Senior IT Security Analyst required to act as a senior technical contributor within a global cyber security team, owning selected cyber security domains end-to-end and driving practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions based on real-world attacker behaviour, and deliver measurable improvements to the organisation cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365 / Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve endpoint security controls. Used Zscaler ZIA/ZPA or equivalent secure web gateway, private access, zero trust or network access security technologies. Performed vulnerability assessment, exposure analysis or remediation prioritisation across enterprise technology environments. Applied threat intelligence, MITRE ATT&CK or exploitation-based evidence to prioritise mitigations. Supported or led cyber security investigations and incident response activities. Collaborated with infrastructure, cloud, application, identity and business teams to deliver security improvements. Used scripting, queries, automation or data analysis to improve security outcomes. Strong hands-on experience administering, tuning and operationalising CrowdStrike Falcon , including endpoint protection, EDR investigations, detection analysis and response workflows. Strong hands-on experience administering and supporting Zscaler ZIA and ZPA , including policy design, access control, traffic analysis and security troubleshooting. Practical experience leading or supporting vulnerability and exposure management programmes , including vulnerability analysis, risk-based prioritisation, remediation tracking and validation of control effectiveness. Strong knowledge of real-world attacker tactics, techniques and procedures (TTPs) and the ability to translate threat intelligence, attack paths and exploitation trends into actionable security improvements. Experience conducting security investigations and incident response activities, including alert triage, root cause analysis, containment, remediation and lessons learned. This is a hybrid role working 3 days a week in the London office and 2 days remotely.
Aug 06, 2026
Full time
Senior IT Security Analyst required to act as a senior technical contributor within a global cyber security team, owning selected cyber security domains end-to-end and driving practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions based on real-world attacker behaviour, and deliver measurable improvements to the organisation cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365 / Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve endpoint security controls. Used Zscaler ZIA/ZPA or equivalent secure web gateway, private access, zero trust or network access security technologies. Performed vulnerability assessment, exposure analysis or remediation prioritisation across enterprise technology environments. Applied threat intelligence, MITRE ATT&CK or exploitation-based evidence to prioritise mitigations. Supported or led cyber security investigations and incident response activities. Collaborated with infrastructure, cloud, application, identity and business teams to deliver security improvements. Used scripting, queries, automation or data analysis to improve security outcomes. Strong hands-on experience administering, tuning and operationalising CrowdStrike Falcon , including endpoint protection, EDR investigations, detection analysis and response workflows. Strong hands-on experience administering and supporting Zscaler ZIA and ZPA , including policy design, access control, traffic analysis and security troubleshooting. Practical experience leading or supporting vulnerability and exposure management programmes , including vulnerability analysis, risk-based prioritisation, remediation tracking and validation of control effectiveness. Strong knowledge of real-world attacker tactics, techniques and procedures (TTPs) and the ability to translate threat intelligence, attack paths and exploitation trends into actionable security improvements. Experience conducting security investigations and incident response activities, including alert triage, root cause analysis, containment, remediation and lessons learned. This is a hybrid role working 3 days a week in the London office and 2 days remotely.
Cyber Security Engineer/Specialist Permanent Up to £80,000 (+ Benefits) Hybrid Working (2 3 days per week Onsite) Surrey Help Shape Enterprise Cyber Security on a Global Scale We're looking for an experienced Cyber Security Engineer/Specialist to join a global organisation where security is a genuine business priority, not simply a compliance exercise. This is an opportunity to play a key role in protecting a complex enterprise environment, helping to identify, assess and mitigate sophisticated cyber threats while influencing the organisation's long-term security strategy. Working alongside infrastructure, architecture and operational teams, you'll strengthen enterprise security capabilities, improve cyber resilience and help safeguard critical business systems across an international environment. If you're looking for a role where you can make a real impact while continuing to develop your career within a stable organisation, we'd love to hear from you. The Role This is an enterprise Cyber Security position focused on proactive threat mitigation, security improvement and risk reduction rather than purely operational support. You'll be responsible for strengthening the organisation's security posture through threat assessment, vulnerability management, incident response and continuous security improvement initiatives. Key responsibilities include: Enterprise Threat Management Identify, assess and mitigate cyber threats across enterprise infrastructure and business systems Conduct proactive threat assessments and vulnerability analysis Develop and implement security controls and remediation strategies Monitor emerging threats and recommend appropriate defensive measures Enhance threat detection, monitoring and incident response capabilities Develop and maintain incident response playbooks and operational procedures Work closely with third-party security providers during incidents and security assessments Security Engineering & Risk Support enterprise security architecture and secure design initiatives Contribute to cyber risk management and governance activities Assess third-party and supply chain security risks Support penetration testing, vulnerability management and security assurance programmes Produce meaningful security metrics and KPI reporting for stakeholders Ensure alignment with recognised security frameworks and regulatory requirements Security Improvement Collaborate with infrastructure, cloud and engineering teams to embed security best practice Participate in Red Team / Blue Team exercises and cyber resilience testing Support business continuity and disaster recovery planning Champion continuous improvement across the organisation's security capability Communicate technical security risks clearly to both technical and business stakeholders What You'll Bring We're looking for someone who enjoys solving complex security challenges within large enterprise environments. You'll ideally have: A minimum of 5 years' experience in Cyber Security or Information Security Strong experience protecting enterprise environments against modern cyber threats Experience designing and implementing security controls to reduce organisational risk Excellent knowledge of enterprise security technologies and security operations Experience with SIEM platforms, incident response and threat detection Strong understanding of vulnerability management and security remediation Experience working with recognised security frameworks including: NIST ISO 27001 CIS Controls Cyber Essentials Knowledge of MITRE ATT&CK, Cyber Kill Chain and modern threat intelligence methodologies Excellent analytical, troubleshooting and stakeholder management skills Technical Environment Experience with several of the following technologies would be advantageous: Microsoft Defender Splunk Qualys Azure Security AWS Microsoft 365 Security PowerShell Python Kubernetes Windows Server Linux SOAR platforms Data Loss Prevention (DLP) DevSecOps practices Experience with AI-driven threat detection technologies would also be beneficial. Qualifications Ideally you'll hold one of the following: CISSP (preferred) CISM GIAC Certification CEH However, we recognise that exceptional enterprise Cyber Security experience is just as valuable. If you've developed your expertise through hands-on experience and hold certifications such as CompTIA Security+ , we'd still be keen to hear from you. Ideal Background We'd particularly like to speak with professionals currently working as: Senior Cyber Security Engineer Cyber Security Engineer Information Security Engineer Security Operations Engineer Threat Detection Engineer Cyber Defence Engineer Blue Team Engineer Senior SOC Engineer Security Consultant Experience within large enterprise or global organisations would be highly desirable. Why Join? You'll become part of a collaborative Cyber Security team within a business that continues to invest heavily in technology and security. In return, you'll benefit from: Competitive salary up to £80,000 (+ benefits) Hybrid working (2 3 days onsite in Surrey) Exposure to enterprise-scale security technologies Opportunities to influence security strategy Ongoing investment in professional development and certifications Long-term career progression within a stable global organisation A supportive and collaborative working culture Ready to Make an Impact? If you're passionate about enterprise Cyber Security, enjoy solving complex security challenges and want to help shape the future of Cyber Security within a global organisation, we'd love to hear from you. If you are passionate about cybersecurity, threat management and strengthening enterprise security capabilities, we would love to hear from you.
Aug 05, 2026
Full time
Cyber Security Engineer/Specialist Permanent Up to £80,000 (+ Benefits) Hybrid Working (2 3 days per week Onsite) Surrey Help Shape Enterprise Cyber Security on a Global Scale We're looking for an experienced Cyber Security Engineer/Specialist to join a global organisation where security is a genuine business priority, not simply a compliance exercise. This is an opportunity to play a key role in protecting a complex enterprise environment, helping to identify, assess and mitigate sophisticated cyber threats while influencing the organisation's long-term security strategy. Working alongside infrastructure, architecture and operational teams, you'll strengthen enterprise security capabilities, improve cyber resilience and help safeguard critical business systems across an international environment. If you're looking for a role where you can make a real impact while continuing to develop your career within a stable organisation, we'd love to hear from you. The Role This is an enterprise Cyber Security position focused on proactive threat mitigation, security improvement and risk reduction rather than purely operational support. You'll be responsible for strengthening the organisation's security posture through threat assessment, vulnerability management, incident response and continuous security improvement initiatives. Key responsibilities include: Enterprise Threat Management Identify, assess and mitigate cyber threats across enterprise infrastructure and business systems Conduct proactive threat assessments and vulnerability analysis Develop and implement security controls and remediation strategies Monitor emerging threats and recommend appropriate defensive measures Enhance threat detection, monitoring and incident response capabilities Develop and maintain incident response playbooks and operational procedures Work closely with third-party security providers during incidents and security assessments Security Engineering & Risk Support enterprise security architecture and secure design initiatives Contribute to cyber risk management and governance activities Assess third-party and supply chain security risks Support penetration testing, vulnerability management and security assurance programmes Produce meaningful security metrics and KPI reporting for stakeholders Ensure alignment with recognised security frameworks and regulatory requirements Security Improvement Collaborate with infrastructure, cloud and engineering teams to embed security best practice Participate in Red Team / Blue Team exercises and cyber resilience testing Support business continuity and disaster recovery planning Champion continuous improvement across the organisation's security capability Communicate technical security risks clearly to both technical and business stakeholders What You'll Bring We're looking for someone who enjoys solving complex security challenges within large enterprise environments. You'll ideally have: A minimum of 5 years' experience in Cyber Security or Information Security Strong experience protecting enterprise environments against modern cyber threats Experience designing and implementing security controls to reduce organisational risk Excellent knowledge of enterprise security technologies and security operations Experience with SIEM platforms, incident response and threat detection Strong understanding of vulnerability management and security remediation Experience working with recognised security frameworks including: NIST ISO 27001 CIS Controls Cyber Essentials Knowledge of MITRE ATT&CK, Cyber Kill Chain and modern threat intelligence methodologies Excellent analytical, troubleshooting and stakeholder management skills Technical Environment Experience with several of the following technologies would be advantageous: Microsoft Defender Splunk Qualys Azure Security AWS Microsoft 365 Security PowerShell Python Kubernetes Windows Server Linux SOAR platforms Data Loss Prevention (DLP) DevSecOps practices Experience with AI-driven threat detection technologies would also be beneficial. Qualifications Ideally you'll hold one of the following: CISSP (preferred) CISM GIAC Certification CEH However, we recognise that exceptional enterprise Cyber Security experience is just as valuable. If you've developed your expertise through hands-on experience and hold certifications such as CompTIA Security+ , we'd still be keen to hear from you. Ideal Background We'd particularly like to speak with professionals currently working as: Senior Cyber Security Engineer Cyber Security Engineer Information Security Engineer Security Operations Engineer Threat Detection Engineer Cyber Defence Engineer Blue Team Engineer Senior SOC Engineer Security Consultant Experience within large enterprise or global organisations would be highly desirable. Why Join? You'll become part of a collaborative Cyber Security team within a business that continues to invest heavily in technology and security. In return, you'll benefit from: Competitive salary up to £80,000 (+ benefits) Hybrid working (2 3 days onsite in Surrey) Exposure to enterprise-scale security technologies Opportunities to influence security strategy Ongoing investment in professional development and certifications Long-term career progression within a stable global organisation A supportive and collaborative working culture Ready to Make an Impact? If you're passionate about enterprise Cyber Security, enjoy solving complex security challenges and want to help shape the future of Cyber Security within a global organisation, we'd love to hear from you. If you are passionate about cybersecurity, threat management and strengthening enterprise security capabilities, we would love to hear from you.
We are a Global Recruitment specialist that provides support to the clients across EMEA, APAC, US and Canada. We have an excellent job opportunity for you. Role Title: Cloud Engineering_Senior GCP DevSecOps Engineer Location: Sheffield -3 days WFO Duration: 30/07/2027 Rate: £460 per day(PAYE through Umbrella) Job Description: Key responsibilities will include: Build, deploy and manage components of the GCP foundation platform using Google Cloud services (eg, GKE, BigQuery, Cloud Build, Cloud Run) and automation-first engineering practices. Engineer repeatable platform and security capabilities using Infrastructure as Code (IaC), such as Terraform and/or Config Connector, following established engineering standards. Implement and enhance preventive security controls and guardrails centrally to improve overall cloud security posture and reduce operational risk. Integrate, configure, deploy and manage common cloud services across IAM, networking, logging/monitoring, operating systems and container platforms. Embed security into delivery pipelines by building and supporting CI/CD and continuous testing capabilities (eg, Cloud Build, GitOps tooling such as FluxCD, Helm). Ensure alignment and compliance with centrally defined Cloud Security Standards and contribute to auditability through evidence, controls mapping and documentation. Operate within agreed change management practices, producing impact assessments where required and ensuring controlled, traceable deployments. Maintain high-quality operational documentation, runbooks and support procedures to enable sustainable operations and effective handover. What you need to have to succeed in this role: The ideal candidate for this role will have the following experience and capabilities: Hands-on, demonstrable experience on GCP building and operating cloud services in production (hands-on GCP experience is essential). Strong experience with core GCP services; exposure to GKE, BigQuery, Cloud Build and/or Cloud Run is highly desirable. Expert understanding of cloud security principles and GCP-specific best practices, including IAM design, logging/monitoring, network security controls and workload security. Strong understanding of DevOps/SRE principles, including reliability, observability, incident response supportability and engineering for resilience. Proven experience implementing Infrastructure as code using Terraform (and/or Config Connector), including module design, environments, policy-driven controls and automated deployment patterns. Experience building and operation CI/CD and related tooling (eg, Cloud Build, GitOps, FluxCD, Helm) with security controls Embedded into delivery workflows. Good programming/Scripting skills in at least one of: Python, Go, Bash, with practical mindset for automation and operational tooling. Security and compliance experience, including auditability, control evidence, configuration management and the ability to work with compliance/auditing/monitoring tooling. Strong communication and stakeholder management skills, with the ability ot explain complex technical topics clearly to engineers and non-engineers. A solid understanding of risk management and proven experience ensuring compliance with relevant regulatory and internal control requirements. Essential skills: Building secure and compliant GCP capabilities using automation-first approaches. Implementing and operating preventive controls and guardrails at scale. Strong troubleshooting capability across cloud infrastructure, Kubernetes/container platforms and CI/CD pipelines. Ability to drive continuous improvement, simplify operational processes and resuce oil through automation. Desirable skills: GCP certifications (eg, Professional Cloud Security Engineer, Professional Cloud DevOps Engineer, Professional Cloud Architect). Experience operation regulated workloads in a large enterprise environment. Experience with container security patterns and Kubernetes hardening approaches. Familiarity integrating security findings and policy checks into DevSecOps workflows and reporting. If you are interested in this position and would like to learn more, please send through your CV and we will get in touch with you as soon as possible. Please note, candidates are often Shortlisted within 48 hours.
Aug 04, 2026
Contractor
We are a Global Recruitment specialist that provides support to the clients across EMEA, APAC, US and Canada. We have an excellent job opportunity for you. Role Title: Cloud Engineering_Senior GCP DevSecOps Engineer Location: Sheffield -3 days WFO Duration: 30/07/2027 Rate: £460 per day(PAYE through Umbrella) Job Description: Key responsibilities will include: Build, deploy and manage components of the GCP foundation platform using Google Cloud services (eg, GKE, BigQuery, Cloud Build, Cloud Run) and automation-first engineering practices. Engineer repeatable platform and security capabilities using Infrastructure as Code (IaC), such as Terraform and/or Config Connector, following established engineering standards. Implement and enhance preventive security controls and guardrails centrally to improve overall cloud security posture and reduce operational risk. Integrate, configure, deploy and manage common cloud services across IAM, networking, logging/monitoring, operating systems and container platforms. Embed security into delivery pipelines by building and supporting CI/CD and continuous testing capabilities (eg, Cloud Build, GitOps tooling such as FluxCD, Helm). Ensure alignment and compliance with centrally defined Cloud Security Standards and contribute to auditability through evidence, controls mapping and documentation. Operate within agreed change management practices, producing impact assessments where required and ensuring controlled, traceable deployments. Maintain high-quality operational documentation, runbooks and support procedures to enable sustainable operations and effective handover. What you need to have to succeed in this role: The ideal candidate for this role will have the following experience and capabilities: Hands-on, demonstrable experience on GCP building and operating cloud services in production (hands-on GCP experience is essential). Strong experience with core GCP services; exposure to GKE, BigQuery, Cloud Build and/or Cloud Run is highly desirable. Expert understanding of cloud security principles and GCP-specific best practices, including IAM design, logging/monitoring, network security controls and workload security. Strong understanding of DevOps/SRE principles, including reliability, observability, incident response supportability and engineering for resilience. Proven experience implementing Infrastructure as code using Terraform (and/or Config Connector), including module design, environments, policy-driven controls and automated deployment patterns. Experience building and operation CI/CD and related tooling (eg, Cloud Build, GitOps, FluxCD, Helm) with security controls Embedded into delivery workflows. Good programming/Scripting skills in at least one of: Python, Go, Bash, with practical mindset for automation and operational tooling. Security and compliance experience, including auditability, control evidence, configuration management and the ability to work with compliance/auditing/monitoring tooling. Strong communication and stakeholder management skills, with the ability ot explain complex technical topics clearly to engineers and non-engineers. A solid understanding of risk management and proven experience ensuring compliance with relevant regulatory and internal control requirements. Essential skills: Building secure and compliant GCP capabilities using automation-first approaches. Implementing and operating preventive controls and guardrails at scale. Strong troubleshooting capability across cloud infrastructure, Kubernetes/container platforms and CI/CD pipelines. Ability to drive continuous improvement, simplify operational processes and resuce oil through automation. Desirable skills: GCP certifications (eg, Professional Cloud Security Engineer, Professional Cloud DevOps Engineer, Professional Cloud Architect). Experience operation regulated workloads in a large enterprise environment. Experience with container security patterns and Kubernetes hardening approaches. Familiarity integrating security findings and policy checks into DevSecOps workflows and reporting. If you are interested in this position and would like to learn more, please send through your CV and we will get in touch with you as soon as possible. Please note, candidates are often Shortlisted within 48 hours.
Role Title: Senior GCP (Google Cloud Platform) DevSecOps Engineer Duration: contract to run until 31/07/2027 Location: Sheffield. Hybrid 3 days per week onsite Rate: up to £473.80 p/d Umbrella inside IR35 Key responsibilities will include: Build, deploy and manage components of the client's GCP foundation platform using Google Cloud services (eg, GKE, BigQuery, Cloud Build, Cloud Run) and automation-first engineering practices. Engineer repeatable platform and security capabilities using Infrastructure as Code (IaC), such as Terraform and/or Config Connector, following established engineering standards. Implement and enhance preventive security controls and guardrails centrally to improve overall cloud security posture and reduce operational risk. Integrate, configure, deploy and manage common cloud services across IAM, networking, logging/monitoring, operating systems and container platforms. Embed security into delivery pipelines by building and supporting CI/CD and continuous testing capabilities (eg, Cloud Build, GitOps tooling such as FluxCD, Helm). Ensure alignment and compliance with centrally defined Cloud Security Standards and contribute to auditability through evidence, controls mapping and documentation. Operate within agreed change management practices, producing impact assessments where required and ensuring controlled, traceable deployments. Maintain high-quality operational documentation, runbooks and support procedures to enable sustainable operations and effective handover. What you need to have to succeed in this role: The ideal candidate for this role will have the following experience and capabilities: Hands-on, demonstrable experience on GCP building and operating cloud services in production (hands-on GCP experience is essential). Strong experience with core GCP services; exposure to GKE, BigQuery, Cloud Build and/or Cloud Run is highly desirable. Expert understanding of cloud security principles and GCP-specific best practices, including IAM design, logging/monitoring, network security controls and workload security. Strong understanding of DevOps/SRE principles, including reliability, observability, incident response supportability and engineering for resilience. Proven experience implementing Infrastructure as code using Terraform (and/or Config Connector), including module design, environments, policy-driven controls and automated deployment patterns. Experience building and operation CI/CD and related tooling (eg, Cloud Build, GitOps, FluxCD, Helm) with security controls Embedded into delivery workflows. Good programming/Scripting skills in at least one of: Python, Go, Bash, with practical mindset for automation and operational tooling. Security and compliance experience, including auditability, control evidence, configuration management and the ability to work with compliance/auditing/monitoring tooling. Strong communication and stakeholder management skills, with the ability ot explain complex technical topics clearly to engineers and non-engineers. A solid understanding of risk management and proven experience ensuring compliance with relevant regulatory and internal control requirements. Essential skills: Building secure and compliant GCP capabilities using automation-first approaches. Implementing and operating preventive controls and guardrails at scale. Strong troubleshooting capability across cloud infrastructure, Kubernetes/container platforms and CI/CD pipelines. Ability to drive continuous improvement, simplify operational processes and resuce oil through automation. Desirable skills: GCP certifications (eg, Professional Cloud Security Engineer, Professional Cloud DevOps Engineer, Professional Cloud Architect). Experience operation regulated workloads in a large enterprise environment. Experience with container security patterns and Kubernetes hardening approaches. Familiarity integrating security findings and policy checks into DevSecOps workflows and reporting. All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply! If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Aug 03, 2026
Contractor
Role Title: Senior GCP (Google Cloud Platform) DevSecOps Engineer Duration: contract to run until 31/07/2027 Location: Sheffield. Hybrid 3 days per week onsite Rate: up to £473.80 p/d Umbrella inside IR35 Key responsibilities will include: Build, deploy and manage components of the client's GCP foundation platform using Google Cloud services (eg, GKE, BigQuery, Cloud Build, Cloud Run) and automation-first engineering practices. Engineer repeatable platform and security capabilities using Infrastructure as Code (IaC), such as Terraform and/or Config Connector, following established engineering standards. Implement and enhance preventive security controls and guardrails centrally to improve overall cloud security posture and reduce operational risk. Integrate, configure, deploy and manage common cloud services across IAM, networking, logging/monitoring, operating systems and container platforms. Embed security into delivery pipelines by building and supporting CI/CD and continuous testing capabilities (eg, Cloud Build, GitOps tooling such as FluxCD, Helm). Ensure alignment and compliance with centrally defined Cloud Security Standards and contribute to auditability through evidence, controls mapping and documentation. Operate within agreed change management practices, producing impact assessments where required and ensuring controlled, traceable deployments. Maintain high-quality operational documentation, runbooks and support procedures to enable sustainable operations and effective handover. What you need to have to succeed in this role: The ideal candidate for this role will have the following experience and capabilities: Hands-on, demonstrable experience on GCP building and operating cloud services in production (hands-on GCP experience is essential). Strong experience with core GCP services; exposure to GKE, BigQuery, Cloud Build and/or Cloud Run is highly desirable. Expert understanding of cloud security principles and GCP-specific best practices, including IAM design, logging/monitoring, network security controls and workload security. Strong understanding of DevOps/SRE principles, including reliability, observability, incident response supportability and engineering for resilience. Proven experience implementing Infrastructure as code using Terraform (and/or Config Connector), including module design, environments, policy-driven controls and automated deployment patterns. Experience building and operation CI/CD and related tooling (eg, Cloud Build, GitOps, FluxCD, Helm) with security controls Embedded into delivery workflows. Good programming/Scripting skills in at least one of: Python, Go, Bash, with practical mindset for automation and operational tooling. Security and compliance experience, including auditability, control evidence, configuration management and the ability to work with compliance/auditing/monitoring tooling. Strong communication and stakeholder management skills, with the ability ot explain complex technical topics clearly to engineers and non-engineers. A solid understanding of risk management and proven experience ensuring compliance with relevant regulatory and internal control requirements. Essential skills: Building secure and compliant GCP capabilities using automation-first approaches. Implementing and operating preventive controls and guardrails at scale. Strong troubleshooting capability across cloud infrastructure, Kubernetes/container platforms and CI/CD pipelines. Ability to drive continuous improvement, simplify operational processes and resuce oil through automation. Desirable skills: GCP certifications (eg, Professional Cloud Security Engineer, Professional Cloud DevOps Engineer, Professional Cloud Architect). Experience operation regulated workloads in a large enterprise environment. Experience with container security patterns and Kubernetes hardening approaches. Familiarity integrating security findings and policy checks into DevSecOps workflows and reporting. All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply! If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Senior Security Risk Assurance Manager - SC cleared Location: Hybrid (75% remote) with on-site presence as required Contract Type: Permanent & Full-time Salary: Competitive + Benefits About the Role The Senior Security Risk Assurance Manager plays a critical role in strengthening the organisation's security posture through strategic risk-based assurance activities. This role supports informed decision-making across the enterprise by providing expert insight into the effectiveness of security controls, risk management practices, and supply chain security. The position may sit within one of several assurance functions, including internal security assurance, supply chain assurance, or enterprise-level risk management. Key Responsibilities Lead and manage a team of security professionals to deliver high-quality assurance activities. Develop and maintain an annual security assurance plan aligned with strategic business risks. Engage with stakeholders to scope, plan, and execute assurance activities across people, processes, and technology. Validate and interpret evidence to provide a holistic view of the organisation's security posture. Present findings and recommendations to senior leadership and governance forums. Collaborate with internal teams (eg, threat intelligence, compliance, audit) to ensure assurance activities reflect current threat landscapes. Act as a primary interface for business units, ensuring alignment between assurance activities and operational priorities. Promote continuous improvement and innovation in assurance practices. Ensure assurance reports are accurate, actionable, and meet quality standards. Share good practices and lessons learned across the organisation. Experience Required Proven leadership experience in security risk assurance or related fields. Strong understanding of enterprise security risk management principles. Experience in conducting security assessments and producing assurance reports. Ability to engage and influence stakeholders at all levels. Familiarity with security frameworks and standards (eg, ISO 27001, NIST, CIS Controls). Excellent communication, planning, and organisational skills. Experience managing teams and developing talent. Ability to interpret complex technical and business information to assess risk. Experience in supply chain security assurance. Knowledge of secure by design principles and accreditation processes. Understanding of threat intelligence and its application in assurance. Experience working in regulated or high-assurance environments (eg, government, finance, defence). Familiarity with risk management tools and methodologies. What's in it for You Flexible Working: Remote-first with travel as needed. Career Development: Continuous learning and professional growth. Benefits Package: Includes Private Health Care, Cash Back Plan, Buy/Sell Holiday Options, Life Assurance, and more. Interested? Submit your application to learn more about this exciting opportunity. Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
Oct 06, 2025
Full time
Senior Security Risk Assurance Manager - SC cleared Location: Hybrid (75% remote) with on-site presence as required Contract Type: Permanent & Full-time Salary: Competitive + Benefits About the Role The Senior Security Risk Assurance Manager plays a critical role in strengthening the organisation's security posture through strategic risk-based assurance activities. This role supports informed decision-making across the enterprise by providing expert insight into the effectiveness of security controls, risk management practices, and supply chain security. The position may sit within one of several assurance functions, including internal security assurance, supply chain assurance, or enterprise-level risk management. Key Responsibilities Lead and manage a team of security professionals to deliver high-quality assurance activities. Develop and maintain an annual security assurance plan aligned with strategic business risks. Engage with stakeholders to scope, plan, and execute assurance activities across people, processes, and technology. Validate and interpret evidence to provide a holistic view of the organisation's security posture. Present findings and recommendations to senior leadership and governance forums. Collaborate with internal teams (eg, threat intelligence, compliance, audit) to ensure assurance activities reflect current threat landscapes. Act as a primary interface for business units, ensuring alignment between assurance activities and operational priorities. Promote continuous improvement and innovation in assurance practices. Ensure assurance reports are accurate, actionable, and meet quality standards. Share good practices and lessons learned across the organisation. Experience Required Proven leadership experience in security risk assurance or related fields. Strong understanding of enterprise security risk management principles. Experience in conducting security assessments and producing assurance reports. Ability to engage and influence stakeholders at all levels. Familiarity with security frameworks and standards (eg, ISO 27001, NIST, CIS Controls). Excellent communication, planning, and organisational skills. Experience managing teams and developing talent. Ability to interpret complex technical and business information to assess risk. Experience in supply chain security assurance. Knowledge of secure by design principles and accreditation processes. Understanding of threat intelligence and its application in assurance. Experience working in regulated or high-assurance environments (eg, government, finance, defence). Familiarity with risk management tools and methodologies. What's in it for You Flexible Working: Remote-first with travel as needed. Career Development: Continuous learning and professional growth. Benefits Package: Includes Private Health Care, Cash Back Plan, Buy/Sell Holiday Options, Life Assurance, and more. Interested? Submit your application to learn more about this exciting opportunity. Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
Role Title: Senior Security AI Solution Architect/Consultant Duration: contract to run until 26/03/2026 Location: London, Hybrid/Flexible (Occasional travel to NW may be required) Rate: up to £671 p/d Umbrella inside IR35 Role purpose/summary Our client is looking for a Snr Security AI Solution Architect/Consultant To support and deliver secure AI solutions within financial services. The architect will shape strategy, design future-state architecture, and deliver practical security capabilities for AI adoption, ensuring compliance with evolving regulations and maintaining a strong security posture. Key Skills/requirements Assess "as-is" and "to-be" security architectures for AI Platforms, AI & GENAI Delivery Roadmaps. Share Security AI & GENAI Security Learnings & Subject Matter Expertise. Shape the short- & long-term AI Security Architecture Strategy incorporating regulation (EUAI Act), standards, framework & policy priorities. Develop architectural documentation for AI security initiatives. Support the delivery of the AI Security Architecture Strategy across both internal & external stakeholders to Security. Ensure there is a fit for purpose set of Functional and Non-Functional Requirements for project technology deliveries Provide hands-on delivery support where required. General "architect" responsibilities that they would also contribute to: Ensure there is a current Security Architecture defined and maintained for key domains (eg, Endpoint, Cloud, Network, etc.) which clearly outlines the security principles, requirements and capabilities required and how those are instantiated Ensure there is an architectural vision for all projects that at minimum has a component architecture and high-level business process defined (including the product owner and operational team) Ensure architecture artifacts allow to us to quickly answer and evidence routine regulatory queries and attestations Ensure there is a fit for purpose set of Functional and Non-Functional Requirements for project technology deliveries Map security tooling deployed in the estate (including non-standard environments and non-CISO managed technologies) to the capabilities it implements (not the set of product features - what is actually in use and operationalised) Ensure that projects have correctly aligned scope to Cyber Excellence Programmes and technology/platform strategy Provide input to and take ownership of relevant architectural artifacts that will be produced as part of Excellence Programme workstreams. Survey emerging threats and emerging technologies to identify opportunities for targeted innovation exercises such Proof of Value evaluations Produce patterns which outline solutions for commonly occurring business security needs and security service consumption Validate patterns are adopted by control domain solutions Support Security Consultants as required on complex engagements and provide architectural artifacts such as patterns and principles where necessary Essential Skills & Experience Proven experience as a Security Solution Architect Deep understanding of AI and Generative AI technologies. Deep understanding of AI and Generative AI Security Capabilities. Knowledge of infrastructure and cloud security (AWS; exposure to Azure, GCP, and on-premise environments also valuable). Areas of Knowledge/Skillset: Emergent Technology Governance Artificial Intelligence Data Security within AI Systems Machine Learning AI Operation Cyber recovery IT Infrastructure, Cloud Risk and Regulation Experience in financial services environments. Ability to work across both strategic (roadmaps, future planning) and tactical (delivery, hands-on execution) levels. Personable and collaborative approach, with the ability to engage stakeholders and "roll up sleeves" when needed. Desirable Skills: Experience with regulatory compliance in AI and security, especially EU AI Act. Previous work on securing AI models and platforms (model trust, data security, usage monitoring). AI & GenAI Architecture: Design and implementation of AI factories, pipelines, and modular platforms across regulated environments. GenAI System Design and Implementation: End to end delivery of AI and GenAI systems using modern architecture techniques including LLM optimisation, RAG and Agentic design. AI Risk Management & Governance: Development of bespoke risk frameworks, taxonomies, and AI control libraries tailored to MRM, CRO, and CDO functions. Responsible & Ethical AI: Integration of RAI principles into system design, controls, audit frameworks, and enterprise AI strategies. Cyber & Resilience in AI: Embedding threat modelling, adversarial robustness, data integrity, and continuity planning into AI solution architecture. AI Enablement & Delivery: End-to-end AI life cycle orchestration including readiness assessments, regulatory reviews, and business adoption. Emerging Technology Strategy: Digital responsibility, AI assurance, and horizon scanning for next-gen regulatory, legal, and societal risks. Experience liaising with senior stakeholders and external consultancies (PwC, Accenture, etc.) All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply!
Oct 03, 2025
Contractor
Role Title: Senior Security AI Solution Architect/Consultant Duration: contract to run until 26/03/2026 Location: London, Hybrid/Flexible (Occasional travel to NW may be required) Rate: up to £671 p/d Umbrella inside IR35 Role purpose/summary Our client is looking for a Snr Security AI Solution Architect/Consultant To support and deliver secure AI solutions within financial services. The architect will shape strategy, design future-state architecture, and deliver practical security capabilities for AI adoption, ensuring compliance with evolving regulations and maintaining a strong security posture. Key Skills/requirements Assess "as-is" and "to-be" security architectures for AI Platforms, AI & GENAI Delivery Roadmaps. Share Security AI & GENAI Security Learnings & Subject Matter Expertise. Shape the short- & long-term AI Security Architecture Strategy incorporating regulation (EUAI Act), standards, framework & policy priorities. Develop architectural documentation for AI security initiatives. Support the delivery of the AI Security Architecture Strategy across both internal & external stakeholders to Security. Ensure there is a fit for purpose set of Functional and Non-Functional Requirements for project technology deliveries Provide hands-on delivery support where required. General "architect" responsibilities that they would also contribute to: Ensure there is a current Security Architecture defined and maintained for key domains (eg, Endpoint, Cloud, Network, etc.) which clearly outlines the security principles, requirements and capabilities required and how those are instantiated Ensure there is an architectural vision for all projects that at minimum has a component architecture and high-level business process defined (including the product owner and operational team) Ensure architecture artifacts allow to us to quickly answer and evidence routine regulatory queries and attestations Ensure there is a fit for purpose set of Functional and Non-Functional Requirements for project technology deliveries Map security tooling deployed in the estate (including non-standard environments and non-CISO managed technologies) to the capabilities it implements (not the set of product features - what is actually in use and operationalised) Ensure that projects have correctly aligned scope to Cyber Excellence Programmes and technology/platform strategy Provide input to and take ownership of relevant architectural artifacts that will be produced as part of Excellence Programme workstreams. Survey emerging threats and emerging technologies to identify opportunities for targeted innovation exercises such Proof of Value evaluations Produce patterns which outline solutions for commonly occurring business security needs and security service consumption Validate patterns are adopted by control domain solutions Support Security Consultants as required on complex engagements and provide architectural artifacts such as patterns and principles where necessary Essential Skills & Experience Proven experience as a Security Solution Architect Deep understanding of AI and Generative AI technologies. Deep understanding of AI and Generative AI Security Capabilities. Knowledge of infrastructure and cloud security (AWS; exposure to Azure, GCP, and on-premise environments also valuable). Areas of Knowledge/Skillset: Emergent Technology Governance Artificial Intelligence Data Security within AI Systems Machine Learning AI Operation Cyber recovery IT Infrastructure, Cloud Risk and Regulation Experience in financial services environments. Ability to work across both strategic (roadmaps, future planning) and tactical (delivery, hands-on execution) levels. Personable and collaborative approach, with the ability to engage stakeholders and "roll up sleeves" when needed. Desirable Skills: Experience with regulatory compliance in AI and security, especially EU AI Act. Previous work on securing AI models and platforms (model trust, data security, usage monitoring). AI & GenAI Architecture: Design and implementation of AI factories, pipelines, and modular platforms across regulated environments. GenAI System Design and Implementation: End to end delivery of AI and GenAI systems using modern architecture techniques including LLM optimisation, RAG and Agentic design. AI Risk Management & Governance: Development of bespoke risk frameworks, taxonomies, and AI control libraries tailored to MRM, CRO, and CDO functions. Responsible & Ethical AI: Integration of RAI principles into system design, controls, audit frameworks, and enterprise AI strategies. Cyber & Resilience in AI: Embedding threat modelling, adversarial robustness, data integrity, and continuity planning into AI solution architecture. AI Enablement & Delivery: End-to-end AI life cycle orchestration including readiness assessments, regulatory reviews, and business adoption. Emerging Technology Strategy: Digital responsibility, AI assurance, and horizon scanning for next-gen regulatory, legal, and societal risks. Experience liaising with senior stakeholders and external consultancies (PwC, Accenture, etc.) All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply!
The Senior Cyber Security Architect is a strategic technical leader responsible for designing, implementing, and evolving the organization's enterprise security architecture to protect critical assets, systems, and data. This role partners with senior IT, engineering, and business leaders to define security principles, standards, and roadmaps that align with business objectives while mitigating cyber risk. The Senior Cyber Security Architect serves as the primary subject matter expert on secure architecture design, emerging threats, and security technology evaluation, ensuring the organization is protected against both current and future cyber risks. The Role Security Architecture & Strategy Develop, maintain, and communicate the enterprise security architecture framework, patterns, and standards. Translate business and technical requirements into secure, scalable, and resilient architecture solutions. Define and champion the organization's secure-by-design and zero trust strategies. Align architecture decisions with regulatory requirements, industry best practices, and organizational risk appetite. Solution Design & Governance Provide architecture oversight and guidance for IT and business projects to ensure compliance with security standards. Conduct architecture reviews and threat modeling for new and existing systems, applications, and cloud deployments. Advise on secure integration of on-premises, hybrid, and multi-cloud environments. Collaborate with DevSecOps teams to embed security in the software development lifecycle (SDLC). Technology Evaluation & Innovation Research and assess emerging security technologies, tools, and practices for enterprise adoption. Drive the evaluation, selection, and implementation of security platforms (e.g., IAM, PAM, SIEM, EDR, NDR, CASB). Partner with infrastructure and network teams to enhance security posture without impeding operational efficiency. Risk Management & Compliance Ensure architecture designs meet compliance requirements such as NIST CSF, ISO 27001, DORA, and local data protection regulations. Support security risk assessments and recommend remediation strategies for high-risk findings. Collaborate with governance, risk, and compliance (GRC) teams to maintain audit readiness. Leadership & Influence Serve as a trusted advisor to the CISO, CTO, and senior business leaders on security architecture matters. Mentor junior architects and security engineers, fostering technical excellence and innovation. Represent the organization in external security forums and architecture working groups. The Requirements Progressive experience in cybersecurity, with experience in an architecture leadership role. Deep expertise in security architecture across cloud, application, network, and endpoint domains. Strong knowledge of zero trust principles, secure cloud architecture (AWS, Azure, GCP), and modern identity solutions (IAM, PAM, MFA, SSO). Familiarity with enterprise security frameworks and regulations (e.g., NIST CSF, TOGAF, SABSA, DORA, GDPR). Relevant certifications (e.g., CISSP, CCSP, SABSA, AWS/Azure Security Specialty) strongly preferred. Exceptional communication, stakeholder management, and influencing skills. Bachelor's degree in Computer Science, Information Security, or related field is preferred. At WTW, we believe difference makes us stronger. We want our workforce to reflect the different and varied markets we operate in and to build a culture of inclusivity that makes colleagues feel welcome, valued and empowered to bring their whole selves to work every day. We are an equal opportunity employer committed to fostering an inclusive work environment throughout our organisation. We embrace all types of diversity. We're committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please contact your recruiter.
Oct 02, 2025
Full time
The Senior Cyber Security Architect is a strategic technical leader responsible for designing, implementing, and evolving the organization's enterprise security architecture to protect critical assets, systems, and data. This role partners with senior IT, engineering, and business leaders to define security principles, standards, and roadmaps that align with business objectives while mitigating cyber risk. The Senior Cyber Security Architect serves as the primary subject matter expert on secure architecture design, emerging threats, and security technology evaluation, ensuring the organization is protected against both current and future cyber risks. The Role Security Architecture & Strategy Develop, maintain, and communicate the enterprise security architecture framework, patterns, and standards. Translate business and technical requirements into secure, scalable, and resilient architecture solutions. Define and champion the organization's secure-by-design and zero trust strategies. Align architecture decisions with regulatory requirements, industry best practices, and organizational risk appetite. Solution Design & Governance Provide architecture oversight and guidance for IT and business projects to ensure compliance with security standards. Conduct architecture reviews and threat modeling for new and existing systems, applications, and cloud deployments. Advise on secure integration of on-premises, hybrid, and multi-cloud environments. Collaborate with DevSecOps teams to embed security in the software development lifecycle (SDLC). Technology Evaluation & Innovation Research and assess emerging security technologies, tools, and practices for enterprise adoption. Drive the evaluation, selection, and implementation of security platforms (e.g., IAM, PAM, SIEM, EDR, NDR, CASB). Partner with infrastructure and network teams to enhance security posture without impeding operational efficiency. Risk Management & Compliance Ensure architecture designs meet compliance requirements such as NIST CSF, ISO 27001, DORA, and local data protection regulations. Support security risk assessments and recommend remediation strategies for high-risk findings. Collaborate with governance, risk, and compliance (GRC) teams to maintain audit readiness. Leadership & Influence Serve as a trusted advisor to the CISO, CTO, and senior business leaders on security architecture matters. Mentor junior architects and security engineers, fostering technical excellence and innovation. Represent the organization in external security forums and architecture working groups. The Requirements Progressive experience in cybersecurity, with experience in an architecture leadership role. Deep expertise in security architecture across cloud, application, network, and endpoint domains. Strong knowledge of zero trust principles, secure cloud architecture (AWS, Azure, GCP), and modern identity solutions (IAM, PAM, MFA, SSO). Familiarity with enterprise security frameworks and regulations (e.g., NIST CSF, TOGAF, SABSA, DORA, GDPR). Relevant certifications (e.g., CISSP, CCSP, SABSA, AWS/Azure Security Specialty) strongly preferred. Exceptional communication, stakeholder management, and influencing skills. Bachelor's degree in Computer Science, Information Security, or related field is preferred. At WTW, we believe difference makes us stronger. We want our workforce to reflect the different and varied markets we operate in and to build a culture of inclusivity that makes colleagues feel welcome, valued and empowered to bring their whole selves to work every day. We are an equal opportunity employer committed to fostering an inclusive work environment throughout our organisation. We embrace all types of diversity. We're committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please contact your recruiter.
Cyber Threat Intelligence Analyst: Cyber, Threat, SOC, Security Clearance Our Global Enterprise client is looking for a skilled Cyber Security Analyst with 5-6 years of experience within Threat Intelligence to join their team. Start Date: ASAP Duration: 55 days Pay Rate: £487 per hour (PLEASE NOTE: Employer NI is paid for by the client) Total Daily Earnings: £553 (includes rolled up holiday) IR35 Status: Inside Location: Hybrid/Hatfield (some travel to Blackfriars if required but this will be on a rare occasion) NOTE: Active SC Clearance is highly desirable. Responsibilities: Threat Intelligence Platform (TIP) Maintenance (20%): Take ownership of the threat intelligence platform and related tooling, ensuring its effective utilisation for monitoring and analysing both cyber and geopolitical threats. Optimise the platform to enhance the team's capabilities in threat detection and response. Continue to develop access to internal data and leverage threat intelligence tooling to maximise intelligence opportunities. Cyber Threat Analysis & Dissemination (50%): Identify intelligence of concern for Computacenter across various sources and tooling and conduct analysis and assessment of such threats and their potential impact to the business. Monitor and analyse geopolitical events to identify potential impacts on the organisation's cyber security landscape. Using a variety of sources to increase knowledge, corroborate and parallel information. This involves engaging in communities and intelligence sharing initiatives. Have confidence in your ability to draw conclusions and provide intelligence led recommendations. Own and run regular briefings of Threat Intelligence to the wider security team. Respond to intelligence requests from internal teams, using all available sources of intelligence to produce assessments on the threat to support decision-making. Ensure clear and concise communication of assessments and complex bits of information for various stakeholders. Collaborate with cross-functional teams to address immediate intelligence needs and contribute to the overall security posture. Work closely alongside other Security Operations teams such as SOC Develop hypotheses based on threat intelligence to direct joint operations with Cyber Threat technical resources to direct threat hunting? Continue to develop access to internal data and leverage threat intelligence tooling to maximise intelligence opportunities. Dark Web Monitoring Ensuring Threat Intelligence Programme Meets Organisational Aims (15%): Collection of Priority Intelligence Requirements from key stakeholders Effective tracking of intelligence activities against these PIRs Reporting of service quality against KPIs Incident Response Support (15%): Required to work out of hours, when situation dictates, to support Incident Response activities Technical Skills & Experience: 5-6 years of experience within Threat Intelligence. Demonstrable experience in analysing and assessing cyber threats, including the ability to identify patterns and trends. Proficient in gathering, correlating, and interpreting data from various sources to produce actionable intelligence. Experience of giving detailed verbal threat briefings to key stakeholders. Experience working with a Threat Intelligence Platform (TIP). Excellent communication skills, including the ability to influence and persuade stakeholders to enact a more security focused approach. Understanding of the intelligence life cycle, from collection through to feedback. Experience in producing high-quality intelligence products and documentation for a variety of audiences. Familiarity with common cyber threats, threat actors, attack vectors, and vulnerabilities. Experience in leveraging open-source intelligence tools and techniques to gather information about threats. Knowledge of information assurance standards and frameworks including CIS, NIST, ISO 27001, Cyber Essentials/Essentials Plus, GDPR. Strong familiarity of threat cyber security frameworks such as MITRE ATT&CK, Killchain and NIST CSF 2.0 Desirable: Recognised information security and/or information technology industry certification. Good organisational and time management skills Experience of delivering and shaping Threat Modelling programmes Soft Skills: Excellent written and verbal English. Good presentation and moderation skills; professional and convincing manner of appearance and expression; clear, targeted communication (verbal and written). A strong desire to help others by sharing knowledge, peer reviewing, and contributing to technical and process standards. Work well within a team, report issues and risks, take part in team meetings, share ideas and work towards improving our service. Excellent communication and Customer facing customer service skills previous experience is essential. Ability to work independently and as part of a team is essential. To apply for this Cyber Threat Intelligence Analyst contract job, please click the button below and submit your latest CV. Curo Services endeavours to respond to all applications, however this may not always be possible during periods of high volume. Thank you for your patience. Curo Services is a trading name of Curo Resourcing Ltd and acts as an Employment Business for contract and temporary recruitment as well as an Employment Agency in relation to permanent vacancies.
Oct 02, 2025
Contractor
Cyber Threat Intelligence Analyst: Cyber, Threat, SOC, Security Clearance Our Global Enterprise client is looking for a skilled Cyber Security Analyst with 5-6 years of experience within Threat Intelligence to join their team. Start Date: ASAP Duration: 55 days Pay Rate: £487 per hour (PLEASE NOTE: Employer NI is paid for by the client) Total Daily Earnings: £553 (includes rolled up holiday) IR35 Status: Inside Location: Hybrid/Hatfield (some travel to Blackfriars if required but this will be on a rare occasion) NOTE: Active SC Clearance is highly desirable. Responsibilities: Threat Intelligence Platform (TIP) Maintenance (20%): Take ownership of the threat intelligence platform and related tooling, ensuring its effective utilisation for monitoring and analysing both cyber and geopolitical threats. Optimise the platform to enhance the team's capabilities in threat detection and response. Continue to develop access to internal data and leverage threat intelligence tooling to maximise intelligence opportunities. Cyber Threat Analysis & Dissemination (50%): Identify intelligence of concern for Computacenter across various sources and tooling and conduct analysis and assessment of such threats and their potential impact to the business. Monitor and analyse geopolitical events to identify potential impacts on the organisation's cyber security landscape. Using a variety of sources to increase knowledge, corroborate and parallel information. This involves engaging in communities and intelligence sharing initiatives. Have confidence in your ability to draw conclusions and provide intelligence led recommendations. Own and run regular briefings of Threat Intelligence to the wider security team. Respond to intelligence requests from internal teams, using all available sources of intelligence to produce assessments on the threat to support decision-making. Ensure clear and concise communication of assessments and complex bits of information for various stakeholders. Collaborate with cross-functional teams to address immediate intelligence needs and contribute to the overall security posture. Work closely alongside other Security Operations teams such as SOC Develop hypotheses based on threat intelligence to direct joint operations with Cyber Threat technical resources to direct threat hunting? Continue to develop access to internal data and leverage threat intelligence tooling to maximise intelligence opportunities. Dark Web Monitoring Ensuring Threat Intelligence Programme Meets Organisational Aims (15%): Collection of Priority Intelligence Requirements from key stakeholders Effective tracking of intelligence activities against these PIRs Reporting of service quality against KPIs Incident Response Support (15%): Required to work out of hours, when situation dictates, to support Incident Response activities Technical Skills & Experience: 5-6 years of experience within Threat Intelligence. Demonstrable experience in analysing and assessing cyber threats, including the ability to identify patterns and trends. Proficient in gathering, correlating, and interpreting data from various sources to produce actionable intelligence. Experience of giving detailed verbal threat briefings to key stakeholders. Experience working with a Threat Intelligence Platform (TIP). Excellent communication skills, including the ability to influence and persuade stakeholders to enact a more security focused approach. Understanding of the intelligence life cycle, from collection through to feedback. Experience in producing high-quality intelligence products and documentation for a variety of audiences. Familiarity with common cyber threats, threat actors, attack vectors, and vulnerabilities. Experience in leveraging open-source intelligence tools and techniques to gather information about threats. Knowledge of information assurance standards and frameworks including CIS, NIST, ISO 27001, Cyber Essentials/Essentials Plus, GDPR. Strong familiarity of threat cyber security frameworks such as MITRE ATT&CK, Killchain and NIST CSF 2.0 Desirable: Recognised information security and/or information technology industry certification. Good organisational and time management skills Experience of delivering and shaping Threat Modelling programmes Soft Skills: Excellent written and verbal English. Good presentation and moderation skills; professional and convincing manner of appearance and expression; clear, targeted communication (verbal and written). A strong desire to help others by sharing knowledge, peer reviewing, and contributing to technical and process standards. Work well within a team, report issues and risks, take part in team meetings, share ideas and work towards improving our service. Excellent communication and Customer facing customer service skills previous experience is essential. Ability to work independently and as part of a team is essential. To apply for this Cyber Threat Intelligence Analyst contract job, please click the button below and submit your latest CV. Curo Services endeavours to respond to all applications, however this may not always be possible during periods of high volume. Thank you for your patience. Curo Services is a trading name of Curo Resourcing Ltd and acts as an Employment Business for contract and temporary recruitment as well as an Employment Agency in relation to permanent vacancies.
FDM is a global business and technology consultancy seeking a Security Architect to work for our client within the public sector. This is initially a 6-month contract with the potential to extend and will be a hybrid role based in Solihull . Our client is seeking an experienced Security Architect to join one of our key public sector client engagements. This is an exciting opportunity to contribute to the strategic design of secure, cloud-based platforms supporting critical national infrastructure. As a Security Architect, you will play a central role in capability mapping, architectural design, and implementation of cloud-native security solutions. You will work closely with stakeholders to ensure that security controls and strategies align with organisational objectives, regulatory requirements, and evolving threat landscapes. This role is especially suited for professionals with a blend of hands-on expertise in Mist (Juniper Networks) and a strong technical foundation in Microsoft Azure security services. Responsibilities Perform detailed capability mapping into Mist (Juniper Networks), ensuring alignment between enterprise security needs and platform capabilities Design and implement scalable, secure security architectures for Microsoft Azure-based services and applications Define and enforce cloud security best practices, including identity and access management (IAM), data encryption, and monitoring Collaborate across teams to ensure consistent implementation of security controls and governance frameworks Lead risk assessments, threat modelling exercises, and security posture evaluations for cloud and hybrid environments Provide architectural guidance on network segmentation, secure integration, and secure connectivity between Mist and Azure ecosystems Monitor industry trends and emerging security technologies, providing expert recommendations on adoption and integration Document and communicate security architecture patterns, standards, and roadmaps to both technical and non-technical stakeholders Requirements Minimum of 10 years' experience in a Security Architect, Cloud Security Engineer, or related role Strong hands-on expertise with Mist (Juniper Networks), particularly around security capability mapping and integrations In-depth experience with Microsoft Azure security services, including Azure Active Directory (Azure AD), Microsoft Defender for Cloud, Azure Key Vault, Azure Security Center. Microsoft Sentinel Deep understanding of cloud-native security, zero-trust models, and secure network architecture Familiarity with compliance standards and security frameworks such as NIST, CIS, ISO 27001, GDPR, and HIPAA Excellent verbal and written communication skills with the ability to convey complex technical issues to business leaders Qualifications such as Microsoft Azure Security Engineer Associate (AZ-500), Certified Information Systems Security Professional (CISSP) and Juniper Networks Certification (Mist AI) are desirable Experience working in hybrid and multi-cloud environments Knowledge of DevSecOps practices and Infrastructure-as-Code (IaC) security tools (e.g., Terraform, Bicep) Why join us Career coaching, mentoring and access to upskilling throughout your entire FDM career Assignments with global companies and opportunities to work abroad Opportunity to re-skill and up-skill into new areas, develop non-linear career paths and build a skillset within your field Annual Leave Work place pension About FDM We are a business and technology consultancy and one of the UK's leading employers, recruiting the brightest talent to become the innovators of tomorrow. We have centres across Europe, North America and Asia-Pacific, and a global workforce of over 2,500 employees. FDM has shown exponential growth throughout the years, firmly establishing itself as an award-winning employer and is listed on the FTSE4Good Index. Diversity and Inclusion FDM Group is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, national origin, age, disability, veteran status or any other status protected by federal, provincial or local laws.
Sep 23, 2025
Full time
FDM is a global business and technology consultancy seeking a Security Architect to work for our client within the public sector. This is initially a 6-month contract with the potential to extend and will be a hybrid role based in Solihull . Our client is seeking an experienced Security Architect to join one of our key public sector client engagements. This is an exciting opportunity to contribute to the strategic design of secure, cloud-based platforms supporting critical national infrastructure. As a Security Architect, you will play a central role in capability mapping, architectural design, and implementation of cloud-native security solutions. You will work closely with stakeholders to ensure that security controls and strategies align with organisational objectives, regulatory requirements, and evolving threat landscapes. This role is especially suited for professionals with a blend of hands-on expertise in Mist (Juniper Networks) and a strong technical foundation in Microsoft Azure security services. Responsibilities Perform detailed capability mapping into Mist (Juniper Networks), ensuring alignment between enterprise security needs and platform capabilities Design and implement scalable, secure security architectures for Microsoft Azure-based services and applications Define and enforce cloud security best practices, including identity and access management (IAM), data encryption, and monitoring Collaborate across teams to ensure consistent implementation of security controls and governance frameworks Lead risk assessments, threat modelling exercises, and security posture evaluations for cloud and hybrid environments Provide architectural guidance on network segmentation, secure integration, and secure connectivity between Mist and Azure ecosystems Monitor industry trends and emerging security technologies, providing expert recommendations on adoption and integration Document and communicate security architecture patterns, standards, and roadmaps to both technical and non-technical stakeholders Requirements Minimum of 10 years' experience in a Security Architect, Cloud Security Engineer, or related role Strong hands-on expertise with Mist (Juniper Networks), particularly around security capability mapping and integrations In-depth experience with Microsoft Azure security services, including Azure Active Directory (Azure AD), Microsoft Defender for Cloud, Azure Key Vault, Azure Security Center. Microsoft Sentinel Deep understanding of cloud-native security, zero-trust models, and secure network architecture Familiarity with compliance standards and security frameworks such as NIST, CIS, ISO 27001, GDPR, and HIPAA Excellent verbal and written communication skills with the ability to convey complex technical issues to business leaders Qualifications such as Microsoft Azure Security Engineer Associate (AZ-500), Certified Information Systems Security Professional (CISSP) and Juniper Networks Certification (Mist AI) are desirable Experience working in hybrid and multi-cloud environments Knowledge of DevSecOps practices and Infrastructure-as-Code (IaC) security tools (e.g., Terraform, Bicep) Why join us Career coaching, mentoring and access to upskilling throughout your entire FDM career Assignments with global companies and opportunities to work abroad Opportunity to re-skill and up-skill into new areas, develop non-linear career paths and build a skillset within your field Annual Leave Work place pension About FDM We are a business and technology consultancy and one of the UK's leading employers, recruiting the brightest talent to become the innovators of tomorrow. We have centres across Europe, North America and Asia-Pacific, and a global workforce of over 2,500 employees. FDM has shown exponential growth throughout the years, firmly establishing itself as an award-winning employer and is listed on the FTSE4Good Index. Diversity and Inclusion FDM Group is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, national origin, age, disability, veteran status or any other status protected by federal, provincial or local laws.