We are seeking a Security Design Engineer (Application Security) to help embed security throughout the software development lifecycle.... Read more
We are seeking a Security Design Engineer (Application Security) to help embed security throughout the software development lifecycle. In this role, you will work closely with software engineers, architects, product teams and delivery stakeholders to design secure, resilient applications and services. You will translate security principles into practical engineering guidance, identify risks early, and support teams in delivering solutions that meet business and regulatory requirements.
Your responsibilities will include conducting threat modelling, security architecture reviews and design assessments for new and existing applications. You will define security requirements, review technical specifications, assess application and API controls, and recommend appropriate mitigations for identified risks. You will contribute to secure coding standards, patterns and reusable guidance, while supporting vulnerability management, penetration testing and remediation activities. The role will also involve helping to improve application security tooling and processes, including security testing within CI/CD pipelines, software composition analysis, static and dynamic testing, and secrets management. You will communicate findings clearly to both technical and non-technical audiences and help teams understand the business impact of security decisions.
The successful candidate will have practical experience in application security, secure software development or security architecture, with a strong understanding of common vulnerabilities and attack techniques, including those identified by OWASP. You should be comfortable reviewing code and designs, analysing threats, and working with modern development methodologies, cloud platforms, APIs, containers and identity technologies. Experience with DevSecOps practices, security automation and risk management is highly desirable. Strong communication, collaboration and problem-solving skills are essential, along with the ability to influence delivery teams and balance security, usability and delivery objectives. Relevant professional certifications or demonstrable equivalent experience would be advantageous.
Read lessSheffield, England, United KingdomPermanent
We are seeking a skilled Network Security Professional to help protect critical systems, networks, and data against evolving... Read more
We are seeking a skilled Network Security Professional to help protect critical systems, networks, and data against evolving cyber threats. In this role, you will design, implement, monitor, and improve network security controls across on-premises and cloud environments. You will work closely with infrastructure, engineering, and operational teams to identify vulnerabilities, strengthen security architecture, and support the secure delivery of technology services.
Key responsibilities include configuring and maintaining firewalls, intrusion detection and prevention systems, secure remote access solutions, network segmentation, endpoint protections, and security monitoring tools. You will investigate security alerts and incidents, perform root-cause analysis, coordinate containment and remediation activities, and maintain accurate documentation of findings and corrective actions. The role will also involve conducting vulnerability assessments, reviewing network and system changes, supporting penetration testing activities, and contributing to incident response plans and disaster recovery exercises. You will help develop and maintain security policies, standards, procedures, and risk assessments in line with relevant industry frameworks and regulatory requirements.
The successful candidate will have demonstrable experience in network security, security operations, or a closely related discipline, together with a strong understanding of TCP/IP, DNS, VPNs, routing, switching, firewalls, network protocols, and common attack methods. Experience with SIEM platforms, vulnerability management tools, cloud security technologies, and scripting or automation is highly desirable. Professional certifications such as Security+, CySA+, CISSP, CCNA Security, or equivalent qualifications would be advantageous. You should possess excellent analytical and problem-solving skills, communicate clearly with both technical and non-technical stakeholders, and be able to prioritise effectively in a fast-paced environment. A proactive approach, strong attention to detail, and a commitment to continuous learning are essential.
Read lessSheffield, England, United KingdomPermanent
We are seeking a Security Design Engineer (App Sec) to strengthen application security across the software development lifecycle.... Read more
We are seeking a Security Design Engineer (App Sec) to strengthen application security across the software development lifecycle. In this role, you will work closely with engineering, architecture, product, and operations teams to design secure, resilient applications and services. You will help embed security into development practices from initial concept through deployment and ongoing maintenance, while providing practical guidance that enables teams to deliver at pace without compromising protection.
Your responsibilities will include conducting threat modelling, security architecture reviews, and risk assessments for applications, APIs, cloud services, and supporting infrastructure. You will define security requirements and design patterns, review technical proposals, and recommend appropriate controls for identity, access management, data protection, secrets management, logging, monitoring, and secure communications. You will support secure coding initiatives, assist with vulnerability assessment and remediation, and contribute to the development of security standards, reusable guidance, and automated checks within CI/CD pipelines. You will also help investigate security issues, assess their impact, and collaborate with relevant teams to track corrective actions through to completion.
The successful candidate will have professional experience in application security, security engineering, software development, or a related discipline, with a strong understanding of secure software development principles and common application vulnerabilities. Experience with threat modelling methodologies, cloud security, APIs, containers, DevSecOps tooling, and modern authentication protocols is highly desirable. You should be comfortable interpreting technical and business risks, communicating clearly with both technical and non-technical audiences, and influencing teams through collaboration rather than authority. Familiarity with recognised security frameworks and standards, such as OWASP guidance, NIST, or ISO 27001, would be advantageous. A proactive, analytical approach and a commitment to continuous learning are essential.
Read lessSheffield, England, United KingdomPermanent
We are seeking a Cyber Security Engineer to help protect critical systems, applications, networks and data against evolving... Read more
We are seeking a Cyber Security Engineer to help protect critical systems, applications, networks and data against evolving cyber threats. In this role, you will contribute to the design, implementation and continuous improvement of security controls across a complex technology environment. You will work closely with infrastructure, software development, cloud and operations teams to embed secure practices throughout the technology lifecycle.
Your responsibilities will include monitoring and investigating security alerts, supporting incident response activities, conducting vulnerability assessments and coordinating remediation efforts. You will help maintain security tools and technologies such as SIEM, endpoint protection, identity and access management, firewalls and vulnerability management platforms. You will also contribute to threat modelling, security testing, configuration reviews and the development of technical standards, procedures and risk assessments. Keeping informed about emerging threats, vulnerabilities and regulatory expectations will be an important part of the role.
The successful candidate will have professional experience in cyber security engineering, infrastructure security, cloud security or a closely related discipline. You should have practical knowledge of networking, operating systems, authentication protocols, encryption, security monitoring and incident management. Experience with scripting or automation, security information and event management platforms, endpoint detection and response solutions, and major cloud environments would be advantageous. Relevant industry certifications are desirable, alongside strong analytical and problem-solving skills. You will be expected to communicate clearly with both technical and non-technical stakeholders, manage competing priorities and work collaboratively to deliver effective, proportionate security improvements.
Read lessSheffield, England, United KingdomPermanent
We are seeking an experienced Security Lead to provide strategic direction and operational leadership across the organisation’s information... Read more
We are seeking an experienced Security Lead to provide strategic direction and operational leadership across the organisation’s information and cyber security activities. The successful candidate will be responsible for developing, maintaining and continuously improving the security framework, ensuring that policies, controls and processes support business objectives while meeting relevant legal, regulatory and industry requirements. This role will act as a trusted adviser to senior stakeholders, translating complex security risks into clear, practical recommendations.
Key responsibilities will include leading security governance, risk assessment and compliance programmes; overseeing vulnerability management, security monitoring and incident response; and coordinating the investigation, containment and recovery of security incidents. You will manage security reviews for systems, applications, suppliers and projects, ensuring that appropriate controls are designed and implemented from the outset. The role will also involve maintaining risk registers, reporting on security performance, supporting audit activity and developing plans to improve organisational resilience. You will contribute to security awareness initiatives and help embed a strong culture of secure working across all teams.
Applicants should have substantial experience in information security, cyber security or a closely related discipline, with a proven record of leading security programmes or teams. Strong knowledge of security frameworks, risk management methodologies, incident response, identity and access management, and data protection principles is required. Professional certifications such as CISSP, CISM, CRISC or equivalent experience would be advantageous. You will need excellent communication and stakeholder management skills, the ability to influence at all levels, and a methodical approach to problem-solving. Experience working in complex, regulated or technology-led environments, together with the confidence to balance security, operational needs and commercial priorities, will be highly valued.
Read lessSheffield, England, United KingdomPermanent
We are seeking a Cryptography and PKI Security Specialist to design, operate and continuously improve secure cryptographic services... Read more
We are seeking a Cryptography and PKI Security Specialist to design, operate and continuously improve secure cryptographic services across a complex technology environment. The successful candidate will be responsible for the lifecycle management of public key infrastructure (PKI), including certificate authorities, registration authorities, digital certificates, encryption keys and hardware security modules (HSMs). You will help ensure that cryptographic controls support business, regulatory and security requirements while maintaining high standards of availability, resilience and operational assurance.
Key responsibilities include developing and maintaining PKI and certificate-management processes; issuing, renewing, revoking and monitoring certificates; administering key-generation, storage, rotation, recovery and destruction procedures; and supporting the secure configuration of HSMs and cryptographic platforms. You will establish and enforce cryptographic standards, policies and procedures, advise technical teams on encryption and digital-signature solutions, and contribute to architecture and security reviews. The role will also involve investigating certificate or key-related incidents, supporting vulnerability remediation, maintaining accurate documentation, and providing evidence for audits and compliance assessments. You may also contribute to automation initiatives that improve certificate discovery, renewal and reporting.
Applicants should have strong practical experience in PKI, cryptography, certificate lifecycle management and enterprise security operations. Knowledge of technologies such as X.509, TLS, mutual TLS, S/MIME, DNSSEC, key-management systems, HSMs and identity-management platforms is expected. Familiarity with cryptographic algorithms, protocols, trust models and relevant security standards is essential, along with experience using scripting or automation tools such as PowerShell, Python or similar. Professional security certifications or equivalent expertise are desirable. You should be analytical, methodical and comfortable explaining complex security concepts to both technical and non-technical stakeholders. The role requires effective collaboration, sound judgement, strong attention to detail and a proactive approach to identifying and reducing cryptographic risk.
Read lessSheffield, England, United KingdomPermanent
We are seeking a Cyber Lead to provide strategic direction and operational leadership across Group Functions Technology. This... Read more
We are seeking a Cyber Lead to provide strategic direction and operational leadership across Group Functions Technology. This role will help shape and deliver a security agenda that protects business services, corporate systems, data and technology platforms against evolving cyber threats. You will work closely with technology, risk, compliance, internal audit and business stakeholders to ensure security is embedded into strategic planning, project delivery and day-to-day operations.
Key responsibilities will include defining and maintaining cyber security strategies, standards, policies and control frameworks; overseeing security risk identification, assessment and remediation; and providing expert guidance on architecture, cloud adoption, identity and access management, vulnerability management, threat detection and incident response. You will lead security reviews for major technology initiatives, monitor the effectiveness of controls, support regulatory and audit requirements, and ensure that security incidents are investigated, contained and addressed through continual improvement. The role will also involve managing third-party security risks, supporting resilience planning and promoting a strong culture of cyber awareness across the organisation.
The successful candidate will bring substantial experience in cyber security leadership, technology risk or information security, ideally within a complex, regulated or multinational environment. You will have a strong understanding of recognised security frameworks and standards, such as ISO 27001, NIST or CIS, together with practical knowledge of modern infrastructure, networks, applications, cloud services and security operations. Excellent stakeholder management and communication skills are essential, as is the ability to translate technical risks into clear business decisions. Relevant professional qualifications, such as CISSP, CISM, CRISC or equivalent experience, would be advantageous. You should be collaborative, commercially aware and confident influencing senior leaders while remaining hands-on enough to challenge, advise and deliver meaningful security outcomes.
Read lessSheffield, England, United KingdomPermanent
We are seeking a Cyber Lead to provide strategic direction and technical leadership across Group Functions Technology. This... Read more
We are seeking a Cyber Lead to provide strategic direction and technical leadership across Group Functions Technology. This role will help shape and deliver a robust cyber security agenda, ensuring that technology services, applications, data and infrastructure are protected against evolving threats. You will work closely with senior stakeholders, technology teams, risk specialists and business leaders to embed security into decision-making, transformation programmes and day-to-day operations.
Key responsibilities will include developing and maintaining cyber security strategies, policies, standards and roadmaps; overseeing security architecture and design assurance; and providing expert guidance on risk management, identity and access management, vulnerability management, threat detection, incident response and third-party security. You will lead security reviews for new and existing technology solutions, identify control gaps, agree pragmatic remediation plans and monitor progress through appropriate metrics and reporting. The role will also support regulatory compliance, audit activity, security awareness and continuous improvement across the technology landscape.
The successful candidate will have significant experience in cyber security leadership, technology risk or security architecture within a complex enterprise environment. You should have a strong understanding of current threats, security controls, cloud technologies, networks, applications, data protection and modern identity principles, together with experience translating technical risks into clear business recommendations. Excellent communication, influencing and stakeholder-management skills are essential, as is the ability to balance security, customer needs, delivery priorities and commercial considerations. Relevant professional certifications such as CISSP, CISM, CRISC, SABSA or equivalent experience are desirable. You will be expected to demonstrate sound judgement, collaborative leadership and a proactive approach to improving security resilience.
Read lessSheffield, England, United KingdomPermanent
We are seeking an experienced Cyber Lead to drive the integration of security throughout the software development and... Read more
We are seeking an experienced Cyber Lead to drive the integration of security throughout the software development and technology lifecycle. This is a strategic and hands-on role responsible for establishing and embedding DevSecOps practices across engineering, cloud, infrastructure and product teams. You will help shape secure-by-design principles, improve development standards and ensure that security is treated as a shared responsibility across the technology function.
Key responsibilities will include defining and implementing a DevSecOps roadmap; integrating security controls, testing and monitoring into CI/CD pipelines; strengthening application, cloud and infrastructure security; and supporting secure architecture and technical design reviews. You will lead activities including threat modelling, vulnerability management, security automation, code and dependency scanning, container security and incident readiness. The role will also involve developing security policies, standards and metrics, managing risk remediation, coordinating penetration testing, and providing clear reporting to senior stakeholders. You will act as a trusted adviser to engineering and delivery teams, promoting practical security improvements without compromising delivery.
The successful candidate will have substantial experience in cybersecurity, DevSecOps, cloud security or a closely related discipline, together with a strong understanding of secure software development and modern engineering practices. You should be comfortable working with CI/CD tooling, infrastructure as code, containers, APIs, identity and access management, and leading security improvements across complex technology environments. Experience with major cloud platforms, security automation, threat modelling frameworks and relevant regulatory or compliance requirements would be advantageous. Strong communication, influencing and leadership skills are essential, as is the ability to translate technical risks into clear business outcomes. Professional certifications such as CISSP, CISM, CCSP, GIAC or equivalent experience are desirable.
Read lessSheffield, England, United KingdomPermanent
We are seeking an experienced Managed Cloud Security Lead to provide strategic and technical leadership across cloud security... Read more
We are seeking an experienced Managed Cloud Security Lead to provide strategic and technical leadership across cloud security operations, governance and service delivery. In this role, you will lead the design, implementation and continual improvement of secure cloud environments, ensuring that security controls support business objectives while meeting regulatory, contractual and industry requirements. You will work closely with infrastructure, engineering, risk, compliance and service management teams to embed security throughout the cloud lifecycle.
Your responsibilities will include owning cloud security standards, policies and operating procedures; overseeing managed security services and third-party suppliers; and maintaining effective processes for security monitoring, vulnerability management, identity and access management, configuration assurance and incident response. You will assess cloud architectures and proposed changes, identify risks, recommend practical mitigations and ensure that security findings are tracked through to resolution. The role will also involve developing service performance measures, reporting security posture to senior stakeholders, supporting audits and exercising oversight of cloud-related business continuity and disaster recovery arrangements.
The successful candidate will have substantial experience leading cloud security functions within complex, regulated or enterprise environments, with strong knowledge of platforms such as Azure, AWS or Google Cloud. You will understand cloud-native security tooling, zero-trust principles, network security, encryption, privileged access management, security information and event management, and secure configuration frameworks. Professional certifications such as CISSP, CCSP, CISM or relevant cloud-security credentials are desirable. Excellent communication, influencing and problem-solving skills are essential, together with the ability to translate technical risks into clear business impacts and priorities. You should be comfortable leading teams, managing suppliers, coordinating incident and remediation activity, and driving continuous improvement in a fast-changing technology landscape.
Read lessSheffield, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria