At a Glance
- Tasks: Secure our innovative cloud-native SaaS platform and enhance its resilience against cyber threats.
- Company: Join Ensek, a leading tech company transforming the energy sector with cutting-edge solutions.
- Benefits: Enjoy 25 days holiday, health insurance, pension contributions, and remote-first work culture.
- Why this job: Make a real impact in cyber security while driving the global energy transition.
- Qualifications: 5+ years in cyber security, strong AWS knowledge, and experience with automation tools.
- Other info: Be part of a dynamic team with opportunities for professional growth and development.
The predicted salary is between 48000 - 84000 ÂŁ per year.
About Ensek
Ensek builds the cloud‑native SaaS software that’s transforming how energy retailers operate, innovate and manage at scale. We help retailers lower operating costs, improve billing accuracy for consumers, and enhance customer experience through automation and AI‑driven insight, all underpinned by modern, cloud‑native architecture. Ensek is at an exciting inflection point as we scale at pace towards new international horizons. If you’re driven by solving complex, real‑world problems and want to protect resilient, cloud‑native platforms that accelerate the global energy transition, you’ll feel right at home with us.
About The Role
As a Senior Cyber Security Engineer you will embed security into the DNA of our B2B SaaS platform. You’ll partner with Engineering, SRE, Risk and Product to build security into every part of our product lifecycle, enabling high‑velocity delivery without ever compromising trust or resilience. This is a hands‑on, high‑impact role. You’ll influence architecture, automate security controls, strengthen detection & response, and drive a measurable uplift in our security posture. You’ll define our standards, lead threat modelling, and champion secure‑by‑design practices across an engineering organisation that’s modernising rapidly and ready for your expertise.
Key responsibilities
- Security architecture & design: Collaborate with engineering and platform teams to design secure solutions, perform threat modelling and review designs for cloud, container and service‑based architectures.
- Cloud security: Define and enforce secure configurations, network segmentation, identity and access controls for public cloud (primarily AWS).
- Application & infrastructure hardening: Implement secure coding practices, vulnerability management, secrets management and runtime protections for services and CI/CD pipelines.
- Detection & response: Build and maintain monitoring, logging and alerting for security events; lead incident response and post‑incident reviews to drive remediation and lessons learned.
- Automation & tooling: Automate security checks, policy enforcement and remediation using IaC, CI/CD integrations and custom tooling where appropriate.
- Compliance & assurance: Work with Risk, Legal and InfoSec to embed controls that support regulatory, privacy and contractual requirements across new territories.
Key outcomes
- Measurable risk reduction: Clear evidence of reduced exposure through vulnerability metrics, patch timelines and remediation actions.
- Robust detection capability: High‑fidelity alerts and shortened MTTD/MTTR for security incidents with thorough RCA and preventative measures.
- Secure‑by‑design practices adopted: Engineering teams consistently apply threat modelling, secure coding and automated security gates.
- Compliance readiness: Security controls aligned with regulatory and contractual requirements for current and new markets.
Experience required
- 5+ years’ experience in cyber security within cloud‑native environments, DevOps or platform engineering contexts.
- Strong cloud security knowledge: Practical experience securing AWS services, IAM, networking, KMS/secrets and managed services.
- Container and orchestration security: Experience securing Kubernetes and related tooling (runtime protection, admission controllers, image scanning).
- Detection and monitoring: Hands‑on with logging, metrics and tracing for security use cases (SIEM, ELK/Opensearch, Prometheus, Grafana, Jaeger or similar).
- Infrastructure as Code & automation: Proficient with Terraform/CloudFormation and CI/CD integration to enforce policy and automate remediations.
- Scripting & development skills: Comfortable writing automation and tools in Python, Go, Bash or similar languages.
Company Benefits
- 25 days’ holiday + bank holidays
- Option to buy or sell 5 extra annual leave days per year
- Vitality Health Insurance, including private healthcare, virtual GP access and mental‑health support
- Pension with 5% matched contribution
- Regular team‑wide and company‑wide events
- 2 volunteering days per year
- Remote‑first working environment with offices in London and Nottingham
Senior Cyber Security Engineer in Nottingham employer: ENSEK
Contact Detail:
ENSEK Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Cyber Security Engineer in Nottingham
✨Network Like a Pro
Get out there and connect with people in the cyber security field! Attend meetups, webinars, or even online forums. The more you engage with others, the better your chances of hearing about job openings that might not be advertised.
✨Show Off Your Skills
Don’t just list your skills on your CV; demonstrate them! Create a portfolio showcasing your projects, contributions to open-source, or any relevant work. This gives potential employers a tangible sense of what you can bring to the table.
✨Ace the Interview
Prepare for interviews by researching common questions in cyber security roles. Practice your responses and think of examples that highlight your experience with AWS, threat modelling, and automation. Confidence is key, so get comfortable talking about your expertise!
✨Apply Through Our Website
When you find a role that excites you, apply directly through our website! It shows your enthusiasm for the position and helps us keep track of your application. Plus, it’s a great way to ensure your CV lands in the right hands.
We think you need these skills to ace Senior Cyber Security Engineer in Nottingham
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Senior Cyber Security Engineer role. Highlight your experience with cloud security, automation, and any relevant projects that showcase your skills in securing cloud-native environments.
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your background aligns with our mission at Ensek. Don’t forget to mention specific experiences that relate to the key responsibilities outlined in the job description.
Showcase Your Technical Skills: We want to see your technical prowess! Be sure to include any relevant certifications or hands-on experience with AWS, Kubernetes, and IaC tools like Terraform. This will help us understand your capabilities in automating security checks and managing cloud security.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you don’t miss out on any important updates from us!
How to prepare for a job interview at ENSEK
✨Know Your Stuff
Make sure you brush up on your cloud security knowledge, especially around AWS services and IAM. Be ready to discuss specific examples of how you've secured cloud environments in the past, as this will show your hands-on experience.
✨Showcase Your Problem-Solving Skills
Prepare to talk about complex security challenges you've faced and how you tackled them. Use the STAR method (Situation, Task, Action, Result) to structure your answers, making it clear how you can solve real-world problems.
✨Get Familiar with Their Tech Stack
Research the tools and technologies Ensek uses, particularly around container security and automation. If you have experience with Kubernetes or Terraform, be ready to share how you've implemented security measures in those contexts.
✨Emphasise Collaboration
Since the role involves working closely with various teams, highlight your experience in cross-functional collaboration. Share examples of how you've partnered with engineering or product teams to embed security into the development lifecycle.