At a Glance
- Tasks: Secure our financial platforms and infrastructure while collaborating with teams.
- Company: Join a leading financial services firm focused on security and compliance.
- Benefits: Enjoy hybrid working, competitive salary, and professional development opportunities.
- Why this job: Make a real impact in securing critical systems and applications.
- Qualifications: 4+ years in security engineering with expertise in application, systems, and network security.
- Other info: Flexible work environment with strong career growth potential.
The predicted salary is between 36000 - 60000 Β£ per year.
Location: Hybrid (Mix of home and office work - e.g., 2-3 days in office)
Reporting To: Chief Information Security Officer (CISO)
Employment Type: Full-time, Permanent
Interfaces with: PCA employees at all levels, Clients, Suppliers & Stakeholders
Overview
We are seeking a highly skilled and proactive Security Engineer to join our Information Security team. This role is fundamental to maintaining the security posture of our critical financial platforms and infrastructure. The successful candidate will be a hands-on technical expert responsible for securing our assets across the full spectrum of Application, Systems, and Network domains. Given the nature of our work, a strong adherence to UK financial regulations (FCA) and data protection laws (GDPR) is paramount. This position offers a hybrid working model, providing flexibility while ensuring effective collaboration with the CISO and broader teams.
Key Responsibilities
- Application Security Engineering (AppSec)
- Secure Development Lifecycle (SDLC): Integrate security tools and processes into the CI/CD pipelines (DevSecOps), ensuring security is "shifted left."
- Vulnerability Management: Manage and execute Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) on proprietary applications.
- Remediation & Guidance: Act as the primary security resource for development teams, providing technical advice on vulnerability fixes and secure coding practices (e.g., adherence to the OWASP Top 10).
- Threat Modeling: Conduct formal threat modeling exercises for new features and application architectures to proactively identify and mitigate design flaws.
- Secure Baselines: Define, implement, and audit secure configuration standards for all corporate systems, including servers (Windows/Linux), cloud resources (AWS, Azure), and critical databases, ensuring compliance with CIS Benchmarks or equivalent standards.
- Endpoint Security: Deploy, manage, and optimize Endpoint Detection and Response (EDR) solutions and host-based firewalls to enhance visibility and defensive capabilities.
- Identity & Access Management (IAM): Engineer and govern the secure configuration of IAM services, including Multi-Factor Authentication (MFA), Single Sign-On (SSO), and Privileged Access Management (PAM) tools.
- Patch & Vulnerability Management: Oversee the technical operation of the enterprise vulnerability scanning program, working with IT Operations to prioritize and track remediation of system and software vulnerabilities.
- Firewall Management: Design, implement, and maintain complex rule sets and policies on Next-Generation Firewall (NGFW) platforms, managing network segmentation, site-to-site VPNs, and secure remote access.
- Intrusion Detection/Prevention (NIPS): Configure and tune Network Intrusion Prevention Systems (NIPS) and Intrusion Detection Systems (IDS) to actively block and alert on malicious network traffic and policy breaches.
- Security Tool Implementation: Lead the research, deployment, and operationalisation of new network and cloud security tooling, ensuring full integration with our Security Information and Event Management (SIEM) system.
- Architecture Review: Conduct security reviews of network diagrams and proposed infrastructure changes to ensure secure deployment prior to production release.
Required Skills and Experience
- Professional Experience: Proven experience (typically 4+ years) in a security engineering role, with demonstrable expertise across Application, Systems, and Network security domains and associated technology controls.
- Industry Knowledge: Previous experience working within the UK financial services, banking, or highly regulated industry.
- Compliance: Excellent working knowledge of UK and EU regulatory requirements, and Exposure to βCyber Essentials plusβ.
- Technical Stack: Expertise in managing and troubleshooting enterprise-grade firewalls (e.g., Palo Alto, Fortinet, Cisco ASA). Strong familiarity with cloud security frameworks and tools (e.g., AWS Security Hub, Azure Security Center). Hands-on experience with scripting for automation (Python, PowerShell, Bash).
- Reporting: Ability to communicate complex technical security risks and compliance gaps effectively to the CISO.
Desirable Qualifications
- Relevant industry certifications (e.g., CISSP, CISM, SSCP).
- Cloud-specific security certification (e.g., AWS Certified Security β Specialty, Microsoft Azure Security Engineer Associate).
- Certifications related to specific technologies, such as PCNSE, CCNP Security, or GIAC.
- Experience with Infrastructure as Code (IaC) security scanning tools (e.g., Checkov, Terrascan).
Work Arrangement and Benefits
This role operates under a flexible hybrid model, requiring attendance at our Manchester or Liverpool, UK office for essential collaboration meetings (e.g., 2-3 days per week) with the remainder of the time working remotely.
Security Engineer in Manchester employer: Phillips & Cohen Associates, Ltd.
Contact Detail:
Phillips & Cohen Associates, Ltd. Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Security Engineer in Manchester
β¨Tip Number 1
Network, network, network! Get out there and connect with people in the industry. Attend meetups, webinars, or even just chat with folks on LinkedIn. You never know who might have a lead on your dream Security Engineer role!
β¨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to security engineering. This gives potential employers a taste of what you can do and sets you apart from the crowd.
β¨Tip Number 3
Prepare for interviews like a pro! Research common security engineering interview questions and practice your responses. Be ready to discuss your experience with tools like firewalls and cloud security frameworks, as well as your approach to vulnerability management.
β¨Tip Number 4
Donβt forget to apply through our website! Weβre always on the lookout for talented individuals like you. Plus, itβs a great way to ensure your application gets the attention it deserves.
We think you need these skills to ace Security Engineer in Manchester
Some tips for your application π«‘
Tailor Your CV: Make sure your CV is tailored to the Security Engineer role. Highlight your experience in Application, Systems, and Network security, and donβt forget to mention any relevant certifications. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why youβre passionate about security engineering and how your background makes you a perfect fit for our team. Keep it concise but impactful β we love a good story!
Showcase Your Technical Skills: In your application, be sure to showcase your technical expertise, especially in areas like vulnerability management and secure coding practices. Mention specific tools and frameworks youβve worked with, as this will help us understand your hands-on experience.
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. Itβs super easy, and youβll be able to keep track of your application status. Plus, we love seeing applications come directly from our site!
How to prepare for a job interview at Phillips & Cohen Associates, Ltd.
β¨Know Your Stuff
Make sure you brush up on your technical knowledge, especially around Application, Systems, and Network security. Be ready to discuss specific tools and processes like DevSecOps, SAST, and DAST, as well as your experience with firewalls and cloud security frameworks.
β¨Understand the Regulations
Familiarise yourself with UK financial regulations such as FCA and GDPR. Be prepared to explain how you've ensured compliance in previous roles and how you would apply that knowledge in this position.
β¨Showcase Your Problem-Solving Skills
Prepare to discuss past experiences where you've identified vulnerabilities or security risks and how you addressed them. Use the STAR method (Situation, Task, Action, Result) to structure your answers effectively.
β¨Ask Insightful Questions
At the end of the interview, donβt shy away from asking questions about the team dynamics, the tools they use, or their approach to security challenges. This shows your genuine interest in the role and helps you gauge if itβs the right fit for you.