An exciting opportunity has arisen to join our growing ICT Department as a member of the InfoSec team, working in a dynamic and fast-paced environment with new challenges every day, based in our Manchester Head Office. Having rationalised our infrastructure and established a modern, cloud-first security stack, it is an exciting time to join the business as we mature our detection, response, and automation capabilities across a global estate. You will work collaboratively with the business and the wider IT team - Infrastructure, Network, Development, DevOps, and Service Desk - to provide security and governance for existing and new services. The purpose of this role is to deliver the day-to-day security operations of the InfoSec Team and to act as a first point of escalation and support for our Junior and Graduate analysts. Reporting to the Associate Director - Cyber Security, you will work closely with other team members, IT colleagues, and the wider business to ensure a consistent approach to information and cyber security across all areas of IT. You will analyse security events, investigate alerts, identify issues, and recommend and implement solutions, while keeping up to date with current threats, technologies, and techniques. You will be responsible for daily security operations, ensuring risks are identified and resolved in a timely manner. In practice, this means managing tickets and requests through Halo ITSM and working daily with Palo Alto Cortex XSIAM and XSOAR, Cortex XDR, Microsoft Purview, Mimecast, Abnormal, Nessus, and Microsoft 365. You will participate in security investigations and incident response, responding to events involving malware, data loss, phishing, or network intrusion, and supporting our data protection and vulnerability management activity. You will work both independently and collaboratively, sharing knowledge openly and supporting your colleagues across all regions. You will follow security best practice, apply the principles of layered security, and serve as a trusted resource to the wider business on all matters of information and cyber security. This is a customer-facing role, so you will be a strong communicator, able to explain complex concepts clearly to both technical and non-technical audiences, with your input helping to shape and improve our day-to-day monitoring, detection, and response. You will be self-motivated, bringing the knowledge and experience gained in previous roles, genuinely passionate about data and cyber security, and committed to continued learning and professional development. Key Objectives and Responsibilities Daily Operations & Incident Handling Manage day-to-day security tickets, requests, and alerts through Halo ITSM, meeting SLAs and making full use of existing automation. Monitor, triage, and investigate alerts within Palo Alto Cortex XSIAM, responding and escalating as required. Respond to security incidents involving malware, data loss, phishing, or network intrusion, following established playbooks and incident response processes. Manage email security operations across Mimecast and Abnormal, including releases, journal pulls, and reported-phishing investigations. Monitor threat feeds and threat intelligence, applying relevant findings to the environment. Maintain and tune detections, correlation rules, and Cortex XSOAR playbooks to reduce noise and improve response times. Identify opportunities for automation and continual improvement across monitoring and response workflows. Contribute to the development and upkeep of SOC processes, runbooks, and documentation. Run and interpret vulnerability scans using Nessus, tracking remediation through to closure with the relevant teams. Support endpoint security and patch compliance across the Windows and macOS estates, working with Intune, Jamf, Alectrona, and Cortex XDR. Data Protection & Compliance Support and monitor the company's Data Loss Prevention controls within Microsoft Purview, and data classification through Azure Information Protection labelling. Help maintain the evidence and controls that support the company's accreditations, including ISO/IEC 27001, 27017, and 27018, Cyber Essentials Plus, and SOC 2. Learn and apply the principles of risk and information governance within the context of cyber security. Experience and Technical Requirements Two or more years' experience in a cyber security, SOC, or information security analyst role. Experience working within an ISO/IEC 27001 (or equivalent) accredited environment. Familiarity with ITIL service management processes, particularly Incident, Request, Change, and Problem management. Understanding of GDPR, data protection, and information governance. Hands-on experience with a SIEM platform (Cortex XSIAM, Microsoft Sentinel, Splunk, or equivalent). Experience with, or a strong aptitude to learn, SOAR and automation tooling (Cortex XSOAR). Experience with Endpoint Detection and Response (Cortex XDR or an equivalent EDR/XDR platform). Experience with email security platforms (O365, Mimecast, Abnormal, or equivalent). Understanding of Data Loss Prevention and data classification (Microsoft Purview and Azure labelling, or equivalent). Experience with vulnerability scanning and management (Nessus or equivalent). Working knowledge of endpoint management across Windows and macOS (Intune, Jamf). Strong knowledge of cloud environments, including Microsoft Azure, AWS, and Microsoft 365. Understanding of layered security, threat hunting, and incident response. Qualifications A degree in a computer-related subject, or equivalent experience in cyber security. Holding, or actively working towards, relevant industry certifications (e.g. SANS GCIH, EC-Council CEH, ISC2 SSCP, CompTIA CySA+, Blue Team Level 1, Microsoft SC-200, or equivalent), with a genuine commitment to continued professional development. Benefits 25 Days Holiday + Bank Holidays Day off for your birthday Health Shield Cash Plan Cycle to Work Scheme Train Season Ticket Scheme Profit Share Scheme Contributory company pension scheme Access to the Employee Assistance Programme (EAP) 51903MS INDMANS The Portfolio Group are acting on behalf of our client in recruiting for this position.
Jul 22, 2026
Full time
An exciting opportunity has arisen to join our growing ICT Department as a member of the InfoSec team, working in a dynamic and fast-paced environment with new challenges every day, based in our Manchester Head Office. Having rationalised our infrastructure and established a modern, cloud-first security stack, it is an exciting time to join the business as we mature our detection, response, and automation capabilities across a global estate. You will work collaboratively with the business and the wider IT team - Infrastructure, Network, Development, DevOps, and Service Desk - to provide security and governance for existing and new services. The purpose of this role is to deliver the day-to-day security operations of the InfoSec Team and to act as a first point of escalation and support for our Junior and Graduate analysts. Reporting to the Associate Director - Cyber Security, you will work closely with other team members, IT colleagues, and the wider business to ensure a consistent approach to information and cyber security across all areas of IT. You will analyse security events, investigate alerts, identify issues, and recommend and implement solutions, while keeping up to date with current threats, technologies, and techniques. You will be responsible for daily security operations, ensuring risks are identified and resolved in a timely manner. In practice, this means managing tickets and requests through Halo ITSM and working daily with Palo Alto Cortex XSIAM and XSOAR, Cortex XDR, Microsoft Purview, Mimecast, Abnormal, Nessus, and Microsoft 365. You will participate in security investigations and incident response, responding to events involving malware, data loss, phishing, or network intrusion, and supporting our data protection and vulnerability management activity. You will work both independently and collaboratively, sharing knowledge openly and supporting your colleagues across all regions. You will follow security best practice, apply the principles of layered security, and serve as a trusted resource to the wider business on all matters of information and cyber security. This is a customer-facing role, so you will be a strong communicator, able to explain complex concepts clearly to both technical and non-technical audiences, with your input helping to shape and improve our day-to-day monitoring, detection, and response. You will be self-motivated, bringing the knowledge and experience gained in previous roles, genuinely passionate about data and cyber security, and committed to continued learning and professional development. Key Objectives and Responsibilities Daily Operations & Incident Handling Manage day-to-day security tickets, requests, and alerts through Halo ITSM, meeting SLAs and making full use of existing automation. Monitor, triage, and investigate alerts within Palo Alto Cortex XSIAM, responding and escalating as required. Respond to security incidents involving malware, data loss, phishing, or network intrusion, following established playbooks and incident response processes. Manage email security operations across Mimecast and Abnormal, including releases, journal pulls, and reported-phishing investigations. Monitor threat feeds and threat intelligence, applying relevant findings to the environment. Maintain and tune detections, correlation rules, and Cortex XSOAR playbooks to reduce noise and improve response times. Identify opportunities for automation and continual improvement across monitoring and response workflows. Contribute to the development and upkeep of SOC processes, runbooks, and documentation. Run and interpret vulnerability scans using Nessus, tracking remediation through to closure with the relevant teams. Support endpoint security and patch compliance across the Windows and macOS estates, working with Intune, Jamf, Alectrona, and Cortex XDR. Data Protection & Compliance Support and monitor the company's Data Loss Prevention controls within Microsoft Purview, and data classification through Azure Information Protection labelling. Help maintain the evidence and controls that support the company's accreditations, including ISO/IEC 27001, 27017, and 27018, Cyber Essentials Plus, and SOC 2. Learn and apply the principles of risk and information governance within the context of cyber security. Experience and Technical Requirements Two or more years' experience in a cyber security, SOC, or information security analyst role. Experience working within an ISO/IEC 27001 (or equivalent) accredited environment. Familiarity with ITIL service management processes, particularly Incident, Request, Change, and Problem management. Understanding of GDPR, data protection, and information governance. Hands-on experience with a SIEM platform (Cortex XSIAM, Microsoft Sentinel, Splunk, or equivalent). Experience with, or a strong aptitude to learn, SOAR and automation tooling (Cortex XSOAR). Experience with Endpoint Detection and Response (Cortex XDR or an equivalent EDR/XDR platform). Experience with email security platforms (O365, Mimecast, Abnormal, or equivalent). Understanding of Data Loss Prevention and data classification (Microsoft Purview and Azure labelling, or equivalent). Experience with vulnerability scanning and management (Nessus or equivalent). Working knowledge of endpoint management across Windows and macOS (Intune, Jamf). Strong knowledge of cloud environments, including Microsoft Azure, AWS, and Microsoft 365. Understanding of layered security, threat hunting, and incident response. Qualifications A degree in a computer-related subject, or equivalent experience in cyber security. Holding, or actively working towards, relevant industry certifications (e.g. SANS GCIH, EC-Council CEH, ISC2 SSCP, CompTIA CySA+, Blue Team Level 1, Microsoft SC-200, or equivalent), with a genuine commitment to continued professional development. Benefits 25 Days Holiday + Bank Holidays Day off for your birthday Health Shield Cash Plan Cycle to Work Scheme Train Season Ticket Scheme Profit Share Scheme Contributory company pension scheme Access to the Employee Assistance Programme (EAP) 51903MS INDMANS The Portfolio Group are acting on behalf of our client in recruiting for this position.
Security Analyst Cardiff Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Jul 21, 2026
Full time
Security Analyst Cardiff Hybrid Working Excellent Benefits Are you looking for a role where you'll play a key part in protecting a leading professional services organisation from evolving cyber threats? We're looking for a proactive Security Analyst to join a growing Technology team, working with modern security technologies in a collaborative environment where you'll have the opportunity to influence security operations, improve processes and develop your technical expertise. This is an excellent opportunity for someone with experience in Security Operations or Cyber Security who enjoys investigating incidents, strengthening security controls and working with the latest Microsoft security technologies. What you'll be doing As part of a dedicated Security team, you'll help safeguard the organisation's technology estate by monitoring threats, responding to incidents and continuously improving the firm's overall security posture. Your responsibilities will include: Monitoring and investigating security alerts across the organisation Responding to cyber security incidents and supporting remediation activities Managing and optimising security tools including Microsoft Defender and other enterprise security platforms Supporting vulnerability assessments, penetration testing and security audits Assisting with the implementation of new security technologies and improvements Developing and maintaining security policies, standards and best practice Providing technical guidance to colleagues on security processes and technologies Keeping up to date with emerging cyber threats and recommending improvements About you You'll already have experience working within a Security Operations, Cyber Security or Information Security environment and be passionate about protecting organisations from modern cyber threats. You'll ideally have experience with: Microsoft Defender or similar endpoint protection solutions Security Operations and Incident Response SIEM monitoring and security investigations Email security platforms such as Mimecast or Proofpoint Secure Web Gateway technologies such as Zscaler Vulnerability Management Cyber Essentials and ISO27001 Microsoft security technologies including Defender, Sentinel or Entra Professional certifications such as CompTIA CySA+, Security+ or Microsoft Security Operations are advantageous but by no means essential. Why apply? This is more than just another Security Analyst role. You'll be joining an organisation that genuinely invests in its people, embraces modern technology and encourages continuous learning and professional development. You'll work alongside experienced cyber security professionals, gain exposure to enterprise-scale technologies and have the opportunity to broaden your technical skills while making a real impact on the firm's security strategy. If you're looking for a role where your expertise is valued, your development is supported and no two days are the same, we'd love to hear from you. Apply today or get in touch for a confidential discussion.
Opus People Solutions Ltd
Bletchley, Buckinghamshire
ICT Security Analyst Daily rate: 19.32 per hour PAYE inside IR35 Location: Milton Keynes Civic Offices Contract: 3 months Working hours: 37 per week, office based Purpose of the Role: Opus People Solutions are recruiting on behalf of Milton Keynes Council for an ICT Security Analyst to join our ICT service at Milton Keynes City Council. The ICT Security team protects the council's systems, data and digital services so the council can continue to operate securely and reliably for the people of Milton Keynes. The team sets and maintains security policies, standards and guidance, manages cyber risk, and works across council services to make sure security is built into day-to-day operations, projects and technology change. The team monitors for threats and weaknesses, investigates incidents, leads response and recovery when issues arise, and helps strengthen resilience through planning, training, awareness and continual improvement. It also supports compliance with recognised frameworks, works with partners and suppliers to improve secure delivery, and helps the council adopt modern technologies in a safe, controlled and responsible way. By protecting information and reducing disruption, the Security team helps Milton Keynes City Council remain resilient, trusted and able to deliver essential services across more than 200 council services. You'll help us protect vital systems, reduce cyber risk, respond to incidents and give practical advice that supports colleagues right across the organisation. Key deliverables will include: Proactively monitor and protect ICT services against cyber threats and vulnerabilities ensuring adherence to appropriate Cyber Security frameworks. Maintain awareness of emerging threats, threat intelligence, standards and frameworks to inform defence actions and improvements. Monitor, triage and investigate security alerts/reports. Analyse security event data, including end-user reports, to identify incidents and support effective response and remediation. Identify, assess and prioritise security risks (current and emerging), evaluating impact and likelihood. Investigate, monitor, and audit system practices to ensure services and configuration items meet cyber security policies and baseline standards. Identify and document vulnerabilities, analyse trends, and present findings with recommendations. Develop, implement and track mitigation plans in collaboration with stakeholders. Lead the response to ICT security incidents, ensuring containment, eradication and recovery activities are carried out in accordance with established incident response plans. To deliver and assist in the delivery of projects in accordance with user specifications and timetables. Work closely with council services on project work, providing expertise on security impact, including risk, cost and deterrent. Understand security features of bespoke systems within MKCC. Collaborate effectively with colleagues, suppliers, and partners to strengthen security controls, enhance security posture, and support organisational objectives. Acting as a subject matter expert for ICT security across the council, including the installation, maintenance, upgrading and optimisation of MKCC systems. Develop and deliver cyber security awareness and guidance to colleagues, promoting secure behaviours and reducing organisational risk. Collaborate with and act as cover for the Identity and Access administrator. Produce regular reporting on security incidents, risks, and trends, providing insights and recommendations to strengthen organisational security posture. Stay informed on Microsoft security product updates, emerging threats, and best practices. Drive initiatives to enhance security posture and ensure adherence to regulatory and organisational compliance standards. Essential skills required: Related professional qualifications and experience, including degree level qualification. Demonstratable experience of Microsoft Security Stack: Experience with Microsoft Defender suite, Sentinel, Entra ID, and Copilot for Security. Ability to monitor, analyse, and respond to alerts in Sentinel and Defender; familiarity with automation playbooks. Demonstrable excellent written and verbal communication skills, with the ability to translate security risks, technical findings and recommended actions for technical and non-technical audiences. Experience using PowerShell or Kusto Query Language (KQL) to support analysis, monitoring, and automation. Exposure to coding (e.g. Python) combined with a demonstrable ability to work with accuracy and attention to detail. Cyber Security certifications, such as: CCSP, CySA+, GCIA, CSA, SC-200, or similar. Demonstrable experience of working in an Enterprise information security function within a large organisation. Ability to work closely with ICT Security Lead, Identity & Access Administrator, and other stakeholders including colleagues across MKCC. Practical experience with asset management systems and experience securing Microsoft 365 services (e.g. SharePoint, Teams, Copilot). Evidenced knowledge and understanding of security frameworks, standards and best practices (CAF, Cyber Essentials, NIST, ISO27001). Proven familiarity with modern network, cloud and identity security concepts such as authentication, firewalls, endpoint protection, email security, vulnerability management, logging, monitoring and security controls. Continuous Learning and Adaptability: Commitment to staying updated on Microsoft security technologies, threat trends, and best practices. For more information or to process your application, please apply now!
Jul 21, 2026
Contractor
ICT Security Analyst Daily rate: 19.32 per hour PAYE inside IR35 Location: Milton Keynes Civic Offices Contract: 3 months Working hours: 37 per week, office based Purpose of the Role: Opus People Solutions are recruiting on behalf of Milton Keynes Council for an ICT Security Analyst to join our ICT service at Milton Keynes City Council. The ICT Security team protects the council's systems, data and digital services so the council can continue to operate securely and reliably for the people of Milton Keynes. The team sets and maintains security policies, standards and guidance, manages cyber risk, and works across council services to make sure security is built into day-to-day operations, projects and technology change. The team monitors for threats and weaknesses, investigates incidents, leads response and recovery when issues arise, and helps strengthen resilience through planning, training, awareness and continual improvement. It also supports compliance with recognised frameworks, works with partners and suppliers to improve secure delivery, and helps the council adopt modern technologies in a safe, controlled and responsible way. By protecting information and reducing disruption, the Security team helps Milton Keynes City Council remain resilient, trusted and able to deliver essential services across more than 200 council services. You'll help us protect vital systems, reduce cyber risk, respond to incidents and give practical advice that supports colleagues right across the organisation. Key deliverables will include: Proactively monitor and protect ICT services against cyber threats and vulnerabilities ensuring adherence to appropriate Cyber Security frameworks. Maintain awareness of emerging threats, threat intelligence, standards and frameworks to inform defence actions and improvements. Monitor, triage and investigate security alerts/reports. Analyse security event data, including end-user reports, to identify incidents and support effective response and remediation. Identify, assess and prioritise security risks (current and emerging), evaluating impact and likelihood. Investigate, monitor, and audit system practices to ensure services and configuration items meet cyber security policies and baseline standards. Identify and document vulnerabilities, analyse trends, and present findings with recommendations. Develop, implement and track mitigation plans in collaboration with stakeholders. Lead the response to ICT security incidents, ensuring containment, eradication and recovery activities are carried out in accordance with established incident response plans. To deliver and assist in the delivery of projects in accordance with user specifications and timetables. Work closely with council services on project work, providing expertise on security impact, including risk, cost and deterrent. Understand security features of bespoke systems within MKCC. Collaborate effectively with colleagues, suppliers, and partners to strengthen security controls, enhance security posture, and support organisational objectives. Acting as a subject matter expert for ICT security across the council, including the installation, maintenance, upgrading and optimisation of MKCC systems. Develop and deliver cyber security awareness and guidance to colleagues, promoting secure behaviours and reducing organisational risk. Collaborate with and act as cover for the Identity and Access administrator. Produce regular reporting on security incidents, risks, and trends, providing insights and recommendations to strengthen organisational security posture. Stay informed on Microsoft security product updates, emerging threats, and best practices. Drive initiatives to enhance security posture and ensure adherence to regulatory and organisational compliance standards. Essential skills required: Related professional qualifications and experience, including degree level qualification. Demonstratable experience of Microsoft Security Stack: Experience with Microsoft Defender suite, Sentinel, Entra ID, and Copilot for Security. Ability to monitor, analyse, and respond to alerts in Sentinel and Defender; familiarity with automation playbooks. Demonstrable excellent written and verbal communication skills, with the ability to translate security risks, technical findings and recommended actions for technical and non-technical audiences. Experience using PowerShell or Kusto Query Language (KQL) to support analysis, monitoring, and automation. Exposure to coding (e.g. Python) combined with a demonstrable ability to work with accuracy and attention to detail. Cyber Security certifications, such as: CCSP, CySA+, GCIA, CSA, SC-200, or similar. Demonstrable experience of working in an Enterprise information security function within a large organisation. Ability to work closely with ICT Security Lead, Identity & Access Administrator, and other stakeholders including colleagues across MKCC. Practical experience with asset management systems and experience securing Microsoft 365 services (e.g. SharePoint, Teams, Copilot). Evidenced knowledge and understanding of security frameworks, standards and best practices (CAF, Cyber Essentials, NIST, ISO27001). Proven familiarity with modern network, cloud and identity security concepts such as authentication, firewalls, endpoint protection, email security, vulnerability management, logging, monitoring and security controls. Continuous Learning and Adaptability: Commitment to staying updated on Microsoft security technologies, threat trends, and best practices. For more information or to process your application, please apply now!
IT Security Analyst Hybrid Are you an experienced Cyber Security professional looking for your next challenge? Our client is seeking a talented Cyber Security Engineer to join their Global IT Security Team, playing a key role in protecting business-critical systems and driving the continual evolution of their cyber security strategy. This is an exciting opportunity to work across a broad range of security technologies, contribute to major security initiatives, and support the ongoing management of an ISO27001-certified Information Security Management System (ISMS). You'll collaborate with internal stakeholders and external partners while helping shape future security programmes within a global organisation. The Role Reporting to the Senior Manager of IT Infrastructure & Security, you will be responsible for protecting the organisation's information assets and strengthening its cyber security posture. Your responsibilities will include: Supporting the ongoing administration and continual improvement of the ISO27001-certified Information Security Management System (ISMS). Working alongside IT Security Management and external consultants to maintain compliance with security standards. Reviewing and enhancing information security policies, procedures and controls. Responding to potential security incidents in collaboration with the wider IT team. Assisting with incident response, investigation, containment and recovery activities. Developing and improving cyber security monitoring, detection and alerting capabilities. Monitoring internal and external threat landscapes and reporting emerging risks. Researching and recommending new security technologies, trends and best practices. Identifying meaningful security KPIs and supporting internal compliance and assurance reviews. You'll ideally have: 5+ years' experience within IT and Network Security operations. CISSP certification (preferred). Hands-on experience with a broad range of security technologies, tools and controls. Good understanding of ISO27001 and/or other recognised Information Security frameworks. Experience in risk assessment, threat detection, vulnerability management and incident response. Strong analytical and problem-solving skills with the ability to perform under pressure. Excellent communication skills with the ability to explain technical concepts clearly to both technical and non-technical stakeholders. A collaborative mindset and passion for continuous improvement. IT Security Analyst Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
Jul 20, 2026
Full time
IT Security Analyst Hybrid Are you an experienced Cyber Security professional looking for your next challenge? Our client is seeking a talented Cyber Security Engineer to join their Global IT Security Team, playing a key role in protecting business-critical systems and driving the continual evolution of their cyber security strategy. This is an exciting opportunity to work across a broad range of security technologies, contribute to major security initiatives, and support the ongoing management of an ISO27001-certified Information Security Management System (ISMS). You'll collaborate with internal stakeholders and external partners while helping shape future security programmes within a global organisation. The Role Reporting to the Senior Manager of IT Infrastructure & Security, you will be responsible for protecting the organisation's information assets and strengthening its cyber security posture. Your responsibilities will include: Supporting the ongoing administration and continual improvement of the ISO27001-certified Information Security Management System (ISMS). Working alongside IT Security Management and external consultants to maintain compliance with security standards. Reviewing and enhancing information security policies, procedures and controls. Responding to potential security incidents in collaboration with the wider IT team. Assisting with incident response, investigation, containment and recovery activities. Developing and improving cyber security monitoring, detection and alerting capabilities. Monitoring internal and external threat landscapes and reporting emerging risks. Researching and recommending new security technologies, trends and best practices. Identifying meaningful security KPIs and supporting internal compliance and assurance reviews. You'll ideally have: 5+ years' experience within IT and Network Security operations. CISSP certification (preferred). Hands-on experience with a broad range of security technologies, tools and controls. Good understanding of ISO27001 and/or other recognised Information Security frameworks. Experience in risk assessment, threat detection, vulnerability management and incident response. Strong analytical and problem-solving skills with the ability to perform under pressure. Excellent communication skills with the ability to explain technical concepts clearly to both technical and non-technical stakeholders. A collaborative mindset and passion for continuous improvement. IT Security Analyst Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
The Company Since the 1970s, the Briggs Group has grown to become one of the world leaders in the marine and environmental services industry, currently employing around 800 dedicated members of staff. Providing clients with services ranging from terminal operations to subsea cable repair, we are committed to employing dedicated and skilled staff who are looking for a career that offers stability, genuine career progression, and recognition. Our core values support the Company s mission and decision-making and provide a benchmark for everything that we believe in. They are the Company s fundamental beliefs and are integrated into every employee process, shaping the Company s culture for future success. The Role The IT Security Analyst is responsible for identifying, analysing, and tracking security risks across systems and applications. The role focuses on monitoring, investigation, vulnerability management, and supporting remediation activities to help protect the organisation's technology estate and information assets. Working within an established security governance framework, you will support security operations, compliance activities, risk management, and continuous improvement initiatives across the business. Key Responsibilities: • Monitor and analyse security alerts from tools such as Microsoft Defender and other security monitoring platforms. • Identify vulnerabilities across systems, applications, and endpoints. • Investigate anomalies, trends, and suspicious activity, escalating security incidents in line with defined procedures. • Participate in incident investigations and post-incident reviews, contributing findings and recommendations. • Assess and track vulnerabilities through to remediation, monitoring progress against agreed actions and timelines. • Conduct access reviews and support permission auditing activities. • Gather and prepare evidence for internal and external audits. • Support risk management activities, including maintaining risk registers and assisting with supplier security assessments. • Deliver security awareness and training initiatives across the organisation. • Identify opportunities to improve and automate security processes, reporting, and operational controls. Skills & Experience: • Experience using security monitoring tools such as Microsoft Defender, SIEM platforms, or similar technologies. • Strong analytical and investigative skills. • Understanding of vulnerability management and incident response processes. • Familiarity with security standards and frameworks such as ISO 27001 and Cyber Essentials Plus. • Ability to interpret security alerts, logs, and system behaviour. • Experience working within governance, compliance, or audit-focused environments. The Candidate: You will be: • Detail-oriented with a strong focus on accuracy. • Proactive in identifying and addressing risks. • Comfortable working within structured processes and governance frameworks. • A clear communicator with the ability to engage with both technical and non-technical stakeholders. • Committed to continuous improvement and professional development. What s in it for you? We offer an excellent package, including a pension, life assurance, the Cycle to Work scheme, and more, along with opportunities for on-the-job training and career progression within a stable environment. Flexible working options are also available. As an equal opportunity employer, we encourage diversity and are committed to creating an inclusive environment for all employees. We welcome applicants from all protected characteristics and are committed to providing any reasonable adjustments you need during the application, assessment, and onboarding process. The next steps You must be able to provide relevant documentation confirming that you have the right to work in the UK. Please send applications or feel free to call for further information
Jul 18, 2026
Full time
The Company Since the 1970s, the Briggs Group has grown to become one of the world leaders in the marine and environmental services industry, currently employing around 800 dedicated members of staff. Providing clients with services ranging from terminal operations to subsea cable repair, we are committed to employing dedicated and skilled staff who are looking for a career that offers stability, genuine career progression, and recognition. Our core values support the Company s mission and decision-making and provide a benchmark for everything that we believe in. They are the Company s fundamental beliefs and are integrated into every employee process, shaping the Company s culture for future success. The Role The IT Security Analyst is responsible for identifying, analysing, and tracking security risks across systems and applications. The role focuses on monitoring, investigation, vulnerability management, and supporting remediation activities to help protect the organisation's technology estate and information assets. Working within an established security governance framework, you will support security operations, compliance activities, risk management, and continuous improvement initiatives across the business. Key Responsibilities: • Monitor and analyse security alerts from tools such as Microsoft Defender and other security monitoring platforms. • Identify vulnerabilities across systems, applications, and endpoints. • Investigate anomalies, trends, and suspicious activity, escalating security incidents in line with defined procedures. • Participate in incident investigations and post-incident reviews, contributing findings and recommendations. • Assess and track vulnerabilities through to remediation, monitoring progress against agreed actions and timelines. • Conduct access reviews and support permission auditing activities. • Gather and prepare evidence for internal and external audits. • Support risk management activities, including maintaining risk registers and assisting with supplier security assessments. • Deliver security awareness and training initiatives across the organisation. • Identify opportunities to improve and automate security processes, reporting, and operational controls. Skills & Experience: • Experience using security monitoring tools such as Microsoft Defender, SIEM platforms, or similar technologies. • Strong analytical and investigative skills. • Understanding of vulnerability management and incident response processes. • Familiarity with security standards and frameworks such as ISO 27001 and Cyber Essentials Plus. • Ability to interpret security alerts, logs, and system behaviour. • Experience working within governance, compliance, or audit-focused environments. The Candidate: You will be: • Detail-oriented with a strong focus on accuracy. • Proactive in identifying and addressing risks. • Comfortable working within structured processes and governance frameworks. • A clear communicator with the ability to engage with both technical and non-technical stakeholders. • Committed to continuous improvement and professional development. What s in it for you? We offer an excellent package, including a pension, life assurance, the Cycle to Work scheme, and more, along with opportunities for on-the-job training and career progression within a stable environment. Flexible working options are also available. As an equal opportunity employer, we encourage diversity and are committed to creating an inclusive environment for all employees. We welcome applicants from all protected characteristics and are committed to providing any reasonable adjustments you need during the application, assessment, and onboarding process. The next steps You must be able to provide relevant documentation confirming that you have the right to work in the UK. Please send applications or feel free to call for further information
Summer-Browning Associates
East Kilbride, Lanarkshire
Summer-Browning Associates is supporting our client in the Central Government who is seeking a SECURITY OPERATIONS CENTER (SOC) ANALYST for an initial 12-month assignment, with the possibility of extension. Location: Hybrid working - 2 days per week onsite at East Kilbride The ideal candidates will hold active SC or DV clearance and have a proven background in Cyber Security, with the following skills and experience: Experience in SOC operations, incident response, and forensic analysis. Proficiency in Security Information and Event Management (SIEM), including tools such as Splunk, Defender, and Tenable Threat Modelling System solutions, as well as with IDS/IPS and vulnerability scanners. Ability to perform triage of security events to determine their scope, priority, and impact, while making recommendations for efficient remediation. Experience in network security principles, firewalls, and access control mechanisms. Preferred Qualifications: - Industry certifications such as CompTIA Security+, CISSP, CISM, CEH, or GIAC are highly desirable
Jul 17, 2026
Contractor
Summer-Browning Associates is supporting our client in the Central Government who is seeking a SECURITY OPERATIONS CENTER (SOC) ANALYST for an initial 12-month assignment, with the possibility of extension. Location: Hybrid working - 2 days per week onsite at East Kilbride The ideal candidates will hold active SC or DV clearance and have a proven background in Cyber Security, with the following skills and experience: Experience in SOC operations, incident response, and forensic analysis. Proficiency in Security Information and Event Management (SIEM), including tools such as Splunk, Defender, and Tenable Threat Modelling System solutions, as well as with IDS/IPS and vulnerability scanners. Ability to perform triage of security events to determine their scope, priority, and impact, while making recommendations for efficient remediation. Experience in network security principles, firewalls, and access control mechanisms. Preferred Qualifications: - Industry certifications such as CompTIA Security+, CISSP, CISM, CEH, or GIAC are highly desirable
hackajob is collaborating with Bet365 to connect them with exceptional professionals for this role. Company Description We're one of the world's leading online gambling companies, revolutionising the industry since 2000. Founded by Denise Coates CBE, we now employ over 10,000 people and serve over 120 million customers in 26 languages. We empower our employees to push boundaries and explore new ideas, cultivating a culture that celebrates and rewards creativity. This offers employees a wealth of growth opportunities, giving them the opportunity to make a real impact in the world of online gambling. As a forward-thinking company, we're breaking new ground in software innovation too, redefining what's possible for our global worldwide. Our focus on In-Play betting has solidified our market-leading position, featuring more than 1.38 million In-Play sporting events a year. With over 750 concurrent sporting fixtures at peak and more live sports streamed than anyone else in Europe (750,000), we handle over 6 million HTTP requests daily and process more than 1.5 million bets per hour at peak. Job Description As an Information Security Analyst in our vulnerability management team, you will ensure IT systems are operating in a secure manner in line with regulatory requirements. Join our vulnerability management team as an Information Security Analyst. You keep our IT systems secure and compliant while protecting our live operation. Our Information Security team monitors our live operation around the clock. We spot anomalies and manage vulnerability scanning across all endpoints. You assess risk, plan specialist testing, and help the business understand the urgency of patching. You also work with governance teams to keep us compliant. This role is eligible for inclusion in the Company's hybrid working from home policy. Qualifications Strong understanding of information and cyber security principles. Hands-on experience with vulnerability scanning tools and risk assessment. Proven ability to explain technical risk to non-technical teams. Experience with security-related technical investigations. Working knowledge of industry-standard security practices. Awareness of the current Payment Card Industry Data Security Standard (PCI DSS) version. Excellent attention to detail and documentation skills. Strong organisational skills with the ability to meet deadlines. Pragmatic approach to governance and risk administration. Committed and flexible attitude towards work. Additional Information Running vulnerability scans using industry-leading tools. Scheduling scanning across the Business to minimise operational impact. Explaining Business risk to technical and non-technical colleagues. Coordinating internal and external resources to meet targets. Embedding security requirements throughout the project lifecycle. Liaising with the Business to ensure we meet all security requirements. Acting as an escalation point for security queries. Creating clear and accurate technical documentation. Monitoring emerging threats and escalate findings to the relevant teams. Supporting internal and external audits. By applying to us you are agreeing to share your Personal Data in accordance with our Recruitment Privacy Notice - At bet365, we're committed to creating an environment where everyone feels welcome, respected and valued. Where all individuals can grow and develop, regardless of their background. We're Never Ordinary, and we're always striving to be better. If you need any adjustments or accommodations to the recruitment process, at either application or interview, please don't hesitate to reach out.
Jul 17, 2026
Full time
hackajob is collaborating with Bet365 to connect them with exceptional professionals for this role. Company Description We're one of the world's leading online gambling companies, revolutionising the industry since 2000. Founded by Denise Coates CBE, we now employ over 10,000 people and serve over 120 million customers in 26 languages. We empower our employees to push boundaries and explore new ideas, cultivating a culture that celebrates and rewards creativity. This offers employees a wealth of growth opportunities, giving them the opportunity to make a real impact in the world of online gambling. As a forward-thinking company, we're breaking new ground in software innovation too, redefining what's possible for our global worldwide. Our focus on In-Play betting has solidified our market-leading position, featuring more than 1.38 million In-Play sporting events a year. With over 750 concurrent sporting fixtures at peak and more live sports streamed than anyone else in Europe (750,000), we handle over 6 million HTTP requests daily and process more than 1.5 million bets per hour at peak. Job Description As an Information Security Analyst in our vulnerability management team, you will ensure IT systems are operating in a secure manner in line with regulatory requirements. Join our vulnerability management team as an Information Security Analyst. You keep our IT systems secure and compliant while protecting our live operation. Our Information Security team monitors our live operation around the clock. We spot anomalies and manage vulnerability scanning across all endpoints. You assess risk, plan specialist testing, and help the business understand the urgency of patching. You also work with governance teams to keep us compliant. This role is eligible for inclusion in the Company's hybrid working from home policy. Qualifications Strong understanding of information and cyber security principles. Hands-on experience with vulnerability scanning tools and risk assessment. Proven ability to explain technical risk to non-technical teams. Experience with security-related technical investigations. Working knowledge of industry-standard security practices. Awareness of the current Payment Card Industry Data Security Standard (PCI DSS) version. Excellent attention to detail and documentation skills. Strong organisational skills with the ability to meet deadlines. Pragmatic approach to governance and risk administration. Committed and flexible attitude towards work. Additional Information Running vulnerability scans using industry-leading tools. Scheduling scanning across the Business to minimise operational impact. Explaining Business risk to technical and non-technical colleagues. Coordinating internal and external resources to meet targets. Embedding security requirements throughout the project lifecycle. Liaising with the Business to ensure we meet all security requirements. Acting as an escalation point for security queries. Creating clear and accurate technical documentation. Monitoring emerging threats and escalate findings to the relevant teams. Supporting internal and external audits. By applying to us you are agreeing to share your Personal Data in accordance with our Recruitment Privacy Notice - At bet365, we're committed to creating an environment where everyone feels welcome, respected and valued. Where all individuals can grow and develop, regardless of their background. We're Never Ordinary, and we're always striving to be better. If you need any adjustments or accommodations to the recruitment process, at either application or interview, please don't hesitate to reach out.
Senior Information Security Analyst / Engineer / Architect to £54k + Benefits ISO27001, COBIT, SECURITY, ITIL, CISM, CISSP, PCI-DSS Lead Information Security Engineer/Analyst: Do you have a background working in an IT Security function and are able to identify and remediate threats or vulnerabilities, implement information security strategies to mitigate risk, and put process in place to alleviate security issues? Are you passionate about technology, with a strong customer service ethos, focused on keeping abreast with Information Security Management frameworks and standards ( ISO2701, COBIT, ITIL) Lead Information Security Engineer/Analyst/ Architect - About the company: Do you want to be part of a successful organisation, that strives to offer stable, sustainable, and thriving communities in their local area.They have a vision and purpose to make a difference by the services they offer across a variety of services in their local area. With offices based in Chesterfield, they are involved in a major transformation, within the local area. They are investing in improving their services to best meet the changing needs of their customers / users. Lead Information Security Engineer/Analyst / Architect - About the role: The Security Engineer / Architect role will be office based in their Chesterfield office,( on average 2-3 days per week) working as part of a small team, provide effective solutions to escalated security issues, and provide a high level of security expertise to the business, across information systems, networks, and data. You will primarily be focused on playing a critical role developing and implementing information security policies, strategies, and procedures to help safeguard their digital assets and mitigate against potential risks.You will be actively responsible for ensuring the successful achievement of external certifications such as ISO27001, MOU, PSN and PCI-DSS etc alongside managing security incident response plans. In addition, the Lead information Security Analyst / Engineer will provide advice and guidance on government standards and industry best practice relating to information security maintain compliance to these standards. Lead Information Security Engineer/Analyst - Key Responsibilities: Oversee information security, compliance and risk management practices following industry frameworks Take ownership of and establish information security policies, standards and procedures ensuring confidentiality and integrity Conduct regular risk assessments to identify security vulnerabilities and potential threats and implement strategies to mitigate risk Implement plans and protocols to respond to security issues Educate other colleagues and employees in security awareness programmes / training sessions in relation to security compliance and best practice Maintain and develop good working relationships with 3rd part suppliers ensuring they meet security standards Monitoring events / alerts from multiple technologies to detect potential malicious activity Ensure effective compliance with relevant laws, regulations, and industry standards such as GDPR, ISO27001, PCI- DSS etc by conducting audits, maintaining documentation etc Support the Head of Digital, Data and Technology to develop, monitor and report on budget that is in line with business & financial objectives Lead Information Security Engineer/Analyst- Essential Skills: Candidates must have some exposure to most of the technologies listed below: Comprehensive knowledge of Information Security Management systems and ability to scope, design and implement such systems Previous experience in ICT infrastructure, application, and Cloud / SaaS technical skills Knowledge & understanding of ISO 27001, ITIL and ideally Prince 2 methodology Leadership qualities to lead a workforce and enhance their information security knowledge Ability to deal with high complex / risk problems across a diverse range of security threats Good knowledge of IT Security Principles All round experience of vulnerability management, information security incident management alongside IT Service and Asset management systems Lead Information Security Engineer/Analyst - Benefits Basic salary of up to £54k on offer Pension - 20% company contribution Training opportunities Child vouchers, discounted leisure, and travel scheme. 32 days holiday plus bank holidays Hybrid working ( 2 days per week from home) Flexible working hours / compressed hours options The Security Engineer role offers the chance to play a leading role in this organisation's information security set-up and contribute your own ideas ( within best practice) to enhance and sustain their Information Security Management You will be given the opportunity to learn and progress within the organisation. and make an impact with their Information Security environment. Langland Consultants acts as an Employment Agency/Business with regards to this vacancy. As an Equal Opportunities employer, Langland Consultants welcomes applications regardless of race, gender, nationality, ethnic origin, sexual orientation, religion, marital status, disability, or age. All applicants are considered on the basis of their merits and abilities for the job. By applying to a job advertised by Langland Consultants or providing your contact information to show interest in a job advertised by Langland Consultants, you consent to the disclosure of your information to us in order to assist our legitimate business needs. This includes agreeing to us in storing your information and allowing us to contact you in regard to suitable job opportunities in the future. You are within your rights to ask us to remove your information at any time.
Jul 17, 2026
Full time
Senior Information Security Analyst / Engineer / Architect to £54k + Benefits ISO27001, COBIT, SECURITY, ITIL, CISM, CISSP, PCI-DSS Lead Information Security Engineer/Analyst: Do you have a background working in an IT Security function and are able to identify and remediate threats or vulnerabilities, implement information security strategies to mitigate risk, and put process in place to alleviate security issues? Are you passionate about technology, with a strong customer service ethos, focused on keeping abreast with Information Security Management frameworks and standards ( ISO2701, COBIT, ITIL) Lead Information Security Engineer/Analyst/ Architect - About the company: Do you want to be part of a successful organisation, that strives to offer stable, sustainable, and thriving communities in their local area.They have a vision and purpose to make a difference by the services they offer across a variety of services in their local area. With offices based in Chesterfield, they are involved in a major transformation, within the local area. They are investing in improving their services to best meet the changing needs of their customers / users. Lead Information Security Engineer/Analyst / Architect - About the role: The Security Engineer / Architect role will be office based in their Chesterfield office,( on average 2-3 days per week) working as part of a small team, provide effective solutions to escalated security issues, and provide a high level of security expertise to the business, across information systems, networks, and data. You will primarily be focused on playing a critical role developing and implementing information security policies, strategies, and procedures to help safeguard their digital assets and mitigate against potential risks.You will be actively responsible for ensuring the successful achievement of external certifications such as ISO27001, MOU, PSN and PCI-DSS etc alongside managing security incident response plans. In addition, the Lead information Security Analyst / Engineer will provide advice and guidance on government standards and industry best practice relating to information security maintain compliance to these standards. Lead Information Security Engineer/Analyst - Key Responsibilities: Oversee information security, compliance and risk management practices following industry frameworks Take ownership of and establish information security policies, standards and procedures ensuring confidentiality and integrity Conduct regular risk assessments to identify security vulnerabilities and potential threats and implement strategies to mitigate risk Implement plans and protocols to respond to security issues Educate other colleagues and employees in security awareness programmes / training sessions in relation to security compliance and best practice Maintain and develop good working relationships with 3rd part suppliers ensuring they meet security standards Monitoring events / alerts from multiple technologies to detect potential malicious activity Ensure effective compliance with relevant laws, regulations, and industry standards such as GDPR, ISO27001, PCI- DSS etc by conducting audits, maintaining documentation etc Support the Head of Digital, Data and Technology to develop, monitor and report on budget that is in line with business & financial objectives Lead Information Security Engineer/Analyst- Essential Skills: Candidates must have some exposure to most of the technologies listed below: Comprehensive knowledge of Information Security Management systems and ability to scope, design and implement such systems Previous experience in ICT infrastructure, application, and Cloud / SaaS technical skills Knowledge & understanding of ISO 27001, ITIL and ideally Prince 2 methodology Leadership qualities to lead a workforce and enhance their information security knowledge Ability to deal with high complex / risk problems across a diverse range of security threats Good knowledge of IT Security Principles All round experience of vulnerability management, information security incident management alongside IT Service and Asset management systems Lead Information Security Engineer/Analyst - Benefits Basic salary of up to £54k on offer Pension - 20% company contribution Training opportunities Child vouchers, discounted leisure, and travel scheme. 32 days holiday plus bank holidays Hybrid working ( 2 days per week from home) Flexible working hours / compressed hours options The Security Engineer role offers the chance to play a leading role in this organisation's information security set-up and contribute your own ideas ( within best practice) to enhance and sustain their Information Security Management You will be given the opportunity to learn and progress within the organisation. and make an impact with their Information Security environment. Langland Consultants acts as an Employment Agency/Business with regards to this vacancy. As an Equal Opportunities employer, Langland Consultants welcomes applications regardless of race, gender, nationality, ethnic origin, sexual orientation, religion, marital status, disability, or age. All applicants are considered on the basis of their merits and abilities for the job. By applying to a job advertised by Langland Consultants or providing your contact information to show interest in a job advertised by Langland Consultants, you consent to the disclosure of your information to us in order to assist our legitimate business needs. This includes agreeing to us in storing your information and allowing us to contact you in regard to suitable job opportunities in the future. You are within your rights to ask us to remove your information at any time.
Senior Cyber Security Analyst - Hackney Contract 6 months initially Hybrid 1-2 days onsite, 3-4 days working from home £500.00 per day Umbrella Full time Summary of the responsibilities of the post: The Senior Cyber Security Analyst will join the Council s central ICT Cyber Security team to strengthen operational resilience and support our active Cyber Transformation Programme. This is a hands-on role focused primarily on supporting day-to-day security operations, endpoint threat detection and internal compliance tracking. This role acts as a bridge between technical security functions and governance frameworks. The successful contractor will leverage their existing exposure to Endpoint Detection and Response (EDR) platforms - specifically CrowdStrike Falcon - and have experience working with compliance frameworks. SERVICE SPECIFIC ACCOUNTABILITIES The contractor will have responsibility and accountability for the following: 1. Security Monitoring: Maintain visibility over the Council's security posture by monitoring alert queues via CrowdStrike Falcon and integrated log management tools. Investigate and escalate alerts where required. 2. Compliance & Governance Support: Assist in maintaining alignment with NIST CSF, track documentation, policy compliance, and audit requirements across ICT teams. 3. Vulnerability Tracking & Reporting: Oversee regular vulnerability scanning schedules. Analyze scan results and recent Penetration Testing reports, prioritizing. To find out more information please contact Abbie at (url removed) Recruitment is done in line with safe recruitment practices. We are an equal opportunity agency.
Jul 16, 2026
Contractor
Senior Cyber Security Analyst - Hackney Contract 6 months initially Hybrid 1-2 days onsite, 3-4 days working from home £500.00 per day Umbrella Full time Summary of the responsibilities of the post: The Senior Cyber Security Analyst will join the Council s central ICT Cyber Security team to strengthen operational resilience and support our active Cyber Transformation Programme. This is a hands-on role focused primarily on supporting day-to-day security operations, endpoint threat detection and internal compliance tracking. This role acts as a bridge between technical security functions and governance frameworks. The successful contractor will leverage their existing exposure to Endpoint Detection and Response (EDR) platforms - specifically CrowdStrike Falcon - and have experience working with compliance frameworks. SERVICE SPECIFIC ACCOUNTABILITIES The contractor will have responsibility and accountability for the following: 1. Security Monitoring: Maintain visibility over the Council's security posture by monitoring alert queues via CrowdStrike Falcon and integrated log management tools. Investigate and escalate alerts where required. 2. Compliance & Governance Support: Assist in maintaining alignment with NIST CSF, track documentation, policy compliance, and audit requirements across ICT teams. 3. Vulnerability Tracking & Reporting: Oversee regular vulnerability scanning schedules. Analyze scan results and recent Penetration Testing reports, prioritizing. To find out more information please contact Abbie at (url removed) Recruitment is done in line with safe recruitment practices. We are an equal opportunity agency.
Robert Walters is working in partnership with a leading international business with operations across the UK, Ireland, and Europe, specializing in the distribution of essential products and services that support a wide range of industries. With a strong focus on innovation, operational excellence, and customer satisfaction, they are committed to delivering high-quality solutions that drive growth and efficiency. Due to continued growth, they are keen to appoint an experienced a Lead IT Security Analyst to be based out of the Lutterworth offices on a hybrid basis, paying a salary range up to £62,000 plus bonus. Lead IT Security Analyst: Duties Lead security operations across multi-site infrastructure (SIEM, EDR, network security) Act as the senior escalation point for cyber incidents and investigations Drive incident response - triage, containment, root cause analysis Oversee and improve vulnerability management and threat detection Support secure design and architecture across infrastructure and cloud changes Enhance and manage key security tooling and controls Work closely with IT, infrastructure, and external partners across sites Lead IT Security Analyst: Technical Experience Proven experience in IT security/cyber operations Strong knowledge of infrastructure, networks, cloud, and endpoint security Hands-on experience with SIEM, EDR, IAM, Firewalls, vulnerability tools Confident leading incident response and technical investigations The permanent opportunity for a Lead IT Security Analyst will be based out of the Lutterworth offices on a hybrid basis, paying a salary range up to £62,000 plus bonus. This is an opportunity to join an industry leader that has grown year on year. For more information, please apply with an updated CV and reach out to Ajay Hayre on (see below) Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates
Jul 16, 2026
Full time
Robert Walters is working in partnership with a leading international business with operations across the UK, Ireland, and Europe, specializing in the distribution of essential products and services that support a wide range of industries. With a strong focus on innovation, operational excellence, and customer satisfaction, they are committed to delivering high-quality solutions that drive growth and efficiency. Due to continued growth, they are keen to appoint an experienced a Lead IT Security Analyst to be based out of the Lutterworth offices on a hybrid basis, paying a salary range up to £62,000 plus bonus. Lead IT Security Analyst: Duties Lead security operations across multi-site infrastructure (SIEM, EDR, network security) Act as the senior escalation point for cyber incidents and investigations Drive incident response - triage, containment, root cause analysis Oversee and improve vulnerability management and threat detection Support secure design and architecture across infrastructure and cloud changes Enhance and manage key security tooling and controls Work closely with IT, infrastructure, and external partners across sites Lead IT Security Analyst: Technical Experience Proven experience in IT security/cyber operations Strong knowledge of infrastructure, networks, cloud, and endpoint security Hands-on experience with SIEM, EDR, IAM, Firewalls, vulnerability tools Confident leading incident response and technical investigations The permanent opportunity for a Lead IT Security Analyst will be based out of the Lutterworth offices on a hybrid basis, paying a salary range up to £62,000 plus bonus. This is an opportunity to join an industry leader that has grown year on year. For more information, please apply with an updated CV and reach out to Ajay Hayre on (see below) Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates
Your new company A leading, highly regulated organisation operating within a complex technology-driven environment is seeking to appoint a Governance & Compliance Analyst. This organisation is recognised for its scale, innovation, and commitment to robust governance frameworks within a dynamic and evolving regulatory landscape.You will join a well-established Strategic Governance function that plays a critical role in enabling safe, compliant, and forward-looking operations across the technology estate. Your new role As a Governance & Compliance Analyst, you will play a pivotal role in embedding and enhancing governance, risk, and compliance (GRC) practices across the full technology lifecycle.Working closely with Technology, Risk, Security, and Operational teams, you will: Support governance and assurance activities across key areas, including technology lifecycle management, vulnerability management, asset governance, and change management. Contribute to regulatory compliance activity aligned to telecoms and security requirements (e.g. Ofcom, Telecoms Security Act, ISO frameworks) Translate strategic governance objectives into practical, measurable controls and processes Provide insight and reporting to support senior leadership and executive decision-making Engage across the business to ensure risk and compliance accountability is embedded within first-line teams Support transformation programmes and GRC maturity initiatives, ensuring governance keeps pace with change Maintain and enhance asset management and configuration data governance frameworks This role acts as a critical bridge between strategic governance direction and operational execution, ensuring the business operates in a controlled and compliant manner. What you'll need to succeed To be successful in this role, you will bring: Proven experience within Governance, Risk & Compliance / Assurance in a regulated environment (e.g. telecoms, financial services, utilities) A strong understanding of regulatory frameworks and operational risk, ideally including experience with ISO standards, SOX, or industry-specific regulation Experience supporting technology or transformation environments, with exposure to lifecycle governance or IT risk The ability to engage and influence senior stakeholders, translating complex risk issues into clear, commercial insight Demonstrable experience in stakeholder management across cross-functional teams Experience contributing to senior-level reporting and governance forums A qualification or background in risk, audit, information security, or a related discipline What you'll get in return Hybrid working, up to 3 days from home Competitive rates of pay The opportunity to work in a high-impact governance role within a large-scale, regulated technology environment Exposure to enterprise-wide risk and compliance frameworks, alongside senior leadership Involvement in significant transformation and change programmes A collaborative and forward-thinking culture with strong investment in governance maturity What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV. If this job isn't quite right for you but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Jun 27, 2026
Seasonal
Your new company A leading, highly regulated organisation operating within a complex technology-driven environment is seeking to appoint a Governance & Compliance Analyst. This organisation is recognised for its scale, innovation, and commitment to robust governance frameworks within a dynamic and evolving regulatory landscape.You will join a well-established Strategic Governance function that plays a critical role in enabling safe, compliant, and forward-looking operations across the technology estate. Your new role As a Governance & Compliance Analyst, you will play a pivotal role in embedding and enhancing governance, risk, and compliance (GRC) practices across the full technology lifecycle.Working closely with Technology, Risk, Security, and Operational teams, you will: Support governance and assurance activities across key areas, including technology lifecycle management, vulnerability management, asset governance, and change management. Contribute to regulatory compliance activity aligned to telecoms and security requirements (e.g. Ofcom, Telecoms Security Act, ISO frameworks) Translate strategic governance objectives into practical, measurable controls and processes Provide insight and reporting to support senior leadership and executive decision-making Engage across the business to ensure risk and compliance accountability is embedded within first-line teams Support transformation programmes and GRC maturity initiatives, ensuring governance keeps pace with change Maintain and enhance asset management and configuration data governance frameworks This role acts as a critical bridge between strategic governance direction and operational execution, ensuring the business operates in a controlled and compliant manner. What you'll need to succeed To be successful in this role, you will bring: Proven experience within Governance, Risk & Compliance / Assurance in a regulated environment (e.g. telecoms, financial services, utilities) A strong understanding of regulatory frameworks and operational risk, ideally including experience with ISO standards, SOX, or industry-specific regulation Experience supporting technology or transformation environments, with exposure to lifecycle governance or IT risk The ability to engage and influence senior stakeholders, translating complex risk issues into clear, commercial insight Demonstrable experience in stakeholder management across cross-functional teams Experience contributing to senior-level reporting and governance forums A qualification or background in risk, audit, information security, or a related discipline What you'll get in return Hybrid working, up to 3 days from home Competitive rates of pay The opportunity to work in a high-impact governance role within a large-scale, regulated technology environment Exposure to enterprise-wide risk and compliance frameworks, alongside senior leadership Involvement in significant transformation and change programmes A collaborative and forward-thinking culture with strong investment in governance maturity What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV. If this job isn't quite right for you but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Senior Vulnerability Analyst 50,000 - 57,000 + bonus and extensive benefits Full Time / Permanent West Midlands / Hybrid - 1-2 days a month in the office on average The Role and Company: I am looking for a driven Senior Vulnerability Analyst to join a large nationally recognised brand head quartered in the West Midlands. As a Senior Vulnerability Analyst you will be joining a highly skilled Cyber Defence team. As a key part if this team you will manage threats to the organisation and safeguard systems that enable the business to function safely and effectively. We are ideally looking for someone Midlands based who can be on site in Warwickshire 1-2 days a month on average. Responsibilities: Conducting regular vulnerability assessments using automated scanning tools, manual testing techniques, and security best practices to identify vulnerabilities in systems, networks, and applications Managing the lifecycle of vulnerabilities from discovery to remediation, including vulnerability triage, prioritisation, tracking, and reporting Analysing the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the organisation, and existing security controls Collaborating with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner Working closely with IT teams to ensure that security patches and updates are applied promptly to mitigate known vulnerabilities and reduce the organisation's exposure to security risks Generating detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders Providing guidance and training to employees on best practices for identifying and reporting security vulnerabilities, promoting a culture of security awareness within the organisation Experience required: Previous experience in a similar Vulnerability Management role preferably with experience in Operational Technology (OT) Skilled in cyber security, physical security, and risk management principles Excellent analytical and investigative skills Strong knowledge of the hardware and software systems in use across both IT and OT domains and the architectural arrangements in place to support management and operation of systems Ability to adapt to evolving threat landscapes Effective communication, critical thinking and problem-solving skills Must either hold SC clearance already or be eligible to obtain this if successful Please apply via the link or contact (url removed) for more information Modis International Ltd acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers in the UK. Modis Europe Ltd provide a variety of international solutions that connect clients to the best talent in the world. For all positions based in Switzerland, Modis Europe Ltd works with its licensed Swiss partner Accurity GmbH to ensure that candidate applications are handled in accordance with Swiss law. Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers. By applying for this role your details will be submitted to Modis International Ltd and/ or Modis Europe Ltd. Our Candidate Privacy Information Statement which explains how we will use your information is available on the Modis website.
Oct 03, 2025
Full time
Senior Vulnerability Analyst 50,000 - 57,000 + bonus and extensive benefits Full Time / Permanent West Midlands / Hybrid - 1-2 days a month in the office on average The Role and Company: I am looking for a driven Senior Vulnerability Analyst to join a large nationally recognised brand head quartered in the West Midlands. As a Senior Vulnerability Analyst you will be joining a highly skilled Cyber Defence team. As a key part if this team you will manage threats to the organisation and safeguard systems that enable the business to function safely and effectively. We are ideally looking for someone Midlands based who can be on site in Warwickshire 1-2 days a month on average. Responsibilities: Conducting regular vulnerability assessments using automated scanning tools, manual testing techniques, and security best practices to identify vulnerabilities in systems, networks, and applications Managing the lifecycle of vulnerabilities from discovery to remediation, including vulnerability triage, prioritisation, tracking, and reporting Analysing the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the organisation, and existing security controls Collaborating with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner Working closely with IT teams to ensure that security patches and updates are applied promptly to mitigate known vulnerabilities and reduce the organisation's exposure to security risks Generating detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders Providing guidance and training to employees on best practices for identifying and reporting security vulnerabilities, promoting a culture of security awareness within the organisation Experience required: Previous experience in a similar Vulnerability Management role preferably with experience in Operational Technology (OT) Skilled in cyber security, physical security, and risk management principles Excellent analytical and investigative skills Strong knowledge of the hardware and software systems in use across both IT and OT domains and the architectural arrangements in place to support management and operation of systems Ability to adapt to evolving threat landscapes Effective communication, critical thinking and problem-solving skills Must either hold SC clearance already or be eligible to obtain this if successful Please apply via the link or contact (url removed) for more information Modis International Ltd acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers in the UK. Modis Europe Ltd provide a variety of international solutions that connect clients to the best talent in the world. For all positions based in Switzerland, Modis Europe Ltd works with its licensed Swiss partner Accurity GmbH to ensure that candidate applications are handled in accordance with Swiss law. Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers. By applying for this role your details will be submitted to Modis International Ltd and/ or Modis Europe Ltd. Our Candidate Privacy Information Statement which explains how we will use your information is available on the Modis website.
Information Security Analyst - Heron Foods Salary: £35,000 - £45,000 per annum (depending on experience) Location: Hull (with hybrid working flexibility) About the Role We are looking for an Information Security Analyst to join the Group Information Security Function at B&M, with a dedicated focus on Heron Foods. In this role, you'll act as the primary contact for all things cyber and information security at Heron Foods, working day-to-day under the steer of the Head of IT at Heron Foods while aligning with the security strategy, policies, and standards set by the Group Head of Information Security. This is an exciting opportunity to be at the frontline of cyber defence - monitoring threats, responding to incidents, managing vulnerabilities, and embedding security into everyday operations across Heron Foods. Key Responsibilities As Information Security Analyst, you will: Be the first point of contact for all cyber and information security matters within Heron Foods. Monitor and respond to alerts from our Managed Security Operations Centre (SOC). Coordinate incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCI DSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall resilience. About You We're looking for someone who combines technical knowledge with an investigative mindset and strong stakeholder communication skills. Essential skills & experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. Desirable: Hands-on exposure to security tooling (e.g., EDR, SIEM, vulnerability scanners). Experience supporting audits and compliance activities. Scripting/automation skills (e.g., PowerShell, Python) to streamline tasks. Why Join Us? At B&M and Heron Foods, we are on a journey to strengthen our cyber resilience. This role offers: A unique opportunity to be the dedicated security lead for Heron Foods while benefiting from Group-level support and expertise. A competitive salary of £35,000 - £45,000 (depending on experience). Hybrid working arrangements. Excellent staff discount across B&M and Heron Foods stores. Opportunities for training, development, and progression within a growing security function. How to Apply If you're passionate about cyber security and want to make a real impact by protecting business-critical systems and data, apply today and help us keep Heron Foods secure.
Oct 02, 2025
Full time
Information Security Analyst - Heron Foods Salary: £35,000 - £45,000 per annum (depending on experience) Location: Hull (with hybrid working flexibility) About the Role We are looking for an Information Security Analyst to join the Group Information Security Function at B&M, with a dedicated focus on Heron Foods. In this role, you'll act as the primary contact for all things cyber and information security at Heron Foods, working day-to-day under the steer of the Head of IT at Heron Foods while aligning with the security strategy, policies, and standards set by the Group Head of Information Security. This is an exciting opportunity to be at the frontline of cyber defence - monitoring threats, responding to incidents, managing vulnerabilities, and embedding security into everyday operations across Heron Foods. Key Responsibilities As Information Security Analyst, you will: Be the first point of contact for all cyber and information security matters within Heron Foods. Monitor and respond to alerts from our Managed Security Operations Centre (SOC). Coordinate incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCI DSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall resilience. About You We're looking for someone who combines technical knowledge with an investigative mindset and strong stakeholder communication skills. Essential skills & experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. Desirable: Hands-on exposure to security tooling (e.g., EDR, SIEM, vulnerability scanners). Experience supporting audits and compliance activities. Scripting/automation skills (e.g., PowerShell, Python) to streamline tasks. Why Join Us? At B&M and Heron Foods, we are on a journey to strengthen our cyber resilience. This role offers: A unique opportunity to be the dedicated security lead for Heron Foods while benefiting from Group-level support and expertise. A competitive salary of £35,000 - £45,000 (depending on experience). Hybrid working arrangements. Excellent staff discount across B&M and Heron Foods stores. Opportunities for training, development, and progression within a growing security function. How to Apply If you're passionate about cyber security and want to make a real impact by protecting business-critical systems and data, apply today and help us keep Heron Foods secure.
Job Title: Lead Security Solution Architect- PAM Location: Hybrid-London, UK (Days/Week Onsite) Duration: 6months+ 550GBP/Day Inside IR35 Project Overview CLIENT is working on a strategic Identity and Access Management programme and is re-shaping the way Authentication, Federation, Privileged Access Management, Access Governance, Secrets Management and API Security is done across the bank. One of the pillars of that programe is Privileged Access Management (PAM). CLIENT is working on uplifting controls and capabilities in privileged access for the Group and introducing the strategic password vaulting solution that will enable to meet strategic requirements. We are seeking an experienced Lead Security Solution Architect that can complement an existing team of Solution Architects to progress with designs of different components of the PAM solution and other supporting systems it will need to integrate with as part of the end-to-end journey. Security Solution Architects manage end-to-end solution design and are responsible for delivering architecture design documents in line with functional and non-functional business requirements, strategies, principles, standards, and patterns. Alongside the creation of high-level designs, Security Solution Architects will be required to record key decisions, design deviations, and technical risks and issues where appropriate. Security Solution Architects should be comfortable presenting and sharing solutions at design authorities and senior leadership & stakeholders. The Lead Security Solution Architect will provide technical thought leadership and direction to their project team and may represent the project/programme as subject matter expert. This role will require someone experienced in managing a team of on-shore and off-shore resources to deliver High- and Low-level designs to the required quality and standard. Principal Preferred Requirements Cybersecurity Expertise: Significant experience and proven technical depth within one of the following domains of cybersecurity; security operations & incident response, threat & vulnerability management, identity & access management, cryptography, infrastructure, network, application, data, cloud Broad background across information technology with the ability to communicate clearly with non-security technical SMEs at a comfortable level Experience in both operational and transformation cybersecurity roles or a clear working understanding of both perspectives Experience working in large-scale IT transformation programmes Experience working with PAM solutions such as CyberArk, Centrify, Delinea and OneIdentity Preparing end-to-end configuration of the strategic PAM capability - including on-prem deployments as well as Cloud native toolings Assisting in preparation of demonstrable journeys on the configured PAM tooling Platform & Technology: BizzDesign, Archi, or generic UML visualisation experience for high-level designs High proficiency and expertise in Jira for project & tasks management Working proficiency in Confluence for documentation Principal Accountabilities and Responsibilities Architecture & Design: Produce, manage, and update end-to-end solution designs in line with reference architecture & business requirements (including High and Low Level Designs Articulate and publish key design decision records and options to ensure all solutions follow a logical, transparent decision-making process Articulate, publish, and ensure approval of any design deviations resulting in technical debt Ensure any technical risks or issues arising from a solution design are recorded and mitigated. Produces, manages and translates the requirements into the architecture for that solution, ensuring technology and services meet the customer needs and expected business outcomes Ensures the design of the solutions are efficient, timely and cost effective throughout the project life cycle Clear understanding of both the motivations of the business and technical security Promote strong documentation and clerkship Governance: Ensures all high-level designs, architecture patterns, decision records, deviation requests, and technical risks or issue records undergo architectural and project governance processes Ensure all architecture artefacts undergo appropriate peer review prior to design authority presentation Present publications at technical design authorities for input, feedback, and approval Risk and Dependency Management: Effectively manages and escalates both technical and project risks or issues Articulates solutions and remediation steps to technical risks & issues Ability to map design decisions to resultant technical risks & issues to articulate the cause and rationale which leads to any negatively impacting change Leadership & Teamwork Provides technical thought leadership to the Design Team and the Project Ability to manage a project team of technical architects, engineers, and/or analysts Ability to take a deputised role in programme management-related tasks where necessary Qualifications & Certifications: Masters or doctorate degree in cybersecurity, computer science, software engineering, or related field CISSP/CISM certification or other broad cybersecurity industry-recognised certificate SABSA or TOGAF certified preferred Priyanka Sharma Senior Delivery Consultant
Oct 02, 2025
Contractor
Job Title: Lead Security Solution Architect- PAM Location: Hybrid-London, UK (Days/Week Onsite) Duration: 6months+ 550GBP/Day Inside IR35 Project Overview CLIENT is working on a strategic Identity and Access Management programme and is re-shaping the way Authentication, Federation, Privileged Access Management, Access Governance, Secrets Management and API Security is done across the bank. One of the pillars of that programe is Privileged Access Management (PAM). CLIENT is working on uplifting controls and capabilities in privileged access for the Group and introducing the strategic password vaulting solution that will enable to meet strategic requirements. We are seeking an experienced Lead Security Solution Architect that can complement an existing team of Solution Architects to progress with designs of different components of the PAM solution and other supporting systems it will need to integrate with as part of the end-to-end journey. Security Solution Architects manage end-to-end solution design and are responsible for delivering architecture design documents in line with functional and non-functional business requirements, strategies, principles, standards, and patterns. Alongside the creation of high-level designs, Security Solution Architects will be required to record key decisions, design deviations, and technical risks and issues where appropriate. Security Solution Architects should be comfortable presenting and sharing solutions at design authorities and senior leadership & stakeholders. The Lead Security Solution Architect will provide technical thought leadership and direction to their project team and may represent the project/programme as subject matter expert. This role will require someone experienced in managing a team of on-shore and off-shore resources to deliver High- and Low-level designs to the required quality and standard. Principal Preferred Requirements Cybersecurity Expertise: Significant experience and proven technical depth within one of the following domains of cybersecurity; security operations & incident response, threat & vulnerability management, identity & access management, cryptography, infrastructure, network, application, data, cloud Broad background across information technology with the ability to communicate clearly with non-security technical SMEs at a comfortable level Experience in both operational and transformation cybersecurity roles or a clear working understanding of both perspectives Experience working in large-scale IT transformation programmes Experience working with PAM solutions such as CyberArk, Centrify, Delinea and OneIdentity Preparing end-to-end configuration of the strategic PAM capability - including on-prem deployments as well as Cloud native toolings Assisting in preparation of demonstrable journeys on the configured PAM tooling Platform & Technology: BizzDesign, Archi, or generic UML visualisation experience for high-level designs High proficiency and expertise in Jira for project & tasks management Working proficiency in Confluence for documentation Principal Accountabilities and Responsibilities Architecture & Design: Produce, manage, and update end-to-end solution designs in line with reference architecture & business requirements (including High and Low Level Designs Articulate and publish key design decision records and options to ensure all solutions follow a logical, transparent decision-making process Articulate, publish, and ensure approval of any design deviations resulting in technical debt Ensure any technical risks or issues arising from a solution design are recorded and mitigated. Produces, manages and translates the requirements into the architecture for that solution, ensuring technology and services meet the customer needs and expected business outcomes Ensures the design of the solutions are efficient, timely and cost effective throughout the project life cycle Clear understanding of both the motivations of the business and technical security Promote strong documentation and clerkship Governance: Ensures all high-level designs, architecture patterns, decision records, deviation requests, and technical risks or issue records undergo architectural and project governance processes Ensure all architecture artefacts undergo appropriate peer review prior to design authority presentation Present publications at technical design authorities for input, feedback, and approval Risk and Dependency Management: Effectively manages and escalates both technical and project risks or issues Articulates solutions and remediation steps to technical risks & issues Ability to map design decisions to resultant technical risks & issues to articulate the cause and rationale which leads to any negatively impacting change Leadership & Teamwork Provides technical thought leadership to the Design Team and the Project Ability to manage a project team of technical architects, engineers, and/or analysts Ability to take a deputised role in programme management-related tasks where necessary Qualifications & Certifications: Masters or doctorate degree in cybersecurity, computer science, software engineering, or related field CISSP/CISM certification or other broad cybersecurity industry-recognised certificate SABSA or TOGAF certified preferred Priyanka Sharma Senior Delivery Consultant
The Information Security Analyst will play a critical role in safeguarding the organisation's systems and data, ensuring compliance with security policies and regulations. Based in Hatfield, this role is ideal for individuals passionate about the life science industry and technology. Client Details The hiring company is a medium-sized organisation operating within the life science industry, with a focus on innovation and excellence in its field. The company is known for its commitment to leveraging technology to drive forward its mission. Description Implement and maintain ISMS aligning with ISO27001 Ensure security controls are in-place based on ISO27001 and NIST As the regional security representative in the global Security / Technology project Lead / execute phishing campaign Conduct vulnerability assessments and implement measures to mitigate potential risks. Involve in global security operations process, analysis and escalate security alerts / tickets from global SOC team Maintain and update security policies, standards, and procedures in alignment with industry regulations. Collaborate with cross-functional teams to ensure secure system designs and implementations. Provide training and support to staff to enhance security awareness across the organisation. Profile Practical experience and understanding of ISO27001 Familiar with NIST and GDPR is preferred Solid experience in threat, risk and vulnerabilities management process Experience with security tools such as SIEM, intrusion detection systems, and endpoint protection. Strong analytical and problem-solving skills. Hold at least one security related professional certification is desirable Job Offer 24 days of holiday leave Performance-based bonus of up to 10%. Pension scheme with contributions up to 10%. Private medical insurance, life assurance, dental cover Finance support on professional certifications / memberships
Oct 02, 2025
Full time
The Information Security Analyst will play a critical role in safeguarding the organisation's systems and data, ensuring compliance with security policies and regulations. Based in Hatfield, this role is ideal for individuals passionate about the life science industry and technology. Client Details The hiring company is a medium-sized organisation operating within the life science industry, with a focus on innovation and excellence in its field. The company is known for its commitment to leveraging technology to drive forward its mission. Description Implement and maintain ISMS aligning with ISO27001 Ensure security controls are in-place based on ISO27001 and NIST As the regional security representative in the global Security / Technology project Lead / execute phishing campaign Conduct vulnerability assessments and implement measures to mitigate potential risks. Involve in global security operations process, analysis and escalate security alerts / tickets from global SOC team Maintain and update security policies, standards, and procedures in alignment with industry regulations. Collaborate with cross-functional teams to ensure secure system designs and implementations. Provide training and support to staff to enhance security awareness across the organisation. Profile Practical experience and understanding of ISO27001 Familiar with NIST and GDPR is preferred Solid experience in threat, risk and vulnerabilities management process Experience with security tools such as SIEM, intrusion detection systems, and endpoint protection. Strong analytical and problem-solving skills. Hold at least one security related professional certification is desirable Job Offer 24 days of holiday leave Performance-based bonus of up to 10%. Pension scheme with contributions up to 10%. Private medical insurance, life assurance, dental cover Finance support on professional certifications / memberships
Information Security Senior Analyst Location: Surrey (Hybrid) Our client, a large corporate organisation based in Surrey, is seeking an Information Security Senior Analyst with experience of Risk & Controls to join their team. The successful candidate will have proven experience in risk management, controls, and governance frameworks, who can lead initiatives, mentor others, and collaborate effectively across business units. You should be both strategic and hands-on, with a passion for proactive security and continuous improvement. Responsibilities: Lead the InfoSec risk register - Identify, assess, and mitigate information security risks. Own control frameworks - Maintain and improve controls to ensure alignment with standards like NIST CSF and COBIT. Drive assurance - Monitor the effectiveness of security controls, including outcomes of penetration testing and red team exercises. Collaborate with business units - Act as a security advocate and guide cross-functional teams in secure practices. Lead technical initiatives - Provide hands-on leadership and mentor more junior team members. Conduct threat and vulnerability assessments - Take a proactive role in identifying potential security threats. Skills and experience required: Strong experience in risk & controls within the information security, ideally in a regulated industry. Experience in large, complex enterprise environments (e.g., multiple sites, technologies). Hands-on leadership in technical InfoSec initiatives. Strong understanding and implementation of control frameworks (NIST CSF, COBIT). Ability to run threat intelligence and vulnerability assessments. Experience collaborating with 2nd and 3rd line governance teams (e.g., audit, compliance). Strong stakeholder engagement and influencing skills. Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
Sep 27, 2025
Full time
Information Security Senior Analyst Location: Surrey (Hybrid) Our client, a large corporate organisation based in Surrey, is seeking an Information Security Senior Analyst with experience of Risk & Controls to join their team. The successful candidate will have proven experience in risk management, controls, and governance frameworks, who can lead initiatives, mentor others, and collaborate effectively across business units. You should be both strategic and hands-on, with a passion for proactive security and continuous improvement. Responsibilities: Lead the InfoSec risk register - Identify, assess, and mitigate information security risks. Own control frameworks - Maintain and improve controls to ensure alignment with standards like NIST CSF and COBIT. Drive assurance - Monitor the effectiveness of security controls, including outcomes of penetration testing and red team exercises. Collaborate with business units - Act as a security advocate and guide cross-functional teams in secure practices. Lead technical initiatives - Provide hands-on leadership and mentor more junior team members. Conduct threat and vulnerability assessments - Take a proactive role in identifying potential security threats. Skills and experience required: Strong experience in risk & controls within the information security, ideally in a regulated industry. Experience in large, complex enterprise environments (e.g., multiple sites, technologies). Hands-on leadership in technical InfoSec initiatives. Strong understanding and implementation of control frameworks (NIST CSF, COBIT). Ability to run threat intelligence and vulnerability assessments. Experience collaborating with 2nd and 3rd line governance teams (e.g., audit, compliance). Strong stakeholder engagement and influencing skills. Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
Information Security Analyst - Heron Foods Salary: £35,000 - £45,000 per annum (depending on experience) Location: Hull (with hybrid working flexibility) About the Role We are looking for an Information Security Analyst to join the Group Information Security Function at B&M, with a dedicated focus on Heron Foods. In this role, you'll act as the primary contact for all things cyber and information security at Heron Foods, working day-to-day under the steer of the Head of IT at Heron Foods while aligning with the security strategy, policies, and standards set by the Group Head of Information Security. This is an exciting opportunity to be at the frontline of cyber defence - monitoring threats, responding to incidents, managing vulnerabilities, and embedding security into everyday operations across Heron Foods. Key Responsibilities As Information Security Analyst, you will: Be the first point of contact for all cyber and information security matters within Heron Foods. Monitor and respond to alerts from our Managed Security Operations Centre (SOC). Coordinate incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCI DSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall resilience. About You We're looking for someone who combines technical knowledge with an investigative mindset and strong stakeholder communication skills. Essential skills & experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. Desirable: Hands-on exposure to security tooling (e.g., EDR, SIEM, vulnerability scanners). Experience supporting audits and compliance activities. Scripting/automation skills (e.g., PowerShell, Python) to streamline tasks. Why Join Us? At B&M and Heron Foods, we are on a journey to strengthen our cyber resilience. This role offers: A unique opportunity to be the dedicated security lead for Heron Foods while benefiting from Group-level support and expertise. A competitive salary of £35,000 - £45,000 (depending on experience). Hybrid working arrangements. Excellent staff discount across B&M and Heron Foods stores. Opportunities for training, development, and progression within a growing security function. How to Apply If you're passionate about cyber security and want to make a real impact by protecting business-critical systems and data, apply today and help us keep Heron Foods secure.
Sep 21, 2025
Full time
Information Security Analyst - Heron Foods Salary: £35,000 - £45,000 per annum (depending on experience) Location: Hull (with hybrid working flexibility) About the Role We are looking for an Information Security Analyst to join the Group Information Security Function at B&M, with a dedicated focus on Heron Foods. In this role, you'll act as the primary contact for all things cyber and information security at Heron Foods, working day-to-day under the steer of the Head of IT at Heron Foods while aligning with the security strategy, policies, and standards set by the Group Head of Information Security. This is an exciting opportunity to be at the frontline of cyber defence - monitoring threats, responding to incidents, managing vulnerabilities, and embedding security into everyday operations across Heron Foods. Key Responsibilities As Information Security Analyst, you will: Be the first point of contact for all cyber and information security matters within Heron Foods. Monitor and respond to alerts from our Managed Security Operations Centre (SOC). Coordinate incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCI DSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall resilience. About You We're looking for someone who combines technical knowledge with an investigative mindset and strong stakeholder communication skills. Essential skills & experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. Desirable: Hands-on exposure to security tooling (e.g., EDR, SIEM, vulnerability scanners). Experience supporting audits and compliance activities. Scripting/automation skills (e.g., PowerShell, Python) to streamline tasks. Why Join Us? At B&M and Heron Foods, we are on a journey to strengthen our cyber resilience. This role offers: A unique opportunity to be the dedicated security lead for Heron Foods while benefiting from Group-level support and expertise. A competitive salary of £35,000 - £45,000 (depending on experience). Hybrid working arrangements. Excellent staff discount across B&M and Heron Foods stores. Opportunities for training, development, and progression within a growing security function. How to Apply If you're passionate about cyber security and want to make a real impact by protecting business-critical systems and data, apply today and help us keep Heron Foods secure.