Government Digital & Data
Location Aberystwyth, Cardiff, Llandudno Junction, Merthyr Tydfil, Swansea About the job Job summary About Us We are an arm's length body of the Welsh Government, responsible for the strategy, funding and oversight of: further education higher education including research and innovation; apprenticeships adult community learning; and local authority maintained school sixth forms. We work in close collaboration with our partners to enable a tertiary education and research system which is centred around the needs of learners; society; and economy with excellence, equality and engagement at its heart. Our values really matter to us, they help shape the culture of our organisation: Dysgu (to learn; to teach; to educate) - learning is at the heart of everything we do. We believe curiosity fuels innovation and helps expand our horizons. Cydweithio (to work together; to collaborate; to co-operate) - we can achieve far more together than we ever could alone. Cynnwys Pawb (to include everyone; to involve everyone) - we are passionate about inclusion, seeking to create the right conditions for everyone to achieve their full potential. Rhagori (to exceed; to excel) - we have high aspirations for tertiary education and research in Wales and always set high standards for ourselves to be the best we can be. We are proud to be a Disability Confident employer and accredited as a Living Wage employer. Location Our headquarters is in 2, Capital Quarter, Cardiff, which has been specifically designed to meet our needs. This is where most colleagues will meet to collaborate, both with each other and with stakeholders. As we operate across Wales, we also have limited office and collaboration space in Welsh Government offices in Llandudno Junction, Aberystwyth, Swansea and Merthyr Tydfil. Main purpose of the job The Cyber Security Analyst is responsible for safeguarding Medr's digital assets by monitoring, analysing, and responding to cyber threats across its systems and services. The role ensures effective security controls are implemented in line with security policies and latest standards, supports secure system and service design, and undertakes real-time threat analysis, risk assessments and incident investigations. The role is critical to maintaining the confidentiality, integrity, and availability of Medr's data and infrastructure, while supporting the resilience of its digital operations in an evolving threat landscape. Job description What you'll be doing Monitor, detect, and respond to cyber threats by conducting real time security monitoring, threat hunting, forensic investigations, and timely system patching to protect systems, networks, software, and data. Identify and mitigate security risks and vulnerabilities through software risk assessments, continuous infrastructure monitoring, audits, and validation activities to ensure data integrity, timeliness, and completeness. Design and enforce robust security controls and policies , embedding security into systems and application design and ensuring compliance with Cyber Essentials Plus and IASME Level 2 standards. Manage access and permissions by maintaining strong user access controls and administrative privileges to prevent unauthorised access and data breaches. Promote a strong security culture by delivering employee training and awareness programmes, supporting and challenging users where necessary, and encouraging continuous improvement and compliance with data standards. Collaborate and communicate effectively with Digital teams, management, external suppliers, and stakeholders, maintaining up to date security documentation, producing security papers, and reporting progress and key challenges to senior leadership. Key challenges you will face Working in a fast-paced environment, with competing priorities and critical deadlines. Ensuring that data governance and management approaches align with business needs, compliance requirements and best practice. Integrate with a shared SOC/MDR service. Incident response under pressure. Preparing and participating in numerous audits where compliance is critical to the business function. Sector collaboration by securing credibility and trust with a range of stakeholders. About your team The Digital Directorate within Medr spans three core areas: Development , Information Systems , and IT Security & Technical Services . Together, we design and manage systems, develop applications and ensure robust security, governance and compliance is in place. The Cyber Security Analyst will report directly to the Senior Technical Services Manager who also manages the IT Support Manager and Officer posts. The team will be led by the Head of IT Security and Technical Services. About your line manager The Senior Technical Services Manager brings over 25 years of digital experience and has been with HEFCW, Medr's predecessor, since 2019, having seconded from a local Governments Network Team. As lead Technical Architect, he had a key role in the design and implementation of Medr's IT environments, security profile, corporate IT systems, client solutions, data management processes, governance controls, and IT risk management. Person specification What you'll bring Attributes Drive : You lead by example, showing dedication and perseverance in meeting organisational objectives Agile : You drive forward improvements, through collaboration, embracing new technologies and nurturing a culture of continuous learning. Resilient : You lead with resilience in terms of uncertainty and change, inspiring your team to persevere despite obstacle Dynamic - You encourage a culture of innovation and continuous improvement, encouraging experimentation and learning. Experience Technical experience in securing Microsoft Azure and Office 365 environments, with hands-on knowledge of cloud security tools such as Microsoft Sentinel, Purview or Microsoft Defender for Endpoint/Cloud SIEM tools. Capable of analysing and interpreting security events and logs, and performing digital forensics tasks. Experienced in responding to threat intelligence and vulnerability management platforms. Demonstrates comprehensive understanding of cybersecurity frameworks, regulatory compliance requirements such as UK GDPR and the Data Protection Act 2018, and expertise with security technologies including firewalls, VPNs, and intrusion detection/prevention systems. Possesses strong analytical, communication, and problem-solving abilities, as well as proficiency in preparing clear and effective technical and non-technical reports. Welsh language requirements We have evaluated that the Welsh language requirements for this post are: Desirable: Welsh desirable means that while having Welsh language skills is useful for the role, it is not an assessment criterion, so it won't disadvantage you during recruitment if you don't currently possess these skills. Qualifications A bachelor's degree in computer science, cybersecurity, or a closely related field is typically required; postgraduate qualifications or professional certifications (e.g., CISSP, CISM, CompTIA Security+) or several years of relevant experience in information security, network administration, or IT risk management.
Location Aberystwyth, Cardiff, Llandudno Junction, Merthyr Tydfil, Swansea About the job Job summary About Us We are an arm's length body of the Welsh Government, responsible for the strategy, funding and oversight of: further education higher education including research and innovation; apprenticeships adult community learning; and local authority maintained school sixth forms. We work in close collaboration with our partners to enable a tertiary education and research system which is centred around the needs of learners; society; and economy with excellence, equality and engagement at its heart. Our values really matter to us, they help shape the culture of our organisation: Dysgu (to learn; to teach; to educate) - learning is at the heart of everything we do. We believe curiosity fuels innovation and helps expand our horizons. Cydweithio (to work together; to collaborate; to co-operate) - we can achieve far more together than we ever could alone. Cynnwys Pawb (to include everyone; to involve everyone) - we are passionate about inclusion, seeking to create the right conditions for everyone to achieve their full potential. Rhagori (to exceed; to excel) - we have high aspirations for tertiary education and research in Wales and always set high standards for ourselves to be the best we can be. We are proud to be a Disability Confident employer and accredited as a Living Wage employer. Location Our headquarters is in 2, Capital Quarter, Cardiff, which has been specifically designed to meet our needs. This is where most colleagues will meet to collaborate, both with each other and with stakeholders. As we operate across Wales, we also have limited office and collaboration space in Welsh Government offices in Llandudno Junction, Aberystwyth, Swansea and Merthyr Tydfil. Main purpose of the job The Cyber Security Analyst is responsible for safeguarding Medr's digital assets by monitoring, analysing, and responding to cyber threats across its systems and services. The role ensures effective security controls are implemented in line with security policies and latest standards, supports secure system and service design, and undertakes real-time threat analysis, risk assessments and incident investigations. The role is critical to maintaining the confidentiality, integrity, and availability of Medr's data and infrastructure, while supporting the resilience of its digital operations in an evolving threat landscape. Job description What you'll be doing Monitor, detect, and respond to cyber threats by conducting real time security monitoring, threat hunting, forensic investigations, and timely system patching to protect systems, networks, software, and data. Identify and mitigate security risks and vulnerabilities through software risk assessments, continuous infrastructure monitoring, audits, and validation activities to ensure data integrity, timeliness, and completeness. Design and enforce robust security controls and policies , embedding security into systems and application design and ensuring compliance with Cyber Essentials Plus and IASME Level 2 standards. Manage access and permissions by maintaining strong user access controls and administrative privileges to prevent unauthorised access and data breaches. Promote a strong security culture by delivering employee training and awareness programmes, supporting and challenging users where necessary, and encouraging continuous improvement and compliance with data standards. Collaborate and communicate effectively with Digital teams, management, external suppliers, and stakeholders, maintaining up to date security documentation, producing security papers, and reporting progress and key challenges to senior leadership. Key challenges you will face Working in a fast-paced environment, with competing priorities and critical deadlines. Ensuring that data governance and management approaches align with business needs, compliance requirements and best practice. Integrate with a shared SOC/MDR service. Incident response under pressure. Preparing and participating in numerous audits where compliance is critical to the business function. Sector collaboration by securing credibility and trust with a range of stakeholders. About your team The Digital Directorate within Medr spans three core areas: Development , Information Systems , and IT Security & Technical Services . Together, we design and manage systems, develop applications and ensure robust security, governance and compliance is in place. The Cyber Security Analyst will report directly to the Senior Technical Services Manager who also manages the IT Support Manager and Officer posts. The team will be led by the Head of IT Security and Technical Services. About your line manager The Senior Technical Services Manager brings over 25 years of digital experience and has been with HEFCW, Medr's predecessor, since 2019, having seconded from a local Governments Network Team. As lead Technical Architect, he had a key role in the design and implementation of Medr's IT environments, security profile, corporate IT systems, client solutions, data management processes, governance controls, and IT risk management. Person specification What you'll bring Attributes Drive : You lead by example, showing dedication and perseverance in meeting organisational objectives Agile : You drive forward improvements, through collaboration, embracing new technologies and nurturing a culture of continuous learning. Resilient : You lead with resilience in terms of uncertainty and change, inspiring your team to persevere despite obstacle Dynamic - You encourage a culture of innovation and continuous improvement, encouraging experimentation and learning. Experience Technical experience in securing Microsoft Azure and Office 365 environments, with hands-on knowledge of cloud security tools such as Microsoft Sentinel, Purview or Microsoft Defender for Endpoint/Cloud SIEM tools. Capable of analysing and interpreting security events and logs, and performing digital forensics tasks. Experienced in responding to threat intelligence and vulnerability management platforms. Demonstrates comprehensive understanding of cybersecurity frameworks, regulatory compliance requirements such as UK GDPR and the Data Protection Act 2018, and expertise with security technologies including firewalls, VPNs, and intrusion detection/prevention systems. Possesses strong analytical, communication, and problem-solving abilities, as well as proficiency in preparing clear and effective technical and non-technical reports. Welsh language requirements We have evaluated that the Welsh language requirements for this post are: Desirable: Welsh desirable means that while having Welsh language skills is useful for the role, it is not an assessment criterion, so it won't disadvantage you during recruitment if you don't currently possess these skills. Qualifications A bachelor's degree in computer science, cybersecurity, or a closely related field is typically required; postgraduate qualifications or professional certifications (e.g., CISSP, CISM, CompTIA Security+) or several years of relevant experience in information security, network administration, or IT risk management.
Interface Recruitment
Senior Security Engineering Team Lead Leeds (Home with 1 HQ visit per quarter) Up to 82,500 (NEG) + Excellent Benefits Are you an experienced Security Engineer ready to lead from the front? We're supporting a leading international managed technology organisation in the search for a Senior Security Engineering Team Lead to head a dedicated cyber security engineering function supporting a major enterprise customer operating within a highly regulated environment. This is far more than a traditional management role. You'll remain hands-on, acting as the technical authority for Microsoft security technologies whilst leading a team of experienced Security Analysts and Engineers responsible for protecting a critical customer environment. If you're passionate about Microsoft security, detection engineering, automation and mentoring technical teams, this is an opportunity to influence the direction of an enterprise-scale security operation. The Opportunity As the technical lead for the Security Engineering function, you'll own the security platform estate, providing architectural guidance, driving continuous improvement and acting as the primary escalation point for complex cyber security incidents. You'll combine strategic leadership with hands-on engineering, working closely with Security Analysts, Infrastructure teams and customer stakeholders to ensure security platforms remain resilient, effective and continually evolving. This is an excellent opportunity to join an organisation that invests heavily in technology, professional development and long-term career progression whilst working with some of the latest Microsoft security technologies. Key Responsibilities Lead and develop a team of Security Engineers and Security Analysts Act as the senior technical escalation point for complex cyber security incidents Own the configuration, maintenance and optimisation of the Microsoft security platform Drive detection engineering, rule tuning and continuous platform improvement Lead SIEM and SOAR engineering activities, including automation and Logic Apps Oversee log ingestion, telemetry quality and detection coverage Support vulnerability management and exposure management tooling Work closely with customers and internal technical teams on security architecture and platform improvements Mentor engineers and analysts, helping raise technical capability across the team Contribute to platform roadmaps, governance, documentation and service improvements Technology Environment You'll work across a modern Microsoft-centric cyber security stack including: Microsoft Defender XDR Defender for Endpoint Defender for Identity Microsoft Sentinel Logic Apps SOAR Automation Microsoft Purview Qualys XM Cyber CyberArk Detection Engineering KQL Threat Hunting Platform Engineering About You We're looking for someone who combines deep technical expertise with natural leadership skills. You'll likely have experience in areas such as: Security Engineering Detection Engineering SOC Engineering Microsoft Security Security Platform Management Cyber Security Architecture Security Automation Team Leadership You'll also possess: Expert knowledge of Microsoft Defender technologies Strong Microsoft Sentinel experience Experience building or improving security detections Knowledge of SOAR and security automation Experience within regulated or enterprise environments Excellent stakeholder management and communication skills Previous leadership or mentoring experience Why Apply? This organisation is recognised as one of the world's leading managed technology providers, delivering cloud, cyber security, data and digital workplace solutions to thousands of enterprise customers across multiple countries. It combines the scale of an international business with a culture that genuinely invests in its people through continuous learning, technical certifications, structured development programmes and internal career progression. You'll be joining at an exciting stage of growth, leading a newly established security capability supporting a strategic customer where you'll have genuine influence over both the technology roadmap and the development of your team. Package Salary up to 82,500 (NEG) Home working with one visit to HQ per quarter Excellent benefits package Significant investment in training and certifications Career progression opportunities Opportunity to work with enterprise Microsoft security technologies Technical leadership role with genuine strategic influence
Senior Security Engineering Team Lead Leeds (Home with 1 HQ visit per quarter) Up to 82,500 (NEG) + Excellent Benefits Are you an experienced Security Engineer ready to lead from the front? We're supporting a leading international managed technology organisation in the search for a Senior Security Engineering Team Lead to head a dedicated cyber security engineering function supporting a major enterprise customer operating within a highly regulated environment. This is far more than a traditional management role. You'll remain hands-on, acting as the technical authority for Microsoft security technologies whilst leading a team of experienced Security Analysts and Engineers responsible for protecting a critical customer environment. If you're passionate about Microsoft security, detection engineering, automation and mentoring technical teams, this is an opportunity to influence the direction of an enterprise-scale security operation. The Opportunity As the technical lead for the Security Engineering function, you'll own the security platform estate, providing architectural guidance, driving continuous improvement and acting as the primary escalation point for complex cyber security incidents. You'll combine strategic leadership with hands-on engineering, working closely with Security Analysts, Infrastructure teams and customer stakeholders to ensure security platforms remain resilient, effective and continually evolving. This is an excellent opportunity to join an organisation that invests heavily in technology, professional development and long-term career progression whilst working with some of the latest Microsoft security technologies. Key Responsibilities Lead and develop a team of Security Engineers and Security Analysts Act as the senior technical escalation point for complex cyber security incidents Own the configuration, maintenance and optimisation of the Microsoft security platform Drive detection engineering, rule tuning and continuous platform improvement Lead SIEM and SOAR engineering activities, including automation and Logic Apps Oversee log ingestion, telemetry quality and detection coverage Support vulnerability management and exposure management tooling Work closely with customers and internal technical teams on security architecture and platform improvements Mentor engineers and analysts, helping raise technical capability across the team Contribute to platform roadmaps, governance, documentation and service improvements Technology Environment You'll work across a modern Microsoft-centric cyber security stack including: Microsoft Defender XDR Defender for Endpoint Defender for Identity Microsoft Sentinel Logic Apps SOAR Automation Microsoft Purview Qualys XM Cyber CyberArk Detection Engineering KQL Threat Hunting Platform Engineering About You We're looking for someone who combines deep technical expertise with natural leadership skills. You'll likely have experience in areas such as: Security Engineering Detection Engineering SOC Engineering Microsoft Security Security Platform Management Cyber Security Architecture Security Automation Team Leadership You'll also possess: Expert knowledge of Microsoft Defender technologies Strong Microsoft Sentinel experience Experience building or improving security detections Knowledge of SOAR and security automation Experience within regulated or enterprise environments Excellent stakeholder management and communication skills Previous leadership or mentoring experience Why Apply? This organisation is recognised as one of the world's leading managed technology providers, delivering cloud, cyber security, data and digital workplace solutions to thousands of enterprise customers across multiple countries. It combines the scale of an international business with a culture that genuinely invests in its people through continuous learning, technical certifications, structured development programmes and internal career progression. You'll be joining at an exciting stage of growth, leading a newly established security capability supporting a strategic customer where you'll have genuine influence over both the technology roadmap and the development of your team. Package Salary up to 82,500 (NEG) Home working with one visit to HQ per quarter Excellent benefits package Significant investment in training and certifications Career progression opportunities Opportunity to work with enterprise Microsoft security technologies Technical leadership role with genuine strategic influence
Hays Technology
Bletchley, Buckinghamshire
6 Month Contract 500 Outside IR35 1/2 days on site in Milton Keynes We're seeking an experienced Purview Data Governance Analyst to play a key role in delivering a modern, governed data platform built on Microsoft Fabric and Azure.This is a delivery-focused contract where you'll work closely with data engineering and information security teams to implement practical governance solutions, ensuring critical data assets are properly catalogued, classified, secured and traceable across the enterprise. The role You'll be responsible for establishing robust data governance foundations, transforming governance policies into working configurations and delivering tangible outcomes across data lineage, classification, sensitivity labelling and access governance. This role is ideal for someone who enjoys getting hands-on with Microsoft Purview, working in fast-paced environments, and creating measurable governance outcomes rather than simply advising on strategy. Key Responsibilities Data Lineage & Metadata Management Configure and manage Microsoft Purview scanning and lineage capabilities across key source systems. Establish end-to-end lineage across Microsoft Fabric's Bronze, Silver and Gold layers and reporting environments. Identify lineage gaps and implement repeatable governance processes and standards. Support the development and maintenance of the enterprise data catalogue and business glossary. Classification & Sensitivity Labelling Define and apply data classifications and Microsoft Information Protection (MIP) sensitivity labels. Configure automated classification rules and custom classifiers. Develop and maintain metadata standards, taxonomies and governance frameworks. Improve data visibility and protection through effective tagging and governance controls. Access Governance & Security Partner with Information Security teams to implement role-based access control (RBAC) models. Align data sensitivity classifications with access entitlements and least-privilege principles. Support access governance reviews and contribute to governance evidence and documentation. Help translate governance and security policies into practical technical controls. Governance Reporting & Knowledge Transfer Produce governance reporting covering lineage, catalogue coverage, classifications and access exceptions. Develop governance standards, runbooks and operating procedures. Support business data stewards and ensure governance capability is embedded within the organisation. Essential Skills & Experience Proven hands-on experience implementing Microsoft Purview in enterprise environments. Strong experience with: Data lineage Data catalogue management Data classification Sensitivity labelling (MIP) Data governance frameworks Experience implementing or enabling RBAC and access governance controls. Strong knowledge of the Microsoft data ecosystem, including: Microsoft Fabric OneLake Medallion Architecture (Bronze, Silver, Gold) Azure Data Factory Power BI Ability to work independently and manage priorities in a fast-moving environment. Excellent stakeholder management, communication and documentation skills. Desirable Experience Experience within regulated or highly data-sensitive environments. Knowledge of UK GDPR and data protection principles. Exposure to data mesh or federated data governance models. Familiarity with data quality frameworks and metadata-driven governance. Microsoft certifications such as DP-700, SC-400 or SC-300. Experience supporting cloud migration or governance implementation across newly established Azure data platforms. What's on Offer? Opportunity to shape governance across a modern Microsoft Fabric data platform. Work alongside data engineering and security specialists on high-profile data initiatives. Genuine ownership and autonomy to drive governance outcomes. Contract role focused on delivering meaningful, measurable business value. What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now. If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
6 Month Contract 500 Outside IR35 1/2 days on site in Milton Keynes We're seeking an experienced Purview Data Governance Analyst to play a key role in delivering a modern, governed data platform built on Microsoft Fabric and Azure.This is a delivery-focused contract where you'll work closely with data engineering and information security teams to implement practical governance solutions, ensuring critical data assets are properly catalogued, classified, secured and traceable across the enterprise. The role You'll be responsible for establishing robust data governance foundations, transforming governance policies into working configurations and delivering tangible outcomes across data lineage, classification, sensitivity labelling and access governance. This role is ideal for someone who enjoys getting hands-on with Microsoft Purview, working in fast-paced environments, and creating measurable governance outcomes rather than simply advising on strategy. Key Responsibilities Data Lineage & Metadata Management Configure and manage Microsoft Purview scanning and lineage capabilities across key source systems. Establish end-to-end lineage across Microsoft Fabric's Bronze, Silver and Gold layers and reporting environments. Identify lineage gaps and implement repeatable governance processes and standards. Support the development and maintenance of the enterprise data catalogue and business glossary. Classification & Sensitivity Labelling Define and apply data classifications and Microsoft Information Protection (MIP) sensitivity labels. Configure automated classification rules and custom classifiers. Develop and maintain metadata standards, taxonomies and governance frameworks. Improve data visibility and protection through effective tagging and governance controls. Access Governance & Security Partner with Information Security teams to implement role-based access control (RBAC) models. Align data sensitivity classifications with access entitlements and least-privilege principles. Support access governance reviews and contribute to governance evidence and documentation. Help translate governance and security policies into practical technical controls. Governance Reporting & Knowledge Transfer Produce governance reporting covering lineage, catalogue coverage, classifications and access exceptions. Develop governance standards, runbooks and operating procedures. Support business data stewards and ensure governance capability is embedded within the organisation. Essential Skills & Experience Proven hands-on experience implementing Microsoft Purview in enterprise environments. Strong experience with: Data lineage Data catalogue management Data classification Sensitivity labelling (MIP) Data governance frameworks Experience implementing or enabling RBAC and access governance controls. Strong knowledge of the Microsoft data ecosystem, including: Microsoft Fabric OneLake Medallion Architecture (Bronze, Silver, Gold) Azure Data Factory Power BI Ability to work independently and manage priorities in a fast-moving environment. Excellent stakeholder management, communication and documentation skills. Desirable Experience Experience within regulated or highly data-sensitive environments. Knowledge of UK GDPR and data protection principles. Exposure to data mesh or federated data governance models. Familiarity with data quality frameworks and metadata-driven governance. Microsoft certifications such as DP-700, SC-400 or SC-300. Experience supporting cloud migration or governance implementation across newly established Azure data platforms. What's on Offer? Opportunity to shape governance across a modern Microsoft Fabric data platform. Work alongside data engineering and security specialists on high-profile data initiatives. Genuine ownership and autonomy to drive governance outcomes. Contract role focused on delivering meaningful, measurable business value. What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now. If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)