encryption, identity and access management (IAM), and security information and event management (SIEM) systems. Strong understanding of security frameworks, standards, and regulations, including ISO 27001, NIST Cybersecurity Framework, GDPR , NCSCCyber Essentials Plus, with experience in implementing and maintaining compliance with these requirements. Excellent leadership and communication skills, with the ability to effectively communicate security-related concepts and risks to More ❯
produce CS&IA incident response plans and coordinate desktop incident response exercises. Broad knowledge and application of common CS&IA bodies, standards, frameworks, guidelines and legislation, including: HMG/NCSC Information Assurance Policies, Standards and Guidelines Cross-government security accreditation and secure by design processes JSP440 (plus other standard MoD IA methods) DCPP’s CyberSecurity Model List X, List More ❯
certification in CI/CD methodology. Relevant vendor certifications (e.g. Microsoft, VMware, Cisco, AWS). Relevant certifications in architecture methodologies. Relevant certifications in agile delivery methodologies. Practical experience implementing NCSC guidance and best practice. Seniority level Not Applicable Employment type Full-time Job function Consulting, Information Technology, and Engineering Industries Defense and Space Manufacturing, IT Services and IT Consulting, and More ❯
London, England, United Kingdom Hybrid / WFH Options
Swyft, Llc
security solutions, working closely with clients to design, deploy, and optimize Swyft’s Velocity platform for advanced threat detection and response. Ensure adherence to UK/EU cybersecurity regulations ( NCSC guidelines, GDPR, NIS Directive ) and implement security controls in alignment with industry standards ( ISO 27001, CIS, NIST ). Engage with Swyft executives, CISOs, and IT security teams to drive cybersecurity More ❯
Horley, England, United Kingdom Hybrid / WFH Options
Tiger Resourcing Group
security requirements into secure, compliant, and cost-effective Azure solutions. Collaborate with cybersecurity teams to ensure solutions meet UK government security classifications, accreditation processes, and relevant compliance frameworks (eg NCSC, MOD JSP, ISO 27001). Support deployment automation and Infrastructure-as-Code (IaC) approaches leveraging Azure Resource Manager (ARM), Bicep, or Terraform. Conduct Azure cost optimisation, performance tuning, and cloud More ❯
Bristol, England, United Kingdom Hybrid / WFH Options
Made Tech
Knowledge of cloud vendor partner programs, such as AWS APN and Azure Partners Experience with well-architected frameworks Knowledge of UK public sector technology guidance and frameworks, such as NCSC's Cyber Assessment Framework (CAF) and the Technology Code of Practice (TCoP) Familiarity with Python, Bash and JavaScript Agile practices such as Scrum, XP, and/or Kanban Experience using More ❯
diagrams. Define and implement cloud best practices around security, automation, and cost optimisation. Provide AWS architectural guidance in migration, modernization, and greenfield projects. Ensure compliance with governance frameworks, including NCSC guidelines and internal controls. Essential Skills and Experience: Current and valid SC Clearance (must be active). Proven experience as an AWS Solutions Architect in secure and regulated environments. Strong … modernization and cloud migration strategies. Excellent stakeholder engagement, documentation, and communication skills. AWS Certified Solutions Architect – Professional/Associate . Familiarity with government standards and frameworks (e.g., G-Cloud, NCSC principles). Experience working with CI/CD pipelines , DevSecOps , and Agile delivery methodologies . Experience with hybrid cloud environments or multi-cloud strategies. Competitive salary and performance-based bonus More ❯
/CD) Familiar with scripting languages like PowerShell, YAML, JSON Expertise in application security tools and DevSecOps processes Understanding of key frameworks and standards (e.g. OWASP, NIST SSDF, ISO27001, NCSC) Experience with threat modelling, risk assessments, and secure design reviews Comfortable owning security strategy and tooling across complex, modern product landscapes Strong communicator - able to engage confidently with both engineers More ❯
Farnborough, England, United Kingdom Hybrid / WFH Options
Parico
implementing infrastructure components for the following Windows, Linux and Virtualisaiton technologies: -Windows Server 2019/2022 Active Directory and NTFS permissions DNS DHCP File Services Group Policy, CIS and NCSCSecurity Hardening NTP SQL Server Windows Server Update Server (WSUS) -Cloud AWS Azure -Virtualisation VMware vSphere VMware vCentre Microsoft Hyper-V Our Ideal Candidate: Constructing Windows and Linux infrastructure components More ❯
The salary for this role is £55,000. Do you bring a wealth of experience in leading and mentoring technical teams in an Azure Engineering or Technical Manager/Lead capacity, with a comprehensive understanding of Identity, Integration, and DevOps More ❯
London, England, United Kingdom Hybrid / WFH Options
Actica Consulting Limited
We have a long track record of delivery and are trusted to work on some of the UK Government’s most important and sensitive projects. We are a NationalCyberSecurityCentre Assured Service Provider. The Role and Responsibilities of a CyberSecurity Consultant: As a CyberSecurity Consultant, you will: Provide expert advice and guidance on Information Assurance topics. More ❯
by attainment of appropriate qualifications e.g. CISSP, ISO27001 Lead Implementor or relevant SANS GIAC or equivalent Knowledge of the NIST framework, PCI DSS, GDPR and NIS as well as NCSCcyber guidance. Experience working in an agile delivery environment would be highly advantageous. Specific cyber knowledge and demonstrable experience in at least one of the following areas: Cloud security, network More ❯
Firewalls, FortiAnalyzer, FortiManager. Knowledge of vulnerability management platforms (Tenable/Nessus/Qualys). Knowledge of threat intelligence, risk management, and cyber incident response frameworks. In-depth knowledge of NCSCCyber Assessment Framework (CAF), PSN Compliance, Cyber Essentials, NIST, or ISO 27001. Qualifications: Degree or equivalent level qualification or experience. ITIL Foundation certification or equivalent. Professional Security Certifications CISSP, CISM More ❯
We're Looking For Strong knowledge of cyber risk management and frameworks (ISO27005, NIST). Experience in security architecture, cloud security, and risk assessment . Understanding of HMG and NCSCsecurity policies, standards, and guidance . Excellent communication skills with the ability to translate security risks into business terms . Ability to work independently and collaboratively in a client-facing More ❯
London, England, United Kingdom Hybrid / WFH Options
Techwaka
addressing vulnerabilities and threats. Key Responsibilities: Vulnerability Management: Develop, implement, and operate vulnerability management capabilities using tools like Tenable One. Deploy, configure, and manage vulnerability assessment tools (e.g., Tenable, NCSC's Active Cyber Defence Toolkit) and Attack Surface Management tools. Deliver a seamless vulnerability management service across infrastructure and business units, ensuring the effectiveness of security measures. Threat Analysis: Utilize … with cross-functional teams. In-depth understanding of the current threat landscape and security best practices. Preferred Qualifications: Relevant certifications (e.g., CISSP, CEH, CompTIA Security+). Experience with the NCSC's Active Cyber Defence Toolkit. Familiarity with regulatory requirements and industry standards (e.g., GDPR, ISO 27001). Work Environment: This is a fully remote position, offering flexibility and the opportunity More ❯
London, England, United Kingdom Hybrid / WFH Options
F5 Consultants
role Experience in customer-facing roles Familiarity with HMG/MoD cyber policies, standards (e.g. JSP440), and processes Experience with Secure by Design implementation and related tooling Knowledge of NCSCCyber Assurance Framework (CAF) and GovAssure audits Understanding of NIST CyberSecurity Framework and risk assessment methods Experience with ISO/IEC 27001 audits and cybersecurity assurance Supplier assurance More ❯
Easter Howgate, Midlothian, United Kingdom Hybrid / WFH Options
Leonardo UK Ltd
platform lockdown and configurations. It would be nice if you had: Understanding of the engineering lifecycle. Knowledge of current Cryptographic technologies,Key ManagementSystems & practicalCOMSECimplementations in line with MOD/NCSC standards. Knowledge of CyberSecurity & Airworthiness (RCTA-DO-326A/B, 355A & 356A). Security Clearance You must be eligible for full security clearance. For more information and guidance please … including Defence, Telecommunications, Energy and Finance to help secure national infrastructure and commerce in the UK and beyond. Our Practice is certified by the UK NationalCyberSecurityCentre (NCSC) in the provision of advice and guidance to our customers. At Leonardo UK, we believe that a diverse and inclusive work environment unlocks our people's full potential and drives More ❯
Edinburgh, Scotland, United Kingdom Hybrid / WFH Options
hackajob
configurations. It Would Be Nice If You Had Understanding of the engineering lifecycle. Knowledge of current Cryptographic technologies, Key Management Systems & practical COMSEC implementations in line with MOD/NCSC standards. Knowledge of CyberSecurity & Airworthiness (RCTA-DO-326A/B, 355A & 356A). Security Clearance You must be eligible for full security clearance. For more information and guidance please … including Defence, Telecommunications, Energy and Finance to help secure national infrastructure and commerce in the UK and beyond. Our Practice is certified by the UK NationalCyberSecurityCentre (NCSC) in the provision of advice and guidance to our customers. At Leonardo UK, we believe that a diverse and inclusive work environment unlocks our people’s full potential and drives More ❯
managing and working with near-shore and off-shore technology teams in order to successfully deliver security solutions. You will also have a deep understanding and experience of UK NCSC Government guidelines and standards in order to ensure compliance throughout. What You'll Be Doing Designing and implementing security controls for the managed tenant and service layer. Validating the design … overseeing all audit requirements requested by the NHSE CISO. Creating the System Level Security Policy (SLSP) for NBSS. Documenting and enforcing security policies and procedures to ensure compliance with NCSC standards and regulations. Investigating security breaches, analysing logs and network traffic to detect suspicious activity, and coordinating response actions to minimize damage. Educating the team on secure design and coding … Azure. Experience in designing, implementing, and maintaining security measures. Proven ability to build and manage relationships with key stakeholders in a complex organisation. Deep understanding and experience with UK NCSC Government guidelines and standards. Please note that successful applicants will be required to pass Security Check (SC) clearance for this role. In order to be considered, you must have resided More ❯
City of London, England, United Kingdom Hybrid / WFH Options
Parser
environments. Perform hands-on threat and risk assessments across cloud, network, and infrastructure stacks; specify mitigating controls where needed. Align security practices with NIST, PCI DSS, GDPR, NIS, and NCSC guidance. Influence senior delivery colleagues and third-party partners, driving security decisions without direct authority. Implement security-by-design frameworks at the portfolio scale and support organizational change. Provide independent … with a focus on Agile/DevOps. Expertise in threat and risk assessments across cloud, network, and infrastructure stacks. Strong working knowledge of NIST, PCI DSS, GDPR, NIS, and NCSC guidance. Relevant certifications such as CISSP, ISO 27001 Lead Implementer, or SANS GIAC (or equivalent). Proven track record of influencing senior colleagues and third-party partners without direct authority. More ❯
London, England, United Kingdom Hybrid / WFH Options
Department for Business and Trade
and concise written and verbal communications to senior stakeholders on complex issues Relevant certifications such as GRCP, ISC2 CGRC, or CRISC or willingness to obtain Experience of working with NCSC & CAF cybersecurity standards and guidance Excellent leadership skills, with an ability to build, motivate and inspire teams through periods of ambiguity, comfortable working in a complex environment and across More ❯
of security technologies such as firewalls, IDS/IPS, endpoint protection, encryption, IAM, and SIEM systems. Strong understanding of security frameworks and standards, including ISO 27001, NIST, GDPR, and NCSCCyber Essentials Plus, with experience in compliance management. Excellent leadership and communication skills, capable of conveying security concepts to diverse audiences and building consensus. Analytical skills and problem-solving abilities More ❯
to resolution ? Running tailored security awareness training for teams ? Maintaining continuous oversight of emerging threats, vulnerabilities, and ensuring swift action ? Supporting alignment with future certification frameworks such as GovAssure, NCSC CAF, ISO27001 Requirements: ? In-depth knowledge of NIST, ISO27001, ISO27701, NCSC, and Cabinet Office security best practices Proven track record across full security lifecycle: risk management, governance, incidents, pen testing More ❯
to resolution ? Running tailored security awareness training for teams ? Maintaining continuous oversight of emerging threats, vulnerabilities, and ensuring swift action ? Supporting alignment with future certification frameworks such as GovAssure, NCSC CAF, ISO27001 Requirements: ? In-depth knowledge of NIST, ISO27001, ISO27701, NCSC, and Cabinet Office security best practices Proven track record across full security lifecycle: risk management, governance, incidents, pen testing More ❯
to resolution ? Running tailored security awareness training for teams ? Maintaining continuous oversight of emerging threats, vulnerabilities, and ensuring swift action ? Supporting alignment with future certification frameworks such as GovAssure, NCSC CAF, ISO27001 Requirements: ? In-depth knowledge of NIST, ISO27001, ISO27701, NCSC, and Cabinet Office security best practices Proven track record across full security lifecycle: risk management, governance, incidents, pen testing More ❯