At a Glance
- Tasks: Join us as a Security Engineer to enhance F1's cloud security and manage vulnerabilities.
- Company: Be part of the dynamic Formula 1 team, where technology meets speed and innovation.
- Benefits: Enjoy a 12-month FTC with opportunities for growth and collaboration in a cutting-edge environment.
- Why this job: Work in a fast-paced culture that values security and innovation while making an impact in motorsport.
- Qualifications: Must have hands-on AWS experience, knowledge of DevSecOps, and familiarity with cloud security tools.
- Other info: Collaborate with top experts in the field and contribute to exciting projects in the world of F1.
The predicted salary is between 36000 - 60000 Β£ per year.
Our team of hundreds of skilled experts keep Formula 1 moving. Weβre on the lookout for a Security Engineer to work with us on a 12-month FTC! Reporting to the Cyber Security Manager, the main purpose of this role is to support the development and management of security technologies across F1βs growing technology landscape.
Main Duties & Responsibilities:
- Assess and maintain high standards of security maturity across Formula 1βs cloud infrastructure.
- Focus on new and existing infrastructure, managing technical vulnerabilities, support continued system maintenance, and minimise technical debt.
- Ensure visibility and reporting of Cloud infrastructure against Formula 1βs compliance and security standards (such as ISO 27001 and CIS).
- Vulnerability Management and reporting across Formula 1βs cloud environment(s), including:
- Development of requirements, design, and implementation of cloud security tools (E.g. compliance and host security).
- A key focus on threat detection and risks across cloud environments.
- Identification, remediation, and reporting of security vulnerabilities.
- Reporting on compliance to F1βs security standards.
- Support in the delivery and management of security design and architecture reviews.
- Working closely with Infrastructure teams on security design and control strategies to reduce risks.
- The definition and operation of secure development / operations (DevOps) practices, inc. code scanning, Kubernetes, container security.
- System and device hardening policies and reporting.
- Technology focused threat assessments to identify threats/risks.
- Documentation of security requirements, patterns, and processes.
- Liaising closely with Formula 1βs cyber security, infrastructure, and digital teams on new and existing initiatives.
About You:
- Extensive hands-on experience with AWS cloud infrastructure β inc. AWS Security Services (CloudTrail, Guard Duty, WAF, IAM, Security Hub etc.).
- Knowledge of CI/CD including DevSecOps patterns and principles.
- Infrastructure as code experience utilising Terraform.
- Knowledge of container technologies.
- Extensive experience with AWS Security Services & Governance and Information Security Best Practices.
- Experience with other enterprise cloud platforms e.g. Azure.
- Kubernetes experience.
- Identity & Access Management deployment and administration (e.g. Okta, Entra ID).
- Web application security technologies β WAF, Bot Protection, DDOS Protection, etc.
- Adaptable, passionate and a team-player.
Division: Technical
For more detail, salary and company information, use the apply link.
Contact Detail:
Formula 1 Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Security Engineer - FTC
β¨Tip Number 1
Familiarise yourself with the specific AWS Security Services mentioned in the job description, such as CloudTrail and Guard Duty. Being able to discuss your hands-on experience with these tools during an interview will demonstrate your suitability for the role.
β¨Tip Number 2
Showcase your knowledge of compliance standards like ISO 27001 and CIS. Prepare examples of how you've previously ensured compliance in your past roles, as this will highlight your understanding of security maturity.
β¨Tip Number 3
Network with professionals in the cybersecurity field, especially those who have experience in cloud environments. Engaging with industry peers can provide insights and potentially lead to referrals that could strengthen your application.
β¨Tip Number 4
Stay updated on the latest trends and threats in cloud security. Being knowledgeable about current issues will not only help you in interviews but also show your passion for the field and commitment to continuous learning.
We think you need these skills to ace Security Engineer - FTC
Some tips for your application π«‘
Tailor Your CV: Make sure your CV highlights relevant experience with AWS cloud infrastructure and security services. Use specific examples that demonstrate your hands-on experience and knowledge of compliance standards like ISO 27001.
Craft a Strong Cover Letter: In your cover letter, express your passion for cybersecurity and how your skills align with the role. Mention your experience with vulnerability management and your ability to work closely with technical teams to enhance security measures.
Showcase Relevant Projects: If you have worked on projects involving CI/CD, DevSecOps, or container technologies, be sure to include these in your application. Highlight any specific tools or methodologies you used, such as Terraform or Kubernetes.
Highlight Soft Skills: Since the role requires teamwork and adaptability, mention instances where you've successfully collaborated with others or adapted to changing environments. This will show that you're not just technically skilled but also a great team player.
How to prepare for a job interview at Formula 1
β¨Showcase Your Cloud Expertise
Make sure to highlight your extensive hands-on experience with AWS cloud infrastructure during the interview. Be prepared to discuss specific AWS Security Services you've worked with, such as CloudTrail and Guard Duty, and how you've implemented them in past projects.
β¨Demonstrate Your Understanding of Security Standards
Familiarise yourself with compliance standards like ISO 27001 and CIS. Be ready to explain how you have ensured compliance in previous roles, particularly in relation to vulnerability management and reporting within cloud environments.
β¨Discuss Your DevSecOps Knowledge
Since the role involves CI/CD and DevSecOps principles, be prepared to discuss your experience with these methodologies. Share examples of how you've integrated security into the development process and any tools you've used for code scanning or container security.
β¨Prepare for Technical Questions
Expect technical questions related to threat detection, risk assessment, and security design. Brush up on your knowledge of Kubernetes, Terraform, and identity management solutions like Okta, as these are crucial for the role.