Security Engineer

Security Engineer

Full-Time 50000 - 65000 £ / year (est.) Home office (partial)
Nucleus Group

At a Glance

  • Tasks: Design and implement security controls to protect our systems and manage risks.
  • Company: Join Nucleus, a forward-thinking company prioritising people and collaboration.
  • Benefits: Enjoy flexible working, health initiatives, and a non-contributory pension.
  • Other info: Be part of a diverse team that values inclusion and cultural contribution.
  • Why this job: Make a real impact in a fast-paced environment while ensuring security.
  • Qualifications: Knowledge of security best practices and strong communication skills required.

The predicted salary is between 50000 - 65000 £ per year.

We're on the lookout for a Security Engineer to join Nucleus' Information Security team, to help ensure that we are secure by design.

About the role

The Security Engineer supports the delivery of Nucleus’s technology and business change agendas by designing and implementing appropriate controls that manage the associated security risks. This will include designing and implementing technical controls, helping to embed these controls into our operations, and validating the controls are working effectively. The Security Engineer must be able to manage relationships with teams across Nucleus to collaborate on improvements; and any outsource partners involved in delivery.

The Information Security team aims to make sure that Nucleus is a trusted partner to the firms and people we work with. Being able to demonstrate that our systems are secure, through a structured control environment, is a core component of building that trust. This role is critical to delivering that outcome: being a go-to contact for implementing security controls; being ‘hands on’ with their implementation; and validating that controls are working as intended through technical assessments to identify opportunities for continuous improvement, operating within our existing frameworks and standards.

You’ll work with SMEs across Nucleus, you’ll ensure that new processes and controls are handed over to the Security Operations team, and that the Information Security Analysis team have suitable evidence to demonstrate that our risks are effectively managed.

Responsibilities

  • Apply security best practice in our change and development programmes, to ensure delivery is within our risk appetites.
  • Design and implementation of security controls, following industry best practices and Nucleus standards, to manage the risks Nucleus is exposed to.
  • Engage and influence cross-functional stakeholders to produce remediation plans for identified vulnerabilities in line with Nucleus’ risk appetites.
  • Maintain systems and integrations that enable these controls.
  • Coordinate on security controls within other members of the Nucleus Group, to ensure Nucleus has an end to end understanding of our exposures and capabilities.
  • Support Audit and Due Diligence activities to help demonstrate Nucleus’s capabilities.
  • Work with Security Operations and Analysis to adopt and maintain standards that ensure Nucleus continues to manage our security risks effectively.
  • Take responsibility in everything you do to deliver good outcomes for our customers.
  • Positively demonstrate the Nucleus Smart, Heart and Courage values and behaviours.
  • Ensure compliance with Code of Conduct at all times.

Our key Security tools currently include: Tenable, Rapid7 InsightIDR, Microsoft 365 with Security and Compliance features, supporting Microsoft, Azure and AWS ecosystems.

About you

Your friends might describe you as ‘the methodical one’. You love to look at how everything fits together to see the bigger picture, identifying where things can go wrong, and putting pragmatic solutions in place to catch them before they happen. You’ll enjoy working within a fast-paced environment that gives you the opportunity to multi-task within set deadlines. Professional with a positive outlook, you’ll take great pride in your ability to act on your own initiative and remain flexible in changing circumstances and priorities. You’ll also enjoy working as part of a diverse and supportive team, collaborating with your colleagues to share ideas and knowledge and suggest improvements.

At Nucleus, we’ve always placed high value in cultural contribution and growing our diversity of thought, over technical capability. But it would be great if you had some of the following:

  • Good knowledge of best practice in security capabilities, frameworks and concepts.
  • Able to identify effective implementation and test plans, and deliver those through either in-house capabilities or by working with external providers, and demonstrate how they help manage Nucleus’ risks.
  • An excellent communicator, able to discuss security effectively with areas of the business.
  • A good level of Information Security experience, preferably within financial services.
  • Strong knowledge of IT, Infrastructure and Networking concepts.
  • Significant experience maintaining the systems and integrations that enable security controls.
  • Experience working with cloud platforms such as Microsoft Azure and AWS, including operating and maintaining security controls and responding to findings from cloud security posture or workload protection tooling.
  • Able to understand other people’s views and provide appropriate challenges to ensure our Information Security risks are effectively managed.
  • Ownership of tasks, attention to detail and following through to conclusion.
  • Ability to prioritise and remain agile with competing work demands.
  • Excellent attention to detail.

A little about us

We are the Nucleus Group Services Limited and we help make retirement more rewarding. Here at Nucleus, people come first - whether it’s our colleagues, or the advisers and customers we support, we know that working in partnership and collaboration leads to the best outcomes. Together, we’ve shaped the platform to how it is today. We work hard, and we celebrate hard too.

Our ambition is to create a platform with a difference, putting the customer centre stage meant tearing up the rule book and starting from scratch. We’ve come a long way since then, but our mission remains just as focused. That’s why our culture, values, and social responsibility are things we keep at the top of our agenda – because we know they matter and have a big impact.

Our culture is one of the many things that sets us apart from the pack. We want to have an environment where our people feel that they can make a real difference, know they’ll be rewarded for their efforts and more importantly, enjoy themselves at work.

Are we a perfect match? Check out this video and find out!

Inclusion and diversity at Nucleus

As with most things in life, who cares, wins. We really care about inclusion. For us it’s not a tick box exercise; inclusion and diversity are embedded in our culture and everything we do. It’s a commercial imperative. It isn’t about being PC. It’s about being future-relevant and durable. We owe it to ourselves and the industry to ensure we are playing our part in creating a fair, balanced and transparent financial services sector.

More diversity means broader experience, a wider set of perspectives and a better collective ability to problem-solve. And it means being more representative of customer groups, which supports areas such as product development.

At Nucleus, we offer a generous blend of benefits for the things that really matter to our people, including a non-contributory pension, bonus, enhanced parental leave, paid time off for emergencies, health and wellbeing initiatives and flexible working options.

If you’d like to find out more about us or the role, please get in touch with our recruitment team.

Security Engineer employer: Nucleus Group

At Nucleus, we pride ourselves on being an exceptional employer that prioritises our people and their growth. Our collaborative work culture fosters innovation and inclusivity, ensuring that every team member feels valued and empowered to make a difference. With a comprehensive benefits package, including flexible working options and a strong commitment to health and wellbeing, we create an environment where you can thrive both personally and professionally while contributing to our mission of making retirement more rewarding.

Nucleus Group

Contact Details:

Nucleus Group Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineer

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Nucleus Group, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Nucleus Group

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Nucleus Group. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Engineer

Security Best Practices
Technical Control Design and Implementation
Cross-Functional Stakeholder Engagement
Vulnerability Remediation Planning
Systems Maintenance
Audit and Due Diligence Support
Cloud Security Management

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Nucleus Group insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Nucleus Group that you’re committed to staying ahead in the game.

How to prepare for a job interview at Nucleus Group

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Nucleus Group to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Nucleus Group.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.