At a Glance
- Tasks: Conduct penetration testing and assess vulnerabilities in web apps and cloud infrastructure.
- Company: Join a dynamic team focused on cutting-edge cyber security solutions in London.
- Benefits: Enjoy flexible work with 2-3 days on-site, plus opportunities for professional growth.
- Why this job: Make a real impact in cyber security while collaborating with talented developers.
- Qualifications: Experience in penetration testing, security tools, and cloud security is essential.
- Other info: Contract runs until October, with potential for extension based on performance.
The predicted salary is between 43200 - 72000 Β£ per year.
We are currently recruiting for a Cyber Security Engineer to work 2-3 days on-site per week in London for a contract running to the start of October this year - it has not yet been confirmed if extensions would be granted.
Key Responsibilities
- Perform penetration testing and vulnerability assessments of web applications, APIs, and cloud infrastructure.
- Evaluate the automated security tooling into CI/CD pipelines (SAST, DAST, dependency checking, IaC etc), and make necessary recommendations.
- Collaborate with developers to remediate identified vulnerabilities and ensure secure code practices.
- Provide expert input on cloud security (AWS, Azure, or GCP) and DevSecOps tooling.
- Assist in maintaining security assurance.
Essential experience
- Penetration testing, ethical hacking, or vulnerability assessments.
- Security testing tools (eg, Burp Suite, OWASP ZAP, Nikto, Nmap, Metasploit, etc.).
- DevSecOps principles and tools (eg, Veracode, SonarQube, GitHub Advanced Security, IaC scanning, etc.).
- Secure Cloud Infrastructure, specifically AWS and Azure.
- Scripting and automation using Python and Bash.
- Strong communication skills and the ability to explain security issues to technical and non-technical stakeholders.
Certifications
- OSCP or Crest/TIGER Scheme.
Desirable
- Experience delivering assessments under the CHECK scheme (eg, as a CHECK Team Member/Leader).
- Threat modelling and secure design practices.
If you feel you have the skills and experience needed for this role; please do apply now.
Contact Detail:
Parker Shaw Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Cyber Security Engineer - Security Cleared
β¨Tip Number 1
Make sure to brush up on your penetration testing skills and tools like Burp Suite and OWASP ZAP. Being able to demonstrate your hands-on experience with these tools during discussions can really set you apart.
β¨Tip Number 2
Familiarise yourself with DevSecOps principles and the specific tools mentioned in the job description, such as Veracode and SonarQube. Showing that you understand how to integrate security into CI/CD pipelines will be a big plus.
β¨Tip Number 3
Since communication is key, practice explaining complex security concepts in simple terms. This will help you connect better with both technical and non-technical stakeholders during interviews.
β¨Tip Number 4
If you have any relevant certifications like OSCP or those under the Crest/TIGER Scheme, be ready to discuss them in detail. Highlighting your commitment to professional development can make a strong impression.
We think you need these skills to ace Cyber Security Engineer - Security Cleared
Some tips for your application π«‘
Tailor Your CV: Make sure your CV highlights relevant experience in penetration testing, vulnerability assessments, and security tools. Use keywords from the job description to demonstrate that you meet the essential experience criteria.
Craft a Strong Cover Letter: Write a cover letter that showcases your expertise in cloud security and DevSecOps principles. Mention specific projects or experiences that align with the responsibilities outlined in the job description.
Showcase Certifications: Clearly list any relevant certifications such as OSCP or Crest/TIGER Scheme in your application. This will help validate your skills and make your application stand out.
Highlight Communication Skills: Since strong communication skills are essential for this role, provide examples in your application of how you've effectively communicated security issues to both technical and non-technical stakeholders.
How to prepare for a job interview at Parker Shaw
β¨Showcase Your Technical Skills
Be prepared to discuss your experience with penetration testing and the specific tools you've used, such as Burp Suite or Metasploit. Highlight any relevant projects where you successfully identified and remediated vulnerabilities.
β¨Demonstrate Your Cloud Knowledge
Since cloud security is a key aspect of this role, make sure to articulate your understanding of AWS and Azure. Be ready to provide examples of how you've implemented security measures in cloud environments.
β¨Communicate Effectively
Strong communication skills are essential. Practice explaining complex security concepts in simple terms, as you may need to convey these ideas to non-technical stakeholders during the interview.
β¨Prepare for Scenario-Based Questions
Expect scenario-based questions that assess your problem-solving abilities. Think about how you would approach a vulnerability assessment or respond to a security incident, and be ready to walk the interviewer through your thought process.