Information Security Jobs in the Thames Valley

1 to 25 of 163 Information Security Jobs in the Thames Valley

Cyber Security Engineer

Milton Keynes, Buckinghamshire, South East, United Kingdom
Hybrid / WFH Options
In Technology Group Limited
Job Title: Cyber Security Engineer Location: Milton Keynes (hybrid- 2 days onsite) Industry: Financial Services Salary: £40,000-50,000 per annum Overview: We are seeking a skilled and proactive Cyber Security Engineer to join our growing Information Security team at a leading finance company based in Milton Keynes. In this role, you will be responsible … for designing, implementing, and maintaining robust cyber security measures to protect our systems, data, and infrastructure against emerging threats. Key Responsibilities: Monitor, detect, and respond to security incidents and threats in real-time. Design and implement security solutions and controls, including firewalls, intrusion detection/prevention systems (IDS/IPS), and endpoint protection. Perform regular vulnerability assessments … risk analysis. Collaborate with IT and development teams to ensure secure system architecture and application development. Maintain and enhance incident response procedures and disaster recovery plans. Investigate and document security breaches, providing root cause analysis and remediation plans. Conduct security awareness training for staff and ensure compliance with internal policies and regulatory requirements (e.g., FCA, GDPR, ISO More ❯
Employment Type: Permanent
Salary: £50,000
Posted:

Chief Information Security Officer

Slough, England, United Kingdom
Hybrid / WFH Options
JR United Kingdom
Social network you want to login/join with: Chief Information Security Officer, slough col-narrow-left Client: SR2 | Socially Responsible Recruitment | Certified B Corporation Location: slough, United Kingdom Job Category: Other - EU work permit required: Yes col-narrow-right Job Views: 3 Posted: 26.06.2025 Expiry Date: 10.08.2025 col-wide Job Description: Chief Information Security Officer … CISO) ? Location: London (Hybrid Working Model) ? Salary: Competitive + Bonus + Equity Options ? Type: Full-time, Permanent About the Role Chief Information Security Officer (CISO) to join a fast-scaling, high-impact organisation in the heart of London. This is a strategic, foundational hire —you will be responsible for designing and building out a brand-new Governance, Risk … GRC) function from the ground up. As the company continues to grow, the need for a comprehensive and mature cybersecurity posture has never been greater. You will own the security vision and strategy while rolling up your sleeves to implement, scale, and continually improve our approach to GRC, risk management, threat mitigation, and compliance frameworks. Key Responsibilities Design and More ❯
Posted:

IT Security Analyst

Gerrards Cross, England, United Kingdom
Causeway
IT Security Analyst Hybrid (UK) Do you want to play a key role in securing customer trust and supplier integrity at a market-leading construction software company? At Causeway, we’re looking for a highly organised, detail-driven Information Security Analyst to support our customer assurance processes and lead our third-party risk management efforts. Who Are … a variety of backgrounds, skills, and views. Creating a culture of equality isn’t just the right thing to do, it improves every aspect of our business. Purpose As Information Security Analyst, you will be a strategic contributor supporting business development and security operations. You'll manage customer-facing security questionnaires, ensuring timely and accurate responses … and drive the Third-Party Due Diligence (TPDD) programme to evaluate and monitor supplier security posture. Your work will help reduce risk exposure, maintain compliance, and uphold Causeway’s reputation as a trusted technology provider. Responsibilities Customer Compliance Own and manage responses to security-based customer questionnaires (SIG, CAIQ, bespoke). Work cross-functionally with Legal, Compliance, Security More ❯
Posted:

SOC Tier 3 Analyst

Reading, England, United Kingdom
Hybrid / WFH Options
Focus on SAP
Full time Start: ASAP Location: Reading – Hybrid Languages: English We are seeking an experienced and highly capable SOC Tier 3 Analyst to serve as a senior member of our Security Operations Center (SOC). You will lead advanced incident response efforts, conduct proactive threat hunting, perform digital forensics, and collaborate cross-functionally to safeguard our digital assets and infrastructure. … Threat Hunting & Analysis Proactively identify emerging threats through behavioral analytics and threat intelligence. Analyze log data, network activity, and endpoints to uncover hidden anomalies or malicious behavior. Partner with security engineering teams to build detection capabilities based on evolving threats. Digital Forensics & Investigation Conduct detailed forensic investigations to determine incident scope, root cause, and impact. Collect and preserve digital … and support threat blocking strategies. Collaboration & Knowledge Sharing Mentor junior SOC analysts and share knowledge across incident response workflows. Engage with stakeholders across IT, DevOps, and legal to enhance security posture. Contribute to post-incident reviews and continuous process improvement. Security Research & Intelligence Stay ahead of industry developments, vulnerabilities, and attacker methodologies. Create detection rules and playbooks to More ❯
Posted:

SOC Tier 3 Analyst

Reading, England, United Kingdom
Hybrid / WFH Options
Focus on SAP
Full time Start: ASAP Location: Reading – Hybrid Languages: English We are seeking an experienced and highly capable SOC Tier 3 Analyst to serve as a senior member of our Security Operations Center (SOC). You will lead advanced incident response efforts, conduct proactive threat hunting, perform digital forensics, and collaborate cross-functionally to safeguard our digital assets and infrastructure. … Threat Hunting & Analysis Proactively identify emerging threats through behavioral analytics and threat intelligence. Analyze log data, network activity, and endpoints to uncover hidden anomalies or malicious behavior. Partner with security engineering teams to build detection capabilities based on evolving threats. 🔬 Digital Forensics & Investigation Conduct detailed forensic investigations to determine incident scope, root cause, and impact. Collect and preserve digital … and support threat blocking strategies. 🤝 Collaboration & Knowledge Sharing Mentor junior SOC analysts and share knowledge across incident response workflows. Engage with stakeholders across IT, DevOps, and legal to enhance security posture. Contribute to post-incident reviews and continuous process improvement. 📚 Security Research & Intelligence Stay ahead of industry developments, vulnerabilities, and attacker methodologies. Create detection rules and playbooks to More ❯
Posted:

Global Head of Information Security and Data Protection

Oxford, England, United Kingdom
Oxfam
Global Head of Information Security and Data Protection Join to apply for the Global Head of Information Security and Data Protection role at Oxfam Global Head of Information Security and Data Protection 3 days ago Be among the first 25 applicants Join to apply for the Global Head of Information Security and … role at Oxfam Oxfam is a global movement of people working together to end the injustice of poverty. Are you a visionary leader with a passion for safeguarding sensitive information on a global scale? Do you have the technical expertise to develop and implement leading information security and data protection strategies that ensure compliance and security? Can you inspire teams to prioritise information security in an ever-evolving digital landscape? The Role Oxfam GB is looking for a global Head of Information Security and Data Protection that will lead the Cybersecurity, Data Protection, and Information Governance teams to manage risk across these areas, while maintaining compliance to with necessary regulations More ❯
Posted:

Technical Cyber Risk Assessment Manager

Reading, Berkshire, United Kingdom
Hybrid / WFH Options
Deloitte LLP
practices and the ability to conduct technical risk assessments. Work with the Global Technology Infrastructure team to integrate system cybersecurity assessments into their processes to ensure consistent implementation of security controls. Work with the Cybersecurity Architecture team and apply reference architectures for security solutions design and implementation. Work with the Cyber Defense group and the Security Operations … Center to evaluate the effectiveness of the security controls and architectures in relationship to actual intrusions seen on the Deloitte network, reported threats at peer organizations, and overall cybersecurity threats in the internet ecosystem and you will notify leadership of potential or existing threats and assist in the development of risk mitigating strategies of these items. Monitor security blogs, articles, and reports and remain current on related laws, regulations, and industry standards to keep up to date on the latest security risks, threats, and technology trends and, where relevant, notify leadership to incorporate information into processes, procedures, and audit preparedness activities. Perform technology security risk assessments. Where appropriate, leverage security shared services (VRA More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Senior Security Architect - NESO

Wokingham, Berkshire, United Kingdom
Hybrid / WFH Options
National Grid plc
build on this momentum, advancing the National Energy System Operator's (NESO) plan for zero carbon operability of the electricity system by 2025. We are seeking an experienced Senior Security Architect to work across all programme workstreams, reporting to the Enterprise Security Architect. This role involves designing secure solutions fit for the future, ensuring NESO's long-term … success. The Senior Security Architect will not only be hands-on when designing architectures, reviewing proposals, designs, and preparing documentation but will also support the Enterprise Security Architect by ensuring that the overall security strategy and policies are considered throughout the design and build process. The Senior Security Architect will play a crucial role in promoting … collaboration among various teams, eliminating siloed workflows, and integrating secure design principles along with other critical security protocols across different stages of the delivery lifecycle. In this role, you will regularly attend the Security Architecture Group meetings, contributing to the development of essential architecture strategies and patterns for NESO. Building and managing relationships with the business is key More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Security programme Manager

Reading, Berkshire, United Kingdom
Primark Stores Limited
office. Purpose of the Role Primark Technology is on a transformation journey supporting the business strategy which includes modernising our operating model as well as technology architecture and Cyber Security and Risk posture. This role is key in building and improving Primark's Cyber Security posture. Duties & Responsibilities Actively progress and improve Primark's cyber security posture … and Agile delivery methodology and development methods Certified with appropriate qualifications is desirable, 1. Structured Project Management : Prince/PMP 2. Agile certification, such as Scrum, SaFe, AgilePM 3. Information Security/Data Protection certification An appropriate degree, equivalent qualification or experience Desirable Be a passionate and visionary technologist able to inspire others to challenge and disrupt the … ways to translate that into business opportunities. Be able to take people along with you, empowering new ways of working and successfully executing on those opportunities. Have extensive cyber security delivery and programme/project management experience, Retail experience would be beneficial. Be technically strong across a range of IT disciplines and systems, including cloud and network security. Have More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Cyber Vulnerability Management Analyst

Slough, England, United Kingdom
Hybrid / WFH Options
JR United Kingdom
days in the office and 2 days working from home. Key Responsibilities: In this fixed term contract role, you will be part of the team supporting the IT & Cyber Security Manager to plan and deliver our business strategy in line with our long-term goals. The role of Cyber Vulnerability Management Analyst is to deal with all remediation work … of cloud technologies such as Azure/Amazon Web Services and Oracle Cloud Infra is essential. Key Skills/Experience: Essential: Bachelor’s degree, preferably in Computer Science, Cyber Security or Cyber Security Professional Qualifications/Certifications Desirable: General understanding of IT Security principles, standards and regulations (e.g. ISO 27001, NIST, CIS, PCI DSS and GDPR) CISM … scoring systems (CVSS/CMSS) Incident/Response & Forensic Management Skills IT Technical Admin Support - Azure, Oracle Cloud Infrastructure (OCI Cloud) Microsoft Windows Support & administration, CE+, ISO27001 Email and Information Security Filtering/Monitoring Solutions, Egress Hands on experience on Linux and Mac Administration Support Good understanding of Windows and Linux patching In return we offer a fantastic More ❯
Posted:

Global Head of Information Security and Data Protection

Oxford, Oxfordshire, United Kingdom
Oxfam
Oxfam is a global movement of people working together to end the injustice of poverty. Are you a visionary leader with a passion for safeguarding sensitive information on a global scale? Do you have the technical expertise to develop and implement leading information security and data protection strategies that ensure compliance and security? Can you inspire … teams to prioritise information security in an ever-evolving digital landscape? The Role: Oxfam GB is seeking a Head of Information Security and Data Protection to lead the Cybersecurity, Data Protection, and Information Governance teams. This role involves managing risks across these areas, ensuring compliance with relevant regulations and control frameworks, and coordinating information security efforts across the wider Oxfam confederation to protect its reputation and systems. Reports to: Chief Transformation Officer Direct reports: Information Security Manager, Data Protection Manager, Data Protection Officer, Information Governance Lead What we are looking for: We seek a candidate who is committed to Oxfam's mission to end poverty and aligns with our More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

NETWORK & SECURITY ADMINISTRATOR - RFX 607

Reading, England, United Kingdom
Zensar Technologies
Job Description Profile IT Specialist - Network and Security administrator Required Education and Certification - - First-level university degree in Computer Science. Information Technology, Engineering, or related field. - Cisco Certified Network Associate - Check Point Certified Security Administrator - Zscaler Certifications - Cisco Certified Network Professional - CISSP - Certified Information Systems Security Professional Required Skills Set - - Excellent understanding of routing and … Software Defined Access. - Excellent knowledge of SASE/Zero-Trust Network Access (ZTNA) principles. - Excellent understanding of Remote Access Service and Application Delivery technologies. - Good working knowledge of the Information Technology Infrastructure Library (ITIL) framework. - Excellent analytical and problem-solving skills. - Flexibility and team spirit. Ability to work quickly and accurately under pressure. - Excellent communication and interpersonal skills and … sensitivity and respect for diversity. - Competent user of Microsoft Office applications (Word, Excel, Outlook, PowerPoint) and the Internet, with the ability to quickly learn and use new software and information management tools. - Fluent professional English (spoken and written, CEFR C1+) Desirable Skills Set - - Thorough understanding of network security technologies (Check Point, Palo Alto, Cisco ASA, Fortinet) - Proficient in More ❯
Posted:

Senior Manager Information Security

Slough, England, United Kingdom
JR United Kingdom
Social network you want to login/join with: Senior Manager Information Security, Slough Client: Location: Slough, United Kingdom Job Category: Other - EU work permit required: Yes Job Views: 5 Posted: 26.06.2025 Expiry Date: 10.08.2025 Job Description: La Fosse has partnered with a well-established financial services organisation. They are looking for their first Information Security Senior Manager. This is a newly created role to lead and own the organisation’s security capability. You’ll be the go-to person for all things security – managing policy and risk, aligning to ISO27001, CE+ and DORA. There’s strong executive buy-in, a healthy security budget, and a clear commitment to maturing the function. … The culture is collaborative, flat-structured, and outcome-focused – a mix of long-term stability with start-up energy when it comes to technology. Responsibilities: Own and lead the security function, frameworks, and controls across multiple entities Deliver CE+ certification and support alignment to ISO27001, DORA, and other regulatory requirements Provide oversight of security tools including Sentinel, Defender More ❯
Posted:

Senior Security Incident Response Engineer

Oxford, England, United Kingdom
RELX
Senior Security Incident Response Engineer About Team: If you are considering a new role and want to work in a company … that is helping to change the world, consider joining an organisation serving the global scientific research community, supporting the brightest minds on the planet. Elsevier is expanding its Global InfoSec Security Incident Response team and is looking for an Incident Response Engineer to join its ranks in the UK. About Role: As a Senior Security Incident Response Engineer … you will be a key internal security support team member, assisting in incident response investigations. You will have experience in analysing, triaging, scoping, containing, providing remediation guidance, and determining the root cause of security incidents. You are familiar with collecting and analysing security incident-related data to identify indicators of attack and compromise. You will be responsible More ❯
Posted:

Senior Information Assurance Consultant

Slough, England, United Kingdom
Hybrid / WFH Options
JR United Kingdom
Senior Information Assurance Consultant, slough Client: Location: slough, United Kingdom Job Category: Other - EU work permit required: Yes Job Views: 5 Posted: 26.06.2025 Expiry Date: 10.08.2025 Job Description: Job Title: Senior Information Assurance Consultant Location: Fully Remote (UK-based candidates) Contract Type: Contract – 3 to 6 months Clearance: Candidates must be eligible for SC (Security Clearance) or … SC clearance. Subject to client approval, candidates may be permitted to start the role prior to clearance being fully completed. Role Overview: We are seeking a highly experienced Senior Information Assurance Consultant to lead the development and implementation of security management processes for a new, high-profile service. This role will be instrumental in establishing and integrating a … comprehensive Information Security Management System (ISMS) aligned with multiple industry standards and frameworks. This is a fully remote position, offering flexibility while working on a critical and impactful programme. As the role involves working with sensitive information, eligibility for SC clearance or holding active SC clearance is essential. Key Responsibilities: Lead the design and implementation of security More ❯
Posted:

Cyber Security Engineer

Milton Keynes, Buckinghamshire, United Kingdom
NHS
Go back Milton Keynes University Hospital NHS Foundation Trust Cyber Security Engineer The closing date is 30 June 2025 Hours: 37.5 per week, all MKUH roles will be considered for flexible working Join Our Journey Towards Digital Excellence As a Global Digital Exemplar Fast Follower, it's an exciting time at Milton Keynes University Hospital. We're on a … journey to become a state-of-the-art digital hospital, and we're looking for a Cyber Security Engineer to join us on a permanent basis. In this role, you'll be part of a friendly multi-disciplinary team in a fast-paced and dynamic environment. You'll work with staff across the organisation and collaborate with a range … availability of our IT infrastructure. This is a unique opportunity to help shape the future for Milton Keynes University Hospital NHS Foundation Trust. If you're passionate about IT security and want to make a real impact in healthcare, we'd love to hear from you. Please note that we are not able to offer sponsorship for this role. More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Assistant Manager - IT Continuity (Backup) Operations Engineer

Reading, Berkshire, United Kingdom
Hybrid / WFH Options
Deloitte LLP
that matter, achieve, and sustain operational excellence. You will be at the heart of fulfilling our mission by working closely with our Global Operations teams, Business operations teams, and Security operations teams to develop plan and execute IT Continuity Services across multiple Data Centers and geographic regions. The role requires advanced skills that enable the individual to deliver a … activities Participate in a 24x7x365 on-call rotation Respond to and manage service issues and problems Responsible for awareness and compliance to policy and guidelines Report any breaches in information security or policies Identify repeatable operational tasks and issues; create automated resolutions to these situations to reduce operational overhead within the virtualization function as well as other enabling More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Head of Information Security, EMEA

Slough, England, United Kingdom
JR United Kingdom
Social network you want to login/join with: Head of Information Security, EMEA, slough col-narrow-left Client: Location: slough, United Kingdom Job Category: Other - EU work permit required: Yes col-narrow-right Job Views: 2 Posted: 04.06.2025 Expiry Date: 19.07.2025 col-wide Job Description: Key Responsibilities: In this role, you will be responsible for overseeing and … leading a team of security personnel across multiple domains including Security Operations, Global Security Administration, Physical Security, Data Security Analytics, PKI/Certificate Management, and Network Security Engineering. Your role will encompass a wide range of strategic, managerial, and technical responsibilities, including but not limited to: Technical Leadership and Strategy: Provide strategic security guidance and direction for the engineering of multiple high-performing teams across diverse domains. Drive the vision and direction of security solutions through active participation in the information security market through involvement with vendors, conferences, connecting with peers for all the firms’ various key technologies. Lead, supervise and inspire local team multiple key areas, Global Security More ❯
Posted:

Risk & Assurance Manager - IT & Infosec

Marlow, England, United Kingdom
Hybrid / WFH Options
Softcat Plc
Softcat Way. Softcat is a £1billion+ technology solutions business and trusted partner to names like Apple, Microsoft and Adobe. Offering a growing portfolio of services including software licensing, cyber security and IT infrastructure, we give our technical teams the tools and support to make exciting things happen. This is where to achieve more for your career. Lead the charge … on IT Risk & Assurance This role focuses on managing and enhancing the IT and Information Security risk landscape. Reporting directly to the Head of Risk and Assurance, you will play a key role in embedding effective risk management practices across Softcat's technology and cybersecurity domains. As a Risk & Assurance Manager, you'll be responsible for: Partnering with … testing and validation of key IT controls (e.g., access management, change control, incident response, vulnerability management), ensuring effectiveness and consistency. Leading in the review and enhancement of IT and infosec risk and control frameworks (e.g., ISO 27001, ITIL, ISO2 2301, NIST), ensuring alignment with business objectives and regulatory requirements. Coordinating and representing IT risk in internal , external audits and certification More ❯
Posted:

Information and Technology Governance & Risk Lead

Snelshall West, Milton Keynes, Buckinghamshire, England, United Kingdom
DS Smith
different countries across EMEA with over 30,000 colleagues. About the role Reporting to Head of I&T GRC, Governance and Risk Lead will be responsible for driving information and cyber security awareness, delivering security awareness training including phishing and facilitation of cyber scenario desktop simulations across central and manufacturing site teams. You will review, manage and … where required prepare responses to internal and external customer enquiries in relation to information and cyber security arrangements. You will support IT, procurement, legal, data protection and digital security and business stakeholder in relation to supplier information and cyber security due diligence and requirements. As the successful candidate you will also lead risk-based party … security assurance, management, and continuous improvement activities. In addition, facilitate and coordinate IT risk management risk register, tools, process, reporting and review. You will take responsibility for managing a subset of aspects of ISO 27001 related documentation and control activities. As the I&T Governance and Risk Lead you will have the responsibility of aspects of the I&T More ❯
Employment Type: Full-Time
Salary: Competitive salary
Posted:

Mandarin Speaking - IT Security Engineer

Slough, England, United Kingdom
JR United Kingdom
Social network you want to login/join with: Mandarin Speaking - IT Security Engineer, slough col-narrow-left Client: Location: slough, United Kingdom Job Category: Other - EU work permit required: Yes col-narrow-right Job Views: 5 Posted: 31.05.2025 Expiry Date: 15.07.2025 col-wide Job Description: Role Overview: Additional Information: Please note, this role requires working full-time … onsite, five days per week. NON Negotiable We are seeking an experienced IT Security Engineer to become a vital part of a growing IT Department. This critical role will focus on protecting our information assets through robust cybersecurity measures, ensuring adherence to best practices, international standards, and local regulations. Ideally suited to candidates who possess expert knowledge of … security frameworks including NIST 800, ISO 27001, and cybersecurity guidelines from PRA, FCA, and ICO. Candidates with at least 3 years' relevant experience in finance or banking, particularly as an information security officer or involvement in regulatory technical projects, are strongly preferred. Key Responsibilities: Develop and maintain cybersecurity policies and procedures, ensuring compliance with industry standards and More ❯
Posted:

Security Operations Manager

Reading, Berkshire, South East, United Kingdom
Hays
with a strong emphasis on safeguarding identity access. The SecOps Manager is a key figure in the organisation's cyber defence efforts, tasked with identifying, detecting, and responding to information security threats, as well as managing the response to cybersecurity incidents. Working closely with colleagues across IT and the wider organisation, this role ensures the protection of digital … and information assets against a range of internal and external threats. The M365, Identity, and Security functions are central to this position, leading a team of specialist engineers to maintain the secure operation of services and contributing to major projects that impact identity management across the organisation. The post holder also serves as a technical authority within the … team and department. What you'll need to succeed Security Operations & Incident Response Lead security operations services, including monitoring, incident response, threat management, and intrusion detection, using both internal and external resources. Manage the outsourced 24/7 security operations service. Lead the organisation's response to security incidents, coordinating recovery efforts with internal teams and More ❯
Employment Type: Permanent
Salary: £70,000
Posted:

Senior IT Security Analyst

Maidenhead, Berkshire, United Kingdom
dynaTrace software GmbH
Your role at Dynatrace Dynatrace exists to make the world's software work perfectly. Our unified software intelligence platform combines broad and deep observability and continuous runtime application security with the most advanced AIOps to provide answers and intelligent automation from data at an enormous scale. This enables innovators to modernize and automate cloud operations, deliver software faster and … values your diverse background, talents, ideas, and expertise, which make our global team stronger and more innovative. Responsibilities Serve as a bridge between the Dynatrace business units and the Security Risk Management organization to promote and facilitate the adaptation and involvement with the Dynatrace Risk Management Framework. Create, conduct, and report on security audits and assessments for all … systems and applications (custom and 3rd Party). Train and coordinate with systems application owners, data custodians, technical leads, and business impact analysts on security standards, guidelines, and vendor risk management. Provide guidance and support to teams to meet risk management requirements and industry control frameworks. Contribute to the development and implementation of security policies, procedures, and controls. More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Director IT Infrastructure Services

Oxford, England, United Kingdom
PSI CRO
design of company-wide IT infrastructure and oversees compliance, follow up and support thereof Oversees the development of PSI IT technology roadmap for automation, network monitoring, cloud, infrastructure and security Supervises and manages IT projects Develops IT infrastructure disaster recovery and business continuity plans Plans the IT infrastructure budget and communicates its priorities to company management and to direct … PSI Supervises IT managers and provides them with strategic guidance and vision Prepares for and attends quality assurance systems audits, both internal and external pertinent to IT Infrastructure Services Information Security Defines and leads the implementation of security controls (Security Operations Center, Identity Access Management, Endpoint Security, etc.) Leads operational engagement and manages metrics for … measuring Information Security maturity Tracks and coordinates Information Security involvement in business-driven technology projects Keeps abreast of Information Security trends, articulates security-related topics and principles in business terms Drives the delivery of Information Security plans and implementation of leading practice controls, based on proactive defense principles and strategies Leads More ❯
Posted:

Lead Penetration Tester

Reading, England, United Kingdom
Hybrid / WFH Options
SITA
something big? Are you ready to love your job? The adventure begins right here, with you, at SITA. PURPOSE As a Lead Penetration Tester , part of the SITA Enterprise Information Security Office, you will assess SITA infrastructure and products to identify information security weaknesses and provide remediation strategies. You will also contribute to the automation of … security testing as part of the product development lifecycle. Key Responsibilities Conduct authorized assessment of infrastructure and applications to proactively identify security weaknesses. Verify weaknesses by leveraging attacker techniques to evaluate the difficulty and effectiveness of potential attack from various threat actors. Provide comprehensive and actionable recommendations to counter the threat posed by identified security weaknesses, given … the applicable threat landscape. Bring an offensive mindset to the design of internal solutions and provide input to the selection of countermeasures and security controls through technical risk assessment. Report findings to technical audiences (e.g.: product development teams, IT, operations), and to business management and leadership, indicating the impact to the business of verified weaknesses found. Research and develop More ❯
Posted:
Information Security
the Thames Valley
10th Percentile
£37,250
25th Percentile
£39,750
Median
£41,500
75th Percentile
£67,500
90th Percentile
£77,500