drjobs Security Engineer (Mid and Senior)

Security Engineer (Mid and Senior)

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

London - UK

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Help us use technology to make a big green dent in the universe! Its a really exciting time in energy. Help us make a real impact on shaping a better more sustainable future.

We are very excited to be building a small and efficient Cyber and Information Security team at Octopus Energy Group. Were hiring for both MidLevel and Senior Security Engineers. We are looking for ambitious knowledgeable and experienced Security Engineers to join our team to grow with the rest of the company and ensure we continue to do so in a secure and safe way.

You will be a key partner in defining what Security is at Octopus Energy Group. We will be shaping this team to provide a world class support service to our employees building our way out of problems with engineering firepower and undertaking transformational organisational change.

Youll play a crucial role in helping to secure our software development processes securing our platform services integrating security practices and shaping a culture of security. This is a creative and collaborative position that is a fulltime member of a CloudFirst organisation. If youre passionate about Cloud technologies and driving security by design we encourage you to apply!

Specifically were looking for Security Engineers with at least 2 years of relevant experience to help us improve security across the Octopus Energy Group. Senior Security Engineers should bring 4 years of relevant experience.

What youll do:

    • Build and maintain security tooling and infrastructure to improve our overall security posture
    • Respond to security incidents and help improve incident processes
    • Work with the wider Platform and application teams to ensure that our infrastructure systems and applications are secure
    • Develop secure coding practices and provide guidance to development teams on application security best practices
    • Keep up to date with the latest security trends and technologies related to application security and evaluate their potential impact on our systems and data
    • Develop and maintain security documentation related to application security including policies procedures and guidelines

    • This is a varied role in a growing team. Youll have the opportunity to get involved in other securityrelated projects and initiatives as needed. We encourage you to take on new challenges that align with your skills and internests and to collaborate with other teams to drive improvements in security across our entire organisation

What youll have:

    • Excellent security and technology background
    • Strong understanding of web application security concepts including OWASP Top 10 vulnerabilities secure coding practices and application security testing tools
    • Experience with security tools and technologies such as web application firewalls (WAFs) and static and dynamic application security testing (SAST/DAST) tools
    • Experience in endpoint (e.g. EDR and ZTNA) and cloud (e.g. CSPM and CNAPP) security tooling
    • Experience security SaaS solutionsGood AWS experience (or knowledge) and familiarity with various AWS security services (or familiarity with Azure and/or GCP with a willingness to learn AWS)
    • Strong analytical and problemsolving skills with the ability to identify and mitigate security risks

    • A good candidate will have experience in at least some of the areas mentioned were not expecting any candidate to be an expert in all areas!

What will help:

    • Security certifications (any of the famous abbreviations)
    • Certifications from cloud providers certification paths
    • Security qualifications (e.g. apprenticeships or degrees)
    • Experience with preparing high quality documentation
    • Experience using logging tools (whether this was a SIEM system or not) to generate alerts and reports
    • Knowledge of the MITRE ATT&CK framework

Why else youll love it here




Employment Type

Full-Time

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.