We are seeking a Cloud Information Specialist Threat Modeler to strengthen the security and resilience of cloud-based platforms,... Read more
We are seeking a Cloud Information Specialist Threat Modeler to strengthen the security and resilience of cloud-based platforms, applications, and information services. In this role, you will identify and assess threats across cloud environments, translate business and technical risks into practical security requirements, and support teams in designing effective controls. You will work closely with architects, developers, engineers, governance specialists, and operational stakeholders to ensure that security is embedded throughout the solution lifecycle.
Your responsibilities will include conducting structured threat modelling and risk assessments for cloud services, data flows, APIs, applications, and infrastructure; documenting attack paths, vulnerabilities, assumptions, and recommended mitigations; and maintaining threat models as systems, technologies, and risks evolve. You will review solution designs and security architectures, advise on identity and access management, encryption, network segmentation, logging, monitoring, and data protection, and help prioritise remediation activities. You will also contribute to security standards, design patterns, assurance processes, and clear reporting for both technical and non-technical audiences.
The successful candidate will have experience in cloud security, information security, threat modelling, security architecture, or a related discipline. Practical knowledge of major cloud concepts, shared responsibility models, secure software development, and common threat modelling frameworks such as STRIDE, attack trees, or data flow analysis is required. Familiarity with cloud-native services, DevSecOps, infrastructure as code, vulnerability management, and relevant data protection or security standards would be advantageous. You should be analytical, collaborative, and confident challenging assumptions constructively, with the ability to explain complex risks clearly and recommend proportionate, achievable solutions. Relevant professional certifications or equivalent experience are welcome.
Read lessLondon, England, United KingdomPermanent
We are seeking a Threat & Exposure Management Analyst to help identify, assess and reduce cyber security risks... Read more
We are seeking a Threat & Exposure Management Analyst to help identify, assess and reduce cyber security risks across a complex technology environment. In this role, you will monitor the organisation’s threat landscape, analyse vulnerability and exposure data, and support the prioritisation of remediation activities based on business impact, exploitability and threat intelligence. You will work closely with security operations, infrastructure, application, cloud and risk teams to improve visibility of the attack surface and strengthen overall resilience.
Key responsibilities will include maintaining accurate inventories of assets, vulnerabilities, misconfigurations and externally exposed services; reviewing findings from vulnerability scanners, attack surface management platforms and security assessments; and investigating emerging threats that may affect the environment. You will produce clear reports and dashboards for technical and senior stakeholders, track remediation progress, validate corrective actions and escalate overdue or high-risk issues where appropriate. You will also contribute to risk assessments, security metrics, threat modelling, incident investigations and continuous improvements to exposure management processes, standards and procedures.
The successful candidate will have practical experience in vulnerability management, threat intelligence, cyber risk, security operations or a closely related discipline. You should be comfortable interpreting technical findings and translating them into clear, risk-based recommendations for both technical and non-technical audiences. Familiarity with common security frameworks, vulnerability scoring methods, cloud security concepts, networking, operating systems and application security is desirable, along with experience using security scanning, ticketing, reporting or attack surface management tools. Strong analytical, organisational and communication skills are essential, as is the ability to manage competing priorities and collaborate effectively across teams. Relevant industry certifications or equivalent practical experience will be welcomed.
Read lessLondon, England, United KingdomPermanent
We are seeking an experienced Vulnerability Research Team Leader to guide a specialist team responsible for identifying, analysing,... Read more
We are seeking an experienced Vulnerability Research Team Leader to guide a specialist team responsible for identifying, analysing, and responsibly disclosing security vulnerabilities across operating systems, applications, embedded devices, and emerging technologies. You will provide technical direction, set research priorities, and help translate complex findings into practical recommendations for engineering, product, and security stakeholders. This role combines hands-on technical leadership with people management and strategic planning.
Key responsibilities include defining and maintaining the team’s research roadmap; overseeing vulnerability discovery, exploit development, reverse engineering, fuzzing, and proof-of-concept creation; reviewing technical reports and ensuring findings are accurately assessed and documented; and coordinating responsible disclosure activities with relevant vendors, researchers, and internal teams. You will establish effective research methodologies, improve tooling and laboratory capabilities, monitor the threat landscape, and contribute to security advisories, technical publications, and presentations. You will also support incident response and risk assessments when specialist vulnerability research expertise is required.
The successful candidate will have substantial experience in vulnerability research, offensive security, or a closely related discipline, together with a strong understanding of operating system internals, networking, software architecture, and common vulnerability classes. Practical knowledge of reverse engineering, debugging, static and dynamic analysis, fuzzing frameworks, and scripting or programming languages such as Python, C, C++, or Rust is essential. Experience leading or mentoring technical teams, managing competing priorities, and communicating complex security issues to varied audiences is also required. A methodical, curious, and collaborative approach is important, along with sound judgement when handling sensitive information. Relevant professional certifications, published research, or a demonstrable history of responsible vulnerability disclosure would be advantageous.
Read lessLondon, England, United KingdomPermanent
We are seeking a Cyber Vulnerability Researcher to identify, analyse, and help mitigate security weaknesses across complex software,... Read more
We are seeking a Cyber Vulnerability Researcher to identify, analyse, and help mitigate security weaknesses across complex software, hardware, and network environments. You will conduct vulnerability research using a combination of manual analysis, reverse engineering, fuzzing, code review, and dynamic testing. The role will involve investigating emerging threats, validating reported vulnerabilities, developing proof-of-concept exploits where appropriate, and assessing the potential impact, exploitability, and scope of identified issues.
You will collaborate with security engineers, developers, incident responders, and technical stakeholders to communicate findings clearly and support effective remediation. Responsibilities will include producing detailed technical reports, documenting attack paths and reproduction steps, recommending practical mitigations, and contributing to vulnerability disclosure and tracking processes. You may also support security assessments, threat modelling, penetration testing, malware analysis, and the development of internal tools, scripts, and automation to improve research efficiency. Staying informed about new attack techniques, vulnerability classes, defensive technologies, and relevant industry standards will be an important part of the position.
Applicants should have professional or demonstrable practical experience in vulnerability research, offensive security, application security, reverse engineering, or a closely related discipline. Strong knowledge of common vulnerability classes, operating systems, networking, secure coding principles, and security testing methodologies is required. Experience with languages such as Python, C, C++, JavaScript, or Rust, along with familiarity with debugging and analysis tools, is highly desirable. Experience using fuzzing frameworks, disassemblers, debuggers, virtualisation platforms, or cloud environments would be advantageous. The successful candidate will demonstrate analytical thinking, careful attention to detail, sound technical judgement, and the ability to explain complex findings to both technical and non-technical audiences. A curious, ethical, and methodical approach to research is essential.
Read lessLondon, England, United KingdomPermanent
We are seeking an experienced Head of Vulnerability Management to lead the development and delivery of a mature,... Read more
We are seeking an experienced Head of Vulnerability Management to lead the development and delivery of a mature, risk-based vulnerability management capability across a complex digital and technology estate. This is a senior role requiring strong leadership, sound technical judgement and the ability to influence stakeholders at all levels. You will set the strategic direction for identifying, assessing, prioritising and remediating vulnerabilities, ensuring that security risks are understood and managed effectively.
You will oversee vulnerability scanning, threat intelligence, exposure assessment, remediation tracking and reporting across infrastructure, applications, cloud services and third-party environments. Working closely with cyber security, architecture, engineering, service management and risk teams, you will establish clear policies, standards, operating procedures and performance measures. You will provide authoritative advice on remediation priorities, risk acceptance and emerging threats, while ensuring that vulnerability data is accurate, actionable and communicated clearly to technical and senior audiences.
The successful candidate will have substantial experience leading vulnerability management or a closely related cyber security function within a large, complex environment. You will bring strong knowledge of vulnerability assessment methodologies, common security weaknesses, risk-based prioritisation, remediation processes and relevant security tooling. Experience of managing teams, suppliers and cross-functional programmes is essential, along with the ability to develop capability, improve operational maturity and deliver measurable outcomes. You should be confident presenting recommendations to senior leaders, challenging constructively and building effective relationships across organisational boundaries. Relevant professional qualifications or demonstrable equivalent experience are welcome. We value people who are collaborative, inclusive, analytical and committed to continuous improvement. This role offers the opportunity to shape security practice, reduce organisational exposure and strengthen resilience across essential digital services.
Read lessManchester, England, United KingdomPermanent
We are seeking a Vulnerability Researcher – Consultant to identify, analyse, and responsibly disclose security weaknesses across software,... Read more
We are seeking a Vulnerability Researcher – Consultant to identify, analyse, and responsibly disclose security weaknesses across software, hardware, embedded systems, and enterprise technologies. You will conduct vulnerability research from initial discovery through proof-of-concept development, validation, documentation, and remediation support. The role involves working with varied technologies and clients, translating complex technical findings into clear risk assessments and practical recommendations.
Responsibilities will include performing vulnerability assessments and security-focused code reviews; developing and refining fuzzing, reverse-engineering, and exploit-development techniques; analysing binaries, protocols, operating systems, applications, and firmware; and creating reliable proof-of-concept demonstrations in controlled environments. You will document findings to a high standard, assess exploitability and business impact, contribute to technical reports and presentations, and support responsible disclosure activities. You may also advise development and security teams on mitigation strategies, secure design principles, and methods for preventing similar weaknesses. The role may require managing multiple assignments, engaging directly with stakeholders, and presenting technical conclusions to both specialist and non-specialist audiences.
Applicants should have demonstrable experience in vulnerability research, penetration testing, exploit development, reverse engineering, or a closely related discipline. Strong knowledge of computer architecture, operating systems, networking, and common security weaknesses is expected, together with practical programming ability in languages such as C, C++, Python, Rust, or assembly. Experience with tools including debuggers, disassemblers, fuzzing frameworks, static and dynamic analysis platforms, and source-control systems would be valuable. An analytical mindset, curiosity, persistence, and the ability to explain complex issues clearly are essential. Relevant professional certifications, academic qualifications, published research, conference contributions, or a portfolio of independent security work are advantageous. A commitment to ethical conduct, confidentiality, continuous learning, and responsible vulnerability handling is required.
Read lessCambridge, England, United KingdomPermanent
We are seeking an experienced Head of Vulnerability Management to lead the development and delivery of a comprehensive,... Read more
We are seeking an experienced Head of Vulnerability Management to lead the development and delivery of a comprehensive, risk-based vulnerability management programme. This is a strategic leadership role responsible for reducing cyber risk across a complex technology environment, including cloud platforms, on-premises infrastructure, applications, endpoints and third-party services. You will define the vulnerability management vision, establish effective governance and ensure that security risks are identified, prioritised and remediated in line with business objectives and regulatory expectations.
You will lead a team of vulnerability management specialists and work closely with Security Operations, Infrastructure, Engineering, Architecture, Risk, Compliance and Technology leadership. Responsibilities will include overseeing vulnerability discovery, scanning, validation, threat intelligence, risk-based prioritisation, remediation tracking and management reporting. You will establish meaningful service levels and key performance indicators, improve asset visibility and coverage, and ensure that vulnerabilities are assessed in the context of exploitability, business criticality and emerging threats. The role will also involve managing strategic relationships with technology and security vendors, supporting audit activity, and providing clear, concise updates to senior stakeholders.
The successful candidate will have substantial experience leading vulnerability management or a closely related cyber security function within a large and complex organisation. You will possess strong knowledge of vulnerability assessment methodologies, common security frameworks, risk management principles and industry tooling, with practical experience across infrastructure, applications and cloud environments. A proven ability to lead teams, influence stakeholders and translate technical risk into business-focused recommendations is essential. Relevant professional certifications such as CISSP, CISM, CRISC, OSCP or equivalent are desirable. You should be analytical, decisive and collaborative, with a continuous improvement mindset and the communication skills needed to drive accountability at all levels.
Read lessLondon, England, United KingdomPermanent
We are seeking a Threat Intelligence Analyst to monitor, assess and communicate cyber threat activity affecting the organisation,... Read more
We are seeking a Threat Intelligence Analyst to monitor, assess and communicate cyber threat activity affecting the organisation, its technology environment and relevant business sectors. You will collect and analyse intelligence from open, commercial and internal sources to identify emerging threats, adversary activity, vulnerabilities and potential impacts. Working closely with security operations, incident response, vulnerability management and risk teams, you will help transform complex information into clear, actionable insight.
Your responsibilities will include tracking threat actors, campaigns, malware, tactics, techniques and procedures; producing regular intelligence reports, alerts, briefings and executive summaries; and supporting investigations by providing relevant context, indicators of compromise and attack-pattern analysis. You will maintain intelligence records and mappings to recognised frameworks, contribute to detection and prevention improvements, and help assess the potential business impact of geopolitical, criminal and technology-related threats. You may also support threat-hunting activities, intelligence requirements, incident reviews and collaboration with trusted industry or public-sector partners.
The successful candidate will have experience in cyber threat intelligence, security analysis, incident response, security operations or a related discipline. You should be confident researching and evaluating information from multiple sources, distinguishing credible reporting from unreliable data, and presenting findings to both technical and non-technical audiences. Familiarity with threat intelligence platforms, security monitoring tools, malware analysis, digital investigations, MITRE ATT&CK and common intelligence lifecycle practices is desirable. Strong analytical, written and verbal communication skills are essential, along with curiosity, sound judgement and the ability to prioritise work in a changing threat environment. Relevant professional certifications or a degree in cybersecurity, computer science, intelligence studies or a similar subject would be advantageous.
Read lessLondon, England, United KingdomPermanent
We are seeking an Advanced Cyber Threat Analyst to identify, investigate and disrupt sophisticated cyber threats across a... Read more
We are seeking an Advanced Cyber Threat Analyst to identify, investigate and disrupt sophisticated cyber threats across a complex technology environment. You will monitor threat activity, analyse security telemetry and intelligence, and assess potential impacts to systems, applications, data and business operations. The role requires a proactive, analytical professional who can connect seemingly unrelated events, identify attack patterns and provide clear, actionable recommendations to strengthen defensive capabilities.
Your responsibilities will include conducting advanced threat hunting across endpoint, network, cloud and identity environments; investigating alerts and suspected incidents; analysing malware, attacker tactics, techniques and procedures; and developing detection logic, use cases and response playbooks. You will correlate information from security information and event management, endpoint detection, vulnerability management and threat intelligence platforms. You will also support incident response activities, including scoping, containment, eradication and recovery, while contributing to post-incident reviews and improvements to security controls. Producing concise technical reports, risk assessments and briefings for both technical and non-technical audiences will be an important part of the role.
The successful candidate will have substantial experience in cyber threat analysis, security operations, incident investigation or a related discipline, together with strong knowledge of networking, operating systems, cloud services, identity platforms and common attack frameworks such as MITRE ATT&CK. Experience with scripting or automation, malware analysis, digital forensics, threat intelligence and query languages used in security platforms is highly desirable. You should be comfortable working with incomplete information, prioritising competing risks and communicating findings confidently. Relevant professional certifications or equivalent practical experience are welcomed. A strong commitment to continuous learning, sound judgement, attention to detail and the ability to collaborate effectively across technical and operational teams are essential.
Read lessStirling, Scotland, United KingdomPermanent
We are seeking a Senior Cyber Threat Detection and Response Analyst to lead the identification, investigation and containment... Read more
We are seeking a Senior Cyber Threat Detection and Response Analyst to lead the identification, investigation and containment of sophisticated cyber threats across a complex technology environment. You will monitor security events, analyse alerts and intelligence, and coordinate effective responses to incidents affecting networks, endpoints, cloud services, applications and critical data. The role will involve working closely with security engineering, infrastructure, risk and operational teams to strengthen defensive capabilities and reduce organisational exposure.
Key responsibilities include developing and tuning detection rules, use cases and correlation logic; conducting advanced threat hunting across security telemetry; investigating indicators of compromise and suspicious activity; and managing incidents from initial triage through to remediation and post-incident review. You will contribute to the development of playbooks, response procedures and threat models, while identifying opportunities to automate repetitive tasks and improve investigation efficiency. The role will also require clear documentation of findings, production of threat and incident reports, participation in vulnerability and risk discussions, and mentoring less experienced analysts. You may be required to support security operations outside standard hours through an agreed on-call or escalation rota.
You will bring significant experience in cyber threat detection, incident response, security operations or a closely related discipline, together with a strong understanding of attack techniques, adversary behaviours and frameworks such as MITRE ATT&CK. Practical experience with SIEM, EDR, SOAR, network monitoring and threat intelligence platforms is essential, as is the ability to investigate using endpoint, network, identity and cloud logs. Scripting or automation skills in languages such as Python or PowerShell are desirable. Relevant professional certifications, such as CISSP, GIAC, GCIH, GCIA or equivalent, would be advantageous. Strong analytical, communication and problem-solving skills are required, along with the ability to explain technical risk clearly to both specialist and non-specialist audiences.
Read lessPortsmouth, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria