At a Glance
- Tasks: Lead security projects, enhance infrastructure security, and respond to incidents.
- Company: Mattermost, a trusted platform for secure collaboration in critical sectors.
- Benefits: Fully remote work, competitive salary, equity, and meaningful impact.
- Other info: Open to diverse backgrounds; we value your unique perspective.
- Why this job: Shape security strategy and work with cutting-edge technology in a global team.
- Qualifications: 3+ years in security engineering, experience with SIEM and EDR tools.
The predicted salary is between 60000 - 80000 ÂŁ per year.
Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure. Trusted by the U.S. Department of War and Fortune 500s, our platform runs on-premises and in private clouds, delivering secure messaging, file sharing, workflow automation, audio/screenshare, and project management—all with full data and operational control. Mattermost powers high‑stakes workflows across mission planning, real‑time, real‑world operations, DevSecOps, incident response, and cyber defense—enabling secure collaboration from tactical edge and DDIL environments to enterprise HQ.
Why Join Mattermost
- Fully remote, globally distributed team | no commute, genuine flexibility
- Be a key voice in shaping and delivering security strategy
- Competitive salary, equity, and benefits with meaningful work attached
The Role
As a Senior Security Engineer, you will lead the design and implementation of security tooling, harden our cloud and IT infrastructure, and serve as a key responder to incidents. You will work across a globally distributed team and partner closely with Engineering to manage AI‑enabled risk.
Key Responsibilities
- Lead security and IT projects to enhance the security posture of infrastructure and the company
- Detect, investigate, and remediate security incidents using SIEM, EDR, and SOAR tooling (e.g. CrowdStrike, SentinelOne)
- Conduct threat hunting across cloud and endpoint environments using a Zero Trust framework
- Administer company‑wide IAM and security monitoring infrastructure
- Contribute to security policies, incident response, forensics, and endpoint management programmes
- Partner with Engineering to assess and mitigate risks from AI‑enabled tools and workflows
- Explore and implement AI/automation in detection, analysis, and response pipelines
- Engage closely with North American and international staff across time zones
Required Background & Skills
- Bachelor’s degree in Computer Science or a related field, or significant professional security experience
- 3+ years of hands‑on experience in security engineering and incident response
- Experience with SIEM platforms and security monitoring systems
- Experience with EDR tools such as CrowdStrike or SentinelOne
- Knowledge of SOAR platforms and automation of security workflows
- Familiarity with Zero Trust architecture principles and threat hunting methodologies
- Experience with cloud security controls across AWS, GCP, and/or Azure
- Strong knowledge of Linux systems and Kubernetes/Docker environments
- Experience with IAM solutions and infrastructure automation
- Practical experience evaluating security implications of AI systems and AI‑assisted workflows
- Experience managing security of Microsoft 365 and Google Workspace tenants
- Excellent written and verbal communication skills
Preferred Background & Skills
- Experience with certification processes: SOC2, ISO 27001, FedRAMP, or Cyber Essentials Plus
- Certifications: OSCP, GCIH, GCFA, or equivalent penetration testing / incident response credentials
- Experience in Go or Python
- Background in open‑source communities
- Endpoint security management experience in a fully remote organisation
This role may involve access to information subject to U.S. export control regulations (EAR/ITAR). Applicants should be aware that eligibility requirements may apply. We encourage candidates with questions about this to reach out. Many UK‑based security professionals with defence backgrounds will qualify. We are happy to discuss your specific situation.
Mattermost is an EEO Employer, we are a remote‑first, open‑source company. Mattermost values your unique perspective—we welcome all applicants. We encourage individuals from all backgrounds to apply and are committed to assessing candidates based on their skills and qualifications. We do not tolerate discrimination against staff or applicants based on race, religion, national origin, age, disability, pregnancy status, veteran status, or other personal characteristics. If you require accommodations during the interview process, please let us know—we’re happy to assist.
Senior Security Engineer United Kingdom employer: Mattermost, Inc.
Contact Detail:
Mattermost, Inc. Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Engineer United Kingdom
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, especially those already at Mattermost. A friendly chat can open doors and give you insider info on what it’s really like working there.
✨Tip Number 2
Show off your skills in real-time! Consider participating in hackathons or security challenges. This not only sharpens your abilities but also gives you something tangible to discuss during interviews.
✨Tip Number 3
Prepare for those tricky interview questions! Brush up on your knowledge of SIEM, EDR tools, and Zero Trust principles. We want to see how you think on your feet and tackle security challenges.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team.
We think you need these skills to ace Senior Security Engineer United Kingdom
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Senior Security Engineer role. Highlight your relevant experience with security engineering, incident response, and any specific tools mentioned in the job description. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about security and how your background makes you a great fit for Mattermost. Don’t forget to mention any experience with cloud security or AI-enabled tools, as these are key for us.
Showcase Your Communication Skills: Since excellent written communication is crucial for this role, make sure your application is clear and concise. Use professional language but keep it friendly—show us your personality while maintaining professionalism. We love a good balance!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about our company culture and values!
How to prepare for a job interview at Mattermost, Inc.
✨Know Your Security Tools
Familiarise yourself with the specific security tools mentioned in the job description, like SIEM, EDR, and SOAR platforms. Be ready to discuss your hands-on experience with these tools and how you've used them to detect and respond to incidents.
✨Understand Zero Trust Principles
Since the role involves threat hunting using a Zero Trust framework, make sure you can explain what Zero Trust means and how it applies to security engineering. Prepare examples of how you've implemented or worked within a Zero Trust architecture in past roles.
✨Showcase Your Cloud Security Knowledge
With cloud security being a key focus, brush up on your knowledge of AWS, GCP, and Azure security controls. Be prepared to discuss any relevant projects where you enhanced security in cloud environments, as well as your understanding of IAM solutions.
✨Communicate Clearly and Confidently
Excellent communication skills are essential for this role. Practice articulating your thoughts clearly, especially when discussing complex security concepts. Use examples from your experience to demonstrate your ability to communicate effectively with both technical and non-technical stakeholders.