IT Security Analyst Location: East Yorkshire area Salary: Competitive, depending on experience Working pattern: Full-time, on-site with collaborative team environment Protect systems. Strengthen resilience. Shape cyber security strategy. An established organisation is investing in its cyber capability and is looking for an IT Security Analyst to play a key role in protecting its systems, data and operations. This is an opportunity to join a collaborative IT environment where security is a business priority, not an afterthought. You will work closely with infrastructure and technical teams to strengthen cyber resilience, respond to threats and continuously improve security practices across the organisation. If you enjoy hands-on security work, problem solving and influencing best practice, this role offers real scope to make an impact. What you will be doing Monitor, develop and optimise SIEM and threat detection systems Investigate security incidents, coordinating response, containment and escalation Conduct vulnerability scanning and support remediation across the IT estate Work closely with infrastructure and technical teams to implement secure configurations Support and maintain security policies, procedures and controls Ensure alignment with recognised frameworks including ISO 27001 and NIST Deliver user awareness initiatives such as phishing simulations and training Stay up to date with emerging threats and recommend improvements to strengthen security posture Support disaster recovery, backup and data protection strategies aligned to business needs What we are looking for Proven experience in a cyber security or infrastructure security role Strong understanding of security principles, threat detection and risk-based thinking Experience with SIEM platforms, vulnerability management tools and detection response technologies such as EDR, XDR or MDR Knowledge of cyber security frameworks such as ISO 27001 or NIST Understanding of data protection legislation including GDPR Ability to investigate incidents, analyse findings and communicate clearly with stakeholders Strong analytical and problem-solving skills Ability to manage priorities and work effectively in a fast-paced environment Full UK driving licence Desirable experience Exposure to cloud platforms such as Azure Security certifications such as CompTIA Security+, CISSP or Microsoft accreditations Experience with ERP systems Scripting or automation knowledge Why apply? Opportunity to influence and improve cyber security across a growing organisation Collaborative environment working alongside infrastructure and technical specialists Exposure to modern security tools, frameworks and evolving technologies A role where your recommendations and expertise will directly shape security strategy Apply now If you are looking for a role where you can take ownership of security improvements and work in a business that values cyber resilience, we would like to hear from you.
Aug 18, 2026
Full time
IT Security Analyst Location: East Yorkshire area Salary: Competitive, depending on experience Working pattern: Full-time, on-site with collaborative team environment Protect systems. Strengthen resilience. Shape cyber security strategy. An established organisation is investing in its cyber capability and is looking for an IT Security Analyst to play a key role in protecting its systems, data and operations. This is an opportunity to join a collaborative IT environment where security is a business priority, not an afterthought. You will work closely with infrastructure and technical teams to strengthen cyber resilience, respond to threats and continuously improve security practices across the organisation. If you enjoy hands-on security work, problem solving and influencing best practice, this role offers real scope to make an impact. What you will be doing Monitor, develop and optimise SIEM and threat detection systems Investigate security incidents, coordinating response, containment and escalation Conduct vulnerability scanning and support remediation across the IT estate Work closely with infrastructure and technical teams to implement secure configurations Support and maintain security policies, procedures and controls Ensure alignment with recognised frameworks including ISO 27001 and NIST Deliver user awareness initiatives such as phishing simulations and training Stay up to date with emerging threats and recommend improvements to strengthen security posture Support disaster recovery, backup and data protection strategies aligned to business needs What we are looking for Proven experience in a cyber security or infrastructure security role Strong understanding of security principles, threat detection and risk-based thinking Experience with SIEM platforms, vulnerability management tools and detection response technologies such as EDR, XDR or MDR Knowledge of cyber security frameworks such as ISO 27001 or NIST Understanding of data protection legislation including GDPR Ability to investigate incidents, analyse findings and communicate clearly with stakeholders Strong analytical and problem-solving skills Ability to manage priorities and work effectively in a fast-paced environment Full UK driving licence Desirable experience Exposure to cloud platforms such as Azure Security certifications such as CompTIA Security+, CISSP or Microsoft accreditations Experience with ERP systems Scripting or automation knowledge Why apply? Opportunity to influence and improve cyber security across a growing organisation Collaborative environment working alongside infrastructure and technical specialists Exposure to modern security tools, frameworks and evolving technologies A role where your recommendations and expertise will directly shape security strategy Apply now If you are looking for a role where you can take ownership of security improvements and work in a business that values cyber resilience, we would like to hear from you.
IT Security Analyst - 40,000/ 45,000 per annum - Brandesburton (Hybrid) Principal IT are proud to be supporting a leading provider of modular buildings for various sectors, such as education, healthcare, defence, and justice. This is an excellent opportunity for someone with a passion for cybersecurity who is looking to play a key role in strengthening and developing an organisation's overall security posture and cyber resilience strategy. Working closely with the Infrastructure & Security Manager, you will be responsible for monitoring, detecting, investigating, and responding to security threats across the organisation's infrastructure and systems. You will also support vulnerability management, compliance initiatives, and wider security improvement projects across the business. This role would suit someone with 2-4 years' experience in a cybersecurity, SOC, or infrastructure security-focused position who enjoys working across a broad technology estate and keeping up to date with emerging threats and security technologies. Key Responsibilities: Monitor and develop SIEM and threat detection platforms Investigate and respond to security incidents and alerts Support vulnerability scanning, remediation, and reporting activities Assist with development of security policies, procedures, and controls Work alongside Infrastructure and Technical Services teams to improve security across the estate Support compliance activities aligned to ISO27001, GDPR, and NIST frameworks Conduct security awareness initiatives including phishing simulations and end-user training Maintain and improve endpoint protection, IDS/IPS, EDR, XDR, and MDR solutions Assist with backup, disaster recovery, and digital asset protection strategies Stay up to date with emerging cyber threats and recommend improvements where appropriate Key Skills & Experience: 2-4 years' experience within a cybersecurity or infrastructure security role Experience working with SIEM tools and vulnerability management platforms Strong understanding of EDR, XDR, MDR, IDS/IPS technologies Good knowledge of Microsoft security technologies and infrastructure environments Understanding of ISO27001, NIST, GDPR, and security best practices Experience investigating security incidents and producing clear documentation Full UK driving licence Desirable: CompTIA Security+ CISSP Associate Microsoft certifications Experience with Azure environments Scripting or automation knowledge Experience working with ERP systems This is a fantastic opportunity to join a business investing heavily in cybersecurity, where you will have the chance to influence security best practices, work with modern technologies, and continue developing your technical skillset within a collaborative environment. The Package: If successful our client is offering a salary of between 40,000/ 45,000 per annum, favorable holiday allowance, company contributed pension scheme and opportunities for professional development including training and advancement. This a hybrid working role 3 days on site and 2 days working from home. How to Apply: If you are interested in hearing more about this IT security analyst vacancy or interested in applying for the role please email me at or contact Principal IT Directly on LinkedIn. INDGH
Aug 18, 2026
Full time
IT Security Analyst - 40,000/ 45,000 per annum - Brandesburton (Hybrid) Principal IT are proud to be supporting a leading provider of modular buildings for various sectors, such as education, healthcare, defence, and justice. This is an excellent opportunity for someone with a passion for cybersecurity who is looking to play a key role in strengthening and developing an organisation's overall security posture and cyber resilience strategy. Working closely with the Infrastructure & Security Manager, you will be responsible for monitoring, detecting, investigating, and responding to security threats across the organisation's infrastructure and systems. You will also support vulnerability management, compliance initiatives, and wider security improvement projects across the business. This role would suit someone with 2-4 years' experience in a cybersecurity, SOC, or infrastructure security-focused position who enjoys working across a broad technology estate and keeping up to date with emerging threats and security technologies. Key Responsibilities: Monitor and develop SIEM and threat detection platforms Investigate and respond to security incidents and alerts Support vulnerability scanning, remediation, and reporting activities Assist with development of security policies, procedures, and controls Work alongside Infrastructure and Technical Services teams to improve security across the estate Support compliance activities aligned to ISO27001, GDPR, and NIST frameworks Conduct security awareness initiatives including phishing simulations and end-user training Maintain and improve endpoint protection, IDS/IPS, EDR, XDR, and MDR solutions Assist with backup, disaster recovery, and digital asset protection strategies Stay up to date with emerging cyber threats and recommend improvements where appropriate Key Skills & Experience: 2-4 years' experience within a cybersecurity or infrastructure security role Experience working with SIEM tools and vulnerability management platforms Strong understanding of EDR, XDR, MDR, IDS/IPS technologies Good knowledge of Microsoft security technologies and infrastructure environments Understanding of ISO27001, NIST, GDPR, and security best practices Experience investigating security incidents and producing clear documentation Full UK driving licence Desirable: CompTIA Security+ CISSP Associate Microsoft certifications Experience with Azure environments Scripting or automation knowledge Experience working with ERP systems This is a fantastic opportunity to join a business investing heavily in cybersecurity, where you will have the chance to influence security best practices, work with modern technologies, and continue developing your technical skillset within a collaborative environment. The Package: If successful our client is offering a salary of between 40,000/ 45,000 per annum, favorable holiday allowance, company contributed pension scheme and opportunities for professional development including training and advancement. This a hybrid working role 3 days on site and 2 days working from home. How to Apply: If you are interested in hearing more about this IT security analyst vacancy or interested in applying for the role please email me at or contact Principal IT Directly on LinkedIn. INDGH
Data Analyst - Cyber Security 45,000 - 50,000 + bonus and extensive benefits Full Time / Permanent West Midlands / Hybrid - 1 day a month in the office The Role and Company: I am looking for a driven Data Analyst / Cyber Security Analyst with a strong data analytics skill set to join a large nationally recognised brand head quartered in the West Midlands. As a Data Analyst within the Cyber Security team, you will play a key role collecting, analysing, and interpreting Cyber Security related data to identify vulnerabilities, threats and detect suspicious activity. You will support the wider team to deliver a comprehensive programme of security testing, including vulnerability scanning and security configuration reviews, ensuring weaknesses are identified early and accurately. Responsibilities: Analyse the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the business, and existing security controls. Collaborate with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner. Generate detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders. Experience required: Previous experience in a similar Data Analyst ideally within a Cyber Security team or environment or with a keen interested or degree in Cyber Security. Excellent analytical and investigative skills Previous experience with Power BI is preferred. Effective communication, critical thinking and problem-solving skills Must either hold SC clearance already or be eligible to obtain this if successful Please apply via the link or contact (url removed) for more information Modis International Ltd acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers in the UK. Modis Europe Ltd provide a variety of international solutions that connect clients to the best talent in the world. For all positions based in Switzerland, Modis Europe Ltd works with its licensed Swiss partner Accurity GmbH to ensure that candidate applications are handled in accordance with Swiss law. Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers. By applying for this role your details will be submitted to Modis International Ltd and/ or Modis Europe Ltd. Our Candidate Privacy Information Statement which explains how we will use your information is available on the Modis website.
Aug 18, 2026
Full time
Data Analyst - Cyber Security 45,000 - 50,000 + bonus and extensive benefits Full Time / Permanent West Midlands / Hybrid - 1 day a month in the office The Role and Company: I am looking for a driven Data Analyst / Cyber Security Analyst with a strong data analytics skill set to join a large nationally recognised brand head quartered in the West Midlands. As a Data Analyst within the Cyber Security team, you will play a key role collecting, analysing, and interpreting Cyber Security related data to identify vulnerabilities, threats and detect suspicious activity. You will support the wider team to deliver a comprehensive programme of security testing, including vulnerability scanning and security configuration reviews, ensuring weaknesses are identified early and accurately. Responsibilities: Analyse the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the business, and existing security controls. Collaborate with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner. Generate detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders. Experience required: Previous experience in a similar Data Analyst ideally within a Cyber Security team or environment or with a keen interested or degree in Cyber Security. Excellent analytical and investigative skills Previous experience with Power BI is preferred. Effective communication, critical thinking and problem-solving skills Must either hold SC clearance already or be eligible to obtain this if successful Please apply via the link or contact (url removed) for more information Modis International Ltd acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers in the UK. Modis Europe Ltd provide a variety of international solutions that connect clients to the best talent in the world. For all positions based in Switzerland, Modis Europe Ltd works with its licensed Swiss partner Accurity GmbH to ensure that candidate applications are handled in accordance with Swiss law. Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers. By applying for this role your details will be submitted to Modis International Ltd and/ or Modis Europe Ltd. Our Candidate Privacy Information Statement which explains how we will use your information is available on the Modis website.
Security Analyst - ISO27001, Cyber Essentials, Cysa+, Mimecast, Microsoft Defender One of our most ambitious and rapidly growing law firm clients are actively looking to take on a new Security Analyst (ISO27001, Cyber Essentials, Cysa+, Mimecast, Microsoft Defender) on a permanent basis. This role will work close with the Security Manager. The firm have grown by 300% in the last 5 years and have further plans to stimulate growth. This role will be best suited for someone with 2-3 years experience looking to bring knowledge and confidence to the team, to be considered for this Security Analyst (ISO27001, Cyber Essentials, Cysa+, Mimecast, Microsoft Defender) it's expected you have that alongside: Relevant Security qualifications (Cysa+ or others) Knowledge of best security frameworks and standards (ISO27001, Cyber Essentials etc.) Ideal but not required law firm experience Key Responsibilities Maintain the operational configuration of all in-place security solutions in line with established baselines. Monitor security tools and services to ensure they are operating effectively and appropriately. Review logs and reports from security tools, workstations, Servers and network devices, interpret activity, and help drive appropriate remediation actions. Support investigations into suspicious or problematic activity and assist with incident response as required. Contribute to vulnerability assessments, penetration testing activities and security audits. Provide support and guidance to end users and act as an escalation point for the Service Desk on security tools, best practice, and firm policies and procedures. Complete client and supplier security surveys as required, ensuring records and supporting documentation are kept accurate and up to date.
Aug 17, 2026
Full time
Security Analyst - ISO27001, Cyber Essentials, Cysa+, Mimecast, Microsoft Defender One of our most ambitious and rapidly growing law firm clients are actively looking to take on a new Security Analyst (ISO27001, Cyber Essentials, Cysa+, Mimecast, Microsoft Defender) on a permanent basis. This role will work close with the Security Manager. The firm have grown by 300% in the last 5 years and have further plans to stimulate growth. This role will be best suited for someone with 2-3 years experience looking to bring knowledge and confidence to the team, to be considered for this Security Analyst (ISO27001, Cyber Essentials, Cysa+, Mimecast, Microsoft Defender) it's expected you have that alongside: Relevant Security qualifications (Cysa+ or others) Knowledge of best security frameworks and standards (ISO27001, Cyber Essentials etc.) Ideal but not required law firm experience Key Responsibilities Maintain the operational configuration of all in-place security solutions in line with established baselines. Monitor security tools and services to ensure they are operating effectively and appropriately. Review logs and reports from security tools, workstations, Servers and network devices, interpret activity, and help drive appropriate remediation actions. Support investigations into suspicious or problematic activity and assist with incident response as required. Contribute to vulnerability assessments, penetration testing activities and security audits. Provide support and guidance to end users and act as an escalation point for the Service Desk on security tools, best practice, and firm policies and procedures. Complete client and supplier security surveys as required, ensuring records and supporting documentation are kept accurate and up to date.
SOC Automation Engineer As a SOC Automation Engineer, you will apply hands-on engineering expertise to design, build, and optimise automation workflows that improve the scalability and efficiency of SOC services. Working across SIEM, endpoint, and orchestration platforms (primarily Palo Alto XSOAR), you will reduce analyst workload, accelerate incident response, and enhance decision-making across customer environments. Key Responsibilities Automation Development - Design, build, and maintain scalable automation workflows across detection and response platforms. Integration & Orchestration - Deliver cross-platform automation enabling fast, reliable response actions. Lifecycle Management - Develop, deploy, and continuously optimise automation for performance, resilience, and coverage. Collaboration & Requirements Gathering - Work with SOC and engineering teams to identify automation opportunities. Documentation - Produce clear documentation to support delivery, troubleshooting, and continuous improvement. Automation Planning - Contribute to automation roadmaps, threat modelling, and use case development. Pre-Sales Support - Assist with demos, scoping, and proof-of-value activities where required. Core Duties Automation Design & Development Build and maintain workflows across SIEM, EDR, and SOAR platforms Develop reusable scripts, templates, and components Ensure solutions support secure, multi-tenant environments Integration & Response Automation Orchestrate containment, enrichment, and remediation actions Integrate with threat intelligence, cloud, vulnerability, and reporting tools Partner with analysts to map and automate response processes Lifecycle Management & Optimisation Manage automation from design through to optimisation Troubleshoot failures and refine logic Use post-incident insights to improve workflows Documentation & Standards Maintain clear documentation of workflows, dependencies, and error handling Ensure consistency and usability for wider teams Strategic Contribution Support use cases aligned to threat modelling and MITRE ATT&CK Contribute to automation playbooks and response strategies Stay current with tools, frameworks, and emerging threats Collaboration Embed automation into SOC workflows Share best practices and support team development Pre-Sales Support workshops, onboarding, and solution design where needed Stakeholder Collaboration SOC Analysts - Automate repeatable triage and response activities Platform & Detection Engineers - Integrate automation into tooling and detections Sales & Pre-Sales - Provide technical input for customer solutions Requirements 2+ years' experience in SOC, automation, or cloud security engineering Experience in managed services or multi-tenant environments Strong experience building automations across SIEM, SOAR, or EDR platforms Proficiency in scripting (e.g., Python, PowerShell) Experience working with APIs, webhooks, and authentication methods Knowledge of threat frameworks (e.g., MITRE ATT&CK) Understanding of cloud security, identity, and event-driven automation Strong communication and analytical skills Security clearance (NPPV and/or SC) may be required. Technical Knowledge Security orchestration and automation principles Scripting and integration patterns (APIs, webhooks) SOC detection and response workflows Threat intelligence integration and use case design Cloud and identity security concepts Multi-tenant automation design Certifications Essential: Hands-on experience with Palo Alto XSOAR Desirable: Palo Alto Networks Certified XSOAR Engineer Palo Alto Networks Certified Security Automation Engineer (PCSAE) Palo Alto Networks Security Operations Professional
Aug 15, 2026
Full time
SOC Automation Engineer As a SOC Automation Engineer, you will apply hands-on engineering expertise to design, build, and optimise automation workflows that improve the scalability and efficiency of SOC services. Working across SIEM, endpoint, and orchestration platforms (primarily Palo Alto XSOAR), you will reduce analyst workload, accelerate incident response, and enhance decision-making across customer environments. Key Responsibilities Automation Development - Design, build, and maintain scalable automation workflows across detection and response platforms. Integration & Orchestration - Deliver cross-platform automation enabling fast, reliable response actions. Lifecycle Management - Develop, deploy, and continuously optimise automation for performance, resilience, and coverage. Collaboration & Requirements Gathering - Work with SOC and engineering teams to identify automation opportunities. Documentation - Produce clear documentation to support delivery, troubleshooting, and continuous improvement. Automation Planning - Contribute to automation roadmaps, threat modelling, and use case development. Pre-Sales Support - Assist with demos, scoping, and proof-of-value activities where required. Core Duties Automation Design & Development Build and maintain workflows across SIEM, EDR, and SOAR platforms Develop reusable scripts, templates, and components Ensure solutions support secure, multi-tenant environments Integration & Response Automation Orchestrate containment, enrichment, and remediation actions Integrate with threat intelligence, cloud, vulnerability, and reporting tools Partner with analysts to map and automate response processes Lifecycle Management & Optimisation Manage automation from design through to optimisation Troubleshoot failures and refine logic Use post-incident insights to improve workflows Documentation & Standards Maintain clear documentation of workflows, dependencies, and error handling Ensure consistency and usability for wider teams Strategic Contribution Support use cases aligned to threat modelling and MITRE ATT&CK Contribute to automation playbooks and response strategies Stay current with tools, frameworks, and emerging threats Collaboration Embed automation into SOC workflows Share best practices and support team development Pre-Sales Support workshops, onboarding, and solution design where needed Stakeholder Collaboration SOC Analysts - Automate repeatable triage and response activities Platform & Detection Engineers - Integrate automation into tooling and detections Sales & Pre-Sales - Provide technical input for customer solutions Requirements 2+ years' experience in SOC, automation, or cloud security engineering Experience in managed services or multi-tenant environments Strong experience building automations across SIEM, SOAR, or EDR platforms Proficiency in scripting (e.g., Python, PowerShell) Experience working with APIs, webhooks, and authentication methods Knowledge of threat frameworks (e.g., MITRE ATT&CK) Understanding of cloud security, identity, and event-driven automation Strong communication and analytical skills Security clearance (NPPV and/or SC) may be required. Technical Knowledge Security orchestration and automation principles Scripting and integration patterns (APIs, webhooks) SOC detection and response workflows Threat intelligence integration and use case design Cloud and identity security concepts Multi-tenant automation design Certifications Essential: Hands-on experience with Palo Alto XSOAR Desirable: Palo Alto Networks Certified XSOAR Engineer Palo Alto Networks Certified Security Automation Engineer (PCSAE) Palo Alto Networks Security Operations Professional
This role has a starting salary of 55,486 per annum, for working 36 hours per week. We are excited to be recruiting a Senior Security Analyst to join our fantastic team based at Woodhatch Place in Reigate. We offer a hybrid working model with a minimum of two office days per week. Our Offer to You 26 days' holiday, rising to 28 days after 2 years' service and 31 days after 5 years' service (prorated for part time staff) Option to buy up to 10 days of additional annual leave A generous local government salary related pension Up to 5 days of carer's leave and 2 paid volunteering days per year Paternity, adoption and dependents leave An Employee Assistance Programme (EAP) to support health and wellbeing Learning and development hub where you can access a wealth of resources Wellbeing and lifestyle discounts including gym, travel, and shopping A chance to make a real difference to the lives of our residents. About The Role As a Senior Security Analyst, you will play a central role in strengthening Surrey County Council's cyber resilience. Your day-to-day work will include proactive security monitoring across our hybrid cloud and on premises environment, triaging and investigating alerts, and supporting coordinated incident response activities. You will operate our vulnerability management processes, translate threat intelligence into actionable defences, and contribute to the improvement of detection content and security controls. You will also work closely with IT colleagues and suppliers to address risks, gather evidence for audits, and prepare clear reporting on security posture and emerging trends. This role does not include direct line management responsibilities, but you will regularly provide specialist guidance, coaching, and support to colleagues across IT&D and partner teams. Over the next 12 to 18 months, you will contribute to several high impact initiatives including: Establishing a more mature, risk based vulnerability management lifecycle and reducing exposure windows across critical systems Enhancing incident response readiness through improved playbooks, scenario testing, and lessons learned processes Uplifting monitoring coverage and the effectiveness of SIEM/EDR/NDR tooling, including tuning and detection improvements Strengthening supplier assurance processes, especially for cloud and SaaS services Supporting the development of updated cyber security policies, standards and operating procedures This is a pivotal role for a motivated cyber professional who wants to make a measurable difference. You will directly influence Surrey County Council's operational security posture and help reduce risk across services that support residents, communities, and frontline operations. Your insights and expertise will shape decision making, improve control maturity, and contribute to a safer, more resilient public service environment. Your Application In order to be considered for shortlisting, your application will clearly evidence the following skills and align with our behaviours: Strong experience in cyber security operations, including alert triage, investigation, and incident response Demonstrable capability in vulnerability management and translating technical risk into meaningful actions Ability to analyse complex information and present clear, concise reports and recommendations Proven ability to work collaboratively with technical and non technical stakeholders Commitment to continuous professional development and staying current with emerging threats High-level proficiency with security tooling (SIEM, EDR, cloud security tools) and modern IT environments Alignment with our values of accountability, teamwork, and inclusive service delivery To apply, we request that you submit a CV and you will be asked the following 4 questions: Give an example of how you have helped build a positive security culture across teams. Describe a time when you led or contributed to triage, investigation, or response during a cyber security incident. What actions did you take, and what was the outcome? Give an example of when you identified a significant technical vulnerability or risk. How did you communicate it to stakeholders, and what actions were taken as a result? Tell us about a situation where you analysed complex security information or data and produced a report or recommendation. How did you ensure your findings were clear, concise, and actionable? Before submitting your application, we recommend you read the job description and our Life at Surrey handbook to get an insight into working at Surrey. An enhanced DBS 'Disclosure and Barring Service' check for regulated activity (formerly known as CRB) and the Children's and Adults' Barred List checks will be required for this role. The job advert closes at 23:59 on 14/08/2026, with interviews planned to follow shortly thereafter. We look forward to receiving your application, please click on the apply online button below to submit. Contact Us Please contact us for any questions relating to the role. This could be to discuss flexible working requests, transferable skills or any barriers to employment. For an informal discussion please contact Kamil Erkadoo via email at . Local Government Reorganisation (LGR) Surrey County Council is undergoing Local Government Reorganisation, moving from a two-tier system to two new unitary councils in April 2027. If you are employed by Surrey on 1st April 2027, your role will transfer with current terms and conditions to one of the new organisations, supporting local devolution and greater powers for our communities. Join our dynamic team and shape the future of local government. Make a lasting impact with innovative solutions and improved services for our community. Help us build a brighter future for our residents! Please see more information here: Information for applicants on Local Government Reorganisation - Surrey County Council Our Commitment We are a disability confident employer which means if you have shared a disability on your application form and have evidenced you meet the minimum shortlisting criteria, as displayed on the advert, we guarantee you an interview. Your skills and experience truly matter to us. From application to your first day, we're committed to supporting you with any adjustments you need, we value inclusion and warmly welcome you to join and help build a workplace where everyone belongs.
Aug 15, 2026
Full time
This role has a starting salary of 55,486 per annum, for working 36 hours per week. We are excited to be recruiting a Senior Security Analyst to join our fantastic team based at Woodhatch Place in Reigate. We offer a hybrid working model with a minimum of two office days per week. Our Offer to You 26 days' holiday, rising to 28 days after 2 years' service and 31 days after 5 years' service (prorated for part time staff) Option to buy up to 10 days of additional annual leave A generous local government salary related pension Up to 5 days of carer's leave and 2 paid volunteering days per year Paternity, adoption and dependents leave An Employee Assistance Programme (EAP) to support health and wellbeing Learning and development hub where you can access a wealth of resources Wellbeing and lifestyle discounts including gym, travel, and shopping A chance to make a real difference to the lives of our residents. About The Role As a Senior Security Analyst, you will play a central role in strengthening Surrey County Council's cyber resilience. Your day-to-day work will include proactive security monitoring across our hybrid cloud and on premises environment, triaging and investigating alerts, and supporting coordinated incident response activities. You will operate our vulnerability management processes, translate threat intelligence into actionable defences, and contribute to the improvement of detection content and security controls. You will also work closely with IT colleagues and suppliers to address risks, gather evidence for audits, and prepare clear reporting on security posture and emerging trends. This role does not include direct line management responsibilities, but you will regularly provide specialist guidance, coaching, and support to colleagues across IT&D and partner teams. Over the next 12 to 18 months, you will contribute to several high impact initiatives including: Establishing a more mature, risk based vulnerability management lifecycle and reducing exposure windows across critical systems Enhancing incident response readiness through improved playbooks, scenario testing, and lessons learned processes Uplifting monitoring coverage and the effectiveness of SIEM/EDR/NDR tooling, including tuning and detection improvements Strengthening supplier assurance processes, especially for cloud and SaaS services Supporting the development of updated cyber security policies, standards and operating procedures This is a pivotal role for a motivated cyber professional who wants to make a measurable difference. You will directly influence Surrey County Council's operational security posture and help reduce risk across services that support residents, communities, and frontline operations. Your insights and expertise will shape decision making, improve control maturity, and contribute to a safer, more resilient public service environment. Your Application In order to be considered for shortlisting, your application will clearly evidence the following skills and align with our behaviours: Strong experience in cyber security operations, including alert triage, investigation, and incident response Demonstrable capability in vulnerability management and translating technical risk into meaningful actions Ability to analyse complex information and present clear, concise reports and recommendations Proven ability to work collaboratively with technical and non technical stakeholders Commitment to continuous professional development and staying current with emerging threats High-level proficiency with security tooling (SIEM, EDR, cloud security tools) and modern IT environments Alignment with our values of accountability, teamwork, and inclusive service delivery To apply, we request that you submit a CV and you will be asked the following 4 questions: Give an example of how you have helped build a positive security culture across teams. Describe a time when you led or contributed to triage, investigation, or response during a cyber security incident. What actions did you take, and what was the outcome? Give an example of when you identified a significant technical vulnerability or risk. How did you communicate it to stakeholders, and what actions were taken as a result? Tell us about a situation where you analysed complex security information or data and produced a report or recommendation. How did you ensure your findings were clear, concise, and actionable? Before submitting your application, we recommend you read the job description and our Life at Surrey handbook to get an insight into working at Surrey. An enhanced DBS 'Disclosure and Barring Service' check for regulated activity (formerly known as CRB) and the Children's and Adults' Barred List checks will be required for this role. The job advert closes at 23:59 on 14/08/2026, with interviews planned to follow shortly thereafter. We look forward to receiving your application, please click on the apply online button below to submit. Contact Us Please contact us for any questions relating to the role. This could be to discuss flexible working requests, transferable skills or any barriers to employment. For an informal discussion please contact Kamil Erkadoo via email at . Local Government Reorganisation (LGR) Surrey County Council is undergoing Local Government Reorganisation, moving from a two-tier system to two new unitary councils in April 2027. If you are employed by Surrey on 1st April 2027, your role will transfer with current terms and conditions to one of the new organisations, supporting local devolution and greater powers for our communities. Join our dynamic team and shape the future of local government. Make a lasting impact with innovative solutions and improved services for our community. Help us build a brighter future for our residents! Please see more information here: Information for applicants on Local Government Reorganisation - Surrey County Council Our Commitment We are a disability confident employer which means if you have shared a disability on your application form and have evidenced you meet the minimum shortlisting criteria, as displayed on the advert, we guarantee you an interview. Your skills and experience truly matter to us. From application to your first day, we're committed to supporting you with any adjustments you need, we value inclusion and warmly welcome you to join and help build a workplace where everyone belongs.
Senior Security Analyst Permanent - Up to 61k + strong benefits Location: Hybrid - Surrey Your new organisation I am recruiting for a Senior Security Analyst to join a well-established organisation undergoing continued investment in its cyber security capabilities and digital services. This role reports directly to the CISO and sits within a growing security function responsible for protecting a complex hybrid environment spanning on-premises infrastructure, cloud platforms and supplier-managed services. This is an excellent opportunity for an experienced cyber security professional who enjoys a blend of security operations, incident response, vulnerability management, security assurance and stakeholder engagement. You will play a key role in improving security controls, reducing organisational risk and enhancing cyber resilience across the business. The role responsibilities As a Senior Security Analyst, you will provide a proactive and consistent cyber security operations and assurance capability across the organisation. You will provide day-to-day security monitoring activities, support incident response processes, manage vulnerability remediation, and contribute to the ongoing development of security controls, policies and procedures. You will need Strong experience in cyber security operations, security monitoring and incident response. Good understanding of SIEM, EDR and network monitoring technologies. Experience investigating security incidents across cloud, endpoint and network environments. Knowledge of vulnerability management processes and remediation tracking. Understanding of modern cyber threats, attack techniques and security controls. Ability to analyse security data and present findings to both technical and non-technical audiences. Strong documentation, reporting and stakeholder management skills. Excellent written and verbal communication skills. Ability to collaborate effectively with internal teams, suppliers and senior stakeholders. 1 or more of SC-200, CySA+, Security+, GCIH or GMON, CISSP What you'll get in return Strong salary of between 55k and 61k. Flexible hybrid working arrangements. More remote than not, initially once a week on site, which will likely reduce in time. Strong pension and benefits package. Ongoing professional development and certification support. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Aug 15, 2026
Full time
Senior Security Analyst Permanent - Up to 61k + strong benefits Location: Hybrid - Surrey Your new organisation I am recruiting for a Senior Security Analyst to join a well-established organisation undergoing continued investment in its cyber security capabilities and digital services. This role reports directly to the CISO and sits within a growing security function responsible for protecting a complex hybrid environment spanning on-premises infrastructure, cloud platforms and supplier-managed services. This is an excellent opportunity for an experienced cyber security professional who enjoys a blend of security operations, incident response, vulnerability management, security assurance and stakeholder engagement. You will play a key role in improving security controls, reducing organisational risk and enhancing cyber resilience across the business. The role responsibilities As a Senior Security Analyst, you will provide a proactive and consistent cyber security operations and assurance capability across the organisation. You will provide day-to-day security monitoring activities, support incident response processes, manage vulnerability remediation, and contribute to the ongoing development of security controls, policies and procedures. You will need Strong experience in cyber security operations, security monitoring and incident response. Good understanding of SIEM, EDR and network monitoring technologies. Experience investigating security incidents across cloud, endpoint and network environments. Knowledge of vulnerability management processes and remediation tracking. Understanding of modern cyber threats, attack techniques and security controls. Ability to analyse security data and present findings to both technical and non-technical audiences. Strong documentation, reporting and stakeholder management skills. Excellent written and verbal communication skills. Ability to collaborate effectively with internal teams, suppliers and senior stakeholders. 1 or more of SC-200, CySA+, Security+, GCIH or GMON, CISSP What you'll get in return Strong salary of between 55k and 61k. Flexible hybrid working arrangements. More remote than not, initially once a week on site, which will likely reduce in time. Strong pension and benefits package. Ongoing professional development and certification support. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Vulnerability Analyst 45,000 - 50,000 + bonus and extensive benefits Full Time / Permanent West Midlands / Hybrid - 1 day a week in the office ideally The Role and Company: I am looking for a driven Vulnerability Analyst to join a large nationally recognised brand head quartered in the West Midlands. As a Vulnerability Analyst you will play a key role in proactively testing, assessing and challenging the resilience of technology and operational environments. The Vulnerability Analyst helps to deliver a comprehensive programme of security testing, including vulnerability scanning and security configuration reviews, ensuring weaknesses are identified early and accurately. We are ideally looking for someone Midlands based who can be on site in Warwickshire 1 day a week on average. Responsibilities: Conducting regular vulnerability assessments using automated scanning tools, manual testing techniques, and security best practices to identify vulnerabilities in systems, networks, and applications Managing the lifecycle of vulnerabilities from discovery to remediation, including vulnerability triage, prioritisation, tracking, and reporting Analysing the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the organisation, and existing security controls Collaborating with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner Working closely with IT teams to ensure that security patches and updates are applied promptly to mitigate known vulnerabilities and reduce the organisation's exposure to security risks Generating detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders Providing guidance and training to employees on best practices for identifying and reporting security vulnerabilities, promoting a culture of security awareness within the organisation Experience required: Previous experience in a similar Vulnerability Management role preferably with experience in Operational Technology (OT) Skilled in cyber security, physical security, and risk management principles Excellent analytical and investigative skills Strong knowledge of the hardware and software systems in use across both IT and OT domains and the architectural arrangements in place to support management and operation of systems Ability to adapt to evolving threat landscapes Effective communication, critical thinking and problem-solving skills Must either hold SC clearance already or be eligible to obtain this if successful Please apply via the link or contact (url removed) for more information Modis International Ltd acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers in the UK. Modis Europe Ltd provide a variety of international solutions that connect clients to the best talent in the world. For all positions based in Switzerland, Modis Europe Ltd works with its licensed Swiss partner Accurity GmbH to ensure that candidate applications are handled in accordance with Swiss law. Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers. By applying for this role your details will be submitted to Modis International Ltd and/ or Modis Europe Ltd. Our Candidate Privacy Information Statement which explains how we will use your information is available on the Modis website.
Aug 14, 2026
Full time
Vulnerability Analyst 45,000 - 50,000 + bonus and extensive benefits Full Time / Permanent West Midlands / Hybrid - 1 day a week in the office ideally The Role and Company: I am looking for a driven Vulnerability Analyst to join a large nationally recognised brand head quartered in the West Midlands. As a Vulnerability Analyst you will play a key role in proactively testing, assessing and challenging the resilience of technology and operational environments. The Vulnerability Analyst helps to deliver a comprehensive programme of security testing, including vulnerability scanning and security configuration reviews, ensuring weaknesses are identified early and accurately. We are ideally looking for someone Midlands based who can be on site in Warwickshire 1 day a week on average. Responsibilities: Conducting regular vulnerability assessments using automated scanning tools, manual testing techniques, and security best practices to identify vulnerabilities in systems, networks, and applications Managing the lifecycle of vulnerabilities from discovery to remediation, including vulnerability triage, prioritisation, tracking, and reporting Analysing the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the organisation, and existing security controls Collaborating with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner Working closely with IT teams to ensure that security patches and updates are applied promptly to mitigate known vulnerabilities and reduce the organisation's exposure to security risks Generating detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders Providing guidance and training to employees on best practices for identifying and reporting security vulnerabilities, promoting a culture of security awareness within the organisation Experience required: Previous experience in a similar Vulnerability Management role preferably with experience in Operational Technology (OT) Skilled in cyber security, physical security, and risk management principles Excellent analytical and investigative skills Strong knowledge of the hardware and software systems in use across both IT and OT domains and the architectural arrangements in place to support management and operation of systems Ability to adapt to evolving threat landscapes Effective communication, critical thinking and problem-solving skills Must either hold SC clearance already or be eligible to obtain this if successful Please apply via the link or contact (url removed) for more information Modis International Ltd acts as an employment agency for permanent recruitment and an employment business for the supply of temporary workers in the UK. Modis Europe Ltd provide a variety of international solutions that connect clients to the best talent in the world. For all positions based in Switzerland, Modis Europe Ltd works with its licensed Swiss partner Accurity GmbH to ensure that candidate applications are handled in accordance with Swiss law. Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers. By applying for this role your details will be submitted to Modis International Ltd and/ or Modis Europe Ltd. Our Candidate Privacy Information Statement which explains how we will use your information is available on the Modis website.
Information Security Lead / Cyber Security Lead Hybrid 60,000 - 70,000 + Excellent Benefits Immediate Start Avvailable Infrastructure Security Network Security Cyber Security ISO 27001 Are you an experienced Infrastructure, Network or Cyber Security professional looking to take the next step in your career? We're looking for a technically strong Information Security Lead to join a growing technology business, taking ownership of information security, governance and compliance while remaining closely involved with infrastructure and cyber security. This is an ideal opportunity for someone who has progressed through Infrastructure Engineering, Network Security, Cyber Security Engineering or Technical Security and is ready to move into a broader Information Security leadership role. Working closely with Infrastructure, IT Operations, Engineering and senior stakeholders, you'll help shape the organisation's security posture, ensuring security is embedded across networks, cloud platforms, servers and business systems. You'll combine hands-on technical knowledge with information security governance, helping drive continual improvement across the Information Security Management System (ISMS), security controls and compliance activities. You'll lead security risk assessments, coordinate vulnerability management and remediation programmes, support penetration testing, oversee supplier security assurance, manage information security incidents and contribute to Business Continuity and Disaster Recovery planning. You'll also play a key role in maintaining ISO 27001 certification, supporting customer audits and promoting a strong security culture throughout the organisation. We're looking for someone with a solid technical background who understands how infrastructure is designed, secured and supported. Experience working with technologies such as network security, firewalls, Windows Server, Active Directory, Microsoft 365, Azure, endpoint security, identity and access management (IAM), vulnerability management, patch management and infrastructure hardening will be highly beneficial. Alongside your technical expertise, you'll have exposure to ISO 27001, information security frameworks, security audits, governance, risk management and compliance. Experience working with Cyber Essentials, supplier assurance, security policies and incident response would also be advantageous. Whether you're currently a Senior Information Security Analyst, Senior Cyber Security Analyst, Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead or Information Security Lead, we'd love to hear from you. This is an opportunity to step into a highly visible role where you'll influence security strategy, work with modern technologies and help shape the future direction of information security within the organisation, while continuing to build on your technical expertise. Key Skills: Information Security Lead, Senior Information Security Analyst, Senior Cyber Security Analyst, Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead, Infrastructure Security, Network Security, Cyber Security, Information Security, ISO 27001, ISMS, Azure Security, Microsoft 365 Security, Active Directory, Firewalls, Vulnerability Management, Patch Management, Endpoint Security, IAM, Security Assurance, Governance, Risk & Compliance, Security Audits, Business Continuity, Disaster Recovery, Incident Response, Cyber Essentials.
Aug 14, 2026
Full time
Information Security Lead / Cyber Security Lead Hybrid 60,000 - 70,000 + Excellent Benefits Immediate Start Avvailable Infrastructure Security Network Security Cyber Security ISO 27001 Are you an experienced Infrastructure, Network or Cyber Security professional looking to take the next step in your career? We're looking for a technically strong Information Security Lead to join a growing technology business, taking ownership of information security, governance and compliance while remaining closely involved with infrastructure and cyber security. This is an ideal opportunity for someone who has progressed through Infrastructure Engineering, Network Security, Cyber Security Engineering or Technical Security and is ready to move into a broader Information Security leadership role. Working closely with Infrastructure, IT Operations, Engineering and senior stakeholders, you'll help shape the organisation's security posture, ensuring security is embedded across networks, cloud platforms, servers and business systems. You'll combine hands-on technical knowledge with information security governance, helping drive continual improvement across the Information Security Management System (ISMS), security controls and compliance activities. You'll lead security risk assessments, coordinate vulnerability management and remediation programmes, support penetration testing, oversee supplier security assurance, manage information security incidents and contribute to Business Continuity and Disaster Recovery planning. You'll also play a key role in maintaining ISO 27001 certification, supporting customer audits and promoting a strong security culture throughout the organisation. We're looking for someone with a solid technical background who understands how infrastructure is designed, secured and supported. Experience working with technologies such as network security, firewalls, Windows Server, Active Directory, Microsoft 365, Azure, endpoint security, identity and access management (IAM), vulnerability management, patch management and infrastructure hardening will be highly beneficial. Alongside your technical expertise, you'll have exposure to ISO 27001, information security frameworks, security audits, governance, risk management and compliance. Experience working with Cyber Essentials, supplier assurance, security policies and incident response would also be advantageous. Whether you're currently a Senior Information Security Analyst, Senior Cyber Security Analyst, Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead or Information Security Lead, we'd love to hear from you. This is an opportunity to step into a highly visible role where you'll influence security strategy, work with modern technologies and help shape the future direction of information security within the organisation, while continuing to build on your technical expertise. Key Skills: Information Security Lead, Senior Information Security Analyst, Senior Cyber Security Analyst, Security Engineer, Infrastructure Security Engineer, Network Security Engineer, Technical Security Lead, Infrastructure Security, Network Security, Cyber Security, Information Security, ISO 27001, ISMS, Azure Security, Microsoft 365 Security, Active Directory, Firewalls, Vulnerability Management, Patch Management, Endpoint Security, IAM, Security Assurance, Governance, Risk & Compliance, Security Audits, Business Continuity, Disaster Recovery, Incident Response, Cyber Essentials.
Job Title: SOC Manager Location: Remote (with occasional business travel) Duration: 6 Months The Role We are seeking an experienced SOC Manager for a 6-month contract. This is a strategic leadership position-not a hands-on technical analyst role. You will take full ownership of the Cyber Security Operations Centre (CSOC), driving strategy, managing incident response, and directing internal teams and external vendors. Key Responsibilities Define and lead the CSOC strategy, operations, and governance. Take command of major incident response, managing remediation and stakeholder communication. Oversee threat intelligence, vulnerability management, and security monitoring capabilities. Manage relationships with external agencies, Managed Security Service Providers (MSSPs), and technology partners. What We Need From You Proven experience as a SOC Manager (previous leadership experience is essential; this is not an entry-level management role). Deep expertise in incident management processes and live crisis response. Strong background in managing third-party vendors (MSSPs). Strategic mindset to plan security investments, tooling, and resourcing. Desirable: CISSP/CISM, Cloud Security (AWS/Azure), ITIL. How to Apply: Please submit your most up-to-date CV to (url removed) to be considered for this critical leadership role. Randstad Technologies is acting as an Employment Business in relation to this vacancy.
Aug 14, 2026
Contractor
Job Title: SOC Manager Location: Remote (with occasional business travel) Duration: 6 Months The Role We are seeking an experienced SOC Manager for a 6-month contract. This is a strategic leadership position-not a hands-on technical analyst role. You will take full ownership of the Cyber Security Operations Centre (CSOC), driving strategy, managing incident response, and directing internal teams and external vendors. Key Responsibilities Define and lead the CSOC strategy, operations, and governance. Take command of major incident response, managing remediation and stakeholder communication. Oversee threat intelligence, vulnerability management, and security monitoring capabilities. Manage relationships with external agencies, Managed Security Service Providers (MSSPs), and technology partners. What We Need From You Proven experience as a SOC Manager (previous leadership experience is essential; this is not an entry-level management role). Deep expertise in incident management processes and live crisis response. Strong background in managing third-party vendors (MSSPs). Strategic mindset to plan security investments, tooling, and resourcing. Desirable: CISSP/CISM, Cloud Security (AWS/Azure), ITIL. How to Apply: Please submit your most up-to-date CV to (url removed) to be considered for this critical leadership role. Randstad Technologies is acting as an Employment Business in relation to this vacancy.
Senior Security Engineering Team Lead Leeds (Home with 1 HQ visit per quarter) Up to 82,500 (NEG) + Excellent Benefits Are you an experienced Security Engineer ready to lead from the front? We're supporting a leading international managed technology organisation in the search for a Senior Security Engineering Team Lead to head a dedicated cyber security engineering function supporting a major enterprise customer operating within a highly regulated environment. This is far more than a traditional management role. You'll remain hands-on, acting as the technical authority for Microsoft security technologies whilst leading a team of experienced Security Analysts and Engineers responsible for protecting a critical customer environment. If you're passionate about Microsoft security, detection engineering, automation and mentoring technical teams, this is an opportunity to influence the direction of an enterprise-scale security operation. The Opportunity As the technical lead for the Security Engineering function, you'll own the security platform estate, providing architectural guidance, driving continuous improvement and acting as the primary escalation point for complex cyber security incidents. You'll combine strategic leadership with hands-on engineering, working closely with Security Analysts, Infrastructure teams and customer stakeholders to ensure security platforms remain resilient, effective and continually evolving. This is an excellent opportunity to join an organisation that invests heavily in technology, professional development and long-term career progression whilst working with some of the latest Microsoft security technologies. Key Responsibilities Lead and develop a team of Security Engineers and Security Analysts Act as the senior technical escalation point for complex cyber security incidents Own the configuration, maintenance and optimisation of the Microsoft security platform Drive detection engineering, rule tuning and continuous platform improvement Lead SIEM and SOAR engineering activities, including automation and Logic Apps Oversee log ingestion, telemetry quality and detection coverage Support vulnerability management and exposure management tooling Work closely with customers and internal technical teams on security architecture and platform improvements Mentor engineers and analysts, helping raise technical capability across the team Contribute to platform roadmaps, governance, documentation and service improvements Technology Environment You'll work across a modern Microsoft-centric cyber security stack including: Microsoft Defender XDR Defender for Endpoint Defender for Identity Microsoft Sentinel Logic Apps SOAR Automation Microsoft Purview Qualys XM Cyber CyberArk Detection Engineering KQL Threat Hunting Platform Engineering About You We're looking for someone who combines deep technical expertise with natural leadership skills. You'll likely have experience in areas such as: Security Engineering Detection Engineering SOC Engineering Microsoft Security Security Platform Management Cyber Security Architecture Security Automation Team Leadership You'll also possess: Expert knowledge of Microsoft Defender technologies Strong Microsoft Sentinel experience Experience building or improving security detections Knowledge of SOAR and security automation Experience within regulated or enterprise environments Excellent stakeholder management and communication skills Previous leadership or mentoring experience Why Apply? This organisation is recognised as one of the world's leading managed technology providers, delivering cloud, cyber security, data and digital workplace solutions to thousands of enterprise customers across multiple countries. It combines the scale of an international business with a culture that genuinely invests in its people through continuous learning, technical certifications, structured development programmes and internal career progression. You'll be joining at an exciting stage of growth, leading a newly established security capability supporting a strategic customer where you'll have genuine influence over both the technology roadmap and the development of your team. Package Salary up to 82,500 (NEG) Home working with one visit to HQ per quarter Excellent benefits package Significant investment in training and certifications Career progression opportunities Opportunity to work with enterprise Microsoft security technologies Technical leadership role with genuine strategic influence
Aug 14, 2026
Full time
Senior Security Engineering Team Lead Leeds (Home with 1 HQ visit per quarter) Up to 82,500 (NEG) + Excellent Benefits Are you an experienced Security Engineer ready to lead from the front? We're supporting a leading international managed technology organisation in the search for a Senior Security Engineering Team Lead to head a dedicated cyber security engineering function supporting a major enterprise customer operating within a highly regulated environment. This is far more than a traditional management role. You'll remain hands-on, acting as the technical authority for Microsoft security technologies whilst leading a team of experienced Security Analysts and Engineers responsible for protecting a critical customer environment. If you're passionate about Microsoft security, detection engineering, automation and mentoring technical teams, this is an opportunity to influence the direction of an enterprise-scale security operation. The Opportunity As the technical lead for the Security Engineering function, you'll own the security platform estate, providing architectural guidance, driving continuous improvement and acting as the primary escalation point for complex cyber security incidents. You'll combine strategic leadership with hands-on engineering, working closely with Security Analysts, Infrastructure teams and customer stakeholders to ensure security platforms remain resilient, effective and continually evolving. This is an excellent opportunity to join an organisation that invests heavily in technology, professional development and long-term career progression whilst working with some of the latest Microsoft security technologies. Key Responsibilities Lead and develop a team of Security Engineers and Security Analysts Act as the senior technical escalation point for complex cyber security incidents Own the configuration, maintenance and optimisation of the Microsoft security platform Drive detection engineering, rule tuning and continuous platform improvement Lead SIEM and SOAR engineering activities, including automation and Logic Apps Oversee log ingestion, telemetry quality and detection coverage Support vulnerability management and exposure management tooling Work closely with customers and internal technical teams on security architecture and platform improvements Mentor engineers and analysts, helping raise technical capability across the team Contribute to platform roadmaps, governance, documentation and service improvements Technology Environment You'll work across a modern Microsoft-centric cyber security stack including: Microsoft Defender XDR Defender for Endpoint Defender for Identity Microsoft Sentinel Logic Apps SOAR Automation Microsoft Purview Qualys XM Cyber CyberArk Detection Engineering KQL Threat Hunting Platform Engineering About You We're looking for someone who combines deep technical expertise with natural leadership skills. You'll likely have experience in areas such as: Security Engineering Detection Engineering SOC Engineering Microsoft Security Security Platform Management Cyber Security Architecture Security Automation Team Leadership You'll also possess: Expert knowledge of Microsoft Defender technologies Strong Microsoft Sentinel experience Experience building or improving security detections Knowledge of SOAR and security automation Experience within regulated or enterprise environments Excellent stakeholder management and communication skills Previous leadership or mentoring experience Why Apply? This organisation is recognised as one of the world's leading managed technology providers, delivering cloud, cyber security, data and digital workplace solutions to thousands of enterprise customers across multiple countries. It combines the scale of an international business with a culture that genuinely invests in its people through continuous learning, technical certifications, structured development programmes and internal career progression. You'll be joining at an exciting stage of growth, leading a newly established security capability supporting a strategic customer where you'll have genuine influence over both the technology roadmap and the development of your team. Package Salary up to 82,500 (NEG) Home working with one visit to HQ per quarter Excellent benefits package Significant investment in training and certifications Career progression opportunities Opportunity to work with enterprise Microsoft security technologies Technical leadership role with genuine strategic influence
Role: Cyber Security Lead Location: Nottinghamshire Working Arrangement: 3 days a week in office Salary: Up to 70k Are you an experienced SOC professional who's ready to take the next step into leadership without leaving the technical work behind? We're looking for a Cyber Security Operations Manager to lead our in-house Security Operations capability while remaining deeply involved in the day-to-day technical aspects of detection, response and continuous improvement. This role is ideal for someone moving from a Senior SOC Analyst, Senior Security Engineer or SOC Team Lead position who wants to develop their leadership skills while staying hands-on. You'll spend around 80% of your time working on technical security operations and 20% leading and developing the team, making this an excellent opportunity for someone looking for their first management role. What you'll be doing Leading and mentoring a small SOC team while remaining an active technical contributor. Investigating and responding to security incidents across enterprise, cloud and operational technology environments. Improving detection capabilities, automation and SOC processes to stay ahead of emerging threats. Working closely with vulnerability management, incident response and governance teams to strengthen the organisation's security posture. Taking part in the on-call rota and providing technical leadership during security incidents. What we're looking for You'll likely have experience in a senior SOC or security operations role and be ready to take the next step into people leadership. You'll bring: Strong experience with security monitoring, threat detection and incident response. Hands-on knowledge of SIEM, SOAR and security tooling. A passion for improving detection capabilities and automating security operations. The confidence to mentor others and influence technical decisions. Excellent communication skills and the ability to collaborate across technical teams. Professional certifications such as CISSP, CISM, GCIH, GCIA, GSEC or cloud security certifications are welcome but not essential. Why join us? This is an opportunity to shape the future of an evolving Security Operations function within a large, complex technology environment. You'll have the autonomy to improve processes, introduce new ideas and develop your leadership career while remaining close to the technology you enjoy. If you're looking for a role that combines technical depth with your first step into management, we'd love to hear from you. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Aug 13, 2026
Full time
Role: Cyber Security Lead Location: Nottinghamshire Working Arrangement: 3 days a week in office Salary: Up to 70k Are you an experienced SOC professional who's ready to take the next step into leadership without leaving the technical work behind? We're looking for a Cyber Security Operations Manager to lead our in-house Security Operations capability while remaining deeply involved in the day-to-day technical aspects of detection, response and continuous improvement. This role is ideal for someone moving from a Senior SOC Analyst, Senior Security Engineer or SOC Team Lead position who wants to develop their leadership skills while staying hands-on. You'll spend around 80% of your time working on technical security operations and 20% leading and developing the team, making this an excellent opportunity for someone looking for their first management role. What you'll be doing Leading and mentoring a small SOC team while remaining an active technical contributor. Investigating and responding to security incidents across enterprise, cloud and operational technology environments. Improving detection capabilities, automation and SOC processes to stay ahead of emerging threats. Working closely with vulnerability management, incident response and governance teams to strengthen the organisation's security posture. Taking part in the on-call rota and providing technical leadership during security incidents. What we're looking for You'll likely have experience in a senior SOC or security operations role and be ready to take the next step into people leadership. You'll bring: Strong experience with security monitoring, threat detection and incident response. Hands-on knowledge of SIEM, SOAR and security tooling. A passion for improving detection capabilities and automating security operations. The confidence to mentor others and influence technical decisions. Excellent communication skills and the ability to collaborate across technical teams. Professional certifications such as CISSP, CISM, GCIH, GCIA, GSEC or cloud security certifications are welcome but not essential. Why join us? This is an opportunity to shape the future of an evolving Security Operations function within a large, complex technology environment. You'll have the autonomy to improve processes, introduce new ideas and develop your leadership career while remaining close to the technology you enjoy. If you're looking for a role that combines technical depth with your first step into management, we'd love to hear from you. We welcome diverse applicants and are dedicated to treating all applicants with dignity and respect, regardless of background.
Senior SOC Engineer - Hybrid Join a leading cyber security services organisation as a Senior SOC Engineer , taking ownership of the technology, automation, and engineering capabilities that support a modern Security Operations Centre (SOC). The Role You'll design, deploy, and enhance core SOC platforms including SIEM, XDR, SOAR, automation, and security tooling , driving improvements in threat detection, response, and operational efficiency. Working closely with operational teams, you'll support customer onboarding, develop automated workflows, and help shape the future direction of SOC engineering. Key Responsibilities Design, deploy and optimise SIEM, XDR and SOAR platforms. Build security automation, integrations, and response workflows. Develop log parsing, data normalisation and telemetry solutions. Lead technical onboarding and implementation projects. Act as an escalation point for complex security engineering issues. Mentor SOC analysts and engineers. Improve detection, response and operational processes through automation. Maintain engineering documentation, standards and best practices. Skills & Experience 3-5+ years' experience within a SOC or cyber security engineering environment. Strong experience with SIEM, SOAR and EDR/XDR technologies. Scripting and automation expertise (Python, Go, APIs). Experience with cloud platforms such as Azure, AWS or GCP. Knowledge of vulnerability management and threat intelligence integrations. Strong communication, analytical and problem-solving skills. Eligibility for UK security clearance desirable. What's on Offer 2 Days in the Office Per Month Exposure to a wide range of security environments and technologies. Opportunity to influence SOC strategy and engineering direction. Dedicated training, development, and lab environments. Competitive salary and comprehensive benefits package. Ideal for an experienced SOC Engineer looking to step into a senior, technically focused role with significant ownership, automation responsibilities, and career progression opportunities.
Aug 13, 2026
Full time
Senior SOC Engineer - Hybrid Join a leading cyber security services organisation as a Senior SOC Engineer , taking ownership of the technology, automation, and engineering capabilities that support a modern Security Operations Centre (SOC). The Role You'll design, deploy, and enhance core SOC platforms including SIEM, XDR, SOAR, automation, and security tooling , driving improvements in threat detection, response, and operational efficiency. Working closely with operational teams, you'll support customer onboarding, develop automated workflows, and help shape the future direction of SOC engineering. Key Responsibilities Design, deploy and optimise SIEM, XDR and SOAR platforms. Build security automation, integrations, and response workflows. Develop log parsing, data normalisation and telemetry solutions. Lead technical onboarding and implementation projects. Act as an escalation point for complex security engineering issues. Mentor SOC analysts and engineers. Improve detection, response and operational processes through automation. Maintain engineering documentation, standards and best practices. Skills & Experience 3-5+ years' experience within a SOC or cyber security engineering environment. Strong experience with SIEM, SOAR and EDR/XDR technologies. Scripting and automation expertise (Python, Go, APIs). Experience with cloud platforms such as Azure, AWS or GCP. Knowledge of vulnerability management and threat intelligence integrations. Strong communication, analytical and problem-solving skills. Eligibility for UK security clearance desirable. What's on Offer 2 Days in the Office Per Month Exposure to a wide range of security environments and technologies. Opportunity to influence SOC strategy and engineering direction. Dedicated training, development, and lab environments. Competitive salary and comprehensive benefits package. Ideal for an experienced SOC Engineer looking to step into a senior, technically focused role with significant ownership, automation responsibilities, and career progression opportunities.
Information Vulnerability Analyst - Staffordshire Our client is looking for an Information Vulnerability Analyst to join their growing Information Security team. This is a key role focused on identifying, assessing, and mitigating security vulnerabilities across IT, OT, cloud, and SaaS environments. You will work closely with infrastructure, applications, and operations teams to ensure that risks are effectively managed and remediated. This position is ideal for someone who is proactive rather than reactive someone who enjoys identifying vulnerabilities before they become issues and takes ownership of driving them through to resolution. We are looking for a hands-on individual who thrives in a collaborative environment. You will work closely with service desk, networking, and infrastructure teams, influencing stakeholders and ensuring a joined-up approach to vulnerability management across the organisation. Key Responsibilities Manage the global vulnerability management process and associated platforms Perform regular vulnerability scans across IT, OT, and SaaS environments using industry-standard tools Coordinate and manage third-party security penetration testing across internal and external systems Analyse scan results, prioritise vulnerabilities, and drive remediation through to completion Maintain and enhance vulnerability management processes and reporting frameworks Contribute to the risk register and support ongoing security improvements Track remediation progress and report on risk posture to senior stakeholders Work closely with IT and engineering teams to ensure secure configurations and effective patch management Identify root causes of vulnerabilities and support long-term solutions Support compliance with frameworks such as NIST and Cyber Essentials Assist with threat modelling and risk assessments Maintain documentation, procedures, and security best practices Proactively identify opportunities to strengthen the organisation s overall security posture This is a fantastic opportunity to make a real impact in a business that values proactive security and continuous improvement. If this sounds like the right next step in your career, we d love to hear from you. This is an onsite position with opportunities for progression and development. For more info, please get in touch.
Aug 13, 2026
Full time
Information Vulnerability Analyst - Staffordshire Our client is looking for an Information Vulnerability Analyst to join their growing Information Security team. This is a key role focused on identifying, assessing, and mitigating security vulnerabilities across IT, OT, cloud, and SaaS environments. You will work closely with infrastructure, applications, and operations teams to ensure that risks are effectively managed and remediated. This position is ideal for someone who is proactive rather than reactive someone who enjoys identifying vulnerabilities before they become issues and takes ownership of driving them through to resolution. We are looking for a hands-on individual who thrives in a collaborative environment. You will work closely with service desk, networking, and infrastructure teams, influencing stakeholders and ensuring a joined-up approach to vulnerability management across the organisation. Key Responsibilities Manage the global vulnerability management process and associated platforms Perform regular vulnerability scans across IT, OT, and SaaS environments using industry-standard tools Coordinate and manage third-party security penetration testing across internal and external systems Analyse scan results, prioritise vulnerabilities, and drive remediation through to completion Maintain and enhance vulnerability management processes and reporting frameworks Contribute to the risk register and support ongoing security improvements Track remediation progress and report on risk posture to senior stakeholders Work closely with IT and engineering teams to ensure secure configurations and effective patch management Identify root causes of vulnerabilities and support long-term solutions Support compliance with frameworks such as NIST and Cyber Essentials Assist with threat modelling and risk assessments Maintain documentation, procedures, and security best practices Proactively identify opportunities to strengthen the organisation s overall security posture This is a fantastic opportunity to make a real impact in a business that values proactive security and continuous improvement. If this sounds like the right next step in your career, we d love to hear from you. This is an onsite position with opportunities for progression and development. For more info, please get in touch.
Senior Network and Security Engineer - L2/L3 Network Infrastructure - Cyber Security - SIEM tools My client who are leaders in their field are looking for a Senior Cyber Security and Network Analyst to provide effective and timely operational support, development and management of the IT network and security infrastructure to meet business requirements and objectives. Responsibilities: Support the delivery and maintenance of the organisation's cyber security and network infrastructure, ensuring systems remain secure, resilient, and aligned to business needs Manage day-to-day security operations, including monitoring SIEM platforms, Firewalls, endpoint protection, and threat detection tools Investigate security incidents and vulnerabilities, recommending and implementing corrective actions where required Maintain and support network technologies including LAN/WAN, Wi-Fi, Internet connectivity, and Layer 2/3 infrastructure Contribute to cyber security and infrastructure projects, including the implementation of new security controls and technologies Perform patching, upgrades, and ongoing maintenance across security and network environments to minimise risk and downtime Develop and maintain security policies, operational procedures, technical documentation, and compliance standards Support disaster recovery and business continuity planning, testing, and readiness activities Key Experience & Skills: Palo Alto Firewalls and all associated NG services Endpoint detection and remediation Proven track record in Cyber security and understanding of cyber security analysis, tools and software Experience of implementing, supporting and developing L2/3 network infrastructure Qualys Vulnerability Management Aruba Wifi L2/3 switching - Cisco Nexus Network Load balancing Penetration Testing (3rd Party) Incident management Data Security
Aug 13, 2026
Full time
Senior Network and Security Engineer - L2/L3 Network Infrastructure - Cyber Security - SIEM tools My client who are leaders in their field are looking for a Senior Cyber Security and Network Analyst to provide effective and timely operational support, development and management of the IT network and security infrastructure to meet business requirements and objectives. Responsibilities: Support the delivery and maintenance of the organisation's cyber security and network infrastructure, ensuring systems remain secure, resilient, and aligned to business needs Manage day-to-day security operations, including monitoring SIEM platforms, Firewalls, endpoint protection, and threat detection tools Investigate security incidents and vulnerabilities, recommending and implementing corrective actions where required Maintain and support network technologies including LAN/WAN, Wi-Fi, Internet connectivity, and Layer 2/3 infrastructure Contribute to cyber security and infrastructure projects, including the implementation of new security controls and technologies Perform patching, upgrades, and ongoing maintenance across security and network environments to minimise risk and downtime Develop and maintain security policies, operational procedures, technical documentation, and compliance standards Support disaster recovery and business continuity planning, testing, and readiness activities Key Experience & Skills: Palo Alto Firewalls and all associated NG services Endpoint detection and remediation Proven track record in Cyber security and understanding of cyber security analysis, tools and software Experience of implementing, supporting and developing L2/3 network infrastructure Qualys Vulnerability Management Aruba Wifi L2/3 switching - Cisco Nexus Network Load balancing Penetration Testing (3rd Party) Incident management Data Security
Senior IT Security Analyst required to act as a senior technical contributor within a global cyber security team, owning selected cyber security domains end-to-end and driving practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions based on real-world attacker behaviour, and deliver measurable improvements to the organisation cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365 / Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve endpoint security controls. Used Zscaler ZIA/ZPA or equivalent secure web gateway, private access, zero trust or network access security technologies. Performed vulnerability assessment, exposure analysis or remediation prioritisation across enterprise technology environments. Applied threat intelligence, MITRE ATT&CK or exploitation-based evidence to prioritise mitigations. Supported or led cyber security investigations and incident response activities. Collaborated with infrastructure, cloud, application, identity and business teams to deliver security improvements. Used scripting, queries, automation or data analysis to improve security outcomes. Strong hands-on experience administering, tuning and operationalising CrowdStrike Falcon , including endpoint protection, EDR investigations, detection analysis and response workflows. Strong hands-on experience administering and supporting Zscaler ZIA and ZPA , including policy design, access control, traffic analysis and security troubleshooting. Practical experience leading or supporting vulnerability and exposure management programmes , including vulnerability analysis, risk-based prioritisation, remediation tracking and validation of control effectiveness. Strong knowledge of real-world attacker tactics, techniques and procedures (TTPs) and the ability to translate threat intelligence, attack paths and exploitation trends into actionable security improvements. Experience conducting security investigations and incident response activities, including alert triage, root cause analysis, containment, remediation and lessons learned. This is a hybrid role working 3 days a week in the London office and 2 days remotely.
Aug 13, 2026
Full time
Senior IT Security Analyst required to act as a senior technical contributor within a global cyber security team, owning selected cyber security domains end-to-end and driving practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions based on real-world attacker behaviour, and deliver measurable improvements to the organisation cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365 / Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve endpoint security controls. Used Zscaler ZIA/ZPA or equivalent secure web gateway, private access, zero trust or network access security technologies. Performed vulnerability assessment, exposure analysis or remediation prioritisation across enterprise technology environments. Applied threat intelligence, MITRE ATT&CK or exploitation-based evidence to prioritise mitigations. Supported or led cyber security investigations and incident response activities. Collaborated with infrastructure, cloud, application, identity and business teams to deliver security improvements. Used scripting, queries, automation or data analysis to improve security outcomes. Strong hands-on experience administering, tuning and operationalising CrowdStrike Falcon , including endpoint protection, EDR investigations, detection analysis and response workflows. Strong hands-on experience administering and supporting Zscaler ZIA and ZPA , including policy design, access control, traffic analysis and security troubleshooting. Practical experience leading or supporting vulnerability and exposure management programmes , including vulnerability analysis, risk-based prioritisation, remediation tracking and validation of control effectiveness. Strong knowledge of real-world attacker tactics, techniques and procedures (TTPs) and the ability to translate threat intelligence, attack paths and exploitation trends into actionable security improvements. Experience conducting security investigations and incident response activities, including alert triage, root cause analysis, containment, remediation and lessons learned. This is a hybrid role working 3 days a week in the London office and 2 days remotely.
IT Service Desk Analyst (2nd Line) 6-Month Contract We're looking for an experienced IT Service Desk Analyst (2nd Line) to join a fast-paced global IT team on an initial 6-month contract . You'll provide advanced technical support across end-user devices, Microsoft 365, identity management, hardware, applications, and collaboration tools, ensuring employees have the technology and support they need to succeed. What You'll Do Resolve complex IT incidents and service requests across Windows, macOS, Microsoft 365, networking, hardware, and enterprise applications Own escalated tickets through to resolution, meeting SLAs and delivering excellent customer service Support onboarding, offboarding, hardware provisioning, software deployment, and access management Collaborate with Infrastructure, Security, and Level 3 teams to troubleshoot and resolve technical issues Provide guidance to Level 1 analysts and contribute to knowledge sharing and process improvement Maintain accurate documentation and work within a compliance-focused environment What We're Looking For 3+ years' experience in IT Service Desk, Desktop Support, or End User Support Strong troubleshooting skills across Windows, macOS, Microsoft 365, networking, and endpoint devices Experience with Active Directory, Entra ID, LDAP, and identity management Knowledge of endpoint management, device lifecycle management, and vulnerability remediation Excellent communication skills and a customer-first approach Experience working within global or regulated environments is highly desirable Contract Details Role: IT Service Desk Analyst (Level 2) Contract: 6 Months Start: ASAP Location: Sheffield 5 days on-site If you're a hands-on IT support professional who enjoys solving complex technical issues and delivering a first-class user experience, please apply to Lina Hayward Hojaij using the links provided.
Aug 12, 2026
Contractor
IT Service Desk Analyst (2nd Line) 6-Month Contract We're looking for an experienced IT Service Desk Analyst (2nd Line) to join a fast-paced global IT team on an initial 6-month contract . You'll provide advanced technical support across end-user devices, Microsoft 365, identity management, hardware, applications, and collaboration tools, ensuring employees have the technology and support they need to succeed. What You'll Do Resolve complex IT incidents and service requests across Windows, macOS, Microsoft 365, networking, hardware, and enterprise applications Own escalated tickets through to resolution, meeting SLAs and delivering excellent customer service Support onboarding, offboarding, hardware provisioning, software deployment, and access management Collaborate with Infrastructure, Security, and Level 3 teams to troubleshoot and resolve technical issues Provide guidance to Level 1 analysts and contribute to knowledge sharing and process improvement Maintain accurate documentation and work within a compliance-focused environment What We're Looking For 3+ years' experience in IT Service Desk, Desktop Support, or End User Support Strong troubleshooting skills across Windows, macOS, Microsoft 365, networking, and endpoint devices Experience with Active Directory, Entra ID, LDAP, and identity management Knowledge of endpoint management, device lifecycle management, and vulnerability remediation Excellent communication skills and a customer-first approach Experience working within global or regulated environments is highly desirable Contract Details Role: IT Service Desk Analyst (Level 2) Contract: 6 Months Start: ASAP Location: Sheffield 5 days on-site If you're a hands-on IT support professional who enjoys solving complex technical issues and delivering a first-class user experience, please apply to Lina Hayward Hojaij using the links provided.
Are you a Glasgow based IT Security Analyst looking to progress your career in a global business with fantastic long term career prospects? If so, this might be the ideal role for you You ll join a small Infrastructure Security team as part of a new local security function based in the Glasgow office. You will work on incident monitoring and response, as well as risk and vulnerability management across the ICT environment. You'll be responsible for all aspects of cyber security. You'll also have input into how infrastructure and operational security are shaped for the EMEA region. This is a hybrid role with 3 days on-site per week. On offer is a great salary and benefits package of around £60k (doe) plus a bonus, good pension, generous holiday allowance (option to purchase more each year) plus more . What you'll be doing Handle incident monitoring and response for EMEA operations. Classify, prioritise, and escalate security events, and drive them through to root cause and closure. Run vulnerability management end-to-end. Run assessments, validate findings, and drive remediation and patching through to resolution. Assess and certify servers, endpoints, and network infrastructure for compliance with security requirements. Implement and enforce security controls across ICT systems, including access management and RBAC. Advise project teams on security risk and approve or block changes based on assessed impact. Extend security oversight into OT environments, including incident response and compliance validation. What you'll bring Solid experience in vulnerability management using tools such as Qualys, or Rapid7 InsightVM etc. A background in incident response and SOC operations, ideally with exposure to SIEM platforms like Splunk or Microsoft Sentinel. Working knowledge of network security: firewalls, IDS, RBAC, LAN/WAN/SD-WAN, using platforms such as Palo Alto, Fortinet, or Cisco. Exposure to OT or industrial control systems is an advantage Confidence advising and pushing back on stakeholders across a global organisation. A degree in IT or equivalent hands-on experience. If this sounds like your next move, and you can commute eaily to the outskirts of Glasgow (West side) 3 days per week, then please apply NOW before it s too late.
Aug 08, 2026
Full time
Are you a Glasgow based IT Security Analyst looking to progress your career in a global business with fantastic long term career prospects? If so, this might be the ideal role for you You ll join a small Infrastructure Security team as part of a new local security function based in the Glasgow office. You will work on incident monitoring and response, as well as risk and vulnerability management across the ICT environment. You'll be responsible for all aspects of cyber security. You'll also have input into how infrastructure and operational security are shaped for the EMEA region. This is a hybrid role with 3 days on-site per week. On offer is a great salary and benefits package of around £60k (doe) plus a bonus, good pension, generous holiday allowance (option to purchase more each year) plus more . What you'll be doing Handle incident monitoring and response for EMEA operations. Classify, prioritise, and escalate security events, and drive them through to root cause and closure. Run vulnerability management end-to-end. Run assessments, validate findings, and drive remediation and patching through to resolution. Assess and certify servers, endpoints, and network infrastructure for compliance with security requirements. Implement and enforce security controls across ICT systems, including access management and RBAC. Advise project teams on security risk and approve or block changes based on assessed impact. Extend security oversight into OT environments, including incident response and compliance validation. What you'll bring Solid experience in vulnerability management using tools such as Qualys, or Rapid7 InsightVM etc. A background in incident response and SOC operations, ideally with exposure to SIEM platforms like Splunk or Microsoft Sentinel. Working knowledge of network security: firewalls, IDS, RBAC, LAN/WAN/SD-WAN, using platforms such as Palo Alto, Fortinet, or Cisco. Exposure to OT or industrial control systems is an advantage Confidence advising and pushing back on stakeholders across a global organisation. A degree in IT or equivalent hands-on experience. If this sounds like your next move, and you can commute eaily to the outskirts of Glasgow (West side) 3 days per week, then please apply NOW before it s too late.
Job Purpose: This role is responsible for overseeing and enhancing the security of our IT systems, data, and networks. You will conduct regular security audits, assessments, and tests, and identify and resolve any vulnerabilities or breaches.You will also develop and implement security policies, procedures, and standards, and ensure compliance with the relevant laws and regulations, and train and educate employees on the best practices and awareness of IT security. Operating Environment: The role operates within the IT Services Team, The IT Services Team includes specialist staff delivering core outputs that are both external-facing and internal key enablers. Framework & Boundaries: The role is responsible for improving the quality, wellbeing and efficiency of our IT Security. The role has external-facing responsibilities and is required and authorised to act as a representative for the organisation. Key accountabilities: Monitor and Inspect: Regularly monitor the network for security threats or breaches. Policy Development: Develop and implement security policies and procedures to safeguard data and systems. Vulnerability Testing: Perform regular vulnerability testing and risk assessments to identify and mitigate security risks. Incident Response: Investigate security incidents and provide post-event analysis and recommendations. Security Tools Management: Manage and maintain Firewalls, intrusion detection and prevention systems, antivirus software, and other security tools. Compliance: Ensure compliance with industry regulations and standards. Training: Train technical and non-technical employees on security protocols, procedures, and best practices. Disaster Recovery: Participate in disaster recovery planning and testing to ensure business continuity in the event of a security incident. Job impact: Risk Mitigation: Implementing robust security measures to significantly reduce the risk of data breaches, cyber-attacks, and other security incidents. Proactive Threat Management: Identifying and addressing vulnerabilities before they can be exploited, thereby enhancing the overall security posture of the organisation. Ensuring that the organisation complies with relevant laws, regulations, and industry standards (eg, GDPR, HIPAA, PCI-DSS), thereby avoiding legal penalties and enhancing trust with stakeholders. Maintaining a state of readiness for security audits and assessments, ensuring that all security controls and measures are well-documented and effective. Developing and implementing disaster recovery plans to ensure business continuity in the event of a security incident or data loss. Efficiently managing and mitigating the impact of security incidents to minimise downtime and operational disruption. Knowledge and experience: Technical Proficiency: In-depth knowledge of network security software - Meraki Cloud, Cloudflare, Mimecast, encryption technologies, and other security hardware and software tools. Current Trends: Stay current with the latest trends in cybersecurity threats and defence strategies. Problem-Solving: Strong problem-solving skills and the ability to work well under pressure. Communication: Good communication skills to effectively train employees and coordinate with other departments. Functional/technical skills: Firewall Management: Proficiency in configuring and managing Firewalls to protect network boundaries. Intrusion Detection/Prevention Systems (IDS/IPS): Experience with IDS/IPS to monitor and respond to potential threats. VPNs and Remote Access: Knowledge of setting up and managing Virtual Private Networks (VPNs) and secure remote access solutions. Patch Management: Ability to manage and deploy security patches and updates to systems and applications. Endpoint Security: Experience with endpoint protection solutions, such as antivirus and anti-malware software. Proficiency in implementing and managing encryption technologies to protect data at rest and in transit. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found on our website.
Mar 30, 2026
Full time
Job Purpose: This role is responsible for overseeing and enhancing the security of our IT systems, data, and networks. You will conduct regular security audits, assessments, and tests, and identify and resolve any vulnerabilities or breaches.You will also develop and implement security policies, procedures, and standards, and ensure compliance with the relevant laws and regulations, and train and educate employees on the best practices and awareness of IT security. Operating Environment: The role operates within the IT Services Team, The IT Services Team includes specialist staff delivering core outputs that are both external-facing and internal key enablers. Framework & Boundaries: The role is responsible for improving the quality, wellbeing and efficiency of our IT Security. The role has external-facing responsibilities and is required and authorised to act as a representative for the organisation. Key accountabilities: Monitor and Inspect: Regularly monitor the network for security threats or breaches. Policy Development: Develop and implement security policies and procedures to safeguard data and systems. Vulnerability Testing: Perform regular vulnerability testing and risk assessments to identify and mitigate security risks. Incident Response: Investigate security incidents and provide post-event analysis and recommendations. Security Tools Management: Manage and maintain Firewalls, intrusion detection and prevention systems, antivirus software, and other security tools. Compliance: Ensure compliance with industry regulations and standards. Training: Train technical and non-technical employees on security protocols, procedures, and best practices. Disaster Recovery: Participate in disaster recovery planning and testing to ensure business continuity in the event of a security incident. Job impact: Risk Mitigation: Implementing robust security measures to significantly reduce the risk of data breaches, cyber-attacks, and other security incidents. Proactive Threat Management: Identifying and addressing vulnerabilities before they can be exploited, thereby enhancing the overall security posture of the organisation. Ensuring that the organisation complies with relevant laws, regulations, and industry standards (eg, GDPR, HIPAA, PCI-DSS), thereby avoiding legal penalties and enhancing trust with stakeholders. Maintaining a state of readiness for security audits and assessments, ensuring that all security controls and measures are well-documented and effective. Developing and implementing disaster recovery plans to ensure business continuity in the event of a security incident or data loss. Efficiently managing and mitigating the impact of security incidents to minimise downtime and operational disruption. Knowledge and experience: Technical Proficiency: In-depth knowledge of network security software - Meraki Cloud, Cloudflare, Mimecast, encryption technologies, and other security hardware and software tools. Current Trends: Stay current with the latest trends in cybersecurity threats and defence strategies. Problem-Solving: Strong problem-solving skills and the ability to work well under pressure. Communication: Good communication skills to effectively train employees and coordinate with other departments. Functional/technical skills: Firewall Management: Proficiency in configuring and managing Firewalls to protect network boundaries. Intrusion Detection/Prevention Systems (IDS/IPS): Experience with IDS/IPS to monitor and respond to potential threats. VPNs and Remote Access: Knowledge of setting up and managing Virtual Private Networks (VPNs) and secure remote access solutions. Patch Management: Ability to manage and deploy security patches and updates to systems and applications. Endpoint Security: Experience with endpoint protection solutions, such as antivirus and anti-malware software. Proficiency in implementing and managing encryption technologies to protect data at rest and in transit. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found on our website.
Senior Cyber Security Analyst Location: London hybrid working IR35: Inside via Triumph Consultants you will be paid PAYE for the length of the 3 month contract It is essential for candidates to have advanced proficiency in using Splunk for security monitoring, log analysis, threat detection, and reporting The role: The Cyber Defence team at the delivers threat intelligence, threat detection, incident response, and vulnerability management to defend both internal IT infrastructure and citizen-facing services. They are looking for a Senior Cyber Security Analyst with proven experience in incident response and Splunk to take a leading role in strengthening the organisation's cyber defence capability. Key Accountabilities: Lead investigations into security alerts and cyber incidents. Perform forensic analysis of systems, files, network traffic, and cloud environments. Drive technical response actions including containment, eradication, and recovery. Coordinate cyber incident responses across teams and stakeholders. Identify lessons learned and embed continual improvement. Develop and update incident response playbooks and knowledge base articles. Act as an escalation point and mentor for security analysts. Provide leadership and line management within the team. Join the out-of-hours on-call rota to support 24/7 incident response. Key Criteria: 5+ years' experience investigating and responding to cyber incidents in large organisations. Strong track record with incident response coordination. Significant hands-on experience with Splunk and security tools (eg, EDR, SIEM). Analytical, problem-solving, and forensic investigation skills. Proven experience coaching or mentoring junior staff. Strong understanding of threat actor tools, techniques, and procedures. Experience of cloud environments such as AWS Excellent written and verbal communication skills. How to Apply Quote the Job Title and Reference Number in your application. Submit your CV in Word format. Applications are reviewed on a rolling basis-early submission is recommended. We will also add your details to our mail out lists. Please note you may receive details of roles outside of your immediate vicinity, as many candidates are able to relocate temporarily for work. Please disregard any such emails that are not of interest and let us know if you would rather not receive such mailouts and/or if you wish us to delete your details and prefer to apply direct to our advertised roles. If you do not hear from us within three working days, unfortunately your application has not been shortlisted on this occasion. Thank you for your interest in working with us.
Oct 07, 2025
Contractor
Senior Cyber Security Analyst Location: London hybrid working IR35: Inside via Triumph Consultants you will be paid PAYE for the length of the 3 month contract It is essential for candidates to have advanced proficiency in using Splunk for security monitoring, log analysis, threat detection, and reporting The role: The Cyber Defence team at the delivers threat intelligence, threat detection, incident response, and vulnerability management to defend both internal IT infrastructure and citizen-facing services. They are looking for a Senior Cyber Security Analyst with proven experience in incident response and Splunk to take a leading role in strengthening the organisation's cyber defence capability. Key Accountabilities: Lead investigations into security alerts and cyber incidents. Perform forensic analysis of systems, files, network traffic, and cloud environments. Drive technical response actions including containment, eradication, and recovery. Coordinate cyber incident responses across teams and stakeholders. Identify lessons learned and embed continual improvement. Develop and update incident response playbooks and knowledge base articles. Act as an escalation point and mentor for security analysts. Provide leadership and line management within the team. Join the out-of-hours on-call rota to support 24/7 incident response. Key Criteria: 5+ years' experience investigating and responding to cyber incidents in large organisations. Strong track record with incident response coordination. Significant hands-on experience with Splunk and security tools (eg, EDR, SIEM). Analytical, problem-solving, and forensic investigation skills. Proven experience coaching or mentoring junior staff. Strong understanding of threat actor tools, techniques, and procedures. Experience of cloud environments such as AWS Excellent written and verbal communication skills. How to Apply Quote the Job Title and Reference Number in your application. Submit your CV in Word format. Applications are reviewed on a rolling basis-early submission is recommended. We will also add your details to our mail out lists. Please note you may receive details of roles outside of your immediate vicinity, as many candidates are able to relocate temporarily for work. Please disregard any such emails that are not of interest and let us know if you would rather not receive such mailouts and/or if you wish us to delete your details and prefer to apply direct to our advertised roles. If you do not hear from us within three working days, unfortunately your application has not been shortlisted on this occasion. Thank you for your interest in working with us.