Information Vulnerability Analyst - Staffordshire Our client is looking for an Information Vulnerability Analyst to join their growing Information Security team. This is a key role focused on identifying, assessing, and mitigating security vulnerabilities across IT, OT, cloud, and SaaS environments. You will work closely with infrastructure, applications, and operations teams to ensure that risks are effectively managed and remediated. This position is ideal for someone who is proactive rather than reactive someone who enjoys identifying vulnerabilities before they become issues and takes ownership of driving them through to resolution. We are looking for a hands-on individual who thrives in a collaborative environment. You will work closely with service desk, networking, and infrastructure teams, influencing stakeholders and ensuring a joined-up approach to vulnerability management across the organisation. Key Responsibilities Manage the global vulnerability management process and associated platforms Perform regular vulnerability scans across IT, OT, and SaaS environments using industry-standard tools Coordinate and manage third-party security penetration testing across internal and external systems Analyse scan results, prioritise vulnerabilities, and drive remediation through to completion Maintain and enhance vulnerability management processes and reporting frameworks Contribute to the risk register and support ongoing security improvements Track remediation progress and report on risk posture to senior stakeholders Work closely with IT and engineering teams to ensure secure configurations and effective patch management Identify root causes of vulnerabilities and support long-term solutions Support compliance with frameworks such as NIST and Cyber Essentials Assist with threat modelling and risk assessments Maintain documentation, procedures, and security best practices Proactively identify opportunities to strengthen the organisation s overall security posture This is a fantastic opportunity to make a real impact in a business that values proactive security and continuous improvement. If this sounds like the right next step in your career, we d love to hear from you. This is an onsite position with opportunities for progression and development. For more info, please get in touch.
Aug 05, 2026
Full time
Information Vulnerability Analyst - Staffordshire Our client is looking for an Information Vulnerability Analyst to join their growing Information Security team. This is a key role focused on identifying, assessing, and mitigating security vulnerabilities across IT, OT, cloud, and SaaS environments. You will work closely with infrastructure, applications, and operations teams to ensure that risks are effectively managed and remediated. This position is ideal for someone who is proactive rather than reactive someone who enjoys identifying vulnerabilities before they become issues and takes ownership of driving them through to resolution. We are looking for a hands-on individual who thrives in a collaborative environment. You will work closely with service desk, networking, and infrastructure teams, influencing stakeholders and ensuring a joined-up approach to vulnerability management across the organisation. Key Responsibilities Manage the global vulnerability management process and associated platforms Perform regular vulnerability scans across IT, OT, and SaaS environments using industry-standard tools Coordinate and manage third-party security penetration testing across internal and external systems Analyse scan results, prioritise vulnerabilities, and drive remediation through to completion Maintain and enhance vulnerability management processes and reporting frameworks Contribute to the risk register and support ongoing security improvements Track remediation progress and report on risk posture to senior stakeholders Work closely with IT and engineering teams to ensure secure configurations and effective patch management Identify root causes of vulnerabilities and support long-term solutions Support compliance with frameworks such as NIST and Cyber Essentials Assist with threat modelling and risk assessments Maintain documentation, procedures, and security best practices Proactively identify opportunities to strengthen the organisation s overall security posture This is a fantastic opportunity to make a real impact in a business that values proactive security and continuous improvement. If this sounds like the right next step in your career, we d love to hear from you. This is an onsite position with opportunities for progression and development. For more info, please get in touch.
SOC Engineer Milton Keynes - Hybrid working SC Clearance Sponsorship Available £50,000 - £55,000 + Bonus We're seeking a hands-on SOC Engineer to join a growing Cyber Security Operations Centre supporting a diverse portfolio of customers across multiple sectors This is a specialist SOC Engineering position focused on building, maintaining, and optimising the tools, telemetry, detections, and automation that enable SOC Analysts to identify and respond to threats effectively. This is not a generalist cyber security role. Key Responsibilities Administer and optimise Microsoft Sentinel (or equivalent SIEM), including log ingestion, parsing, normalisation, and retention. Develop and maintain SOAR workflows and automation using Azure Logic Apps, Python, PowerShell, Bash, and KQL. Onboard and manage security telemetry from a range of data sources. Design, implement, and tune detection rules to improve alert quality and reduce false positives. Conduct proactive threat hunting using SIEM, EDR, and threat intelligence sources. Support incident investigations, containment, and response activities. Monitor and maintain the health of SOC tooling, sensors, agents, and log pipelines. Produce documentation, runbooks, and operational procedures. Skills & Experience Experience engineering and supporting SIEM platforms, ideally Microsoft Sentinel. Strong Scripting and automation skills (Python, PowerShell, Bash, KQL). Experience with SOAR technologies and security automation. Knowledge of detection engineering and threat hunting. Strong understanding of Windows and Linux logging. Good networking knowledge including TCP/IP, DNS, Firewalls, and proxies. Experience within a SOC, NOC, or 24/7 operational environment. Familiarity with MITRE ATT&CK, CVEs, and vulnerability management. Exposure to cloud security monitoring across Azure, AWS, or Microsoft 365. Desirable Certifications Microsoft SC-200 CompTIA Security+/CySA+ ISC2 CC or CISSP GIAC GCIA CEH Cisco CyberOps or Fortinet certifications What's on Offer? Opportunity to work within a mature and growing SOC environment. Exposure to a wide range of customer environments and technologies. Security Clearance sponsorship available for eligible candidates. Clear opportunities to contribute to automation, detection engineering, and SOC improvement initiatives. Location: Milton Keynes (full-time onsite) Working Pattern: Shift rota including evenings, weekends, bank holidays on-call support. Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
Aug 04, 2026
Full time
SOC Engineer Milton Keynes - Hybrid working SC Clearance Sponsorship Available £50,000 - £55,000 + Bonus We're seeking a hands-on SOC Engineer to join a growing Cyber Security Operations Centre supporting a diverse portfolio of customers across multiple sectors This is a specialist SOC Engineering position focused on building, maintaining, and optimising the tools, telemetry, detections, and automation that enable SOC Analysts to identify and respond to threats effectively. This is not a generalist cyber security role. Key Responsibilities Administer and optimise Microsoft Sentinel (or equivalent SIEM), including log ingestion, parsing, normalisation, and retention. Develop and maintain SOAR workflows and automation using Azure Logic Apps, Python, PowerShell, Bash, and KQL. Onboard and manage security telemetry from a range of data sources. Design, implement, and tune detection rules to improve alert quality and reduce false positives. Conduct proactive threat hunting using SIEM, EDR, and threat intelligence sources. Support incident investigations, containment, and response activities. Monitor and maintain the health of SOC tooling, sensors, agents, and log pipelines. Produce documentation, runbooks, and operational procedures. Skills & Experience Experience engineering and supporting SIEM platforms, ideally Microsoft Sentinel. Strong Scripting and automation skills (Python, PowerShell, Bash, KQL). Experience with SOAR technologies and security automation. Knowledge of detection engineering and threat hunting. Strong understanding of Windows and Linux logging. Good networking knowledge including TCP/IP, DNS, Firewalls, and proxies. Experience within a SOC, NOC, or 24/7 operational environment. Familiarity with MITRE ATT&CK, CVEs, and vulnerability management. Exposure to cloud security monitoring across Azure, AWS, or Microsoft 365. Desirable Certifications Microsoft SC-200 CompTIA Security+/CySA+ ISC2 CC or CISSP GIAC GCIA CEH Cisco CyberOps or Fortinet certifications What's on Offer? Opportunity to work within a mature and growing SOC environment. Exposure to a wide range of customer environments and technologies. Security Clearance sponsorship available for eligible candidates. Clear opportunities to contribute to automation, detection engineering, and SOC improvement initiatives. Location: Milton Keynes (full-time onsite) Working Pattern: Shift rota including evenings, weekends, bank holidays on-call support. Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
Our client Scottish Power are looking for a Security Operations Lead for an initial 12 month contract role, which will in all likelihood extend further. This is based at the client offices in Glasgow, working hybrid, 3 days in the office. SP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations and deliver a cyber resilient business, the Security Operations Lead will be essential in achieving our goals. The Security Operations Lead will be a subject matter expert on security incident detection and response. They will drive continuous improvement across the outsourced SOC and in-house SOC teams of analysts and engineers. Youll have experience of configuring SIEM tools, onboarding sources, writing processes and alerts, understanding business environments and managing incidents affecting applications and infrastructure across a varied technology stack spanning operational technology and information technology environments. You ll also be able to undertake post incident reviews to identify root causes and put follow-up mitigations in place. The postholder will work within a security operations team containing various cyber security functions such as threat intelligence, identity & access management, response & recovery and vulnerability management. What Youll be doing Support the Security Operations Manager in the running of BAU activities Implement and maintain 3rd line security incident / event management, escalation and technical response process and investigate suspected and actual incidents / events. Acting as a key escalation point in the team to the relevant team/individual Design, implement, manage, monitor, and upgrade security measures for the protections of the information systems and networks Identify and feedback any potential improvements from a cyber perspective to OT systems and infrastructure Ensuring incident identification, assessment, quantification, reporting, communication, mitigation and monitoring Ensuring compliance to policy, process, and procedure adherence and process improvisation to achieve operational objectives Revise and develop processes to strengthen the current Security Operations Framework Review policies and highlight the challenges in managing SLAs Ensuring daily management, administration & maintenance of security technology to achieve operational effectiveness Ensure the orchestration and integration of security services and platforms to maximise its usage and coverage The role will be integrated into an active and ambitious global cyber security function, contributing to SPEN s cyber security purpose of delivering cyber resilient OT and IT, to enable a safe and reliable electricity supply to customers What Youll bring Skills and experience in understanding at a technical level security operations. Awareness of key legislation and regulation impacting IT/OT General Control requirements in an energy utility. Experience in working within a SOC. Record of academic achievement, including some form of recognised qualification from further education, such as a degree or diploma. Good oral and written communication skills. Must be a proven team player to work, promote and consolidate efficient team working relationships.
Aug 04, 2026
Contractor
Our client Scottish Power are looking for a Security Operations Lead for an initial 12 month contract role, which will in all likelihood extend further. This is based at the client offices in Glasgow, working hybrid, 3 days in the office. SP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations and deliver a cyber resilient business, the Security Operations Lead will be essential in achieving our goals. The Security Operations Lead will be a subject matter expert on security incident detection and response. They will drive continuous improvement across the outsourced SOC and in-house SOC teams of analysts and engineers. Youll have experience of configuring SIEM tools, onboarding sources, writing processes and alerts, understanding business environments and managing incidents affecting applications and infrastructure across a varied technology stack spanning operational technology and information technology environments. You ll also be able to undertake post incident reviews to identify root causes and put follow-up mitigations in place. The postholder will work within a security operations team containing various cyber security functions such as threat intelligence, identity & access management, response & recovery and vulnerability management. What Youll be doing Support the Security Operations Manager in the running of BAU activities Implement and maintain 3rd line security incident / event management, escalation and technical response process and investigate suspected and actual incidents / events. Acting as a key escalation point in the team to the relevant team/individual Design, implement, manage, monitor, and upgrade security measures for the protections of the information systems and networks Identify and feedback any potential improvements from a cyber perspective to OT systems and infrastructure Ensuring incident identification, assessment, quantification, reporting, communication, mitigation and monitoring Ensuring compliance to policy, process, and procedure adherence and process improvisation to achieve operational objectives Revise and develop processes to strengthen the current Security Operations Framework Review policies and highlight the challenges in managing SLAs Ensuring daily management, administration & maintenance of security technology to achieve operational effectiveness Ensure the orchestration and integration of security services and platforms to maximise its usage and coverage The role will be integrated into an active and ambitious global cyber security function, contributing to SPEN s cyber security purpose of delivering cyber resilient OT and IT, to enable a safe and reliable electricity supply to customers What Youll bring Skills and experience in understanding at a technical level security operations. Awareness of key legislation and regulation impacting IT/OT General Control requirements in an energy utility. Experience in working within a SOC. Record of academic achievement, including some form of recognised qualification from further education, such as a degree or diploma. Good oral and written communication skills. Must be a proven team player to work, promote and consolidate efficient team working relationships.
Our client is a leading global specialty (re)insurance business, recognised for its innovative approach to underwriting and strong reputation across international markets. With operations spanning multiple locations, the business focuses on delivering bespoke insurance and reinsurance solutions across a diverse portfolio of specialty risks. Combining underwriting expertise, entrepreneurial thinking, and a collaborative culture, they continue to drive growth while investing in technology, talent, and operational excellence PURPOSE OF THIS ROLE The Senior IT Cyber Governance, Risk & Compliance Analyst will support the development, implementation and oversight of the organisation's IT governance, cyber risk and compliance activities. This role involves supporting IT and cyber risk assessments, compliance with relevant regulatory and control frameworks, audit activity, and the identification and tracking of vulnerabilities, control gaps and remediation actions across IT systems and processes. The Senior IT Cyber Governance, Risk & Compliance Analyst will work closely with internal stakeholders to help ensure that IT and cyber activities are aligned with regulatory expectations, internal policies and good practice. KEY RESPONSIBILITIES Compliance and Risk Management: Support compliance with applicable regulatory, IT, cyber and control frameworks, which may include DORA, ISO 27001, NIST CSF, SOX and Cyber Essentials. Support the evaluation and management of IT, cyber, compliance and security risks across systems, processes and operations. Monitor emerging technology, cyber and operational resilience risks to support proactive risk management and timely escalation. Assist in preparing for and supporting regulatory inspections and internal, external and third-party audits. Support the tracking of cyber risk remediation actions, including actions arising from risk assessments, assurance reviews, incidents, audits, control reviews and control improvement initiatives. Support the maintenance of the cyber risk register, including the capture of risks, issues and remediation actions, and the preparation of updates for governance forums. Support third-party and supplier security assurance activities, including security due diligence, assessment of supplier responses and tracking of supplier remediation actions. Coordinate and evidence user access reviews and privileged access reviews with system owners and the business, supporting the move to tool-based access certification. Perform first-line compliance monitoring and control checks against information security policies and standards, including the tracking of policy exceptions. Policy & Procedure Development: Support the development, implementation and updating of IT risk, cyber security and compliance policies, standards and procedures to ensure alignment with legal, regulatory, control and sound practice requirements. Maintain an up-to-date understanding of applicable regulatory requirements and help implement changes to comply with new or evolving regulations. Assist in developing and delivering internal training and awareness on IT governance, cyber risk and compliance topics. Reporting & Communication: Support the preparation of cyber risk, control and remediation reporting for management and governance forums. Support the development and tracking of key performance indicators (KPIs) related to IT risk and compliance. Support internal breach notification and escalation processes where required, in coordination with Legal, Data Protection and relevant stakeholders, including supporting regulatory reporting where appropriate. SKILLS, QUALIFICATIONS AND EXPERIENCE Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or a related field, or equivalent experience. Relevant certifications such as CRISC, CISA, CISM, ISO 27001 or CISSP, or a willingness to undertake similar, are desirable. Minimum of 5 years' experience in IT governance, risk management, cyber or information security, or a related role, with a strong knowledge of related control and compliance requirements. Working knowledge of key technology areas, including infrastructure, applications, networking, cloud services, vulnerability management, incident management and access controls. Experience supporting audit, regulatory or compliance activities, including evidence coordination, issue tracking and remediation follow-up. Experience with SOX compliance and ITGCs is desirable. Experience in insurance or wider financial services, or another regulated environment, is desirable. Excellent communication skills, with the ability to convey technical information to non-technical stakeholders.
Aug 03, 2026
Contractor
Our client is a leading global specialty (re)insurance business, recognised for its innovative approach to underwriting and strong reputation across international markets. With operations spanning multiple locations, the business focuses on delivering bespoke insurance and reinsurance solutions across a diverse portfolio of specialty risks. Combining underwriting expertise, entrepreneurial thinking, and a collaborative culture, they continue to drive growth while investing in technology, talent, and operational excellence PURPOSE OF THIS ROLE The Senior IT Cyber Governance, Risk & Compliance Analyst will support the development, implementation and oversight of the organisation's IT governance, cyber risk and compliance activities. This role involves supporting IT and cyber risk assessments, compliance with relevant regulatory and control frameworks, audit activity, and the identification and tracking of vulnerabilities, control gaps and remediation actions across IT systems and processes. The Senior IT Cyber Governance, Risk & Compliance Analyst will work closely with internal stakeholders to help ensure that IT and cyber activities are aligned with regulatory expectations, internal policies and good practice. KEY RESPONSIBILITIES Compliance and Risk Management: Support compliance with applicable regulatory, IT, cyber and control frameworks, which may include DORA, ISO 27001, NIST CSF, SOX and Cyber Essentials. Support the evaluation and management of IT, cyber, compliance and security risks across systems, processes and operations. Monitor emerging technology, cyber and operational resilience risks to support proactive risk management and timely escalation. Assist in preparing for and supporting regulatory inspections and internal, external and third-party audits. Support the tracking of cyber risk remediation actions, including actions arising from risk assessments, assurance reviews, incidents, audits, control reviews and control improvement initiatives. Support the maintenance of the cyber risk register, including the capture of risks, issues and remediation actions, and the preparation of updates for governance forums. Support third-party and supplier security assurance activities, including security due diligence, assessment of supplier responses and tracking of supplier remediation actions. Coordinate and evidence user access reviews and privileged access reviews with system owners and the business, supporting the move to tool-based access certification. Perform first-line compliance monitoring and control checks against information security policies and standards, including the tracking of policy exceptions. Policy & Procedure Development: Support the development, implementation and updating of IT risk, cyber security and compliance policies, standards and procedures to ensure alignment with legal, regulatory, control and sound practice requirements. Maintain an up-to-date understanding of applicable regulatory requirements and help implement changes to comply with new or evolving regulations. Assist in developing and delivering internal training and awareness on IT governance, cyber risk and compliance topics. Reporting & Communication: Support the preparation of cyber risk, control and remediation reporting for management and governance forums. Support the development and tracking of key performance indicators (KPIs) related to IT risk and compliance. Support internal breach notification and escalation processes where required, in coordination with Legal, Data Protection and relevant stakeholders, including supporting regulatory reporting where appropriate. SKILLS, QUALIFICATIONS AND EXPERIENCE Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or a related field, or equivalent experience. Relevant certifications such as CRISC, CISA, CISM, ISO 27001 or CISSP, or a willingness to undertake similar, are desirable. Minimum of 5 years' experience in IT governance, risk management, cyber or information security, or a related role, with a strong knowledge of related control and compliance requirements. Working knowledge of key technology areas, including infrastructure, applications, networking, cloud services, vulnerability management, incident management and access controls. Experience supporting audit, regulatory or compliance activities, including evidence coordination, issue tracking and remediation follow-up. Experience with SOX compliance and ITGCs is desirable. Experience in insurance or wider financial services, or another regulated environment, is desirable. Excellent communication skills, with the ability to convey technical information to non-technical stakeholders.
This role has a starting salary of 55,486 per annum, for working 36 hours per week. We are excited to be recruiting a Senior Security Analyst to join our fantastic team based at Woodhatch Place in Reigate. We offer a hybrid working model with a minimum of two office days per week. Our Offer to You 26 days' holiday, rising to 28 days after 2 years' service and 31 days after 5 years' service (prorated for part time staff) Option to buy up to 10 days of additional annual leave A generous local government salary related pension Up to 5 days of carer's leave and 2 paid volunteering days per year Paternity, adoption and dependents leave An Employee Assistance Programme (EAP) to support health and wellbeing Learning and development hub where you can access a wealth of resources Wellbeing and lifestyle discounts including gym, travel, and shopping A chance to make a real difference to the lives of our residents. About The Role As a Senior Security Analyst, you will play a central role in strengthening Surrey County Council's cyber resilience. Your day-to-day work will include proactive security monitoring across our hybrid cloud and on premises environment, triaging and investigating alerts, and supporting coordinated incident response activities. You will operate our vulnerability management processes, translate threat intelligence into actionable defences, and contribute to the improvement of detection content and security controls. You will also work closely with IT colleagues and suppliers to address risks, gather evidence for audits, and prepare clear reporting on security posture and emerging trends. This role does not include direct line management responsibilities, but you will regularly provide specialist guidance, coaching, and support to colleagues across IT&D and partner teams. Over the next 12 to 18 months, you will contribute to several high impact initiatives including: Establishing a more mature, risk based vulnerability management lifecycle and reducing exposure windows across critical systems Enhancing incident response readiness through improved playbooks, scenario testing, and lessons learned processes Uplifting monitoring coverage and the effectiveness of SIEM/EDR/NDR tooling, including tuning and detection improvements Strengthening supplier assurance processes, especially for cloud and SaaS services Supporting the development of updated cyber security policies, standards and operating procedures This is a pivotal role for a motivated cyber professional who wants to make a measurable difference. You will directly influence Surrey County Council's operational security posture and help reduce risk across services that support residents, communities, and frontline operations. Your insights and expertise will shape decision making, improve control maturity, and contribute to a safer, more resilient public service environment. Your Application In order to be considered for shortlisting, your application will clearly evidence the following skills and align with our behaviours: Strong experience in cyber security operations, including alert triage, investigation, and incident response Demonstrable capability in vulnerability management and translating technical risk into meaningful actions Ability to analyse complex information and present clear, concise reports and recommendations Proven ability to work collaboratively with technical and non technical stakeholders Commitment to continuous professional development and staying current with emerging threats High-level proficiency with security tooling (SIEM, EDR, cloud security tools) and modern IT environments Alignment with our values of accountability, teamwork, and inclusive service delivery To apply, we request that you submit a CV and you will be asked the following 4 questions: Give an example of how you have helped build a positive security culture across teams. Describe a time when you led or contributed to triage, investigation, or response during a cyber security incident. What actions did you take, and what was the outcome? Give an example of when you identified a significant technical vulnerability or risk. How did you communicate it to stakeholders, and what actions were taken as a result? Tell us about a situation where you analysed complex security information or data and produced a report or recommendation. How did you ensure your findings were clear, concise, and actionable? Before submitting your application, we recommend you read the job description and our Life at Surrey handbook to get an insight into working at Surrey. An enhanced DBS 'Disclosure and Barring Service' check for regulated activity (formerly known as CRB) and the Children's and Adults' Barred List checks will be required for this role. The job advert closes at 23:59 on 14/08/2026, with interviews planned to follow shortly thereafter. We look forward to receiving your application, please click on the apply online button below to submit. Contact Us Please contact us for any questions relating to the role. This could be to discuss flexible working requests, transferable skills or any barriers to employment. For an informal discussion please contact Kamil Erkadoo via email at . Local Government Reorganisation (LGR) Surrey County Council is undergoing Local Government Reorganisation, moving from a two-tier system to two new unitary councils in April 2027. If you are employed by Surrey on 1st April 2027, your role will transfer with current terms and conditions to one of the new organisations, supporting local devolution and greater powers for our communities. Join our dynamic team and shape the future of local government. Make a lasting impact with innovative solutions and improved services for our community. Help us build a brighter future for our residents! Please see more information here: Information for applicants on Local Government Reorganisation - Surrey County Council Our Commitment We are a disability confident employer which means if you have shared a disability on your application form and have evidenced you meet the minimum shortlisting criteria, as displayed on the advert, we guarantee you an interview. Your skills and experience truly matter to us. From application to your first day, we're committed to supporting you with any adjustments you need, we value inclusion and warmly welcome you to join and help build a workplace where everyone belongs.
Jul 31, 2026
Full time
This role has a starting salary of 55,486 per annum, for working 36 hours per week. We are excited to be recruiting a Senior Security Analyst to join our fantastic team based at Woodhatch Place in Reigate. We offer a hybrid working model with a minimum of two office days per week. Our Offer to You 26 days' holiday, rising to 28 days after 2 years' service and 31 days after 5 years' service (prorated for part time staff) Option to buy up to 10 days of additional annual leave A generous local government salary related pension Up to 5 days of carer's leave and 2 paid volunteering days per year Paternity, adoption and dependents leave An Employee Assistance Programme (EAP) to support health and wellbeing Learning and development hub where you can access a wealth of resources Wellbeing and lifestyle discounts including gym, travel, and shopping A chance to make a real difference to the lives of our residents. About The Role As a Senior Security Analyst, you will play a central role in strengthening Surrey County Council's cyber resilience. Your day-to-day work will include proactive security monitoring across our hybrid cloud and on premises environment, triaging and investigating alerts, and supporting coordinated incident response activities. You will operate our vulnerability management processes, translate threat intelligence into actionable defences, and contribute to the improvement of detection content and security controls. You will also work closely with IT colleagues and suppliers to address risks, gather evidence for audits, and prepare clear reporting on security posture and emerging trends. This role does not include direct line management responsibilities, but you will regularly provide specialist guidance, coaching, and support to colleagues across IT&D and partner teams. Over the next 12 to 18 months, you will contribute to several high impact initiatives including: Establishing a more mature, risk based vulnerability management lifecycle and reducing exposure windows across critical systems Enhancing incident response readiness through improved playbooks, scenario testing, and lessons learned processes Uplifting monitoring coverage and the effectiveness of SIEM/EDR/NDR tooling, including tuning and detection improvements Strengthening supplier assurance processes, especially for cloud and SaaS services Supporting the development of updated cyber security policies, standards and operating procedures This is a pivotal role for a motivated cyber professional who wants to make a measurable difference. You will directly influence Surrey County Council's operational security posture and help reduce risk across services that support residents, communities, and frontline operations. Your insights and expertise will shape decision making, improve control maturity, and contribute to a safer, more resilient public service environment. Your Application In order to be considered for shortlisting, your application will clearly evidence the following skills and align with our behaviours: Strong experience in cyber security operations, including alert triage, investigation, and incident response Demonstrable capability in vulnerability management and translating technical risk into meaningful actions Ability to analyse complex information and present clear, concise reports and recommendations Proven ability to work collaboratively with technical and non technical stakeholders Commitment to continuous professional development and staying current with emerging threats High-level proficiency with security tooling (SIEM, EDR, cloud security tools) and modern IT environments Alignment with our values of accountability, teamwork, and inclusive service delivery To apply, we request that you submit a CV and you will be asked the following 4 questions: Give an example of how you have helped build a positive security culture across teams. Describe a time when you led or contributed to triage, investigation, or response during a cyber security incident. What actions did you take, and what was the outcome? Give an example of when you identified a significant technical vulnerability or risk. How did you communicate it to stakeholders, and what actions were taken as a result? Tell us about a situation where you analysed complex security information or data and produced a report or recommendation. How did you ensure your findings were clear, concise, and actionable? Before submitting your application, we recommend you read the job description and our Life at Surrey handbook to get an insight into working at Surrey. An enhanced DBS 'Disclosure and Barring Service' check for regulated activity (formerly known as CRB) and the Children's and Adults' Barred List checks will be required for this role. The job advert closes at 23:59 on 14/08/2026, with interviews planned to follow shortly thereafter. We look forward to receiving your application, please click on the apply online button below to submit. Contact Us Please contact us for any questions relating to the role. This could be to discuss flexible working requests, transferable skills or any barriers to employment. For an informal discussion please contact Kamil Erkadoo via email at . Local Government Reorganisation (LGR) Surrey County Council is undergoing Local Government Reorganisation, moving from a two-tier system to two new unitary councils in April 2027. If you are employed by Surrey on 1st April 2027, your role will transfer with current terms and conditions to one of the new organisations, supporting local devolution and greater powers for our communities. Join our dynamic team and shape the future of local government. Make a lasting impact with innovative solutions and improved services for our community. Help us build a brighter future for our residents! Please see more information here: Information for applicants on Local Government Reorganisation - Surrey County Council Our Commitment We are a disability confident employer which means if you have shared a disability on your application form and have evidenced you meet the minimum shortlisting criteria, as displayed on the advert, we guarantee you an interview. Your skills and experience truly matter to us. From application to your first day, we're committed to supporting you with any adjustments you need, we value inclusion and warmly welcome you to join and help build a workplace where everyone belongs.
Senior Vulnerability Analyst 50,000 - 57,000 + bonus and extensive benefits Full Time / Permanent West Midlands / Hybrid - 1-2 days a month in the office on average The Role and Company: I am looking for a driven Senior Vulnerability Analyst to join a large nationally recognised brand head quartered in the West Midlands. As a Senior Vulnerability Analyst you will be joining a highly skilled Cyber Defence team. As a key part if this team you will manage threats to the organisation and safeguard systems that enable the business to function safely and effectively. We are ideally looking for someone Midlands based who can be on site in Warwickshire 1-2 days a month on average. Responsibilities: Conducting regular vulnerability assessments using automated scanning tools, manual testing techniques, and security best practices to identify vulnerabilities in systems, networks, and applications Managing the lifecycle of vulnerabilities from discovery to remediation, including vulnerability triage, prioritisation, tracking, and reporting Analysing the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the organisation, and existing security controls Collaborating with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner Working closely with IT teams to ensure that security patches and updates are applied promptly to mitigate known vulnerabilities and reduce the organisation's exposure to security risks Generating detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders Providing guidance and training to employees on best practices for identifying and reporting security vulnerabilities, promoting a culture of security awareness within the organisation Experience required: Previous experience in a similar Vulnerability Management role preferably with experience in Operational Technology (OT) Skilled in cyber security, physical security, and risk management principles Excellent analytical and investigative skills Strong knowledge of the hardware and software systems in use across both IT and OT domains and the architectural arrangements in place to support management and operation of systems Ability to adapt to evolving threat landscapes Effective communication, critical thinking and problem-solving skills Must either hold SC clearance already or be eligible to obtain this if successful Please apply via the link or contact (url removed) for more information Modis International Ltd acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers in the UK. Modis Europe Ltd provide a variety of international solutions that connect clients to the best talent in the world. For all positions based in Switzerland, Modis Europe Ltd works with its licensed Swiss partner Accurity GmbH to ensure that candidate applications are handled in accordance with Swiss law. Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers. By applying for this role your details will be submitted to Modis International Ltd and/ or Modis Europe Ltd. Our Candidate Privacy Information Statement which explains how we will use your information is available on the Modis website.
Oct 03, 2025
Full time
Senior Vulnerability Analyst 50,000 - 57,000 + bonus and extensive benefits Full Time / Permanent West Midlands / Hybrid - 1-2 days a month in the office on average The Role and Company: I am looking for a driven Senior Vulnerability Analyst to join a large nationally recognised brand head quartered in the West Midlands. As a Senior Vulnerability Analyst you will be joining a highly skilled Cyber Defence team. As a key part if this team you will manage threats to the organisation and safeguard systems that enable the business to function safely and effectively. We are ideally looking for someone Midlands based who can be on site in Warwickshire 1-2 days a month on average. Responsibilities: Conducting regular vulnerability assessments using automated scanning tools, manual testing techniques, and security best practices to identify vulnerabilities in systems, networks, and applications Managing the lifecycle of vulnerabilities from discovery to remediation, including vulnerability triage, prioritisation, tracking, and reporting Analysing the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the organisation, and existing security controls Collaborating with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner Working closely with IT teams to ensure that security patches and updates are applied promptly to mitigate known vulnerabilities and reduce the organisation's exposure to security risks Generating detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders Providing guidance and training to employees on best practices for identifying and reporting security vulnerabilities, promoting a culture of security awareness within the organisation Experience required: Previous experience in a similar Vulnerability Management role preferably with experience in Operational Technology (OT) Skilled in cyber security, physical security, and risk management principles Excellent analytical and investigative skills Strong knowledge of the hardware and software systems in use across both IT and OT domains and the architectural arrangements in place to support management and operation of systems Ability to adapt to evolving threat landscapes Effective communication, critical thinking and problem-solving skills Must either hold SC clearance already or be eligible to obtain this if successful Please apply via the link or contact (url removed) for more information Modis International Ltd acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers in the UK. Modis Europe Ltd provide a variety of international solutions that connect clients to the best talent in the world. For all positions based in Switzerland, Modis Europe Ltd works with its licensed Swiss partner Accurity GmbH to ensure that candidate applications are handled in accordance with Swiss law. Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers. By applying for this role your details will be submitted to Modis International Ltd and/ or Modis Europe Ltd. Our Candidate Privacy Information Statement which explains how we will use your information is available on the Modis website.
Information Security Analyst - Heron Foods Salary: £35,000 - £45,000 per annum (depending on experience) Location: Hull (with hybrid working flexibility) About the Role We are looking for an Information Security Analyst to join the Group Information Security Function at B&M, with a dedicated focus on Heron Foods. In this role, you'll act as the primary contact for all things cyber and information security at Heron Foods, working day-to-day under the steer of the Head of IT at Heron Foods while aligning with the security strategy, policies, and standards set by the Group Head of Information Security. This is an exciting opportunity to be at the frontline of cyber defence - monitoring threats, responding to incidents, managing vulnerabilities, and embedding security into everyday operations across Heron Foods. Key Responsibilities As Information Security Analyst, you will: Be the first point of contact for all cyber and information security matters within Heron Foods. Monitor and respond to alerts from our Managed Security Operations Centre (SOC). Coordinate incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCI DSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall resilience. About You We're looking for someone who combines technical knowledge with an investigative mindset and strong stakeholder communication skills. Essential skills & experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. Desirable: Hands-on exposure to security tooling (e.g., EDR, SIEM, vulnerability scanners). Experience supporting audits and compliance activities. Scripting/automation skills (e.g., PowerShell, Python) to streamline tasks. Why Join Us? At B&M and Heron Foods, we are on a journey to strengthen our cyber resilience. This role offers: A unique opportunity to be the dedicated security lead for Heron Foods while benefiting from Group-level support and expertise. A competitive salary of £35,000 - £45,000 (depending on experience). Hybrid working arrangements. Excellent staff discount across B&M and Heron Foods stores. Opportunities for training, development, and progression within a growing security function. How to Apply If you're passionate about cyber security and want to make a real impact by protecting business-critical systems and data, apply today and help us keep Heron Foods secure.
Oct 02, 2025
Full time
Information Security Analyst - Heron Foods Salary: £35,000 - £45,000 per annum (depending on experience) Location: Hull (with hybrid working flexibility) About the Role We are looking for an Information Security Analyst to join the Group Information Security Function at B&M, with a dedicated focus on Heron Foods. In this role, you'll act as the primary contact for all things cyber and information security at Heron Foods, working day-to-day under the steer of the Head of IT at Heron Foods while aligning with the security strategy, policies, and standards set by the Group Head of Information Security. This is an exciting opportunity to be at the frontline of cyber defence - monitoring threats, responding to incidents, managing vulnerabilities, and embedding security into everyday operations across Heron Foods. Key Responsibilities As Information Security Analyst, you will: Be the first point of contact for all cyber and information security matters within Heron Foods. Monitor and respond to alerts from our Managed Security Operations Centre (SOC). Coordinate incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCI DSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall resilience. About You We're looking for someone who combines technical knowledge with an investigative mindset and strong stakeholder communication skills. Essential skills & experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. Desirable: Hands-on exposure to security tooling (e.g., EDR, SIEM, vulnerability scanners). Experience supporting audits and compliance activities. Scripting/automation skills (e.g., PowerShell, Python) to streamline tasks. Why Join Us? At B&M and Heron Foods, we are on a journey to strengthen our cyber resilience. This role offers: A unique opportunity to be the dedicated security lead for Heron Foods while benefiting from Group-level support and expertise. A competitive salary of £35,000 - £45,000 (depending on experience). Hybrid working arrangements. Excellent staff discount across B&M and Heron Foods stores. Opportunities for training, development, and progression within a growing security function. How to Apply If you're passionate about cyber security and want to make a real impact by protecting business-critical systems and data, apply today and help us keep Heron Foods secure.
Job Title: Lead Security Solution Architect- PAM Location: Hybrid-London, UK (Days/Week Onsite) Duration: 6months+ 550GBP/Day Inside IR35 Project Overview CLIENT is working on a strategic Identity and Access Management programme and is re-shaping the way Authentication, Federation, Privileged Access Management, Access Governance, Secrets Management and API Security is done across the bank. One of the pillars of that programe is Privileged Access Management (PAM). CLIENT is working on uplifting controls and capabilities in privileged access for the Group and introducing the strategic password vaulting solution that will enable to meet strategic requirements. We are seeking an experienced Lead Security Solution Architect that can complement an existing team of Solution Architects to progress with designs of different components of the PAM solution and other supporting systems it will need to integrate with as part of the end-to-end journey. Security Solution Architects manage end-to-end solution design and are responsible for delivering architecture design documents in line with functional and non-functional business requirements, strategies, principles, standards, and patterns. Alongside the creation of high-level designs, Security Solution Architects will be required to record key decisions, design deviations, and technical risks and issues where appropriate. Security Solution Architects should be comfortable presenting and sharing solutions at design authorities and senior leadership & stakeholders. The Lead Security Solution Architect will provide technical thought leadership and direction to their project team and may represent the project/programme as subject matter expert. This role will require someone experienced in managing a team of on-shore and off-shore resources to deliver High- and Low-level designs to the required quality and standard. Principal Preferred Requirements Cybersecurity Expertise: Significant experience and proven technical depth within one of the following domains of cybersecurity; security operations & incident response, threat & vulnerability management, identity & access management, cryptography, infrastructure, network, application, data, cloud Broad background across information technology with the ability to communicate clearly with non-security technical SMEs at a comfortable level Experience in both operational and transformation cybersecurity roles or a clear working understanding of both perspectives Experience working in large-scale IT transformation programmes Experience working with PAM solutions such as CyberArk, Centrify, Delinea and OneIdentity Preparing end-to-end configuration of the strategic PAM capability - including on-prem deployments as well as Cloud native toolings Assisting in preparation of demonstrable journeys on the configured PAM tooling Platform & Technology: BizzDesign, Archi, or generic UML visualisation experience for high-level designs High proficiency and expertise in Jira for project & tasks management Working proficiency in Confluence for documentation Principal Accountabilities and Responsibilities Architecture & Design: Produce, manage, and update end-to-end solution designs in line with reference architecture & business requirements (including High and Low Level Designs Articulate and publish key design decision records and options to ensure all solutions follow a logical, transparent decision-making process Articulate, publish, and ensure approval of any design deviations resulting in technical debt Ensure any technical risks or issues arising from a solution design are recorded and mitigated. Produces, manages and translates the requirements into the architecture for that solution, ensuring technology and services meet the customer needs and expected business outcomes Ensures the design of the solutions are efficient, timely and cost effective throughout the project life cycle Clear understanding of both the motivations of the business and technical security Promote strong documentation and clerkship Governance: Ensures all high-level designs, architecture patterns, decision records, deviation requests, and technical risks or issue records undergo architectural and project governance processes Ensure all architecture artefacts undergo appropriate peer review prior to design authority presentation Present publications at technical design authorities for input, feedback, and approval Risk and Dependency Management: Effectively manages and escalates both technical and project risks or issues Articulates solutions and remediation steps to technical risks & issues Ability to map design decisions to resultant technical risks & issues to articulate the cause and rationale which leads to any negatively impacting change Leadership & Teamwork Provides technical thought leadership to the Design Team and the Project Ability to manage a project team of technical architects, engineers, and/or analysts Ability to take a deputised role in programme management-related tasks where necessary Qualifications & Certifications: Masters or doctorate degree in cybersecurity, computer science, software engineering, or related field CISSP/CISM certification or other broad cybersecurity industry-recognised certificate SABSA or TOGAF certified preferred Priyanka Sharma Senior Delivery Consultant
Oct 02, 2025
Contractor
Job Title: Lead Security Solution Architect- PAM Location: Hybrid-London, UK (Days/Week Onsite) Duration: 6months+ 550GBP/Day Inside IR35 Project Overview CLIENT is working on a strategic Identity and Access Management programme and is re-shaping the way Authentication, Federation, Privileged Access Management, Access Governance, Secrets Management and API Security is done across the bank. One of the pillars of that programe is Privileged Access Management (PAM). CLIENT is working on uplifting controls and capabilities in privileged access for the Group and introducing the strategic password vaulting solution that will enable to meet strategic requirements. We are seeking an experienced Lead Security Solution Architect that can complement an existing team of Solution Architects to progress with designs of different components of the PAM solution and other supporting systems it will need to integrate with as part of the end-to-end journey. Security Solution Architects manage end-to-end solution design and are responsible for delivering architecture design documents in line with functional and non-functional business requirements, strategies, principles, standards, and patterns. Alongside the creation of high-level designs, Security Solution Architects will be required to record key decisions, design deviations, and technical risks and issues where appropriate. Security Solution Architects should be comfortable presenting and sharing solutions at design authorities and senior leadership & stakeholders. The Lead Security Solution Architect will provide technical thought leadership and direction to their project team and may represent the project/programme as subject matter expert. This role will require someone experienced in managing a team of on-shore and off-shore resources to deliver High- and Low-level designs to the required quality and standard. Principal Preferred Requirements Cybersecurity Expertise: Significant experience and proven technical depth within one of the following domains of cybersecurity; security operations & incident response, threat & vulnerability management, identity & access management, cryptography, infrastructure, network, application, data, cloud Broad background across information technology with the ability to communicate clearly with non-security technical SMEs at a comfortable level Experience in both operational and transformation cybersecurity roles or a clear working understanding of both perspectives Experience working in large-scale IT transformation programmes Experience working with PAM solutions such as CyberArk, Centrify, Delinea and OneIdentity Preparing end-to-end configuration of the strategic PAM capability - including on-prem deployments as well as Cloud native toolings Assisting in preparation of demonstrable journeys on the configured PAM tooling Platform & Technology: BizzDesign, Archi, or generic UML visualisation experience for high-level designs High proficiency and expertise in Jira for project & tasks management Working proficiency in Confluence for documentation Principal Accountabilities and Responsibilities Architecture & Design: Produce, manage, and update end-to-end solution designs in line with reference architecture & business requirements (including High and Low Level Designs Articulate and publish key design decision records and options to ensure all solutions follow a logical, transparent decision-making process Articulate, publish, and ensure approval of any design deviations resulting in technical debt Ensure any technical risks or issues arising from a solution design are recorded and mitigated. Produces, manages and translates the requirements into the architecture for that solution, ensuring technology and services meet the customer needs and expected business outcomes Ensures the design of the solutions are efficient, timely and cost effective throughout the project life cycle Clear understanding of both the motivations of the business and technical security Promote strong documentation and clerkship Governance: Ensures all high-level designs, architecture patterns, decision records, deviation requests, and technical risks or issue records undergo architectural and project governance processes Ensure all architecture artefacts undergo appropriate peer review prior to design authority presentation Present publications at technical design authorities for input, feedback, and approval Risk and Dependency Management: Effectively manages and escalates both technical and project risks or issues Articulates solutions and remediation steps to technical risks & issues Ability to map design decisions to resultant technical risks & issues to articulate the cause and rationale which leads to any negatively impacting change Leadership & Teamwork Provides technical thought leadership to the Design Team and the Project Ability to manage a project team of technical architects, engineers, and/or analysts Ability to take a deputised role in programme management-related tasks where necessary Qualifications & Certifications: Masters or doctorate degree in cybersecurity, computer science, software engineering, or related field CISSP/CISM certification or other broad cybersecurity industry-recognised certificate SABSA or TOGAF certified preferred Priyanka Sharma Senior Delivery Consultant
The Information Security Analyst will play a critical role in safeguarding the organisation's systems and data, ensuring compliance with security policies and regulations. Based in Hatfield, this role is ideal for individuals passionate about the life science industry and technology. Client Details The hiring company is a medium-sized organisation operating within the life science industry, with a focus on innovation and excellence in its field. The company is known for its commitment to leveraging technology to drive forward its mission. Description Implement and maintain ISMS aligning with ISO27001 Ensure security controls are in-place based on ISO27001 and NIST As the regional security representative in the global Security / Technology project Lead / execute phishing campaign Conduct vulnerability assessments and implement measures to mitigate potential risks. Involve in global security operations process, analysis and escalate security alerts / tickets from global SOC team Maintain and update security policies, standards, and procedures in alignment with industry regulations. Collaborate with cross-functional teams to ensure secure system designs and implementations. Provide training and support to staff to enhance security awareness across the organisation. Profile Practical experience and understanding of ISO27001 Familiar with NIST and GDPR is preferred Solid experience in threat, risk and vulnerabilities management process Experience with security tools such as SIEM, intrusion detection systems, and endpoint protection. Strong analytical and problem-solving skills. Hold at least one security related professional certification is desirable Job Offer 24 days of holiday leave Performance-based bonus of up to 10%. Pension scheme with contributions up to 10%. Private medical insurance, life assurance, dental cover Finance support on professional certifications / memberships
Oct 02, 2025
Full time
The Information Security Analyst will play a critical role in safeguarding the organisation's systems and data, ensuring compliance with security policies and regulations. Based in Hatfield, this role is ideal for individuals passionate about the life science industry and technology. Client Details The hiring company is a medium-sized organisation operating within the life science industry, with a focus on innovation and excellence in its field. The company is known for its commitment to leveraging technology to drive forward its mission. Description Implement and maintain ISMS aligning with ISO27001 Ensure security controls are in-place based on ISO27001 and NIST As the regional security representative in the global Security / Technology project Lead / execute phishing campaign Conduct vulnerability assessments and implement measures to mitigate potential risks. Involve in global security operations process, analysis and escalate security alerts / tickets from global SOC team Maintain and update security policies, standards, and procedures in alignment with industry regulations. Collaborate with cross-functional teams to ensure secure system designs and implementations. Provide training and support to staff to enhance security awareness across the organisation. Profile Practical experience and understanding of ISO27001 Familiar with NIST and GDPR is preferred Solid experience in threat, risk and vulnerabilities management process Experience with security tools such as SIEM, intrusion detection systems, and endpoint protection. Strong analytical and problem-solving skills. Hold at least one security related professional certification is desirable Job Offer 24 days of holiday leave Performance-based bonus of up to 10%. Pension scheme with contributions up to 10%. Private medical insurance, life assurance, dental cover Finance support on professional certifications / memberships
Information Security Senior Analyst Location: Surrey (Hybrid) Our client, a large corporate organisation based in Surrey, is seeking an Information Security Senior Analyst with experience of Risk & Controls to join their team. The successful candidate will have proven experience in risk management, controls, and governance frameworks, who can lead initiatives, mentor others, and collaborate effectively across business units. You should be both strategic and hands-on, with a passion for proactive security and continuous improvement. Responsibilities: Lead the InfoSec risk register - Identify, assess, and mitigate information security risks. Own control frameworks - Maintain and improve controls to ensure alignment with standards like NIST CSF and COBIT. Drive assurance - Monitor the effectiveness of security controls, including outcomes of penetration testing and red team exercises. Collaborate with business units - Act as a security advocate and guide cross-functional teams in secure practices. Lead technical initiatives - Provide hands-on leadership and mentor more junior team members. Conduct threat and vulnerability assessments - Take a proactive role in identifying potential security threats. Skills and experience required: Strong experience in risk & controls within the information security, ideally in a regulated industry. Experience in large, complex enterprise environments (e.g., multiple sites, technologies). Hands-on leadership in technical InfoSec initiatives. Strong understanding and implementation of control frameworks (NIST CSF, COBIT). Ability to run threat intelligence and vulnerability assessments. Experience collaborating with 2nd and 3rd line governance teams (e.g., audit, compliance). Strong stakeholder engagement and influencing skills. Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
Sep 27, 2025
Full time
Information Security Senior Analyst Location: Surrey (Hybrid) Our client, a large corporate organisation based in Surrey, is seeking an Information Security Senior Analyst with experience of Risk & Controls to join their team. The successful candidate will have proven experience in risk management, controls, and governance frameworks, who can lead initiatives, mentor others, and collaborate effectively across business units. You should be both strategic and hands-on, with a passion for proactive security and continuous improvement. Responsibilities: Lead the InfoSec risk register - Identify, assess, and mitigate information security risks. Own control frameworks - Maintain and improve controls to ensure alignment with standards like NIST CSF and COBIT. Drive assurance - Monitor the effectiveness of security controls, including outcomes of penetration testing and red team exercises. Collaborate with business units - Act as a security advocate and guide cross-functional teams in secure practices. Lead technical initiatives - Provide hands-on leadership and mentor more junior team members. Conduct threat and vulnerability assessments - Take a proactive role in identifying potential security threats. Skills and experience required: Strong experience in risk & controls within the information security, ideally in a regulated industry. Experience in large, complex enterprise environments (e.g., multiple sites, technologies). Hands-on leadership in technical InfoSec initiatives. Strong understanding and implementation of control frameworks (NIST CSF, COBIT). Ability to run threat intelligence and vulnerability assessments. Experience collaborating with 2nd and 3rd line governance teams (e.g., audit, compliance). Strong stakeholder engagement and influencing skills. Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
Information Security Analyst - Heron Foods Salary: £35,000 - £45,000 per annum (depending on experience) Location: Hull (with hybrid working flexibility) About the Role We are looking for an Information Security Analyst to join the Group Information Security Function at B&M, with a dedicated focus on Heron Foods. In this role, you'll act as the primary contact for all things cyber and information security at Heron Foods, working day-to-day under the steer of the Head of IT at Heron Foods while aligning with the security strategy, policies, and standards set by the Group Head of Information Security. This is an exciting opportunity to be at the frontline of cyber defence - monitoring threats, responding to incidents, managing vulnerabilities, and embedding security into everyday operations across Heron Foods. Key Responsibilities As Information Security Analyst, you will: Be the first point of contact for all cyber and information security matters within Heron Foods. Monitor and respond to alerts from our Managed Security Operations Centre (SOC). Coordinate incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCI DSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall resilience. About You We're looking for someone who combines technical knowledge with an investigative mindset and strong stakeholder communication skills. Essential skills & experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. Desirable: Hands-on exposure to security tooling (e.g., EDR, SIEM, vulnerability scanners). Experience supporting audits and compliance activities. Scripting/automation skills (e.g., PowerShell, Python) to streamline tasks. Why Join Us? At B&M and Heron Foods, we are on a journey to strengthen our cyber resilience. This role offers: A unique opportunity to be the dedicated security lead for Heron Foods while benefiting from Group-level support and expertise. A competitive salary of £35,000 - £45,000 (depending on experience). Hybrid working arrangements. Excellent staff discount across B&M and Heron Foods stores. Opportunities for training, development, and progression within a growing security function. How to Apply If you're passionate about cyber security and want to make a real impact by protecting business-critical systems and data, apply today and help us keep Heron Foods secure.
Sep 21, 2025
Full time
Information Security Analyst - Heron Foods Salary: £35,000 - £45,000 per annum (depending on experience) Location: Hull (with hybrid working flexibility) About the Role We are looking for an Information Security Analyst to join the Group Information Security Function at B&M, with a dedicated focus on Heron Foods. In this role, you'll act as the primary contact for all things cyber and information security at Heron Foods, working day-to-day under the steer of the Head of IT at Heron Foods while aligning with the security strategy, policies, and standards set by the Group Head of Information Security. This is an exciting opportunity to be at the frontline of cyber defence - monitoring threats, responding to incidents, managing vulnerabilities, and embedding security into everyday operations across Heron Foods. Key Responsibilities As Information Security Analyst, you will: Be the first point of contact for all cyber and information security matters within Heron Foods. Monitor and respond to alerts from our Managed Security Operations Centre (SOC). Coordinate incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCI DSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall resilience. About You We're looking for someone who combines technical knowledge with an investigative mindset and strong stakeholder communication skills. Essential skills & experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. Desirable: Hands-on exposure to security tooling (e.g., EDR, SIEM, vulnerability scanners). Experience supporting audits and compliance activities. Scripting/automation skills (e.g., PowerShell, Python) to streamline tasks. Why Join Us? At B&M and Heron Foods, we are on a journey to strengthen our cyber resilience. This role offers: A unique opportunity to be the dedicated security lead for Heron Foods while benefiting from Group-level support and expertise. A competitive salary of £35,000 - £45,000 (depending on experience). Hybrid working arrangements. Excellent staff discount across B&M and Heron Foods stores. Opportunities for training, development, and progression within a growing security function. How to Apply If you're passionate about cyber security and want to make a real impact by protecting business-critical systems and data, apply today and help us keep Heron Foods secure.