We are partnered with a growing cyber security business in Buckinghamshire, supporting customers with threat monitoring, incident response, and managed security services. They are looking for a Level 3 SOC Analyst to join their experienced SOC team, leading complex investigations and acting as the technical escalation point for major security incidents. In this Level 3 SOC Analyst role in Buckinghamshire, you will: Lead investigations into complex cyber security incidents across endpoint, network, cloud, and identity environments Carry out proactive threat hunting and help improve detection capabilities across customer estates Act as the technical escalation point for the SOC, supporting major incidents and mentoring junior analysts Help develop detection rules, automate workflows, and continuously improve SOC operations The ideal Level 3 SOC Analyst will have: Strong commercial experience within a SOC, incident response, or cyber security operations environment Experience investigating complex threats including ransomware, malware, account compromise, and targeted attacks Hands-on experience with SIEM, EDR, cloud security, and detection technologies A methodical approach, strong technical judgement, and the ability to remain calm during high-pressure incidents This is a hybrid role (3 days per week at their Buckinghamshire office) with normal office hours, plus participation in an on-call rota for major incidents. It's an excellent opportunity to join a highly technical SOC where you'll play a key role in shaping detection capabilities while mentoring the wider team. For more information on this Level 3 SOC Analyst role in Buckinghamshire, email Ed at (url removed) or call (phone number removed).
Jul 28, 2026
Full time
We are partnered with a growing cyber security business in Buckinghamshire, supporting customers with threat monitoring, incident response, and managed security services. They are looking for a Level 3 SOC Analyst to join their experienced SOC team, leading complex investigations and acting as the technical escalation point for major security incidents. In this Level 3 SOC Analyst role in Buckinghamshire, you will: Lead investigations into complex cyber security incidents across endpoint, network, cloud, and identity environments Carry out proactive threat hunting and help improve detection capabilities across customer estates Act as the technical escalation point for the SOC, supporting major incidents and mentoring junior analysts Help develop detection rules, automate workflows, and continuously improve SOC operations The ideal Level 3 SOC Analyst will have: Strong commercial experience within a SOC, incident response, or cyber security operations environment Experience investigating complex threats including ransomware, malware, account compromise, and targeted attacks Hands-on experience with SIEM, EDR, cloud security, and detection technologies A methodical approach, strong technical judgement, and the ability to remain calm during high-pressure incidents This is a hybrid role (3 days per week at their Buckinghamshire office) with normal office hours, plus participation in an on-call rota for major incidents. It's an excellent opportunity to join a highly technical SOC where you'll play a key role in shaping detection capabilities while mentoring the wider team. For more information on this Level 3 SOC Analyst role in Buckinghamshire, email Ed at (url removed) or call (phone number removed).
hackajob is collaborating with Leonardo to connect them with exceptional professionals for this role. Job Description: Your impact Are you ready to start your career in data engineering and support solutions that underpin secure, high-integrity systems and services? At Leonardo UK, our Data Engineer Technicians assist with data workflows, automation, and integration under the guidance of experienced engineers. Your work at Leonardo UK will see you take the lead in solving customer problems in an agile, innovative and team-centric manner. The role may involve a blended hybrid working model, with a mixture of working from home and working on site at one of our Leonardo offices to ensure close collaboration with the wider team and with our customers. What you will do as a Data Engineer Assist in designing and building secure, scalable data solutions under guidance, progressing to independent tasks. Develop tools for data-driven insights and task automation Research and train in emerging technologies Work with cloud platforms and diverse operating systems Support development and deployment of machine learning models Collaborate with DevOps Engineers, Data Scientists, Analysts and Cyber Consultants Leverage big data technologies and orchestration tools Document processes and maintain configuration records Participate in team meetings and knowledge-sharing sessions What you'll bring Assist in preparing and integrating data across systems. Support ETL processes and basic pipeline testing. Maintain documentation and configuration records. Learn and apply secure coding practices. Ability to work independently on defined tasks and escalate issues when needed Core Areas (must have): Data engineering fundamentals (ETL, pipelines). Programming (Python, SQL). Cloud and orchestration exposure. Documentation and compliance awareness. Collaboration and communication. Desirable: Degree in STEM, Data, AI or Programming-related field Experience to Docker and APIs Familiarity with CI/CD practices Interest in Agile and DevOps practices. Exposure to big data tools e.g. Spark, Hadoop, NiFi Understanding of ML algorithms and deployment This is not an exhaustive list, and we are keen to hear from you even if you might not have experience in all the above. The most important skill is a good attitude and willingness to learn. Security Clearance This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). For more information and guidance please visit: Why join us At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we're here to help you thrive. Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year. Secure your Future: Benefit from our award-winning pension scheme with up to 15% employer contribution. Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks championing inclusion and diversity (Enable, Pride, Equalise, Armed Forces, Carers, Wellbeing and Ethnicity). Rewarding Performance : All employees at management level and below are eligible for our bonus scheme. Never Stop Learning : Free access to 4,000+ online courses via Coursera and LinkedIn Learning. Refer a friend: Receive a financial reward through our referral programme. Tailored Perks : Spend up to £500 annually on flexible benefits including private healthcare, dental, family cover, tech & lifestyle discounts, gym memberships and more. Flexible working: Flexible hours with hybrid working options. For part time opportunities, please talk to us about what might be possible for this role. For a full list of our company benefits please visit our website. Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team-they are key contributors to shaping innovation, advancing technology, and enhancing global safety. At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know. Be part of something bigger - apply now! Primary Location: GB - Bristol - Coldharbour Lane Contract Type: Permanent Hybrid Working: Hybrid
Jul 28, 2026
Full time
hackajob is collaborating with Leonardo to connect them with exceptional professionals for this role. Job Description: Your impact Are you ready to start your career in data engineering and support solutions that underpin secure, high-integrity systems and services? At Leonardo UK, our Data Engineer Technicians assist with data workflows, automation, and integration under the guidance of experienced engineers. Your work at Leonardo UK will see you take the lead in solving customer problems in an agile, innovative and team-centric manner. The role may involve a blended hybrid working model, with a mixture of working from home and working on site at one of our Leonardo offices to ensure close collaboration with the wider team and with our customers. What you will do as a Data Engineer Assist in designing and building secure, scalable data solutions under guidance, progressing to independent tasks. Develop tools for data-driven insights and task automation Research and train in emerging technologies Work with cloud platforms and diverse operating systems Support development and deployment of machine learning models Collaborate with DevOps Engineers, Data Scientists, Analysts and Cyber Consultants Leverage big data technologies and orchestration tools Document processes and maintain configuration records Participate in team meetings and knowledge-sharing sessions What you'll bring Assist in preparing and integrating data across systems. Support ETL processes and basic pipeline testing. Maintain documentation and configuration records. Learn and apply secure coding practices. Ability to work independently on defined tasks and escalate issues when needed Core Areas (must have): Data engineering fundamentals (ETL, pipelines). Programming (Python, SQL). Cloud and orchestration exposure. Documentation and compliance awareness. Collaboration and communication. Desirable: Degree in STEM, Data, AI or Programming-related field Experience to Docker and APIs Familiarity with CI/CD practices Interest in Agile and DevOps practices. Exposure to big data tools e.g. Spark, Hadoop, NiFi Understanding of ML algorithms and deployment This is not an exhaustive list, and we are keen to hear from you even if you might not have experience in all the above. The most important skill is a good attitude and willingness to learn. Security Clearance This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). For more information and guidance please visit: Why join us At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we're here to help you thrive. Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year. Secure your Future: Benefit from our award-winning pension scheme with up to 15% employer contribution. Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks championing inclusion and diversity (Enable, Pride, Equalise, Armed Forces, Carers, Wellbeing and Ethnicity). Rewarding Performance : All employees at management level and below are eligible for our bonus scheme. Never Stop Learning : Free access to 4,000+ online courses via Coursera and LinkedIn Learning. Refer a friend: Receive a financial reward through our referral programme. Tailored Perks : Spend up to £500 annually on flexible benefits including private healthcare, dental, family cover, tech & lifestyle discounts, gym memberships and more. Flexible working: Flexible hours with hybrid working options. For part time opportunities, please talk to us about what might be possible for this role. For a full list of our company benefits please visit our website. Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team-they are key contributors to shaping innovation, advancing technology, and enhancing global safety. At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know. Be part of something bigger - apply now! Primary Location: GB - Bristol - Coldharbour Lane Contract Type: Permanent Hybrid Working: Hybrid
About the Role We are looking for an Entry-Level Cyber Security Analyst to join our growing cyber security consultancy in London. You will support the delivery of cyber security services to clients across a range of industries. This will include vulnerability assessments, security reviews, compliance projects, incident analysis and client reporting. This is a hands-on entry-level position for someone with a strong understanding of cyber security fundamentals who is ready to apply their knowledge in a professional environment. Key Responsibilities Support vulnerability assessments across client systems, networks and applications Investigate security alerts, suspicious activity and potential incidents Document security risks, findings and recommended actions Assist with Cyber Essentials, ISO 27001 and compliance projects Review security policies, procedures and technical controls Prepare professional reports and supporting documentation Research emerging threats, vulnerabilities and security trends Work with senior consultants on client projects and internal assessments Candidate Requirements Degree, qualification or certification in cyber security, IT, computer science or a related subject Good understanding of cyber security principles, networking and operating systems Strong analytical, problem-solving and attention-to-detail skills Good written and verbal communication skills Ability to manage tasks, meet deadlines and work professionally with confidential information Eligible to work in the United Kingdom Knowledge of tools or frameworks such as Nmap, Wireshark, Nessus, Burp Suite, Microsoft Sentinel, Cyber Essentials or ISO 27001 would be beneficial but is not essential. What We Offer A full-time position within a growing cyber security consultancy Exposure to live client projects across technical security, risk and compliance Support from experienced cyber security consultants Career progression and support towards professional certifications Hybrid working opportunities, depending on project requirements Who Should Apply? This role is suitable for graduates, candidates with entry-level cyber security certifications, IT professionals moving into cyber security and applicants with practical knowledge but limited commercial experience. Previous experience in a cyber security role is not essential. Applicants should, however, have a good understanding of cyber security fundamentals and be ready to contribute within a professional consultancy environment. Application Process Please submit your CV together with a brief statement explaining your interest in cyber security and any relevant qualifications, certifications, projects or practical experience.
Jul 26, 2026
Full time
About the Role We are looking for an Entry-Level Cyber Security Analyst to join our growing cyber security consultancy in London. You will support the delivery of cyber security services to clients across a range of industries. This will include vulnerability assessments, security reviews, compliance projects, incident analysis and client reporting. This is a hands-on entry-level position for someone with a strong understanding of cyber security fundamentals who is ready to apply their knowledge in a professional environment. Key Responsibilities Support vulnerability assessments across client systems, networks and applications Investigate security alerts, suspicious activity and potential incidents Document security risks, findings and recommended actions Assist with Cyber Essentials, ISO 27001 and compliance projects Review security policies, procedures and technical controls Prepare professional reports and supporting documentation Research emerging threats, vulnerabilities and security trends Work with senior consultants on client projects and internal assessments Candidate Requirements Degree, qualification or certification in cyber security, IT, computer science or a related subject Good understanding of cyber security principles, networking and operating systems Strong analytical, problem-solving and attention-to-detail skills Good written and verbal communication skills Ability to manage tasks, meet deadlines and work professionally with confidential information Eligible to work in the United Kingdom Knowledge of tools or frameworks such as Nmap, Wireshark, Nessus, Burp Suite, Microsoft Sentinel, Cyber Essentials or ISO 27001 would be beneficial but is not essential. What We Offer A full-time position within a growing cyber security consultancy Exposure to live client projects across technical security, risk and compliance Support from experienced cyber security consultants Career progression and support towards professional certifications Hybrid working opportunities, depending on project requirements Who Should Apply? This role is suitable for graduates, candidates with entry-level cyber security certifications, IT professionals moving into cyber security and applicants with practical knowledge but limited commercial experience. Previous experience in a cyber security role is not essential. Applicants should, however, have a good understanding of cyber security fundamentals and be ready to contribute within a professional consultancy environment. Application Process Please submit your CV together with a brief statement explaining your interest in cyber security and any relevant qualifications, certifications, projects or practical experience.
We re Hiring: Senior Cyber Security Analyst Corsham I m currently looking for a Senior Cyber Security Analyst to join our SOC team at Computer Network Defence Ltd (CND). This is a key hire within our MSSP Security Operations Centre, offering the opportunity to take a lead role in incident analysis, client engagement, and mentoring junior analysts, while shaping how the SOC continues to evolve. The Role As a Senior Cyber Security Analyst, you will support the SOC Team Lead and play a central role in monitoring, triaging, and investigating security events across a range of client environments. You ll be working across SIEM platforms, vulnerability management tools, threat intelligence sources, and network telemetry to deliver effective detection and response. You will also take on client-facing responsibilities, presenting findings, trends, and insights, as well as contributing to reporting and continuous improvement within the SOC. Key Responsibilities Monitor, triage and investigate security alerts across multiple platforms Conduct in-depth incident analysis and support ongoing client investigations Act as deputy to the SOC Team Lead when required Review and assess escalated Tier 2 alerts for urgency and impact Deliver weekly and monthly reporting to clients and stakeholders Communicate security findings and trends directly to clients Support vulnerability management analysis and remediation efforts Lead false-positive reduction and SIEM tuning activities Mentor and support development of Tier 1 and junior analysts Contribute to SOC process improvement and operational efficiency Participate in incident response activities as part of the wider team Lead internal SOC initiatives and projects where required Create and deliver presentations for clients and internal teams What We re Looking For Strong experience within a SOC or cyber security operations environment Proven ability to investigate and analyse complex security incidents Experience with SIEM platforms, threat intelligence, and security tooling Strong stakeholder and client communication skills Ability to mentor and develop junior team members Proactive approach to problem-solving and continuous improvement Good understanding of current cyber threats, tactics and trends Package & Details Location: Isle of Man (relocation package)/Corsham Hours: 37.5 hours per week, plus on-call rota Working pattern: Monday to Friday, 09 00 (early Friday finish at 16:00, workload permitting) Clearance: SC Cleared This is a great opportunity for someone looking to step into a more senior, visible role within a growing SOC, with real influence over both technical delivery and team development.
Jul 24, 2026
Full time
We re Hiring: Senior Cyber Security Analyst Corsham I m currently looking for a Senior Cyber Security Analyst to join our SOC team at Computer Network Defence Ltd (CND). This is a key hire within our MSSP Security Operations Centre, offering the opportunity to take a lead role in incident analysis, client engagement, and mentoring junior analysts, while shaping how the SOC continues to evolve. The Role As a Senior Cyber Security Analyst, you will support the SOC Team Lead and play a central role in monitoring, triaging, and investigating security events across a range of client environments. You ll be working across SIEM platforms, vulnerability management tools, threat intelligence sources, and network telemetry to deliver effective detection and response. You will also take on client-facing responsibilities, presenting findings, trends, and insights, as well as contributing to reporting and continuous improvement within the SOC. Key Responsibilities Monitor, triage and investigate security alerts across multiple platforms Conduct in-depth incident analysis and support ongoing client investigations Act as deputy to the SOC Team Lead when required Review and assess escalated Tier 2 alerts for urgency and impact Deliver weekly and monthly reporting to clients and stakeholders Communicate security findings and trends directly to clients Support vulnerability management analysis and remediation efforts Lead false-positive reduction and SIEM tuning activities Mentor and support development of Tier 1 and junior analysts Contribute to SOC process improvement and operational efficiency Participate in incident response activities as part of the wider team Lead internal SOC initiatives and projects where required Create and deliver presentations for clients and internal teams What We re Looking For Strong experience within a SOC or cyber security operations environment Proven ability to investigate and analyse complex security incidents Experience with SIEM platforms, threat intelligence, and security tooling Strong stakeholder and client communication skills Ability to mentor and develop junior team members Proactive approach to problem-solving and continuous improvement Good understanding of current cyber threats, tactics and trends Package & Details Location: Isle of Man (relocation package)/Corsham Hours: 37.5 hours per week, plus on-call rota Working pattern: Monday to Friday, 09 00 (early Friday finish at 16:00, workload permitting) Clearance: SC Cleared This is a great opportunity for someone looking to step into a more senior, visible role within a growing SOC, with real influence over both technical delivery and team development.
An exciting opportunity has arisen to join our growing ICT Department as a member of the InfoSec team, working in a dynamic and fast-paced environment with new challenges every day, based in our Manchester Head Office. Having rationalised our infrastructure and established a modern, cloud-first security stack, it is an exciting time to join the business as we mature our detection, response, and automation capabilities across a global estate. You will work collaboratively with the business and the wider IT team - Infrastructure, Network, Development, DevOps, and Service Desk - to provide security and governance for existing and new services. The purpose of this role is to deliver the day-to-day security operations of the InfoSec Team and to act as a first point of escalation and support for our Junior and Graduate analysts. Reporting to the Associate Director - Cyber Security, you will work closely with other team members, IT colleagues, and the wider business to ensure a consistent approach to information and cyber security across all areas of IT. You will analyse security events, investigate alerts, identify issues, and recommend and implement solutions, while keeping up to date with current threats, technologies, and techniques. You will be responsible for daily security operations, ensuring risks are identified and resolved in a timely manner. In practice, this means managing tickets and requests through Halo ITSM and working daily with Palo Alto Cortex XSIAM and XSOAR, Cortex XDR, Microsoft Purview, Mimecast, Abnormal, Nessus, and Microsoft 365. You will participate in security investigations and incident response, responding to events involving malware, data loss, phishing, or network intrusion, and supporting our data protection and vulnerability management activity. You will work both independently and collaboratively, sharing knowledge openly and supporting your colleagues across all regions. You will follow security best practice, apply the principles of layered security, and serve as a trusted resource to the wider business on all matters of information and cyber security. This is a customer-facing role, so you will be a strong communicator, able to explain complex concepts clearly to both technical and non-technical audiences, with your input helping to shape and improve our day-to-day monitoring, detection, and response. You will be self-motivated, bringing the knowledge and experience gained in previous roles, genuinely passionate about data and cyber security, and committed to continued learning and professional development. Key Objectives and Responsibilities Daily Operations & Incident Handling Manage day-to-day security tickets, requests, and alerts through Halo ITSM, meeting SLAs and making full use of existing automation. Monitor, triage, and investigate alerts within Palo Alto Cortex XSIAM, responding and escalating as required. Respond to security incidents involving malware, data loss, phishing, or network intrusion, following established playbooks and incident response processes. Manage email security operations across Mimecast and Abnormal, including releases, journal pulls, and reported-phishing investigations. Monitor threat feeds and threat intelligence, applying relevant findings to the environment. Maintain and tune detections, correlation rules, and Cortex XSOAR playbooks to reduce noise and improve response times. Identify opportunities for automation and continual improvement across monitoring and response workflows. Contribute to the development and upkeep of SOC processes, runbooks, and documentation. Run and interpret vulnerability scans using Nessus, tracking remediation through to closure with the relevant teams. Support endpoint security and patch compliance across the Windows and macOS estates, working with Intune, Jamf, Alectrona, and Cortex XDR. Data Protection & Compliance Support and monitor the company's Data Loss Prevention controls within Microsoft Purview, and data classification through Azure Information Protection labelling. Help maintain the evidence and controls that support the company's accreditations, including ISO/IEC 27001, 27017, and 27018, Cyber Essentials Plus, and SOC 2. Learn and apply the principles of risk and information governance within the context of cyber security. Experience and Technical Requirements Two or more years' experience in a cyber security, SOC, or information security analyst role. Experience working within an ISO/IEC 27001 (or equivalent) accredited environment. Familiarity with ITIL service management processes, particularly Incident, Request, Change, and Problem management. Understanding of GDPR, data protection, and information governance. Hands-on experience with a SIEM platform (Cortex XSIAM, Microsoft Sentinel, Splunk, or equivalent). Experience with, or a strong aptitude to learn, SOAR and automation tooling (Cortex XSOAR). Experience with Endpoint Detection and Response (Cortex XDR or an equivalent EDR/XDR platform). Experience with email security platforms (O365, Mimecast, Abnormal, or equivalent). Understanding of Data Loss Prevention and data classification (Microsoft Purview and Azure labelling, or equivalent). Experience with vulnerability scanning and management (Nessus or equivalent). Working knowledge of endpoint management across Windows and macOS (Intune, Jamf). Strong knowledge of cloud environments, including Microsoft Azure, AWS, and Microsoft 365. Understanding of layered security, threat hunting, and incident response. Qualifications A degree in a computer-related subject, or equivalent experience in cyber security. Holding, or actively working towards, relevant industry certifications (e.g. SANS GCIH, EC-Council CEH, ISC2 SSCP, CompTIA CySA+, Blue Team Level 1, Microsoft SC-200, or equivalent), with a genuine commitment to continued professional development. Benefits 25 Days Holiday + Bank Holidays Day off for your birthday Health Shield Cash Plan Cycle to Work Scheme Train Season Ticket Scheme Profit Share Scheme Contributory company pension scheme Access to the Employee Assistance Programme (EAP) 51903MS INDMANS The Portfolio Group are acting on behalf of our client in recruiting for this position.
Jul 22, 2026
Full time
An exciting opportunity has arisen to join our growing ICT Department as a member of the InfoSec team, working in a dynamic and fast-paced environment with new challenges every day, based in our Manchester Head Office. Having rationalised our infrastructure and established a modern, cloud-first security stack, it is an exciting time to join the business as we mature our detection, response, and automation capabilities across a global estate. You will work collaboratively with the business and the wider IT team - Infrastructure, Network, Development, DevOps, and Service Desk - to provide security and governance for existing and new services. The purpose of this role is to deliver the day-to-day security operations of the InfoSec Team and to act as a first point of escalation and support for our Junior and Graduate analysts. Reporting to the Associate Director - Cyber Security, you will work closely with other team members, IT colleagues, and the wider business to ensure a consistent approach to information and cyber security across all areas of IT. You will analyse security events, investigate alerts, identify issues, and recommend and implement solutions, while keeping up to date with current threats, technologies, and techniques. You will be responsible for daily security operations, ensuring risks are identified and resolved in a timely manner. In practice, this means managing tickets and requests through Halo ITSM and working daily with Palo Alto Cortex XSIAM and XSOAR, Cortex XDR, Microsoft Purview, Mimecast, Abnormal, Nessus, and Microsoft 365. You will participate in security investigations and incident response, responding to events involving malware, data loss, phishing, or network intrusion, and supporting our data protection and vulnerability management activity. You will work both independently and collaboratively, sharing knowledge openly and supporting your colleagues across all regions. You will follow security best practice, apply the principles of layered security, and serve as a trusted resource to the wider business on all matters of information and cyber security. This is a customer-facing role, so you will be a strong communicator, able to explain complex concepts clearly to both technical and non-technical audiences, with your input helping to shape and improve our day-to-day monitoring, detection, and response. You will be self-motivated, bringing the knowledge and experience gained in previous roles, genuinely passionate about data and cyber security, and committed to continued learning and professional development. Key Objectives and Responsibilities Daily Operations & Incident Handling Manage day-to-day security tickets, requests, and alerts through Halo ITSM, meeting SLAs and making full use of existing automation. Monitor, triage, and investigate alerts within Palo Alto Cortex XSIAM, responding and escalating as required. Respond to security incidents involving malware, data loss, phishing, or network intrusion, following established playbooks and incident response processes. Manage email security operations across Mimecast and Abnormal, including releases, journal pulls, and reported-phishing investigations. Monitor threat feeds and threat intelligence, applying relevant findings to the environment. Maintain and tune detections, correlation rules, and Cortex XSOAR playbooks to reduce noise and improve response times. Identify opportunities for automation and continual improvement across monitoring and response workflows. Contribute to the development and upkeep of SOC processes, runbooks, and documentation. Run and interpret vulnerability scans using Nessus, tracking remediation through to closure with the relevant teams. Support endpoint security and patch compliance across the Windows and macOS estates, working with Intune, Jamf, Alectrona, and Cortex XDR. Data Protection & Compliance Support and monitor the company's Data Loss Prevention controls within Microsoft Purview, and data classification through Azure Information Protection labelling. Help maintain the evidence and controls that support the company's accreditations, including ISO/IEC 27001, 27017, and 27018, Cyber Essentials Plus, and SOC 2. Learn and apply the principles of risk and information governance within the context of cyber security. Experience and Technical Requirements Two or more years' experience in a cyber security, SOC, or information security analyst role. Experience working within an ISO/IEC 27001 (or equivalent) accredited environment. Familiarity with ITIL service management processes, particularly Incident, Request, Change, and Problem management. Understanding of GDPR, data protection, and information governance. Hands-on experience with a SIEM platform (Cortex XSIAM, Microsoft Sentinel, Splunk, or equivalent). Experience with, or a strong aptitude to learn, SOAR and automation tooling (Cortex XSOAR). Experience with Endpoint Detection and Response (Cortex XDR or an equivalent EDR/XDR platform). Experience with email security platforms (O365, Mimecast, Abnormal, or equivalent). Understanding of Data Loss Prevention and data classification (Microsoft Purview and Azure labelling, or equivalent). Experience with vulnerability scanning and management (Nessus or equivalent). Working knowledge of endpoint management across Windows and macOS (Intune, Jamf). Strong knowledge of cloud environments, including Microsoft Azure, AWS, and Microsoft 365. Understanding of layered security, threat hunting, and incident response. Qualifications A degree in a computer-related subject, or equivalent experience in cyber security. Holding, or actively working towards, relevant industry certifications (e.g. SANS GCIH, EC-Council CEH, ISC2 SSCP, CompTIA CySA+, Blue Team Level 1, Microsoft SC-200, or equivalent), with a genuine commitment to continued professional development. Benefits 25 Days Holiday + Bank Holidays Day off for your birthday Health Shield Cash Plan Cycle to Work Scheme Train Season Ticket Scheme Profit Share Scheme Contributory company pension scheme Access to the Employee Assistance Programme (EAP) 51903MS INDMANS The Portfolio Group are acting on behalf of our client in recruiting for this position.
An exciting opportunity has arisen to join our growing ICT Department as a junior member of the InfoSec team, working in a dynamic and fast-paced environment with new challenges every day, based in our Manchester Head Office. This is an entry-level role offering a structured route into a rewarding cyber security career. With a modern, cloud-first security stack already in place, it is an exciting time to join the business and learn your craft as we mature our detection, response, and automation capabilities across a global estate. You will work alongside the wider IT team - Infrastructure, Network, Development, DevOps, and Service Desk - gaining a rounded understanding of how security supports the business. The purpose of this role is to build a working knowledge of security operations, protective monitoring, and incident handling by working closely with, and learning from, the wider InfoSec team. Reporting to the Associate Director - Cyber Security, with day-to-day guidance from our Cyber Security Analysts and Senior Cyber Security Analyst, you will develop the skills, knowledge, and confidence to grow into a Cyber Security Analyst over time. You will learn to analyse security alerts and incidents, help identify issues, and support the team in recommending solutions, while building familiarity with the tools we use every day - Palo Alto Cortex XSIAM and XSOAR, Cortex XDR, Microsoft Purview, Mimecast, Abnormal, Nessus, and Microsoft 365. You will manage your assigned tickets and requests through Halo ITSM and, under guidance, support our day-to-day security operations to help ensure risks are identified and resolved in a timely manner. You will support security investigations and incident response - learning how we respond to events involving malware, data loss, phishing, or network intrusion - and begin to apply the principles of layered security, risk, and information governance. You will work both independently and collaboratively, sharing what you learn and contributing openly to team projects and meetings across all regions. We are looking for someone bright, enthusiastic, and quick to learn, with a genuine passion for data and cyber security and a real appetite for problem-solving. You will be a developing communicator, self-motivated, and reliable, and you will be actively encouraged and supported to study towards relevant certifications as part of a genuine commitment to continual learning and professional development. Key Objectives and Responsibilities Daily Operations & Incident Handling Work alongside the team to actively support day-to-day security operations and monitoring. Learn to analyse security alerts and incidents within Cortex XSIAM and respond effectively under guidance. Build familiarity with the organisation's SIEM, SOAR, DLP, email security, and endpoint tooling and processes. Use developing analytical skills to help evaluate risks posed by cyber threats and support reporting for decision-making. Manage assigned tickets and requests through Halo ITSM. Strategic & Developmental Duties Learn how to develop effective controls to detect, prevent, and mitigate cyber-attacks. Provide regular status updates to the team and stakeholders. Support the team in preparing documentation, communications, and reports. Learn about risk and information governance within the context of cyber security. Participate in and contribute to relevant project and team meetings. Work towards becoming a recognised contact within the context of the role. Knowledge & Technical Skills A working understanding of cyber-attack techniques, tools, and mitigation controls. Awareness of up-to-date security threats and common exploits. Understanding of threat vectors against Windows, macOS, and Linux platforms. Awareness of anti-virus, anti-malware, and endpoint protection concepts. Familiarity with SIEM concepts (Cortex XSIAM, Microsoft Sentinel, or equivalent). Familiarity with cloud services (Microsoft Azure, Microsoft 365, AWS). Awareness of incident management processes. Understanding of adversary motivations in cybercrime and phishing attacks. Qualifications A degree in Information Security, Computer Science, Computer Forensics, or a similar subject; alternatively, equivalent prior experience or a demonstrable hands-on interest in cyber security. Holding, or actively working towards, an entry-level certification (e.g. ISC2 Certified in Cybersecurity, CompTIA Security+ or Blue Team Level 1) is desirable. Benefits 25 Days Holiday + Bank Holidays Day off for your birthday Health Shield Cash Plan Cycle to Work Scheme Train Season Ticket Scheme Profit Share Scheme Contributory company pension scheme Access to the Employee Assistance Programme (EAP) 51903MS INDMANS The Portfolio Group are acting on behalf of our client in recruiting for this position.
Jul 22, 2026
Full time
An exciting opportunity has arisen to join our growing ICT Department as a junior member of the InfoSec team, working in a dynamic and fast-paced environment with new challenges every day, based in our Manchester Head Office. This is an entry-level role offering a structured route into a rewarding cyber security career. With a modern, cloud-first security stack already in place, it is an exciting time to join the business and learn your craft as we mature our detection, response, and automation capabilities across a global estate. You will work alongside the wider IT team - Infrastructure, Network, Development, DevOps, and Service Desk - gaining a rounded understanding of how security supports the business. The purpose of this role is to build a working knowledge of security operations, protective monitoring, and incident handling by working closely with, and learning from, the wider InfoSec team. Reporting to the Associate Director - Cyber Security, with day-to-day guidance from our Cyber Security Analysts and Senior Cyber Security Analyst, you will develop the skills, knowledge, and confidence to grow into a Cyber Security Analyst over time. You will learn to analyse security alerts and incidents, help identify issues, and support the team in recommending solutions, while building familiarity with the tools we use every day - Palo Alto Cortex XSIAM and XSOAR, Cortex XDR, Microsoft Purview, Mimecast, Abnormal, Nessus, and Microsoft 365. You will manage your assigned tickets and requests through Halo ITSM and, under guidance, support our day-to-day security operations to help ensure risks are identified and resolved in a timely manner. You will support security investigations and incident response - learning how we respond to events involving malware, data loss, phishing, or network intrusion - and begin to apply the principles of layered security, risk, and information governance. You will work both independently and collaboratively, sharing what you learn and contributing openly to team projects and meetings across all regions. We are looking for someone bright, enthusiastic, and quick to learn, with a genuine passion for data and cyber security and a real appetite for problem-solving. You will be a developing communicator, self-motivated, and reliable, and you will be actively encouraged and supported to study towards relevant certifications as part of a genuine commitment to continual learning and professional development. Key Objectives and Responsibilities Daily Operations & Incident Handling Work alongside the team to actively support day-to-day security operations and monitoring. Learn to analyse security alerts and incidents within Cortex XSIAM and respond effectively under guidance. Build familiarity with the organisation's SIEM, SOAR, DLP, email security, and endpoint tooling and processes. Use developing analytical skills to help evaluate risks posed by cyber threats and support reporting for decision-making. Manage assigned tickets and requests through Halo ITSM. Strategic & Developmental Duties Learn how to develop effective controls to detect, prevent, and mitigate cyber-attacks. Provide regular status updates to the team and stakeholders. Support the team in preparing documentation, communications, and reports. Learn about risk and information governance within the context of cyber security. Participate in and contribute to relevant project and team meetings. Work towards becoming a recognised contact within the context of the role. Knowledge & Technical Skills A working understanding of cyber-attack techniques, tools, and mitigation controls. Awareness of up-to-date security threats and common exploits. Understanding of threat vectors against Windows, macOS, and Linux platforms. Awareness of anti-virus, anti-malware, and endpoint protection concepts. Familiarity with SIEM concepts (Cortex XSIAM, Microsoft Sentinel, or equivalent). Familiarity with cloud services (Microsoft Azure, Microsoft 365, AWS). Awareness of incident management processes. Understanding of adversary motivations in cybercrime and phishing attacks. Qualifications A degree in Information Security, Computer Science, Computer Forensics, or a similar subject; alternatively, equivalent prior experience or a demonstrable hands-on interest in cyber security. Holding, or actively working towards, an entry-level certification (e.g. ISC2 Certified in Cybersecurity, CompTIA Security+ or Blue Team Level 1) is desirable. Benefits 25 Days Holiday + Bank Holidays Day off for your birthday Health Shield Cash Plan Cycle to Work Scheme Train Season Ticket Scheme Profit Share Scheme Contributory company pension scheme Access to the Employee Assistance Programme (EAP) 51903MS INDMANS The Portfolio Group are acting on behalf of our client in recruiting for this position.
About the opportunity Complete the free training, gain a qualification and career guidance - no brainer! Are you ready to launch a career in cyber security? Netcom Training s fully-funded Cyber Security course (NCFE Certificate in Principles of Cyber Security, Level 2) equips you with the practical skills employers are actively seeking. From threat intelligence and security testing to incident response and ethical compliance, you ll gain hands-on experience that prepares you for today s fast-growing cyber security and IT roles. Our learners have gone on to roles such as IT support, second line support, junior development, cyber security analysis and business analyst positions, working with companies across tech, logistics, public services and digital sectors. Complete the with, helping you start your career protecting businesses, data and digital systems. What you ll learn Principles: Understand cyber security principles and core frameworks Threat Intelligence: Develop expertise to identify risks Testing: Conduct cyber security testing, identify vulnerabilities and implement controls Incident Response: Prepare for and respond to cyber security incidents Ethics: Understand legislation and ethical conduct within cyber security Professional Skills: Build professional skills and behaviours for the sector Protection: Gain practical knowledge to protect and secure digital environments Potential Roles: Cyber Security Analyst IT Support Technician Junior Penetration Tester SOC Analyst Eligibility To apply, you must: Live in the Sheffield area Be aged 19 or over Earn below the gross annual wage cap of £24,570 Not currently be undertaking other government-funded training Not be in the UK on a student, graduate, postgraduate, or sponsored visa, or as a dependent Cost This is a fully-funded course with no fees complete the training, gain essential cyber security skills.
Jul 22, 2026
Full time
About the opportunity Complete the free training, gain a qualification and career guidance - no brainer! Are you ready to launch a career in cyber security? Netcom Training s fully-funded Cyber Security course (NCFE Certificate in Principles of Cyber Security, Level 2) equips you with the practical skills employers are actively seeking. From threat intelligence and security testing to incident response and ethical compliance, you ll gain hands-on experience that prepares you for today s fast-growing cyber security and IT roles. Our learners have gone on to roles such as IT support, second line support, junior development, cyber security analysis and business analyst positions, working with companies across tech, logistics, public services and digital sectors. Complete the with, helping you start your career protecting businesses, data and digital systems. What you ll learn Principles: Understand cyber security principles and core frameworks Threat Intelligence: Develop expertise to identify risks Testing: Conduct cyber security testing, identify vulnerabilities and implement controls Incident Response: Prepare for and respond to cyber security incidents Ethics: Understand legislation and ethical conduct within cyber security Professional Skills: Build professional skills and behaviours for the sector Protection: Gain practical knowledge to protect and secure digital environments Potential Roles: Cyber Security Analyst IT Support Technician Junior Penetration Tester SOC Analyst Eligibility To apply, you must: Live in the Sheffield area Be aged 19 or over Earn below the gross annual wage cap of £24,570 Not currently be undertaking other government-funded training Not be in the UK on a student, graduate, postgraduate, or sponsored visa, or as a dependent Cost This is a fully-funded course with no fees complete the training, gain essential cyber security skills.
hackajob is collaborating with Leonardo to connect them with exceptional professionals for this role. Job Description: Salary Range: £53,269 - £68,000 Leonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity. Your impact At Leonardo, our Principal Data Engineers lead the design and delivery of secure, scalable data solutions that underpin critical defence, government, and commercial operations. As a technical authority and people manager, you'll guide engineering teams through the full data lifecycle-transforming raw data into actionable insight across hybrid and cloud environments. This role blends technical leadership, stakeholder engagement, and team development, offering the opportunity to shape data strategy and capability across multiple programmes. Your work at Leonardo UK will see you take the lead in solving customer problems in an agile, innovative and team-centric manner. The role may involve a blended hybrid working model, with a mixture of working from home and working on site at one of our Leonardo offices to ensure close collaboration with the wider team and with our customers. What you will do as a Principal Data Engineer Provide technical leadership and oversight for data engineering delivery within your team Lead the design, implementation and maintenance of end-to-end data solutions: acquisition, integration, storage, processing, and analysis Implement scalable data solutions using big data architectures and workflow management systems Guide the development of tools for data-driven insights and task automation Continuously test and monitor systems to improve performance and reliability Research and adopt emerging technologies Work with cloud platforms and diverse operating systems Support development and deployment of machine learning models Collaborate with DevOps Engineers, Data Scientists, Analysts and Cyber Consultants Mentor and coach junior data engineers to build team capability, while managing project tasks across your own and their workloads. Support technology assessments, feasibility studies, and roadmap development Engage with stakeholders and customers, presenting and defending technical solutions Manage a small team of direct reports, providing guidance, mentorship and support for their career development Support the effective operation of the wider team through utilisation tracking, chairing team meetings and resource management What you'll bring Demonstrated leadership in data engineering, with experience managing and mentoring others. Ability to take ownership of engineering delivery and drive team performance. Strong communication and stakeholder engagement skills. A proactive mindset with a commitment to continuous learning and capability development. Proven ability to work across disciplines and collaborate effectively in multi-functional teams. A strategic approach to problem-solving and technical decision-making. Core Areas (must have): Strong Python and SQL skills Experience with ETL flows, data pipelines, and orchestration tools Understanding of database architecture (SQL and NoSQL) Experience with cloud technologies Experience with cloud platforms Experience with CI/CD practices Experience with big data tools e.g. Spark, Hadoop, NiFi Experience managing direct reports, providing regular guidance and performance feedback Ability to create delivery plans with estimated timelines for personal and team workloads Experience supporting ML model deployment and DevOps collaboration Desirable: Degree in STEM, Data, AI, or Programming-related field Awareness of data security best practices Experience with designing data architecture Experience with scaling infrastructure and code, (e.g. Kubernetes) Exposure to Ansible and Terraform Understanding of ML algorithms and deployment This is not an exhaustive list, and we are keen to hear from you even if you might not have experience in all the above. The most important skill is a good attitude and willingness to learn. Security Clearance This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). For more information and guidance please visit: Why join us At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we're here to help you thrive. Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year. Secure your Future: Benefit from our award-winning pension scheme with up to 15% employer contribution. Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks championing inclusion and diversity (Enable, Pride, Equalise, Armed Forces, Carers, Wellbeing and Ethnicity). Rewarding Performance : All employees at management level and below are eligible for our bonus scheme. Never Stop Learning : Free access to 4,000+ online courses via Coursera and LinkedIn Learning. Refer a friend: Receive a financial reward through our referral programme. Tailored Perks : Spend up to £500 annually on flexible benefits including private healthcare, dental, family cover, tech & lifestyle discounts, gym memberships and more. Flexible working: Flexible hours with hybrid working options. For part time opportunities, please talk to us about what might be possible for this role. For a full list of our company benefits please visit our website. Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team-they are key contributors to shaping innovation, advancing technology, and enhancing global safety. At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know. Be part of something bigger - apply now! Primary Location: GB - Bristol - Coldharbour Lane Contract Type: Permanent Hybrid Working: Hybrid
Jul 21, 2026
Full time
hackajob is collaborating with Leonardo to connect them with exceptional professionals for this role. Job Description: Salary Range: £53,269 - £68,000 Leonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity. Your impact At Leonardo, our Principal Data Engineers lead the design and delivery of secure, scalable data solutions that underpin critical defence, government, and commercial operations. As a technical authority and people manager, you'll guide engineering teams through the full data lifecycle-transforming raw data into actionable insight across hybrid and cloud environments. This role blends technical leadership, stakeholder engagement, and team development, offering the opportunity to shape data strategy and capability across multiple programmes. Your work at Leonardo UK will see you take the lead in solving customer problems in an agile, innovative and team-centric manner. The role may involve a blended hybrid working model, with a mixture of working from home and working on site at one of our Leonardo offices to ensure close collaboration with the wider team and with our customers. What you will do as a Principal Data Engineer Provide technical leadership and oversight for data engineering delivery within your team Lead the design, implementation and maintenance of end-to-end data solutions: acquisition, integration, storage, processing, and analysis Implement scalable data solutions using big data architectures and workflow management systems Guide the development of tools for data-driven insights and task automation Continuously test and monitor systems to improve performance and reliability Research and adopt emerging technologies Work with cloud platforms and diverse operating systems Support development and deployment of machine learning models Collaborate with DevOps Engineers, Data Scientists, Analysts and Cyber Consultants Mentor and coach junior data engineers to build team capability, while managing project tasks across your own and their workloads. Support technology assessments, feasibility studies, and roadmap development Engage with stakeholders and customers, presenting and defending technical solutions Manage a small team of direct reports, providing guidance, mentorship and support for their career development Support the effective operation of the wider team through utilisation tracking, chairing team meetings and resource management What you'll bring Demonstrated leadership in data engineering, with experience managing and mentoring others. Ability to take ownership of engineering delivery and drive team performance. Strong communication and stakeholder engagement skills. A proactive mindset with a commitment to continuous learning and capability development. Proven ability to work across disciplines and collaborate effectively in multi-functional teams. A strategic approach to problem-solving and technical decision-making. Core Areas (must have): Strong Python and SQL skills Experience with ETL flows, data pipelines, and orchestration tools Understanding of database architecture (SQL and NoSQL) Experience with cloud technologies Experience with cloud platforms Experience with CI/CD practices Experience with big data tools e.g. Spark, Hadoop, NiFi Experience managing direct reports, providing regular guidance and performance feedback Ability to create delivery plans with estimated timelines for personal and team workloads Experience supporting ML model deployment and DevOps collaboration Desirable: Degree in STEM, Data, AI, or Programming-related field Awareness of data security best practices Experience with designing data architecture Experience with scaling infrastructure and code, (e.g. Kubernetes) Exposure to Ansible and Terraform Understanding of ML algorithms and deployment This is not an exhaustive list, and we are keen to hear from you even if you might not have experience in all the above. The most important skill is a good attitude and willingness to learn. Security Clearance This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). For more information and guidance please visit: Why join us At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we're here to help you thrive. Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year. Secure your Future: Benefit from our award-winning pension scheme with up to 15% employer contribution. Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks championing inclusion and diversity (Enable, Pride, Equalise, Armed Forces, Carers, Wellbeing and Ethnicity). Rewarding Performance : All employees at management level and below are eligible for our bonus scheme. Never Stop Learning : Free access to 4,000+ online courses via Coursera and LinkedIn Learning. Refer a friend: Receive a financial reward through our referral programme. Tailored Perks : Spend up to £500 annually on flexible benefits including private healthcare, dental, family cover, tech & lifestyle discounts, gym memberships and more. Flexible working: Flexible hours with hybrid working options. For part time opportunities, please talk to us about what might be possible for this role. For a full list of our company benefits please visit our website. Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team-they are key contributors to shaping innovation, advancing technology, and enhancing global safety. At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know. Be part of something bigger - apply now! Primary Location: GB - Bristol - Coldharbour Lane Contract Type: Permanent Hybrid Working: Hybrid
Senior Cyber Security Analyst Location: London hybrid working IR35: Inside via Triumph Consultants you will be paid PAYE for the length of the 3 month contract It is essential for candidates to have advanced proficiency in using Splunk for security monitoring, log analysis, threat detection, and reporting The role: The Cyber Defence team at the delivers threat intelligence, threat detection, incident response, and vulnerability management to defend both internal IT infrastructure and citizen-facing services. They are looking for a Senior Cyber Security Analyst with proven experience in incident response and Splunk to take a leading role in strengthening the organisation's cyber defence capability. Key Accountabilities: Lead investigations into security alerts and cyber incidents. Perform forensic analysis of systems, files, network traffic, and cloud environments. Drive technical response actions including containment, eradication, and recovery. Coordinate cyber incident responses across teams and stakeholders. Identify lessons learned and embed continual improvement. Develop and update incident response playbooks and knowledge base articles. Act as an escalation point and mentor for security analysts. Provide leadership and line management within the team. Join the out-of-hours on-call rota to support 24/7 incident response. Key Criteria: 5+ years' experience investigating and responding to cyber incidents in large organisations. Strong track record with incident response coordination. Significant hands-on experience with Splunk and security tools (eg, EDR, SIEM). Analytical, problem-solving, and forensic investigation skills. Proven experience coaching or mentoring junior staff. Strong understanding of threat actor tools, techniques, and procedures. Experience of cloud environments such as AWS Excellent written and verbal communication skills. How to Apply Quote the Job Title and Reference Number in your application. Submit your CV in Word format. Applications are reviewed on a rolling basis-early submission is recommended. We will also add your details to our mail out lists. Please note you may receive details of roles outside of your immediate vicinity, as many candidates are able to relocate temporarily for work. Please disregard any such emails that are not of interest and let us know if you would rather not receive such mailouts and/or if you wish us to delete your details and prefer to apply direct to our advertised roles. If you do not hear from us within three working days, unfortunately your application has not been shortlisted on this occasion. Thank you for your interest in working with us.
Oct 07, 2025
Contractor
Senior Cyber Security Analyst Location: London hybrid working IR35: Inside via Triumph Consultants you will be paid PAYE for the length of the 3 month contract It is essential for candidates to have advanced proficiency in using Splunk for security monitoring, log analysis, threat detection, and reporting The role: The Cyber Defence team at the delivers threat intelligence, threat detection, incident response, and vulnerability management to defend both internal IT infrastructure and citizen-facing services. They are looking for a Senior Cyber Security Analyst with proven experience in incident response and Splunk to take a leading role in strengthening the organisation's cyber defence capability. Key Accountabilities: Lead investigations into security alerts and cyber incidents. Perform forensic analysis of systems, files, network traffic, and cloud environments. Drive technical response actions including containment, eradication, and recovery. Coordinate cyber incident responses across teams and stakeholders. Identify lessons learned and embed continual improvement. Develop and update incident response playbooks and knowledge base articles. Act as an escalation point and mentor for security analysts. Provide leadership and line management within the team. Join the out-of-hours on-call rota to support 24/7 incident response. Key Criteria: 5+ years' experience investigating and responding to cyber incidents in large organisations. Strong track record with incident response coordination. Significant hands-on experience with Splunk and security tools (eg, EDR, SIEM). Analytical, problem-solving, and forensic investigation skills. Proven experience coaching or mentoring junior staff. Strong understanding of threat actor tools, techniques, and procedures. Experience of cloud environments such as AWS Excellent written and verbal communication skills. How to Apply Quote the Job Title and Reference Number in your application. Submit your CV in Word format. Applications are reviewed on a rolling basis-early submission is recommended. We will also add your details to our mail out lists. Please note you may receive details of roles outside of your immediate vicinity, as many candidates are able to relocate temporarily for work. Please disregard any such emails that are not of interest and let us know if you would rather not receive such mailouts and/or if you wish us to delete your details and prefer to apply direct to our advertised roles. If you do not hear from us within three working days, unfortunately your application has not been shortlisted on this occasion. Thank you for your interest in working with us.
We are currently recruiting for Senior Cyber Security Analysts and Associate Security Analysts - both working a 3-month contract for our client 3 days per week on-site in London. As a senior security analyst with responsibility for incident response, you will: lead the investigation of security alerts to understand the nature and extent of possible cyber incidents lead the forensic analysis of systems, files, network traffic and cloud environments lead the technical response to cyber incidents by identifying and implementing (or coordinating the implementation of) containment, eradication and recovery actions support the wider coordination of cyber incidents review previous incidents to identify lessons and actions identify and deliver opportunities for continual improvement of the incident response capability work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities develop and update internal plans, playbooks and knowledge base articles act as an escalation point for, and provide coaching and mentoring to, security analysts be responsible for leadership and line management of security analysts Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join. We're interested in people who have: significant experience investigating and responding to cyber incidents significant experience using security tools (eg, EDR, SIEM) to support the investigation and response to cyber incidents experience managing and coordinating the response to cyber incidents experience coaching and mentoring junior staff an in-depth understanding of the tools, techniques and procedures used by threat actors excellent analytical and problem solving skills excellent verbal and written communication skills It's desirable, but not essential, that you have: experience with Splunk experience working in an Agile environment experience with cloud environments such as AWS As an associate security analyst you will: triage and investigate cyber security alerts and reports from users use a variety of techniques to analyse systems, files, network traffic and cloud environments and understand the nature and extent of possible cyber incidents support the technical response to cyber incidents by identifying and implementing (or supporting the implementation of) containment, eradication and recovery actions support the coordination of cyber incidents contribute to post-incident reviews to identify lessons and actions identify opportunities for, and support the delivery of, continual improvements to the incident investigation and response capability work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities contribute to internal plans, playbooks and knowledge base articles act as an escalation point for, and provide coaching and mentoring to, apprentice security analysts be responsible for line management of apprentice security analysts Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join We're interested in people who have: experience investigating and responding to cyber incidents experience using security tools (eg, EDR, SIEM) to support the investigation and response to cyber incidents Experience with SIEM tools (experience of Splunk preferred but experience of Microsoft Sentinel or an equivalent SIEM tool is acceptable) an understanding of the tools, techniques and procedures commonly used by threat actors good analytical and problem-solving skills good verbal and written communication skills It's desirable, but not essential, that you have: experience with Splunk experience working in an Agile environment experience with cloud environments such as AWS If you feel you have the skills and experience needed for this role; please do apply now.
Oct 06, 2025
Contractor
We are currently recruiting for Senior Cyber Security Analysts and Associate Security Analysts - both working a 3-month contract for our client 3 days per week on-site in London. As a senior security analyst with responsibility for incident response, you will: lead the investigation of security alerts to understand the nature and extent of possible cyber incidents lead the forensic analysis of systems, files, network traffic and cloud environments lead the technical response to cyber incidents by identifying and implementing (or coordinating the implementation of) containment, eradication and recovery actions support the wider coordination of cyber incidents review previous incidents to identify lessons and actions identify and deliver opportunities for continual improvement of the incident response capability work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities develop and update internal plans, playbooks and knowledge base articles act as an escalation point for, and provide coaching and mentoring to, security analysts be responsible for leadership and line management of security analysts Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join. We're interested in people who have: significant experience investigating and responding to cyber incidents significant experience using security tools (eg, EDR, SIEM) to support the investigation and response to cyber incidents experience managing and coordinating the response to cyber incidents experience coaching and mentoring junior staff an in-depth understanding of the tools, techniques and procedures used by threat actors excellent analytical and problem solving skills excellent verbal and written communication skills It's desirable, but not essential, that you have: experience with Splunk experience working in an Agile environment experience with cloud environments such as AWS As an associate security analyst you will: triage and investigate cyber security alerts and reports from users use a variety of techniques to analyse systems, files, network traffic and cloud environments and understand the nature and extent of possible cyber incidents support the technical response to cyber incidents by identifying and implementing (or supporting the implementation of) containment, eradication and recovery actions support the coordination of cyber incidents contribute to post-incident reviews to identify lessons and actions identify opportunities for, and support the delivery of, continual improvements to the incident investigation and response capability work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities contribute to internal plans, playbooks and knowledge base articles act as an escalation point for, and provide coaching and mentoring to, apprentice security analysts be responsible for line management of apprentice security analysts Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join We're interested in people who have: experience investigating and responding to cyber incidents experience using security tools (eg, EDR, SIEM) to support the investigation and response to cyber incidents Experience with SIEM tools (experience of Splunk preferred but experience of Microsoft Sentinel or an equivalent SIEM tool is acceptable) an understanding of the tools, techniques and procedures commonly used by threat actors good analytical and problem-solving skills good verbal and written communication skills It's desirable, but not essential, that you have: experience with Splunk experience working in an Agile environment experience with cloud environments such as AWS If you feel you have the skills and experience needed for this role; please do apply now.
Senior Cyber Security Analyst - Central Gov (Contract) Incident Response | Threat Detection | Forensics | SIEM The Cyber Defence team is hiring a Senior Cyber Security Analyst to lead on incident response and protect critical citizen-facing services. You'll: Investigate and respond to cyber incidents at scale Lead forensic analysis (systems, files, network, cloud) Coordinate containment, eradication & recovery actions Mentor Junior Analysts and shape IR playbooks Must have strong Splunk skills. Requirements: Strong incident response & cyber investigation experience Skilled with EDR/SIEM tools - splunk Deep knowledge of attacker TTPs Excellent problem solving & communication London | Competitive Day Rate | SC Clearance required | On-call rota
Oct 03, 2025
Contractor
Senior Cyber Security Analyst - Central Gov (Contract) Incident Response | Threat Detection | Forensics | SIEM The Cyber Defence team is hiring a Senior Cyber Security Analyst to lead on incident response and protect critical citizen-facing services. You'll: Investigate and respond to cyber incidents at scale Lead forensic analysis (systems, files, network, cloud) Coordinate containment, eradication & recovery actions Mentor Junior Analysts and shape IR playbooks Must have strong Splunk skills. Requirements: Strong incident response & cyber investigation experience Skilled with EDR/SIEM tools - splunk Deep knowledge of attacker TTPs Excellent problem solving & communication London | Competitive Day Rate | SC Clearance required | On-call rota
*Senior Cyber Security Analyst - £600-800pd (experience dependent) INSIDE IR35 - 3 month initial contract - London (3 days per week onsite)* Please note: Due to the nature of the role, we are ideally looking for candidates to hold an active SC clearance. We are looking for a SC Cleared Senior Cyber Security Analyst with SPLUNK experience to join our central government client on an initial 3-month contract. You must have experience investigating and responding to cyber incidents, co-ordinating incident response in a large organisation. We have both a Senior and mid-level role available. Main responsibilities: As a senior security analyst with responsibility for incident response, you will: Lead the investigation of security alerts to understand the nature and extent of possible cyber incidents Lead the forensic analysis of systems, files, network traffic and cloud environment Lead the technical response to cyber incidents by identifying and implementing (or coordinating the implementation of) containment, eradication and recovery actions Support the wider coordination of cyber incidents Review previous incidents to identify lessons and actions Identify and deliver opportunities for continual improvement of the incident response capability Work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities Develop and update internal plans, playbooks and knowledge base articles Act as an escalation point for, and provide coaching and mentoring to, security analysts Be responsible for leadership and line management of security analysts Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join. Essential skills and experience: SPLUNK EDR (Endpoint Detection and Response) Significant experience investigating and responding to cyber incidents Significant experience using security tools (eg, EDR, SIEM) to support the investigation and response to cyber incidents Experience managing and coordinating the response to cyber incidents Experience coaching and mentoring junior staff An in-depth understanding of the tools, techniques and procedures used by threat actors Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy which can be found on our website. Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and ability to perform the duties of the job. Damia Group is acting as an Employment Business in relation to this vacancy and in accordance to Conduct Regulations 2003.
Oct 03, 2025
Contractor
*Senior Cyber Security Analyst - £600-800pd (experience dependent) INSIDE IR35 - 3 month initial contract - London (3 days per week onsite)* Please note: Due to the nature of the role, we are ideally looking for candidates to hold an active SC clearance. We are looking for a SC Cleared Senior Cyber Security Analyst with SPLUNK experience to join our central government client on an initial 3-month contract. You must have experience investigating and responding to cyber incidents, co-ordinating incident response in a large organisation. We have both a Senior and mid-level role available. Main responsibilities: As a senior security analyst with responsibility for incident response, you will: Lead the investigation of security alerts to understand the nature and extent of possible cyber incidents Lead the forensic analysis of systems, files, network traffic and cloud environment Lead the technical response to cyber incidents by identifying and implementing (or coordinating the implementation of) containment, eradication and recovery actions Support the wider coordination of cyber incidents Review previous incidents to identify lessons and actions Identify and deliver opportunities for continual improvement of the incident response capability Work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities Develop and update internal plans, playbooks and knowledge base articles Act as an escalation point for, and provide coaching and mentoring to, security analysts Be responsible for leadership and line management of security analysts Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join. Essential skills and experience: SPLUNK EDR (Endpoint Detection and Response) Significant experience investigating and responding to cyber incidents Significant experience using security tools (eg, EDR, SIEM) to support the investigation and response to cyber incidents Experience managing and coordinating the response to cyber incidents Experience coaching and mentoring junior staff An in-depth understanding of the tools, techniques and procedures used by threat actors Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy which can be found on our website. Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and ability to perform the duties of the job. Damia Group is acting as an Employment Business in relation to this vacancy and in accordance to Conduct Regulations 2003.
Senior Cyber Security Analyst - Government, Splunk, EDR, Defence, AWS, Hybrid, London, SC Clearance, £800 pd We are seeking an experienced SC cleared Senior Cyber Security Analyst to lead incident response efforts within a dynamic cyber defence team. The ideal candidate will have a strong background in investigating, managing, and responding to cyber threats, with a focus on incident containment and forensic analysis. Key Responsibilities: Lead investigations into security alerts to determine the nature and scope of potential cyber incidents Conduct forensic analysis across systems, network traffic, files, and cloud environments Manage technical responses, including containment, eradication, and recovery actions Support the coordination and management of cyber incident responses Review incidents post-event to identify lessons learned and areas for improvement Develop and maintain incident response plans, playbooks, and knowledge resources Lead and line-manage security team members Experience & Skills Needed: Extensive experience investigating and responding to cyber incidents Proficiency with security tools such as EDR and SIEM platforms Proven track record of managing and coordinating incident response activities Experience in mentoring and coaching junior staff Strong understanding of threat actor techniques, tools, and tactics Excellent analytical, problem-solving, and communication skills Experience with Splunk or similar log management tools Familiarity with Agile working practices Knowledge of cloud platforms such as AWS If you possess the relevant experience and are ready to lead critical cyber defence initiatives, we encourage you to apply. Minorities, women, LGBTQ+ candidates, and individuals with disabilities are encouraged to apply. Interviews will take place next week, so please apply immediately to be considered for this contract role.
Oct 03, 2025
Contractor
Senior Cyber Security Analyst - Government, Splunk, EDR, Defence, AWS, Hybrid, London, SC Clearance, £800 pd We are seeking an experienced SC cleared Senior Cyber Security Analyst to lead incident response efforts within a dynamic cyber defence team. The ideal candidate will have a strong background in investigating, managing, and responding to cyber threats, with a focus on incident containment and forensic analysis. Key Responsibilities: Lead investigations into security alerts to determine the nature and scope of potential cyber incidents Conduct forensic analysis across systems, network traffic, files, and cloud environments Manage technical responses, including containment, eradication, and recovery actions Support the coordination and management of cyber incident responses Review incidents post-event to identify lessons learned and areas for improvement Develop and maintain incident response plans, playbooks, and knowledge resources Lead and line-manage security team members Experience & Skills Needed: Extensive experience investigating and responding to cyber incidents Proficiency with security tools such as EDR and SIEM platforms Proven track record of managing and coordinating incident response activities Experience in mentoring and coaching junior staff Strong understanding of threat actor techniques, tools, and tactics Excellent analytical, problem-solving, and communication skills Experience with Splunk or similar log management tools Familiarity with Agile working practices Knowledge of cloud platforms such as AWS If you possess the relevant experience and are ready to lead critical cyber defence initiatives, we encourage you to apply. Minorities, women, LGBTQ+ candidates, and individuals with disabilities are encouraged to apply. Interviews will take place next week, so please apply immediately to be considered for this contract role.
Job Title: Senior Cyber Security Analyst - SC Location : Hybrid/London - 3 days a week on site Contract Duration : 3 months initially Daily Rate: £800/day (Umbrella - Maximum) IR35 Status: Inside IR35 Minimum requirement: Experience of investigating and responding to cyber incidents, coordinating incident response in large org 5+ years' experience with SPLUNK EDR (Endpoint Detection and Response) Analytical, problem solving Security Clearance: SC Senior Cyber Security Analyst The Cyber Defence team delivers cyber threat intelligence, threat detection, incident response and Vulnerability management capabilities for the organisation, and is responsible for defending both internal IT infrastructure and citizen-facing services. As a senior security analyst, you'll take a leading role in building and delivering these core capabilities, focusing on incident response. As a senior security analyst with responsibility for incident response, you will l: Lead the investigation of security alerts to understand the nature and extent of possible cyber incidents Lead the forensic analysis of systems, files, network traffic and cloud environments Lead the technical response to cyber incidents by identifying and implementing (or coordinating the implementation of) containment, eradication and recovery actions Support the wider coordination of cyber incidents Review previous incidents to identify lessons and actions Identify and deliver opportunities for continual improvement of the incident response capability Work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities Develop and update internal plans, playbooks and knowledge base articles Act as an escalation point for, and provide coaching and mentoring to, security analysts Be responsible for leadership and line management of security analysts Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join. We're interested in people who have: Significant experience investigating and responding to cyber incidents Significant experience using security tools (eg, EDR, SIEM) to support the investigation and response to cyber incidents Experience managing and coordinating the response to cyber incidents Experience coaching and mentoring junior staff An in-depth understanding of the tools, techniques and procedures used by threat actors Excellent analytical and problem solving skills Excellent verbal and written communication skills Experience with Splunk Experience working in an Agile environment Experience with cloud environments such as AWS Disability Confident As a member of the disability confident scheme, CLIENT guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Armed Forces Covenant CLIENT is proud to support the Armed Forces Covenant and as such, we guarantee to interview all veterans or spouses/partners of military personnel who meet all the essential criteria for the vacancy. In cases where we have a high volume of ex-military candidates/military spouses or partners, who meet all of the essential criteria, we will interview the best candidates from within that group. If you qualify for the above, please notify us. We will be in touch to discuss your suitability and arrange your Guaranteed Interview. Should you require reasonable adjustments at any point during the recruitment process or if there is a more accessible way for us to communicate, please do let me know. To apply for this role please submit your latest CV or contact Aspect Resources
Oct 03, 2025
Contractor
Job Title: Senior Cyber Security Analyst - SC Location : Hybrid/London - 3 days a week on site Contract Duration : 3 months initially Daily Rate: £800/day (Umbrella - Maximum) IR35 Status: Inside IR35 Minimum requirement: Experience of investigating and responding to cyber incidents, coordinating incident response in large org 5+ years' experience with SPLUNK EDR (Endpoint Detection and Response) Analytical, problem solving Security Clearance: SC Senior Cyber Security Analyst The Cyber Defence team delivers cyber threat intelligence, threat detection, incident response and Vulnerability management capabilities for the organisation, and is responsible for defending both internal IT infrastructure and citizen-facing services. As a senior security analyst, you'll take a leading role in building and delivering these core capabilities, focusing on incident response. As a senior security analyst with responsibility for incident response, you will l: Lead the investigation of security alerts to understand the nature and extent of possible cyber incidents Lead the forensic analysis of systems, files, network traffic and cloud environments Lead the technical response to cyber incidents by identifying and implementing (or coordinating the implementation of) containment, eradication and recovery actions Support the wider coordination of cyber incidents Review previous incidents to identify lessons and actions Identify and deliver opportunities for continual improvement of the incident response capability Work closely alongside other Cyber Defence functions, supporting the continual improvement of wider capabilities Develop and update internal plans, playbooks and knowledge base articles Act as an escalation point for, and provide coaching and mentoring to, security analysts Be responsible for leadership and line management of security analysts Cyber incidents can and do arise on a 24/7 basis. The team operates an out-of-hours on call rota, which you will be expected to join. We're interested in people who have: Significant experience investigating and responding to cyber incidents Significant experience using security tools (eg, EDR, SIEM) to support the investigation and response to cyber incidents Experience managing and coordinating the response to cyber incidents Experience coaching and mentoring junior staff An in-depth understanding of the tools, techniques and procedures used by threat actors Excellent analytical and problem solving skills Excellent verbal and written communication skills Experience with Splunk Experience working in an Agile environment Experience with cloud environments such as AWS Disability Confident As a member of the disability confident scheme, CLIENT guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Armed Forces Covenant CLIENT is proud to support the Armed Forces Covenant and as such, we guarantee to interview all veterans or spouses/partners of military personnel who meet all the essential criteria for the vacancy. In cases where we have a high volume of ex-military candidates/military spouses or partners, who meet all of the essential criteria, we will interview the best candidates from within that group. If you qualify for the above, please notify us. We will be in touch to discuss your suitability and arrange your Guaranteed Interview. Should you require reasonable adjustments at any point during the recruitment process or if there is a more accessible way for us to communicate, please do let me know. To apply for this role please submit your latest CV or contact Aspect Resources
Job Title: Cyber Security Incident Response Specialist Location: London, Wokingham, or Warwick (2 days per week onsite - hybrid working) Contract Duration: 6months + initially, with high potential for extension (long-term programme) Clearance: SC required or eligible THIS PROJECT IS INSIDE IR35 Project Overview: We are looking for an experienced Cyber Security Incident Response Specialist to join a high-impact security programme supporting the resilience of UK critical national infrastructure (CNI) . You'll join a team responsible for responding to cyber threats across both cyber and physical domains - helping to manage the full incident life cycle, improve response maturity, and develop scalable IR documentation and exercises. This is a specialist role for someone with real-world IR experience and the ability to assess, escalate, and coordinate technical and business responses. Key Responsibilities: Lead or support incident response (IR) activities across the full life cycle: detection, triage, containment, eradication, recovery, and lessons learned Develop and maintain IR playbooks, plans, and post-incident reports Support post-incident reviews , including root cause analysis (RCA) and lessons learned sessions Design and deliver incident response exercises (eg tabletop simulations) Act as a subject matter expert (SME) for incident response processes and frameworks Collaborate with SOC teams, technical SMEs, and non-technical stakeholders Communicate IR outcomes effectively via reports, presentations, and briefings Build working relationships across internal security functions and external CNI/regulatory stakeholders Mandatory Requirements (Must-Have): Strong, recent experience in cybersecurity incident response Ability to make informed decisions during incidents (triage, escalate, communicate) Experience working in Critical National Infrastructure (CNI) sectors - eg utilities, energy, telco, banking, health, defence, or transport Working knowledge of NIST, MITRE ATT&CK , or equivalent frameworks Proven ability to communicate IR findings to technical and non-technical audiences Experience contributing to or owning IR playbooks, SOPs, or RCA documentation Must hold current SC clearance or have been previously cleared within the last 12-18 months Desirable Skills (Nice-to-Have): Experience within the energy or utilities sector Exposure to OT/ICS environments (eg SCADA, PLCs, DCS) Experience delivering or supporting tabletop IR exercises Familiarity with tools like Microsoft Sentinel, Defender, Splunk, QRadar, Tenable, CrowdStrike, etc. Industry certifications such as CISSP, GCFA, GEIR, CCIM, CISM, CEH , or equivalent What We're Not Looking For: Junior SOC analysts (L1/L2 triage only) Generalist cyber roles without deep IR exposure Candidates without experience in CNI or enterprise-scale IR
Oct 01, 2025
Contractor
Job Title: Cyber Security Incident Response Specialist Location: London, Wokingham, or Warwick (2 days per week onsite - hybrid working) Contract Duration: 6months + initially, with high potential for extension (long-term programme) Clearance: SC required or eligible THIS PROJECT IS INSIDE IR35 Project Overview: We are looking for an experienced Cyber Security Incident Response Specialist to join a high-impact security programme supporting the resilience of UK critical national infrastructure (CNI) . You'll join a team responsible for responding to cyber threats across both cyber and physical domains - helping to manage the full incident life cycle, improve response maturity, and develop scalable IR documentation and exercises. This is a specialist role for someone with real-world IR experience and the ability to assess, escalate, and coordinate technical and business responses. Key Responsibilities: Lead or support incident response (IR) activities across the full life cycle: detection, triage, containment, eradication, recovery, and lessons learned Develop and maintain IR playbooks, plans, and post-incident reports Support post-incident reviews , including root cause analysis (RCA) and lessons learned sessions Design and deliver incident response exercises (eg tabletop simulations) Act as a subject matter expert (SME) for incident response processes and frameworks Collaborate with SOC teams, technical SMEs, and non-technical stakeholders Communicate IR outcomes effectively via reports, presentations, and briefings Build working relationships across internal security functions and external CNI/regulatory stakeholders Mandatory Requirements (Must-Have): Strong, recent experience in cybersecurity incident response Ability to make informed decisions during incidents (triage, escalate, communicate) Experience working in Critical National Infrastructure (CNI) sectors - eg utilities, energy, telco, banking, health, defence, or transport Working knowledge of NIST, MITRE ATT&CK , or equivalent frameworks Proven ability to communicate IR findings to technical and non-technical audiences Experience contributing to or owning IR playbooks, SOPs, or RCA documentation Must hold current SC clearance or have been previously cleared within the last 12-18 months Desirable Skills (Nice-to-Have): Experience within the energy or utilities sector Exposure to OT/ICS environments (eg SCADA, PLCs, DCS) Experience delivering or supporting tabletop IR exercises Familiarity with tools like Microsoft Sentinel, Defender, Splunk, QRadar, Tenable, CrowdStrike, etc. Industry certifications such as CISSP, GCFA, GEIR, CCIM, CISM, CEH , or equivalent What We're Not Looking For: Junior SOC analysts (L1/L2 triage only) Generalist cyber roles without deep IR exposure Candidates without experience in CNI or enterprise-scale IR
Launch Your Cyber Security Career - Job Guaranteed! Cyber attacks are rising, and companies need skilled professionals now more than ever. With Newto Training's Cyber Security Career Programme, you'll gain 4 top certifications (Azure Fundamentals, CompTIA Security+, CompTIA CySA+, Forescout FSCA) plus real-world project work that doubles as hands-on experience. 100+ hours of live training Practical skills in troubleshooting, networking (Cisco), Azure cloud, Splunk SIEM & Tenable vulnerability management Job guarantee with our hiring partners Get certified, get experience, get hired. Apply today and start your journey into cyber security. Course cost - £2795, or, £232.91 per month We guarantee you will be offered a job upon completion, or we will refund you 100% of your course fees.
Sep 23, 2025
Full time
Launch Your Cyber Security Career - Job Guaranteed! Cyber attacks are rising, and companies need skilled professionals now more than ever. With Newto Training's Cyber Security Career Programme, you'll gain 4 top certifications (Azure Fundamentals, CompTIA Security+, CompTIA CySA+, Forescout FSCA) plus real-world project work that doubles as hands-on experience. 100+ hours of live training Practical skills in troubleshooting, networking (Cisco), Azure cloud, Splunk SIEM & Tenable vulnerability management Job guarantee with our hiring partners Get certified, get experience, get hired. Apply today and start your journey into cyber security. Course cost - £2795, or, £232.91 per month We guarantee you will be offered a job upon completion, or we will refund you 100% of your course fees.