Help us use technology to make a big green dent in the universe! Its a really exciting time in energy. Help us make a real impact on shaping a better more sustainable future.
We are very excited to be building a small and efficient Cyber and Information Security team at Octopus Energy Group. Were hiring for both MidLevel and Senior Security Engineers. We are looking for ambitious knowledgeable and experienced Security Engineers to join our team to grow with the rest of the company and ensure we continue to do so in a secure and safe way.
You will be a key partner in defining what Security is at Octopus Energy Group. We will be shaping this team to provide a world class support service to our employees building our way out of problems with engineering firepower and undertaking transformational organisational change.
Youll play a crucial role in helping to secure our software development processes securing our platform services integrating security practices and shaping a culture of security. This is a creative and collaborative position that is a fulltime member of a CloudFirst organisation. If youre passionate about Cloud technologies and driving security by design we encourage you to apply!
Specifically were looking for Security Engineers with at least 2 years of relevant experience to help us improve security across the Octopus Energy Group. Senior Security Engineers should bring 4 years of relevant experience.
What youll do:
Build and maintain security tooling and infrastructure to improve our overall security posture
Respond to security incidents and help improve incident processes
Work with the wider Platform and application teams to ensure that our infrastructure systems and applications are secure
Develop secure coding practices and provide guidance to development teams on application security best practices
Keep up to date with the latest security trends and technologies related to application security and evaluate their potential impact on our systems and data
Develop and maintain security documentation related to application security including policies procedures and guidelines
This is a varied role in a growing team. Youll have the opportunity to get involved in other securityrelated projects and initiatives as needed. We encourage you to take on new challenges that align with your skills and internests and to collaborate with other teams to drive improvements in security across our entire organisation
What youll have:
Excellent security and technology background
Strong understanding of web application security concepts including OWASP Top 10 vulnerabilities secure coding practices and application security testing tools
Experience with security tools and technologies such as web application firewalls (WAFs) and static and dynamic application security testing (SAST/DAST) tools
Experience in endpoint (e.g. EDR and ZTNA) and cloud (e.g. CSPM and CNAPP) security tooling
Experience security SaaS solutionsGood AWS experience (or knowledge) and familiarity with various AWS security services (or familiarity with Azure and/or GCP with a willingness to learn AWS)
Strong analytical and problemsolving skills with the ability to identify and mitigate security risks
A good candidate will have experience in at least some of the areas mentioned were not expecting any candidate to be an expert in all areas!
What will help:
Security certifications (any of the famous abbreviations)
Certifications from cloud providers certification paths
Security qualifications (e.g. apprenticeships or degrees)
Experience with preparing high quality documentation
Experience using logging tools (whether this was a SIEM system or not) to generate alerts and reports
Knowledge of the MITRE ATT&CK framework
Why else youll love it here
Wondering what the salary for this role isJust ask us! On a call with one of our recruiters its something we always cover as we genuinely want to match your experience with the correct salary. The reason why we dont advertise is because we honestly have a degree of flexibility and would never want salary to be a reason why someone doesnt apply to Octopus whats more important to us is finding the right octofit!
Our process usually takes up to 4 weeks but well always do our best to flex around what works for you. Along the way youll chat with our recruitment team and your Recruiter will help you throughout different stages. Got any burning questions before then Drop us a message at and wed love to help!
If this sounds like you then wed love to hear from you.
Are you ready for a career with us We want to ensure you have all the tools and environment you need to unleash your any specific accommodationsWhether you require specific accommodations or have a unique preference let us know and well do what we can to customise your interview process for comfort and maximum magic!
Studies have shown that some groups of people like women are less likely to apply to a role unless they meet 100% of the job requirements. Whoever you are if you like one of our jobs we encourage you to apply as you might just be the candidate we hire. Across Octopus were looking for genuinely decent people who are honest and empathetic. Our people are our strongest asset and the unique skills and perspectives people bring to the team are the driving force of our success. As an equal opportunity employer we do not discriminate on the basis of any protected attribute. Our commitment is to provide equal opportunities an inclusive work environment and fairness for everyone.
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.