technology job

Information Assurance Analyst

  • Posted August 20, 2026
  • £540 - £590 per day
  • London
  • Contract

Information Assurance Analyst (BAU) x2

Location: UK (London 3 days a week)
Security Clearance: Active SC Clearance required
Contract Length: 6 -18 Months
Rate: £545 – £590 per day (Inside IR35)
Positions Available: 2

About the Role

We are seeking two experienced Information Assurance Analysts to support Business-as-Usual (BAU) Information Assurance activities across a portfolio of government-facing projects delivered by a leading consultancy.

This role is ideal for professionals with experience in Information Assurance, Governance, Risk, Compliance, Quality Assurance, or Operational Resilience who are passionate about maintaining high standards of security, compliance, quality, and resilience within complex and regulated environments.

As an Information Assurance Analyst, you will play a key role in supporting assurance programmes, monitoring compliance with policies and standards, maintaining governance controls, and driving continuous improvement initiatives. Working closely with delivery, security, operations, risk, and quality teams, you will help ensure services remain compliant, resilient, and aligned to client and organisational objectives.

The successful candidate will be expected to operate as a trusted advisor, influence stakeholders, support informed decision-making, and contribute to the ongoing enhancement of assurance practices across multiple government projects.

Key Responsibilities

Information Assurance & Compliance

  • Support the delivery of Information Assurance activities across operational and project environments.
  • Monitor compliance with organisational policies, procedures, standards, and regulatory requirements.
  • Conduct assurance reviews and quality assessments to identify areas of risk and non-compliance.
  • Assist with audit preparation, evidence gathering, and remediation tracking.
  • Support governance and assurance reporting across multiple workstreams.

Quality Assurance Management

  • Support and enhance quality assurance frameworks, methodologies, and processes.
  • Review operational processes to ensure adherence to established standards and controls.
  • Monitor performance against agreed quality measures and KPIs.
  • Identify trends and recurring issues that may impact compliance, quality, or service delivery.
  • Recommend and implement quality improvements to strengthen operational effectiveness.

Business Continuity & Operational Resilience

  • Support Business Continuity and Disaster Recovery (BCDR) activities.
  • Contribute to continuity planning, testing, and resilience assessments.
  • Assist with the review and maintenance of recovery plans and procedures.
  • Help ensure critical services meet resilience and recovery objectives.

Continuous Improvement

  • Lead and contribute to process improvement initiatives across multiple teams.
  • Identify opportunities to improve assurance, governance, and quality management practices.
  • Promote best practice and continuous improvement methodologies.
  • Support the development of new assurance processes and operating models.

Stakeholder Management

  • Collaborate with security, operations, delivery, risk, compliance, and governance teams.
  • Engage with stakeholders to promote quality standards and assurance objectives.
  • Provide guidance and support to colleagues on assurance and compliance matters.
  • Facilitate workshops, reviews, and assurance activities where required.

Reporting & Analysis

  • Analyse assurance, compliance, and quality-related data to identify trends and risks.
  • Produce reports, dashboards, metrics, and management information.
  • Present findings and recommendations to stakeholders and senior leadership.
  • Track actions and support remediation plans through to completion.

Required Skills & Experience

  • Experience within Information Assurance, Governance, Risk, Compliance, Quality Assurance, or related disciplines.
  • Strong understanding of quality assurance principles and methodologies.
  • Experience monitoring compliance against policies, processes, and standards.
  • Ability to assess, analyse, and improve operational processes and controls.
  • Strong understanding of governance and assurance practices.
  • Experience producing reports, metrics, and management information.
  • Excellent communication and stakeholder engagement skills.
  • Strong analytical and problem-solving capabilities.
  • Experience working within regulated, security-conscious, or highly governed environments.
  • Active SC Clearance.

Desirable Skills & Experience

  • Experience supporting government departments, public sector organisations, or other highly regulated environments.
  • Knowledge of Information Assurance frameworks and governance requirements.
  • Experience with:
    • Business Continuity Management (BCM)
    • Disaster Recovery Planning
    • Operational Resilience
    • Risk Management Frameworks
    • Internal Audit Activities
    • Control Assessments
    • Process Improvement Programmes
  • Familiarity with:
    • ISO 27001
    • ISO 22301
    • NIST Cybersecurity Framework
    • Cyber Assessment Framework (CAF)
    • ITIL
    • Governance, Risk and Compliance (GRC) tools

Preferred Certifications

The following certifications would be advantageous but are not essential:

  • ISO 27001 Lead Auditor or Lead Implementer
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CRISC (Certified in Risk and Information Systems Control)
  • ISO 22301 Business Continuity Certifications
  • CIA (Certified Internal Auditor)
  • ITIL Foundation or higher
  • IRM Risk Management Certifications

Reasonable Adjustments:

Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

Apply for this Job

    technology job

    PAM Engineer (CyberArk)

    • Posted August 19, 2026
    • £440 - £540 per day + Inside IR35
    • Permanent

    PAM/EMP Engineer (CyberArk)

    Contract | 2 Positions Available

    📍 Location: Manchester (5 Days Onsite)
    💰 Rate: £440 – £540 per day Inside IR35
    🕒 Duration: 3 months

    About the Role

    I’m actively searching for two experienced BeyondTrust Endpoint Privilege Management (EPM) Engineers to support a large-scale, highly customised endpoint privilege management environment within a secure enterprise setting.

    This is an excellent opportunity for individuals with strong expertise in BeyondTrust EPM, endpoint security, application control, and privilege management. You will work closely with Application Packaging, Endpoint Engineering, and Security teams to ensure the ongoing operation, optimisation, and enhancement of a complex EPM estate.

    Candidates with significant CyberArk Endpoint Privilege Manager experience who are interested in cross-training into BeyondTrust EPM are also encouraged to apply.

    Key Responsibilities

    • Administer, support, and maintain a highly customised BeyondTrust EPM platform.
    • Design, implement, and manage policies covering privilege elevation, application control, allow-listing, and endpoint security.
    • Collaborate with Application Packaging and Endpoint Engineering teams to support application deployment and compatibility.
    • Analyse application requirements and define appropriate privilege management solutions.
    • Troubleshoot complex endpoint privilege management and application control issues.
    • Develop, test, and deploy policy changes while maintaining operational stability and security.
    • Support the on-boarding of new applications into the EPM environment.
    • Investigate and resolve incidents relating to privilege elevation, application execution, and endpoint security controls.
    • Work closely with infrastructure, packaging, and security teams to ensure seamless service delivery.
    • Produce and maintain technical documentation, support procedures, and operational standards.
    • Contribute to continuous improvement initiatives and platform optimisation activities.

    Essential Skills & Experience

    • Extensive hands-on experience with BeyondTrust Endpoint Privilege Management (EPM) administration and engineering.
    • Strong understanding of Windows endpoint security architecture.
    • Proven experience creating, modifying, and troubleshooting BeyondTrust EPM policies.
    • Experience supporting application packaging and software deployment processes.
    • Strong knowledge of:
      • Windows Desktop Operating Systems
      • Application Control
      • Privilege Elevation
      • Endpoint Security
      • Software Packaging and Deployment
      • Group Policy Administration
    • Ability to analyse software requirements and design effective privilege management solutions.
    • Experience supporting highly customised enterprise EPM environments.
    • Excellent troubleshooting and root cause analysis skills.
    • Experience working within secure, controlled, or highly regulated environments.
    • Strong documentation and technical communication skills.
    • Ability to work independently in a complex operational setting.

    Desirable Skills

    • Experience with CyberArk Endpoint Privilege Manager (EPM).
    • Experience migrating between endpoint privilege management platforms.
    • Knowledge of Microsoft Intune, MECM/SCCM, or similar endpoint management solutions.
    • PowerShell scripting and automation experience.
    • Experience supporting large-scale enterprise endpoint estates.
    • Familiarity with ITIL-based operational environments.
    • Experience working within secure facilities or restricted-access environments.

    What’s Required?

    To be considered for this opportunity, you must:

    ✅ Be eligible for BPSS clearance
    ✅ Be able to work 5 days per week onsite in Manchester or Inverness
    ✅ Be available to participate in a 24×7 support rota

    If you have strong BeyondTrust EPM expertise and are looking to work on a complex, enterprise-scale deployment within a secure environment, apply to be considered.

    Reasonable Adjustments:

    Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

    If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

    Apply for this Job

      technology job

      Security Architect (Zero Trust) - DV Cleared

      • Posted
      • Bonus + Benefits
      • Farnborough
      • Permanent

      Security Architect – Zero Trust – DV Cleared

      • Location: Farnborough, Hampshire, UK
      • Employment Type: Permanent, Full-Time
      • Security Clearance: Developed Vetting (DV) – Essential

      About the Role We are seeking a highly experienced Security Architect with a strong focus on Zero Trust Architecture (ZTA) to design, implement and evolve secure enterprise environments. You will lead security transformation initiatives, develop enterprise-wide security strategies, and implement identity-centric security architectures aligned with modern Zero Trust principles. This role requires deep expertise across identity, cloud, infrastructure and cyber security domains, ensuring organisations remain resilient against evolving cyber threats whilst meeting security requirements.

      Key Responsibilities Zero Trust Strategy & Architecture

      • Define and deliver enterprise-wide Zero Trust strategies and roadmaps
      • Design Zero Trust architectures aligned to NIST 800-207 principles
      • Implement identity-first security models across users, devices, applications and data
      • Develop continuous verification and adaptive access control frameworks
      • Lead micro-segmentation and least privilege initiatives across enterprise environments

      Security Strategy & Architecture

      • Design holistic security architectures incorporating people, process and technology security
      • Develop enterprise-wide security strategies aligned with and Defence Security Policy requirements
      • Architect defence-in-depth security solutions across network, cloud, endpoint and application layers
      • Lead security architecture reviews and technical security assessments
      • Develop security standards, reference architectures and design patterns

      Identity & Access Management

      • Architect and implement enterprise IAM, MFA and Single Sign-On solutions
      • Design Conditional Access and Privileged Access Management (PAM) capabilities
      • Lead identity governance and administration initiatives
      • Develop secure authentication and authorisation frameworks
      • Ensure access management aligns with Zero Trust and least privilege principles

      Cyber Threat & Risk Management

      • Assess cyber threat landscapes and design threat-informed security architectures
      • Lead security risk assessments and vulnerability management programmes
      • Design incident response, threat intelligence and cyber defence capabilities
      • Architect security monitoring, detection and response solutions
      • Develop cyber resilience and business continuity frameworks

      Cloud & Security Solutions

      • Design cloud security architectures across Azure, AWS and hybrid environments
      • Architect endpoint protection, DLP and advanced threat protection solutions
      • Design application security, API security and secure SDLC integration
      • Architect Security Operations Centre (SOC) and SIEM capabilities
      • Lead security technology evaluation, selection and implementation programmes

      Technical Leadership & Governance

      • Lead security technical teams and provide architectural mentoring
      • Establish security design standards, architecture patterns and governance processes
      • Drive technical decision-making through security design reviews
      • Document security architecture decisions and design specifications
      • Support organisational security transformation programmes

      Customer & Stakeholder Engagement

      • Act as the subject matter expert for Security Architecture and Zero Trust initiatives
      • Present security recommendations to senior leadership and programme stakeholders
      • Lead architecture workshops and customer engagement activities
      • Communicate complex security concepts to both technical and non-technical audiences

      Essential Requirements Experience & Expertise

      • Minimum 10 years’ experience within Cyber Security and Information Security
      • At least 5 years’ experience in a Security Architect position
      • Proven experience delivering enterprise-scale Zero Trust transformation programmes
      • Strong background within defence, aerospace, government or highly regulated sectors
      • Experience leading security transformation and modernisation initiatives

      Technical Knowledge

      • Deep expertise in Zero Trust Architecture principles and implementation methodologies
      • Strong knowledge of NIST 800-207 and modern security architecture frameworks
      • Expert understanding of Identity & Access Management technologies
      • Experience with Microsoft Entra ID, Conditional Access, PIM and PAM solutions
      • Strong understanding of network security, micro-segmentation and secure access technologies
      • Proficiency in cloud security across Azure, AWS or equivalent platforms
      • Knowledge of security technologies including SIEM, EDR/XDR, DLP, CASB, ZTNA, WAF and firewalls
      • Understanding of cryptography, encryption standards and secure communication protocols
      • Familiarity with MOD security requirements, defence standards and accreditation processes
      • Knowledge of ISO 27001, NIST CSF and CIS Controls frameworks

      Personal Attributes

      • Exceptional strategic thinking combined with strong technical depth
      • Outstanding communication and stakeholder engagement skills
      • Strong problem-solving and analytical capabilities
      • Proven ability to influence technical teams and executive stakeholders
      • Passion for cyber security innovation and continuous improvement

      Desirable Requirements

      • Experience delivering Microsoft Zero Trust programmes
      • CISSP, CISM, SABSA, TOGAF or equivalent industry certifications
      • Microsoft Cybersecurity Architect Expert certification
      • AWS Security Specialty or Azure Security Engineer certification
      • Experience implementing SASE, SSE or ZTNA technologies
      • Knowledge of ITAR compliance and export controls
      • Previous DV or SC Clearance
      • Armed Forces, Defence or National Security background

      What We Offer

      • Highly competitive salary and comprehensive benefits package
      • Enhanced pension and private medical insurance
      • Flexible and hybrid working options
      • Professional development and industry certification support
      • Opportunity to lead strategic Zero Trust transformation programmes
      • Exposure to mission-critical defence and national security projects

      Reasonable Adjustments:

      Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

      If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

      Apply for this Job

        technology job

        Security Architect - DV Cleared

        • Posted
        • £70000 - £85000 per annum + Bonus + Benefits
        • Farnborough
        • Permanent

        Security Architect – DV Cleared

        • Location: Farnborough, Hampshire, UK
        • Employment Type: Permanent, Full-Time
        • Security Clearance: Developed Vetting (DV) – Essential
        • Salary: £70,000 – £85,000 + Benefits

        About the Role

        The Security Architect designs and implements comprehensive security architectures protecting defence and aerospace IT environments. You will develop enterprise security strategies, lead security programme implementations, architect integrated defence-in-depth solutions, and ensure compliance with stringent MOD security requirements. This role demands exceptional expertise in security architecture, risk management and defence security standards.

        Key Responsibilities

        Security Strategy & Architecture

        • Design holistic security architectures incorporating people, process and technology security
        • Develop enterprise-wide security strategies aligned with Defence Security Policy
        • Architect defence-in-depth security solutions across network, application, data and endpoint layers
        • Lead security architecture reviews and technical security assessments
        • Design zero-trust security models and continuous verification frameworks

        Cyber Threat & Risk Management

        • Assess cyber threat landscape and design threat-informed security architectures
        • Lead security risk assessments and vulnerability management programmes
        • Design incident response, threat intelligence and cyber defence capabilities
        • Architect security monitoring, detection and response solutions
        • Design business continuity and cyber resilience frameworks

        Compliance & Standards Implementation

        • Ensure security architectures comply with MOD security requirements and ITAR regulations
        • Design security solutions supporting Information Security Management System (ISMS) compliance
        • Architect compliance and audit capabilities for regulatory reporting
        • Lead security standards implementation and controls frameworks

        Security Solutions & Integration

        • Architect endpoint protection, data loss prevention (DLP) and advanced threat protection solutions
        • Design cloud security architectures supporting hybrid and multi-cloud environments
        • Architect application security, API security and secure SDLC integration
        • Design security operations centre (SOC) capabilities and security information and event management (SIEM)
        • Lead security technology evaluation and implementation programmes

        Technical Leadership & Governance

        • Lead security technical teams and provide architectural mentoring
        • Establish security design standards, architecture patterns and operational governance
        • Drive technical decision-making through security design reviews
        • Document security architecture decisions and design specifications

        Customer & Stakeholder Engagement

        • Serve as technical authority for security architecture discussions with customer leadership
        • Present security recommendations to defence programme teams and executive stakeholders
        • Lead security architecture workshops and customer engagement activities
        • Communicate complex security concepts to technical and non-technical audiences

        Essential Requirements

        Experience & Expertise

        • Minimum 12 years’ information security experience with 5+ years in architecture role
        • Proven experience designing enterprise-scale security architectures
        • Strong background in defence, aerospace or government security programmes
        • Demonstrated expertise with security operations, incident response and threat management
        • Track record of leading security transformation and programme implementations

        Technical Knowledge

        • Deep expertise in security architecture frameworks, methodologies and best practices
        • Expert-level knowledge of network security, endpoint security and application security
        • Strong understanding of threat models, attack vectors and defence-in-depth strategies
        • Proficiency in cloud security (AWS, Azure security, or equivalent)
        • Knowledge of security tools (SIEM, DLP, EDR, WAF, firewalls, etc.)
        • Understanding of cryptography, encryption and security protocols
        • Familiarity with MOD security requirements, Classification Guides and defence standards
        • Knowledge of compliance frameworks (ISO 27001, NIST CSF, etc.)

        Personal Attributes

        • Exceptional strategic thinking combined with strong technical depth
        • Outstanding communication and stakeholder engagement skills
        • Strong problem-solving and analytical capabilities
        • Proven ability to lead technical teams and influence executive stakeholders
        • Passion for security excellence and continuous improvement

        Desirable Requirements

        • Experience with defence or aerospace security programmes
        • CISSP, CISM, CCSK or equivalent security certifications
        • AWS Security or Azure Security certifications
        • Experience with security governance and compliance frameworks
        • Knowledge of ITAR compliance and export controls
        • Armed Forces or military security background

        What We Offer

        • Highly competitive salary and comprehensive benefits package
        • Enhanced pension and private medical insurance
        • Flexible working and professional development support
        • Opportunity to architect security for mission-critical defence organisations

        Reasonable Adjustments:

        Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

        If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

        Apply for this Job

          technology job

          Senior Cyber Security Consultant - Perm - SC Cleared

          • Posted
          • £65000 - £80000 per annum + + Package
          • Remote first w occasional customer site travel
          • Permanent

          Senior Cyber Security Consultant

          Clearance: SC
          Salary: £65k – £80k + Package
          Location: Remote first w occasional travel to customer site

          The Role in a Nutshell:

          In this role you’ll work within the Consulting team, supporting new and existing clients across various sectors to define and implement security risk assessment and best practice solutions that match their requirements. You’ll work in close partnership with clients to ensure the delivery of expert services by complementing their inhouse Information and Cyber Security resources combining expertise in information security, solution architecture and business advice.

          As a Senior Cyber Security Consultant, you will be responsible for the identification of risks relating to Security Architecture, maintaining an awareness of published vulnerabilities and best practices across various platforms, especially cloud infrastructures. Working across the business and multiple technology platforms, you will play a key role in ensuring clients make the best use of their existing technology and make proportionate, risk-informed decisions, ensuring protection of client assets and transformation of their security architecture.  

          This role forms part of the wider Consultancy team and will work cross functionally with the Delivery Manager and others to support and assure project delivery through all phases of the agile workflow. As a team, we’re always looking to raise the bar, learn new things and incorporate new technologies and you will too! 

          The Impact You’ll Make

          In this role, you’ll be:

          • Providing expert advice on cyber risk management, assessment principles and frameworks, such as ISO27005 and the NIST Risk Management Framework.
          • Working with multi-disciplinary teams, helping to ensure that products are delivered in a secure manner that is aligned with the wider business risk appetite.
          • Managing and supporting risk identification, assessment, remediation and risk treatment for digital systems, applications and infrastructure.
          • Identifying and validating technical, procedural, physical and personnel security controls, making recommendations to address security vulnerabilities and control weaknesses.
          • Facilitating cyber risk workshops and threat modelling to identify and assess risks that arise from solution architectures.
          • Supporting the scoping of IT Health Checks, which will identify principal security concerns for service lines.
          • Reviewing outcomes of the ITHC and providing advice and guidance, and where required production of an action plan for vulnerabilities identified with clear recommendations and outcomes to mitigate and address.
          • Producing informative and succinct reporting that clearly articulates any identified vulnerabilities, associated risks, controls and risk treatment activity.
          • Producing residual risk registers.
          • Providing accurate and pragmatic remediation/risk management guidance/advice.
          • Conducting Security gap analysis against security control frameworks, remediation planning and monitoring.
          • Evaluating third-party suppliers to provide assurance of the effective design and operation of security controls.
          • Producing security audit reports, checklists and briefings.

          What You’ll Bring to the Team and the Tools you’ll need:

          You’ll bring:

          • Strong analytical and problem-solving skills. Excellent communication and teamwork abilities, passion for cyber security and a desire to learn and grow within the field. Ability to adapt and thrive in a fast-paced, dynamic environment, Organisation skills and forward planning.
          • Possess strong hands-on experience and working knowledge of:
            • Security related legislation (e.g. GDPR, PCI DSS, ICO requirements).
            • Security Control Frameworks such as NCSC Cyber Assurance Framework, ISO 27001, NIST CSF and CIS.
            • HMG and NCSC security policies, standards and guidance.
          • Have an understanding of cyber risk management in an agile delivery environment.
          • Have a good understanding of modern IT technologies and services, such as Cloud Computing (Azure, M365, AWS, Google), Mobile Computing, IT Security, Infrastructure technologies, Zero Trust and demonstrate an understanding of security architecture.
          • Be skilled in workshop facilitation particularly with respect to risk identification and assessment.
          • As a team, we’re always looking to raise the bar, learn new things and incorporate new technologies and you will too!  You’ll share your knowledge with the team, our clients and the wider Cyberfort community, contributing to Group blogs and undertaking research related to technology enhancements.
          • Certifications That Set You Apart: Relevant certifications, e.g., CISSP, CISM, CRISC or other. Have achieved or be working towards Full Membership of CIISEC and UK Cyber Security Council professional registration at either Chartered or Principal for Cyber Security Governance & Risk Management.

          What’s in it for You?

          You’ll enjoy:

          • Flexibility First: Work-life balance through hybrid/remote working options.
          • Your Growth Journey: Continuous learning opportunities and professional development.
          • Perks with a Purpose: Comprehensive benefits package to support your wellbeing, health, family and future, from Private Health Care, Cash Back Plan, Buy and Sell Holiday Options, Life Assurance….

          Reasonable Adjustments:

          Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

          If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

          Apply for this Job

            technology job

            Junior GRC Analyst

            • Posted August 17, 2026
            • £200 - £300 per day
            • Hybrid - London
            • Contract

            Junior GRC Analyst

            Rate – £200 – £300 per day Inside IR35

            Duration – 6 Month Contract

            Location – Remote / London

            We’re supporting a client looking for a Junior GRC Analyst to join their cyber security team.

            This is an ideal opportunity for someone with some exposure to Governance, Risk and Compliance who is looking to develop their career within a supportive environment. Working alongside an experienced GRC professional, you’ll help manage day to day governance activities and provide support across supplier assurance, policy management and compliance processes.

            Key Responsibilities:

            • Support third party supplier security assessments and due diligence reviews.
            • Assist with reviewing supplier responses and gathering evidence where required.
            • Help maintain and update security policies, standards and procedures.
            • Support governance, risk and compliance activities across the business.
            • Review contracts and legal agreements to identify security and compliance requirements.
            • Maintain governance documentation and audit evidence.
            • Track actions and follow up with stakeholders across the organisation.
            • Provide general administrative and operational support to the wider GRC function.

            Skills and Experience:

            • Previous experience in a GRC, information security, risk, compliance or governance focused role.
            • Understanding of third party supplier assessments and risk management.
            • Exposure to security policies, procedures or governance documentation.
            • Awareness of security, privacy or compliance requirements within contracts and legal agreements.
            • Strong organisational skills and attention to detail.
            • Confident communicating with a range of stakeholders.
            • Eagerness to learn and develop within cyber security governance.

            Reasonable Adjustments:

            Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

            If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

            Apply for this Job

              technology job

              Security Operations Lead -

              • Posted
              • £500 - £600 per day
              • Preston or Inverness - 5 days on-site
              • Contract

              Role Title: Security Operations Lead

              Clearance: SC Cleared
              Location: Inverness or Preston | 5 days onsite
              Initial Contract to 31/03/2027
              Pay: £500 – £600
              Status: Inside IR35

              Role Description:

              The Senior Security Incident Management Consultant operates within the Operational Integrator (OI) function and provides governance, leadership, assurance, and strategic oversight of security incident management across a complex multi-supplier environment.

              The role is responsible for ensuring suppliers manage security incidents consistently, effectively, and in accordance with client policy, regulatory obligations, and operational risk requirements. Acting as the primary OI lead for incident governance, the consultant provides a consolidated view of incident risk, drives supplier accountability, and supports continual improvement across the incident management lifecycle.

              Key Responsibilities:

              Security Incident Governance

              • Own and govern the security incident management framework across suppliers
              • Define and maintain:
                • Incident classification criteria
                • Escalation models
                • Reporting standards
                • Major incident governance processes
              • Ensure alignment to client policies, regulatory obligations, and security controls

              Supplier Governance & Performance Management

              • Act as the primary OI lead for security incident governance
              • Challenge, validate, and assure supplier incident management processes
              • Drive consistency in reporting, escalation, communications, and evidence standards
              • Manage escalations relating to significant or recurring incidents

              Incident Risk & Executive Oversight

              • Maintain visibility of security incident exposure across all suppliers
              • Ensure major incidents receive appropriate governance attention
              • Support risk-based decision making through accurate incident reporting
              • Provide oversight of supplier corrective and preventative actions

              Reporting & Executive Visibility

              • Produce consolidated security incident reporting across suppliers
              • Provide insight into:
                • Incident trends
                • Response performance
                • SLA adherence
                • Recurring root causes
                • Risk exposure
              • Support governance boards, service review meetings, and client security leadership

              Assurance & Evidence Management

              • Define incident management evidence requirements
              • Ensure traceability across:
                • Detection
                • Escalation
                • Investigation outcomes
                • Recovery activities
                • Closure decisions
              • Support audits, assurance reviews, and regulatory inspections

              Post-Incident Review & Continuous Improvement

              • Coordinate governance of Post Incident Reviews (PIRs)
              • Ensure suppliers provide:
                • Root cause analysis
                • Corrective actions
                • Improvement activities
              • Identify opportunities to improve incident governance, reporting, and operational effectiveness

              Your skills and experience

              Essential

              • Significant experience in Security Incident Management, Cyber Governance, Service Management, or GRC roles
              • Strong understanding of:
                • Security incident lifecycles
                • Major incident management
                • Security reporting and governance
              • Experience working within complex multi-supplier environments
              • Strong stakeholder engagement and supplier management skills
              • Experience presenting incident risk information to senior stakeholders

              Desirable

              • Knowledge of:
                • NIST Cyber Security Framework (CSF)
                • NCSC guidance
                • ITIL Major Incident Management
                • ISO 27001
              • Experience supporting security assurance and audit activities
              • Experience in Defence, Government, or highly regulated sectors

              Key Deliverables

              • Security Incident Management Framework
              • Consolidated supplier incident reporting
              • Executive incident dashboards
              • Governance and assurance reporting packs
              • Post Incident Review governance outputs
              • Continuous improvement roadmap

              Role Definition

              The role governs and assures security incident management across suppliers, ensuring incidents are consistently escalated, evidenced, reviewed, and reported to the client through a controlled and audit-ready process, without performing operational security response activities

              Reasonable Adjustments:

              Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

              If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

              Apply for this Job

                technology job

                SC Cleared OT Cyber Security Risk Assessment Consultant

                • Posted August 14, 2026
                • £550 - £700 per day + Outside IR35
                • Reading
                • Contract

                OT Cyber Security Risk Assessment Consultant
                Pay rate: £600 – £700 outside IR35
                Clearance: SC
                Nationality: Must be Sole British
                Start date: ASAP
                Duration: 12 months

                Role Summary

                Support the delivery of IEC 62443-3-2 cyber security risk assessments across approximately 33 OT/industrial systems, working closely with engineering, security, and project stakeholders.

                Key Responsibilities

                • Conduct IEC 62443-3-2 Initial Risk Assessments (ZCR1-ZCR4).
                • Perform Detailed Risk Assessments (ZCR1-ZCR7) where risks exceed tolerable levels.
                • Gather information from stakeholders and facilitate assessment activities.
                • Produce and maintain risk assessment documentation using customer-approved templates.
                • Address review comments and deliver final assessment artefacts.
                • Provide project updates, effort estimates, and progress reports

                Required Skills & Experience

                • Experience conducting cyber security risk assessments in OT/ICS environments.
                • Strong knowledge of IEC 62443-3-2.
                • Excellent stakeholder engagement and communication skills.
                • Experience producing technical reports and risk documentation.
                • Ability to work independently and manage multiple assessments.

                Working Pattern

                • 37 hours per week, Monday-Friday.
                • Hybrid working, initially requiring a minimum of 3 days per week onsite in Reading area
                • Work must be carried out using company-provided equipment and approved security procedures.

                Reasonable Adjustments:

                Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

                If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

                Apply for this Job

                  technology job

                  Beyond Trust

                  • Posted August 12, 2026
                  • £440 - £540 per annum + Inside IR35
                  • Permanent

                  EPM Engineer (BeyondTrust)

                  Contract | 2 Positions Available

                  📍 Location: Manchester (5 Days Onsite)
                  💰 Rate: £440 – £540 per day Inside IR35
                  🕒 Duration: 3 months

                  About the Role

                  I’m actively searching for two experienced BeyondTrust Endpoint Privilege Management (EPM) Engineers to support a large-scale, highly customised endpoint privilege management environment within a secure enterprise setting.

                  This is an excellent opportunity for individuals with strong expertise in BeyondTrust EPM, endpoint security, application control, and privilege management. You will work closely with Application Packaging, Endpoint Engineering, and Security teams to ensure the ongoing operation, optimisation, and enhancement of a complex EPM estate.

                  Candidates with significant CyberArk Endpoint Privilege Manager experience who are interested in cross-training into BeyondTrust EPM are also encouraged to apply.

                  Key Responsibilities

                  • Administer, support, and maintain a highly customised BeyondTrust EPM platform.
                  • Design, implement, and manage policies covering privilege elevation, application control, allow-listing, and endpoint security.
                  • Collaborate with Application Packaging and Endpoint Engineering teams to support application deployment and compatibility.
                  • Analyse application requirements and define appropriate privilege management solutions.
                  • Troubleshoot complex endpoint privilege management and application control issues.
                  • Develop, test, and deploy policy changes while maintaining operational stability and security.
                  • Support the on-boarding of new applications into the EPM environment.
                  • Investigate and resolve incidents relating to privilege elevation, application execution, and endpoint security controls.
                  • Work closely with infrastructure, packaging, and security teams to ensure seamless service delivery.
                  • Produce and maintain technical documentation, support procedures, and operational standards.
                  • Contribute to continuous improvement initiatives and platform optimisation activities.

                  Essential Skills & Experience

                  • Extensive hands-on experience with BeyondTrust Endpoint Privilege Management (EPM) administration and engineering.
                  • Strong understanding of Windows endpoint security architecture.
                  • Proven experience creating, modifying, and troubleshooting BeyondTrust EPM policies.
                  • Experience supporting application packaging and software deployment processes.
                  • Strong knowledge of:
                    • Windows Desktop Operating Systems
                    • Application Control
                    • Privilege Elevation
                    • Endpoint Security
                    • Software Packaging and Deployment
                    • Group Policy Administration
                  • Ability to analyse software requirements and design effective privilege management solutions.
                  • Experience supporting highly customised enterprise EPM environments.
                  • Excellent troubleshooting and root cause analysis skills.
                  • Experience working within secure, controlled, or highly regulated environments.
                  • Strong documentation and technical communication skills.
                  • Ability to work independently in a complex operational setting.

                  Desirable Skills

                  • Experience with CyberArk Endpoint Privilege Manager (EPM).
                  • Experience migrating between endpoint privilege management platforms.
                  • Knowledge of Microsoft Intune, MECM/SCCM, or similar endpoint management solutions.
                  • PowerShell scripting and automation experience.
                  • Experience supporting large-scale enterprise endpoint estates.
                  • Familiarity with ITIL-based operational environments.
                  • Experience working within secure facilities or restricted-access environments.

                  What’s Required?

                  To be considered for this opportunity, you must:

                  ✅ Be eligible for BPSS clearance
                  ✅ Be able to work 5 days per week onsite in Manchester or Inverness
                  ✅ Be available to participate in a 24×7 support rota

                  If you have strong BeyondTrust EPM expertise and are looking to work on a complex, enterprise-scale deployment within a secure environment, apply to be considered.

                  Reasonable Adjustments:

                  Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

                  If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

                  Apply for this Job

                    technology job

                    Security Assurance Manager

                    • Posted
                    • Inside IR35
                    • Bristol
                    • Permanent

                    Job Title

                    Security Assurance Manager

                    Office Location:

                    Flexible within UK offices

                    Start Date:

                    ASAP

                    End Date:

                    12 – 18 months from start

                    Pay rate per day:

                    £550 – £680 Inside IR35

                    Hours per week:

                    37.5

                    Active SC Clearance Required

                    Job Description:

                    Responsibilities

                    • Oversee and guide a team of consultants from the UK business who are fulfilling our cloud security assurance process for non-core cloud systems
                    • Maintain and implement our overall Secure Networks Security Assurance framework, including creation of protocols and processes as required.
                    • Maintain our secure network approvals including risk assessments, security arguments, and compliance statements against the DCPP Cyber Security Model (plus against other standards and control sets as required)
                    • Carry out and maintain security assessments for core Secure Networks cloud systems such as Microsoft 365
                    • Oversee Secure Networks elements of broader company certification to the Defence Cyber Certification
                    • Carry out compliance audits to ensure that the Secure Networks Team, local security contacts, and project teams are carrying out required assurance activities, both in our secure networks and for cloud systems
                    • Stay up to date with MOD and other regulatory guidance, and relevant commercial standards such as Microsoft 365 guidance, and incorporate the results into our Secure Networks security assurance approaches
                    • Provide security assurance guidance to the Secure Networks Team to review and influence the design and operation of our secure networks
                    • Periodically update the risk assessments for our secure networks, communicate implications to relevant stakeholders, and track progress against action items
                    • Stay up to date with the threat landscape affecting our secure networks, using a range of sources such as the corporate Threat Intelligence team
                    • Track progress made by a range of parties against security action plans
                    • Collaborate with, learn from and advise relevant internal stakeholders such as Global Security, Security Points of Contact, the Secure Networks Team, the UK business security managers, Security Controllers, corporate and UK project procurement, HR Vetting, project teams, and individual staff members seeking guidance e.g. for overseas working
                    • Liaise with relevant external stakeholders such as MOD CyDR
                    • Annually revise and reissue Security Operating Procedures for our secure networks and core Secure Networks cloud systems
                    • Support external security-related audits such as ISO27001 and by clients including MOD
                    • Oversee authorisations of third parties who will handle information from our secure networks or connect in to them, including both initial approval and ongoing maintenance
                    • Assess devices that require connection to our secure networks, for example point cloud scanners
                    • Maintain a co-ordinated programme for all security assurance activities to ensure they are delivered in a timely manner
                    • Arrange, report to, and provide advice and recommendations to Secure Networks Governance Committee meetings
                    • Report into the Office of the Chief Information Security Officer to provide confidence to them that our UK Secure Networks have adequate security assurance
                    • Carry out security assurance for key elements of the Secure Networks supply chain (hardware, software, services)
                    • Create and maintain infrastructure required to move the Security Assurance function from being an individual contact to a comprehensive standalone function, for example a group mailbox, a Team, communications methods, and site(s) for publication of Security Assurance policies, trackers, etc.

                    Required Skills & Qualifications

                    • A ‘completer finisher’, with an eye for detail.
                    • Demonstrable experience of working in cyber security in a UK MOD-related environment
                    • Strong familiarity with UK MOD security standards such as Def Stan 05-138 versions 3 and 4, the Cyber Security Model, Secure By Design, Industry Security Notices
                    • Strong familiarity with UK Government security standards such as 007/SPF, NCSC Cloud Security Principles, NCSC Principles for Using Software as a Service (SaaS) securely, Cyber Essentials, and the CHECK penetration testing scheme
                    • Broad familiarity with UK Government physical and personnel security such as NPSA and UKSV
                    • Risk assessment using recognised standards such as IS1 and NIST SP800-30
                    • Able to express yourself effectively, with a high degree of clarity, in English, especially when justifying and explaining required security measures
                    • Able to liaise effectively with a wide range of stakeholders, from senior leaders to technical IT staff
                    • Able to prioritise and manage your time to achieve multiple different tasks
                    • (Desirable) Familiarity with broader international security standards such as ISO27001, CMMC, and the NIST Cyber Security Framework (especially SP800-30 and SP800-53)
                    • (Desirable) Familiarity with UK nuclear regulations such as the ONR SyAPs
                    • Competent with Microsoft Word, Excel and PowerPoint

                    Reasonable Adjustments:

                    Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

                    If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

                    Apply for this Job