Information Security Engineer
Location: Hybrid, London - 3 days onsite
Contract: 6 months to start, inside IR35
The Information Security Engineer is responsible for establishing and enhancing the security engineering capability within the organisation's Information Security team. The role focuses on identifying and addressing security gaps, collaborating with stakeholders, documenting security processes, and maintaining a secure IT infrastructure.
Key Responsibilities:
- Identify, assess, analyse, and document security control requirements, recommending solutions and implementing controls.
- Monitor systems for irregular behaviour, enabling preventive measures to address potential threats.
- Collaborate with stakeholders to configure, troubleshoot, and maintain security infrastructure, software, and hardware.
- Perform security reviews to identify vulnerabilities, define risk management plans, and ensure adequate protection.
- Capture and manage risks, assumptions, issues, decisions, and dependencies throughout security problem-solving activities.
- Improve, document, and maintain security processes and procedures, contributing to the security knowledge base.
- Develop and track the performance of security measures to protect the organisation's information and systems.
- Work alongside governance, risk, and compliance (GRC) functions to address and mitigate risks with contextual insights.
Key Skills:
- Strong understanding of security engineering requirements and best practices.
- Knowledge of security risk management frameworks such as NIST, ISO 27001, and PCI.
- Exceptional communication and stakeholder management skills, with the ability to translate technical security concepts for non-technical audiences.
- Strong documentation, presentation, and reporting skills.
- Critical thinking and problem-solving abilities in complex scenarios.
- Ability to work collaboratively across departments and with external partners to implement effective security measures.
Knowledge & Experience:
- Bachelor's degree in Computer Science, Cybersecurity, or related field; or equivalent certifications such as CEH.
- CISSP certification.
- Multi-year experience in security engineering.
- Hands-on experience with a wide range of security controls, including firewalls, IDS/IPS, encryption, and APIs.
- Familiarity with frameworks such as NIST, ISO 27001, OWASP, and CIS.
- Cloud security qualifications (e.g., AWS, GCP, Azure).
- Risk management experience (CRISC, ISO27005, NIST RMF)
- Secure Software Development Lifecycle (SSDLC) experience.
Personal Characteristics:
- High level of initiative and independence in managing security tasks.
- Strong problem-solving skills, capable of addressing complex issues within constraints.
- High personal integrity and sound judgement in handling sensitive security matters.
- Excellent collaboration, communication, and stakeholder management skills.