Senior Security & Compliance Engineer

Senior Security & Compliance Engineer

Full-Time 60000 - 80000 £ / year (est.) No working from home possible
U

At a Glance

  • Tasks: Monitor security events, lead vulnerability management, and conduct security audits.
  • Company: Join Upstream, a global leader in mobile marketing automation and digital innovation.
  • Benefits: Competitive salary, dynamic team environment, and opportunities for professional growth.
  • Other info: Flexible work style and strong teamwork culture in a fast-paced environment.
  • Why this job: Make a real impact in security while working with cutting-edge technologies.
  • Qualifications: Expertise in security testing, networking, and compliance frameworks required.

The predicted salary is between 60000 - 80000 £ per year.

Who we are

Upstream is a global leader in mobile marketing automation and digital service innovation, enabling Mobile Network Operators (MNOs) and brands to grow revenue, improve customer engagement and succeed in the digital economy. With over two decades of experience and operations spanning 45+ markets across Africa, Latin America, Asia, Europe, and the Middle East, we are a trusted partner to more than 60 MNOs worldwide. Headquartered in Athens, Greece, and with regional hubs in London, Dubai, Johannesburg, Lagos, São Paulo and Rio de Janeiro, Upstream combines global expertise with deep local insight. Our end-to-end approach encompasses strategy, creative development, technical deployment, campaign execution, and ongoing optimization, ensuring seamless, scalable, and performance-driven service delivery.

About the role

Our focus centers on bringing domain-specific security knowledge, skills, and best practices to our talented network and engineering teams. We are seeking a Sr. Security & Compliance Engineer to provide added value services, helping ensure our business remains highly available, flexible, and robust. An ideal candidate would be a passionate engineer who is dedicated to pursuing complicated technical security problems and coming up with robust engineering solutions. This role requires someone who can exhibit a technical lead role for projects and technologies, who acts as a crucial point of reference within the company, and thrives in challenging, production-facing environments.

What you will do

  • Monitor and respond to security events, managing escalation and acting as a liaison during security incidents.
  • Serve as a dedicated security analyst for critical projects.
  • Lead the vulnerability management lifecycle, overseeing installation and patching efforts.
  • Conduct specialized security work, including security audits, Penetration Testing (e.g., CHECK, CREST, CEH, TIGER), evidence collection, and forensics analysis.
  • Drive and own technical tasks, pursuing their completion within time and technological constraints.
  • Contribute to end-user security education and awareness.
  • Maintain and update compliance posture, ensuring security policies and standards remain current and effective.
  • Serve as a primary technical resource for security-related client discussions, articulating technical concepts to various types of audiences.
  • Provide essential security content and review for commercial engagements, including RFPs, bids, and client assurances.

Requirements

  • Networking & Infrastructure: Excellent knowledge of TCP/IP and comprehensive understanding of the core Linux network stack.
  • Security Testing Methodologies: Expert proficiency in essential security disciplines including Network Traffic and Protocol Analysis, comprehensive Vulnerability Assessment and Scanning methodologies, network service enumeration, and hands‑on Web Application Penetration Testing techniques.
  • System and Infrastructure Hardening: Proven, hands‑on experience in developing, implementing, and auditing standardized security baselines, robust configuration management controls, and effective patch management strategies across diverse operating system and application platforms, including critical data services.
  • Security Control Systems: Deep knowledge and hands‑on experience with SIEM solutions and Vulnerability Management platforms. Experience implementing and managing IPS Systems (Cisco, Checkpoint) and Firewalls (Cisco, Checkpoint).
  • Proficiency with DLP and Endpoint Protection solutions, including Application Control and Device Control.
  • Experience with Web Application Firewalls (WAF).
  • Familiarity with products for IDAM (Identity and Access Management).
  • Data Protection: Experienced in data encryption technologies and products.
  • Development: High-quality Python/shell development experience is considered a plus.
  • Knowledge of Cloud and Mobile Security Architecture: Experience with cloud and mobile security principles and practices.
  • Security Governance: Demonstrable knowledge of common security standards and compliance frameworks (e.g., ISO 27001, NIST Cybersecurity Framework, SOC 2) and practical experience translating technical controls into formal, auditable security policies and procedures.
  • Formal Documentation: Proven ability to translate complex security testing results, audits, and posture assessments into high-quality, professional, and accessible documentation suitable for internal leadership and external client assurance reviews.
  • Stakeholder Communication: Solid communication skills (both oral and written), being able to explain concepts and ideas to various types of audiences, with proven experience presenting technical security findings and strategy to both C‑level executives and external clients.

Additional Experience

  • Knowledge of Cloud and Mobile Security Architecture and experience in datacenter protection strategies.
  • Prior experience in a network position will be considered a plus.

Core Competencies

  • Operational Excellence: Track record of meeting deadlines in challenging situations, dependable, reliable, with strong attention to detail; requires a flexible work style to ensure quality standards are met.
  • Teamwork: Strong team player, capable of providing guidelines and assistance to peers.

Benefits

We offer a competitive base salary and benefits, directly dependent on the candidate’s qualifications and skills. The real excitement comes from working closely with a dynamic, smart, agile, and highly motivated team in a competitive and fast‑paced environment.

Senior Security & Compliance Engineer employer: Upstream

At Upstream, we pride ourselves on being an excellent employer by fostering a vibrant work culture that encourages innovation and collaboration among our talented teams. Located in Athens, Greece, we offer competitive salaries, comprehensive benefits, and ample opportunities for professional growth, all while working on cutting-edge security solutions in a dynamic and fast-paced environment. Join us to be part of a global leader in mobile marketing automation, where your contributions will directly impact our success and the satisfaction of our clients worldwide.

U

Contact Details:

Upstream Recruitment Team

We think you need these skills to ace Senior Security & Compliance Engineer

Security Event Monitoring
Vulnerability Management
Penetration Testing
Security Audits
Network Traffic Analysis
Vulnerability Assessment
System Hardening