FDM is a global business and technology consultancy seeking a Security SME with Active SC to work for our client within the public sector. This is initially a 6 month contract with very good prospects to extend and will be a hybrid role that will be based in Leeds or London
We are seeking a Security SME to support a UK Government client in enhancing security monitoring and incident response capabilities within an AWS-based environment. In this position, you will play a key role in developing and refining monitoring approaches, strengthening detection and response processes, and partnering with technical teams to effectively manage security incidents in a highly secure setting. As the Security SME, you will lead the evolution of the monitoring roadmap, contribute to day-to-day security operations, and ensure that processes for alert handling, investigation, and escalation are robust and continuously optimised.
This is a hands-on role requiring close collaboration with both infrastructure and application teams within a cloud-native platform. You will provide expert input during incident containment, remediation, and recovery, while also helping to design and implement automated monitoring capabilities and recommending improvements to tooling and detection methods.
This position requires active SC-level security clearance and the ability to operate within a secure UK Government environment.
Responsibilities:
- Oversee delivery and progression of the security monitoring roadmap
- Contribute to the definition and ongoing refinement of the monitoring strategy, ensuring alignment with organisational security policies and standards
- Monitor and assess security alerts across monitoring platforms, including triage and investigation activities
- Analyse event data to identify potential incidents and ensure appropriate escalation pathways are followed
- Lead the development and implementation of automated monitoring and detection capabilities
- Evaluate, recommend, and deploy SIEM and network monitoring tools, along with associated processes and methodologies
- Promote continuous improvement through metrics, dashboards, and post-incident reviews
- Support incident response activities, including containment, remediation, recovery, and reporting
- Collaboration with infrastructure teams on activities such as: Network isolation, Revocation of IAM permissions, Security group modifications, Snapshot and backup management, Rebuilding environments using Infrastructure as Code (IaC) and Restoring systems from clean backups
- Collaboration with application teams on activities such as: Disabling impacted functionality, terminating user or system sessions, Rolling back releases or deployments, Restoring affected application components, and contribute to security operations across AWS environments and IaC-driven infrastructure