technology job

Security Assurance Manager

  • Posted August 12, 2026
  • Inside IR35
  • Bristol
  • Permanent

Job Title

Security Assurance Manager

Office Location:

Flexible within UK offices

Start Date:

ASAP

End Date:

12 – 18 months from start

Pay rate per day:

£550 – £680 Inside IR35

Hours per week:

37.5

Active SC Clearance Required

Job Description:

Responsibilities

  • Oversee and guide a team of consultants from the UK business who are fulfilling our cloud security assurance process for non-core cloud systems
  • Maintain and implement our overall Secure Networks Security Assurance framework, including creation of protocols and processes as required.
  • Maintain our secure network approvals including risk assessments, security arguments, and compliance statements against the DCPP Cyber Security Model (plus against other standards and control sets as required)
  • Carry out and maintain security assessments for core Secure Networks cloud systems such as Microsoft 365
  • Oversee Secure Networks elements of broader company certification to the Defence Cyber Certification
  • Carry out compliance audits to ensure that the Secure Networks Team, local security contacts, and project teams are carrying out required assurance activities, both in our secure networks and for cloud systems
  • Stay up to date with MOD and other regulatory guidance, and relevant commercial standards such as Microsoft 365 guidance, and incorporate the results into our Secure Networks security assurance approaches
  • Provide security assurance guidance to the Secure Networks Team to review and influence the design and operation of our secure networks
  • Periodically update the risk assessments for our secure networks, communicate implications to relevant stakeholders, and track progress against action items
  • Stay up to date with the threat landscape affecting our secure networks, using a range of sources such as the corporate Threat Intelligence team
  • Track progress made by a range of parties against security action plans
  • Collaborate with, learn from and advise relevant internal stakeholders such as Global Security, Security Points of Contact, the Secure Networks Team, the UK business security managers, Security Controllers, corporate and UK project procurement, HR Vetting, project teams, and individual staff members seeking guidance e.g. for overseas working
  • Liaise with relevant external stakeholders such as MOD CyDR
  • Annually revise and reissue Security Operating Procedures for our secure networks and core Secure Networks cloud systems
  • Support external security-related audits such as ISO27001 and by clients including MOD
  • Oversee authorisations of third parties who will handle information from our secure networks or connect in to them, including both initial approval and ongoing maintenance
  • Assess devices that require connection to our secure networks, for example point cloud scanners
  • Maintain a co-ordinated programme for all security assurance activities to ensure they are delivered in a timely manner
  • Arrange, report to, and provide advice and recommendations to Secure Networks Governance Committee meetings
  • Report into the Office of the Chief Information Security Officer to provide confidence to them that our UK Secure Networks have adequate security assurance
  • Carry out security assurance for key elements of the Secure Networks supply chain (hardware, software, services)
  • Create and maintain infrastructure required to move the Security Assurance function from being an individual contact to a comprehensive standalone function, for example a group mailbox, a Team, communications methods, and site(s) for publication of Security Assurance policies, trackers, etc.

Required Skills & Qualifications

  • A ‘completer finisher’, with an eye for detail.
  • Demonstrable experience of working in cyber security in a UK MOD-related environment
  • Strong familiarity with UK MOD security standards such as Def Stan 05-138 versions 3 and 4, the Cyber Security Model, Secure By Design, Industry Security Notices
  • Strong familiarity with UK Government security standards such as 007/SPF, NCSC Cloud Security Principles, NCSC Principles for Using Software as a Service (SaaS) securely, Cyber Essentials, and the CHECK penetration testing scheme
  • Broad familiarity with UK Government physical and personnel security such as NPSA and UKSV
  • Risk assessment using recognised standards such as IS1 and NIST SP800-30
  • Able to express yourself effectively, with a high degree of clarity, in English, especially when justifying and explaining required security measures
  • Able to liaise effectively with a wide range of stakeholders, from senior leaders to technical IT staff
  • Able to prioritise and manage your time to achieve multiple different tasks
  • (Desirable) Familiarity with broader international security standards such as ISO27001, CMMC, and the NIST Cyber Security Framework (especially SP800-30 and SP800-53)
  • (Desirable) Familiarity with UK nuclear regulations such as the ONR SyAPs
  • Competent with Microsoft Word, Excel and PowerPoint

Reasonable Adjustments:

Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

Apply for this Job

    technology job

    Cloud Vulnerability Lead

    • Posted
    • £600 - £650 per day
    • London - three times a week on site
    • Contract

    Cloud Vulnerability Lead

    Rate – £600 – £650 Inside IR35
    Duration – 6 months initial
    Location – London (3 days a week on site)

    We’re looking for a Cloud Vulnerability Lead to own and mature our cloud vulnerability management and CSPM capability across AWS and GCP.

    This role combines hands-on technical expertise with leadership responsibility. You’ll be the go-to SME for Qualys, ensuring the platform is being used effectively, while providing oversight of vulnerability management, cloud security posture and remediation activity across the organisation.

    You’ll also manage a small team and work closely with Cloud Engineering, Infrastructure and Security stakeholders to drive continuous improvement and reduce cloud security risk.

    Key Responsibilities

    • Lead the cloud vulnerability management and CSPM function across AWS and GCP.
    • Own and optimise the use of Qualys VMDR, CSAM, TotalCloud and CSPM capabilities.
    • Assess current processes, tooling and coverage, identifying opportunities to improve effectiveness and maturity.
    • Provide technical oversight of vulnerability prioritisation, remediation tracking and risk reporting.
    • Identify cloud misconfigurations, exposure risks and compliance gaps, driving remediation with key stakeholders.
    • Manage and develop a small team, providing technical guidance and support.
    • Produce metrics and reporting to demonstrate security posture and risk reduction.
    • Act as the senior point of contact for cloud vulnerability and posture management activities.

    Required Experience

    • Strong hands-on experience with Qualys VMDR, CSAM and CSPM.
    • Deep understanding of AWS and GCP security and cloud risk management.
    • Experience leading or improving vulnerability management and CSPM programmes.
    • Ability to balance technical delivery with oversight and governance responsibilities.
    • Previous experience managing or mentoring a small team.
    • Strong stakeholder engagement skills with the ability to influence technical and non-technical audiences.

    Reasonable Adjustments:

    Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

    If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

    Apply for this Job

      technology job

      Technical Engineering/Project Manager - SC Cleared - Inside

      • Posted August 11, 2026
      • £500 - £800 per day
      • Oxford - 1 day a week, requirement for international travel
      • Contract

      Technical Engineering/Project Manager x2 – Inside IR35 – SC Cleared

      • Location: Oxford – 1 day a week on-site
      • Travel: Some requirement for European travel (sporadic)
      • Rate: £500 – £800
      • IR35: Inside
      • Length: Initial 6-9 Months

      Sanderson G&D are seeking technical project managers with a background in hands-on engineering for a new deployment in the Public Sectors. The programme of work is highly technical, working with an organisation on the cutting edge delivering interesting and impactful work.

      This role requires strong governance, stakeholder confidence, and proficiency operating in structured, security conscious environments while maintaining pace of delivery and innovation working alongside Scientists and Engineers on deeply technical projects.

      Key Responsibilities

      • Manage the end-to-end project lifecycle of deeply technical projects – from pre-project planning, to mobilisation, delivery and closure. This includes risk identification, monitoring and mitigations; resourcing; performance reporting; and issue escalation.
      • Successful delivery of the project outcomes, ensuring high-quality outputs and alignment with client mission outcomes and organisational strategy.
      • Team building and leadership of multiple project teams.
      • Act as the primary point of contact on projects, developing and maintaining strong client and partner relationships to support project delivery and contribute to winning new business.
      • Deploy to customer locations when required to support the installation, configuration and operational handover of systems, including working independently on site with remote support from UK-based engineering teams.
      • Support end users in understanding, adopting and troubleshooting deployed systems, acting as a trusted on-site representative who can diagnose issues, gather feedback and coordinate effective resolution with engineering colleagues.
      • Contributing to the development and implementation of best practice frameworks and methodologies for project and programme management across the company.
      • Manage project budgets, including forecasting, cost tracking and escalation of financial risks.
      • Maintain full project compliance with applicable government regulations, standards and internal policies.

      Core Skills & Experience

      • Proven project management experience and delivery within Government and Defence.
      • Comfortable working independently in the field, including operational customer environments, with the judgement to make sound decisions while drawing on remote engineering support.
      • Hands-on technical confidence, ideally gained through an engineering, systems, field support or similarly practical technical background; you do not need to be a software engineer, but you should be comfortable getting close to the technology and resolving practical issues on site.
      • Formal project management credentials such as APM Qualification, PRINCE2 or equivalent.
      • Strong stakeholder engagement and communication skills.
      • Ability to present complex information in clear, accessible formats.
      • Experience managing resources and mentoring multidisciplinary teams.

      Reasonable Adjustments:

      Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

      If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

      Apply for this Job

        technology job

        Security Architect - SC Cleared - Inside IR35

        • Posted
        • £600 - £700 per day
        • Very flexible, remote first with ad-hoc travel to Croydon/London
        • Contract

        Security Architect – SC Cleared – Inside IR35

        • Location: London
        • Type: Home based with occasional travel to London or Croydon
        • Rate: £600 – £700
        • Status: Inside
        • Length: Initial 6 months

        Role Overview

        The Security Architect will validate and complete the security architecture for the programme, ensuring designs are Secure by Design, supported by discovery-phase outputs, and taken through to verified high-level and low-level designs ahead of beta.

        Key Responsibilities

        • Verify and develop security architectural artefacts, including high-level and low-level designs, building on discovery-phase outputs, using programme architecture tooling, aligning to governance processes and developing Secure by Design (SbD) artefacts
        • Identify and close gaps in discovery outputs required to complete security designs
        • Engage directly with programme stakeholders and the wider community to gather information, run options analysis, workshop solutions and analyse documentation
        • Engage with the PPPT and wider Home Office security community to ensure solutions are compliant and informed by wider Home Office knowledge and experience
        • Develop security architectural artefacts compliant with programme and wider organisational standards, including Secure by Design processes
        • Validate security options and recommendations through programme peer engagements, design forums and technical design authorities
        • Work hands-on with alpha-phase development and DevOps resources to explain agreed architectures and incorporate feedback as architectures evolve
        • Support requirements development for future procurements and development activity, informed by discovery and alpha-phase hypothesis testing

        Required Skills & Experience

        • Security architecture delivery across large, complex IT landscapes in a regulated, critical environment
        • Broad experience across security architecture styles (e.g. cloud, distributed, monolithic)
        • A pragmatic approach to picking up architecture work started by previous resources, quickly assessing what is needed and driving to conclusions
        • Excellent stakeholder management, including influencing senior stakeholders and negotiating contentious architectural issues to reach consensus
        • Experience managing and recording key design decisions
        • Good understanding of programme reference architecture and governance processes
        • Able to manage people, navigate conflict, problem-solve, distil key discussion points, organise work and communicate effectively

        Reasonable Adjustments:

        Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

        If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

        Apply for this Job

          technology job

          Cyber Security Operations Specialist

          • Posted
          • £500 - £550 per day
          • Twice a week on site into Bristol
          • Contract

          Cyber Security Operations Specialist

          Rate – £500 – £550 Inside IR35
          Duration – 6 months
          Location – Bristol – twice a week on site

          A major organisation is seeking a Cyber Security Operations Specialist to join its Security Operations team.

          This is a hands on role focused on incident response, threat detection, vulnerability management and continuous improvement across enterprise technology environments. You’ll be expected to hit the ground running, managing security alerts, investigations, tickets and operational queues while helping improve the effectiveness of the security tooling estate.

          The Role

          • Monitor, investigate and respond to cyber security incidents.
          • Manage and triage security alerts, tickets and operational queues.
          • Lead or support incident response activities through to resolution.
          • Support vulnerability management and remediation activities.
          • Apply threat intelligence to strengthen detection and response capabilities.
          • Develop and optimise SIEM detections, alerting rules and response workflows.
          • Improve the performance and effectiveness of security platforms rather than simply operating them.
          • Produce clear incident reports and recommendations.
          • Work closely with teams across the business to explain risks, security controls and operational blockers.
          • Build strong relationships with both technical and non technical stakeholders to drive security improvements.

          Technology Environment

          Experience with the following is highly desirable:

          • Microsoft Defender
          • Microsoft Sentinel
          • Microsoft Purview
          • Proofpoint
          • SIEM, EDR and related security technologies

          About You

          You’ll have a strong background in Security Operations and Incident Response, with hands on experience working with Microsoft security technologies and enterprise security tooling. You’ll be comfortable managing multiple priorities, working through investigations and security queues, and responding effectively to incidents as they arise.

          We’re looking for someone who can quickly become a key contributor to the team, bringing experience in vulnerability management, threat intelligence and detection engineering. You’ll enjoy improving platforms, processes and controls, identifying opportunities to strengthen security capability and driving measurable improvements across the environment.

          Strong communication skills are essential. You’ll be confident engaging with stakeholders at all levels, translating technical issues into business language and helping teams understand security requirements without creating unnecessary friction.

          This is an excellent opportunity for a security professional who combines strong technical capability with a collaborative approach and a genuine passion for improving cyber security operations.

          Reasonable Adjustments:

          Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

          If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

          Apply for this Job

            technology job

            Security Engineer

            • Posted
            • £500 - £600 per day
            • Surrey - twice a week on site
            • Contract

            Web & API Security Engineer (Akamai)

            Rate – £500 – £600 Inside IR35
            Duration – 6 months initial
            Location – Surrey – Twice a week on site

            We’re supporting a major organisation looking for a Cyber Security Engineer to join its growing security team.

            You’ll play a key role in protecting customer facing applications, APIs and internet facing services, taking ownership of web and API security controls while helping to strengthen the organisation’s overall security posture.

            Key Responsibilities

            • Manage and optimise Akamai WAAP configurations, WAF policies, security rules and exceptions.
            • Tune controls to improve protection and reduce false positives.
            • Identify vulnerabilities and drive remediation activities.
            • Support the wider cyber security strategy and security improvement initiatives.
            • Work closely with Security Engineering, SOC, Architecture and Infrastructure teams.
            • Present security recommendations to technical and senior stakeholders.
            • Support audit and compliance activities, including remediation of audit findings.
            • Contribute to security projects from design through to implementation.

            About You

            • Strong Cyber Security background with hands on security engineering experience.
            • Proven experience administering Akamai WAAP.
            • Strong knowledge of WAF policy tuning, API security controls and application onboarding.
            • Good understanding of OWASP Top 10 and OWASP API Security Top 10.
            • Knowledge of HTTP/S, REST APIs and application layer attack mitigation.
            • Experience with vulnerability management, Qualys and attack surface monitoring tools.
            • Understanding of patch management and vulnerability remediation.
            • Strong stakeholder engagement and communication skills.

            Reasonable Adjustments:

            Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

            If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

            Apply for this Job

              technology job

              Security Architect (Zero Trust) - DV Cleared

              • Posted
              • £70000 - £85000 per annum + Bonus + Benefits
              • Farnborough
              • Permanent

              Security Architect – Zero Trust – DV Cleared

              • Location: Farnborough, Hampshire, UK
              • Employment Type: Permanent, Full-Time
              • Security Clearance: Developed Vetting (DV) – Essential
              • Salary: £70,000 – £85,000 + Benefits

              About the Role We are seeking a highly experienced Security Architect with a strong focus on Zero Trust Architecture (ZTA) to design, implement and evolve secure enterprise environments. You will lead security transformation initiatives, develop enterprise-wide security strategies, and implement identity-centric security architectures aligned with modern Zero Trust principles. This role requires deep expertise across identity, cloud, infrastructure and cyber security domains, ensuring organisations remain resilient against evolving cyber threats whilst meeting security requirements.

              Key Responsibilities Zero Trust Strategy & Architecture

              • Define and deliver enterprise-wide Zero Trust strategies and roadmaps
              • Design Zero Trust architectures aligned to NIST 800-207 principles
              • Implement identity-first security models across users, devices, applications and data
              • Develop continuous verification and adaptive access control frameworks
              • Lead micro-segmentation and least privilege initiatives across enterprise environments

              Security Strategy & Architecture

              • Design holistic security architectures incorporating people, process and technology security
              • Develop enterprise-wide security strategies aligned with and Defence Security Policy requirements
              • Architect defence-in-depth security solutions across network, cloud, endpoint and application layers
              • Lead security architecture reviews and technical security assessments
              • Develop security standards, reference architectures and design patterns

              Identity & Access Management

              • Architect and implement enterprise IAM, MFA and Single Sign-On solutions
              • Design Conditional Access and Privileged Access Management (PAM) capabilities
              • Lead identity governance and administration initiatives
              • Develop secure authentication and authorisation frameworks
              • Ensure access management aligns with Zero Trust and least privilege principles

              Cyber Threat & Risk Management

              • Assess cyber threat landscapes and design threat-informed security architectures
              • Lead security risk assessments and vulnerability management programmes
              • Design incident response, threat intelligence and cyber defence capabilities
              • Architect security monitoring, detection and response solutions
              • Develop cyber resilience and business continuity frameworks

              Cloud & Security Solutions

              • Design cloud security architectures across Azure, AWS and hybrid environments
              • Architect endpoint protection, DLP and advanced threat protection solutions
              • Design application security, API security and secure SDLC integration
              • Architect Security Operations Centre (SOC) and SIEM capabilities
              • Lead security technology evaluation, selection and implementation programmes

              Technical Leadership & Governance

              • Lead security technical teams and provide architectural mentoring
              • Establish security design standards, architecture patterns and governance processes
              • Drive technical decision-making through security design reviews
              • Document security architecture decisions and design specifications
              • Support organisational security transformation programmes

              Customer & Stakeholder Engagement

              • Act as the subject matter expert for Security Architecture and Zero Trust initiatives
              • Present security recommendations to senior leadership and programme stakeholders
              • Lead architecture workshops and customer engagement activities
              • Communicate complex security concepts to both technical and non-technical audiences

              Essential Requirements Experience & Expertise

              • Minimum 10 years’ experience within Cyber Security and Information Security
              • At least 5 years’ experience in a Security Architect position
              • Proven experience delivering enterprise-scale Zero Trust transformation programmes
              • Strong background within defence, aerospace, government or highly regulated sectors
              • Experience leading security transformation and modernisation initiatives

              Technical Knowledge

              • Deep expertise in Zero Trust Architecture principles and implementation methodologies
              • Strong knowledge of NIST 800-207 and modern security architecture frameworks
              • Expert understanding of Identity & Access Management technologies
              • Experience with Microsoft Entra ID, Conditional Access, PIM and PAM solutions
              • Strong understanding of network security, micro-segmentation and secure access technologies
              • Proficiency in cloud security across Azure, AWS or equivalent platforms
              • Knowledge of security technologies including SIEM, EDR/XDR, DLP, CASB, ZTNA, WAF and firewalls
              • Understanding of cryptography, encryption standards and secure communication protocols
              • Familiarity with MOD security requirements, defence standards and accreditation processes
              • Knowledge of ISO 27001, NIST CSF and CIS Controls frameworks

              Personal Attributes

              • Exceptional strategic thinking combined with strong technical depth
              • Outstanding communication and stakeholder engagement skills
              • Strong problem-solving and analytical capabilities
              • Proven ability to influence technical teams and executive stakeholders
              • Passion for cyber security innovation and continuous improvement

              Desirable Requirements

              • Experience delivering Microsoft Zero Trust programmes
              • CISSP, CISM, SABSA, TOGAF or equivalent industry certifications
              • Microsoft Cybersecurity Architect Expert certification
              • AWS Security Specialty or Azure Security Engineer certification
              • Experience implementing SASE, SSE or ZTNA technologies
              • Knowledge of ITAR compliance and export controls
              • Previous DV or SC Clearance
              • Armed Forces, Defence or National Security background

              What We Offer

              • Highly competitive salary and comprehensive benefits package
              • Enhanced pension and private medical insurance
              • Flexible and hybrid working options
              • Professional development and industry certification support
              • Opportunity to lead strategic Zero Trust transformation programmes
              • Exposure to mission-critical defence and national security projects

              Reasonable Adjustments:

              Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

              If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

              Apply for this Job

                technology job

                Security Architect - DV Cleared

                • Posted
                • Bonus + Benefits
                • Farnborough
                • Permanent

                Security Architect – DV Cleared

                • Location: Farnborough, Hampshire, UK
                • Employment Type: Permanent, Full-Time
                • Security Clearance: Developed Vetting (DV) – Essential
                • Salary: £70,000 – £85,000 + Benefits

                About the Role

                The Security Architect designs and implements comprehensive security architectures protecting defence and aerospace IT environments. You will develop enterprise security strategies, lead security programme implementations, architect integrated defence-in-depth solutions, and ensure compliance with stringent MOD security requirements. This role demands exceptional expertise in security architecture, risk management and defence security standards.

                Key Responsibilities

                Security Strategy & Architecture

                • Design holistic security architectures incorporating people, process and technology security
                • Develop enterprise-wide security strategies aligned with Defence Security Policy
                • Architect defence-in-depth security solutions across network, application, data and endpoint layers
                • Lead security architecture reviews and technical security assessments
                • Design zero-trust security models and continuous verification frameworks

                Cyber Threat & Risk Management

                • Assess cyber threat landscape and design threat-informed security architectures
                • Lead security risk assessments and vulnerability management programmes
                • Design incident response, threat intelligence and cyber defence capabilities
                • Architect security monitoring, detection and response solutions
                • Design business continuity and cyber resilience frameworks

                Compliance & Standards Implementation

                • Ensure security architectures comply with MOD security requirements and ITAR regulations
                • Design security solutions supporting Information Security Management System (ISMS) compliance
                • Architect compliance and audit capabilities for regulatory reporting
                • Lead security standards implementation and controls frameworks

                Security Solutions & Integration

                • Architect endpoint protection, data loss prevention (DLP) and advanced threat protection solutions
                • Design cloud security architectures supporting hybrid and multi-cloud environments
                • Architect application security, API security and secure SDLC integration
                • Design security operations centre (SOC) capabilities and security information and event management (SIEM)
                • Lead security technology evaluation and implementation programmes

                Technical Leadership & Governance

                • Lead security technical teams and provide architectural mentoring
                • Establish security design standards, architecture patterns and operational governance
                • Drive technical decision-making through security design reviews
                • Document security architecture decisions and design specifications

                Customer & Stakeholder Engagement

                • Serve as technical authority for security architecture discussions with customer leadership
                • Present security recommendations to defence programme teams and executive stakeholders
                • Lead security architecture workshops and customer engagement activities
                • Communicate complex security concepts to technical and non-technical audiences

                Essential Requirements

                Experience & Expertise

                • Minimum 12 years’ information security experience with 5+ years in architecture role
                • Proven experience designing enterprise-scale security architectures
                • Strong background in defence, aerospace or government security programmes
                • Demonstrated expertise with security operations, incident response and threat management
                • Track record of leading security transformation and programme implementations

                Technical Knowledge

                • Deep expertise in security architecture frameworks, methodologies and best practices
                • Expert-level knowledge of network security, endpoint security and application security
                • Strong understanding of threat models, attack vectors and defence-in-depth strategies
                • Proficiency in cloud security (AWS, Azure security, or equivalent)
                • Knowledge of security tools (SIEM, DLP, EDR, WAF, firewalls, etc.)
                • Understanding of cryptography, encryption and security protocols
                • Familiarity with MOD security requirements, Classification Guides and defence standards
                • Knowledge of compliance frameworks (ISO 27001, NIST CSF, etc.)

                Personal Attributes

                • Exceptional strategic thinking combined with strong technical depth
                • Outstanding communication and stakeholder engagement skills
                • Strong problem-solving and analytical capabilities
                • Proven ability to lead technical teams and influence executive stakeholders
                • Passion for security excellence and continuous improvement

                Desirable Requirements

                • Experience with defence or aerospace security programmes
                • CISSP, CISM, CCSK or equivalent security certifications
                • AWS Security or Azure Security certifications
                • Experience with security governance and compliance frameworks
                • Knowledge of ITAR compliance and export controls
                • Armed Forces or military security background

                What We Offer

                • Highly competitive salary and comprehensive benefits package
                • Enhanced pension and private medical insurance
                • Flexible working and professional development support
                • Opportunity to architect security for mission-critical defence organisations

                Reasonable Adjustments:

                Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

                If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

                Apply for this Job

                  technology job

                  SOAR Engineer

                  • Posted August 10, 2026
                  • £80000 - £100000 per annum
                  • Remote with occasional site visits
                  • Permanent

                  SOAR/SIEM Security Engineer – Critical National Infrastructure (OT)
                  18-Month FTC | SC Cleared

                  A leading cyber security firm is looking for a SOAR/SIEM Security Engineer to join a critical national infrastructure (CNI) client on an 18-month fixed-term contract, supporting the protection of operational technology (OT) environments that underpin essential national services.

                  This is a high-visibility role within a security operations function tasked with detecting, responding to, and automating defence against threats across converged IT/OT infrastructure. You’ll be working on live, high-stakes environments.

                  What you’ll be doing

                  • Designing, building, and maintaining SOAR playbooks to automate detection and response workflows
                  • Developing and tuning Splunk use cases, dashboards, and correlation searches across IT and OT data sources
                  • Supporting incident detection and response within CNI/OT environments, working closely with engineering and safety teams
                  • Contributing to the maturity of security monitoring across converged industrial and enterprise networks
                  • Working within a team that understands the unique constraints of OT – availability, safety, and legacy systems – versus traditional IT security

                  What you’ll need

                  • Active SC clearance
                  • Proven experience working within CNI or OT environments
                  • Strong hands-on experience with SOAR platforms and Splunk
                  • A solid grasp of the differences between securing OT and IT – this isn’t a generic SOC role
                  • Comfortable operating in a live, high-consequence environment where good judgement matters as much as technical skill

                  The contract

                  • 18-month FTC
                  • Strong potential for extension or conversion to a permanent role further down the line (not guaranteed, but a realistic prospect based on programme trajectory)

                  Reasonable Adjustments:

                  Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

                  If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

                  Apply for this Job

                    technology job

                    IDAM Architect - DV Cleared - Perm

                    • Posted August 7, 2026
                    • £70000 - £85000 per annum + Benefits
                    • Farnborough
                    • Permanent

                    IDAM Architect – DV Cleared

                    • Location: Farnborough, Hampshire, UK
                    • Employment Type: Permanent, Full-Time
                    • Security Clearance: Developed Vetting (DV) – Essential
                    • Salary: £70,000 – £85,000 + Benefits

                    About the Role

                    The IDAM (Identity, Access and Data Management) Architect designs, governs and implements enterprise-scale identity and access management solutions for defence and aerospace environments. You will architect secure authentication, authorisation and identity governance frameworks, lead IDAM modernisation programmes, and ensure compliance with stringent defence security and regulatory requirements. This role demands deep expertise in identity platforms, security architecture and MOD-compliant IDAM design.

                    Key Responsibilities

                    IDAM Architecture & Strategy

                    • Design enterprise-scale identity and access management architectures supporting defence operations
                    • Architect secure authentication, multi-factor authentication (MFA) and authorisation frameworks
                    • Design role-based access control (RBAC), attribute-based access control (ABAC) and privilege access management (PAM) solutions
                    • Develop identity governance, access lifecycle management and entitlement management strategies
                    • Lead IDAM technology evaluation and vendor selection processes

                    Security & Compliance

                    • Ensure IDAM architectures comply with MOD Classification Guides, Defence Security Policy and ITAR regulations
                    • Design identity solutions supporting defence contractor personnel vetting (PRF) requirements
                    • Architect data protection and encryption strategies aligned with defence security standards
                    • Lead security risk assessments for IDAM systems and vulnerabilities
                    • Design audit and logging capabilities supporting MOD compliance and forensic requirements

                    IDAM Modernisation & Implementation

                    • Lead design and implementation of modern IDAM platforms (AD/Azure AD, Okta, Ping, ForgeRock)
                    • Design cloud-ready and hybrid identity solutions supporting multi-cloud environments
                    • Guide API-driven identity architecture and microservices-based identity solutions
                    • Lead IDAM system migrations and technology modernisation programmes

                    Technical Leadership & Governance

                    • Lead IDAM technical teams and provide architectural mentoring
                    • Establish IDAM design standards, architecture patterns and operational governance
                    • Drive technical decision-making through IDAM design reviews
                    • Document IDAM architecture decisions and design specifications

                    Integration & Operations

                    • Design IDAM integration with enterprise applications, systems and cloud platforms
                    • Architect identity federation, single sign-on (SSO) and cross-domain authentication
                    • Support IDAM operational readiness, performance monitoring and incident response
                    • Establish IDAM lifecycle management and continuous improvement processes

                    Customer & Stakeholder Engagement

                    • Serve as technical authority for IDAM architecture discussions with customer leadership
                    • Present identity and access management recommendations to defence programme teams
                    • Lead IDAM design workshops and customer validation activities

                    Essential Requirements

                    Experience & Expertise

                    • Minimum 12 years’ identity and access management experience with 5+ years in architecture role
                    • Proven experience designing enterprise-scale IDAM solutions
                    • Strong background in defence, aerospace or government IDAM programmes
                    • Demonstrated expertise with modern identity platforms (Azure AD, Okta, Ping, ForgeRock)
                    • Track record of leading IDAM modernisation and technology transformation programmes

                    Technical Knowledge

                    • Deep expertise in IDAM architecture patterns, methodologies and best practices
                    • Expert-level knowledge of identity technologies including LDAP, Active Directory, OAuth, SAML and OpenID Connect
                    • Strong understanding of Azure AD, Office 365 identity, hybrid identity and cloud-native identity solutions
                    • Proficiency in privilege access management (PAM), role/attribute-based access control (RBAC/ABAC)
                    • Knowledge of identity governance, access certification and entitlement management
                    • Expertise in API security, service-to-service authentication and microservices identity
                    • Familiarity with MOD security requirements, Classification Guides and defence compliance
                    • Understanding of cryptography, encryption and security protocols

                    Personal Attributes

                    • Exceptional strategic thinking with strong technical depth
                    • Outstanding communication and stakeholder engagement skills
                    • Strong problem-solving and analytical capabilities
                    • Proven ability to lead technical teams and influence senior stakeholders
                    • Commitment to security and compliance excellence

                    Desirable Requirements

                    • Experience with defence or aerospace IDAM programmes
                    • CISSP, CISM or equivalent security certifications
                    • Azure AD or Okta advanced certifications
                    • Experience with identity-driven security and zero-trust architecture
                    • Knowledge of ITAR compliance and export controls

                    Reasonable Adjustments:

                    Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

                    If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

                    Apply for this Job