About this role
This is a hands-on, first-line security role for a doer — not a policy-writer or a manager. You will effectively be the operational security function, running vulnerability management, incident response and day-to-day controls yourself.
There is no SOC and no team beneath you — so we need someone who is genuinely self-sufficient, gets stuck in, and can also talk risk credibly to an ISO 27001-minded leadership team.
What you'll actually do
- Run vulnerability management end to end on Tenable — scanning, triage, risk-based prioritisation (CVE/KEV, severity, business impact) and driving owners to remediate to SLA.
- Own the security incident process — detection, triage, containment, recovery — and escalate to the ISO/2nd line properly.
- Conduct or coordinate regular and ad-hoc security assessments (VAPT) and close the findings.
- Run control-based risk assessments and keep the risk register current — you'll be expected to know the difference between a risk and an issue, and to explain both clearly.
- Implement and maintain security controls in line with the Group NFR Control Catalogue, ISO 27001.
- Support compliance and audit, IAM and access reviews, and security awareness across the business.
Background
- A hands-on security operator background — you've personally run vulnerability management and worked incidents, not just overseen them.
- Real experience with vulnerability scanners (Tenable ideal; Qualys/Nessus transferable) and endpoint/network monitoring.
- Genuine grasp of IT risk — risk assessment, risk registers, risk vs issue, and how controls map to frameworks (ISO 27001, PCI-DSS, NIST).
- Solid cloud and identity fundamentals (Azure / M365 / Entra ID; AWS or OCI welcome).
- The temperament to work autonomously as the sole first-line resource and communicate risk clearly to non-technical stakeholders.
- Ideally from a regulated / financial-services environment;
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in London →Why this fits a police background
- Incident command & response
- Risk & threat assessment
- Working to legislation & regulation
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |