Jobs Companies Montu UK IT Security Specialist

Sobre esta vaga de IT Security Specialist na Montu UK

Montu UK · Híbrido · Winnersh

What is the job?

Montu UK is entering an exciting new phase in its security journey: creating an independent, future-ready architecture for the UK and Europe. We’re moving beyond shared APAC infrastructure to establish our own tenants, controls and security ecosystem -built specifically for the unique demands of our rapidly growing UK and EU operations.

Australia has already developed a mature security architecture; this role is an opportunity to take that strong foundation and shape it for an entirely different regulatory and operational landscape. You’ll build security around requirements including CQC, GPhC, MHRA, Home Office controlled drugs, UK GDPR and NHS DSPT, while supporting an expanding estate that includes our Winnersh Triangle site, EU tenant separation and continued European growth.

This is not a governance-only role focused on auditing, reporting or writing policies - we already have dedicated teams owning that work. We need a hands-on security builder: someone who can design, implement and operate meaningful controls, solve complex technical challenges and strengthen our security capabilities from the inside.

You’ll work directly alongside the IT Manager as a close collaborator on both strategy and delivery, with the Support Analyst and HiLabs Ireland contact forming your wider working circle. You’ll be part of the team building and delivering the architecture -not standing outside it and checking the work.

Given the regulatory responsibility Montu carries, sound judgement and trustworthiness are essential - but so is momentum. We value practical progress over perfection: someone who can implement a strong, effective control today, learn from it and continue improving it, rather than spend months developing a flawless policy that never makes it into practice.

What will you be doing?

This is a delivery role. Representative work already in flight or on the near-term roadmap:

  • Endpoint & identity security engineering - contributing to the CrowdStrike AU→UK CID migration (Intune-deployed, scripted), Entra ID configuration for the new EU/UK tenant, and Intune/MDM policy build-out.

  • Network security delivery - hands-on work on Netskope deployment for SaaS/web steering, Tailscale ACL and zero-trust access design, and FortiGate/UniFi security configuration for the Winnersh Triangle site.

  • Site security build - working the physical/technical security side of the Winnersh Triangle stand-up: access control (Paxton), CCTV, structured cabling security, vendor delivery oversight (we're mid-RFP with Safeguard Systems and FTL Secure Solutions) - this is real vendor and project management, not paperwork.

  • Compliance-as-engineering - turning ISO 27001 and Cyber Essentials Plus requirements into actual implemented controls rather than just gap-analysis documents; supporting DSPT evidence with real technical artefacts.

  • Incident response & monitoring - building out our detection and response capability as it matures, being a genuine first responder rather than a policy author.

  • Vendor & pentest liaison - working with our security partners (e.g. Klaatu IT Security) on delivery, not just contract admin - reviewing findings and personally driving remediation.

  • Documentation that's useful, not performative - technical runbooks, architecture diagrams, and control evidence that the team actually uses, versus policy for policy's sake.

You'll be a second pair of hands and a second brain on all of this - someone the IT Manager can hand a problem to and trust it gets solved, not just assessed.

What do you need?

The mindset matters more than the checklist:

  • You'd rather fix the thing than write a memo about the thing.

  • You see security as an enabler of the business (clinicians, pharmacy, patients) rather than a department of "no."

  • You're comfortable being hands-on in Intune, a firewall config, or a script at 4pm and in a vendor negotiation or compliance conversation at 10am.

  • You work well in a very small, very autonomous team - this is not an environment with layers of process to hide behind; you'll need to be self-directed.

  • You’ll need to “muck-in” with the team if the need arises for any & all technology issues.

Technical experience (ideally several of the following):

  • Endpoint protection platforms (CrowdStrike, Sophos, or similar EDR/XDR)

  • Microsoft Entra ID / Intune, and modern zero-trust access tooling (Tailscale, Netskope, Cloudflare Zero Trust, or similar)

  • Network security fundamentals (FortiGate or similar UTM/firewall, VLAN segmentation, secure site network design)

  • ISO 27001 and/or Cyber Essentials Plus - from an implementation angle, not just an audit angle

  • Working knowledge of UK GDPR and healthcare-adjacent regulatory environments (CQC, NHS DSPT, GPhC, MHRA) - or a fast learner who can pick this up with support

  • Scripting/automation (PowerShell, Python, or similar) for security tooling and deployment

  • Comfort working with regulated, patient-data-adjacent systems

Bonus points if you have:

  • Experience in a healthcare, pharmacy, or life sciences environment

  • Experience helping a business separate from a parent company's IT estate (tenant migrations, identity separation)

  • CREST, CISSP, CISM, or equivalent - valued but not gatekept on; we care more about what you've built than the letters after your name

What this role is not:

  • Not a compliance-only or audit-only function

  • Not a "security says no" gatekeeper role

  • Not a large-team, heavily hierarchical environment - this is scrappy, fast-moving, and hands-on

  • Not someone who hands work back to the IT Manager to implement - you implement it

What we offer:

  • Generous Leave: 25 days holiday (rising to 27 after year one and 30 after year three) + usual bank holidays

  • Pension Matching: Up to 5% employer matching contributions

  • Flexibility and Wellness: Work-from-home options, cycle-to-work scheme, private healthcare and more

  • Growth Opportunities: Collaborate across teams and represent Montu at events, with support to grow your skills and impact

  • Enhanced Maternity & Paternity Leave

About Us

Montu UK is a leading digital health company specialising in cannabis-based medicines (CBPM), dedicated to improving patient access to safe and effective treatments. Our mission is to transform lives by combining innovative technology with high-quality clinical care, ensuring patients receive the support they need at every step of their journey.

As a fast-growing organisation, we offer a collaborative and supportive environment where talented people can develop their careers while contributing to meaningful change in healthcare. At Montu UK, your work has a direct impact on improving patients’ lives and expanding access to modern medical treatments.

Pronto para se candidatar à Montu UK?
Candidatar-se à Montu UK

Vagas semelhantes

Cadastre-se para receber sugestões sob medida com base nas vagas que você abre e nas buscas que você salva.

Mais vagas na Montu UK

Ver todas as vagas na Montu UK →

Candidatar-se agora
🤖

Opa — calma aí

A JobsRadar foi feita para pessoas de verdade passando por um momento difícil na busca por emprego — não para requisições automatizadas. Você está clicando rápido demais e agora está temporariamente bloqueado.

Volte mais tarde. Se você está mesmo procurando emprego, estamos com você — apenas aja como um ser humano.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Ganhe vantagem na sua busca por emprego.

Entre no nosso canal do Telegram para o que ajuda você a conseguir a vaga — referências salariais, o pulso semanal do mercado e avisos de novos recursos. Sem spam, só sinal.

Entre no canal — é grátis