Security Engineer

SOUTHERN COMMUNICATIONS LIMITED
Basingstoke, UK
7 days ago
Apply on www.totaljobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£40,000.0 - £50,000.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security Identity and Access Management Software Vulnerability Management Information Security Management System Information Technology

Job description

The purpose of this role is to protect the organisation’s IT systems and data through implementing, managing and monitoring security controls, responding to security incidents, and ensuring compliance with security accreditations.

Responsibilities:

Security Operations & Incident Management:

  • Managing ticket workload within the Security team.
  • Gathering, analysing and acting upon threat intelligence.
  • Responding to on-going security incidents.
  • Responding to active alerts from security systems.
  • Writing change management requests for security-related changes.

Vulnerability & Endpoint Management:

  • Conducting penetration testing and tracking corrective actions.
  • Resolving vulnerabilities in the infrastructure and EUC estate.
  • Defining and managing the configuration of endpoint protection policies.
  • Managing the configuration of Identity and Access Management services.

Accreditation & Compliance:

  • Writing and ratifying policies and ensuring compliance with the Information Security Management System (ISO27001).
  • Ensuring compliance with CyberEssentials and CyberEssentials+ requirements and carrying out audits.
  • Ensuring compliance with accreditation policies through auditing with external 3rd party auditors.

Requirements

  • Strong technical knowledge of security tools, frameworks and best practices.
  • Experience with penetration testing and vulnerability management processes.
  • Understanding of endpoint protection technologies and policies.
  • Knowledge of identity and access management principles.
  • Familiarity with security accreditations such as ISO27001, CyberEssentials and CyberEssentials+.
  • Excellent incident response and threat intelligence skills.
  • Strong communication skills to convey security matters to technical and non-technical audiences.

Benefits & conditions

  • 25 Days Holiday
  • Birthday Day Off
  • Buy Holiday Scheme
  • Career Development and Progression Opportunities
  • Employee Assistance Programme
  • Enhanced Company Sick Pay
  • Discounted Retail Vouchers
  • Reduced Gym Membership
  • SCG Mobile Benefit
  • Employee Referral Bonus
  • Annual Salary Reviews
  • Pension Scheme
  • Onsite Canteen (offering free croissants and free freshly made soup daily)
  • Free On-Site Parking
  • Charity Events

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all