At a Glance
- Tasks: Own security across our estate and collaborate with engineering teams for secure design.
- Company: Join Surevine, a leader in secure collaboration solutions for sensitive information.
- Benefits: Flexible working, professional development support, and a collaborative environment.
- Other info: Inclusive culture with diverse perspectives and clear mentorship opportunities.
- Why this job: Make a real impact on security while growing your skills in a dynamic team.
- Qualifications: 3-5 years in security or related tech roles; curiosity and willingness to learn are key.
The predicted salary is between 45000 - 55000 £ per year.
Surevine's mission is to build and deliver secure, scalable, collaboration solutions for the most security conscious organisations, enabling collaboration on their most highly sensitive information. Our customers trust us with their most sensitive information. That trust has to be earned twice: in how we build our products, and how we run ourselves.
This is a new role. Your first job is to take ownership of security across our own estate — our corporate services, our cloud environments and the standards we hold ourselves to. Your second is to work alongside our engineering teams so that what we build for customers is secure-by-design. You'll do both by getting into the detail of how we engineer, not by writing policy about it.
We are not expecting you to arrive able to do all of this. This is a role with room to grow into, and we would rather hire someone with the right foundation and appetite than wait for someone who ticks every box.
Security in Surevine
We are a small company, so this is a broad job rather than a narrow one. You will move between looking after our own estate, working alongside our engineering teams on the security of what we build and over time, working directly with customers. ISO 27001, Cyber Essentials, Cyber Essential Plus, Defence Cyber Certification and the standards our sector demands are real and they matter. But we want them woven into how we work rather than bolted on afterwards. If your instinct when you see a gap is to write a procedure, this isn't the role. If your instinct is to work out what would actually close it and then help get that change made, it just might be.
There is a path into client-facing work as you grow into the role. Our customers in government, defence and critical national infrastructure need help with secure design, security architecture, assurance evidence and integrating with their own security operations. This isn't where you'll start: the first job is our own house. But if being in the room with a customer and producing work that goes to their security authority with our name on it is somewhere you want to get to, even better.
We are actively using AI tools across our development work and inside the business. That changes the security picture; new data handling questions, new governance questions that nobody has settled answers to yet. We want someone curious about that rather than defensive.
What you will be doing
- Take ownership of security across our corporate estate — our SaaS applications, our identity provider, our endpoints and our AWS-hosted environments — driving the plan and getting stuck into the work alongside our InfraCare team.
- Make our ISO27001 and Cyber Essentials obligations business-as-usual; automated where it can be and evidenced as a by-product of how we work.
- Help us build the visibility we need: logging, monitoring and alerting good enough that we find out about problems ourselves rather than being told about them.
- Take part in security reviews and help our engineers run their own.
- Play a leading role when something goes wrong: running the process, knowing when to escape, and liaising with clients, internal teams and support partners.
- Advise our engineering teams on the security of what we build; contributing to design workshops, challenging assumptions early, and helping teams reach good security decisions without stalling delivery.
- Own our security risk picture and make it useful: understood by the board, owned by the people who can act on it, and reviewed often enough to mean something.
- Be the person who answers hard security questions from customers, prospects and their assurance teams — security questionnaires, supplier assessments, and the evidence behind our claims.
The environment you will be working in
We don't expect experience across all of this. We do expect curiosity about it.
- Our corporate estate: Google Workspace, SaaS applications, endpoints, identity and access management.
- Our cloud platforms: AWS, GCP, containerised workloads.
- Our delivery tooling: GitLab CI/CD, Terraform and Pulumi.
- Our products, built in Typescript, Python and Java, deployed to customer environments including some that are highly restricted.
- AI-assisted development tooling across our engineering teams, and AI tooling across the wider business.
How we will support you
We know we are asking for range, and that nobody arrives with all of it. We will back you with:
- Time and budget for structured learning and professional certification.
- Working alongside our InfraCare team, who know our estate inside out.
- External specialist support where it makes sense, particularly around certification and assessment.
- Direct access to our CISO, who has been carrying much of this thinking so far.
- Clear agreement, up front, on what we expect you to own in year one and what can wait.
About you
We value diverse thinking styles and backgrounds. You don't need to match every point below perfectly; we are interested in your overall fit and potential.
- 3-5 years experience in security, security risk, or a related technology role.
- Working knowledge of ISO 27001, Cyber Essentials and comparable frameworks as a practitioner who has implemented controls, not only assessed them.
- Some exposure to cloud and SaaS security; identity and access management, logging, configuration hardening etc. and an appetite to take that further.
- Comfortable thinking about security risk end to end; spotting it, getting it owned by the right person, tracking what happens next, and reporting it honestly to people who will act on it.
- Credible with engineers. You will be advising people who build secure systems for a living, so you need to be curious about how they work and specific about what you're asking for.
- Comfortable facilitating a room; design workshops, threat modelling sessions, risk reviews.
- Able to explain security trade-offs to engineers, to executives and to customers, and to adjust the explanation for each.
- Security-conscious pragmatism. We need someone who can tell the difference between a risk worth stopping for and a risk worth documenting and moving past.
- Able to communicate effectively in a remote environment through written and verbal channels. We accommodate different communication preferences and styles, and value clarity over any particular communication approach.
Working at Surevine
We're committed to building an inclusive environment where diverse perspectives and working styles strengthen our team. We:
- Provide reasonable accommodations throughout the application and employment process.
- Support different communication and collaboration preferences.
- Offer flexible working arrangements.
- Value both collaborative work and focused individual contribution time.
- Provide clear expectations, structured onboarding, and ongoing mentorship.
If you need any accommodations during the application process or have questions about how we work, please let us know.
Security Engineer in London employer: Surevine Limited
At Surevine Limited, we pride ourselves on fostering a collaborative and innovative work culture that empowers our employees to take ownership of their roles. As a Security Engineer, you will not only have the opportunity to influence security practices from the ground up but also benefit from continuous professional development and the chance to engage directly with clients. Located in a dynamic environment, we offer a unique blend of flexibility and support, making us an excellent employer for those seeking meaningful and rewarding careers in security.
StudySmarter Expert Advice🤫
We think this is how you could land Security Engineer in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Surevine Limited, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Surevine Limited
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Surevine Limited. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Security Engineer in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Surevine Limited insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Surevine Limited that you’re committed to staying ahead in the game.
How to prepare for a job interview at Surevine Limited
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Surevine Limited to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Surevine Limited.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.