Location: Elland Road, Leeds
Contract: Permanent
Hours of Work: 37.5 Hours Per Week
Application Deadline: 2nd September 2026
What You’ll Be Doing
We are seeking an experienced and hands-on IT Infrastructure Security Engineer to become the Club's first dedicated cybersecurity specialist.
This is an exciting opportunity to establish and develop the Club's security capability, playing a key role in protecting critical systems, data, and infrastructure while supporting major technology projects, including stadium expansion plans.
Reporting to the IT Manager, you will operate as a technical specialist responsible for building the Club's security foundations, embedding security into infrastructure projects, and developing ongoing security operations and best practice across the organisation.
Key Responsibilities:
Security Architecture & Infrastructure
Design and implement secure network architectures across club and stadium environments.
Develop and maintain network segmentation, firewall configurations, and zero-trust access controls.
Support the secure design and deployment of new infrastructure projects.
Review and validate technical security requirements across infrastructure environments.
Stadium Expansion & Technology Projects
Act as the security lead across technology workstreams relating to stadium development projects.
Review supplier and vendor security requirements.
Define security acceptance criteria and secure build standards.
Ensure cybersecurity considerations are embedded throughout project delivery.
Vulnerability & Patch Management
Establish and manage the Club's vulnerability management programme.
Conduct vulnerability assessments and coordinate remediation activities.
Manage patching processes across servers, endpoints, and infrastructure.
Monitor emerging vulnerabilities and security risks.
Identity & Access Management
Manage and develop Microsoft Entra ID and Microsoft Intune environments.
Implement and maintain Multi-Factor Authentication (MFA).
Develop Conditional Access policies and Privileged Access Management controls.
Support secure user lifecycle and access management processes.
Incident Response & Cyber Resilience
Develop, implement, and maintain the Club's Incident Response Plan.
Support Business Continuity and Disaster Recovery planning.
Participate in testing and exercising cyber response procedures.
Investigate and respond to security incidents where required.
Security Monitoring & Reporting
Implement and manage SIEM and security monitoring solutions.
Support threat detection and security investigations.
Monitor security events and recommend improvements.
Produce security reports and provide updates to IT leadership.
Data Protection & Security Governance
Support the Club's compliance with UK GDPR and data security obligations.
Work alongside the Data Protection Officer on security-related matters.
Assess and mitigate data security risks.
Contribute to security documentation, standards, and policies.
Third-Party Security & Awareness
Conduct supplier security assessments and reviews.
Ensure third-party partners meet security standards.
Deliver security awareness initiatives and phishing simulations.
Promote good cybersecurity practices throughout the organisation.
What We’re Looking For
You’ll have:
CompTIA Security+, SC-200, or an equivalent cybersecurity qualification.
Strong technical knowledge across cybersecurity and infrastructure security.
Excellent problem-solving and analytical skills.
Strong communication and stakeholder management abilities.
Ability to work independently and take ownership of security initiatives.
Strong documentation and reporting skills.
Commitment to continuous professional development.
Experience
Minimum 3 years' experience in a hands-on technical cybersecurity role.
Experience working with Microsoft 365 security technologies.
Experience administering Microsoft Intune and Microsoft Entra ID.
Experience implementing MFA, Conditional Access, and identity management controls.
Experience securing network infrastructure including VLANs, firewalls, IDS/IPS, and segmentation.
Experience using vulnerability management tools such as Nessus, Qualys, or similar.
Experience developing or contributing to incident response processes.
Experience conducting technical security assessments and risk reviews.
Experience supporting security monitoring and threat detection activities.
Knowledge & Technical Skills
Microsoft 365 Security.
Microsoft Intune.
Microsoft Entra ID.
Identity & Access Management.
Vulnerability Management.
Endpoint Security.
Network Security.
Firewall Management.
Zero Trust Security Principles.
SIEM Platforms and Security Monitoring.
UK GDPR and Data Security Requirements.
Cyber Incident Response.
Business Continuity and Disaster Recovery Planning.
Desirable
Experience within sport, entertainment, stadium, or public venue environments.
Experience implementing Microsoft Sentinel, Splunk, or similar SIEM platforms.
Knowledge of OT/IoT security in venue environments.
Experience working alongside Managed Service Providers.
CISSP, CISM, or ISO 27001 Lead Implementer certification.
Experience supporting major technology or infrastructure projects.
Experience within complex multi-site environments.
Why Should You Join Leeds United?
Whether you are on the pitch or behind the scenes here, we’re united by passion, pride, and a drive to always improve. You’ll be joining a supportive team where your voice is valued and your development matters.
In return for your dedication, you’ll receive a competitive salary package and pension scheme, along with a range of exciting benefits perks.
If you’re looking to take the next step in your career and want to be part of a club that’s as committed to its people as it is to performance, we would love to see your application.
Deadline: 2nd September 2026