We are seeking an IAM Analyst to support the secure and efficient management of user identities, access rights... Read more
We are seeking an IAM Analyst to support the secure and efficient management of user identities, access rights and authentication services across the organisation. In this role, you will help ensure that employees, contractors and third parties have appropriate access to systems and data based on their responsibilities, while maintaining strong security and compliance standards. You will work closely with technology, security, HR and business teams to deliver reliable identity and access management services.
Your responsibilities will include processing and reviewing access requests, user provisioning and deprovisioning, role and group administration, password and authentication support, and the investigation of access-related issues. You will contribute to joiner, mover and leaver processes, perform regular access reviews and assist with the implementation and maintenance of identity governance controls. The role will also involve monitoring service queues, maintaining accurate records, supporting audit activity and preparing reports on access activity, exceptions and compliance. You may assist with the administration of single sign-on, multi-factor authentication and privileged access solutions.
The successful candidate will have experience in an identity and access management, IT support, security operations or systems administration environment. You should understand core IAM principles, least-privilege access, segregation of duties and access lifecycle management. Familiarity with directory services, cloud platforms, ticketing systems and authentication protocols is desirable, along with experience using IAM or identity governance tools. Strong analytical and problem-solving skills are essential, as is the ability to communicate clearly with technical and non-technical stakeholders. You will be organised, security-conscious and comfortable working with confidential information. Relevant certifications or training in cybersecurity, identity management or IT service management would be advantageous.
Read lessSouthampton, England, United KingdomPermanent
We are seeking a Product Cyber Resilience Manager to lead the development and continuous improvement of cyber resilience... Read more
We are seeking a Product Cyber Resilience Manager to lead the development and continuous improvement of cyber resilience across a diverse portfolio of products and services. In this role, you will help ensure that products are designed, operated and supported to withstand, respond to and recover from cyber incidents while maintaining the confidentiality, integrity and availability of critical information and customer services. You will work closely with product, engineering, architecture, security, risk, compliance and operational teams to embed resilience throughout the product lifecycle.
Your responsibilities will include defining and maintaining product cyber resilience standards, policies, principles and control frameworks; assessing cyber risks and resilience maturity across products; and translating regulatory, industry and business requirements into practical, measurable actions. You will coordinate resilience assessments, threat modelling, scenario analysis, business impact assessments and recovery planning, ensuring that identified weaknesses are prioritised and addressed. You will also oversee the development and testing of incident response, disaster recovery and cyber recovery plans, capturing lessons learned and driving continuous improvement. The role will involve producing clear reporting for senior stakeholders, monitoring key risk and resilience indicators, and supporting governance forums and assurance activities.
The successful candidate will have substantial experience in cyber security, operational resilience, technology risk, business continuity or a related discipline, ideally within a complex or highly regulated environment. You will understand secure product development, cloud and modern technology architectures, incident management, recovery principles and third-party risk. Strong knowledge of recognised cyber security and resilience frameworks, together with experience interpreting regulatory expectations, is desirable. You should be an excellent communicator who can influence stakeholders at all levels, explain complex issues clearly and build effective relationships across multidisciplinary teams. A structured, analytical and proactive approach is essential, along with the ability to manage competing priorities and deliver practical outcomes. Relevant professional qualifications in cyber security, risk, audit, business continuity or information technology would be advantageous.
Read lessSouthampton, England, United KingdomPermanent
We are seeking a Principal Software Engineer (DevSecOps) to provide technical leadership across the design, development, deployment, and... Read more
We are seeking a Principal Software Engineer (DevSecOps) to provide technical leadership across the design, development, deployment, and operation of secure, scalable software platforms. You will help shape engineering strategy, establish modern DevSecOps practices, and guide teams in delivering reliable products at pace. The role requires a hands-on leader who can work across architecture, software engineering, cloud infrastructure, automation, and cybersecurity while influencing technical decisions across the wider organisation.
Your responsibilities will include defining and evolving CI/CD strategies, embedding security controls throughout the software development lifecycle, and developing automated pipelines for build, test, release, compliance, and infrastructure provisioning. You will design and improve cloud-native platforms, champion infrastructure as code, strengthen observability and operational resilience, and promote engineering standards for quality, performance, and maintainability. You will also identify technical risks, lead architectural reviews, support incident resolution, and ensure that systems meet appropriate security, regulatory, and availability requirements. A key part of the role will be mentoring engineers, facilitating knowledge sharing, and building alignment between software, platform, security, and delivery teams.
Applicants should have substantial experience in software engineering and DevSecOps, with a strong background in designing and operating distributed systems and cloud environments. You will be confident working with modern programming languages, containers, orchestration platforms, version control, automated testing, monitoring, and CI/CD tooling. Experience with public cloud services, infrastructure-as-code frameworks, secure software supply chains, vulnerability management, identity and access management, and policy-as-code is highly desirable. Strong understanding of software architecture, Agile delivery, reliability engineering, and secure coding practices is expected. Excellent communication and stakeholder-management skills are essential, along with the ability to translate complex technical issues into clear recommendations and to lead through influence in a changing environment.
Read lessSouthampton, England, United KingdomPermanent
We are seeking a Senior Product Security Engineer to help protect products and services throughout their development lifecycle.... Read more
We are seeking a Senior Product Security Engineer to help protect products and services throughout their development lifecycle. In this role, you will work closely with software engineering, architecture, infrastructure, and product teams to embed security into design, development, testing, and deployment. You will provide practical guidance on secure architecture, threat modelling, vulnerability management, authentication and authorisation, data protection, and secure software development practices.
Your responsibilities will include leading security reviews for new and existing products, identifying and prioritising risks, and supporting teams in delivering effective remediation. You will develop and maintain security standards, patterns, tooling, and documentation, while helping to improve security controls across cloud environments, APIs, applications, and third-party integrations. You will also contribute to security automation, code and dependency scanning, penetration testing coordination, incident investigations, and the continuous improvement of product security processes. An important part of the role will be mentoring engineers and promoting a practical, risk-based security culture.
You will bring substantial experience in product, application, or software security, together with a strong understanding of secure development methodologies and modern engineering practices. Experience with cloud platforms, containerised workloads, CI/CD pipelines, threat modelling frameworks, and common application security risks is highly desirable. You should be comfortable reviewing code and architecture, communicating technical risks to varied audiences, and influencing decisions without relying on formal authority. Relevant industry certifications or equivalent practical experience are welcome. The successful candidate will be curious, collaborative, and pragmatic, with the ability to balance robust security requirements against usability, delivery timelines, and business priorities.
Read lessSouthampton, England, United KingdomPermanent
We are seeking a Business Information Security Officer (BISO) to act as the trusted link between business teams,... Read more
We are seeking a Business Information Security Officer (BISO) to act as the trusted link between business teams, technology functions, and information security. In this role, you will help embed security into business planning, operational processes, and change initiatives while ensuring that risks are identified, assessed, and managed effectively. You will provide practical, risk-based advice that supports business objectives without compromising the confidentiality, integrity, or availability of information and services.
Your responsibilities will include partnering with stakeholders to understand business requirements, advising on security controls, and supporting the secure delivery of projects, products, and services. You will identify and assess information security, technology, and third-party risks, agree appropriate mitigation plans, and monitor progress through to completion. You will contribute to security assessments, risk acceptance decisions, control reviews, audit activity, incident management, and regulatory or policy compliance. The role will also involve promoting security awareness, helping business teams interpret security standards, and reporting key risks, issues, and performance indicators to relevant governance forums.
Applicants should have experience in information security, cyber risk, technology risk, governance, or a related discipline, ideally within a complex or regulated environment. You will need a strong understanding of security principles, risk management frameworks, control design, data protection, and common security threats. Excellent communication and influencing skills are essential, as you will work with both technical and non-technical audiences and be confident challenging decisions constructively. The ability to translate complex security matters into clear, actionable business advice is particularly important. Relevant professional qualifications, such as CISSP, CISM, CRISC, ISO 27001, or equivalent experience, are desirable. We are looking for someone who is collaborative, pragmatic, organised, and committed to continually improving security maturity across the organisation.
Read lessSouthampton, England, United KingdomPermanent
We are seeking a Junior Information Security Analyst to support governance, risk and compliance activities within a growing... Read more
We are seeking a Junior Information Security Analyst to support governance, risk and compliance activities within a growing technology environment. This is an excellent opportunity for someone early in their information security career who is keen to develop practical experience across security controls, risk management, regulatory requirements and assurance. You will work closely with colleagues across technology, operations and the wider business to help maintain a strong security posture and promote effective risk management.
Your responsibilities will include supporting the maintenance of information security policies, standards and procedures; assisting with risk assessments, control reviews and evidence collection; and helping to monitor remediation actions through to completion. You will contribute to internal and external audit preparation, manage security-related documentation and records, and support third-party or supplier security assessments. You may also help track vulnerabilities, incidents, exceptions and compliance metrics, preparing clear reports and updates for relevant stakeholders. The role will involve investigating issues, identifying opportunities for improvement and escalating risks appropriately.
We are looking for strong analytical and organisational skills, with excellent attention to detail and the ability to communicate clearly with both technical and non-technical audiences. You should have an interest in information security, governance, risk or compliance, together with a willingness to learn and develop. Familiarity with frameworks or standards such as ISO 27001, NIST, CIS Controls, SOC 2 or relevant data protection legislation would be advantageous. Experience using spreadsheets, ticketing systems, GRC platforms or other tools for tracking actions and evidence is desirable. A relevant degree, qualification or equivalent practical experience is welcome, but enthusiasm, sound judgement and a proactive approach are equally important. You will be expected to handle sensitive information responsibly, collaborate effectively and contribute positively in a fast-paced, continuously changing environment.
Read lessSouthampton, England, United KingdomPermanent
We are seeking an Information Security Analyst - SecOps Response to support the monitoring, investigation and resolution of... Read more
We are seeking an Information Security Analyst - SecOps Response to support the monitoring, investigation and resolution of security events across a complex technology environment. You will play a key role in protecting systems, data and users by identifying suspicious activity, assessing potential threats and coordinating effective incident response. This position is suited to an analytical and proactive security professional who can work calmly under pressure and communicate clearly with both technical and non-technical stakeholders.
Key responsibilities will include monitoring security alerts and event data using SIEM, endpoint detection and response, network monitoring and other security tools; triaging and investigating suspected incidents; conducting initial analysis of malware, phishing, unauthorised access and other threats; and escalating issues in line with established procedures. You will support containment, eradication and recovery activities, maintain accurate incident records, and contribute to post-incident reviews and lessons learned. The role will also involve developing and improving detection rules, response playbooks and operational processes, as well as producing clear reports and metrics for relevant stakeholders. You may assist with vulnerability investigations, threat hunting, security assessments and the ongoing improvement of controls.
Applicants should have practical experience in a security operations, incident response or similarly focused information security role, together with a sound understanding of security principles, attack techniques and incident management methodologies. Familiarity with SIEM platforms, endpoint security technologies, cloud environments, firewalls, identity systems and common investigative tools is highly desirable. Experience analysing logs, network traffic and system activity, along with the ability to document findings accurately, is essential. Relevant certifications or formal training in information security are advantageous. You will need strong problem-solving skills, attention to detail and the ability to prioritise competing demands while working effectively as part of a collaborative team. A commitment to continuous learning and maintaining current knowledge of emerging threats is expected.
Read lessSouthampton, England, United KingdomPermanent
We are seeking an Information Security Analyst - SecOps Detection to support the monitoring, investigation and continuous improvement... Read more
We are seeking an Information Security Analyst - SecOps Detection to support the monitoring, investigation and continuous improvement of security operations. You will help identify, assess and respond to potential threats across cloud, network, endpoint and application environments, working as part of a collaborative security team. This role is suited to an analytical and proactive professional who enjoys investigating suspicious activity, improving detection capability and translating technical findings into clear, actionable outcomes.
Responsibilities will include monitoring security alerts and events through SIEM, EDR and other security technologies; triaging and investigating suspected incidents; identifying indicators of compromise; and supporting containment, eradication and recovery activities. You will develop, tune and maintain detection rules, alert logic, dashboards and playbooks, while reducing false positives and improving detection coverage. The role will also involve threat hunting, malware and log analysis, vulnerability and exposure investigations, and contributing to post-incident reviews. You will document investigations accurately, produce concise reports, maintain relevant security procedures and collaborate with infrastructure, engineering and risk teams to strengthen controls. Participation in an out-of-hours or on-call rota may be required.
Applicants should have experience in a security operations, detection engineering, incident response or similar role, with a good understanding of common attack techniques, cyber threat intelligence and security frameworks. Practical experience with SIEM, EDR, vulnerability management or cloud security platforms is essential, along with the ability to analyse logs and events using query languages such as KQL, SPL or equivalent. Familiarity with scripting, automation and detection-as-code practices would be advantageous. You should be comfortable working with ambiguity, prioritising competing demands and communicating technical issues to both specialist and non-specialist audiences. Relevant professional certifications or demonstrable equivalent experience are welcomed. A methodical approach, strong attention to detail, sound judgement and a commitment to continuous learning are essential.
Read lessSouthampton, England, United KingdomPermanent
We are seeking a highly skilled Senior Product Security Engineer to join our dynamic team. In this role,... Read more
We are seeking a highly skilled Senior Product Security Engineer to join our dynamic team. In this role, you will be responsible for ensuring the security and integrity of our products throughout the development lifecycle. You will collaborate closely with cross-functional teams, including product management, engineering, and quality assurance, to identify and mitigate potential security vulnerabilities. Your expertise will be vital in developing and implementing security best practices, conducting threat modeling, and performing security assessments to enhance the overall security posture of our products.
The ideal candidate will have a strong background in software security, with experience in secure coding practices and vulnerability management. You will be tasked with creating and maintaining security documentation, providing security training for developers, and staying current with industry trends and emerging threats. Excellent problem-solving skills and the ability to communicate complex security concepts to non-technical stakeholders are essential. A deep understanding of security frameworks, compliance requirements, and relevant regulations will also be critical in this role.
If you are passionate about product security and thrive in a fast-paced environment, we encourage you to apply. Join us in our mission to deliver secure and reliable products that protect our customers and their data.
Read lessSouthampton, England, United KingdomPermanent
We are seeking a Senior Information Security Governance Analyst to join our dynamic team. In this role, you... Read more
We are seeking a Senior Information Security Governance Analyst to join our dynamic team. In this role, you will be responsible for developing, implementing, and maintaining comprehensive information security governance frameworks and policies to ensure compliance with industry standards and regulations. You will work closely with cross-functional teams to assess security risks, conduct audits, and facilitate risk assessments to identify areas of improvement. This position requires a strong understanding of security governance practices, risk management, and regulatory requirements.
Your primary duties will include monitoring and reporting on the effectiveness of security controls, conducting regular reviews of security policies, and providing guidance on best practices. You will also lead initiatives aimed at enhancing security awareness across the organization and support the development of security training programs. Additionally, you will be responsible for preparing and presenting security governance reports to senior management, ensuring that all stakeholders are informed of the current security posture and any potential vulnerabilities.
The ideal candidate will possess a deep knowledge of information security frameworks such as ISO 27001, NIST, or COBIT, along with strong analytical and problem-solving skills. Proven experience in a similar role, along with relevant certifications such as CISSP, CISM, or CRISC, is highly desirable. Excellent communication skills and the ability to work collaboratively in a fast-paced environment will be crucial for success in this position.
Read lessSouthampton, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria