At a Glance
- Tasks: Enhance and maintain security controls while collaborating with tech teams.
- Company: Join a forward-thinking organisation focused on operational efficiency and impactful change.
- Benefits: Enjoy a competitive salary, discretionary bonuses, and flexible office days.
- Why this job: Be part of a transformative journey in cybersecurity with a supportive culture.
- Qualifications: Experience in IT Security, knowledge of security frameworks, and cloud infrastructure expertise required.
- Other info: Opportunity to work with cutting-edge security technologies and contribute to significant projects.
The predicted salary is between 42000 - 84000 £ per year.
Buckinghamshire – 1 or 2 days a week in the office
Up to £70,000 salary plus a discretionary bonus of up to 15%
After a transformative 3-year change initiative, they have outlined a strategic 5-year plan to broaden their impact and enhance operational efficiency. They are now seeking an Information Security Engineer to continue to develop, optimise, and maintain their security controls to protect the organisation's assets and data.
About the role
As the Information Security Engineer, you will be responsible for enhancing and maintaining security controls. This role involves working closely with technology teams to ensure robust security architecture, providing expert advice on security requirements, and managing all technical change activities related to security. You will also identify and address security design gaps and recommend enhancements to existing and proposed architectures.
What you will be responsible for?
- Security Control Development:
- Develop and optimise security controls in collaboration with relevant technology teams.
- Ensure adherence to architectural principles during design to minimise risk.
- Drive adoption of security policies, standards, and guidelines across the organisation.
- Provide consultancy and Expert Advice:
- Provide authoritative advice on security controls and requirements in collaboration with legal, technical support, and other functional experts.
- Maintain recognised expert-level knowledge in one or more security specialisms.
- Promote and support the development and sharing of specialist knowledge within the organisation.
- Conduct Research and Analysis:
- Conduct research to evaluate, develop, and implement security practices and standards.
- Track and understand emerging security technologies and practices.
- Assess impacts, threats, and control opportunities, and create reports and technology roadmaps.
- Share knowledge and insights with relevant stakeholders.
- SecOps and Security Administration:
- Monitor and ensure compliance with security administration procedures.
- Review information systems for potential security breaches and collaborate with SecOps for investigations and control changes.
- Contribute to the creation and maintenance of security policies, standards, procedures, and documentation.
- Support the maintenance of the companies NIST capability maturity.
What do you need to be successful?
- Experience as a Security Engineer or in a similar role with a strong background in IT Security/IT Operations.
- Demonstrable expertise in security controls and architecture.
- Proficiency in security frameworks such as ISO, NIST, and OWASP.
- Knowledge of Cloud infrastructure (e.g., Azure).
- Experience with security technologies (e.g., SIEM, EDR, IPS, web and email gateways).
- Qualifications (desirable): CISSP or similar certification, TOGAF or similar architectural framework certification, Vendor technology training/certifications (e.g., SIEM, EDR, IPS), Experience in security delivery roles.
Contact Detail:
identifi Global Resources Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Engineer
✨Tip Number 1
Familiarise yourself with the specific security frameworks mentioned in the job description, such as ISO, NIST, and OWASP. Being able to discuss these frameworks in detail during your interview will demonstrate your expertise and alignment with the role.
✨Tip Number 2
Showcase your experience with cloud infrastructure, particularly Azure, as this is a key requirement for the position. If you have relevant projects or achievements, be ready to discuss them and how they relate to enhancing security controls.
✨Tip Number 3
Prepare to talk about your experience with security technologies like SIEM, EDR, and IPS. Highlight any specific instances where you've successfully implemented or managed these technologies to improve security posture.
✨Tip Number 4
Network with professionals in the information security field, especially those who work with the technologies and frameworks relevant to this role. Engaging with industry peers can provide insights and potentially lead to referrals that could strengthen your application.
We think you need these skills to ace Information Security Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience as a Security Engineer or in similar roles. Emphasise your expertise in security controls, architecture, and any specific technologies mentioned in the job description.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for information security. Address how your background aligns with the responsibilities of the role, particularly in developing and optimising security controls and providing expert advice.
Highlight Relevant Certifications: If you have certifications like CISSP or TOGAF, make sure to mention them prominently in your application. These qualifications can set you apart from other candidates and demonstrate your commitment to the field.
Showcase Your Knowledge of Security Frameworks: In your application, reference your proficiency in security frameworks such as ISO, NIST, and OWASP. Discuss any practical experience you have with these frameworks and how they relate to the role.
How to prepare for a job interview at identifi Global Resources
✨Showcase Your Technical Expertise
Be prepared to discuss your experience with security controls and architecture in detail. Highlight specific projects where you've implemented security measures, and be ready to explain the frameworks you are familiar with, such as ISO, NIST, and OWASP.
✨Demonstrate Your Problem-Solving Skills
Expect questions that assess your ability to identify and address security design gaps. Prepare examples of how you've tackled similar challenges in the past, focusing on your analytical approach and the outcomes of your solutions.
✨Familiarise Yourself with Their Security Policies
Research the company's existing security policies and procedures. Understanding their current practices will allow you to provide informed suggestions for improvements during the interview, showcasing your proactive mindset.
✨Prepare for Scenario-Based Questions
Be ready for scenario-based questions that test your response to potential security breaches or compliance issues. Think through your thought process and decision-making steps, as this will demonstrate your practical knowledge and readiness for the role.