At a Glance
- Tasks: Join our team to enhance security and manage vulnerabilities across diverse platforms.
- Company: Wellington Management, a leader in investment management with a collaborative culture.
- Benefits: Competitive salary, flexible remote work, and opportunities for professional growth.
- Other info: Dynamic team environment with mentorship opportunities and a commitment to diversity.
- Why this job: Make a real impact in cyber-security while working with cutting-edge technologies.
- Qualifications: Passion for cyber-security and experience in vulnerability management are essential.
The predicted salary is between 63000 - 77000 £ per year.
About Us
Wellington Management offers comprehensive investment management capabilities that span nearly all segments of the global capital markets. Our investment solutions, tailored to the unique return and risk objectives of institutional clients in more than 60 countries, draw on a robust body of proprietary research and a collaborative culture that encourages independent thought and healthy debate. As a private partnership, we believe our ownership structure fosters a long-term view that aligns our perspectives with those of our clients.
About the Role
THE POSITION
The Attack Surface Management team is seeking a Senior Security Engineer to be a key member of our team. There will be a heavy focus on building, maturing, and operationalizing a configuration baselines program spanning physical and virtual systems, serverless workloads, container security, and other platforms. This engineer will assist in the minimization of potential attack surfaces through vulnerability management, managing a baselines program, cloud configuration assessments, incorporating threat intelligence from public and private sources, and work internally to build and enhance policies, standards, and processes. They will be working with various technologies that surface vulnerabilities, misconfigurations, end of life software, and other vectors. The ideal candidate is one that has a passion for cyber-security, a natural curiosity, and is willing to think outside the box to challenge the status quo in Attack Surface Management.
RESPONSIBILITIES
- Develop and mature an internal security hardening and baselines program. This effort develops standards and process to ensure attack surface risk is reduced and configuration baseline is met both according to CIS Controls and cyber threats actively targeting the firm.
- Perform assessments and communicate to stakeholders on the likelihood of exploitation and potential impact of vulnerabilities, misconfiguration findings, and other potential vectors to determine the appropriate course of action to mitigate potential risk.
- Leverage Cloud Native Application Protection Platform (CNAPP) technology to assess findings and contribute guidance and expertise to application custodians on fixing issues.
- Act as a security liaison between Information Security and the Development staff to bring a security mindset to the software development lifecycle.
- Assess and understand the Wellington CI/CD pipeline to be able to provide recommendations to developers for securing their code.
- Stay up to date with current and relevant cyber security threats as well as any associated countermeasures.
- Participate in internal meetings to map industry cyber threats to our current attack surface.
- Review of both internal and open-source threat intelligence sources for recently disclosed vulnerabilities at risk of introduction into the Wellington environment.
- Work with our Third-Party Risk team to engage third parties in Wellington's vendor ecosystem to understand when third and fourth parties may be exposed to critical vulnerabilities.
- Contribute to team documentation for updates to existing processes, new processes, assessment tool infrastructure details and workflows.
- Contribute to firmwide documentation by being an SME contributor to policies and standards.
NON-TECHNICAL QUALIFICATIONS
- A Passion for cyber-security is a must.
- Ability to self-motivate, with an eagerness to dig into potential risks. Ask questions, be curious, dig deeper.
- BS degree in Information Systems/related discipline or equivalent IT work experience.
- Experience in developing new processes and procedures that match evolving attack surfaces.
- Excellent oral and written communication skills with a proven ability to effectively interact with teams representing a wide variety of technical disciplines.
- Ability to work with global teams effectively.
- Ability to mentor junior team members and share discoveries about your work.
TECHNICAL QUALIFICATIONS
- Experience working with best practices frameworks such as CIS Critical Security Controls to drive an internal discovery and risk assessment program for a system baselines / hardening program.
- Knowledge of common cyber-attack types such as DDoS, SQLi, XSS, and others. This experience relied upon to make rational decisions in our baselines program.
- Hands-on experience with vulnerability assessment software and prioritizing results using a combination of various frameworks tied to internal objects (CVE, CVSS, EPSS, etc.).
- Previous experience assessing, documenting, and communicating information security risk, particularly related to cyber vulnerabilities is preferred.
- Experience in the use of common scripting languages such as python to automate job functions.
- Working knowledge of IaC (Infrastructure as Code) concepts, especially with AWS.
- Knowledge in the areas of network architecture and engineering and software application development.
- Working knowledge of the use of threat intelligence feeds and resources.
Preferred:
- Experience working with Splunk, Qualys, WIZ, Artifactory, AWS Cloudformation.
- Working knowledge of Amazon AWS services.
- Home labs, security practitioner meetups, research, we would love to hear it!
Not sure you meet 100% of our qualifications? That's ok. If you believe that you could excel in this role, we encourage you to apply and welcome a chance to review your background. We are dedicated to building and maintaining a diversified workforce and considering a broad array of candidates with a variety of skill, workplace experiences, and backgrounds. As an equal opportunity employer, Wellington Management ensures that all qualified applicants will receive equal consideration for employment without regard to race, color, sex, sexual orientation, gender identity, gender expression, religion, creed, national origin, age, ancestry, disability (physical or mental), medical condition, citizenship, marital status, pregnancy, veteran or military status, genetic information or any other characteristic protected by applicable law.
If you are a candidate with a disability, or are assisting a candidate with a disability, and require an accommodation to apply for one of our jobs, please email us at .
We believe that in person interactions inspire and energize our community and are essential to our culture. In support of this commitment, our employees work from our offices 4 days a week with flexibility to work remotely 1 day a week. We believe that this approach ultimately supports our mission to deliver investment excellence to our clients and their beneficiaries over the long term.
Senior Systems Engineer - Wellington Management Company, LLP in London employer: Wellington Management Company, LLP
Wellington Management is an exceptional employer, offering a dynamic work environment in the heart of London that fosters collaboration and independent thought. With a strong commitment to employee growth, we provide comprehensive training and development opportunities, ensuring that our Business Associates thrive in their careers while contributing to meaningful client relationships. Our culture prioritises diversity and inclusion, making it a rewarding place for recent graduates eager to make an impact in the investment management industry.
Contact Details:
Wellington Management Company, LLP Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Senior Systems Engineer - Wellington Management Company, LLP in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Wellington Management Company, LLP, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Wellington Management Company, LLP
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Wellington Management Company, LLP. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Systems Engineer - Wellington Management Company, LLP in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Wellington Management Company, LLP insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Wellington Management Company, LLP that you’re committed to staying ahead in the game.
How to prepare for a job interview at Wellington Management Company, LLP
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Wellington Management Company, LLP to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Wellington Management Company, LLP.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.