At a Glance
- Tasks: Design and implement security controls for a fast-growing digital health company.
- Company: Montu UK, a leader in cannabis-based medicines and digital health.
- Benefits: Generous leave, pension matching, flexible work options, and growth opportunities.
- Other info: Join a small, autonomous team focused on practical progress and meaningful change.
- Why this job: Make a real impact on healthcare while shaping security architecture in a dynamic environment.
- Qualifications: Hands-on experience in IT security, compliance knowledge, and problem-solving skills.
The predicted salary is between 55000 - 65000 £ per year.
Montu UK is entering an exciting new phase in its security journey: creating an independent, future-ready architecture for the UK and Europe. We're moving beyond shared APAC infrastructure to establish our own tenants, controls and security ecosystem built specifically for the unique demands of our rapidly growing UK and EU operations. Australia has already developed a mature security architecture; this role is an opportunity to take that strong foundation and shape it for an entirely different regulatory and operational landscape.
You'll build security around requirements including CQC, GPhC, MHRA, Home Office controlled drugs, UK GDPR and NHS DSPT, while supporting an expanding estate that includes our Winnersh Triangle site, EU tenant separation and continued European growth. This is not a governance-only role focused on auditing, reporting or writing policies - we already have dedicated teams owning that work. We need a hands-on security builder: someone who can design, implement and operate meaningful controls, solve complex technical challenges and strengthen our security capabilities from the inside.
You'll work directly alongside the IT Manager as a close collaborator on both strategy and delivery, with the Support Analyst and HiLabs Ireland contact forming your wider working circle. You'll be part of the team building and delivering the architecture - not standing outside it and checking the work. Given the regulatory responsibility Montu carries, sound judgement and trustworthiness are essential - but so is momentum. We value practical progress over perfection: someone who can implement a strong, effective control today, learn from it and continue improving it, rather than spend months developing a flawless policy that never makes it into practice.
This is a delivery role. Representative work already in flight or on the near-term roadmap:
- Endpoint & identity security engineering - contributing to the CrowdStrike AU→UK CID migration (Intune-deployed, scripted), Entra ID configuration for the new EU/UK tenant, and Intune/MDM policy build-out.
- Network security delivery - hands-on work on Netskope deployment for SaaS/web steering, Tailscale ACL and zero-trust access design, and FortiGate/UniFi security configuration for the Winnersh Triangle site.
- Site security build - working the physical/technical security side of the Winnersh Triangle stand-up: access control (Paxton), CCTV, structured cabling security, vendor delivery oversight.
- Compliance-as-engineering - turning ISO 27001 and Cyber Essentials Plus requirements into actual implemented controls rather than just gap-analysis documents; supporting DSPT evidence with real technical artefacts.
- Incident response & monitoring - building out our detection and response capability as it matures, being a genuine first responder rather than a policy author.
- Vendor & pentest liaison - working with our security partners on delivery, not just contract admin - reviewing findings and personally driving remediation.
- Documentation that's useful, not performative - technical runbooks, architecture diagrams, and control evidence that the team actually uses.
You'll be a second pair of hands and a second brain on all of this - someone the IT Manager can hand a problem to and trust it gets solved, not just assessed.
You'd rather fix the thing than write a memo about the thing. You see security as an enabler of the business rather than a department of 'no.' You're comfortable being hands-on in Intune, a firewall config, or a script at 4pm and in a vendor negotiation or compliance conversation at 10am. You work well in a very small, very autonomous team - this is not an environment with layers of process to hide behind; you'll need to be self-directed. You’ll need to 'muck-in' with the team if the need arises for any & all technology issues.
Technical experience (ideally several of the following):
- Endpoint protection platforms (CrowdStrike, Sophos, or similar EDR/XDR)
- Microsoft Entra ID / Intune, and modern zero-trust access tooling (Tailscale, Netskope, Cloudflare Zero Trust, or similar)
- Network security fundamentals (FortiGate or similar UTM/firewall, VLAN segmentation, secure site network design)
- ISO 27001 and/or Cyber Essentials Plus - from an implementation angle, not just an audit angle
- Working knowledge of UK GDPR and healthcare-adjacent regulatory environments (CQC, NHS DSPT, GPhC, MHRA) - or a fast learner who can pick this up with support
- Scripting/automation (PowerShell, Python, or similar) for security tooling and deployment
- Comfort working with regulated, patient-data-adjacent systems
Bonus points if you have:
- Experience in a healthcare, pharmacy, or life sciences environment
- Experience helping a business separate from a parent company's IT estate (tenant migrations, identity separation)
- CREST, CISSP, CISM, or equivalent - valued but not gatekept on; we care more about what you've built than the letters after your name
What this role is not:
- Not a compliance-only or audit-only function
- Not a 'security says no' gatekeeper role
- Not a large-team, heavily hierarchical environment - this is scrappy, fast-moving, and hands-on
- Not someone who hands work back to the IT Manager to implement - you implement it
What we offer:
- Generous Leave: 25 days holiday (rising to 27 after year one and 30 after year three) + usual bank holidays
- Pension Matching: Up to 5% employer matching contributions
- Flexibility and Wellness: Work-from-home options, cycle-to-work scheme, private healthcare and more
- Growth Opportunities: Collaborate across teams and represent Montu at events, with support to grow your skills and impact
- Enhanced Maternity & Paternity Leave
Montu UK is a leading digital health company specializing in cannabis-based medicines (CBPM), dedicated to improving patient access to safe and effective treatments. Our mission is to transform lives by combining innovative technology with high-quality clinical care, ensuring patients receive the support they need at every step of their journey. As a fast-growing organisation, we offer a collaborative and supportive environment where talented people can develop their careers while contributing to meaningful change in healthcare. At Montu UK, your work has a direct impact on improving patients' lives and expanding access to modern medical treatments.
IT Security Specialist in Winnersh employer: Montu UK
Montu UK in Bristol is an exceptional employer, offering a unique opportunity for Clinical Pharmacists to make a significant impact in patient care through cannabis-based medicines. With a supportive work culture that values autonomy and flexibility, employees benefit from a comprehensive package that includes generous leave and ample opportunities for professional development, making it an ideal place for those seeking meaningful and rewarding employment.
StudySmarter Expert Advice🤫
We think this is how you could land IT Security Specialist in Winnersh
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Montu UK, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Montu UK
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Montu UK. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace IT Security Specialist in Winnersh
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Montu UK insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Montu UK that you’re committed to staying ahead in the game.
How to prepare for a job interview at Montu UK
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Montu UK to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Montu UK.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.