At a Glance
- Tasks: Join our Cyber Security team to manage and optimise critical security platforms.
- Company: Laing O'Rourke is a leading international engineering and construction company with over 150 years of experience.
- Benefits: Enjoy flexible working options and a supportive environment focused on accessibility.
- Why this job: Be part of transforming the construction industry while enhancing your cyber security skills in a dynamic team.
- Qualifications: 5+ years in IT, with 3 years in operational environments; knowledge of security protocols is essential.
- Other info: Office-based role in Dartford; we support candidates with disabilities through our interview scheme.
The predicted salary is between 36000 - 60000 £ per year.
Be part of transforming the construction industry, be part of our Cyber Security team. Do you want to be part of something different? At Laing O'Rourke we have an opportunity for a Cyber Security Technical Specialist to join the team. Are you able to support comprehensive Cyber Security programs whilst optimising the operational performance and reliability of Infrastructure technologies? Then we need your expertise in controls and activities for the effective management of critical cyber security platforms.
Are you skilled with Privilege Access management, Application Control and Data Loss Prevention solutions? Then we need you to help optimise performance and ensure compliance to our cyber security certification requirements. This position requires a deep understanding of security protocols, risk management, and the ability to proactively identify and mitigate potential threats to the business, whilst delivering cyber security with a service mindset. You will work closely with cross-functional teams from infrastructure and network support analysts across the business units to ensure the integrity and security of our applications and data.
Key accountabilities include:
- Keeping abreast of potential and emerging cyber security threats, vulnerabilities, and control techniques and the trade-offs required to manage the different levels of risk appetite and risk exposure across the business.
- Focused on day-to-day operational tasks and maintenance of core Cyber Security infrastructure service platforms, including but not limited to:
- Manage and administer the Privileged Access Management (PAM) platform, including user access, permissions, audits and configurations.
- Collaborate with IT and business teams to integrate and expand PAM controls into existing systems and applications.
- Manage and administer the Application Control platform, including policy configuration, rule creation, and software whitelisting/blacklisting to prevent unauthorized software installations and executions.
- Collaborate with IT teams to integrate Application Control mechanisms into existing systems and processes.
- Work with cyber analysts and engineers to maintain and optimise other cyber security platforms and tools to improve performance and end-user experience.
- Develop processes and procedures to manage, monitor and improve performance, reliability, recovery, capacity and user experience of cyber security controls.
- Work with IT stakeholders to implement and test cyber security controls to ensure compliance with DR and BCP policies and scenarios.
- Working with the Cyber and Infrastructure Engineering team to form SME relationships.
- To implement security best practices as directed by the Cyber Security Tech Ops Lead, Cyber Security Architect and Engineering teams.
- Responsible for the quality and response time of support tickets.
- Ensure knowledge and information are documented and passed to the relevant Service delivery teams.
- Research and assess new threats and security alerts and recommend remedial actions.
- Play an active part in responding to and resolving security incidents (Prepare, Identify, Contain, Remediate, Recover).
- Work with key suppliers, partners and vendors to drive maximum value and security benefits from security services and solutions.
- Work with Cyber Security leadership to develop plans to enforce security requirements and address identified risks.
You will need knowledge of Infrastructure and Cyber Security principles being able to create and develop operational processes. Part of the role is to develop and maintain technical documentation, procedures, guidelines, and training. This means keeping a service management mindset to provide support and guidance to IT teams for best practice.
Do you have experience in Security Incident Management tools (SIEM)? How about demonstrating excellent knowledge of security technologies, enterprise systems and cloud solutions? Then join our Cyber Security team and showcase your knowledge of regulation standards, compliance and governance.
Essential experience includes:
- Around 5 years+ experience in IT including circa 3 years in an operational environment.
- Knowledge of best practices of IT security hardware and software, security suites, identity and access management, and encryption.
- Experience in configuring and managing PAM solutions in enterprise environments.
- Familiarity with identity and access management (IAM) principles, including role-based access control (RBAC) and least privilege.
- Strong understanding of Application Control concepts, tools, and technologies (e.g., whitelisting, blacklisting, application allowlisting).
- Experience in configuring and managing Application Control solutions in enterprise environments preferred.
- Understanding of security frameworks such as NIST, CIS Controls, or ISO 27001.
- Formal industry recognised Cyber Security qualification such as ISC2 CISSP, ISC2 CISM or Certified Ethical Hacker (CEH) (desired).
- Security and Network technology experience.
The position will require time in our Dartford office, due to the nature of the work and sensitive sites we work on; this is an office-based position. Need flexibility? Talk to the team about your current circumstances.
About us: We are an international engineering and construction company delivering state-of-the-art infrastructure and buildings projects for clients in the UK, Middle East and Australia. Certainty, reliability, quality – this is what our clients want. And at Laing O'Rourke, we have more than 150 years of experience delivering it. Laing O'Rourke's story is one of energy, passion, ambition, people and teamwork. We harness the power of our experience, stretching back over a century and a half to deliver certainty for our clients.
As part of the Disability Confident scheme, we would like to enable access to candidates with long-term health conditions and disabilities through the ‘Offer an interview scheme’. This supports applicants that meet the essential criteria by offering an interview for the advertised position. Please let us know prior to interview what adjustments are required as well as discussing how we can support you in the workplace. We want to ensure our recruitment process is accessible to all. If you need the application form in an alternative format or you would like to know more about our recruitment process, please email resourcingteam@laingorourke.com.
Cyber Security Technical Specialist employer: Laing O'Rourke
Contact Detail:
Laing O'Rourke Recruiting Team
resourcingteam@laingorourke.com
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Technical Specialist
✨Tip Number 1
Familiarise yourself with the latest trends in cyber security, especially around Privileged Access Management and Application Control. Being able to discuss recent developments or case studies during your interview can demonstrate your proactive approach and genuine interest in the field.
✨Tip Number 2
Network with professionals in the cyber security industry, particularly those who work in operational roles. Attend relevant meetups or webinars to build connections and gain insights that could be beneficial during your application process.
✨Tip Number 3
Prepare to showcase your problem-solving skills by thinking of examples where you've successfully identified and mitigated security threats in previous roles. This will help you illustrate your hands-on experience and ability to handle real-world challenges.
✨Tip Number 4
Research Laing O'Rourke's projects and values to align your answers with their mission. Understanding their approach to cyber security and how it fits into their overall business strategy can give you an edge in the interview.
We think you need these skills to ace Cyber Security Technical Specialist
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in cyber security, particularly focusing on Privileged Access Management and Application Control. Use specific examples that demonstrate your skills and achievements in these areas.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for cyber security and your understanding of the role. Mention how your experience aligns with the key accountabilities listed in the job description, and express your enthusiasm for joining Laing O'Rourke's Cyber Security team.
Highlight Relevant Qualifications: If you have any formal industry-recognised qualifications such as CISSP or CEH, make sure to mention them prominently in your application. This will demonstrate your commitment to the field and your expertise in cyber security.
Showcase Your Problem-Solving Skills: In your application, provide examples of how you've proactively identified and mitigated potential threats in previous roles. This will illustrate your ability to handle the responsibilities outlined in the job description effectively.
How to prepare for a job interview at Laing O'Rourke
✨Understand Cyber Security Fundamentals
Make sure you have a solid grasp of key cyber security concepts, especially those related to Privileged Access Management and Application Control. Be prepared to discuss how these principles apply to real-world scenarios and how they can be optimised in an operational environment.
✨Showcase Your Experience
Highlight your relevant experience, particularly the 5+ years in IT and 3 years in an operational role. Be ready to provide specific examples of how you've managed security incidents or implemented security controls in previous positions.
✨Familiarise Yourself with Security Frameworks
Brush up on security frameworks like NIST, CIS Controls, or ISO 27001. Understanding these frameworks will not only help you answer questions but also demonstrate your commitment to best practices in cyber security.
✨Prepare for Technical Questions
Expect technical questions related to security technologies, incident management tools, and cloud solutions. Practise explaining complex concepts in simple terms, as you may need to communicate these ideas to cross-functional teams.