyone to perform to their best ability. What to Expect Online Situational Judgement Test (SJT) Initial short online bespoke analysis test Sift - assessment of two application questions, conducted without personal information Longer online bespoke analysis test Virtual interview Each successful stage must be passed to progress to the next. The overall application process can take 6 to 9 months, including vetting. Before You Apply To work at GCHQ you must be a British citizen or hold dual British nationality. The role requires the highest security clearance - Developed Vetting (DV). A strict drugs policy applies: recreational drugs cannot be used during the application process. The role is based in Cheltenham, Manchester or Samlesbury. Applicants must live within a reasonable commuting distance of one of these locations and will not receive relocation costs. Successful applicants are expected to start between July and September 2027, with no deferrals. Candidates may use separate emails for application correspondence to preserve privacy. Travel costs for in person appointments may be reasonably reimbursed in line with our Candidate Expenses Policy. Applicants must book and retain receipts for reimbursement. Right to Withdraw Statement We reserve the right to bring forward the closing date for this role at any location once a certain number of applications have been received. Please submit your application promptly to avoid disappointment.
26/07/2026
Full time
Flexible Working During your initial nine month training period you will commit to full time hours, Monday to Friday (37 hours per week). After that period you may adjust your hours. We offer flexitime, part time, job share and compressed hours. The role is fully office based. Expected Start Dates Between July and September 2027. About Us GCHQ is an intelligence, cyber and security agency dedicated to keeping the UK safe. We use cutting edge technology and partnerships to identify, analyse and disrupt threats, working with MI5 and MI6 to protect the UK from terrorism, cyber attacks and espionage. The role offers varied, interesting work within a supportive, inclusive environment that emphasises teamwork. The role can be based at several locations, including the National Cyber Force (NCF) in Samlesbury. The NCF operates across cyberspace to counter, disrupt and contest those who could threaten the UK or its allies, protecting the UK's interests at home and abroad. The Role As an Intelligence Data Analyst you will support real world events and gain unique insight into what happens behind the news headlines. You will gather information from a variety of sources, including high volumes of data from internet connected devices, and use your analytical and interpretive skills to synthesize this information. Your work may involve short or long term projects, finding and tracking adversaries and using analysis to inform foreign policy, law enforcement and national security. About You You enjoy making sense of complex information and asking questions. Curiosity drives you to investigate further, and you are resilient and persistent. You are eager to learn new things, including emerging technologies, and you do not need a technical background. We welcome people of all ages and backgrounds who offer diverse perspectives. No degree or previous experience is required. All that matters is a Level 2 (GCSE or equivalent) qualification in English Language and Maths at Grade 4/C or above. A higher qualification is welcome but not essential. Training and Development You will start your training in the Comprehensive Analysis Development Programme, which begins immediately after induction. This bespoke programme is designed for new entrants with no intelligence data analysis experience. You will train in a classroom and on the job with tutors, mentors and colleagues, gaining exposure to real life problems. Rewards and Benefits You will receive a starting salary of £37,892 and the following benefits: 25 days annual leave rising to 30 days after five years of service, plus 10.5 public and private holidays Recognition through the employee performance scheme Interest free season ticket loan Excellent pension scheme Cycle to work scheme On site facilities such as a gym, restaurant and coffee bars (selected locations) Paid parental and adoption leave Equal Opportunities GCHQ seeks a diverse workforce that reflects our society, including people of all ages, ethnicities, gender identities, sexual orientations, neurodivergent conditions and those with disabilities. We encourage applications from under represented groups such as women, ethnic minorities, people with disabilities and those from low socio economic backgrounds. We're Disability Confident GCHQ is a Leader in the Department for Work and Pensions' Disability Confident scheme. We aim to provide fair and proportionate opportunities for disabled applicants who meet the essential minimum criteria for this position. Eligibility criteria for interview include a Level 2 qualification in English Language and Maths, passing the online Situational Judgement Test, meeting the minimum pass marks for application questions, bespoke analysis exercise and test, and the analysis test prior to interview. Additional support is available throughout recruitment to allow everyone to perform to their best ability. What to Expect Online Situational Judgement Test (SJT) Initial short online bespoke analysis test Sift - assessment of two application questions, conducted without personal information Longer online bespoke analysis test Virtual interview Each successful stage must be passed to progress to the next. The overall application process can take 6 to 9 months, including vetting. Before You Apply To work at GCHQ you must be a British citizen or hold dual British nationality. The role requires the highest security clearance - Developed Vetting (DV). A strict drugs policy applies: recreational drugs cannot be used during the application process. The role is based in Cheltenham, Manchester or Samlesbury. Applicants must live within a reasonable commuting distance of one of these locations and will not receive relocation costs. Successful applicants are expected to start between July and September 2027, with no deferrals. Candidates may use separate emails for application correspondence to preserve privacy. Travel costs for in person appointments may be reasonably reimbursed in line with our Candidate Expenses Policy. Applicants must book and retain receipts for reimbursement. Right to Withdraw Statement We reserve the right to bring forward the closing date for this role at any location once a certain number of applications have been received. Please submit your application promptly to avoid disappointment.
Flexible Working During your initial nine month training period you will commit to full time hours, Monday to Friday (37 hours per week). After that period you may adjust your hours. We offer flexitime, part time, job share and compressed hours. The role is fully office based. Expected Start Dates Between July and September 2027. About Us GCHQ is an intelligence, cyber and security agency dedicated to keeping the UK safe. We use cutting edge technology and partnerships to identify, analyse and disrupt threats, working with MI5 and MI6 to protect the UK from terrorism, cyber attacks and espionage. The role offers varied, interesting work within a supportive, inclusive environment that emphasises teamwork. The role can be based at several locations, including the National Cyber Force (NCF) in Samlesbury. The NCF operates across cyberspace to counter, disrupt and contest those who could threaten the UK or its allies, protecting the UK's interests at home and abroad. The Role As an Intelligence Data Analyst you will support real world events and gain unique insight into what happens behind the news headlines. You will gather information from a variety of sources, including high volumes of data from internet connected devices, and use your analytical and interpretive skills to synthesize this information. Your work may involve short or long term projects, finding and tracking adversaries and using analysis to inform foreign policy, law enforcement and national security. About You You enjoy making sense of complex information and asking questions. Curiosity drives you to investigate further, and you are resilient and persistent. You are eager to learn new things, including emerging technologies, and you do not need a technical background. We welcome people of all ages and backgrounds who offer diverse perspectives. No degree or previous experience is required. All that matters is a Level 2 (GCSE or equivalent) qualification in English Language and Maths at Grade 4/C or above. A higher qualification is welcome but not essential. Training and Development You will start your training in the Comprehensive Analysis Development Programme, which begins immediately after induction. This bespoke programme is designed for new entrants with no intelligence data analysis experience. You will train in a classroom and on the job with tutors, mentors and colleagues, gaining exposure to real life problems. Rewards and Benefits You will receive a starting salary of £37,892 and the following benefits: 25 days annual leave rising to 30 days after five years of service, plus 10.5 public and private holidays Recognition through the employee performance scheme Interest free season ticket loan Excellent pension scheme Cycle to work scheme On site facilities such as a gym, restaurant and coffee bars (selected locations) Paid parental and adoption leave Equal Opportunities GCHQ seeks a diverse workforce that reflects our society, including people of all ages, ethnicities, gender identities, sexual orientations, neurodivergent conditions and those with disabilities. We encourage applications from under represented groups such as women, ethnic minorities, people with disabilities and those from low socio economic backgrounds. We're Disability Confident GCHQ is a Leader in the Department for Work and Pensions' Disability Confident scheme. We aim to provide fair and proportionate opportunities for disabled applicants who meet the essential minimum criteria for this position. Eligibility criteria for interview include a Level 2 qualification in English Language and Maths, passing the online Situational Judgement Test, meeting the minimum pass marks for application questions, bespoke analysis exercise and test, and the analysis test prior to interview. Additional support is available throughout recruitment to allow everyone to perform to their best ability. What to Expect Online Situational Judgement Test (SJT) Initial short online bespoke analysis test Sift - assessment of two application questions, conducted without personal information Longer online bespoke analysis test Virtual interview Each successful stage must be passed to progress to the next. The overall application process can take 6 to 9 months, including vetting. Before You Apply To work at GCHQ you must be a British citizen or hold dual British nationality. The role requires the highest security clearance - Developed Vetting (DV). A strict drugs policy applies: recreational drugs cannot be used during the application process. The role is based in Cheltenham, Manchester or Samlesbury. Applicants must live within a reasonable commuting distance of one of these locations and will not receive relocation costs. Successful applicants are expected to start between July and September 2027, with no deferrals. Candidates may use separate emails for application correspondence to preserve privacy. Travel costs for in person appointments may be reasonably reimbursed in line with our Candidate Expenses Policy. Applicants must book and retain receipts for reimbursement. Right to Withdraw Statement We reserve the right to bring forward the closing date for this role at any location once a certain number of applications have been received. Please submit your application promptly to avoid disappointment.
26/07/2026
Full time
Flexible Working During your initial nine month training period you will commit to full time hours, Monday to Friday (37 hours per week). After that period you may adjust your hours. We offer flexitime, part time, job share and compressed hours. The role is fully office based. Expected Start Dates Between July and September 2027. About Us GCHQ is an intelligence, cyber and security agency dedicated to keeping the UK safe. We use cutting edge technology and partnerships to identify, analyse and disrupt threats, working with MI5 and MI6 to protect the UK from terrorism, cyber attacks and espionage. The role offers varied, interesting work within a supportive, inclusive environment that emphasises teamwork. The role can be based at several locations, including the National Cyber Force (NCF) in Samlesbury. The NCF operates across cyberspace to counter, disrupt and contest those who could threaten the UK or its allies, protecting the UK's interests at home and abroad. The Role As an Intelligence Data Analyst you will support real world events and gain unique insight into what happens behind the news headlines. You will gather information from a variety of sources, including high volumes of data from internet connected devices, and use your analytical and interpretive skills to synthesize this information. Your work may involve short or long term projects, finding and tracking adversaries and using analysis to inform foreign policy, law enforcement and national security. About You You enjoy making sense of complex information and asking questions. Curiosity drives you to investigate further, and you are resilient and persistent. You are eager to learn new things, including emerging technologies, and you do not need a technical background. We welcome people of all ages and backgrounds who offer diverse perspectives. No degree or previous experience is required. All that matters is a Level 2 (GCSE or equivalent) qualification in English Language and Maths at Grade 4/C or above. A higher qualification is welcome but not essential. Training and Development You will start your training in the Comprehensive Analysis Development Programme, which begins immediately after induction. This bespoke programme is designed for new entrants with no intelligence data analysis experience. You will train in a classroom and on the job with tutors, mentors and colleagues, gaining exposure to real life problems. Rewards and Benefits You will receive a starting salary of £37,892 and the following benefits: 25 days annual leave rising to 30 days after five years of service, plus 10.5 public and private holidays Recognition through the employee performance scheme Interest free season ticket loan Excellent pension scheme Cycle to work scheme On site facilities such as a gym, restaurant and coffee bars (selected locations) Paid parental and adoption leave Equal Opportunities GCHQ seeks a diverse workforce that reflects our society, including people of all ages, ethnicities, gender identities, sexual orientations, neurodivergent conditions and those with disabilities. We encourage applications from under represented groups such as women, ethnic minorities, people with disabilities and those from low socio economic backgrounds. We're Disability Confident GCHQ is a Leader in the Department for Work and Pensions' Disability Confident scheme. We aim to provide fair and proportionate opportunities for disabled applicants who meet the essential minimum criteria for this position. Eligibility criteria for interview include a Level 2 qualification in English Language and Maths, passing the online Situational Judgement Test, meeting the minimum pass marks for application questions, bespoke analysis exercise and test, and the analysis test prior to interview. Additional support is available throughout recruitment to allow everyone to perform to their best ability. What to Expect Online Situational Judgement Test (SJT) Initial short online bespoke analysis test Sift - assessment of two application questions, conducted without personal information Longer online bespoke analysis test Virtual interview Each successful stage must be passed to progress to the next. The overall application process can take 6 to 9 months, including vetting. Before You Apply To work at GCHQ you must be a British citizen or hold dual British nationality. The role requires the highest security clearance - Developed Vetting (DV). A strict drugs policy applies: recreational drugs cannot be used during the application process. The role is based in Cheltenham, Manchester or Samlesbury. Applicants must live within a reasonable commuting distance of one of these locations and will not receive relocation costs. Successful applicants are expected to start between July and September 2027, with no deferrals. Candidates may use separate emails for application correspondence to preserve privacy. Travel costs for in person appointments may be reasonably reimbursed in line with our Candidate Expenses Policy. Applicants must book and retain receipts for reimbursement. Right to Withdraw Statement We reserve the right to bring forward the closing date for this role at any location once a certain number of applications have been received. Please submit your application promptly to avoid disappointment.
Flexible Working During your initial nine month training period you will commit to full time hours, Monday to Friday (37 hours per week). After that period you may adjust your hours. We offer flexitime, part time, job share and compressed hours. The role is fully office based. Expected Start Dates Between July and September 2027. About Us GCHQ is an intelligence, cyber and security agency dedicated to keeping the UK safe. We use cutting edge technology and partnerships to identify, analyse and disrupt threats, working with MI5 and MI6 to protect the UK from terrorism, cyber attacks and espionage. The role offers varied, interesting work within a supportive, inclusive environment that emphasises teamwork. The role can be based at several locations, including the National Cyber Force (NCF) in Samlesbury. The NCF operates across cyberspace to counter, disrupt and contest those who could threaten the UK or its allies, protecting the UK's interests at home and abroad. The Role As an Intelligence Data Analyst you will support real world events and gain unique insight into what happens behind the news headlines. You will gather information from a variety of sources, including high volumes of data from internet connected devices, and use your analytical and interpretive skills to synthesize this information. Your work may involve short or long term projects, finding and tracking adversaries and using analysis to inform foreign policy, law enforcement and national security. About You You enjoy making sense of complex information and asking questions. Curiosity drives you to investigate further, and you are resilient and persistent. You are eager to learn new things, including emerging technologies, and you do not need a technical background. We welcome people of all ages and backgrounds who offer diverse perspectives. No degree or previous experience is required. All that matters is a Level 2 (GCSE or equivalent) qualification in English Language and Maths at Grade 4/C or above. A higher qualification is welcome but not essential. Training and Development You will start your training in the Comprehensive Analysis Development Programme, which begins immediately after induction. This bespoke programme is designed for new entrants with no intelligence data analysis experience. You will train in a classroom and on the job with tutors, mentors and colleagues, gaining exposure to real life problems. Rewards and Benefits You will receive a starting salary of £37,892 and the following benefits: 25 days annual leave rising to 30 days after five years of service, plus 10.5 public and private holidays Recognition through the employee performance scheme Interest free season ticket loan Excellent pension scheme Cycle to work scheme On site facilities such as a gym, restaurant and coffee bars (selected locations) Paid parental and adoption leave Equal Opportunities GCHQ seeks a diverse workforce that reflects our society, including people of all ages, ethnicities, gender identities, sexual orientations, neurodivergent conditions and those with disabilities. We encourage applications from under represented groups such as women, ethnic minorities, people with disabilities and those from low socio economic backgrounds. We're Disability Confident GCHQ is a Leader in the Department for Work and Pensions' Disability Confident scheme. We aim to provide fair and proportionate opportunities for disabled applicants who meet the essential minimum criteria for this position. Eligibility criteria for interview include a Level 2 qualification in English Language and Maths, passing the online Situational Judgement Test, meeting the minimum pass marks for application questions, bespoke analysis exercise and test, and the analysis test prior to interview. Additional support is available throughout recruitment to allow everyone to perform to their best ability. What to Expect Online Situational Judgement Test (SJT) Initial short online bespoke analysis test Sift - assessment of two application questions, conducted without personal information Longer online bespoke analysis test Virtual interview Each successful stage must be passed to progress to the next. The overall application process can take 6 to 9 months, including vetting. Before You Apply To work at GCHQ you must be a British citizen or hold dual British nationality. The role requires the highest security clearance - Developed Vetting (DV). A strict drugs policy applies: recreational drugs cannot be used during the application process. The role is based in Cheltenham, Manchester or Samlesbury. Applicants must live within a reasonable commuting distance of one of these locations and will not receive relocation costs. Successful applicants are expected to start between July and September 2027, with no deferrals. Candidates may use separate emails for application correspondence to preserve privacy. Travel costs for in person appointments may be reasonably reimbursed in line with our Candidate Expenses Policy. Applicants must book and retain receipts for reimbursement. Right to Withdraw Statement We reserve the right to bring forward the closing date for this role at any location once a certain number of applications have been received. Please submit your application promptly to avoid disappointment.
26/07/2026
Full time
Flexible Working During your initial nine month training period you will commit to full time hours, Monday to Friday (37 hours per week). After that period you may adjust your hours. We offer flexitime, part time, job share and compressed hours. The role is fully office based. Expected Start Dates Between July and September 2027. About Us GCHQ is an intelligence, cyber and security agency dedicated to keeping the UK safe. We use cutting edge technology and partnerships to identify, analyse and disrupt threats, working with MI5 and MI6 to protect the UK from terrorism, cyber attacks and espionage. The role offers varied, interesting work within a supportive, inclusive environment that emphasises teamwork. The role can be based at several locations, including the National Cyber Force (NCF) in Samlesbury. The NCF operates across cyberspace to counter, disrupt and contest those who could threaten the UK or its allies, protecting the UK's interests at home and abroad. The Role As an Intelligence Data Analyst you will support real world events and gain unique insight into what happens behind the news headlines. You will gather information from a variety of sources, including high volumes of data from internet connected devices, and use your analytical and interpretive skills to synthesize this information. Your work may involve short or long term projects, finding and tracking adversaries and using analysis to inform foreign policy, law enforcement and national security. About You You enjoy making sense of complex information and asking questions. Curiosity drives you to investigate further, and you are resilient and persistent. You are eager to learn new things, including emerging technologies, and you do not need a technical background. We welcome people of all ages and backgrounds who offer diverse perspectives. No degree or previous experience is required. All that matters is a Level 2 (GCSE or equivalent) qualification in English Language and Maths at Grade 4/C or above. A higher qualification is welcome but not essential. Training and Development You will start your training in the Comprehensive Analysis Development Programme, which begins immediately after induction. This bespoke programme is designed for new entrants with no intelligence data analysis experience. You will train in a classroom and on the job with tutors, mentors and colleagues, gaining exposure to real life problems. Rewards and Benefits You will receive a starting salary of £37,892 and the following benefits: 25 days annual leave rising to 30 days after five years of service, plus 10.5 public and private holidays Recognition through the employee performance scheme Interest free season ticket loan Excellent pension scheme Cycle to work scheme On site facilities such as a gym, restaurant and coffee bars (selected locations) Paid parental and adoption leave Equal Opportunities GCHQ seeks a diverse workforce that reflects our society, including people of all ages, ethnicities, gender identities, sexual orientations, neurodivergent conditions and those with disabilities. We encourage applications from under represented groups such as women, ethnic minorities, people with disabilities and those from low socio economic backgrounds. We're Disability Confident GCHQ is a Leader in the Department for Work and Pensions' Disability Confident scheme. We aim to provide fair and proportionate opportunities for disabled applicants who meet the essential minimum criteria for this position. Eligibility criteria for interview include a Level 2 qualification in English Language and Maths, passing the online Situational Judgement Test, meeting the minimum pass marks for application questions, bespoke analysis exercise and test, and the analysis test prior to interview. Additional support is available throughout recruitment to allow everyone to perform to their best ability. What to Expect Online Situational Judgement Test (SJT) Initial short online bespoke analysis test Sift - assessment of two application questions, conducted without personal information Longer online bespoke analysis test Virtual interview Each successful stage must be passed to progress to the next. The overall application process can take 6 to 9 months, including vetting. Before You Apply To work at GCHQ you must be a British citizen or hold dual British nationality. The role requires the highest security clearance - Developed Vetting (DV). A strict drugs policy applies: recreational drugs cannot be used during the application process. The role is based in Cheltenham, Manchester or Samlesbury. Applicants must live within a reasonable commuting distance of one of these locations and will not receive relocation costs. Successful applicants are expected to start between July and September 2027, with no deferrals. Candidates may use separate emails for application correspondence to preserve privacy. Travel costs for in person appointments may be reasonably reimbursed in line with our Candidate Expenses Policy. Applicants must book and retain receipts for reimbursement. Right to Withdraw Statement We reserve the right to bring forward the closing date for this role at any location once a certain number of applications have been received. Please submit your application promptly to avoid disappointment.
Flexible Working During your initial nine month training period you will commit to full time hours, Monday to Friday (37 hours per week). After that period you may adjust your hours. We offer flexitime, part time, job share and compressed hours. The role is fully office based. Expected Start Dates Between July and September 2027. About Us GCHQ is an intelligence, cyber and security agency dedicated to keeping the UK safe. We use cutting edge technology and partnerships to identify, analyse and disrupt threats, working with MI5 and MI6 to protect the UK from terrorism, cyber attacks and espionage. The role offers varied, interesting work within a supportive, inclusive environment that emphasises teamwork. The role can be based at several locations, including the National Cyber Force (NCF) in Samlesbury. The NCF operates across cyberspace to counter, disrupt and contest those who could threaten the UK or its allies, protecting the UK's interests at home and abroad. The Role As an Intelligence Data Analyst you will support real world events and gain unique insight into what happens behind the news headlines. You will gather information from a variety of sources, including high volumes of data from internet connected devices, and use your analytical and interpretive skills to synthesize this information. Your work may involve short or long term projects, finding and tracking adversaries and using analysis to inform foreign policy, law enforcement and national security. About You You enjoy making sense of complex information and asking questions. Curiosity drives you to investigate further, and you are resilient and persistent. You are eager to learn new things, including emerging technologies, and you do not need a technical background. We welcome people of all ages and backgrounds who offer diverse perspectives. No degree or previous experience is required. All that matters is a Level 2 (GCSE or equivalent) qualification in English Language and Maths at Grade 4/C or above. A higher qualification is welcome but not essential. Training and Development You will start your training in the Comprehensive Analysis Development Programme, which begins immediately after induction. This bespoke programme is designed for new entrants with no intelligence data analysis experience. You will train in a classroom and on the job with tutors, mentors and colleagues, gaining exposure to real life problems. Rewards and Benefits You will receive a starting salary of £37,892 and the following benefits: 25 days annual leave rising to 30 days after five years of service, plus 10.5 public and private holidays Recognition through the employee performance scheme Interest free season ticket loan Excellent pension scheme Cycle to work scheme On site facilities such as a gym, restaurant and coffee bars (selected locations) Paid parental and adoption leave Equal Opportunities GCHQ seeks a diverse workforce that reflects our society, including people of all ages, ethnicities, gender identities, sexual orientations, neurodivergent conditions and those with disabilities. We encourage applications from under represented groups such as women, ethnic minorities, people with disabilities and those from low socio economic backgrounds. We're Disability Confident GCHQ is a Leader in the Department for Work and Pensions' Disability Confident scheme. We aim to provide fair and proportionate opportunities for disabled applicants who meet the essential minimum criteria for this position. Eligibility criteria for interview include a Level 2 qualification in English Language and Maths, passing the online Situational Judgement Test, meeting the minimum pass marks for application questions, bespoke analysis exercise and test, and the analysis test prior to interview. Additional support is available throughout recruitment to allow everyone to perform to their best ability. What to Expect Online Situational Judgement Test (SJT) Initial short online bespoke analysis test Sift - assessment of two application questions, conducted without personal information Longer online bespoke analysis test Virtual interview Each successful stage must be passed to progress to the next. The overall application process can take 6 to 9 months, including vetting. Before You Apply To work at GCHQ you must be a British citizen or hold dual British nationality. The role requires the highest security clearance - Developed Vetting (DV). A strict drugs policy applies: recreational drugs cannot be used during the application process. The role is based in Cheltenham, Manchester or Samlesbury. Applicants must live within a reasonable commuting distance of one of these locations and will not receive relocation costs. Successful applicants are expected to start between July and September 2027, with no deferrals. Candidates may use separate emails for application correspondence to preserve privacy. Travel costs for in person appointments may be reasonably reimbursed in line with our Candidate Expenses Policy. Applicants must book and retain receipts for reimbursement. Right to Withdraw Statement We reserve the right to bring forward the closing date for this role at any location once a certain number of applications have been received. Please submit your application promptly to avoid disappointment.
26/07/2026
Full time
Flexible Working During your initial nine month training period you will commit to full time hours, Monday to Friday (37 hours per week). After that period you may adjust your hours. We offer flexitime, part time, job share and compressed hours. The role is fully office based. Expected Start Dates Between July and September 2027. About Us GCHQ is an intelligence, cyber and security agency dedicated to keeping the UK safe. We use cutting edge technology and partnerships to identify, analyse and disrupt threats, working with MI5 and MI6 to protect the UK from terrorism, cyber attacks and espionage. The role offers varied, interesting work within a supportive, inclusive environment that emphasises teamwork. The role can be based at several locations, including the National Cyber Force (NCF) in Samlesbury. The NCF operates across cyberspace to counter, disrupt and contest those who could threaten the UK or its allies, protecting the UK's interests at home and abroad. The Role As an Intelligence Data Analyst you will support real world events and gain unique insight into what happens behind the news headlines. You will gather information from a variety of sources, including high volumes of data from internet connected devices, and use your analytical and interpretive skills to synthesize this information. Your work may involve short or long term projects, finding and tracking adversaries and using analysis to inform foreign policy, law enforcement and national security. About You You enjoy making sense of complex information and asking questions. Curiosity drives you to investigate further, and you are resilient and persistent. You are eager to learn new things, including emerging technologies, and you do not need a technical background. We welcome people of all ages and backgrounds who offer diverse perspectives. No degree or previous experience is required. All that matters is a Level 2 (GCSE or equivalent) qualification in English Language and Maths at Grade 4/C or above. A higher qualification is welcome but not essential. Training and Development You will start your training in the Comprehensive Analysis Development Programme, which begins immediately after induction. This bespoke programme is designed for new entrants with no intelligence data analysis experience. You will train in a classroom and on the job with tutors, mentors and colleagues, gaining exposure to real life problems. Rewards and Benefits You will receive a starting salary of £37,892 and the following benefits: 25 days annual leave rising to 30 days after five years of service, plus 10.5 public and private holidays Recognition through the employee performance scheme Interest free season ticket loan Excellent pension scheme Cycle to work scheme On site facilities such as a gym, restaurant and coffee bars (selected locations) Paid parental and adoption leave Equal Opportunities GCHQ seeks a diverse workforce that reflects our society, including people of all ages, ethnicities, gender identities, sexual orientations, neurodivergent conditions and those with disabilities. We encourage applications from under represented groups such as women, ethnic minorities, people with disabilities and those from low socio economic backgrounds. We're Disability Confident GCHQ is a Leader in the Department for Work and Pensions' Disability Confident scheme. We aim to provide fair and proportionate opportunities for disabled applicants who meet the essential minimum criteria for this position. Eligibility criteria for interview include a Level 2 qualification in English Language and Maths, passing the online Situational Judgement Test, meeting the minimum pass marks for application questions, bespoke analysis exercise and test, and the analysis test prior to interview. Additional support is available throughout recruitment to allow everyone to perform to their best ability. What to Expect Online Situational Judgement Test (SJT) Initial short online bespoke analysis test Sift - assessment of two application questions, conducted without personal information Longer online bespoke analysis test Virtual interview Each successful stage must be passed to progress to the next. The overall application process can take 6 to 9 months, including vetting. Before You Apply To work at GCHQ you must be a British citizen or hold dual British nationality. The role requires the highest security clearance - Developed Vetting (DV). A strict drugs policy applies: recreational drugs cannot be used during the application process. The role is based in Cheltenham, Manchester or Samlesbury. Applicants must live within a reasonable commuting distance of one of these locations and will not receive relocation costs. Successful applicants are expected to start between July and September 2027, with no deferrals. Candidates may use separate emails for application correspondence to preserve privacy. Travel costs for in person appointments may be reasonably reimbursed in line with our Candidate Expenses Policy. Applicants must book and retain receipts for reimbursement. Right to Withdraw Statement We reserve the right to bring forward the closing date for this role at any location once a certain number of applications have been received. Please submit your application promptly to avoid disappointment.