Employment OS for your Business

Cyber Security Lead

Great Torrington, SouthWest EX38, United Kingdom • Full-time
AI Job Summary
  • Practical experience in a cyber security, infrastructure, or senior IT support role with responsibility for improving OT
  • Experience securing Microsoft-based environments incl. on-prem Active Directory, Microsoft 365, Azure, and Entra ID (ten
  • Ability to work hybrid onsite in Torrington, Devon, and right to work in the UK

Role Type

Permanent • Full-time • Mid-level Senior

Pay Rate

£40,000 GBP – £45,000 GBP (Annum)

Description

About us

CMTG is a global leader in condition monitoring solutions, specialising in rotor track and balance for helicopters, condition monitoring for critical rotating industrial machinery and noise vibration analysis. With a legacy of innovation and excellence, we’re at the forefront of creating safer skies, smoother operations, and quieter environments.

From helicopters soaring above cities to industrial turbines powering the global energy industry, our cutting-edge technologies ensure optimal performance, safety, and efficiency. Our expertise expands across:

Rotor Track and Balance: Ensuring helicopters operate at peak performance by delivering solutions that reduce vibration and enhance safety.

Industrial Condition Monitoring: Helping the global energy sector keep their turbines and rotating machinery running seamlessly through advanced noise and vibration analysis.

Precision Accelerometers: Designing and manufacturing state-of-the-art accelerometers trusted worldwide for critical applications.

With a dedicated team of 130 experts across our sites in the UK, USA, France, and Germany, we bring a collaborative, international perspective to every challenge we solve. This global presence ensures our customers benefit from local support combined with a world-class standard of innovation.

                                                                                                                                           

About the Role

Are you passionate about cyber security but still enjoy being close to the technology and the people who use it? We’re looking for an experienced, hands-on Cyber Security Lead & Senior IT Support Technician to help protect our growing international Group and shape the future of cyber security at CMTG.

This is a genuinely varied role where you can make a visible impact. You’ll combine cyber security leadership with practical IT delivery, working closely with the Group IT Manager to influence our security roadmap, strengthen our controls, and build confidence in how we prevent, identify, and respond to emerging threats.

You won’t be working at arm’s length from the business. You’ll stay connected to day-to-day IT operations, support colleagues with complex technical issues, improve our infrastructure, and work alongside engineering teams to strengthen the security of CMTG products and software.

Key responsibilities include:

Cyber Security Leadership & Governance

•    Become CMTG’s trusted subject matter expert for cyber security, providing clear, practical advice across the Group.

•    Evaluate IT systems, infrastructure, software, and working practices to identify security risks, prioritise remediation, and drive continuous improvement.

•    Turn security priorities into clear policies, practical standards, meaningful risk registers, and evidence that supports confident decision-making.

•    Support the business in working towards and maintaining appropriate alignment with Cyber Essentials, NIST SP 800-171, and ISO/IEC 27001.

•    Coordinate cyber security audits, assessments, and customer assurance activities, ensuring actions are tracked through to completion.

•    Bring security risks, incidents, vulnerabilities, and improvement priorities to life through clear, useful reporting for stakeholders.

Security Operations & Resilience

•   Work with the Group IT Manager to manage and improve security controls including endpoint detection and response, SIEM, firewalls, VPNs, network segmentation, Active Directory, Microsoft Entra ID, and least-privilege access.

•    Lead and improve vulnerability management activities, including discovery, assessment, prioritisation, mitigation, remediation, and verification.

•    Monitor and respond to security alerts and incidents, coordinating investigation, containment, recovery, lessons learned, and appropriate escalation.

•   Maintain and test cyber incident response and business continuity/disaster recovery arrangements for major security events.

•    Use threat intelligence and frameworks such as MITRE ATT&CK to understand emerging threats, assess exposure, and strengthen defensive controls.

•    Build a positive security culture through engaging awareness training and proportionate phishing and vishing simulation programmes.

Infrastructure, Support & Improvement

•   Be a trusted point of escalation for colleagues, resolving complex incidents and helping people use technology confidently, effectively, and securely.

•    Support the maintenance, hardening, enhancement, and upgrade of Group IT infrastructure, cloud services, networks, devices, and management tools.

•    Administer and improve Microsoft 365, Azure, Microsoft Entra ID, and on-premises Active Directory environments.

•    Configure and maintain secure network and firewall controls, including access and NAT rules.

•    Record, prioritise, and manage incidents, problems, service requests, and system enhancement requests through to resolution.

•    Create and maintain accurate technical documentation, operating procedures, security records, and user guidance.

Product & Stakeholder Engagement

•    Partner with engineering teams as an internal cyber security consultant, influencing secure thinking throughout the product and software lifecycle.

•    Build effective relationships with colleagues, customers, suppliers, and external assessors, translating complex security issues into clear business actions.

•    Support occasional travel to other CMTG sites where required.

 

About you

You’re an experienced cyber security and IT professional who wants the freedom to influence, improve, and get things done. You combine sound security judgement with a practical, service-focused approach and enjoy turning complex technical findings into proportionate actions that genuinely help the business.

You have hands-on experience securing Microsoft-based environments, including on-premises Active Directory, Microsoft 365, Azure, and Microsoft Entra ID. You understand network security and can confidently work with enterprise firewalls, access and NAT rules, endpoint security, vulnerability scanning, identity and access management, and security monitoring tools.

 

You are familiar with recognised standards and frameworks such as Cyber Essentials, NIST SP 800-171, and ISO/IEC 27001, and can contribute to policies, risk assessments, audits, incident response, and continuous improvement. Experience using vulnerability scanning tools such as Nessus or OpenVAS is important.

Just as importantly, you enjoy working with people. You can make complex security issues feel clear and manageable, stay calm when priorities compete, and move comfortably between strategic improvement work and hands-on troubleshooting. Curious, organised, and approachable, you build credibility by listening well, following through, and finding solutions that work in practice.

Relevant professional certifications or equivalent practical experience would be welcomed. Above all, we’re looking for someone with sound judgement, current technical knowledge, and the enthusiasm to keep learning while helping CMTG become even more secure and resilient.

 

Essential experience and capabilities

•    Practical experience in a cyber security, infrastructure, or senior IT support role, with responsibility for improving organisational security.

•    Knowledge of Cyber Essentials, NIST security guidance, and ISO/IEC 27001 principles.

•    Experience with vulnerability scanning and remediation using tools such as Nessus, OpenVAS, or equivalent.

•    Experience configuring enterprise firewalls, including secure access and NAT rules.

•    Strong working knowledge of Active Directory-based networks and devices, including hardening and Group Policy deployment.

•    Good understanding of Microsoft 365, Azure, Microsoft Entra ID, identity security, and tenant hardening.

•    Strong problem-solving, communication, prioritisation, and organisational skills.

Desirable experience

•    Implementing zero-trust and least-privilege principles.

•    Writing organisational security policies and contributing to an ISMS.

•    Using Wazuh or other SIEM platforms, EDR tools, and MITRE ATT&CK for threat modelling or detection improvement.

•    Implementing application control or allow-listing using AppLocker or similar technologies.

•    Automating repeatable tasks using PowerShell, Python, or comparable scripting tools.

•    Working within engineering, manufacturing, aerospace, defence, or another regulated environment.

 

We believe in equal opportunities

We believe teamwork, no matter where you’re from or how you identify, we’re committed to building a diverse and inclusive environment where everyone can thrive.

We’re looking for hardworking, passionate individuals to join our team. When you come on board, we’ll provide the support and opportunities you need to unlock your potential and do your best work.

We’re committed to ensuring an accessible and comfortable experience for everyone. If there’s anything we can do to make your application process or working environment more accommodating, please let us know—either in your application or by reaching out directly. We’ll be more than happy to help.

If you don’t meet all the requirements but think you might still be right for the role, please apply anyway. We’re always keen to speak to people who connect with our mission and values.

Company Overview

CMTG Group Specialises in vibration and acoustic analysis, vibration condition monitoring, and the intricate science of structural and rotating machinery, our expertise spans across industries such as aviation, power generation, automotive, defence, and manufacturing.