InfoSec Engineer

InfoSec Engineer

Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
watchTowr

At a Glance

  • Tasks: Join us to safeguard information assets and enhance our cybersecurity capabilities.
  • Company: Fast-growing cybersecurity firm trusted by Fortune 500 companies.
  • Benefits: Competitive pay, top-notch tools, and endless growth opportunities.
  • Why this job: Make a real impact in cybersecurity while working with industry experts.
  • Qualifications: 5+ years in cybersecurity, cloud security expertise, and strong scripting skills.
  • Other info: Inclusive culture that values diverse backgrounds and experiences.

The predicted salary is between 60000 - 80000 £ per year.

Hello, let us introduce ourselves! watchTowr is the Preemptive Exposure Management capability trusted by Fortune 500 companies and critical infrastructure providers. By combining proactive threat intelligence, real attacker telemetry, and automated red teaming, watchTowr continuously identifies and validates real exposure - so security teams can outrun real-world threats. When exploitation happens in hours, watchTowr delivers what no one else can: time to respond. We are a global team of operators, researchers, and engineers who have spent years thinking like attackers - and we are now building the technology to stop them. Our work is recognised across the industry, with original vulnerability research from watchTowr Labs and innovations like Instinct and Attacker Eye shaping the future of cybersecurity. Backed by $29M in funding, recognised by Gartner, and scaling fast across the globe, we are in a high-growth phase of our journey. We are a young, high-energy, and research-driven team, obsessed with building world-class technology - and we want exceptional people to join us.

But what’s the role? We are looking for an ambitious and hands-on InfoSec Engineer to join us to manage and continuously evolve watchTowr’s internal cyber security capability. The role will be responsible for safeguarding the organization’s information assets, ensuring compliance with industry regulations and internal policies, and supporting the secure management of internal IT systems. This role requires a balance of technical security expertise, compliance awareness, and hands-on IT administration skills.

Sounds great – what will I do? The role will focus on three main areas:

  • Information Security
  • Cloud Security Architecture (AWS): Design, implement, and maintain secure architectures within our AWS environment to protect against evolving threats.
  • Vulnerability Assessment and Management: Conduct regular internal vulnerability scans, analyze results, and coordinate remediation to improve overall security posture.
  • Implementation of Security Controls: Deploy and manage security controls across infrastructure, servers, and endpoints (laptops), ensuring both compliance and proactive defense.
  • Security Architecture in the Cloud: Continuously evaluate and strengthen cloud security, ensuring scalability, resilience, and compliance with best practices.
  • Automation and Scripting: Develop scripts and tools (Python, PowerShell, etc.) to automate repetitive security tasks and improve operational efficiency.
  • Compliance and governance
    • Compliance Programmes: Support and maintain alignment with ISO 27001 and SOC 2 Type 2 frameworks, contributing to audits, documentation, and evidence collection.
    • Security Awareness: Develop, deliver, and assess security awareness training to ensure staff understand and follow security best practices.
    • Policy and Process Maintenance: Assist in reviewing and updating security policies, standards, and processes to ensure ongoing compliance.
  • Internal IT management
    • Endpoint Management: Oversee deployment, configuration, patching, and security of all endpoints, including servers and laptops.
    • Identity and Access Management: Administer and secure user identities through Azure Active Directory, including role-based access control, MFA, and SSO.
    • MDM Administration: Manage InTune and mobile device management solutions to enforce secure configurations and compliance across devices.

    Sounds perfect to me, what specifics are you looking for?

    Core Skills

    • 5+ years of professional experience in cybersecurity, with exposure to IT administration in a startup or lean environment.
    • Proven expertise in cloud security (AWS), including architecture and controls.
    • Hands-on experience with endpoint security solutions and best practices.
    • Proficiency in vulnerability management, including assessment and remediation.
    • Experience managing Azure AD and MDM platforms.
    • Strong automation and scripting skills (Python, PowerShell, or similar).
    • Experience delivering security awareness training and assessments.
    • Ability to operate independently in a resource-constrained environment (hands-on, no team to delegate to).

    Advantages

    • Experience in incident response, including planning, execution, and post-incident review.
    • Relevant certifications (e.g., CISSP, CISM, AWS Security Specialty, Azure Security Engineer Associate, ISO 27001 Lead Implementer).
    • Familiarity with DevSecOps and security integration in CI/CD pipelines.
    • Exposure to regulated industries (finance, healthcare, etc.).

    What’s in it for me?

    • Competitive compensation - we believe that hard work, skills and ambition should be fairly compensated.
    • Meaningful role in a company - You will be a key and early contributor to a fast-growing cybersecurity business that helps protect some of the world's largest enterprises.
    • The best tools and powerful kit - we enable you with the tools to effectively fulfil your role.
    • Endless opportunities – we are in a high-growth phase of our journey, and plan to promote from within as we scale.
    • Work with cyber security experts – we are solving cutting-edge industry-wide cyber security challenges with some of the world’s most advanced organisations.

    watchTowr is proud to be an Equal Opportunity Employer. At watchTowr, we’re dedicated to fostering an inclusive, respectful, and diverse environment where every individual is recognised for their talent and potential. Our hiring decisions are guided by your capabilities, experience, and what you bring to the role - not by unrelated personal attributes. We have a zero-tolerance approach to any form of discrimination or harassment. This includes - but isn’t limited to - discrimination based on race, ethnicity, religion, colour, nationality, sex, sexual orientation, gender identity or expression, age, disability, pregnancy or parental status, veteran status, or any other characteristic protected by law. We actively encourage people from all backgrounds to apply. Even if you don’t tick every box in the job description, we’d still love to hear from you.

    InfoSec Engineer employer: watchTowr

    At watchTowr, we pride ourselves on being an exceptional employer, offering a dynamic and inclusive work culture that fosters innovation and collaboration. As a rapidly growing cybersecurity firm, we provide our employees with competitive compensation, access to cutting-edge tools, and ample opportunities for professional growth within a supportive environment. Join us in making a meaningful impact as we protect some of the world's largest enterprises from evolving cyber threats.
    watchTowr

    Contact Detail:

    watchTowr Recruiting Team

    StudySmarter Expert Advice 🤫

    We think this is how you could land InfoSec Engineer

    ✨Tip Number 1

    Network like a pro! Reach out to current employees at watchTowr on LinkedIn or other platforms. Ask them about their experiences and any tips they might have for landing the InfoSec Engineer role. Personal connections can give you an edge!

    ✨Tip Number 2

    Show off your skills! If you’ve got hands-on experience with AWS, Python, or vulnerability management, consider creating a small project or demo that showcases your abilities. Bring this along to interviews to demonstrate your expertise in action.

    ✨Tip Number 3

    Prepare for the technical interview! Brush up on your cloud security knowledge and be ready to discuss real-world scenarios. Think about how you would handle specific vulnerabilities or security challenges, as this will show you’re ready for the fast-paced environment at watchTowr.

    ✨Tip Number 4

    Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in being part of the watchTowr team!

    We think you need these skills to ace InfoSec Engineer

    Cloud Security Architecture (AWS)
    Vulnerability Assessment and Management
    Implementation of Security Controls
    Automation and Scripting (Python, PowerShell)
    Compliance with ISO 27001 and SOC 2 Type 2
    Security Awareness Training
    Endpoint Management
    Identity and Access Management (Azure Active Directory)
    MDM Administration (InTune)
    Incident Response
    DevSecOps
    Security Integration in CI/CD Pipelines

    Some tips for your application 🫡

    Show Your Passion for Cybersecurity: When writing your application, let your enthusiasm for cybersecurity shine through! We want to see how your experiences and interests align with our mission at watchTowr. Share specific examples of projects or challenges you've tackled that demonstrate your commitment to the field.

    Tailor Your CV and Cover Letter: Make sure to customise your CV and cover letter for the InfoSec Engineer role. Highlight relevant skills like cloud security, vulnerability management, and automation. We love seeing how your unique background fits into our team, so don’t hold back on showcasing your expertise!

    Be Clear and Concise: Keep your application clear and to the point. Use bullet points where possible to make it easy for us to read through your qualifications. Remember, we’re looking for someone who can communicate effectively, so show us you can do that right from the start!

    Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re proactive and keen to join our team at watchTowr!

    How to prepare for a job interview at watchTowr

    ✨Know Your Stuff

    Make sure you brush up on your knowledge of cloud security, especially AWS. Be ready to discuss specific architectures and controls you've implemented in the past. This will show that you not only understand the theory but have practical experience too.

    ✨Showcase Your Hands-On Skills

    Since this role requires a hands-on approach, prepare examples of how you've managed endpoint security or conducted vulnerability assessments. Highlight any automation or scripting you've done with Python or PowerShell to streamline security tasks.

    ✨Understand Compliance Inside Out

    Familiarise yourself with ISO 27001 and SOC 2 Type 2 frameworks. Be prepared to discuss how you've contributed to compliance programmes in previous roles, including audits and policy maintenance. This will demonstrate your ability to align with industry regulations.

    ✨Be Ready for Scenario Questions

    Expect scenario-based questions that test your problem-solving skills in real-world situations. Think about past incidents you've handled or how you'd approach a new threat. This will help the interviewers see your critical thinking and decision-making abilities in action.

    Land your dream job quicker with Premium

    You’re marked as a top applicant with our partner companies
    Individual CV and cover letter feedback including tailoring to specific job roles
    Be among the first applications for new jobs with our AI application
    1:1 support and career advice from our career coaches
    Go Premium

    Money-back if you don't land a job in 6-months

    >