Company Detail

NCC Group
Member Since,
Login to View contact details
Login

About Company

Job Openings

  • AD - Global Detection Engineering  

    - London
    The purpose of this role is to lead a global team that builds, maintai... Read More
    The purpose of this role is to lead a global team that builds, maintains and continuously improves detection logic across a variety of MXDR technologies, according to a clear strategy that is regularly updated to meet market and client demands. The global team will be made up of regionally located colleagues (UK, NL, AU & PH), that all contribute to a global set of detection logic, custom detections for clients and structural improvement projects around these themes. The head of global detection engineering will be responsible for ensuring a market leading detection coverage on the technologies we deploy as part of our MXDR services. They ensure that we detect high risk cyber attack techniques, that result in high fidelity detections at our clients, with low false positive ratios. A key part of the role is engaging and collaborating with other leaders in the GMS and NCC business, to ensure that we achieve the following key ambitions: Develop new detection logic to contribute to Detection Engineering content repository. Continuously improve existing detection logic. Write and maintain detection tests cases. Review findings of TI, CERT, and Red Team activities and evaluate from a detection engineering improvement perspective. Key Responsibilities• Lead a global implementation team that builds, maintains and continuously improves detection logic across a variety of MXDR technologies • Be part of the GMS DevSecOps leadership team and actively contribute to setting vision, direction and feature set of our technology platforms • Ensure that our detection logic is a differentiator in the market, providing extensive and high quality coverage for advanced cyber attacks • Manage senior detection engineers who each manage a number of detection engineers on a specific technology set (EDR, NDR, SIEM) • Work pro-actively with wider NCC teams to ensure all relevant inputs are available (TI, DFIR, RTO etc) to build top-notch detection logic and to ensure other teams (like solution architecture and implementations) have the required information to deploy high quality MXDR systems with the best possible coverage • Ensure that we can always provide transparency to clients about the detection coverage they receive • Ensure that we develop new ways of applying data science to our vast data sets in order to further improve detection of cyber attacks, correlation of alerts and other efficiencies and improvements that provide improved coverage to clients and improved efficiency to our SOC.Skills, Knowledge & ExpertiseExperience in detection engineering on a range of technologies (SIEM and EDR, ideally NDR as well) Experience in working in a global firm in a multi-cultural context Experience in working in a complex international environment, that’s subjected to a significant amount of change Excellent oral and written communication skills Ability to work with clients and NCC colleagues to continuously improve the service we deliver Experience with and knowledge of application of data science within a cyber security context Inspiring leader, with ability to communicate effectively at all levels, creating an approachable and supportive environment for colleagues Desirable skills:Have hands-on experience with a variety of technologies we use: Sentinel, Defender for End-point, Carbon Black, Splunk, etc Experience with purple teaming and other adjacent cyber security practices/topics that strengthen detection engineering Forensics and/or incident response experience Job BenefitsWhat do we offer in return?  We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Enhanced Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments. DepartmentCyber Services and CapabilitiesEmployment TypeFull TimeWorkplace typeHybrid Read Less
  • Senior Software Developer  

    - London
    The ServiceNow Certified Application Developer is responsible for desi... Read More
    The ServiceNow Certified Application Developer is responsible for designing, developing, and implementing custom applications and solutions within the ServiceNow platform to meet the business needs of our cybersecurity company. This role requires a blend of programming expertise and a deep understanding of the ServiceNow platform's capabilities to create efficient, scalable, and effective applications. The ServiceNow Application Developer has experience with the latest web technologies, and a creative mindset for solving complex problems.Key ResponsibilitiesKey accountabilities: Application Development: Design and develop custom applications within ServiceNow to automate business processes and resolve complex operational challenges. Requirements Gathering: Collaborate with stakeholders across the organization to understand their needs and translate them into technical solutions within ServiceNow. Customization and Integration: Customize existing ServiceNow applications and integrate with external systems and APIs to enhance functionality and user experience. Quality Assurance: Conduct thorough testing of developed applications and solutions. Ensure compliance with coding standards and best practices. Documentation and Support: Create comprehensive documentation for developed applications and provide ongoing support and enhancements based on user feedback. Collaboration: Work closely with the ServiceNow System Administrator and other IT team members to ensure seamless implementation and operation of ServiceNow applications. Skills, Knowledge & ExpertiseMinimum RequirementsCertification as a ServiceNow Application Developer Expert knowledge of ServiceNow platform development capabilities Strong knowledge of JavaScript and the AngularJS framework Strong knowledge of ServiceNow Client & Server API’s General programming skills and understanding of secure software development lifecycle (SSDLC) Excellent communication and teamwork abilities Ability to manage multiple projects simultaneously and meet deadlines Creative thinking and problem-solving skills  Desirable RequirementsBachelor’s degree in computer science, information systems, or related field At least 5 years of experience with ServiceNow development. Other relevant certifications. Job BenefitsFlexible Working: Balance your work and personal life with our flexible working options.Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.Medicash & Critical Illness SchemeFinancial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.Green Car Scheme: Drive green and save money with our eco-friendly car scheme.Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.DepartmentCyber Services and CapabilitiesEmployment TypeFull TimeWorkplace typeHybrid Read Less
  • Senior Python Developer  

    - London
    An exciting opportunity to be one of the core team members of the Soft... Read More
    An exciting opportunity to be one of the core team members of the Software Engineering team within NCC Group’s GMS division. You will be a development SME playing a key role in designing, delivering, and supporting high‑quality software solutions.  This is a great opportunity to work on mission critical Cyber Security-related products and services, for one of the world’s leading practices.  The role requires strong hands‑on expertise in Python along with a broad and deep understanding of modern coding practices, multiple programming languages, and software delivery standards spanning across a number of new and existing project streams; working alongside a wider global team to efficiently develop cloud solutions following CICD best practices. We are looking for a highly skilled and experienced Senior Python Developer to join our dynamic team. The ideal candidate will be responsible for designing, developing, and maintaining scalable and efficient software systems using Python, cloud and serverless technologies. This role requires a deep understanding of Python and related technologies, as well as strong leadership and mentoring abilities. You will be a senior member of the development team with the ability to contribute as well as guide other members of the team towards the development of high-quality software with the help of the Product Engineering / Architecture Lead Work closely with other Developers, UX, QA, DevOps and Cloud Architecture  Development of high-quality code following development practices set by the Product Engineering / Architecture Lead  Mentoring of more junior members of the team Perform regular code reviews Implement a test first approach and contribute to upholding code quality metrics Key ResponsibilitiesDesign and Development: Create and implement Python-based applications and systems, ensuring functionality and performance. Leadership & Mentorship: Guide and mentor junior developers, providing technical expertise and ensuring adherence to best practices. Collaboration: Work collaboratively with cross-functional teams to define project requirements and specifications, ensuring software meets business objectives. Code Quality Assurance: Conduct code reviews to ensure quality, suggest improvements, and maintain best practices. Troubleshooting and Debugging:Identify and resolve code bugs, ensuring smooth operation of software. Staying Informed: Keep up-to-date with the latest trends and standards in Python development. Performance Optimisation:Optimize and test software to ensure functionality and smooth operation. Documentation: Prepare and maintain technical documentation to ensure transparency and accessibility for the team. Skills, Knowledge & ExpertiseBehaviours:Focusing on Clients and Customers.  Working as One NCC. Always Learning. Being Inclusive and Respectful.  Delivery Brilliantly.  Qualifications:Bachelor’s or Master’s degree in Computer Science, Engineering, or a related field. Proven experience as a Python Developer. Familiarity with creating code in serverless environments Familiarity with Azure Architecture and REST APIs. Understanding of databases and SQL. Secure Software Development. Attention to detail and strong problem-solving abilities. Excellent communication and leadership skills. Desired Skills:Full stack python development Expert Experience with cloud architectures and infrastructure. Agile Development  Experience working with CI/CD practices  Test first approach  Microservice infrastructure Knowledge of software development best practices and standards. Strong analytical and problem-solving abilities. Job BenefitsFlexible Working: Balance your work and personal life with our flexible working options.Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.Medicash & Critical Illness SchemeFinancial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.Green Car Scheme: Drive green and save money with our eco-friendly car scheme.Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.DepartmentCyber Services and CapabilitiesEmployment TypeFull TimeWorkplace typeHybrid Read Less
  • Lead Security Researcher  

    - London
    A Lead Security Researcher within the Exploit Development Group (EDG)... Read More
    A Lead Security Researcher within the Exploit Development Group (EDG) is responsible for conducting high‑impact vulnerability research and exploit development that advances the state of the art in cybersecurity. The role contributes directly to NCC Group’s reputation as a global authority in security research by delivering original research with deep technical expertise and representing the organisation externally through publications, presentations, and industry engagement. Through both long‑term strategic research and short‑notice tactical support, this role helps protect clients, strengthen NCC Group services and shape the wider security community.Key ResponsibilitiesConduct vulnerability research and exploit development across a range of platforms, architectures, and technologies. Deliver high‑quality vulnerabilities and reliable exploits as part of strategic research programmes. Provide short‑notice tactical support to consulting, professional, and managed services teams in areas such as reverse engineering and exploit development. Advance exploit development techniques and contribute to world‑leading security research. Participate in vulnerability research and exploit development competitions, such as Pwn2Own. Publish research findings and support their internal and external promotion through articles, whitepapers, presentations, and conference talks. Act as a subject matter expert within NCC Group, mentoring and supporting colleagues who are developing skills in vulnerability research and exploitation. Collaborate effectively with multi‑disciplinary teams to deliver research and client outcomes to the highest possible standard. Skills, Knowledge and ExpertiseStrong knowledge of vulnerability research and exploitation techniques. Experience with major CPU architectures and operating systems or platforms. Ability to reverse engineer software written in both unmanaged and managed languages. Understanding of common programming languages, vulnerability classes and exploitation methods. Knowledge of modern exploitation mitigations and approaches for bypassing them. Ability to research and exploit unfamiliar instruction sets, programming languages and platforms. Clear written communication skills for documenting and presenting complex technical findings. BenefitsFlexible Working: Balance your work and personal life with our flexible working options.Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.Medicash & Critical Illness SchemeFinancial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.Green Car Scheme: Drive green and save money with our eco-friendly car scheme.Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.DepartmentCyber Services and CapabilitiesEmployment TypeFull TimeWorkplace typeHybrid Read Less
  • Transport - Managing Security Consultant  

    - Greater London
    We are seeking a highly skilled Automotive Cyber Security Lead to join... Read More
    We are seeking a highly skilled Automotive Cyber Security Lead to join our Global Transport practice. This role is pivotal in strengthening and expanding our cyber security capability within the global automotive ecosystem, while also supporting cross-domain engagements in rail, maritime, and aviation as needed.The ideal candidate will bring deep knowledge of automotive cyber security, connected and software-defined vehicle technologies, operational technology (OT), embedded systems, relevant international cyber security standards and regulations (including ISO/SAE 21434, UNECE R155, UNECE R156, and ISO 26262), penetration testing methodologies, and the broader transport ecosystem. In addition to technical delivery, the individual will play a key role in supporting business development, building client trust, and elevating NCC Group's profile within the automotive sector.This is a fully remote, client-facing role requiring strong collaboration, communication, and consulting skills.Key ResponsibilitiesTechnical Delivery & Automotive Cyber Security ExpertiseAct as a subject matter expert (SME) for automotive cyber security across global engagements.Lead and deliver complex cyber security assessments across vehicle, engineering, manufacturing, operational technology (OT), and information technology (IT) environments.Apply deep knowledge of automotive-specific standards and frameworks, including: ISO/SAE 21434 (Road Vehicle Cybersecurity Engineering)UNECE R155 (Cyber Security Management System)UNECE R156 (Software Update Management System)ISO 26262 (Functional Safety)Conduct or support penetration testing, vulnerability assessments, architecture reviews, risk assessments, and Threat Analysis and Risk Assessments (TARA) for automotive clients.Provide expert interpretation of cyber security requirements for vehicle manufacturers, suppliers, technology providers, and mobility operators.Ensure security recommendations are aligned with safety, regulatory, operational, and business requirements throughout the vehicle lifecycle.Automotive Domain ExpertiseProvide expert understanding of the automotive ecosystem, including: Connected vehiclesSoftware-defined vehicles (SDVs)Electronic Control Units (ECUs)In-vehicle networks (CAN, LIN, FlexRay, Automotive Ethernet)Telematics and connected servicesElectric vehicle charging infrastructureManufacturing and production environmentsVehicle development, validation, and homologation processesTranslate complex automotive engineering and operational knowledge into training and knowledge-sharing activities for internal teams.Contribute to the development of internal automotive cyber security capabilities, methodologies, and best practices.Maintain awareness of emerging threats, vulnerabilities, regulations, and industry trends affecting the automotive sector.Business Development & Practice GrowthSupport the identification, creation, and growth of automotive cyber security opportunities globally.Help strengthen NCC Group's presence within the automotive sector through: Thought leadership activities, including white papers, webinars, and industry eventsClient engagements and pre-sales supportCollaboration with OEMs, Tier 1 suppliers, mobility providers, and industry bodiesCollaborate with engagement managers and practice leadership to support the development of automotive-focused service offerings.Contribute to bids, proposals, statements of work, and technical scoping activities for prospective customers.Cross-Domain Support (Multi-Modal Transport)Support projects across rail, maritime, and aviation domains where automotive cyber security expertise can add value.Maintain awareness of common OT, embedded, and safety-critical technologies across transport sectors.Promote knowledge sharing and collaboration across the wider Transport Cyber Security practice.Client Engagement & Delivery ExcellenceAct as a trusted advisor to clients, providing clear and actionable cyber security recommendations.Communicate complex technical concepts in a professional and client-friendly manner.Deliver high-quality outputs and maintain strong client satisfaction throughout engagements.Build and maintain positive working relationships with clients and key stakeholders.Skills, Knowledge and ExpertiseTechnical ExperienceProven experience in automotive cyber security, ideally within OEMs, Tier 1 suppliers, mobility providers, automotive technology companies, or a cyber security consultancy.Strong experience working with and applying: ISO/SAE 21434UNECE R155UNECE R156ISO 26262Strong understanding of embedded systems, vehicle electronics, automotive communications networks, connected vehicle platforms, and safety-critical environments.Practical experience conducting or supporting penetration testing and security assessment activities.Experience performing secure architecture reviews, threat modelling, TARA activities, and risk assessments within automotive or transportation environments.Familiarity with automotive development lifecycles, software delivery processes, and regulatory compliance requirements.Domain KnowledgeIn-depth understanding of the automotive ecosystem, including vehicle architectures, connected vehicle platforms, software-defined vehicles, manufacturing environments, supplier ecosystems, and automotive cyber security regulations.Direct experience working within or alongside automotive OEMs, Tier 1 suppliers, mobility service providers, or automotive cyber security programmes.Understanding of vehicle engineering, safety, validation, and homologation processes.Soft Skills & Professional AttributesExcellent communication skills in both technical and non-technical contexts.Strong client-facing and stakeholder management skills.Ability to lead workstreams and influence stakeholders at all levels.Ability to work collaboratively across geographies, teams, and disciplines.Strong consulting mindset with the ability to understand client challenges and provide pragmatic solutions.A passion for coaching, mentoring, and knowledge sharing.Desirable (Not Mandatory)Recognised cyber security certifications such as CISSP, GICSP, ISA/IEC 62443 Cyber Security Expert, OSCP, or GIAC certifications.Automotive cyber security certifications or formal training relating to ISO/SAE 21434, UNECE R155/R156, or automotive engineering disciplines.Experience contributing to industry standards, working groups, or regulatory consultations.Background in automotive engineering, systems engineering, functional safety, or vehicle development.Knowledge of EV ecosystems, charging infrastructure security, and software-defined vehicle architectures.BenefitsWhat do we offer in return? We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments. DepartmentCyber Services and CapabilitiesEmployment TypeFull TimeWorkplace typeHybrid Read Less
  • Transport - Managing Security Consultant  

    - Greater London
    We are seeking a highly skilled Automotive Cyber Security Lead to join... Read More
    We are seeking a highly skilled Automotive Cyber Security Lead to join our Global Transport practice. This role is pivotal in strengthening and expanding our cyber security capability within the global automotive ecosystem, while also supporting cross-domain engagements in rail, maritime, and aviation as needed.The ideal candidate will bring deep knowledge of automotive cyber security, connected and software-defined vehicle technologies, operational technology (OT), embedded systems, relevant international cyber security standards and regulations (including ISO/SAE 21434, UNECE R155, UNECE R156, and ISO 26262), penetration testing methodologies, and the broader transport ecosystem. In addition to technical delivery, the individual will play a key role in supporting business development, building client trust, and elevating NCC Group's profile within the automotive sector.This is a fully remote, client-facing role requiring strong collaboration, communication, and consulting skills.Key ResponsibilitiesTechnical Delivery & Automotive Cyber Security ExpertiseAct as a subject matter expert (SME) for automotive cyber security across global engagements.Lead and deliver complex cyber security assessments across vehicle, engineering, manufacturing, operational technology (OT), and information technology (IT) environments.Apply deep knowledge of automotive-specific standards and frameworks, including: ISO/SAE 21434 (Road Vehicle Cybersecurity Engineering)UNECE R155 (Cyber Security Management System)UNECE R156 (Software Update Management System)ISO 26262 (Functional Safety)Conduct or support penetration testing, vulnerability assessments, architecture reviews, risk assessments, and Threat Analysis and Risk Assessments (TARA) for automotive clients.Provide expert interpretation of cyber security requirements for vehicle manufacturers, suppliers, technology providers, and mobility operators.Ensure security recommendations are aligned with safety, regulatory, operational, and business requirements throughout the vehicle lifecycle.Automotive Domain ExpertiseProvide expert understanding of the automotive ecosystem, including: Connected vehiclesSoftware-defined vehicles (SDVs)Electronic Control Units (ECUs)In-vehicle networks (CAN, LIN, FlexRay, Automotive Ethernet)Telematics and connected servicesElectric vehicle charging infrastructureManufacturing and production environmentsVehicle development, validation, and homologation processesTranslate complex automotive engineering and operational knowledge into training and knowledge-sharing activities for internal teams.Contribute to the development of internal automotive cyber security capabilities, methodologies, and best practices.Maintain awareness of emerging threats, vulnerabilities, regulations, and industry trends affecting the automotive sector.Business Development & Practice GrowthSupport the identification, creation, and growth of automotive cyber security opportunities globally.Help strengthen NCC Group's presence within the automotive sector through: Thought leadership activities, including white papers, webinars, and industry eventsClient engagements and pre-sales supportCollaboration with OEMs, Tier 1 suppliers, mobility providers, and industry bodiesCollaborate with engagement managers and practice leadership to support the development of automotive-focused service offerings.Contribute to bids, proposals, statements of work, and technical scoping activities for prospective customers.Cross-Domain Support (Multi-Modal Transport)Support projects across rail, maritime, and aviation domains where automotive cyber security expertise can add value.Maintain awareness of common OT, embedded, and safety-critical technologies across transport sectors.Promote knowledge sharing and collaboration across the wider Transport Cyber Security practice.Client Engagement & Delivery ExcellenceAct as a trusted advisor to clients, providing clear and actionable cyber security recommendations.Communicate complex technical concepts in a professional and client-friendly manner.Deliver high-quality outputs and maintain strong client satisfaction throughout engagements.Build and maintain positive working relationships with clients and key stakeholders.Skills, Knowledge and ExpertiseTechnical ExperienceProven experience in automotive cyber security, ideally within OEMs, Tier 1 suppliers, mobility providers, automotive technology companies, or a cyber security consultancy.Strong experience working with and applying: ISO/SAE 21434UNECE R155UNECE R156ISO 26262Strong understanding of embedded systems, vehicle electronics, automotive communications networks, connected vehicle platforms, and safety-critical environments.Practical experience conducting or supporting penetration testing and security assessment activities.Experience performing secure architecture reviews, threat modelling, TARA activities, and risk assessments within automotive or transportation environments.Familiarity with automotive development lifecycles, software delivery processes, and regulatory compliance requirements.Domain KnowledgeIn-depth understanding of the automotive ecosystem, including vehicle architectures, connected vehicle platforms, software-defined vehicles, manufacturing environments, supplier ecosystems, and automotive cyber security regulations.Direct experience working within or alongside automotive OEMs, Tier 1 suppliers, mobility service providers, or automotive cyber security programmes.Understanding of vehicle engineering, safety, validation, and homologation processes.Soft Skills & Professional AttributesExcellent communication skills in both technical and non-technical contexts.Strong client-facing and stakeholder management skills.Ability to lead workstreams and influence stakeholders at all levels.Ability to work collaboratively across geographies, teams, and disciplines.Strong consulting mindset with the ability to understand client challenges and provide pragmatic solutions.A passion for coaching, mentoring, and knowledge sharing.Desirable (Not Mandatory)Recognised cyber security certifications such as CISSP, GICSP, ISA/IEC 62443 Cyber Security Expert, OSCP, or GIAC certifications.Automotive cyber security certifications or formal training relating to ISO/SAE 21434, UNECE R155/R156, or automotive engineering disciplines.Experience contributing to industry standards, working groups, or regulatory consultations.Background in automotive engineering, systems engineering, functional safety, or vehicle development.Knowledge of EV ecosystems, charging infrastructure security, and software-defined vehicle architectures.BenefitsWhat do we offer in return? We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments. DepartmentCyber Services and CapabilitiesEmployment TypeFull TimeWorkplace typeHybrid Read Less
  • Lead Security Researcher  

    - Greater London
    A Lead Security Researcher within the Exploit Development Group (EDG)... Read More
    A Lead Security Researcher within the Exploit Development Group (EDG) is responsible for conducting high‑impact vulnerability research and exploit development that advances the state of the art in cybersecurity. The role contributes directly to NCC Group’s reputation as a global authority in security research by delivering original research with deep technical expertise and representing the organisation externally through publications, presentations, and industry engagement. Through both long‑term strategic research and short‑notice tactical support, this role helps protect clients, strengthen NCC Group services and shape the wider security community.Key ResponsibilitiesConduct vulnerability research and exploit development across a range of platforms, architectures, and technologies. Deliver high‑quality vulnerabilities and reliable exploits as part of strategic research programmes. Provide short‑notice tactical support to consulting, professional, and managed services teams in areas such as reverse engineering and exploit development. Advance exploit development techniques and contribute to world‑leading security research. Participate in vulnerability research and exploit development competitions, such as Pwn2Own. Publish research findings and support their internal and external promotion through articles, whitepapers, presentations, and conference talks. Act as a subject matter expert within NCC Group, mentoring and supporting colleagues who are developing skills in vulnerability research and exploitation. Collaborate effectively with multi‑disciplinary teams to deliver research and client outcomes to the highest possible standard. Skills, Knowledge and ExpertiseStrong knowledge of vulnerability research and exploitation techniques. Experience with major CPU architectures and operating systems or platforms. Ability to reverse engineer software written in both unmanaged and managed languages. Understanding of common programming languages, vulnerability classes and exploitation methods. Knowledge of modern exploitation mitigations and approaches for bypassing them. Ability to research and exploit unfamiliar instruction sets, programming languages and platforms. Clear written communication skills for documenting and presenting complex technical findings. BenefitsFlexible Working: Balance your work and personal life with our flexible working options.Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.Medicash & Critical Illness SchemeFinancial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.Green Car Scheme: Drive green and save money with our eco-friendly car scheme.Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.DepartmentCyber Services and CapabilitiesEmployment TypeFull TimeWorkplace typeHybrid Read Less
  • Lead Security Researcher  

    - Greater London
    A Lead Security Researcher within the Exploit Development Group (EDG)... Read More
    A Lead Security Researcher within the Exploit Development Group (EDG) is responsible for conducting high‑impact vulnerability research and exploit development that advances the state of the art in cybersecurity. The role contributes directly to NCC Group’s reputation as a global authority in security research by delivering original research with deep technical expertise and representing the organisation externally through publications, presentations, and industry engagement. Through both long‑term strategic research and short‑notice tactical support, this role helps protect clients, strengthen NCC Group services and shape the wider security community.Key ResponsibilitiesConduct vulnerability research and exploit development across a range of platforms, architectures, and technologies. Deliver high‑quality vulnerabilities and reliable exploits as part of strategic research programmes. Provide short‑notice tactical support to consulting, professional, and managed services teams in areas such as reverse engineering and exploit development. Advance exploit development techniques and contribute to world‑leading security research. Participate in vulnerability research and exploit development competitions, such as Pwn2Own. Publish research findings and support their internal and external promotion through articles, whitepapers, presentations, and conference talks. Act as a subject matter expert within NCC Group, mentoring and supporting colleagues who are developing skills in vulnerability research and exploitation. Collaborate effectively with multi‑disciplinary teams to deliver research and client outcomes to the highest possible standard. Skills, Knowledge and ExpertiseStrong knowledge of vulnerability research and exploitation techniques. Experience with major CPU architectures and operating systems or platforms. Ability to reverse engineer software written in both unmanaged and managed languages. Understanding of common programming languages, vulnerability classes and exploitation methods. Knowledge of modern exploitation mitigations and approaches for bypassing them. Ability to research and exploit unfamiliar instruction sets, programming languages and platforms. Clear written communication skills for documenting and presenting complex technical findings. BenefitsFlexible Working: Balance your work and personal life with our flexible working options.Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.Medicash & Critical Illness SchemeFinancial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.Green Car Scheme: Drive green and save money with our eco-friendly car scheme.Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.DepartmentCyber Services and CapabilitiesEmployment TypeFull TimeWorkplace typeHybrid Read Less
  • Technical Account Manager  

    - Greater London
    The TAM is the customer's technical owner for the service and the expe... Read More
    The TAM is the customer's technical owner for the service and the expert voice in the relationship. They quantify the customer's security maturity through the TAM Score framework, build and steer a defensible 12-month technical roadmap, and provide the depth of Microsoft Azure Sentinel/Defender XDR expertise needed to advise credibly on priorities. TAMs translate data into narrative - interpreting scores, surfacing the highest-leverage gaps, and guiding customers toward measurable improvement quarter by quarter. They act as a technical buffer between customers and internal operational teams by resolving technical queries, advising on improvements, and ensuring issues are properly packaged when escalation is required.Key ResponsibilitiesOwn the technical relationship: understand the customer environment end-to-end, maintain technical context, and operate as the trusted advisor in the partnership.Own the TAM Score narrative: interpret Environment, SOC, and Health scores into a credible story about where the customer stands and where to focus next - accountable for the quality of the diagnosis and recommendations, not the absolute score.Build and maintain the 12-month technical roadmap: anchored to the TAM Score, with defined quarterly focus areas tied to the highest-leverage gaps.Deliver the TAM/technical portion of Quarterly Business Reviews: present the score, narrate progress, and align with customer stakeholders up to CISO/senior IT leadership.Deliver reactive technical support via tickets (troubleshooting, investigation support, remediation guidance).Deliver proactive technical expertise and drive continuous improvement (Tier A included): posture and coverage advisory, tuning/noise reduction, cost/retention optimisation, automation uplift.Own technical deliverables: automation/playbooks where in scope, custom analytics and workbooks.Drive the operational health-check catalogue as scheduled workstreams within the roadmap.Advise on Defensive Breadth gaps (pentest cadence, IR retainer, EASM, DLP, tabletops, etc) - surfacing risk credibly and identifying where NCC services can close the gap.Maintain and refresh the threat overview as the customer's environment and threat landscape evolve.Key RequirementsProven experience in cybersecurity, IT operations, or managed security services (3–7+ years)Background in a customer-facing technical role (e.g. TAM, Security Consultant)Experience engaging senior stakeholders (CISO, Head of IT/Security)Strong understanding of SOC operations, threat detection, and incident responseAbility to understand end-to-end customer environments (cloud, infrastructure, security stack)Experience with security tools (e.g. SIEM, EDR, SOAR, DLP, vulnerability management)Able to interpret and translate security metrics into clear risk-based narrativesProven ability to build and maintain 12-month technical roadmaps with quarterly focusStrong skills in data analysis, prioritisation, and identifying high-impact improvementsExperience delivering Quarterly Business Reviews (QBRs) to senior audiencesAbility to act as a trusted advisor, owning the technical customer relationshipExperience balancing reactive support (tickets, troubleshooting) and proactive improvementCapability to deliver continuous improvement initiatives (tuning, optimisation, automation)Experience creating technical deliverables (playbooks, dashboards, analytics, reports)Knowledge of defensive security domains (pentest, IR, EASM, DLP, tabletop exercises)Ability to identify security gaps and align solutions/services to mitigate riskStrong communication and storytelling skills, adapting for technical and non-technical audiencesFamiliarity with service management practices (e.g. ITIL, ticketing systems)Relevant certifications (e.g. CISSP, CISM, Security+, cloud security) – desirableProactive, accountable, and customer-focused mindset with strong ownershipJob BenefitsFlexible Working: Balance your work and personal life with our flexible working options.Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.Medicash & Critical Illness SchemeFinancial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.Green Car Scheme: Drive green and save money with our eco-friendly car scheme.Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.DepartmentCyber Services and CapabilitiesEmployment TypeFull TimeWorkplace typeHybrid Read Less
  • Developer  

    - Greater London
    NCC’s Threat Intelligence engineering team is looking for a Developer... Read More
    NCC’s Threat Intelligence engineering team is looking for a Developer to support analysts and engineers in delivering a world-class cyber threat intelligence capability. This role will do so by building, deploying, securing, monitoring, and maintaining application extensions, automations, and auxiliary tooling for our primary Threat Intelligence platforms. Key ResponsibilitiesBuilding, deploying, securing, monitoring, and maintaining our existing Python application extensions and CLI tooling Connecting diverse backend systems together to break down siloed data repositories Plugging the technical gap between our developers, engineers, and analysts by providing automations and tooling Support engineers, developers, and analysts by providing robust support for automatable processes Identifying automation opportunities within the department Skills, Knowledge & ExpertiseEssential Capabilities and UnderstandingProficiency in Python and Bash, particularly in connecting backend systems and building CLI tooling Cloud networking and computing concepts, particularly in AWS Working in a DevOps team Containerisation technologies, including Docker and Kubernetes Security principals involved when working with cloud computing technologies Concise explanations of complex technical topics to other members of a DevOps team Problem solving and creative thinking to build new solutions from the ground-up Preferable Capabilities and UnderstandingBackend system development Data management and transformation Threat Intelligence tooling and platforms, such as OpenCTI or MISP Familiarity with STIX2/TAXII2 standards Working on open-source software Any additional programming/scripting/development experience Job BenefitsFlexible Working: Balance your work and personal life with our flexible working options.Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.Medicash & Critical Illness SchemeFinancial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.Green Car Scheme: Drive green and save money with our eco-friendly car scheme.Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.DepartmentCyber Services and CapabilitiesEmployment TypeFull TimeWorkplace typeHybrid Read Less

Company Detail

  • Is Email Verified
    No
  • Total Employees
  • Established In
  • Current jobs

Google Map

For Jobseekers
For Employers
Contact Us
Astrid-Lindgren-Weg 12 38229 Salzgitter Germany