At a Glance
- Tasks: Join us as a Security Engineer to enhance F1's cloud security and manage vulnerabilities.
- Company: Be part of the dynamic Formula 1 team, where technology meets high-speed racing.
- Benefits: Enjoy a 12-month FTC with opportunities for growth and collaboration in a cutting-edge environment.
- Why this job: Work on exciting projects that impact global events while developing your skills in a fast-paced culture.
- Qualifications: Must have hands-on AWS experience, knowledge of DevSecOps, and familiarity with cloud security tools.
- Other info: Collaborate with top experts in the field and contribute to the future of motorsport technology.
The predicted salary is between 36000 - 60000 £ per year.
Our team of hundreds of skilled experts keep Formula 1 moving. We’re on the lookout for a Security Engineer to work with us on a 12-month FTC! Reporting to the Cyber Security Manager, the main purpose of this role is to support the development and management of security technologies across F1’s growing technology landscape.
Main Duties & Responsibilities:
- Assess and maintain high standards of security maturity across Formula 1’s cloud infrastructure
- Focus on new and existing infrastructure, managing technical vulnerabilities, support continued system maintenance, and minimise technical debt
- Ensure visibility and reporting of Cloud infrastructure against Formula 1’s compliance and security standards (such as ISO 27001 and CIS)
- Main duties to be carried out include, but not limited to:
- Vulnerability Management and reporting across Formula 1’s cloud environment(s), including:
- Development of requirements, design, and implementation of cloud security tools (E.g. compliance and host security)
- A key focus on threat detection and risks across cloud environments
- Identification, remediation, and reporting of security vulnerabilities
- Reporting on compliance to F1’s security standards
- Support in the delivery and management of security design and architecture reviews
- Working closely with Infrastructure teams on security design and control strategies to reduce risks
- The definition and operation of secure development / operations (DevOps) practices, inc. code scanning, Kubernetes, container security.
- System and device hardening policies and reporting
- Technology focused threat assessments to identify threats/risks
- Documentation of security requirements, patterns, and processes
- Liaising closely with Formula 1’s cyber security, infrastructure, and digital teams on new and existing initiatives.
About You:
- Extensive hands-on experience with AWS cloud infrastructure – inc. AWS Security Services (CloudTrail, Guard Duty, WAF, IAM, Security Hub etc.)
- Knowledge of CI/CD including DevSecOps patterns and principles
- Infrastructure as code experience utilising Terraform
- Knowledge of container technologies
- Extensive experience with AWS Security Services & Governance and Information Security Best Practices
- Experience with other enterprise cloud platforms e.g. Azure
- Kubernetes experience
- Identity & Access Management deployment and administration (e.g. Okta, Entra ID)
- Web application security technologies – WAF, Bot Protection, DDOS Protection, etc.
- Adaptable, passionate and a team-player
Division: Technical
Security Engineer - FTC employer: F1
Contact Detail:
F1 Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Engineer - FTC
✨Tip Number 1
Familiarise yourself with the specific security technologies mentioned in the job description, such as AWS Security Services and Kubernetes. Being able to discuss these tools confidently during your interview will show that you're not only qualified but also genuinely interested in the role.
✨Tip Number 2
Network with professionals in the cybersecurity field, especially those who have experience in cloud environments. Engaging with them on platforms like LinkedIn can provide you with insights into the role and potentially lead to referrals.
✨Tip Number 3
Stay updated on the latest trends and threats in cloud security. Being knowledgeable about current issues and solutions will help you stand out as a candidate who is proactive and well-informed.
✨Tip Number 4
Prepare to discuss real-world scenarios where you've successfully managed vulnerabilities or implemented security measures. Having concrete examples ready will demonstrate your hands-on experience and problem-solving skills.
We think you need these skills to ace Security Engineer - FTC
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your extensive hands-on experience with AWS cloud infrastructure and security services. Use specific examples that demonstrate your knowledge of CI/CD, DevSecOps, and container technologies.
Craft a Strong Cover Letter: In your cover letter, express your passion for cybersecurity and how your skills align with the responsibilities outlined in the job description. Mention your experience with vulnerability management and compliance reporting to show you understand the role's requirements.
Showcase Relevant Projects: If you've worked on projects involving AWS Security Services or Kubernetes, be sure to include these in your application. Detail your contributions and the outcomes to illustrate your capability in managing security technologies.
Highlight Team Collaboration: Since the role involves liaising with various teams, emphasise your experience working collaboratively in cross-functional teams. Provide examples of how you've successfully communicated security needs and strategies to non-technical stakeholders.
How to prepare for a job interview at F1
✨Showcase Your Cloud Expertise
Make sure to highlight your extensive hands-on experience with AWS cloud infrastructure during the interview. Be prepared to discuss specific AWS Security Services you've worked with, such as CloudTrail and Guard Duty, and how you've implemented them in past projects.
✨Demonstrate Your Knowledge of Security Standards
Familiarise yourself with compliance standards like ISO 27001 and CIS. During the interview, be ready to explain how you have ensured compliance in previous roles and how you would approach maintaining high security maturity across Formula 1's cloud infrastructure.
✨Discuss Your DevSecOps Experience
Since the role involves CI/CD and DevSecOps principles, be prepared to share your experiences with these methodologies. Talk about how you've integrated security into the development process and any tools you've used for code scanning or vulnerability management.
✨Prepare for Technical Questions
Expect technical questions related to threat detection, risk assessment, and vulnerability management. Brush up on your knowledge of container technologies and Kubernetes, as well as your experience with identity and access management solutions like Okta or Entra ID.