SP
Managing Consultant - Cyber Security
SysGroup plc
London, England, GB
London, England, GB (On-site)2 open jobs
UK-based managed technology partner (AIM: SYS) delivering 24/7 managed IT and cloud, plus CREST-certified pen testing, XDR/SOC, compliance assurance, and ransomware-resilient data protection for 500+ enterprise customers.
SysGroup plc is a UK managed technology partner headquartered in London and listed on AIM (ticker: SYS) that spends a lot of its time on the defensive side of the house. The security work is not a bolt-on: it runs through SysGuard, which pairs continuous threat validation with CREST-certified penetration testing, XDR, and SOC services, and through SysProve, which keeps clients continuously aligned to ISO 27001, Cyber Essentials, and GDPR rather than treating compliance as an annual scramble. SysVault covers the failure case nobody wants to plan for - BaaS, DRaaS, and ransomware defence.
The threat model is practical. Assume breach, assume encrypted payloads, assume the restore path is the last line. That means the day-to-day mixes offensive testing (penetration testing, threat validation) with detection engineering and response (XDR, SOC), plus data protection and disaster recovery when the prevention layer misses. Alongside that, the managed IT estate - SysAccess runs 24/7 support and cloud management - feeds the telemetry the security functions work from. Cloud management, AI, data analytics, and automation are treated as operating disciplines, not slogans.
Scale is the context for hiring: over 20 years delivering enterprise IT services, more than 500 customers, and upwards of £1 billion in client revenue under protection. The company describes its approach as "MSP 3.0" - AI-driven and insight-led, aimed at predicting problems and preventing incidents rather than break-fix firefighting or a solution catalogue. Partner selection follows the same line: Microsoft, Zscaler, Rubrik, NetApp, CyberArk, Tenable, Mimecast.
Work spans enterprise IT, managed services, cybersecurity, and cloud services in the United Kingdom. For security practitioners that means exposure to both sides of the ledger - validating controls and building the ones that hold when validation finds the gap.