At a Glance
- Tasks: Lead vulnerability management and enhance endpoint security across a global tech landscape.
- Company: Join Jacobs, a forward-thinking company prioritising cybersecurity and innovation.
- Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
- Other info: Dynamic work environment with a focus on continuous improvement and career advancement.
- Why this job: Make a real impact in reducing cyber risks and enhancing security measures.
- Qualifications: Experience in cybersecurity and strong collaboration skills are essential.
The predicted salary is between 60000 - 80000 £ per year.
Overview
Endpoint Security & Exposure Management Engineer at Jacobs.
This role focuses on reducing cyber risk by managing vulnerabilities, strengthening endpoint controls, and improving visibility across a global technology estate.
Responsibilities
- Lead vulnerability and exposure management activities, ensuring risks are identified, prioritised, and remediated.
- Work closely with technology teams to drive remediation programmes and reduce organisational cyber risk.
- Support and enhance endpoint security capabilities (application control, allowlisting, privilege management, hardening).
- Use data, reporting, and dashboards to provide visibility of cyber exposure and remediation performance.
- Assess emerging vulnerabilities and threats, providing risk‑based recommendations and guidance to stakeholders.
- Act as a trusted security partner across infrastructure, cloud, application, and operational teams.
Qualifications – Required
- Experience in cybersecurity, vulnerability management, security engineering, or endpoint security.
- Strong understanding of risk‑based vulnerability management and remediation prioritisation.
- Experience with vulnerability management platforms (e. g., Tenable, Qualys, Rapid7).
- Experience with Service Now Vulnerability Response or similar remediation workflow platforms.
- Knowledge of endpoint security technologies (application control, privilege management, protection).
- Collaboration and stakeholder engagement skills.
- Ability to translate technical security risks into business outcomes.
Qualifications – Desirable
- Zero Trust implementation experience.
- Exposure to Microsoft Defender for Endpoint, Intune, Active Directory, Entra ID.
- Experience in cloud environments (Azure, AWS, GCP).
- Knowledge of frameworks (NIST, ISO 27001, CIS Controls, Cyber Essentials Plus, NCSC CAF).
- Industry certifications (CISSP, CISM, Security+, GIAC, Microsoft Security, Service Now).
- Technical Skills
- Application control and allowlisting technologies.
- Privilege management solutions.
- Endpoint hardening methodologies.
- Zero Trust security principles.
- Least‑privilege administration.
- Endpoint security architecture.
- Vulnerability assessment and management.
- Exposure management practices.
- Risk prioritisation frameworks.
- Attack surface management.
- Patch and remediation management.
- Security risk analysis.
- Microsoft Windows Server, Windows 11, Linux OS.
- Active Directory, Entra ID, Microsoft Intune.
- Microsoft Defender for Endpoint.
- Cloud platforms (Azure, AWS, GCP).
- Service Now Vulnerability Response.
- Power Shell, Python, API integrations, workflow automation, security reporting and dashboard development.
- Key Competencies
- Strong analytical and problem‑solving skills.
- Excellent stakeholder management and communication.
- Ability to translate technical risk into business impact.
- Strong organisational and prioritisation skills.
- Collaborative approach to remediation and risk reduction.
- Continuous improvement mindset focused on measurable security outcomes.
- Success Measures
- Reduction in privileged access risk.
- Increased endpoint security control coverage.
- Reduction in critical and high‑risk vulnerabilities.
- Improved vulnerability remediation performance and SLA compliance.
- Improved visibility of enterprise cyber exposure.
- Implementation of least‑privilege principles across the endpoint estate.
- Reduction in organisational attack surface and cyber risk.
EEO Statement
Jacobs is an equal opportunity employer.
We are a disability confident employer and will interview disabled candidates who best meet the criteria.
All qualified applicants will receive consideration for employment.
#J-18808-Ljbffr
Endpoint Security & Exposure Engineer in Cardiff employer: Jacobs
At Jacobs, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. Our commitment to employee growth is evident through continuous professional development opportunities and mentorship programmes, ensuring that our team members thrive in their careers while making a meaningful impact on global water quality initiatives. Located in a vibrant environment, we provide a unique chance to engage with high-profile projects that not only challenge the status quo but also contribute to sustainable solutions for communities and ecosystems.