5 months ago
Remote, United KingdomSenior
Responsibilities
- Lead improvements to detection, monitoring, alerting, and incident response capabilities.
- Participate in an on-call rotation and respond to escalated security incidents.
- Conduct vulnerability assessments, identify security-control gaps, and implement mitigation strategies.
- Deploy, maintain, and optimise security tools including SIEMs and vulnerability scanners.
- Own security project execution, prioritisation, and cross-functional delivery.
- Support compliance documentation, audits, certifications, and regulatory standards.
- Collaborate with development and IT teams to integrate security practices into architectures.
- Lead security awareness and secure-coding education initiatives.
- Develop scripts and tools to automate security operations, detection, response, and repetitive tasks.
- Mentor junior and mid-level engineers and provide security guidance to internal and external stakeholders.
- Produce reporting on incidents, vulnerabilities, project progress, and security metrics.
- Develop and document security processes for routine and high-stress incidents.
Requirements
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent security experience.
- 5+ years of experience in security engineering and operations, including blue-team operations, security architecture, DevOps, and general operations.
- Deep knowledge of information technology, evolving threats, attack patterns, incident response, and cybersecurity standards.
- Experience developing and leading incident response, including remediation, mitigation, status updates, and reporting.
- Experience evaluating security events, investigating incidents, applying countermeasures, and monitoring impact.
- Strong understanding of operating-system, networking, application-hardening, and virtualisation security for Windows, macOS, and Linux.
- Experience with IDS, DLP, FIM, firewalls, SIEM, MFA, vulnerability assessment tools, web proxies, and WAFs.
- Experience with cloud providers and Infrastructure as Code tools such as Terraform, Ansible, or CloudFormation.
- Proficiency in AWS security best practices.
- Skills in automation, development, or scripting for security operations.
- Advanced knowledge of Application Security, modern web protocols, and Web Application Firewalls.
- Proficiency with SPF, DKIM, and DMARC email security protocols.
Benefits
- Fully remote work from anywhere within the UK.
- Opportunity to mentor engineers and contribute to security strategy, risk management, and cross-functional initiatives.
