Head of Cyber Threat Exposure

4 weeks ago


London, UK, United Kingdom Bupa Full time

At Bupa, were passionate about technology. With colleagues, customers, patients and residents in mind youll have the opportunity to work on innovative projects and make a real impact on their lives.

As Head of Cyber Threat Exposure, youll play a crucial role in vulnerability management and offensive activities across Bupa. Youll provide threat-led cyber security leadership, subject matter expertise, oversight, E2E process design and implementation, and coordination of vulnerability management and offensive security services across all technology in Bupa.

How youll help us make health happen

• Lead a team of technical security experts to drive a continuous ecosystem for managing vulnerabilities and offensive security to limit Bupas exposure from both strategic and tactical threats.

• End to end management and delivery of security services including penetration testing, assumed breach testing, attack and social engineering simulations, red and purple teaming.

• Provide comprehensive dashboarding and reporting capabilities leveraging threat intelligence and proactively identify, prioritise, and remediate vulnerabilities and threat exposures

• Ensure that all technology, cloud services and third-party solutions comply with defined vulnerability management and penetration testing requirements.

• Act as Bupas subject matter expert on vulnerability impact and risk, providing guidance on root cause and managing the full lifecycle of reported vulnerabilities through to closure.

• Collaborate with their counterparts in other Bupa Markets to share knowledge, ideas, innovation, and areas for improvement.

• Stay abreast of emerging cybersecurity industry thought leadership, external industry colleagues, threats, vulnerabilities, and attack techniques.

What youll bring

• Solid experience in cybersecurity, with extensive experience in threat management, vulnerability management, offensive security practices and security testing.

• Strong knowledge of common security vulnerabilities, attack vectors, and security testing frameworks, such as OWASP, MITRE ATT&CK, CVE / CVSS, and NIST SP 800-53.

• Experience of vulnerability scanning tools, penetration testing tools, and security testing frameworks (e.g., Nessus, Metasploit, Burp Suite, Nmap, Claire, and OpenSCAP).

• Extensive experience with Red Teaming, Purple Teaming and Attack Automation.

• Familiarity with industry regulations and compliance standards related to cybersecurity, such as NIST CSF, SOC2, PCI DSS, and ISO 27001.

• A relevant professional qualification in Cyber and Information Security (e.g., OCSP, CISM, CISSP, CEH)

• Experience of vulnerability management and security testing in cloud environments (such as Azure, GCP and/or AWS) including containers, containerised applications, and infrastructure e.g., Kubernetes.

• Excellent analytical and problem-solving skills, with the ability to analyse complex technical issues and recommend effective solutions.

• Strong communication skills, with the ability to convey technical concepts and findings to non-technical stakeholders and senior management.

• Ability to take decisive action where time is critical factor and maintain a high degree of confidentiality, even under pressure.

Benefits

Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health – from mental and physical, to financial, social and environmental wellbeing. We support flexible working and have a range of family friendly benefits.

• Joining Bupa in this role you will receive the following benefits and more:

• 25 days holiday, increasing through length of service, with option to buy or sell

• Bupa health insurance as a benefit in kind

• An enhanced pension plan and life insurance

• Annual performance-based bonus

• Onsite gyms or local discounts where no onsite gym available

• Various other benefits and online discounts


  • Cyber Threat Detection

    2 months ago


    London,, UK, United Kingdom 55 Exec Search Full time

    Cyber Threat Detection Our client is a pure-play cyber security consulting firm, due to a recent M&A and continued growth they are looking for a technical and driven Threat Detection Engineer to join the growing team.You will collaborate closely with the SOC analysts, ensuring clients’ security posture is enhanced. As a Threat Intelligence Analyst, you...


  • London, UK, United Kingdom Allianz Full time

    Whether it’s aircraft, international business or offshore wind parks, Allianz Commercial has an extensive range of risks covered when it comes to protecting businesses. We are looking for a Regional Head of Cyber Underwriting based in London. Your Team At Allianz Commercial we combine specialist expertise and global reach with high levels of AA rated...


  • London,, UK, United Kingdom Cyber Search Partners Full time

    Location: UK based - South West, East or London offices Salary: up to £70k Contract Type: PermanentCyber Security and Information Assurance Senior ConsultantCompany OverviewA defense company focused on transforming commercial innovation into solutions for the toughest challenges in national security. Leveraging deep mission expertise, it delivers...

  • Head of London

    2 weeks ago


    London, UK, United Kingdom myGwork Full time

    This job is with Beazley, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. GeneralJob Title: Head of London & International Underwriting Management, Cyber Risks Division: Cyber Risks Reports To: As per Beazley’s organisation chart Key...


  • London,, UK, United Kingdom HD Tech Recruitment Full time

    Key ResponsibilitiesDevelop, implement, and maintain a business-aligned Information and Cyber Security strategy and operating model.Establish and enforce an Information Security Policy Framework that complies with relevant legislation and industry standards.Advise the Executive and Senior Leadership Team on integrating security best practices into strategic...


  • London, UK, United Kingdom TP ICAP Full time

    The TP ICAP Group is a world leading provider of market infrastructure. Our purpose is to provide clients with access to global financial and commodities markets, improving price discovery, liquidity, and distribution of data, through responsible and innovative solutions. Through our people and technology, we connect clients to superior liquidity and data...

  • Threat Hunter

    3 weeks ago


    London,, UK, United Kingdom Trident Search Full time

    Think you know the attacker mindset? Trident Search’s defence team are working with a well known MDR provider who are expanding their ASM team - naturally given the increase of sophisticated attacks across the globe. The client are looking for individuals who are enthusiastic about learning the ways of APT groups and staying ahead of them. Ultimately...


  • London,, UK, United Kingdom Vallum Associates Full time

    Role: Cyber Security AnalystLocation : Office location London. Hybrid working available.Full Time role Insurance/Finance experience is mandatory Duties and accountabilitiesWorking with our third parties ensure that we are continually monitoring the organisations networks, systems and applications for security breaches, intrusions and other suspicious...


  • London,, UK, United Kingdom Lorien Full time

    Cyber Security Analyst (SOC)Location: LondonHybrid workingSalary: Up to £60,000 (DOE)Our client is a global investment bank that operates in the financial services sector, and they are looking for a Cyber Security Analyst around L1/L2 that will strengthen their security posture provide expertise on incident response and vulnerability...


  • London,, UK, United Kingdom IPS Group Full time

    We are currently partnering with a reputable syndicate who are seeking a senior cyber underwriter to join the team in an impactful position where you will be the only Senior in the team, reporting into the Head of Cyber . This D&F Cyber and Technology is made up of international (non US) risks, written both on a delegated and open market basis, aside from...


  • London,, UK, United Kingdom Bestman Solutions Full time

    We’re looking for an experienced Cyber Security Engineer who thrives in a fast-paced environment and is passionate about protecting digital infrastructure. Join our team and take on a key role in strengthening and advancing our security measures. If you’re ready to bring expertise and creativity to drive effective cybersecurity solutions, we’d love to...


  • London,, UK, United Kingdom Comtecs Group Full time

    Cyber Security Analyst – Security Monitoring, Security Incident Response, Security ITSM, PAM, MS Sentinel, MS Defender (XDR/TVM), IDS/IPS, Cisco ISE, Windows (Desktop/Server), O365, InTune, VMWARE, Legal Applications; NIST. Law Firm/Professional Services. Permanent, London, £70k - £80k +Bonus + Benefits***NOTE: This vacancy is offered by the IT...


  • London,, UK, United Kingdom Insight Global Full time

    Insight Global is seeking a Cyber Security Team Lead to sit in Central London. The team is expected to be on-site 3-days a week minimum working core hours of 9AM-5:30PM GMT. This role will work directly with the Senior Cyber Security Lead. The successful candidate will be skilled in threat hunting, analysing indicators of compromise (IOCs), investigating...

  • Head of Product

    2 weeks ago


    London,, UK, United Kingdom Space Executive Full time

    My client, a leading provider of cyber security solutions, dedicated to delivering actionable intelligence, innovative technology, and expert insights that empower our clients to navigate today’s complex threat landscape, is seeking a 'hands on' Head of Product and Technology to join their growing team.Currently my client has an office in the North...


  • London, UK, United Kingdom Paritas Recruitment - Risk Full time

    Operational Resilience Risk Specialist - Cyber & Technology A leading UK based bank is currently recruiting for an Operational Resilience professional who has in depth Cyber and Technology exposure. The team sits in the 2nd LOD and provides oversight, guidance, and challenge to the first line, ensuring business activities align with the banks risk...


  • London, UK, United Kingdom CER Financial Full time

    Head of Operational Risk City of London Permanent £150,000 3/2 work practices cer Financial are working alongside a well-structured, well established international bank who are based in the City of London. They are seeking a Head of Operational Risk to work with them on a permanent basis. The responsibilities of a Head of Operational Risk will...


  • London,, UK, United Kingdom Harnham Full time

    HEAD OF FRAUD£120,00LONDONTHE COMPANY This company is an exciting FinTech that are on a great growth trajectory. They have exciting plans for the next few years and are looking for an experienced candidate to help them on their journey. The business are expanding globally and this role offers the chance to help with this whilst having a very hands-on,...


  • London,, UK, United Kingdom McCabe & Barton Full time

    SOC - SecOps – SIEM / XDR / SOAR – Detection and Response – Threat Intelligence – CiSSP Vendor Management – Law Firm – London – c£70k + BenefitsOur Client, a prestigious London based Law Firm are looking for a Senior SOC Analyst / Lead SOC Analyst who is looking for their next role within an interesting and ever evolving mid-sized...


  • London, UK, United Kingdom Backstop Solutions Group Full time

    The IT Security Analyst is a global role within the ION Analytics Division. The role will support the division’s security strategy through the identification, mitigation and remediation of information security risks to the business. This role reports to the divisional CISO.As a member of the Analytics’ IT Security Team, the successful candidate will be...

  • Head of Marketing

    2 weeks ago


    London,, UK, United Kingdom Aspiron Search Full time

    Join a small but mighty team making a big impact in the Cyber Security industryLead the marketing function and drive growth for a leading ASM and Vulnerability Management platformEnjoy a flexible, collaborative culture focused on continuous improvement and employee well-beingOur client is a fast-growing Cyber Security company that provides a proactive...