Senior Cyber Security Engineer — Portfolio Security Lead

Senior Cyber Security Engineer — Portfolio Security Lead

Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
D

At a Glance

  • Tasks: Lead security across digital products, managing vulnerabilities and ensuring compliance.
  • Company: DNV Energy Systems, a leader in cyber security with a focus on innovation.
  • Benefits: 26 days leave, flexible working, health benefits, and career development opportunities.
  • Other info: Join a diverse team that values your unique background and perspective.
  • Why this job: Make a real impact by enhancing security practices in a dynamic tech environment.
  • Qualifications: Experience in application security tools and vulnerability management is essential.

The predicted salary is between 60000 - 80000 £ per year.

Are you a cyber security engineer who gets genuine satisfaction from closing vulnerabilities, not just finding them? DNV Energy Systems is seeking a Senior Cyber Security Engineer to take ownership of the hands-on delivery of security across a portfolio of digital products. In this role, you will work closely with product and engineering teams to actively reduce risk, meet compliance requirements, and embed secure, sustainable practices that last.

Reporting to the Digital Portfolio Manager, you will be the primary security engineering resource for the UK&I digital product portfolio. You will own the security posture of the portfolio end-to-end, from tooling and triage through to remediation support, assessment execution, and audit preparation. This is an individual contributor role with substantial scope. You'll be the one closest to the work, with direct influence over how security is practised across the portfolio. There is genuine opportunity for the function to grow around you as the team expands.

You will work across multiple products and engineering teams simultaneously, acting as the technical security authority for the region. You'll be joining teams that value security and want to get it right, giving you the platform to drive meaningful, lasting improvements.

What you'll do:

  • Vulnerability Management & Tooling
    • Maintain and operate SAST/DAST tooling (including Veracode) across the digital portfolio
    • Lead CVE triage, assessing severity, exploitability and remediation priority across all products
    • Track and manage vulnerability remediation to closure, working directly with engineering teams
    • Maintain the portfolio security risk register, ensuring visibility of open issues and remediation status
  • Security Assessment & Audit
    • Plan and execute security assessments across the product portfolio against DNV standards and industry frameworks (eg OWASP ASVS)
    • Support audit preparation and evidence gathering for internal and external audit cycles
    • Maintain assessment documentation, findings registers and remediation tracking artefacts
  • Secure Development Practice
    • Embed security into the software development lifecycle (SDL/SSDLC) across product teams
    • Conduct threat modelling and architecture review for new and materially changed products
    • Advise development teams on secure coding practices, dependency management and secrets handling
    • Act as technical security subject matter expert, the first point of contact for engineering and product teams when security questions arise

Benefits

  • Exceptional Development and career progression opportunities with regular development discussions with your manager
  • Non-contractual Profit Share Scheme
  • Lifestyle benefits: 26 days annual leave + bank holidays, opportunity for up to 10 days unpaid leave, sabbatical leave, flexible working options
  • Wellbeing benefits: (including Private Medical, Dental Insurance, Health Assessments, Gym allowance). Company contribution towards eye tests and glasses (for computer/laptop users), and Flu Vaccinations. Also, our Employee Assistance Programme (EAP) provides free and confidential support for issues including work, family, relationships, money and health and we provide free fruit in our offices
  • Financial Benefits: including a Pension Scheme with employer pension contributions up to 9%, Life Assurance and Income Protection
  • Travel benefits: Season Ticket Loan, Cycle to Work Scheme, Electric Vehicle Salary Sacrifice Scheme (for personal use)
  • Re-imbursement of relevant Professional Membership Fees (up to £570)
  • Access to employee retail discount site for high street and on-line shopping

DNV is an Equal Opportunity Employer and gives consideration for employment to qualified applicants without regard to gender, religion, race, national or ethnic origin, cultural background, social group, disability, sexual orientation, gender identity, marital status, age or political opinion. Diversity is fundamental to our culture and we invite you to be part of this diversity.

Qualifications

We're looking for a Cyber Security Engineer who is focused on practical outcomes and understands that lasting remediation comes from a combination of strong technical fixes, clear communication, good documentation, and solid process. Our colleagues come from a vast range of different backgrounds, and we value the diversity of experience, knowledge and thought that this brings to our approach. We therefore try to keep our mandatory requirements to a minimum. As a Senior Cyber Security Engineer, there are a few typical traits that we'd love you to bring, to complement the more specific role requirements.

Essential

  • Experience with application security tooling (SAST, DAST, SCA) including commercial platforms such as Veracode
  • CVE triage and vulnerability management capability across multi-product environments
  • Working knowledge of OWASP Top 10, ASVS, and common web application attack vectors
  • Experience executing or supporting security assessments and audit preparation
  • Ability to communicate technical security risk clearly to non-security audiences, including product and senior stakeholders
  • Comfortable working as an individual contributor across multiple products simultaneously

Desirable

  • Experience with cloud-hosted applications and infrastructure security (AWS, Azure or GCP)
  • Familiarity with ISO 27005, ISO 27001 or equivalent risk management frameworks
  • Exposure to threat modelling methodologies (STRIDE, PASTA or similar)
  • Relevant security certifications (CEH, OSCP, CISSP, CompTIA Security+, or equivalent)
  • Experience in energy, infrastructure, engineering consultancy, or other regulated technical environments

We recognise that equivalent tools and frameworks exist across the industry. If your experience is with comparable tooling or your background doesn't map neatly to our list, we'd still like to hear from you, we're interested in your underlying capability and the value you'd bring to the role.

Senior Cyber Security Engineer — Portfolio Security Lead employer: Det Norske Veritas

At DNV Energy Systems, we pride ourselves on being an exceptional employer that fosters a culture of collaboration and innovation. Our commitment to employee growth is evident through our extensive development opportunities, flexible working options, and comprehensive wellbeing benefits, including private medical insurance and a profit share scheme. Join us in our UK&I office, where you will have the chance to make a meaningful impact on security practices across a diverse portfolio of digital products while enjoying a supportive and inclusive work environment.

D

Contact Details:

Det Norske Veritas Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Cyber Security Engineer — Portfolio Security Lead

Tip Number 1

Network like a pro! Get out there and connect with folks in the cyber security field. Attend meetups, webinars, or even local events. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Show off your skills! Create a portfolio showcasing your past projects, especially those related to vulnerability management and security assessments. This will give potential employers a taste of what you can bring to the table.

Tip Number 3

Don’t just apply blindly! Tailor your approach for each role. Research the company and its products, and be ready to discuss how your experience aligns with their needs during interviews. This shows you’re genuinely interested and not just sending out cookie-cutter applications.

Tip Number 4

Use our website to apply! We’ve got a streamlined process that makes it easy for you to showcase your skills and experience. Plus, it’s a great way to ensure your application gets the attention it deserves!

We think you need these skills to ace Senior Cyber Security Engineer — Portfolio Security Lead

Vulnerability Management
SAST/DAST Tooling
CVE Triage
Security Assessment
Audit Preparation
OWASP ASVS
Secure Development Lifecycle (SDL/SSDLC)

Some tips for your application 🫡

Tailor Your CV:Make sure your CV speaks directly to the role of Senior Cyber Security Engineer. Highlight your experience with application security tooling and vulnerability management, and don’t forget to mention any relevant certifications you have!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your skills align with DNV's mission. Be sure to mention your hands-on experience in closing vulnerabilities.

Showcase Your Communication Skills:Since you'll be communicating technical risks to non-security audiences, make sure to demonstrate your ability to simplify complex concepts in your application. This will show us that you can bridge the gap between tech and business.

Apply Through Our Website:We encourage you to apply through our website for a smoother process. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates from our team!

How to prepare for a job interview at Det Norske Veritas

Know Your Tools Inside Out

Make sure you’re well-versed in the application security tooling mentioned in the job description, especially SAST, DAST, and Veracode. Be ready to discuss your hands-on experience with these tools and how you've used them to manage vulnerabilities effectively.

Showcase Your Communication Skills

Since you'll need to communicate technical risks to non-security audiences, practice explaining complex concepts in simple terms. Prepare examples of how you've successfully communicated security issues to product teams or stakeholders in the past.

Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think about past experiences where you triaged CVEs or led security assessments, and be ready to walk through your thought process and the outcomes.

Demonstrate Your Passion for Security

Show genuine enthusiasm for cyber security and the impact it has on digital products. Share your thoughts on current trends in the industry, and be prepared to discuss how you stay updated on best practices and emerging threats.