Luton, Bedfordshire, United Kingdom Hybrid / WFH Options
Matchtech
concept to maintenance-ensuring alignment with customer and regulatory requirements. Key Responsibilities: Lead the definition, implementation, and governance of product security measures across the entire system lifecycle. Develop Security Management Plans, risk assessments, and mitigation strategies. Define and review security requirements for product teams. Support system accreditation, liaising with security accreditors and assurance teams. Prepare security documentation including Protection … Profiles, Security Targets, and TEMPEST Control Plans. Assist with platform lockdown, penetration testing, and vulnerability management. Lead incident response efforts and support product security training. Skills & Experience: Background in securing defence or commercial systems. Degree in engineering, computer science, or related field. Certified security professional (e.g. CISSP, NCSC Certified Professional). Familiar with UK/NATO IA standards (ISO More ❯
in automations using Python, Java, or Typescript. Experience writing secure-by-default Terraform configurations for cloud deployments. Strong understanding of cloud and application security principles. Knowledge of network protocols, vulnerabilitymanagement, and incident response planning. Willingness to learn and adapt to new security challenges and technologies. Relevant certifications such as AWS Certified Security, GIAC GC*, ISC2 CCSP/ More ❯
write automations in Python, Java, or Typescript Ability to write secure-by-default Terraform for cloud deployments Solid understanding of cloud and application security principles Knowledge of network protocols, vulnerabilitymanagement, and creation of Incident Response programs Willingness to learn and adapt to new security challenges and technologies Relevant certifications such as AWS Certified Security, GIAC GC*, ISC2 More ❯
STEM" Majors (Science, Technology, Engineering and Math) CISSP, CISM or related SANs or Industry certifications Desired Expertise Relevant Cyber or IT related experience in client and server environments. Infrastructure management and support Understanding of CND-based analytical models (Kill Chain, ATT&CK, Pyramid of Pain, etc.) Understanding of APT, Cyber Crime and other associated tactics Understanding of host forensics … and network analysis techniques and tools Understanding of malware and reverse engineering Understanding of vulnerabilities. Vulnerabilitymanagement, remediation and implementation techniques. Understanding of responding to threats in cloud platforms (AWS, Azure, Google, etc.) Excellent verbal and written communication skills Excellent organizational and analytical skills Detail oriented with the ability to multi-task and prioritize efforts Ability to express More ❯
Selby, England, United Kingdom Hybrid / WFH Options
Drax
vulnerabilities, assess their impact, and prioritize responses accordingly. Incident Response: Developing and implementing incident response plans for handling cyber incidents in OT environments, including containment, eradication, and recovery procedures. VulnerabilityManagement: Identifying and assessing vulnerabilities in OT systems and coordinate with relevant teams to remediate them. Security Assessment: Conducting security assessments and facilitate penetration testing of OT systems … level of attention to detail, be self-motivated and have the ability to think outside the box when working on complex problems. This role requires strong communication and stakeholder management skills, with the ability to influence beyond your sphere of control. Rewards and benefits As you help us to shape the future, we’ve shaped our rewards and benefits More ❯
you'll have the opportunity to work across multiple areas of Cyber Security, fostering your growth and career development. We provide comprehensive services to our clients, including Risk Assessments, VulnerabilityManagement, ISO27001 and GDPR compliance, Governance, Risk, and Compliance (GRC), Security Architecture Design and Implementation, Incident Response, Protective Monitoring, Penetration Testing, and more. Our goal is to enhance More ❯
deployments. Provide technical support with risk assessments on PHI, and steering improvements to our environment in line with common standards such as NIST. Support External Penetration Testing and application vulnerability efforts, delivering assessments and prioritizing remediation activities across the organization. Be across Threat Intelligence relevant to our industry and geographic regions, and translating that to real world defenses for … Suite, Kali, Metasploit and such Scripting including the use of python, Powershell, bash or Javascript Securing networks, hosts, web applications and cloud native deployments Working with toolsets such as: vulnerabilitymanagement, firewalls, SIEM, PAM, IDS/IPS, EDR/XDR, WAF Working with code security controls such as SAST/DAST/IAST/RASP You should also More ❯
London, England, United Kingdom Hybrid / WFH Options
Fitch Group
department where innovation meets impact. Our team includes the Chief Data Office, Chief Software Office, Chief Technology Office, Emerging Technology, Shared Technology Services, Technology, Risk and the Executive Program Management Office (EPMO).Driven by our investment in cutting-edge technologies like AI and cloud solutions, we’re home to a diverse range of roles and backgrounds united by a … risk, financial crimes, or technology risk in enterprise environments. Ability to introduce AI/ML solutions to enhance productivity and compliance monitoring within employee engagement systems. History of leading vulnerabilitymanagement, issue remediation, and exception handling within a governance framework. Strong documentation and policy development skills, capable of aligning business unit security practices with corporate standards. Passion for More ❯
Eastbourne, England, United Kingdom Hybrid / WFH Options
AxisOps
backup strategy Write markdown-based SOPs, runbooks, and infra playbooks that are used, tested, and evolved Work in regulated environments , including audit trail design, SBOM production, and CI-driven vulnerability/pentest workflows Collaborate closely with software engineers to make infrastructure serve delivery, not slow it down Note: this role requires you to work from our Eastbourne (UK) office … infra-as-code tooling Real-world experience operating hybrid environments (on-prem, AWS, Azure) Strong networking fundamentals: routing, firewalls, VPNs, switching A security-first mindset, with practical exposure to vulnerabilitymanagement and secure provisioning Clear written communication – your runbooks don’t need walkthroughs Familiarity with datacentre hardware: racking, patching, switch config, server diagnostics Proactive problem-solving skills and More ❯
London, England, United Kingdom Hybrid / WFH Options
Fitch Ratings
department where innovation meets impact. Our team includes the Chief Data Office, Chief Software Office, Chief Technology Office, Emerging Technology, Shared Technology Services, Technology, Risk and the Executive Program Management Office (EPMO). Driven by our investment in cutting-edge technologies like AI and cloud solutions, we’re home to a diverse range of roles and backgrounds united by … risk, financial crimes, or technology risk in enterprise environments. Ability to introduce AI/ML solutions to enhance productivity and compliance monitoring within employee engagement systems. History of leading vulnerabilitymanagement, issue remediation, and exception handling within a governance framework. Strong documentation and policy development skills, capable of aligning business unit security practices with corporate standards. Passion for More ❯
Manchester, England, United Kingdom Hybrid / WFH Options
Smart DCC
design and implement all security controls. In-depth understanding of the cyber threat landscape and advanced adversary tactics. Expert knowledge and experience of Linux, Windows, Azure, AWS, Elastic Search, Vulnerabilitymanagement, and Mitre ATT&CK. Excellent experience with NW configuration, Routing, Transit Gateways, Private endpoints, and log collection specifically Cloud watch, Cloudtrail, and S3 buckets. About the DCC More ❯
detections, SIEM rules, or EDR Significant experience with standard incident response processes Expertise in a broad range of information technologies, such as public cloud infrastructure (AWS, GCP), authentication systems, vulnerabilitymanagement solutions, network infrastructure, etc. Experience in dissecting attacker methodologies and techniques Comprehensive understanding of product and infrastructure logs from a security perspective Experience building and delivering projects More ❯
Belfast, Northern Ireland, United Kingdom Hybrid / WFH Options
Smart Brokers Limited
including Microsoft technologies Your experience should include: Securing systems by deploying patches and antivirus products Working with network switches, firewalls and wireless access points Working with toolsets such as vulnerabilitymanagement, SIEM, PAM, IDS/IPS, EDR or DLP platforms Familiarity with IAM best practices, including Multi-Factor Authentication (MFA), Conditional Access, and Identity Governance. RBAC configurations and More ❯
Hunting and Threat Intelligence (MITRE ATT&CK) Penetration Testing Security Automation (SOAR) It would help if you had experience with the following: SIEM tools (Microsoft Sentinel, Splunk, ELK, Siemplify) VulnerabilityManagement (Qualys, Nessus, Nexpose) Anti-Malware/EDR Software (Carbon Black, Microsoft Defender ATP, FireEye, CrowdStrike) Programming (Python, or other languages) What you can expect from us We More ❯
Welwyn Garden City, England, United Kingdom Hybrid / WFH Options
Tesco UK
evolving threats. We focus on anticipating and mitigating risks by identifying emerging threats and reducing uncertainty. Our CTI team collaborates closely with internal teams, including Security Operations, Incident Response, VulnerabilityManagement, and Security Engineering, as well as external intelligence-sharing communities, to enhance detection, response, and our understanding of the global threat landscape. We are committed to continuous More ❯
NIST, IPCI-DSS, ISO27001, ISO27701, ISO42001, NIST 800-53 Experience in internal enterprise or external customer-facing environment as a security technical lead Experience in Security operations such as vulnerabilitymanagement, security incident response, and large-scale compliance implementations. PREFERRED QUALIFICATIONS Deep experience in Cloud Security architecture design, build, deploy and maintenance Deep experience implementing and managing compliance More ❯
Social network you want to login/join with: Security Engineer, VulnerabilityManagement and Remediation Operations, London col-narrow-left Client: Amazon Data Services UK Limited Location: London, United Kingdom Job Category: Other - EU work permit required: Yes col-narrow-right Job Reference: 875722497038 Job Views: 43 Posted: 24.06.2025 Expiry Date: 08.08.2025 col-wide Job Description: Embark on … a Mission to Fortify Amazon's Defenses as a Security Engineer with the VulnerabilityManagement & Remediation Operations team! Amazon Security is seeking a Security Engineer to join our VulnerabilityManagement and Remediation Operations (VMRO) team in London, UK. The VMRO team is responsible for discovering, assessing, triaging, detecting, and driving the remediation of vulnerabilities across the … Amazon ecosystem Key job responsibilities - Analyse public and private vulnerability disclosures and exploit code - Deeply understand and assess the technical details and potential impact of vulnerabilities across Amazon's infrastructure, services, and applications. - Investigate and triage vulnerabilities, identifying severity and the scope of potential impact to Amazon. - Support response and remediation efforts, assisting builder teams to fix their security More ❯
Reading, England, United Kingdom Hybrid / WFH Options
Liberty Global
We’re looking for a Senior VulnerabilityManagement Analyst to join us in either Amsterdam, London or Reading In this role you will be working closely with one of our Operating companies, Telenet, which will mean regular visits to their site in Mechelen, Belgium. The Threat and VulnerabilityManagement team ensure effective prioritization and management of vulnerabilities to reduce risk of infection, remote execution and data exfiltration across the Liberty Global estate. The team's key role is to provide proactive and effective management of vulnerabilities to reduce the attack surface and improve the overall security posture of Liberty Global and their entities. As such the Threat & VulnerabilityManagement team are … looking for talented and passionate security professionals to join their team. As part of TVM our VulnerabilityManagement Analysts focus on delivering the end-to-end vulnerabilitymanagement process, including proactive monitoring and scanning of threats and vulnerabilities in order to protect and defend Liberty Global's interests. With vulnerabilities impacting network, endpoint, and cloud in More ❯
DESCRIPTION Embark on a Mission to Fortify Amazon's Defenses as a Security Engineer with the VulnerabilityManagement & Remediation Operations team! Amazon Security is seeking a Security Engineer to join our VulnerabilityManagement and Remediation Operations (VMRO) team in London, UK. The VMRO team is responsible for discovering, assessing, triaging, detecting, and driving the remediation of … vulnerabilities across the Amazon ecosystem Key job responsibilities Analyse public and private vulnerability disclosures and exploit code Deeply understand and assess the technical details and potential impact of vulnerabilities across Amazon's infrastructure, services, and applications. Investigate and triage vulnerabilities, identifying severity and the scope of potential impact to Amazon. Support response and remediation efforts, assisting builder teams to … fix their security issues in a timely manner Engineer high quality, scalable, and accurate vulnerability detection mechanisms Design and implement automation, tools and workflows to enhance our operations capabilities. Be part of a global team and participate in periodic on-call responsibilities to ensure the continuous monitoring and remediation of vulnerabilities. Experience programming in Python, Ruby, Go, Swift, Java More ❯
to not just be recognised for your skills but encouraged to build upon them and empowered to do your absolute best. We have an exciting opportunity for a Cyber Vulnerability Analyst to join our Cyber Defence Centre! Reporting into the Vulnerability & Testing Manager, you'll be a key member of our Cyber Defence ‘Assure’ function and perform identification … opportunity with two London or Bristol office days a week. What you'll be doing: This role, as part of the wider team, will focus on running an effective vulnerabilitymanagement and cloud security posture management (CSPM) service. You'll be responsible for: Managing aspects of the vulnerability and CSPM lifecycle excluding patch management. Identifying, alongside … your peers, vulnerability & CSPM improvement opportunities. Improving and maintaining documentation that defines DLG’s vulnerability and posture weakness identification, contextualisation, prioritisation, and tracking framework. Relationship management with key technology stakeholders to ensure vulnerability (including cloud configuration weakness) priorities are understood and tracked appropriately. Collaborating with the wider Cyber Defence and CISO teams to ensure appropriate mitigation More ❯
Bath, Somerset, South West, United Kingdom Hybrid / WFH Options
Sanderson Recruitment
Infrastructure Security Analyst, SCCM, Vulnerability, Patch management, Qualys/Nessus Our client, a leading private sector business based in Bath, is looking to hire contractor with a background in infrastructure and related security. The successful candidate will be responsible for ensuring security and integrity for our clients IT infrastructure, taking responsibility for patching and vulnerability remediation for … patches to Windows servers to address vulnerabilities, ensuring compliance with security policies. Manage patching windows and downtime coordination with various business units to minimize disruption during updates. Monitor patch management systems to ensure all systems are up to date and protected from security threats. Server hardening to Windows systems, both physical and virtual. Maintain accurate documentation of remediation activities … incident response by applying emergency patches and remediations Contribute to disaster recovery and business continuity plans Skills and experience required: - Windows server including patching processes Server/security hardening. Vulnerabilitymanagement tools e.g. Nessus, Qualys, for conducting vulnerability assessments Hands-on experience in patch management systems - SCCM, WSUS, or Azure Update Management - for deploying patches More ❯
Surrey - 2 days per week with incorporated flexibility Currently support the x2 Directors we have onboarded for a global professional services brand onboard a Cloud Security Analyst within there Vulnerability & SecOps team (Azure). Skills needed: - Experience of working in enterprise/complex environment; they have 1000's of VM's, active subscriptions, tenants, etc. - Proficiency with Microsoft Security … suite products, including Microsoft Defender for Cloud, Sentinel, Azure Update Manager, and Azure cloud services. - Experienced in vulnerabilitymanagement, threat assessment, countermeasure implementation, and patch management within cloud-based infrastructures and services. - Certifications such as CISSP, AZ-500, etc would be favourable but are not essential. Note - this is not a SOC role; the business have an More ❯
Edinburgh, Midlothian, Scotland, United Kingdom Hybrid / WFH Options
Lorien
to-end delivery of large cyber security projects, ensuring alignment with business and regulatory requirements. Coordinate cross-functional teams across infrastructure, cloud, and security domains. Oversee project planning, risk management, reporting, and stakeholder engagement. Ensure effective implementation of security controls and best practices across networks, cloud platforms, and infrastructure. Support vulnerabilitymanagement and firewall/security configuration … initiatives. Required Experience & Skills: Proven experience managing large-scale Cyber Security projects. Strong understanding of Networks, VulnerabilityManagement, Cloud Security, and Firewalls . Experience working in regulated environments, ideally financial services. Excellent communication and stakeholder management skills. Ability to work in a fast-paced, delivery-focused environment. If you're a delivery-focused Cyber Security Project Manager More ❯
PCI DSS & AWS cloud background is required to join our global client's new UK cybersecurity team. This role is predominantly end-client facing, advising on security best practices, vulnerabilitymanagement and security standard compliance (e.g. NIST, ISO, PCI DSS etc), and leading audits and examinations. You will be reporting to the UK Head of Security and consulting … Skills & Experience Required: 4+ years of experience working in Cyber Security within an AWS cloud environment Any experience with CrowdStrike would be a bonus Good experience with PCI DSS Vulnerabilitymanagement & Compliance Lead on Audits Strong Security standard knowledge and experience, consulting on a range of security policies and standards such as GDPR, ISO, PCI, NIST Confidence when … headquarters. You will be working in a vibrant office with some of most forward-thinking technical people Key Responsibilities: Analysing and developing security requirements, as well as carrying out vulnerabilitymanagement & compliance work in PCI DSS type projects Ensure consistency across IT Security risk management activities. Advise Engineers on information related to new vulnerabilities and threats and More ❯
PCI DSS & AWS cloud background is required to join our global client's new UK cybersecurity team. This role is predominantly end-client facing, advising on security best practices, vulnerabilitymanagement and security standard compliance (e.g. NIST, ISO, PCI DSS etc), and leading audits and examinations. You will be reporting to the UK Head of Security and consulting … Skills & Experience Required: 4+ years of experience working in Cyber Security within an AWS cloud environment Any experience with CrowdStrike would be a bonus Good experience with PCI DSS Vulnerabilitymanagement & Compliance Lead on Audits Strong Security standard knowledge and experience, consulting on a range of security policies and standards such as GDPR, ISO, PCI, NIST Confidence when … headquarters. You will be working in a vibrant office with some of most forward-thinking technical people Key Responsibilities: Analysing and developing security requirements, as well as carrying out vulnerabilitymanagement & compliance work in PCI DSS type projects Ensure consistency across IT Security risk management activities. Advise Engineers on information related to new vulnerabilities and threats and More ❯