We are seeking an experienced Cybersecurity Project Manager to lead and coordinate projects that strengthen organisational security, resilience,... Read more
We are seeking an experienced Cybersecurity Project Manager to lead and coordinate projects that strengthen organisational security, resilience, and compliance. The successful candidate will manage initiatives from planning through delivery, ensuring that objectives, timelines, budgets, risks, and quality standards are clearly defined and effectively controlled. Projects may include security technology implementations, vulnerability management improvements, identity and access management, cloud security, incident response readiness, regulatory compliance, and business continuity.
Key responsibilities include developing project plans, defining milestones and dependencies, coordinating cross-functional teams, and maintaining clear communication with technical and non-technical stakeholders. You will work closely with cybersecurity, IT, risk, legal, procurement, and business teams to translate security requirements into practical deliverables. The role will involve monitoring progress, managing risks and issues, tracking budgets, preparing status reports, facilitating governance meetings, and ensuring that decisions and actions are properly documented. You will also support vendor management, oversee testing and implementation activities, and contribute to continuous improvements in project delivery processes.
Applicants should have proven experience managing cybersecurity, information technology, or risk-related projects in complex environments. A strong understanding of cybersecurity principles, common control frameworks, data protection requirements, and technology delivery methods is essential. Experience with Agile, waterfall, or hybrid project management approaches is desirable, as is a recognised qualification such as PRINCE2, PMP, AgilePM, or an equivalent certification. Excellent organisational, communication, negotiation, and stakeholder-management skills are required, together with the ability to manage competing priorities and explain technical concepts clearly. You should be confident working independently, comfortable challenging assumptions, and committed to delivering practical, measurable security outcomes.
Read lessEdinburgh, Scotland, United KingdomPermanent
We are seeking a Cyber Security Analyst to help protect critical systems, applications, data and networks from evolving... Read more
We are seeking a Cyber Security Analyst to help protect critical systems, applications, data and networks from evolving cyber threats. In this role, you will monitor security events, investigate suspicious activity and support the timely detection, containment and resolution of incidents. You will work closely with technology, infrastructure and business teams to strengthen security controls, reduce risk and promote effective security practices across the organisation.
Key responsibilities include reviewing alerts from security monitoring platforms, analysing logs and network activity, conducting initial incident triage and escalating significant events in line with established procedures. You will contribute to vulnerability management by reviewing scan results, prioritising remediation activities and tracking actions through to completion. The role will also involve supporting endpoint, identity and access security, assisting with threat hunting, maintaining accurate incident records and contributing to post-incident reviews. You may be asked to support security assessments, audit requests, policy updates, awareness activities and the continuous improvement of monitoring and response processes.
The successful candidate will have experience in a cyber security operations, security analysis or related technical role, with a sound understanding of incident response, network security, vulnerability management and common attack techniques. Familiarity with SIEM, EDR, vulnerability scanning and ticketing tools is highly desirable, along with the ability to interpret logs and investigate events methodically. Relevant certifications or training in cyber security are welcome but not essential. You should be analytical, curious and able to communicate technical findings clearly to both technical and non-technical audiences. Strong organisation, sound judgement, attention to detail and a commitment to confidentiality are essential. This is an opportunity to develop your expertise while contributing to a proactive, resilient and risk-aware security environment.
Read lessEdinburgh, Scotland, United KingdomPermanent
We are seeking a Security Operations Manager – Cryptography to lead the delivery, governance, and continuous improvement of... Read more
We are seeking a Security Operations Manager – Cryptography to lead the delivery, governance, and continuous improvement of cryptographic security operations across a complex technology environment. This role will be responsible for ensuring that encryption, key management, certificates, secrets, and related security controls are implemented, monitored, and maintained in line with regulatory requirements and industry best practice. You will provide operational leadership while working closely with information security, infrastructure, cloud, engineering, risk, and compliance teams.
Key responsibilities include managing cryptographic services and platforms; overseeing the lifecycle of encryption keys, digital certificates, and secrets; establishing and enforcing standards, procedures, and control frameworks; and ensuring effective backup, recovery, rotation, revocation, and compromise-response processes. You will lead the investigation and resolution of cryptographic incidents, coordinate vulnerability remediation, support audits, and maintain accurate documentation, inventories, risk assessments, and performance metrics. The role will also contribute to security architecture and transformation initiatives, including cloud adoption, automation, hardware security module operations, public key infrastructure, and the implementation of modern cryptographic capabilities. You will manage operational priorities, suppliers, service performance, and improvement plans, while coaching and developing team members.
The successful candidate will have substantial experience in cryptography, information security, or security operations, with a strong understanding of encryption algorithms, key management principles, certificates, PKI, TLS, secrets management, and hardware security modules. Experience operating cryptographic services across on-premises and cloud environments, together with knowledge of relevant regulatory and control frameworks, is highly desirable. You should be confident managing incidents and risk, communicating with technical and senior stakeholders, and translating complex security requirements into practical operational processes. Strong leadership, analytical, organisational, and problem-solving skills are essential. Professional certifications in information security, risk, cloud, or cryptography would be advantageous.
Read lessEdinburgh, Scotland, United KingdomPermanent
We are seeking a Cyber Risk Analyst to support the identification, assessment, and management of information and cyber... Read more
We are seeking a Cyber Risk Analyst to support the identification, assessment, and management of information and cyber security risks across the organisation. In this role, you will work with technology, security, compliance, and business teams to maintain a clear view of the cyber risk landscape and help ensure that appropriate controls are designed, implemented, and monitored. You will contribute to risk assessments for systems, applications, suppliers, projects, and business processes, providing practical recommendations that support informed decision-making.
Your responsibilities will include maintaining risk registers, reviewing control effectiveness, tracking remediation activities, and preparing clear reports for risk and governance forums. You will support the development and monitoring of key risk indicators, assist with security assurance and audit activities, and help assess the impact of emerging threats, vulnerabilities, and regulatory requirements. You will also contribute to third-party risk reviews, policy and standards updates, incident lessons learned, and continuous improvement of cyber risk management processes. The role requires you to communicate complex technical and risk issues clearly to both technical and non-technical stakeholders.
Applicants should have experience in cyber security, technology risk, information security, audit, compliance, or a related discipline, together with a sound understanding of risk management principles and security frameworks such as ISO 27001, NIST, or CIS Controls. Familiarity with governance, risk, and compliance tools, vulnerability management, cloud environments, data protection, and supplier assurance would be advantageous. Strong analytical, writing, organisational, and stakeholder-management skills are essential, along with the ability to challenge constructively and prioritise competing demands. Relevant professional qualifications, such as CRISC, CISA, CISSP, or equivalent experience, are desirable. You will be expected to demonstrate integrity, attention to detail, curiosity, and a proactive approach to identifying and reducing cyber risk.
Read lessEdinburgh, Scotland, United KingdomPermanent
We are seeking a Cyber Risk Analyst to support the identification, assessment and management of information security and... Read more
We are seeking a Cyber Risk Analyst to support the identification, assessment and management of information security and technology risks across the organisation. In this role, you will work with stakeholders across technology, operations, compliance and internal audit to assess cyber risks, maintain accurate risk records and promote effective risk management practices. You will help ensure that security risks are understood, prioritised and addressed in line with business objectives, regulatory expectations and established policies.
Your responsibilities will include conducting cyber and technology risk assessments; reviewing control effectiveness; identifying gaps and recommending practical remediation actions; maintaining risk registers, issues logs and supporting documentation; and preparing clear reports for management and relevant governance forums. You will contribute to third-party and supplier risk assessments, support security reviews for projects and changes, monitor remediation progress and assist with the development of risk metrics and dashboards. You may also support incident and control reviews, policy updates, audit activity and the ongoing improvement of risk management frameworks, procedures and reporting.
The successful candidate will have experience in cyber security, information technology risk, technology controls, compliance or a related discipline, together with a sound understanding of common security principles, risk assessment methodologies and control frameworks. Familiarity with standards such as ISO 27001, NIST, COBIT or similar frameworks is desirable. You should be analytical, well organised and comfortable interpreting technical information for both technical and non-technical audiences. Strong written and verbal communication skills, sound judgement and the ability to manage competing priorities are essential. Relevant professional qualifications in information security, risk management or audit are advantageous. This role offers the opportunity to influence security outcomes, build relationships across the business and contribute to a mature, risk-aware culture.
Read lessEdinburgh, Scotland, United KingdomPermanent
We are seeking a Consultant/Senior Consultant, Cyber Strategy & Transformation to support organisations in strengthening their cyber resilience,... Read more
We are seeking a Consultant/Senior Consultant, Cyber Strategy & Transformation to support organisations in strengthening their cyber resilience, managing risk and delivering sustainable transformation. Working with senior stakeholders across technology, risk and business functions, you will help clients understand their current cyber maturity, define future-state capabilities and develop practical strategies aligned to business priorities and regulatory expectations.
You will contribute to a diverse range of engagements, including cyber operating model design, target-state architecture, security governance, risk management, regulatory and compliance assessments, transformation roadmaps, resilience programmes and technology-enabled change. Responsibilities may include conducting current-state assessments, analysing risks and control environments, facilitating workshops, gathering and documenting requirements, developing business cases, preparing executive-level presentations and supporting the implementation of strategic initiatives. At Senior Consultant level, you will also be expected to lead workstreams, manage client relationships, coach junior colleagues and contribute to proposals and thought leadership.
Applicants should have experience in cyber security, technology risk, information security, digital transformation or a related advisory environment. Strong knowledge of cyber frameworks, risk and control principles, governance models and emerging security trends is desirable, alongside the ability to translate complex technical issues into clear business recommendations. Relevant professional qualifications or certifications are advantageous. You will need excellent analytical, communication and stakeholder management skills, a structured approach to problem-solving and the confidence to work independently in fast-paced, changing environments. The role may involve working across multiple projects and locations, with opportunities to develop specialist expertise and progress within a collaborative consulting team.
Read lessEdinburgh, Scotland, United KingdomPermanent
We are seeking a Manager/Senior Manager, Cyber Strategy & Transformation to help organisations strengthen their cyber resilience, manage... Read more
We are seeking a Manager/Senior Manager, Cyber Strategy & Transformation to help organisations strengthen their cyber resilience, manage technology risk and respond to an increasingly complex threat landscape. In this role, you will work with senior stakeholders to define practical, business-aligned cyber strategies and lead transformation initiatives from initial assessment through to implementation. You will bring structure to complex challenges, identify opportunities for improvement and help establish sustainable operating models, governance frameworks and risk management practices.
Your responsibilities will include assessing current cyber capabilities, maturity and control environments; developing target-state strategies, roadmaps and investment cases; and supporting the design of security operating models, policies and governance processes. You will lead or contribute to projects covering areas such as cyber risk management, identity and access management, cloud security, security architecture, incident response, third-party risk and regulatory compliance. You will manage project plans, budgets, deliverables and risks, while producing clear reports and recommendations for executive and board-level audiences. The role will also involve coaching junior team members, contributing to business development and maintaining strong relationships with clients and key stakeholders.
Applicants should have significant experience in cyber security, technology risk, digital transformation or a related advisory environment, with a track record of delivering strategy and transformation programmes. You will have strong knowledge of cyber security principles, governance frameworks, risk methodologies and relevant industry standards, together with the ability to translate technical issues into clear business implications. Excellent communication, stakeholder management, analytical and presentation skills are essential. Experience leading multidisciplinary teams, managing multiple priorities and working with senior decision-makers is highly desirable. Relevant professional certifications, such as CISSP, CISM, CRISC, SABSA or equivalent, would be advantageous. A proactive, commercially aware and collaborative approach is essential, along with the ability to operate effectively in ambiguous and fast-paced environments.
Read lessEdinburgh, Scotland, United KingdomPermanent
We are seeking a Senior Identity and Full-Stack Engineer to design, build and operate secure identity experiences across... Read more
We are seeking a Senior Identity and Full-Stack Engineer to design, build and operate secure identity experiences across web applications and internal platforms. You will work across authentication, authorisation, user lifecycle management, and access governance, while contributing to the development of reliable, scalable front-end and back-end services. This role is ideal for an engineer who enjoys solving complex security and product challenges and can translate business needs into clear, maintainable technical solutions.
Your responsibilities will include developing and enhancing identity services such as single sign-on, multi-factor authentication, role-based access control, provisioning, and account recovery. You will build customer-facing interfaces and supporting APIs, integrate with external identity providers, and improve the security, performance and usability of existing systems. You will contribute to architectural decisions, write automated tests, conduct code reviews, troubleshoot production issues, and help establish observability, documentation and engineering standards. You will also collaborate closely with product, security, infrastructure and compliance stakeholders to deliver well-governed solutions without compromising user experience.
You should have substantial experience in full-stack software engineering and a strong understanding of modern identity and security concepts, including OAuth 2.0, OpenID Connect, SAML, JWTs, session management and secure API design. Proficiency with a modern front-end framework, a server-side language, relational or NoSQL databases, and cloud-based development is expected. Experience designing highly available services, working with CI/CD pipelines, infrastructure as code and containerised environments would be valuable. You will be comfortable working autonomously, communicating technical decisions clearly, mentoring other engineers and balancing delivery with long-term quality. A methodical approach to security, privacy and operational resilience is essential.
Read lessEdinburgh, Scotland, United KingdomPermanent
We are seeking a Principal Engineer – Identity & Privacy to provide technical leadership across the design, delivery,... Read more
We are seeking a Principal Engineer – Identity & Privacy to provide technical leadership across the design, delivery, and evolution of secure identity platforms and privacy-focused capabilities. You will help shape the technical direction for authentication, authorisation, identity lifecycle management, consent, data protection, and access governance across a complex digital environment. Working at principal level, you will influence architecture decisions, establish engineering standards, and ensure that solutions are scalable, resilient, compliant, and straightforward for customers and internal teams to use.
Your responsibilities will include defining reference architectures and technical strategies; leading the delivery of identity and privacy initiatives from discovery through to production; and mentoring engineers and technical leaders. You will collaborate closely with product, security, legal, risk, compliance, and platform teams to translate regulatory and business requirements into practical engineering outcomes. You will also identify and manage technical risks, improve observability and operational resilience, support incident response, and promote secure-by-design and privacy-by-design principles throughout the software development lifecycle.
To succeed in this role, you will have significant experience designing and operating identity and access management solutions in large-scale or distributed environments. You will bring strong knowledge of authentication and authorisation standards and protocols, such as OAuth 2.0, OpenID Connect, SAML, SCIM, and multi-factor authentication, together with an understanding of privacy engineering, consent management, data minimisation, retention, and regulatory expectations. Experience with cloud platforms, modern software development practices, APIs, event-driven architectures, and infrastructure automation is highly desirable. You will be an effective communicator who can explain complex technical concepts clearly, influence decisions without relying on formal authority, and balance long-term strategy with pragmatic delivery. A strong commitment to security, customer trust, continuous improvement, and inclusive collaboration is essential.
Read lessEdinburgh, Scotland, United KingdomPermanent
We are seeking an experienced Associate Director, OT & Cybersecurity to lead the development and execution of security... Read more
We are seeking an experienced Associate Director, OT & Cybersecurity to lead the development and execution of security strategies across operational technology (OT), industrial control systems, and connected infrastructure. This senior role will be responsible for protecting critical environments, reducing cyber risk, and ensuring that security is embedded into operational resilience, engineering, and technology programmes. You will provide strategic direction while working closely with information security, engineering, operations, risk, compliance, and technology teams.
Key responsibilities include defining and maintaining the OT cybersecurity roadmap, policies, standards, and governance framework; overseeing risk assessments, security architecture, vulnerability management, incident response, and security monitoring across OT environments; and ensuring appropriate controls are implemented throughout the design, deployment, and lifecycle of industrial systems. You will lead the assessment of emerging threats, coordinate responses to cyber incidents, and support business continuity and disaster recovery planning. The role will also involve managing third-party and supply-chain security, contributing to audits and regulatory requirements, and providing clear reporting on risk, control effectiveness, and remediation progress to senior stakeholders.
The successful candidate will bring substantial experience in OT, ICS, SCADA, industrial networks, or critical infrastructure cybersecurity, together with a strong understanding of enterprise security principles and risk management. Experience leading multidisciplinary teams, complex transformation programmes, and security improvements across geographically distributed environments is highly desirable. You should be confident engaging with executives, technical specialists, operational teams, and external partners, translating complex security issues into practical business actions. Relevant certifications such as CISSP, CISM, GIAC, ISA/IEC 62443, or comparable qualifications are advantageous. Strong communication, influencing, analytical, and decision-making skills are essential, alongside a pragmatic approach to balancing security, safety, availability, and operational performance.
Read lessEdinburgh, Scotland, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria