At a Glance
- Tasks: Own and operate security controls across endpoint, network, identity, and data security domains.
- Company: Join a leading firm focused on innovative security solutions.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Dynamic role with significant hands-on experience in operational security.
- Why this job: Make a real impact in protecting vital information and systems.
- Qualifications: Degree or equivalent experience in a technical discipline; relevant certifications are a plus.
The predicted salary is between 60000 - 80000 £ per year.
The Senior Operational Security Engineer owns and operates the firm's core protective and detective security controls across endpoint, network, identity and data security domains, converting multiple best-efforts operational security activities into sustainable, auditable and scalable services. A critical and deliberate outcome of this role is the capacity it releases across the wider CISO team. By absorbing the day-to-day operational security workload, the role frees the CISO and other senior team members to properly resource strategic, governance and management responsibilities that were previously being delivered on a best-efforts basis.
Security Operations – Endpoint & Network
- Own and operate Endpoint Detection & Response (EDR) tooling including alert triage, threat containment and endpoint health monitoring across all firm devices.
- Enforce endpoint security baselines, compliance checks and hardening standards across the estate.
- Manage anti-malware controls including policy configuration, update management and alert response.
- Configure and manage firewall and Web Application Firewall (WAF) controls, network segmentation, and remote access security.
- Work closely with the SD and Workspace team to maintain baseline security standards across endpoint environments.
- Own email security controls including anti-spam, anti-phishing, DMARC/DKIM/SPF and attachment scanning.
- Manage web filtering, proxy controls and malicious URL/content blocking.
Identity & Access Management
- Administer and manage multi-factor authentication (MFA) and single sign-on (SSO) solutions across the firm.
- Manage Privileged Access Management (PAM/PIM) controls including PAM/PIM platform administration and privileged session management.
- Own joiner, mover and leaver (JML) processes across all systems, ensuring timely and accurate access changes.
- Run periodic access review and recertification cycles, ensuring least-privilege is maintained across the estate.
- Support customer-facing access controls and authentication governance.
Data Security
- Manage Data Loss Prevention (DLP) controls including policy configuration, alert triage and response for data exfiltration events.
- Oversee data classification, retention, archiving and disposal controls within M365 and across the estate.
- Support insider threat monitoring controls and escalation procedures.
- Manage encryption standards and certificate lifecycle including monitoring, renewal and revocation.
Detection & Response
- Triage and analyse security alerts from across the tooling estate, coordinating with the SOC to ensure timely detection and response.
- Lead threat hunting activities using XDR telemetry and threat intelligence to proactively identify attacker activity.
- Own and maintain the XDR platform including rule management, integrations and telemetry quality.
- Investigate security incidents, anomalous activity and SOC escalations, producing clear findings and recommendations.
- Develop and maintain incident response runbooks covering key threat scenarios and response procedures.
- Own ransomware readiness and business resilience testing activities, including backup validation and playbook maintenance.
- Manage security automation and SOAR playbook development to improve detection and response efficiency.
- Provide operational interface with the SOC, supporting SLA management and technical escalation.
Operational Reporting
- Produce clear, accurate and timely reporting covering endpoint health, network control status, DLP alert volumes, IAM control health and incident metrics.
- Contribute security operations data and metrics to the master CISO reporting pack.
Qualifications
- Degree or equivalent professional experience in a relevant technical discipline.
- Relevant industry certification desirable, such as SC-200, AZ-500, CompTIA Security+, GIAC (GCIA, GCED, GCIH) or CISSP.
- Candidates with strong hands-on experience and demonstrable technical capability will be considered regardless of formal qualification.
- Significant hands-on experience in an operational information security or security engineering role.
- Demonstrable experience managing EDR/AV, SIEM/XDR platforms, and network security controls including firewalls, WAF and segmentation.
- Practical experience with identity and access management including MFA, PAM/PIM and access review processes.
- Experience with the enterprise security solutions suites (Endpoint, Cloud, XDR, Identity, etc) and Purview/DLP.
- Working knowledge of PAM tooling.
- Experience in a regulated financial services environment preferred but not essential; working knowledge of ISO 27001, NIST CSF, DORA or NYDFS Part 500 beneficial.
- Ability to produce clear technical documentation, reports and evidence suitable for audit and regulatory review.
Senior Operational Security Engineer employer: Crown Agents Bank
Crown Agents Bank is an excellent employer that values integrity and compliance, offering a dynamic work culture where collaboration and attention to detail are paramount. Employees benefit from ongoing professional development opportunities and a supportive environment that encourages growth within the financial sector. Located in a vibrant area, the bank provides a unique chance to engage with diverse banking partners while contributing to meaningful anti-financial crime initiatives.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Operational Security Engineer
✨Tip Number 1
Network with industry professionals! Attend security conferences, webinars, or local meetups. This is a great way to get your name out there and learn about job openings that might not be advertised.
✨Tip Number 2
Show off your skills in practical ways! Consider contributing to open-source projects or writing blogs about security topics. This not only builds your portfolio but also demonstrates your passion for the field.
✨Tip Number 3
Prepare for interviews by practising common security scenarios. Be ready to discuss how you would handle specific incidents or manage security tools like EDR and SIEM. The more prepared you are, the more confident you'll feel!
✨Tip Number 4
Don't forget to apply through our website! We often have exclusive listings and it’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive!
We think you need these skills to ace Senior Operational Security Engineer
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Senior Operational Security Engineer role. Highlight your hands-on experience with EDR, SIEM/XDR platforms, and any relevant certifications. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about operational security and how your experience aligns with our needs. Keep it concise but impactful – we love a good story!
Showcase Your Technical Skills:In your application, don't forget to showcase your technical skills clearly. Mention specific tools and technologies you've worked with, like firewalls, MFA, or DLP controls. We’re keen on seeing your expertise in action!
Apply Through Our Website:We encourage you to apply through our website for the best experience. It helps us keep track of your application and ensures you don’t miss out on any important updates. Plus, it’s super easy!
How to prepare for a job interview at Crown Agents Bank
✨Know Your Security Tools
Familiarise yourself with the specific security tools mentioned in the job description, like EDR, SIEM/XDR platforms, and firewalls. Be ready to discuss your hands-on experience with these tools and how you've used them to manage security controls effectively.
✨Demonstrate Your Problem-Solving Skills
Prepare to share examples of how you've triaged security alerts or managed incidents in the past. Highlight your analytical skills and ability to develop clear findings and recommendations, as this role requires a proactive approach to threat detection and response.
✨Understand Compliance Standards
Brush up on relevant compliance standards such as ISO 27001 and NIST CSF. Be prepared to discuss how you've implemented these standards in previous roles, especially in relation to data security and access management.
✨Showcase Your Communication Skills
Since you'll be producing reports and documentation, practice explaining complex security concepts in simple terms. Be ready to demonstrate how you can communicate effectively with both technical teams and non-technical stakeholders.