Job summary Cyber Operations purpose is to support safe care and build public trust by building NHS England's cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS. The Cyber Operations sub-directorate consists of 4 operational areas: Cyber SecurityOperations Unit (CSOU) Cyber Delivery Unit (CDU) Cyber Improvement Programme Chief Information Security Office Function (CISO) The Security Analyst (XDR) role is within the SecurityOperations pillar of the CSOC (Cyber SecurityOperations Centre) providing second line security analytics and incident response services. The post of Security Analyst has been … an additional monthly RRP payment equal to 20% per annum. Please be aware that RRP is non contractual and subject to review. Main duties of the job As a Security Analyst (XDR) you will: Act as a Tier 2 Extended Detection and Response (XDR) analyst for the SecurityOperations team. Deputise for Senior Analysts in their absence. More ❯
Job summary The Senior Security Analyst (Ops) sits within the Protective Monitoring function of the Cyber SecurityOperations Centre (CSOC). The CSOC is made up of Protective Monitoring, Incident Management, Threat Operations, Engineering and Consultancy. The role is a Tier 3 analyst in the XDR Protective Monitoring Sub team. Cyber Operations purpose is to … cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS. The Cyber Operations sub-directorate consists of 4 operational areas: Cyber SecurityOperations Unit (CSOU) Cyber Delivery Unit (CDU). Cyber Improvement Programme. Chief Information Security Office Function (CISO … The post of Senior Security Analyst has been awarded a Recruitment and Retention Premia (RRP) in response to current labour market conditions. In recognition of this, the role attracts an additional monthly RRP payment equal to 20% per annum. Please be aware that RRP is non contractual and subject to review. Main duties of the job As a Senior More ❯
Job summary Cyber Operations purpose is to support safe care and build public trust by building NHS England's cyber resilience and enabling the wider health system to be cyber resilient, supporting NHS England's purpose of delivering the best care and outcomes for the NHS. The Cyber Operations sub-directorate consists of 4 operational areas: Cyber SecurityOperations Unit (CSOU) Cyber Delivery Unit (CDU) Cyber Improvement Programme (CIP) Chief Information Security Office Function (CISO) This role is in the Cyber SecurityOperations Centre (CSOC) which is part of the CSOU and provides centralised security monitoring across both NHS England and the wider health and care system in England. The CSOC consists … of Protective Monitoring, Threat Operations, Incident Management, Service Operations and Engineering. To support our strategy to improve NHS cyber resilience, we are recruiting for a Senior Security Analyst who specialises in Service Delivery Management as part of the CSOC Service Operations team. The post of Senior Security Analyst for Service Delivery has been awarded a More ❯
Warwick, Warwickshire, United Kingdom Hybrid / WFH Options
Pontoon
Job Title: Cyber Security Response Specialist Location: Warwick OR Wokingham, Hybrid, 2 days onsite per week Remuneration: Daily Rate From: £650 Contract Details: Fixed Term Contract, 6 months, Full Time Responsibilities: Develop and maintain incident response plans, processes, and documentation. Implement effective Incident Response processes for remediation and restoration. Lead Post Incident Response and Lessons Learned initiatives. Design and … deliver engaging incident response exercises at various command levels. Communicate vital information through reports, presentations, and briefings. Provide expert cyber security knowledge and drive continuous improvement. Establish and nurture relationships for effective incident communication. Collaborate with government and energy sector stakeholders to enhance security. About the Role: Join our vibrant team as a Cyber Security Response Specialist, where … your expertise in incident response will shine! This exciting opportunity allows you to design and implement robust incident response processes, providing critical support to SecurityOperations and ensuring seamless management of all Security Incidents. You'll be part of a dynamic joint cyber and physical security response team, with the chance to broaden your expertise in More ❯
IT SecurityOperations Engineer - London Up to £550 p/d (outside IR35) 3 month initial term A leading construction engineering business is seeking an SecOps Engineer to their team. They are a well-established business about to enter considerable operational change making it an exciting time to join and be a part of their journey. This role … carries responsibility for ensuring collaboration between Information Security and the IT Ops team, you'll ensure the implementation of technical security controls supporting risk mitigation and contributing to the continual improvement of the business's security composure. Responsibilities: * Provide expertise on application, network and infrastructure security * Monitor security solutions including SIEM, threat detection and data … security, endpoint protection, network analytics for alerts * Provide documentation for technical standards to meet corporate security policies/industry best practice * Perform security reviews, identify gaps in security architecture and apply appropriate remediation * Ensure appropriate technical measures are in place to comply with regulations/legislations * Conduct vulnerability scanning, analysis and remediation * Patch management * Identify root More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Context Recruitment Limited
IT SecurityOperations Engineer - London Up to £550 p/d (outside IR35) 3 month initial term A leading construction engineering business is seeking an SecOps Engineer to their team. They are a well-established business about to enter considerable operational change making it an exciting time to join and be a part of their journey. This role … carries responsibility for ensuring collaboration between Information Security and the IT Ops team, you'll ensure the implementation of technical security controls supporting risk mitigation and contributing to the continual improvement of the business's security composure. Responsibilities: * Provide expertise on application, network and infrastructure security * Monitor security solutions including SIEM, threat detection and data … security, endpoint protection, network analytics for alerts * Provide documentation for technical standards to meet corporate security policies/industry best practice * Perform security reviews, identify gaps in security architecture and apply appropriate remediation * Ensure appropriate technical measures are in place to comply with regulations/legislations * Conduct vulnerability scanning, analysis and remediation * Patch management * Identify root More ❯
Job summary The Security Lead (Analyst) Ops sits within the Protective Monitoring function of the Cyber SecurityOperations Centre (CSOC). The CSOC is made up of Protective Monitoring, Incident Management, Threat Operations, Engineering and Consulting. The role is responsible for leading the Network Protective Monitoring sub team. Cyber Operations purpose is to support safe … cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS. The Cyber Operations sub-directorate consists of 4 operational areas: Cyber SecurityOperations Unit (CSOU) Cyber Delivery Unit (CDU). Cyber Improvement Programme. Chief Information Security Office Function (CISO … The post of Security Lead (Analyst) Ops has been awarded a Recruitment and Retention Premia (RRP) in response to current labour market conditions. In recognition of this, the role attracts an additional monthly RRP payment equal to 30% per annum. Please be aware that RRP is non contractual and subject to review Main duties of the job As a More ❯
Job summary Cyber Operations purpose is to support safe care and build public trust by building NHS England's cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS. The Cyber Operations sub-directorate consists of 4 operational areas:Cyber SecurityOperations Unit (CSOU)Cyber Delivery Unit (CDU).Cyber Improvement Programme.Chief Information Security Office Function (CISO) To support our strategy to improve NHS England's cyber resilience, we are recruiting for a Cyber Security Analyst who is a Threat Hunting specialist . This role is within the Cyber Security - Threat Hunting team, which is one of … three core pillars of the Threat Operations pod within NHS England's CSOU. The Threat Hunting team is responsible for several key functions: Multi-Platform Threat Hunting at Scale - Run hunting queries and analytics across large datasets using a variety of cloud-based and hybrid security solutions. Custom Analytic and Detection Development - Writing and reviewing custom rules to More ❯
partners to deliver a safe, resilient, robust Network Platform and continuously review the industry and market, testing new concepts and technologies that can add value. Your purpose The Network Security Engineer supports the Lead Network Security Engineer in delivering the Network Security Roadmap. This role supports the implementation of Infosec-driven initiatives and acts as the second … line of escalation for Network Security Incidents and ad hoc service and portfolio support requests. This role is accountable for establishing and maintaining secure network configurations, including firewalls, routers, switches, and VPNs, and periodically reviewing firewall rules and user access to the network. The Network Security Engineer focuses on continuous improvement through automation and tooling, working with SecurityOperations to monitor and analyse network traffic for malicious activity or potential breaches. Additionally, this role implements network access controls, enforces robust patch management for network devices, and works with network security partners to identify network vulnerabilities, planning and implementing upgrades to ensure the highest standards of network security. This role is required to participate in an More ❯
Job Title: Security Subject Matter Expert - Endpoint Contract Duration: Until End of Year Location: Hybrid (Onsite as required) Overview: We are seeking a Security Subject Matter Expert (SME) with a strong focus on endpoint security to join a critical security initiative. This role plays a key part in shaping and governing foundational security controls within … a global enterprise environment. You will act as a strategic advisor and technical authority, supporting the development and implementation of endpoint security practices, vulnerability management, asset control, and governance-aligned with the organisation's broader 2026 security strategy . This is an ideal opportunity for someone who may not see themselves as a traditional architect but brings deep … technical insight , strategic vision , and the ability to embed practical, scalable security controls . Key Responsibilities: Provide subject matter expertise in endpoint security controls, tooling , and decision-making. Partner with security analysts to design, embed, and operationalise foundational security controls. Maintain oversight of securityoperations to ensure alignment with long-term strategic goals. Contribute More ❯
CYBER SECURITY ANALYST | SECURITYOPERATIONS CENTER |HIGH THREAT GOVERNMENT Summer-Browning Associates is supporting our client in the Central Government who is seeking a Cyber Security Analyst for an initial 12-month assignment, with the possibility of extension. Location: London | Hybrid| Remote The ideal candidates will possess an active DV Security clearance and have a … solid background in Cyber Security, with the following skills and experience: Proficiency in Security Information and Event Management (SIEM), including tools such as Splunk, Defender, and Tenable Threat Modelling System solutions, as well as with IDS/IPS and vulnerability scanners. Experience in SOC operations, incident response, and forensic analysis. Ability to perform triage of security events to determine their scope, priority, and impact, while making recommendations for efficient remediation. Experience in network security principles, firewalls, and access control mechanisms. Preferred Qualifications: - Industry certifications such as CompTIA Security+, CISSP, CISM, CEH, or GIAC are highly desirable. To apply, please submit your latest CV for review. More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
Queen Square Recruitment Limited
Intelligence Specialist Location: Reading, UK (Hybrid 4 days onsite) Duration: 6 months Rate: £465 per day Inside IR35 We are seeking a Threat Intelligence Specialist to join a global security team on a 6-month contract. This is a hands-on role where youll play a key part in strengthening the organisations cyber defence posture by collecting, analysing, and … disseminating actionable intelligence. Youll work closely with incident response, securityoperations, vulnerability management, and leadership teams to anticipate threats, mitigate risks, and improve resilience. Key Responsibilities: Collect and analyse intelligence to address high-priority security requirements. Produce and share actionable threat intelligence with stakeholders across securityoperations, incident response, and fraud prevention. Conduct dark web … internal and external threats, including insider threats, and escalate as appropriate. Support the running of a threat intelligence platform to structure and standardise cyber threat data. Write and present security reports in clear, business-focused formats. Build partnerships with third parties (e.g., government, industry groups) to exchange intelligence. Contribute to broader security initiatives as part of a cutting More ❯
City of London, Bishopsgate, United Kingdom Hybrid / WFH Options
Morson Talent
Security Engineer - SC Cleared (or Eligible) - £550 per day - Inside IR35 - Remote - 12 Months initial contract We are currently working with a leading client in the zero carbon energy sector who are looking to bring on board an experienced Security Engineer to join their security implementation and engineering delivery team. This is a fantastic opportunity to work … on large-scale, business-critical projects in a highly regulated environment. The Role - As part of the security engineering team, you'll be: Delivering on the security portfolio, with a focus on SASE and firewall estates. Working within a SAFe Agile framework, participating in sprints and stand-ups. Managing and tracking workloads via Jira. Triaging customer requirements into … actionable deliverables. Acting as an escalation engineer for the Security Support Team. Supporting and mentoring junior engineers. Producing documentation and knowledge base material, as well as delivering knowledge transfer sessions. Occasionally supporting out-of-hours work. Technical Skills We're Looking For - My client is looking for demonstrable experience in as many of the following as possible: Enterprise firewalls More ❯
a recently lapsed clearance will be prioritised. Our client, one of the UKs largest producers of zero carbon energy, is looking for 2 Senior SOC Analysts to join their SecurityOperations Centre. This is an excellent opportunity for an experienced SOC professional to step into a senior role, leading on complex investigations and incident response within a high … The Senior SOC Analyst will act as the technical expert within the SOC, responsible for handling escalations from Tier 1 and Tier 2 analysts and managing the most complex security incidents. You will lead deep-dive investigations, improve detection and response processes, and play a key role in stakeholder engagement. Key responsibilities include: Analysing advanced security incidents, determining … technology stack, including: SIEM: Microsoft Sentinel EDR/XDR: Microsoft Defender for Endpoint Threat Intel: Recorded Future Network Analysis: Wireshark/tcpdump SOAR & Automation: Palo Alto Cortex XSOAR, ServiceNow SecOps Vulnerability Management: Tenable Nessus/Tenable.io Other nice to have tools: Shodan, Censys, BloodHound, Metasploit, Cobalt Strike, MITRE ATT&CK Navigator Cloud Security (advantageous): AWS GuardDuty, Security Hub More ❯
London, Old Bailey, United Kingdom Hybrid / WFH Options
Morson Talent
a recently lapsed clearance will be prioritised. Our client, one of the UKs largest producers of zero carbon energy, is looking for 2 Senior SOC Analysts to join their SecurityOperations Centre. This is an excellent opportunity for an experienced SOC professional to step into a senior role, leading on complex investigations and incident response within a high … The Senior SOC Analyst will act as the technical expert within the SOC, responsible for handling escalations from Tier 1 and Tier 2 analysts and managing the most complex security incidents. You will lead deep-dive investigations, improve detection and response processes, and play a key role in stakeholder engagement. Key responsibilities include: Analysing advanced security incidents, determining … technology stack, including: SIEM: Microsoft Sentinel EDR/XDR: Microsoft Defender for Endpoint Threat Intel: Recorded Future Network Analysis: Wireshark/tcpdump SOAR & Automation: Palo Alto Cortex XSOAR, ServiceNow SecOps Vulnerability Management: Tenable Nessus/Tenable.io Other nice to have tools: Shodan, Censys, BloodHound, Metasploit, Cobalt Strike, MITRE ATT&CK Navigator Cloud Security (advantageous): AWS GuardDuty, Security Hub More ❯
Job summary Cyber Operations purpose is to support safe care and build public trust by building NHS England's cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS. The Cyber Operations sub-directorate consists of 4 operational areas: Cyber SecurityOperations Unit (CSOU). Cyber Delivery Unit (CDU). Cyber Improvement Programme (CIP). Chief Information Security Office Function (CISO). The Cyber Improvement Programme (CIP) aims to deliver cyber improvements that provide long-term foundational change towards sustainable cyber risk management across the health and social care system, working towards the vision of creating a health … escalation for project and programme managers within the team. The delivery of complex organisational change programmes and facilitating the uptake of initiatives that support excellence and embedding of cyber security across the health and care system. Stakeholder engagement and communications engaging on complex issues, strategy and policy with stakeholders at all levels including programme reporting to stakeholders and senior More ❯
i need a BA will strong experience of working on ServiceNow and specifically implementing the 'SecurityOperations' or 'SecOps' module of ServiceNow. This SecOps module integrates with multiple cyber monitoring tools like Sentinel, Defender and Mend that the client use. Currently each of these tools create their own separate reports and create their own different tickets for resolutions … however the SecOps module of ServiceNow integrates all of this into a single report, with a single integrated ticketing system. This BA will do a current state analysis of all of the existing tools, then document a future state with the ServiceNow SecOps module including integrations, and also document the gap analysis and design the roadmap. Reasonable Adjustments: Respect and More ❯
dynamic team. The ideal candidate will design, implement, and optimize secure network architectures, leveraging Microsoft cloud technologies to protect enterprise environments against evolving cyber threats. Key Responsibilities: Network Architecture & Security: Design and implement secure network infrastructures using Azure networking components (VNETs, NSGs, Azure Firewall, VPN Gateway, etc.). Integrate M365 security features (Defender for Office 365, Conditional Access … Entra. Consulting & Advisory: Provide expert guidance to clients on cybersecurity best practices, compliance (e.g., ISO 27001, NIST), and risk mitigation. Conduct assessments and audits of existing network and cloud security postures. Deliver workshops and training sessions on M365 and Azure security capabilities. Incident Response & Monitoring: Collaborate with SOC teams to monitor and respond to network-based threats. Utilize … for Cloud to detect and remediate vulnerabilities. Develop playbooks and automation for threat response. Required Skills & Experience: Proven experience in networking and cybersecurity consulting. Strong knowledge of Microsoft 365 security and compliance features. Hands-on experience with Azure networking and security services. Familiarity with SIEM tools, especially Microsoft Sentinel. Understanding of identity and access management (IAM), MFA, and More ❯
South West London, London, England, United Kingdom
Tenth Revolution Group
dynamic team. The ideal candidate will design, implement, and optimize secure network architectures, leveraging Microsoft cloud technologies to protect enterprise environments against evolving cyber threats. Key Responsibilities: Network Architecture & Security: Design and implement secure network infrastructures using Azure networking components (VNETs, NSGs, Azure Firewall, VPN Gateway, etc.). Integrate M365 security features (Defender for Office 365, Conditional Access … Entra. Consulting & Advisory: Provide expert guidance to clients on cybersecurity best practices, compliance (e.g., ISO 27001, NIST), and risk mitigation. Conduct assessments and audits of existing network and cloud security postures. Deliver workshops and training sessions on M365 and Azure security capabilities. Incident Response & Monitoring: Collaborate with SOC teams to monitor and respond to network-based threats. Utilize … for Cloud to detect and remediate vulnerabilities. Develop playbooks and automation for threat response. Required Skills & Experience: Proven experience in networking and cybersecurity consulting. Strong knowledge of Microsoft 365 security and compliance features. Hands-on experience with Azure networking and security services. Familiarity with SIEM tools, especially Microsoft Sentinel. Understanding of identity and access management (IAM), MFA, and More ❯
have a proven track record in delivering complex ServiceNow projects in large-scale or enterprise environments. Strong hands-on experience across multiple ServiceNow modules (e.g. ITSM, ITOM, HRSD, CSM, SecOps). Solid understanding of ServiceNow scripting (JavaScript, Glide) and integrations (REST, SOAP, APIs). Excellent stakeholder engagement and consultancy skills. ServiceNow certifications (CSA, CIS in relevant modules) highly desirable. SC More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Robert Half
have a proven track record in delivering complex ServiceNow projects in large-scale or enterprise environments. Strong hands-on experience across multiple ServiceNow modules (e.g. ITSM, ITOM, HRSD, CSM, SecOps). Solid understanding of ServiceNow scripting (JavaScript, Glide) and integrations (REST, SOAP, APIs). Excellent stakeholder engagement and consultancy skills. ServiceNow certifications (CSA, CIS in relevant modules) highly desirable. SC More ❯
Architect – ServiceNow IRM and SecOps Solution Extensive experience as a ServiceNow Technical Architect or in a similar lead architectural role. Demonstrated ability to design and implement end-to-end ServiceNow solutions across multiple modules. Deep understanding of the ServiceNow platform architecture, data model, and security framework. Expertise in ServiceNow best practices, including platform governance, performance optimization, and security … technical and non-technical audiences. Experience with Agile development methodologies. Relevant ServiceNow certifications (e.g., Certified Master Architect, Certified Technical Architect, Certified Application Developer, Certified System Administrator). ServiceNow GRC & SecOps B.E/B.Tech , BCA/MCA ServiceNow Certified Consultant 2- Functional Consultant – ServiceNow IRM and SecOps Solution Certified ServiceNow IRM/SecOps administrator/consultant (this is mandatory) Must have … concluded at least 1 lifecycle of ServiceNow IRM/SecOps implementation. Experience in JavaScript, API, Web Services Working knowledge of Vulnerability Mgmt. process & tools ISO/CISA/CISM/CISSP/CRICS (preferred) ServiceNow GRC & SecOps B.E/B.Tech , BCA/MCA ServiceNow Certified Consultant More ❯