Job Description Data Security Analyst - Cyber & Information Resilience Salary: National ranging from £51,200 to £68,000 and London from £56,400 to £75,000 Eligibility of Security clearance is mandatory Are you interested in joining a team that will design and implement a data security strategy? The team/department The Cyber and Information Resilience (C&IR) Team is a department that has been formed to respond to the growing threat from cyber security and the organisation's increasing reliance on the data in order to effectively regulate of the financial sector and ensure that relevant markets function well. Within the department, the C&IR Operational Assurance Team is responsible for the definition and provision of and integrated set of security and information assurance activities across the whole of the FCA. C&IR Operational Assurance will conduct security and data reviews, analysis and testing to confirm the appropriate application (whether through technology, process or behaviour) of the policies and the secure operation of the FCA's systems and the information and data thereon. What you will be doing (the role) * Manage the design, development, and implementation of data security strategy and policies across the organisation * Conduct risk assessments and audits to identify vulnerabilities and areas for improvement in data security practices * Collaborate with internal stakeholders to assess data security requirements for new projects and initiatives * Provide guidance and support to business units on data security best practices and compliance requirements * Monitor and analyse data security incidents, investigate root causes, and implement corrective actions as necessary * Lead Data Loss Protection (DLP) rule development life cycle including policy development, response rules, and maintenance * Acts as the subject matter expert for a DLP domain, producing knowledge transfer materials, and dealing with complex internal and external stakeholder queries * Develop and enforce security controls for cloud-based infrastructure in alignment with enterprise requirements What you will get from the role * Being part of a multi-disciplinary team that is strategically important to the mission of the FCA * Influence the strategic direction of information compliance and resilience at the FCA * Work in an environment that encourages learning and collaboration within all areas of Cyber and Information Security * Opportunity to develop and mature the information assurance control framework through leadership and direction, driving values and behaviours to ensure alignment and commitment between key stakeholders and the wider business Our competitive flexible benefits scheme gives you the opportunity to create a personalised benefits package, tailored to suit your life cycle. You can use this allowance to purchase additional benefits such as dental or cycle to work or you have the option top up your base salary by taking this as cash. Core benefits that you will receive as standard are: * 25 days holiday per year plus bank holidays * Private healthcare with Bupa * A non-contributory Pension of at least 8% of basic salary each month (there are several contribution levels that increase depending on your age - up to 12% a month once you reach age 35) * Life assurance of eight times your basic salary * Income protection We support hybrid working which means you will be able to work from home up to 60% of the time over a month with the remainder of your time in one of our three office locations. The skills and experience you will have Minimum We are a signatory to the Government's Disability Confident scheme. This means that we will offer an interview to disabled candidates entering under the scheme, who best meet the minimum criteria for a role. * Proven experience of Data Loss Prevention technologies (Network, Email, Endpoint, etc.) and processes * Demonstrable evidence of performing technical assessments and audits of information and data repositories, such as M365, as well as auditing IT processes * Experience of Information and Data Risk Management practices Essential * Proven background in security engineering, data protection, data life cycle management, data loss prevention or the supporting of these security solutions * Experience implementing policy modules for automation across industry standards including ISO27001 and GDPR * Working knowledge of Microsoft Purview functionality, ability to deliver the best business solution to ensure compliance across the Microsoft Office Suite of products * Hands-on involvement in the delivery and execution of more than one of the areas listed in the job description key responsibilities * Analytical and problem-solving skills, with the ability to identify and oversee mitigation of data security risks About the FCA The FCA regulates the conduct of nearly 45,000 firms in the UK to ensure our financial markets are honest, fair and competitive. We do this to make sure markets work well for individuals, businesses and the economy as a whole. For more information on what we do, our three-year strategy can be found here. The FCA's Values & Diversity Our ambition is to cultivate a culture of inclusion for all employees that respects their individual strengths, views, and experiences. We believe that our differences and similarities enable us to be a better organisation - one that makes better decisions, drives innovation, and delivers better regulation. The FCA is committed to achieving greater diversity across all levels of the organisations. Given this, we particularly welcome applications from women, disabled and minority ethnic candidates for our senior associate role. Flexible working We welcome applications from candidates who are looking for flexible arrangements. Many of our staff work flexibly including working part time, staggered hours, and job shares. We can't promise to give you exactly what you want but we won't judge you for asking. Multi-location As part of the FCA's on-going commitment to develop our national presence, most of our vacancies are now open to working in our Edinburgh, Leeds, or London offices. This means that as part of the application process you will be able to select your preference of which office location you would like to work from. Our Recruitment Delivery Team are committed to offering an inclusive recruitment experience to all candidates. If you require any accommodations or adjustments as a result of disability, impairment, or health condition, please do not hesitate to let me know by emailing.
03/05/2024
Full time
Job Description Data Security Analyst - Cyber & Information Resilience Salary: National ranging from £51,200 to £68,000 and London from £56,400 to £75,000 Eligibility of Security clearance is mandatory Are you interested in joining a team that will design and implement a data security strategy? The team/department The Cyber and Information Resilience (C&IR) Team is a department that has been formed to respond to the growing threat from cyber security and the organisation's increasing reliance on the data in order to effectively regulate of the financial sector and ensure that relevant markets function well. Within the department, the C&IR Operational Assurance Team is responsible for the definition and provision of and integrated set of security and information assurance activities across the whole of the FCA. C&IR Operational Assurance will conduct security and data reviews, analysis and testing to confirm the appropriate application (whether through technology, process or behaviour) of the policies and the secure operation of the FCA's systems and the information and data thereon. What you will be doing (the role) * Manage the design, development, and implementation of data security strategy and policies across the organisation * Conduct risk assessments and audits to identify vulnerabilities and areas for improvement in data security practices * Collaborate with internal stakeholders to assess data security requirements for new projects and initiatives * Provide guidance and support to business units on data security best practices and compliance requirements * Monitor and analyse data security incidents, investigate root causes, and implement corrective actions as necessary * Lead Data Loss Protection (DLP) rule development life cycle including policy development, response rules, and maintenance * Acts as the subject matter expert for a DLP domain, producing knowledge transfer materials, and dealing with complex internal and external stakeholder queries * Develop and enforce security controls for cloud-based infrastructure in alignment with enterprise requirements What you will get from the role * Being part of a multi-disciplinary team that is strategically important to the mission of the FCA * Influence the strategic direction of information compliance and resilience at the FCA * Work in an environment that encourages learning and collaboration within all areas of Cyber and Information Security * Opportunity to develop and mature the information assurance control framework through leadership and direction, driving values and behaviours to ensure alignment and commitment between key stakeholders and the wider business Our competitive flexible benefits scheme gives you the opportunity to create a personalised benefits package, tailored to suit your life cycle. You can use this allowance to purchase additional benefits such as dental or cycle to work or you have the option top up your base salary by taking this as cash. Core benefits that you will receive as standard are: * 25 days holiday per year plus bank holidays * Private healthcare with Bupa * A non-contributory Pension of at least 8% of basic salary each month (there are several contribution levels that increase depending on your age - up to 12% a month once you reach age 35) * Life assurance of eight times your basic salary * Income protection We support hybrid working which means you will be able to work from home up to 60% of the time over a month with the remainder of your time in one of our three office locations. The skills and experience you will have Minimum We are a signatory to the Government's Disability Confident scheme. This means that we will offer an interview to disabled candidates entering under the scheme, who best meet the minimum criteria for a role. * Proven experience of Data Loss Prevention technologies (Network, Email, Endpoint, etc.) and processes * Demonstrable evidence of performing technical assessments and audits of information and data repositories, such as M365, as well as auditing IT processes * Experience of Information and Data Risk Management practices Essential * Proven background in security engineering, data protection, data life cycle management, data loss prevention or the supporting of these security solutions * Experience implementing policy modules for automation across industry standards including ISO27001 and GDPR * Working knowledge of Microsoft Purview functionality, ability to deliver the best business solution to ensure compliance across the Microsoft Office Suite of products * Hands-on involvement in the delivery and execution of more than one of the areas listed in the job description key responsibilities * Analytical and problem-solving skills, with the ability to identify and oversee mitigation of data security risks About the FCA The FCA regulates the conduct of nearly 45,000 firms in the UK to ensure our financial markets are honest, fair and competitive. We do this to make sure markets work well for individuals, businesses and the economy as a whole. For more information on what we do, our three-year strategy can be found here. The FCA's Values & Diversity Our ambition is to cultivate a culture of inclusion for all employees that respects their individual strengths, views, and experiences. We believe that our differences and similarities enable us to be a better organisation - one that makes better decisions, drives innovation, and delivers better regulation. The FCA is committed to achieving greater diversity across all levels of the organisations. Given this, we particularly welcome applications from women, disabled and minority ethnic candidates for our senior associate role. Flexible working We welcome applications from candidates who are looking for flexible arrangements. Many of our staff work flexibly including working part time, staggered hours, and job shares. We can't promise to give you exactly what you want but we won't judge you for asking. Multi-location As part of the FCA's on-going commitment to develop our national presence, most of our vacancies are now open to working in our Edinburgh, Leeds, or London offices. This means that as part of the application process you will be able to select your preference of which office location you would like to work from. Our Recruitment Delivery Team are committed to offering an inclusive recruitment experience to all candidates. If you require any accommodations or adjustments as a result of disability, impairment, or health condition, please do not hesitate to let me know by emailing.
Request Technology - Craig Johnson
San Francisco, California
*We are unable to sponsor for this 6+ Month Contract role* Prestigious Fortune 500 Company is currently seeking a Security Red Team Operator. Candidate will take a structured approach to Red Team operations (ie, testing in lab environments, creating and operating according to runbooks and SOPs, writing detailed after-action reports, participating in daily operation syncs). This is currently a two-person team. As such, the candidate will need to be a highly motivated, self-sufficient, and capable of collaborating on a small team where consensus is a must for operations to be successful. This role will also be involved in our Tabletop Exercise planning and execution, and therefore, will need excellent written and oral communication skills when dealing with all levels of the organization, from executives to individual contributors. The Red team is responsible for testing the overall strength of our organizations defenses (the technology, the processes, and the people) by simulating the objectives and actions of an attacker. Responsibilities: Perform internal and external penetration testing of network infrastructure and applications Perform Red team assessments including physical, social engineering, and network exploitation Perform well controlled vulnerability exploitation/penetration testing on applications, network protocols, and databases Perform network reconnaissance, OSINT, social engineering, and physical security reviews Participate in regular exercises and perform adversary simulations to test defense controls Assist with scoping prospective engagements, leading engagements from kickoff through remediation Work closely with Blue team to test efficacy of existing alerts and help create new detection. Create findings reports and communicate to stakeholders Contribute to enhancing the teams toolkit Write custom scripts to automate tasks related to finding new vulnerabilities Maintain runbooks to continually improve penetration testing methodologies and threat modelling. Qualifications : 5+ years of experience in Penetration testing, Red Team and Purple Team Bachelor of Science in Engineering, Computer Science, Information Technology, or equivalent work experience Advanced knowledge in common penetration testing tools (Metasploit, Burp Suite, Cobalt Strike, Empire, KALI Linux etc.) Must have a demonstrable understanding of voice and data networks, major operating systems, Active Directory, cloud technologies Must demonstrate knowledge of MITREs ATT&CK framework, execute and chain TTPs Must be able to critically examine an organization and system through the perspective of a threat actor and articulate risk in clear, precise terms. Ability to optimally code in a Scripting language (Python, Bash, PowerShell, Perl, etc.) OSCP
01/05/2024
Project-based
*We are unable to sponsor for this 6+ Month Contract role* Prestigious Fortune 500 Company is currently seeking a Security Red Team Operator. Candidate will take a structured approach to Red Team operations (ie, testing in lab environments, creating and operating according to runbooks and SOPs, writing detailed after-action reports, participating in daily operation syncs). This is currently a two-person team. As such, the candidate will need to be a highly motivated, self-sufficient, and capable of collaborating on a small team where consensus is a must for operations to be successful. This role will also be involved in our Tabletop Exercise planning and execution, and therefore, will need excellent written and oral communication skills when dealing with all levels of the organization, from executives to individual contributors. The Red team is responsible for testing the overall strength of our organizations defenses (the technology, the processes, and the people) by simulating the objectives and actions of an attacker. Responsibilities: Perform internal and external penetration testing of network infrastructure and applications Perform Red team assessments including physical, social engineering, and network exploitation Perform well controlled vulnerability exploitation/penetration testing on applications, network protocols, and databases Perform network reconnaissance, OSINT, social engineering, and physical security reviews Participate in regular exercises and perform adversary simulations to test defense controls Assist with scoping prospective engagements, leading engagements from kickoff through remediation Work closely with Blue team to test efficacy of existing alerts and help create new detection. Create findings reports and communicate to stakeholders Contribute to enhancing the teams toolkit Write custom scripts to automate tasks related to finding new vulnerabilities Maintain runbooks to continually improve penetration testing methodologies and threat modelling. Qualifications : 5+ years of experience in Penetration testing, Red Team and Purple Team Bachelor of Science in Engineering, Computer Science, Information Technology, or equivalent work experience Advanced knowledge in common penetration testing tools (Metasploit, Burp Suite, Cobalt Strike, Empire, KALI Linux etc.) Must have a demonstrable understanding of voice and data networks, major operating systems, Active Directory, cloud technologies Must demonstrate knowledge of MITREs ATT&CK framework, execute and chain TTPs Must be able to critically examine an organization and system through the perspective of a threat actor and articulate risk in clear, precise terms. Ability to optimally code in a Scripting language (Python, Bash, PowerShell, Perl, etc.) OSCP
Michael Bailey Associates - Amsterdam
Amsterdam, Noord-Holland
General information: Job Title: Cyber Security Specialist Location: Amsterdam Permanent position Hybrid working Salary indication: Our Client is seeking dynamic individuals to join their team as Cyber Security Specialists. As a Cyber Security Specialist, you will play a crucial role in safeguarding our client's systems and data against cyber threats. Your primary responsibilities will include conducting proactive research, identifying vulnerabilities, and developing innovative solutions to enhance security measures. Key Responsibilities: Conduct proactive research to identify potential security vulnerabilities and threats. Collaborate with cross-functional teams to develop and implement effective security strategies. Perform security assessments and penetration testing to identify weaknesses in systems and applications. Develop and implement innovative security solutions to mitigate risks and protect against cyber threats. Stay abreast of the latest cybersecurity trends, technologies, and best practices. Ideal Candidate Profile: Experience in and success in the field of cybersecurity in combination with the bullet point below. Background in high threat level companies. With an engineering background or a bachelors/master's degree in cyber security or other relevant domain. You value an environment where innovative security projects, personal development, and being valued as an employee is important. Relevant certifications such as Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), Certified Information Systems Security Professional (CISSP), or other recognized credentials in ethical hacking or defensive cybersecurity. Why Choose Our Client? Joining our client's team provides a unique opportunity for personal and professional growth. Our client prioritizes delivering high-quality work and fostering a culture of continuous improvement. As a member of the team, you will have the chance to engage in proactive research, unleash your creativity, and contribute to innovative security projects. Dutch is a pre Proficiency in Dutch is highly desirable for effective communication and collaboration within the team and with Dutch-speaking stakeholders. In case you are not fully confident about your Dutch skills - please feel free to apply and we can have a conversation about this opportunity. If you are passionate about cybersecurity and eager to make a meaningful impact, we encourage you to apply for this exciting opportunity with our client. Join us but mainly them in the fight against cyber threats and help shape the future of cybersecurity. Michael Bailey International is acting as an Employment Agency in relation to this vacancy.
30/04/2024
Full time
General information: Job Title: Cyber Security Specialist Location: Amsterdam Permanent position Hybrid working Salary indication: Our Client is seeking dynamic individuals to join their team as Cyber Security Specialists. As a Cyber Security Specialist, you will play a crucial role in safeguarding our client's systems and data against cyber threats. Your primary responsibilities will include conducting proactive research, identifying vulnerabilities, and developing innovative solutions to enhance security measures. Key Responsibilities: Conduct proactive research to identify potential security vulnerabilities and threats. Collaborate with cross-functional teams to develop and implement effective security strategies. Perform security assessments and penetration testing to identify weaknesses in systems and applications. Develop and implement innovative security solutions to mitigate risks and protect against cyber threats. Stay abreast of the latest cybersecurity trends, technologies, and best practices. Ideal Candidate Profile: Experience in and success in the field of cybersecurity in combination with the bullet point below. Background in high threat level companies. With an engineering background or a bachelors/master's degree in cyber security or other relevant domain. You value an environment where innovative security projects, personal development, and being valued as an employee is important. Relevant certifications such as Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), Certified Information Systems Security Professional (CISSP), or other recognized credentials in ethical hacking or defensive cybersecurity. Why Choose Our Client? Joining our client's team provides a unique opportunity for personal and professional growth. Our client prioritizes delivering high-quality work and fostering a culture of continuous improvement. As a member of the team, you will have the chance to engage in proactive research, unleash your creativity, and contribute to innovative security projects. Dutch is a pre Proficiency in Dutch is highly desirable for effective communication and collaboration within the team and with Dutch-speaking stakeholders. In case you are not fully confident about your Dutch skills - please feel free to apply and we can have a conversation about this opportunity. If you are passionate about cybersecurity and eager to make a meaningful impact, we encourage you to apply for this exciting opportunity with our client. Join us but mainly them in the fight against cyber threats and help shape the future of cybersecurity. Michael Bailey International is acting as an Employment Agency in relation to this vacancy.