Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

IT Security Specialist

Montu Uk
CompanyMontu Uk
CategorySecurity
LocationWinnersh
RemoteHybrid
EmploymentNot stated
LevelMid
SalaryGBP 55k–60k
Posted29 Jul 2026
Last verified30 Jul 2026
SourceEmployer career page (ashby)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
What is the job? Montu UK is entering an exciting new phase in its security journey: creating an independent, future-ready architecture for the UK and Europe. We’re moving beyond shared APAC infrastructure to establish our own tenants, controls and security ecosystem -built specifically for the unique demands of our rapidly growing UK and EU operations. Australia has already developed a mature security architecture; this role is an opportunity to take that strong foundation and shape it for an entirely different regulatory and operational landscape. You’ll build security around requirements including CQC, GPhC, MHRA, Home Office controlled drugs, UK GDPR and NHS DSPT, while supporting an expanding estate that includes our Winnersh Triangle site, EU tenant separation and continued European growth. This is not a governance-only role focused on auditing, reporting or writing policies - we already have dedicated teams owning that work. We need a hands-on security builder: someone who can design, implement and operate meaningful controls, solve complex technical challenges and strengthen our security capabilities from the inside. You’ll work directly alongside the IT Manager as a close collaborator on both strategy and delivery, with the Support Analyst and HiLabs Ireland contact forming your wider working circle. You’ll be part of the team building and delivering the architecture -not standing outside it and checking the work. Given the regulatory responsibility Montu carries, sound judgement and trustworthiness are essential - but so is momentum. We value practical progress over perfection: someone who can implement a strong, effective control today, learn from it and continue improving it, rather than spend months developing a flawless policy that never makes it into practice. What will you be doing? This is a delivery role. Representative work already in flight or on the near-term roadmap: - Endpoint & identity security engineering - contributing to the CrowdStrike AU→UK CID migration (Intune-deployed, scripted), Entra ID configuration for the new EU/UK tenant, and Intune/MDM policy build-out. - Network security delivery - hands-on work on Netskope deployment for SaaS/web steering, Tailscale ACL and zero-trust access design, and FortiGate/UniFi security configuration for the Winnersh Triangle site. - Site security build - working the physical/technical security side of the Winnersh Triangle stand-up: access control (Paxton), CCTV, structured cabling security, vendor delivery oversight (we're mid-RFP with Safeguard Systems and FTL Secure Solutions) - this is real vendor and project management, not paperwork. - Compliance-as-engineering - turning ISO 27001 and Cyber Essentials Plus requirements into actual implemented controls rather than just gap-analysis documents; supporting DSPT evidence with real technical artefacts. - Incident response & monitoring - building out our detection and response capability as it matures, being a genuine first responder rather than a policy author. - Vendor & pentest liaison - working with our security partners (e.g. Klaatu IT Security) on delivery, not just contract admin - reviewing findings and personally driving remediation. - Documentation that's useful, not performative - technical runbooks, architecture diagrams, and control evidence that the team actually uses, versus policy for policy's sake. You'll be a second pair of hands and a second brain on all of this - someone the IT Manager can hand a problem to and trust it gets solved, not just assessed. What do you need? The mindset matters more than the checklist: - You'd rather fix the thing than write a memo about the thing. - You see security as an enabler of the business (clinicians, pharmacy, patients) rather than a department of "no." - You're comfortable being hands-on in Intune, a firewall config, or a script at 4pm and in a vendor negotiation or compliance conversation at 10am
HOUSE AD991,236 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →