We are seeking an IT Security Engineer (AI) to help protect critical systems, data, and services in an... Read more
We are seeking an IT Security Engineer (AI) to help protect critical systems, data, and services in an increasingly intelligent and interconnected technology environment. In this role, you will design, implement, and maintain security controls across cloud, on-premises, and AI-enabled platforms. You will work closely with infrastructure, software engineering, data, and risk teams to identify vulnerabilities, reduce exposure, and ensure that security is embedded throughout the technology lifecycle.
Your responsibilities will include monitoring security events, investigating and responding to incidents, conducting vulnerability assessments, and supporting penetration testing and remediation activities. You will develop and maintain security policies, technical standards, threat models, and secure configuration baselines. A key part of the role will involve assessing AI and machine-learning solutions for risks such as data leakage, model manipulation, prompt injection, insecure integrations, unauthorised access, and misuse of sensitive information. You will also contribute to identity and access management, endpoint protection, network security, encryption, logging, and security automation initiatives.
The successful candidate will have proven experience in IT security engineering, cybersecurity operations, or a related technical discipline, along with strong knowledge of security principles, threat detection, incident response, and risk management. Experience securing cloud environments, APIs, CI/CD pipelines, containers, or AI and machine-learning systems is highly desirable. Familiarity with industry frameworks and standards such as ISO 27001, NIST, CIS Controls, or relevant data-protection requirements would be advantageous. You should be analytical, practical, and confident communicating technical risks to both specialist and non-specialist audiences. Relevant certifications such as CISSP, CISM, Security+, Azure Security Engineer, or equivalent experience are welcomed.
Read lessLeeds, England, United KingdomPermanent
We are seeking an AI Security Engineer to help design, implement, and maintain security controls for artificial intelligence... Read more
We are seeking an AI Security Engineer to help design, implement, and maintain security controls for artificial intelligence and machine learning systems. You will work across engineering, data science, infrastructure, and risk teams to identify threats, strengthen system resilience, and support the secure development and deployment of AI-enabled products. The role will involve assessing models, data pipelines, APIs, cloud environments, and supporting services throughout their lifecycle.
Your responsibilities will include conducting threat modelling and security assessments for AI workloads; identifying risks such as prompt injection, data poisoning, model extraction, adversarial manipulation, insecure integrations, and unintended data disclosure; and developing practical mitigations. You will create and maintain security requirements, testing strategies, monitoring processes, and incident response playbooks. You will also support vulnerability management, security reviews, red-team exercises, access-control design, secrets management, and compliance activities. Clear documentation and communication will be essential, as you will present technical findings and recommendations to both technical and non-technical stakeholders.
Applicants should have professional experience in cybersecurity, application security, cloud security, or a related engineering discipline, together with a strong understanding of machine learning concepts and AI system architectures. Experience securing large language models, generative AI applications, APIs, containers, and cloud platforms is highly desirable. Familiarity with secure software development practices, identity and access management, network security, threat intelligence, and common security frameworks will be valuable. Programming or scripting experience in languages such as Python, Java, or Go is expected, along with the ability to automate security testing and analysis. We are looking for someone who is analytical, collaborative, curious, and comfortable working in a fast-changing environment. Relevant certifications or demonstrable experience in AI security, application security, penetration testing, or cloud security are advantageous.
Read lessLeeds, England, United KingdomPermanent
We are seeking a Principal Cyber Security Risk Manager to lead the development and delivery of a mature,... Read more
We are seeking a Principal Cyber Security Risk Manager to lead the development and delivery of a mature, enterprise-wide cyber security risk management framework. In this senior role, you will provide authoritative advice on cyber risk, resilience and control effectiveness, helping business and technology leaders make informed decisions in a complex and evolving threat landscape. You will work across multiple functions to ensure that security risks are identified, assessed, recorded and managed in line with agreed risk appetite and regulatory expectations.
Your responsibilities will include defining risk management methodologies, standards and reporting practices; overseeing risk assessments for strategic initiatives, systems, suppliers and major change programmes; and challenging control owners to develop effective remediation plans. You will maintain clear oversight of cyber risk exposure, emerging threats, vulnerabilities and control gaps, providing concise reports and insights to senior governance forums. You will also support the development of key risk indicators, risk acceptance processes, scenario analysis and assurance activities, while contributing to incident, crisis and operational resilience planning where appropriate.
You will bring significant experience in cyber security, technology risk, information security or a closely related discipline, with a proven record of operating at a strategic or principal level. Strong knowledge of recognised security and risk frameworks, control principles, regulatory requirements and third-party risk management is essential. You should be confident interpreting complex technical issues and translating them into clear business impacts and practical recommendations for senior stakeholders. Excellent communication, influencing and relationship-building skills are required, alongside the ability to work independently, manage competing priorities and provide constructive challenge. Professional certifications in cyber security, audit, risk or governance would be advantageous.
Read lessLeeds, England, United KingdomPermanent
We are seeking a Principal Cyber Security Engineer to provide technical leadership across the design, implementation and continuous... Read more
We are seeking a Principal Cyber Security Engineer to provide technical leadership across the design, implementation and continuous improvement of enterprise security capabilities. You will define security architecture and engineering standards, guide the adoption of secure-by-design principles, and advise technology and delivery teams on risk-based controls. The role will involve shaping security strategy, translating regulatory and business requirements into practical solutions, and acting as a senior technical authority for complex security decisions.
Key responsibilities will include leading the development of security patterns for cloud, on-premises and hybrid environments; assessing solutions, applications and infrastructure for vulnerabilities and design weaknesses; and overseeing the implementation of identity and access management, network security, endpoint protection, encryption, logging and monitoring controls. You will support threat modelling, security reviews, penetration testing and incident response, while helping to improve detection, resilience and recovery capabilities. You will also contribute to security governance, risk assessments, technical standards and remediation plans, working closely with engineering, architecture, operations, compliance and third-party teams.
The successful candidate will have substantial experience in cyber security engineering or architecture, with a strong understanding of modern infrastructure, cloud platforms, application security, networking and security operations. Relevant professional certifications or equivalent practical experience are desirable. You will be confident analysing complex technical risks, communicating clearly with both technical and non-technical stakeholders, and influencing outcomes without relying on direct authority. A track record of delivering security improvements in large or complex environments, alongside knowledge of recognised security frameworks and standards, is essential. The ability to mentor engineers, challenge existing approaches constructively and remain current with emerging threats and technologies will be central to success in this role.
Read lessLeeds, England, United KingdomPermanent
We are seeking a skilled Penetration Tester to join a remote security team supporting clients across the UK.... Read more
We are seeking a skilled Penetration Tester to join a remote security team supporting clients across the UK. In this role, you will assess the security of networks, applications, cloud environments and infrastructure, identifying vulnerabilities before they can be exploited. You will plan and conduct authorised penetration tests, perform reconnaissance and threat modelling, exploit weaknesses safely, and evaluate the potential business impact of your findings. The role may involve web application, API, internal and external infrastructure, wireless, mobile, social engineering and cloud security assessments.
You will be responsible for maintaining clear testing documentation, capturing reliable evidence and producing high-quality technical reports for both technical and non-technical audiences. You will explain vulnerabilities, rate risk appropriately and provide practical remediation guidance. You may also present findings to stakeholders, support retesting activities and contribute to improving testing methodologies, tooling and internal security practices. All work must be conducted ethically, professionally and in accordance with agreed rules of engagement, relevant legislation and recognised security standards.
Applicants should have commercial penetration testing experience and a strong understanding of common attack techniques, vulnerability management and secure configuration principles. Experience with tools such as Burp Suite, Nmap, Metasploit, Kali Linux and relevant scripting languages is expected, alongside the ability to interpret source code or troubleshoot complex technical environments. Industry certifications such as CREST, OSCP, CHECK, CRT or equivalent are advantageous. Strong written and verbal communication skills are essential, as is the ability to manage competing assignments independently while working remotely. You should be curious, methodical and committed to continuous professional development. The successful candidate must be eligible to work in the UK and be available to work remotely, with occasional travel if required.
Read lessLeeds, England, United KingdomPermanent
We are seeking a skilled Cyber Security Engineer to help protect critical systems, applications, networks and data from... Read more
We are seeking a skilled Cyber Security Engineer to help protect critical systems, applications, networks and data from evolving cyber threats. In this role, you will contribute to the design, implementation and continuous improvement of security controls across a complex technology environment. You will work closely with infrastructure, software development, cloud and operations teams to embed security throughout the technology lifecycle and support a strong culture of risk awareness.
Your responsibilities will include monitoring and investigating security alerts, conducting vulnerability assessments, supporting incident response activities and recommending appropriate remediation. You will help maintain and improve security tools such as SIEM, endpoint detection and response, vulnerability management and identity and access management platforms. The role will also involve reviewing system and application changes, assisting with penetration testing, developing security documentation and procedures, and contributing to audits, risk assessments and compliance initiatives. You will stay informed about emerging threats and provide practical advice to improve resilience against them.
Applicants should have proven experience in cyber security engineering, security operations or a closely related technical discipline, along with a strong understanding of networking, operating systems, cloud technologies and common attack techniques. Experience with security monitoring, threat detection, incident handling, scripting or automation is highly desirable. Familiarity with recognised security frameworks and standards, such as NIST, ISO 27001 or CIS Controls, would be advantageous. Strong analytical and problem-solving skills are essential, as is the ability to communicate technical risks clearly to both technical and non-technical audiences. Relevant professional certifications, such as Security+, CySA+, CISSP, GIAC or cloud security certifications, are welcome but not essential.
Read lessLeeds, England, United KingdomPermanent
We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance... Read more
We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives. In this role, you will help strengthen the organisation’s security posture by developing and maintaining cybersecurity policies, standards, procedures and control frameworks aligned with recognised industry practices and regulatory requirements. You will work closely with technology, risk, legal, audit and business stakeholders to translate security objectives into practical, measurable and sustainable outcomes.
Your responsibilities will include leading cybersecurity risk assessments, control evaluations, compliance reviews and third-party risk assessments; identifying gaps; and recommending prioritised remediation plans. You will coordinate evidence collection and responses for internal and external audits, track control effectiveness and provide clear reporting to senior leadership. The role will also involve supporting regulatory and customer assurance activities, maintaining risk registers, advising on security requirements for projects and suppliers, and contributing to the continuous improvement of governance processes. You will mentor consultants and colleagues, promote a strong culture of accountability, and lead workshops to improve awareness of cybersecurity risk and control ownership.
To be successful, you will have substantial experience in cybersecurity governance, risk and compliance, with a strong understanding of frameworks such as ISO 27001, NIST CSF, COBIT or similar. Experience with regulatory obligations, privacy principles, security control testing, audit management and third-party risk is highly desirable. Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor are advantageous. You will bring excellent analytical, communication and stakeholder management skills, with the ability to present complex information clearly to both technical and non-technical audiences. A proactive, collaborative approach, strong attention to detail and the confidence to influence at all levels are essential.
Read lessLeeds, England, United KingdomPermanent
We are seeking a Senior Application Security Engineer to help strengthen the security of modern software products and... Read more
We are seeking a Senior Application Security Engineer to help strengthen the security of modern software products and services across their full development lifecycle. In this role, you will work closely with software engineers, architects, product teams and infrastructure specialists to embed secure-by-design principles into applications, platforms and delivery processes. You will help shape security standards, provide pragmatic guidance and support teams in identifying and addressing risks without unnecessarily slowing innovation.
Your responsibilities will include conducting threat modelling, reviewing application and infrastructure designs, and performing or coordinating security assessments, code reviews and penetration testing. You will analyse findings from automated and manual testing, support vulnerability triage and remediation, and advise on appropriate risk treatment. You will contribute to secure development standards, reusable security patterns and developer enablement through training, documentation and hands-on coaching. You will also help improve application security tooling, including software composition analysis, static and dynamic testing, secrets detection and security monitoring within CI/CD pipelines.
To succeed, you will have substantial experience in application or product security, with strong knowledge of secure software development practices, common vulnerabilities and recognised frameworks such as OWASP. You should be comfortable reviewing code in one or more programming languages and working with cloud-native architectures, APIs, containers and modern DevOps practices. Experience with threat modelling methodologies, security automation and incident or vulnerability management is highly desirable. Strong communication skills are essential, as you will need to explain complex security issues clearly to both technical and non-technical audiences and influence positive change across distributed teams. This is a remote role for candidates based in the United Kingdom, with occasional collaboration across working hours and potential travel for team or business events.
Read lessLeeds, England, United KingdomPermanent
We are seeking an experienced Associate Director, OT & Cybersecurity to lead the development and delivery of a... Read more
We are seeking an experienced Associate Director, OT & Cybersecurity to lead the development and delivery of a robust security strategy across operational technology, industrial control systems and connected environments. This is a senior leadership role responsible for protecting critical assets, improving cyber resilience and ensuring that security is embedded throughout the design, operation and transformation of OT environments. You will work closely with technology, engineering, operations, risk, compliance and senior leadership teams to establish practical, risk-based security outcomes.
Your responsibilities will include setting the OT cybersecurity roadmap; defining governance, policies, standards and control frameworks; and overseeing security assessments, vulnerability management, network segmentation, monitoring, incident response and recovery planning. You will provide direction on secure architecture, remote access, identity and access management, third-party risk and the secure integration of IT and OT systems. The role will also involve leading cyber risk assessments, prioritising remediation activity, managing budgets and external partners, and reporting security posture, risks and progress to senior stakeholders. You will promote security-by-design principles across projects and support the development of effective business continuity and crisis management capabilities.
Applicants should have significant experience in OT, industrial cybersecurity or a closely related field, together with a strong understanding of ICS, SCADA, PLC and other control-system technologies. Experience developing and implementing OT security programmes across complex, geographically distributed environments is essential. You will bring knowledge of recognised frameworks and standards such as IEC 62443, NIST, ISO 27001 and relevant regulatory requirements, as well as experience leading incident response, audits and risk reduction initiatives. Strong communication, influencing and people-leadership skills are required, along with the ability to translate technical risk into clear business priorities. Relevant professional certifications, such as CISSP, CISM, GIAC or IEC 62443, would be advantageous.
Read lessLeeds, England, United KingdomPermanent
We are seeking an IAM Security Engineer to design, implement and maintain secure identity and access management solutions... Read more
We are seeking an IAM Security Engineer to design, implement and maintain secure identity and access management solutions across a complex technology environment. You will help protect critical systems and data by ensuring that users, applications and devices receive appropriate access based on business requirements and security principles. Working closely with cybersecurity, infrastructure, application and compliance teams, you will contribute to the continuous improvement of identity security controls and operational processes.
Your responsibilities will include administering and enhancing identity governance, access management, privileged access management and single sign-on capabilities. You will support the full identity lifecycle, including joiner, mover and leaver processes, access requests, approvals, certifications and role management. The role will involve integrating cloud and on-premises platforms, configuring authentication and authorisation controls, supporting multi-factor authentication, and monitoring identity-related events for suspicious activity. You will investigate incidents, troubleshoot access issues, develop automation using scripting or APIs, and maintain clear technical documentation, standards and procedures.
The successful candidate will have practical experience in IAM, cybersecurity or a related engineering discipline, with knowledge of directory services, federation protocols and modern authentication technologies such as SAML, OAuth2 and OpenID Connect. Experience with platforms such as Active Directory, Entra ID, Okta, SailPoint, CyberArk or comparable solutions would be advantageous. You should understand least-privilege access, role-based access control, segregation of duties, privileged account security and relevant data protection principles. Strong analytical, communication and problem-solving skills are essential, along with the ability to manage competing priorities and collaborate effectively with technical and non-technical stakeholders. Relevant security or cloud certifications are desirable.
Read lessLeeds, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria