Senior Cyber Security Engineer in Glasgow

Senior Cyber Security Engineer in Glasgow

Glasgow Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
DNV

At a Glance

  • Tasks: Close vulnerabilities and enhance security across multiple digital products.
  • Company: Join a leading assurance and risk management expert dedicated to safety and innovation.
  • Benefits: Enjoy flexible working, 26 days leave, private medical, and career development opportunities.
  • Other info: Diverse and inclusive workplace with excellent growth potential.
  • Why this job: Make a real impact in cyber security while working with cutting-edge technology.
  • Qualifications: Experience in application security tooling and vulnerability management is essential.

The predicted salary is between 60000 - 80000 £ per year.

About Us

We are the independent expert in assurance and risk management. Driven by our purpose, to safeguard life, property, and the environment, we empower our customers and their stakeholders with facts and reliable insights so that critical decisions can be made with confidence. As a trusted voice for many of the world’s most successful organizations, we use our knowledge to advance safety and performance, set industry benchmarks, and inspire and invent solutions to tackle global transformations.

About the Role

DNV Energy Systems is seeking a Senior Cyber Security Engineer who gets genuine satisfaction from closing vulnerabilities, not just finding them. In this role, you will work closely with product and engineering teams to actively reduce risk, meet compliance requirements, and embed secure, sustainable practices that last. Reporting to the Digital Portfolio Manager, you will be the primary security engineering resource for the UK&I digital product portfolio. You will own the security posture of the portfolio end‑to‑end, from tooling and triage through to remediation support, assessment execution, and audit preparation. This is an individual contributor role with substantial scope. You'll be the one closest to the work, with direct influence over how security is practised across the portfolio. There is genuine opportunity for the function to grow around you as the team expands. You will work across multiple products and engineering teams simultaneously, acting as the technical security authority for the region. You’ll be joining teams that value security and want to get it right, giving you the platform to drive meaningful, lasting improvements.

What You’ll Do

  • Vulnerability Management & Tooling
    • Maintain and operate SAST/DAST tooling (including Veracode) across the digital portfolio
    • Lead CVE triage, assessing severity, exploitability and remediation priority across all products
    • Track and manage vulnerability remediation to closure, working directly with engineering teams
    • Maintain the portfolio security risk register, ensuring visibility of open issues and remediation status
  • Security Assessment & Audit
    • Plan and execute security assessments across the product portfolio against DNV standards and industry frameworks (eg OWASP ASVS)
    • Support audit preparation and evidence gathering for internal and external audit cycles
    • Maintain assessment documentation, findings registers and remediation tracking artefacts
  • Secure Development Practice
    • Embed security into the software development lifecycle (SDL/SSDLC) across product teams
    • Conduct threat modelling and architecture review for new and materially changed products
    • Advise development teams on secure coding practices, dependency management and secrets handling
    • Act as technical security subject matter expert, the first point of contact for engineering and product teams when security questions arise

Benefits

  • Exceptional Development and career progression opportunities with regular development discussions with your manager
  • Non‑contractual Profit Share Scheme
  • Lifestyle benefits: 26 days annual leave + bank holidays, opportunity for up to 10 days unpaid leave, sabbatical leave, flexible working options
  • Wellbeing benefits: Private Medical, Dental Insurance, Health Assessments, Gym allowance, company contribution towards eye tests and glasses (for computer/laptop users), flu vaccinations, Employee Assistance Programme (EAP) with free confidential support, free fruit in offices
  • Financial Benefits: Pension Scheme with employer pension contributions up to 9%, Life Assurance and Income Protection
  • Travel benefits: Season Ticket Loan, Cycle to Work Scheme, Electric Vehicle Salary Sacrifice Scheme (personal use)
  • Re‑imbursement of relevant Professional Membership Fees (up to £570)
  • Access to employee retail discount site for high street and online shopping

DNV is an Equal Opportunity Employer and gives consideration for employment to qualified applicants without regard to gender, religion, race, national or ethnic origin, cultural background, social group, disability, sexual orientation, gender identity, marital status, age or political opinion. Diversity is fundamental to our culture and we invite you to be part of this diversity.

About You

We’re looking for a Cyber Security Engineer who is focused on practical outcomes and understands that lasting remediation comes from a combination of strong technical fixes, clear communication, good documentation, and solid process.

Essential

  • Experience with application security tooling (SAST, DAST, SCA) including commercial platforms such as Veracode
  • Experience with CVE triage and vulnerability management across multi‑product environments
  • Working knowledge of OWASP Top 10, ASVS, and common web application attack vectors
  • Experience executing or supporting security assessments and audit preparation
  • Ability to communicate technical security risk clearly to non‑security audiences, including product and senior stakeholders
  • Comfortable working as an individual contributor across multiple products simultaneously

Desirable

  • Experience with cloud‑hosted applications and infrastructure security (AWS, Azure or GCP)
  • Familiarity with ISO 27005, ISO 27001 or equivalent risk management frameworks
  • Exposure to threat modelling methodologies (STRIDE, PASTA or similar)
  • Relevant security certifications (CEH, OSCP, CISSP, CompTIA Security+ or equivalent)
  • Experience in energy, infrastructure, engineering consultancy or other regulated technical environments

Equivalents

We recognise that equivalent tools and frameworks exist across the industry. If your experience is with comparable tooling or your background doesn't map neatly to our list, we’d still like to hear from you – we are interested in your underlying capability and the value you’d bring to the role.

Senior Cyber Security Engineer in Glasgow employer: DNV

At DNV, we pride ourselves on being an exceptional employer that champions employee growth and well-being. Our collaborative work culture fosters innovation and security excellence, providing you with the opportunity to make a meaningful impact in the field of cyber security while enjoying comprehensive benefits such as flexible working options, a generous leave policy, and a commitment to your professional development. Join us in our mission to safeguard life, property, and the environment, and be part of a diverse team that values your contributions and supports your career aspirations.

DNV

Contact Details:

DNV Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Cyber Security Engineer in Glasgow

Tip Number 1

Network, network, network! Get out there and connect with people in the cyber security field. Attend meetups, webinars, or industry conferences. You never know who might have a lead on your dream job!

Tip Number 2

Show off your skills! Create a portfolio showcasing your projects, especially those related to vulnerability management and secure coding practices. This will give potential employers a taste of what you can bring to the table.

Tip Number 3

Don’t just apply for jobs; tailor your approach! Research the companies you're interested in and understand their security needs. When you reach out, mention how your experience aligns with their goals—this shows genuine interest.

Tip Number 4

Apply through our website! We love seeing candidates who take the initiative. Plus, it gives you a better chance to stand out in the application process. Let’s get you that Senior Cyber Security Engineer role!

We think you need these skills to ace Senior Cyber Security Engineer in Glasgow

Vulnerability Management
SAST/DAST Tooling
CVE Triage
Security Assessment
Audit Preparation
OWASP Top 10
Secure Development Lifecycle (SDL/SSDLC)

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Senior Cyber Security Engineer role. Highlight your experience with application security tooling and vulnerability management, as these are key aspects of the job. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how you can contribute to our mission. Be sure to mention specific experiences that demonstrate your ability to close vulnerabilities and work with engineering teams.

Showcase Your Technical Skills:In your application, don't shy away from showcasing your technical skills. Mention your familiarity with tools like Veracode and your understanding of OWASP standards. We love seeing candidates who can communicate complex security concepts clearly!

Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It helps us keep track of applications and ensures you’re considered for the role. Plus, it’s super easy to do!

How to prepare for a job interview at DNV

Know Your Tools Inside Out

Make sure you’re well-versed in application security tooling like SAST, DAST, and SCA, especially with platforms like Veracode. Be ready to discuss your hands-on experience with these tools and how you've used them to manage vulnerabilities effectively.

Master the Art of Communication

You’ll need to explain technical security risks to non-security folks, so practice articulating complex concepts in simple terms. Think about examples where you’ve successfully communicated risks to product teams or senior stakeholders.

Showcase Your Problem-Solving Skills

Prepare to discuss specific instances where you’ve closed vulnerabilities rather than just identified them. Highlight your approach to vulnerability management and how you’ve collaborated with engineering teams to ensure lasting remediation.

Familiarise Yourself with Industry Standards

Brush up on OWASP Top 10, ASVS, and relevant risk management frameworks like ISO 27001. Being able to reference these standards during your interview will show that you understand the broader context of security practices and compliance requirements.