IT Security Engineer

SR2
UK
2 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
£45,000.0 - £50,000.0
Working hours
Regular working hours

Tech stack

Cloud Computing Security Cyber Security Identity and Access Management Phishing Security Information and Event Management Software Vulnerability Management Scripting Cybercrime Performance Monitor Vulnerability Analysis

Job description

IT Security Engineer (Hybrid: 3 days on-site in Hertfordshire / 2 days remote) £45-50k Permanent

SR2 is partnering with a well-established, member-owned UK organisation to hire an IT Security Engineer to strengthen cyber resilience and improve day-to-day security operations. This is a hands-on role sitting within IT, working closely with infrastructure and support teams to embed security into BAU and projects.

What you’ll be doing

  • Own day-to-day vulnerability monitoring and remediation, including maintaining a vulnerability register and tracking actions to closure
  • Triage, categorise and prioritise vulnerabilities based on risk, exposure and business impact
  • Support patching, configuration hardening and decommissioning activities to reduce risk exposure
  • Monitor and respond to security alerts and incidents, contributing to investigation and improvement actions
  • Help improve detection and response capability (more proactive monitoring and response workflows)
  • Work with external providers (e.g., SOC / security vendors) to reduce high-priority risks
  • Develop and maintain security playbooks (phishing, ransomware, account compromise, etc.)
  • Provide security input into projects, changes and supplier reviews so security is built-in from the start
  • Support audits / assessments (e.g., vulnerability assessments, pen tests, configuration benchmarks, PCI where relevant)
  • Contribute to awareness initiatives and practical security guidance across the business
  • Support progress against NIST CSF focus areas and maturity improvements

What we’re looking for

  • 3+ years in security operations / cybersecurity engineering (or strong IT ops experience with security ownership)
  • Strong understanding of vulnerability management processes and risk-based prioritisation
  • Familiarity with email + endpoint security controls (e.g., Defender-style toolsets, phishing controls, email security)
  • Awareness of IAM concepts: MFA, conditional access, privileged access/PIM
  • Comfortable working with technical teams to get remediation delivered (patching cycles, change, infrastructure support)
  • Clear communicator who can explain risk to both technical and non-technical stakeholders
  • Bonus points for: SIEM exposure, threat hunting, cloud security, automation/scripting, infrastructure/networking

Package

  • £45-50k salary range
  • Private medical insurance, life assurance, permanent health insurance
  • Staff discount, interest-free loan scheme, sports & social club

Working pattern

  • Hybrid: 3 days per week on-site in Hertfordshire, 2 days remote

Requirements

  • 3+ years in security operations / cybersecurity engineering (or strong IT ops experience with security ownership)
  • Strong understanding of vulnerability management processes and risk-based prioritisation
  • Familiarity with email + endpoint security controls (e.g., Defender-style toolsets, phishing controls, email security)
  • Awareness of IAM concepts: MFA, conditional access, privileged access/PIM
  • Comfortable working with technical teams to get remediation delivered (patching cycles, change, infrastructure support)
  • Clear communicator who can explain risk to both technical and non-technical stakeholders
  • Bonus points for: SIEM exposure, threat hunting, cloud security, automation/scripting, infrastructure/networking

Benefits & conditions

  • £45-50k salary range
  • Private medical insurance, life assurance, permanent health insurance
  • Staff discount, interest-free loan scheme, sports & social club

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all