At a Glance
- Tasks: Join us as a Security Engineer to tackle security incidents and enhance our cyber defence.
- Company: Be part of a dynamic Group IT team in Basingstoke, dedicated to safeguarding digital assets.
- Benefits: Enjoy flexible working options, professional development opportunities, and a collaborative work culture.
- Why this job: Make a real impact on security while growing your skills in a supportive environment.
- Qualifications: Knowledge of security tools, incident management, and network analysis is essential.
- Other info: Ideal for tech-savvy individuals eager to learn and contribute to cutting-edge security solutions.
The predicted salary is between 36000 - 60000 Β£ per year.
Job Description
Security Engineer
Location: Dummer, Basingstoke
Salary: Β£40,000 β Β£50,000
Weβre looking for a Security Engineer to come on board to join our team to lead the technical security function within Group IT Services, ensuring robust protection of systems, data and users. You will be managing the security ticket workload within the Security team and responding to and managing security incidents and alerts. In addition you will provide consultation and expertise on security matters.
Responsibilities:
Security Operations & Incident Management:
- Managing ticket workload within the Security team.
- Gathering, analysing and acting upon threat intelligence.
- Responding to on-going security incidents.
- Responding to active alerts from security systems.
- Writing change management requests for security-related changes.
Vulnerability & Endpoint Management:
- Conducting penetration testing and tracking corrective actions.
- Resolving vulnerabilities in the infrastructure and EUC estate.
- Defining and managing the configuration of endpoint protection policies.
- Managing the configuration of Identity and Access Management services.
Accreditation & Compliance:
- Writing and ratifying policies and ensuring compliance with the Information Security Management System (ISO27001).
- Ensuring compliance with CyberEssentials and CyberEssentials+ requirements and carrying out audits.
- Ensuring compliance with accreditation policies through auditing with external 3rd party auditors.
- Being consulted on project plans and designs in principle.
- Providing security expertise on Change Request Approvals (CAB).
- Being consulted on software deployment from a security perspective.
- Being consulted on endpoint protection matters for infrastructure and EUC.
- Being consulted on identity and access administration matters
Skills Required:
- Strong technical knowledge of security tools, frameworks and best practices.
- Experience with penetration testing and vulnerability management processes.
- Understanding of endpoint protection technologies and policies.
- Knowledge of identity and access management principles.
- Familiarity with security accreditations such as ISO27001, CyberEssentials and CyberEssentials+.
- Excellent incident response and threat intelligence skills.
- Strong communication skills to convey security matters to technical and non-technical audiences.
Benefits:
- 25 Days Holiday
- Birthday Day Off
- Buy Holiday Scheme
- Career Development and Progression Opportunities
- Employee Assistance Programme
- Enhanced Company Sick Pay
- Discounted Retail Vouchers
- Reduced Gym Membership
- SCG Mobile Benefit
- Employee Referral Bonus
- Annual Salary Reviews
- Pension Scheme
- Onsite Canteen (offering free croissants and free freshly made soup daily)
- Free On-Site Parking
- Charity Events
SCG is proud to be an equal opportunities employer.
We welcome applications from all parts of the community and are committed to upholding the principles of the Equality Act 2010.
We are committed to supporting applicants with disabilities. We will endeavour to make necessary adjustments to ensure a fair and accessible recruitment process.
Contact Detail:
SCG Connected Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Security Engineer
β¨Tip Number 1
Familiarise yourself with the specific security tools mentioned in the job description, such as IDS/IPS, SIEM, and vulnerability scanning tools like Nessus. Having hands-on experience or even personal projects showcasing your skills with these tools can set you apart.
β¨Tip Number 2
Network troubleshooting skills are crucial for this role. Brush up on your TCP/IP knowledge and consider taking part in online forums or communities where you can discuss and solve network issues to demonstrate your expertise.
β¨Tip Number 3
Develop a solid understanding of incident response protocols and ITIL disciplines. You might want to create a mock incident response plan or participate in simulations to showcase your ability to handle real-world scenarios effectively.
β¨Tip Number 4
Effective communication is key in this role. Practice explaining complex security concepts in simple terms, as you'll need to engage with various stakeholders. Consider joining local meetups or online webinars to enhance your presentation skills.
We think you need these skills to ace Security Engineer
Some tips for your application π«‘
Tailor Your CV: Make sure your CV highlights relevant experience and skills that align with the Security Engineer role. Focus on your knowledge of IDS/IPS, SIEM tools, and any hands-on experience with security products mentioned in the job description.
Craft a Strong Cover Letter: In your cover letter, express your passion for cybersecurity and detail how your background makes you a suitable candidate. Mention specific projects or experiences that demonstrate your ability to handle security incidents and your understanding of security standards.
Showcase Problem-Solving Skills: Provide examples in your application that showcase your problem-solving abilities, especially in high-pressure situations. Highlight instances where you've made decisions with incomplete information or successfully managed security incidents.
Highlight Communication Skills: Since effective communication is crucial for this role, emphasise your ability to build collaborative relationships and communicate complex security concepts clearly. Include examples of how you've worked with teams or reported on security issues in the past.
How to prepare for a job interview at SCG Connected
β¨Know Your Security Tools
Familiarise yourself with the specific security tools mentioned in the job description, such as IDS/IPS, SIEM, and firewalls. Be prepared to discuss your hands-on experience with these tools and how you've used them in past roles.
β¨Demonstrate Incident Response Skills
Prepare to share examples of how you've handled security incidents in the past. Highlight your decision-making process, especially when dealing with incomplete information, and how you escalated issues to higher management.
β¨Showcase Your Analytical Abilities
Be ready to discuss your approach to analysing logs and identifying potential threats. You might be asked to walk through a hypothetical scenario, so practice explaining your thought process clearly and logically.
β¨Communicate Effectively
Effective communication is key in this role. Practice articulating complex security concepts in simple terms, as you'll need to engage with various stakeholders. Show that you can build collaborative relationships while maintaining accountability.