Security Operations Technician

Date: 22 Sept 2026

Location: Castleford, GB

Company: CMS Distribution Limited

Job Purpose Summary

The Security Operations Technician plays a key role within the Cyber Security Team, supporting the ongoing management, improvement and effectiveness of the organisation's security platforms and controls.

This position is responsible for maintaining and enhancing the organisation's security posture through the administration of our security technologies, supporting vulnerability management, endpoint security, security hardening and compliance initiatives.

The role involves analysing security data, prioritising and coordinating remediation activities, implementing security improvements, and ensuring security controls remain effective against evolving threats and business requirements.

Working closely with IT Operations Team, the Security Operations Technician  will contribute to the achievement and retention of security standards, accreditations and best practice security frameworks through the continuous improvement of security controls, configurations and operational processes.

The role will also support the development and enhancement of security platforms, helping to reduce organisational risk, strengthen cyber resilience and enable secure business growth.

Role Responsibilities

  • Monitor changes in governance, legislation and accreditation requirements, assessing impact and supporting updates to policies, procedures and controls to maintain compliance.
  • Own vulnerability management activities, including assessment, prioritisation, remediation tracking and reporting, ensuring risks are reduced and compliance requirements are maintained.
  • Manage and prioritise workloads, proactively identifying risks to contractualy and legislative obligation, taking corrective action to ensure timely resolution.
  • Create and manage change requests, ensuring changes are properly documented, reviewed, approved and implemented through the change enablement process.
  • Support problem management activities by driving resolution of underlying issues, reducing service impact and improving user experience.
  • Apply the organisation's risk management framework by identifying risks, maintaining risk records and taking ownership of remediation actions.
  • Apply, maintain and validate security hardening standards, endpoint security controls and security baselines to ensure systems remain secure and compliant.
  • Analyse security data, metrics and trends to identify vulnerabilities, hardening opportunities and operational risks, coordinating remediation activities as required.
  • Adhere to security policies, standards and operational procedures, ensuring activities remain aligned to governance and compliance requirements.
  • Identify opportunities to automate vulnerability remediation, reporting and security monitoring activities.
  • Develop and implement new security capabilities, configurations and controls to improve organisational security posture.
  • Contribute to continuous service improvement by identifying performance gaps, recommending enhancements and supporting the implementation of improvements.
  • Manage supplier relationships, ensuring contractual obligations and service level agreements are met and issues are resolved to maintain service continuity.

Additional Responsibilities

Skills & Personal Attributes

  • Experience of vulnerability management activities, including vulnerability assessment, risk prioritisation, remediation tracking and reporting.
  • Knowledge of security hardening principles, endpoint security controls and security baselines across Windows and enterprise environments.
  • Ability to analyse security data, metrics and trends to identify vulnerabilities, operational risks and opportunities for security improvement.
  • Understanding of cyber security governance, regulatory requirements and accreditation frameworks, with the ability to support compliance activities.
  • Experience using Microsoft Defender and other security tools to monitor, investigate and remediate security risks.
  • Working knowledge of change, problem and incident management processes within an IT service management environment.
  • Ability to assess, document and manage security and operational risks, taking ownership of remediation activities where required.
  • Experience working with third-party suppliers and support partners to resolve issues and maintain service continuity.
  • Strong analytical and troubleshooting skills, with the ability to identify root causes and implement effective solutions.
  • Excellent organisational skills with the ability to manage workloads, prioritise tasks and meet agreed service levels.
  • Strong written and verbal communication skills, with the ability to document findings, recommendations and remediation activities clearly.
  • Relevant cyber security, Microsoft or IT service management certifications, or equivalent demonstrable experience in a related role.

Key Traits

CMS believes that a diverse and inclusive workforce enriches and is integral to the success of our company. We value diverse opinions and perspectives, and therefore welcome candidates from all backgrounds including but not limited to, ethnicity, gender, age, nationality, culture, religious beliefs, sexual orientation and neuro-diversity.