At a Glance
- Tasks: Analyse software designs for security, identify vulnerabilities, and propose solutions.
- Company: Join Motorola Solutions, a global leader in safety technology.
- Benefits: Enjoy competitive salary, bonus schemes, flexible working, and health insurance.
- Other info: Dynamic work environment with excellent career development opportunities.
- Why this job: Make a real impact on community safety through innovative cybersecurity solutions.
- Qualifications: 7+ years in Security Engineering and strong knowledge of Cloud and Container security.
The predicted salary is between 63000 - 77000 £ per year.
Company Overview
At Motorola Solutions, we believe that everything starts with our people. We’re a global close-knit community, united by the relentless pursuit to help keep people safer everywhere. We build and connect technologies to help protect people, property and places. Our solutions foster the collaboration that’s critical for safer communities, safer schools, safer hospitals, safer businesses, and ultimately, safer nations. Connect with a career that matters, and help us build a safer future.
Department Overview
The Senior Software Cybersecurity Engineer will be responsible for analysing software designs and implementations from a security perspective, identifying and proposing remediations to security issues throughout the software development lifecycle (SDLC).
This role is hybrid, with an expectation of being in either the Uxbridge or Edinburgh offices 1 to 2 days a week.
Responsibilities
- Security Design and Implementation
- Perform threat modelling, risk assessments, and architecture reviews to identify and mitigate risk.
- Perform requirements analysis, security audits, and provide detailed mitigation recommendations specifically for Cloud and Container environments.
- Design, review, and enforce Key Management and Identity and Access Management (IAM) controls.
- Support the engineering teams on definition on detailed security requirements to meet compliance requirements and industry best practices.
- Perform security code reviews looking for potential security vulnerabilities.
- Act as a subject matter expert to advise and answer questions from engineering and compliance teams on technical product security matters.
- Security Testing
- Define and oversee the deployment of Software Composition Analysis (SCA) tools to compile SBOMs of software components, helping to identify known vulnerabilities and license compliance violations.
- Define and oversee the deployment of automated security testing tools into CI pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Secret Detection scanning tools.
- Apply a basic level of knowledge and experience in manual network and application security testing to validate controls.
- Write custom scripts or unit test cases to check for vulnerabilities or broken/missing security controls.
- Recommend improvements to existing security scanning tools and processes, and propose new ones.
- Vulnerability Management
- Drive vulnerability management with a strong focus on Kubernetes (K8s) infrastructure and container images.
- Periodically triage the findings from the automated security scanning tools.
- Validate potential security vulnerabilities to determine whether they are actual true positives, or false positives (i.e. non-applicable) in the product context.
- Assess the risk of vulnerabilities and threats in order to help the business determine their remediation priority order.
- Communicate the identified security issues to engineering and compliance stakeholders, and manage them throughout the SDLC process to ensure they are properly addressed.
- SDLC and DevSecOps Integration
- Establish and maintain secure coding standards, baseline product security requirements and more general best practices to provide guidance to development teams.
- Assist the program area with implementing a secure Continuous Integration/Continuous Delivery (CI/CD) pipeline utilizing DevSecOps principles and practices to increase automation.
- Implement automated security controls as part of CI/CD pipelines.
- Incident Response and Compliance
- Support product security incident response processes, including root cause analysis (identify the affected product components, data, and the overall impact level) and definition of mitigation strategies.
- Apply Detection Engineering principles, including the determination of baseline application security parameters and the creation/maintenance of application-level rules for IDS/IPS.
- Define clear criteria and protocols for security incident response, including creation of technical runbooks.
- Conduct post-incident analysis to compile lists of lessons learned, and measures to prevent similar incidents from reoccurring, and refine response strategies.
- Monitor emerging security threats, vulnerabilities, and trends to proactively investigate, remediate, and integrate new protections.
- Ensure products comply with relevant security standards, certifications, and regulations (e.g., OWASP, NIST).
Basic Requirements
- Required Qualifications
- 7+ years of experience in Security Engineering with a focus on product security and/or application security.
- Bachelor’s degree in Computer Science, Information Security, or a related technical field.
- Experience leading cybersecurity process change and mentoring on secure by design principles.
- Partnering with engineering teams to ensure secure coding practices and adoption of industry best practices.
- Proactively monitor emerging security threats, vulnerabilities, and trends to investigate, remediate, and integrate new protections.
- Drive continuous improvement of product security posture by identifying gaps and implementing solutions.
- Technical Skills
- Strong knowledge of Cloud and Container security, including orchestration (e.g. AWS, Azure, Google Cloud, Docker, Kubernetes).
- Vulnerability Management lifecycle experience, specifically for cloud infrastructure and container images.
- Strong understanding of Key Management and IAM controls.
- Proven experience in designing and implementing threat modelling programs (e.g., STRIDE, PASTA, DREAD).
- Exceptional analytical and investigative skills, with hands-on experience in root cause analysis.
- In-depth knowledge of techniques, standards, and state-of-the-art authentication and authorization technologies, applied cryptography, security vulnerabilities and remediations.
- Strong knowledge of web-related protocols and technologies (HTTP, REST APIs), networking protocols (IP, TCP, UDP), and security protocols (TLS).
- Significant software development experience. Experience in Go and C#.
- Strong knowledge of security principles, best practices, and industry standards, such as NIST, ISO 27001, and CIS Critical Security Controls, OWASP ASVS and Testing Guides.
- Experience designing and implementing processes to integrate SCA, SAST, DAST, IAST, and RASP tooling as part of the SDLC and driving adherence.
- Experience with CI/CD pipeline, security tools integration.
- Experience with defining and enforcing technical security standards and controls.
- Desirable Qualifications
- Deep vulnerability analysis, research, and development of exploits to validate findings.
- Background in Web Application security.
- Advanced manual penetration testing skills in the domains of cloud infrastructure, web applications, embedded/OS, or mobile.
- Familiarity with security considerations for AI/ML systems is desirable.
- Understanding of distributed systems design, implementation and operation.
- Understanding of privacy threats and controls, including on how to adapt generic best practices to specific scenarios in the product by providing detailed specifications to stakeholders.
- Experience with SIEM, enterprise log collection and analysis platforms (e.g., Splunk, OSQuery).
- Education and Certifications
- Master's degree or equivalent experience preferred.
- Cloud focus security certifications is a strong plus, especially CCAK, CCSP, AWS Certified Security - Specialty.
- Additional certifications are also relevant including OSCP, SANS/GIAC, CCSP, and CISSP.
- Soft Skills and Leadership
- Excellent verbal and written communication, with the ability to translate complex security concepts to technical and non-technical stakeholders.
- Demonstrated ability to design, document, and implement new security processes.
- Experience in a high-growth technology environment or SaaS business.
- Ability to remain calm under pressure, especially during incidents or audits.
In return for your expertise, we’ll support you in this new challenge with coaching & development every step of the way. Also, to reward your hard work you’ll get:
- Competitive salary and bonus schemes
- Two weeks additional pay per year (holiday bonus)
- 25 days holiday entitlement + bank holidays
- Attractive defined contribution pension scheme
- Private medical insurance
- Employee stock purchase plan
- Flexible working options
- Life assurance
- Enhanced maternity and paternity pay
- Career development support and wide ranging learning opportunities
- Employee health and wellbeing support EAP, wellbeing guidance etc.
- Carbon neutral initiatives/goals
- Corporate social responsibility initiatives including support for volunteering days
- Well known companies discount scheme
Travel Requirements
Under 10%
Relocation Provided
None
Position Type
Experienced
Referral Payment Plan
Yes
Company
Motorola Solutions UK Limited
EEO Statement
Motorola Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion or belief, sex, sexual orientation, gender identity, national origin, disability, veteran status or any other legally-protected characteristic. We are proud of our people-first and community-focused culture, empowering every Motorolan to be their most authentic self and to do their best work to deliver on the promise of a safer world. If you’d like to join our team but feel that you don’t quite meet all of the preferred skills, we’d still love to hear why you think you’d be a great addition to our team.
Summary
Location: United Kingdom Offsite (ZUK99); Edinburgh, UK (ZUK126)
Type: Full time
Senior Software Cybersecurity Engineer in Edinburgh employer: Indigo Vision
At Motorola Solutions, we pride ourselves on being a people-first employer, fostering a collaborative and inclusive work culture that empowers our employees to thrive. As a Commercial Manager, you'll enjoy competitive benefits, including flexible working options, comprehensive health support, and extensive career development opportunities, all while contributing to meaningful projects that enhance public safety across the UK. Join us in our mission to build a safer future and be part of a team that values your expertise and growth.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Software Cybersecurity Engineer in Edinburgh
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Indigo Vision, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Indigo Vision
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Indigo Vision. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Software Cybersecurity Engineer in Edinburgh
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Indigo Vision insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Indigo Vision that you’re committed to staying ahead in the game.
How to prepare for a job interview at Indigo Vision
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Indigo Vision to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Indigo Vision.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.