Kainos

Lead Security Engineer

Kainos
Apply
14 days ago
Remote, United Kingdom or Birmingham, United KingdomStaff+

Responsibilities

  • Lead security engineering and security testing across Kainos platforms and services.
  • Set direction for security testing methodology, engagement scoping, outputs, and tool and technology selection.
  • Perform and document manual or automated penetration tests on web applications, networks, and computer systems.
  • Assess software and infrastructure source code from a security perspective.
  • Develop secure practices with agile delivery teams throughout the software development lifecycle.
  • Lead threat modeling exercises and workshops and articulate security threats and risks.
  • Educate customers, colleagues, and the wider community on security practices.
  • Manage, mentor, coach, and develop a small number of staff, including supporting performance and career development.
  • Stay current with new threats and attack types.

Requirements

  • Expertise securing web applications and cloud platforms such as AWS or Azure.
  • Experience in the defence sector and current, active security clearance.
  • Expertise testing software and infrastructure security with manual or automated security tools.
  • Expertise assessing software and infrastructure source code from a security standpoint.
  • Expertise with continuous security, continuous integration, and continuous delivery techniques.
  • Knowledge of security standards and regulations including NCSC, NIST, CIS, PCI, GDPR, OWASP ASVS, HIPAA, and SOC 2.
  • Knowledge of cyber security attack vectors including OWASP Top 10, SQL, XSS, XXE, and MITM.
  • Excellent communication skills for explaining security complexity to varied technical audiences.
  • Demonstrated ability to manage, mentor, and coach team and community members.
  • Good programming or scripting experience across Windows, Linux, and macOS.
  • Penetration testing qualifications such as OSCP, CREST, TIGER, or equivalent are desirable.
  • Experience working with external penetration testing companies and translating findings into actionable tasks is desirable.
  • Experience with security tools such as Burp Suite, OWASP ZAP, Nmap, Nessus, Kali, and Metasploit is desirable.
  • Knowledge of cyber security areas including OSINT, network scanning, enumeration, sniffing, session hijacking, social engineering, firewalls, honeypots, IDS, IPS, WAF, AV, DLP, cryptography, PKI, IoT threats, trojans, viruses, worms, backdoors, and ransomware is desirable.
  • Active participation in knowledge sharing, security communities, conferences, or external speaking is desirable.
  • Experience working in an Agile environment is desirable.

Tech Stack

AWSAzureLinuxmacOSSQLWindows

Categories

Kainos

About Kainos

1,001-5,000 employees
Contact me