Find an apprenticeship
2027 Cloud Assurance and Cyber Security Apprentice - Crawley

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
2027 Cloud Assurance and Cyber Security Apprentice - Crawley
THALES UK LIMITED
Crawley (RH10 9HA)
Closes on: Wednesday 17 February 2027
Posted on: 5 October 2026
Summary
Do you love troubleshooting and finding a solution to complex challenges? If so, turn your curiosity into a career…. We would love to hear from you. This apprenticeship is a fantastic opportunity to learn about cloud assurance and cyber security within a leading UK tech and defence company.
Wage: £24,000 a year
Minimum wage rates: [Competitive salary of £24,000 per annum](opens in new tab)
Performance-related pay uplifts
Contributory Company Pension
Training Course
Cyber security technologist (2021) (level 4)
Hours:
- Monday - Friday: 8 hours
- Monday - Thursday: 5 hours on a Friday
- 37 hours a week
Start date: Monday 6 September 2027
Duration: 2 years
Positions available: 1
Work
Most of your apprenticeship is spent working. You’ll learn on the job by getting hands-on experience.
What you'll do at work
As a Cloud Assurance and Cyber Security Apprentice, you will gain hands-on experience and practical knowledge in cyber security, particularly focused on security operations and safeguarding cloud platforms. This role offers a unique opportunity to contribute to the security and integrity of critical systems while gaining exposure to government-level security operations.
What You Will Learn:
- Cloud Security Monitoring: Assist in monitoring and maintaining the security of the Thales adopted public cloud infrastructure (e.g., Azure, Google Cloud) in compliance with government security guidelines
- Incident Response: Support the reporting, investigation and analysis of security incidents and potential breaches within classified environments, helping to resolve issues swiftly
- Security Auditing: Help perform regular audits of cloud-based systems to ensure compliance with security protocols and government regulations
- Risk and Vulnerability Assessments: Participate in identifying vulnerabilities within cloud services, maintaining Risk reporting mechanisms and proposing mitigations to improve security posture
- Compliance & Governance: Assist in ensuring that the Thales cloud environments comply with government policies, such as GDPR, NCSC guidelines, and other relevant frameworks
- Collaboration with Development Teams: Work alongside cloud architects, developers, and engineers to ensure security is integrated into all stages of development, from design to deployment
- Training & Development: Engage in continuous learning and development, including completing certifications relevant to cloud security and government standards
Training
Apprenticeships include time away from working for specialist training. You’ll study to gain professional knowledge and skills.
Training Provider
QA LIMITED
Training Course
Cyber security technologist (2021) (level 4)
Understanding apprenticeship levels: [opens in new tab](opens in new tab)
What you'll learn:
- Discover vulnerabilities in a system by using a mix of research and practical exploration.
- Analyse and evaluate security threats and hazards to a system or service or processes.
- Use relevant external source of threat intelligence or advice (e.g. National Cyber Security Centre)
- Combine different sources to create an enriched view of cyber threats and hazards.
- Research and investigate common attack techniques and relate these to normal and observed digital system behaviour and recommend how to defend against them.
- Interpret and demonstrate use of external source of vulnerabilities (e.g. OWASP, intelligence sharing initiatives, open source).
- Undertake security risk assessments for simple systems without direct supervision and propose basic remediation advice in the context of the employer.
- Source and analyse security cases and describe what threats, vulnerability or risks are mitigated and identify any residual areas of concern.
- Analyse employer or customer requirements to derive security objectives and taking account of the threats and overall context develop a security case which sets out the proposed security measures in the context with reasoned justification.
- Identify and follow organisational policies and standards for information and cyber security and operate according to service level agreements or other defined performance targets.
- Configure, deploy and use computer, digital network and cyber security technology.
- Recommend improvements to the cyber security posture of an employer or customer based on research into future potential cyber threats and considering threat trends.
- Write program code or scripts to meet a given design requirement in accordance with employers' coding standards.
- Identify cyber security threats relevant to a defined context.
- Accurately, objectively and concisely record and report the appropriate cyber security information, including in written reports within a structure or template provided.
- Design, build, test and troubleshoot a network incorporating more than one subnet with static and dynamic routes, to a given design requirement without supervision. Provide evidence that the system meets the design requirement.
- Analyse security requirements given (functional and non-functional security requirements that may be presented in a security case) against other design requirements (e.g. usability, cost, size, weight, power, heat, supportability etc.) for a given system or product.
- Identify conflicting requirements and propose, with reasoning, resolution through appropriate trade-offs.
- Design and build, systems in accordance with a security case within broad but generally well-defined parameters. This should include selection and configuration of typical security hardware and software components. Provide evidence that the system has properly implemented the security controls required by the security case.
- Design systems employing encryption to meet defined security objectives.
- Develop and implement a plan for managing the associated encryption keys for the given scenario or system.
- Use tools, techniques and processes to actively prevent breaches to digital system security.
- Configure digital system monitoring and analysis tools (e.g. SIEM tools), taking account of threat & vulnerability intelligence, indicators of compromise.
- Conduct cyber-risk assessments against an externally (market) recognised cyber security standard using a recognised risk assessment methodology.
- Develop information security policies or processes to address a set of identified risks, for example from security audit recommendations.
- Develop information security policies within a defined scope to take account of legislation and regulation relevant to cyber security.
- Take an active part in a security audits against recognised cyber security standards, undertake gap analysis and make recommendations for remediation.
- Develop plans for local business continuity for approval within defined governance arrangements for business continuity.
- Assess security culture using a recognised approach.
- Design and implement a simple ‘security awareness’ campaign to address a specific aspect of a security culture.
- Develop plans for incident response for approval within defined governance arrangements for incident response.
- Integrate and correlate information from various sources (including log files from different sources, digital system monitoring tools, Secure Information and Event Management (SIEM) tools, access control systems, physical security systems) and compare to known threat and vulnerability data to form a judgement based on evidence with reasoning that the anomaly represents a digital system security breach.
- Recognise anomalies in observed digital system data structures (including by inspection of network packet data structures) and digital system behaviours (including by inspection of protocol behaviours) and by inspection of log files and by investigation of alerts raised by automated tools including SIEM tools.
- Undertake root cause analysis of events and make recommendations to reduce false positives and false negatives.
- Manage local response to non-major incidents in accordance with a defined procedure.
- Discover vulnerabilities in a system by using a mix of research and practical exploration.
- Analyse and evaluate security threats and hazards to a system or service or processes.
- Use relevant external source of threat intelligence or advice (e.g. National Cyber Security Centre)
- Combine different sources to create an enriched view of cyber threats and hazards.
- Research and investigate common attack techniques and relate these to normal and observed digital system behaviour and recommend how to defend against them.
- Interpret and demonstrate use of external source of vulnerabilities (e.g. OWASP, intelligence sharing initiatives, open source).
- Undertake security risk assessments for simple systems without direct supervision and propose basic remediation advice in the context of the employer.
- Source and analyse security cases and describe what threats, vulnerability or risks are mitigated and identify any residual areas of concern.
- Analyse employer or customer requirements to derive security objectives and taking account of the threats and overall context develop a security case which sets out the proposed security measures in the context with reasoned justification.
- Identify and follow organisational policies and standards for information and cyber security and operate according to service level agreements or other defined performance targets.
- Configure, deploy and use computer, digital network and cyber security technology.
- Recommend improvements to the cyber security posture of an employer or customer based on research into future potential cyber threats and considering threat trends.
- Write program code or scripts to meet a given design requirement in accordance with employers' coding standards.
- Identify cyber security threats relevant to a defined context.
- Accurately, objectively and concisely record and report the appropriate cyber security information, including in written reports within a structure or template provided.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Training Schedule


Get help with your application
Your very own career expert that helps elevate your application to the next level.
This is a 24-month programme aligned to the Level 4 Cyber Security Technologist Apprenticeship standard and delivered in partnership with a digital specialist provider. The programme is delivered via a virtual learning model consisting of live taught lectures and online learning materials.
More training information
The programme will conclude with an End Point Assessment, followed by roll-off into your permanent role within the Thales UK business.
Requirements
Essential Qualifications
- GCSE: in: 5 subjects to include English and Maths (grade 9-4 (A-C))
- A Level: in: ICT (grade C, or above)
Share if you have other relevant qualifications and industry experience. The apprenticeship can
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills