At a Glance
- Tasks: Join the Application Security Team to enhance security in digital services.
- Company: Work with a Central Government Institution focused on cyber security.
- Benefits: Earn £700 per day with flexible remote work options.
- Why this job: Make a real impact by securing vital government applications and services.
- Qualifications: Experience in penetration testing, DevSecOps, and cloud security is essential.
- Other info: This is a 6-month contract requiring SC clearance and offers hands-on experience.
The predicted salary is between 42000 - 84000 £ per year.
A Central Government Institution are seeking a Cyber Security Engineer, with experience of DevSecOps principles and tools, to undertake an initial 6 month contract.
You will be joining the Application Security Team who are focused on building security automation into delivery pipelines and conducting security focused tests against digital services.
Key Responsibilities- Perform penetration testing and vulnerability assessments of web applications, APIs, and cloud infrastructure.
- Evaluate the automated security tooling into CI/CD pipelines (SAST, DAST, dependency checking, IaC etc), and make necessary recommendations.
- Collaborate with developers to remediate identified vulnerabilities and ensure secure code practices.
- Provide expert input on cloud security (AWS, Azure, or GCP) and DevSecOps tooling.
- Assist in maintaining security assurance across the SDLC in line with NCSC guidelines.
- Demonstrable experience with:
- Penetration testing, ethical hacking, or vulnerability assessments.
- Security testing tools (e.g., Burp Suite, OWASP ZAP, Nikto, Nmap, Metasploit, etc.).
- DevSecOps principles and tools (e.g., Veracode, SonarQube, GitHub Advanced Security, IaC scanning, etc.).
- Secure Cloud Infrastructure, specifically AWS and Azure.
- Scripting and automation using Python and Bash.
- Experience delivering assessments under the CHECK scheme (e.g., as a CHECK Team Member/Leader).
- Knowledge of UK public sector security and data protection standards (e.g., NCSC, Cyber Essentials Plus).
- Threat modelling and secure design practices.
If you are available and interested, please apply in the first instance and you will be contacted to discuss the position further.
Contact Detail:
Involved Solutions Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Engineer - SC Cleared - 6 months
✨Tip Number 1
Make sure to highlight your experience with penetration testing and vulnerability assessments during any conversations. Be ready to discuss specific projects where you've successfully identified and remediated vulnerabilities.
✨Tip Number 2
Familiarise yourself with the specific security tools mentioned in the job description, such as Burp Suite and OWASP ZAP. Being able to speak confidently about these tools will demonstrate your hands-on experience and technical knowledge.
✨Tip Number 3
Since collaboration with developers is key, prepare examples of how you've worked with development teams in the past to implement secure coding practices. This will show your ability to communicate effectively across different roles.
✨Tip Number 4
Stay updated on the latest trends in cloud security, especially regarding AWS and Azure. Being knowledgeable about current threats and best practices will help you stand out as a candidate who is proactive and well-informed.
We think you need these skills to ace Cyber Security Engineer - SC Cleared - 6 months
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in penetration testing, vulnerability assessments, and DevSecOps principles. Use specific examples that demonstrate your skills with tools like Burp Suite and AWS.
Craft a Strong Cover Letter: In your cover letter, express your enthusiasm for the role and the organisation. Mention your experience with security automation and how you can contribute to the Application Security Team's goals.
Highlight Certifications: Clearly list your certifications such as OSCP or CREST / TIGER Scheme in your application. This will help you stand out as a qualified candidate for the Cyber Security Engineer position.
Showcase Communication Skills: Since strong communication skills are essential, provide examples in your application of how you've effectively communicated security issues to both technical and non-technical stakeholders.
How to prepare for a job interview at Involved Solutions
✨Showcase Your Technical Skills
Be prepared to discuss your experience with penetration testing and the specific tools you've used, such as Burp Suite or OWASP ZAP. Highlight any relevant projects where you successfully identified and remediated vulnerabilities.
✨Understand DevSecOps Principles
Familiarise yourself with DevSecOps practices and be ready to explain how you've integrated security into CI/CD pipelines. Discuss any specific tools you've worked with, like Veracode or SonarQube, and how they contributed to secure software delivery.
✨Communicate Effectively
Demonstrate your strong communication skills by explaining complex security concepts in simple terms. Be prepared to discuss how you've collaborated with developers to ensure secure coding practices and how you can bridge the gap between technical and non-technical stakeholders.
✨Research the Organisation
Take some time to understand the Central Government Institution's mission and values. Being able to relate your skills and experiences to their specific needs will show that you're genuinely interested in the role and how you can contribute to their security objectives.