Skip to main content
AfterDuty

IT Security Specialist

Montu Group · London, Greater London

Salary
£55,000 – £60,000Estimated
Type
Full-time
Posted
3 days ago

Overview

What is the job? Montu UK is entering an exciting new phase in its security journey: creating an independent, future-ready architecture for the UK and Europe.

About this role

What is the job?

Montu UK is entering an exciting new phase in its security journey: creating an independent, future-ready architecture for the UK and Europe. We’re moving beyond shared APAC infrastructure to establish our own tenants, controls and security ecosystem -built specifically for the unique demands of our rapidly growing UK and EU operations.

Australia has already developed a mature security architecture; this role is an opportunity to take that strong foundation and shape it for an entirely different regulatory and operational landscape. You’ll build security around requirements including CQC, GPhC, MHRA, Home Office controlled drugs, UK GDPR and NHS DSPT, while supporting an expanding estate that includes our Winnersh Triangle site, EU tenant separation and continued European growth.

This is not a governance-only role focused on auditing, reporting or writing policies - we already have dedicated teams owning that work. We need a hands-on security builder: someone who can design, implement and operate meaningful controls, solve complex technical challenges and strengthen our security capabilities from the inside.

You’ll work directly alongside the IT Manager as a close collaborator on both strategy and delivery, with the Support Analyst and HiLabs Ireland contact forming your wider working circle. You’ll be part of the team building and delivering the architecture -not standing outside it and checking the work.

Given the regulatory responsibility Montu carries, sound judgement and trustworthiness are essential - but so is momentum. We value practical progress over perfection: someone who can implement a strong, effective control today, learn from it and continue improving it, rather than spend months developing a flawless policy that never makes it into practice.

What will you be doing?

This is a delivery role. Representative work already in flight or on the near-term roadmap:

Endpoint & identity security engineering - contributing to the CrowdStrike AU UK CID migration (Intune-deployed, scripted), Entra ID configuration for the new EU/UK tenant, and Intune/MDM policy build-out.

Network security delivery - hands-on work on Netskope deployment for SaaS/web steering, Tailscale ACL and zero-trust access design, and FortiGate/UniFi security configuration for the Winnersh Triangle site.

Site security build - working the physical/technical security side of the Winnersh Triangle stand-up: access control (Paxton), CCTV, structured cabling security, vendor delivery oversight (we're mid-RFP with Safeguard Systems and FTL Secure Solutions) - this is real vendor and project management, not paperwork.

Compliance-as-engineering - turning ISO 27001 and Cyber Essentials Plus requirements into actual implemented controls rather than just gap-analysis documents; supporting DSPT evidence with real technical artefacts.

Incident response & monitoring - building out our detection and response capability as it matures, being a genuine first responder rather than a policy author.

Vendor & pentest liaison - working with our security partners (e.g. Klaatu IT Security) on delivery, not just contract admin - reviewing findings and personally driving remediation.

Documentation that's useful, not performative - technical runbooks, architecture diagrams, and control evidence that the team actually uses, versus policy for policy's sake.

You'll be a second pair of hands and a second brain on all of this - someone the IT Manager can hand a problem to and trust it gets solved, not just assessed.

What do you need?

The mindset matters more than the checklist

You'd rather fix the thing than write a memo about the thing.

You see security as an enabler of the business (clinicians, pharmacy, patients) rather than a department of "no."

You're comfortable being hands-on in Intune, a firewall config, or a script at 4pm and in a vendor negotiation or compliance conversation at 10am.

You work well in a very small, very autonomous team - this is not an environment with layers of process to hide behind; you'll need to be self-directed.

You’ll need to “muck-in” with the team if the need arises for any & all technology issues.

Technical experience (ideally several of the following)

Endpoint protection platforms (CrowdStrike, Sophos, or similar EDR/XDR)

Microsoft Entra ID / Intune, and modern zero-trust access tooling (Tailscale, Netskope, Cloudflare Zero Trust, or similar)

Network security fundamentals (FortiGate or similar UTM/firewall, VLAN segmentation, secure site network design)

ISO 27001 and/or Cyber Essentials Plus - from an implementation angle, not just an audit angle

Working knowledge of UK GDPR and healthcare-adjacent regulatory environments (CQC, NHS DSPT, GPhC, MHRA) - or a fast learner who can pick this up with support

Scripting/automation (PowerShell, Python, or similar) for security tooling and deployment

Comfort working with regulated, patient-data-adjacent systems

Bonus points if you have

Experience in a healthcare, pharmacy, or life sciences environment

Experience helping a business separate from a parent company's IT estate (tenant migrations, identity separation)

CREST, CISSP, CISM, or equivalent - valued but not gatekept on; we care more about what you've built than the letters after your name

What this role is not

Not a compliance-only or audit-only function

Not a "security says no" gatekeeper role

Not a large-team, heavily hierarchical environment - this is scrappy, fast-moving, and hands-on

Not someone who hands work back to the IT Manager to implement - you implement it

What we offer

Generous Leave: 25 days holiday (rising to 27 after year one and 30 after year three) + usual bank holidays

Pension Matching: Up to 5% employer matching contributions

Flexibility and Wellness: Work-from-home options, cycle-to-work scheme, private healthcare and more

Growth Opportunities: Collaborate across teams and represent Montu at events, with support to grow your skills and impact

Enhanced Maternity & Paternity Leave

About Us

Montu UK is a leading digital health company specialising in cannabis-based medicines (CBPM), dedicated to improving patient access to safe and effective treatments. Our mission is to transform lives by combining innovative technology with high-quality clinical care, ensuring patients receive the support they need at every step of their journey.

As a fast-growing organisation, we offer a collaborative and supportive environment where talented people can develop their careers while contributing to meaningful change in healthcare. At Montu UK, your work has a direct impact on improving patients’ lives and expanding access to modern medical treatments.

Compensation Range: £55K - £60K

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 87/100

  • Incident command & response
  • Working to legislation & regulation
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Job details *Location:*London, Manchester *Capability:*Advisory *Experience Level:*Associate/Assistant Manager *Type:*Full Time *Business Area:*Cyber *Contract type:*Permanent Job description Cyber Response & Recovery Assistant Manager (Reactive DFIR) This role requires current SC or DV clearance,…

    Posted 3 days ago

  • Security Analyst

    Kubrick Group · London

    Full-time

    The opportunity Join us at the forefront of cyber defence, where you'll play a critical role in protecting our business from evolving threats. You'll proactively monitor, investigate and respond to security incidents using Microsoft Sentinel, Microsoft Defender and leading EDR technologies, working…

    Posted 3 days ago

  • SOC Lead

    NCC Group · London

    Contract

    Description We are looking for a proactive SOC Analyst to monitor, detect, investigate, and respond to cyber security threats using the Splunk Enterprise Security toolset.

    Posted 3 days ago

  • Head of IT

    metropolitan gaming · London

    Full-time

    About Us Metropolitan Gaming is about more than the games or the buzz of the venue. It’s about energy. Atmosphere. Service that’s sharp and in sync with the moment.

    Posted 4 days ago