Bristol, Avon, England, United Kingdom Hybrid / WFH Options
Sanderson
Assurance and Risks. Security related legislation (e.g. GDPR, PCI DSS, ICO requirements). Security Control Frameworks such as ISO 27001, NIST CSF and CIS Controls v8. HMG, NPSA and NCSCsecurity policies, standards and guidance. Have experience building and implementing secure by design principals within the software development lifecycle (SDLC). Threat Modelling - Kill Chain - Attack tree analysis. Working understanding More ❯
cyber leaders Ideal Background Proven experience in cyber strategy, transformation, and risk management within complex organisations Strong knowledge of regulatory and security frameworks (e.g. NIST CSF, ISO27001, GDPR, NIS2, NCSC CAF) Experience across areas such as GRC, security architecture, threat management, or vulnerability management Outstanding communication and stakeholder engagement skills, with the ability to influence at C-suite and board More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Sanderson Government and Defence
Assurance and Risks. Security related legislation (e.g. GDPR, PCI DSS, ICO requirements). Security Control Frameworks such as ISO 27001, NIST CSF and CIS Controls v8. HMG, NPSA and NCSCsecurity policies, standards and guidance. Have experience building and implementing secure by design principals within the software development lifecycle (SDLC). Threat Modelling - Kill Chain - Attack tree analysis. Working understanding More ❯
Plymouth, Devon, United Kingdom Hybrid / WFH Options
Pontoon
of cloud platforms such as AWS and Microsoft Azure, as well as Microsoft Entra ID and M365. Familiarity with frameworks such as NIST CSF, Cyber Assessment Framework (CAF), and NCSC Cloud Security Principles. Proven ability to influence stakeholders and support secure delivery in large, complex environments. Excellent communication skills and ability to collaborate with globally distributed teams. A degree in More ❯
Greater Bristol Area, United Kingdom Hybrid / WFH Options
Logiq
security certification. Desirable Full Membership of the Chartered Institute of Information Security (CIISec) - highly desirable. Chartered or Principal status via the UK CyberSecurity Council for Secure Systems Architecture. NCSC Certified Cyber Professional in Security Architecture. IEng or CEng registered with UK Engineering body. Chartership through the British Computer Society. SABSA Chartered Security Architect Other information: Logiq is committed to More ❯
newport, wales, united kingdom Hybrid / WFH Options
Logiq
security certification. Desirable Full Membership of the Chartered Institute of Information Security (CIISec) - highly desirable. Chartered or Principal status via the UK CyberSecurity Council for Secure Systems Architecture. NCSC Certified Cyber Professional in Security Architecture. IEng or CEng registered with UK Engineering body. Chartership through the British Computer Society. SABSA Chartered Security Architect Other information: Logiq is committed to More ❯
bath, south west england, united kingdom Hybrid / WFH Options
Logiq
security certification. Desirable Full Membership of the Chartered Institute of Information Security (CIISec) - highly desirable. Chartered or Principal status via the UK CyberSecurity Council for Secure Systems Architecture. NCSC Certified Cyber Professional in Security Architecture. IEng or CEng registered with UK Engineering body. Chartership through the British Computer Society. SABSA Chartered Security Architect Other information: Logiq is committed to More ❯
bradley stoke, south west england, united kingdom Hybrid / WFH Options
Logiq
security certification. Desirable Full Membership of the Chartered Institute of Information Security (CIISec) - highly desirable. Chartered or Principal status via the UK CyberSecurity Council for Secure Systems Architecture. NCSC Certified Cyber Professional in Security Architecture. IEng or CEng registered with UK Engineering body. Chartership through the British Computer Society. SABSA Chartered Security Architect Other information: Logiq is committed to More ❯
Market Harborough, Leicestershire, East Midlands, United Kingdom Hybrid / WFH Options
4C Resourcing
youll be doing Lead and deliver client engagements across governance, risk and compliance (GRC), including audits, assessments and improvement plans aligned to frameworks such as ISO/IEC 27001, NCSC CAF, and PCI DSS. Lead independent assurance , review and test security policies, procedures and controls; identify gaps; and recommend pragmatic remediation strategies. Develop and present security strategies that enhance resilience More ❯
Newport, Gwent, Wales, United Kingdom Hybrid / WFH Options
Intellectual Property Office
duties consist of but are not limited to: Ensure security architecture aligns with wider Gov security policies and frameworks, legal frameworks, industry regulations and best practise (e.g ISO 27001, NCSC Standards, GDPR, PCI DSS, GovAssure, Secure by Design). Support the secure by design champion in building awareness and understanding of secure by design framework across DDaT. Manage the securityMore ❯
cross-HMG security principles), into usable, department-specific tools and guidance. Engage with OGDs and cross-HMG forums to ensure our frameworks align with DSIT, Cabinet Office and NationalCyberSecurityCentre standards. Establish and maintain secure-by-design and explainability guardrails for AI across the estate. Provide enterprise-level architectural governance across AI pilots, ensuring reuse, integration and compliance. More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Hays Technology
cross-HMG security principles), into usable, department-specific tools and guidance. Engage with OGDs and cross-HMG forums to ensure our frameworks align with DSIT, Cabinet Office and NationalCyberSecurityCentre standards. Establish and maintain secure-by-design and explainability guardrails for AI across the estate. Provide enterprise-level architectural governance across AI pilots, ensuring reuse, integration and compliance. More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hays
cross-HMG security principles), into usable, department-specific tools and guidance. Engage with OGDs and cross-HMG forums to ensure our frameworks align with DSIT, Cabinet Office and NationalCyberSecurityCentre standards. Establish and maintain secure-by-design and explainability guardrails for AI across the estate. Provide enterprise-level architectural governance across AI pilots, ensuring reuse, integration and compliance. More ❯
Leeds, Yorkshire, United Kingdom Hybrid / WFH Options
Pentest People
living threat management system throughout the contract duration. As CHECK Team Leader , you will lead and oversee penetration testing engagements for government and critical infrastructure clients, ensuring compliance with NCSC methodologies while delivering technical and strategic value. This role requires both Infrastructure and Application CHECK certifications alongside a UK CyberSecurity Council Principal Professional Title in Security Testing. You will … systems and sensitive commercial environments, making Security Check (SC) clearance essential for role performance. Key Responsibilities Lead complex penetration testing engagements across infrastructure and application domains, ensuring adherence to NCSC CHECK methodologies. Personally conduct advanced security assessments when required, with expertise in network penetration testing, web application security, cloud infrastructure assessment, and modern technology stacks, including containerised environments and microservices … regular status updates and immediate notification of critical findings. Build long-term strategic partnerships through exceptional service delivery and proactive security guidance. Ensure all penetration testing activities comply with NCSC CHECK scheme requirements, maintaining meticulous documentation and audit trails. Implement and maintain quality management processes aligned with ISO 9001 and ISO 27001 standards, driving continuous improvement in service delivery and More ❯
Liverpool, Merseyside, North West, United Kingdom Hybrid / WFH Options
Curveball Solutions
Microsoft 365 security leveraging Purview, Conditional Access, MFA to safeguard modern workplaces. Ensuring compliance with GDPR (DPA 2018), Cyber Essentials (Basic & Plus), and ISO 27001, supported by frameworks like NCSC and NIST. Operating around cybersecurity fundamentals: CIA (Confidentiality, Integrity, Availability), proactive threat prevention, and rapid incident response About You You're naturally aligned with MSP-style work, deeply familiar with … designing and delivering compliance aligned services across GDPR, Cyber Essentials, ISO 27001. Proficient in using Microsoft 365 security stack: Purview, Defender, Conditional Access, MFA. Fluent in cybersecurity frameworks (CIA, NCSC, NIST) and modern threat prevention approaches. Why Curveball Make a real impact : You'll lead the cybersecurity footprint across clients and services. True partnership : We treat clients like collaborators, not More ❯
Birmingham, West Midlands, West Midlands (County), United Kingdom Hybrid / WFH Options
CPS Group (UK) Limited
Security Specialist Role: CyberSecurity Specialist Specialism(s): Microsoft Security, Microsoft Azure Security, Sentinel, Defender, Network Security, Network Configuration, NIST, Cyber Essentials, Gap Analysis, Technical Documentation, CyberSecurity Roadmap, NCSC CAF Type: Contract, Daily Rate IR35 Determination: Inside IR35 (via Umbrella) Pay Rate: £500 - £600 per day (rate to Umbrella) Start: ASAP/Urgent Duration: 3-6 Months Location: Remote … Security products and initiatives as well as deep Microsoft Azure security knowledge. The Consultant will also support the renewing and gaining of CyberSecurity accreditations such as ISO27001, ISO22301, NCSC CAF & NIST. This is a remote-first role, with very occasional on-site meetings. Required Skills & Experience * Excellent Microsoft Security stack knowledge * Demonstrable experience of reviewing, restructuring and hardening Microsoft More ❯
assessments for new applications and infrastructure, translating risks into actionable controls. * Network Security: Design secure network architectures, segmentation strategies, and firewall configurations. * Governance & Compliance: Ensure alignment with NIS regulations, NCSC CAF, and ISO27001 standards. * Stakeholder Engagement: Act as a trusted advisor to senior leaders, translating technical risks into business insights. What You'll Bring Essential: * 5+ years in IT solution … development (architecture, infrastructure, cloud) * Proven experience with threat modelling and security architecture * Strong knowledge of NIS, NCSC CAF, and ISO27001 * Experience working with external audit and certification bodies * Familiarity with Agile, DevOps, and other SDLC methodologies Desirable: * Degree in Computer Science, Engineering, or related field * Experience in regulated environments (e.g., Distribution Network Operators) Who Should Apply? This role is ideal More ❯
Leeds, Yorkshire, United Kingdom Hybrid / WFH Options
Harvey Nash Plc
assessments for new applications and infrastructure, translating risks into actionable controls Network Security: Design secure network architectures, segmentation strategies, and Firewall configurations Governance & Compliance: Ensure alignment with NIS regulations, NCSC CAF, and ISO27001 standards Stakeholder Engagement: Act as a trusted advisor to senior leaders, translating technical risks into business insights. What You'll Bring Essential. 5+ years in IT solution … development (architecture, infrastructure, cloud). Proven experience with threat modelling and security architecture. Strong knowledge of NIS, NCSC CAF, and ISO27001. Experience working with external audit and certification bodies. Familiarity with Agile, DevOps, and other SDLC methodologies Desirable. Degree in Computer Science, Engineering, or related field. Experience in regulated environments (eg, Distribution Network Operators) Who Should Apply? This role is More ❯
Belfast, Northern Ireland, United Kingdom Hybrid / WFH Options
Cyber Guarded Ltd
and client site requirements. Sponsorship is not available. Who we are: Cyber Guarded Ltd is a long-established and independent cybersecurity company based in Belfast. As the premier NCSC-approved supplier for CHECK Penetration Testing in Northern Ireland, including Cyber Incident Exercising being conducted at the highest levels, along with Cyber Advisor - Cyber Essentials, we support clients across both … Cyber Scheme Team Member (CSTM) or CREST Registered Penetration Tester (CRT) or have the technical ability and motivation to gain the above qualifications in the near future to achieve NCSC CHECK Penetration Testing status. What You’ll Do: Perform infrastructure, web, cloud, and OT penetration testing Produce clear, actionable reports and remediation advice Engage with clients through the full testing More ❯