At a Glance
- Tasks: Join the Application Security Team to enhance security in digital services.
- Company: Work with a Central Government Institution focused on cyber security.
- Benefits: Earn £700 per day with flexible remote work options.
- Why this job: Make a real impact by securing vital government applications and collaborating with top developers.
- Qualifications: Experience in penetration testing, DevSecOps, and cloud security is essential.
- Other info: This is a 6-month contract requiring SC clearance, with 2 days on-site in London.
The predicted salary is between 42000 - 84000 £ per year.
A Central Government Institution are seeking a Cyber Security Engineer, with experience of DevSecOps principles and tools, to undertake an initial 6 month contract.
You will be joining the Application Security Team who are focused on building security automation into delivery pipelines and conducting security focused tests against digital services.
Key Responsibilities- Perform penetration testing and vulnerability assessments of web applications, APIs, and cloud infrastructure.
- Evaluate the automated security tooling into CI/CD pipelines (SAST, DAST, dependency checking, IaC etc), and make necessary recommendations.
- Collaborate with developers to remediate identified vulnerabilities and ensure secure code practices.
- Provide expert input on cloud security (AWS, Azure, or GCP) and DevSecOps tooling.
- Assist in maintaining security assurance across the SDLC in line with NCSC guidelines.
- Demonstrable experience with:
- Penetration testing, ethical hacking, or vulnerability assessments.
- Security testing tools (e.g., Burp Suite, OWASP ZAP, Nikto, Nmap, Metasploit, etc.).
- DevSecOps principles and tools (e.g., Veracode, SonarQube, GitHub Advanced Security, IaC scanning, etc.).
- Secure Cloud Infrastructure, specifically AWS and Azure.
- Scripting and automation using Python and Bash.
- Experience delivering assessments under the CHECK scheme (e.g., as a CHECK Team Member/Leader).
- Knowledge of UK public sector security and data protection standards (e.g., NCSC, Cyber Essentials Plus).
- Threat modelling and secure design practices.
If you are available and interested, please apply in the first instance and you will be contacted to discuss the position further.
Cyber Security Engineer - SC Cleared - 6 months employer: Involved Solutions
Contact Detail:
Involved Solutions Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Engineer - SC Cleared - 6 months
✨Tip Number 1
Make sure to highlight your experience with penetration testing and vulnerability assessments during any conversations. Be ready to discuss specific projects where you've successfully identified and remediated vulnerabilities.
✨Tip Number 2
Familiarise yourself with the specific security tools mentioned in the job description, such as Burp Suite and OWASP ZAP. Being able to speak confidently about these tools and how you've used them will set you apart.
✨Tip Number 3
Since this role involves collaboration with developers, practice explaining complex security concepts in simple terms. This will demonstrate your strong communication skills and ability to work effectively with both technical and non-technical teams.
✨Tip Number 4
Stay updated on the latest trends in cloud security, especially for AWS and Azure. Showing that you're knowledgeable about current best practices will make you a more attractive candidate for this position.
We think you need these skills to ace Cyber Security Engineer - SC Cleared - 6 months
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in penetration testing, vulnerability assessments, and DevSecOps principles. Use specific examples that demonstrate your skills with tools like Burp Suite and AWS.
Craft a Strong Cover Letter: In your cover letter, express your enthusiasm for the role and the organisation. Mention your experience with security automation and how it aligns with the responsibilities of the position.
Highlight Certifications: Clearly list any relevant certifications such as OSCP or CREST/TIGER Scheme in your application. This will help you stand out as a qualified candidate.
Showcase Communication Skills: Since strong communication skills are essential, provide examples in your application of how you've effectively communicated security issues to both technical and non-technical stakeholders.
How to prepare for a job interview at Involved Solutions
✨Showcase Your Technical Skills
Be prepared to discuss your experience with penetration testing and the specific tools you've used, such as Burp Suite or OWASP ZAP. Highlight any relevant projects where you successfully identified and remediated vulnerabilities.
✨Understand DevSecOps Principles
Familiarise yourself with DevSecOps practices and be ready to explain how you've integrated security into CI/CD pipelines. Discuss any specific tools you've worked with, like Veracode or SonarQube, and how they contributed to secure software delivery.
✨Communicate Effectively
Demonstrate your strong communication skills by explaining complex security concepts in simple terms. Be prepared to discuss how you've collaborated with developers to ensure secure coding practices and how you can bridge the gap between technical and non-technical stakeholders.
✨Research the Organisation
Take some time to understand the Central Government Institution's mission and values. Being able to relate your skills and experiences to their specific needs will show your genuine interest in the role and help you stand out as a candidate.